CVE-2026-11537
- EPSS 0.19%
- Veröffentlicht 18.09.2026 16:17:05
- Zuletzt bearbeitet 19.09.2026 15:16:56
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet.
CVE-2026-15396
- EPSS 0.25%
- Veröffentlicht 14.09.2026 20:08:38
- Zuletzt bearbeitet 16.09.2026 19:22:22
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP transfer-encoding request header. By sending a specially crafted HTTP transf...
CVE-2026-15412
- EPSS 0.22%
- Veröffentlicht 14.09.2026 20:08:05
- Zuletzt bearbeitet 16.09.2026 19:24:58
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a rem...
CVE-2026-15634
- EPSS 0.25%
- Veröffentlicht 14.09.2026 20:01:35
- Zuletzt bearbeitet 16.09.2026 19:24:58
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP transfer-encoding request header. By sending a specially crafted HTTP transf...
CVE-2026-15887
- EPSS 0.18%
- Veröffentlicht 14.09.2026 19:58:40
- Zuletzt bearbeitet 16.09.2026 19:24:58
IBM WebSphere Application Server 9.0, and 8.5 is affected by blind server-side request forgery when processing SOAP requests.
CVE-2026-16186
- EPSS 0.18%
- Veröffentlicht 14.09.2026 19:58:02
- Zuletzt bearbeitet 16.09.2026 19:22:22
IBM WebSphere Application Server 9.0, and 8.5 is affected by a reflected cross-site scripting vulnerability.
CVE-2026-16185
- EPSS 0.2%
- Veröffentlicht 14.09.2026 19:57:30
- Zuletzt bearbeitet 16.09.2026 19:22:22
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication on an admin console servlet.
CVE-2026-16187
- EPSS 0.25%
- Veröffentlicht 14.09.2026 19:54:23
- Zuletzt bearbeitet 16.09.2026 19:22:22
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication and obtain sensitive information by sending a crafted unauthenticated request.
CVE-2026-16188
- EPSS 0.28%
- Veröffentlicht 14.09.2026 19:52:56
- Zuletzt bearbeitet 16.09.2026 19:22:22
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log entries into the server's administrative log.
CVE-2026-16190
- EPSS 0.16%
- Veröffentlicht 14.09.2026 19:51:47
- Zuletzt bearbeitet 16.09.2026 19:24:58
IBM WebSphere Application Server 9.0, and 8.5 is affected by an authorization bypass vulnerability.