CVE-2026-16189
- EPSS 0.22%
- Veröffentlicht 14.09.2026 19:51:31
- Zuletzt bearbeitet 16.09.2026 19:24:58
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log entries into the server's administrative log.
CVE-2026-16435
- EPSS 0.31%
- Veröffentlicht 14.09.2026 19:49:05
- Zuletzt bearbeitet 16.09.2026 19:24:58
IBM WebSphere Application Server 9.0, and 8.5 is affected by an authentication bypass vulnerability when using XD or Intelligent-Management features.
CVE-2026-9667
- EPSS 0.31%
- Veröffentlicht 10.09.2026 20:57:22
- Zuletzt bearbeitet 15.09.2026 17:05:49
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) that could allow a remote, unauthenticated attacker to cause the server to send outbound requests to arbitrary endpoints.
CVE-2026-9176
- EPSS 0.13%
- Veröffentlicht 10.09.2026 20:45:57
- Zuletzt bearbeitet 15.09.2026 17:11:15
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a security bypass due to improper authentication controls. A local attacker could exploit this vulnerability to escalate privileges and gain unauthorized access to protected resources.
CVE-2026-9327
- EPSS 0.19%
- Veröffentlicht 10.09.2026 20:44:01
- Zuletzt bearbeitet 15.09.2026 17:08:56
IBM WebSphere Application Server 9.0, and 8.5 could allow an authenticated user with a low-privilege administrative role to modify security configuration. This could result in information disclosure or denial of service.
CVE-2026-9336
- EPSS 0.22%
- Veröffentlicht 10.09.2026 18:45:02
- Zuletzt bearbeitet 16.09.2026 18:15:26
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted HTTP request to an administrative endpoint. A remote attacker could exploit this vulnerability to cause the server to exhaust fi...
CVE-2026-9338
- EPSS 0.29%
- Veröffentlicht 10.09.2026 18:44:35
- Zuletzt bearbeitet 16.09.2026 18:14:23
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to trigger excessive resource consumption, potentially leading to re...
CVE-2026-14525
- EPSS 0.55%
- Veröffentlicht 13.08.2026 19:37:33
- Zuletzt bearbeitet 17.08.2026 18:10:40
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is vulnerable to an authentication bypass when the rtcomm-1.0 or rtcommGateway-1.0 feature is enabled.
CVE-2026-10571
- EPSS 0.53%
- Veröffentlicht 13.08.2026 19:30:52
- Zuletzt bearbeitet 17.08.2026 18:29:39
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service caused by insecure deserialization. A low-privileged, administrative user could exploit this vulnerability to consume system resources when the re...
CVE-2026-18499
- EPSS 0.27%
- Veröffentlicht 12.08.2026 16:25:07
- Zuletzt bearbeitet 17.08.2026 17:36:35
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to a privilege escalation when using Liberty collectives.