CVE-2026-11806
- EPSS 0.26%
- Veröffentlicht 30.06.2026 20:17:28
- Zuletzt bearbeitet 02.07.2026 17:58:55
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 is affected by an arbitrary file read vulnerability with the restConnector-2.0 feature enabled.
CVE-2026-11546
- EPSS 0.21%
- Veröffentlicht 30.06.2026 20:17:27
- Zuletzt bearbeitet 02.07.2026 18:09:50
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the adminCenter-1.0 feature enabled.
CVE-2026-11595
- EPSS 0.66%
- Veröffentlicht 30.06.2026 20:17:27
- Zuletzt bearbeitet 02.07.2026 18:09:06
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information from the administrative console's integrated help system.
CVE-2026-11708
- EPSS 0.36%
- Veröffentlicht 30.06.2026 20:17:27
- Zuletzt bearbeitet 02.07.2026 18:07:30
IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console's integrated help system.
CVE-2026-11712
- EPSS 0.34%
- Veröffentlicht 30.06.2026 20:17:27
- Zuletzt bearbeitet 02.07.2026 18:06:52
IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console help system.
CVE-2026-10852
- EPSS 0.29%
- Veröffentlicht 22.06.2026 19:32:28
- Zuletzt bearbeitet 09.07.2026 21:16:54
IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to denial of service in the WebSphere WebServer Plug-in component when an attacker can pass crafted requests to the web server.
CVE-2026-9320
- EPSS 0.35%
- Veröffentlicht 22.06.2026 14:53:36
- Zuletzt bearbeitet 23.06.2026 20:46:51
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerab...
CVE-2026-9071
- EPSS 0.55%
- Veröffentlicht 22.06.2026 14:47:39
- Zuletzt bearbeitet 23.06.2026 20:46:35
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerab...
CVE-2026-9006
- EPSS 0.24%
- Veröffentlicht 22.06.2026 14:46:47
- Zuletzt bearbeitet 24.06.2026 05:17:30
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an attacker to send unauthorized requests from the system, resulting in a security bypass or information ...
CVE-2026-8646
- EPSS 0.37%
- Veröffentlicht 22.06.2026 14:44:42
- Zuletzt bearbeitet 24.06.2026 05:17:30
IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to HTTP request smuggling. A remote attacker could smuggle a specially crafted request to the application server ther...