CVE-2026-14446
- EPSS 0.29%
- Veröffentlicht 28.07.2026 20:52:17
- Zuletzt bearbeitet 05.08.2026 16:26:56
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the administrative console.
CVE-2026-14515
- EPSS 0.18%
- Veröffentlicht 28.07.2026 20:50:33
- Zuletzt bearbeitet 05.08.2026 16:21:39
IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to conduct a cross-site scripting attack.
CVE-2026-14512
- EPSS 0.52%
- Veröffentlicht 28.07.2026 20:50:08
- Zuletzt bearbeitet 05.08.2026 16:24:19
IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attacker to bypass authentication or execute arbitrary code.
CVE-2026-14528
- EPSS 0.26%
- Veröffentlicht 28.07.2026 20:37:32
- Zuletzt bearbeitet 05.08.2026 16:00:48
IBM WebSphere Application Server 9.0, and 8.5 traditional could allow a remote attacker to obtain sensitive information.
CVE-2026-14974
- EPSS 0.38%
- Veröffentlicht 28.07.2026 20:29:47
- Zuletzt bearbeitet 05.08.2026 15:54:54
IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of untrusted data.
CVE-2026-14976
- EPSS 0.31%
- Veröffentlicht 28.07.2026 20:29:09
- Zuletzt bearbeitet 05.08.2026 15:53:53
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code execution with the collectiveController-1.0 feature enabled.
CVE-2026-14981
- EPSS 0.26%
- Veröffentlicht 28.07.2026 20:22:37
- Zuletzt bearbeitet 23.09.2026 21:16:57
IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty are affected by a denial of service vulnerability in the HTTP channel due to unbounded allocation of resources without limits.
CVE-2026-15057
- EPSS 0.26%
- Veröffentlicht 28.07.2026 20:11:58
- Zuletzt bearbeitet 05.08.2026 19:21:02
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service due to uncontrolled heap allocation.
CVE-2026-15064
- EPSS 0.22%
- Veröffentlicht 28.07.2026 20:10:16
- Zuletzt bearbeitet 23.09.2026 21:16:58
IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTTP Response Smuggling due to improper handling of non-standard HTTP version tokens.
CVE-2026-15280
- EPSS 0.34%
- Veröffentlicht 28.07.2026 20:09:11
- Zuletzt bearbeitet 05.08.2026 19:51:37
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 ND Collective Controller is affected by a path-segment injection vulnerability in the collective routing mechanism.