- EPSS 0.46%
- Veröffentlicht 01.06.2026 17:59:43
- Zuletzt bearbeitet 22.07.2026 08:10:00
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of untrusted data via JAX-WS endpoints with WS-Security.
- EPSS 0.51%
- Veröffentlicht 01.06.2026 17:49:42
- Zuletzt bearbeitet 22.07.2026 08:10:00
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security controls.
CVE-2026-8644
- EPSS 0.33%
- Veröffentlicht 01.06.2026 17:46:04
- Zuletzt bearbeitet 22.07.2026 08:10:00
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing.
CVE-2026-5516
- EPSS 0.21%
- Veröffentlicht 27.05.2026 13:00:04
- Zuletzt bearbeitet 02.06.2026 17:16:38
IBM WebSphere Application Server - Liberty 22.0.0.11 through 26.0.0.5 IBM WebSphere Application Server Liberty could allow a remote attacker to bypass security under limited conditions by exploiting a specific timing window.
CVE-2026-4410
- EPSS 0.5%
- Veröffentlicht 27.05.2026 12:54:48
- Zuletzt bearbeitet 01.06.2026 14:28:24
IBM WebSphere Application Server - Liberty 19.0.0.7 through 26.0.0.5 and IBM WebSphere Application Server 9.0, and 8.5 and WebSphere Application Server Liberty are vulnerable to a denial of service, caused by sending a specially-crafted request. A re...
CVE-2026-8633
- EPSS 0.85%
- Veröffentlicht 26.05.2026 17:19:55
- Zuletzt bearbeitet 23.07.2026 11:10:00
IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to remote code execution in the Web Server Plug-ins, through a specially ...
CVE-2026-8620
- EPSS 0.28%
- Veröffentlicht 26.05.2026 17:15:00
- Zuletzt bearbeitet 23.07.2026 11:10:00
IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to HTTP request smuggling in the Web Server Plug-ins through a specially ...
CVE-2026-3621
- EPSS 0.28%
- Veröffentlicht 22.04.2026 23:07:31
- Zuletzt bearbeitet 13.05.2026 20:24:13
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.4 IBM WebSphere Application Server Liberty is vulnerable to identity spoofing under limited conditions when an application is deployed without authentication and authorization configu...
CVE-2025-14917
- EPSS 0.36%
- Veröffentlicht 25.03.2026 20:13:55
- Zuletzt bearbeitet 30.03.2026 16:59:11
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty could provide weaker than expected security when administering security settings.
CVE-2025-14915
- EPSS 0.5%
- Veröffentlicht 25.03.2026 20:12:27
- Zuletzt bearbeitet 30.03.2026 16:59:31
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty is affected by privilege escalation. A privileged user could gain additional access to the application server.