CVE-2026-1561
- EPSS 0.28%
- Veröffentlicht 25.03.2026 20:10:10
- Zuletzt bearbeitet 30.03.2026 16:58:21
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty is vulnerable to server-side request forgery (SSRF). This may allow remote attacker to send unauthorized requests from the system, potential...
CVE-2025-14923
- EPSS 0.17%
- Veröffentlicht 03.03.2026 19:47:25
- Zuletzt bearbeitet 04.03.2026 18:23:23
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.2 IBM WebSphere Application Server Liberty could provide weaker than expected security when using the Security Utility when administering security settings.
CVE-2025-13333
- EPSS 0.31%
- Veröffentlicht 17.02.2026 22:45:10
- Zuletzt bearbeitet 20.02.2026 16:49:01
IBM WebSphere Application Server 9.0, and 8.5 could provide weaker than expected security during system administration of security settings.
CVE-2025-14914
- EPSS 0.39%
- Veröffentlicht 02.02.2026 16:16:17
- Zuletzt bearbeitet 12.02.2026 21:16:54
IBM WebSphere Application Server Liberty 17.0.0.3 through 26.0.0.1 could allow a privileged user to upload a zip archive containing path traversal sequences resulting in an overwrite of files leading to arbitrary code execution.
CVE-2025-12635
- EPSS 0.16%
- Veröffentlicht 08.12.2025 21:58:13
- Zuletzt bearbeitet 07.10.2026 20:10:01
IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.12 are affected by cross-site scripting due to improper validation of user-supplied input. An attacker could exploit this vulnerability by ...
CVE-2025-36099
- EPSS 0.3%
- Veröffentlicht 29.09.2025 19:15:34
- Zuletzt bearbeitet 09.10.2026 09:10:00
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to a denial of service, caused by sending a specially-crafted request. A privileged user could exploit this vulnerability to cause the server to consume memory resources.
CVE-2025-33142
- EPSS 0.27%
- Veröffentlicht 14.08.2025 15:41:59
- Zuletzt bearbeitet 18.08.2025 18:05:01
IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security for TLS connections.
CVE-2025-36047
- EPSS 0.45%
- Veröffentlicht 14.08.2025 15:38:11
- Zuletzt bearbeitet 03.11.2025 20:18:30
IBM WebSphere Application Server Liberty 18.0.0.2 through 25.0.0.8 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources...
CVE-2025-36000
- EPSS 0.18%
- Veröffentlicht 12.08.2025 19:39:17
- Zuletzt bearbeitet 14.08.2025 01:29:01
IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.8 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality p...
CVE-2025-36124
- EPSS 0.4%
- Veröffentlicht 12.08.2025 18:45:24
- Zuletzt bearbeitet 14.08.2025 01:23:45
IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.8 could allow a remote attacker to bypass security restrictions caused by a failure to honor JMS messaging configuration