Total
498 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-14528 | 1 Ibm | 1 Websphere Application Server | 2026-08-05 | N/A | 7.4 HIGH |
| IBM WebSphere Application Server 9.0, and 8.5 traditional could allow a remote attacker to obtain sensitive information. | |||||
| CVE-2026-14974 | 1 Ibm | 1 Websphere Application Server | 2026-08-05 | N/A | 8.1 HIGH |
| IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of untrusted data. | |||||
| CVE-2026-14976 | 1 Ibm | 1 Websphere Application Server | 2026-08-05 | N/A | 7.1 HIGH |
| IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code execution with the collectiveController-1.0 feature enabled. | |||||
| CVE-2026-15328 | 1 Ibm | 1 Websphere Application Server | 2026-08-05 | N/A | 7.4 HIGH |
| IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to HTTP request smuggling. | |||||
| CVE-2026-10842 | 1 Ibm | 1 Websphere Application Server | 2026-08-05 | N/A | 7.5 HIGH |
| IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 Traditional and Liberty could allow a remote attacker to bypass security constraints. | |||||
| CVE-2026-11897 | 1 Ibm | 1 Websphere Application Server | 2026-08-04 | N/A | 7.5 HIGH |
| IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. | |||||
| CVE-2026-14980 | 1 Ibm | 1 Websphere Application Server | 2026-08-04 | N/A | 8.3 HIGH |
| IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to perform SSRF attacks with elevated privileges when the collectiveController-1.0 feature is enabled. | |||||
| CVE-2026-14529 | 1 Ibm | 1 Websphere Application Server | 2026-08-04 | N/A | 9.4 CRITICAL |
| IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side request forgery (SSRF) when the SIP container feature (sipServlet-1.1) is enabled. | |||||
| CVE-2026-2482 | 1 Ibm | 1 Websphere Application Server | 2026-08-04 | N/A | 3.1 LOW |
| IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. | |||||
| CVE-2026-16184 | 1 Ibm | 1 Websphere Application Server | 2026-08-03 | N/A | 7.0 HIGH |
| IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafted unauthenticated request. | |||||
| CVE-2026-16192 | 1 Ibm | 1 Websphere Application Server | 2026-08-03 | N/A | 7.1 HIGH |
| IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service vulnerability when the restConnector-2.0 feature is enabled. | |||||
| CVE-2026-11541 | 1 Ibm | 1 Websphere Application Server | 2026-07-29 | N/A | 7.4 HIGH |
| IBM CICS Transaction Gateway for Multiplatforms 9.1, 9.2, 9.3, and 10.1 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are affected by an HTTP request smuggling vulnerability. | |||||
| CVE-2026-8620 | 1 Ibm | 1 Websphere Application Server | 2026-07-23 | N/A | 7.5 HIGH |
| IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to HTTP request smuggling in the Web Server Plug-ins through a specially crafted request. | |||||
| CVE-2026-8633 | 1 Ibm | 1 Websphere Application Server | 2026-07-23 | N/A | 9.8 CRITICAL |
| IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to remote code execution in the Web Server Plug-ins, through a specially crafted request. | |||||
| CVE-2026-9330 | 1 Ibm | 1 Websphere Application Server | 2026-07-22 | N/A | 8.5 HIGH |
| IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validation of user-supplied data during deserialization using the SAML Web Single Sign-On component. This could result in remote code execution via a crafted HTTP request when combined with a suitable gadget chain. | |||||
| CVE-2026-8644 | 1 Ibm | 1 Websphere Application Server | 2026-07-22 | N/A | 9.1 CRITICAL |
| IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing. | |||||
| CVE-2026-9311 | 1 Ibm | 1 Websphere Application Server | 2026-07-22 | N/A | 9.0 CRITICAL |
| IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security controls. | |||||
| CVE-2026-9319 | 1 Ibm | 1 Websphere Application Server | 2026-07-22 | N/A | 9.0 CRITICAL |
| IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of untrusted data via JAX-WS endpoints with WS-Security. | |||||
| CVE-2026-11546 | 1 Ibm | 1 Websphere Application Server | 2026-07-02 | N/A | 7.1 HIGH |
| IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the adminCenter-1.0 feature enabled. | |||||
| CVE-2026-11595 | 1 Ibm | 1 Websphere Application Server | 2026-07-02 | N/A | 4.3 MEDIUM |
| IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information from the administrative console's integrated help system. | |||||
