Total
498 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-9176 | 1 Ibm | 1 Websphere Application Server | 2026-09-15 | N/A | 6.7 MEDIUM |
| IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a security bypass due to improper authentication controls. A local attacker could exploit this vulnerability to escalate privileges and gain unauthorized access to protected resources. | |||||
| CVE-2026-9327 | 1 Ibm | 1 Websphere Application Server | 2026-09-15 | N/A | 6.3 MEDIUM |
| IBM WebSphere Application Server 9.0, and 8.5 could allow an authenticated user with a low-privilege administrative role to modify security configuration. This could result in information disclosure or denial of service. | |||||
| CVE-2026-9667 | 1 Ibm | 1 Websphere Application Server | 2026-09-15 | N/A | 5.3 MEDIUM |
| IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) that could allow a remote, unauthenticated attacker to cause the server to send outbound requests to arbitrary endpoints. | |||||
| CVE-2026-11383 | 3 Ibm, Linux, Microsoft | 7 Aix, I, Tivoli System Automation Application Manager and 4 more | 2026-08-18 | N/A | 5.4 MEDIUM |
| IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by cross-site scripting in the Administrative Console. | |||||
| CVE-2026-11707 | 3 Ibm, Linux, Microsoft | 7 Aix, I, Tivoli System Automation Application Manager and 4 more | 2026-08-18 | N/A | 9.3 CRITICAL |
| IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-site scripting vulnerability in the administrative console login page. | |||||
| CVE-2026-10571 | 4 Apple, Ibm, Linux and 1 more | 7 Macos, Aix, I and 4 more | 2026-08-17 | N/A | 5.7 MEDIUM |
| IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service caused by insecure deserialization. A low-privileged, administrative user could exploit this vulnerability to consume system resources when the restConnector-2.0 feature is enabled. | |||||
| CVE-2026-14525 | 4 Apple, Ibm, Linux and 1 more | 7 Macos, Aix, I and 4 more | 2026-08-17 | N/A | 9.4 CRITICAL |
| IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is vulnerable to an authentication bypass when the rtcomm-1.0 or rtcommGateway-1.0 feature is enabled. | |||||
| CVE-2026-18499 | 1 Ibm | 1 Websphere Application Server | 2026-08-17 | N/A | 8.1 HIGH |
| IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to a privilege escalation when using Liberty collectives. | |||||
| CVE-2026-9322 | 1 Ibm | 1 Websphere Application Server | 2026-08-12 | N/A | 7.5 HIGH |
| IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to a denial of service via a crafted HTTP request. | |||||
| CVE-2026-8400 | 1 Ibm | 1 Websphere Application Server | 2026-08-10 | N/A | 8.1 HIGH |
| IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server to induce loading and instantation of arbitrary classes. | |||||
| CVE-2026-15325 | 1 Ibm | 1 Websphere Application Server | 2026-08-06 | N/A | 8.7 HIGH |
| IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTTP request smuggling due to improper handling of TRACE requests. | |||||
| CVE-2026-11714 | 1 Ibm | 1 Websphere Application Server | 2026-08-06 | N/A | 8.5 HIGH |
| IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability with the apiDiscovery-1.0 feature enabled. | |||||
| CVE-2026-11536 | 1 Ibm | 1 Websphere Application Server | 2026-08-05 | N/A | 8.5 HIGH |
| IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability in the SOAP/JMX connector. | |||||
| CVE-2026-15280 | 1 Ibm | 1 Websphere Application Server | 2026-08-05 | N/A | 7.5 HIGH |
| IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 ND Collective Controller is affected by a path-segment injection vulnerability in the collective routing mechanism. | |||||
| CVE-2026-15064 | 1 Ibm | 1 Websphere Application Server | 2026-08-05 | N/A | 8.7 HIGH |
| IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to HTTP Response Smuggling due to improper handling of non-standard HTTP version tokens. | |||||
| CVE-2026-15057 | 1 Ibm | 1 Websphere Application Server | 2026-08-05 | N/A | 7.5 HIGH |
| IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service due to uncontrolled heap allocation. | |||||
| CVE-2026-14981 | 1 Ibm | 1 Websphere Application Server | 2026-08-05 | N/A | 7.5 HIGH |
| IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are affected by a denial of service vulnerability in the HTTP channel due to unbounded allocation of resources without limits. | |||||
| CVE-2026-14446 | 1 Ibm | 1 Websphere Application Server | 2026-08-05 | N/A | 9.8 CRITICAL |
| IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the administrative console. | |||||
| CVE-2026-14512 | 1 Ibm | 1 Websphere Application Server | 2026-08-05 | N/A | 9.8 CRITICAL |
| IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attacker to bypass authentication or execute arbitrary code. | |||||
| CVE-2026-14515 | 1 Ibm | 1 Websphere Application Server | 2026-08-05 | N/A | 6.1 MEDIUM |
| IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to conduct a cross-site scripting attack. | |||||
