📦 Websphere Application Server

by Ibm

🔍 What is Websphere Application Server?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-36038

CRITICAL CVSS 9.0 Jun 25, 2025

CVE-2025-36038 is a critical deserialization vulnerability in IBM WebSphere Application Server that allows remote attackers to execute arbitrary code by sending specially crafted serialized objects. T...

CVE-2025-14914

HIGH CVSS 7.6 Feb 2, 2026

This vulnerability allows a privileged user in IBM WebSphere Application Server Liberty to upload a zip archive containing path traversal sequences, which can overwrite files and lead to arbitrary cod...

CVE-2025-36097

HIGH CVSS 7.5 Jul 16, 2025

A stack-based buffer overflow vulnerability in IBM WebSphere Application Server allows attackers to cause denial of service by sending specially crafted requests that consume excessive memory. This af...

CVE-2024-35154

HIGH CVSS 7.2 Jul 9, 2024

This vulnerability allows remote authenticated attackers with administrative console access to execute arbitrary code on IBM WebSphere Application Server. Attackers can exploit specially crafted input...

CVE-2024-37532

HIGH CVSS 8.8 Jun 20, 2024

IBM WebSphere Application Server 8.5 and 9.0 has an identity spoofing vulnerability where authenticated users can impersonate other users due to improper signature validation. This allows attackers to...

CVE-2024-22354

HIGH CVSS 7.0 Apr 17, 2024

This XML External Entity Injection (XXE) vulnerability in IBM WebSphere Application Server allows attackers to process malicious XML data, potentially exposing sensitive information, consuming memory ...

CVE-2023-30441

HIGH CVSS 7.5 Apr 29, 2023

This vulnerability in IBM Runtime Environment Java Technology Edition's IBMJCEPlus and JSSE components could expose sensitive information due to cryptographic weaknesses. It affects IBM Java 8.0.7.0 t...

CVE-2022-22476

HIGH CVSS 8.8 Jul 8, 2022

This vulnerability allows authenticated users to impersonate other users by sending specially crafted requests to IBM WebSphere Application Server Liberty and Open Liberty. Attackers can spoof identit...

CVE-2021-39031

HIGH CVSS 8.8 Jan 25, 2022

This LDAP injection vulnerability in IBM WebSphere Application Server - Liberty allows authenticated remote attackers to manipulate LDAP queries through specially crafted requests. Successful exploita...

CVE-2021-38951

HIGH CVSS 7.5 Dec 9, 2021

This vulnerability in IBM WebSphere Application Server allows remote attackers to cause a denial of service by sending specially crafted requests that consume all available CPU resources. Affected ver...

CVE-2021-29736

HIGH CVSS 8.8 Jul 30, 2021

CVE-2021-29736 is a privilege escalation vulnerability in IBM WebSphere Application Server that allows a remote authenticated user to gain elevated privileges on the system. This affects WebSphere App...

CVE-2021-29754

HIGH CVSS 8.8 Jun 11, 2021

IBM WebSphere Application Server versions 7.0-9.0 contain a privilege escalation vulnerability in the SAML Web Inbound Trust Association Interceptor (TAI). This allows authenticated users to gain elev...

CVE-2021-20454

HIGH CVSS 8.2 Apr 21, 2021

This CVE describes an XML External Entity (XXE) injection vulnerability in IBM WebSphere Application Server, allowing remote attackers to read sensitive files from the server or cause denial of servic...

CVE-2021-20453

HIGH CVSS 8.2 Apr 20, 2021

This XXE vulnerability in IBM WebSphere Application Server allows remote attackers to read arbitrary files from the server filesystem or cause denial of service through memory consumption. It affects ...

CVE-2025-14923

MEDIUM CVSS 4.7 Mar 3, 2026

IBM WebSphere Application Server Liberty versions 17.0.0.3 through 26.0.0.2 have a security weakness in the Security Utility that could allow reduced security when administering security settings. Thi...

CVE-2025-13333

MEDIUM CVSS 4.4 Feb 17, 2026

IBM WebSphere Application Server versions 9.0 and 8.5 have a security weakness in system administration security settings that could allow attackers to bypass intended security controls. This affects ...

CVE-2025-12635

MEDIUM CVSS 5.4 Dec 8, 2025

This CVE describes a cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server and Liberty versions where improper input validation allows attackers to craft malicious URLs. When us...

CVE-2025-36047

MEDIUM CVSS 5.3 Aug 14, 2025

IBM WebSphere Application Server Liberty versions 18.0.0.2 through 25.0.0.8 are vulnerable to a denial of service attack where a remote attacker can send specially crafted requests to cause excessive ...

CVE-2025-33142

MEDIUM CVSS 5.3 Aug 14, 2025

IBM WebSphere Application Server 8.5 and 9.0 have a TLS security weakness that could allow attackers to downgrade or weaken TLS connections. This affects organizations using these versions for web app...

CVE-2025-36000

MEDIUM CVSS 4.4 Aug 12, 2025

IBM WebSphere Application Server Liberty versions 17.0.0.3 through 25.0.0.8 contain a stored cross-site scripting vulnerability that allows privileged users to inject malicious JavaScript into the web...

CVE-2025-36124

MEDIUM CVSS 5.9 Aug 12, 2025

IBM WebSphere Application Server Liberty versions 17.0.0.3 through 25.0.0.8 contain a vulnerability where JMS messaging configuration is not properly enforced, allowing remote attackers to bypass secu...

CVE-2024-45072

MEDIUM CVSS 5.5 Oct 16, 2024

IBM WebSphere Application Server 8.5 and 9.0 contains an XML External Entity (XXE) vulnerability that allows privileged users to read arbitrary files from the server or cause denial of service through...

CVE-2024-35153

MEDIUM CVSS 4.8 Jun 27, 2024

IBM WebSphere Application Server 8.5 and 9.0 contains a cross-site scripting (XSS) vulnerability that allows authenticated privileged users to inject malicious JavaScript into the web interface. This ...