VulnSea

websphere_application_server vulnerabilities

CVEs whose affected-version data names the websphere_application_server package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

28 CVEsRSS

CVE-2026-11545Low· 3.7
4d ago

IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to obtain sensitive information from the administrative console due to missing authorization checks.

IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to obtain sensitive information from the administrative console due to missing authorization checks.

SunlitIBM · WebSphere Application ServerEPSS 0.34%via NVD
CVE-2026-11540Medium· 5.3
4d ago

IBM WebSphere Application Server 9.0 and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet.

IBM WebSphere Application Server 9.0 and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet.

SunlitIBM · WebSphere Application ServerEPSS 0.30%via NVD
CVE-2026-11539Medium· 5.3
4d ago

IBM WebSphere Application Server 9.0 and 8.5 is affected by an authentication bypass vulnerability in the SOAP/JMX connector.

IBM WebSphere Application Server 9.0 and 8.5 is affected by an authentication bypass vulnerability in the SOAP/JMX connector.

SunlitIBM · WebSphere Application ServerEPSS 0.30%via NVD
CVE-2026-11711Medium· 6.5
4d ago

IBM WebSphere Application Server 9.0 and 8.5 is affected by a deserialization vulnerability in the Name Service component.

IBM WebSphere Application Server 9.0 and 8.5 is affected by a deserialization vulnerability in the Name Service component.

SunlitIBM · WebSphere Application ServerEPSS 0.38%via NVD
CVE-2026-11710Medium· 6.5
4d ago

IBM WebSphere Application Server 8.5 is affected by an HTTP request smuggling vulnerability due to improper handling of Content-Length headers.

IBM WebSphere Application Server 8.5 is affected by an HTTP request smuggling vulnerability due to improper handling of Content-Length headers.

SunlitIBM · WebSphere Application ServerEPSS 0.28%via NVD
CVE-2026-11538Low· 3.7
4d ago

IBM WebSphere Application Server 9.0 and 8.5 is affected by a log injection vulnerability through crafted LTPA token cookies.

IBM WebSphere Application Server 9.0 and 8.5 is affected by a log injection vulnerability through crafted LTPA token cookies.

SunlitIBM · WebSphere Application ServerEPSS 0.16%via NVD
CVE-2026-11537Medium· 4.3
4d ago

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet.

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet.

SunlitIBM · WebSphere Application ServerEPSS 0.18%via NVD
CVE-2026-16435Medium· 5.9
1w ago

IBM WebSphere Application Server 9.0, and 8.5 is affected by an authentication bypass vulnerability when using XD or Intelligent-Management features.

IBM WebSphere Application Server 9.0, and 8.5 is affected by an authentication bypass vulnerability when using XD or Intelligent-Management features.

SunlitIBM · WebSphere Application ServerEPSS 0.31%via NVD
CVE-2026-16190Low· 3.1
1w ago

IBM WebSphere Application Server 9.0, and 8.5 is affected by an authorization bypass vulnerability.

IBM WebSphere Application Server 9.0, and 8.5 is affected by an authorization bypass vulnerability.

SunlitIBM · WebSphere Application ServerEPSS 0.16%via NVD
CVE-2026-16189Medium· 4.8
1w ago

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log entries into the server's administrative log.

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log entries into the server's administrative log.

SunlitIBM · WebSphere Application ServerEPSS 0.22%via NVD
CVE-2026-16188Medium· 5.3
1w ago

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log entries into the server's administrative log.

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log entries into the server's administrative log.

SunlitIBM · WebSphere Application ServerEPSS 0.27%via NVD
CVE-2026-16187Medium· 6.5
1w ago

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication and obtain sensitive information by sending a crafted unauthenticated request.

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication and obtain sensitive information by sending a crafted unauthenticated request.

SunlitIBM · WebSphere Application ServerEPSS 0.25%via NVD
CVE-2026-16185Medium· 6.4
1w ago

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication on an admin console servlet.

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication on an admin console servlet.

SunlitIBM · WebSphere Application ServerEPSS 0.20%via NVD
CVE-2026-16186Medium· 5.4
1w ago

IBM WebSphere Application Server 9.0, and 8.5 is affected by a reflected cross-site scripting vulnerability.

IBM WebSphere Application Server 9.0, and 8.5 is affected by a reflected cross-site scripting vulnerability.

SunlitIBM · WebSphere Application ServerEPSS 0.18%via NVD
CVE-2026-15887Medium· 5.4
1w ago

IBM WebSphere Application Server 9.0, and 8.5 is affected by blind server-side request forgery when processing SOAP requests.

IBM WebSphere Application Server 9.0, and 8.5 is affected by blind server-side request forgery when processing SOAP requests.

SunlitIBM · WebSphere Application ServerEPSS 0.18%via NVD
CVE-2026-15634Medium· 6.5
1w ago

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP transfer-encoding request header

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP transfer-encoding request header. By sending a specially crafte…

SunlitIBM · WebSphere Application ServerEPSS 0.25%via NVD
CVE-2026-15396Medium· 6.5
1w ago

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP transfer-encoding request header

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP transfer-encoding request header. By sending a specially crafte…

SunlitIBM · WebSphere Application ServerEPSS 0.25%via NVD
CVE-2026-15412Medium· 6.5
1w ago

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty could allow a remote attacker to conduct phishing attacks, using an open redirect attack

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted We…

SunlitIBM · WebSphere Application ServerEPSS 0.22%via NVD
CVE-2026-9176Medium· 6.7
1w ago

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a security bypass due to improper authentication controls

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a security bypass due to improper authentication controls. A local attacker could exploit this vulnerability to escalate privileges and gain unauthorized access to protected …

Sunlitibm · websphere_application_serverEPSS 0.11%via NVD
CVE-2026-9327Medium· 6.3
1w ago

IBM WebSphere Application Server 9.0, and 8.5 could allow an authenticated user with a low-privilege administrative role to modify security configuration

IBM WebSphere Application Server 9.0, and 8.5 could allow an authenticated user with a low-privilege administrative role to modify security configuration. This could result in information disclosure or denial of service.

Sunlitibm · websphere_application_serverEPSS 0.21%via NVD
CVE-2026-9338Medium· 5.3
1w ago

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted request

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to trigger excessive resource consumption, potentially …

Sunlitibm · websphere_application_serverEPSS 0.29%via NVD
CVE-2026-9336Medium· 6.5
1w ago

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted HTTP request to an administrative endpoint

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted HTTP request to an administrative endpoint. A remote attacker could exploit this vulnerability to cause the server …

Sunlitibm · websphere_application_serverEPSS 0.39%via NVD
CVE-2026-9667Medium· 5.3
1w ago

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) that could allow a remote, unauthenticated attacker to cause the server to send outbound requests to arbitrary endpoints.

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) that could allow a remote, unauthenticated attacker to cause the server to send outbound requests to arbitrary endpoints.

Sunlitibm · websphere_application_serverEPSS 0.31%via NVD
CVE-2026-11714High· 8.5
2mo ago

IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability with the apiDiscovery-1.0 feature enabled.

IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability with the apiDiscovery-1.0 feature enabled.

Twilightibm · websphere_application_serverEPSS 0.36%via NVD
CVE-2026-9330High· 8.5
3mo ago

IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validation of user-supplied data during deserialization using the SAML Web Single Sign-On component

IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validation of user-supplied data during deserialization using the SAML Web Single Sign-On component. This could result in remote code execution via a crafted HTTP r…

Twilightibm · websphere_application_serverEPSS 0.52%via NVD
CVE-2026-9319Critical· 9.0
3mo ago

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of untrusted data via JAX-WS endpoints with WS-Security.

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of untrusted data via JAX-WS endpoints with WS-Security.

Midnightibm · websphere_application_serverEPSS 0.46%via NVD
CVE-2026-9311Critical· 9.0
3mo ago

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security controls.

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security controls.

Midnightibm · websphere_application_serverEPSS 0.51%via NVD
CVE-2026-8644Critical· 9.1
3mo ago

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing.

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing.

Midnightibm · websphere_application_serverEPSS 0.33%via NVD
websphere_application_server vulnerabilities (CVEs) · VulnSea