CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

ibm

websphere_application_server

141 known vulnerabilities · sorted by CVSS score

CVE-2011-4889
CRITICAL9.8

The javax.naming.directory.AttributeInUseException class in the Virtual Member Manager in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.43, 7.0 before 7.0.0.21, and 8.0 before 8.0.0.2 does not properly update passwords on a configuration using Tivoli Directory Server, which might allow remote attackers to gain access to an application by leveraging knowledge of an old password. IBM X-Force ID: 72581.

ibm / websphere_application_server+2
Network
Published Feb 8, 2018
Page 1 of 8
CVE-2020-4450
CRITICAL9.8

IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects. IBM X-Force ID: 181231.

ibm / websphere_application_server+1
Network
Published Jun 5, 2020
CVE-2018-1567
CRITICAL9.8

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbitrary Java code through the SOAP connector with a serialized object from untrusted sources. IBM X-Force ID: 143024.

ibm / websphere_application_server+3
Network
Published Sep 7, 2018
CVE-2020-4589
CRITICAL9.8

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects from untrusted sources. IBM X-Force ID: 184585.

ibm / websphere_application_server+3
Network
Published Aug 13, 2020
CVE-2019-4279
CRITICAL9.8

IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects from untrusted sources. IBM X-Force ID: 160445.

ibm / websphere_application_server+2
Network
Published May 17, 2019
CVE-2020-4448
CRITICAL9.8

IBM WebSphere Application Server Network Deployment 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects from untrusted sources. IBM X-Force ID: 181228.

ibm / websphere_application_server+3
Network
Published Jun 5, 2020
CVE-2025-36038
CRITICAL9.0

IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially crafted sequence of serialized objects.

ibm / websphere_application_server+1
Network
Published Jun 25, 2025
CVE-2022-22476
HIGH8.8

IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.7 and Open Liberty are vulnerable to identity spoofing by an authenticated user using a specially crafted request. IBM X-Force ID: 225604.

ibm / open_liberty+1
Network
Published Jul 8, 2022
CVE-2024-37532
HIGH8.8

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to identity spoofing by an authenticated user due to improper signature validation. IBM X-Force ID: 294721.

ibm / websphere_application_server+1
Network
Published Jun 20, 2024
CVE-2021-29754
HIGH8.8

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a privilege escalation vulnerability when using the SAML Web Inbound Trust Association Interceptor (TAI). IBM X-Force ID: 202006.

ibm / websphere_application_server+3
Network
Published Jun 11, 2021
CVE-2020-4464
HIGH8.8

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code on a system with a specially-crafted sequence of serialized objects over the SOAP connector. IBM X-Force ID: 181489.

ibm / websphere_application_server+3
Network
Published Jul 17, 2020
CVE-2017-1731
HIGH8.8

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could provide weaker than expected security when using the Administrative Console. An authenticated remote attacker could exploit this vulnerability to possibly gain elevated privileges.

ibm / websphere_application_server+3
Network
Published Jan 30, 2018
CVE-2021-39031
HIGH8.8

IBM WebSphere Application Server - Liberty 17.0.0.3 through 22.0.0.1 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this vulnerability and could result in in granting permission to unauthorized resources. IBM X-Force ID: 213875.

ibm / websphere_application_server
Network
Published Jan 25, 2022
CVE-2021-29736
HIGH8.8

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote user to gain elevated privileges on the system. IBM X-Force ID: 201300.

ibm / websphere_application_server+3
Network
Published Jul 30, 2021
CVE-2020-4534
HIGH8.8

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local authenticated attacker to gain elevated privileges on the system, caused by improper handling of UNC paths. By scheduling a task with a specially-crafted UNC path, an attacker could exploit this vulnerability to execute arbitrary code with higher privileges. IBM X-Force ID: 182808.

ibm / websphere_application_server+3
Local
Published Aug 3, 2020
CVE-2020-4362
HIGH8.8

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional is vulnerable to a privilege escalation vulnerability when using token-based authentication in an admin request over the SOAP connector. IBM X-Force ID: 178929.

ibm / websphere_application_server+3
Network
Published Apr 10, 2020
CVE-2021-20492
HIGH8.2

IBM WebSphere Application Server 8.0, 8.5, 9.0, and Liberty Java Batch is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 197793.

ibm / websphere_application_server+3
Network
Published May 26, 2021
CVE-2021-20453
HIGH8.2

IBM WebSphere Application Server 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 196648.

ibm / websphere_application_server+2
Network
Published Apr 20, 2021
CVE-2021-20454
HIGH8.2

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 196649.

ibm / websphere_application_server+3
Network
Published Apr 21, 2021
CVE-2021-20353
HIGH8.2

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 194882.

ibm / websphere_application_server+3
Network
Published Feb 10, 2021