Vulnerabilities > IBM > Websphere Application Server > 8.5.5.12

DATE CVE VULNERABILITY TITLE RISK
2019-03-06 CVE-2019-4030 Cross-site Scripting vulnerability in IBM products
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2019-02-19 CVE-2018-1996 Use of a Broken or Risky Cryptographic Algorithm vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could provide weaker than expected security, caused by the improper TLS configuration.
network
high complexity
ibm CWE-327
5.3
2018-12-12 CVE-2018-1926 Cross-Site Request Forgery (CSRF) vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Admin Console is vulnerable to cross-site request forgery, caused by improper validation of user-supplied input.
network
low complexity
ibm CWE-352
8.8
2018-12-12 CVE-2018-1901 Unspecified vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to temporarily gain elevated privileges on the system, caused by incorrect cached value being used.
network
low complexity
ibm
8.8
2018-12-11 CVE-2018-1904 Deserialization of Untrusted Data vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbitrary Java code through an administrative client class with a serialized object from untrusted sources.
network
low complexity
ibm CWE-502
critical
9.8
2018-12-03 CVE-2018-1840 Exposure of Resource to Wrong Sphere vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to gain elevated privileges on the system, caused when a security domain is configured to use a federated repository other than global federated repository and then migrated to a newer release of WebSphere Application Server.
network
high complexity
ibm CWE-668
8.1
2018-11-16 CVE-2018-1797 Path Traversal vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using Enterprise bundle Archives (EBA) could allow a local attacker to traverse directories on the system.
local
low complexity
ibm CWE-22
5.5
2018-11-15 CVE-2018-1643 Cross-site Scripting vulnerability in IBM Websphere Application Server
The Installation Verification Tool of IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
6.1
2018-11-12 CVE-2018-1798 Cross-site Scripting vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
6.1
2018-10-29 CVE-2018-1767 Cross-site Scripting vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Cachemonitor is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
6.1