Vulnerabilities > IBM > Websphere Application Server

DATE CVE VULNERABILITY TITLE RISK
2018-08-24 CVE-2018-1755 Information Exposure vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive information, caused by incorrect transport being used when Liberty is configured to use Java Authentication SPI for Containers (JASPIC).
network
high complexity
ibm CWE-200
5.9
2018-07-06 CVE-2018-1621 Cleartext Storage of Sensitive Information vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local attacker to obtain clear text password in a trace file caused by improper handling of some datasource custom properties.
local
low complexity
ibm CWE-312
6.7
2018-06-27 CVE-2018-1553 Information Exposure vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server Liberty prior to 18.0.0.2 could allow a remote attacker to obtain sensitive information, caused by mishandling of exceptions by the SAML Web SSO feature.
network
low complexity
ibm CWE-200
7.5
2018-06-26 CVE-2018-1614 Information Exposure vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using malformed SAML responses from the SAML identity provider could allow a remote attacker to obtain sensitive information.
network
low complexity
ibm CWE-200
7.5
2018-05-24 CVE-2013-3024 Permissions, Privileges, and Access Controls vulnerability in IBM Websphere Application Server 8.5.0.0/8.5.0.1/8.5.0.2
IBM WebSphere Application Server (WAS) 8.5 through 8.5.0.2 on UNIX allows local users to gain privileges by leveraging improper process initialization.
local
low complexity
ibm CWE-264
7.8
2018-05-04 CVE-2017-1743 Information Exposure vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sensitive information caused by improper handling of Administrative Console panel fields.
network
low complexity
ibm CWE-200
4.3
2018-03-22 CVE-2017-1788 Unspecified vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server 9 installations using Form Login could allow a remote attacker to conduct spoofing attacks.
network
low complexity
ibm
5.3
2018-03-14 CVE-2017-1741 Information Exposure vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sensitive information caused by improper handling of Administrative Console panel fields.
network
low complexity
ibm CWE-200
4.3
2018-02-08 CVE-2011-4889 7PK - Security Features vulnerability in IBM Websphere Application Server
The javax.naming.directory.AttributeInUseException class in the Virtual Member Manager in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.43, 7.0 before 7.0.0.21, and 8.0 before 8.0.0.2 does not properly update passwords on a configuration using Tivoli Directory Server, which might allow remote attackers to gain access to an application by leveraging knowledge of an old password.
network
low complexity
ibm CWE-254
critical
9.8
2018-01-30 CVE-2017-1731 Unspecified vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could provide weaker than expected security when using the Administrative Console.
network
low complexity
ibm
8.8