Vulnerabilities > IBM > Websphere Application Server > High

DATE CVE VULNERABILITY TITLE RISK
2018-09-07 CVE-2018-1567 Deserialization of Untrusted Data vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbitrary Java code through the SOAP connector with a serialized object from untrusted sources.
network
low complexity
ibm CWE-502
7.5
2018-05-24 CVE-2013-3024 Permissions, Privileges, and Access Controls vulnerability in IBM Websphere Application Server 8.5.0.0/8.5.0.1/8.5.0.2
IBM WebSphere Application Server (WAS) 8.5 through 8.5.0.2 on UNIX allows local users to gain privileges by leveraging improper process initialization.
local
low complexity
ibm CWE-264
7.2
2018-02-08 CVE-2011-4889 7PK - Security Features vulnerability in IBM Websphere Application Server
The javax.naming.directory.AttributeInUseException class in the Virtual Member Manager in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.43, 7.0 before 7.0.0.21, and 8.0 before 8.0.0.2 does not properly update passwords on a configuration using Tivoli Directory Server, which might allow remote attackers to gain access to an application by leveraging knowledge of an old password.
network
low complexity
ibm CWE-254
7.5
2017-02-01 CVE-2016-8919 Resource Management Errors vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server may be vulnerable to a denial of service, caused by allowing serialized objects from untrusted sources to run and cause the consumption of resources.
network
low complexity
ibm CWE-399
7.8
2015-04-27 CVE-2015-1882 Race Condition vulnerability in IBM Websphere Application Server
Multiple race conditions in IBM WebSphere Application Server (WAS) 8.5 Liberty Profile before 8.5.5.5 allow remote authenticated users to gain privileges by leveraging thread conflicts that result in Java code execution outside the context of the configured EJB Run-as user.
network
ibm CWE-362
8.5
2014-08-22 CVE-2014-4764 Denial of Service vulnerability in IBM WebSphere Application Server
IBM WebSphere Application Server (WAS) 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.3, when Load Balancer for IPv4 Dispatcher is enabled, allows remote attackers to cause a denial of service (Load Balancer crash) via unspecified vectors.
network
ibm
7.1
2014-05-16 CVE-2014-0964 Resource Management Errors vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server (WAS) 6.1.0.0 through 6.1.0.47 and 6.0.2.0 through 6.0.2.43 allows remote attackers to cause a denial of service via crafted TLS traffic, as demonstrated by traffic from a CVE-2014-0160 vulnerability-assessment tool.
network
ibm CWE-399
7.1
2012-11-14 CVE-2012-4850 Improper Input Validation vulnerability in IBM Websphere Application Server 8.5.0.0
IBM WebSphere Application Server 8.5 Liberty Profile before 8.5.0.1, when JAX-RS is used, does not properly validate requests, which allows remote attackers to gain privileges via unspecified vectors.
network
low complexity
ibm CWE-20
7.5
2011-03-08 CVE-2011-1309 Improper Input Validation vulnerability in IBM Websphere Application Server
The Plug-in component in IBM WebSphere Application Server (WAS) before 7.0.0.15 does not properly handle trace requests, which has unspecified impact and attack vectors.
network
low complexity
ibm CWE-20
7.5
2010-06-22 CVE-2010-1632 Improper Input Validation vulnerability in Apache Axis2
Apache Axis2 before 1.5.2, as used in IBM WebSphere Application Server (WAS) 7.0 through 7.0.0.12, IBM Feature Pack for Web Services 6.1.0.9 through 6.1.0.32, IBM Feature Pack for Web 2.0 1.0.1.0, Apache Synapse, Apache ODE, Apache Tuscany, Apache Geronimo, and other products, does not properly reject DTDs in SOAP messages, which allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via a crafted DTD, as demonstrated by an entity declaration in a request to the Synapse SimpleStockQuoteService.
network
low complexity
ibm apache CWE-20
7.5