Vulnerabilities > IBM > Websphere Application Server > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-04-02 CVE-2023-50313 Use of a Broken or Risky Cryptographic Algorithm vulnerability in IBM Websphere Application Server 8.5/9.0
IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security for outbound TLS connections caused by a failure to honor user configuration.
low complexity
ibm CWE-327
6.5
2023-07-07 CVE-2023-35890 Use of a Broken or Risky Cryptographic Algorithm vulnerability in IBM Websphere Application Server 8.5.5.23/9.0.5.15/9.0.5.16
IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security, caused by the improper encoding in a local configuration file.
local
low complexity
ibm CWE-327
5.5
2023-05-03 CVE-2022-39161 Improper Certificate Validation vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0, and IBM WebSphere Application Server Liberty, when configured to communicate with the Web Server Plug-ins for IBM WebSphere Application Server, could allow an authenticated user to conduct spoofing attacks.
network
high complexity
ibm CWE-295
5.3
2023-04-27 CVE-2023-24966 Cross-site Scripting vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
6.1
2023-04-02 CVE-2023-26283 Cross-site Scripting vulnerability in IBM Websphere Application Server 9.0
IBM WebSphere Application Server 9.0 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2022-11-11 CVE-2022-40750 Cross-site Scripting vulnerability in IBM Websphere Application Server 8.5/9.0
IBM WebSphere Application Server 8.5, and 9.0 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2022-11-03 CVE-2022-38712 Authentication Bypass by Spoofing vulnerability in IBM Websphere Application Server
"IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Web services could allow a man-in-the-middle attacker to conduct SOAPAction spoofing to execute unwanted or unauthorized operations.
network
high complexity
ibm CWE-290
5.9
2022-09-28 CVE-2022-35282 Server-Side Request Forgery (SSRF) vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to server-side request forgery (SSRF).
low complexity
ibm CWE-918
6.5
2022-09-09 CVE-2022-34165 Injection vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.9 are vulnerable to HTTP header injection, caused by improper validation.
network
low complexity
ibm CWE-74
5.4
2022-07-14 CVE-2022-22473 Unspecified vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sensitive information caused by improper handling of Administrative Console data.
network
low complexity
ibm
5.3