Vulnerabilities > IBM > Websphere Application Server > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-07-30 CVE-2019-4285 Improper Restriction of Rendered UI Layers or Frames vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server - Liberty Admin Center could allow a remote attacker to hijack the clicking action of the victim.
network
low complexity
ibm CWE-1021
5.4
2019-04-02 CVE-2019-4080 Resource Exhaustion vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server Admin Console 7.5, 8.0, 8.5, and 9.0 is vulnerable to a potential denial of service, caused by improper parameter parsing.
network
low complexity
ibm CWE-400
6.5
2019-03-11 CVE-2018-1902 Information Exposure vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to spoof connection information which could be used to launch further attacks against the system.
network
low complexity
ibm CWE-200
4.3
2019-03-06 CVE-2019-4030 Cross-site Scripting vulnerability in IBM products
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2019-02-19 CVE-2018-1996 Use of a Broken or Risky Cryptographic Algorithm vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could provide weaker than expected security, caused by the improper TLS configuration.
network
high complexity
ibm CWE-327
5.3
2018-12-10 CVE-2018-1957 Information Exposure vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server 9 could allow sensitive information to be available caused by mishandling of data by the application based on an incorrect return by the httpServletRequest#authenticate() API when an unprotected URI is accessed.
local
low complexity
ibm CWE-200
5.5
2018-11-16 CVE-2018-1797 Path Traversal vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using Enterprise bundle Archives (EBA) could allow a local attacker to traverse directories on the system.
local
low complexity
ibm CWE-22
5.5
2018-11-15 CVE-2018-1643 Cross-site Scripting vulnerability in IBM Websphere Application Server
The Installation Verification Tool of IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
6.1
2018-11-12 CVE-2018-1798 Cross-site Scripting vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
6.1
2018-10-29 CVE-2018-1767 Cross-site Scripting vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Cachemonitor is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
6.1