IBM Vulnerabilities and Affected Products
Vulnerabilities associated with WebSphere Application Server.
Products
Clear product- Db2 for Linux, UNIX and Windows168 vulnerabilities
- i162 vulnerabilities
- WebSphere Application Server152 vulnerabilities
- InfoSphere Information Server146 vulnerabilities
- Sterling B2B Integrator132 vulnerabilities
- Rational Quality Manager126 vulnerabilities
- Rational Collaborative Lifecycle Management114 vulnerabilities
- Security Guardium106 vulnerabilities
- QRadar SIEM100 vulnerabilities
- Cognos Analytics98 vulnerabilities
- Rational DOORS Next Generation91 vulnerabilities
- MQ83 vulnerabilities
- Maximo Asset Management81 vulnerabilities
- API Connect78 vulnerabilities
- Rational Engineering Lifecycle Manager76 vulnerabilities
- Rational Team Concert72 vulnerabilities
- AIX69 vulnerabilities
- Langflow OSS68 vulnerabilities
- Sterling File Gateway64 vulnerabilities
- Security Key Lifecycle Manager57 vulnerabilities
- Security Verify Access57 vulnerabilities
- Cloud Pak for Security55 vulnerabilities
- Cognos Controller52 vulnerabilities
- Engineering Lifecycle Optimization52 vulnerabilities
- Spectrum Protect Plus49 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-8400HIGH | Multiple Vulnerabilities in IBM® Java SDK affect IBM WebSphere Application Server and WebSphere Application Server Liberty due to the July 2026 CPUIBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server to induce loading and instantation of arbitrary classes. CWE-470Aug 5, 2026 | CVSS8.1v3.1 | EPSS0.482% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-11536HIGH | IBM WebSphere Application Server is affected by a remote code execution vulnerabilityIBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability in the SOAP/JMX connector. CWE-502Jul 30, 2026 | CVSS8.5v3.1 | EPSS0.344% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-9322HIGH | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilitiesIBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to a denial of service via a crafted HTTP request. CWE-400Jul 30, 2026 | CVSS7.5v3.1 | EPSS0.305% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-10842HIGH | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a security bypass vulnerabilityIBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 Traditional and Liberty could allow a remote attacker to bypass security constraints. CWE-289Jul 30, 2026 | CVSS7.5v3.1 | EPSS0.31% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-14529CRITICAL | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a server-side request forgeryIBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side request forgery (SSRF) when the SIP container feature (sipServlet-1.1) is enabled. CWE-306Jul 29, 2026 | CVSS9.4v3.1 | EPSS0.36% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-14446CRITICAL | IBM WebSphere Application Server is affected by a privilege escalationIBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the administrative console. CWE-306Jul 28, 2026 | CVSS9.8v3.1 | EPSS0.292% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-14515MEDIUM | IBM WebSphere Application Server is affected by cross-site scripting and deserialization vulnerabilitiesIBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to conduct a cross-site scripting attack. CWE-79Jul 28, 2026 | CVSS6.1v3.1 | EPSS0.177% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-14512CRITICAL | IBM WebSphere Application Server is affected by an unsafe deserialization and exposure of sensitive informationIBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attacker to bypass authentication or execute arbitrary code. CWE-502Jul 28, 2026 | CVSS9.8v3.1 | EPSS0.523% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-14528HIGH | IBM WebSphere Application Server is affected by an unsafe deserialization and exposure of sensitive informationIBM WebSphere Application Server 9.0, and 8.5 traditional could allow a remote attacker to obtain sensitive information. CWE-532Jul 28, 2026 | CVSS7.4v3.1 | EPSS0.259% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-14974HIGH | IBM WebSphere Application Server is affected by cross-site scripting and deserialization vulnerabilitiesIBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of untrusted data. CWE-502Jul 28, 2026 | CVSS8.1v3.1 | EPSS0.378% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-14981HIGH | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilitiesIBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are affected by a denial of service vulnerability in the HTTP channel due to unbounded allocation of resources without limits. CWE-400Jul 28, 2026 | CVSS7.5v3.1 | EPSS0.263% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-15064HIGH | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilitiesIBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to HTTP Response Smuggling due to improper handling of non-standard HTTP version tokens. CWE-444Jul 28, 2026 | CVSS8.7v3.1 | EPSS0.22% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-15325HIGH | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilitiesIBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTTP request smuggling due to improper handling of TRACE requests. CWE-444Jul 28, 2026 | CVSS8.7v3.1 | EPSS0.208% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-15328HIGH | IBM WebSphere Application Server and WebSphere Application Server Liberty is inconsistent Interpretation of HTTP RequestsIBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to HTTP request smuggling. CWE-444Jul 28, 2026 | CVSS7.4v3.1 | EPSS0.23% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-16184HIGH | IBM WebSphere Application Server is affected by an authentication bypassIBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafted unauthenticated request. CWE-862Jul 28, 2026 | CVSS7.0v3.1 | EPSS0.322% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-11594HIGH | IBM WebSphere Application Server is affected by multiple cross-site scripting vulnerabilitiesIBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console. CWE-79Jun 30, 2026 | CVSS8.5v3.1 | EPSS0.173% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-11595MEDIUM | IBM WebSphere Application Server is affected by a Path Traversal vulnerabilityIBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information from the administrative console's integrated help system. CWE-22Jun 30, 2026 | CVSS4.3v3.1 | EPSS0.663% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-11708CRITICAL | IBM WebSphere Application Server is affected by a cross-site scripting vulnerabilityIBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console's integrated help system. CWE-79Jun 30, 2026 | CVSS9.3v3.1 | EPSS0.36% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-11712CRITICAL | IBM WebSphere Application Server is affected by a cross-site scripting vulnerabilityIBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console help system. CWE-79Jun 30, 2026 | CVSS9.3v3.1 | EPSS0.336% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-10852MEDIUM | Websphere Application Server is Affected By a Denial of ServiceIBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to denial of service in the WebSphere WebServer Plug-in component when an attacker can pass crafted requests to the web server. CWE-476Jun 22, 2026 | CVSS5.9v3.1 | EPSS0.293% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-9320MEDIUM | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilitiesIBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. CWE-400Jun 22, 2026 | CVSS5.9v3.1 | EPSS0.349% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-9071HIGH | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by Uncontrolled Resource ConsumptionIBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. CWE-400Jun 22, 2026 | CVSS7.5v3.1 | EPSS0.549% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-9006HIGH | IBM WebSphere Application Server is affected by server-side request forgeryIBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an attacker to send unauthorized requests from the system, resulting in a security bypass or information disclosure. CWE-918Jun 22, 2026 | CVSS7.4v3.1 | EPSS0.239% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-8646HIGH | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilitiesIBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to HTTP request smuggling. A remote attacker could smuggle a specially crafted request to the application server thereby allowing the attacker to bypass security controls, spoof identity, escalate privilege, and expose sensitive information. CWE-444Jun 22, 2026 | CVSS7.4v3.1 | EPSS0.365% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-10845HIGH | IBM WebSphere Application Server is affected by an authentication bypass vulnerabilityIBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to bypass authentication and gain unauthorized access to JAX-WS applications. CWE-287Jun 22, 2026 | CVSS7.3v3.1 | EPSS0.466% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |