IBM Vulnerabilities and Affected Products
Vulnerabilities associated with WebSphere Application Server - Liberty.
Products
Clear product- Db2 for Linux, UNIX and Windows168 vulnerabilities
- i162 vulnerabilities
- WebSphere Application Server152 vulnerabilities
- InfoSphere Information Server146 vulnerabilities
- Sterling B2B Integrator132 vulnerabilities
- Rational Quality Manager126 vulnerabilities
- Rational Collaborative Lifecycle Management114 vulnerabilities
- Security Guardium106 vulnerabilities
- QRadar SIEM100 vulnerabilities
- Cognos Analytics98 vulnerabilities
- Rational DOORS Next Generation91 vulnerabilities
- MQ83 vulnerabilities
- Maximo Asset Management81 vulnerabilities
- API Connect78 vulnerabilities
- Rational Engineering Lifecycle Manager76 vulnerabilities
- Rational Team Concert72 vulnerabilities
- AIX69 vulnerabilities
- Langflow OSS68 vulnerabilities
- Sterling File Gateway64 vulnerabilities
- Security Key Lifecycle Manager57 vulnerabilities
- Security Verify Access57 vulnerabilities
- Cloud Pak for Security55 vulnerabilities
- Cognos Controller52 vulnerabilities
- Engineering Lifecycle Optimization52 vulnerabilities
- Spectrum Protect Plus49 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-14525CRITICAL | IBM WebSphere Application Server Liberty is affected by an authenication bypassIBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is vulnerable to an authentication bypass when the rtcomm-1.0 or rtcommGateway-1.0 feature is enabled. CWE-306Aug 13, 2026 | CVSS9.4v3.1 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-10571MEDIUM | IBM WebSphere Application Server Liberty is affected by a denial of serviceIBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service caused by insecure deserialization. A low-privileged, administrative user could exploit this vulnerability to consume system resources when the restConnector-2.0 feature is enabled. CWE-502Aug 13, 2026 | CVSS5.7v3.1 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-18499HIGH | IBM WebSphere Application Server Liberty is affected by a privilege escalationIBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to a privilege escalation when using Liberty collectives. CWE-285Aug 12, 2026 | CVSS8.1v3.1 | EPSS0.27% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-8400HIGH | Multiple Vulnerabilities in IBM® Java SDK affect IBM WebSphere Application Server and WebSphere Application Server Liberty due to the July 2026 CPUIBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server to induce loading and instantation of arbitrary classes. CWE-470Aug 5, 2026 | CVSS8.1v3.1 | EPSS0.482% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-9322HIGH | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilitiesIBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to a denial of service via a crafted HTTP request. CWE-400Jul 30, 2026 | CVSS7.5v3.1 | EPSS0.305% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-10842HIGH | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a security bypass vulnerabilityIBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 Traditional and Liberty could allow a remote attacker to bypass security constraints. CWE-289Jul 30, 2026 | CVSS7.5v3.1 | EPSS0.31% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-11897HIGH | IBM WebSphere Application Server Liberty is affected by a denial of service vulnerability with HTTP/2IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. CWE-770Jul 30, 2026 | CVSS7.5v3.1 | EPSS0.304% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-14980HIGH | IBM WebSphere Application Server Liberty is affected by a cross-site request forgeryIBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to perform SSRF attacks with elevated privileges when the collectiveController-1.0 feature is enabled. CWE-269Jul 30, 2026 | CVSS8.3v3.1 | EPSS0.235% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
IBM WebSphere Application Server Liberty is affected by a cross-site request forgeryIBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. CWE-352Jul 29, 2026 | CVSS3.1v3.1 | EPSS0.098% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2026-14529CRITICAL | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a server-side request forgeryIBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side request forgery (SSRF) when the SIP container feature (sipServlet-1.1) is enabled. CWE-306Jul 29, 2026 | CVSS9.4v3.1 | EPSS0.36% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-14976HIGH | IBM WebSphere Application Server Liberty is affected by a remote code execution and path-segment injection vulnerabilityIBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code execution with the collectiveController-1.0 feature enabled. CWE-306Jul 28, 2026 | CVSS7.1v3.1 | EPSS0.305% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-14981HIGH | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilitiesIBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are affected by a denial of service vulnerability in the HTTP channel due to unbounded allocation of resources without limits. CWE-400Jul 28, 2026 | CVSS7.5v3.1 | EPSS0.263% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-15057HIGH | IBM WebSphere Application Server Liberty is affected by a denial of service vulnerabilityIBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service due to uncontrolled heap allocation. CWE-787Jul 28, 2026 | CVSS7.5v3.1 | EPSS0.263% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-15064HIGH | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilitiesIBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to HTTP Response Smuggling due to improper handling of non-standard HTTP version tokens. CWE-444Jul 28, 2026 | CVSS8.7v3.1 | EPSS0.22% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-15280HIGH | IBM WebSphere Application Server Liberty is affected by a remote code execution and path-segment injection vulnerabilityIBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 ND Collective Controller is affected by a path-segment injection vulnerability in the collective routing mechanism. CWE-22Jul 28, 2026 | CVSS7.5v3.1 | EPSS0.335% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-15325HIGH | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilitiesIBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTTP request smuggling due to improper handling of TRACE requests. CWE-444Jul 28, 2026 | CVSS8.7v3.1 | EPSS0.208% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-15328HIGH | IBM WebSphere Application Server and WebSphere Application Server Liberty is inconsistent Interpretation of HTTP RequestsIBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to HTTP request smuggling. CWE-444Jul 28, 2026 | CVSS7.4v3.1 | EPSS0.23% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-16192HIGH | IBM WebSphere Application Server Liberty is affected by a denial of serviceIBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service vulnerability when the restConnector-2.0 feature is enabled. CWE-674Jul 28, 2026 | CVSS7.1v3.1 | EPSS0.263% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-11546HIGH | IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerabilityIBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the adminCenter-1.0 feature enabled. CWE-918Jun 30, 2026 | CVSS7.1v3.1 | EPSS0.222% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-11714HIGH | IBM WebSphere Application Server Liberty is affected by an authorization bypass vulnerabilityIBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability with the apiDiscovery-1.0 feature enabled. CWE-918Jun 30, 2026 | CVSS8.5v3.1 | EPSS0.207% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-11806HIGH | IBM WebSphere Application Server Liberty is affected by a an arbitrary file read vulnerabilityIBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 is affected by an arbitrary file read vulnerability with the restConnector-2.0 feature enabled. CWE-444Jun 30, 2026 | CVSS7.2v3.1 | EPSS0.262% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-9320MEDIUM | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilitiesIBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. CWE-400Jun 22, 2026 | CVSS5.9v3.1 | EPSS0.349% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-9071HIGH | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by Uncontrolled Resource ConsumptionIBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. CWE-400Jun 22, 2026 | CVSS7.5v3.1 | EPSS0.549% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-8646HIGH | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilitiesIBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to HTTP request smuggling. A remote attacker could smuggle a specially crafted request to the application server thereby allowing the attacker to bypass security controls, spoof identity, escalate privilege, and expose sensitive information. CWE-444Jun 22, 2026 | CVSS7.4v3.1 | EPSS0.365% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-5516MEDIUM | IBM WebSphere Application Server Liberty is affected by a security bypass vulnerabilityIBM WebSphere Application Server - Liberty 22.0.0.11 through 26.0.0.5 IBM WebSphere Application Server Liberty could allow a remote attacker to bypass security under limited conditions by exploiting a specific timing window. CWE-362May 27, 2026 | CVSS4.4v3.1 | EPSS0.213% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |