Show filters
432 Total Results
Displaying 41-50 of 432
Sort by:
Attacker Value
Unknown

CVE-2022-22475

Disclosure Date: May 16, 2022 (last updated October 07, 2023)
IBM WebSphere Application Server Liberty and Open Liberty 17.0.0.3 through 22.0.0.5 are vulnerable to identity spoofing by an authenticated user. IBM X-Force ID: 225603.
Attacker Value
Unknown

CVE-2022-22393

Disclosure Date: May 12, 2022 (last updated October 07, 2023)
IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.5 , with the adminCenter-1.0 feature configured, could allow an authenticated user to issue a request to obtain the status of HTTP/HTTPS ports which are accessible by the application server. IBM X-Force ID: 222078.
Attacker Value
Unknown

CVE-2021-39038

Disclosure Date: February 23, 2022 (last updated October 07, 2023)
IBM WebSphere Application Server 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.2 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 213968.
Attacker Value
Unknown

CVE-2021-39031

Disclosure Date: January 24, 2022 (last updated October 07, 2023)
IBM WebSphere Application Server - Liberty 17.0.0.3 through 22.0.0.1 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this vulnerability and could result in in granting permission to unauthorized resources. IBM X-Force ID: 213875.
Attacker Value
Unknown

CVE-2022-22310

Disclosure Date: January 18, 2022 (last updated October 07, 2023)
IBM WebSphere Application Server Liberty 21.0.0.10 through 21.0.0.12 could provide weaker than expected security. A remote attacker could exploit this weakness to obtain sensitive information and gain unauthorized access to JAX-WS applications. IBM X-Force ID: 217224.
Attacker Value
Unknown

CVE-2021-38951

Disclosure Date: December 08, 2021 (last updated October 07, 2023)
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume all available CPU resources. IBM X-Force ID: 211405.
Attacker Value
Unknown

CVE-2021-29842

Disclosure Date: September 15, 2021 (last updated February 23, 2025)
IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0 and Liberty 17.0.0.3 through 21.0.0.9 could allow a remote user to enumerate usernames due to a difference of responses from valid and invalid login attempts. IBM X-Force ID: 205202.
Attacker Value
Unknown

CVE-2021-29736

Disclosure Date: July 29, 2021 (last updated November 28, 2024)
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote user to gain elevated privileges on the system. IBM X-Force ID: 201300.
Attacker Value
Unknown

CVE-2021-29754

Disclosure Date: June 10, 2021 (last updated November 28, 2024)
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a privilege escalation vulnerability when using the SAML Web Inbound Trust Association Interceptor (TAI). IBM X-Force ID: 202006.
Attacker Value
Unknown

CVE-2021-20517

Disclosure Date: May 27, 2021 (last updated February 22, 2025)
IBM WebSphere Application Server Network Deployment 8.5 and 9.0 could allow a remote authenticated attacker to traverse directories. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to read and delete arbitrary files on the system. IBM X-Force ID: 198435.