Known vulnerabilities in IBM WebSphere Application Server - page 8

Software CPE: cpe:2.3:a:ibm_corporation:ibm_websphere_application_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 169
Public exploits: 4
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting IBM WebSphere Application Server IBM WebSphere Application Server is affected by 169 known vulnerabilities: 3 critical, 21 high, 78 medium, 67 low Critical High Medium Low

Vulnerabilities (169)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU76477 - Exposure of sensitive information to an unauthorized actor
CVE-2018-1838
CWE-200 Low
No
No
- 24.05.2023 SB2018101214
#VU15899 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2018-1643
CWE-79 Low
No
No
8.5.5.14, 9.0.0.9 13.11.2018 SB2018111418
SB2023011822
#VU15788 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2018-1798
CWE-79 Low
No
No
8.5.5.15, 9.0.0.10 09.11.2018 SB2018110913
SB2023011824
#VU15558 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2018-1767
CWE-79 Low
No
No
8.5.5.15, 9.0.0.10 26.10.2018 SB2018102905
SB2022121107
SB2023011818
#VU15369 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2018-1770
CWE-22 Medium
No
No
8.5.5.15, 9.0.0.10 16.10.2018 SB2018101601
SB2023011820
#VU15372 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2018-1777
CWE-79 Low
No
No
8.5.5.15, 9.0.0.10 15.10.2018 SB2018101606
SB2023011821
#VU15288 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2018-1793
CWE-79 Low
No
No
8.5.5.15, 9.0.0.10 10.10.2018 SB2018100402
SB2023011825
#VU15287 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2018-1794
CWE-79 Low
No
No
8.5.5.15, 9.0.0.10 10.10.2018 SB2018100402
SB2023011817
#VU14491 - Configuration
CWE-16 High
No
No
8.5.5.15 20.08.2018 SB2018082207
#VU13607 - Exposure of sensitive information to an unauthorized actor
CVE-2018-1621
CWE-200 Low
No
No
8.5.5.13, 9.0.0.8 06.07.2018 SB2018070910
SB2023013028
#VU13452 - Exposure of sensitive information to an unauthorized actor
CVE-2018-1614
CWE-200 Low
No
No
8.5.5.14, 9.0.0.9 22.06.2018 SB2018062512
SB2023013026
#VU12527 - Exposure of sensitive information to an unauthorized actor
CVE-2017-1743
CWE-200 Low
No
No
- 10.05.2018 SB2018051116
SB2023013029
#VU11067 - Exposure of sensitive information to an unauthorized actor
CVE-2017-1741
CWE-200 Low
No
No
- 12.03.2018 SB2018031402
SB2023013030
#VU10435 - Permissions, Privileges, and Access Controls
CVE-2017-1731
CWE-264 Low
No
No
- 09.02.2018 SB2018020905
#VU10431 - Exposure of sensitive information to an unauthorized actor
CVE-2017-1681
CWE-200 Low
No
No
- 09.02.2018 SB2018020905
SB2018041604
SB2018050202
#VU9019 - Exposure of sensitive information to an unauthorized actor
CVE-2011-4343
CWE-200 Low
No
No
- 31.10.2017 SB2017103107
#VU9017 - Error Handling
CVE-2017-1583
CWE-388 Low
No
No
- 31.10.2017 SB2017103107
#VU8787 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2017-1503
CWE-79 Low
No
No
- 10.10.2017 SB2017101101
#VU7984 - Exposure of sensitive information to an unauthorized actor
CVE-2017-1501
CWE-200 Low
No
No
- 18.08.2017 SB2017081801
#VU7647 - Exposure of sensitive information to an unauthorized actor
CVE-2017-1381
CWE-200 Low
No
No
- 01.08.2017 SB2017071813


Showing elements 141 - 160 out of 169