WebSphere Application Server IBM WebSphere Application Server

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in IBM WebSphere Application Server.

By the Year

In 2026 there have been 35 vulnerabilities in IBM WebSphere Application Server with an average score of 7.6 out of ten. Last year, in 2025 WebSphere Application Server had 11 security vulnerabilities published. That is, 24 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 1.22.




Year Vulnerabilities Average Score
2026 35 7.63
2025 11 6.41
2024 19 6.43
2023 8 6.39
2022 11 6.41
2021 8 5.90
2020 22 7.26
2019 18 5.92
2018 24 0.00

It may take a day or so for new WebSphere Application Server vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent IBM WebSphere Application Server Security Vulnerabilities

IBM WAS 9.0/8.5 RCE via SOAP/JMX Connector
CVE-2026-11536 8.5 - High - July 30, 2026

IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability in the SOAP/JMX connector.

Marshaling, Unmarshaling

IBM WAS DoS via Crafted HTTP Request in 8.5-9.0 and Liberty 17-26
CVE-2026-9322 7.5 - High - July 30, 2026

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to a denial of service via a crafted HTTP request.

Resource Exhaustion

IBM WebSphere App Server 8.5/9.0 & Liberty 17.0.0.3-26.0.0.7 Bypass Security Constraints
CVE-2026-10842 7.5 - High - July 30, 2026

IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 Traditional and Liberty could allow a remote attacker to bypass security constraints.

Authentication Bypass by Alternate Name

IBM WSS/LIBERTY SIP SSRF via sipServlet-1.1 pre-26.0.0.9
CVE-2026-14529 9.4 - Critical - July 29, 2026

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side request forgery (SSRF) when the SIP container feature (sipServlet-1.1) is enabled.

Missing Authentication for Critical Function

Broken Access Control in IBM WebSphere App Server 8.5/9.0 Admin Console
CVE-2026-14446 9.8 - Critical - July 28, 2026

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the administrative console.

Missing Authentication for Critical Function

IBM WAS 8.5/9.0 Traditional XSS Vulnerability
CVE-2026-14515 6.1 - Medium - July 28, 2026

IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to conduct a cross-site scripting attack.

XSS

IBM WebSphere App Server 9.0/8.5 pre-auth unsafe deserialization
CVE-2026-14512 9.8 - Critical - July 28, 2026

IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attacker to bypass authentication or execute arbitrary code.

Marshaling, Unmarshaling

IBM WebSphere AppServer 8.5/9.0 Remote Info Disclosure
CVE-2026-14528 7.4 - High - July 28, 2026

IBM WebSphere Application Server 9.0, and 8.5 traditional could allow a remote attacker to obtain sensitive information.

Insertion of Sensitive Information into Log File

IBM WebSphere AppServer 8.5/9.0 RCE via Unsafe Deserialization
CVE-2026-14974 8.1 - High - July 28, 2026

IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of untrusted data.

Marshaling, Unmarshaling

IBM WebSphere WAS & Liberty DoS via HTTP Channel Unbounded Resource Allocation
CVE-2026-14981 7.5 - High - July 28, 2026

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are affected by a denial of service vulnerability in the HTTP channel due to unbounded allocation of resources without limits.

Resource Exhaustion

IBM WS HTTP Resp Smuggling via HTTP version token (pre 9.0/8.5, Liberty 17+)
CVE-2026-15064 8.7 - High - July 28, 2026

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to HTTP Response Smuggling due to improper handling of non-standard HTTP version tokens.

HTTP Request Smuggling

IBM WAS HTTP Request Smuggling via TRACE (8.5/9.0; Liberty 17-26)
CVE-2026-15325 8.7 - High - July 28, 2026

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to HTTP request smuggling due to improper handling of TRACE requests.

HTTP Request Smuggling

Request smuggling in IBM WebSphere App Server 8.5/9.0 & Liberty 17.0.0.3-26.0.0.7
CVE-2026-15328 7.4 - High - July 28, 2026

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to HTTP request smuggling.

HTTP Request Smuggling

IBM WAS 9.0/8.5 Auth Bypass via Unauthenticated Request
CVE-2026-16184 7 - High - July 28, 2026

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafted unauthenticated request.

AuthZ

HTTP Req Smuggling in IBM WebSphere WSAS 8.5/9.0 & Liberty 17.0.0.3-26.0.0.6
CVE-2026-11541 7.4 - High - June 30, 2026

IBM CICS Transaction Gateway for Multiplatforms 9.1, 9.2, 9.3, and 10.1 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are affected by an HTTP request smuggling vulnerability.

HTTP Request Smuggling

IBM WAS 9.0/8.5 XSS in Admin Console
CVE-2026-11594 8.5 - High - June 30, 2026

IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console.

XSS

IBM WebSphere App Server 8.5-9.0 Sensitive Info Disclosure via Admin Console Help
CVE-2026-11595 4.3 - Medium - June 30, 2026

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information from the administrative console's integrated help system.

Directory traversal

XSS on IBM WAS 9.0/8.5 Admin Console Help System
CVE-2026-11708 9.3 - Critical - June 30, 2026

IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console's integrated help system.

XSS

IBM WebSphere App Server 8.5-9.0: XSS in Admin Help System
CVE-2026-11712 9.3 - Critical - June 30, 2026

IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console help system.

XSS

Denial of Service via WebSphere WebServer Plug-in in IBM WAS 7.3-7.6
CVE-2026-10852 5.9 - Medium - June 22, 2026

IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to denial of service in the WebSphere WebServer Plug-in component when an attacker can pass crafted requests to the web server.

NULL Pointer Dereference

IBM WebSphere App Server DoS: crafted request (pre 9.0/8.5, Liberty 1726)
CVE-2026-9320 5.9 - Medium - June 22, 2026

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.

Resource Exhaustion

WAS DoS via crafted request (8.59.0 & Liberty 17.026.0)
CVE-2026-9071 7.5 - High - June 22, 2026

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.

Resource Exhaustion

IBM WAS 9.0/8.5 SSRF via Ajax Proxy
CVE-2026-9006 7.4 - High - June 22, 2026

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an attacker to send unauthorized requests from the system, resulting in a security bypass or information disclosure.

SSRF

IBM WebSphere App Server 9.0/8.5/Liberty 17-26 HTTP Request Smuggling
CVE-2026-8646 7.4 - High - June 22, 2026

IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to HTTP request smuggling. A remote attacker could smuggle a specially crafted request to the application server thereby allowing the attacker to bypass security controls, spoof identity, escalate privilege, and expose sensitive information.

HTTP Request Smuggling

IBM WAS 8.5/9.0 JAX-WS Auth Bypass Remote Exploit
CVE-2026-10845 7.3 - High - June 22, 2026

IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to bypass authentication and gain unauthorized access to JAX-WS applications.

authentification

Remote Code Exec in IBM WebSphere WebServer Plugin (IBM i 7.37.6)
CVE-2026-9072 8.1 - High - June 22, 2026

IBM WebSphere Application Server and IBM WebSphere Application Server Liberty - when using Intelligent Management with the WebSphere WebServer Plug-in component - are vulnerable to remote code execution and denial of service. This vulnerability can be exploited when an attacker impersonates backend servers and sends crafted responses to the plug-in.

Code Injection

IBM WebSphere Web Server Plug-in RCE (7.3-7.6)
CVE-2026-8858 7.5 - High - June 22, 2026

IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to remote code execution and denial of service in the WebSphere Web Server Plug-in component. This vulnerability can be exploited when an attacker impersonates the application server and sends crafted responses to the plug-in.

Code Injection

IBM WAS 9.0/8.5 SAML WebSSO RCE via Deserialization Gadget
CVE-2026-9330 8.5 - High - June 01, 2026

IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validation of user-supplied data during deserialization using the SAML Web Single Sign-On component. This could result in remote code execution via a crafted HTTP request when combined with a suitable gadget chain.

Marshaling, Unmarshaling

IBM WAS 8.5-9.0 RCE via Deserialization in JAX-WS WS-Security
CVE-2026-9319 9 - Critical - June 01, 2026

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of untrusted data via JAX-WS endpoints with WS-Security.

Marshaling, Unmarshaling

IBM WebSphere App Server 8.5-9.0 RCE via Security Control Bypass
CVE-2026-9311 9 - Critical - June 01, 2026

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security controls.

Code Injection

IBM WebSphere App Server 8.5/9.0 Identity Spoofing Vulnerability
CVE-2026-8644 9.1 - Critical - June 01, 2026

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing.

Authentication Bypass by Spoofing

IBM WebSphere App Server Liberty DoS via crafted request (v19.0-26.0)
CVE-2026-4410 4.8 - Medium - May 27, 2026

IBM WebSphere Application Server - Liberty 19.0.0.7 through 26.0.0.5 and IBM WebSphere Application Server 9.0, and 8.5 and WebSphere Application Server Liberty are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.

Resource Exhaustion

SSRF in IBM WebSphere Application Server Liberty 17.0.0.3-26.0.0.3
CVE-2026-1561 5.4 - Medium - March 25, 2026

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty is vulnerable to server-side request forgery (SSRF). This may allow remote attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

SSRF

IBM WebSphere Application Server 9.0/8.5 Weak Security Admin (CVE-2025-13333)
CVE-2025-13333 4.4 - Medium - February 17, 2026

IBM WebSphere Application Server 9.0, and 8.5 could provide weaker than expected security during system administration of security settings.

Improperly Implemented Security Check for Standard

IBM WAS Liberty 17.0.0.3-26.0.0.1 ZIP Path Traversal Arbitrary Code Execution
CVE-2025-14914 7.6 - High - February 02, 2026

IBM WebSphere Application Server Liberty 17.0.0.3 through 26.0.0.1 could allow a privileged user to upload a zip archive containing path traversal sequences resulting in an overwrite of files leading to arbitrary code execution.

Directory traversal

IBM WebSphere App Server 8.5/9.0 & Lib 17.0.0.3-25.0.0.12 XSS URL Redirect
CVE-2025-12635 5.4 - Medium - December 08, 2025

IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.12 are affected by cross-site scripting due to improper validation of user-supplied input. An attacker could exploit this vulnerability by using a specially crafted URL to redirect the user to a malicious site.

XSS

IBM WebSphere AS 8.5/9.0 DoS via Memory Exhaustion
CVE-2025-36099 4.9 - Medium - September 29, 2025

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to a denial of service, caused by sending a specially-crafted request. A privileged user could exploit this vulnerability to cause the server to consume memory resources.

Allocation of Resources Without Limits or Throttling

IBM WAS Liberty 18.0.0.2–25.0.0.8 DOS via memory exhaustion
CVE-2025-36047 5.3 - Medium - August 14, 2025

IBM WebSphere Application Server Liberty 18.0.0.2 through 25.0.0.8 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.

Allocation of Resources Without Limits or Throttling

IBM WebSphere AS 8.5/9.0 TLS Weak Cipher Suite
CVE-2025-33142 7.5 - High - August 14, 2025

IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security for TLS connections.

Improper Certificate Validation

IBM WebSphere Liberty 17.0.0.3-25.0.0.8 Stored XSS via Web UI
CVE-2025-36000 4.8 - Medium - August 12, 2025

IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.8 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

XSS

IBM WebSphere Liberty JMS Config Ignorance 17.0.0.3-25.0.0.8
CVE-2025-36124 7.5 - High - August 12, 2025

IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.8 could allow a remote attacker to bypass security restrictions caused by a failure to honor JMS messaging configuration

Privilege Chaining

IBM WebSphere App Server Config Bypass (9.0, 17.0.0.3-25.0.0.7)
CVE-2024-56339 7.5 - High - August 07, 2025

IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7 could allow a remote attacker to bypass security restrictions caused by a failure to honor security configuration.

IBM WebSphere App Server DoS via Stack Overflow (before 25.0.0.7)
CVE-2025-36097 7.5 - High - July 16, 2025

IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7 are vulnerable to a denial of service, caused by a stack-based overflow. An attacker can send a specially crafted request that cause the server to consume excessive memory resources.

Stack Overflow

RCE via Serialized Objects in IBM WebSphere App Server 8.5 & 9.0
CVE-2025-36038 9.8 - Critical - June 25, 2025

IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially crafted sequence of serialized objects.

Marshaling, Unmarshaling

IBM WebSphere Application Server 8.5/9.0 XSS in Web UI
CVE-2025-33104 7.6 - High - May 14, 2025

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

XSS

SSRF Vulnerability in IBM WebSphere App Server 8.5/9.0
CVE-2025-27907 2.7 - Low - April 22, 2025

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

SSRF

IBM WebSphere Application Server 8.5/9.0 XSS Vulnerability in Web UI
CVE-2024-45087 4.8 - Medium - November 11, 2024

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

XSS

IBM WebSphere XXE Injection Vulnerability
CVE-2024-45086 5.5 - Medium - November 04, 2024

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to expose sensitive information or consume memory resources.

XXE

IBM WebSphere App Server 8.5/9.0 XSS via Web UI (CVE-2024-45071)
CVE-2024-45071 4.8 - Medium - October 16, 2024

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

XSS

IBM WebSphere App Server 8.5/9.0 XXE Vulnerable XML Parser
CVE-2024-45072 5.5 - Medium - October 16, 2024

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to expose sensitive information or consume memory resources.

XXE

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for IBM WebSphere Application Server or by IBM? Click the Watch button to subscribe.

IBM
Vendor

subscribe