WebSphere Application Server IBM WebSphere Application Server

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in IBM WebSphere Application Server.

By the Year

In 2026 there have been 59 vulnerabilities in IBM WebSphere Application Server with an average score of 6.8 out of ten. Last year, in 2025 WebSphere Application Server had 11 security vulnerabilities published. That is, 48 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.42.




Year Vulnerabilities Average Score
2026 59 6.83
2025 11 6.41
2024 19 6.43
2023 8 6.39
2022 11 6.41
2021 8 5.90
2020 22 7.26
2019 18 5.92
2018 24 0.00

It may take a day or so for new WebSphere Application Server vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent IBM WebSphere Application Server Security Vulnerabilities

IBM WebSphere App Server 9.0/8.5 Deserialization in Name Service
CVE-2026-11711 6.5 - Medium - September 18, 2026

IBM WebSphere Application Server 9.0 and 8.5 is affected by a deserialization vulnerability in the Name Service component.

Marshaling, Unmarshaling

IBM WebSphere WSAS 8.5 HTTP Request Smuggling via Content-Length
CVE-2026-11710 6.5 - Medium - September 18, 2026

IBM WebSphere Application Server 8.5 is affected by an HTTP request smuggling vulnerability due to improper handling of Content-Length headers.

HTTP Request Smuggling

IBM WebSphere App Server 8.5/9.0 Auth Bypass in Admin Console
CVE-2026-11545 3.7 - Low - September 18, 2026

IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to obtain sensitive information from the administrative console due to missing authorization checks.

AuthZ

IBM WebSphere AS 8.5/9.0 FileTransfer Servlet Info Disclosure
CVE-2026-11540 5.3 - Medium - September 18, 2026

IBM WebSphere Application Server 9.0 and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet.

AuthZ

IBM WebSphere App Server 9.0/8.5 Auth Bypass in SOAP/JMX Connector
CVE-2026-11539 5.3 - Medium - September 18, 2026

IBM WebSphere Application Server 9.0 and 8.5 is affected by an authentication bypass vulnerability in the SOAP/JMX connector.

Missing Authentication for Critical Function

IBM WebSphere AS 9.0/8.5 Log Injection via LTPA Token
CVE-2026-11538 3.7 - Low - September 18, 2026

IBM WebSphere Application Server 9.0 and 8.5 is affected by a log injection vulnerability through crafted LTPA token cookies.

Improper Output Neutralization for Logs

Info Disclosure via FileTransfer Servlet in IBM WBS 8.5/9.0 (CVE-2026-11537)
CVE-2026-11537 4.3 - Medium - September 18, 2026

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet.

Trusting HTTP Permission Methods on the Server Side

HTTP Request Smuggling in IBM WebSphere App Server 8.5/9.0 & Liberty
CVE-2026-15396 6.5 - Medium - September 14, 2026

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP transfer-encoding request header. By sending a specially crafted HTTP transfer-encoding request header, an attacker could exploit this vulnerability to poison the web cache, bypass web application firewall protection, and conduct XSS attacks.

HTTP Request Smuggling

IBM WebSphere App Server V8.5/9.0 & Liberty: ODR Phishing via Open Redirect
CVE-2026-15412 6.5 - Medium - September 14, 2026

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.

Open Redirect

IBM WebSphere App Server 9.0 HTTP Request Smuggling via Transfer-Encoding
CVE-2026-15634 6.5 - Medium - September 14, 2026

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP transfer-encoding request header. By sending a specially crafted HTTP transfer-encoding request header, an attacker could exploit this vulnerability to poison the web cache, bypass web application firewall protection, and conduct XSS attacks.

HTTP Request Smuggling

IBM WebSphere App Server 9.0/8.5 Blind SSRF via SOAP Requests
CVE-2026-15887 5.4 - Medium - September 14, 2026

IBM WebSphere Application Server 9.0, and 8.5 is affected by blind server-side request forgery when processing SOAP requests.

SSRF

IBM WAS 9.0/8.5 Reflected XSS in WebSphere Application Server
CVE-2026-16186 5.4 - Medium - September 14, 2026

IBM WebSphere Application Server 9.0, and 8.5 is affected by a reflected cross-site scripting vulnerability.

XSS

IBM WebSphere Application Server 9.0, and 8.5 could
CVE-2026-16185 6.4 - Medium - September 14, 2026

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication on an admin console servlet.

AuthZ

IBM WebSphere Application Server 9.0, and 8.5 could
CVE-2026-16187 6.5 - Medium - September 14, 2026

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication and obtain sensitive information by sending a crafted unauthenticated request.

AuthZ

IBM WebSphere Application Server 9.0, and 8.5 could
CVE-2026-16188 5.3 - Medium - September 14, 2026

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log entries into the server's administrative log.

Improper Output Neutralization for Logs

IBM WebSphere Application Server 9.0
CVE-2026-16190 3.1 - Low - September 14, 2026

IBM WebSphere Application Server 9.0, and 8.5 is affected by an authorization bypass vulnerability.

AuthZ

IBM WebSphere Application Server 9.0, and 8.5 could
CVE-2026-16189 4.8 - Medium - September 14, 2026

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log entries into the server's administrative log.

Improper Output Neutralization for Logs

IBM WebSphere Application Server 9.0
CVE-2026-16435 5.9 - Medium - September 14, 2026

IBM WebSphere Application Server 9.0, and 8.5 is affected by an authentication bypass vulnerability when using XD or Intelligent-Management features.

Trusting HTTP Permission Methods on the Server Side

IBM WebSphere AS SSRF in 9.0/8.5: remote unauthenticated attack
CVE-2026-9667 5.3 - Medium - September 10, 2026

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) that could allow a remote, unauthenticated attacker to cause the server to send outbound requests to arbitrary endpoints.

SSRF

IBM WebSphere App Server 8.5/9.0 Auth Bypass Prior to 9.1
CVE-2026-9176 6.7 - Medium - September 10, 2026

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a security bypass due to improper authentication controls. A local attacker could exploit this vulnerability to escalate privileges and gain unauthorized access to protected resources.

Code Injection

IBM WebSphere AppServer 8.5-9.0: Low-Priv Auth Admin Mod Config for Info Leak/DoS
CVE-2026-9327 6.3 - Medium - September 10, 2026

IBM WebSphere Application Server 9.0, and 8.5 could allow an authenticated user with a low-privilege administrative role to modify security configuration. This could result in information disclosure or denial of service.

Improper Privilege Management

IBM WebSphere App Server 8.5-9.0 DoS via Admin HTTP Endpoint
CVE-2026-9336 6.5 - Medium - September 10, 2026

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted HTTP request to an administrative endpoint. A remote attacker could exploit this vulnerability to cause the server to exhaust filesystem space.

Missing Authentication for Critical Function

IBM WebSphere App Server 8.5-9.0 DoS via crafted request
CVE-2026-9338 5.3 - Medium - September 10, 2026

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to trigger excessive resource consumption, potentially leading to reduced availability of the affected service.

Resource Exhaustion

IBM WebSphere AppServer 8.5/9.0 ORB flaw permits arbitrary class loading via IIOP
CVE-2026-8400 8.1 - High - August 05, 2026

IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server to induce loading and instantation of arbitrary classes.

Reflection Injection

IBM WAS 9.0/8.5 RCE via SOAP/JMX Connector
CVE-2026-11536 8.5 - High - July 30, 2026

IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability in the SOAP/JMX connector.

Marshaling, Unmarshaling

IBM WAS DoS via Crafted HTTP Request in 8.5-9.0 and Liberty 17-26
CVE-2026-9322 7.5 - High - July 30, 2026

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to a denial of service via a crafted HTTP request.

Resource Exhaustion

IBM WebSphere App Server 8.5/9.0 & Liberty 17.0.0.3-26.0.0.7 Bypass Security Constraints
CVE-2026-10842 7.5 - High - July 30, 2026

IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 Traditional and Liberty could allow a remote attacker to bypass security constraints.

Authentication Bypass by Alternate Name

IBM WSS/LIBERTY SIP SSRF via sipServlet-1.1 pre-26.0.0.9
CVE-2026-14529 9.4 - Critical - July 29, 2026

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side request forgery (SSRF) when the SIP container feature (sipServlet-1.1) is enabled.

Missing Authentication for Critical Function

Broken Access Control in IBM WebSphere App Server 8.5/9.0 Admin Console
CVE-2026-14446 9.8 - Critical - July 28, 2026

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the administrative console.

Missing Authentication for Critical Function

IBM WAS 8.5/9.0 Traditional XSS Vulnerability
CVE-2026-14515 6.1 - Medium - July 28, 2026

IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to conduct a cross-site scripting attack.

XSS

IBM WebSphere App Server 9.0/8.5 pre-auth unsafe deserialization
CVE-2026-14512 9.8 - Critical - July 28, 2026

IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attacker to bypass authentication or execute arbitrary code.

Marshaling, Unmarshaling

IBM WebSphere AppServer 8.5/9.0 Remote Info Disclosure
CVE-2026-14528 7.4 - High - July 28, 2026

IBM WebSphere Application Server 9.0, and 8.5 traditional could allow a remote attacker to obtain sensitive information.

Insertion of Sensitive Information into Log File

IBM WebSphere AppServer 8.5/9.0 RCE via Unsafe Deserialization
CVE-2026-14974 8.1 - High - July 28, 2026

IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of untrusted data.

Marshaling, Unmarshaling

IBM WebSphere WAS & Liberty DoS via HTTP Channel Unbounded Resource Allocation
CVE-2026-14981 7.5 - High - July 28, 2026

IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty are affected by a denial of service vulnerability in the HTTP channel due to unbounded allocation of resources without limits.

Resource Exhaustion

IBM WS HTTP Resp Smuggling via HTTP version token (pre 9.0/8.5, Liberty 17+)
CVE-2026-15064 8.7 - High - July 28, 2026

IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTTP Response Smuggling due to improper handling of non-standard HTTP version tokens.

HTTP Request Smuggling

IBM WAS HTTP Request Smuggling via TRACE (8.5/9.0; Liberty 17-26)
CVE-2026-15325 8.7 - High - July 28, 2026

IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTTP request smuggling due to improper handling of TRACE requests.

HTTP Request Smuggling

Request smuggling in IBM WebSphere App Server 8.5/9.0 & Liberty 17.0.0.3-26.0.0.7
CVE-2026-15328 7.4 - High - July 28, 2026

IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTTP request smuggling.

HTTP Request Smuggling

IBM WAS 9.0/8.5 Auth Bypass via Unauthenticated Request
CVE-2026-16184 7 - High - July 28, 2026

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafted unauthenticated request.

AuthZ

HTTP Req Smuggling in IBM WebSphere WSAS 8.5/9.0 & Liberty 17.0.0.3-26.0.0.6
CVE-2026-11541 7.4 - High - June 30, 2026

IBM CICS Transaction Gateway for Multiplatforms 9.1, 9.2, 9.3, and 10.1 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are affected by an HTTP request smuggling vulnerability.

HTTP Request Smuggling

IBM WAS 9.0/8.5 XSS in Admin Console
CVE-2026-11594 8.5 - High - June 30, 2026

IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console.

XSS

IBM WebSphere App Server 8.5-9.0 Sensitive Info Disclosure via Admin Console Help
CVE-2026-11595 4.3 - Medium - June 30, 2026

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information from the administrative console's integrated help system.

Directory traversal

XSS on IBM WAS 9.0/8.5 Admin Console Help System
CVE-2026-11708 9.3 - Critical - June 30, 2026

IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console's integrated help system.

XSS

IBM WebSphere App Server 8.5-9.0: XSS in Admin Help System
CVE-2026-11712 9.3 - Critical - June 30, 2026

IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console help system.

XSS

Denial of Service via WebSphere WebServer Plug-in in IBM WAS 7.3-7.6
CVE-2026-10852 5.9 - Medium - June 22, 2026

IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to denial of service in the WebSphere WebServer Plug-in component when an attacker can pass crafted requests to the web server.

NULL Pointer Dereference

IBM WebSphere App Server DoS: crafted request (pre 9.0/8.5, Liberty 1726)
CVE-2026-9320 5.9 - Medium - June 22, 2026

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.

Resource Exhaustion

WAS DoS via crafted request (8.59.0 & Liberty 17.026.0)
CVE-2026-9071 7.5 - High - June 22, 2026

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.

Resource Exhaustion

IBM WAS 9.0/8.5 SSRF via Ajax Proxy
CVE-2026-9006 7.4 - High - June 22, 2026

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an attacker to send unauthorized requests from the system, resulting in a security bypass or information disclosure.

SSRF

IBM WebSphere App Server 9.0/8.5/Liberty 17-26 HTTP Request Smuggling
CVE-2026-8646 7.4 - High - June 22, 2026

IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to HTTP request smuggling. A remote attacker could smuggle a specially crafted request to the application server thereby allowing the attacker to bypass security controls, spoof identity, escalate privilege, and expose sensitive information.

HTTP Request Smuggling

IBM WAS 8.5/9.0 JAX-WS Auth Bypass Remote Exploit
CVE-2026-10845 7.3 - High - June 22, 2026

IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to bypass authentication and gain unauthorized access to JAX-WS applications.

authentification

Remote Code Exec in IBM WebSphere WebServer Plugin (IBM i 7.37.6)
CVE-2026-9072 8.1 - High - June 22, 2026

IBM WebSphere Application Server and IBM WebSphere Application Server Liberty - when using Intelligent Management with the WebSphere WebServer Plug-in component - are vulnerable to remote code execution and denial of service. This vulnerability can be exploited when an attacker impersonates backend servers and sends crafted responses to the plug-in.

Code Injection

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for IBM WebSphere Application Server or by IBM? Click the Watch button to subscribe.

IBM
Vendor

subscribe