IBM
IBM Websphere Application Server: vulnerabilidades y CVE
IBM Websphere Application Server tiene 519 vulnerabilidades publicadas, 83 de ellas en los últimos 12 meses. 35 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE519
Últimos 12 meses83
Críticas35
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2015-7450 | Crítica (9.8) | 98% | ⚠ Explotación activa | 2 ene 2016 | Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-11722 | Media (4.8) | 0.18% | — | 18 sept 2026 | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vulnerability. |
| CVE-2026-11711 | Media (6.5) | 0.38% | — | 18 sept 2026 | IBM WebSphere Application Server 9.0 and 8.5 is affected by a deserialization vulnerability in the Name Service component. |
| CVE-2026-11710 | Media (6.5) | 0.23% | — | 18 sept 2026 | IBM WebSphere Application Server 8.5 is affected by an HTTP request smuggling vulnerability due to improper handling of Content-Length headers. |
| CVE-2026-11549 | Media (6.5) | 0.23% | — | 18 sept 2026 | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a virtual host bypass vulnerability. |
| CVE-2026-11548 | Media (4.8) | 0.18% | — | 18 sept 2026 | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vulnerability. |
| CVE-2026-11545 | Baja (3.7) | 0.26% | — | 18 sept 2026 | IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to obtain sensitive information from the administrative console due to missing authorization checks. |
| CVE-2026-11540 | Media (5.3) | 0.30% | — | 18 sept 2026 | IBM WebSphere Application Server 9.0 and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet. |
| CVE-2026-11539 | Media (5.3) | 0.30% | — | 18 sept 2026 | IBM WebSphere Application Server 9.0 and 8.5 is affected by an authentication bypass vulnerability in the SOAP/JMX connector. |
| CVE-2026-11538 | Media (5.3) | 0.16% | — | 18 sept 2026 | IBM WebSphere Application Server 9.0 and 8.5 is affected by a log injection vulnerability through crafted LTPA token cookies. |
| CVE-2026-11537 | Media (4.3) | 0.18% | — | 18 sept 2026 | IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet. |
| CVE-2026-10841 | Media (4.8) | 0.18% | — | 18 sept 2026 | IBM WebSphere Application Server 8.5, 9.0, and Liberty are vulnerable to HTTP request smuggling. |
| CVE-2026-16435 | Media (5.9) | 0.31% | — | 14 sept 2026 | IBM WebSphere Application Server 9.0, and 8.5 is affected by an authentication bypass vulnerability when using XD or Intelligent-Management features. |
| CVE-2026-16190 | Baja (3.1) | 0.16% | — | 14 sept 2026 | IBM WebSphere Application Server 9.0, and 8.5 is affected by an authorization bypass vulnerability. |
| CVE-2026-16189 | Media (4.8) | 0.22% | — | 14 sept 2026 | IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log entries into the server's administrative log. |
| CVE-2026-16188 | Media (5.3) | 0.27% | — | 14 sept 2026 | IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log entries into the server's administrative log. |
| CVE-2026-16187 | Media (6.5) | 0.25% | — | 14 sept 2026 | IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication and obtain sensitive information by sending a crafted unauthenticated request. |
| CVE-2026-16186 | Media (5.4) | 0.18% | — | 14 sept 2026 | IBM WebSphere Application Server 9.0, and 8.5 is affected by a reflected cross-site scripting vulnerability. |
| CVE-2026-16185 | Media (6.4) | 0.20% | — | 14 sept 2026 | IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication on an admin console servlet. |
| CVE-2026-15887 | Media (5.4) | 0.18% | — | 14 sept 2026 | IBM WebSphere Application Server 9.0, and 8.5 is affected by blind server-side request forgery when processing SOAP requests. |
| CVE-2026-15634 | Media (6.5) | 0.25% | — | 14 sept 2026 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP transfer-encoding request header. By sending… |
| CVE-2026-15412 | Media (6.5) | 0.23% | — | 14 sept 2026 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a… |
| CVE-2026-15396 | Media (6.5) | 0.25% | — | 14 sept 2026 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP transfer-encoding request header. By sending… |
| CVE-2026-9667 | Media (5.3) | 0.43% | — | 10 sept 2026 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) that could allow a remote, unauthenticated attacker to cause the server to send outbound requests to arbitrary endpoints. |
| CVE-2026-9327 | Alta (8.1) | 0.37% | — | 10 sept 2026 | IBM WebSphere Application Server 9.0, and 8.5 could allow an authenticated user with a low-privilege administrative role to modify security configuration. This could result in information disclosure or denial of service. |
| CVE-2026-9176 | Alta (7.1) | 0.16% | — | 10 sept 2026 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a security bypass due to improper authentication controls. A local attacker could exploit this vulnerability to escalate privileges and gain unauthorized… |
| CVE-2026-9338 | Media (5.3) | 0.49% | — | 10 sept 2026 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to trigger excessive resource… |
| CVE-2026-9336 | Alta (7.5) | 0.77% | — | 10 sept 2026 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted HTTP request to an administrative endpoint. A remote attacker could exploit this vulnerability to… |
| CVE-2026-14525 | Crítica (9.4) | 0.55% | — | 13 ago 2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is vulnerable to an authentication bypass when the rtcomm-1.0 or rtcommGateway-1.0 feature is enabled. |
| CVE-2026-10571 | Media (5.3) | 0.59% | — | 13 ago 2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service caused by insecure deserialization. A low-privileged, administrative user could exploit this vulnerability to… |
| CVE-2026-18499 | Alta (8.1) | 0.42% | — | 12 ago 2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to a privilege escalation when using Liberty collectives. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de IBM
AIX · 551DB2 · 355Vios · 237Sterling B2B Integrator · 205I · 203Rational Quality Manager · 202Qradar Security Information AND Event Manager · 192Infosphere Information Server · 189Maximo Asset Management · 182Rational Doors Next Generation · 153Rational Team Concert · 142Rational Engineering Lifecycle Manager · 141