IBM websphere application server是美国IBM公司的一个Web应用执行环境。 IBM WebSphere Application Server 9.0版本和8.5版本存在反序列化注入漏洞,该漏洞源于预身份验证不安全反序列化,可能导致远程攻击者绕过身份验证或执行任意代码。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| IBM | WebSphere Application Server | 9.0 |
affected |
8.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| IBM | WebSphere Application Server | 9.0 |
cpe:2.3:a:ibm:websphere_application_server:9.0:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-14446 | 9.8 CRITICAL | IBM WebSphere Application Server is affected by a privilege escalation |
| CVE-2026-14973 | 9.3 CRITICAL | Path Traversal in IBM Desktop App |
| CVE-2026-14958 | 9.1 CRITICAL | OS command injection in IBM Aspera Faspex |
| CVE-2026-14959 | 9.1 CRITICAL | OS Command Injection in IBM Aspera Faspex |
| CVE-2026-15064 | 8.7 HIGH | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by |
| CVE-2026-15325 | 8.7 HIGH | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by |
| CVE-2026-14996 | 8.2 HIGH | Multiple vulnerabilities in IBM Aspera Faspex |
| CVE-2026-14974 | 8.1 HIGH | IBM WebSphere Application Server is affected by cross-site scripting and deserialization v |
| CVE-2026-7769 | 8.1 HIGH | SQL injection Security Vulnerability in IBM Sterling B2B Integrator and IBM Sterling File |
| CVE-2026-14981 | 7.5 HIGH | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by |
| CVE-2026-15280 | 7.5 HIGH | IBM WebSphere Application Server Liberty is affected by a remote code execution and path-s |
| CVE-2026-15057 | 7.5 HIGH | IBM WebSphere Application Server Liberty is affected by a denial of service vulnerability |
| CVE-2026-13463 | 7.5 HIGH | Due to use of IBM Storage Protect, IBM Cloud Pak System is affected by vulnerability [] |
| CVE-2026-15328 | 7.4 HIGH | IBM WebSphere Application Server and WebSphere Application Server Liberty is inconsistent |
| CVE-2026-14528 | 7.4 HIGH | IBM WebSphere Application Server is affected by an unsafe deserialization and exposure of |
| CVE-2026-14893 | 7.3 HIGH | IBM Instana Observability is affected by multiple Prototype Pollution within Instana Agent |
| CVE-2026-13442 | 7.1 HIGH | Langflow is affected by NET Misconfiguration: Use of Impersonation due to multiple unauthe |
| CVE-2026-14976 | 7.1 HIGH | IBM WebSphere Application Server Liberty is affected by a remote code execution and path-s |
| CVE-2026-16192 | 7.1 HIGH | IBM WebSphere Application Server Liberty is affected by a denial of service |
| CVE-2026-16184 | 7.0 HIGH | IBM WebSphere Application Server is affected by an authentication bypass |
Showing top 20 of 31 CVEs. View all on vendor page → →
No comments yet