Websphere Application Server

Vendor:

First CVE: Dec 2, 1999 · Active for 26 years

468
Total CVEs
More Total CVEs than 100% of tracked products
17.3
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 24% of tracked products
0.2%
KEV Rate
Higher KEV Rate than 95% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Websphere Application Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 2, 1999
26 years ago
Most Recent CVE
Jun 30, 2026
24 days ago

CVE Severity & Scoring

Websphere Application Server468 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local10 (2.1%)
Network183 (39.1%)
Unknown270 (57.7%)
Physical0 (0.0%)
Adjacent Network5 (1.1%)
Attack Complexity
Low171 (36.5%)
High27 (5.8%)
Unknown270 (57.7%)
User Interaction
None153 (32.7%)
Unknown270 (57.7%)
Required45 (9.6%)
Privileges Required
Low67 (14.3%)
High16 (3.4%)
None115 (24.6%)
Unknown270 (57.7%)

Top CVEs

Signals from CVEs in this product scope (468 CVEs).

468 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary
Jan 2, 20169.899YESYES
modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure
Mar 5, 201010.091NOYES
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects from untr
May 17, 20199.887NOYES
IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objec
Jun 5, 20209.849NONO
IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to
May 26, 20269.843NONO
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are affected by an HTTP request smuggling vulnerability.
Jun 30, 20269.841NONO
IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console help system.
Jun 30, 20269.341NONO
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of untrusted data via JAX-WS endpoints with WS-Security.
Jun 1, 20269.040NONO
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing.
Jun 1, 20269.140NONO
IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console's integrated help system.
Jun 30, 20269.339NONO

Exploit Exposure

Signals from CVEs in this product scope (468 CVEs).

CISA KEV
1 CVE
0.2% of CVEs· 95th percentile
Metasploit
4 CVEs
0.9% of CVEs· 96th percentile
Nuclei
1 CVE
0.2% of CVEs· 96th percentile
ExploitDB
12 CVEs
2.6% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (468 CVEs).

Media Mentions

Signals from CVEs in this product scope (468 CVEs).

Top CNAs Publishing CVEs For Websphere Application Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.0.5.1615.50.1%00
9.0.5.1515.50.1%00
9.0.0.426.21.5%00
9.0.0.315.92.0%00
9.0.0.225.71.4%00
9.0.0.146.62.3%00
9.0.0.0146.33.8%00
9.0236.41.2%00
8.5.5.9126.24.8%00
8.5.5.8146.14.3%00
8.5.5.7155.84.1%00
8.5.5.6175.73.8%00
8.5.5.5226.07.4%11
8.5.5.4256.03.4%00
8.5.5.3285.61.9%00
8.5.5.2315.50.1%00
8.5.5.2385.73.0%00
8.5.5.1125.71.4%00
8.5.5.1046.62.3%00
8.5.5.1435.52.9%00