Websphere Application Server
Vendor:
First CVE: Dec 2, 1999 · Active for 26 years
468
Total CVEs
More Total CVEs than 100% of tracked products
17.3
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 24% of tracked products
0.2%
KEV Rate
Higher KEV Rate than 95% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Websphere Application Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 2, 1999
26 years ago
Most Recent CVE
Jun 30, 2026
24 days ago
CVE Severity & Scoring
Websphere Application Server468 CVEs
9%
57%
29%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local10 (2.1%)
Network183 (39.1%)
Unknown270 (57.7%)
Physical0 (0.0%)
Adjacent Network5 (1.1%)
Attack Complexity
Low171 (36.5%)
High27 (5.8%)
Unknown270 (57.7%)
User Interaction
None153 (32.7%)
Unknown270 (57.7%)
Required45 (9.6%)
Privileges Required
Low67 (14.3%)
High16 (3.4%)
None115 (24.6%)
Unknown270 (57.7%)
Top CVEs
Signals from CVEs in this product scope (468 CVEs).
468 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-7450CRITICAL Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary | Jan 2, 2016 | 9.8 | 99 | YES | YES |
CVE-2010-0425HIGH modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure | Mar 5, 2010 | 10.0 | 91 | NO | YES |
CVE-2019-4279CRITICAL IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects from untr | May 17, 2019 | 9.8 | 87 | NO | YES |
CVE-2020-4450CRITICAL IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objec | Jun 5, 2020 | 9.8 | 49 | NO | NO |
CVE-2026-8633CRITICAL IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to | May 26, 2026 | 9.8 | 43 | NO | NO |
CVE-2026-11541CRITICAL IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are affected by an HTTP request smuggling vulnerability. | Jun 30, 2026 | 9.8 | 41 | NO | NO |
CVE-2026-11712CRITICAL IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console help system. | Jun 30, 2026 | 9.3 | 41 | NO | NO |
CVE-2026-9319CRITICAL IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of untrusted data via JAX-WS endpoints with WS-Security. | Jun 1, 2026 | 9.0 | 40 | NO | NO |
CVE-2026-8644CRITICAL IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing. | Jun 1, 2026 | 9.1 | 40 | NO | NO |
CVE-2026-11708CRITICAL IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console's integrated help system. | Jun 30, 2026 | 9.3 | 39 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (468 CVEs).
CISA KEV
1 CVE
0.2% of CVEs· 95th percentile
Metasploit
4 CVEs
0.9% of CVEs· 96th percentile
Nuclei
1 CVE
0.2% of CVEs· 96th percentile
ExploitDB
12 CVEs
2.6% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (468 CVEs).
Media Mentions
Signals from CVEs in this product scope (468 CVEs).
Top CNAs Publishing CVEs For Websphere Application Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.0.5.16 | 1 | 5.5 | 0.1% | 0 | 0 |
| 9.0.5.15 | 1 | 5.5 | 0.1% | 0 | 0 |
| 9.0.0.4 | 2 | 6.2 | 1.5% | 0 | 0 |
| 9.0.0.3 | 1 | 5.9 | 2.0% | 0 | 0 |
| 9.0.0.2 | 2 | 5.7 | 1.4% | 0 | 0 |
| 9.0.0.1 | 4 | 6.6 | 2.3% | 0 | 0 |
| 9.0.0.0 | 14 | 6.3 | 3.8% | 0 | 0 |
| 9.0 | 23 | 6.4 | 1.2% | 0 | 0 |
| 8.5.5.9 | 12 | 6.2 | 4.8% | 0 | 0 |
| 8.5.5.8 | 14 | 6.1 | 4.3% | 0 | 0 |
| 8.5.5.7 | 15 | 5.8 | 4.1% | 0 | 0 |
| 8.5.5.6 | 17 | 5.7 | 3.8% | 0 | 0 |
| 8.5.5.5 | 22 | 6.0 | 7.4% | 1 | 1 |
| 8.5.5.4 | 25 | 6.0 | 3.4% | 0 | 0 |
| 8.5.5.3 | 28 | 5.6 | 1.9% | 0 | 0 |
| 8.5.5.23 | 1 | 5.5 | 0.1% | 0 | 0 |
| 8.5.5.2 | 38 | 5.7 | 3.0% | 0 | 0 |
| 8.5.5.11 | 2 | 5.7 | 1.4% | 0 | 0 |
| 8.5.5.10 | 4 | 6.6 | 2.3% | 0 | 0 |
| 8.5.5.1 | 43 | 5.5 | 2.9% | 0 | 0 |