Websphere Virtual Enterprise

Vendor:

First CVE: Nov 18, 2013 · Active for 12 years

8
Total CVEs
More Total CVEs than 85% of tracked products
1.6
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
5.4
Avg CVSS
Higher Avg CVSS than 11% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Websphere Virtual Enterprise over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 18, 2013
12 years ago
Most Recent CVE
Aug 27, 2020
2,159 days ago

CVE Severity & Scoring

Websphere Virtual Enterprise8 CVEs
All CVEs352,713 CVEs
LowMediumCritical
Attack Vector
Local0 (0.0%)
Network4 (50.0%)
Unknown4 (50.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (50.0%)
High0 (0.0%)
Unknown4 (50.0%)
User Interaction
None2 (25.0%)
Unknown4 (50.0%)
Required2 (25.0%)
Privileges Required
Low1 (12.5%)
High0 (0.0%)
None3 (37.5%)
Unknown4 (50.0%)

Top CVEs

Signals from CVEs in this product scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
IBM WebSphere Application Server Network Deployment 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence o
Jun 5, 20209.831NONO
IBM WebSphere Application Server ND 8.5 and 9.0, and IBM WebSphere Virtual Enterprise 7.0 and 8.0 are vulnerable to cross-site scripting when High Availability Deployment Manager i
Aug 27, 20206.121NONO
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Network Deployment could allow a remote attacker to obtain sensitive information, caused by sending a specially-crafted URL.
Sep 20, 20195.321NONO
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering t
Mar 6, 20195.420NONO
IBM WebSphere Application Server 7.x before 7.0.0.39, 8.0.x before 8.0.0.11, and 8.5.x before 8.5.5.7 and WebSphere Virtual Enterprise before 7.0.0.7 allow remote attackers to obta
Aug 22, 20155.015NONO
IBM WebSphere Application Server (WAS) 8.5 before 8.5.5.6, and WebSphere Virtual Enterprise 7.0 before 7.0.0.6 for WebSphere Application Server (WAS) 7.0 and 8.0, does not properly
Jul 14, 20154.414NONO
Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 7.x before 7.0.0.33, 8.x before 8.0.0.9, and 8.5.x before 8.5.5.2,
May 1, 20143.513NONO
Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Virtual Enterprise 6.1 before 6.1.1.6 and 7.0 before 7.0.0.4 allows remote authenticated use
Nov 18, 20133.513NONO

Exploit Exposure

Signals from CVEs in this product scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (8 CVEs).

Media Mentions

Signals from CVEs in this product scope (8 CVEs).

Top CNAs Publishing CVEs For Websphere Virtual Enterprise

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
8.046.74.0%00
7.0.0.514.40.4%00
7.0.0.424.01.0%00
7.0.0.333.81.1%00
7.0.0.233.81.1%00
7.0.0.133.81.1%00
7.075.42.8%00
6.1.1.513.51.4%00
6.1.1.413.51.4%00
6.1.1.313.51.4%00
6.1.1.213.51.4%00
6.1.1.113.51.4%00
6.1.113.51.4%00
6.113.51.4%00