Websphere Virtual Enterprise
Vendor:
First CVE: Nov 18, 2013 · Active for 12 years
8
Total CVEs
More Total CVEs than 85% of tracked products
1.6
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
5.4
Avg CVSS
Higher Avg CVSS than 11% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Websphere Virtual Enterprise over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 18, 2013
12 years ago
Most Recent CVE
Aug 27, 2020
2,159 days ago
CVE Severity & Scoring
Websphere Virtual Enterprise8 CVEs
25%
63%
13%
All CVEs352,713 CVEs
45%
40%
11%
LowMediumCritical
Attack Vector
Local0 (0.0%)
Network4 (50.0%)
Unknown4 (50.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (50.0%)
High0 (0.0%)
Unknown4 (50.0%)
User Interaction
None2 (25.0%)
Unknown4 (50.0%)
Required2 (25.0%)
Privileges Required
Low1 (12.5%)
High0 (0.0%)
None3 (37.5%)
Unknown4 (50.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-4448CRITICAL IBM WebSphere Application Server Network Deployment 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence o | Jun 5, 2020 | 9.8 | 31 | NO | NO |
CVE-2020-4575MEDIUM IBM WebSphere Application Server ND 8.5 and 9.0, and IBM WebSphere Virtual Enterprise 7.0 and 8.0 are vulnerable to cross-site scripting when High Availability Deployment Manager i | Aug 27, 2020 | 6.1 | 21 | NO | NO |
CVE-2019-4505MEDIUM IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Network Deployment could allow a remote attacker to obtain sensitive information, caused by sending a specially-crafted URL. | Sep 20, 2019 | 5.3 | 21 | NO | NO |
CVE-2019-4030MEDIUM IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering t | Mar 6, 2019 | 5.4 | 20 | NO | NO |
CVE-2015-1932MEDIUM IBM WebSphere Application Server 7.x before 7.0.0.39, 8.0.x before 8.0.0.11, and 8.5.x before 8.5.5.7 and WebSphere Virtual Enterprise before 7.0.0.7 allow remote attackers to obta | Aug 22, 2015 | 5.0 | 15 | NO | NO |
CVE-2015-1946MEDIUM IBM WebSphere Application Server (WAS) 8.5 before 8.5.5.6, and WebSphere Virtual Enterprise 7.0 before 7.0.0.6 for WebSphere Application Server (WAS) 7.0 and 8.0, does not properly | Jul 14, 2015 | 4.4 | 14 | NO | NO |
Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 7.x before 7.0.0.33, 8.x before 8.0.0.9, and 8.5.x before 8.5.5.2, | May 1, 2014 | 3.5 | 13 | NO | NO |
Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Virtual Enterprise 6.1 before 6.1.1.6 and 7.0 before 7.0.0.4 allows remote authenticated use | Nov 18, 2013 | 3.5 | 13 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Websphere Virtual Enterprise
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 8.0 | 4 | 6.7 | 4.0% | 0 | 0 |
| 7.0.0.5 | 1 | 4.4 | 0.4% | 0 | 0 |
| 7.0.0.4 | 2 | 4.0 | 1.0% | 0 | 0 |
| 7.0.0.3 | 3 | 3.8 | 1.1% | 0 | 0 |
| 7.0.0.2 | 3 | 3.8 | 1.1% | 0 | 0 |
| 7.0.0.1 | 3 | 3.8 | 1.1% | 0 | 0 |
| 7.0 | 7 | 5.4 | 2.8% | 0 | 0 |
| 6.1.1.5 | 1 | 3.5 | 1.4% | 0 | 0 |
| 6.1.1.4 | 1 | 3.5 | 1.4% | 0 | 0 |
| 6.1.1.3 | 1 | 3.5 | 1.4% | 0 | 0 |
| 6.1.1.2 | 1 | 3.5 | 1.4% | 0 | 0 |
| 6.1.1.1 | 1 | 3.5 | 1.4% | 0 | 0 |
| 6.1.1 | 1 | 3.5 | 1.4% | 0 | 0 |
| 6.1 | 1 | 3.5 | 1.4% | 0 | 0 |