Skip to main content

Vendor/product archive

ibm / websphere_extreme_scale CVEs

Beta · best-effort

23 CVEs tagged to ibm / websphere_extreme_scale0 Critical, 3 High, 15 Medium, 5 Low, 0 Unrated.

CVE-2026-9002

Published Jun 30, 2026

IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 could allow an adjacent attacker to cause a denial of service due to improper validation in the XDF decoder. The application pr…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-13773

Published Jun 30, 2026

IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 Approximately 50 generated CORBA stub classes in WebSphere eXtreme Scale's ogclient.jar call ORB.string_to_object() on an attac…

CVSS 6.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-13772

Published Jun 30, 2026

IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 's Object Query Language engine resolves attacker-supplied class names via Class.forName() and invokes their constructors with…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-13759

Published Jun 30, 2026

IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 ships three ObjectInputStream subclasses (WsObjectInputStream, ObjectStreamPool$ReusableInputStream, ObjectInputStreamResolver)…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-4336

Published Jan 6, 2021

IBM WebSphere eXtreme Scale 8.6.1 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via serve…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-4115

Published Sep 30, 2019

IBM WebSphere eXtreme Scale 8.6 Admin API is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-4112

Published Sep 30, 2019

IBM WebSphere eXtreme Scale 8.6 Admin Console allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 158105.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2019-4109

Published Sep 30, 2019

IBM WebSphere eXtreme Scale 8.6 Admin Console could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a re…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-4106

Published Sep 30, 2019

IBM WebSphere eXtreme Scale 8.6 Admin Console is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-7418

Published Feb 8, 2017

IBM WebSphere eXtreme Scale and the WebSphere DataPower XC10 Appliance allow some sensitive data to linger in memory instead of being overwritten which could allow a local user wi…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-2861

Published Jul 2, 2016

IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3, 7.1.1 before 7.1.1.1, 8.5 before 8.5.0.3, and 8.6 before 8.6.0.8 does not properly encrypt data, which makes it easier for remote…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2016-0400

Published Jul 2, 2016

CRLF injection vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3, 7.1.1 before 7.1.1.1, 8.5 before 8.5.0.3, and 8.6 before 8.6.0.8 allows remote attackers to injec…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-2031

Published Oct 4, 2015

Cross-site scripting (XSS) vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 allows remote authenticated users to inject arbitrary web scr…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2015-2030

Published Oct 4, 2015

IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 has an improper account-lockout setting, which makes it easier for remote attackers to obtain access via…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-2029

Published Oct 4, 2015

Session fixation vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 allows remote attackers to hijack web sessions via a session identifier.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-2028

Published Oct 4, 2015

CRLF injection vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-2027

Published Oct 4, 2015

IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 improperly performs logout actions, which allows remote attackers to bypass intended access restrictions…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2015-2026

Published Oct 4, 2015

Cross-site request forgery (CSRF) vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 allows remote authenticated users to hijack the authen…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-2025

Published Oct 4, 2015

IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 does not set the secure flag for the session cookie in an https session, which makes it easier for remote…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-4936

Published Aug 3, 2015

Unspecified vulnerability in IBM WebSphere eXtreme Scale 8.6 through 8.6.0.8 allows remote attackers to cause a denial of service via unknown vectors.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-5394

Published Oct 16, 2013

The monitoring console in IBM WebSphere eXtreme Scale 7.1.0, 7.1.1, 8.5.0, and 8.6.0 allows remote authenticated users to conduct phishing attacks via unspecified vectors.

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-5393

Published Oct 16, 2013

The monitoring console in IBM WebSphere eXtreme Scale 7.1.0, 7.1.1, 8.5.0, and 8.6.0 does not properly process logoff actions, which has unspecified impact and remote attack vecto…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-5390

Published Oct 16, 2013

Cross-site scripting (XSS) vulnerability in the monitoring console in IBM WebSphere eXtreme Scale 7.1.0, 7.1.1, 8.5.0, and 8.6.0 allows remote authenticated users to inject arbitr…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort
Showing 1-23 of 23 CVEsPage 1 of 1