Vulnerabilities
Vulnerable Software
Security Vulnerabilities
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service due to uncontrolled heap allocation.
CVSS Score
7.5
EPSS Score
0.003
Published
2026-07-28
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to HTTP Response Smuggling due to improper handling of non-standard HTTP version tokens.
CVSS Score
8.7
EPSS Score
0.002
Published
2026-07-28
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 ND Collective Controller is affected by a path-segment injection vulnerability in the collective routing mechanism.
CVSS Score
7.5
EPSS Score
0.003
Published
2026-07-28
IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTTP request smuggling due to improper handling of TRACE requests.
CVSS Score
8.7
EPSS Score
0.002
Published
2026-07-28
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to HTTP request smuggling.
CVSS Score
7.4
EPSS Score
0.002
Published
2026-07-28
IBM WebSphere Application Server 9.0, and 8.5 traditional could allow a remote attacker to obtain sensitive information.
CVSS Score
7.4
EPSS Score
0.003
Published
2026-07-28
IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to unquoted shell interpolation.
CVSS Score
9.1
EPSS Score
0.005
Published
2026-07-28
IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to shell command injection.
CVSS Score
9.1
EPSS Score
0.01
Published
2026-07-28
IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination.
CVSS Score
9.3
EPSS Score
0.005
Published
2026-07-28
IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of untrusted data.
CVSS Score
8.1
EPSS Score
0.004
Published
2026-07-28


Contact Us

Shodan ® - All rights reserved