Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
CVE-LINKED INVENTORY175 SECURITY RECORDS

IBM Corporation

WebSphere Application Server

Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.

Lifecycle evidence status

This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.

A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.

CVE-observed version history

CVEPublishedAffected versionsFixed version informationPublisher evidence
CVE-2026-9330 1 Jun 2026 9.0 ≤ 1.1.9.12; 8.5 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-9319 1 Jun 2026 9.0 ≤ 1.1.9.12; 8.5 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-9311 1 Jun 2026 9.0 ≤ 1.1.9.12; 8.5 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-8644 1 Jun 2026 9.0 ≤ 1.1.9.12; 8.5 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-13333 17 Feb 2026 9.0 ≤ 9.0.5.27; 8.5 ≤ 8.5.5.29 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-12635 8 Dec 2025 WebSphere Application Server: 9.0 ≤ 2.0.18, 8.5; WebSphere Application Server Liberty: 17.0.0.3 ≤ 25.0.0.12 Remediation/Fixes IBM strongly recommends addressing the vulnerability now by applying a currently available interim fix or fix pack that contains the fix for APAR PH68817 and PH68243. To determine if a feature is enabled for WebSphere Application Server Liberty, refer to How to determine if Liberty is using a specific feature . For IBM WebSphere Application Server Liberty 17.0.0.3 - 25.0.0.12 using the servlet-3.0, servlet-3.1, servlet-4.0, servlet-5.0, or servlet-6.0 feature: · Upgrade to minimal fix pack levels as required by the interim fix and then apply the Interim Fix that resolves PH68817 --OR-- · Apply Fix Pack 26.0.0.1 or later (targeted availability 1Q2026). For IBM WebSphere Application Server traditional: For V9.0.0.0 through 9.0.5.26: · Upgrade to minimal fix pack levels as required by the interim fix and then apply the Interim Fix that resolves PH68243 --OR-- · Apply Fix Pack 9.0.5.27 or later (targeted availability 1Q2026). For V8.5.0.0 through 8.5.5.28: · Upgrade to minimal fix pack levels as required by interim fix and then apply Interim Fix that resolves PH68243 --OR-- · Apply Fix Pack 8.5.5.29 or later (targeted availability 1Q2026). Additional interim fixes may be available and linked off the interim fix download page. Update reference ↗
CVE-2025-36099 29 Sep 2025 8.5; 9.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-33142 14 Aug 2025 8.5; 9.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-56339 7 Aug 2025 9.0; 17.0.0.3 ≤ 25.0.0.7 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-36097 16 Jul 2025 9.0; 17.0.0.3 ≤ 25.0.0.7 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-36038 25 Jun 2025 8.5; 9.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-33104 14 May 2025 8.5, 9.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-27907 22 Apr 2025 8.5; 9.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-45087 11 Nov 2024 8.5, 9.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-45086 4 Nov 2024 8.5, 9.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-45071 16 Oct 2024 8.5, 9.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-45072 16 Oct 2024 8.5, 9.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-45085 15 Oct 2024 8.5 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-45073 30 Sep 2024 8.5, 9.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2023-50315 14 Aug 2024 8.5, 9.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-35154 9 Jul 2024 8.5, 9.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-35153 27 Jun 2024 8.5, 9.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-37532 20 Jun 2024 8.5, 9.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-25026 25 Apr 2024 8.5, 9.0; 17.0.0.3 ≤ 24.0.0.4 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-22329 17 Apr 2024 8.5, 9.0; 17.0.0.3 ≤ 24.0.0.3 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-22354 17 Apr 2024 8.5, 9.0; 17.0.0.3 ≤ 24.0.0.5; cpe:2.3:a:ibm:websphere_application_server:17.0.0.3:*:*:*:liberty:*:*:*; cpe:2.3:a:ibm:websphere_application_server:24.0.0.5:*:*:*:liberty:*:*:* No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2023-50313 2 Apr 2024 8.5, 9.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2023-35890 7 Jul 2023 8.5, 9.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2023-27554 11 May 2023 8.5, 9.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2022-39161 3 May 2023 7.0, 8.0, 8.5, 9.0, Liberty No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2023-24966 27 Apr 2023 8.5, 9.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2023-26283 22 Mar 2023 9.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2023-23477 3 Feb 2023 8.5, 9.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2022-43917 25 Jan 2023 8.5, 9.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2022-40750 11 Nov 2022 8.5, 9.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2022-35282 28 Sep 2022 7.0; 8.0; 8.5; 9.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2022-34336 13 Sep 2022 7.0; 8.0; 8.5; 9.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2022-34165 9 Sep 2022 7.0; 8.0; 8.5; 9.0; 17.0.0.3; 22.0.0.9 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2022-22477 14 Jul 2022 8.5; 9.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2022-22473 14 Jul 2022 7.0; 8.0; 8.5; 9.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2022-22365 20 May 2022 7.0; 8.0; 8.5; 9.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2021-38951 9 Dec 2021 7.0; 8.0; 8.5; 9.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2021-29842 16 Sep 2021 7.0; 8.0; 8.5; 9.0; 17.0.0.3; 21.0.0.9 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2021-29736 30 Jul 2021 7.0; 8.0; 8.5; 9.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2021-29754 11 Jun 2021 7.0; 8.0; 8.5; 9.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2021-20492 26 May 2021 8.0; 8.5; 9.0; Liberty An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2021-20454 21 Apr 2021 7.0; 8.0; 8.5; 9.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2021-20453 20 Apr 2021 8.0; 8.5; 9.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2021-20480 8 Apr 2021 7.0; 8.0; 8.5 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2020-5016 10 Mar 2021 7.0; 8.0; 8.5; 9.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗

How this record is maintained

The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.