CVE-2014-0859: IBM WebSphere Application Server

Medium severity, CVSS 5.0. EPSS: 2.6% chance of exploitation in the next 30 days.

The web-server plugin in IBM WebSphere Application Server (WAS) 7.x before 7.0.0.33, 8.x before 8.0.0.9, and 8.5.x before 8.5.5.2, when POST retries are enabled, allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors.

Affected products

  • IBM WebSphere Application Server: version 8.0.0.0 only; version 8.0.0.1 only; version 8.0.0.2 only; version 8.0.0.3 only; version 8.0.0.4 only; version 8.0.0.5 only; …

Published 2014-05-01. Last modified 2026-06-17.