ibm CVE Vulnerabilities & Metrics

Focus on ibm vulnerabilities and metrics.

Last updated: 08 May 2026, 22:25 UTC

About ibm Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with ibm. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total ibm CVEs: 5340
Earliest CVE date: 01 Mar 1992, 05:00 UTC
Latest CVE date: 30 Apr 2026, 22:16 UTC

Latest CVE reference: CVE-2026-2311

Rolling Stats

30-day Count (Rolling): 11
365-day Count (Rolling): 465

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): -85.71%
Year Variation (Calendar): -9.71%

Month Growth Rate (30-day Rolling): -85.71%
Year Growth Rate (365-day Rolling): -9.71%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical ibm CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 3.96

Max CVSS: 10.0

Critical CVEs (≥9): 460

CVSS Range vs. Count

Range Count
0.0-3.9 3353
4.0-6.9 3489
7.0-8.9 658
9.0-10.0 460

CVSS Distribution Chart

Top 5 Highest CVSS ibm CVEs

These are the five CVEs with the highest CVSS scores for ibm, sorted by severity first and recency.

All CVEs for ibm

CVE-2026-2311 ibm vulnerability CVSS: 0 30 Apr 2026, 22:16 UTC

IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 s vulnerable to privilege escalation caused by an invalid IBM i Web Administration GUI authorization check.  A malicious actor could cause user-controlled code to run with administrator privilege.

CVE-2026-1577 ibm vulnerability CVSS: 0 30 Apr 2026, 22:16 UTC

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic.

CVE-2025-36122 ibm vulnerability CVSS: 0 30 Apr 2026, 22:16 UTC

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user to cause a denial of service using a specially crafted SQL query due to improper allocation of system resources.

CVE-2025-14688 ibm vulnerability CVSS: 0 30 Apr 2026, 22:16 UTC

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic when certain configurations exist.

CVE-2026-4919 ibm vulnerability CVSS: 0 23 Apr 2026, 00:16 UTC

IBM Guardium Data Protection 12.1 is vulnerable to cross-site scripting. This vulnerability allows an administrative user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVE-2026-4918 ibm vulnerability CVSS: 0 23 Apr 2026, 00:16 UTC

IBM Guardium Data Protection 12.1 is vulnerable to stored cross-site scripting. This vulnerability allows an administrative user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVE-2026-4917 ibm vulnerability CVSS: 0 23 Apr 2026, 00:16 UTC

IBM Guardium Data Protection 12.1 could allow an administrative user to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to write arbitrary files on the system.

CVE-2026-1726 ibm vulnerability CVSS: 0 23 Apr 2026, 00:16 UTC

IBM Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2, 4.2.1, 5.0, and 5.1

CVE-2026-1352 ibm vulnerability CVSS: 0 23 Apr 2026, 00:16 UTC

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic.

CVE-2026-1274 ibm vulnerability CVSS: 0 23 Apr 2026, 00:16 UTC

IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a Bypass Business Logic vulnerability in the access management control panel.

CVE-2026-1272 ibm vulnerability CVSS: 0 23 Apr 2026, 00:16 UTC

IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to Security Misconfiguration vulnerability in the user access control panel.

CVE-2026-4788 ibm vulnerability CVSS: 0 08 Apr 2026, 01:16 UTC

IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.37 stores sensitive information in log files that could be read by a local user.

CVE-2026-1346 ibm vulnerability CVSS: 0 08 Apr 2026, 01:16 UTC

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 could allow a locally authenticated user to escalate their privileges to root due to execution with unnecessary privileges than required.

CVE-2026-1343 ibm vulnerability CVSS: 0 08 Apr 2026, 01:16 UTC

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 allows an attacker to contact internal authentication endpoints which are protected by the Reverse Proxy.

CVE-2026-1342 ibm vulnerability CVSS: 0 08 Apr 2026, 00:16 UTC

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 could allow a locally authenticated user to execute malicious scripts from outside of its control sphere.

CVE-2025-13044 ibm vulnerability CVSS: 0 07 Apr 2026, 02:16 UTC

IBM Concert 1.0.0 through 2.2.0 creates temporary files with predictable names, which allows local users to overwrite arbitrary files via a symlink attack.

CVE-2026-1243 ibm vulnerability CVSS: 0 02 Apr 2026, 01:16 UTC

IBM Content Navigator 3.0.15, 3.1.0, and 3.2.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVE-2025-66487 ibm vulnerability CVSS: 0 01 Apr 2026, 23:17 UTC

IBM Aspera Shares 1.9.9 through 1.11.0 does not properly rate limit the frequency that an authenticated user can send emails, which could result in email flooding or a denial of service.

CVE-2025-66486 ibm vulnerability CVSS: 0 01 Apr 2026, 23:17 UTC

IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.

CVE-2025-66485 ibm vulnerability CVSS: 0 01 Apr 2026, 23:17 UTC

IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers.  This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking.

CVE-2025-66484 ibm vulnerability CVSS: 0 01 Apr 2026, 23:17 UTC

IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVE-2025-66483 ibm vulnerability CVSS: 0 01 Apr 2026, 23:17 UTC

IBM Aspera Shares 1.9.9 through 1.11.0 does not invalidate session after a password reset which could allow an authenticated user to impersonate another user on the system.

CVE-2025-36375 ibm vulnerability CVSS: 0 01 Apr 2026, 23:17 UTC

IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and IBM DataPower Gateway 10.6.0 10.6.0.0 through 10.6.0.8 IBM DataPower Gateway is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

CVE-2026-4820 ibm vulnerability CVSS: 0 01 Apr 2026, 21:17 UTC

IBM Maximo Application Suite 9.1, 9.0, 8.11, and 8.10 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic.

CVE-2026-4364 ibm vulnerability CVSS: 0 01 Apr 2026, 21:17 UTC

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 allows certificate listings retrieved via a browser session to return a JSON payload while incorrectly specifying the response Content-Type as text/html. Because the content is delivered with an HTML MIME type, browsers may interpret the JSON data as executable script under certain conditions. This creates an opportunity for JavaScript injection, potentially leading to cross-site scripting (XSS).

CVE-2026-4101 ibm vulnerability CVSS: 0 01 Apr 2026, 21:17 UTC

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 under certain load conditions could allow an attacker to bypass authentication mechanisms and gain unauthorized access to the application.

CVE-2026-2862 ibm vulnerability CVSS: 0 01 Apr 2026, 21:16 UTC

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 IBM Security Verify could allow a remote attacker to access sensitive information due to an inconsistent interpretation of an HTTP request by a reverse proxy.

CVE-2026-2475 ibm vulnerability CVSS: 0 01 Apr 2026, 21:16 UTC

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 could allow a remote attacker to conduct phishing attacks, caused by an open redirect vulnerability. An attacker could exploit this vulnerability using a specially crafted request to redirect a victim to arbitrary Web sites.

CVE-2026-1491 ibm vulnerability CVSS: 0 01 Apr 2026, 21:16 UTC

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 IBM Security Verify could allow a remote attacker to access sensitive information due to an inconsistent interpretation of an HTTP request by a reverse proxy.

CVE-2026-1345 ibm vulnerability CVSS: 0 01 Apr 2026, 21:16 UTC

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 could allow an unauthenticated user to execute arbitrary commands as lower user privileges on the system due to improper validation of user supplied input.

CVE-2025-36373 ibm vulnerability CVSS: 0 01 Apr 2026, 21:16 UTC

IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and IBM DataPower Gateway 10.6.0 10.6.0.0 through 10.6.0.8 IBM DataPower Gateway could disclose sensitive system information from other domains to an administrative user.

CVE-2025-13916 ibm vulnerability CVSS: 0 01 Apr 2026, 21:16 UTC

IBM Aspera Shares 1.9.9 through 1.11.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information

CVE-2025-13855 ibm vulnerability CVSS: 0 01 Apr 2026, 01:16 UTC

IBM Storage Protect Server 8.2.0 IBM Storage Protect Plus Server is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

CVE-2025-36187 ibm vulnerability CVSS: 0 25 Mar 2026, 22:16 UTC

IBM Knowledge Catalog Standard Cartridge 5.0.0, 5.0.1, 5.0.2, 5.0.3, 5.1, 5.1.1, 5,1.2, 5.1.3, 5.2.0, 5.2.1 stores potentially sensitive information in log files that could be read by a local privileged user.

CVE-2025-14684 ibm vulnerability CVSS: 0 25 Mar 2026, 22:16 UTC

IBM Maximo Application Suite - Monitor Component 9.1, 9.0, 8.11, and 8.10 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.

CVE-2026-2485 ibm vulnerability CVSS: 0 25 Mar 2026, 21:16 UTC

IBM Infosphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVE-2026-2484 ibm vulnerability CVSS: 0 25 Mar 2026, 21:16 UTC

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is affected by an information exposure vulnerability caused by overly verbose error messages

CVE-2026-2483 ibm vulnerability CVSS: 0 25 Mar 2026, 21:16 UTC

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session

CVE-2026-1561 ibm vulnerability CVSS: 0 25 Mar 2026, 21:16 UTC

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty is vulnerable to server-side request forgery (SSRF). This may allow remote attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

CVE-2026-1262 ibm vulnerability CVSS: 0 25 Mar 2026, 21:16 UTC

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is affected by an information disclosure vulnerability.

CVE-2026-1015 ibm vulnerability CVSS: 0 25 Mar 2026, 21:16 UTC

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

CVE-2026-1014 ibm vulnerability CVSS: 0 25 Mar 2026, 21:16 UTC

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to exposure of sensitive information via JSON server response manipulation.

CVE-2025-64648 ibm vulnerability CVSS: 0 25 Mar 2026, 21:16 UTC

IBM Concert 1.0.0 through 2.2.0 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.

CVE-2025-64647 ibm vulnerability CVSS: 0 25 Mar 2026, 21:16 UTC

IBM Concert 1.0.0 through 2.2.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information

CVE-2025-64646 ibm vulnerability CVSS: 0 25 Mar 2026, 21:16 UTC

IBM Concert 1.0.0 through 2.2.0 could allow an attacker to access sensitive information in memory due to the buffer not properly clearing resources.

CVE-2025-36440 ibm vulnerability CVSS: 0 25 Mar 2026, 21:16 UTC

IBM Concert 1.0.0 through 2.2.0 could allow a local user to obtain sensitive information due to missing function level access control.

CVE-2025-36438 ibm vulnerability CVSS: 0 25 Mar 2026, 21:16 UTC

IBM Concert 1.0.0 through 2.2.0 could allow a privileged user to perform unauthorized actions due to improper restriction of channel communication to intended endpoints.

CVE-2025-36422 ibm vulnerability CVSS: 0 25 Mar 2026, 21:16 UTC

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 IBM InfoSphere DataStage Flow Designer is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

CVE-2025-36258 ibm vulnerability CVSS: 0 25 Mar 2026, 21:16 UTC

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 product stores user credentials and other sensitive information in plain text which can be read by a local user.

CVE-2025-14974 ibm vulnerability CVSS: 0 25 Mar 2026, 21:16 UTC

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable due to Insecure Direct Object Reference (IDOR).

CVE-2025-14917 ibm vulnerability CVSS: 0 25 Mar 2026, 21:16 UTC

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty could provide weaker than expected security when administering security settings.

CVE-2025-14915 ibm vulnerability CVSS: 0 25 Mar 2026, 21:16 UTC

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty is affected by privilege escalation. A privileged user could gain additional access to the application server.

CVE-2025-14912 ibm vulnerability CVSS: 0 25 Mar 2026, 21:16 UTC

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

CVE-2025-14810 ibm vulnerability CVSS: 0 25 Mar 2026, 21:16 UTC

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 does not invalidate a session after privileges have been modified which could allow an authenticated user to retain access to sensitive information. CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L CWE: CWE-613: Insufficient Session Expiration CVSS Source: IBM CVSS Base score: 6.3 CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L)

CVE-2025-14808 ibm vulnerability CVSS: 0 25 Mar 2026, 21:16 UTC

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an attacker to obtain sensitive information from the query string of an HTTP GET method to process a request which could be obtained using man in the middle techniques.

CVE-2025-14807 ibm vulnerability CVSS: 0 25 Mar 2026, 21:16 UTC

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking.

CVE-2025-14790 ibm vulnerability CVSS: 0 25 Mar 2026, 20:16 UTC

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an attacker to obtain sensitive information due to insufficiently protected credentials.

CVE-2025-12708 ibm vulnerability CVSS: 0 25 Mar 2026, 20:16 UTC

IBM Concert 1.0.0 through 2.2.0 contains hard-coded credentials that could be obtained by a local user.

CVE-2026-1276 ibm vulnerability CVSS: 0 19 Mar 2026, 03:16 UTC

IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVE-2025-36051 ibm vulnerability CVSS: 0 19 Mar 2026, 03:16 UTC

IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 stores potentially sensitive information in configuration files that could be read by a local user.

CVE-2025-15051 ibm vulnerability CVSS: 0 19 Mar 2026, 03:16 UTC

IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality.

CVE-2025-13995 ibm vulnerability CVSS: 0 19 Mar 2026, 03:16 UTC

IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 could allow an attacker with access to one tenant to access hostname data from another tenant's account.

CVE-2026-3856 ibm vulnerability CVSS: 0 17 Mar 2026, 23:16 UTC

IBM Db2 Recovery Expert for Linux, UNIX and Windows 5.5 IF 2 could allow an attacker to modify or corrupt data due to an insecure mechanism used for verifying the integrity of the data during transmission.

CVE-2026-1264 ibm vulnerability CVSS: 0 17 Mar 2026, 23:16 UTC

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.0 allows a remote unauthenticated attacker to view and delete the partners of a community and to delete the communities.

CVE-2025-14031 ibm vulnerability CVSS: 0 17 Mar 2026, 23:16 UTC

IBM Sterling B2B Integrator and and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.0 could allow an unauthenticated attacker to send a specially crafted request that causes the application to crash.

CVE-2026-1376 ibm vulnerability CVSS: 0 17 Mar 2026, 22:16 UTC

IBM i 7.6 could allow a remote attacker to cause a denial of service using failed authentication connections due to improper allocation of resources.

CVE-2026-1267 ibm vulnerability CVSS: 0 17 Mar 2026, 22:16 UTC

IBM Planning Analytics Local 2.1.0 through 2.1.17 could allow an unauthorized access to sensitive application data and administrative functionalities due to lack of proper access controls.

CVE-2025-14806 ibm vulnerability CVSS: 0 17 Mar 2026, 22:16 UTC

IBM Planning Analytics Local 2.1.0 through 2.1.17 could allow an attacker to trick the caching mechanism into storing and serving sensitive, user-specific responses as publicly cacheable resources.

CVE-2026-0977 ibm vulnerability CVSS: 0 16 Mar 2026, 14:18 UTC

IBM CICS Transaction Gateway for Multiplatforms 9.3 and 10.1 could allow a user to transfer or view files due to improper access controls.

CVE-2025-13460 ibm vulnerability CVSS: 0 16 Mar 2026, 14:17 UTC

IBM Aspera Console 3.3.0 through 3.4.8 could allow an attacker to enumerate usernames due to an observable response discrepancy.

CVE-2025-13459 ibm vulnerability CVSS: 0 16 Mar 2026, 14:17 UTC

IBM Aspera Console 3.3.0 through 3.4.8 could allow a privileged user to cause a denial of service due to improper enforcement of behavioral workflow.

CVE-2025-13212 ibm vulnerability CVSS: 0 16 Mar 2026, 14:17 UTC

IBM Aspera Console 3.3.0 through 3.4.8 could allow an authenticated user to cause a denial of service in the email service due to improper control of interaction frequency.

CVE-2026-0835 ibm vulnerability CVSS: 0 13 Mar 2026, 19:53 UTC

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.0 are vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVE-2025-36368 ibm vulnerability CVSS: 0 13 Mar 2026, 19:53 UTC

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, and 6.2.1.0 through 6.2.1.1_1 are vulnerable to SQL injection. An administrative user could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

CVE-2025-14811 ibm vulnerability CVSS: 0 13 Mar 2026, 19:53 UTC

IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow an attacker to obtain sensitive information from the query string of an HTTP GET method to process a request which could be obtained using man in the middle techniques.

CVE-2025-14504 ibm vulnerability CVSS: 0 13 Mar 2026, 19:53 UTC

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVE-2025-14483 ibm vulnerability CVSS: 0 13 Mar 2026, 19:53 UTC

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.0 could disclose sensitive host information to authenticated users in responses that could be used in further attacks against the system.

CVE-2025-13726 ibm vulnerability CVSS: 0 13 Mar 2026, 19:53 UTC

IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow a remote attacker to obtain sensitive information when detailed technical error messages are returned. This information could be used in further attacks against the system.

CVE-2025-13723 ibm vulnerability CVSS: 0 13 Mar 2026, 19:53 UTC

IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow an attacker to obtain sensitive user information using an expired access token

CVE-2025-13718 ibm vulnerability CVSS: 0 13 Mar 2026, 19:53 UTC

IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow a remote attacker to obtain sensitive information in cleartext in a communication channel that can be sniffed by unauthorized actors.

CVE-2025-13702 ibm vulnerability CVSS: 0 13 Mar 2026, 19:53 UTC

IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVE-2023-40693 ibm vulnerability CVSS: 0 13 Mar 2026, 19:53 UTC

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, and 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVE-2025-13213 ibm vulnerability CVSS: 0 10 Mar 2026, 21:16 UTC

IBM Aspera Orchestrator 3.0.0 through 4.1.2 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking

CVE-2026-2713 ibm vulnerability CVSS: 0 10 Mar 2026, 20:16 UTC

IBM Trusteer Rapport installer 3.5.2309.290 IBM Trusteer Rapport could allow a local attacker to execute arbitrary code on the system, caused by DLL uncontrolled search path element vulnerability. By placing a specially crafted file in a compromised folder, an attacker could exploit this vulnerability to execute arbitrary code on the system.

CVE-2025-36227 ibm vulnerability CVSS: 0 10 Mar 2026, 20:16 UTC

IBM Aspera Faspex 5 5.0.0 through 5.0.14.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers.  This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking.

CVE-2025-36226 ibm vulnerability CVSS: 0 10 Mar 2026, 20:16 UTC

IBM Aspera Faspex 5 5.0.0 through 5.0.14.3 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVE-2025-13219 ibm vulnerability CVSS: 0 10 Mar 2026, 20:16 UTC

IBM Aspera Orchestrator 3.0.0 through 4.1.2 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history.

CVE-2025-36173 ibm vulnerability CVSS: 0 10 Mar 2026, 16:50 UTC

Affected Product(s)Version(s)InfoSphere Data Architect9.2.1

CVE-2026-1713 ibm vulnerability CVSS: 0 03 Mar 2026, 21:15 UTC

IBM MQ 9.1.0.0 through 9.1.0.33 LTS, 9.2.0.0 through 9.2.0.40 LTS, 9.3.0.0 through 9.3.0.36 LTS, 9.30.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.17 LTS, and 9.4.0.0 through 9.4.4.1 CD

CVE-2026-1567 ibm vulnerability CVSS: 0 03 Mar 2026, 21:15 UTC

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 An XML External Entity (XXE) vulnerability in IBM InfoSphere Information Server could allow attackers to retrieve sensitive information from the server.

CVE-2025-14480 ibm vulnerability CVSS: 0 03 Mar 2026, 21:15 UTC

IBM Aspera faspio Gateway 1.3.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information

CVE-2026-2606 ibm vulnerability CVSS: 0 03 Mar 2026, 20:16 UTC

IBM webMethods API Gateway (on-prem) 10.11 through 10.11_Fix3210.15 to 10.15_Fix2711.1 to 11.1_Fix7 IBM webMethods API Management (on-prem) fails to properly validate user-supplied input passed to the url parameter on the /createapi endpoint. An attacker can modify this parameter to use a file:// URI schema instead of the expected https:// schema, enabling unauthorized arbitrary file read access on the underlying server file system.

CVE-2026-1265 ibm vulnerability CVSS: 0 03 Mar 2026, 20:16 UTC

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to writing of sensitive Information in a log file.

CVE-2025-14923 ibm vulnerability CVSS: 0 03 Mar 2026, 20:16 UTC

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.2 IBM WebSphere Application Server Liberty could provide weaker than expected security when using the Security Utility when administering security settings.

CVE-2025-14604 ibm vulnerability CVSS: 0 03 Mar 2026, 20:16 UTC

IBM Storage Scale IBM S through rage Scale 5.2.3.0 - 5.2.3.5, and IBM S through rage Scale 6.0.0.0 - 6.0.0.1 could allow a local user to unintentionally trigger additional permissions for resources in a way that allows that resource to be executed by unintended actors.

CVE-2025-13734 ibm vulnerability CVSS: 0 03 Mar 2026, 20:16 UTC

IBM Engineering Requirements Management DOORS Next 7.1, and 7.2 could allow an authenticated user to view and edit data beyond their authorized access permissions.

CVE-2025-13490 ibm vulnerability CVSS: 0 03 Mar 2026, 20:16 UTC

IBM App Connect Operator versions CD 11.3.0 through 11.6.0 and 12.1.0 through 12.20.0, LTS versions 12.0.0 through 12.0.20, and IBM App Connect Enterprise Certified Containers Operands versions CD 12.0.11.2‑r1 through 12.0.12.5‑r1 and 13.0.1.0‑r1 through 13.0.6.1‑r1, and LTS versions 12.0.12‑r1 through 12.0.12‑r20, contain a vulnerability in which the IBM App Connect Enterprise Certified Container transmits data in clear text, potentially allowing an attacker to intercept and obtain sensitive information through man‑in‑the‑middle techniques.

CVE-2025-13333 ibm vulnerability CVSS: 0 17 Feb 2026, 23:16 UTC

IBM WebSphere Application Server 9.0, and 8.5 could provide weaker than expected security during system administration of security settings.

CVE-2025-36348 ibm vulnerability CVSS: 0 17 Feb 2026, 22:18 UTC

IBM Sterling B2B Integrator versions 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 through 6.2.1.1, and IBM Sterling File Gateway versions 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 through 6.2.1.1 may expose sensitive information to a remote privileged attacker due to the application returning detailed technical error messages in the browser.

CVE-2025-36183 ibm vulnerability CVSS: 0 17 Feb 2026, 22:18 UTC

IBM watsonx.data 2.2 through 2.2.1 IBM Lakehouse could allow a privileged user to upload malicious files that could be executed server to modify limited files or data.

CVE-2025-33088 ibm vulnerability CVSS: 0 17 Feb 2026, 22:18 UTC

IBM Concert 1.0.0 through 2.1.0 could allow a local user with specific knowledge about the system's architecture to escalate their privileges due to incorrect file permissions for critical resources.

CVE-2023-38005 ibm vulnerability CVSS: 0 17 Feb 2026, 22:18 UTC

IBM Cloud Pak System 2.3.3.6, 2.3.3.7, 2.3.4.0, 2.3.4.1, and 2.3.5.0 could allow an authenticated user to perform unauthorized tasks due to improper access controls.

CVE-2025-36376 ibm vulnerability CVSS: 0 17 Feb 2026, 21:22 UTC

IBM Security QRadar EDR 3.12 through 3.12.23 does not invalidate session after a session expiration which could allow an authenticated user to impersonate another user on the system.

CVE-2025-14289 ibm vulnerability CVSS: 0 17 Feb 2026, 21:22 UTC

IBM webMethods Integration Server 12.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.

CVE-2025-36243 ibm vulnerability CVSS: 0 17 Feb 2026, 20:22 UTC

IBM Concert 1.0.0 through 2.1.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

CVE-2025-33130 ibm vulnerability CVSS: 0 17 Feb 2026, 20:22 UTC

IBM DB2 Merge Backup for Linux, UNIX and Windows 12.1.0.0 could allow an authenticated user to cause the program to crash due to a buffer being overwritten when it is allocated on the stack.

CVE-2025-33124 ibm vulnerability CVSS: 0 17 Feb 2026, 20:22 UTC

IBM DB2 Merge Backup for Linux, UNIX and Windows 12.1.0.0 could allow an authenticated user to cause the program to crash due to the incorrect calculation of a buffer size.

CVE-2025-33101 ibm vulnerability CVSS: 0 17 Feb 2026, 20:22 UTC

IBM Concert 1.0.0 through 2.1.0 could allow an attacker to obtain sensitive information using man in the middle techniques due to improper clearing of heap memory.

CVE-2025-33089 ibm vulnerability CVSS: 0 17 Feb 2026, 20:22 UTC

IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information or perform unauthorized actions due to the use of hard coded user credentials.

CVE-2025-27904 ibm vulnerability CVSS: 0 17 Feb 2026, 20:22 UTC

IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 IBM Db2 Recovery Expert for Linux, UNIX and Windows is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

CVE-2025-27903 ibm vulnerability CVSS: 0 17 Feb 2026, 20:22 UTC

IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 IBM Db2 Recovery Expert for Linux, UNIX and Windows transmits data in a cleartext communication channel that could allow an attacker to obtain sensitive information using man in the middle techniques.

CVE-2025-27901 ibm vulnerability CVSS: 0 17 Feb 2026, 20:22 UTC

IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 IBM Db2 Recovery Expert for Linux, UNIX and Windows is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers.  This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking.

CVE-2025-27900 ibm vulnerability CVSS: 0 17 Feb 2026, 20:22 UTC

IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.

CVE-2025-27899 ibm vulnerability CVSS: 0 17 Feb 2026, 20:22 UTC

IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 discloses sensitive information in an environment variable that could aid in further attacks against the system.

CVE-2025-27898 ibm vulnerability CVSS: 0 17 Feb 2026, 20:22 UTC

IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 does not invalidate session after a timeout which could allow an authenticated user to impersonate another user on the system.

CVE-2025-13108 ibm vulnerability CVSS: 0 17 Feb 2026, 20:22 UTC

IBM DB2 Merge Backup for Linux, UNIX and Windows 12.1.0.0 could allow an attacker to access sensitive information in memory due to the buffer not properly clearing resources.

CVE-2023-38265 ibm vulnerability CVSS: 0 17 Feb 2026, 20:22 UTC

IBM Cloud Pak System 2.3.3.6, 2.3.3.7, 2.3.4.0, 2.3.4.1, and 2.3.5.0 could disclose folder location information to an unauthenticated attacker that could aid in further attacks against the system.

CVE-2025-36019 ibm vulnerability CVSS: 0 17 Feb 2026, 19:21 UTC

IBM Concert 1.0.0 through 2.1.0 for Z hub framework is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVE-2025-36018 ibm vulnerability CVSS: 0 17 Feb 2026, 19:21 UTC

IBM Concert 1.0.0 through 2.1.0 for Z hub component is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

CVE-2024-43178 ibm vulnerability CVSS: 0 17 Feb 2026, 19:21 UTC

IBM Concert 1.0.0 through 2.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

CVE-2025-36425 ibm vulnerability CVSS: 0 17 Feb 2026, 18:20 UTC

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 could allow an authenticated user to obtain sensitive information under specific HADR configuration.

CVE-2025-36247 ibm vulnerability CVSS: 0 17 Feb 2026, 18:20 UTC

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.

CVE-2025-14689 ibm vulnerability CVSS: 0 17 Feb 2026, 18:20 UTC

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 12.1.0 through 12.1.3 could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic with federated objects.

CVE-2025-13867 ibm vulnerability CVSS: 0 17 Feb 2026, 18:20 UTC

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic

CVE-2025-13379 ibm vulnerability CVSS: 0 05 Feb 2026, 14:16 UTC

IBM Aspera Console 3.4.0 through 3.4.8 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

CVE-2024-51451 ibm vulnerability CVSS: 0 04 Feb 2026, 22:15 UTC

IBM Concert 1.0.0 through 2.1.0 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking.

CVE-2024-43181 ibm vulnerability CVSS: 0 04 Feb 2026, 22:15 UTC

IBM Concert 1.0.0 through 2.1.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.

CVE-2025-2134 ibm vulnerability CVSS: 0 04 Feb 2026, 21:15 UTC

IBM Jazz Reporting Service could allow an authenticated user on the network to affect the system's performance using complicated queries due to insufficient resource pooling.

CVE-2025-27550 ibm vulnerability CVSS: 0 04 Feb 2026, 21:15 UTC

IBM Jazz Reporting Service could allow an authenticated user on the host network to obtain sensitive information about other projects that reside on the server.

CVE-2025-1823 ibm vulnerability CVSS: 0 04 Feb 2026, 21:15 UTC

IBM Jazz Reporting Service could allow an authenticated user on the host network to cause a denial of service using specially crafted SQL query that consumes excess memory resources.

CVE-2023-38281 ibm vulnerability CVSS: 0 04 Feb 2026, 21:15 UTC

IBM Cloud Pak System does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic.

CVE-2023-38017 ibm vulnerability CVSS: 0 04 Feb 2026, 21:15 UTC

IBM Cloud Pak System is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVE-2023-38010 ibm vulnerability CVSS: 0 04 Feb 2026, 21:15 UTC

IBM Cloud Pak System displays sensitive information in user messages that could aid in further attacks against the system.

CVE-2025-36094 ibm vulnerability CVSS: 0 03 Feb 2026, 23:16 UTC

IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 Interim Fix 007 could allow an authenticated user to cause a denial of service or corrupt existing data due to the improper validation of input length.

CVE-2025-36033 ibm vulnerability CVSS: 0 03 Feb 2026, 23:16 UTC

IBM Engineering Lifecycle Management - Global Configuration Management 7.0.3 through 7.0.3 Interim Fix 017, and 7.1.0 through 7.1.0 Interim Fix 004 IBM Global Configuration Management is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVE-2025-33081 ibm vulnerability CVSS: 0 03 Feb 2026, 23:16 UTC

IBM Concert 1.0.0 through 2.1.0 stores potentially sensitive information in log files that could be read by a local user.

CVE-2025-36436 ibm vulnerability CVSS: 0 02 Feb 2026, 23:15 UTC

IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 Interim Fix 007  is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVE-2025-36253 ibm vulnerability CVSS: 0 02 Feb 2026, 23:15 UTC

IBM Concert 1.0.0 through 2.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

CVE-2025-36238 ibm vulnerability CVSS: 0 02 Feb 2026, 23:15 UTC

IBM PowerVM Hypervisor FW1110.00 through FW1110.03, FW1060.00 through FW1060.51, and FW950.00 through FW950.F0 could allow a local user with administration privileges to obtain sensitive information from a Virtual TPM through a series of PowerVM service procedures.

CVE-2025-36194 ibm vulnerability CVSS: 0 02 Feb 2026, 23:15 UTC

IBM PowerVM Hypervisor FW1110.00 through FW1110.03, FW1060.00 through FW1060.51, and FW950.00 through FW950.F0 may expose a limited amount of data to a peer partition in specific shared processor configurations during certain operations.

CVE-2025-13096 ibm vulnerability CVSS: 0 02 Feb 2026, 23:15 UTC

IBM Business Automation Workflow containers V25.0.0 through V25.0.0-IF007, V24.0.1 - V24.0.1-IF007, V24.0.0 - V24.0.0-IF007 and IBM Business Automation Workflow traditional V25.0.0, V24.0.1, V24.0.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.

CVE-2025-15395 ibm vulnerability CVSS: 0 02 Feb 2026, 16:16 UTC

IBM Jazz Foundation 7.0.3 through 7.0.3 iFix019 and 7.1.0 through 7.1.0 iFix005 is vulnerable to access control violations that allows the users to view or access/perform actions beyond their expected capability.

CVE-2025-14914 ibm vulnerability CVSS: 0 02 Feb 2026, 16:16 UTC

IBM WebSphere Application Server Liberty 17.0.0.3 through 26.0.0.1 could allow a privileged user to upload a zip archive containing path traversal sequences resulting in an overwrite of files leading to arbitrary code execution.

CVE-2025-36442 ibm vulnerability CVSS: 0 30 Jan 2026, 22:15 UTC

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query with XML columns.

CVE-2025-36428 ibm vulnerability CVSS: 0 30 Jan 2026, 22:15 UTC

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic when the RPSCAN feature is enabled.

CVE-2025-36427 ibm vulnerability CVSS: 0 30 Jan 2026, 22:15 UTC

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a user to cause a denial of service due to insufficient validation of special elements in data query logic.

CVE-2025-36424 ibm vulnerability CVSS: 0 30 Jan 2026, 22:15 UTC

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a user to cause a denial of service due to improper neutralization of special elements in data query logic.

CVE-2025-36423 ibm vulnerability CVSS: 0 30 Jan 2026, 22:15 UTC

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 12.1.0 - 12.1.3 could allow a local user to cause a denial of service due to improper neutralization of special elements in data query logic.

CVE-2025-36407 ibm vulnerability CVSS: 0 30 Jan 2026, 22:15 UTC

IBM® Db2® is vulnerable to a denial of service with a specially crafted query that uses ALTER TABLE operations.

CVE-2025-36387 ibm vulnerability CVSS: 0 30 Jan 2026, 22:15 UTC

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 - 11.5.9 could allow an authenticated user to cause a denial of service when given specially crafted query.

CVE-2025-36384 ibm vulnerability CVSS: 0 30 Jan 2026, 22:15 UTC

IBM Db2 for Windows 12.1.0 - 12.1.3 could allow a local user with filesystem access to escalate their privileges due to the use of an unquoted search path element.

CVE-2025-36366 ibm vulnerability CVSS: 0 30 Jan 2026, 22:15 UTC

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a user to cause a denial of service by executing a query that invokes the JSON_Object scalar function, which may trigger an unhandled exception leading to abnormal server termination.

CVE-2025-36365 ibm vulnerability CVSS: 0 30 Jan 2026, 22:15 UTC

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 under specific configuration of cataloged remote storage aliases could allow an authenticated user to execute unauthorized commands due to an authorization bypass vulnerability using a user-controlled key.

CVE-2025-36353 ibm vulnerability CVSS: 0 30 Jan 2026, 22:15 UTC

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow a local user to cause a denial of service due to improper neutralization of special elements in data query logic.

CVE-2025-36184 ibm vulnerability CVSS: 0 30 Jan 2026, 22:15 UTC

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 could allow an instance owner to execute malicious code that escalate their privileges to root due to execution of unnecessary privileges operated at a higher than minimum level.

CVE-2025-36123 ibm vulnerability CVSS: 0 30 Jan 2026, 22:15 UTC

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow a local user to cause a denial of service when copying large table containing XML data due to improper allocation of system resources.

CVE-2025-36098 ibm vulnerability CVSS: 0 30 Jan 2026, 22:15 UTC

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow an authenticated user to cause a denial of service due to improper allocation of resources.

CVE-2025-36070 ibm vulnerability CVSS: 0 30 Jan 2026, 22:15 UTC

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 is vulnerable to a denial of service as a trap may occur when selecting from certain types of tables.

CVE-2025-36009 ibm vulnerability CVSS: 0 30 Jan 2026, 22:15 UTC

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user to cause a denial of service due to excessive use of a global variable.

CVE-2025-36001 ibm vulnerability CVSS: 0 30 Jan 2026, 22:15 UTC

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow an authenticated user to cause a denial of service using a specially crafted SQL statement including XML that performs uncontrolled recursion.

CVE-2025-2668 ibm vulnerability CVSS: 0 30 Jan 2026, 22:15 UTC

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 is vulnerable to a denial of service as the server may crash when an authenticated user creates a specially crafted query.

CVE-2025-36419 ibm vulnerability CVSS: 0 20 Jan 2026, 16:16 UTC

IBM ApplinX 11.1 could disclose sensitive information about server architecture that could aid in further attacks against the system.

CVE-2025-36418 ibm vulnerability CVSS: 0 20 Jan 2026, 16:16 UTC

IBM ApplinX 11.1 is vulnerable due to a privilege escalation vulnerability due to improper verification of JWT tokens. An attacker may be able to craft or modify a JSON web token in order to impersonate another user or to elevate their privileges.

CVE-2025-36411 ibm vulnerability CVSS: 0 20 Jan 2026, 16:16 UTC

IBM ApplinX 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

CVE-2025-36410 ibm vulnerability CVSS: 0 20 Jan 2026, 16:16 UTC

IBM ApplinX 11.1 could allow an authenticated user to perform unauthorized administrative actions on the server due to server-side enforcement of client-side security.

CVE-2025-36409 ibm vulnerability CVSS: 0 20 Jan 2026, 16:16 UTC

IBM ApplinX 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVE-2025-36408 ibm vulnerability CVSS: 0 20 Jan 2026, 16:16 UTC

IBM ApplinX 11.1 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVE-2025-36397 ibm vulnerability CVSS: 0 20 Jan 2026, 16:16 UTC

IBM Application Gateway 23.10 through 25.09 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.

CVE-2025-36396 ibm vulnerability CVSS: 0 20 Jan 2026, 16:16 UTC

IBM Application Gateway 23.10 through 25.09 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVE-2025-36059 ibm vulnerability CVSS: 0 20 Jan 2026, 16:16 UTC

IBM Business Automation Workflow containers 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 Interim Fix 006. IBM Cloud Pak for Business Automation could allow a local user with access to the container to execute OS system calls.

CVE-2025-36058 ibm vulnerability CVSS: 0 20 Jan 2026, 16:16 UTC

IBM Business Automation Workflow containers 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 Interim Fix 006. IBM Cloud Pak for Business Automation and IBM Business Automation Workflow containers may disclose sensitve configuration information in a config map.

CVE-2025-33015 ibm vulnerability CVSS: 0 20 Jan 2026, 16:16 UTC

IBM Concert 1.0.0 through 2.1.0 is vulnerable to malicious file upload by not validating the content of the file uploaded to the web interface.

CVE-2025-1722 ibm vulnerability CVSS: 0 20 Jan 2026, 15:16 UTC

IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.

CVE-2025-1719 ibm vulnerability CVSS: 0 20 Jan 2026, 15:16 UTC

IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.

CVE-2025-13925 ibm vulnerability CVSS: 0 20 Jan 2026, 15:16 UTC

IBM Aspera Console 3.4.7 stores potentially sensitive information in log files that could be read by a local privileged user.

CVE-2025-64645 ibm vulnerability CVSS: 0 26 Dec 2025, 15:15 UTC

IBM Concert 1.0.0 through 2.1.0 could allow a local user to escalate their privileges due to a race condition of a symbolic link.

CVE-2025-36230 ibm vulnerability CVSS: 0 26 Dec 2025, 15:15 UTC

IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.

CVE-2025-36229 ibm vulnerability CVSS: 0 26 Dec 2025, 15:15 UTC

IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 could allow authenticated users to enumerate sensitive information of data due by enumerating package identifiers.

CVE-2025-36228 ibm vulnerability CVSS: 0 26 Dec 2025, 15:15 UTC

IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 may allow inconsistent permissions between the user interface and backend API allowed users to access features that appeared disabled, potentially leading to misuse.

CVE-2025-36192 ibm vulnerability CVSS: 0 26 Dec 2025, 14:15 UTC

IBM DS8A00( R10.1) 10.10.106.0 and IBM DS8A00 ( R10.0) 10.1.3.010.2.45.0 and IBM DS8900F ( R9.4) 89.40.83.089.42.18.089.44.5.0 IBM System Storage DS8000 could allow a local user with authorized CCW update permissions to delete or corrupt backups due to missing authorization in IBM Safeguarded Copy / GDPS Logical corruption protection mechanisms.

CVE-2025-13915 ibm vulnerability CVSS: 0 26 Dec 2025, 14:15 UTC

IBM API Connect 10.0.8.0 through 10.0.8.5, and 10.0.11.0 could allow a remote attacker to bypass authentication mechanisms and gain unauthorized access to the application.

CVE-2025-1721 ibm vulnerability CVSS: 0 26 Dec 2025, 13:15 UTC

IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.

CVE-2025-12771 ibm vulnerability CVSS: 0 26 Dec 2025, 13:15 UTC

IBM Concert 1.0.0 through 2.1.0 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local user could overflow the buffer and execute arbitrary code on the system.

CVE-2025-36154 ibm vulnerability CVSS: 0 24 Dec 2025, 19:15 UTC

IBM Concert 1.0.0 through 2.1.0 stores sensitive information in cleartext during recursive docker builds which could be obtained by a local user.

CVE-2025-36360 ibm vulnerability CVSS: 0 15 Dec 2025, 20:15 UTC

IBM UCD - IBM UrbanCode Deploy 7.1 through 7.1.2.27, 7.2 through 7.2.3.20, and 7.3 through 7.3.2.15 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.10, and 8.1 through 8.1.2.3 is susceptible to a race condition in http-session client-IP binding enforcement which may allow a session to be briefly reused from a new IP address before it is invalidated, potentially enabling unauthorized access under certain network conditions.

CVE-2025-13481 ibm vulnerability CVSS: 0 11 Dec 2025, 20:15 UTC

IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.

CVE-2025-13214 ibm vulnerability CVSS: 0 11 Dec 2025, 20:15 UTC

IBM Aspera Orchestrator 4.0.0 through 4.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

CVE-2025-13211 ibm vulnerability CVSS: 0 11 Dec 2025, 20:15 UTC

IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow an authenticated user to cause a denial of service in the email service due to improper control of interaction frequency.

CVE-2025-13148 ibm vulnerability CVSS: 0 11 Dec 2025, 20:15 UTC

IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow could an authenticated user to change the password of another user without prior knowledge of that password.

CVE-2025-36437 ibm vulnerability CVSS: 0 09 Dec 2025, 22:16 UTC

IBM Planning Analytics Local 2.1.0 - 2.1.15 could disclose sensitive information about server architecture that could aid in further attacks against the system.

CVE-2024-56464 ibm vulnerability CVSS: 0 09 Dec 2025, 16:17 UTC

IBM QRadar SIEM 7.5 - 7.5.0 UP14 IF01 is affected by an information disclosure vulnerability involving exposure of directory information. IBM has addressed this vulnerability in the latest update.

CVE-2025-64650 ibm vulnerability CVSS: 0 08 Dec 2025, 22:15 UTC

IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.18 could disclose sensitive user credentials in log files.

CVE-2025-36102 ibm vulnerability CVSS: 0 08 Dec 2025, 22:15 UTC

IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 could allow a privileged user to bypass validation, passing user input into the application as trusted data, due to client-side enforcement of server-side security.

CVE-2025-36017 ibm vulnerability CVSS: 0 08 Dec 2025, 22:15 UTC

IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 stores unencrypted sensitive information in environmental variables files which can be obtained by an authenticated user.

CVE-2025-36015 ibm vulnerability CVSS: 0 08 Dec 2025, 22:15 UTC

IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 could allow an authenticated user to cause a denial of service due to improper validation of a specified quantity size input.

CVE-2025-33111 ibm vulnerability CVSS: 0 08 Dec 2025, 22:15 UTC

IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 is vulnerable to creation of temporary files without atomic operations which may expose sensitive information to an authenticated user due to race condition attacks.

CVE-2025-12832 ibm vulnerability CVSS: 0 08 Dec 2025, 22:15 UTC

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

CVE-2025-12635 ibm vulnerability CVSS: 0 08 Dec 2025, 22:15 UTC

IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.12 are affected by cross-site scripting due to improper validation of user-supplied input. An attacker could exploit this vulnerability by using a specially crafted URL to redirect the user to a malicious site.

CVE-2024-45675 ibm vulnerability CVSS: 0 02 Dec 2025, 03:16 UTC

IBM Informix Dynamic Server 14.10 could allow a local user on the system to log into the Informix server as administrator without a password.

CVE-2025-36134 ibm vulnerability CVSS: 0 25 Nov 2025, 15:15 UTC

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.5 and 6.2.1.1 could disclose sensitive information due to a missing or insecure SameSite attribute for a sensitive cookie.

CVE-2025-36150 ibm vulnerability CVSS: 0 24 Nov 2025, 21:16 UTC

IBM Concert 1.0.0 through 2.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

CVE-2025-36112 ibm vulnerability CVSS: 0 24 Nov 2025, 19:15 UTC

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.5 and 6.2.1.1 could reveal sensitive server IP configuration information to an unauthorized user.

CVE-2025-36149 ibm vulnerability CVSS: 0 21 Nov 2025, 20:15 UTC

IBM Concert Software 1.0.0 through 2.0.0 could allow a remote attacker to hijack the clicking action of the victim.

CVE-2025-36072 ibm vulnerability CVSS: 0 20 Nov 2025, 23:15 UTC

IBM webMethods Integration 10.11 through 10.11_Core_Fix22, 10.15 through 10.15_Core_Fix22, and 11.1 through 11.1_Core_Fix6 IBM webMethods Integration allow an authenticated user to execute arbitrary code on the system, caused by the deserialization of untrusted object graphs data.

CVE-2025-36160 ibm vulnerability CVSS: 0 20 Nov 2025, 22:15 UTC

IBM Concert 1.0.0 through 2.0.0 could disclose sensitive server information from HTTP response headers that could aid in further attacks against the system.

CVE-2025-36159 ibm vulnerability CVSS: 0 20 Nov 2025, 22:15 UTC

IBM Concert 1.0.0 through 2.0.0 could allow a local user to forge log files to impersonate other users or hide their identity due to improper neutralization of output.

CVE-2025-36158 ibm vulnerability CVSS: 0 20 Nov 2025, 22:15 UTC