VYPR

Vendor CVEs

IBM

All CVEs

8,825 total · sorted by risk
  • CVE-2026-16890LowAug 19, 2026
    risk 0.23cvss 3.6epss 0.00

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain sensitive information or cause a denial of service due to an integer overflow.

  • CVE-2025-2134LowFeb 4, 2026
    risk 0.23cvss 3.5epss 0.00

    IBM Jazz Reporting Service could allow an authenticated user on the network to affect the system's performance using complicated queries due to insufficient resource pooling.

  • CVE-2025-27550LowFeb 4, 2026
    risk 0.23cvss 3.5epss 0.00

    IBM Jazz Reporting Service could allow an authenticated user on the host network to obtain sensitive information about other projects that reside on the server.

  • CVE-2025-1823LowFeb 4, 2026
    risk 0.23cvss 3.5epss 0.00

    IBM Jazz Reporting Service could allow an authenticated user on the host network to cause a denial of service using specially crafted SQL query that consumes excess memory resources.

  • CVE-2025-36411LowJan 20, 2026
    risk 0.23cvss 3.5epss 0.00

    IBM ApplinX 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

  • CVE-2025-2139LowOct 12, 2025
    risk 0.23cvss 3.5epss 0.00

    IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the network to delete reviews from other users due to client-side enforcement of server-side security.

  • CVE-2025-2138LowOct 12, 2025
    risk 0.23cvss 3.5epss 0.00

    IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the network to delete comments from other users due to client-side enforcement of server-side security.

  • CVE-2023-37397LowApr 19, 2024
    risk 0.23cvss 3.6epss 0.00

    IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain or modify sensitive information due to improper encryption of certain data. IBM X-Force ID: 259672.

  • CVE-2021-20534LowJul 15, 2021
    risk 0.23cvss 3.5epss 0.01

    IBM Security Verify Access Docker 10.0.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to…

  • CVE-2020-4725LowMar 2, 2021
    risk 0.23cvss 3.5epss 0.01

    IBM Monitoring (IBM Cloud APM 8.1.4 ) could allow an authenticated user to modify HTML content by sending a specially crafted HTTP request to the APM UI, which could mislead another user. IBM X-Force ID: 187974.

  • CVE-2019-4349LowNov 3, 2020
    risk 0.23cvss 3.5epss 0.00

    IBM Maximo Anywhere 7.6.2.0, 7.6.2.1, 7.6.3.0, and 7.6.3.1 applications can be installed on a deprecated operating system version that could compromised the confidentiality and integrity of the service. IBM X-Force ID: 161486

  • CVE-2019-4616LowFeb 5, 2020
    risk 0.23cvss 3.5epss 0.00

    IBM Cloud Automation Manager 3.2.1.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to…

  • CVE-2019-4271LowSep 17, 2019
    risk 0.23cvss 3.5epss 0.01

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Admin console is vulnerable to a Client-side HTTP parameter pollution vulnerability. IBM X-Force ID: 160243.

  • CVE-2018-1917LowApr 2, 2019
    risk 0.23cvss 3.5epss 0.01

    IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow an authenticated user to access JSP files and disclose sensitive information. IBM X-Force ID: 152784.

  • CVE-2018-1842LowNov 9, 2018
    risk 0.23cvss 3.6epss 0.00

    IBM Cognos Analytics 11 Configuration tool, under certain circumstances, will bypass OIDC namespace signature verification on its id_token. IBM X-Force ID: 150902.

  • CVE-2017-1353LowDec 7, 2017
    risk 0.23cvss 3.5epss 0.01

    IBM Atlas eDiscovery Process Management 6.0.3 could allow an authenticated attacker to obtain sensitive information when an unsuspecting user clicks on unsafe third-party links. IBM X-Force ID: 126680.

  • CVE-2016-3009LowNov 30, 2016
    risk 0.23cvss 3.5epss 0.01

    Cross-site request forgery (CSRF) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to hijack the authentication of arbitrary users for requests that modify the Connections generic page.

  • CVE-2016-2998LowSep 1, 2016
    risk 0.23cvss 3.5epss 0.00

    Cross-site request forgery (CSRF) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to hijack the authentication of arbitrary users for requests that update data.

  • CVE-2015-4962LowJan 3, 2016
    risk 0.23cvss 3.5epss 0.00

    Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.x and 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF9, and 6.x before 6.0.1; Rational Quality Manager (RQM) 3.x before 3.0.1.6 IF7, 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF9, and 6.x…

  • CVE-2026-16891LowAug 19, 2026
    risk 0.21cvss 3.3epss 0.00

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain sensitive information due to an out-of-bounds read.

  • CVE-2026-18096LowAug 12, 2026
    risk 0.21cvss 3.3epss 0.00

    IBM Db2 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacker to cause a denial of service due to a memory leak.

  • CVE-2025-33081LowFeb 3, 2026
    risk 0.21cvss 3.3epss 0.00

    IBM Concert 1.0.0 through 2.1.0 stores potentially sensitive information in log files that could be read by a local user.

  • CVE-2025-36144LowSep 27, 2025
    risk 0.21cvss 3.3epss 0.00

    IBM Lakehouse (watsonx.data 2.2) stores potentially sensitive information in log files that could be read by a local user.

  • CVE-2025-0759LowFeb 27, 2025
    risk 0.21cvss 3.3epss 0.00

    IBM EntireX 11.1 could allow a local user to unintentionally modify data timestamp integrity due to improper shared resource synchronization.

  • CVE-2024-56812LowFeb 27, 2025
    risk 0.21cvss 3.3epss 0.00

    IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.

  • CVE-2024-56811LowFeb 27, 2025
    risk 0.21cvss 3.3epss 0.00

    IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.

  • CVE-2024-56810LowFeb 27, 2025
    risk 0.21cvss 3.3epss 0.00

    IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.

  • CVE-2024-56496LowFeb 27, 2025
    risk 0.21cvss 3.3epss 0.00

    IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.

  • CVE-2024-56495LowFeb 27, 2025
    risk 0.21cvss 3.3epss 0.00

    IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.

  • CVE-2024-56494LowFeb 27, 2025
    risk 0.21cvss 3.3epss 0.00

    IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.

  • CVE-2024-56493LowFeb 27, 2025
    risk 0.21cvss 3.3epss 0.00

    IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.

  • CVE-2024-45674LowFeb 22, 2025
    risk 0.21cvss 3.3epss 0.00

    IBM Security Verify Bridge Directory Sync 1.0.1 through 1.0.12, IBM Security Verify Gateway for Windows Login 1.0.1 through 1.0.10, and IBM Security Verify Gateway for Radius 1.0.1 through 1.0.11 stores potentially sensitive information in log files that could be read by a…

  • CVE-2024-56467LowFeb 6, 2025
    risk 0.21cvss 3.3epss 0.00

    IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.

  • CVE-2023-35022LowJun 30, 2024
    risk 0.21cvss 3.3epss 0.00

    IBM InfoSphere Information Server 11.7 could allow a local user to update projects that they do not have the authorization to access. IBM X-Force ID: 258254.

  • CVE-2024-31870LowJun 15, 2024
    risk 0.21cvss 3.3epss 0.00

    IBM Db2 for i 7.2, 7.3, 7.4, and 7.5 supplies user defined table function is vulnerable to user enumeration by a local authenticated attacker, without having authority to the related *USRPRF objects. This can be used by a malicious actor to gather information about users that…

  • CVE-2024-22333LowJun 13, 2024
    risk 0.21cvss 3.3epss 0.00

    IBM Maximo Asset Management 7.6.1.3 and IBM Maximo Application Suite 8.10 and 8.11 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 279973.

  • CVE-2023-26279LowNov 24, 2023
    risk 0.21cvss 3.3epss 0.00

    IBM QRadar WinCollect Agent 10.0 through 10.1.7 could allow a local user to perform unauthorized actions due to improper encoding. IBM X-Force ID: 248160.

  • CVE-2023-35018LowOct 16, 2023
    risk 0.21cvss 3.3epss 0.00

    IBM Security Verify Governance 10.0 could allow a privileged use to upload arbitrary files due to improper file validation. IBM X-Force ID: 259382.

  • CVE-2022-42442LowNov 3, 2022
    risk 0.21cvss 3.3epss 0.00

    IBM Robotic Process Automation for Cloud Pak 21.0.1, 21.0.2, 21.0.3, 21.0.4, and 21.0.5 is vulnerable to exposure of the first tenant owner e-mail address to users with access to the container platform. IBM X-Force ID: 238214.

  • CVE-2022-22314LowSep 8, 2022
    risk 0.21cvss 3.3epss 0.00

    IBM Planning Analytics Local 2.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 217371.

  • CVE-2022-22326LowAug 1, 2022
    risk 0.21cvss 3.3epss 0.00

    IBM Datapower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.5, and 2018.4.1.0 through 2018.4.1.18 could allow unauthorized viewing of logs and files due to insufficient authorization checks. IBM X-Force ID: 218856.

  • CVE-2021-20551LowJun 24, 2022
    risk 0.21cvss 3.3epss 0.00

    IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 199149.

  • CVE-2022-22426LowJun 10, 2022
    risk 0.21cvss 3.3epss 0.00

    IBM Spectrum Copy Data Management Admin 2.2.0.0 through 2.2.15.0 could allow a local attacker to bypass authentication restrictions, caused by the lack of proper session management. An attacker could exploit this vulnerability to bypass authentication and gain unauthorized…

  • CVE-2020-4951LowOct 15, 2021
    risk 0.21cvss 3.3epss 0.00

    IBM Cognos Analytics 11.1.7 and 11.2.0 contains locally cached browser data, that could allow a local attacker to obtain sensitive information.

  • CVE-2020-4809LowSep 23, 2021
    risk 0.21cvss 3.3epss 0.00

    IBM Edge 4.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 189633.

  • CVE-2020-4805LowSep 23, 2021
    risk 0.21cvss 3.3epss 0.00

    IBM Edge 4.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 189539.

  • CVE-2020-4803LowSep 23, 2021
    risk 0.21cvss 3.3epss 0.00

    IBM Edge 4.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 189535.

  • CVE-2021-20478LowJul 20, 2021
    risk 0.21cvss 3.3epss 0.00

    IBM Cloud Pak System 2.3 could allow a local user in some situations to view the artifacts of another user in self service console. IBM X-Force ID: 197497.

  • CVE-2021-20396LowJun 11, 2021
    risk 0.21cvss 3.3epss 0.00

    IBM QRadar Analyst Workflow App 1.0 through 1.18.0 for IBM QRadar SIEM allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 196009.

  • CVE-2021-20575LowJun 1, 2021
    risk 0.21cvss 3.3epss 0.00

    IBM Security Verify Access 20.07 allows web pages to be stored locally which can be read by another user on the system. X-Force ID: 199278.

Page 118 of 177