VYPR

Vendor CVEs

IBM

All CVEs

8,825 total · sorted by risk
  • CVE-2025-36193HigSep 3, 2025
    risk 0.55cvss 8.4epss 0.00

    IBM Transformation Advisor 2.0.1 through 4.3.1 incorrectly assigns privileges to security critical files which could allow a local root escalation inside a container running the IBM Transformation Advisor Operator Catalog image.

  • CVE-2025-33108HigJun 14, 2025
    risk 0.55cvss 8.5epss 0.01

    IBM Backup, Recovery and Media Services for i 7.4 and 7.5 could allow a user with the capability to compile or restore a program to gain elevated privileges due to a library unqualified call made by a BRMS program. A malicious actor could cause user-controlled code to run with…

  • CVE-2025-33112HigJun 10, 2025
    risk 0.55cvss 8.4epss 0.00

    IBM AIX 7.3 and IBM VIOS 4.1.1 Perl implementation could allow a non-privileged local user to exploit a vulnerability to execute arbitrary code due to improper neutralization of pathname input.

  • CVE-2025-33103HigMay 17, 2025
    risk 0.55cvss 8.5epss 0.00

    IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 product IBM TCP/IP Connectivity Utilities for i contains a privilege escalation vulnerability. A malicious actor with command line access to the host operating system can elevate privileges to gain root access to the host operating system.

  • CVE-2025-1951HigApr 22, 2025
    risk 0.55cvss 8.4epss 0.00

    IBM Hardware Management Console - Power Systems V10.2.1030.0 and V10.3.1050.0 could allow a local user to execute commands as a privileged user due to execution of commands with unnecessary privileges.

  • CVE-2024-51459HigMar 19, 2025
    risk 0.55cvss 8.4epss 0.00

    IBM InfoSphere Information Server 11.7 could allow a local user to execute privileged commands due to the improper handling of permissions.

  • CVE-2024-55898HigFeb 24, 2025
    risk 0.55cvss 8.5epss 0.00

    IBM i 7.2, 7.3, 7.4, and 7.5 could allow a user with the capability to compile or restore a program to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-controlled code to run with administrator privilege.

  • CVE-2024-52899HigNov 26, 2024
    risk 0.55cvss 8.5epss 0.01

    IBM Data Virtualization Manager for z/OS 1.1 and 1.2 could allow an authenticated user to inject malicious JDBC URL parameters and execute code on the server.

  • CVE-2024-35142HigMay 31, 2024
    risk 0.55cvss 8.4epss 0.00

    IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to execution of unnecessary privileges. IBM X-Force ID: 292418.

  • CVE-2024-3301HigMay 30, 2024
    risk 0.55cvss 8.5epss 0.01

    An unsafe .NET object deserialization vulnerability in DELMIA Apriso Release 2019 through Release 2024 could lead to post-authentication remote code execution.

  • CVE-2024-27260HigMay 16, 2024
    risk 0.55cvss 8.4epss 0.00

    IBM AIX could 7.2, 7.3, VIOS 3.1, and VIOS 4.1 allow a non-privileged local user to exploit a vulnerability in the invscout command to execute arbitrary commands. IBM X-Force ID: 283985.

  • CVE-2024-25050HigApr 28, 2024
    risk 0.55cvss 8.4epss 0.00

    IBM i 7.2, 7.3, 7.4, 7.5 and IBM Rational Development Studio for i 7.2, 7.3, 7.4, 7.5 networking and compiler infrastructure could allow a local user to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-controlled code to run with…

  • CVE-2024-22346HigMar 14, 2024
    risk 0.55cvss 8.4epss 0.00

    Db2 for IBM i 7.2, 7.3, 7.4, and 7.5 infrastructure could allow a local user to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-controlled code to run with administrator privilege. IBM X-Force ID: 280203.

  • CVE-2023-25921HigFeb 29, 2024
    risk 0.55cvss 8.5epss 0.01

    IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment. IBM X-Force ID: 247620.

  • CVE-2023-25925HigFeb 28, 2024
    risk 0.55cvss 8.5epss 0.01

    IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 247632.

  • CVE-2024-25021HigFeb 22, 2024
    risk 0.55cvss 8.4epss 0.00

    IBM AIX 7.3, VIOS 4.1's Perl implementation could allow a non-privileged local user to exploit a vulnerability to execute arbitrary commands. IBM X-Force ID: 281320.

  • CVE-2023-31003HigJan 11, 2024
    risk 0.55cvss 8.4epss 0.00

    IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.6.1) could allow a local user to obtain root access due to improper access controls. IBM X-Force ID: 254658.

  • CVE-2023-47145HigJan 7, 2024
    risk 0.55cvss 8.4epss 0.00

    IBM Db2 for Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow a local user to escalate their privileges to the SYSTEM user using the MSI repair functionality. IBM X-Force ID: 270402.

  • CVE-2023-45174HigDec 13, 2023
    risk 0.55cvss 8.4epss 0.00

    IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a privileged local user to exploit a vulnerability in the qdaemon command to escalate privileges or cause a denial of service. IBM X-Force ID: 267972.

  • CVE-2023-45170HigDec 13, 2023
    risk 0.55cvss 8.4epss 0.00

    IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the piobe command to escalate privileges or cause a denial of service. IBM X-Force ID: 267968.

  • CVE-2023-45166HigDec 13, 2023
    risk 0.55cvss 8.4epss 0.00

    IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the piodmgrsu command to obtain elevated privileges. IBM X-Force ID: 267964.

  • CVE-2023-28523HigDec 9, 2023
    risk 0.55cvss 8.4epss 0.00

    IBM Informix Dynamic Server 12.10 and 14.10 onsmsync is vulnerable to a heap buffer overflow, caused by improper bounds checking which could allow an attacker to execute arbitrary code. IBM X-Force ID: 250753.

  • CVE-2023-42006HigDec 1, 2023
    risk 0.55cvss 8.4epss 0.00

    IBM Administration Runtime Expert for i 7.2, 7.3, 7.4, and 7.5 could allow a local user to obtain sensitive information caused by improper authority checks. IBM X-Force ID: 265266.

  • CVE-2023-45168HigDec 1, 2023
    risk 0.55cvss 8.4epss 0.00

    IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the invscout command to execute arbitrary commands. IBM X-Force ID: 267966.

  • CVE-2023-38280HigOct 16, 2023
    risk 0.55cvss 8.4epss 0.00

    IBM HMC (Hardware Management Console) 10.1.1010.0 and 10.2.1030.0 could allow a local user to escalate their privileges to root access on a restricted shell. IBM X-Force ID: 260740.

  • CVE-2023-35897HigOct 6, 2023
    risk 0.55cvss 8.4epss 0.00

    IBM Spectrum Protect Client and IBM Storage Protect for Virtual Environments 8.1.0.0 through 8.1.19.0 could allow a local user to execute arbitrary code on the system using a specially crafted file, caused by a DLL hijacking flaw. IBM X-Force ID: 259246.

  • CVE-2023-37410HigSep 20, 2023
    risk 0.55cvss 8.4epss 0.00

    IBM Personal Communications 14.05, 14.06, and 15.0.0 could allow a local user to escalate their privileges to the SYSTEM user due to overly permissive access controls. IBM X-Force ID: 260138.

  • CVE-2023-38721HigAug 14, 2023
    risk 0.55cvss 8.4epss 0.00

    The IBM i 7.2, 7.3, 7.4, and 7.5 product Facsimile Support for i contains a local privilege escalation vulnerability. A malicious actor could gain access to a command line with elevated privileges allowing root access to the host operating system. IBM X-Force ID: 262173.

  • CVE-2022-43910HigJul 19, 2023
    risk 0.55cvss 8.4epss 0.00

    IBM Security Guardium 11.3 could allow a local user to escalate their privileges due to improper permission controls. IBM X-Force ID: 240908.

  • CVE-2023-30989HigJul 16, 2023
    risk 0.55cvss 8.4epss 0.00

    IBM Performance Tools for i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability. A malicious actor with command line access to the host operating system can elevate privileges to gain all object access to the host operating system. IBM X-Force ID: …

  • CVE-2023-30988HigJul 16, 2023
    risk 0.55cvss 8.4epss 0.00

    The IBM i 7.2, 7.3, 7.4, and 7.5 product Facsimile Support for i contains a local privilege escalation vulnerability. A malicious actor with command line access to the host operating system can elevate privileges to gain root access to the host operating system. IBM X-Force…

  • CVE-2023-30431HigJul 10, 2023
    risk 0.55cvss 8.4epss 0.00

    IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 db2set is vulnerable to a buffer overflow, caused by improper bounds checking. An attacker could overflow the buffer and execute arbitrary code. IBM X-Force ID: 252184.

  • CVE-2023-27558HigJul 10, 2023
    risk 0.55cvss 8.4epss 0.00

    IBM Db2 on Windows 10.5, 11.1, and 11.5 may be vulnerable to a privilege escalation caused by at least one installed service using an unquoted service path. A local attacker could exploit this vulnerability to gain elevated privileges by inserting an executable file in the…

  • CVE-2023-28956HigJun 22, 2023
    risk 0.55cvss 8.4epss 0.00

    IBM Spectrum Protect Backup-Archive Client 8.1.0.0 through 8.1.17.2 may allow a local user to escalate their privileges due to improper access controls.

  • CVE-2023-27285HigJun 5, 2023
    risk 0.55cvss 8.4epss 0.00

    IBM Aspera Connect 4.2.5 and IBM Aspera Cargo 4.2.5 is vulnerable to a buffer overflow, caused by improper bounds checking. An attacker could overflow a buffer and execute arbitrary code on the system. IBM X-Force ID: 248625.

  • CVE-2022-41736HigApr 29, 2023
    risk 0.55cvss 8.4epss 0.00

    IBM Spectrum Scale Container Native Storage Access 5.1.2.1 through 5.1.6.0 contains an unspecified vulnerability that could allow a local user to obtain root privileges. IBM X-Force ID: 237810.

  • CVE-2023-26286HigApr 26, 2023
    risk 0.55cvss 8.4epss 0.00

    IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX runtime services library to execute arbitrary commands. IBM X-Force ID: 248421.

  • CVE-2023-2141HigApr 21, 2023
    risk 0.55cvss 8.5epss 0.01

    An unsafe .NET object deserialization in DELMIA Apriso Release 2017 through Release 2022 could lead to post-authentication remote code execution.

  • CVE-2023-27286HigApr 2, 2023
    risk 0.55cvss 8.4epss 0.01

    IBM Aspera Cargo 4.2.5 and IBM Aspera Connect 4.2.5 are vulnerable to a buffer overflow, caused by improper bounds checking. An attacker could overflow a buffer and execute arbitrary code on the system. IBM X-Force ID: 248616.

  • CVE-2023-27284HigApr 2, 2023
    risk 0.55cvss 8.4epss 0.01

    IBM Aspera Cargo 4.2.5 and IBM Aspera Connect 4.2.5 are vulnerable to a buffer overflow, caused by improper bounds checking. An attacker could overflow a buffer and execute arbitrary code on the system. IBM X-Force ID: 248616.

  • CVE-2023-22875HigJan 17, 2023
    risk 0.55cvss 8.4epss 0.00

    IBM QRadar SIEM 7.4 and 7.5copies certificate key files used for SSL/TLS in the QRadar web user interface to managed hosts in the deployment that do not require that key. IBM X-Force ID: 244356.

  • CVE-2022-41290HigDec 23, 2022
    risk 0.55cvss 8.4epss 0.00

    IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the rm_rlcache_file command to obtain root privileges. IBM X-Force ID: 236690.

  • CVE-2018-1936HigApr 3, 2019
    risk 0.55cvss 8.4epss 0.01

    IBM DB2 9.7, 10.1, 10.5, and 11.1 libdb2e.so.1 is vulnerable to a stack based buffer overflow, caused by improper bounds checking which could allow an attacker to execute arbitrary code. IBM X-Force ID: 153316.

  • CVE-2018-1980HigMar 11, 2019
    risk 0.55cvss 8.4epss 0.01

    IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-ForceID: 154078.

  • CVE-2018-1978HigMar 11, 2019
    risk 0.55cvss 8.4epss 0.01

    IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-ForceID: 154069.

  • CVE-2018-1923HigMar 11, 2019
    risk 0.55cvss 8.4epss 0.01

    IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is affected by buffer overflow vulnerability that can potentially result in arbitrary code execution. IBM X-Force ID: 152859.

  • CVE-2018-1922HigMar 11, 2019
    risk 0.55cvss 8.4epss 0.01

    IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is affected by buffer overflow vulnerability that can potentially result in arbitrary code execution. IBM X-Force ID: 152858.

  • CVE-2018-1701HigFeb 15, 2019
    risk 0.55cvss 8.5epss 0.01

    IBM InfoSphere Information Server 11.7 could allow an authenciated user under specialized conditions to inject commands into the installation process that would execute on the WebSphere Application Server. IBM X-Force ID: 145970.

  • CVE-2018-1771HigDec 20, 2018
    risk 0.55cvss 8.4epss 0.00

    IBM Domino 9.0 and 9.0.1 could allow an attacker to execute commands on the system by triggering a buffer overflow in the parsing of command line arguments passed to nsd.exe. IBM X-force ID: 148687.

  • CVE-2018-1941HigDec 5, 2018
    risk 0.55cvss 8.4epss 0.00

    IBM Campaign 9.1.0 and 9.1.2 could allow a local user to obtain admini privileges due to the application not validating access permissions. IBM X-Force ID: 153382.

Page 14 of 177