VYPR

Vendor CVEs

IBM

All CVEs

8,825 total · sorted by risk
  • CVE-2026-3366HigMay 27, 2026
    risk 0.49cvss 7.5epss 0.01

    IBM InfoSphere Optim Test Data Fabrication 1.0.0, 1.0.0.1, 1.0.0.2, 1.0.2, 1.0.2.2, 1.0.2.3, 1.0.2.4, 1.0.2.5, 1.0.2.6, 1.0.2.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot"…

  • CVE-2026-8854HigMay 26, 2026
    risk 0.49cvss 7.5epss 0.00

    IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_mem_cache.

  • CVE-2026-8620HigMay 26, 2026
    risk 0.49cvss 7.5epss 0.00

    IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to HTTP request smuggling in the Web Server Plug-ins through a specially crafted request.

  • CVE-2026-8850HigMay 26, 2026
    risk 0.49cvss 7.5epss 0.00

    IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_ibm_upload.

  • CVE-2026-4503HigApr 30, 2026
    risk 0.49cvss 7.5epss 0.00

    IBM Langflow Desktop 1.0.0 through 1.8.4 Langflow could allow an unauthenticated user to view other users' images due to an indirect object reference through a user-controlled key.

  • CVE-2026-3621HigApr 23, 2026
    risk 0.49cvss 7.5epss 0.00

    IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.4 IBM WebSphere Application Server Liberty is vulnerable to identity spoofing under limited conditions when an application is deployed without authentication and authorization configured.

  • CVE-2025-13855HigApr 1, 2026
    risk 0.49cvss 7.6epss 0.00

    IBM Storage Protect Server 8.2.0 IBM Storage Protect Plus Server is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

  • CVE-2025-14031HigMar 17, 2026
    risk 0.49cvss 7.5epss 0.00

    IBM Sterling B2B Integrator and and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.0 could allow an unauthenticated attacker to send a specially crafted request that causes the application to crash.

  • CVE-2026-1376HigMar 17, 2026
    risk 0.49cvss 7.5epss 0.01

    IBM i 7.6 could allow a remote attacker to cause a denial of service using failed authentication connections due to improper allocation of resources.

  • CVE-2025-14914HigFeb 2, 2026
    risk 0.49cvss 7.6epss 0.00

    IBM WebSphere Application Server Liberty 17.0.0.3 through 26.0.0.1 could allow a privileged user to upload a zip archive containing path traversal sequences resulting in an overwrite of files leading to arbitrary code execution.

  • CVE-2025-13214HigDec 11, 2025
    risk 0.49cvss 7.6epss 0.00

    IBM Aspera Orchestrator 4.0.0 through 4.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

  • CVE-2025-36118HigNov 17, 2025
    risk 0.49cvss 7.5epss 0.00

    IBM Storage Virtualize 8.4, 8.5, 8.7, and 9.1 IKEv1 implementation allows remote attackers to obtain sensitive information from device memory via a Security Association (SA) negotiation request.

  • CVE-2025-3355HigOct 30, 2025
    risk 0.49cvss 7.5epss 0.00

    IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.

  • CVE-2025-36128HigOct 16, 2025
    risk 0.49cvss 7.5epss 0.01

    IBM MQ 9.1, 9.2, 9.3, 9.4 LTS and 9.3, 9.4 CD is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual read operations. By conducting slowloris-type attacks, a remote attacker could exploit this vulnerability to cause a denial of service.

  • CVE-2025-36274HigSep 26, 2025
    risk 0.49cvss 7.5epss 0.00

    IBM Aspera HTTP Gateway 2.0.0 through 2.3.1 stores sensitive information in clear text in easily obtainable files which can be read by an unauthenticated user.

  • CVE-2025-36202HigSep 22, 2025
    risk 0.49cvss 7.5epss 0.00

    IBM webMethods Integration 10.15 and 11.1 could allow an authenticated user with required execute Services to execute commands on the system due to the improper validation of format string strings passed as an argument from an external source.

  • CVE-2025-0165HigAug 30, 2025
    risk 0.49cvss 7.6epss 0.00

    IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data 4.8.4, 4.8.5, and 5.0.0 through 5.2.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the…

  • CVE-2025-36003HigAug 28, 2025
    risk 0.49cvss 7.5epss 0.00

    IBM Security Verify Governance Identity Manager 10.0.2 could allow a remote attacker to obtain sensitive information when detailed technical error messages are returned. This information could be used in further attacks against the system.

  • CVE-2025-33090HigAug 18, 2025
    risk 0.49cvss 7.5epss 0.00

    IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to cause a denial of service using a specially crafted regular expression that would cause excessive resource consumption.

  • CVE-2024-49342HigJul 28, 2025
    risk 0.49cvss 7.5epss 0.00

    IBM Informix Dynamic Server 12.10 and 14.10 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.

  • CVE-2025-33109HigJul 24, 2025
    risk 0.49cvss 7.5epss 0.00

    IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 is vulnerable to a privilege escalation caused by an invalid database authority check. A bad actor could execute a database procedure or function without having all required permissions, in addition to causing denial of service for some…

  • CVE-2025-36097HigJul 16, 2025
    risk 0.49cvss 7.5epss 0.00

    IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7 are vulnerable to a denial of service, caused by a stack-based overflow. An attacker can send a specially crafted request that cause the server to consume excessive memory…

  • CVE-2024-56468HigJul 8, 2025
    risk 0.49cvss 7.5epss 0.00

    IBM InfoSphere Data Replication VSAM for z/OS Remote Source 11.4 could allow a remote user to cause a denial of service by sending an invalid HTTP request to the log reading service.

  • CVE-2025-1991HigJun 28, 2025
    risk 0.49cvss 7.5epss 0.00

    IBM Informix Dynamic Server 12.10,14.10, and15.0 could allow a remote attacker to cause a denial of service due to an integer underflow when processing packets.

  • CVE-2025-0966HigJun 25, 2025
    risk 0.49cvss 7.6epss 0.00

    IBM InfoSphere Information Server 11.7 vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

  • CVE-2025-3221HigJun 21, 2025
    risk 0.49cvss 7.5epss 0.00

    IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.

  • CVE-2025-33122HigJun 17, 2025
    risk 0.49cvss 7.5epss 0.00

    IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 could allow a user to gain elevated privileges due to an unqualified library call in IBM Advanced Job Scheduler for i. A malicious actor could cause user-controlled code to run with administrator privilege.

  • CVE-2025-25032HigJun 11, 2025
    risk 0.49cvss 7.5epss 0.00

    IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 could allow an authenticated user to cause a denial of service by sending a specially crafted request that would exhaust memory resources.

  • CVE-2025-2900HigMay 14, 2025
    risk 0.49cvss 7.5epss 0.00

    IBM Semeru Runtime 8.0.302.0 through 8.0.442.0, 11.0.12.0 through 11.0.26.0, 17.0.0.0 through 17.0.14.0, and 21.0.0.0 through 12.0.6.0 is vulnerable to a denial of service caused by a buffer overflow and subsequent crash, due to a defect in its native AES/CBC encryption…

  • CVE-2025-3632HigMay 12, 2025
    risk 0.49cvss 7.5epss 0.00

    IBM 4769 Developers Toolkit 7.0.0 through 7.5.52 could allow a remote attacker to cause a denial of service in the Hardware Security Module (HSM) due to improper memory allocation of an excessive size.

  • CVE-2025-1137HigMay 10, 2025
    risk 0.49cvss 7.5epss 0.00

    IBM Storage Scale 5.2.2.0 and 5.2.2.1, under certain configurations, could allow an authenticated user to execute privileged commands due to improper input neutralization.

  • CVE-2025-33093HigMay 7, 2025
    risk 0.49cvss 7.5epss 0.00

    IBM Sterling Partner Engagement Manager 6.1.0, 6.2.0, 6.2.2 JWT secret is stored in public Helm Charts and is not stored as a Kubernetes secret.

  • CVE-2025-2898HigMay 6, 2025
    risk 0.49cvss 7.5epss 0.00

    IBM Maximo Application Suite 9.0 could allow an attacker with some level of access to elevate their privileges due to a security configuration vulnerability in Role-Based Access Control (RBAC) configurations.

  • CVE-2024-51476HigMar 6, 2025
    risk 0.49cvss 7.5epss 0.00

    IBM Concert Software 1.0.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.

  • CVE-2024-41771HigMar 3, 2025
    risk 0.49cvss 7.5epss 0.00

    IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7.1 could allow a remote attacker to download temporary files which could expose application logic or other sensitive information.

  • CVE-2024-41770HigMar 3, 2025
    risk 0.49cvss 7.5epss 0.00

    IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7.1 could allow a remote attacker to download temporary files which could expose application logic or other sensitive information.

  • CVE-2025-1403HigFeb 21, 2025
    risk 0.49cvss 8.6epss 0.01

    Qiskit SDK 0.45.0 through 1.2.4 could allow a remote attacker to cause a denial of service using a maliciously crafted QPY file containing a malformed symengine serialization stream which can cause a segfault within the symengine library.

  • CVE-2024-45650HigJan 31, 2025
    risk 0.49cvss 7.5epss 0.00

    IBM Security Verify Directory 10.0 through 10.0.3 is vulnerable to a denial of service when sending an LDAP extended operation.

  • CVE-2024-41743HigJan 19, 2025
    risk 0.49cvss 7.5epss 0.01

    IBM TXSeries for Multiplatforms 10.1 could allow a remote attacker to cause a denial of service using persistent connections due to improper allocation of resources.

  • CVE-2024-41742HigJan 19, 2025
    risk 0.49cvss 7.5epss 0.01

    IBM TXSeries for Multiplatforms 10.1 is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual read operations. By conducting a slowloris-type attacks, a remote attacker could exploit this vulnerability to cause a denial of service.

  • CVE-2024-45662HigJan 18, 2025
    risk 0.49cvss 7.5epss 0.01

    IBM Safer Payments 6.4.0.00 through 6.4.2.07, 6.5.0.00 through 6.5.0.05, and 6.6.0.00 through 6.6.0.03 could allow a remote attacker to cause a denial of service due to improper allocation of resources.

  • CVE-2024-41766HigJan 4, 2025
    risk 0.49cvss 7.5epss 0.00

    IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 could allow a remote attacker to cause a denial of service using a complex regular expression.

  • CVE-2024-31892HigDec 14, 2024
    risk 0.49cvss 7.5epss 0.00

    IBM Storage Scale GUI 5.1.9.0 through 5.1.9.6 and 5.2.0.0 through 5.2.1.1 could allow a user to perform unauthorized actions after intercepting and modifying a csv file due to improper neutralization of formula elements.

  • CVE-2024-41777HigDec 3, 2024
    risk 0.49cvss 7.5epss 0.00

    IBM Cognos Controller 11.0.0 and 11.0.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.

  • CVE-2024-49353HigNov 26, 2024
    risk 0.49cvss 7.5epss 0.00

    IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data 4.0.0 through 5.0.2 does not properly check inputs to resources that are used concurrently, which might lead to unexpected states, possibly resulting in a crash.

  • CVE-2024-52360HigNov 19, 2024
    risk 0.49cvss 7.6epss 0.00

    IBM Concert Software 1.0.0, 1.0.1, 1.0.2, and 1.0.2.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

  • CVE-2024-41784HigNov 15, 2024
    risk 0.49cvss 7.5epss 0.01

    IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, and 6.1.0.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot dot" sequences (/.../) to view arbitrary files on the system.

  • CVE-2024-40681HigSep 7, 2024
    risk 0.49cvss 7.5epss 0.00

    IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow an authenticated user in a specifically defined role, to bypass security restrictions and execute actions against the queue manager.

  • CVE-2024-35124HigAug 13, 2024
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in the combination of the OpenBMC's FW1050.00 through FW1050.10, FW1030.00 through FW1030.50, and FW1020.00 through FW1020.60 default password and session management allow an attacker to gain administrative access to the BMC. IBM X-Force ID: 290674.

  • CVE-2024-40697HigAug 13, 2024
    risk 0.49cvss 7.5epss 0.00

    IBM Common Licensing 9.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 297895.

Page 25 of 177