VYPR

Vendor CVEs

IBM

All CVEs

8,825 total · sorted by risk
  • CVE-2017-1196CriJun 7, 2017
    risk 0.64cvss 9.8epss 0.01

    IBM BigFix Compliance (TEMA SUAv1 SCA SCM) 1.9.70 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 123671.

  • CVE-2016-6087CriJun 7, 2017
    risk 0.64cvss 9.8epss 0.02

    IBM Domino 8.5 and 9.0 could allow an attacker to steal credentials using multiple sessions and large amounts of data using Domino TLS Key Exchange validation. IBM X-Force ID: 117918.

  • CVE-2016-0360CriFeb 15, 2017
    risk 0.64cvss 9.8epss 0.02

    IBM Websphere MQ JMS 7.0.1, 7.1, 7.5, 8.0, and 9.0 client provides classes that deserialize objects from untrusted sources which could allow a malicious user to execute arbitrary Java code by adding vulnerable classes to the classpath. IBM Reference #: 1983457.

  • CVE-2016-9005CriFeb 8, 2017
    risk 0.64cvss 9.8epss 0.02

    IBM System Storage TS3100-TS3200 Tape Library could allow an unauthenticated user with access to the company network, to change a user's password and gain remote access to the system.

  • CVE-2016-8954CriFeb 8, 2017
    risk 0.64cvss 9.8epss 0.02

    IBM dashDB Local uses hard-coded credentials that could allow a remote attacker to gain access to the Docker container or database.

  • CVE-2016-6095CriFeb 2, 2017
    risk 0.64cvss 9.8epss 0.01

    IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.

  • CVE-2016-6090CriFeb 1, 2017
    risk 0.64cvss 9.8epss 0.02

    IBM WebSphere Commerce contains an unspecified vulnerability that could allow disclosure of user personal data, performing of unauthorized administrative operations, and potentially causing a denial of service.

  • CVE-2016-5964CriFeb 1, 2017
    risk 0.64cvss 9.8epss 0.01

    IBM Security Privileged Identity Manager Virtual Appliance version 2.0.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.

  • CVE-2016-2944CriNov 30, 2016
    risk 0.64cvss 9.8epss 0.01

    IBM BigFix Remote Control before 9.1.3 does not properly restrict failed login attempts, which makes it easier for remote attackers to obtain access via a brute-force approach.

  • CVE-2016-0391CriJul 2, 2016
    risk 0.64cvss 9.8epss 0.01

    The IBM Watson Developer Cloud services on Bluemix platforms do not properly generate random numbers for service-instance credentials, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack.

  • CVE-2016-0224CriJun 28, 2016
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in IBM Marketing Platform 8.5.x, 8.6.x, and 9.x before 9.1.2.2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2015-8522CriApr 5, 2016
    risk 0.64cvss 9.8epss 0.03

    Buffer overflow in the server in IBM Tivoli Storage Manager FastBack 5.5.x and 6.x before 6.1.12.2 allows remote attackers to execute arbitrary code via a crafted command, a different vulnerability than CVE-2015-8519, CVE-2015-8520, and CVE-2015-8521.

  • CVE-2015-8521CriApr 5, 2016
    risk 0.64cvss 9.8epss 0.03

    Buffer overflow in the server in IBM Tivoli Storage Manager FastBack 5.5.x and 6.x before 6.1.12.2 allows remote attackers to execute arbitrary code via a crafted command, a different vulnerability than CVE-2015-8519, CVE-2015-8520, and CVE-2015-8522.

  • CVE-2015-8520CriApr 5, 2016
    risk 0.64cvss 9.8epss 0.03

    Buffer overflow in the server in IBM Tivoli Storage Manager FastBack 5.5.x and 6.x before 6.1.12.2 allows remote attackers to execute arbitrary code via a crafted command, a different vulnerability than CVE-2015-8519, CVE-2015-8521, and CVE-2015-8522.

  • CVE-2015-8519CriApr 5, 2016
    risk 0.64cvss 9.8epss 0.03

    Buffer overflow in the server in IBM Tivoli Storage Manager FastBack 5.5.x and 6.x before 6.1.12.2 allows remote attackers to execute arbitrary code via a crafted command, a different vulnerability than CVE-2015-8520, CVE-2015-8521, and CVE-2015-8522.

  • CVE-2016-0216CriFeb 29, 2016
    risk 0.64cvss 9.8epss 0.02

    Stack-based buffer overflow in IBM Tivoli Storage Manager FastBack 5.5 and 6.1.x through 6.1.11.1 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, a different vulnerability than CVE-2016-0212 and CVE-2016-0213.

  • CVE-2016-0213CriFeb 29, 2016
    risk 0.64cvss 9.8epss 0.02

    Stack-based buffer overflow in IBM Tivoli Storage Manager FastBack 5.5 and 6.1.x through 6.1.11.1 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, a different vulnerability than CVE-2016-0212 and CVE-2016-0216.

  • CVE-2016-0212CriFeb 29, 2016
    risk 0.64cvss 9.8epss 0.02

    Stack-based buffer overflow in IBM Tivoli Storage Manager FastBack 5.5 and 6.1.x through 6.1.11.1 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, a different vulnerability than CVE-2016-0213 and CVE-2016-0216.

  • CVE-2015-0192CriJul 2, 2015
    risk 0.64cvss 9.8epss 0.04

    Unspecified vulnerability in IBM Java 8 before SR1, 7 R1 before SR2 FP11, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 FP10 allows remote attackers to gain privileges via unknown vectors related to the Java Virtual Machine.

  • CVE-2023-27290CriMar 3, 2023
    risk 0.63cvss 9.1epss 0.09

    Docker based datastores for IBM Instana (IBM Observability with Instana 239-0 through 239-2, 241-0 through 241-2, and 243-0) do not currently require authentication. Due to this, an attacker within the network could access the datastores with read/write access. IBM X-Force ID: …

  • CVE-2020-4280HigOct 8, 2020
    risk 0.63cvss 8.8epss 0.73

    IBM QRadar SIEM 7.3 and 7.4 could allow a remote attacker to execute arbitrary commands on the system, caused by insecure deserialization of user-supplied content by the Java deserialization function. By sending a malicious serialized Java object, an attacker could exploit this…

  • CVE-2020-4241HigMar 31, 2020
    risk 0.63cvss 8.8epss 0.66

    IBM Spectrum Scale and IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on…

  • CVE-2019-4013CriApr 10, 2019
    risk 0.63cvss 9.0epss 0.13

    IBM BigFix Platform 9.5 could allow any authenticated user to upload any file to any location on the server with root privileges. This results in code execution on underlying system with root privileges. IBM X-Force ID: 155887.

  • CVE-2026-16903CriAug 19, 2026
    risk 0.62cvss 9.6epss 0.00

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code or cause a denial of service due to an out-of-bounds write.

  • CVE-2026-16835CriAug 19, 2026
    risk 0.62cvss 9.6epss 0.00

    IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the FSP management network protocol. An unauthenticated attacker on the management network can bypass authentication…

  • CVE-2026-16687CriAug 19, 2026
    risk 0.62cvss 9.6epss 0.00

    IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the ASMI web interface. An unauthenticated attacker with network access can send the FSP a malformed request, allowing…

  • CVE-2026-17276CriAug 12, 2026
    risk 0.62cvss 9.6epss 0.00

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to escalate privileges due to improper authorization in the handling of high-authority threads.

  • CVE-2026-10140CriJun 30, 2026
    risk 0.62cvss 9.6epss 0.00

    IBM Langflow OSS 1.0.0 through 1.10.0 voice mode contains improper shared-state handling that allows reuse of API clients across tenant boundaries. An authenticated attacker can manipulate cache state to cause requests from other users to be processed using incorrect upstream…

  • CVE-2025-36251CriNov 13, 2025
    risk 0.62cvss 9.6epss 0.01

    IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 nimsh service SSL/TLS implementations could allow a remote attacker to execute arbitrary commands due to improper process controls. This addresses additional attack vectors for a vulnerability that was previously addressed in…

  • CVE-2025-25022CriJun 3, 2025
    risk 0.62cvss 9.6epss 0.00

    IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow an unauthenticated user in the environment to obtain highly sensitive information in configuration files.

  • CVE-2024-56347CriMar 18, 2025
    risk 0.62cvss 9.6epss 0.01

    IBM AIX 7.2 and 7.3 nimsh service SSL/TLS protection mechanisms could allow a remote attacker to execute arbitrary commands due to improper process controls.

  • CVE-2020-4888HigJan 28, 2021
    risk 0.62cvss 8.8epss 0.62

    IBM QRadar SIEM 7.4.0 to 7.4.2 Patch 1 and 7.3.0 to 7.3.3 Patch 7 could allow a remote attacker to execute arbitrary commands on the system, caused by insecure deserialization of user-supplied content by the Java deserialization function. By sending a malicious serialized Java…

  • CVE-2026-16839CriAug 19, 2026
    risk 0.61cvss 9.4epss 0.01

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information due to an integer underflow in the IPv4 IP-options parser.

  • CVE-2026-14525CriAug 13, 2026
    risk 0.61cvss 9.4epss 0.01

    IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is vulnerable to an authentication bypass when the rtcomm-1.0 or rtcommGateway-1.0 feature is enabled.

  • CVE-2024-49806CriNov 29, 2024
    risk 0.61cvss 9.4epss 0.00

    IBM Security Verify Access Appliance 10.0.0 through 10.0.8 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.

  • CVE-2024-49805CriNov 29, 2024
    risk 0.61cvss 9.4epss 0.00

    IBM Security Verify Access Appliance 10.0.0 through 10.0.8 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.

  • CVE-2017-1274HigApr 25, 2017
    risk 0.61cvss 8.8epss 0.05

    IBM Domino 8.5.3, and 9.0 is vulnerable to a stack based overflow in the IMAP service that could allow an authenticated attacker to execute arbitrary code by specifying a large mailbox name. IBM X-Force ID: 124749.

  • CVE-2015-0104HigApr 24, 2017
    risk 0.61cvss 8.8epss 0.07

    IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration Management Database 7.1 through 7.1.1.8 and 7.2 and Maximo Asset Management and Maximo Industry Solutions 7.1 through 7.1.1.8, 7.5 before 7.5.0.7 IFIX003, and 7.6 before 7.6.0.0…

  • CVE-2013-3993MedKEVJul 7, 2014
    risk 0.61cvss 6.5epss 0.05

    IBM InfoSphere BigInsights before 2.1.0.3 allows remote authenticated users to bypass intended file and directory restrictions, or access untrusted data or code, via crafted parameters in unspecified API calls.

  • CVE-2026-17422CriAug 20, 2026
    risk 0.60cvss 9.3epss 0.00

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a buffer overflow.

  • CVE-2026-16822CriAug 19, 2026
    risk 0.60cvss 9.3epss 0.00

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to impersonate the TNC policy server and modify traffic due to improper certificate validation.

  • CVE-2026-17181CriAug 14, 2026
    risk 0.60cvss 9.3epss 0.01

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write files to arbitrary locations due to path traversal.

  • CVE-2026-11707CriJul 30, 2026
    risk 0.60cvss 9.3epss 0.00

    IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-site scripting vulnerability in the administrative console login page.

  • CVE-2026-14973CriJul 28, 2026
    risk 0.60cvss 9.3epss 0.00

    IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination.

  • CVE-2026-1346CriApr 8, 2026
    risk 0.60cvss 9.3epss 0.00

    IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 could allow a locally authenticated user to escalate…

  • CVE-2025-36356CriOct 6, 2025
    risk 0.60cvss 9.3epss 0.00

    IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 could allow a locally authenticated user to escalate their privileges to root due to execution with more privileges than required.

  • CVE-2025-1950CriApr 22, 2025
    risk 0.60cvss 9.3epss 0.00

    IBM Hardware Management Console - Power Systems V10.2.1030.0 and V10.3.1050.0 could allow a local user to execute commands locally due to improper validation of libraries of an untrusted source.

  • CVE-2023-30438CriMay 17, 2023
    risk 0.60cvss 9.3epss 0.00

    An internally discovered vulnerability in PowerVM on IBM Power9 and Power10 systems could allow an attacker with privileged user access to a logical partition to perform an undetected violation of the isolation between logical partitions which could lead to data leakage or the…

  • CVE-2015-5073CriDec 13, 2016
    risk 0.60cvss 9.1epss 0.07

    Heap-based buffer overflow in the find_fixedlength function in pcre_compile.c in PCRE before 8.38 allows remote attackers to cause a denial of service (crash) or obtain sensitive information from heap memory and possibly bypass the ASLR protection mechanism via a crafted regular…

  • CVE-2015-2023HigJan 2, 2016
    risk 0.60cvss 8.8epss 0.01

    Buffer overflow in IBM i Access 7.1 on Windows allows local users to gain privileges via unspecified vectors.

Page 5 of 177