VYPR

Vendor CVEs

IBM

All CVEs

8,825 total · sorted by risk
  • CVE-2026-16926CriAug 20, 2026
    risk 0.59cvss 9.1epss 0.01

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to overwrite arbitrary files due to improper neutralization of special elements in input.

  • CVE-2026-15065CriAug 19, 2026
    risk 0.59cvss 9.1epss 0.01

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote attacker to bypass security restrictions due to the exposure of intermediate certificate authority private keys in a publicly available update file.

  • CVE-2026-19297CriAug 13, 2026
    risk 0.59cvss 9.1epss 0.00

    IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to improper restriction of excessive authentication attempts.

  • CVE-2026-14959CriJul 28, 2026
    risk 0.59cvss 9.1epss 0.01

    IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to shell command injection.

  • CVE-2026-14958CriJul 28, 2026
    risk 0.59cvss 9.1epss 0.01

    IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to unquoted shell interpolation.

  • CVE-2026-12628CriJun 22, 2026
    risk 0.59cvss 9.1epss 0.00

    IBM Storage Protect Client 8.1.0.0 through 8.2.1.0 and IBM Storage Protect Snapshot For Windows 8.1.0.0 through 8.2.1.0 could allow a remote attacker to bypass authentication due to the use of a hardcoded credential in the FlashCopy Manager (FCM) authentication mechanism. The…

  • CVE-2026-9319CriJun 1, 2026
    risk 0.59cvss 9.0epss 0.00

    IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of untrusted data via JAX-WS endpoints with WS-Security.

  • CVE-2026-9311CriJun 1, 2026
    risk 0.59cvss 9.0epss 0.01

    IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security controls.

  • CVE-2026-8644CriJun 1, 2026
    risk 0.59cvss 9.1epss 0.00

    IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing.

  • CVE-2026-7876CriMay 27, 2026
    risk 0.59cvss 9.1epss 0.00

    IBM Aspera HSTS for CP4I 1.5.1 through 1.5.19 is affected by an authentication bypass vulnerability. A transfer client may be able to take advantage of this vulnerability to access files in the server's local storage that they should not have access to, when specific…

  • CVE-2025-36096CriNov 13, 2025
    risk 0.59cvss 9.0epss 0.00

    IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 stores NIM private keys used in NIM environments in an insecure way which is susceptible to unauthorized access by an attacker using man in the middle techniques.

  • CVE-2025-36038CriJun 25, 2025
    risk 0.59cvss 9.0epss 0.09

    IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially crafted sequence of serialized objects.

  • CVE-2025-33117CriJun 19, 2025
    risk 0.59cvss 9.1epss 0.00

    IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 could allow a privileged user to modify configuration files that would allow the upload of a malicious autoupdate file to execute arbitrary commands.

  • CVE-2025-0159CriFeb 28, 2025
    risk 0.59cvss 9.1epss 0.01

    IBM FlashSystem (IBM Storage Virtualize (8.5.0.0 through 8.5.0.13, 8.5.1.0, 8.5.2.0 through 8.5.2.3, 8.5.3.0 through 8.5.3.1, 8.5.4.0, 8.6.0.0 through 8.6.0.5, 8.6.1.0, 8.6.2.0 through 8.6.2.1, 8.6.3.0, 8.7.0.0 through 8.7.0.2, 8.7.1.0, 8.7.2.0 through 8.7.2.1) could allow a…

  • CVE-2024-51450CriFeb 6, 2025
    risk 0.59cvss 9.1epss 0.01

    IBM Security Verify Directory 10.0.0 through 10.0.3 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.

  • CVE-2024-41783CriJan 19, 2025
    risk 0.59cvss 9.1epss 0.01

    IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow a privileged user to inject commands into the underlying operating system due to improper validation of a specified type of input.

  • CVE-2024-38337CriJan 19, 2025
    risk 0.59cvss 9.1epss 0.00

    IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow an unauthorized attacker to retrieve or alter sensitive information contents due to incorrect permission assignments.

  • CVE-2024-51466CriDec 20, 2024
    risk 0.59cvss 9.0epss 0.01

    IBM Cognos Analytics 11.2.0 through 11.2.4 FP4 and 12.0.0 through 12.0.4 is vulnerable to an Expression Language (EL) Injection vulnerability. A remote attacker could exploit this vulnerability to expose sensitive information, consume memory resources, and/or cause the server…

  • CVE-2024-3300CriMay 30, 2024
    risk 0.59cvss 9.0epss 0.03

    An unsafe .NET object deserialization vulnerability in DELMIA Apriso Release 2019 through Release 2024 could lead to pre-authentication remote code execution.

  • CVE-2023-47709CriMay 14, 2024
    risk 0.59cvss 9.1epss 0.01

    IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 271524.

  • CVE-2024-25029CriApr 6, 2024
    risk 0.59cvss 9.0epss 0.01

    IBM Personal Communications 14.0.6 through 15.0.1 includes a Windows service that is vulnerable to remote code execution (RCE) and local privilege escalation (LPE). The vulnerability allows any unprivileged user with network access to a target computer to run commands with full…

  • CVE-2024-22319HigFeb 2, 2024
    risk 0.59cvss 8.1epss 0.76

    IBM Operational Decision Manager 8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, 8.11.1 and 8.12.0.1 is susceptible to remote code execution attack via JNDI injection when passing an unchecked argument to a certain API. IBM X-Force ID: 279145.

  • CVE-2024-22317CriJan 18, 2024
    risk 0.59cvss 9.1epss 0.01

    IBM App Connect Enterprise 11.0.0.1 through 11.0.0.24 and 12.0.1.0 through 12.0.11.0 could allow a remote attacker to obtain sensitive information or cause a denial of service due to improper restriction of excessive authentication attempts. IBM X-Force ID: 279143.

  • CVE-2022-40747CriNov 3, 2022
    risk 0.59cvss 9.1epss 0.01

    "IBM InfoSphere Information Server 11.7 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 236584."

  • CVE-2022-22489CriAug 19, 2022
    risk 0.59cvss 9.1epss 0.02

    IBM MQ 8.0, (9.0, 9.1, 9.2 LTS), and (9.1 and 9.2 CD) are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 226339.

  • CVE-2022-31775CriAug 1, 2022
    risk 0.59cvss 9.1epss 0.01

    IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose…

  • CVE-2022-35643CriJul 29, 2022
    risk 0.59cvss 9.1epss 0.01

    IBM PowerVM VIOS 3.1 could allow a remote attacker to tamper with system configuration or cause a denial of service. IBM X-Force ID: 230956.

  • CVE-2020-4926CriMay 24, 2022
    risk 0.59cvss 9.1epss 0.01

    A vulnerability in the Spectrum Scale 5.1 core component and IBM Elastic Storage System 6.1 could allow unauthorized access to user data or injection of arbitrary data in the communication protocol. IBM X-Force ID: 191600.

  • CVE-2022-22374CriMar 24, 2022
    risk 0.59cvss 9.1epss 0.01

    The BMC (IBM Power 9 AC922 OP910, OP920, OP930, and OP940) may be subject to a firmware downgrade attack which may affect its ability to operate its host. IBM X-Force ID: 221442.

  • CVE-2021-39063CriDec 13, 2021
    risk 0.59cvss 9.1epss 0.01

    IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information due to a misconfiguration in access control headers. IBM X-Force ID: 214956.

  • CVE-2021-38917CriDec 10, 2021
    risk 0.59cvss 9.1epss 0.01

    IBM PowerVM Hypervisor FW860, FW940, and FW950 could allow an attacker that gains service access to the FSP can read and write arbitrary host system memory through a series of carefully crafted service procedures. IBM X-Force ID: 210018.

  • CVE-2021-38948CriNov 2, 2021
    risk 0.59cvss 9.1epss 0.02

    IBM InfoSphere Information Server 11.7 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 211402.

  • CVE-2021-38923CriOct 6, 2021
    risk 0.59cvss 9.1epss 0.01

    IBM PowerVM Hypervisor FW1010 could allow a privileged user to gain access to another VM due to assigning duplicate WWPNs. IBM X-Force ID: 210162.

  • CVE-2021-29715CriAug 26, 2021
    risk 0.59cvss 9.1epss 0.02

    IBM API Connect 5.0.0.0 through 5.0.8.11 could alllow a remote user to obtain sensitive information or conduct denial of serivce attacks due to open ports. IBM X-Force ID: 201018.

  • CVE-2021-20399CriJul 27, 2021
    risk 0.59cvss 9.1epss 0.02

    IBM Qradar SIEM 7.3.0 to 7.3.3 Patch 8 and 7.4.0 to 7.4.3 GA is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID:…

  • CVE-2020-5003CriJun 11, 2021
    risk 0.59cvss 9.1epss 0.02

    IBM Financial Transaction Manager 3.2.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 192956.

  • CVE-2021-20487CriMay 26, 2021
    risk 0.59cvss 9.1epss 0.01

    IBM Power9 Self Boot Engine(SBE) could allow a privileged user to inject malicious code and compromise the integrity of the host firmware bypassing the host firmware signature verification process.

  • CVE-2020-4670CriMay 17, 2021
    risk 0.59cvss 9.1epss 0.02

    IBM Planning Analytics Local 2.0 connects to a Redis server. The Redis server, an in-memory data structure store, running on the remote host is not protected by password authentication. A remote attacker can exploit this to gain unauthorized access to the server. IBM X-Force ID:…

  • CVE-2020-4669CriMay 17, 2021
    risk 0.59cvss 9.1epss 0.02

    IBM Planning Analytics Local 2.0 connects to a MongoDB server. MongoDB, a document-oriented database system, is listening on the remote port, and it is configured to allow connections without password authentication. A remote attacker can gain unauthorized access to the…

  • CVE-2021-20538CriMay 10, 2021
    risk 0.59cvss 9.1epss 0.01

    IBM Cloud Pak for Security (CP4S) 1.5.0.0 and 1.5.0.1 could allow a user to obtain sensitive information or perform actions they should not have access to due to incorrect authorization mechanisms. IBM X-Force ID: 198919.

  • CVE-2020-4899CriJan 5, 2021
    risk 0.59cvss 9.1epss 0.01

    IBM API Connect 5.0.0.0 through 5.0.8.10 could potentially leak sensitive information or allow for data corruption due to plain text transmission of sensitive information across the network. IBM X-Force ID: 190990.

  • CVE-2020-4627CriNov 30, 2020
    risk 0.59cvss 9.0epss 0.02

    IBM Cloud Pak for Security 1.3.0.1(CP4S) potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 185367.

  • CVE-2020-4377CriAug 3, 2020
    risk 0.59cvss 9.1epss 0.02

    IBM Cognos Anaytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 179156.

  • CVE-2019-4244CriDec 10, 2019
    risk 0.59cvss 9.1epss 0.02

    IBM SmartCloud Analytics 1.3.1 through 1.3.5 could allow a remote attacker to gain unauthorized information and unrestricted control over Zookeeper installations due to missing authentication. IBM X-Force ID: 159518.

  • CVE-2019-4169CriAug 26, 2019
    risk 0.59cvss 9.1epss 0.02

    IBM Open Power Firmware OP910 and OP920 could allow access to BMC via IPMI using default OpenBMC password even after BMC password was changed away from the default password. IBM X-Force ID: 158702.

  • CVE-2018-1969CriJan 14, 2019
    risk 0.59cvss 9.0epss 0.02

    IBM Security Identity Manager 6.0.0 allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment. IBM X-Force ID: 153750.

  • CVE-2014-0931CriApr 20, 2018
    risk 0.59cvss 9.1epss 0.02

    Multiple XML external entity (XXE) vulnerabilities in the (1) CCRC WAN Server / CM Server, (2) Perl CC/CQ integration trigger scripts, (3) CMAPI Java interface, (4) ClearCase remote client, and (5) CMI and OSLC-based ClearQuest integrations components in IBM Rational ClearCase…

  • CVE-2018-1383CriFeb 13, 2018
    risk 0.59cvss 9.1epss 0.02

    A software logic bug creates a vulnerability in an AIX 6.1, 7.1, and 7.2 daemon which could allow a user with root privileges on one system, to obtain root access on another machine. IBM X-force ID: 138117.

  • CVE-2017-1383CriAug 2, 2017
    risk 0.59cvss 9.1epss 0.02

    IBM InfoSphere Information Server 9.1, 11.3, and 11.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 127155.

  • CVE-2016-6111CriMar 31, 2017
    risk 0.59cvss 9.1epss 0.02

    IBM Curam Social Program Management 6.0 and 7.0 are vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all…

Page 6 of 177