Skip to main content

Vendor archive

ibm CVEs

Beta · best-effort

8,230 CVEs tagged to vendor ibm584 Critical, 1,727 High, 5,176 Medium, 743 Low, 0 Unrated.

CVE-2025-36226

Published Mar 10, 2026

IBM Aspera Faspex 5 5.0.0 through 5.0.14.3 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-1713

Published Mar 3, 2026

IBM MQ 9.1.0.0 through 9.1.0.33 LTS, 9.2.0.0 through 9.2.0.40 LTS, 9.3.0.0 through 9.3.0.36 LTS, 9.30.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.17 LTS, and 9.4.0.0 through 9.4.4…

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-1567

Published Mar 3, 2026

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 An XML External Entity (XXE) vulnerability in IBM InfoSphere Information Server could allow attackers to retrieve sensi…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-14480

Published Mar 3, 2026

IBM Aspera faspio Gateway 1.3.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-13688

Published Mar 3, 2026

IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper v…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-13687

Published Mar 3, 2026

IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper v…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-13686

Published Mar 3, 2026

IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper v…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-2606

Published Mar 3, 2026

IBM webMethods API Gateway (on-prem) 10.11 through 10.11_Fix3210.15 to 10.15_Fix2711.1 to 11.1_Fix7 IBM webMethods API Management (on-prem) fails to properly validate user-supplie…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-1265

Published Mar 3, 2026

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to writing of sensitive Information in a log file.

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-36364

Published Mar 3, 2026

IBM DevOps Plan 3.0.0 through 3.0.5 allows web page cache to be stored locally which can be read by another user on the system.

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-36363

Published Mar 3, 2026

IBM DevOps Plan 3.0.0 through 3.0.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-14923

Published Mar 3, 2026

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.2 IBM WebSphere Application Server Liberty could provide weaker than expected security when using the Security U…

CVSS 4.7 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-14604

Published Mar 3, 2026

IBM Storage Scale IBM S through rage Scale 5.2.3.0 - 5.2.3.5, and IBM S through rage Scale 6.0.0.0 - 6.0.0.1 could allow a local user to unintentionally trigger additional permiss…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-13616

Published Mar 3, 2026

IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 returns sensitive information in an HTTP response that could be used in further attacks against the system.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-13689

Published Feb 17, 2026

IBM DataStage on Cloud Pak for Data could allow an authenticated user to execute arbitrary commands and gain access to sensitive information due to unrestricted file uploads.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-36183

Published Feb 17, 2026

IBM watsonx.data 2.2 through 2.2.1 IBM Lakehouse could allow a privileged user to upload malicious files that could be executed server to modify limited files or data.

CVSS 3.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-33088

Published Feb 17, 2026

IBM Concert 1.0.0 through 2.1.0 could allow a local user with specific knowledge about the system's architecture to escalate their privileges due to incorrect file permissions for…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort
Showing 201-225 of 8,230 CVEsPage 9 of 330