← Back

Ibm

ibm

8,250 CVEs • 1,572 products

Products (1,572)

Click to collapse
Toggle
Aix
aix
Db2
db2
Vios
vios
Websphere Mq
websphere_mq
Lotus Domino
lotus_domino
Api Connect
api_connect
Lotus Notes
lotus_notes
Concert
concert
I
i
Mq Appliance
mq_appliance
Mq
mq
Sametime
sametime
Aspera Faspex
aspera_faspex
Cics Tx
cics_tx
Connections
connections
Java
java
Domino
domino
Doors Next
doors_next

CVEs (8,250)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Websphere Application Server
Jun 17, 2026
Feb 24, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM WebSphere Application Server 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.2 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a mal...Show more
IBM WebSphere Application Server 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.2 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 213968.Show less
1Ibm
2Aix
Vios
Jun 17, 2026
Feb 24, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 213073.
1Ibm
2Aix
Vios
Jun 17, 2026
Feb 24, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 213072.
1Ibm
2Sterling External Authentication Server
Sterling Secure Proxy
Jun 17, 2026
Feb 23, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM Sterling External Authentication Server and IBM Sterling Secure Proxy 6.0.3.0, 6.0.2.0, and 3.4.3.2 could allow a remote user to consume resources causing a denial of service due to a resource leak. IBM X-Force ID: 2...Show more
IBM Sterling External Authentication Server and IBM Sterling Secure Proxy 6.0.3.0, 6.0.2.0, and 3.4.3.2 could allow a remote user to consume resources causing a denial of service due to a resource leak. IBM X-Force ID: 219395.Show less
1Ibm
2Sterling External Authentication Server
Sterling Secure Proxy
Jun 17, 2026
Feb 23, 2022
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
IBM Sterling Secure Proxy 6.0.3.0, 6.0.2.0, and 3.4.3.2 and IBM Sterling External Authentication Server are vulnerable a buffer overflow, due to the Jetty based GUI in the Secure Zone not properly validating the sizes of...Show more
IBM Sterling Secure Proxy 6.0.3.0, 6.0.2.0, and 3.4.3.2 and IBM Sterling External Authentication Server are vulnerable a buffer overflow, due to the Jetty based GUI in the Secure Zone not properly validating the sizes of the form content and/or HTTP headers submitted. A local attacker positioned inside the Secure Zone could submit a specially crafted HTTP request to disrupt service. IBM X-Force ID: 219133.Show less
1Ibm
1Planning Analytics
Jun 17, 2026
Feb 21, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
IBM Planning Analytics 2.0 is vulnerable to a Remote File Include (RFI) attack. User input could be passed into file include commands and the web application could be tricked into including remote files with malicious co...Show more
IBM Planning Analytics 2.0 is vulnerable to a Remote File Include (RFI) attack. User input could be passed into file include commands and the web application could be tricked into including remote files with malicious code. IBM X-Force ID: 216891.Show less
1Ibm
1Guardium Data Encryption
Jun 17, 2026
Feb 18, 2022
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
IBM Guardium Data Encryption (GDE) 5.0.0.2 and 5.0.0.3 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit thi...Show more
IBM Guardium Data Encryption (GDE) 5.0.0.2 and 5.0.0.3 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 213964.Show less
1Ibm
1Maximo Asset Management
Jun 17, 2026
Feb 18, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM Maximo Asset Management 7.6.1.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 210892.
1Ibm
1Mq
Jun 17, 2026
Feb 17, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM MQ 9.1 LTS is vulnerable to a denial of service attack caused by an issue within the channel process. IBM X-Force ID: 213964.
1Ibm
1Maximo Anywhere
Jun 17, 2026
Feb 16, 2022
N/A· v4
2.4 LOW· v3
2.1 LOW· v2
IBM Maximo Anywhere 7.6.4.0 applications could allow obfuscation of the application source code. IBM X-Force ID: 161494.
1Ibm
1Maximo Anywhere
Jun 17, 2026
Feb 16, 2022
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
IBM Maximo Anywhere 7.6.4.0 applications could disclose sensitive information to a user with physical access to the device. IBM X-Force ID: 161493.
1Ibm
1Maximo Anywhere
Jun 17, 2026
Feb 16, 2022
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
IBM Maximo Anywhere 7.6.4.0 could allow an attacker to reverse engineer the application due to the lack of binary protection precautions. IBM X-Force ID: 160697.
1Ibm
1Cognos Analytics Mobile
Jun 17, 2026
Feb 14, 2022
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
Due to weak obfuscation, IBM Cognos Analytics Mobile for Android application prior to version 1.1.14 , an attacker could be able to reverse engineer the codebase to gain knowledge about the programming technique, interfa...Show more
Due to weak obfuscation, IBM Cognos Analytics Mobile for Android application prior to version 1.1.14 , an attacker could be able to reverse engineer the codebase to gain knowledge about the programming technique, interface, class definitions, algorithms and functions used. IBM X-Force ID: 215593.Show less
1Ibm
1Cognos Analytics Mobile
Jun 17, 2026
Feb 14, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Cognos Analytics Mobile for Android applications prior to version 1.1.14 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the inten...Show more
IBM Cognos Analytics Mobile for Android applications prior to version 1.1.14 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 215592.Show less
1Ibm
3Power Hardware Management Console (7063 Cr2) Firmware
Power System Ac922 (8335 Gth) FirmwarePower System Ac922 (8335 Gtx) Firmware
Jun 17, 2026
Feb 4, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM OPENBMC OP920, OP930, and OP940 could allow an unauthenticated user to obtain sensitive information. IBM X-Force ID: 212047.
1Ibm
1Guardium Data Encryption
Jun 17, 2026
Feb 2, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM Guardium Data Encryption (GDE) 5.0.0.2 behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which could facilitate username enumeration....Show more
IBM Guardium Data Encryption (GDE) 5.0.0.2 behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which could facilitate username enumeration. IBM X-Force ID: 213856.Show less
1Ibm
2Security Verify Access
Security Verify Access Docker
Jun 17, 2026
Feb 2, 2022
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
IBM Security Verify Access 10.0.0.0, 10.0.1.0 and 10.0.2.0 with the advanced access control authentication service enabled could allow an attacker to authenticate as any user on the system. IBM X-Force ID: 215353.
1Ibm
1Financial Transaction Manager
Jun 17, 2026
Feb 2, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
IBM Financial Transaction Manager 3.2.4 does not invalidate session any existing session identifier gives an attacker the opportunity to steal authenticated sessions. IBM X-Force ID: 215040.
1Ibm
1Financial Transaction Manager
Jun 17, 2026
Feb 2, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
IBM Financial Transaction Manager 3.2.4 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force...Show more
IBM Financial Transaction Manager 3.2.4 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 214210.Show less
1Ibm
1Security Guardium Insights
Jun 17, 2026
Jan 26, 2022
N/A· v4
2.7 LOW· v3
4.0 MEDIUM· v2
IBM Security Guardium Insights 3.0 could allow an authenticated user to obtain sensitive information due to insufficient session expiration. IBM X-Force ID: 205256.