← Back

Ibm

ibm

8,252 CVEs • 1,572 products

Products (1,572)

Click to collapse
Toggle
Aix
aix
Db2
db2
Vios
vios
Websphere Mq
websphere_mq
Lotus Domino
lotus_domino
Api Connect
api_connect
Lotus Notes
lotus_notes
Concert
concert
I
i
Mq Appliance
mq_appliance
Mq
mq
Sametime
sametime
Aspera Faspex
aspera_faspex
Cics Tx
cics_tx
Connections
connections
Java
java
Domino
domino
Doors Next
doors_next

CVEs (8,252)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Security Access Manager
Jun 17, 2026
Jun 25, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBM Security Access Manager 9.0.1 through 9.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially...Show more
IBM Security Access Manager 9.0.1 through 9.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 158573.Show less
1Ibm
1Security Access Manager
Jun 17, 2026
Jun 25, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
IBM Security Access Manager 9.0.1 through 9.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 158572.
1Ibm
1Security Access Manager
Jun 17, 2026
Jun 25, 2019
N/A· v4
6.8 MEDIUM· v3
3.5 LOW· v2
IBM Security Access Manager 9.0.1 through 9.0.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker co...Show more
IBM Security Access Manager 9.0.1 through 9.0.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 158517.Show less
1Ibm
1Security Access Manager
Jun 17, 2026
Jun 25, 2019
N/A· v4
4.4 MEDIUM· v3
3.6 LOW· v2
IBM Security Access Manager 9.0.1 through 9.0.6 does not invalidate session tokens in a timely manner. The lack of proper session expiration may allow attackers with local access to login into a closed browser session. I...Show more
IBM Security Access Manager 9.0.1 through 9.0.6 does not invalidate session tokens in a timely manner. The lack of proper session expiration may allow attackers with local access to login into a closed browser session. IBM X-Force ID: 158515.Show less
1Ibm
1Security Access Manager
Jun 17, 2026
Jun 25, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
IBM Security Access Manager 9.0.1 through 9.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 158512.
1Ibm
1Security Access Manager
Jun 17, 2026
Jun 25, 2019
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
IBM Security Access Manager 9.0.1 through 9.0.6 does not validate, or incorrectly validates, a certificate which could allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack. IBM X-Force I...Show more
IBM Security Access Manager 9.0.1 through 9.0.6 does not validate, or incorrectly validates, a certificate which could allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack. IBM X-Force ID: 158510.Show less
1Ibm
1Security Access Manager
Jun 17, 2026
Jun 25, 2019
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
IBM Security Access Manager 9.0.1 through 9.0.6 could reveal highly sensitive in specialized conditions to a local user which could be used in further attacks against the system. IBM X-Force ID: 158400.
1Ibm
1Security Access Manager
Jun 17, 2026
Jun 25, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
IBM Security Access Manager 9.0.1 through 9.0.6 is affected by a security vulnerability that could allow authenticated users to impersonate other users. IBM X-Force ID: 158331.
1Ibm
1Api Connect
Nov 21, 2024
Jun 25, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM API Connect 2018.1 through 2018.4.1.5 could disclose sensitive information to an unauthorized user that could aid in further attacks against the system. IBM X-Force ID: 155193.
1Ibm
1Api Connect
Nov 21, 2024
Jun 25, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM API Connect 2018.1 through 2018.4.1.5 could allow an attacker to obtain sensitive information from a specially crafted HTTP request that could aid an attacker in further attacks against the system. IBM X-Force ID: 15...Show more
IBM API Connect 2018.1 through 2018.4.1.5 could allow an attacker to obtain sensitive information from a specially crafted HTTP request that could aid an attacker in further attacks against the system. IBM X-Force ID: 155150.Show less
1Ibm
1Api Connect
Nov 21, 2024
Jun 25, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
IBM API Connect 5.0.0.0 through 5.0.8.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force...Show more
IBM API Connect 5.0.0.0 through 5.0.8.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 151256.Show less
1Ibm
1Spectrum Protect Plus
Jun 17, 2026
Jun 19, 2019
N/A· v4
6.5 MEDIUM· v3
2.1 LOW· v2
IBM Spectrum Protect Plus 10.1.2 may display the vSnap CIFS password in the IBM Spectrum Protect Plus Joblog. This can result in an attacker gaining access to sensitive information as well as vSnap. IBM X-Force ID: 16217...Show more
IBM Spectrum Protect Plus 10.1.2 may display the vSnap CIFS password in the IBM Spectrum Protect Plus Joblog. This can result in an attacker gaining access to sensitive information as well as vSnap. IBM X-Force ID: 162173.Show less
1Ibm
1Campaign
Jun 17, 2026
Jun 19, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Campaign 9.1.2 and 10.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the...Show more
IBM Campaign 9.1.2 and 10.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 162172.Show less
1Ibm
10Control Desk
Maximo Asset ManagementMaximo For Aviation+7 more
Jun 17, 2026
Jun 19, 2019
N/A· v4
8.0 HIGH· v3
8.5 HIGH· v2
IBM Maximo Asset Management 7.6 is vulnerable to CSV injection, which could allow a remote authenticated attacker to execute arbirary commands on the system. IBM X-Force ID: 161680.
1Ibm
10Control Desk
Maximo Asset ManagementMaximo For Aviation+7 more
Jun 17, 2026
Jun 19, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cred...Show more
IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 160949.Show less
1Ibm
1Marketing Platform
Nov 21, 2024
Jun 19, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Marketing Platform 9.1.0, 9.1.2, 10.0, and 10.1 exposes sensitive information in the headers that could be used by an authenticated attacker in further attacks against the system. IBM X-Force ID: 120906.
1Ibm
1Cloud Private
Jun 17, 2026
Jun 18, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
IBM Cloud Private 2.1.0, 3.1.0, 3.1.1, and 3.1.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IB...Show more
IBM Cloud Private 2.1.0, 3.1.0, 3.1.1, and 3.1.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 158338.Show less
1Ibm
1Cognos Controller
Jun 17, 2026
Jun 17, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 158882.
1Ibm
1Cognos Controller
Jun 17, 2026
Jun 17, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 could allow a remote attacker to bypass security restrictions, caused by an error related to insecure HTTP Methods. An attacker could exploit this vulnerab...Show more
IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 could allow a remote attacker to bypass security restrictions, caused by an error related to insecure HTTP Methods. An attacker could exploit this vulnerability to gain access to the system. IBM X-Force ID: 158881.Show less
1Ibm
1Cognos Controller
Jun 17, 2026
Jun 17, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 158879.