← Back

Ibm

ibm

8,250 CVEs • 1,572 products

Products (1,572)

Click to collapse
Toggle
Aix
aix
Db2
db2
Vios
vios
Websphere Mq
websphere_mq
Lotus Domino
lotus_domino
Api Connect
api_connect
Lotus Notes
lotus_notes
Concert
concert
I
i
Mq Appliance
mq_appliance
Mq
mq
Sametime
sametime
Aspera Faspex
aspera_faspex
Cics Tx
cics_tx
Connections
connections
Java
java
Domino
domino
Doors Next
doors_next

CVEs (8,250)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Terracotta
Jun 17, 2026
Oct 15, 2025
N/A· v4
3.7 LOW· v3
N/A· v2
Applications using affected versions of Ehcache 3.x can experience degraded cache-write performance if the application using Ehcache utilizes keys sourced from (malicious) external parties in an unfiltered/unsalted way.
1Ibm
1Content Navigator
Jun 17, 2026
Oct 14, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
IBM Content Navigator 3.0.11, 3.0.15, 3.1.0, and 3.2.0 could expose the directory listing of the application upon using an application URL. Application files and folders are visible in the browser to a user; however, the...Show more
IBM Content Navigator 3.0.11, 3.0.15, 3.1.0, and 3.2.0 could expose the directory listing of the application upon using an application URL. Application files and folders are visible in the browser to a user; however, the contents of the files cannot be read obtained or modified.Show less
1Ibm
2Security Verify Access
Verify Identity Access
Jun 17, 2026
Oct 13, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
IBM Security Verify Access 10.0.0 through 10.0.9, 11.0.0, IBM Verify Identity Access Container 10.0.0 through 10.0.9, and 11.0.0, under certain configurations, contains hard-coded credentials, such as a password or crypt...Show more
IBM Security Verify Access 10.0.0 through 10.0.9, 11.0.0, IBM Verify Identity Access Container 10.0.0 through 10.0.9, and 11.0.0, under certain configurations, contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.Show less
1Ibm
1Engineering Requirements Management Doors Next
Jun 17, 2026
Oct 12, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user to cause a denial of service by uploading specially crafted files using uncontrolled recursion.
1Ibm
1Engineering Requirements Management Doors Next
Jun 17, 2026
Oct 12, 2025
N/A· v4
5.7 MEDIUM· v3
N/A· v2
IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the network to spoof email identity of the sender due to improper verification of source data.
1Ibm
1Engineering Requirements Management Doors Next
Jun 17, 2026
Oct 12, 2025
N/A· v4
3.5 LOW· v3
N/A· v2
IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the network to delete reviews from other users due to client-side enforcement of server-side security.
1Ibm
1Engineering Requirements Management Doors Next
Jun 17, 2026
Oct 12, 2025
N/A· v4
3.5 LOW· v3
N/A· v2
IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the network to delete comments from other users due to client-side enforcement of server-side security.
1Ibm
1Aspera Faspex
Jun 17, 2026
Oct 9, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
IBM Aspera 5.0.0 through 5.0.13.1 could disclose sensitive user information from the system to an authenticated user due to an observable discrepancy of returned data.
1Ibm
1Aspera Faspex
Jun 17, 2026
Oct 9, 2025
N/A· v4
4.9 MEDIUM· v3
N/A· v2
IBM Aspera Faspex 5.0.0 through 5.0.13.1 could allow a privileged user to cause a denial of service from improperly validated API input due to excessive resource consumption.
1Ibm
1Aspera Faspex
Jun 17, 2026
Oct 9, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
IBM Aspera Faspex 5.0.0 through 5.0.13.1 uses a cross-domain policy file that includes domains that should not be trusted.
1Ibm
1Infosphere Data Replication Vsam For Z/os Remote Source
Jun 17, 2026
Oct 7, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
IBM InfoSphere Data Replication VSAM for z/OS Remote Source 11.4 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local user with access to the files storing CECSUB or CECRM on the co...Show more
IBM InfoSphere Data Replication VSAM for z/OS Remote Source 11.4 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local user with access to the files storing CECSUB or CECRM on the container could overflow the buffer and execute arbitrary code on the system.Show less
1Ibm
1Jazz Foundation
Jun 17, 2026
Oct 7, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
IBM Engineering Requirements Management DOORS Next (IBM Jazz Foundation 7.0.2 to 7.0.2 iFix034, 7.0.3 to 7.0.3 iFix016, and 7.1.0 to 7.1.0 iFix004) is vulnerable to stored cross-site scripting. This vulnerability allows...Show more
IBM Engineering Requirements Management DOORS Next (IBM Jazz Foundation 7.0.2 to 7.0.2 iFix034, 7.0.3 to 7.0.3 iFix016, and 7.1.0 to 7.1.0 iFix004) is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users on the host network to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.Show less
1Ibm
4Security Verify Access
Security Verify Access DockerVerify Identity Access+1 more
Jun 17, 2026
Oct 6, 2025
N/A· v4
9.3 CRITICAL· v3
N/A· v2
IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 could allow a locally authenticated user to escalate their privileges to root due to execution with...Show more
IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 could allow a locally authenticated user to escalate their privileges to root due to execution with more privileges than required.Show less
1Ibm
4Security Verify Access
Security Verify Access DockerVerify Identity Access+1 more
Jun 17, 2026
Oct 6, 2025
N/A· v4
8.5 HIGH· v3
N/A· v2
IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 could allow a locally authenticated user to execute malicious scripts from outside of its control...Show more
IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 could allow a locally authenticated user to execute malicious scripts from outside of its control sphere.Show less
1Ibm
4Security Verify Access
Security Verify Access DockerVerify Identity Access+1 more
Jun 17, 2026
Oct 6, 2025
N/A· v4
7.3 HIGH· v3
N/A· v2
IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 could allow an unauthenticated user to execute arbitrary commands with lower user privileges on...Show more
IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 could allow an unauthenticated user to execute arbitrary commands with lower user privileges on the system due to improper validation of user supplied input.Show less
1Ibm
1Transformation Extender Advanced
Jun 17, 2026
Oct 6, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
IBM Standards Processing Engine 10.0.1.10 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe java deserialization. By sending specially crafted input, an attacker could exploit thi...Show more
IBM Standards Processing Engine 10.0.1.10 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe java deserialization. By sending specially crafted input, an attacker could exploit this vulnerability to execute arbitrary code on the system.Show less
1Ibm
1Transformation Extender Advanced
Jun 17, 2026
Oct 1, 2025
N/A· v4
6.2 MEDIUM· v3
N/A· v2
IBM Transformation Extender Advanced 10.0.1 could allow a local user to perform unauthorized actions due to improper access controls.
1Ibm
1Transformation Extender Advanced
Jun 17, 2026
Oct 1, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
IBM Transformation Extender Advanced 10.0.1 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
1Ibm
1Transformation Extender Advanced
Jun 17, 2026
Oct 1, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
IBM Transformation Extender Advanced 10.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.
1Ibm
1Transformation Extender Advanced
Jun 17, 2026
Oct 1, 2025
N/A· v4
4.4 MEDIUM· v3
N/A· v2
IBM Transformation Extender Advanced 10.0.1 stores potentially sensitive information in log files that could be read by a local user.