← Back

Ibm

ibm

8,252 CVEs • 1,572 products

Products (1,572)

Click to collapse
Toggle
Aix
aix
Db2
db2
Vios
vios
Websphere Mq
websphere_mq
Lotus Domino
lotus_domino
Api Connect
api_connect
Lotus Notes
lotus_notes
Concert
concert
I
i
Mq Appliance
mq_appliance
Mq
mq
Sametime
sametime
Aspera Faspex
aspera_faspex
Cics Tx
cics_tx
Connections
connections
Java
java
Domino
domino
Doors Next
doors_next

CVEs (8,252)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Websphere Commerce
Nov 21, 2024
Oct 24, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM WebSphere Commerce Enterprise V7, V8, and V9 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentiall...Show more
IBM WebSphere Commerce Enterprise V7, V8, and V9 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142596.Show less
1Ibm
1Security Access Manager
Nov 21, 2024
Oct 22, 2018
N/A· v4
7.5 HIGH· v3
8.5 HIGH· v2
IBM Security Access Manager Appliance 9.0.3.1, 9.0.4.0 and 9.0.5.0 could allow unauthorized administration operations when Advanced Access Control services are running. IBM X-Force ID: 150998.
1Ibm
2Flashsystem 840 Firmware
Flashsystem 900 Firmware
Nov 21, 2024
Oct 18, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
IBM FlashSystem 900 product GUI allows a specially crafted attack to bypass the authentication requirements of the system, resulting in the ability to remotely change the superuser password. This can be used by an attack...Show more
IBM FlashSystem 900 product GUI allows a specially crafted attack to bypass the authentication requirements of the system, resulting in the ability to remotely change the superuser password. This can be used by an attacker to gain administrative control or to deny service. IBM X-Force ID: 150296.Show less
1Ibm
2Infosphere Information Server
Infosphere Information Server On Cloud
Nov 21, 2024
Oct 18, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
IBM InfoSphere Information Server 11.7 is affected by a weak password encryption vulnerability that could allow a local user to obtain highly sensitive information. IBM X-Force ID: 141682.
1Ibm
1Websphere Application Server
Nov 21, 2024
Oct 16, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality pot...Show more
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148800.Show less
1Ibm
1Security Key Lifecycle Manager
Nov 21, 2024
Oct 15, 2018
N/A· v4
7.1 HIGH· v3
5.5 MEDIUM· v2
IBM Security Key Lifecycle Manager 2.5, 2.6, 2.7, and 3.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive inf...Show more
IBM Security Key Lifecycle Manager 2.5, 2.6, 2.7, and 3.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 148428.Show less
1Ibm
1Security Key Lifecycle Manager
Nov 21, 2024
Oct 15, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
IBM Security Key Lifecycle Manager 2.5, 2.6, 2.7, and 3.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../)...Show more
IBM Security Key Lifecycle Manager 2.5, 2.6, 2.7, and 3.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 148423.Show less
1Ibm
1Filenet Content Manager
Nov 21, 2024
Oct 12, 2018
N/A· v4
7.1 HIGH· v3
5.5 MEDIUM· v2
IBM FileNet Content Manager 5.2.1 and 5.5.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or co...Show more
IBM FileNet Content Manager 5.2.1 and 5.5.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 150904.Show less
1Ibm
1Websphere Application Server
Nov 21, 2024
Oct 12, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to...Show more
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 148686.Show less
1Ibm
1Engineering Lifecycle Optimization Publishing
Mar 25, 2025
Oct 12, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Rational Publishing Engine 6.0.5 and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially...Show more
IBM Rational Publishing Engine 6.0.5 and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142432.Show less
1Ibm
1Engineering Lifecycle Optimization Publishing
Mar 25, 2025
Oct 12, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Rational Publishing Engine 6.0.5 and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially...Show more
IBM Rational Publishing Engine 6.0.5 and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142431.Show less
1Ibm
1Websphere Application Server
Nov 21, 2024
Oct 12, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
IBM WebSphere Application Server 8.5 and 9.0 in IBM Cloud could allow a remote attacker to obtain sensitive information caused by improper handling of passwords. IBM X-Force ID: 150811.
1Ibm
1Websphere Portal
Nov 21, 2024
Oct 12, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially lea...Show more
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 145108.Show less
1Ibm
1Bigfix Platform
Nov 21, 2024
Oct 12, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
IBM BigFix Platform 9.5 - 9.5.9 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 123910.
1Ibm
1Security Key Lifecycle Manager
Nov 21, 2024
Oct 11, 2018
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
IBM Security Key Lifecycle Manager 2.7 and 3.0 could allow an unauthenticated user to restart the SKLM server due to missing authentication. IBM X-Force ID: 148424.
1Ibm
1Security Key Lifecycle Manager
Nov 21, 2024
Oct 11, 2018
N/A· v4
7.1 HIGH· v3
5.5 MEDIUM· v2
IBM Security Key Lifecycle Manager 2.6, 2.7, 3.0 could allow an authenticated user to obtain highly sensitive information or jeopardize system integrity due to improper authentication mechanisms. IBM X-Force ID: 147907.
1Ibm
1Spectrum Lsf
Nov 21, 2024
Oct 11, 2018
N/A· v4
5.3 MEDIUM· v3
4.6 MEDIUM· v2
IBM Spectrum LSF 9.1.1 9.1.2, 9.1.3, and 10.1 could allow a local user to change their job user at job submission time due to improper file permission settings. IBM X-Force ID: 147439.
1Ibm
2Platform Symphony
Specturm Symphony
Nov 21, 2024
Oct 11, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
IBM Spectrum Symphony 7.1.2 and 7.2.0.2 could allow an authenticated user to obtain sensitive user information such as passwords through the WebUI. IBM X-Force ID: 146343.
1Ibm
1Spectrum Symphony
Nov 21, 2024
Oct 11, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Spectrum Symphony 7.2.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to creden...Show more
IBM Spectrum Symphony 7.2.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 146341.Show less
1Ibm
2Qlogic 20 Port 4/8 Gb San Switch Module Firmware
Qlogic 4 Gb Fibre Channel Expansion Card Firmware
Nov 21, 2024
Oct 10, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
The QLogic 4Gb Fibre Channel 5.5.2.6.0 and 4/8Gb SAN 7.10.1.20.0 modules for IBM BladeCenter have an undocumented support account with a support password, an undocumented diags account with a diags password, and an undoc...Show more
The QLogic 4Gb Fibre Channel 5.5.2.6.0 and 4/8Gb SAN 7.10.1.20.0 modules for IBM BladeCenter have an undocumented support account with a support password, an undocumented diags account with a diags password, and an undocumented prom account with a prom password.Show less