← Back

Ibm

ibm

8,252 CVEs • 1,572 products

Products (1,572)

Click to collapse
Toggle
Aix
aix
Db2
db2
Vios
vios
Websphere Mq
websphere_mq
Lotus Domino
lotus_domino
Api Connect
api_connect
Lotus Notes
lotus_notes
Concert
concert
I
i
Mq Appliance
mq_appliance
Mq
mq
Sametime
sametime
Aspera Faspex
aspera_faspex
Cics Tx
cics_tx
Connections
connections
Java
java
Domino
domino
Doors Next
doors_next

CVEs (8,252)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Api Connect
May 13, 2026
Sep 25, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM API Connect 5.0.0.0 through 5.0.7.2 could allow an authenticated user to generate an API token when not subscribed to the application plan. IBM X-Force ID: 131545.
1Ibm
1Api Connect
May 13, 2026
Sep 25, 2017
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
IBM API Connect 5.0.0.0 through 5.0.7.2 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability...Show more
IBM API Connect 5.0.0.0 through 5.0.7.2 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 131291.Show less
1Ibm
1Business Process Manager
May 13, 2026
Sep 25, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Business Process Manager 8.5.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to c...Show more
IBM Business Process Manager 8.5.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 127477.Show less
1Ibm
1Security Identity Manager
May 13, 2026
Sep 25, 2017
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
IBM Security Identity Manager Adapters 6.0 and 7.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 126801.
1Ibm
1Business Process Manager
May 13, 2026
Sep 25, 2017
N/A· v4
2.5 LOW· v3
1.9 LOW· v2
IBM Business Process Manager 7.5, 8.0, and 8.5 temporarily stores files in a temporary folder during offline installs which could be read by a local user within a short timespan. IBM X-Force ID: 126461.
1Ibm
1Websphere Mq
May 13, 2026
Sep 25, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
IBM WebSphere MQ 8.0 could allow an authenticated user to cause a premature termination of a client application thread which could potentially cause denial of service. IBM X-Force ID: 123914.
1Ibm
1Security Siteprotector System
May 13, 2026
Sep 20, 2017
N/A· v4
7.0 HIGH· v3
6.9 MEDIUM· v2
IBM Security SiteProtector System 3.0, 3.1, and 3.1.1 allows local users to gain privileges.
1Ibm
1Curam Social Program Management
May 13, 2026
Sep 19, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management 6.0 SP2, 6.0.4, and 6.0.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 98568.
1Ibm
1Security Identity Manager
May 13, 2026
Sep 18, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in IBM Security Identity Manager 5.1, 6.0, and 7.0 allows remote attackers to hijack the authentication of users for requests that can cause cross-site scripting attacks, w...Show more
Cross-site request forgery (CSRF) vulnerability in IBM Security Identity Manager 5.1, 6.0, and 7.0 allows remote attackers to hijack the authentication of users for requests that can cause cross-site scripting attacks, web cache poisoning, or other unspecified impacts via unknown vectors.Show less
1Ibm
2Business Process Manager
Websphere Application Server
May 13, 2026
Sep 15, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
IBM Business Process Manager (aka BPM) 7.5.x, 8.0.x, and 8.5.x and WebSphere Lombardi Edition (aka WLE) 7.2.x allow remote authenticated users to bypass intended access restrictions on internal service types via vectors...Show more
IBM Business Process Manager (aka BPM) 7.5.x, 8.0.x, and 8.5.x and WebSphere Lombardi Edition (aka WLE) 7.2.x allow remote authenticated users to bypass intended access restrictions on internal service types via vectors involving the executeServiceByName URL.Show less
1Ibm
1Jazz Reporting Service
May 13, 2026
Sep 14, 2017
N/A· v4
5.3 MEDIUM· v3
3.5 LOW· v2
An unspecified vulnerability in the Lifecycle Query Engine of Jazz Reporting Service 6.0 through 6.0.4 could disclose highly sensitive information.
1Ibm
1Api Connect
May 13, 2026
Sep 13, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
IBM API Connect 5.0.7.0 through 5.0.7.2 is vulnerable to a regular expression attack that could allow an authenticated attacker to use a regex and cause the system to slow or hang. IBM X-Force ID: 131546.
1Ibm
1Informix Dynamic Server
May 13, 2026
Sep 13, 2017
N/A· v4
6.7 MEDIUM· v3
6.8 MEDIUM· v2
IBM Informix Dynamic Server 12.1 could allow a local user logged in with database administrator user to gain root privileges. IBM X-Force ID: 129620.
1Ibm
2Db2
Db2 Connect
May 13, 2026
Sep 12, 2017
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
IBM DB2 9.7, 10,1, 10.5, and 11.1 is vulnerable to an unauthorized command that allows the database to be activated when authentication type is CLIENT. IBM X-Force ID: 129830.
1Ibm
2Db2
Db2 Connect
May 13, 2026
Sep 12, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
IBM DB2 10.5 and 11.1 contains a denial of service vulnerability. A remote user can cause disruption of service for DB2 Connect Server setup with a particular configuration. IBM X-Force ID: 129829.
1Ibm
2Db2
Db2 Connect
May 13, 2026
Sep 12, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user to obtain elevated privilege and overwrite DB2 files. IBM X-Force ID: 128180.
1Ibm
2Db2
Db2 Connect
May 13, 2026
Sep 12, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user with DB2 instance owner privileges to obtain root access. IBM X-Force ID: 128178.
1Ibm
2Db2
Db2 Connect
May 13, 2026
Sep 12, 2017
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user with DB2 instance owner privileges to obtain root access. IBM X-Force ID: 128058.
1Ibm
2Db2
Db2 Connect
May 13, 2026
Sep 12, 2017
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user with DB2 instance owner privileges to obtain root access. IBM X-Force ID: 128057.
1Ibm
2Db2
Db2 Connect
May 13, 2026
Sep 12, 2017
N/A· v4
4.7 MEDIUM· v3
2.1 LOW· v2
IBM DB2 for Linux, UNIX and Windows 11.1 (includes DB2 Connect Server) under unusual circumstances, could expose highly sensitive information in the error log to a local user.