← Back

Ibm

ibm

8,252 CVEs • 1,572 products

Products (1,572)

Click to collapse
Toggle
Aix
aix
Db2
db2
Vios
vios
Websphere Mq
websphere_mq
Lotus Domino
lotus_domino
Api Connect
api_connect
Lotus Notes
lotus_notes
Concert
concert
I
i
Mq Appliance
mq_appliance
Mq
mq
Sametime
sametime
Aspera Faspex
aspera_faspex
Cics Tx
cics_tx
Connections
connections
Java
java
Domino
domino
Doors Next
doors_next

CVEs (8,252)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Maximo Asset Management
May 13, 2026
Mar 7, 2017
N/A· v4
2.9 LOW· v3
1.9 LOW· v2
IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a local attacker to obtain sensitive information using HTTP Header Injection. IBM Reference #: 1998053.
1Ibm
1Qradar Security Information And Event Manager
May 13, 2026
Mar 7, 2017
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
IBM QRadar 7.2 could allow a remote attacker to consume all resources on the server due to not properly restricting the size or amount of resources requested by an actor. IBM Reference #: 1999556.
1Ibm
2Qradar Incident Forensics
Qradar Security Information And Event Manager
May 13, 2026
Mar 7, 2017
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
IBM QRadar Incident Forensics 7.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM Reference #:...Show more
IBM QRadar Incident Forensics 7.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM Reference #: 1999549.Show less
1Ibm
1Qradar Security Information And Event Manager
May 13, 2026
Mar 7, 2017
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
IBM QRadar 7.2 does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. IBM Reference #: 1999545.
1Ibm
1Qradar Security Information And Event Manager
May 13, 2026
Mar 7, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM Qradar 7.2 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, information in the back-end database. IBM Reference #: 1999543.
1Ibm
2Qradar Incident Forensics
Qradar Security Information And Event Manager
May 13, 2026
Mar 7, 2017
N/A· v4
8.5 HIGH· v3
8.5 HIGH· v2
IBM QRadar 7.2 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands o...Show more
IBM QRadar 7.2 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM Reference #: 1999542.Show less
1Ibm
2Qradar Incident Forensics
Qradar Security Information And Event Manager
May 13, 2026
Mar 7, 2017
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
IBM QRadar Incident Forensics 7.2 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute a...Show more
IBM QRadar Incident Forensics 7.2 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM Reference #: 1999542.Show less
1Ibm
1Qradar Security Information And Event Manager
May 13, 2026
Mar 7, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM QRadar Incident Forensics 7.2 allows for Cross-Origin Resource Sharing (CORS), which is a mechanism that allows web sites to request resources from external sites, avoiding the need to duplicate them. IBM Reference #...Show more
IBM QRadar Incident Forensics 7.2 allows for Cross-Origin Resource Sharing (CORS), which is a mechanism that allows web sites to request resources from external sites, avoiding the need to duplicate them. IBM Reference #: 1999539.Show less
1Ibm
1Qradar Security Information And Event Manager
May 13, 2026
Mar 7, 2017
N/A· v4
8.1 HIGH· v3
7.5 HIGH· v2
IBM QRadar 7.2 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive informat...Show more
IBM QRadar 7.2 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM Reference #: 1999537.Show less
1Ibm
2Qradar Incident Forensics
Qradar Security Information And Event Manager
May 13, 2026
Mar 7, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBM QRadar 7.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosur...Show more
IBM QRadar 7.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1999534.Show less
1Ibm
2Qradar Incident Forensics
Qradar Security Information And Event Manager
May 13, 2026
Mar 7, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM QRadar 7.2 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM Reference #: 1999533.
1Ibm
2Business Process Manager
Websphere
May 13, 2026
Mar 7, 2017
N/A· v4
6.1 MEDIUM· v3
6.8 MEDIUM· v2
IBM Business Process Manager 7.5, 8.0, and 8.5 has a file download capability that is vulnerable to a set of attacks. Ultimately, an attacker can cause an unauthenticated victim to download a malicious payload. An existi...Show more
IBM Business Process Manager 7.5, 8.0, and 8.5 has a file download capability that is vulnerable to a set of attacks. Ultimately, an attacker can cause an unauthenticated victim to download a malicious payload. An existing file type restriction can be bypassed so that the payload might be considered executable and cause damage on the victim's machine. IBM Reference #: 1998655.Show less
1Ibm
1Websphere Mq
May 13, 2026
Mar 7, 2017
N/A· v4
6.5 MEDIUM· v3
6.8 MEDIUM· v2
IBM WebSphere MQ 8.0 could allow an authenticated user with queue manager permissions to cause a segmentation fault which would result in the box having to be rebooted to resume normal operations. IBM Reference #: 199866...Show more
IBM WebSphere MQ 8.0 could allow an authenticated user with queue manager permissions to cause a segmentation fault which would result in the box having to be rebooted to resume normal operations. IBM Reference #: 1998663.Show less
1Ibm
1Tivoli Storage Manager
May 13, 2026
Mar 7, 2017
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
IBM Tivoli Storage Manager (IBM Spectrum Protect) 6.1, 6.2, 6.3, and 7.1 does not perform sufficient authority checking on SQL queries. As a result, an attacker is able to submit SQL queries that access database tables t...Show more
IBM Tivoli Storage Manager (IBM Spectrum Protect) 6.1, 6.2, 6.3, and 7.1 does not perform sufficient authority checking on SQL queries. As a result, an attacker is able to submit SQL queries that access database tables that are not intended for access or use by administrators. The access of these product specific database tables may allow access to passwords or other sensitive information for the product. IBM Reference #: 1998946.Show less
1Ibm
1Kenexa Lcms Premier
May 13, 2026
Mar 1, 2017
N/A· v4
7.1 HIGH· v3
6.5 MEDIUM· v2
IBM Kenexa LCMS Premier on Cloud 9.0, and 10.0.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in...Show more
IBM Kenexa LCMS Premier on Cloud 9.0, and 10.0.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM Reference #: 1976805.Show less
1Ibm
1Kenexa Lcms Premier
May 13, 2026
Mar 1, 2017
N/A· v4
7.1 HIGH· v3
6.5 MEDIUM· v2
IBM Kenexa LCMS Premier on Cloud 9.0, and 10.0.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in...Show more
IBM Kenexa LCMS Premier on Cloud 9.0, and 10.0.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM Reference #: 1992067.Show less
1Ibm
1Kenexa Lcms Premier
May 13, 2026
Mar 1, 2017
N/A· v4
7.1 HIGH· v3
6.5 MEDIUM· v2
IBM Kenexa LCMS Premier on Cloud 9.0, and 10.0.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in...Show more
IBM Kenexa LCMS Premier on Cloud 9.0, and 10.0.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM Reference #: 1992067.Show less
1Ibm
1Advanced Management Module Firmware
May 13, 2026
Mar 1, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Document Object Model-(DOM) based cross-site scripting vulnerability in the Advanced Management Module (AMM) versions earlier than 66Z of Lenovo IBM BladeCenter HS22, HS22V, HS23, HS23E, HX5 allows an unauthenticated att...Show more
Document Object Model-(DOM) based cross-site scripting vulnerability in the Advanced Management Module (AMM) versions earlier than 66Z of Lenovo IBM BladeCenter HS22, HS22V, HS23, HS23E, HX5 allows an unauthenticated attacker with access to the AMM's IP address to send a crafted URL that could inject a malicious script to access a user's AMM data such as cookies or other session information.Show less
1Ibm
1Connections
May 13, 2026
Mar 1, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Connections 4.0, 4.5, 5.0, and 5.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading...Show more
IBM Connections 4.0, 4.5, 5.0, and 5.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1998294.Show less
1Ibm
1Qradar Security Information And Event Manager
May 13, 2026
Mar 1, 2017
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
IBM QRadar 7.2 stores the encryption key used to encrypt the service account password which can be obtained by a local user. IBM Reference #: 1997340.