← Back

Ibm

ibm

8,252 CVEs • 1,572 products

Products (1,572)

Click to collapse
Toggle
Aix
aix
Db2
db2
Vios
vios
Websphere Mq
websphere_mq
Lotus Domino
lotus_domino
Api Connect
api_connect
Lotus Notes
lotus_notes
Concert
concert
I
i
Mq Appliance
mq_appliance
Mq
mq
Sametime
sametime
Aspera Faspex
aspera_faspex
Cics Tx
cics_tx
Connections
connections
Java
java
Domino
domino
Doors Next
doors_next

CVEs (8,252)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Infosphere Information Server
May 13, 2026
Feb 8, 2017
N/A· v4
4.7 MEDIUM· v3
1.9 LOW· v2
IBM InfoSphere Information Server could allow a local user under special circumstances to execute commands during installation processes that could expose sensitive information.
1Ibm
1Websphere Extreme Scale
May 13, 2026
Feb 8, 2017
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
IBM WebSphere eXtreme Scale and the WebSphere DataPower XC10 Appliance allow some sensitive data to linger in memory instead of being overwritten which could allow a local user with administrator privileges to obtain sen...Show more
IBM WebSphere eXtreme Scale and the WebSphere DataPower XC10 Appliance allow some sensitive data to linger in memory instead of being overwritten which could allow a local user with administrator privileges to obtain sensitive information.Show less
1Ibm
2Security Directory Server
Tivoli Directory Server
May 13, 2026
Feb 8, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
IBM Security Directory Server could allow an authenticated user to execute commands into the web administration tool that would cause the tool to crash.
1Ibm
2Rational Doors Next Generation
Rational Requirements Composer
May 13, 2026
Feb 8, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Rational DOORS Next Generation 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potent...Show more
IBM Rational DOORS Next Generation 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.Show less
1Ibm
2Rational Doors Next Generation
Rational Requirements Composer
May 13, 2026
Feb 8, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Rational DOORS Next Generation 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potenti...Show more
IBM Rational DOORS Next Generation 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.Show less
1Ibm
2Rational Doors Next Generation
Rational Requirements Composer
May 13, 2026
Feb 8, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Rational DOORS Next Generation 5.0 and 6.0 discloses sensitive information in error response messages that could be used for further attacks against the system.
1Ibm
1Rational Collaborative Lifecycle Management
May 13, 2026
Feb 8, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Rational Team Concert 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially lead...Show more
IBM Rational Team Concert 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.Show less
1Ibm
1Rational Collaborative Lifecycle Management
May 13, 2026
Feb 8, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
An unspecified vulnerability in IBM Jazz Team Server may disclose some deployment information to an authenticated user.
1Ibm
3Security Access Manager 9.0 Firmware
Security Access Manager For MobileSecurity Access Manager For Web 8.0 Firmware
May 13, 2026
Feb 8, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The IBM Security Access Manager appliance includes configuration files that contain obfuscated plaintext-passwords which authenticated users can access.
1Ibm
3Client Application Access
DominoNotes
May 13, 2026
Feb 8, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
IBM Domino 9.0.1 Fix Pack 3 Interim Fix 2 through 9.0.1 Fix Pack 5 Interim Fix 1, when using TLS and AES GCM, uses random nonce generation, which makes it easier for remote attackers to obtain the authentication key and...Show more
IBM Domino 9.0.1 Fix Pack 3 Interim Fix 2 through 9.0.1 Fix Pack 5 Interim Fix 1, when using TLS and AES GCM, uses random nonce generation, which makes it easier for remote attackers to obtain the authentication key and spoof data by leveraging the reuse of a nonce in a session and a "forbidden attack." NOTE: this CVE has been incorrectly used for GCM nonce reuse issues in other products; see CVE-2016-10213 for the A10 issue, CVE-2016-10212 for the Radware issue, and CVE-2017-5933 for the Citrix issue.Show less
1Ibm
1Security Key Lifecycle Manager
May 13, 2026
Feb 7, 2017
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
IBM Tivoli Key Lifecycle Manager 2.5, and 2.6 could allow a remote attacker to upload arbitrary files, caused by the improper validation of file extensions, which could allow the attacker to execute arbitrary code on the...Show more
IBM Tivoli Key Lifecycle Manager 2.5, and 2.6 could allow a remote attacker to upload arbitrary files, caused by the improper validation of file extensions, which could allow the attacker to execute arbitrary code on the vulnerable system.Show less
1Ibm
2Security Key Lifecycle Manager
Tivoli Key Lifecycle Manager
May 13, 2026
Feb 7, 2017
N/A· v4
4.0 MEDIUM· v3
2.1 LOW· v2
IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 allows web pages to be stored locally which can be read by another user on the system.
1Ibm
2Security Key Lifecycle Manager
Tivoli Key Lifecycle Manager
May 13, 2026
Feb 7, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potent...Show more
IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.Show less
1Ibm
2Security Key Lifecycle Manager
Tivoli Key Lifecycle Manager
May 13, 2026
Feb 7, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 generates an error message that includes sensitive information about its environment, users, or associated data.
1Ibm
2Security Key Lifecycle Manager
Tivoli Key Lifecycle Manager
May 13, 2026
Feb 7, 2017
N/A· v4
6.2 MEDIUM· v3
2.1 LOW· v2
IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 stores user credentials in plain in clear text which can be read by a local user.
1Ibm
4Security Access Manager 9.0 Firmware
Security Access Manager For MobileSecurity Access Manager For Web 7.0 Firmware+1 more
May 13, 2026
Feb 7, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
IBM Security Access Manager for Web 7.0.0, 8.0.0, and 9.0.0 could allow a remote attacker to bypass security restrictions, caused by improper content validation. By persuading a victim to open specially-crafted content,...Show more
IBM Security Access Manager for Web 7.0.0, 8.0.0, and 9.0.0 could allow a remote attacker to bypass security restrictions, caused by improper content validation. By persuading a victim to open specially-crafted content, an attacker could exploit this vulnerability to bypass validation and load a page with malicious content.Show less
1Ibm
1Aix
May 13, 2026
Feb 2, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
IBM AIX 6.1, 7.1, and 7.2 could allow a local user to exploit a vulnerability in the bellmail binary to gain root privileges.
1Ibm
1Security Key Lifecycle Manager
May 13, 2026
Feb 2, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerab...Show more
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.Show less
1Ibm
1Security Key Lifecycle Manager
May 13, 2026
Feb 2, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
1Ibm
1Security Key Lifecycle Manager
May 13, 2026
Feb 2, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system.