← Back

Ibm

ibm

8,252 CVEs • 1,572 products

Products (1,572)

Click to collapse
Toggle
Aix
aix
Db2
db2
Vios
vios
Websphere Mq
websphere_mq
Lotus Domino
lotus_domino
Api Connect
api_connect
Lotus Notes
lotus_notes
Concert
concert
I
i
Mq Appliance
mq_appliance
Mq
mq
Sametime
sametime
Aspera Faspex
aspera_faspex
Cics Tx
cics_tx
Connections
connections
Java
java
Domino
domino
Doors Next
doors_next

CVEs (8,252)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Security Key Lifecycle Manager
May 13, 2026
Feb 2, 2017
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.
1Ibm
1Dashboard Application Services Hub
May 13, 2026
Feb 2, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
IBM Jazz for Service Management could allow a remote attacker to obtain sensitive information, caused by the failure to properly validate the SSL certificate. An attacker could exploit this vulnerability to obtain sensit...Show more
IBM Jazz for Service Management could allow a remote attacker to obtain sensitive information, caused by the failure to properly validate the SSL certificate. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.Show less
1Ibm
1Security Identity Manager
May 13, 2026
Feb 1, 2017
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
IBM Security Identity Manager Virtual Appliance stores user credentials in plain in clear text which can be read by a local user.
1Ibm
1Security Identity Manager Virtual Appliance
May 13, 2026
Feb 1, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBM Security Identity Manager Virtual Appliance is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially...Show more
IBM Security Identity Manager Virtual Appliance is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.Show less
1Ibm
1Security Identity Manager Virtual Appliance
May 13, 2026
Feb 1, 2017
N/A· v4
2.4 LOW· v3
2.1 LOW· v2
IBM Security Identity Manager Virtual Appliance does not invalidate session tokens which could allow an unauthorized user with physical access to the work station to obtain sensitive information.
1Ibm
1Urbancode Deploy
May 13, 2026
Feb 1, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM UrbanCode Deploy could allow a malicious user to access the Agent Relay ActiveMQ Broker JMX interface and run plugins on the agent.
1Ibm
2Infosphere Datastage
Infosphere Information Server On Cloud
May 13, 2026
Feb 1, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBM InfoSphere DataStage is vulnerable to cross-frame scripting, caused by insufficient HTML iframe protection. A remote attacker could exploit this vulnerability using a specially-crafted URL to navigate to a web page t...Show more
IBM InfoSphere DataStage is vulnerable to cross-frame scripting, caused by insufficient HTML iframe protection. A remote attacker could exploit this vulnerability using a specially-crafted URL to navigate to a web page the attacker controls. An attacker could use this vulnerability to conduct clickjacking or other client-side browser attacks.Show less
1Ibm
3Infosphere Datastage
Infosphere Information ServerInfosphere Information Server On Cloud
May 13, 2026
Feb 1, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM InfoSphere Information Server contains a Path-relative stylesheet import vulnerability that allows attackers to render a page in quirks mode thereby facilitating an attacker to inject malicious CSS.
1Ibm
1Infosphere Datastage
May 13, 2026
Feb 1, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM InfoSphere Information Server stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser histor...Show more
IBM InfoSphere Information Server stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history.Show less
1Ibm
2Bigfix Inventory
License Metric Tool
May 13, 2026
Feb 1, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM BigFix Inventory v9 could disclose sensitive information to an unauthorized user using HTTP GET requests. This information could be used to mount further attacks against the system.
1Ibm
2Bigfix Inventory
License Metric Tool
May 13, 2026
Feb 1, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
IBM BigFix Inventory v9 stores potentially sensitive information in log files that could be read by a local user.
1Ibm
1Urbancode Deploy
May 13, 2026
Feb 1, 2017
N/A· v4
10.0 CRITICAL· v3
10.0 HIGH· v2
IBM UrbanCode Deploy could allow a user to execute code using a specially crafted file upload that would replace code on the server. This code could be executed on the UCD agent machines that host customer's production a...Show more
IBM UrbanCode Deploy could allow a user to execute code using a specially crafted file upload that would replace code on the server. This code could be executed on the UCD agent machines that host customer's production applications.Show less
1Ibm
1Kenexa Lms
May 13, 2026
Feb 1, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
IBM Kenexa LMS on Cloud could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing dot dot sequences (/../) to view arbitrary files on the syste...Show more
IBM Kenexa LMS on Cloud could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing dot dot sequences (/../) to view arbitrary files on the system.Show less
1Ibm
1Kenexa Lms
May 13, 2026
Feb 1, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
IBM Kenexa LMS on Cloud could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server.
1Ibm
1Kenexa Lms
May 13, 2026
Feb 1, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
IBM Kenexa LMS on Cloud could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server.
1Ibm
1Kenexa Lms
May 13, 2026
Feb 1, 2017
N/A· v4
7.6 HIGH· v3
6.5 MEDIUM· v2
IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
1Ibm
1Kenexa Lms
May 13, 2026
Feb 1, 2017
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
1Ibm
1Kenexa Lms
May 13, 2026
Feb 1, 2017
N/A· v4
7.6 HIGH· v3
6.5 MEDIUM· v2
IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
1Ibm
1Websphere Application Server
May 13, 2026
Feb 1, 2017
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
IBM WebSphere Application Server may be vulnerable to a denial of service, caused by allowing serialized objects from untrusted sources to run and cause the consumption of resources.
1Ibm
2General Parallel File System
Spectrum Scale
May 13, 2026
Feb 1, 2017
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
IBM General Parallel File System is vulnerable to a buffer overflow. A remote authenticated attacker could overflow a buffer and execute arbitrary code on the system with root privileges or cause the server to crash.