← Back

Ibm

ibm

8,252 CVEs • 1,572 products

Products (1,572)

Click to collapse
Toggle
Aix
aix
Db2
db2
Vios
vios
Websphere Mq
websphere_mq
Lotus Domino
lotus_domino
Api Connect
api_connect
Lotus Notes
lotus_notes
Concert
concert
I
i
Mq Appliance
mq_appliance
Mq
mq
Sametime
sametime
Aspera Faspex
aspera_faspex
Cics Tx
cics_tx
Connections
connections
Java
java
Domino
domino
Doors Next
doors_next

CVEs (8,252)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Business Process Manager
May 13, 2026
Feb 1, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Business Process Manager is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credent...Show more
IBM Business Process Manager is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.Show less
1Ibm
2Bigfix Inventory
License Metric Tool
May 13, 2026
Feb 1, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
IBM BigFix Inventory v9 allows web pages to be stored locally which can be read by another user on the system.
1Ibm
2Bigfix Inventory
License Metric Tool
May 13, 2026
Feb 1, 2017
N/A· v4
8.1 HIGH· v3
7.5 HIGH· v2
IBM BigFix Inventory v9 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive...Show more
IBM BigFix Inventory v9 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources.Show less
1Ibm
2Bigfix Inventory
License Metric Tool
May 13, 2026
Feb 1, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
IBM BigFix Inventory v9 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensi...Show more
IBM BigFix Inventory v9 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.Show less
1Ibm
2Bigfix Inventory
License Metric Tool
May 13, 2026
Feb 1, 2017
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
IBM BigFix Inventory v9 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnera...Show more
IBM BigFix Inventory v9 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.Show less
1Ibm
2Spectrum Control
Tivoli Storage Productivity Center
May 13, 2026
Feb 1, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Tivoli Storage Productivity Center is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading...Show more
IBM Tivoli Storage Productivity Center is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.Show less
1Ibm
2Spectrum Control
Tivoli Storage Productivity Center
May 13, 2026
Feb 1, 2017
N/A· v4
3.1 LOW· v3
3.5 LOW· v2
IBM Tivoli Storage Productivity Center could allow an authenticated user with intimate knowledge of the system to edit a limited set of properties on the server.
1Ibm
2Spectrum Control
Tivoli Storage Productivity Center
May 13, 2026
Feb 1, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
IBM Tivoli Storage Productivity Center is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
1Ibm
1Social Rendering Templates For Digital Data Connector
May 13, 2026
Feb 1, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBM Social Rendering Templates for Digital Data Connector is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality p...Show more
IBM Social Rendering Templates for Digital Data Connector is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.Show less
1Ibm
1Websphere Application Server
May 13, 2026
Feb 1, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM WebSphere Application Server is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cre...Show more
IBM WebSphere Application Server is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.Show less
1Ibm
2Web Content Manager Production Analytics
Websphere Portal
May 13, 2026
Feb 1, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Exphox WebRadar is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosu...Show more
Exphox WebRadar is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.Show less
1Ibm
1Filenet Workplace Xt
May 13, 2026
Feb 1, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
IBM FileNet WorkPlace XT could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server.
1Ibm
1Kenexa Lms On Cloud
May 13, 2026
Feb 1, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially...Show more
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.Show less
1Ibm
1Integration Bus
May 13, 2026
Feb 1, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
IBM Integration Bus, under non default configurations, could allow a remote user to authenticate without providing valid credentials.
1Ibm
1Kenexa Lms On Cloud
May 13, 2026
Feb 1, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arb...Show more
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.Show less
1Ibm
1Kenexa Lms On Cloud
May 13, 2026
Feb 1, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 stores potentially sensitive information in in log files that could be read by an authenticated user.
1Ibm
1Kenexa Lms On Cloud
May 13, 2026
Feb 1, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnera...Show more
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim.Show less
1Ibm
1Kenexa Lms On Cloud
May 13, 2026
Feb 1, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arb...Show more
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.Show less
1Ibm
1Kenexa Lms On Cloud
May 13, 2026
Feb 1, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially...Show more
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.Show less
1Ibm
1Kenexa Lms On Cloud
May 13, 2026
Feb 1, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server.