← Back

Ibm

ibm

8,252 CVEs • 1,572 products

Products (1,572)

Click to collapse
Toggle
Aix
aix
Db2
db2
Vios
vios
Websphere Mq
websphere_mq
Lotus Domino
lotus_domino
Api Connect
api_connect
Lotus Notes
lotus_notes
Concert
concert
I
i
Mq Appliance
mq_appliance
Mq
mq
Sametime
sametime
Aspera Faspex
aspera_faspex
Cics Tx
cics_tx
Connections
connections
Java
java
Domino
domino
Doors Next
doors_next

CVEs (8,252)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
4Security Access Manager 9.0 Firmware
Security Access Manager For Mobile 8.0 FirmwareSecurity Access Manager For Web 7.0 Firmware+1 more
May 13, 2026
Feb 1, 2017
N/A· v4
2.7 LOW· v3
4.0 MEDIUM· v2
IBM Security Access Manager for Web could allow an authenticated attacker to obtain sensitive information from error message using a specially crafted HTTP request.
1Ibm
3Security Access Manager
Security Access Manager For MobileSecurity Access Manager For Web
May 13, 2026
Feb 1, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBM Security Access Manager for Web is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to...Show more
IBM Security Access Manager for Web is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.Show less
1Ibm
4Security Access Manager 9.0 Firmware
Security Access Manager For Mobile 8.0 FirmwareSecurity Access Manager For Web 7.0 Firmware+1 more
May 13, 2026
Feb 1, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM Security Access Manager for Web could allow a remote attacker to obtain sensitive information due to security misconfigurations.
1Ibm
4Security Access Manager 9.0 Firmware
Security Access Manager For Mobile 8.0 FirmwareSecurity Access Manager For Web 7.0 Firmware+1 more
May 13, 2026
Feb 1, 2017
N/A· v4
4.4 MEDIUM· v3
3.5 LOW· v2
IBM Security Access Manager for Web processes patches, image backups and other updates without sufficiently verifying the origin and integrity of the code, which could allow an authenticated attacker to load malicious co...Show more
IBM Security Access Manager for Web processes patches, image backups and other updates without sufficiently verifying the origin and integrity of the code, which could allow an authenticated attacker to load malicious code.Show less
1Ibm
6Rational Doors Next Generation
Rational Engineering Lifecycle ManagerRational Quality Manager+3 more
May 13, 2026
Feb 1, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
An undisclosed vulnerability in CLM applications may result in some administrative deployment parameters being shown to an attacker.
1Ibm
2Domino
Inotes
May 13, 2026
Feb 1, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure wi...Show more
IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.Show less
1Ibm
2Domino
Inotes
May 13, 2026
Feb 1, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure wi...Show more
IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.Show less
1Ibm
3Security Access Manager 9.0 Firmware
Security Access Manager For Mobile 8.0 FirmwareSecurity Access Manager For Web 8.0 Firmware
May 13, 2026
Feb 1, 2017
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
IBM Single Sign On for Bluemix could allow a remote attacker to obtain sensitive information, caused by a XML external entity (XXE) error when processing XML data by the XML parser. A remote attacker could exploit this v...Show more
IBM Single Sign On for Bluemix could allow a remote attacker to obtain sensitive information, caused by a XML external entity (XXE) error when processing XML data by the XML parser. A remote attacker could exploit this vulnerability to read arbitrary files on the system or cause a denial of service.Show less
1Ibm
1Bigfix Platform
May 13, 2026
Feb 1, 2017
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
IBM Tivoli Endpoint Manager could allow a user under special circumstances to inject commands that would be executed with unnecessary higher privileges than expected.
1Ibm
2Integration Bus
Websphere Message Broker
May 13, 2026
Feb 1, 2017
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
IBM Integration Bus and WebSphere Message broker sets incorrect permissions for an object that could allow a local attacker to manipulate certain files.
1Ibm
1Bigfix Platform
May 13, 2026
Feb 1, 2017
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
IBM Tivoli Endpoint Manager - Mobile Device Management (MDM) could allow a remote attacker to obtain sensitive information due to a missing HTTP Strict-Transport-Security Header through man in the middle techniques.
1Ibm
1Bigfix Platform
May 13, 2026
Feb 1, 2017
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
IBM Tivoli Endpoint Manager - Mobile Device Management (MDM) stores potentially sensitive information in log files that could be available to a local user.
1Ibm
1Campaign
May 13, 2026
Feb 1, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Campaign is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's W...Show more
IBM Campaign is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.Show less
2Ibm
Vmware
2Spring Security
Websphere Application Server
May 6, 2026
Jan 6, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Pivotal Spring Security before 3.2.10, 4.1.x before 4.1.4, and 4.2.x before 4.2.1. Spring Security does not consider URL path parameters when processing security constraints. By adding a URL pa...Show more
An issue was discovered in Pivotal Spring Security before 3.2.10, 4.1.x before 4.1.4, and 4.2.x before 4.2.1. Spring Security does not consider URL path parameters when processing security constraints. By adding a URL path parameter with an encoded "/" to a request, an attacker may be able to bypass a security constraint. The root cause of this issue is a lack of clarity regarding the handling of path parameters in the Servlet Specification. Some Servlet containers include path parameters in the value returned for getPathInfo() and some do not. Spring Security uses the value returned by getPathInfo() as part of the process of mapping requests to security constraints. The unexpected presence of path parameters can cause a constraint to be bypassed. Users of Apache Tomcat (all current versions) are not affected by this vulnerability since Tomcat follows the guidance previously provided by the Servlet Expert group and strips path parameters from the value returned by getContextPath(), getServletPath(), and getPathInfo(). Users of other Servlet containers based on Apache Tomcat may or may not be affected depending on whether or not the handling of path parameters has been modified. Users of IBM WebSphere Application Server 8.5.x are known to be affected. Users of other containers that implement the Servlet specification may be affected.Show less
2Ibm
Pcre
2Pcre
Powerkvm
May 6, 2026
Dec 13, 2016
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Heap-based buffer overflow in the find_fixedlength function in pcre_compile.c in PCRE before 8.38 allows remote attackers to cause a denial of service (crash) or obtain sensitive information from heap memory and possibly...Show more
Heap-based buffer overflow in the find_fixedlength function in pcre_compile.c in PCRE before 8.38 allows remote attackers to cause a denial of service (crash) or obtain sensitive information from heap memory and possibly bypass the ASLR protection mechanism via a crafted regular expression with an excess closing parenthesis.Show less
2Ibm
Pcre
3Pcre
Pcre2Powerkvm
May 6, 2026
Dec 13, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
PCRE 7.8 and 8.32 through 8.37, and PCRE2 10.10 mishandle group empty matches, which might allow remote attackers to cause a denial of service (stack-based buffer overflow) via a crafted regular expression, as demonstrat...Show more
PCRE 7.8 and 8.32 through 8.37, and PCRE2 10.10 mishandle group empty matches, which might allow remote attackers to cause a denial of service (stack-based buffer overflow) via a crafted regular expression, as demonstrated by /^(?:(?(1)\\.|([^\\\\W_])?)+)+$/.Show less
1Ibm
1Filenet Workplace
May 6, 2026
Dec 1, 2016
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
IBM FileNet Workplace 4.0.2 before 4.0.2.14 LA012 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via an XML document containing an external entity declaration...Show more
IBM FileNet Workplace 4.0.2 before 4.0.2.14 LA012 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.Show less
1Ibm
1Filenet Workplace
May 6, 2026
Dec 1, 2016
N/A· v4
6.8 MEDIUM· v3
4.9 MEDIUM· v2
Open redirect vulnerability in IBM FileNet Workplace 4.0.2 through 4.0.2.14 IF001 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
1Ibm
1Powerkvm
May 6, 2026
Dec 1, 2016
N/A· v4
6.5 MEDIUM· v3
4.9 MEDIUM· v2
The Linux kernel component in IBM PowerKVM 2.1 before 2.1.1.3-65.10 and 3.1 before 3.1.0.2 allows guest OS users to cause a denial of service (host OS infinite loop and hang) via unspecified vectors.
1Ibm
1Appscan Source
May 6, 2026
Dec 1, 2016
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
IBM AppScan Source 8.7 through 9.0.3.3 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via an XML document containing an external entity declaration in conjunct...Show more
IBM AppScan Source 8.7 through 9.0.3.3 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.Show less