← Back

Ibm

ibm

8,704 CVEs • 1,613 products

Products (1,613)

Click to collapse
Toggle
Aix
aix
Db2
db2
Vios
vios
I
i
Websphere Mq
websphere_mq
Lotus Domino
lotus_domino
Api Connect
api_connect
Lotus Notes
lotus_notes
Concert
concert
Aspera Faspex
aspera_faspex
Mq Appliance
mq_appliance
Mq
mq
Sametime
sametime
Cics Tx
cics_tx
Connections
connections
Java
java
Domino
domino

CVEs (8,704)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Websphere Application Server
Apr 23, 2026
Jun 26, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The web container in IBM WebSphere Application Server (WAS) before 6.0.2.21, and 6.1.x before 6.1.0.9, sends response data intended for a different request in certain circumstances after a closed connection error, which...Show more
The web container in IBM WebSphere Application Server (WAS) before 6.0.2.21, and 6.1.x before 6.1.0.9, sends response data intended for a different request in certain circumstances after a closed connection error, which might allow remote attackers to obtain sensitive information.Show less
1Ibm
1Websphere Application Server
Apr 23, 2026
Jun 19, 2007
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the Samples component in IBM WebSphere Application Server (WAS) 6.1.0.7 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
1Ibm
1Websphere Application Server
Apr 23, 2026
Jun 19, 2007
N/A· v4
N/A· v3
10.0 HIGH· v2
Unspecified vulnerability in the PD tools component in IBM WebSphere Application Server (WAS) 6.1.0.7 and earlier has unknown impact and attack vectors.
1Ibm
1Websphere Application Server
Apr 23, 2026
Jun 19, 2007
N/A· v4
N/A· v3
10.0 HIGH· v2
Unspecified vulnerability in the Default Messaging Component in IBM WebSphere Application Server (WAS) 6.1.0.7 and earlier has unknown impact and attack vectors, related to "incorrect authorization on a remote interface...Show more
Unspecified vulnerability in the Default Messaging Component in IBM WebSphere Application Server (WAS) 6.1.0.7 and earlier has unknown impact and attack vectors, related to "incorrect authorization on a remote interface to the SDO repository."Show less
1Ibm
1Websphere Application Server
Apr 23, 2026
Jun 19, 2007
N/A· v4
N/A· v3
7.8 HIGH· v2
Unspecified vulnerability in the Default Messaging Component in IBM WebSphere Application Server (WAS) 6.1.0.7 and earlier allows remote attackers to cause a denial of service related to a thread hang, and possibly relat...Show more
Unspecified vulnerability in the Default Messaging Component in IBM WebSphere Application Server (WAS) 6.1.0.7 and earlier allows remote attackers to cause a denial of service related to a thread hang, and possibly related to a "TCP issue," or to MPAlarmThread and a resultant memory leak.Show less
1Ibm
1Websphere Portal
Apr 23, 2026
Jun 19, 2007
N/A· v4
N/A· v3
6.4 MEDIUM· v2
SQL injection vulnerability in content.php in WSPortal 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the page parameter.
1Ibm
1Websphere Portal
Apr 23, 2026
Jun 19, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
content.php in WSPortal 1.0, when magic_quotes_gpc is disabled, allows remote attackers to obtain sensitive information via a "';" (quote semicolon) sequence in the page parameter, which reveals the installation path in...Show more
content.php in WSPortal 1.0, when magic_quotes_gpc is disabled, allows remote attackers to obtain sensitive information via a "';" (quote semicolon) sequence in the page parameter, which reveals the installation path in the resulting forced SQL error message.Show less
1Ibm
1Totalstorage Ds400
Apr 23, 2026
Jun 15, 2007
N/A· v4
N/A· v3
10.0 HIGH· v2
The IBM TotalStorage DS400 with firmware 4.15 uses a blank password for the (1) root, (2) user, (3) manager, (4) administrator, and (5) operator accounts, which allows remote attackers to gain login access via certain Li...Show more
The IBM TotalStorage DS400 with firmware 4.15 uses a blank password for the (1) root, (2) user, (3) manager, (4) administrator, and (5) operator accounts, which allows remote attackers to gain login access via certain Linux daemons, including a telnet daemon on a nonstandard port, tcp/6000.Show less
1Ibm
1Lotus Domino
Apr 23, 2026
Jun 6, 2007
N/A· v4
N/A· v3
9.3 HIGH· v2
IBM Lotus Domino 7.0.x before 7.0.3 does not revalidate the signature on a signed scheduled agent after the agent is modified, which allows remote authenticated users to gain privileges via a modified agent in a server d...Show more
IBM Lotus Domino 7.0.x before 7.0.3 does not revalidate the signature on a signed scheduled agent after the agent is modified, which allows remote authenticated users to gain privileges via a modified agent in a server database.Show less
1Ibm
1Lotus Domino Web Server
Apr 23, 2026
Jun 6, 2007
N/A· v4
N/A· v3
7.8 HIGH· v2
Unspecified vulnerability in the Lotus Domino Web Server 6.0, 6.5.x before 6.5.6, and 7.0.x before 7.0.3 allows remote attackers to cause a denial of service (daemon crash) via requests for URLs that reference certain fi...Show more
Unspecified vulnerability in the Lotus Domino Web Server 6.0, 6.5.x before 6.5.6, and 7.0.x before 7.0.3 allows remote attackers to cause a denial of service (daemon crash) via requests for URLs that reference certain files.Show less
1Ibm
1Aix
Apr 23, 2026
Jun 4, 2007
N/A· v4
N/A· v3
6.6 MEDIUM· v2
Unspecified vulnerability in perl.rte 5.8.0.10 through 5.8.0.95 on IBM AIX 5.2, and 5.8.2.10 through 5.8.2.50 on AIX 5.3, allows local users to gain privileges via unspecified vectors related to the installation and "wai...Show more
Unspecified vulnerability in perl.rte 5.8.0.10 through 5.8.0.95 on IBM AIX 5.2, and 5.8.2.10 through 5.8.2.50 on AIX 5.3, allows local users to gain privileges via unspecified vectors related to the installation and "waiting for a legitimate user to execute a binary that ships with Perl."Show less
1Ibm
1Aix
Apr 23, 2026
Jun 4, 2007
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Unspecified vulnerability in sysmgt.websm.rte in IBM AIX 5.2.0 and 5.3.0 has unknown impact and attack vectors.
1Ibm
1Db2
Apr 23, 2026
May 10, 2007
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple buffer overflows in the DB2 JDBC Applet Server (DB2JDS) service in IBM DB2 9.x and earlier allow remote attackers to (1) execute arbitrary code via a crafted packet to the DB2JDS service on tcp/6789; and cause a...Show more
Multiple buffer overflows in the DB2 JDBC Applet Server (DB2JDS) service in IBM DB2 9.x and earlier allow remote attackers to (1) execute arbitrary code via a crafted packet to the DB2JDS service on tcp/6789; and cause a denial of service via (2) an invalid LANG parameter or (2) a long packet that generates a "MemTree overflow."Show less
1Ibm
1Websphere Application Server
Apr 23, 2026
Apr 30, 2007
N/A· v4
N/A· v3
10.0 HIGH· v2
Unspecified vulnerability in IBM WebSphere Application Server (WAS) before 5.1.1.14, and WAS for z/OS 601 before 6.0.2.13, has unknown impact and attack vectors, related to a "Potential security exposure," aka PK26123.
1Ibm
1Tivoli Monitoring Express
Apr 23, 2026
Apr 22, 2007
N/A· v4
N/A· v3
10.0 HIGH· v2
Heap-based buffer overflow in kde.dll in IBM Tivoli Monitoring Express 6.1.0 before Fix Pack 2, as used in Tivoli Universal Agent, Windows OS Monitoring agent, and Enterprise Portal Server, allows remote attackers to exe...Show more
Heap-based buffer overflow in kde.dll in IBM Tivoli Monitoring Express 6.1.0 before Fix Pack 2, as used in Tivoli Universal Agent, Windows OS Monitoring agent, and Enterprise Portal Server, allows remote attackers to execute arbitrary code by sending a long string to a certain TCP port.Show less
1Ibm
1Websphere Application Server
Apr 23, 2026
Apr 11, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
Unspecified vulnerability in the Servlet Engine/Web Container in IBM WebSphere Application Server (WAS) before 6.1.0.7 has unknown impact and attack vectors.
1Ibm
1Websphere Application Server
Apr 23, 2026
Apr 11, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Java Message Service (JMS) in IBM WebSphere Application Server (WAS) before 6.1.0.7 allows attackers to cause a denial of service via unknown vectors involving the "double release [of] a bytebuffer input stream," pos...Show more
The Java Message Service (JMS) in IBM WebSphere Application Server (WAS) before 6.1.0.7 allows attackers to cause a denial of service via unknown vectors involving the "double release [of] a bytebuffer input stream," possibly a double free vulnerability.Show less
1Ibm
1Lotus Notes
Apr 23, 2026
Apr 11, 2007
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the Active Content Filter feature in Domino Web Access (DWA) in IBM Lotus Notes before 6.5.6 and 7.x before 7.0.2 FP1 allows remote attackers to inject arbitrary web script or...Show more
Cross-site scripting (XSS) vulnerability in the Active Content Filter feature in Domino Web Access (DWA) in IBM Lotus Notes before 6.5.6 and 7.x before 7.0.2 FP1 allows remote attackers to inject arbitrary web script or HTML via a multipart/related e-mail message, a different issue than CVE-2006-4843.Show less
1Ibm
1Tivoli Business Service Manager
Apr 23, 2026
Apr 11, 2007
N/A· v4
N/A· v3
4.9 MEDIUM· v2
IBM Tivoli Business Service Manager (TBSM) 4.1 before Interim Fix 1 logs passwords in plaintext, which allows local users to obtain sensitive information by reading (1) ncisetup.db or (2) msi.log.
1Ibm
1Tivoli Provisioning Manager Os Deployment
Apr 23, 2026
Apr 4, 2007
N/A· v4
N/A· v3
10.0 HIGH· v2
The management service in IBM Tivoli Provisioning Manager for OS Deployment before 5.1 Fix Pack 2 does not properly handle multipart/form-data in HTTP POST requests, which allows remote attackers to execute arbitrary cod...Show more
The management service in IBM Tivoli Provisioning Manager for OS Deployment before 5.1 Fix Pack 2 does not properly handle multipart/form-data in HTTP POST requests, which allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via crafted POST requests to port 8080/tcp or 443/tcp.Show less