← Back

Ibm

ibm

8,704 CVEs • 1,613 products

Products (1,613)

Click to collapse
Toggle
Aix
aix
Db2
db2
Vios
vios
I
i
Websphere Mq
websphere_mq
Lotus Domino
lotus_domino
Api Connect
api_connect
Lotus Notes
lotus_notes
Concert
concert
Aspera Faspex
aspera_faspex
Mq Appliance
mq_appliance
Mq
mq
Sametime
sametime
Cics Tx
cics_tx
Connections
connections
Java
java
Domino
domino

CVEs (8,704)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Os 400
Apr 23, 2026
Jan 23, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in IBM OS/400 R530 and R535 has unknown impact and remote attack vectors, related to an "Integrity Problem" involving LIC-TCPIP and TCP reset. NOTE: it is possible that this issue is related to...Show more
Unspecified vulnerability in IBM OS/400 R530 and R535 has unknown impact and remote attack vectors, related to an "Integrity Problem" involving LIC-TCPIP and TCP reset. NOTE: it is possible that this issue is related to CVE-2004-0230, but this is not certain.Show less
1Ibm
1Aix
Apr 23, 2026
Jan 19, 2007
N/A· v4
N/A· v3
4.6 MEDIUM· v2
IBM AIX 5.3 does not properly verify the status of file descriptors before setuid execution, which allows local users to gain privileges by closing file descriptor 0, 1, or 2 and then invoking a setuid program, a variant...Show more
IBM AIX 5.3 does not properly verify the status of file descriptors before setuid execution, which allows local users to gain privileges by closing file descriptor 0, 1, or 2 and then invoking a setuid program, a variant of CVE-2002-0572.Show less
1Ibm
1Aix
Apr 23, 2026
Dec 31, 2006
N/A· v4
N/A· v3
4.0 MEDIUM· v2
ftpd in IBM AIX 5.2.0 and 5.3.0 allows remote authenticated users to cause a denial of service (port exhaustion) via unspecified vectors. NOTE: some details were obtained from third party sources.
1Ibm
1Aix
Apr 23, 2026
Dec 31, 2006
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in ftpd in IBM AIX 5.2.0 and 5.3.0 allows remote attackers to obtain sensitive information, including passwords, via unspecified vectors.
1Ibm
1Os 400
Apr 23, 2026
Dec 31, 2006
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple unspecified vulnerabilities in osp-cert in IBM OS/400 V5R3M0 have unspecified impact and attack vectors, related to ASN.1 parsing.
1Ibm
1Db2 Universal Database
Apr 23, 2026
Dec 19, 2006
N/A· v4
N/A· v3
5.0 MEDIUM· v2
IBM DB2 8.1 before FixPak 14 allows remote attackers to cause a denial of service via a crafted SQLJRA packet, which causes a NULL pointer dereference in the sqle_db2ra_as_recvrequest function in DB2ENGN.DLL, a different...Show more
IBM DB2 8.1 before FixPak 14 allows remote attackers to cause a denial of service via a crafted SQLJRA packet, which causes a NULL pointer dereference in the sqle_db2ra_as_recvrequest function in DB2ENGN.DLL, a different issue than CVE-2006-4257.Show less
1Ibm
1Websphere Application Server
Apr 23, 2026
Dec 19, 2006
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Servlet Engine and Web Container in IBM WebSphere Application Server (WAS) before 6.0.2.17, when ibm-web-ext.xmi sets fileServingEnabled to true and servlet caching is enabled, allows remote attackers to obtain JSP s...Show more
The Servlet Engine and Web Container in IBM WebSphere Application Server (WAS) before 6.0.2.17, when ibm-web-ext.xmi sets fileServingEnabled to true and servlet caching is enabled, allows remote attackers to obtain JSP source code and other sensitive information via "specific requests."Show less
1Ibm
1Websphere Application Server
Apr 23, 2026
Dec 19, 2006
N/A· v4
N/A· v3
10.0 HIGH· v2
Unspecified vulnerability in the Utility Classes for IBM WebSphere Application Server (WAS) before 5.1.1.13 and 6.x before 6.0.2.17 has unknown impact and attack vectors.
1Ibm
1Tivoli Identity Manager
Apr 23, 2026
Dec 18, 2006
N/A· v4
N/A· v3
2.7 LOW· v2
The Java Key Store (JKS) for WebSphere Application Server (WAS) for IBM Tivoli Identity Manager (ITIM) 4.6 places the JKS password in a -Djavax.net.ssl.trustStorePassword command line argument, which allows local users t...Show more
The Java Key Store (JKS) for WebSphere Application Server (WAS) for IBM Tivoli Identity Manager (ITIM) 4.6 places the JKS password in a -Djavax.net.ssl.trustStorePassword command line argument, which allows local users to obtain the password by listing the process or using other methods.Show less
1Ibm
1Websphere Host On Demand
Apr 23, 2026
Dec 14, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
IBM WebSphere Host On-Demand 6.0, 7.0, 8.0, 9.0, and possibly 10, allows remote attackers to bypass authentication via a modified pnl parameter, related to hod/HODAdmin.html and hod/frameset.html.
1Ibm
1Tivoli Storage Manager
Apr 23, 2026
Dec 6, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple array index errors in IBM Tivoli Storage Manager (TSM) before 5.2.9 and 5.3.x before 5.3.4 allow remote attackers to read arbitrary memory locations and cause a denial of service (crash) via a large index value...Show more
Multiple array index errors in IBM Tivoli Storage Manager (TSM) before 5.2.9 and 5.3.x before 5.3.4 allow remote attackers to read arbitrary memory locations and cause a denial of service (crash) via a large index value in unspecified messages, a different issue than CVE-2006-5855.Show less
1Ibm
1Tivoli Storage Manager
Apr 23, 2026
Dec 6, 2006
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple buffer overflows in IBM Tivoli Storage Manager (TSM) before 5.2.9 and 5.3.x before 5.3.4 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in (1) t...Show more
Multiple buffer overflows in IBM Tivoli Storage Manager (TSM) before 5.2.9 and 5.3.x before 5.3.4 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in (1) the language field at logon that begins with a 0x18 byte, (2) two unspecified parameters to the SmExecuteWdsfSession function, and (3) the contact field in an open registration message.Show less
1Ibm
1Websphere Application Server
Apr 23, 2026
Nov 28, 2006
N/A· v4
N/A· v3
10.0 HIGH· v2
IBM WebSphere Application Server 6.1.0 before Fix Pack 3 (6.1.0.3) does not perform EAL4 authentication checks at the proper time during "registering of response operation," which has unknown impact and attack vectors.
1Ibm
1Websphere Application Server
Apr 23, 2026
Nov 28, 2006
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple unspecified vulnerabilities in IBM WebSphere Application Server 6.1.0 before Fix Pack 3 (6.1.0.3) have unknown impact and attack vectors, related to (1) a "Potential security vulnerability" (PK29725) and (2) "Po...Show more
Multiple unspecified vulnerabilities in IBM WebSphere Application Server 6.1.0 before Fix Pack 3 (6.1.0.3) have unknown impact and attack vectors, related to (1) a "Potential security vulnerability" (PK29725) and (2) "Potential security exposure" (PK30831).Show less
1Ibm
1Lotus Notes
Apr 23, 2026
Nov 10, 2006
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Notes Remote Procedure Call (NRPC) protocol in IBM Lotus Notes Domino before 6.5.5 FP2 and 7.x before 7.0.2 does not require authentication to perform user lookups, which allows remote attackers to obtain the user ID...Show more
The Notes Remote Procedure Call (NRPC) protocol in IBM Lotus Notes Domino before 6.5.5 FP2 and 7.x before 7.0.2 does not require authentication to perform user lookups, which allows remote attackers to obtain the user ID file.Show less
1Ibm
1Lotus Domino
Apr 23, 2026
Nov 8, 2006
N/A· v4
N/A· v3
7.2 HIGH· v2
Multiple buffer overflows in tunekrnl in IBM Lotus Domino 6.x before 6.5.5 FP2 and 7.x before 7.0.2 allow local users to gain privileges and execute arbitrary code via unspecified vectors.
1Ibm
3Informix Client Sdk
Informix Dynamic ServerInformix I Connect
Apr 23, 2026
Nov 3, 2006
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The installation script in IBM Informix Dynamic Server 10.00, Informix Client Software Development Kit (CSDK) 2.90, and Informix I-Connect 2.90 allows local users to "compromise security" via a symlink attack on temporar...Show more
The installation script in IBM Informix Dynamic Server 10.00, Informix Client Software Development Kit (CSDK) 2.90, and Informix I-Connect 2.90 allows local users to "compromise security" via a symlink attack on temporary files.Show less
1Ibm
3Informix Client Sdk
Informix Dynamic ServerInformix I Connect
Apr 23, 2026
Nov 3, 2006
N/A· v4
N/A· v3
4.6 MEDIUM· v2
IBM Informix Dynamic Server 10.00, Informix Client Software Development Kit (CSDK) 2.90, and Informix I-Connect 2.90 use insecure permissions for installation scripts, which allows local users to gain privileges by modif...Show more
IBM Informix Dynamic Server 10.00, Informix Client Software Development Kit (CSDK) 2.90, and Informix I-Connect 2.90 use insecure permissions for installation scripts, which allows local users to gain privileges by modifying the scripts.Show less
1Ibm
1Websphere Application Server
Apr 23, 2026
Oct 17, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
The Web Services Notification (WSN) security component of IBM WebSphere Application Server before 6.1.0.2 allows attackers to obtain unspecified access without supplying a username and password, aka PK28374.
1Ibm
1Websphere Application Server
Apr 23, 2026
Oct 17, 2006
N/A· v4
N/A· v3
10.0 HIGH· v2
Unspecified vulnerability in IBM WebSphere Application Server before 6.1.0.2 has unspecified impact and attack vectors, related to a "possible security exposure," aka PK29360.