Ibm
ibm
8,704 CVEs • 1,613 products
Products (1,613)
Click to collapseToggle
Products (1,613)
Click to collapse
CVEs (8,704)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ibm 1Engineering Requirements Management Doors Next Jun 17, 2026 Oct 12, 2025 N/A· v4 3.5 LOW· v3 N/A· v2 IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1
could allow an authenticated user on the network to delete comments from other users due to client-side enforcement of server-side security. |
IBM Aspera 5.0.0 through 5.0.13.1
could disclose sensitive user information from the system to an authenticated user due to an observable discrepancy of returned data. |
IBM Aspera Faspex 5.0.0 through 5.0.13.1 could allow a privileged user to cause a denial of service from improperly validated API input due to excessive resource consumption. |
IBM Aspera Faspex 5.0.0 through 5.0.13.1 uses a cross-domain policy file that includes domains that should not be trusted. |
1Ibm 1Infosphere Data Replication Vsam For Z/os Remote Source Jun 17, 2026 Oct 7, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 IBM InfoSphere Data Replication VSAM for z/OS Remote Source 11.4 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local user with access to the files storing CECSUB or CECRM on the co...Show more |
IBM Engineering Requirements Management DOORS Next (IBM Jazz Foundation 7.0.2 to 7.0.2 iFix034, 7.0.3 to 7.0.3 iFix016, and 7.1.0 to 7.1.0 iFix004) is vulnerable to stored cross-site scripting. This vulnerability allows...Show more |
1Ibm 4Security Verify Access Security Verify Access DockerVerify Identity Access+1 moreJun 17, 2026 Oct 6, 2025 N/A· v4 9.3 CRITICAL· v3 N/A· v2 IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 could allow a locally authenticated user to escalate their privileges to root due to execution with...Show more |
1Ibm 4Security Verify Access Security Verify Access DockerVerify Identity Access+1 moreJun 17, 2026 Oct 6, 2025 N/A· v4 8.5 HIGH· v3 N/A· v2 IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 could allow a locally authenticated user to execute malicious scripts from outside of its control...Show more |
1Ibm 4Security Verify Access Security Verify Access DockerVerify Identity Access+1 moreJun 17, 2026 Oct 6, 2025 N/A· v4 7.3 HIGH· v3 N/A· v2 IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 could allow an unauthenticated user to execute arbitrary commands with lower user privileges on...Show more |
1Ibm 1Transformation Extender Advanced Jun 17, 2026 Oct 6, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 IBM Standards Processing Engine 10.0.1.10 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe java deserialization. By sending specially crafted input, an attacker could exploit thi...Show more |
1Ibm 1Transformation Extender Advanced Jun 17, 2026 Oct 1, 2025 N/A· v4 6.2 MEDIUM· v3 N/A· v2 IBM Transformation Extender Advanced 10.0.1
could allow a local user to perform unauthorized actions due to improper access controls. |
1Ibm 1Transformation Extender Advanced Jun 17, 2026 Oct 1, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 IBM Transformation Extender Advanced 10.0.1
does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. |
1Ibm 1Transformation Extender Advanced Jun 17, 2026 Oct 1, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 IBM Transformation Extender Advanced 10.0.1
does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. |
1Ibm 1Transformation Extender Advanced Jun 17, 2026 Oct 1, 2025 N/A· v4 4.4 MEDIUM· v3 N/A· v2 IBM Transformation Extender Advanced 10.0.1 stores potentially sensitive information in log files that could be read by a local user. |
IBM Planning Analytics Local 2.0.0 through 2.0.106 and 2.1.0 through 2.1.13 could allow a malicious privileged user to bypass the UI to gain unauthorized access to sensitive information due to the improper validation o...Show more |
IBM Planning Analytics Local 2.0.0 through 2.0.106 and 2.1.0 through 2.1.13 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus alt...Show more |
IBM InfoSphere 11.7.0.0 through 11.7.1.6 Information Server could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input. |
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to a denial of service, caused by sending a specially-crafted request. A privileged user could exploit this vulnerability to cause the server to consume memory r...Show more |
IBM License Metric Tool 9.2.0 through 9.2.40 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended funct...Show more |
IBM License Metric Tool 9.2.0 through 9.2.40
could allow an authenticated user to bypass access controls in the REST API interface and perform unauthorized actions. |