Vulnerability index

Browse CVEs

385 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Websphere Application Server CRITICAL 9.8
CVE-2026-11714

IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability with the apiDiscovery-1.0 feature enabled.

Fix: 26.0.0.8+
Fix from $2,300 2026-06-30
Business Automation Manager CRITICAL 9.1
CVE-2026-13449

IBM Business Automation Manager Open Editions 9.0.0 through 9.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML …

Fix: 9.5.0+
Fix from $2,300 2026-06-30
Websphere Application Server CRITICAL 9.8
CVE-2026-11546

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the adminCenter-…

Fix: 26.0.0.8+
Fix from $2,300 2026-06-30
Websphere Application Server CRITICAL 9.3
CVE-2026-11708

IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console's integrated help sys…

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $2,300 2026-06-30
Websphere Application Server CRITICAL 9.3
CVE-2026-11712

IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console help system.

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $2,300 2026-06-30
Db2 CRITICAL 9.8
CVE-2026-10109

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution due to improper pre-auth DRDA handshake handling.

Fix: after 12.1.4
Fix from $2,300 2026-06-30
I CRITICAL 9.8
CVE-2026-9072

IBM WebSphere Application Server and IBM WebSphere Application Server Liberty - when using Intelligent Management with the WebSphere WebServer Plug-i…

Fix: after 7.6
Fix from $2,300 2026-06-22
Websphere Application Server CRITICAL 9.1
CVE-2026-9006

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an a…

Fix: 8.5.5.30 / 9.0.5.29+
Fix from $2,300 2026-06-22
Websphere Application Server CRITICAL 9.1
CVE-2026-8646

IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to HTTP request …

Fix: 8.5.5.30 / 9.0.5.29+
Fix from $2,300 2026-06-22
Storage Protect CRITICAL 9.1
CVE-2026-12628

IBM Storage Protect Client 8.1.0.0 through 8.2.1.0 and IBM Storage Protect Snapshot For Windows 8.1.0.0 through 8.2.1.0 could allow a remote attacker…

Fix: 8.2.1.1+
Fix from $2,300 2026-06-22
Websphere Application Server CRITICAL 9.1
CVE-2026-8644

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing.

Fix: 8.5.5.30 / 9.0.5.29+
Fix from $2,300 2026-06-01
Websphere Application Server CRITICAL 9.0
CVE-2026-9311

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security controls.

Fix: 8.5.5.30 / 9.0.5.29+
Fix from $2,300 2026-06-01
Websphere Application Server CRITICAL 9.0
CVE-2026-9319

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of untrusted data via JAX-WS en…

Fix: 8.5.5.30 / 9.0.5.29+
Fix from $2,300 2026-06-01
Aspera High Speed Transfer Endpoint CRITICAL 9.8
CVE-2026-8175

IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and I…

Fix: after 4.4.6
Fix from $2,300 2026-05-27
Aspera High Speed Transfer Server For Cloud Pak For Integration CRITICAL 9.1
CVE-2026-7876

IBM Aspera HSTS for CP4I 1.5.1 through 1.5.19 is affected by an authentication bypass vulnerability. A transfer client may be able to take advantage …

Fix: 1.5.20+
Fix from $2,300 2026-05-27
Operations Analytics Log Analysis CRITICAL 9.8
CVE-2024-40684

IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, and 1.3.8.0, 1.3.8.1, 1.3.8.…

Mitigation only
Fix from $2,300 2026-05-27
Engineering Lifecycle Management CRITICAL 9.8
CVE-2026-3660

IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an unauthenticated remote attacker to update server property files that woul…

Mitigation only
Fix from $2,300 2026-05-26
HTTP Server CRITICAL 9.8
CVE-2026-8855

IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial of service in configurations with TLS mutual authentication (client au…

Fix: 8.5.5.30 / 9.0.5.29+
Fix from $2,300 2026-05-26
HTTP Server CRITICAL 9.8
CVE-2026-9170

IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service and a potential remote code execution due to improper input validation.

Mitigation only
Fix from $2,300 2026-05-26
HTTP Server CRITICAL 9.1
CVE-2026-8856

IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configurations where an attacker has write access to parts of the server configura…

Fix: 8.5.5.30 / 9.0.5.29+
Fix from $2,300 2026-05-26
Websphere Application Server CRITICAL 9.8
CVE-2026-8633

IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Se…

Fix: after 9.0.5.27
Fix from $2,300 2026-05-26
Cloud Pak For Data System Cyclops CRITICAL 9.8
CVE-2025-36220

IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System is vulnerable to SQL injection. A remote atta…

Fix: 11.3.0.2+
Fix from $2,300 2026-05-26
I CRITICAL 9.8
CVE-2026-2311

IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 s vulnerable to privilege escalation caused by an invalid IBM i Web Administration GUI authorization check.  A mali…

Mitigation only
Fix from $2,300 2026-04-30
Total Storage Service Console CRITICAL 9.8
CVE-2026-5935

IBM Total Storage Service Console (TSSC) / TS4500 IMC 9.2, 9.3, 9.4, 9.5, 9.6 TSSC/IMC could allow an unauthenticated user to execute arbitrary comma…

Mitigation only
Fix from $2,300 2026-04-23
Security Verify Access CRITICAL 9.8
CVE-2026-4101

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Acces…

Fix: after 11.0.2.0
Fix from $2,300 2026-04-01
Websphere Application Server CRITICAL 9.8
CVE-2025-14917

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty could provide weaker than expected secu…

Fix: 26.0.0.4+
Fix from $2,300 2026-03-25
Db2 Recovery Expert CRITICAL 9.1
CVE-2026-3856

IBM Db2 Recovery Expert for Linux, UNIX and Windows 5.5 IF 2 could allow an attacker to modify or corrupt data due to an insecure mechanism used for …

Patch available
Fix from $2,300 2026-03-17
Websphere Application Server CRITICAL 9.8
CVE-2025-14923

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.2 IBM WebSphere Application Server Liberty could provide weaker than expected secu…

Fix: 26.0.0.3+
Fix from $2,300 2026-03-03
Concert CRITICAL 9.8
CVE-2025-33089

IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information or perform unauthorized actions due to the use of hard …

Fix: 2.2.0+
Fix from $2,300 2026-02-17
Applinx CRITICAL 9.8
CVE-2025-36418

IBM ApplinX 11.1 is vulnerable due to a privilege escalation vulnerability due to improper verification of JWT tokens. An attacker may be able to cra…

Mitigation only
Fix from $2,300 2026-01-20