Vulnerability index

Browse CVEs

37 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Db2 MEDIUM 5.5
CVE-2026-10695

IBM Db2 12.1.0 through 12.1.4 federated server is vulnerable to a denial of service when running non fenced federated queries.

Fix: 12.1.5+
Fix from $1,600 2026-07-30
Engineering Requirements Management Doors Web Access HIGH 7.5
CVE-2024-25039

IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 do not limit the length of …

Fix: after 9.7.2.11
Fix from $1,950 2026-07-30
Websphere Application Server HIGH 7.5
CVE-2026-9322

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to a denial of …

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $1,950 2026-07-30
Websphere Application Server HIGH 7.5
CVE-2026-14981

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are affected by a denial of se…

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $1,950 2026-07-28
Powervm Novalink HIGH 7.5
CVE-2026-9171

IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to a denial of service, caused by sending a specially-crafte…

No fix yet
Fix from $1,950 2026-07-17
Websphere Extreme Scale MEDIUM 6.5
CVE-2026-9002

IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 could allow an adjacent attacker to cause a denial of service due to improper validation in the X…

Fix: after 8.6.1.6
Fix from $1,600 2026-06-30
Websphere Application Server HIGH 7.5
CVE-2026-9071

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of …

Fix: 8.5.5.30 / 9.0.5.29+
Fix from $1,950 2026-06-22
Websphere Application Server HIGH 7.5
CVE-2026-9320

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of …

Fix: 8.5.5.30 / 9.0.5.29+
Fix from $1,950 2026-06-22
Db2 HIGH 7.5
CVE-2026-6051

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service when executing a specially crafted query with a small s…

Fix: after 12.1.4
Fix from $1,950 2026-05-27
Db2 HIGH 7.5
CVE-2026-6052

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to running out of memory when executing certain queries with MDC tables.

Fix: after 12.1.4
Fix from $1,950 2026-05-27
Websphere Application Server HIGH 7.5
CVE-2026-4410

IBM WebSphere Application Server - Liberty 19.0.0.7 through 26.0.0.5 and IBM WebSphere Application Server 9.0, and 8.5 and WebSphere Application Serv…

Fix: after 26.0.0.5
Fix from $1,950 2026-05-27
HTTP Server CRITICAL 9.1
CVE-2026-8856

IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configurations where an attacker has write access to parts of the server configura…

Fix: 8.5.5.30 / 9.0.5.29+
Fix from $2,300 2026-05-26
Common Cryptographic Architecture HIGH 7.5
CVE-2023-47150

IBM Common Cryptographic Architecture (CCA) 7.0.0 through 7.5.36 could allow a remote user to cause a denial of service due to incorrect data handlin…

Fix: 7.5.37+
Fix from $1,950 2024-03-26
Integration Bus MEDIUM 6.5
CVE-2024-22332

The IBM Integration Bus for z/OS 10.1 through 10.1.0.2 AdminAPI is vulnerable to a denial of service due to file system exhaustion. IBM X-Force ID: …

Fix: after 10.1.0.2
Fix from $1,600 2024-02-09
Sterling B2b Integrator MEDIUM 6.5
CVE-2023-32341

IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.3 could allow an authenticated user to cause a denial of service due to…

Fix: after 6.1.2.3
Fix from $1,600 2024-02-09
Security Verify Access HIGH 7.5
CVE-2023-31006

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 …

Fix: after 10.0.6.1
Fix from $1,950 2024-02-03
Security Verify Access HIGH 7.5
CVE-2023-30999

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 …

Fix: after 10.0.6.1
Fix from $1,950 2024-02-03
Db2 HIGH 7.5
CVE-2023-40692

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, 11.5 is vulnerable to denial of service under extreme stress conditions…

Patch available
Fix from $1,950 2023-12-04
Vios MEDIUM 5.5
CVE-2023-45167

IBM AIX's 7.3 Python implementation could allow a non-privileged local user to exploit a vulnerability to cause a denial of service. IBM X-Force ID:…

No fix yet
Fix from $1,600 2023-11-10
Security Verify Access Oidc Provider HIGH 7.5
CVE-2022-43740

IBM Security Verify Access OIDC Provider could allow a remote user to cause a denial of service due to uncontrolled resource consumption. IBM X-Forc…

Patch available
Fix from $1,950 2023-10-14
Websphere Application Server HIGH 7.5
CVE-2023-38737

IBM WebSphere Application Server Liberty 22.0.0.13 through 23.0.0.7 is vulnerable to a denial of service, caused by sending a specially-crafted reque…

Fix: after 23.0.0.7
Fix from $1,950 2023-08-16
Txseries For Multiplatform HIGH 7.5
CVE-2023-38741

IBM TXSeries for Multiplatforms 8.1, 8.2, and 9.1 is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual r…

Mitigation only
Fix from $1,950 2023-08-14
Security Directory Suite Va HIGH 7.5
CVE-2022-33168

IBM Security Directory Suite VA 8.0.1 could allow an attacker to cause a denial of service due to uncontrolled resource consumption. IBM X-Force ID:…

Patch available
Fix from $1,950 2023-06-15
Mq Appliance MEDIUM 5.5
CVE-2023-22874

IBM MQ Clients 9.2 CD, 9.3 CD, and 9.3 LTS are vulnerable to a denial of service attack when processing configuration files. IBM X-Force ID: 244216.

Fix: 9.3.0.5 / 9.3.2+
Fix from $1,600 2023-05-05
Sterling Partner Engagement Manager MEDIUM 6.5
CVE-2022-34335

IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.1 could allow an authenticated user to exhaust server resources which could lead to a d…

Patch available
Fix from $1,600 2023-01-11
Vios MEDIUM 6.2
CVE-2022-39164

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service.…

Patch available
Fix from $1,600 2022-12-23
Vios MEDIUM 6.2
CVE-2022-39165

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a non-privileged local user to exploit a vulnerability in CAA to cause a denial of service. IBM X-For…

Patch available
Fix from $1,600 2022-12-23
Spectrum Protect Plus HIGH 7.5
CVE-2020-5023

IBM Spectrum Protect Plus 10.1.0 through 10.1.7 could allow a remote user to inject arbitrary data iwhich could cause the serivce to crash due to exc…

Fix: after 10.1.7
Fix from $1,950 2021-02-10
Mq Internet Pass Thru HIGH 7.5
CVE-2020-4766

IBM MQ Internet Pass-Thru 2.1 and 9.2 could allow a remote user to cause a denial of service by sending malformed MQ data requests which would consum…

Patch available
Fix from $1,950 2021-01-22
Websphere Mq MEDIUM 6.5
CVE-2012-4863

IBM WebSphere MQ 7.1 and 7.5: Queue manager has a DoS vulnerability

Fix: 7.1.0.2 / 7.5.0.1+
Fix from $1,600 2020-01-23