Vulnerability index

Browse CVEs

47 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Websphere Application Server MEDIUM 5.3
CVE-2026-10571

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service caused by insecure deserialization. A low-pri…

No fix yet
Fix from $4,000 2026-08-13
Websphere Application Server HIGH 8.5
CVE-2026-11536

IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability in the SOAP/JMX connector.

Fix: 8.5.5.29 / 9.0.5.28+
Fix from $1,950 2026-07-30
Webmethods Integration CRITICAL 9.8
CVE-2026-12118

IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the d…

No fix yet
Fix from $2,300 2026-07-30
Websphere Application Server CRITICAL 9.8
CVE-2026-14974

IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of…

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $2,300 2026-07-28
Websphere Application Server CRITICAL 9.8
CVE-2026-14512

IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attac…

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $2,300 2026-07-28
Websphere Extreme Scale HIGH 8.8
CVE-2026-13759

IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 ships three ObjectInputStream subclasses (WsObjectInputStream, ObjectStreamPool$ReusableInputStre…

Fix: after 8.6.1.6
Fix from $1,950 2026-06-30
Websphere Application Server CRITICAL 9.0
CVE-2026-9319

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of untrusted data via JAX-WS en…

Fix: 8.5.5.30 / 9.0.5.29+
Fix from $2,300 2026-06-01
Websphere Application Server HIGH 8.5
CVE-2026-9330

IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validation of user-supplied data during deserialization using the SAML Web S…

Fix: 8.5.5.30 / 9.0.5.29+
Fix from $1,950 2026-06-01
Webmethods Integration HIGH 8.8
CVE-2025-36072

IBM webMethods Integration 10.11 through 10.11_Core_Fix22, 10.15 through 10.15_Core_Fix22, and 11.1 through 11.1_Core_Fix6 IBM webMethods Integration…

Mitigation only
Fix from $1,950 2025-11-20
Transformation Extender Advanced CRITICAL 9.8
CVE-2023-49886

IBM Standards Processing Engine 10.0.1.10 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe java deserializa…

Mitigation only
Fix from $2,300 2025-10-06
Websphere Application Server CRITICAL 9.8
CVE-2025-36038EPSS 9%

IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially crafted sequence …

Fix: 8.5.5.28 / 9.0.5.25+
Fix from $2,300 2025-06-25
Qiskit CRITICAL 9.8
CVE-2025-2000

A maliciously crafted QPY file can potential execute arbitrary-code embedded in the payload without privilege escalation when deserialising QPY forma…

Fix: 1.4.2+
Fix from $2,300 2025-03-14
Qiskit HIGH 8.6
CVE-2025-1403

Qiskit SDK 0.45.0 through 1.2.4 could allow a remote attacker to cause a denial of service using a maliciously crafted QPY file containing a malforme…

Fix: after 1.2.4
Fix from $1,950 2025-02-21
Cognos Controller HIGH 8.8
CVE-2024-28777

IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to unrestricted deserialization. This vulnerability allow…

Fix: 11.0.1.4+
Fix from $1,950 2025-02-19
Sterling B2b Integrator HIGH 8.8
CVE-2024-31903

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 allow an attacker on the local network to execute ar…

Fix: after 6.2.0.2
Fix from $1,950 2025-01-22
Cloud Pak For Multicloud Management Monitoring HIGH 8.8
CVE-2024-43191

IBM ManageIQ could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted yaml file request.

Mitigation only
Fix from $1,950 2024-09-26
I HIGH 7.5
CVE-2024-31879

IBM i 7.2, 7.3, and 7.4 could allow a remote attacker to execute arbitrary code leading to a denial of service of network ports on the system, caused…

Mitigation only
Fix from $1,950 2024-05-18
Java Software Development Kit HIGH 7.5
CVE-2023-38264

The IBM SDK, Java Technology Edition's Object Request Broker (ORB) 7.1.0.0 through 7.1.5.21 and 8.0.0.0 through 8.0.8.21 is vulnerable to a denial of…

Fix: 7.1.5.22 / 8.0.8.25+
Fix from $1,950 2024-05-14
Qiskit Ibm Runtime HIGH 7.8
CVE-2024-29032

Qiskit IBM Runtime is an environment that streamlines quantum computations and provides optimal implementations of the Qiskit quantum computing SDK. …

Fix: 0.21.2+
Fix from $1,950 2024-03-20
Operational Decision Manager HIGH 8.8
CVE-2024-22320EPSS 73%

IBM Operational Decision Manager 8.10.3 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unsafe dese…

Patch available
Fix from $1,950 2024-02-02
Sdk CRITICAL 9.8
CVE-2022-40609

IBM SDK, Java Technology Edition 7.1.5.18 and 8.0.8.0 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe dese…

Fix: 7.1.5.19 / 8.0.8.5+
Fix from $2,300 2023-08-02
B2b Advanced Communications MEDIUM 6.5
CVE-2023-24971

IBM B2B Advanced Communications 1.0.0.0 and IBM Multi-Enterprise Integration Gateway 1.0.0.1 could allow a user to cause a denial of service due to t…

Fix: 1.0.0.8+
Fix from $1,600 2023-07-31
Infosphere Information Server CRITICAL 9.8
CVE-2023-32336

IBM InfoSphere Information Server 11.7 is affected by a remote code execution vulnerability due to insecure deserialization in an RMI service. IBM X…

Mitigation only
Fix from $2,300 2023-05-22
Aspera Faspex CRITICAL 9.8
CVE-2022-47986 KEVEPSS 100%

IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserializa…

Fix: after 4.4.1
Fix from $2,300 2023-02-17
Partner Engagement Manager CRITICAL 9.8
CVE-2021-29781

IBM Partner Engagement Manager 2.0 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization flaw. B…

Patch available
Fix from $2,300 2021-07-30
Mq CRITICAL 9.8
CVE-2020-4682EPSS 8%

IBM MQ 7.5, 8.0, 9.0, 9.1, 9.2 LTS, and 9.2 CD could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserializa…

Patch available
Fix from $2,300 2021-01-28
Qradar Security Information And Event Manager HIGH 8.8
CVE-2020-4888EPSS 62%

IBM QRadar SIEM 7.4.0 to 7.4.2 Patch 1 and 7.3.0 to 7.3.3 Patch 7 could allow a remote attacker to execute arbitrary commands on the system, caused b…

Patch available
Fix from $1,950 2021-01-28
Infosphere Information Server CRITICAL 9.8
CVE-2020-27583

IBM InfoSphere Information Server 8.5.0.0 is affected by deserialization of untrusted data which could allow remote unauthenticated attackers to exec…

No fix yet
Fix from $2,300 2021-01-26
Sterling B2b Integrator HIGH 8.8
CVE-2019-4728

IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_2, 6.0.0.0 through 6.0.3.2, and 6.1.0.0 could allow a remote attacker to execute…

Fix: after 6.0.3.2
Fix from $1,950 2021-01-05
Qradar Security Information And Event Manager HIGH 8.8
CVE-2020-4280EPSS 73%

IBM QRadar SIEM 7.3 and 7.4 could allow a remote attacker to execute arbitrary commands on the system, caused by insecure deserialization of user-sup…

Fix: after 7.4.1
Fix from $1,950 2020-10-08