Vulnerability index

Browse CVEs

56 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Application Gateway Operator CRITICAL 9.8
CVE-2026-17617

IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of URLs specif…

Fix: after 26.6.0
Fix from $2,300 2026-08-05
Websphere Extreme Scale CRITICAL 10.0
CVE-2026-13773

IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 Approximately 50 generated CORBA stub classes in WebSphere eXtreme Scale's ogclient.jar call ORB.…

Fix: after 8.6.1.6
Fix from $2,300 2026-06-30
Websphere Application Server CRITICAL 9.8
CVE-2026-11714

IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability with the apiDiscovery-1.0 feature enabled.

Fix: 26.0.0.8+
Fix from $2,300 2026-06-30
Websphere Application Server CRITICAL 9.8
CVE-2026-11546

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the adminCenter-…

Fix: 26.0.0.8+
Fix from $2,300 2026-06-30
Websphere Application Server CRITICAL 9.1
CVE-2026-9006

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an a…

Fix: 8.5.5.30 / 9.0.5.29+
Fix from $2,300 2026-06-22
Watson Speech Services Cartridge MEDIUM 6.0
CVE-2026-7253

IBM Sterling B2B Integrator and IBM Sterling File Gateway are vulnerable to SQL injection. A privileged user could send specially crafted SQL stateme…

Fix: 5.3.1+
Fix from $1,600 2026-06-22
Webmethods Integration Server MEDIUM 5.4
CVE-2025-14290

IBM webMethods Integration (on prem) -Integration Server 10.15 through IS_10.15_Core_Fix2611.1 to IS_11.1_Core_Fix10 IBM webMethods Integration is vu…

Mitigation only
Fix from $1,600 2026-05-26
Security Verify Access HIGH 7.2
CVE-2026-1343

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Acces…

Fix: after 11.0.2.0
Fix from $1,950 2026-04-08
Infosphere Information Server MEDIUM 5.4
CVE-2026-1015

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated atta…

Fix: after 11.7.1.6
Fix from $1,600 2026-03-25
Websphere Application Server MEDIUM 5.4
CVE-2026-1561

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty is vulnerable to server-side request fo…

Fix: 26.0.0.4+
Fix from $1,600 2026-03-25
Infosphere Information Server MEDIUM 5.4
CVE-2025-14912

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated atta…

Fix: after 11.7.1.6
Fix from $1,600 2026-03-25
Business Automation Workflow HIGH 7.1
CVE-2025-13096

IBM Business Automation Workflow containers V25.0.0 through V25.0.0-IF007, V24.0.1 - V24.0.1-IF007, V24.0.0 - V24.0.0-IF007 and IBM Business Automati…

Fix: after 24.0.0
Fix from $1,950 2026-02-02
Concert MEDIUM 5.4
CVE-2025-36085

IBM Concert 1.0.0 through 2.0.0 Software is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauth…

Fix: 2.1.0+
Fix from $1,600 2025-10-28
Webmethods Integration MEDIUM 5.4
CVE-2025-36037

IBM webMethods Integration 10.15 and 11.1 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send una…

Mitigation only
Fix from $1,600 2025-09-22
Edge Application Manager MEDIUM 5.4
CVE-2025-1142

IBM Edge Application Manager 4.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized r…

Mitigation only
Fix from $1,600 2025-08-20
Concert MEDIUM 6.5
CVE-2024-55910

IBM Concert Software 1.0.0 through 1.0.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauth…

Fix: 1.1.0+
Fix from $1,600 2025-05-02
Maximo Asset Management MEDIUM 5.4
CVE-2025-2987

IBM Maximo Asset Management 7.6.1.3 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorize…

Mitigation only
Fix from $1,600 2025-04-22
Aspera Shares MEDIUM 5.4
CVE-2024-56470

IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send una…

Fix: 1.10.0+
Fix from $1,600 2025-02-05
Aspera Shares MEDIUM 5.4
CVE-2024-56471

IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send una…

Fix: 1.10.0+
Fix from $1,600 2025-02-05
I MEDIUM 5.4
CVE-2024-51463

IBM i 7.3, 7.4, and 7.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests…

Mitigation only
Fix from $1,600 2024-12-21
Security Guardium MEDIUM 5.4
CVE-2024-49336

IBM Security Guardium 11.5 and 12.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorize…

Mitigation only
Fix from $1,600 2024-12-19
Infosphere Information Server MEDIUM 5.4
CVE-2023-50952

IBM InfoSphere Information Server 11.7 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthor…

Mitigation only
Fix from $1,600 2024-06-30
Maximo Application Suite MEDIUM 5.4
CVE-2023-32337

IBM Maximo Spatial Asset Management 8.10 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauth…

Fix: 8.10.6+
Fix from $1,600 2024-01-19
Content Navigator MEDIUM 5.4
CVE-2023-35896

IBM Content Navigator 3.0.13 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized reque…

Patch available
Fix from $1,600 2023-11-03
Cognos Analytics MEDIUM 5.4
CVE-2023-35011

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send…

Fix: 11.1.7 / 11.2.4+
Fix from $1,600 2023-08-16
Sterling Connect\ MEDIUM 5.4
CVE-2023-29260

IBM Sterling Connect:Express for UNIX 1.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unaut…

Patch available
Fix from $1,600 2023-07-19
Watson Machine Learning On Cloud Pak For Data MEDIUM 6.5
CVE-2023-30444

IBM Watson Machine Learning on Cloud Pak for Data 4.0 and 4.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated at…

Patch available
Fix from $1,600 2023-04-27
Cognos Analytics CRITICAL 9.1
CVE-2022-38708

IBM Cognos Analytics 11.1.7 11.2.0, and 11.2.1 could be vulnerable to a Server-Side Request Forgery Attack (SSRF) attack by constructing URLs from us…

Fix: after 11.2.3
Fix from $2,300 2022-12-19
Websphere Application Server MEDIUM 6.5
CVE-2022-35282

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, …

Fix: 7.0.0.45 / 8.0.0.15+
Fix from $1,600 2022-09-28
Datapower Gateway HIGH 8.8
CVE-2022-31776

IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21 is vulnerable to server-side…

Fix: 10.5.0.1+
Fix from $1,950 2022-08-01