Vulnerability index

Browse CVEs

56 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
CRITICAL 9.8 CVE-2026-17617 IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of URLs specif… Application Gateway Operator after 26.6.0 Fix from $2,3002026-08-05 CRITICAL 10.0 CVE-2026-13773 IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 Approximately 50 generated CORBA stub classes in WebSphere eXtreme Scale's ogclient.jar call ORB.… Websphere Extreme Scale after 8.6.1.6 Fix from $2,3002026-06-30 CRITICAL 9.8 CVE-2026-11714 IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability with the apiDiscovery-1.0 feature enabled. Websphere Application Server 26.0.0.8+ Fix from $2,3002026-06-30 CRITICAL 9.8 CVE-2026-11546 IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the adminCenter-… Websphere Application Server 26.0.0.8+ Fix from $2,3002026-06-30 CRITICAL 9.1 CVE-2026-9006 IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an a… Websphere Application Server 8.5.5.30 / 9.0.5.29+ Fix from $2,3002026-06-22 MEDIUM 6.0 CVE-2026-7253 IBM Sterling B2B Integrator and IBM Sterling File Gateway are vulnerable to SQL injection. A privileged user could send specially crafted SQL stateme… Watson Speech Services Cartridge 5.3.1+ Fix from $1,6002026-06-22 MEDIUM 5.4 CVE-2025-14290 IBM webMethods Integration (on prem) -Integration Server 10.15 through IS_10.15_Core_Fix2611.1 to IS_11.1_Core_Fix10 IBM webMethods Integration is vu… Webmethods Integration Server Mitigation only Fix from $1,6002026-05-26 HIGH 7.2 CVE-2026-1343 IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Acces… Security Verify Access after 11.0.2.0 Fix from $1,9502026-04-08 MEDIUM 5.4 CVE-2026-1015 IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated atta… Infosphere Information Server after 11.7.1.6 Fix from $1,6002026-03-25 MEDIUM 5.4 CVE-2026-1561 IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty is vulnerable to server-side request fo… Websphere Application Server 26.0.0.4+ Fix from $1,6002026-03-25 MEDIUM 5.4 CVE-2025-14912 IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated atta… Infosphere Information Server after 11.7.1.6 Fix from $1,6002026-03-25 HIGH 7.1 CVE-2025-13096 IBM Business Automation Workflow containers V25.0.0 through V25.0.0-IF007, V24.0.1 - V24.0.1-IF007, V24.0.0 - V24.0.0-IF007 and IBM Business Automati… Business Automation Workflow after 24.0.0 Fix from $1,9502026-02-02 MEDIUM 5.4 CVE-2025-36085 IBM Concert 1.0.0 through 2.0.0 Software is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauth… Concert 2.1.0+ Fix from $1,6002025-10-28 MEDIUM 5.4 CVE-2025-36037 IBM webMethods Integration 10.15 and 11.1 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send una… Webmethods Integration Mitigation only Fix from $1,6002025-09-22 MEDIUM 5.4 CVE-2025-1142 IBM Edge Application Manager 4.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized r… Edge Application Manager Mitigation only Fix from $1,6002025-08-20 MEDIUM 6.5 CVE-2024-55910 IBM Concert Software 1.0.0 through 1.0.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauth… Concert 1.1.0+ Fix from $1,6002025-05-02 MEDIUM 5.4 CVE-2025-2987 IBM Maximo Asset Management 7.6.1.3 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorize… Maximo Asset Management Mitigation only Fix from $1,6002025-04-22 MEDIUM 5.4 CVE-2024-56470 IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send una… Aspera Shares 1.10.0+ Fix from $1,6002025-02-05 MEDIUM 5.4 CVE-2024-56471 IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send una… Aspera Shares 1.10.0+ Fix from $1,6002025-02-05 MEDIUM 5.4 CVE-2024-51463 IBM i 7.3, 7.4, and 7.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests… I Mitigation only Fix from $1,6002024-12-21 MEDIUM 5.4 CVE-2024-49336 IBM Security Guardium 11.5 and 12.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorize… Security Guardium Mitigation only Fix from $1,6002024-12-19 MEDIUM 5.4 CVE-2023-50952 IBM InfoSphere Information Server 11.7 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthor… Infosphere Information Server Mitigation only Fix from $1,6002024-06-30 MEDIUM 5.4 CVE-2023-32337 IBM Maximo Spatial Asset Management 8.10 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauth… Maximo Application Suite 8.10.6+ Fix from $1,6002024-01-19 MEDIUM 5.4 CVE-2023-35896 IBM Content Navigator 3.0.13 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized reque… Content Navigator Patch available Fix from $1,6002023-11-03 MEDIUM 5.4 CVE-2023-35011 IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send… Cognos Analytics 11.1.7 / 11.2.4+ Fix from $1,6002023-08-16 MEDIUM 5.4 CVE-2023-29260 IBM Sterling Connect:Express for UNIX 1.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unaut… Sterling Connect\ Patch available Fix from $1,6002023-07-19 MEDIUM 6.5 CVE-2023-30444 IBM Watson Machine Learning on Cloud Pak for Data 4.0 and 4.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated at… Watson Machine Learning On Cloud Pak For Data Patch available Fix from $1,6002023-04-27 CRITICAL 9.1 CVE-2022-38708 IBM Cognos Analytics 11.1.7 11.2.0, and 11.2.1 could be vulnerable to a Server-Side Request Forgery Attack (SSRF) attack by constructing URLs from us… Cognos Analytics after 11.2.3 Fix from $2,3002022-12-19 MEDIUM 6.5 CVE-2022-35282 IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, … Websphere Application Server 7.0.0.45 / 8.0.0.15+ Fix from $1,6002022-09-28 HIGH 8.8 CVE-2022-31776 IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21 is vulnerable to server-side… Datapower Gateway 10.5.0.1+ Fix from $1,9502022-08-01