Vulnerability index

Browse CVEs

55 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
I Access Client Solutions HIGH 7.8
CVE-2026-13094

IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution on Windows when installed for all users due to publi…

No fix yet
Fix from $4,900 2026-08-12
Db2 HIGH 7.8
CVE-2026-9762

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution when jdbc url is under user control.

Fix: 12.1.5+
Fix from $1,950 2026-07-17
Db2 CRITICAL 9.8
CVE-2026-10109

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution due to improper pre-auth DRDA handshake handling.

Fix: after 12.1.4
Fix from $2,300 2026-06-30
I CRITICAL 9.8
CVE-2026-9072

IBM WebSphere Application Server and IBM WebSphere Application Server Liberty - when using Intelligent Management with the WebSphere WebServer Plug-i…

Fix: after 7.6
Fix from $2,300 2026-06-22
I HIGH 8.8
CVE-2026-8858

IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to remote code execution and denial of service in the We…

Fix: after 7.6
Fix from $1,950 2026-06-22
Websphere Application Server CRITICAL 9.0
CVE-2026-9311

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security controls.

Fix: 8.5.5.30 / 9.0.5.29+
Fix from $2,300 2026-06-01
HTTP Server CRITICAL 9.8
CVE-2026-8855

IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial of service in configurations with TLS mutual authentication (client au…

Fix: 8.5.5.30 / 9.0.5.29+
Fix from $2,300 2026-05-26
HTTP Server CRITICAL 9.8
CVE-2026-9170

IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service and a potential remote code execution due to improper input validation.

Mitigation only
Fix from $2,300 2026-05-26
Websphere Application Server CRITICAL 9.8
CVE-2026-8633

IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Se…

Fix: after 9.0.5.27
Fix from $2,300 2026-05-26
Integration Bus MEDIUM 6.7
CVE-2025-36014

IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.5 is vulnerable to code injection by a privileged user with access to the IIB install directory.

Fix: after 10.1.0.5
Fix from $1,600 2025-07-07
Cloud Pak For Security HIGH 7.2
CVE-2025-25021

IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow a privileged execute code …

Fix: after 1.11.2.0
Fix from $1,950 2025-06-03
Security Verify Access HIGH 7.8
CVE-2025-0161

IBM Security Verify Access Appliance 10.0.0.0 through 10.0.0.9 and 11.0.0.0 could allow a local user to execute arbitrary code due to improper restri…

Fix: after 10.0.0.9
Fix from $1,950 2025-02-20
Data Virtualization Manager For Z\/os HIGH 8.8
CVE-2024-52899

IBM Data Virtualization Manager for z/OS 1.1 and 1.2 could allow an authenticated user to inject malicious JDBC URL parameters and execute code on th…

Mitigation only
Fix from $1,950 2024-11-26
Soar HIGH 8.8
CVE-2024-38319

IBM Security SOAR 51.0.2.0 could allow an authenticated user to execute malicious code loaded from a specially crafted script. IBM X-Force ID: 2948…

Fix: after 51.0.2.0
Fix from $1,950 2024-06-22
Storage Protect HIGH 7.8
CVE-2023-35897

IBM Spectrum Protect Client and IBM Storage Protect for Virtual Environments 8.1.0.0 through 8.1.19.0 could allow a local user to execute arbitrary c…

Fix: after 8.1.19.0
Fix from $1,950 2023-10-06
Db2 HIGH 8.8
CVE-2023-27867

IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote authenticated attacker to execute arbitrary code vi…

Patch available
Fix from $1,950 2023-07-10
Db2 HIGH 8.8
CVE-2023-27868

IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote authenticated attacker to execute arbitrary code on…

Patch available
Fix from $1,950 2023-07-10
Db2 HIGH 8.8
CVE-2023-27869

IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote authenticated attacker to execute arbitrary code on…

Patch available
Fix from $1,950 2023-07-10
I CRITICAL 9.8
CVE-2023-30990

IBM i 7.2, 7.3, 7.4, and 7.5 could allow a remote attacker to execute CL commands as QUSER, caused by an exploitation of DDM architecture. IBM X-For…

Patch available
Fix from $2,300 2023-07-04
Informix Jdbc Driver CRITICAL 9.8
CVE-2023-27866

IBM Informix JDBC Driver 4.10 and 4.50 is susceptible to remote code execution attack via JNDI injection when driver code or the application using th…

Fix: 4.50.10+
Fix from $2,300 2023-06-28
Websphere Application Server CRITICAL 9.8
CVE-2023-23477

IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially craft…

Mitigation only
Fix from $2,300 2023-02-03
Mq Appliance MEDIUM 6.7
CVE-2021-38967

IBM MQ Appliance 9.2 CD and 9.2 LTS could allow a local privileged user to inject and execute malicious code. IBM X-Force ID: 212441.

Patch available
Fix from $1,600 2021-11-30
Cognos Analytics HIGH 8.8
CVE-2021-29679

IBM Cognos Analytics 11.1.7 and 11.2.0 could allow an authenticated user to execute code remotely due to incorrectly neutralizaing user-contrlled inp…

Patch available
Fix from $1,950 2021-10-15
Api Connect CRITICAL 9.8
CVE-2021-29772

IBM API Connect 5.0.0.0 through 5.0.8.11 could allow a user to potentially inject code due to unsanitized user input. IBM X-Force ID: 202774.

Fix: after 5.0.8.11
Fix from $2,300 2021-08-26
Planning Analytics CRITICAL 9.8
CVE-2019-4716 KEVEPSS 86%

IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and th…

Fix: after 2.0.8
Fix from $2,300 2019-12-18
Security Identity Manager MEDIUM 6.2
CVE-2019-4038

IBM Security Identity Manager 6.0 and 7.0 could allow an attacker to create unexpected control flow paths through the application, potentially bypass…

Fix: after 7.0.1.10
Fix from $1,600 2019-02-04
Websphere Commerce HIGH 8.8
CVE-2018-1808

IBM WebSphere Commerce 9.0.0.0 through 9.0.0.6 could allow some server-side code injection due to inadequate input control. IBM X-Force ID: 149828.

Fix: after 9.0.0.6
Fix from $1,950 2018-11-13
Websphere Mq HIGH 7.8
CVE-2018-1792

IBM WebSphere MQ 8.0.0.0 through 8.0.0.10, 9.0.0.0 through 9.0.0.5, 9.0.1 through 9.0.5, and 9.1.0.0 could allow a local user to inject code that cou…

Fix: after 9.0.5
Fix from $1,950 2018-11-13
Rational Doors Next Generation MEDIUM 5.4
CVE-2017-1753

Multiple IBM Rational products are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be exec…

Fix: after 6.0.5
Fix from $1,600 2018-08-20
Rational Quality Manager MEDIUM 6.1
CVE-2017-1248

IBM Quality Manager (RQM) 5.0.x and 6.0 through 6.0.5 are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which whe…

Fix: after 6.0.5
Fix from $1,600 2018-07-06