Vulnerability index

Browse CVEs

6,286 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Engineering Lifecycle Management CRITICAL 9.8
CVE-2026-3660

IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an unauthenticated remote attacker to update server property files that woul…

Mitigation only
Fix from $2,300 2026-05-26
Engineering Lifecycle Management HIGH 7.1
CVE-2026-3603

IBM Engineering Lifecycle Management 7.0.3 Interim Fix 001 through  Interim Fix 021, 7.1.0  Interim Fix 001 through  Interim Fix 009, and 7.2.0 and 7…

Patch available
Fix from $1,950 2026-05-26
HTTP Server CRITICAL 9.8
CVE-2026-8855

IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial of service in configurations with TLS mutual authentication (client au…

Fix: 8.5.5.30 / 9.0.5.29+
Fix from $2,300 2026-05-26
HTTP Server CRITICAL 9.8
CVE-2026-9170

IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service and a potential remote code execution due to improper input validation.

Mitigation only
Fix from $2,300 2026-05-26
HTTP Server CRITICAL 9.1
CVE-2026-8856

IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configurations where an attacker has write access to parts of the server configura…

Fix: 8.5.5.30 / 9.0.5.29+
Fix from $2,300 2026-05-26
HTTP Server HIGH 7.5
CVE-2026-8854

IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_mem_cache.

Fix: 8.5.5.30 / 9.0.5.29+
Fix from $1,950 2026-05-26
Websphere Application Server CRITICAL 9.8
CVE-2026-8633

IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Se…

Fix: after 9.0.5.27
Fix from $2,300 2026-05-26
HTTP Server HIGH 8.0
CVE-2026-8834

IBM HTTP Server 8.5, and 9.0 contains a buffer overflow vulnerability. A privileged user, authenticated to the Administration Server, could exploit t…

Fix: 8.5.5.30 / 9.0.5.29+
Fix from $1,950 2026-05-26
Websphere Application Server HIGH 7.5
CVE-2026-8620

IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Se…

Fix: 8.5.5.30 / 9.0.5.28+
Fix from $1,950 2026-05-26
HTTP Server HIGH 7.3
CVE-2026-8835

IBM HTTP Server 8.5, and 9.0 is vulnerable to invalid pointer dereference. A privileged user, authenticated to the Administration Server, could explo…

Fix: 8.5.5.30 / 9.0.5.29+
Fix from $1,950 2026-05-26
HTTP Server HIGH 7.5
CVE-2026-8850

IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_ibm_upload.

Fix: 8.5.5.30 / 9.0.5.29+
Fix from $1,950 2026-05-26
HTTP Server HIGH 7.5
CVE-2026-8852

IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_fastcgi module.

Fix: 8.5.5.30 / 9.0.5.29+
Fix from $1,950 2026-05-26
Cloud Pak For Data System Cyclops CRITICAL 9.8
CVE-2025-36220

IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System is vulnerable to SQL injection. A remote atta…

Fix: 11.3.0.2+
Fix from $2,300 2026-05-26
Cloud Pak For Data System Cyclops HIGH 7.5
CVE-2025-36221

IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System uses default passwords default passwords from…

Fix: 11.3.0.2+
Fix from $1,950 2026-05-26
Financial Transaction Manager For Multiplatform MEDIUM 6.1
CVE-2025-36148

IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.15 IBM Financial Transaction Manager SWIFT is vulnerabl…

Fix: 3.2.4.16+
Fix from $1,600 2026-05-26
Cognos Analytics HIGH 7.6
CVE-2025-36126

IBM Cognos Analytics 11.2.0, 12.0, and 12.1.0 and IBM Cognos Transformer 12.0, 11.2.4, and 12.1.0 is vulnerable to stored cross-site scripting (XSS) …

Fix: 12.1.2+
Fix from $1,950 2026-05-26
Webmethods Integration Server MEDIUM 5.4
CVE-2025-14290

IBM webMethods Integration (on prem) -Integration Server 10.15 through IS_10.15_Core_Fix2611.1 to IS_11.1_Core_Fix10 IBM webMethods Integration is vu…

Mitigation only
Fix from $1,600 2026-05-26
Watsonx.data MEDIUM 5.3
CVE-2025-36145

IBM watsonx.data 2.2 through 2.3.1 IBM Lakehouse does not properly restrict inbound and outbound connections which could allow an attacker to transfe…

Fix: after 2.3.1
Fix from $1,600 2026-05-26
Db2 MEDIUM 5.5
CVE-2025-13755

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes DB2 Connect Server) stores potentially sensitive infor…

Fix: after 12.1.4
Fix from $1,600 2026-05-26
Turbonomic Prometurbo Agent HIGH 7.8
CVE-2026-6389

IBM Turbonomic prometurbo agent 8.16.0 through 8.17.6 IBM Turbonomic Application Resource Management grants excessive cluster‑wide permissions, inclu…

Fix: 8.18.0+
Fix from $1,950 2026-04-30
I CRITICAL 9.8
CVE-2026-2311

IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 s vulnerable to privilege escalation caused by an invalid IBM i Web Administration GUI authorization check.  A mali…

Mitigation only
Fix from $2,300 2026-04-30
Db2 MEDIUM 6.5
CVE-2026-1577

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user …

Fix: after 12.1.4
Fix from $1,600 2026-04-30
Watsonx.data HIGH 7.5
CVE-2025-36180

IBM watsonx.data 2.2 through 2.3 IBM Lakehouse does not properly restrict communication between pods which could allow an attacker to transfer data b…

Fix: after 2.3
Fix from $1,950 2026-04-30
Db2 MEDIUM 6.5
CVE-2025-36122

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user …

Fix: after 12.1.3
Fix from $1,600 2026-04-30
Watsonx.data MEDIUM 5.5
CVE-2025-36335

IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.3.0, 5.3.1 stores user credentials in plain text which can be read by a local user.

Mitigation only
Fix from $1,600 2026-04-30
Db2 MEDIUM 5.3
CVE-2025-14688

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user …

Fix: after 12.1.3
Fix from $1,600 2026-04-30
Total Storage Service Console CRITICAL 9.8
CVE-2026-5935

IBM Total Storage Service Console (TSSC) / TS4500 IMC 9.2, 9.3, 9.4, 9.5, 9.6 TSSC/IMC could allow an unauthenticated user to execute arbitrary comma…

Mitigation only
Fix from $2,300 2026-04-23
Security Verify Access MEDIUM 6.5
CVE-2026-5926

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Acces…

Fix: after 11.0.2.0
Fix from $1,600 2026-04-23
Websphere Application Server MEDIUM 5.9
CVE-2026-3621

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.4 IBM WebSphere Application Server Liberty is vulnerable to identity spoofing unde…

Fix: 26.0.0.5+
Fix from $1,600 2026-04-23
Db2 MEDIUM 6.5
CVE-2026-1352

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user …

Fix: after 12.1.4
Fix from $1,600 2026-04-23