Vulnerability index

Browse CVEs

6,286 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Websphere Application Server CRITICAL 9.8
CVE-2025-14917

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty could provide weaker than expected secu…

Fix: 26.0.0.4+
Fix from $2,300 2026-03-25
Infosphere Information Server HIGH 7.5
CVE-2025-14974

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable due to Insecure Direct Object Reference (IDOR).

Fix: after 11.7.1.6
Fix from $1,950 2026-03-25
Websphere Application Server HIGH 7.2
CVE-2025-14915

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty is affected by privilege escalation. A …

Fix: 26.0.0.4+
Fix from $1,950 2026-03-25
Infosphere Information Server MEDIUM 5.5
CVE-2025-36258

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 product stores user credentials and other sensitive information in plain text which can b…

Fix: after 11.7.1.6
Fix from $1,600 2026-03-25
Infosphere Information Server MEDIUM 5.4
CVE-2025-14912

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated atta…

Fix: after 11.7.1.6
Fix from $1,600 2026-03-25
Infosphere Information Server MEDIUM 6.5
CVE-2025-14807

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to HTTP header injection, caused by improper validation of input by the HOS…

Fix: after 11.7.1.6
Fix from $1,600 2026-03-25
Infosphere Information Server MEDIUM 6.5
CVE-2025-14810

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 does not invalidate a session after privileges have been modified which could allow an au…

Fix: after 11.7.1.6
Fix from $1,600 2026-03-25
Infosphere Information Server MEDIUM 6.5
CVE-2025-14790

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an attacker to obtain sensitive information due to insufficiently protected c…

Fix: after 11.7.1.6
Fix from $1,600 2026-03-25
Concert MEDIUM 5.5
CVE-2025-12708

IBM Concert 1.0.0 through 2.2.0 contains hard-coded credentials that could be obtained by a local user.

Fix: after 2.2.0
Fix from $1,600 2026-03-25
Qradar Security Information And Event Manager MEDIUM 5.5
CVE-2025-36051

IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 stores potentially sensitive information in configuration files that could be read by a local u…

Mitigation only
Fix from $1,600 2026-03-19
Qradar Security Information And Event Manager MEDIUM 5.4
CVE-2025-15051

IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaS…

Mitigation only
Fix from $1,600 2026-03-19
Qradar Security Information And Event Manager MEDIUM 5.4
CVE-2026-1276

IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed…

Mitigation only
Fix from $1,600 2026-03-19
Qradar Security Information And Event Manager MEDIUM 5.0
CVE-2025-13995

IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 could allow an attacker with access to one tenant to access hostname data from another tenant's…

Mitigation only
Fix from $1,600 2026-03-19
Db2 Recovery Expert CRITICAL 9.1
CVE-2026-3856

IBM Db2 Recovery Expert for Linux, UNIX and Windows 5.5 IF 2 could allow an attacker to modify or corrupt data due to an insecure mechanism used for …

Patch available
Fix from $2,300 2026-03-17
Sterling B2b Integrator MEDIUM 6.5
CVE-2026-1264

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.…

Fix: 6.1.2.8 / 6.2.0.5_2+
Fix from $1,600 2026-03-17
Sterling B2b Integrator HIGH 7.5
CVE-2025-14031

IBM Sterling B2B Integrator and and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.…

Fix: 6.1.2.8 / 6.2.0.5_2+
Fix from $1,950 2026-03-17
I HIGH 7.5
CVE-2026-1376

IBM i 7.6 could allow a remote attacker to cause a denial of service using failed authentication connections due to improper allocation of resources.

Mitigation only
Fix from $1,950 2026-03-17
Planning Analytics Local MEDIUM 6.5
CVE-2026-1267

IBM Planning Analytics Local 2.1.0 through 2.1.17 could allow an unauthorized access to sensitive application data and administrative functionalities…

Fix: 2.1.18+
Fix from $1,600 2026-03-17
Planning Analytics Local MEDIUM 5.7
CVE-2025-14806

IBM Planning Analytics Local 2.1.0 through 2.1.17 could allow an attacker to trick the caching mechanism into storing and serving sensitive, user-spe…

Fix: 2.1.18+
Fix from $1,600 2026-03-17
Cics Transaction Gateway HIGH 7.1
CVE-2026-0977

IBM CICS Transaction Gateway for Multiplatforms 9.3 and 10.1 could allow a user to transfer or view files due to improper access controls.

Mitigation only
Fix from $1,950 2026-03-16
Aspera Console MEDIUM 5.3
CVE-2025-13460

IBM Aspera Console 3.3.0 through 3.4.8 could allow an attacker to enumerate usernames due to an observable response discrepancy.

Fix: 3.4.9+
Fix from $1,600 2026-03-16
Sterling B2b Integrator MEDIUM 5.4
CVE-2026-0835

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.…

Fix: 6.1.2.8 / 6.2.0.5_2+
Fix from $1,600 2026-03-13
Sterling B2b Integrator HIGH 7.2
CVE-2025-36368

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, and 6.2.1.0 through 6.2.1.1_1 are vul…

Fix: 6.1.2.8 / 6.2.0.5_2+
Fix from $1,950 2026-03-13
Sterling Partner Engagement Manager MEDIUM 5.9
CVE-2025-14811

IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow an attacker to obtain sensitive information f…

Fix: 6.2.3.6 / 6.2.4.3+
Fix from $1,600 2026-03-13
Sterling B2b Integrator MEDIUM 5.4
CVE-2025-14504

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.…

Fix: 6.1.2.8 / 6.2.0.5_2+
Fix from $1,600 2026-03-13
Sterling B2b Integrator MEDIUM 6.5
CVE-2025-14483

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.…

Fix: 6.1.2.8 / 6.2.0.5_2+
Fix from $1,600 2026-03-13
Sterling Partner Engagement Manager HIGH 7.5
CVE-2025-13718

IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow a remote attacker to obtain sensitive informa…

Fix: 6.2.3.6 / 6.2.4.3+
Fix from $1,950 2026-03-13
Sterling Partner Engagement Manager HIGH 7.5
CVE-2025-13723

IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow an attacker to obtain sensitive user informat…

Fix: 6.2.3.6 / 6.2.4.3+
Fix from $1,950 2026-03-13
Sterling Partner Engagement Manager HIGH 7.5
CVE-2025-13726

IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow a remote attacker to obtain sensitive informa…

Fix: 6.2.3.6 / 6.2.4.3+
Fix from $1,950 2026-03-13
Sterling Partner Engagement Manager MEDIUM 5.4
CVE-2025-13702

IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 is vulnerable to cross-site scripting. This vulnerability…

Fix: 6.2.3.6 / 6.2.4.3+
Fix from $1,600 2026-03-13