Vulnerability index

Browse CVEs

6,286 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Sterling B2b Integrator MEDIUM 5.4
CVE-2023-40693

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, and 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1 are vul…

Fix: 6.1.2.8 / 6.2.0.5_2+
Fix from $1,600 2026-03-13
Aspera Orchestrator MEDIUM 5.4
CVE-2025-13213

IBM Aspera Orchestrator 3.0.0 through 4.1.2 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This …

Fix: 4.1.3+
Fix from $1,600 2026-03-10
Trusteer Rapport HIGH 7.8
CVE-2026-2713

IBM Trusteer Rapport installer 3.5.2309.290 IBM Trusteer Rapport could allow a local attacker to execute arbitrary code on the system, caused by DLL …

Mitigation only
Fix from $1,950 2026-03-10
Aspera Faspex MEDIUM 5.4
CVE-2025-36227

IBM Aspera Faspex 5 5.0.0 through 5.0.14.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers.  This …

Fix: 5.0.15+
Fix from $1,600 2026-03-10
Aspera Orchestrator HIGH 7.5
CVE-2025-13219

IBM Aspera Orchestrator 3.0.0 through 4.1.2 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized p…

Fix: 4.1.3+
Fix from $1,950 2026-03-10
Aspera Faspex MEDIUM 5.4
CVE-2025-36226

IBM Aspera Faspex 5 5.0.0 through 5.0.14.3 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary …

Fix: 5.0.15+
Fix from $1,600 2026-03-10
Infosphere Data Architect MEDIUM 6.1
CVE-2025-36173

Affected Product(s)Version(s)InfoSphere Data Architect9.2.1

No fix yet
Fix from $1,600 2026-03-10
Infosphere Information Server HIGH 7.5
CVE-2026-1567

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 An XML External Entity (XXE) vulnerability in IBM InfoSphere Information Server could all…

Fix: after 11.7.1.6
Fix from $1,950 2026-03-03
Mq MEDIUM 5.0
CVE-2026-1713

IBM MQ 9.1.0.0 through 9.1.0.33 LTS, 9.2.0.0 through 9.2.0.40 LTS, 9.3.0.0 through 9.3.0.36 LTS, 9.30.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.17 …

Fix: 9.1.0.34 / 9.2.0.41+
Fix from $1,600 2026-03-03
Datastage On Cloud Pak For Data HIGH 8.8
CVE-2025-13687

IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 could allow an authenticated user to execute arbitrary commands with normal user privileges o…

Fix: 5.3.1+
Fix from $1,950 2026-03-03
Datastage On Cloud Pak For Data HIGH 8.8
CVE-2025-13688

IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 could allow an authenticated user to execute arbitrary commands with normal user privileges o…

Fix: 5.3.1+
Fix from $1,950 2026-03-03
Aspera Faspio Gateway HIGH 7.5
CVE-2025-14480

IBM Aspera faspio Gateway 1.3.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive informati…

Mitigation only
Fix from $1,950 2026-03-03
Mq Appliance MEDIUM 5.9
CVE-2025-14456

IBM MQ Appliance 9.4 CD through 9.4.4.0 to 9.4.4.1

Fix: 9.4.5.0+
Fix from $1,600 2026-03-03
Datastage On Cloud Pak For Data HIGH 8.8
CVE-2025-13686

IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 could allow an authenticated user to execute arbitrary commands with normal user privileges o…

Fix: 5.3.1+
Fix from $1,950 2026-03-03
Webmethods Api Gateway MEDIUM 6.5
CVE-2026-2606

IBM webMethods API Gateway (on-prem) 10.11 through 10.11_Fix3210.15 to 10.15_Fix2711.1 to 11.1_Fix7 IBM webMethods API Management (on-prem) fails to …

Mitigation only
Fix from $1,600 2026-03-03
Infosphere Information Server MEDIUM 5.3
CVE-2026-1265

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to writing of sensitive Information in a log file.

Fix: after 11.7.1.6
Fix from $1,600 2026-03-03
Websphere Application Server CRITICAL 9.8
CVE-2025-14923

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.2 IBM WebSphere Application Server Liberty could provide weaker than expected secu…

Fix: 26.0.0.3+
Fix from $2,300 2026-03-03
Storage Scale HIGH 7.8
CVE-2025-14604

IBM Storage Scale IBM S through rage Scale 5.2.3.0 - 5.2.3.5, and IBM S through rage Scale 6.0.0.0 - 6.0.0.1 could allow a local user to unintentiona…

Fix: 5.2.3.6 / 6.0.0.2+
Fix from $1,950 2026-03-03
Datastage On Cloud Pak For Data HIGH 7.5
CVE-2025-13616

IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 returns sensitive information in an HTTP response that could be used in further attacks again…

Fix: 5.3.1+
Fix from $1,950 2026-03-03
App Connect Enterprise Certified Containers Operands MEDIUM 5.9
CVE-2025-13490

IBM App Connect Operator versions CD 11.3.0 through 11.6.0 and 12.1.0 through 12.20.0, LTS versions 12.0.0 through 12.0.20, and IBM App Connect Enter…

Fix: after 12.20.1
Fix from $1,600 2026-03-03
Engineering Requirements Management Doors Next MEDIUM 5.4
CVE-2025-13734

IBM Engineering Requirements Management DOORS Next 7.1, and 7.2 could allow an authenticated user to view and edit data beyond their authorized acces…

Mitigation only
Fix from $1,600 2026-03-03
Datastage On Cloud Pak For Data HIGH 8.8
CVE-2025-13689

IBM DataStage on Cloud Pak for Data could allow an authenticated user to execute arbitrary commands and gain access to sensitive information due to u…

Fix: 5.3.1+
Fix from $1,950 2026-02-17
Concert HIGH 7.4
CVE-2025-33088

IBM Concert 1.0.0 through 2.1.0 could allow a local user with specific knowledge about the system's architecture to escalate their privileges due to …

Fix: 2.2.0+
Fix from $1,950 2026-02-17
Qradar Edr HIGH 7.5
CVE-2025-36379

IBM Security QRadar EDR 3.12 through 3.12.23 IBM Security ReaQta uses weaker than expected cryptographic algorithms that could allow an attacker to d…

Fix: 3.12.24+
Fix from $1,950 2026-02-17
Security Qradar Edr HIGH 8.8
CVE-2025-36376

IBM Security QRadar EDR 3.12 through 3.12.23 does not invalidate session after a session expiration which could allow an authenticated user to impers…

Fix: 3.12.24+
Fix from $1,950 2026-02-17
Qradar Edr HIGH 8.8
CVE-2025-36377

IBM Security QRadar EDR 3.12 through 3.12.23 does not invalidate session after a session expiration which could allow an authenticated user to impers…

Fix: 3.12.24+
Fix from $1,950 2026-02-17
Webmethods Integration Server MEDIUM 5.4
CVE-2025-14289

IBM webMethods Integration Server 12.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would …

Mitigation only
Fix from $1,600 2026-02-17
Datastage On Cloud Pak For Data MEDIUM 6.5
CVE-2025-13691

IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 returns sensitive information in an HTTP response that could be used to impersonate other use…

Fix: 5.3.1+
Fix from $1,600 2026-02-17
Concert CRITICAL 9.8
CVE-2025-33089

IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information or perform unauthorized actions due to the use of hard …

Fix: 2.2.0+
Fix from $2,300 2026-02-17
Db2 Merge Backup MEDIUM 6.5
CVE-2025-33124

IBM DB2 Merge Backup for Linux, UNIX and Windows 12.1.0.0 could allow an authenticated user to cause the program to crash due to the incorrect calcul…

Mitigation only
Fix from $1,600 2026-02-17