Vulnerability index

Browse CVEs

6,286 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Db2 Merge Backup MEDIUM 6.5
CVE-2025-33130

IBM DB2 Merge Backup for Linux, UNIX and Windows 12.1.0.0 could allow an authenticated user to cause the program to crash due to a buffer being overw…

Mitigation only
Fix from $1,600 2026-02-17
Concert MEDIUM 5.9
CVE-2025-33101

IBM Concert 1.0.0 through 2.1.0 could allow an attacker to obtain sensitive information using man in the middle techniques due to improper clearing o…

Fix: 2.2.0+
Fix from $1,600 2026-02-17
Db2 Recovery Expert MEDIUM 6.5
CVE-2025-27901

IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 IBM Db2 Recovery Expert for Linux, UNIX and Windows is vulnerable to HTTP header injection, cause…

Mitigation only
Fix from $1,600 2026-02-17
Db2 Recovery Expert MEDIUM 6.5
CVE-2025-27904

IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 IBM Db2 Recovery Expert for Linux, UNIX and Windows is vulnerable to cross-site request forgery w…

Patch available
Fix from $1,600 2026-02-17
Db2 Recovery Expert MEDIUM 6.1
CVE-2025-27900

IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By pers…

Patch available
Fix from $1,600 2026-02-17
Db2 Recovery Expert MEDIUM 5.9
CVE-2025-27903

IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 IBM Db2 Recovery Expert for Linux, UNIX and Windows transmits data in a cleartext communication c…

Mitigation only
Fix from $1,600 2026-02-17
Db2 Recovery Expert MEDIUM 5.3
CVE-2025-27899

IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 discloses sensitive information in an environment variable that could aid in further attacks agai…

Patch available
Fix from $1,600 2026-02-17
Db2 Merge Backup HIGH 7.5
CVE-2025-13108

IBM DB2 Merge Backup for Linux, UNIX and Windows 12.1.0.0 could allow an attacker to access sensitive information in memory due to the buffer not pro…

Mitigation only
Fix from $1,950 2026-02-17
Db2 Recovery Expert MEDIUM 6.3
CVE-2025-27898

IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 does not invalidate session after a timeout which could allow an authenticated user to impersonat…

Patch available
Fix from $1,600 2026-02-17
Cloud Pak System MEDIUM 5.3
CVE-2023-38265

IBM Cloud Pak System 2.3.3.6, 2.3.3.7, 2.3.4.0, 2.3.4.1, and 2.3.5.0 could disclose folder location information to an unauthenticated attacker that c…

Mitigation only
Fix from $1,600 2026-02-17
Concert MEDIUM 6.5
CVE-2025-36018

IBM Concert 1.0.0 through 2.1.0 for Z hub component is vulnerable to cross-site request forgery which could allow an attacker to execute malicious an…

Fix: 2.2.0+
Fix from $1,600 2026-02-17
Concert MEDIUM 6.1
CVE-2025-36019

IBM Concert 1.0.0 through 2.1.0 for Z hub framework is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to e…

Fix: 2.2.0+
Fix from $1,600 2026-02-17
Concert HIGH 7.5
CVE-2024-43178

IBM Concert 1.0.0 through 2.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive informati…

Fix: 2.2.0+
Fix from $1,950 2026-02-17
Db2 MEDIUM 6.5
CVE-2025-36425

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 could allow an authenticated user t…

Fix: after 12.1.3
Fix from $1,600 2026-02-17
Db2 HIGH 8.2
CVE-2025-36247

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 is vulnerable to an XML external en…

Fix: after 12.1.3
Fix from $1,950 2026-02-17
Db2 MEDIUM 6.5
CVE-2025-14689

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 12.1.0 through 12.1.3 could allow an authenticated user to cause a denial of servic…

Fix: after 12.1.3
Fix from $1,600 2026-02-17
Db2 MEDIUM 6.5
CVE-2025-13867

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 could allow an authenticated user t…

Fix: after 12.1.3
Fix from $1,600 2026-02-17
Aspera Console HIGH 8.6
CVE-2025-13379

IBM Aspera Console 3.4.0 through 3.4.8 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could all…

Fix: after 3.4.8
Fix from $1,950 2026-02-05
Concert MEDIUM 6.5
CVE-2024-51451

IBM Concert 1.0.0 through 2.1.0 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow…

Fix: 2.2.0+
Fix from $1,600 2026-02-04
Concert MEDIUM 6.3
CVE-2024-43181

IBM Concert 1.0.0 through 2.1.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the s…

Fix: 2.2.0+
Fix from $1,600 2026-02-04
Cloud Pak System MEDIUM 5.3
CVE-2023-38017

IBM Cloud Pak System is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alt…

Mitigation only
Fix from $1,600 2026-02-04
Cloud Pak System MEDIUM 5.3
CVE-2023-38281

IBM Cloud Pak System does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by …

Mitigation only
Fix from $1,600 2026-02-04
Cloud Pak System HIGH 7.5
CVE-2023-38010

IBM Cloud Pak System displays sensitive information in user messages that could aid in further attacks against the system.

Mitigation only
Fix from $1,950 2026-02-04
Cloud Pak For Business Automation HIGH 8.1
CVE-2025-36094

IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 Interim…

Mitigation only
Fix from $1,950 2026-02-03
Concert MEDIUM 5.5
CVE-2025-33081

IBM Concert 1.0.0 through 2.1.0 stores potentially sensitive information in log files that could be read by a local user.

Fix: 2.2.0+
Fix from $1,600 2026-02-03
Engineering Lifecycle Management MEDIUM 5.4
CVE-2025-36033

IBM Engineering Lifecycle Management - Global Configuration Management 7.0.3 through 7.0.3 Interim Fix 017, and 7.1.0 through 7.1.0 Interim Fix 004 I…

Mitigation only
Fix from $1,600 2026-02-03
Concert HIGH 7.5
CVE-2025-36253

IBM Concert 1.0.0 through 2.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive informati…

Fix: 2.2.0+
Fix from $1,950 2026-02-02
Powervm Hypervisor MEDIUM 6.0
CVE-2025-36238

IBM PowerVM Hypervisor FW1110.00 through FW1110.03, FW1060.00 through FW1060.51, and FW950.00 through FW950.F0 could allow a local user with administ…

Mitigation only
Fix from $1,600 2026-02-02
Cloud Pak For Business Automation MEDIUM 5.4
CVE-2025-36436

IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 Interim…

Mitigation only
Fix from $1,600 2026-02-02
Business Automation Workflow HIGH 7.1
CVE-2025-13096

IBM Business Automation Workflow containers V25.0.0 through V25.0.0-IF007, V24.0.1 - V24.0.1-IF007, V24.0.0 - V24.0.0-IF007 and IBM Business Automati…

Fix: after 24.0.0
Fix from $1,950 2026-02-02