Vulnerability index

Browse CVEs

6,286 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Application Gateway MEDIUM 5.4
CVE-2025-36396

IBM Application Gateway 23.10 through 25.09 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary…

Fix: after 25.09
Fix from $1,600 2026-01-20
Concert HIGH 8.8
CVE-2025-33015

IBM Concert 1.0.0 through 2.1.0 is vulnerable to malicious file upload by not validating the content of the file uploaded to the web interface.

Fix: 2.2.0+
Fix from $1,950 2026-01-20
Business Automation Workflow MEDIUM 5.5
CVE-2025-36058

IBM Business Automation Workflow containers 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 I…

Mitigation only
Fix from $1,600 2026-01-20
Business Automation Workflow MEDIUM 5.5
CVE-2025-36059

IBM Business Automation Workflow containers 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 I…

Mitigation only
Fix from $1,600 2026-01-20
Concert HIGH 7.5
CVE-2025-1722

IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap …

Fix: 2.2.0+
Fix from $1,950 2026-01-20
Concert HIGH 7.5
CVE-2025-1719

IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap …

Fix: 2.2.0+
Fix from $1,950 2026-01-20
Concert HIGH 7.4
CVE-2025-64645

IBM Concert 1.0.0 through 2.1.0 could allow a local user to escalate their privileges due to a race condition of a symbolic link.

Fix: 2.2.0+
Fix from $1,950 2025-12-26
Aspera Faspex MEDIUM 5.4
CVE-2025-36230

IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, wo…

Fix: 5.0.14.2+
Fix from $1,600 2025-12-26
Api Connect CRITICAL 9.8
CVE-2025-13915EPSS 9%

IBM API Connect 10.0.8.0 through 10.0.8.5, and 10.0.11.0 could allow a remote attacker to bypass authentication mechanisms and gain unauthorized acce…

Fix: after 10.0.8.5
Fix from $2,300 2025-12-26
Ds8a00 Firmware HIGH 7.1
CVE-2025-36192

IBM DS8A00( R10.1) 10.10.106.0 and IBM DS8A00 ( R10.0) 10.1.3.010.2.45.0 and IBM DS8900F ( R9.4) 89.40.83.089.42.18.089.44.5.0 IBM System Storage DS8…

Mitigation only
Fix from $1,950 2025-12-26
Db2 Intelligence Center MEDIUM 6.5
CVE-2025-14687

IBM Db2 Intelligence Center 1.1.0, 1.1.1, 1.1.2 could allow an authenticated user to perform unauthorized actions due to client-side enforcement of s…

Fix: 1.1.3+
Fix from $1,600 2025-12-26
Concert HIGH 7.5
CVE-2025-1721

IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap …

Fix: 2.2.0+
Fix from $1,950 2025-12-26
Concert HIGH 7.8
CVE-2025-12771

IBM Concert 1.0.0 through 2.1.0 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local user could overflow the b…

Fix: 2.2.0+
Fix from $1,950 2025-12-26
Concert MEDIUM 6.2
CVE-2025-36154

IBM Concert 1.0.0 through 2.1.0 stores sensitive information in cleartext during recursive docker builds which could be obtained by a local user.

Fix: 2.2.0+
Fix from $1,600 2025-12-24
Devops Deploy MEDIUM 5.0
CVE-2025-36360

IBM UCD - IBM UrbanCode Deploy 7.1 through 7.1.2.27, 7.2 through 7.2.3.20, and 7.3 through 7.3.2.15 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1…

Fix: 7.1.2.28 / 7.2.3.21+
Fix from $1,600 2025-12-15
Devops Deploy MEDIUM 6.5
CVE-2025-14148

IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.3 could allow an authenticated user with LLM integration configuration privileges to recover a previous…

Fix: 8.1.2.4+
Fix from $1,600 2025-12-15
Devops Deploy MEDIUM 5.9
CVE-2025-13489

IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.3 IBM DevOps Deploy transmits data in clear text that could allow an attacker to obtain sensitive infor…

Fix: 8.1.2.4+
Fix from $1,600 2025-12-15
Aspera Orchestrator HIGH 8.8
CVE-2025-13214

IBM Aspera Orchestrator 4.0.0 through 4.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which coul…

Fix: 4.1.1+
Fix from $1,950 2025-12-11
Aspera Orchestrator HIGH 8.8
CVE-2025-13481

IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow an authenticated user to execute arbitrary commands with elevated privileges on the system du…

Fix: 4.1.1+
Fix from $1,950 2025-12-11
Aspera Orchestrator MEDIUM 6.5
CVE-2025-13148

IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow could an authenticated user to change the password of another user without prior knowledge of…

Fix: 4.1.1+
Fix from $1,600 2025-12-11
Aspera Orchestrator MEDIUM 6.5
CVE-2025-13211

IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow an authenticated user to cause a denial of service in the email service due to improper contr…

Fix: 4.1.1+
Fix from $1,600 2025-12-11
Watsonx.data MEDIUM 6.5
CVE-2025-36140

IBM watsonx.data 2.2 through 2.2.1 could allow an authenticated user to cause a denial of service through ingestion pods due to improper allocation o…

Fix: 2.2.2+
Fix from $1,600 2025-12-08
Storage Defender Resiliency Service MEDIUM 6.5
CVE-2025-64650

IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.18 could disclose sensitive user credentials in log files.

Fix: after 2.0.18
Fix from $1,600 2025-12-08
Cognos Controller MEDIUM 6.5
CVE-2025-36015

IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 could allow an authenticated user to cause a denial of servi…

Fix: 11.0.1.7 / 11.1.2+
Fix from $1,600 2025-12-08
Controller MEDIUM 6.5
CVE-2025-36017

IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 stores unencrypted sensitive information in environmental va…

Fix: 11.1.2+
Fix from $1,600 2025-12-08
Websphere Application Server MEDIUM 5.4
CVE-2025-12635

IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.12 are affected by cross-site scriptin…

Fix: 8.5.5.29 / 9.0.5.27+
Fix from $1,600 2025-12-08
Informix Dynamic Server HIGH 7.8
CVE-2024-45675

IBM Informix Dynamic Server 14.10 could allow a local user on the system to log into the Informix server as administrator without a password.

Fix: 14.10+
Fix from $1,950 2025-12-02
Sterling B2b Integrator HIGH 7.5
CVE-2025-36134

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.5 and 6.2.1.1 could disclose sensitive in…

Fix: 6.1.2.7_2 / 6.2.0.5_1+
Fix from $1,950 2025-11-25
Concert HIGH 7.5
CVE-2025-36150

IBM Concert 1.0.0 through 2.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive informati…

Fix: after 2.0.0
Fix from $1,950 2025-11-24
Sterling B2b Integrator MEDIUM 5.3
CVE-2025-36112

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.5 and 6.2.1.1 could reveal sensitive serv…

Fix: 6.1.2.7_2 / 6.2.0.5_1+
Fix from $1,600 2025-11-24