Vulnerability index

Browse CVEs

6,286 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Concert MEDIUM 5.4
CVE-2025-36149

IBM Concert Software 1.0.0 through 2.0.0 could allow a remote attacker to hijack the clicking action of the victim.

Fix: 2.1.0+
Fix from $1,600 2025-11-21
Webmethods Integration HIGH 8.8
CVE-2025-36072

IBM webMethods Integration 10.11 through 10.11_Core_Fix22, 10.15 through 10.15_Core_Fix22, and 11.1 through 11.1_Core_Fix6 IBM webMethods Integration…

Mitigation only
Fix from $1,950 2025-11-20
Concert HIGH 7.5
CVE-2025-36160

IBM Concert 1.0.0 through 2.0.0 could disclose sensitive server information from HTTP response headers that could aid in further attacks against the …

Fix: 2.1.0+
Fix from $1,950 2025-11-20
Concert MEDIUM 5.5
CVE-2025-36158

IBM Concert 1.0.0 through 2.0.0 could allow a local user with specific permission to obtain sensitive information from files due to uncontrolled recu…

Fix: 2.1.0+
Fix from $1,600 2025-11-20
Concert MEDIUM 5.5
CVE-2025-36159

IBM Concert 1.0.0 through 2.0.0 could allow a local user to forge log files to impersonate other users or hide their identity due to improper neutral…

Fix: 2.1.0+
Fix from $1,600 2025-11-20
Concert MEDIUM 6.1
CVE-2025-36153

IBM Concert 1.0.0 through 2.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaS…

Fix: 2.1.0+
Fix from $1,600 2025-11-20
Concert MEDIUM 5.9
CVE-2025-36161

IBM Concert 1.0.0 through 2.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict-T…

Fix: 2.1.0+
Fix from $1,600 2025-11-20
I MEDIUM 6.5
CVE-2025-36371

IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 are impacted by obtaining an information vulnerability in the database plan cache implementation.  A user with acce…

Mitigation only
Fix from $1,600 2025-11-19
Storage Virtualize HIGH 7.5
CVE-2025-36118

IBM Storage Virtualize 8.4, 8.5, 8.7, and 9.1 IKEv1 implementation allows remote attackers to obtain sensitive information from device memory via a S…

Mitigation only
Fix from $1,950 2025-11-17
Planning Analytics Local HIGH 8.0
CVE-2025-36357

IBM Planning Analytics Local 2.1.0 through 2.1.14 could allow a remote authenticated user to traverse directories on the system. An attacker could se…

Fix: 2.1.15+
Fix from $1,950 2025-11-17
Vios CRITICAL 9.8
CVE-2025-36251

IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 nimsh service SSL/TLS implementations could allow a remote attacker to execute arbitrary commands due …

Mitigation only
Fix from $2,300 2025-11-13
Vios CRITICAL 9.8
CVE-2025-36250

IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a remote attacker to execute a…

Mitigation only
Fix from $2,300 2025-11-13
Vios CRITICAL 9.1
CVE-2025-36236

IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a remote attacker to traverse …

Mitigation only
Fix from $2,300 2025-11-13
Vios HIGH 8.1
CVE-2025-36096

IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 stores NIM private keys used in NIM environments in an insecure way which is susceptible to unauthoriz…

Mitigation only
Fix from $1,950 2025-11-13
Qradar Security Information And Event Manager MEDIUM 6.5
CVE-2025-33119

IBM QRadar SIEM 7.5 through 7.5.0 UP14 stores user credentials in configuration files in source control which can be read by an authenticated user.

Mitigation only
Fix from $1,600 2025-11-12
Openpages MEDIUM 6.1
CVE-2025-36223

IBM OpenPages 9.0 and 9.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an att…

Mitigation only
Fix from $1,600 2025-11-12
Cognos Analytics Certified Containers MEDIUM 5.3
CVE-2025-33150

IBM Cognos Analytics Certified Containers 12.1.0 could disclose package parameter information due to the presence of hidden pages.

Mitigation only
Fix from $1,600 2025-11-10
Db2 HIGH 7.8
CVE-2025-36186

IBM Db2 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) under specific configurations could allow a local user to exe…

Fix: after 12.1.3
Fix from $1,950 2025-11-07
Db2 MEDIUM 5.5
CVE-2025-36136

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local user to cause …

Fix: after 12.1.3
Fix from $1,600 2025-11-07
Db2 MEDIUM 5.5
CVE-2025-36185

IBM Db2 12.1.0 through 12.1.2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a local user to cause a denial of service due to …

Fix: after 12.1.2
Fix from $1,600 2025-11-07
Sterling B2b Integrator MEDIUM 5.4
CVE-2025-36135

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.7_1, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7_1, …

Fix: after 6.2.0.5
Fix from $1,600 2025-11-07
Db2 MEDIUM 6.5
CVE-2025-36006

IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 C…

Fix: after 12.1.3
Fix from $1,600 2025-11-07
Db2 MEDIUM 6.5
CVE-2025-36008

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user …

Fix: after 12.1.3
Fix from $1,600 2025-11-07
Db2 HIGH 8.8
CVE-2025-33012

IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux could allow an authenticated user…

Fix: after 12.1.3
Fix from $1,950 2025-11-07
Db2 HIGH 7.5
CVE-2025-2534

IBM Db2 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulner…

Fix: after 12.1.3
Fix from $1,950 2025-11-07
Db2 HIGH 7.5
CVE-2024-47118

IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 C…

Fix: after 12.1.3
Fix from $1,950 2025-11-07
Openpages MEDIUM 5.4
CVE-2025-33110

IBM OpenPages 9.1, and 9.0 with Watson is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would …

Mitigation only
Fix from $1,600 2025-11-06
Business Automation Workflow MEDIUM 6.1
CVE-2025-36054

IBM Business Automation Workflow containers 24.0.0 through 24.0.0-IF006, 24.0.1 through 24.0.1-IF004, 25.0.0 through 25.0.0-IF001 and IBM Business Au…

Patch available
Fix from $1,600 2025-11-06
Cloud Pak For Business Automation MEDIUM 5.4
CVE-2025-36172

IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 001, 24.0.1 through 24.0.1 Interim Fix 004, 24.0.0 through 24.0.0 Interim Fix…

Mitigation only
Fix from $1,600 2025-11-03
Infosphere Information Server CRITICAL 9.1
CVE-2025-12531

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. …

Fix: after 11.7.1.6
Fix from $2,300 2025-11-03