Vulnerability index

Browse CVEs

6,286 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cloud Pak For Business Automation HIGH 7.4
CVE-2025-36093

IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an attacker to access unauthorized content or perform unauthorized actio…

Mitigation only
Fix from $1,950 2025-11-03
Cloud Pak For Business Automation MEDIUM 6.5
CVE-2025-36092

IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an authenticated user to cause a denial of service due to the improper v…

Mitigation only
Fix from $1,600 2025-11-03
I HIGH 8.8
CVE-2025-36367

IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 is vulnerable to privilege escalation caused by an invalid IBM i SQL services authorization check. A malicious acto…

Mitigation only
Fix from $1,950 2025-11-01
Infosphere Information Server HIGH 7.8
CVE-2025-33003

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow a non-root user to gain higher privileges/capabilities within the scope of a …

Fix: after 11.7.1.6
Fix from $1,950 2025-10-31
Jazz For Service Management MEDIUM 5.3
CVE-2025-36249

IBM Jazz for Service Management 1.1.3.0 through 1.1.3.25 does not set the secure attribute on authorization tokens or session cookies. Attackers may …

Fix: 1.1.3.26+
Fix from $1,600 2025-10-31
Tivoli Monitoring CRITICAL 9.8
CVE-2025-3356

IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on the system. An attacker could …

Mitigation only
Fix from $2,300 2025-10-30
Tivoli Monitoring HIGH 7.5
CVE-2025-3355

IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on the system. An attacker could …

Mitigation only
Fix from $1,950 2025-10-30
Sterling Connect\ HIGH 7.2
CVE-2025-36137

IBM Sterling Connect Direct for Unix 6.2.0.7 through 6.2.0.9 iFix004, 6.4.0.0 through 6.4.0.2 iFix001, and 6.3.0.2 through 6.3.0.5 iFix002 incorrectl…

Fix: 6.2.0.9 / 6.3.0.5+
Fix from $1,950 2025-10-30
Maximo Application Suite CRITICAL 9.8
CVE-2025-36386

IBM Maximo Application Suite 9.0.0 through 9.0.15 and 9.1.0 through 9.1.4 could allow a remote attacker to bypass authentication mechanisms and gain …

Fix: after 9.1.4
Fix from $2,300 2025-10-28
Concert MEDIUM 5.5
CVE-2025-36083

IBM Concert Software 1.0.0 through 2.0.0 could allow a local user to obtain sensitive information from buffers due to improper clearing of heap mem…

Fix: 2.1.0+
Fix from $1,600 2025-10-28
Concert MEDIUM 5.4
CVE-2025-36085

IBM Concert 1.0.0 through 2.0.0 Software is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauth…

Fix: 2.1.0+
Fix from $1,600 2025-10-28
Concert MEDIUM 5.3
CVE-2025-36081

IBM Concert Software 1.0.0 through 2.0.0 could allow a user to modify system logs due to improper neutralization of log input.

Fix: 2.1.0+
Fix from $1,600 2025-10-28
Db2 High Performance Unload Load MEDIUM 6.5
CVE-2025-33131

IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, and 5.1 could allow an authenticated user to cause the pro…

Fix: after 6.1.0.0
Fix from $1,600 2025-10-28
Db2 High Performance Unload Load MEDIUM 6.5
CVE-2025-33132

IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, and 5.1 could allow an authenticated user to cause the pro…

Fix: after 6.1.0.0
Fix from $1,600 2025-10-28
Db2 High Performance Unload Load MEDIUM 6.5
CVE-2025-33133

IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, and 5.1 could allow an authenticated user to cause the pro…

Fix: after 6.1.0.0
Fix from $1,600 2025-10-28
Db2 High Performance Unload Load MEDIUM 6.5
CVE-2025-33126

IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, 5.1, 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1,…

Fix: after 6.1.0.0
Fix from $1,600 2025-10-28
Qradar Security Information And Event Manager HIGH 7.8
CVE-2025-36007

IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 13 Independent Fix 02 is vulnerable to privilege escalation due to improper privilege assignment to an …

Mitigation only
Fix from $1,950 2025-10-27
Qradar Security Information And Event Manager MEDIUM 5.4
CVE-2025-36138

IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 13 Independent Fix 02 is vulnerable to stored cross-site scripting. This vulnerability allows an authen…

Mitigation only
Fix from $1,600 2025-10-27
Qradar Security Information And Event Manager MEDIUM 5.4
CVE-2025-36170

IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 13 Independent Fix 02 is vulnerable to stored cross-site scripting. This vulnerability allows an authen…

Mitigation only
Fix from $1,600 2025-10-27
Openpages MEDIUM 5.4
CVE-2025-36121

IBM OpenPages 9.1 and 9.0 is vulnerable to HTML injection. A remotely authenticated attacker could inject malicious HTML code, which when viewed, wou…

Mitigation only
Fix from $1,600 2025-10-27
App Connect Enterprise HIGH 8.8
CVE-2025-36361

IBM App Connect Enterprise 13.0.1.0 through 13.0.4.2, and 12.0.1.0 through 12.0.12.17 could allow an authenticated user to perform unauthorized actio…

Fix: after 13.0.4.2
Fix from $1,950 2025-10-24
Mq HIGH 7.5
CVE-2025-36128

IBM MQ 9.1, 9.2, 9.3, 9.4 LTS and 9.3, 9.4 CD is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual read …

Mitigation only
Fix from $1,950 2025-10-16
Sterling B2b Integrator MEDIUM 5.5
CVE-2025-36002

IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5, and 6.2.1.0 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5, and 6.2.1.0 stores user crede…

Fix: 6.2.0.5_1+
Fix from $1,600 2025-10-16
Content Navigator MEDIUM 5.3
CVE-2025-27906

IBM Content Navigator 3.0.11, 3.0.15, 3.1.0, and 3.2.0 could expose the directory listing of the application upon using an application URL. Applicati…

Mitigation only
Fix from $1,600 2025-10-14
Security Verify Access CRITICAL 9.8
CVE-2025-36087

IBM Security Verify Access 10.0.0 through 10.0.9, 11.0.0, IBM Verify Identity Access Container 10.0.0 through 10.0.9, and 11.0.0, under certain confi…

Fix: after 10.0.9
Fix from $2,300 2025-10-13
Engineering Requirements Management Doors Next MEDIUM 6.5
CVE-2025-33096

IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user to cause a denial of service by uploading …

Mitigation only
Fix from $1,600 2025-10-12
Engineering Requirements Management Doors Next MEDIUM 5.7
CVE-2025-2140

IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the network to spoof email identity of …

Mitigation only
Fix from $1,600 2025-10-12
Aspera Faspex MEDIUM 5.3
CVE-2023-37401

IBM Aspera Faspex 5.0.0 through 5.0.13.1 uses a cross-domain policy file that includes domains that should not be trusted.

Fix: 5.0.14+
Fix from $1,600 2025-10-09
Infosphere Data Replication Vsam For Z\/os Remote Source HIGH 7.8
CVE-2025-36156

IBM InfoSphere Data Replication VSAM for z/OS Remote Source 11.4 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. …

Mitigation only
Fix from $1,950 2025-10-07
Jazz Foundation MEDIUM 5.4
CVE-2025-1826

IBM Engineering Requirements Management DOORS Next (IBM Jazz Foundation 7.0.2 to 7.0.2 iFix034, 7.0.3 to 7.0.3 iFix016, and 7.1.0 to 7.1.0 iFix004) i…

Patch available
Fix from $1,600 2025-10-07