Vulnerability index

Browse CVEs

6,286 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Storage Ts4500 Library Firmware MEDIUM 5.4
CVE-2025-36088

IBM TS4500 1.11.0.0-D00, 1.11.0.1-C00, 1.11.0.2-C00, and 1.10.00-F00 web GUI is vulnerable to cross-site scripting. This vulnerability allows an auth…

Mitigation only
Fix from $1,600 2025-08-15
Websphere Application Server HIGH 7.5
CVE-2025-36047

IBM WebSphere Application Server Liberty 18.0.0.2 through 25.0.0.8 is vulnerable to a denial of service, caused by sending a specially-crafted reques…

Fix: 25.0.0.9+
Fix from $1,950 2025-08-14
Websphere Application Server HIGH 7.5
CVE-2025-33142

IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security for TLS connections.

Fix: 8.5.5.29 / 9.0.5.25+
Fix from $1,950 2025-08-14
Websphere Application Server HIGH 7.5
CVE-2025-36124

IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.8 could allow a remote attacker to bypass security restrictions caused by a failure …

Fix: 25.0.0.9+
Fix from $1,950 2025-08-12
I HIGH 8.8
CVE-2025-36119

IBM i 7.3, 7.4, 7.5, and 7.6 is affected by an authenticated user obtaining elevated privileges with IBM Digital Certificate Manager for i (DCM) due …

Mitigation only
Fix from $1,950 2025-08-08
Cloud Pak For Business Automation MEDIUM 6.5
CVE-2025-36023

IBM Cloud Pak for Business Automation 24.0.0 through 24.0.0 IF005 and 24.0.1 through 24.0.1 IF002 could allow an authenticated user to view sensitive…

Mitigation only
Fix from $1,600 2025-08-08
Websphere Application Server HIGH 7.5
CVE-2024-56339

IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7 could allow a remote attacker to bypass secur…

Fix: after 25.0.0.7
Fix from $1,950 2025-08-07
Guardium Data Protection HIGH 7.5
CVE-2025-36020

IBM Guardium Data Protection could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive credential info…

Mitigation only
Fix from $1,950 2025-08-06
Tivoli Monitoring CRITICAL 9.8
CVE-2025-3320

IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 20 is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A re…

Mitigation only
Fix from $2,300 2025-08-06
Tivoli Monitoring CRITICAL 9.8
CVE-2025-3354

IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 20 is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A re…

Mitigation only
Fix from $2,300 2025-08-06
Engineering Lifecycle Optimization MEDIUM 6.1
CVE-2024-52890

IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.03 could be susceptible to cross-site scripting due to no validation of URIs.

Mitigation only
Fix from $1,600 2025-08-05
Operational Decision Manager HIGH 7.4
CVE-2025-2824

IBM Operational Decision Manager 8.11.0.1, 8.11.1.0, 8.12.0.1, 9.0.0.1, and 9.5.0 could allow a remote attacker to conduct phishing attacks, using an…

Mitigation only
Fix from $1,950 2025-08-01
Qradar Security Information And Event Manager MEDIUM 5.4
CVE-2025-33118

IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 12 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed…

Mitigation only
Fix from $1,600 2025-08-01
Aspera Faspex MEDIUM 6.5
CVE-2025-36039

IBM Aspera Faspex 5.0.0 through 5.0.12.1 could allow an authenticated user to perform unauthorized actions due to client-side enforcement of sever si…

Fix: after 5.0.12.1
Fix from $1,600 2025-07-31
Aspera Faspex MEDIUM 6.5
CVE-2025-36040

IBM Aspera Faspex 5.0.0 through 5.0.12.1 could allow an authenticated user to perform unauthorized actions due to client-side enforcement of sever si…

Fix: after 5.0.12.1
Fix from $1,600 2025-07-31
Db2 HIGH 7.8
CVE-2025-33092

IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2 is vulnerable to a stack-based buffer overflow in db2fm, caused by improper bounds checking. A local u…

Mitigation only
Fix from $1,950 2025-07-29
Db2 HIGH 7.5
CVE-2025-33114

IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2 is vulnerable to denial of service with a specially crafted query under certain non-default conditio…

Mitigation only
Fix from $1,950 2025-07-29
Db2 HIGH 7.5
CVE-2025-36071

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.2 is vulnerable to a denial of servic…

Fix: after 12.1.2
Fix from $1,950 2025-07-29
Db2 HIGH 7.5
CVE-2024-49828

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5.0.0 through 10.5.0.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.…

Fix: after 12.1.2
Fix from $1,950 2025-07-29
Db2 HIGH 7.5
CVE-2024-51473

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5.0.0 through 10.5.0.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.…

Fix: after 12.1.2
Fix from $1,950 2025-07-29
Db2 HIGH 7.5
CVE-2025-36010

IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2 could allow an unauthenticated user to cause a denial of service due to executable segments that are w…

Mitigation only
Fix from $1,950 2025-07-29
Db2 HIGH 7.5
CVE-2025-2533

IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2 is vulnerable to a denial of service as the server may crash under certain conditions with a specially c…

Mitigation only
Fix from $1,950 2025-07-29
Informix Dynamic Server HIGH 7.5
CVE-2024-49342

IBM Informix Dynamic Server 12.10 and 14.10 uses an inadequate account lockout setting that could allow a remote attacker to brute force account cred…

Mitigation only
Fix from $1,950 2025-07-28
Informix Dynamic Server MEDIUM 5.4
CVE-2024-49343

IBM Informix Dynamic Server 12.10 and 14.10 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, w…

Mitigation only
Fix from $1,600 2025-07-28
Mq Operator MEDIUM 6.5
CVE-2025-36005

IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1, 3.6.0, and MQ Operator…

Fix: after 3.6.0
Fix from $1,600 2025-07-24
I HIGH 8.8
CVE-2025-33109

IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 is vulnerable to a privilege escalation caused by an invalid database authority check. A bad actor could execute a…

Mitigation only
Fix from $1,950 2025-07-24
Mq Operator MEDIUM 5.5
CVE-2025-33013

IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1, 3.6.0, and MQ Operator…

Fix: after 3.6.0
Fix from $1,600 2025-07-24
Engineering Systems Design Rhapsody HIGH 8.8
CVE-2025-33076

IBM Engineering Systems Design Rhapsody 9.0.2, 10.0, and 10.0.1 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A…

Mitigation only
Fix from $1,950 2025-07-23
Engineering Systems Design Rhapsody HIGH 8.8
CVE-2025-33077

IBM Engineering Systems Design Rhapsody 9.0.2, 10.0, and 10.0.1 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A…

Mitigation only
Fix from $1,950 2025-07-23
Engineering Systems Design Rhapsody HIGH 7.5
CVE-2025-33020

IBM Engineering Systems Design Rhapsody 9.0.2, 10.0, and 10.0.1 transmits sensitive information without encryption that could allow an attacker to ob…

Mitigation only
Fix from $1,950 2025-07-23