Vulnerability index

Browse CVEs

6,286 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Db2 Mirror For I MEDIUM 6.3
CVE-2025-36116

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 GUI is affected by cross-site WebSocket hijacking vulnerability. By sending a specially crafted request, an u…

Mitigation only
Fix from $1,600 2025-07-23
Db2 Mirror For I MEDIUM 6.3
CVE-2025-36117

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 does not disallow the session id after use which could allow an authenticated user to impersonate another user…

Mitigation only
Fix from $1,600 2025-07-23
Smartcloud Analytics Log Analysis MEDIUM 5.5
CVE-2024-41751

IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 could allow a local, authenticated attacker to bypas…

Mitigation only
Fix from $1,600 2025-07-23
Smartcloud Analytics Log Analysis MEDIUM 6.1
CVE-2024-40686

IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 is vulnerable to HTTP header injection, caused by im…

Mitigation only
Fix from $1,600 2025-07-23
Smartcloud Analytics Log Analysis MEDIUM 5.5
CVE-2024-40682

IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 could allow a local user to cause a denial of servic…

No fix yet
Fix from $1,600 2025-07-23
Smartcloud Analytics Log Analysis MEDIUM 5.5
CVE-2024-41750

IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 could allow a local, authenticated attacker to bypas…

Mitigation only
Fix from $1,600 2025-07-23
Cognos Analytics Mobile HIGH 8.2
CVE-2025-36106

IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 could allow malicious actors to view and modify information coming to and from the application…

Fix: 1.1.23+
Fix from $1,950 2025-07-21
Cognos Analytics Mobile HIGH 7.5
CVE-2025-36062

IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 could be vulnerable to information exposure due to the use of unencrypted network traffic.

Fix: 1.1.23+
Fix from $1,950 2025-07-21
Cognos Analytics Mobile HIGH 7.5
CVE-2025-36107

IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 could allow malicious actors to obtain sensitive information due to the cleartext transmission…

Fix: 1.1.23+
Fix from $1,950 2025-07-21
Sterling B2b Integrator MEDIUM 6.1
CVE-2025-33014

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.4 uses a web link with untrusted referenc…

Fix: 6.1.2.7_1 / 6.2.0.5+
Fix from $1,600 2025-07-18
Websphere Application Server HIGH 7.5
CVE-2025-36097

IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7 are vulnerable to a denial of service, caused…

Fix: 9.0.5.24 / 25.0.0.8+
Fix from $1,950 2025-07-16
Qradar Security Information And Event Manager MEDIUM 5.4
CVE-2025-33097

IBM QRadar SIEM 7.5 - 7.5.0 UP12 IF02 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary …

Mitigation only
Fix from $1,600 2025-07-15
Storage Scale MEDIUM 6.5
CVE-2025-36104

IBM Storage Scale 5.2.3.0 and 5.2.3.1 could allow an authenticated user to obtain sensitive information from files due to the insecure permissions in…

Mitigation only
Fix from $1,600 2025-07-12
Mq Appliance HIGH 7.5
CVE-2025-3631

An IBM MQ 9.3 and 9.4 Client connecting to an MQ Queue Manager can cause a SIGSEGV in the AMQRMPPA channel process terminating it.

Fix: 9.4.0.12 / 9.4.3+
Fix from $1,950 2025-07-11
Analytics Content Hub CRITICAL 9.8
CVE-2024-39752

IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could be vulnerable to malicious file upload by not validating the type of file uploaded to Explore …

Fix: 2.4+
Fix from $2,300 2025-07-10
Analytics Content Hub MEDIUM 5.3
CVE-2025-36090

IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could allow a remote attacker to obtain information about the application framework which could be u…

Fix: 2.4+
Fix from $1,600 2025-07-10
Analytics Content Hub CRITICAL 9.8
CVE-2024-38327

IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 is vulnerable to information exposure and further attacks due to an exposed JavaScript source map wh…

Fix: 2.4+
Fix from $2,300 2025-07-10
Analytics Content Hub MEDIUM 5.3
CVE-2024-37524

IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could allow a remote attacker to obtain sensitive information when a detailed technical error messag…

Fix: 2.4+
Fix from $1,600 2025-07-10
Infosphere Data Replication MEDIUM 6.5
CVE-2024-56468

IBM InfoSphere Data Replication VSAM for z/OS Remote Source 11.4 could allow a remote user to cause a denial of service by sending an invalid HTTP re…

Mitigation only
Fix from $1,600 2025-07-08
Openpages With Watson MEDIUM 6.5
CVE-2025-27367

IBM OpenPages with Watson 8.3 and 9.0 is vulnerable to improper input validation due to bypassing of client-side validation for the data types …

Fix: 8.3.0.3.2 / 9.0.0.5.3+
Fix from $1,600 2025-07-08
Openpages With Watson MEDIUM 6.5
CVE-2024-49784

IBM OpenPages with Watson 8.3 and 9.0 could provide weaker than expected security in storage of encrypted data with AES encryption and CBC mode. If…

Fix: 8.3.0.3.1 / 9.0.0.5+
Fix from $1,600 2025-07-08
Openpages With Watson MEDIUM 6.5
CVE-2024-49783

IBM OpenPages with Watson 8.3 and 9.0 could provide weaker than expected security in storage of encrypted data. If an authenticated remote attack…

Fix: 8.3.0.3.1 / 9.0.0.5+
Fix from $1,600 2025-07-08
Openpages With Watson MEDIUM 6.1
CVE-2023-43039

IBM OpenPages with Watson 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI…

Fix: 9.0.0.3+
Fix from $1,600 2025-07-08
Sterling B2b Integrator MEDIUM 5.4
CVE-2025-2793

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.6, 6.2.0.0 through 6.2.0.4, IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6, and 6.2.0.0 throug…

Fix: 6.1.2.7_1 / 6.2.0.5+
Fix from $1,600 2025-07-08
Sterling B2b Integrator MEDIUM 5.4
CVE-2025-3630

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.6, 6.2.0.0 through 6.2.0.4, IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6, and 6.2.0.0 throug…

Fix: 6.1.2.7_1 / 6.2.0.5+
Fix from $1,600 2025-07-08
Engineering Requirements Management Doors MEDIUM 5.9
CVE-2024-43190

IBM Engineering Requirements Management DOORS 9.7.2.9, under certain configurations, could allow a remote attacker to obtain password reset instructi…

Fix: after 9.6.1.13
Fix from $1,600 2025-07-07
Storage Virtualize HIGH 7.0
CVE-2025-1351

IBM Storage Virtualize 8.5, 8.6, and 8.7 products could allow a user to escalate their privileges to that of another user logging in at the same time…

Mitigation only
Fix from $1,950 2025-07-07
Integration Bus MEDIUM 6.7
CVE-2025-36014

IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.5 is vulnerable to code injection by a privileged user with access to the IIB install directory.

Fix: after 10.1.0.5
Fix from $1,600 2025-07-07
3957 Ved Firmware MEDIUM 5.4
CVE-2025-36056

IBM System Storage Virtualization Engine TS7700 3957 VED R5.4 8.54.2.17, R6.0 8.60.0.115, 3948 VED R5.4 8.54.2.17, R6.0 8.60.0.115, and 3948 VEF R6.0…

Fix: after 8.60.0.115
Fix from $1,600 2025-07-01
3948 Vef Firmware MEDIUM 6.1
CVE-2025-2141

IBM System Storage Virtualization Engine TS7700 3957 VED R5.4 8.54.2.17, R6.0 8.60.0.115, 3948 VED R5.4 8.54.2.17, R6.0 8.60.0.115, and 3948 VEF R6.0…

Fix: after 8.60.0.115
Fix from $1,600 2025-07-01