Vulnerability index

Browse CVEs

6,266 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Websphere Application Server HIGH 7.5
CVE-2026-10842

IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 Traditional and Liberty could …

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $1,950 2026-07-30
App Connect Enterprise CRITICAL 9.8
CVE-2026-15435

IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to traverse directories on the sy…

Fix: 12.0.12.28 / 13.0.8.0+
Fix from $2,300 2026-07-30
Websphere Application Server HIGH 8.8
CVE-2026-14980

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to per…

Fix: 26.0.0.9+
Fix from $1,950 2026-07-30
App Connect Enterprise CRITICAL 9.8
CVE-2026-14522

IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to execute arbitrary commands due…

Fix: 12.0.12.28 / 13.0.8.0+
Fix from $2,300 2026-07-30
App Connect Enterprise HIGH 7.5
CVE-2026-14519

IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to read arbitrary files due to a …

Fix: 12.0.12.28 / 13.0.8.0+
Fix from $1,950 2026-07-30
Websphere Application Server CRITICAL 9.3
CVE-2026-11707

IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-site scripting vulnerability in the …

Mitigation only
Fix from $2,300 2026-07-30
Websphere Application Server HIGH 7.5
CVE-2026-11897

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service, caused by sending a specially crafted requ…

Fix: 26.0.0.8+
Fix from $1,950 2026-07-30
App Connect Enterprise HIGH 7.5
CVE-2026-12947

IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 stores potentially sensitive information in log files that coul…

Fix: 12.0.12.28 / 13.0.8.0+
Fix from $1,950 2026-07-30
Aspera HIGH 7.3
CVE-2026-11980

IBM Aspera Desktop App 1.0.5 through 1.0.19 can allow arbitrary code execution by loading DLL files at start-up.

Fix: after 1.0.19
Fix from $1,950 2026-07-30
Sterling B2b Integrator MEDIUM 5.4
CVE-2025-36431

IBM Sterling B2B Integrator 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.2.0 through 6.2.2.0_1 is vulnerable to cross-site scripting. …

No fix yet
Fix from $1,600 2026-07-30
Websphere Application Server MEDIUM 5.4
CVE-2026-11383

IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by cross-site scripting in the Administrative C…

No fix yet
Fix from $1,600 2026-07-30
Sterling B2b Integrator MEDIUM 5.4
CVE-2025-36298

IBM Sterling B2B Integrator 6.1.2.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM St…

No fix yet
Fix from $1,600 2026-07-30
Websphere Application Server HIGH 8.8
CVE-2026-2482

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to exe…

Fix: 26.0.0.9+
Fix from $1,950 2026-07-29
Websphere Application Server CRITICAL 9.8
CVE-2026-14529

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to s…

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $2,300 2026-07-29
Websphere Application Server HIGH 8.7
CVE-2026-15064

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to HTTP Response…

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $1,950 2026-07-28
Websphere Application Server HIGH 8.7
CVE-2026-15325

IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTTP request smuggling due to improper handling of T…

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $1,950 2026-07-28
Aspera Faspex HIGH 8.2
CVE-2026-14996

IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 has addressed a vulnerability related to session management.

Fix: 5.0.16+
Fix from $1,950 2026-07-28
Websphere Application Server HIGH 8.1
CVE-2026-15328

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to HTTP request …

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $1,950 2026-07-28
Websphere Application Server HIGH 7.5
CVE-2026-14981

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are affected by a denial of se…

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $1,950 2026-07-28
Websphere Application Server HIGH 7.5
CVE-2026-15057

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service due to uncontrolled heap allocation.

Fix: 26.0.0.8+
Fix from $1,950 2026-07-28
Websphere Application Server HIGH 7.5
CVE-2026-15280

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 ND Collective Controller is affected by a path-segment injection vulnerability i…

Fix: 26.0.0.9+
Fix from $1,950 2026-07-28
Websphere Application Server CRITICAL 9.8
CVE-2026-14974

IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of…

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $2,300 2026-07-28
Websphere Application Server CRITICAL 9.8
CVE-2026-14976

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code execution with the collectiveController-1.0 feature e…

Fix: 26.0.0.9+
Fix from $2,300 2026-07-28
Aspera CRITICAL 9.3
CVE-2026-14973

IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination.

Fix: after 1.0.19
Fix from $2,300 2026-07-28
Websphere Application Server HIGH 7.5
CVE-2026-14528

IBM WebSphere Application Server 9.0, and 8.5 traditional could allow a remote attacker to obtain sensitive information.

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $1,950 2026-07-28
Aspera Faspex HIGH 7.2
CVE-2026-14958

IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to unquoted shell interpolation.

Fix: 5.0.16+
Fix from $1,950 2026-07-28
Aspera Faspex HIGH 7.2
CVE-2026-14959

IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to shell command injection.

Fix: 5.0.16+
Fix from $1,950 2026-07-28
Websphere Application Server CRITICAL 9.8
CVE-2026-14446

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the administrative console.

Fix: 8.5.5.30 / 9.0.5.28+
Fix from $2,300 2026-07-28
Websphere Application Server CRITICAL 9.8
CVE-2026-14512

IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attac…

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $2,300 2026-07-28
Websphere Application Server MEDIUM 6.1
CVE-2026-14515

IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to conduct a cross-site scripting attack.

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $1,600 2026-07-28