Vulnerability index

Browse CVEs

6,266 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Infosphere Information Server HIGH 7.5
CVE-2026-9836

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is affected by an information disclosure vulnerability.

Fix: after 11.7.1.6
Fix from $1,950 2026-06-30
Websphere Extreme Scale MEDIUM 6.5
CVE-2026-9002

IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 could allow an adjacent attacker to cause a denial of service due to improper validation in the X…

Fix: after 8.6.1.6
Fix from $1,600 2026-06-30
Websphere Extreme Scale CRITICAL 10.0
CVE-2026-13773

IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 Approximately 50 generated CORBA stub classes in WebSphere eXtreme Scale's ogclient.jar call ORB.…

Fix: after 8.6.1.6
Fix from $2,300 2026-06-30
Websphere Extreme Scale CRITICAL 9.9
CVE-2026-13772

IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 's Object Query Language engine resolves attacker-supplied class names via Class.forName() and in…

Fix: after 8.6.1.6
Fix from $2,300 2026-06-30
App Connect Enterprise MEDIUM 5.5
CVE-2026-3602

IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.26 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 is v…

Fix: 12.0.12.27 / 13.0.8.0+
Fix from $1,600 2026-06-30
Websphere Application Server CRITICAL 9.8
CVE-2026-11714

IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability with the apiDiscovery-1.0 feature enabled.

Fix: 26.0.0.8+
Fix from $2,300 2026-06-30
Business Automation Manager CRITICAL 9.1
CVE-2026-13449

IBM Business Automation Manager Open Editions 9.0.0 through 9.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML …

Fix: 9.5.0+
Fix from $2,300 2026-06-30
Websphere Extreme Scale HIGH 8.8
CVE-2026-13759

IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 ships three ObjectInputStream subclasses (WsObjectInputStream, ObjectStreamPool$ReusableInputStre…

Fix: after 8.6.1.6
Fix from $1,950 2026-06-30
Websphere Application Server HIGH 7.5
CVE-2026-11806

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 is affected by an arbitrary file read vulnerability with the restConnector-2.0 f…

Fix: 26.0.0.7+
Fix from $1,950 2026-06-30
Devops Deploy HIGH 7.5
CVE-2026-12084

IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to c…

Fix: 8.1.2.7 / 8.2.2.0+
Fix from $1,950 2026-06-30
Db2 MEDIUM 6.5
CVE-2026-11906

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user …

Fix: after 12.1.4
Fix from $1,600 2026-06-30
Devops Deploy MEDIUM 6.5
CVE-2026-12085

IBM UCD - IBM UrbanCode Deploy 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 through 8.1.2.6, and 8.2 through 8.2.1.…

Fix: 7.3.2.19 / 8.0.1.14+
Fix from $1,600 2026-06-30
Devops Deploy MEDIUM 5.5
CVE-2026-12086

IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.23, and 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 through 8.1.2…

Fix: 7.2.3.24 / 7.3.2.19+
Fix from $1,600 2026-06-30
Websphere Application Server CRITICAL 9.8
CVE-2026-11546

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the adminCenter-…

Fix: 26.0.0.8+
Fix from $2,300 2026-06-30
Websphere Application Server CRITICAL 9.3
CVE-2026-11708

IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console's integrated help sys…

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $2,300 2026-06-30
Websphere Application Server CRITICAL 9.3
CVE-2026-11712

IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console help system.

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $2,300 2026-06-30
Websphere Application Server HIGH 7.5
CVE-2026-11595

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information from the administrative console's integra…

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $1,950 2026-06-30
Db2 CRITICAL 9.8
CVE-2026-10109

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution due to improper pre-auth DRDA handshake handling.

Fix: after 12.1.4
Fix from $2,300 2026-06-30
Db2 MEDIUM 6.5
CVE-2025-36372

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could disclose sensitive informati…

Fix: 11.5.9+
Fix from $1,600 2026-06-30
I HIGH 7.5
CVE-2026-10852

IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to denial of service in the WebSphere WebServer Plug-in …

Mitigation only
Fix from $1,950 2026-06-22
I CRITICAL 9.8
CVE-2026-9072

IBM WebSphere Application Server and IBM WebSphere Application Server Liberty - when using Intelligent Management with the WebSphere WebServer Plug-i…

Fix: after 7.6
Fix from $2,300 2026-06-22
Websphere Application Server CRITICAL 9.1
CVE-2026-9006

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an a…

Fix: 8.5.5.30 / 9.0.5.29+
Fix from $2,300 2026-06-22
Websphere Application Server HIGH 7.5
CVE-2026-9071

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of …

Fix: 8.5.5.30 / 9.0.5.29+
Fix from $1,950 2026-06-22
Websphere Application Server HIGH 7.5
CVE-2026-9320

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of …

Fix: 8.5.5.30 / 9.0.5.29+
Fix from $1,950 2026-06-22
Datacap MEDIUM 5.3
CVE-2026-9610

IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 exposes resources or functionality that isn't linked in the UI …

Mitigation only
Fix from $1,600 2026-06-22
Websphere Application Server CRITICAL 9.1
CVE-2026-8646

IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to HTTP request …

Fix: 8.5.5.30 / 9.0.5.29+
Fix from $2,300 2026-06-22
I HIGH 8.8
CVE-2026-8858

IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to remote code execution and denial of service in the We…

Fix: after 7.6
Fix from $1,950 2026-06-22
Datacap HIGH 7.5
CVE-2026-8636

IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 allows an attacker to retrieve user passwords and cryptographic…

Mitigation only
Fix from $1,950 2026-06-22
Datacap MEDIUM 6.1
CVE-2026-8059

IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 is vulnerable to cross-site scripting. This vulnerability allow…

Mitigation only
Fix from $1,600 2026-06-22
Watson Speech Services Cartridge MEDIUM 6.0
CVE-2026-7253

IBM Sterling B2B Integrator and IBM Sterling File Gateway are vulnerable to SQL injection. A privileged user could send specially crafted SQL stateme…

Fix: 5.3.1+
Fix from $1,600 2026-06-22