Vulnerability index

Browse CVEs

6,286 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Websphere Application Server CRITICAL 9.1
CVE-2026-8644

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing.

Fix: 8.5.5.30 / 9.0.5.29+
Fix from $2,300 2026-06-01
Websphere Application Server CRITICAL 9.0
CVE-2026-9311

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security controls.

Fix: 8.5.5.30 / 9.0.5.29+
Fix from $2,300 2026-06-01
Websphere Application Server CRITICAL 9.0
CVE-2026-9319

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of untrusted data via JAX-WS en…

Fix: 8.5.5.30 / 9.0.5.29+
Fix from $2,300 2026-06-01
Websphere Application Server HIGH 8.5
CVE-2026-9330

IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validation of user-supplied data during deserialization using the SAML Web S…

Fix: 8.5.5.30 / 9.0.5.29+
Fix from $1,950 2026-06-01
Aspera High Speed Transfer Endpoint HIGH 7.5
CVE-2026-8180

IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and I…

Fix: after 4.4.6
Fix from $1,950 2026-05-27
Guardium Data Protection MEDIUM 6.5
CVE-2026-8405

IBM Guardium Data Protection 12.2.1, and 12.2.2 's add-on feature of Guardium Data Protection named "Long Term Retention" (LTR) can expose sensitive …

Mitigation only
Fix from $1,600 2026-05-27
Aspera High Speed Transfer Endpoint MEDIUM 6.5
CVE-2026-9035

IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and I…

Fix: after 4.4.6
Fix from $1,600 2026-05-27
Aspera High Speed Transfer Endpoint HIGH 8.8
CVE-2026-8179

IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and I…

Fix: after 4.4.6
Fix from $1,950 2026-05-27
Aspera High Speed Transfer Endpoint CRITICAL 9.8
CVE-2026-8175

IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and I…

Fix: after 4.4.6
Fix from $2,300 2026-05-27
Aspera High Speed Transfer Server For Cloud Pak For Integration CRITICAL 9.1
CVE-2026-7876

IBM Aspera HSTS for CP4I 1.5.1 through 1.5.19 is affected by an authentication bypass vulnerability. A transfer client may be able to take advantage …

Fix: 1.5.20+
Fix from $2,300 2026-05-27
Operations Analytics Log Analysis HIGH 7.8
CVE-2026-7365

IBM Operations Analytics - Log Analysis  and IBM SmartCloud Analytics - Log Analysis uses default passwords default passwords from the manufacturing …

Mitigation only
Fix from $1,950 2026-05-27
Db2 HIGH 7.5
CVE-2026-6938

IBM Db2 12.1.0 through 12.1.4 is vulnerable to authorization bypass when uploading to a remote object storage path with a special query.

Fix: after 12.1.4
Fix from $1,950 2026-05-27
Openbmc MEDIUM 5.3
CVE-2026-7254

IBM OPENBMC FW1110.00 through FW1110.11 is vulnerable to denial of service attacks by unauthenticated network users.

Fix: after 1110.11
Fix from $1,600 2026-05-27
Db2 HIGH 7.5
CVE-2026-6051

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service when executing a specially crafted query with a small s…

Fix: after 12.1.4
Fix from $1,950 2026-05-27
Db2 HIGH 7.5
CVE-2026-6052

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to running out of memory when executing certain queries with MDC tables.

Fix: after 12.1.4
Fix from $1,950 2026-05-27
I MEDIUM 6.5
CVE-2026-6936

IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to a denial-of-service attack due to uncontrolled recursion in the Integrated Language Environment (ILE) co…

Fix: after 7.6
Fix from $1,600 2026-05-27
Websphere Application Server MEDIUM 5.9
CVE-2026-5516

IBM WebSphere Application Server - Liberty 22.0.0.11 through 26.0.0.5 IBM WebSphere Application Server Liberty could allow a remote attacker to bypas…

Fix: after 26.0.0.5
Fix from $1,600 2026-05-27
App Connect Enterprise MEDIUM 5.5
CVE-2026-5515

IBM App Connect Enterprise 13.0.1.0 through 13.0.7.0 stores potentially sensitive information in log files that could be read by a local user.

Fix: 13.0.7.1+
Fix from $1,600 2026-05-27
Db2 MEDIUM 5.5
CVE-2026-6053

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service when a specially crafted query is run with range partit…

Fix: after 12.1.4
Fix from $1,600 2026-05-27
Controller HIGH 8.8
CVE-2026-5065

IBM Controller 11.0.1, 11.1.0, 11.1.1, and 11.1.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own…

Fix: 11.1.3+
Fix from $1,950 2026-05-27
Websphere Application Server HIGH 7.5
CVE-2026-4410

IBM WebSphere Application Server - Liberty 19.0.0.7 through 26.0.0.5 and IBM WebSphere Application Server 9.0, and 8.5 and WebSphere Application Serv…

Fix: after 26.0.0.5
Fix from $1,950 2026-05-27
Netezza Performance Server Replication Services HIGH 7.8
CVE-2026-3623

IBM Netezza Performance Server Replication Services 3.0.2.0 through 3.0.5.0 allows an attacker with low‑privileged access to escalate their privilege…

Fix: 3.0.5.1+
Fix from $1,950 2026-05-27
Cloud Application Performance Managemen MEDIUM 6.5
CVE-2026-3676

IBM Cloud APM, Base Private 8.1.4 and IBM Cloud APM, Advanced Private 8.1.4 IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) could a…

Mitigation only
Fix from $1,600 2026-05-27
Infosphere Optim Test Data Fabrication HIGH 7.5
CVE-2026-3366

IBM InfoSphere Optim Test Data Fabrication 1.0.0, 1.0.0.1, 1.0.0.2, 1.0.2, 1.0.2.2, 1.0.2.3, 1.0.2.4, 1.0.2.5, 1.0.2.6, 1.0.2.7 could allow a remote …

Mitigation only
Fix from $1,950 2026-05-27
Db2 HIGH 7.5
CVE-2026-1718

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service with a specially crafted query when autonomous transact…

Fix: after 12.1.4
Fix from $1,950 2026-05-27
Cognos Analytics HIGH 8.2
CVE-2025-3633

IBM Cognos Analytics 11.2.0, 11.2.4, 12.0, and 12.1.0 and IBM Cognos Transformer 11.2.4, 12.0, and 12.1.0 are vulnerable to cross-site scripting (XSS…

Fix: 11.2.4 / 12.0.4+
Fix from $1,950 2026-05-27
Qradar Security Information And Event Manager HIGH 8.8
CVE-2024-56462

IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 002 could allow a privileged user to upload a malicious backup archive that could be restored and use…

Mitigation only
Fix from $1,950 2026-05-27
Operations Analytics Log Analysis CRITICAL 9.8
CVE-2024-40684

IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, and 1.3.8.0, 1.3.8.1, 1.3.8.…

Mitigation only
Fix from $2,300 2026-05-27
Security Directory Integrator MEDIUM 5.3
CVE-2024-28765

IBM SDI 7.2.0.0 through 7.2.0.14 and IBM Security Directory Integrator 10.0.0.0 through 10.0.0.2 could allow a remote attacker to obtain sensitive in…

Fix: 7.2.0.15 / 10.0.0.3+
Fix from $1,600 2026-05-27
Engineering Lifecycle Management HIGH 7.2
CVE-2026-4051

IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an attacker with administrative privileges to execute remote code due to exp…

Mitigation only
Fix from $1,950 2026-05-26