ibm
8,153 tracked vulnerabilities.
CVE-2025-36102
LOW
IBM Controller <11.1.1 - Auth Bypass
Dec 08, 2025
CVSS 2.7
EPSS 0.00
CVE-2025-36017
MEDIUM
IBM Controller <11.1.1 - Info Disclosure
Dec 08, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-36015
MEDIUM
IBM Cognos Controller 11.0.0-11.0.1 FP6 & 11.1.0-11.1.1 Authenticated DoS via Input Validation
Dec 08, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-33111
MEDIUM
IBM Controller <11.1.1 - Info Disclosure
Dec 08, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-12832
MEDIUM
IBM InfoSphere Information Server <11.7.1.6 - SSRF
Dec 08, 2025
CVSS 4.6
EPSS 0.00
CVE-2025-12635
MEDIUM
IBM WebSphere Application Server <9.0 - XSS
Dec 08, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-36134
LOW
IBM Sterling B2B Integrator & File Gateway <6.2.1.1 - Info Disclosure
Nov 25, 2025
CVSS 3.7
EPSS 0.00
CVE-2025-36150
MEDIUM
IBM Concert 1.0.0-2.0.0 - Use of a Broken or Risky Cryptographic Algorithm
Nov 24, 2025
CVSS 5.9
EPSS 0.00
CVE-2025-36112
MEDIUM
IBM Sterling B2B Integrator & File Gateway <6.2.1.1 - Info Disclosure
Nov 24, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-36149
MEDIUM
IBM Concert 1.0.0-2.0.0 - Clickjacking
Nov 21, 2025
CVSS 6.3
EPSS 0.00
CVE-2025-36072
HIGH
IBM Webmethods Integration - Insecure Deserialization
Nov 20, 2025
CVSS 8.8
EPSS 0.01
CVE-2025-36160
MEDIUM
IBM Concert <2.0.0 - Info Disclosure
Nov 20, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-36159
MEDIUM
IBM Concert <2.0.0 - Info Disclosure
Nov 20, 2025
CVSS 6.2
EPSS 0.00
CVE-2025-36158
MEDIUM
IBM Concert <2.0.0 - Info Disclosure
Nov 20, 2025
CVSS 5.1
EPSS 0.00
CVE-2025-36153
MEDIUM
IBM Concert 1.0.0-2.0.0 - Unauthenticated Stored Cross-Site Scripting
Nov 20, 2025
CVSS 6.1
EPSS 0.00
CVE-2025-36161
MEDIUM
IBM Concert 1.0.0-2.0.0 - Sensitive Information Exposure via Missing HSTS
Nov 20, 2025
CVSS 5.9
EPSS 0.00
CVE-2025-36371
MEDIUM
IBM i 7.2-7.6 - Unauthorized Information Disclosure in Database Plan Cache
Nov 19, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-36118
HIGH
IBM Storage Virtualize <9.1 - Info Disclosure
Nov 17, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-36357
HIGH
IBM Planning Analytics Local 2.1.0-2.1.14 - Authenticated Absolute Path Traversal
Nov 17, 2025
CVSS 8.0
EPSS 0.00
CVE-2025-36299
MEDIUM
IBM Planning Analytics Local <2.1.14 - Info Disclosure
Nov 17, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-36251
CRITICAL
IBM AIX 7.2,7.3 & VIOS 3.1,4.1 - RCE
Nov 13, 2025
CVSS 9.6
EPSS 0.00
CVE-2025-36250
CRITICAL
IBM AIX 7.2,7.3 & VIOS 3.1,4.1 - Command Injection
Nov 13, 2025
CVSS 10.0
EPSS 0.00
CVE-2025-36236
HIGH
IBM AIX 7.2-7.3 and VIOS 3.1-4.1 - Path Traversal and Arbitrary File Write via NIM Server URL Request
Nov 13, 2025
CVSS 8.2
EPSS 0.00
CVE-2025-36096
CRITICAL
IBM AIX 7.2-7.3 and VIOS 3.1-4.1 - Insufficiently Protected Credentials in NIM Private Key Storage
Nov 13, 2025
CVSS 9.0
EPSS 0.00
CVE-2025-33119
MEDIUM
IBM QRadar SIEM <7.5.0 UP14 - Info Disclosure
Nov 12, 2025
CVSS 6.5
EPSS 0.00
Products
websphere_application_server 444
aix 393
db2 327
rational_quality_manager 202
sterling_b2b_integrator 195
infosphere_information_server 188
qradar_security_information_and_event_manager 187
maximo_asset_management 182
rational_doors_next_generation 153
rational_team_concert 142
rational_collaborative_lifecycle_management 141
rational_engineering_lifecycle_manager 141
websphere_portal 126
security_guardium 112
cognos_analytics 102
sterling_file_gateway 93
rational_rhapsody_design_manager 90
security_verify_access 90
websphere_mq 89
business_process_manager 88
lotus_domino 86
vios 85
rational_software_architect_design_manager 81
api_connect 79
lotus_notes 71
security_key_lifecycle_manager 70
db2_universal_database 66
concert 65
smartcloud_control_desk 65
urbancode_deploy 63
Quick Filters