ibm

8,153 tracked vulnerabilities.

CVE-2025-36102 LOW
IBM Controller <11.1.1 - Auth Bypass
Dec 08, 2025
CVSS 2.7
EPSS 0.00
CVE-2025-36017 MEDIUM
IBM Controller <11.1.1 - Info Disclosure
Dec 08, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-36015 MEDIUM
IBM Cognos Controller 11.0.0-11.0.1 FP6 & 11.1.0-11.1.1 Authenticated DoS via Input Validation
Dec 08, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-33111 MEDIUM
IBM Controller <11.1.1 - Info Disclosure
Dec 08, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-12832 MEDIUM
IBM InfoSphere Information Server <11.7.1.6 - SSRF
Dec 08, 2025
CVSS 4.6
EPSS 0.00
CVE-2025-12635 MEDIUM
IBM WebSphere Application Server <9.0 - XSS
Dec 08, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-36134 LOW
IBM Sterling B2B Integrator & File Gateway <6.2.1.1 - Info Disclosure
Nov 25, 2025
CVSS 3.7
EPSS 0.00
CVE-2025-36150 MEDIUM
IBM Concert 1.0.0-2.0.0 - Use of a Broken or Risky Cryptographic Algorithm
Nov 24, 2025
CVSS 5.9
EPSS 0.00
CVE-2025-36112 MEDIUM
IBM Sterling B2B Integrator & File Gateway <6.2.1.1 - Info Disclosure
Nov 24, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-36149 MEDIUM
IBM Concert 1.0.0-2.0.0 - Clickjacking
Nov 21, 2025
CVSS 6.3
EPSS 0.00
CVE-2025-36072 HIGH
IBM Webmethods Integration - Insecure Deserialization
Nov 20, 2025
CVSS 8.8
EPSS 0.01
CVE-2025-36160 MEDIUM
IBM Concert <2.0.0 - Info Disclosure
Nov 20, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-36159 MEDIUM
IBM Concert <2.0.0 - Info Disclosure
Nov 20, 2025
CVSS 6.2
EPSS 0.00
CVE-2025-36158 MEDIUM
IBM Concert <2.0.0 - Info Disclosure
Nov 20, 2025
CVSS 5.1
EPSS 0.00
CVE-2025-36153 MEDIUM
IBM Concert 1.0.0-2.0.0 - Unauthenticated Stored Cross-Site Scripting
Nov 20, 2025
CVSS 6.1
EPSS 0.00
CVE-2025-36161 MEDIUM
IBM Concert 1.0.0-2.0.0 - Sensitive Information Exposure via Missing HSTS
Nov 20, 2025
CVSS 5.9
EPSS 0.00
CVE-2025-36371 MEDIUM
IBM i 7.2-7.6 - Unauthorized Information Disclosure in Database Plan Cache
Nov 19, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-36118 HIGH
IBM Storage Virtualize <9.1 - Info Disclosure
Nov 17, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-36357 HIGH
IBM Planning Analytics Local 2.1.0-2.1.14 - Authenticated Absolute Path Traversal
Nov 17, 2025
CVSS 8.0
EPSS 0.00
CVE-2025-36299 MEDIUM
IBM Planning Analytics Local <2.1.14 - Info Disclosure
Nov 17, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-36251 CRITICAL
IBM AIX 7.2,7.3 & VIOS 3.1,4.1 - RCE
Nov 13, 2025
CVSS 9.6
EPSS 0.00
CVE-2025-36250 CRITICAL
IBM AIX 7.2,7.3 & VIOS 3.1,4.1 - Command Injection
Nov 13, 2025
CVSS 10.0
EPSS 0.00
CVE-2025-36236 HIGH
IBM AIX 7.2-7.3 and VIOS 3.1-4.1 - Path Traversal and Arbitrary File Write via NIM Server URL Request
Nov 13, 2025
CVSS 8.2
EPSS 0.00
CVE-2025-36096 CRITICAL
IBM AIX 7.2-7.3 and VIOS 3.1-4.1 - Insufficiently Protected Credentials in NIM Private Key Storage
Nov 13, 2025
CVSS 9.0
EPSS 0.00
CVE-2025-33119 MEDIUM
IBM QRadar SIEM <7.5.0 UP14 - Info Disclosure
Nov 12, 2025
CVSS 6.5
EPSS 0.00