ibm
8,153 tracked vulnerabilities.
CVE-2025-1826
MEDIUM
IBM Engineering Requirements Management DOORS Next 7.0.2-7.1.0 - XSS
Oct 07, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-36356
CRITICAL
IBM Security Verify Access <11.0.1.0 - Privilege Escalation
Oct 06, 2025
CVSS 9.3
EPSS 0.00
CVE-2025-36355
HIGH
IBM Security Verify Access <11.0.2 - RCE
Oct 06, 2025
CVSS 8.5
EPSS 0.00
CVE-2025-36354
HIGH
IBM Security Verify Access 10.0.0.0-10.0.9.0 and 11.0.0.0-11.0.1.0 - Unauthenticated OS Command Injection
Oct 06, 2025
CVSS 7.3
EPSS 0.00
CVE-2025-36262
MEDIUM
IBM Planning Analytics Local <2.0.106, <2.1.13 - Info Disclosure
Sep 30, 2025
CVSS 4.9
EPSS 0.00
CVE-2025-36132
MEDIUM
IBM Planning Analytics Local 2.0.0-2.0.106 and 2.1.0-2.1.13 - Authenticated Stored Cross-Site Scripting
Sep 30, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-36245
HIGH
IBM InfoSphere Information Server 11.7.0.0-11.7.1.6 - Authenticated OS Command Injection
Sep 29, 2025
CVSS 8.8
EPSS 0.00
CVE-2025-36099
MEDIUM
IBM WebSphere Application Server 8.5 and 9.0 - Denial of Service via Crafted Request
Sep 29, 2025
CVSS 4.9
EPSS 0.00
CVE-2025-36352
MEDIUM
IBM License Metric Tool 9.2.0-9.2.40 - Authenticated Stored Cross-Site Scripting
Sep 29, 2025
CVSS 6.4
EPSS 0.00
CVE-2025-36351
MEDIUM
IBM License Metric Tool 9.2.0-9.2.40 - Authenticated Access Control Bypass in REST API
Sep 29, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-36239
MEDIUM
IBM Storage TS4500 Library 1.11.0.0 and 2.11.0.0 - Unauthenticated Cross-Site Scripting
Sep 27, 2025
CVSS 6.1
EPSS 0.00
CVE-2025-36144
LOW
IBM watsonx.data 2.2 - Sensitive Information Exposure in Log Files
Sep 27, 2025
CVSS 3.3
EPSS 0.00
CVE-2025-36326
LOW
IBM Cognos Controller <11.0.1 - Info Disclosure
Sep 26, 2025
CVSS 3.7
EPSS 0.00
CVE-2025-36274
HIGH
IBM Aspera HTTP Gateway 2.0.0-2.3.1 - Unauthenticated Cleartext Transmission of Sensitive Information
Sep 26, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-33116
MEDIUM
IBM Watson Studio 4.0-5.2.0 - Authenticated Stored Cross-Site Scripting
Sep 25, 2025
CVSS 4.4
EPSS 0.00
CVE-2025-36064
MEDIUM
IBM Sterling Connect:Express 3.1.0.0-3.1.0.22 - Unauthenticated Brute Force via Inadequate Account Lockout
Sep 22, 2025
CVSS 5.9
EPSS 0.00
CVE-2025-36202
HIGH
IBM webMethods Integration 10.15 and 11.1 - Authenticated Command Execution via Format String Vulnerability
Sep 22, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-36037
MEDIUM
IBM webMethods Integration 10.15 and 11.1 - Authenticated Server-Side Request Forgery
Sep 22, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-36248
MEDIUM
IBM Copy Services Manager < 6.3.14 - Unauthenticated Cross-Site Scripting
Sep 19, 2025
CVSS 6.1
EPSS 0.00
CVE-2025-36146
MEDIUM
IBM watsonx.data 2.2 - Authenticated Sensitive Information Exposure
Sep 18, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-36143
MEDIUM
IBM watsonx.data 2.2 - Authenticated OS Command Injection
Sep 18, 2025
CVSS 4.7
EPSS 0.00
CVE-2025-36139
MEDIUM
IBM watsonx.data 2.2 - Stored Cross-Site Scripting
Sep 18, 2025
CVSS 5.5
EPSS 0.00
CVE-2025-36244
HIGH
IBM AIX <7.2-7.3, VIOS <4.1 - Privilege Escalation
Sep 16, 2025
CVSS 7.4
EPSS 0.00
CVE-2025-36082
MEDIUM
IBM OpenPages <9.1 - Info Disclosure
Sep 15, 2025
CVSS 4.0
EPSS 0.00
CVE-2025-36035
MEDIUM
IBM PowerVM Hypervisor FW950.00-FW950.E0, FW1050.00-FW1050.50, FW1060.00-FW1060.40 DoS
Sep 14, 2025
CVSS 6.7
EPSS 0.00
Products
websphere_application_server 444
aix 393
db2 327
rational_quality_manager 202
sterling_b2b_integrator 195
infosphere_information_server 188
qradar_security_information_and_event_manager 187
maximo_asset_management 182
rational_doors_next_generation 153
rational_team_concert 142
rational_collaborative_lifecycle_management 141
rational_engineering_lifecycle_manager 141
websphere_portal 126
security_guardium 112
cognos_analytics 102
sterling_file_gateway 93
rational_rhapsody_design_manager 90
security_verify_access 90
websphere_mq 89
business_process_manager 88
lotus_domino 86
vios 85
rational_software_architect_design_manager 81
api_connect 79
lotus_notes 71
security_key_lifecycle_manager 70
db2_universal_database 66
concert 65
smartcloud_control_desk 65
urbancode_deploy 63
Quick Filters