ibm

8,153 tracked vulnerabilities.

CVE-2025-36042 MEDIUM
IBM QRadar SIEM 7.5-7.5.0 - Authenticated Stored Cross-Site Scripting in Dashboard
Aug 22, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-33120 HIGH
IBM QRadar SIEM <7.5.0 UP13 - Privilege Escalation
Aug 22, 2025
CVSS 7.8
EPSS 0.00
CVE-2025-36114 MEDIUM
IBM QRadar SOAR Plugin App 1.0.0-5.6.0 - Path Traversal via URL Request
Aug 20, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-1142 MEDIUM
IBM Edge Application Manager 4.5 - Authenticated Server-Side Request Forgery
Aug 20, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-1139 MEDIUM
IBM Edge Application Manager 4.5 - Incorrect Permission Assignment for Critical Resource
Aug 20, 2025
CVSS 6.1
EPSS 0.00
CVE-2025-2988 LOW
IBM Sterling B2B Integrator & File Gateway <6.2.1 - Info Disclosure
Aug 19, 2025
CVSS 2.7
EPSS 0.00
CVE-2025-33008 MEDIUM
IBM Sterling B2B Integrator 6.2.1.0-File Gateway 6.2.1.0 - XSS
Aug 19, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-36120 HIGH
IBM Storage Virtualize 8.4-8.7 - Authenticated Privilege Escalation via SSH Session
Aug 18, 2025
CVSS 8.8
EPSS 0.00
CVE-2025-33100 MEDIUM
IBM Concert Software <1.2 - Info Disclosure
Aug 18, 2025
CVSS 6.2
EPSS 0.00
CVE-2025-33090 HIGH
IBM Concert 1.0.0-1.1.0 - Denial of Service via Inefficient Regular Expression
Aug 18, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-27909 MEDIUM
IBM Concert 1.0.0-1.1.0 - Permissive Cross-domain Security Policy with Untrusted Domains
Aug 18, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-1759 MEDIUM
IBM Concert Software <1.2 - Info Disclosure
Aug 18, 2025
CVSS 5.9
EPSS 0.00
CVE-2025-36088 MEDIUM
IBM TS4500 Library Firmware <=1.11.0.2-C00 Authenticated Stored XSS
Aug 15, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-36047 MEDIUM
IBM WebSphere Application Server Liberty 18.0.0.2-25.0.0.8 - Denial of Service via Crafted Request
Aug 14, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-33142 MEDIUM
IBM WebSphere App Server <9.0 - Info Disclosure
Aug 14, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-36000 MEDIUM
IBM WebSphere Application Server Liberty 17.0.0.3-25.0.0.8 - Stored Cross-Site Scripting
Aug 12, 2025
CVSS 4.4
EPSS 0.00
CVE-2025-36124 MEDIUM
IBM WebSphere Application Server Liberty <25.0.0.8 - Auth Bypass
Aug 12, 2025
CVSS 5.9
EPSS 0.00
CVE-2025-36119 HIGH
IBM i 7.3-7.6 - Authenticated Privilege Escalation via Web Session Hijacking in Digital Certificate Manager
Aug 08, 2025
CVSS 7.1
EPSS 0.00
CVE-2025-36023 MEDIUM
IBM Cloud Pak For Business Automation - IDOR
Aug 08, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-36020 MEDIUM
IBM Guardium Data Protection - Cleartext Transmission of Sensitive Credential Information
Aug 06, 2025
CVSS 5.9
EPSS 0.00
CVE-2025-3354 HIGH
IBM Tivoli Monitoring <6.3.0.7 - Buffer Overflow
Aug 06, 2025
CVSS 8.1
EPSS 0.00
CVE-2025-3320 HIGH
IBM Tivoli Monitoring <6.3.0.7 - Buffer Overflow
Aug 06, 2025
CVSS 8.1
EPSS 0.00
CVE-2025-33118 MEDIUM
IBM QRadar SIEM 7.5-7.5.0 Update Pack 12 - Authenticated Stored Cross-Site Scripting
Aug 01, 2025
CVSS 6.4
EPSS 0.00
CVE-2025-2824 HIGH
IBM Operational Decision Manager 8.11.0.1, 8.11.1.0, 8.12.0.1, 9.0.0.1, 9.5.0 - Open Redirect
Aug 01, 2025
CVSS 7.4
EPSS 0.00
CVE-2025-36040 MEDIUM
IBM Aspera Faspex 5.0.0-5.0.12.1 - Authenticated Insufficient Session Expiration
Jul 31, 2025
CVSS 6.5
EPSS 0.00