ibm
8,153 tracked vulnerabilities.
CVE-2024-49344
MEDIUM
IBM OpenPages with Watson <9.0 - Info Disclosure
Feb 20, 2025
CVSS 4.3
EPSS 0.00
CVE-2024-49337
MEDIUM
IBM OpenPages with Watson 8.3-8.3.0.2 - Authenticated HTML Injection in Workflow Email Notifications
Feb 20, 2025
CVSS 5.4
EPSS 0.00
CVE-2024-49782
MEDIUM
IBM OpenPages with Watson <9.0 - SSRF
Feb 20, 2025
CVSS 6.8
EPSS 0.00
CVE-2024-49780
MEDIUM
IBM OpenPages <9.0 - Path Traversal
Feb 20, 2025
CVSS 5.3
EPSS 0.00
CVE-2024-49355
MEDIUM
IBM OpenPages with Watson <9.0 - Info Disclosure
Feb 20, 2025
CVSS 5.3
EPSS 0.00
CVE-2024-43196
MEDIUM
IBM OpenPages with Watson <9.0 - Privilege Escalation
Feb 20, 2025
CVSS 4.3
EPSS 0.00
CVE-2024-45084
HIGH
IBM Cognos Controller <11.0.2 - Command Injection
Feb 19, 2025
CVSS 8.0
EPSS 0.00
CVE-2024-45081
MEDIUM
IBM Cognos Controller 11.0.0-11.0.1 FP3 & 11.1.0 - Privilege Escala...
Feb 19, 2025
CVSS 6.5
EPSS 0.00
CVE-2024-28780
MEDIUM
IBM Cognos Controller 11.0.0-11.0.1 FP3 and IBM Controller 11.1.0 - Use of a Broken or Risky Cryptographic Algorithm
Feb 19, 2025
CVSS 5.9
EPSS 0.00
CVE-2024-28777
HIGH
IBM Cognos Controller 11.0.0-11.0.1 FP3 and IBM Controller 11.1.0 - Deserialization of Untrusted Data
Feb 19, 2025
CVSS 8.8
EPSS 0.00
CVE-2024-28776
MEDIUM
IBM Cognos Controller 11.0.0-11.0.1 FP3 and IBM Controller 11.1.0 - Cross-Site Scripting
Feb 19, 2025
CVSS 5.4
EPSS 0.00
CVE-2024-52902
HIGH
IBM Cognos Controller 11.0.0-11.0.1 FP3 and IBM Controller 11.1.0 - Use of Hard-coded Credentials
Feb 19, 2025
CVSS 8.8
EPSS 0.00
CVE-2024-56463
MEDIUM
IBM QRadar SIEM 7.5 - Stored Cross-Site Scripting via Web UI
Feb 14, 2025
CVSS 4.8
EPSS 0.00
CVE-2024-56477
MEDIUM
IBM Power Hardware Management Console V10.3.1050.0 - Path Traversal
Feb 14, 2025
CVSS 6.5
EPSS 0.01
CVE-2024-52895
MEDIUM
IBM i 7.4-7.5 - Database Access Denial of Service via Capabilities Restriction Bypass
Feb 14, 2025
CVSS 6.5
EPSS 0.00
CVE-2024-55904
HIGH
IBM DevOps Deploy 8.0.0.0-8.0.1.4 and UrbanCode Deploy 7.0.0.0-7.0.5.25 - Authenticated OS Command Injection
Feb 14, 2025
CVSS 7.2
EPSS 0.01
CVE-2024-54176
MEDIUM
IBM DevOps Deploy <8.0.1.4, UCD <7.3.2 - Info Disclosure
Feb 08, 2025
CVSS 4.3
EPSS 0.00
CVE-2024-56467
LOW
IBM EntireX 11.1 - Sensitive Information Exposure via Detailed Technical Error Message
Feb 06, 2025
CVSS 3.3
EPSS 0.00
CVE-2024-54171
HIGH
IBM EntireX 11.1 - Authenticated XML External Entity Injection
Feb 06, 2025
CVSS 7.1
EPSS 0.00
CVE-2024-52892
MEDIUM
IBM Jazz for Service Management 1.1.3-1.1.3.23 - Unauthenticated Stored Cross-Site Scripting
Feb 06, 2025
CVSS 6.1
EPSS 0.01
CVE-2024-51450
CRITICAL
IBM Security Verify Directory 10.0.0-10.0.3 - Authenticated OS Command Injection
Feb 06, 2025
CVSS 9.1
EPSS 0.01
CVE-2024-49814
HIGH
IBM Security Verify Access Appliance <10.0.4 - Privilege Escalation
Feb 06, 2025
CVSS 7.8
EPSS 0.00
CVE-2024-49800
MEDIUM
IBM ApplinX 11.1 - Authenticated Cleartext Storage of Sensitive Information in Memory
Feb 06, 2025
CVSS 4.3
EPSS 0.00
CVE-2024-49798
MEDIUM
IBM ApplinX 11.1 - Sensitive Information Exposure via Detailed Error Messages
Feb 06, 2025
CVSS 4.3
EPSS 0.00
CVE-2024-49797
MEDIUM
IBM ApplinX 11.1 - Sensitive Information Exposure via Missing HTTP Strict Transport Security
Feb 06, 2025
CVSS 5.9
EPSS 0.00
Products
websphere_application_server 444
aix 393
db2 327
rational_quality_manager 202
sterling_b2b_integrator 195
infosphere_information_server 188
qradar_security_information_and_event_manager 187
maximo_asset_management 182
rational_doors_next_generation 153
rational_team_concert 142
rational_collaborative_lifecycle_management 141
rational_engineering_lifecycle_manager 141
websphere_portal 126
security_guardium 112
cognos_analytics 102
sterling_file_gateway 93
rational_rhapsody_design_manager 90
security_verify_access 90
websphere_mq 89
business_process_manager 88
lotus_domino 86
vios 85
rational_software_architect_design_manager 81
api_connect 79
lotus_notes 71
security_key_lifecycle_manager 70
db2_universal_database 66
concert 65
smartcloud_control_desk 65
urbancode_deploy 63
Quick Filters