ibm

8,153 tracked vulnerabilities.

CVE-2025-1722 MEDIUM
IBM Concert <2.1.0 - Info Disclosure
Jan 20, 2026
CVSS 5.9
EPSS 0.00
CVE-2025-1719 MEDIUM
IBM Concert <2.1.0 - Info Disclosure
Jan 20, 2026
CVSS 5.9
EPSS 0.00
CVE-2025-14115 HIGH
IBM Sterling Connect:Direct for UNIX Container - Info Disclosure
Jan 20, 2026
CVSS 8.4
EPSS 0.00
CVE-2025-13925 MEDIUM
IBM Aspera Console 3.4.7 - Sensitive Information Exposure in Log Files
Jan 20, 2026
CVSS 4.9
EPSS 0.00
CVE-2025-12985 HIGH
IBM Licensing Operator - Privilege Escalation
Jan 20, 2026
CVSS 8.4
EPSS 0.00
CVE-2025-64645 HIGH
IBM Concert 1.0.0-2.1.0 - Privilege Escalation via Symbolic Link Race Condition
Dec 26, 2025
CVSS 7.7
EPSS 0.00
CVE-2025-36230 MEDIUM
IBM Aspera Faspex 5.0.0-5.0.14.1 - HTML Injection
Dec 26, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-36229 LOW
IBM Aspera Faspex <5.0.14.1 - Info Disclosure
Dec 26, 2025
CVSS 3.1
EPSS 0.00
CVE-2025-36228 LOW
IBM Aspera Faspex <5.0.14.1 - Privilege Escalation
Dec 26, 2025
CVSS 3.8
EPSS 0.00
CVE-2025-36192 MEDIUM
IBM DS8A00 and DS8900F - Missing Authorization in Safeguarded Copy / GDPS Logical Corruption Protection
Dec 26, 2025
CVSS 6.7
EPSS 0.00
CVE-2025-14687 MEDIUM
IBM Db2 Intelligence Center <1.1.3 - Privilege Escalation
Dec 26, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-13915 CRITICAL
IBM API Connect <10.0.8.5, 10.0.11.0 - Auth Bypass
Dec 26, 2025
CVSS 9.8
EPSS 0.00
CVE-2025-1721 MEDIUM
IBM Concert <2.1.0 - Info Disclosure
Dec 26, 2025
CVSS 5.9
EPSS 0.00
CVE-2025-12771 HIGH
IBM Concert <2.1.0 - Buffer Overflow
Dec 26, 2025
CVSS 7.8
EPSS 0.00
CVE-2025-36154 MEDIUM
IBM Concert <2.1.0 - Info Disclosure
Dec 24, 2025
CVSS 6.2
EPSS 0.00
CVE-2025-36360 MEDIUM
IBM UrbanCode/DevOps Deploy Insufficient Session Expiration via Race Condition
Dec 15, 2025
CVSS 5.0
EPSS 0.00
CVE-2025-14148 MEDIUM
IBM UCD - IBM DevOps Deploy <8.1.2.3 - Info Disclosure
Dec 15, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-13489 MEDIUM
IBM DevOps Deploy 8.1.0.0-8.1.2.3 - Cleartext Transmission of Sensitive Information
Dec 15, 2025
CVSS 5.9
EPSS 0.00
CVE-2025-13481 HIGH
IBM Aspera Orchestrator 4.0.0-4.1.0 - Authenticated OS Command Injection
Dec 11, 2025
CVSS 8.8
EPSS 0.00
CVE-2025-13214 HIGH
IBM Aspera Orchestrator 4.0.0-4.1.0 - SQL Injection
Dec 11, 2025
CVSS 7.6
EPSS 0.00
CVE-2025-13211 MEDIUM
IBM Aspera Orchestrator 4.0.0-4.1.0 - Authenticated Denial of Service in Email Service
Dec 11, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-13148 HIGH
IBM Aspera Orchestrator <4.1.0 - Privilege Escalation
Dec 11, 2025
CVSS 8.1
EPSS 0.00
CVE-2025-36437 MEDIUM
IBM Planning Analytics Local 2.1.0-2.1.15 - Sensitive Information Disclosure in Error Messages
Dec 09, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-36140 MEDIUM
IBM watsonx.data 2.2.0-2.2.1 - Authenticated Denial of Service via Ingestion Pods
Dec 08, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-64650 MEDIUM
IBM Storage Defender Resiliency Service 2.0.0-2.0.18 - Sensitive Credential Disclosure in Log Files
Dec 08, 2025
CVSS 6.5
EPSS 0.00