Skip to main content

Vendor archive

ibm CVEs

Beta · best-effort

8,230 CVEs tagged to vendor ibm584 Critical, 1,727 High, 5,176 Medium, 743 Low, 0 Unrated.

CVE-2025-36251

Published Nov 13, 2025

IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 nimsh service SSL/TLS implementations could allow a remote attacker to execute arbitrary commands due to improper process controls.…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-36250

Published Nov 13, 2025

IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a remote attacker to execute arbitrary commands due to impro…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-36236

Published Nov 13, 2025

IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a remote attacker to traverse directories on the system. An…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-36096

Published Nov 13, 2025

IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 stores NIM private keys used in NIM environments in an insecure way which is susceptible to unauthorized access by an attacker using…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-36223

Published Nov 12, 2025

IBM OpenPages 9.0 and 9.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attac…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-27368

Published Nov 12, 2025

IBM OpenPages 9.0 and 9.1 is vulnerable to information disclosure of sensitive information due to a weaker than expected security for certain REST end points used by the user inte…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-36186

Published Nov 7, 2025

IBM Db2 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) under specific configurations could allow a local user to execute malicious code that escal…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2025-36185

Published Nov 7, 2025

IBM Db2 12.1.0 through 12.1.2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a local user to cause a denial of service due to improper neutralization of spe…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-36136

Published Nov 7, 2025

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local user to cause a denial of service due to the…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-36131

Published Nov 7, 2025

IBM Db2 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) clpplus command exposes user credential…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-36008

Published Nov 7, 2025

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service d…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-36006

Published Nov 7, 2025

IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-33012

Published Nov 7, 2025

IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux could allow an authenticated user to regain access after accoun…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-2534

Published Nov 7, 2025

IBM Db2 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of service as…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-47118

Published Nov 7, 2025

IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable t…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-33110

Published Nov 6, 2025

IBM OpenPages 9.1, and 9.0 with Watson is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's We…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-36172

Published Nov 3, 2025

IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 001, 24.0.1 through 24.0.1 Interim Fix 004, 24.0.0 through 24.0.0 Interim Fix 006, and earlier unsupported…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-12531

Published Nov 3, 2025

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploi…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-36093

Published Nov 3, 2025

IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an attacker to access unauthorized content or perform unauthorized actions using man in the middle tec…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 351-375 of 8,230 CVEsPage 15 of 330