Skip to main content

Vendor archive

ibm CVEs

Beta · best-effort

8,230 CVEs tagged to vendor ibm584 Critical, 1,727 High, 5,176 Medium, 743 Low, 0 Unrated.

CVE-2025-36092

Published Nov 3, 2025

IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an authenticated user to cause a denial of service due to the improper validation of input length.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-36091

Published Nov 3, 2025

IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an authenticated user to cause dashboards to become inaccessible to legitimate users due to invalid ow…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-36367

Published Nov 1, 2025

IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 is vulnerable to privilege escalation caused by an invalid IBM i SQL services authorization check. A malicious actor can use the elevated privile…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-36249

Published Oct 31, 2025

IBM Jazz for Service Management 1.1.3.0 through 1.1.3.25 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie valu…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-33003

Published Oct 31, 2025

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow a non-root user to gain higher privileges/capabilities within the scope of a container due to execution wit…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-3356

Published Oct 30, 2025

IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL r…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2025-3355

Published Oct 30, 2025

IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL r…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-36137

Published Oct 30, 2025

IBM Sterling Connect Direct for Unix 6.2.0.7 through 6.2.0.9 iFix004, 6.4.0.0 through 6.4.0.2 iFix001, and 6.3.0.2 through 6.3.0.5 iFix002 incorrectly assigns permissions for main…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-62230

Published Oct 30, 2025

A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detachi…

CVSS 7.3 · High

CVE-2025-62231

Published Oct 30, 2025

A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCompatMap() function can cause an unsigned short overflow. If…

CVSS 7.3 · High

CVE-2025-36386

Published Oct 28, 2025

IBM Maximo Application Suite 9.0.0 through 9.0.15 and 9.1.0 through 9.1.4 could allow a remote attacker to bypass authentication mechanisms and gain unauthorized access to the app…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-36085

Published Oct 28, 2025

IBM Concert 1.0.0 through 2.0.0 Software is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the syste…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-36083

Published Oct 28, 2025

IBM Concert Software 1.0.0 through 2.0.0 could allow a local user to obtain sensitive information from buffers due to improper clearing of heap memory before release.

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-36121

Published Oct 27, 2025

IBM OpenPages 9.1 and 9.0 is vulnerable to HTML injection. A remotely authenticated attacker could inject malicious HTML code, which when viewed, would be executed in the victim's…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-36361

Published Oct 24, 2025

IBM App Connect Enterprise 13.0.1.0 through 13.0.4.2, and 12.0.1.0 through 12.0.12.17 could allow an authenticated user to perform unauthorized actions on customer defined resourc…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 376-400 of 8,230 CVEsPage 16 of 330