Skip to main content

Vendor archive

ibm CVEs

Beta · best-effort

8,230 CVEs tagged to vendor ibm584 Critical, 1,727 High, 5,176 Medium, 743 Low, 0 Unrated.

CVE-2025-2529

Published Oct 15, 2025

Applications using affected versions of Ehcache 3.x can experience degraded cache-write performance if the application using Ehcache utilizes keys sourced from (malicious) externa…

CVSS 2.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-1826

Published Oct 7, 2025

IBM Engineering Requirements Management DOORS Next (IBM Jazz Foundation 7.0.2 to 7.0.2 iFix034, 7.0.3 to 7.0.3 iFix016, and 7.1.0 to 7.1.0 iFix004) is vulnerable to stored cross-s…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-49886

Published Oct 6, 2025

IBM Standards Processing Engine 10.0.1.10 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe java deserialization. By sending specially cra…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-49883

Published Oct 1, 2025

IBM Transformation Extender Advanced 10.0.1 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accou…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-49881

Published Oct 1, 2025

IBM Transformation Extender Advanced 10.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-36262

Published Sep 30, 2025

IBM Planning Analytics Local 2.0.0 through 2.0.106 and 2.1.0 through 2.1.13 could allow a malicious privileged user to bypass the UI to gain unauthorized access to sensitive inf…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-36132

Published Sep 30, 2025

IBM Planning Analytics Local 2.0.0 through 2.0.106 and 2.1.0 through 2.1.13 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitra…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-36245

Published Sep 29, 2025

IBM InfoSphere 11.7.0.0 through 11.7.1.6 Information Server could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-36099

Published Sep 29, 2025

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to a denial of service, caused by sending a specially-crafted request. A privileged user could exploit this vulnerabilit…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-36352

Published Sep 29, 2025

IBM License Metric Tool 9.2.0 through 9.2.40 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in th…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 401-425 of 8,230 CVEsPage 17 of 330