Skip to main content

Vendor archive

ibm CVEs

Beta · best-effort

8,236 CVEs tagged to vendor ibm585 Critical, 1,729 High, 5,179 Medium, 743 Low, 0 Unrated.

CVE-2025-1494

Published Aug 26, 2025

IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a re…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-36174

Published Aug 24, 2025

IBM Integrated Analytics System 1.0.0.0 through 1.0.30.0 could allow an authenticated user to upload a file with dangerous types that could be executed by another user if opened.

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2025-36157

Published Aug 24, 2025

IBM Jazz Foundation 7.0.2 to 7.0.2 iFix035, 7.0.3 to 7.0.3 iFix018, and 7.1.0 to 7.1.0 iFix004 could allow an unauthenticated remote attacker to update server property files that…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-36114

Published Aug 20, 2025

IBM QRadar SOAR Plugin App 1.0.0 through 5.6.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containi…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-1142

Published Aug 20, 2025

IBM Edge Application Manager 4.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, poten…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-1139

Published Aug 20, 2025

IBM Edge Application Manager 4.5 could allow a local user to read or modify resources that they should not have authorization to access due to incorrect permission assignment.

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-36120

Published Aug 18, 2025

IBM Storage Virtualize 8.4, 8.5, 8.6, and 8.7 could allow an authenticated user to escalate their privileges in an SSH session due to incorrect authorization checks to access reso…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-33100

Published Aug 18, 2025

IBM Concert Software 1.0.0 through 1.1.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound com…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-33090

Published Aug 18, 2025

IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to cause a denial of service using a specially crafted regular expression that would cause excessive resourc…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-27909

Published Aug 18, 2025

IBM Concert Software 1.0.0 through 1.1.0 uses cross-origin resource sharing (CORS) which could allow an attacker to carry out privileged actions as the domain name is not being li…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-1759

Published Aug 18, 2025

IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-49827

Published Aug 18, 2025

IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to excessive data exposure, allowing attackers to access sensitive information without proper filtering.

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-36000

Published Aug 12, 2025

IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.8 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary J…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-36124

Published Aug 12, 2025

IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.8 could allow a remote attacker to bypass security restrictions caused by a failure to honor JMS messaging configu…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-36119

Published Aug 8, 2025

IBM i 7.3, 7.4, 7.5, and 7.6 is affected by an authenticated user obtaining elevated privileges with IBM Digital Certificate Manager for i (DCM) due to a web session hijacking vul…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-36023

Published Aug 8, 2025

IBM Cloud Pak for Business Automation 24.0.0 through 24.0.0 IF005 and 24.0.1 through 24.0.1 IF002 could allow an authenticated user to view sensitive user and system information d…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-56339

Published Aug 7, 2025

IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7 could allow a remote attacker to bypass security restrictions caused by a f…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort
Showing 476-500 of 8,236 CVEsPage 20 of 330