Ibm Security Vulnerabilities (CVEs)

Track 891 security vulnerabilities affecting Ibm products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.

84 Critical
366 High
428 Medium
13 Low
🔔 Get Alerts for Ibm
CVE-2022-33954 4.6

This vulnerability in IBM Robotic Process Automation allows users with physical access to systems to obtain sensitive information due to insufficient ...

Dec 19, 2024
CVE-2021-20553 5.4

This CVE describes a cross-site scripting (XSS) vulnerability in IBM Sterling B2B Integrator that allows attackers to inject malicious JavaScript into...

Dec 19, 2024
CVE-2024-51470 6.5

This vulnerability in IBM MQ allows authenticated users to cause denial-of-service by sending messages with improperly set values. It affects multiple...

Dec 18, 2024
CVE-2024-41752 5.4

IBM Cognos Analytics is vulnerable to HTML injection where attackers can inject malicious HTML that executes in victims' browsers. This affects IBM Co...

Dec 18, 2024
CVE-2024-47119 5.9

IBM Storage Defender - Resiliency Service versions 2.0.0 through 2.0.9 fail to properly validate SSL/TLS certificates, allowing attackers to perform m...

Dec 18, 2024
CVE-2024-52361 5.7

IBM Storage Defender - Resiliency Service versions 2.0.0 through 2.0.9 store user credentials in plain text within pod files. This allows authenticate...

Dec 18, 2024
CVE-2023-50956 4.4

IBM Storage Defender - Resiliency Service versions 2.0.0 through 2.0.9 store secret keys containing user credentials in clear text. This allows privil...

Dec 18, 2024
CVE-2024-47104 6.8

This vulnerability allows authenticated IBM i users with view authority to modify security attributes of underlying physical files without proper obje...

Dec 18, 2024
CVE-2024-49818 4.3

IBM Security Guardium Key Lifecycle Manager versions 4.1 through 4.2.1 expose detailed technical error messages to remote attackers, potentially revea...

Dec 17, 2024
CVE-2024-49816 4.9

IBM Security Guardium Key Lifecycle Manager versions 4.1 through 4.2.1 store sensitive information in log files that could be read by local privileged...

Dec 17, 2024
CVE-2024-31891 7.8

This CVE describes a local privilege escalation vulnerability in IBM Storage Scale GUI where an authenticated attacker with command line access to the...

Dec 14, 2024
CVE-2024-52901 6.5

IBM InfoSphere Information Server 11.7 contains an improper input validation vulnerability in its GUI component. Authenticated users can cause the GUI...

Dec 12, 2024
CVE-2024-35117 4.4

IBM OpenPages with Watson 9.0 may write sensitive information in clear text to system tracing log files under specific configurations. This could allo...

Dec 11, 2024
CVE-2024-47107 6.4

IBM QRadar SIEM 7.5 has a stored cross-site scripting (XSS) vulnerability that allows authenticated users to inject malicious JavaScript into the web ...

Dec 7, 2024
CVE-2024-47115 7.8

This CVE describes a local privilege escalation vulnerability in IBM AIX and VIOS systems where improper input sanitization allows a local user to exe...

Dec 7, 2024
CVE-2024-51465 8.8

This vulnerability allows remote authenticated attackers to execute arbitrary commands on IBM App Connect Enterprise Certified Container systems by se...

Dec 4, 2024
CVE-2024-41776 6.5

IBM Cognos Controller versions 11.0.0 and 11.0.1 contain a cross-site request forgery (CSRF) vulnerability that allows attackers to trick authenticate...

Dec 3, 2024
CVE-2024-41777 7.5

IBM Cognos Controller versions 11.0.0 and 11.0.1 contain hard-coded credentials that could be used for authentication, communication, or data encrypti...

Dec 3, 2024
CVE-2024-45676 4.3

This vulnerability in IBM Cognos Controller allows authenticated users to upload insecure files due to insufficient file type validation. Attackers co...

Dec 3, 2024
CVE-2024-25020 5.5

IBM Cognos Controller versions 11.0.0 and 11.0.1 allow unrestricted file uploads in the Journal entry page, enabling attackers to upload malicious exe...

Dec 3, 2024
CVE-2024-40691 8.0

This vulnerability in IBM Cognos Controller allows attackers to upload malicious executable files through the web interface due to insufficient file v...

Dec 3, 2024
CVE-2024-25035 5.3

IBM Cognos Controller versions 11.0.0 and 11.0.1 expose server details through an information disclosure vulnerability. This allows attackers to gathe...

Dec 3, 2024
CVE-2021-29892 5.9

CVE-2021-29892 is an information disclosure vulnerability in IBM Cognos Controller where HTTP Strict Transport Security (HSTS) is not properly enabled...

Dec 3, 2024
CVE-2024-49803 9.8

This vulnerability allows remote authenticated attackers to execute arbitrary commands on IBM Security Verify Access Appliances. Attackers can achieve...

Nov 29, 2024
CVE-2024-49805 9.4

IBM Security Verify Access Appliance versions 10.0.0 through 10.0.8 contain hard-coded credentials that could allow attackers to authenticate to the s...

Nov 29, 2024
CVE-2024-49353 7.5

This vulnerability in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data allows concurrent resource access without proper input validatio...

Nov 26, 2024
CVE-2024-52899 8.5

This vulnerability allows authenticated users to inject malicious parameters into JDBC URLs in IBM Data Virtualization Manager for z/OS, potentially l...

Nov 26, 2024
CVE-2023-26280 5.3

This vulnerability allows authenticated users in IBM Jazz Foundation to modify dashboards they shouldn't have access to by sending specially crafted H...

Nov 25, 2024
CVE-2024-41761 5.3

IBM Db2 databases on Linux, UNIX, and Windows (including Db2 Connect Server) versions 10.5, 11.1, and 11.5 can be crashed by a specially crafted query...

Nov 23, 2024
CVE-2024-41779 9.8

A race condition vulnerability in IBM Engineering Systems Design Rhapsody - Model Manager allows remote attackers to bypass security restrictions and ...

Nov 22, 2024
CVE-2024-52360 7.6

IBM Concert Software versions 1.0.0 through 1.0.2.1 contain a SQL injection vulnerability that allows remote attackers to execute arbitrary SQL comman...

Nov 19, 2024
CVE-2024-37070 4.3

This vulnerability in IBM Concert Software allows authenticated users to access sensitive information that could facilitate further attacks. It affect...

Nov 19, 2024
CVE-2024-41784 7.5

CVE-2024-41784 is a path traversal vulnerability in IBM Sterling Secure Proxy that allows remote attackers to read arbitrary files on the system by se...

Nov 15, 2024
CVE-2024-41785 6.1

IBM Concert Software versions 1.0.0 through 1.0.1 contain a cross-site scripting (XSS) vulnerability that allows unauthenticated attackers to inject m...

Nov 15, 2024
CVE-2024-45642 5.3

IBM Security ReaQta 3.12 contains a cross-site scripting vulnerability that allows privileged users to inject malicious JavaScript into the web interf...

Nov 14, 2024
CVE-2024-41738 5.9

IBM TXSeries for Multiplatforms 10.1 has an information disclosure vulnerability where sensitive data in HTTP GET query strings can be intercepted via...

Nov 1, 2024
CVE-2024-41744 6.5

IBM CICS TX Standard 11.1 has a cross-site request forgery (CSRF) vulnerability that allows attackers to trick authenticated users into performing una...

Nov 1, 2024
CVE-2024-45656 9.8

IBM Flexible Service Processor (FSP) firmware contains hardcoded credentials that could allow network users to gain service privileges. This affects m...

Oct 29, 2024
CVE-2024-38314 5.9

IBM Maximo Application Suite Monitor Component versions 8.10, 8.11, and 9.0 contain a hard-coded cryptographic key vulnerability. This allows attacker...

Oct 24, 2024
CVE-2023-50310 4.9

IBM CICS Transaction Gateway for Multiplatforms versions 9.2 and 9.3 transmits or stores authentication credentials using insecure methods, making the...

Oct 23, 2024
CVE-2024-31880 5.3

IBM Db2 databases on Linux, UNIX, and Windows can crash when authenticated users execute specially crafted SQL statements, causing denial of service. ...

Oct 23, 2024
CVE-2024-43177 5.9

IBM Concert versions 1.0.0 and 1.0.1 are vulnerable to cross-site request forgery (CSRF) and related attacks because they use cookies without the Same...

Oct 22, 2024
CVE-2024-45072 5.5

IBM WebSphere Application Server 8.5 and 9.0 contains an XML External Entity (XXE) vulnerability that allows privileged users to read arbitrary files ...

Oct 16, 2024
CVE-2023-46175 4.4

IBM Cloud Pak for Multicloud Management versions 2.3 through 2.3 FP8 store user credentials in plain text within log files. This allows privileged use...

Sep 26, 2024
CVE-2021-38963 8.0

This CSV injection vulnerability in IBM Aspera Console allows authenticated attackers to execute arbitrary code on affected systems by tricking users ...

Sep 25, 2024
CVE-2024-40703 5.5

This vulnerability allows a local attacker to obtain sensitive API key information from IBM Cognos Analytics and IBM Cognos Analytics Reports for iOS....

Sep 22, 2024
CVE-2024-43180 4.3

IBM Concert 1.0 fails to set the secure attribute on authorization tokens and session cookies, allowing attackers to intercept these cookies when user...

Sep 13, 2024
CVE-2024-45097 5.9

IBM Aspera Faspex versions 5.0.0 through 5.0.9 contain an access control bypass vulnerability that allows authenticated users to modify resources beyo...

Sep 5, 2024
CVE-2024-45075 8.8

CVE-2024-45075 is an authentication bypass vulnerability in IBM webMethods Integration 10.15 that allows authenticated users to create scheduler tasks...

Sep 4, 2024
CVE-2024-45076 9.9

This vulnerability in IBM webMethods Integration 10.15 allows authenticated users to upload and execute arbitrary files on the underlying operating sy...

Sep 4, 2024

Why Monitor Ibm Security Vulnerabilities?

Real-time CVE tracking: Our automated system monitors 891+ known vulnerabilities affecting Ibm products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.

Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Ibm packages in under 60 seconds. No agents required - completely agentless scanning that works across Ibm deployments.

Free vulnerability database: Access detailed information about every Ibm CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.

🚀 Get Started in 60 Seconds

  • Register free account & add your servers
  • Run one-time scan or schedule automatic monitoring (every 1-24 hours)
  • Receive instant alerts when new Ibm CVEs affect your systems
  • Access dashboard with severity breakdown & fix instructions
Start Monitoring Ibm CVEs Free