Ibm Security Vulnerabilities (CVEs)

Track 891 security vulnerabilities affecting Ibm products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.

84 Critical
366 High
428 Medium
13 Low
🔔 Get Alerts for Ibm
CVE-2024-39747 8.1

IBM Sterling Connect:Direct Web Services uses default credentials for critical functionality, allowing attackers to gain unauthorized access. This aff...

Aug 31, 2024
CVE-2024-35118 4.6

IBM MaaS360 for Android versions 6.31 through 8.60 contain hard-coded credentials that can be extracted by anyone with physical access to the device. ...

Aug 29, 2024
CVE-2022-43915 6.8

This vulnerability in IBM App Connect Enterprise Certified Container allows users with privileged access to running Pods to elevate their privileges b...

Aug 24, 2024
CVE-2024-35151 6.5

IBM OpenPages with Watson versions 8.3 and 9.0 contain an improper authorization vulnerability in APIs that allows authenticated users to access sensi...

Aug 22, 2024
CVE-2024-39745 5.9

IBM Sterling Connect:Direct Web Services uses weak cryptographic algorithms that could allow attackers to decrypt sensitive data transmitted by the ap...

Aug 22, 2024
CVE-2024-41773 6.5

This vulnerability in IBM Global Configuration Management allows authenticated users to archive global baselines due to improper access controls. It a...

Aug 20, 2024
CVE-2023-47728 6.5

This vulnerability allows remote attackers to obtain sensitive technical error information from IBM QRadar Suite and Cloud Pak for Security systems. A...

Aug 16, 2024
CVE-2024-40704 4.9

IBM InfoSphere Information Server 11.7 contains an information disclosure vulnerability where privileged users can access sensitive authentication dat...

Aug 15, 2024
CVE-2024-35152 6.5

This vulnerability in IBM Db2 allows authenticated users to cause denial of service through specially crafted queries that trigger improper memory all...

Aug 14, 2024
CVE-2024-31882 5.3

IBM Db2 databases running versions 11.1 or 11.5 on Linux, UNIX, or Windows are vulnerable to a denial of service attack. An authenticated user can cra...

Aug 14, 2024
CVE-2024-28799 5.6

IBM QRadar Suite and Cloud Pak for Security in non-default configurations improperly display sensitive data to local privileged users during back-end ...

Aug 14, 2024
CVE-2024-35124 7.5

This vulnerability allows attackers to gain administrative access to OpenBMC systems by exploiting default passwords and session management weaknesses...

Aug 13, 2024
CVE-2024-41774 4.8

IBM Common Licensing 9.0 has a stored cross-site scripting (XSS) vulnerability that allows privileged users to inject malicious JavaScript into the we...

Aug 13, 2024
CVE-2022-38382 4.7

This vulnerability allows authenticated users to access sensitive information from other users' sessions after they have logged out. It affects IBM Cl...

Aug 13, 2024
CVE-2024-35143 6.7

IBM Planning Analytics Local 2.0 and 2.1 connects to MongoDB without requiring authentication, allowing remote attackers to access the database. This ...

Aug 4, 2024
CVE-2024-38321 5.3

IBM Business Automation Workflow versions 22.0.2 through 24.0.0 store sensitive information in log files that authenticated users can read. This infor...

Aug 3, 2024
CVE-2023-38001 6.5

IBM Aspera Orchestrator 4.0.1 has a cross-site request forgery (CSRF) vulnerability that allows attackers to trick authenticated users into performing...

Jul 30, 2024
CVE-2023-26288 5.5

IBM Aspera Orchestrator 4.0.1 fails to invalidate user sessions after password changes, allowing authenticated users to maintain access with old crede...

Jul 30, 2024
CVE-2024-40689 6.0

IBM InfoSphere Information Server 11.7 contains a SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands. This cou...

Jul 26, 2024
CVE-2024-28772 6.8

IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 contain a stored cross-site scripting (XSS) vulnerability ...

Jul 25, 2024
CVE-2024-39735 5.4

This CVE describes a cross-site scripting (XSS) vulnerability in IBM Datacap Navigator versions 9.1.5 through 9.1.9. An authenticated attacker can inj...

Jul 15, 2024
CVE-2024-39741 4.3

This vulnerability allows remote attackers to perform directory traversal attacks on IBM Datacap Navigator systems. By sending specially crafted URLs ...

Jul 15, 2024
CVE-2024-39739 5.4

This CVE describes a server-side request forgery (SSRF) vulnerability in IBM Datacap Navigator versions 9.1.5 through 9.1.9. An authenticated attacker...

Jul 15, 2024
CVE-2024-39728 6.4

This stored cross-site scripting (XSS) vulnerability in IBM Datacap Navigator allows authenticated users to inject malicious JavaScript into the web i...

Jul 15, 2024
CVE-2024-39736 6.5

IBM Datacap Navigator versions 9.1.5 through 9.1.9 are vulnerable to HTTP header injection due to improper validation of HOST headers. This allows att...

Jul 15, 2024
CVE-2024-39733 5.5

IBM Datacap Navigator versions 9.1.5 through 9.1.9 store user credentials in plain text, allowing local users to read sensitive authentication data. T...

Jul 14, 2024
CVE-2023-33860 5.3

IBM Security QRadar EDR 3.12 fails to set the 'secure' attribute on authorization tokens and session cookies, allowing attackers to potentially steal ...

Jul 10, 2024
CVE-2024-35154 7.2

This vulnerability allows remote authenticated attackers with administrative console access to execute arbitrary code on IBM WebSphere Application Ser...

Jul 9, 2024
CVE-2024-39742 8.1

IBM MQ Operator versions 3.2.2 and 2.0.24 contain a partial string comparison vulnerability that could allow users to bypass authentication under cert...

Jul 8, 2024
CVE-2024-37528 4.8

This CVE describes a stored cross-site scripting (XSS) vulnerability in IBM Cloud Pak for Business Automation that allows privileged users to inject m...

Jul 8, 2024
CVE-2024-38330 7.0

This vulnerability in IBM System Management for i allows a local user to escalate privileges by exploiting an unqualified library program call. An att...

Jul 8, 2024
CVE-2024-28794 5.4

IBM InfoSphere Information Server 11.7 contains a cross-site scripting (XSS) vulnerability that allows authenticated users to inject malicious JavaScr...

Jun 30, 2024
CVE-2024-31898 5.4

This vulnerability in IBM InfoSphere Information Server 11.7 allows authenticated users to bypass authorization controls and access or modify sensitiv...

Jun 30, 2024
CVE-2023-50953 5.4

IBM InfoSphere Information Server 11.7 discloses sensitive technical error information to remote attackers. This information leakage could reveal syst...

Jun 30, 2024
CVE-2024-35119 5.3

IBM InfoSphere Information Server 11.7 discloses sensitive technical information in error messages, potentially revealing system details that could ai...

Jun 30, 2024
CVE-2023-50954 4.3

IBM InfoSphere Information Server 11.7 exposes sensitive information in URLs, potentially revealing system details that could aid attackers in reconna...

Jun 30, 2024
CVE-2024-28798 7.2

IBM InfoSphere Information Server 11.7 contains a stored cross-site scripting (XSS) vulnerability that allows authenticated users to inject malicious ...

Jun 30, 2024
CVE-2024-28795 5.4

IBM InfoSphere Information Server 11.7 contains a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious JavaScript into t...

Jun 30, 2024
CVE-2024-38322 5.3

IBM Storage Defender - Resiliency Service versions 2.0.0 through 2.0.4 have a username and password error response discrepancy that allows attackers t...

Jun 28, 2024
CVE-2024-35116 5.9

IBM MQ versions 9.0 LTS through 9.3 CD are vulnerable to denial of service attacks when configuration changes are applied. Attackers can exploit this ...

Jun 28, 2024
CVE-2024-25041 5.4

This CVE describes a cross-site scripting (XSS) vulnerability in IBM Cognos Analytics that allows remote attackers to execute malicious scripts in use...

Jun 28, 2024
CVE-2022-38383 4.0

This vulnerability allows web pages to be stored locally in IBM Cloud Pak for Security and IBM QRadar Software Suite, which can then be read by other ...

Jun 28, 2024
CVE-2024-35155 6.5

IBM MQ Console versions 9.3 LTS and 9.3 CD expose detailed technical error messages to remote attackers, potentially revealing sensitive system inform...

Jun 28, 2024
CVE-2024-31912 7.5

IBM MQ 9.3 LTS and 9.3 CD contain a privilege escalation vulnerability where authenticated users can gain elevated privileges under certain configurat...

Jun 28, 2024
CVE-2024-35139 6.2

This vulnerability in IBM Security Access Manager Docker allows local users to access sensitive information within the container due to incorrect defa...

Jun 28, 2024
CVE-2023-38368 5.5

IBM Security Access Manager Docker versions 10.0.0.0 through 10.0.7.1 have improper permission controls that could allow local users to access sensiti...

Jun 27, 2024
CVE-2023-38370 7.5

IBM Security Access Manager Docker containers (versions 10.0.0.0 through 10.0.7.1) with certain configurations allow network users to install maliciou...

Jun 27, 2024
CVE-2023-30997 7.8

This vulnerability in IBM Security Access Manager Docker allows a local user to escalate privileges to root due to improper access controls. It affect...

Jun 27, 2024
CVE-2024-35153 4.8

IBM WebSphere Application Server 8.5 and 9.0 contains a cross-site scripting (XSS) vulnerability that allows authenticated privileged users to inject ...

Jun 27, 2024
CVE-2023-42011 4.3

This vulnerability in IBM Sterling B2B Integrator allows clickjacking attacks where malicious websites can embed the application's interface in hidden...

Jun 27, 2024

Why Monitor Ibm Security Vulnerabilities?

Real-time CVE tracking: Our automated system monitors 891+ known vulnerabilities affecting Ibm products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.

Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Ibm packages in under 60 seconds. No agents required - completely agentless scanning that works across Ibm deployments.

Free vulnerability database: Access detailed information about every Ibm CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.

🚀 Get Started in 60 Seconds

  • Register free account & add your servers
  • Run one-time scan or schedule automatic monitoring (every 1-24 hours)
  • Receive instant alerts when new Ibm CVEs affect your systems
  • Access dashboard with severity breakdown & fix instructions
Start Monitoring Ibm CVEs Free