Ibm Security Vulnerabilities (CVEs)

Track 869 security vulnerabilities affecting Ibm products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.

80 Critical
348 High
428 Medium
13 Low
🔔 Get Alerts for Ibm
CVE-2025-36437 4.3

This vulnerability in IBM Planning Analytics Local versions 2.1.0 through 2.1.15 allows attackers to obtain sensitive information about server archite...

Dec 9, 2025
CVE-2024-56464 2.7

IBM QRadar SIEM versions 7.5 through 7.5.0 UP14 IF01 have an information disclosure vulnerability that exposes directory information. This could allow...

Dec 9, 2025
CVE-2025-36140 6.5

This vulnerability in IBM watsonx.data allows authenticated users to cause denial of service by exhausting resources in ingestion pods due to improper...

Dec 8, 2025
CVE-2025-64650 6.5

IBM Storage Defender - Resiliency Service versions 2.0.0 through 2.0.18 write sensitive user credentials to log files. This allows attackers with acce...

Dec 8, 2025
CVE-2025-33111 4.3

This vulnerability in IBM Controller and Cognos Controller allows authenticated attackers to potentially access sensitive information through race con...

Dec 8, 2025
CVE-2025-36015 6.5

This vulnerability in IBM Controller and Cognos Controller allows authenticated users to cause denial of service by sending specially crafted input th...

Dec 8, 2025
CVE-2025-36017 6.5

IBM Controller and Cognos Controller versions store sensitive information unencrypted in environmental variables files, allowing authenticated users t...

Dec 8, 2025
CVE-2025-36102 2.7

This vulnerability allows privileged users in IBM Controller/Cognos Controller to bypass server-side security validation by manipulating client-side i...

Dec 8, 2025
CVE-2025-12635 5.4

This CVE describes a cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server and Liberty versions where improper input validation...

Dec 8, 2025
CVE-2025-12832 4.6

This CVE describes a server-side request forgery (SSRF) vulnerability in IBM InfoSphere Information Server versions 11.7.0.0 through 11.7.1.6. An auth...

Dec 8, 2025
CVE-2025-36134 3.7

This vulnerability allows attackers to potentially steal sensitive session cookies in IBM Sterling B2B Integrator and Sterling File Gateway products. ...

Nov 25, 2025
CVE-2025-36150 5.9

IBM Concert versions 1.0.0 through 2.0.0 use weak cryptographic algorithms that could allow attackers to decrypt sensitive information. This affects o...

Nov 24, 2025
CVE-2025-36112 5.3

This vulnerability in IBM Sterling B2B Integrator and Sterling File Gateway allows unauthorized users to access sensitive server IP configuration info...

Nov 24, 2025
CVE-2025-36149 6.3

IBM Concert Software versions 1.0.0 through 2.0.0 contain a clickjacking vulnerability (CWE-1021) that allows remote attackers to hijack user clicks. ...

Nov 21, 2025
CVE-2025-36072 8.8

This vulnerability in IBM webMethods Integration allows authenticated users to execute arbitrary code on affected systems through insecure deserializa...

Nov 20, 2025
CVE-2025-36158 5.1

IBM Concert versions 1.0.0 through 2.0.0 contain an uncontrolled recursive directory copying vulnerability that allows local users with specific permi...

Nov 20, 2025
CVE-2025-36159 6.2

IBM Concert versions 1.0.0 through 2.0.0 have a log file forgery vulnerability where local users can manipulate log entries to impersonate other users...

Nov 20, 2025
CVE-2025-36160 5.3

IBM Concert versions 1.0.0 through 2.0.0 disclose sensitive server information via HTTP response headers. This information leakage could help attacker...

Nov 20, 2025
CVE-2025-36153 6.1

IBM Concert versions 1.0.0 through 2.0.0 contain a cross-site scripting (XSS) vulnerability that allows unauthenticated attackers to inject malicious ...

Nov 20, 2025
CVE-2025-36161 5.9

IBM Concert versions 1.0.0 through 2.0.0 fail to properly enable HTTP Strict-Transport-Security (HSTS), allowing man-in-the-middle attackers to interc...

Nov 20, 2025
CVE-2025-36371 6.5

IBM i operating systems (versions 7.2-7.6) have an information disclosure vulnerability in the database plan cache implementation. Authenticated users...

Nov 19, 2025
CVE-2025-36118 7.5

IBM Storage Virtualize IKEv1 implementation contains an information disclosure vulnerability where remote attackers can extract sensitive data from de...

Nov 17, 2025
CVE-2025-36299 4.3

IBM Planning Analytics Local versions 2.1.0 through 2.1.14 store sensitive information in source code, potentially exposing credentials or configurati...

Nov 17, 2025
CVE-2025-36357 8.0

CVE-2025-36357 is a directory traversal vulnerability in IBM Planning Analytics Local that allows authenticated remote attackers to access arbitrary f...

Nov 17, 2025
CVE-2025-36251 9.6

This vulnerability in IBM AIX and VIOS nimsh service allows remote attackers to execute arbitrary commands due to improper SSL/TLS process controls. I...

Nov 13, 2025
CVE-2025-36250 10.0

This vulnerability allows remote attackers to execute arbitrary commands on IBM AIX and VIOS systems running the NIM server service (nimesis) due to i...

Nov 13, 2025
CVE-2025-36096 9.0

IBM AIX and VIOS systems store NIM private keys insecurely, allowing attackers with network access to intercept and misuse these keys. This affects IB...

Nov 13, 2025
CVE-2025-33119 6.5

IBM QRadar SIEM versions 7.5 through 7.5.0 UP14 store user credentials in configuration files that are committed to source control. This allows authen...

Nov 12, 2025
CVE-2025-36223 5.4

IBM OpenPages 9.0 and 9.1 is vulnerable to HTTP header injection due to improper validation of HOST headers. This allows attackers to inject malicious...

Nov 12, 2025
CVE-2025-27368 4.3

IBM OpenPages 9.0 and 9.1 has insecure REST endpoints that allow authenticated users to access system metadata beyond their intended permissions. This...

Nov 12, 2025
CVE-2025-33150 5.3

IBM Cognos Analytics Certified Containers 12.1.0 contains hidden pages that can expose package parameter information to unauthorized users. This infor...

Nov 10, 2025
CVE-2025-36131 4.6

IBM Db2's clpplus command exposes user credentials in terminal output, allowing anyone with physical access to the system to view them. This affects D...

Nov 7, 2025
CVE-2025-36135 5.4

This CVE describes a cross-site scripting (XSS) vulnerability in IBM Sterling B2B Integrator and Sterling File Gateway. An authenticated attacker can ...

Nov 7, 2025
CVE-2025-36136 5.1

A local user on systems running vulnerable IBM Db2 versions can cause a denial of service by exploiting a flaw in the database monitor script. The scr...

Nov 7, 2025
CVE-2025-36185 6.2

This vulnerability in IBM Db2 allows a local user to cause a denial of service by exploiting improper neutralization of special elements in data query...

Nov 7, 2025
CVE-2025-36186 7.4

IBM Db2 12.1.0 through 12.1.3 on Linux, UNIX, and Windows (including Db2 Connect Server) contains a local privilege escalation vulnerability. Under sp...

Nov 7, 2025
CVE-2025-36006 6.5

This vulnerability in IBM Db2 allows authenticated users to cause denial of service by exploiting improper resource release after use. It affects Db2 ...

Nov 7, 2025
CVE-2025-36008 6.5

This vulnerability in IBM Db2 allows authenticated users to cause denial of service by exploiting improper resource allocation. It affects Db2 version...

Nov 7, 2025
CVE-2025-2534 5.3

IBM Db2 databases running vulnerable versions can be crashed by a specially crafted query, causing denial of service. This affects Db2 11.1.0-11.1.4.7...

Nov 7, 2025
CVE-2025-33012 6.3

This vulnerability in IBM Db2 allows authenticated users to regain access to their accounts even after being locked out due to password expiration. It...

Nov 7, 2025
CVE-2025-33110 5.4

IBM OpenPages versions 9.0 and 9.1 with Watson are vulnerable to HTML injection, allowing attackers to inject malicious HTML that executes in victims'...

Nov 6, 2025
CVE-2025-36172 6.4

This stored XSS vulnerability in IBM Cloud Pak for Business Automation allows authenticated users to inject malicious JavaScript into the web interfac...

Nov 3, 2025
CVE-2025-12531 7.1

IBM InfoSphere Information Server versions 11.7.0.0 through 11.7.1.6 contain an XML external entity injection (XXE) vulnerability that allows remote a...

Nov 3, 2025
CVE-2025-36091 4.3

This vulnerability in IBM Cloud Pak for Business Automation allows authenticated users to assign invalid ownership to dashboards, potentially making t...

Nov 3, 2025
CVE-2025-36092 6.5

This vulnerability in IBM Cloud Pak for Business Automation allows authenticated users to cause denial of service by sending specially crafted input t...

Nov 3, 2025
CVE-2025-36093 4.8

This vulnerability in IBM Cloud Pak for Business Automation allows attackers to perform unauthorized actions or access restricted content through man-...

Nov 3, 2025
CVE-2025-33003 7.8

This vulnerability in IBM InfoSphere Information Server allows non-root users within a container environment to escalate their privileges to root-leve...

Oct 31, 2025
CVE-2025-3355 7.5

CVE-2025-3355 is a directory traversal vulnerability in IBM Tivoli Monitoring that allows remote attackers to read arbitrary files on the system by se...

Oct 30, 2025
CVE-2025-36137 7.2

This vulnerability in IBM Sterling Connect Direct for Unix allows CCD users with existing privileges to escalate their permissions further through mai...

Oct 30, 2025
CVE-2025-36386 9.8

CVE-2025-36386 is an authentication bypass vulnerability in IBM Maximo Application Suite that allows remote attackers to gain unauthorized access with...

Oct 28, 2025

Why Monitor Ibm Security Vulnerabilities?

Real-time CVE tracking: Our automated system monitors 869+ known vulnerabilities affecting Ibm products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.

Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Ibm packages in under 60 seconds. No agents required - completely agentless scanning that works across Ibm deployments.

Free vulnerability database: Access detailed information about every Ibm CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.

🚀 Get Started in 60 Seconds

  • Register free account & add your servers
  • Run one-time scan or schedule automatic monitoring (every 1-24 hours)
  • Receive instant alerts when new Ibm CVEs affect your systems
  • Access dashboard with severity breakdown & fix instructions
Start Monitoring Ibm CVEs Free