Ibm Security Vulnerabilities (CVEs)

Track 876 security vulnerabilities affecting Ibm products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.

82 Critical
353 High
428 Medium
13 Low
🔔 Get Alerts for Ibm
CVE-2025-36081 5.3

IBM Concert Software versions 1.0.0 through 2.0.0 contain a log injection vulnerability (CWE-117) that allows authenticated users to modify system log...

Oct 28, 2025
CVE-2025-36083 6.2

IBM Concert Software versions 1.0.0 through 2.0.0 contain a heap memory clearing vulnerability that allows local users to access sensitive information...

Oct 28, 2025
CVE-2025-36085 5.4

IBM Concert versions 1.0.0 through 2.0.0 contain a server-side request forgery (SSRF) vulnerability that allows authenticated attackers to make unauth...

Oct 28, 2025
CVE-2025-33131 6.5

This vulnerability in IBM DB2 High Performance Unload allows authenticated users to trigger a stack-based buffer overflow, causing the program to cras...

Oct 28, 2025
CVE-2025-33132 6.5

IBM DB2 High Performance Unload contains a use-after-free vulnerability (CWE-467) where incorrect pointer size calculations allow authenticated users ...

Oct 28, 2025
CVE-2025-33133 6.5

This vulnerability in IBM DB2 High Performance Unload allows authenticated users to trigger an out-of-bounds write that crashes the program. It affect...

Oct 28, 2025
CVE-2025-33126 6.5

This CVE describes an incorrect buffer size calculation vulnerability in IBM DB2 High Performance Unload that could allow authenticated users to cause...

Oct 28, 2025
CVE-2025-36007 7.8

IBM QRadar SIEM versions 7.5 through 7.5.0 Update Pack 13 Independent Fix 02 contain a privilege escalation vulnerability due to improper privilege as...

Oct 27, 2025
CVE-2025-36170 6.4

IBM QRadar SIEM versions 7.5 through 7.5.0 Update Pack 13 Independent Fix 02 contain a stored cross-site scripting vulnerability. Authenticated users ...

Oct 27, 2025
CVE-2025-36121 5.4

IBM OpenPages 9.1 and 9.0 contains an HTML injection vulnerability that allows authenticated attackers to inject malicious HTML code. When victims vie...

Oct 27, 2025
CVE-2025-36361 6.3

This vulnerability in IBM App Connect Enterprise allows authenticated users to perform unauthorized actions on customer-defined resources due to missi...

Oct 24, 2025
CVE-2025-36128 7.5

IBM MQ is vulnerable to denial of service attacks where attackers can exploit improper timeout enforcement on read operations to exhaust server resour...

Oct 16, 2025
CVE-2025-27906 5.3

IBM Content Navigator versions 3.0.11 through 3.2.0 expose directory listings when accessing specific application URLs, allowing attackers to view fil...

Oct 14, 2025
CVE-2025-2140 5.7

This vulnerability in IBM Engineering Requirements Management Doors Next allows authenticated users to spoof email sender identities due to improper s...

Oct 12, 2025
CVE-2025-33096 6.5

This vulnerability in IBM Engineering Requirements Management Doors Next allows authenticated users to cause denial of service by uploading specially ...

Oct 12, 2025
CVE-2025-36225 4.3

IBM Aspera versions 5.0.0 through 5.0.13.1 contain an information disclosure vulnerability where authenticated users can access sensitive system infor...

Oct 9, 2025
CVE-2023-37401 5.3

IBM Aspera Faspex versions 5.0.0 through 5.0.13.1 have an overly permissive cross-domain policy file that includes untrusted domains. This could allow...

Oct 9, 2025
CVE-2025-36156 7.4

A local attacker with access to specific files (CECSUB or CECRM) on IBM InfoSphere Data Replication VSAM for z/OS can exploit a stack-based buffer ove...

Oct 7, 2025
CVE-2025-1826 5.4

This stored XSS vulnerability in IBM Engineering Requirements Management DOORS Next allows authenticated users to inject malicious JavaScript into the...

Oct 7, 2025
CVE-2025-36354 7.3

This vulnerability allows unauthenticated attackers to execute arbitrary commands with limited privileges on IBM Security Verify Access systems. It af...

Oct 6, 2025
CVE-2025-36356 9.3

This vulnerability allows a locally authenticated user on affected IBM Security Verify Access systems to escalate their privileges to root due to impr...

Oct 6, 2025
CVE-2023-49886 9.8

CVE-2023-49886 is a critical remote code execution vulnerability in IBM Standards Processing Engine caused by unsafe Java deserialization. Attackers c...

Oct 6, 2025
CVE-2023-49883 5.9

IBM Transformation Extender Advanced 10.0.1 does not enforce strong password requirements by default, allowing attackers to more easily guess or brute...

Oct 1, 2025
CVE-2025-36262 4.9

This vulnerability in IBM Planning Analytics Local allows malicious privileged users to bypass the user interface and access sensitive information thr...

Sep 30, 2025
CVE-2025-36351 4.3

This vulnerability in IBM License Metric Tool allows authenticated users to bypass access controls in the REST API interface, enabling unauthorized ac...

Sep 29, 2025
CVE-2025-36352 6.4

IBM License Metric Tool versions 9.2.0 through 9.2.40 contain a stored cross-site scripting vulnerability that allows authenticated users to inject ma...

Sep 29, 2025
CVE-2025-36239 6.1

IBM Storage TS4500 Library versions 1.11.0.0 and 2.11.0.0 contain a cross-site scripting (XSS) vulnerability in their web interface. This allows unaut...

Sep 27, 2025
CVE-2024-43192 6.5

IBM Storage TS4500 Library versions 1.11.0.0 and 2.11.0.0 contain a cross-site request forgery (CSRF) vulnerability that allows attackers to trick aut...

Sep 27, 2025
CVE-2025-36274 7.5

IBM Aspera HTTP Gateway versions 2.0.0 through 2.3.1 store sensitive information in plain text files that can be accessed by unauthenticated users. Th...

Sep 26, 2025
CVE-2025-33116 4.4

IBM Watson Studio 4.0 through 5.2.0 on Cloud Pak for Data contains a cross-site scripting (XSS) vulnerability that allows authenticated users to injec...

Sep 25, 2025
CVE-2025-36202 7.5

This CVE describes a format string vulnerability in IBM webMethods Integration that allows authenticated users with execute Services permissions to ex...

Sep 22, 2025
CVE-2025-36248 6.1

IBM Copy Services Manager 6.3.13 contains a cross-site scripting (XSS) vulnerability that allows unauthenticated attackers to inject malicious JavaScr...

Sep 19, 2025
CVE-2025-36139 5.5

IBM Lakehouse (watsonx.data 2.2) contains a stored cross-site scripting vulnerability that allows privileged users to inject malicious JavaScript into...

Sep 18, 2025
CVE-2025-36143 4.7

CVE-2025-36143 is an OS command injection vulnerability in IBM Lakehouse (watsonx.data 2.2) that allows authenticated privileged users to execute arbi...

Sep 18, 2025
CVE-2025-36146 4.3

IBM Lakehouse (watsonx.data 2.2) exposes sensitive server component version information to authenticated users. This information disclosure vulnerabil...

Sep 18, 2025
CVE-2025-36244 7.4

This vulnerability allows local users on affected IBM AIX and VIOS systems to write files with root privileges when Kerberos authentication is configu...

Sep 16, 2025
CVE-2025-36035 6.7

This vulnerability in IBM PowerVM Hypervisor allows a local privileged user to cause denial of service through specially crafted IBM i hypervisor call...

Sep 14, 2025
CVE-2025-36222 8.7

This vulnerability exposes AMQStreams without client authentication in IBM Fusion products due to insecure default configurations. Attackers could per...

Sep 11, 2025
CVE-2024-45671 5.9

IBM Security Verify Information Queue versions 10.0.5 through 10.0.8 use weak cryptographic algorithms that could allow attackers to decrypt sensitive...

Sep 10, 2025
CVE-2024-47120 6.4

This vulnerability in IBM Security Verify Information Queue allows privileged users to escalate their privileges and expand their attack surface on th...

Sep 10, 2025
CVE-2024-45669 6.5

This vulnerability in IBM Security Verify Information Queue allows remote attackers to cause denial of service by sending specially crafted requests w...

Sep 10, 2025
CVE-2025-36011 4.3

IBM Jazz for Service Management versions 1.1.3.0 through 1.1.3.24 fail to set the secure attribute on authorization tokens and session cookies, allowi...

Sep 9, 2025
CVE-2025-36125 6.4

IBM Hardware Management Console for Power systems is vulnerable to stored cross-site scripting (XSS) that allows authenticated users to inject malicio...

Sep 9, 2025
CVE-2025-36100 5.1

IBM MQ stores passwords in client configuration files when trace functionality is enabled, allowing local users to read sensitive credentials. This af...

Sep 7, 2025
CVE-2025-25048 6.5

This vulnerability allows authenticated users to upload files to restricted directories in IBM Jazz Foundation due to improper path neutralization. It...

Sep 4, 2025
CVE-2025-2694 4.8

This cross-site scripting (XSS) vulnerability in IBM Sterling B2B Integrator and File Gateway allows privileged users to inject malicious JavaScript i...

Sep 4, 2025
CVE-2024-43184 6.1

This cross-site scripting (XSS) vulnerability in IBM Jazz Foundation allows unauthenticated attackers to inject malicious JavaScript into the web inte...

Sep 4, 2025
CVE-2025-36193 8.4

This vulnerability allows local privilege escalation to root within containers running vulnerable IBM Transformation Advisor Operator Catalog images. ...

Sep 3, 2025
CVE-2025-36162 4.3

This vulnerability in IBM DevOps Deploy/UrbanCode Deploy allows authenticated users to access sensitive configuration information they shouldn't have ...

Sep 2, 2025
CVE-2025-33099 5.9

IBM Concert Software versions 1.0.0 through 1.1.0 have improper certificate validation, allowing man-in-the-middle attacks. This enables attackers to ...

Sep 1, 2025

Why Monitor Ibm Security Vulnerabilities?

Real-time CVE tracking: Our automated system monitors 876+ known vulnerabilities affecting Ibm products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.

Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Ibm packages in under 60 seconds. No agents required - completely agentless scanning that works across Ibm deployments.

Free vulnerability database: Access detailed information about every Ibm CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.

🚀 Get Started in 60 Seconds

  • Register free account & add your servers
  • Run one-time scan or schedule automatic monitoring (every 1-24 hours)
  • Receive instant alerts when new Ibm CVEs affect your systems
  • Access dashboard with severity breakdown & fix instructions
Start Monitoring Ibm CVEs Free