Ibm Security Vulnerabilities (CVEs)

Track 890 security vulnerabilities affecting Ibm products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.

84 Critical
365 High
428 Medium
13 Low
🔔 Get Alerts for Ibm
CVE-2024-22351 6.3

IBM InfoSphere Information Server 11.7 fails to properly invalidate user sessions after logout, allowing authenticated users to reuse old session toke...

Apr 23, 2025
CVE-2025-1951 8.4

This CVE describes a local privilege escalation vulnerability in IBM Hardware Management Console for Power Systems. A local authenticated user can exe...

Apr 22, 2025
CVE-2024-45651 6.3

IBM Sterling Connect:Direct Web Services versions 6.1.0, 6.2.0, and 6.3.0 fail to properly invalidate user sessions when a browser is closed. This all...

Apr 18, 2025
CVE-2024-22314 5.9

IBM Storage Defender - Resiliency Service versions 2.0.0 through 2.0.12 use weak cryptographic algorithms, potentially allowing attackers to decrypt s...

Apr 16, 2025
CVE-2022-43851 5.9

IBM Aspera Console versions 3.4.0 through 3.4.4 use weak cryptographic algorithms that could allow attackers to decrypt sensitive data. This affects o...

Apr 14, 2025
CVE-2022-43847 5.4

IBM Aspera Console versions 3.4.0 through 3.4.4 are vulnerable to HTTP header injection due to improper validation of HOST headers. This allows attack...

Apr 14, 2025
CVE-2024-51461 4.3

This vulnerability in IBM QRadar WinCollect Agent allows remote attackers to cause denial of service by interrupting HTTP requests, leading to memory ...

Apr 11, 2025
CVE-2023-42007 5.4

IBM Sterling Control Center versions 6.2.1, 6.3.1, and 6.4.0 contain a cross-site scripting (XSS) vulnerability that allows authenticated users to inj...

Apr 10, 2025
CVE-2023-43037 6.5

This vulnerability in IBM Maximo Application Suite allows authenticated users to perform unauthorized actions due to improper input validation. It aff...

Apr 10, 2025
CVE-2025-1500 5.5

This vulnerability in IBM Maximo Application Suite 9.0 allows authenticated users to upload files with dangerous extensions that could be executed by ...

Apr 5, 2025
CVE-2025-0154 5.3

IBM TXSeries for Multiplatforms versions 9.1 and 11.1 have an HTTP header injection vulnerability that could allow remote attackers to read sensitive ...

Apr 2, 2025
CVE-2024-56475 5.4

IBM TXSeries for Multiplatforms versions 9.1 and 11.1 contain a cross-site scripting (XSS) vulnerability that allows authenticated users to inject mal...

Apr 2, 2025
CVE-2024-56341 5.4

IBM Content Navigator versions 3.0.11, 3.0.15, and 3.1.0 contain a cross-site scripting (XSS) vulnerability that allows authenticated users to inject ...

Apr 2, 2025
CVE-2024-7577 4.4

IBM InfoSphere Information Server 11.7 may expose sensitive user credentials in log files during new installations. This vulnerability allows attacker...

Mar 29, 2025
CVE-2024-43186 5.3

IBM InfoSphere Information Server 11.7 contains an information disclosure vulnerability where authenticated users can access sensitive local data unde...

Mar 29, 2025
CVE-2025-0986 4.5

This vulnerability in IBM PowerVM Hypervisor firmware allows a local user with specific Linux processor compatibility mode configurations to cause und...

Mar 28, 2025
CVE-2023-38272 5.9

This vulnerability in IBM Cloud Pak System allows authenticated users with network access to view sensitive information from command-line interface ar...

Mar 27, 2025
CVE-2023-43029 6.8

IBM Storage Virtualize vSphere Remote Plug-in versions 1.0 and 1.1 expose sensitive credential information to remote users after deployment. This vuln...

Mar 21, 2025
CVE-2024-45644 4.7

This vulnerability allows privileged users in IBM Security ReaQta to upload dangerous file types that can be automatically processed within the produc...

Mar 19, 2025
CVE-2024-56346 10.0

This critical vulnerability in IBM AIX's nimesis NIM master service allows remote attackers to execute arbitrary commands on affected systems due to i...

Mar 18, 2025
CVE-2024-45643 5.9

IBM Security QRadar 3.12 EDR uses weak cryptographic algorithms that could allow attackers to decrypt stored credential information. This affects orga...

Mar 14, 2025
CVE-2024-56338 4.8

This cross-site scripting (XSS) vulnerability in IBM Sterling B2B Integrator allows privileged users to inject malicious JavaScript into the web inter...

Mar 11, 2025
CVE-2024-22340 6.5

This vulnerability in IBM Common Cryptographic Architecture allows remote attackers to perform timing attacks against ECDSA signature generation, pote...

Mar 11, 2025
CVE-2024-49823 6.5

This vulnerability in IBM Common Cryptographic Architecture allows authenticated users to send specially crafted valid requests that can cause a denia...

Mar 11, 2025
CVE-2023-43052 5.3

IBM Control Center versions 6.2.1 through 6.3.1 are vulnerable to server-side request forgery (SSRF) via improper input validation. Attackers can make...

Mar 7, 2025
CVE-2024-51476 7.5

IBM Concert Software 1.0.5 has an inadequate account lockout mechanism that allows attackers to perform brute force attacks against user credentials. ...

Mar 6, 2025
CVE-2024-43169 8.8

IBM Engineering Requirements Management DOORS Next versions 7.0.2, 7.0.3, and 7.1 contain a vulnerability that allows users to download malicious file...

Mar 3, 2025
CVE-2024-41770 7.5

This vulnerability in IBM Engineering Requirements Management DOORS Next allows remote attackers to download temporary files, potentially exposing sen...

Mar 3, 2025
CVE-2024-54179 5.4

This CVE describes a cross-site scripting (XSS) vulnerability in IBM Business Automation Workflow and IBM Business Automation Workflow Enterprise Serv...

Mar 3, 2025
CVE-2025-0159 9.1

This vulnerability allows remote attackers to bypass authentication on IBM FlashSystem RPCAdapter endpoints by sending specially crafted HTTP requests...

Feb 28, 2025
CVE-2024-54175 5.5

This vulnerability in IBM MQ allows a local user to cause a denial of service by exploiting improper error handling. It affects IBM MQ 9.3 LTS, 9.3 CD...

Feb 28, 2025
CVE-2025-0823 6.5

This directory traversal vulnerability in IBM Cognos Analytics allows remote attackers to read arbitrary files on the server by sending specially craf...

Feb 28, 2025
CVE-2025-0975 8.8

CVE-2025-0975 is an improper input validation vulnerability in IBM MQ console that allows authenticated users to execute arbitrary code by exploiting ...

Feb 28, 2025
CVE-2025-23225 6.5

This vulnerability in IBM MQ allows authenticated users to send specially crafted messages with invalid headers to queues, causing the queue manager t...

Feb 28, 2025
CVE-2024-54173 4.7

IBM MQ versions 9.3 and 9.4 expose sensitive information in trace files when webconsole trace is enabled. This information disclosure vulnerability al...

Feb 28, 2025
CVE-2024-54169 6.5

This vulnerability allows authenticated attackers to perform directory traversal attacks on IBM EntireX 11.1 systems. By sending specially crafted URL...

Feb 27, 2025
CVE-2025-0719 6.1

IBM Cloud Pak for Data versions 4.0.0 through 4.8.5 and 5.0.0 contain a cross-site scripting (XSS) vulnerability that allows unauthenticated attackers...

Feb 26, 2025
CVE-2024-55898 8.5

This vulnerability allows users with program compilation or restoration capabilities on IBM i systems to gain elevated privileges through an unqualifi...

Feb 24, 2025
CVE-2024-22341 5.3

This vulnerability in IBM Watson Query on Cloud Pak for Data allows unauthorized access to remote data sources due to improper privilege management. A...

Feb 22, 2025
CVE-2025-1403 8.6

This vulnerability allows remote attackers to cause denial of service by sending maliciously crafted QPY files to Qiskit applications. The malformed s...

Feb 21, 2025
CVE-2024-45673 5.5

This vulnerability allows local users to read stored user credentials from configuration files in affected IBM Security products. It affects IBM Secur...

Feb 21, 2025
CVE-2025-0161 7.8

This vulnerability in IBM Security Verify Access Appliance allows local users to execute arbitrary code due to improper restrictions on code generatio...

Feb 20, 2025
CVE-2024-49344 4.3

IBM OpenPages with Watson versions 8.3 and 9.0 have a session management vulnerability where chat sessions remain active after user logout. This allow...

Feb 20, 2025
CVE-2024-49781 7.1

IBM OpenPages with Watson versions 8.3 and 9.0 contain an XML external entity injection (XXE) vulnerability that allows attackers to read sensitive fi...

Feb 20, 2025
CVE-2024-49355 5.3

IBM OpenPages with Watson versions 8.3 and 9.0 may write improperly neutralized data to server log files when System Tracing is enabled. This could al...

Feb 20, 2025
CVE-2024-49782 6.8

This vulnerability in IBM OpenPages with Watson allows attackers to spoof mail server identity when SSL/TLS security is used. Attackers could intercep...

Feb 20, 2025
CVE-2023-47160 8.2

IBM Cognos Controller and IBM Controller are vulnerable to XML External Entity Injection (XXE) attacks when processing XML data. This allows remote at...

Feb 19, 2025
CVE-2024-28777 8.8

IBM Cognos Controller and IBM Controller contain an unrestricted deserialization vulnerability that allows authenticated users to execute arbitrary co...

Feb 19, 2025
CVE-2024-28780 5.9

IBM Cognos Controller and IBM Controller Rich Client use weak cryptographic algorithms that could allow attackers to decrypt sensitive information. Th...

Feb 19, 2025
CVE-2024-45084 8.0

This vulnerability in IBM Cognos Controller allows authenticated attackers to perform formula injection attacks by manipulating file contents. Success...

Feb 19, 2025

Why Monitor Ibm Security Vulnerabilities?

Real-time CVE tracking: Our automated system monitors 890+ known vulnerabilities affecting Ibm products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.

Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Ibm packages in under 60 seconds. No agents required - completely agentless scanning that works across Ibm deployments.

Free vulnerability database: Access detailed information about every Ibm CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.

🚀 Get Started in 60 Seconds

  • Register free account & add your servers
  • Run one-time scan or schedule automatic monitoring (every 1-24 hours)
  • Receive instant alerts when new Ibm CVEs affect your systems
  • Access dashboard with severity breakdown & fix instructions
Start Monitoring Ibm CVEs Free