Ibm Security Vulnerabilities (CVEs)

Track 891 security vulnerabilities affecting Ibm products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.

84 Critical
366 High
428 Medium
13 Low
🔔 Get Alerts for Ibm
CVE-2024-28776 5.4

This cross-site scripting (XSS) vulnerability in IBM Cognos Controller allows attackers to inject malicious JavaScript into the web interface. When ex...

Feb 19, 2025
CVE-2024-52902 8.8

IBM Cognos Controller and IBM Controller client applications contain hard-coded database passwords in their source code, allowing attackers to gain un...

Feb 19, 2025
CVE-2024-56463 4.8

IBM QRadar SIEM 7.5 contains a cross-site scripting vulnerability that allows privileged users to inject malicious JavaScript into the web interface. ...

Feb 14, 2025
CVE-2024-52895 6.5

This vulnerability allows privileged users on IBM i 7.4 and 7.5 systems to bypass database capability restrictions, potentially deleting or modifying ...

Feb 14, 2025
CVE-2024-55904 7.2

This vulnerability allows authenticated privileged attackers to execute arbitrary commands on IBM DevOps Deploy and UrbanCode Deploy systems by sendin...

Feb 14, 2025
CVE-2024-54176 4.3

This vulnerability in IBM DevOps Deploy and UrbanCode Deploy allows authenticated users to access sensitive information about other users due to missi...

Feb 8, 2025
CVE-2024-54171 7.1

IBM EntireX 11.1 has an XML external entity injection vulnerability that allows authenticated attackers to read sensitive files from the server or cau...

Feb 6, 2025
CVE-2025-0158 5.5

This vulnerability in IBM EntireX 11.1 allows a local user to cause a denial of service through an unhandled error condition. The issue stems from imp...

Feb 6, 2025
CVE-2024-52892 6.1

IBM Jazz for Service Management versions 1.1.3 through 1.1.3.23 contain a cross-site scripting (XSS) vulnerability that allows unauthenticated attacke...

Feb 6, 2025
CVE-2024-51450 9.1

CVE-2024-51450 is an OS command injection vulnerability in IBM Security Verify Directory that allows authenticated remote attackers to execute arbitra...

Feb 6, 2025
CVE-2024-49796 5.4

IBM ApplinX 11.1 contains a clickjacking vulnerability that allows attackers to hijack user clicks by tricking victims into visiting malicious website...

Feb 6, 2025
CVE-2024-49798 4.3

IBM ApplinX 11.1 can expose sensitive technical error information to remote attackers through browser responses. This information disclosure vulnerabi...

Feb 6, 2025
CVE-2024-49792 5.4

IBM ApplinX 11.1 contains a cross-site scripting (XSS) vulnerability that allows authenticated users to inject malicious JavaScript into the web inter...

Feb 6, 2025
CVE-2024-49794 4.3

IBM ApplinX 11.1 contains a cross-site request forgery (CSRF) vulnerability that allows attackers to trick authenticated users into performing unautho...

Feb 6, 2025
CVE-2024-56473 5.3

IBM Aspera Shares versions 1.9.0 through 1.10.0 PL6 improperly validate 'Client-IP' headers, allowing attackers to spoof their IP addresses in log fil...

Feb 5, 2025
CVE-2024-38318 4.8

IBM Aspera Shares versions 1.9.0 through 1.10.0 PL6 are vulnerable to HTML injection, allowing attackers to inject malicious HTML that executes in vic...

Feb 5, 2025
CVE-2024-56471 5.4

IBM Aspera Shares versions 1.9.0 through 1.10.0 PL6 contain a server-side request forgery (SSRF) vulnerability that allows authenticated attackers to ...

Feb 5, 2025
CVE-2024-38316 4.3

IBM Aspera Shares versions 1.9.0 through 1.10.0 PL6 have an email rate limiting vulnerability that allows authenticated users to send excessive emails...

Feb 5, 2025
CVE-2024-52364 5.4

This CVE describes a cross-site scripting (XSS) vulnerability in IBM Cloud Pak for Business Automation that allows authenticated users to inject malic...

Feb 5, 2025
CVE-2024-49352 7.1

IBM Cognos Analytics is vulnerable to XML External Entity Injection (XXE), allowing attackers to read sensitive files from the server or cause denial ...

Feb 5, 2025
CVE-2024-35138 6.5

IBM Security Verify Access Appliance and Container versions 10.0.0 through 10.0.8 contain a cross-site request forgery (CSRF) vulnerability. This allo...

Feb 4, 2025
CVE-2024-43187 5.9

IBM Security Verify Access Appliance and Container versions 10.0.0 through 10.0.8 transmit sensitive data in cleartext over network channels, allowing...

Feb 4, 2025
CVE-2024-49339 6.4

IBM Financial Transaction Manager for SWIFT Services for Multiplatforms versions 3.2.4.0 through 3.2.4.1 contains a stored cross-site scripting (XSS) ...

Jan 31, 2025
CVE-2024-47103 4.8

This cross-site scripting (XSS) vulnerability in IBM Sterling B2B Integrator allows privileged users to inject malicious JavaScript into the web inter...

Jan 31, 2025
CVE-2024-49807 6.4

This stored XSS vulnerability in IBM Sterling B2B Integrator allows authenticated users to inject malicious JavaScript into the web interface. If expl...

Jan 31, 2025
CVE-2024-40696 4.8

This CVE describes a cross-site scripting (XSS) vulnerability in IBM Sterling B2B Integrator that allows privileged users to inject malicious JavaScri...

Jan 31, 2025
CVE-2023-38739 4.3

This CSRF vulnerability in IBM Sterling B2B Integrator allows attackers to trick authenticated users into performing unauthorized actions by sending m...

Jan 31, 2025
CVE-2024-45650 7.5

IBM Security Verify Directory versions 10.0 through 10.0.3 are vulnerable to denial of service when processing LDAP extended operations. Attackers can...

Jan 31, 2025
CVE-2023-37398 5.9

IBM Aspera Faspex versions 5.0.0 through 5.0.10 do not enforce strong password policies by default, allowing attackers to more easily compromise user ...

Jan 29, 2025
CVE-2023-37413 5.3

IBM Aspera Faspex versions 5.0.0 through 5.0.10 can leak sensitive username information through observable response discrepancies. This vulnerability ...

Jan 29, 2025
CVE-2023-33838 4.4

IBM Security Verify Governance 10.0.2 Identity Manager stores passwords using unsalted cryptographic hashes, making them vulnerable to rainbow table a...

Jan 29, 2025
CVE-2023-35017 5.9

IBM Security Verify Governance 10.0.2 Identity Manager transmits user credentials in clear text during communication, allowing attackers to intercept ...

Jan 29, 2025
CVE-2024-22315 4.0

IBM Fusion and IBM Fusion HCI versions 2.3.0 through 2.8.2 allow insecure network connections from compromised containers. An attacker who gains acces...

Jan 28, 2025
CVE-2024-22316 4.3

CVE-2024-22316 is an improper access control vulnerability in IBM Sterling File Gateway that allows authenticated users to perform unauthorized action...

Jan 27, 2025
CVE-2024-38320 5.9

IBM Storage Protect for Virtual Environments and Backup-Archive Client versions 8.1.0.0 through 8.1.23.0 use weak cryptographic algorithms that could ...

Jan 27, 2025
CVE-2023-47159 4.3

IBM Sterling File Gateway versions 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 contain an information disclosure vulnerability where authentic...

Jan 27, 2025
CVE-2024-28770 4.8

This vulnerability allows attackers to steal session cookies or authorization tokens from IBM Security Directory Integrator users by intercepting unen...

Jan 27, 2025
CVE-2023-46187 5.4

IBM InfoSphere Master Data Management versions 11.6, 12.0, and 14.0 contain a stored cross-site scripting (XSS) vulnerability that allows authenticate...

Jan 27, 2025
CVE-2023-50945 6.2

IBM Common Licensing 9.0 stores user credentials in plain text, allowing local users to read sensitive authentication data. This affects systems runni...

Jan 26, 2025
CVE-2024-31906 6.2

IBM Automation Decision Services 23.0.2 stores web pages locally in a way that allows other users on the same system to read them. This information di...

Jan 26, 2025
CVE-2024-35148 6.3

This SQL injection vulnerability in IBM Maximo Application Suite's Monitor Component allows remote attackers to execute arbitrary SQL commands. Succes...

Jan 25, 2025
CVE-2024-35144 5.3

IBM Maximo Application Suite's Monitor Component stores source code files on the web server that could be accessed by attackers. This information disc...

Jan 25, 2025
CVE-2024-35113 4.3

IBM Control Center versions 6.2.1 and 6.3.1 contain an information disclosure vulnerability where authenticated users can access sensitive information...

Jan 25, 2025
CVE-2024-35134 5.3

IBM Analytics Content Hub 2.0 discloses sensitive technical error information to remote attackers via browser responses. This information leakage coul...

Jan 25, 2025
CVE-2024-39750 8.8

IBM Analytics Content Hub 2.0 contains a buffer overflow vulnerability (CWE-120) that allows authenticated remote attackers to execute arbitrary code ...

Jan 25, 2025
CVE-2023-38271 4.3

This vulnerability in IBM Cloud Pak System allows authenticated users to access sensitive information from log files. It affects multiple versions of ...

Jan 25, 2025
CVE-2023-38714 5.3

IBM Cloud Pak System versions 2.3.3.0 through 2.3.3.7 iFix1 contain an information disclosure vulnerability that could expose sensitive system details...

Jan 25, 2025
CVE-2024-35111 4.3

IBM Control Center versions 6.2.1 and 6.3.1 expose detailed technical error messages to remote attackers, potentially revealing sensitive system infor...

Jan 25, 2025
CVE-2023-38012 5.3

This vulnerability allows remote attackers to perform directory traversal attacks on IBM Cloud Pak System. By sending specially crafted URLs containin...

Jan 25, 2025
CVE-2024-40693 8.0

IBM Planning Analytics 2.0 and 2.1 have a file upload vulnerability that allows attackers to upload malicious executable files through the web interfa...

Jan 24, 2025

Why Monitor Ibm Security Vulnerabilities?

Real-time CVE tracking: Our automated system monitors 891+ known vulnerabilities affecting Ibm products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.

Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Ibm packages in under 60 seconds. No agents required - completely agentless scanning that works across Ibm deployments.

Free vulnerability database: Access detailed information about every Ibm CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.

🚀 Get Started in 60 Seconds

  • Register free account & add your servers
  • Run one-time scan or schedule automatic monitoring (every 1-24 hours)
  • Receive instant alerts when new Ibm CVEs affect your systems
  • Access dashboard with severity breakdown & fix instructions
Start Monitoring Ibm CVEs Free