Vulnerabilities (CVE)

Filtered by vendor Ibm Subscribe
Total 8804 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-13105 1 Ibm 1 I Access Client Solutions 2026-08-18 N/A 8.8 HIGH
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to zip slip path traversal exploit when importing a configuration.
CVE-2026-13367 7 Canonical, Hp, Ibm and 4 more 9 Ubuntu Linux, Hp-ux, Aix and 6 more 2026-08-18 N/A 7.8 HIGH
IBM Informix Dynamic Server 14.10, and 15.0 contain a local privilege escalation vulnerability in the oninit setuid-root utility.
CVE-2026-13433 1 Ibm 1 I Access Client Solutions 2026-08-18 N/A 8.3 HIGH
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 (ACS) is vulnerable to downloading unverified product code when configured to update from an IBM i. A bad actor could use this vulnerablity to run compromised code on the ACS user's workstation.
CVE-2026-11383 3 Ibm, Linux, Microsoft 7 Aix, I, Tivoli System Automation Application Manager and 4 more 2026-08-18 N/A 5.4 MEDIUM
IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by cross-site scripting in the Administrative Console.
CVE-2026-11707 3 Ibm, Linux, Microsoft 7 Aix, I, Tivoli System Automation Application Manager and 4 more 2026-08-18 N/A 9.3 CRITICAL
IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-site scripting vulnerability in the administrative console login page.
CVE-2026-19483 2 Ibm, Linux 2 Storage Scale, Linux Kernel 2026-08-18 N/A 7.1 HIGH
IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 Secrets may be disclosed in log files in IBM Storage Scale Management GUI The admin password is logged into the GUI log of IBM Storage Scale Systems Deploy and Upgrade from GUI. Secrets may be disclosed in information related to exceptions in IBM Storage Scale Management GUI.
CVE-2026-16982 1 Ibm 1 I 2026-08-18 N/A 7.5 HIGH
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a heap buffer overflow.
CVE-2026-13460 2 Ibm, Linux 2 Storage Scale, Linux Kernel 2026-08-17 N/A 7.5 HIGH
IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 GUI contains a hardcoded token in the source code, which was used for inter-node cluster communication and REST API authentication between GUI.
CVE-2026-16887 1 Ibm 1 I 2026-08-17 N/A 7.5 HIGH
IBM i 7.6 could allow a remote attacker to cause a denial of service due to an out-of-bounds write.
CVE-2026-16861 1 Ibm 1 I 2026-08-17 N/A 5.3 MEDIUM
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds read.
CVE-2026-16713 1 Ibm 1 Documentation Offline 2026-08-17 N/A 4.3 MEDIUM
IBM Documentation Offline 1.0.0 through 1.4.1 IBM Documentation could allow a remote attacker to obtain sensitive information due to a security misconfiguration where the documentation server binds to an unrestricted IP address.
CVE-2026-17482 1 Ibm 1 Documentation Offline 2026-08-17 N/A 9.8 CRITICAL
IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to improper control of file paths.
CVE-2026-17045 1 Ibm 1 I 2026-08-17 N/A 8.1 HIGH
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to perform unauthorized operations and access sensitive information due to improper session management.
CVE-2026-16929 1 Ibm 1 I 2026-08-17 N/A 5.3 MEDIUM
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a buffer overflow.
CVE-2026-18097 1 Ibm 1 Db2 2026-08-17 N/A 5.5 MEDIUM
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacker to obtain sensitive information due to the logging of plain text passwords in trace files.
CVE-2026-10571 4 Apple, Ibm, Linux and 1 more 7 Macos, Aix, I and 4 more 2026-08-17 N/A 5.7 MEDIUM
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service caused by insecure deserialization. A low-privileged, administrative user could exploit this vulnerability to consume system resources when the restConnector-2.0 feature is enabled.
CVE-2026-14875 1 Ibm 1 I Access Client Solutions 2026-08-17 N/A 7.3 HIGH
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution on Windows when installed for all users due to publicly writeable directory.
CVE-2026-7366 1 Ibm 1 Datapower Gateway 2026-08-17 N/A 4.2 MEDIUM
IBM DataPower Gateway 11.0.0.0 through 11.0.0.1 and IBM DataPower Gateway 10.5.0.0 through 10.5.0.21 and IBM DataPower Gateway 10.6.0.0 through 10.6.0.9 allows a race condition that results in improper isolation of request state when handling the built‑in X‑Client‑IP header. Under concurrent request processing, X‑Client‑IP values may be contaminated across requests, enabling IP spoofing and disclosure of other clients’ IP addresses.
CVE-2026-14525 4 Apple, Ibm, Linux and 1 more 7 Macos, Aix, I and 4 more 2026-08-17 N/A 9.4 CRITICAL
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is vulnerable to an authentication bypass when the rtcomm-1.0 or rtcommGateway-1.0 feature is enabled.
CVE-2026-13267 1 Ibm 3 Security Verify Access, Verify Identity Access, Verify Identity Access Container 2026-08-17 N/A 8.1 HIGH
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 could allow an authenticated user to gain privileges of another user via a specially crafted request.