Filtered by vendor Ibm
Subscribe
Total
8804 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-12618 | 1 Ibm | 3 Security Verify Access, Verify Identity Access, Verify Identity Access Container | 2026-08-17 | N/A | 7.2 HIGH |
| IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 could allow an administrator to execute additional commands they are not entitled to due to improper validation of user supplied input. | |||||
| CVE-2026-12359 | 1 Ibm | 3 Security Verify Access, Verify Identity Access, Verify Identity Access Container | 2026-08-17 | N/A | 8.1 HIGH |
| IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 could allow a remote attacker to access sensitive information due to an inconsistent interpretation of an HTTP request by a reverse proxy. | |||||
| CVE-2026-12005 | 1 Ibm | 3 Security Verify Access, Verify Identity Access, Verify Identity Access Container | 2026-08-17 | N/A | 7.2 HIGH |
| IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 contains a input validation vulnerability in the management interface that allows already privileged attackers to execute additional operations by crafting a malicious HTTP request. | |||||
| CVE-2026-17111 | 1 Ibm | 1 I | 2026-08-17 | N/A | 7.6 HIGH |
| IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. | |||||
| CVE-2026-17417 | 1 Ibm | 1 I | 2026-08-17 | N/A | 8.8 HIGH |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of shell metacharacters. | |||||
| CVE-2026-17445 | 1 Ibm | 1 I | 2026-08-17 | N/A | 8.2 HIGH |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper validation of an attacker-supplied user profile name. | |||||
| CVE-2026-17642 | 1 Ibm | 1 I | 2026-08-17 | N/A | 8.8 HIGH |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. | |||||
| CVE-2026-18099 | 1 Ibm | 1 I | 2026-08-17 | N/A | 8.9 HIGH |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary script code due to improper neutralization of user-controlled input. | |||||
| CVE-2026-18148 | 1 Ibm | 1 I | 2026-08-17 | N/A | 4.3 MEDIUM |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to inject arbitrary content into Navigator log files due to improper output neutralization for logs. | |||||
| CVE-2026-18150 | 1 Ibm | 1 I | 2026-08-17 | N/A | 4.3 MEDIUM |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a race condition. | |||||
| CVE-2026-12004 | 1 Ibm | 3 Security Verify Access, Verify Identity Access, Verify Identity Access Container | 2026-08-17 | N/A | 8.7 HIGH |
| IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 contains a format string injection vulnerability in the management interface that allows attackers to cause denial of service and information disclosure by crafting a malicious HTTP request. | |||||
| CVE-2026-11937 | 1 Ibm | 3 Security Verify Access, Verify Identity Access, Verify Identity Access Container | 2026-08-17 | N/A | 3.1 LOW |
| IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 and IBM Security Verify Access Container 10.0 through 10.0.9.2 Reverse Proxy in certain configurations is vulnerable to a denial of service attack. | |||||
| CVE-2026-11923 | 1 Ibm | 3 Security Verify Access, Verify Identity Access, Verify Identity Access Container | 2026-08-17 | N/A | 7.4 HIGH |
| IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data. | |||||
| CVE-2026-13365 | 1 Ibm | 1 Planning Analytics Local | 2026-08-17 | N/A | 7.1 HIGH |
| IBM Planning Analytics 2.0, and 2.1 Local is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. | |||||
| CVE-2026-18499 | 1 Ibm | 1 Websphere Application Server | 2026-08-17 | N/A | 8.1 HIGH |
| IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to a privilege escalation when using Liberty collectives. | |||||
| CVE-2026-18096 | 1 Ibm | 1 Db2 | 2026-08-17 | N/A | 3.3 LOW |
| IBM Db2 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacker to cause a denial of service due to a memory leak. | |||||
| CVE-2026-17616 | 1 Ibm | 4 Security Verify Access, Security Verify Access Container, Verify Identity Access and 1 more | 2026-08-17 | N/A | 6.8 MEDIUM |
| IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data. | |||||
| CVE-2026-10534 | 1 Ibm | 1 Db2 | 2026-08-17 | N/A | 8.4 HIGH |
| IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer overflow in the IXF IMPORT parser. | |||||
| CVE-2026-16867 | 1 Ibm | 1 I | 2026-08-17 | N/A | 8.1 HIGH |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to access server resources with the privileges of an authenticated user due to improper authentication during NTLM session negotiation. | |||||
| CVE-2026-16896 | 1 Ibm | 1 I | 2026-08-17 | N/A | 7.1 HIGH |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to obtain unauthorized access to files due to a time-of-check time-of-use (TOCTOU) race condition. | |||||
