Filtered by vendor Ibm
Subscribe
Total
8801 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-9327 | 1 Ibm | 1 Websphere Application Server | 2026-09-15 | N/A | 6.3 MEDIUM |
| IBM WebSphere Application Server 9.0, and 8.5 could allow an authenticated user with a low-privilege administrative role to modify security configuration. This could result in information disclosure or denial of service. | |||||
| CVE-2026-9667 | 1 Ibm | 1 Websphere Application Server | 2026-09-15 | N/A | 5.3 MEDIUM |
| IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) that could allow a remote, unauthenticated attacker to cause the server to send outbound requests to arbitrary endpoints. | |||||
| CVE-2026-18905 | 1 Ibm | 1 Contextforge | 2026-09-15 | N/A | 7.7 HIGH |
| IBM ContextForge MCP Gateway (`mcp-contextforge-gateway`) <= v1.0.6 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive information due to a DNS rebinding vulnerability during tool invocation. | |||||
| CVE-2026-77822 | 1 Ibm | 1 Contextforge | 2026-09-15 | N/A | 8.2 HIGH |
| IBM ContextForge MCP Gateway could allow a remote authenticated attacker to obtain sensitive information due to server-side request forgery via DNS rebinding. | |||||
| CVE-2026-18486 | 1 Ibm | 1 Contextforge | 2026-09-15 | N/A | 8.8 HIGH |
| IBM ContextForge MCP Gateway <= v1.0.7 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive credentials and escalate privileges due to improper validation of jq filters. | |||||
| CVE-2026-18489 | 1 Ibm | 1 Contextforge | 2026-09-15 | N/A | 7.4 HIGH |
| IBM ContextForge MCP Gateway - Translate utility <= 1.0.8 MCP Context Forge could allow a remote attacker to obtain sensitive information from other sessions due to exposure of data elements to the wrong session. | |||||
| CVE-2026-86087 | 1 Ibm | 1 Db2 | 2026-09-14 | N/A | 4.3 MEDIUM |
| IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an authenticated user to send a specially crafted request to write arbitrary files on the system. | |||||
| CVE-2026-86093 | 1 Ibm | 1 Db2 | 2026-09-14 | N/A | 7.5 HIGH |
| IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands on Db2 clients due to a stack-based buffer overflow that improperly copies user-controlled data into a fixed-size stack buffer without bounds checking. | |||||
| CVE-2026-87958 | 1 Ibm | 1 Db2 | 2026-09-14 | N/A | 8.1 HIGH |
| IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by a privileged user under certain conditions. | |||||
| CVE-2026-9036 | 1 Ibm | 1 Netezza Performance Server | 2026-09-10 | N/A | 5.9 MEDIUM |
| IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive information using man in the middle techniques. | |||||
| CVE-2026-18175 | 1 Ibm | 1 I | 2026-09-10 | N/A | 8.1 HIGH |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to manipulate database transactions due to improper authorization in the DDM target dispatcher. | |||||
| CVE-2026-17444 | 1 Ibm | 2 App Connect Enterprise, Integration Bus For Z\/os | 2026-09-10 | N/A | 5.3 MEDIUM |
| IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection. | |||||
| CVE-2026-17273 | 1 Ibm | 1 I | 2026-09-10 | N/A | 6.5 MEDIUM |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a NULL pointer dereference. | |||||
| CVE-2026-17270 | 1 Ibm | 1 I | 2026-09-10 | N/A | 4.3 MEDIUM |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a denial of service due to a stack-based buffer overflow. | |||||
| CVE-2026-16941 | 1 Ibm | 1 I | 2026-09-10 | N/A | 4.3 MEDIUM |
| IBM i 7.6, 7.5, and 7.4 could allow a remote authenticated attacker to modify certain system messages due to improper authorization. | |||||
| CVE-2026-16660 | 1 Ibm | 1 Db2 Mirror For I | 2026-09-10 | N/A | 5.3 MEDIUM |
| IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service due to an out-of-bounds read. | |||||
| CVE-2026-8862 | 1 Ibm | 1 Netezza Performance Server | 2026-09-10 | N/A | 7.5 HIGH |
| IBM Netezza Software 11.3.0.3 through Interim Fix 002 has credentials that are hardcoded in the application source code, allowing unauthorized access to the container registry. The exposed secret enables attackers to pull private container images, potentially revealing proprietary code, configuration details, and other sensitive information. | |||||
| CVE-2026-9736 | 1 Ibm | 1 Netezza Performance Server | 2026-09-10 | N/A | 5.3 MEDIUM |
| IBM Netezza Software 11.3.0.3 through Interim Fix 002 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files. | |||||
| CVE-2026-9744 | 1 Ibm | 1 Netezza Performance Server | 2026-09-10 | N/A | 5.3 MEDIUM |
| IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive information using man in the middle techniques. | |||||
| CVE-2026-9745 | 1 Ibm | 1 Netezza Performance Server | 2026-09-10 | N/A | 6.5 MEDIUM |
| IBM Netezza Software 11.3.0.3 through Interim Fix 002 has operations that are performed without validating bucket ownership using the ExpectedBucketOwner parameter. This omission may allow a remote attacker to exploit misconfigurations or naming collisions to redirect application requests to an unintended S3 bucket under their control. | |||||
