Filtered by vendor Ibm
Subscribe
Total
8804 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-9171 | 1 Ibm | 1 Powervm Novalink | 2026-08-11 | N/A | 7.5 HIGH |
| IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. | |||||
| CVE-2026-13473 | 2 Ibm, Microsoft | 2 Storage Protect, Windows | 2026-08-11 | N/A | 8.1 HIGH |
| IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 through 8.2.1.0 IBM Storage Protect is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote attacker could overflow a buffer and execute arbitrary code on the system or cause the server to crash. | |||||
| CVE-2026-14501 | 1 Ibm | 2 Agentics, Db2 Genius Hub | 2026-08-11 | N/A | 4.3 MEDIUM |
| IBM Db2 Genius Hub 1.1, 1.1.1, 1.1.2 and IBM Agentics 1.0 could allow an attacker to execute arbitrary code or obtain sensitive information due to the use of dangerous functions without sufficient restrictions. | |||||
| CVE-2026-14971 | 1 Ibm | 1 Powervm Novalink | 2026-08-11 | N/A | 3.9 LOW |
| IBM PowerVM Novalink 2.2.02.2.12.2.1.1, and 2.3.02.3.0.12.3.12.3.2 IBM NovaLink APIs misconfiguration may increase attack surface and enable unintended or unauthorized operations under non-default conditions. | |||||
| CVE-2026-14979 | 1 Ibm | 1 Engineering Lifecycle Management | 2026-08-11 | N/A | 5.3 MEDIUM |
| IBM Engineering Lifecycle Management 7.0.3 ( Interim Fix 001 through ) Interim Fix 021, 7.1.0 ( Interim Fix 001 through ) Interim Fix 009, and 7.2.0 and 7.2.0 Interim Fix 001 DOORS could allow a remote attacker to cause a denial of service due to improper handling of XML entity expansion. | |||||
| CVE-2026-15995 | 1 Ibm | 1 Cognos Analytics | 2026-08-11 | N/A | 5.4 MEDIUM |
| IBM Cognos Analytics 12.1.3 GA Version with build number through 12.1.3-2606251736 could allow an attacker to obtain incorrect report summary results or cause report-processing failures due to a race condition in the Agentic AI assistant's concurrent request-handling logic when multiple authenticated users submit report-related tasks simultaneously. | |||||
| CVE-2026-8861 | 1 Ibm | 4 Security Verify Access, Security Verify Access Container, Verify Identity Access and 1 more | 2026-08-11 | N/A | 5.3 MEDIUM |
| IBM Security Verify could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. | |||||
| CVE-2026-12118 | 1 Ibm | 1 Webmethods Integration | 2026-08-10 | N/A | 9.8 CRITICAL |
| IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of untrusted data. | |||||
| CVE-2026-12733 | 1 Ibm | 1 Datapower Gateway | 2026-08-10 | N/A | 7.5 HIGH |
| IBM DataPower Gateway could allow a remote attacker to cause a denial of service due to improper resource limitations. | |||||
| CVE-2026-12943 | 1 Ibm | 1 Hardware Management Console | 2026-08-10 | N/A | 9.8 CRITICAL |
| IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power environments (HMC and Novalink) could allow an unauthenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input. | |||||
| CVE-2026-10569 | 1 Ibm | 2 Devops Deploy, Urbancode Deploy | 2026-08-10 | N/A | 4.3 MEDIUM |
| IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.23, and 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 is susceptible to an Exposure of Sensitive Information Vulnerability in plugin output logs. This exposure could allow an attacker with access to the logs to potentially obtain senstive values related to that step. | |||||
| CVE-2026-10025 | 1 Ibm | 1 Qradar Security Information And Event Manager | 2026-08-10 | N/A | 8.2 HIGH |
| IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulnerability resides in the parseXmlPayload() function within the event processing pipeline ( q1labs_core.jar ). When at least one log source type is configured to use XML-format property autodetection, the system processes XML-formatted syslog events sent to port 514 (UDP/TCP) without authentication. | |||||
| CVE-2026-12730 | 1 Ibm | 1 Business Automation Workflow | 2026-08-10 | N/A | 3.8 LOW |
| IBM Business Automation Workflow containers and traditional 26.0.0, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 007, and 24.0.0 through 24.0.0 Interim Fix 009 IBM Business Automation Workflow fails to properly verify that the hostname matches the server certificate potentially allowing connections to an attacker-controlled server. | |||||
| CVE-2026-12762 | 1 Ibm | 1 Business Automation Insights | 2026-08-10 | N/A | 5.3 MEDIUM |
| IBM Cloud Pak For Business Automation 24.0.0, 24.0.1, 25.0.0, and 26.0.0 could allow a remote attacker to obtain sensitive information exposed in manifest files. | |||||
| CVE-2026-17617 | 1 Ibm | 1 Application Gateway Operator | 2026-08-10 | N/A | 8.5 HIGH |
| IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of URLs specified in custom resources. | |||||
| CVE-2026-13477 | 1 Ibm | 1 Qradar Security Information And Event Manager | 2026-08-10 | N/A | 4.7 MEDIUM |
| IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privileged user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input. | |||||
| CVE-2026-15656 | 1 Ibm | 1 Maximo Application Suite | 2026-08-10 | N/A | 4.3 MEDIUM |
| IBM Maximo Application Suite 9.2, 9.1, and 9.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. | |||||
| CVE-2026-18531 | 1 Ibm | 1 Maximo Application Suite | 2026-08-10 | N/A | 5.3 MEDIUM |
| IBM Maximo Application Suite 9.2, 9.1, and 9.0 could allow a remote attacker to tamper with session data due to the use of a weak HMAC session signing secret. | |||||
| CVE-2026-8400 | 1 Ibm | 1 Websphere Application Server | 2026-08-10 | N/A | 8.1 HIGH |
| IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server to induce loading and instantation of arbitrary classes. | |||||
| CVE-2026-15325 | 1 Ibm | 1 Websphere Application Server | 2026-08-06 | N/A | 8.7 HIGH |
| IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTTP request smuggling due to improper handling of TRACE requests. | |||||
