Filtered by vendor Ibm
Subscribe
Total
8804 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-12084 | 1 Ibm | 1 Devops Deploy | 2026-07-02 | N/A | 5.4 MEDIUM |
| IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains. | |||||
| CVE-2026-11906 | 4 Ibm, Linux, Microsoft and 1 more | 4 Db2, Linux Kernel, Windows and 1 more | 2026-07-02 | N/A | 6.5 MEDIUM |
| IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in the data query logic of XMLTable-derived columns. | |||||
| CVE-2026-12085 | 1 Ibm | 2 Devops Deploy, Urbancode Deploy | 2026-07-02 | N/A | 6.5 MEDIUM |
| IBM UCD - IBM UrbanCode Deploy 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 IBM DevOps Deploy could disclose sensitive configurations and secrets to authenticated users in API responses that could be used in further attacks against the system. | |||||
| CVE-2026-13449 | 1 Ibm | 1 Business Automation Manager | 2026-07-02 | N/A | 7.6 HIGH |
| IBM Business Automation Manager Open Editions 9.0.0 through 9.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. | |||||
| CVE-2026-13773 | 1 Ibm | 1 Websphere Extreme Scale | 2026-07-02 | N/A | 6.0 MEDIUM |
| IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 Approximately 50 generated CORBA stub classes in WebSphere eXtreme Scale's ogclient.jar call ORB.string_to_object() on an attacker-controlled IOR string during Java deserialization, turning any unfiltered ObjectInputStream sink in WAS into outbound IIOP SSRF to an attacker-chosen host; when chained with the IBM ORB's getUserException class-instantiation flaw (WAS-26), this SSRF escalates to remote code execution on the calling JVM. | |||||
| CVE-2026-11546 | 1 Ibm | 1 Websphere Application Server | 2026-07-02 | N/A | 7.1 HIGH |
| IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the adminCenter-1.0 feature enabled. | |||||
| CVE-2026-11595 | 1 Ibm | 1 Websphere Application Server | 2026-07-02 | N/A | 4.3 MEDIUM |
| IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information from the administrative console's integrated help system. | |||||
| CVE-2026-11708 | 1 Ibm | 1 Websphere Application Server | 2026-07-02 | N/A | 9.3 CRITICAL |
| IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console's integrated help system. | |||||
| CVE-2026-11712 | 1 Ibm | 1 Websphere Application Server | 2026-07-02 | N/A | 9.3 CRITICAL |
| IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console help system. | |||||
| CVE-2026-11806 | 1 Ibm | 1 Websphere Application Server | 2026-07-02 | N/A | 7.2 HIGH |
| IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 is affected by an arbitrary file read vulnerability with the restConnector-2.0 feature enabled. | |||||
| CVE-2026-11594 | 1 Ibm | 1 Websphere Application Server | 2026-07-02 | N/A | 8.5 HIGH |
| IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console. | |||||
| CVE-2026-10109 | 1 Ibm | 1 Db2 | 2026-07-02 | N/A | 9.8 CRITICAL |
| IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution due to improper pre-auth DRDA handshake handling. | |||||
| CVE-2025-8732 | 3 Ibm, Siemens, Xmlsoft | 5 Aix, Vios, Ruggedcom Rst2428p and 2 more | 2026-07-01 | 1.7 LOW | 3.3 LOW |
| A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the function xmlParseSGMLCatalog of the component xmlcatalog. The manipulation leads to uncontrolled recursion. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The code maintainer explains, that "[t]he issue can only be triggered with untrusted SGML catalogs and it makes absolutely no sense to use untrusted catalogs. I also doubt that anyone is still using SGML catalogs at all." | |||||
| CVE-2025-62231 | 4 Debian, Ibm, Redhat and 1 more | 11 Debian Linux, Aix, Vios and 8 more | 2026-07-01 | N/A | 7.3 HIGH |
| A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCompatMap() function can cause an unsigned short overflow. If an attacker sends specially crafted input data, the value calculation may overflow, leading to memory corruption or a crash. | |||||
| CVE-2025-62230 | 4 Debian, Ibm, Redhat and 1 more | 11 Debian Linux, Aix, Vios and 8 more | 2026-07-01 | N/A | 7.3 HIGH |
| A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources, leading to a use-after-free condition. This can cause memory corruption or a crash when affected clients disconnect. | |||||
| CVE-2024-54178 | 1 Ibm | 3 Cloud Pak For Data, Db2, Db2 Warehouse | 2026-06-30 | N/A | 6.5 MEDIUM |
| IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8,5.0,5.1,5.2,5.3 could allow an authenticated user to cause a denial of service when creating new databases due to improper allocation of resources. | |||||
| CVE-2025-2669 | 1 Ibm | 3 Cloud Pak For Data, Db2, Db2 Warehouse | 2026-06-30 | N/A | 6.0 MEDIUM |
| IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, 5.3 could allow a privileged user to perform operations and obtain sensitive information outside of their authority due to improper token validation. | |||||
| CVE-2023-33854 | 1 Ibm | 3 Cloud Pak For Data, Db2, Db2 Warehouse | 2026-06-30 | N/A | 5.3 MEDIUM |
| IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, and 5.3 could allow an authenticated user to bypass client-side validation and manipulate input data using man in the middle techniques. | |||||
| CVE-2026-11372 | 1 Ibm | 1 Tririga Application Platform | 2026-06-30 | N/A | 5.4 MEDIUM |
| IBM TRIRIGA Application Platform 5.0.2 through 5.0.3 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |||||
| CVE-2026-8059 | 1 Ibm | 2 Datacap, Datacap Navigator | 2026-06-26 | N/A | 6.1 MEDIUM |
| IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |||||
