Vulnerabilities (CVE)

Filtered by vendor Ibm Subscribe
Total 8801 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-18076 1 Ibm 1 I 2026-09-10 N/A 4.3 MEDIUM
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a memory leak.
CVE-2026-17483 1 Ibm 1 Db2 Mirror For I 2026-09-10 N/A 4.3 MEDIUM
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 IBM i could allow a local attacker to delete historical flight-recorder archives due to improper access control in an SQL procedure.
CVE-2026-17442 1 Ibm 2 App Connect Enterprise, Integration Bus For Z\/os 2026-09-10 N/A 5.1 MEDIUM
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to credentials being written to trace logs in cleartext.
CVE-2026-17255 1 Ibm 1 I 2026-09-10 N/A 4.3 MEDIUM
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper validation of the prefix length in ICMPv6 Router Advertisements.
CVE-2026-16826 1 Ibm 1 I 2026-09-10 N/A 5.3 MEDIUM
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
CVE-2026-17443 1 Ibm 2 App Connect Enterprise, Integration Bus For Z\/os 2026-09-09 N/A 5.3 MEDIUM
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection flaw.
CVE-2026-17469 1 Ibm 1 I 2026-09-09 N/A 5.3 MEDIUM
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to an off-by-one write in the LPD queue name parser.
CVE-2026-17470 1 Ibm 1 I 2026-09-09 N/A 5.3 MEDIUM
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a buffer overflow.
CVE-2026-17499 1 Ibm 1 I 2026-09-09 N/A 4.4 MEDIUM
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
CVE-2026-19649 1 Ibm 2 App Connect Enterprise, Integration Bus For Z\/os 2026-09-09 N/A 6.2 MEDIUM
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to improper logging of database credentials.
CVE-2026-78543 1 Ibm 2 App Connect Enterprise, Integration Bus For Z\/os 2026-09-09 N/A 5.3 MEDIUM
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote attacker to cause a denial of service due to an infinite loop.
CVE-2026-16180 1 Ibm 2 App Connect Enterprise, Integration Bus For Z\/os 2026-09-09 N/A 5.7 MEDIUM
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 Toolkit could allow an authenticated user to cause a denial-of-service condition due to improper validation of XML entities.
CVE-2026-17274 1 Ibm 1 I 2026-09-09 N/A 5.4 MEDIUM
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to predictable server seeds.
CVE-2026-17440 1 Ibm 2 App Connect Enterprise, Integration Bus For Z\/os 2026-09-09 N/A 5.5 MEDIUM
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to cause a denial of service due to uncontrolled recursion.
CVE-2026-81832 1 Ibm 2 App Connect Enterprise, Integration Bus For Z\/os 2026-09-08 N/A 7.7 HIGH
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 SAP Adapter is vulnerable to an XML external entity (XXE) attack.
CVE-2026-18567 1 Ibm 1 Db2 Mirror For I 2026-09-08 N/A 4.4 MEDIUM
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a local attacker to obtain information due to a race condition involving a predictable Unix domain socket path in a world-writable directory.
CVE-2026-18858 1 Ibm 1 I 2026-09-08 N/A 3.3 LOW
IBM i 7.6, and 7.5 could allow a local authenticated attacker to obtain information from a privileged file when using SSH.
CVE-2026-18887 1 Ibm 1 I 2026-09-08 N/A 6.5 MEDIUM
IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to obtain sensitive information in PASE. An attacker could exploit this vulnerability to access information about process they shouldn't be permitted to access.
CVE-2026-18073 1 Ibm 1 I 2026-09-08 N/A 4.4 MEDIUM
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to inject parameters into a CL command due to improper neutralization of special elements.
CVE-2026-18078 1 Ibm 1 I 2026-09-08 N/A 4.3 MEDIUM
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to an integer overflow.