Vulnerabilities (CVE)

Filtered by vendor Ibm Subscribe
Total 8801 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-18221 1 Ibm 1 I 2026-09-08 N/A 8.1 HIGH
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to gain unauthorized access due to improper validation of client-supplied authentication parameters.
CVE-2026-18341 1 Ibm 1 I 2026-09-08 N/A 6.3 MEDIUM
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to corrupt memory due to an integer underflow.
CVE-2026-17057 1 Ibm 1 I 2026-09-08 N/A 6.5 MEDIUM
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and affect data integrity due to missing authentication for critical functions.
CVE-2026-16689 1 Ibm 2 App Connect Enterprise, Integration Bus For Z\/os 2026-09-08 N/A 6.2 MEDIUM
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to improper logging of credentials.
CVE-2026-16693 1 Ibm 1 I 2026-09-08 N/A 4.4 MEDIUM
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to the use of hardcoded cryptographic constants to obfuscate encryption keys.
CVE-2026-16892 1 Ibm 1 I 2026-09-08 N/A 5.4 MEDIUM
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper authentication during service-name matching.
CVE-2026-17207 1 Ibm 1 I 2026-09-08 N/A 6.5 MEDIUM
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and compromise integrity due to a buffer overflow.
CVE-2026-17259 1 Ibm 1 I 2026-09-08 N/A 4.3 MEDIUM
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a stack-based buffer overflow.
CVE-2026-18824 1 Ibm 2 Aix, Vios 2026-09-04 N/A 8.4 HIGH
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
CVE-2026-14514 1 Ibm 1 Reliable Scalable Cluster Technology 2026-09-04 N/A 6.5 MEDIUM
IBM Reliable Scalable Cluster Technology (RSCT) 3.0 could allow a remote attacker to cause a denial of service by sending a specially crafted request due improper input validation.
CVE-2026-18544 1 Ibm 1 Portieris 2026-09-02 N/A 8.1 HIGH
IBM Portieris 0.5.0 through 0.14.2 could allow a remote authenticated attacker to bypass image policy enforcement due to improper authorization of pod owner references.
CVE-2026-18849 1 Ibm 17 Openbmc, Power System E1050 \(9043-mrx\), Power System E1050 \(9043-mrx\) Firmware and 14 more 2026-09-02 N/A 6.8 MEDIUM
IBM OpenBMC FW1060.00 through FW1060.80 is affected by a vulnerability in the BMC firmware update process. An attacker with authenticated administrator-level access to the BMC can, under specific conditions, execute arbitrary code, resulting in a confidentiality, integrity, and availability impact.
CVE-2025-36271 1 Ibm 1 Integrated Analytics System 2026-09-02 N/A 5.9 MEDIUM
IBM Integrated Analytics System 1.0.0.0 through 1.0.31.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
CVE-2025-36290 1 Ibm 1 Integrated Analytics System 2026-09-02 N/A 5.9 MEDIUM
IBM Integrated Analytics System 1.0.0.0 through 1.0.31.0 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive information using man in the middle techniques.
CVE-2025-64649 2 Ibm, Linux 2 Concert, Linux Kernel 2026-09-02 N/A 5.9 MEDIUM
IBM Concert 1.0.0 through 2.3.1 could allow a remote attacker to perform unauthorized actions using man in the middle techniques due to improper certificate validation.
CVE-2026-16821 1 Ibm 2 Aix, Vios 2026-09-02 N/A 7.0 HIGH
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to a format string vulnerability.
CVE-2026-3627 2 Ibm, Linux 2 Concert, Linux Kernel 2026-09-02 N/A 9.1 CRITICAL
IBM Concert 1.0.0 through 2.3.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
CVE-2026-0992 3 Ibm, Redhat, Xmlsoft 7 Aix, Vios, Enterprise Linux and 4 more 2026-09-01 N/A 2.9 LOW
A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated <nextCatalog> elements pointing to the same downstream catalog. A remote attacker can exploit this by supplying crafted catalogs, causing the parser to redundantly traverse catalog chains. This leads to excessive CPU consumption and degrades application availability, resulting in a denial-of-service condition.
CVE-2026-0989 3 Ibm, Redhat, Xmlsoft 7 Aix, Vios, Enterprise Linux and 4 more 2026-09-01 N/A 3.7 LOW
A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested <include> directives. Specially crafted or overly complex schemas can cause excessive recursion during parsing. This may lead to stack exhaustion and application crashes, creating a denial-of-service risk.
CVE-2026-0990 3 Ibm, Redhat, Xmlsoft 7 Aix, Vios, Enterprise Linux and 4 more 2026-09-01 N/A 5.9 MEDIUM
A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A remote attacker could exploit this configuration-dependent issue by providing a specially crafted XML catalog, leading to infinite recursion and call stack exhaustion. This ultimately results in a segmentation fault, causing a Denial of Service (DoS) by crashing affected applications.