Filtered by vendor Ibm
Subscribe
Total
8801 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-78573 | 1 Ibm | 1 Contextforge | 2026-09-16 | N/A | 9.8 CRITICAL |
| IBM ContextForge MCP Gateway 1.0.0 through 1.0.7 could allow a remote attacker to gain administrative access due to the use of default credentials. | |||||
| CVE-2026-80436 | 1 Ibm | 1 Datastage On Cloud Pak For Data | 2026-09-16 | N/A | 8.5 HIGH |
| IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service by deleting arbitrary RabbitMQ queues or exchanges due to improper authorization. | |||||
| CVE-2026-80434 | 1 Ibm | 1 Datastage On Cloud Pak For Data | 2026-09-16 | N/A | 7.4 HIGH |
| IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to manipulate runtime caches and cause a denial of service due to an insecure direct object reference. | |||||
| CVE-2026-80424 | 1 Ibm | 1 Datastage On Cloud Pak For Data | 2026-09-16 | N/A | 9.1 CRITICAL |
| IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to create arbitrary files due to path traversal during archive extraction. | |||||
| CVE-2026-80380 | 1 Ibm | 1 Datastage On Cloud Pak For Data | 2026-09-16 | N/A | 7.1 HIGH |
| IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote attacker to perform unauthorized actions due to cross-site request forgery. | |||||
| CVE-2026-80378 | 1 Ibm | 1 Datastage On Cloud Pak For Data | 2026-09-16 | N/A | 8.5 HIGH |
| IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to improper authorization. | |||||
| CVE-2026-81210 | 1 Ibm | 1 Datastage On Cloud Pak For Data | 2026-09-16 | N/A | 7.7 HIGH |
| IBM DataStage on Cloud Pak for Data 5.4.0.0 concatenates three caller-supplied strings into a String.format path on the shared /ds-storage RWX PVC and returns the file with no project ACL — pure IDOR plus traversal. Read is constrained to files named job.log/error.log, but DataStage job logs routinely carry connection strings, {dsnextenc} ciphertexts (decryptable via d2-f023), and customer-data row samples. This is the operator's tenant-to-tenant PVC-leakage threat verbatim; MEDIUM→HIGH via threat match. | |||||
| CVE-2026-81207 | 1 Ibm | 1 Datastage On Cloud Pak For Data | 2026-09-16 | N/A | 8.5 HIGH |
| IBM DataStage on Cloud Pak for Data 5.4.0.0 allows any authenticated tenant — with no project membership or role — fully controls scheme/host/port/path of an outbound fetch originating from a shared-infrastructure pod, and the WSDL body is reflected verbatim to the caller. The ds-canvas pod sits on the OpenShift overlay with reach to co-tenant services, in-cluster CP4D APIs, and link-local addresses. Scope is Changed, confidentiality High (response-reflecting), integrity Low (GET-only side-effects). | |||||
| CVE-2026-81540 | 1 Ibm | 1 Datastage On Cloud Pak For Data | 2026-09-16 | N/A | 8.5 HIGH |
| IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to overwrite ruleset files belonging to other tenants due to a path traversal vulnerability. | |||||
| CVE-2026-81550 | 1 Ibm | 1 Datastage On Cloud Pak For Data | 2026-09-16 | N/A | 8.8 HIGH |
| IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command. | |||||
| CVE-2026-81554 | 1 Ibm | 1 Datastage On Cloud Pak For Data | 2026-09-16 | N/A | 8.8 HIGH |
| IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability. | |||||
| CVE-2026-81551 | 1 Ibm | 1 Datastage On Cloud Pak For Data | 2026-09-16 | N/A | 8.8 HIGH |
| IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to arbitrarily write to or delete files on shared storage due to a path traversal vulnerability. | |||||
| CVE-2026-82092 | 1 Ibm | 1 Datastage On Cloud Pak For Data | 2026-09-16 | N/A | 8.8 HIGH |
| IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability. | |||||
| CVE-2026-82095 | 1 Ibm | 1 Datastage On Cloud Pak For Data | 2026-09-16 | N/A | 8.8 HIGH |
| IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command. | |||||
| CVE-2026-82097 | 1 Ibm | 1 Datastage On Cloud Pak For Data | 2026-09-16 | N/A | 8.8 HIGH |
| IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to a Server-Side Request Forgery (SSRF) vulnerability. | |||||
| CVE-2026-82098 | 1 Ibm | 1 Datastage On Cloud Pak For Data | 2026-09-16 | N/A | 8.8 HIGH |
| IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. | |||||
| CVE-2026-82099 | 1 Ibm | 1 Datastage On Cloud Pak For Data | 2026-09-16 | N/A | 8.8 HIGH |
| IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command. | |||||
| CVE-2026-82100 | 1 Ibm | 1 Datastage On Cloud Pak For Data | 2026-09-16 | N/A | 9.6 CRITICAL |
| IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to a path traversal vulnerability. | |||||
| CVE-2026-82107 | 1 Ibm | 1 Datastage On Cloud Pak For Data | 2026-09-16 | N/A | 9.6 CRITICAL |
| IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to improper authentication. | |||||
| CVE-2026-9176 | 1 Ibm | 1 Websphere Application Server | 2026-09-15 | N/A | 6.7 MEDIUM |
| IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a security bypass due to improper authentication controls. A local attacker could exploit this vulnerability to escalate privileges and gain unauthorized access to protected resources. | |||||
