Filtered by vendor Ibm
Subscribe
Total
8310 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-36170 | 1 Ibm | 1 Qradar Security Information And Event Manager | 2026-06-17 | N/A | 6.4 MEDIUM |
| IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 13 Independent Fix 02 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |||||
| CVE-2025-36162 | 1 Ibm | 1 Devops Deploy | 2026-06-17 | N/A | 4.3 MEDIUM |
| IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) 8.1 before 8.1.2.2 could allow an authenticated user to obtain sensitive information about configuration on the system. | |||||
| CVE-2025-36161 | 2 Ibm, Linux | 2 Concert, Linux Kernel | 2026-06-17 | N/A | 5.9 MEDIUM |
| IBM Concert 1.0.0 through 2.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict-Transport-Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. | |||||
| CVE-2025-36160 | 1 Ibm | 1 Concert | 2026-06-17 | N/A | 5.3 MEDIUM |
| IBM Concert 1.0.0 through 2.0.0 could disclose sensitive server information from HTTP response headers that could aid in further attacks against the system. | |||||
| CVE-2025-36159 | 1 Ibm | 1 Concert | 2026-06-17 | N/A | 6.2 MEDIUM |
| IBM Concert 1.0.0 through 2.0.0 could allow a local user to forge log files to impersonate other users or hide their identity due to improper neutralization of output. | |||||
| CVE-2025-36158 | 1 Ibm | 1 Concert | 2026-06-17 | N/A | 5.1 MEDIUM |
| IBM Concert 1.0.0 through 2.0.0 could allow a local user with specific permission to obtain sensitive information from files due to uncontrolled recursive directory copying. | |||||
| CVE-2025-36157 | 1 Ibm | 1 Jazz Foundation | 2026-06-17 | N/A | 9.8 CRITICAL |
| IBM Jazz Foundation 7.0.2 to 7.0.2 iFix035, 7.0.3 to 7.0.3 iFix018, and 7.1.0 to 7.1.0 iFix004 could allow an unauthenticated remote attacker to update server property files that would allow them to perform unauthorized actions. | |||||
| CVE-2025-36156 | 1 Ibm | 1 Infosphere Data Replication Vsam For Z\/os Remote Source | 2026-06-17 | N/A | 7.4 HIGH |
| IBM InfoSphere Data Replication VSAM for z/OS Remote Source 11.4 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local user with access to the files storing CECSUB or CECRM on the container could overflow the buffer and execute arbitrary code on the system. | |||||
| CVE-2025-36154 | 1 Ibm | 1 Concert | 2026-06-17 | N/A | 6.2 MEDIUM |
| IBM Concert 1.0.0 through 2.1.0 stores sensitive information in cleartext during recursive docker builds which could be obtained by a local user. | |||||
| CVE-2025-36153 | 1 Ibm | 1 Concert | 2026-06-17 | N/A | 6.1 MEDIUM |
| IBM Concert 1.0.0 through 2.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |||||
| CVE-2025-36150 | 1 Ibm | 1 Concert | 2026-06-17 | N/A | 5.9 MEDIUM |
| IBM Concert 1.0.0 through 2.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. | |||||
| CVE-2025-36149 | 1 Ibm | 1 Concert | 2026-06-17 | N/A | 6.3 MEDIUM |
| IBM Concert Software 1.0.0 through 2.0.0 could allow a remote attacker to hijack the clicking action of the victim. | |||||
| CVE-2025-36148 | 1 Ibm | 1 Financial Transaction Manager For Multiplatform | 2026-06-17 | N/A | 5.4 MEDIUM |
| IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.15 IBM Financial Transaction Manager SWIFT is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |||||
| CVE-2025-36146 | 1 Ibm | 1 Watsonx.data | 2026-06-17 | N/A | 4.3 MEDIUM |
| IBM Lakehouse (watsonx.data 2.2) could allow an authenticated user to obtain sensitive server component version information which could aid in further attacks against the system. | |||||
| CVE-2025-36145 | 1 Ibm | 1 Watsonx.data | 2026-06-17 | N/A | 5.4 MEDIUM |
| IBM watsonx.data 2.2 through 2.3.1 IBM Lakehouse does not properly restrict inbound and outbound connections which could allow an attacker to transfer or modify files without restrictions. | |||||
| CVE-2025-36144 | 1 Ibm | 1 Watsonx.data | 2026-06-17 | N/A | 3.3 LOW |
| IBM Lakehouse (watsonx.data 2.2) stores potentially sensitive information in log files that could be read by a local user. | |||||
| CVE-2025-36143 | 1 Ibm | 1 Watsonx.data | 2026-06-17 | N/A | 4.7 MEDIUM |
| IBM Lakehouse (watsonx.data 2.2) could allow an authenticated privileged user to execute arbitrary commands on the system due to improper validation of user supplied input. | |||||
| CVE-2025-36140 | 1 Ibm | 1 Watsonx.data | 2026-06-17 | N/A | 6.5 MEDIUM |
| IBM watsonx.data 2.2 through 2.2.1 could allow an authenticated user to cause a denial of service through ingestion pods due to improper allocation of resources without limits. | |||||
| CVE-2025-36139 | 1 Ibm | 1 Watsonx.data | 2026-06-17 | N/A | 5.5 MEDIUM |
| IBM Lakehouse (watsonx.data 2.2) is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |||||
| CVE-2025-36138 | 1 Ibm | 1 Qradar Security Information And Event Manager | 2026-06-17 | N/A | 6.4 MEDIUM |
| IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 13 Independent Fix 02 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |||||
