Vulnerabilities (CVE)

Filtered by vendor Ibm Subscribe
Total 8131 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-41296 1 Ibm 2 Db2, Db2 Warehouse 2026-02-25 N/A 6.5 MEDIUM
IBM Db2U 3.5, 4.0, and 4.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 237210.
CVE-2023-38010 1 Ibm 2 Cloud Pak System, Os Image For Red Hat Linux Systems 2026-02-25 N/A 5.3 MEDIUM
IBM Cloud Pak System displays sensitive information in user messages that could aid in further attacks against the system.
CVE-2023-38017 1 Ibm 2 Cloud Pak System, Os Image For Red Hat Linux Systems 2026-02-25 N/A 5.3 MEDIUM
IBM Cloud Pak System is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVE-2023-38281 1 Ibm 2 Cloud Pak System, Os Image For Red Hat Linux Systems 2026-02-25 N/A 5.3 MEDIUM
IBM Cloud Pak System does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic.
CVE-2025-27550 1 Ibm 1 Jazz Reporting Service 2026-02-23 N/A 3.5 LOW
IBM Jazz Reporting Service could allow an authenticated user on the host network to obtain sensitive information about other projects that reside on the server.
CVE-2025-2134 1 Ibm 1 Jazz Reporting Service 2026-02-23 N/A 3.5 LOW
IBM Jazz Reporting Service could allow an authenticated user on the network to affect the system's performance using complicated queries due to insufficient resource pooling.
CVE-2023-38265 1 Ibm 1 Cloud Pak System 2026-02-23 N/A 5.3 MEDIUM
IBM Cloud Pak System 2.3.3.6, 2.3.3.7, 2.3.4.0, 2.3.4.1, and 2.3.5.0 could disclose folder location information to an unauthenticated attacker that could aid in further attacks against the system.
CVE-2025-36376 1 Ibm 1 Security Qradar Edr 2026-02-20 N/A 6.3 MEDIUM
IBM Security QRadar EDR 3.12 through 3.12.23 does not invalidate session after a session expiration which could allow an authenticated user to impersonate another user on the system.
CVE-2025-14289 1 Ibm 1 Webmethods Integration Server 2026-02-20 N/A 5.4 MEDIUM
IBM webMethods Integration Server 12.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
CVE-2025-13691 1 Ibm 1 Datastage On Cloud Pak For Data 2026-02-20 N/A 8.1 HIGH
IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 returns sensitive information in an HTTP response that could be used to impersonate other users in the system.
CVE-2025-33130 1 Ibm 1 Db2 Merge Backup 2026-02-20 N/A 6.5 MEDIUM
IBM DB2 Merge Backup for Linux, UNIX and Windows 12.1.0.0 could allow an authenticated user to cause the program to crash due to a buffer being overwritten when it is allocated on the stack.
CVE-2025-36377 1 Ibm 1 Qradar Edr 2026-02-20 N/A 6.3 MEDIUM
IBM Security QRadar EDR 3.12 through 3.12.23 does not invalidate session after a session expiration which could allow an authenticated user to impersonate another user on the system.
CVE-2025-36379 1 Ibm 1 Qradar Edr 2026-02-20 N/A 5.9 MEDIUM
IBM Security QRadar EDR 3.12 through 3.12.23 IBM Security ReaQta uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
CVE-2023-38005 1 Ibm 1 Cloud Pak System 2026-02-20 N/A 4.3 MEDIUM
IBM Cloud Pak System 2.3.3.6, 2.3.3.7, 2.3.4.0, 2.3.4.1, and 2.3.5.0 could allow an authenticated user to perform unauthorized tasks due to improper access controls.
CVE-2025-36183 1 Ibm 1 Watsonx.data 2026-02-20 N/A 3.8 LOW
IBM watsonx.data 2.2 through 2.2.1 IBM Lakehouse could allow a privileged user to upload malicious files that could be executed server to modify limited files or data.
CVE-2025-36348 1 Ibm 2 Sterling B2b Integrator, Sterling File Gateway 2026-02-20 N/A 4.9 MEDIUM
IBM Sterling B2B Integrator versions 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 through 6.2.1.1, and IBM Sterling File Gateway versions 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 through 6.2.1.1 may expose sensitive information to a remote privileged attacker due to the application returning detailed technical error messages in the browser.
CVE-2025-13333 1 Ibm 1 Websphere Application Server 2026-02-20 N/A 4.4 MEDIUM
IBM WebSphere Application Server 9.0, and 8.5 could provide weaker than expected security during system administration of security settings.
CVE-2025-13689 1 Ibm 1 Datastage On Cloud Pak For Data 2026-02-20 N/A 8.8 HIGH
IBM DataStage on Cloud Pak for Data could allow an authenticated user to execute arbitrary commands and gain access to sensitive information due to unrestricted file uploads.
CVE-2025-36194 1 Ibm 1 Powervm Hypervisor 2026-02-19 N/A 2.8 LOW
IBM PowerVM Hypervisor FW1110.00 through FW1110.03, FW1060.00 through FW1060.51, and FW950.00 through FW950.F0 may expose a limited amount of data to a peer partition in specific shared processor configurations during certain operations.
CVE-2025-36238 1 Ibm 1 Powervm Hypervisor 2026-02-19 N/A 6.0 MEDIUM
IBM PowerVM Hypervisor FW1110.00 through FW1110.03, FW1060.00 through FW1060.51, and FW950.00 through FW950.F0 could allow a local user with administration privileges to obtain sensitive information from a Virtual TPM through a series of PowerVM service procedures.