Filtered by vendor Ibm
Subscribe
Total
8310 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-3144 | 1 Ibm | 1 Api Connect | 2026-07-10 | N/A | 8.1 HIGH |
| IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized access to the application before the system enforces a credential update. | |||||
| CVE-2026-9074 | 1 Ibm | 1 Api Connect | 2026-07-10 | N/A | 9.1 CRITICAL |
| IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection vulnerability in the password reset functionality. | |||||
| CVE-2026-9072 | 1 Ibm | 1 I | 2026-07-09 | N/A | 8.1 HIGH |
| IBM WebSphere Application Server and IBM WebSphere Application Server Liberty - when using Intelligent Management with the WebSphere WebServer Plug-in component - are vulnerable to remote code execution and denial of service. This vulnerability can be exploited when an attacker impersonates backend servers and sends crafted responses to the plug-in. | |||||
| CVE-2026-8858 | 1 Ibm | 1 I | 2026-07-09 | N/A | 7.5 HIGH |
| IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to remote code execution and denial of service in the WebSphere Web Server Plug-in component. This vulnerability can be exploited when an attacker impersonates the application server and sends crafted responses to the plug-in. | |||||
| CVE-2026-10852 | 1 Ibm | 1 I | 2026-07-09 | N/A | 5.9 MEDIUM |
| IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to denial of service in the WebSphere WebServer Plug-in component when an attacker can pass crafted requests to the web server. | |||||
| CVE-2025-36359 | 1 Ibm | 2 Devops Automation, Devops Loop | 2026-07-06 | N/A | 8.1 HIGH |
| IBM DevOps Automation 1.0.1 and IBM DevOps Loop 1.0.2 does not invalidate session IDs after expiration which could allow an authenticated user to impersonate another user on the system. | |||||
| CVE-2025-12530 | 1 Ibm | 2 Software Hub, Watsonx.data Intelligence | 2026-07-06 | N/A | 5.9 MEDIUM |
| IBM watsonx.data intelligence 5.2.2, 5.3.0, 5.3.1, 5.3.1 through patch-1 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques. | |||||
| CVE-2025-36319 | 1 Ibm | 2 Software Hub, Watsonx.data Intelligence | 2026-07-06 | N/A | 4.3 MEDIUM |
| IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow an authenticated user to cause a temporary denial using a specially crafted HTTP request due to improper allocation of resource throttling. | |||||
| CVE-2025-36320 | 1 Ibm | 2 Software Hub, Watsonx.data Intelligence | 2026-07-06 | N/A | 6.4 MEDIUM |
| IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |||||
| CVE-2025-36321 | 1 Ibm | 2 Software Hub, Watsonx.data Intelligence | 2026-07-06 | N/A | 5.7 MEDIUM |
| IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. | |||||
| CVE-2025-36323 | 1 Ibm | 2 Software Hub, Watsonx.data Intelligence | 2026-07-06 | N/A | 5.4 MEDIUM |
| IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |||||
| CVE-2025-36324 | 1 Ibm | 2 Software Hub, Watsonx.data Intelligence | 2026-07-06 | N/A | 4.3 MEDIUM |
| IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 s vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. | |||||
| CVE-2025-36327 | 1 Ibm | 2 Software Hub, Watsonx.data Intelligence | 2026-07-06 | N/A | 6.5 MEDIUM |
| IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow an authenticated user to bypass security controls and perform unauthorized actions due to client-side enforcement of sever-side security. | |||||
| CVE-2025-36328 | 1 Ibm | 2 Software Hub, Watsonx.data Intelligence | 2026-07-06 | N/A | 4.3 MEDIUM |
| IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. | |||||
| CVE-2025-36333 | 1 Ibm | 2 Software Hub, Watsonx.data Intelligence | 2026-07-06 | N/A | 4.3 MEDIUM |
| IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow an authenticated user to perform unauthorized actions due to the improper enforcement of behavioral workflow. | |||||
| CVE-2025-36336 | 1 Ibm | 2 Software Hub, Watsonx.data Intelligence | 2026-07-06 | N/A | 5.9 MEDIUM |
| IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques. | |||||
| CVE-2026-13772 | 1 Ibm | 1 Websphere Extreme Scale | 2026-07-03 | N/A | 7.5 HIGH |
| IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 's Object Query Language engine resolves attacker-supplied class names via Class.forName() and invokes their constructors with no allow-list at three distinct sinks (SELECT NEW, enum literals, and reflection-based comparators); an authenticated remote attacker who can influence an application-built OQL query string can execute arbitrary constructors on the WAS JVM, and a SELECT DISTINCT variant using planted grid values fires the same gadget post-readObject in a manner that survives JEP-290 serialization filters across grid node boundaries | |||||
| CVE-2026-13759 | 1 Ibm | 1 Websphere Extreme Scale | 2026-07-03 | N/A | 7.5 HIGH |
| IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 ships three ObjectInputStream subclasses (WsObjectInputStream, ObjectStreamPool$ReusableInputStream, ObjectInputStreamResolver) that install no JEP-290 class filter; when Coherence is on the classpath, multiple RCE gadget chains including RemoteConstructor.readResolve and PriorityQueue/ExtractorComparator are confirmed working, allowing a post-login attacker who can write a session attribute or a LAN-adjacent attacker on the grid replication wire to execute arbitrary code on peer WAS JVMs | |||||
| CVE-2026-9002 | 1 Ibm | 1 Websphere Extreme Scale | 2026-07-02 | N/A | 6.5 MEDIUM |
| IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 could allow an adjacent attacker to cause a denial of service due to improper validation in the XDF decoder. The application processes deeply nested Protocol Buffers messages and attacker-controlled length prefixes without sufficient bounds checking, which may allow an attacker on the same network to trigger a StackOverflowError or OutOfMemoryError, resulting in a crash of the WebSphere Application Server JVM. | |||||
| CVE-2026-9836 | 1 Ibm | 1 Infosphere Information Server | 2026-07-02 | N/A | 3.5 LOW |
| IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is affected by an information disclosure vulnerability. | |||||
