Ibm
13,901 known vulnerabilities
Top Products
IBM QRadar 7.2 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when process
IBM QRadar 7.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code
IBM QRadar 7.2 discloses sensitive information to unauthorized users. The information can be used to mount further attac
IBM Business Process Manager 7.5, 8.0, and 8.5 has a file download capability that is vulnerable to a set of attacks. Ul
IBM WebSphere MQ 8.0 could allow an authenticated user with queue manager permissions to cause a segmentation fault whic
IBM Tivoli Storage Manager (IBM Spectrum Protect) 6.1, 6.2, 6.3, and 7.1 does not perform sufficient authority checking
IBM Kenexa LCMS Premier on Cloud 9.0, and 10.0.0 is vulnerable to SQL injection. A remote attacker could send specially-
IBM Kenexa LCMS Premier on Cloud 9.0, and 10.0.0 is vulnerable to SQL injection. A remote attacker could send specially-
IBM Kenexa LCMS Premier on Cloud 9.0, and 10.0.0 is vulnerable to SQL injection. A remote attacker could send specially-
Document Object Model-(DOM) based cross-site scripting vulnerability in the Advanced Management Module (AMM) versions ea
IBM Connections 4.0, 4.5, 5.0, and 5.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed a
IBM QRadar 7.2 stores the encryption key used to encrypt the service account password which can be obtained by a local u
IBM QRadar 7.2 uses outdated hashing algorithms to hash certain passwords, which could allow a local user to obtain and
IBM Jazz for Service Management 1.1.2.1 and 1.1.3 is vulnerable to cross-site request forgery which could allow an attac
IBM WebSphere MQ 8.0 could allow an authenticated user with authority to create a cluster object to cause a denial of se
IBM Tivoli Storage Manager Server 7.1 could allow an authenticated user with TSM administrator privileges to cause a buf
IBM Rhapsody DM 4.0, 5.0 and 6.0 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE)
IBM Rational DOORS Next Generation 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows us
IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScr
IBM WebSphere MQ 8.0 could allow an authenticated user with access to the queue manager to bring down MQ channels using
IBM WebSphere MQ 8.0 could allow an authenticated user with access to the queue manager and queue, to deny service to ot
Under non-standard configurations, IBM WebSphere MQ might send password data in clear text over the network. This data c
IBM WebSphere MQ 8.0 could allow an authenticated user to crash the MQ channel due to improper data conversion handling.
IBM Resilient v26.0, v26.1, and v26.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed ar
IBM Security Access Manager for Web 7.0.0, 8.0.0, and 9.0.0 uses weaker than expected cryptographic algorithms that coul
IBM Integration Bus 9.0 and 10.0 and WebSphere Message Broker SOAP FLOWS is vulnerable to a denial of service, caused by
IBM WebSphere Message Broker 9.0 and 10.0 could allow a remote attacker to hijack the clicking action of the victim. By
IBM AIX 6.1, 7.1, and 7.2 could allow a local user to gain root privileges using a specially crafted command within the
IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript
IBM AIX 7.1 and 7.2 allows a local user to open a file with a specially crafted argument that would crash the system. IB
IBM AIX 5.3, 6.1, 7.1, and 7.2 contains an unspecified vulnerability that would allow a locally authenticated user to ob
IBM Cognos Disclosure Management 10.2 could allow a malicious attacker to execute commands as a lower privileged user th
An undisclosed vulnerability in IBM Rational DOORS Next Generation 4.0, 5.0, and 6.0 could allow a JazzGuest user to see
IBM Tivoli Storage Manager for Virtual Environments 7.1 (VMware) is vulnerable to cross-site request forgery which could
IBM Websphere MQ JMS 7.0.1, 7.1, 7.5, 8.0, and 9.0 client provides classes that deserialize objects from untrusted sourc
IBM WebSphere Application Server 7.0, 8.0, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows user
IBM System Storage TS3100-TS3200 Tape Library could allow an unauthenticated user with access to the company network, to
IBM dashDB Local uses hard-coded credentials that could allow a remote attacker to gain access to the Docker container o
IBM Tivoli Storage Manager FastBack installer could allow a remote attacker to execute arbitrary code on the system. By
IBM Tivoli Storage Manager HSM for Windows displays the encrypted Tivoli Storage Manager password in application trace o
IBM Maximo Asset Management is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Ja
IBM Tealeaf Customer Experience on Cloud Network Capture Add-On could allow a remote attacker to obtain sensitive inform
IBM Connections 5.5 and earlier is vulnerable to possible host header injection attack that could cause navigation to th
IBM Connections 5.5 and earlier is vulnerable to possible link manipulation attack that could result in the display of i
IBM Connections 5.5 and earlier allows remote attackers to obtain sensitive information by reading stack traces in retur
IBM Connections is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote at
IBM Tivoli Endpoint Manager could allow a remote attacker to upload arbitrary files. A remote attacker could exploit thi
IBM Sterling B2B Integrator Standard Edition could allow a remote attacker to obtain sensitive information. By allowing
IBM Cloud Orchestrator could allow a local authenticated attacker to cause the server to slow down for a short period of
A vulnerability has been identified in the IBM Cloud Orchestrator task API. The task API might allow an authenticated us
Frequently Asked Questions
How many CVEs affect Ibm?
Ibm has 13,901 CVE records in our database, including 535 critical and 3690 high severity vulnerabilities. 6 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Ibm vulnerabilities?
Ibm has 535 critical severity (CVSS 9.0+) and 3690 high severity (CVSS 7.0-8.9) vulnerabilities. 6 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Ibm vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Ibm products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Ibm Vulnerabilities
CyberStrike scans your infrastructure for Ibm vulnerabilities and provides real-time remediation guidance.
Get Started