Ibm
13,901 known vulnerabilities
Top Products
A vulnerability has been identified in tasks, backend object generated for handling any action performed by the applicat
A vulnerability has been identified in IBM Cloud Orchestrator services/[action]/launch API. An authenticated domain admi
IBM InfoSphere Information Server could allow a local user under special circumstances to execute commands during instal
IBM WebSphere eXtreme Scale and the WebSphere DataPower XC10 Appliance allow some sensitive data to linger in memory ins
IBM Security Directory Server could allow an authenticated user to execute commands into the web administration tool tha
IBM Rational DOORS Next Generation 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows us
IBM Rational DOORS Next Generation 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows use
IBM Rational DOORS Next Generation 5.0 and 6.0 discloses sensitive information in error response messages that could be
IBM Rational Team Concert 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to emb
An unspecified vulnerability in IBM Jazz Team Server may disclose some deployment information to an authenticated user.
The IBM Security Access Manager appliance includes configuration files that contain obfuscated plaintext-passwords which
IBM Domino 9.0.1 Fix Pack 3 Interim Fix 2 through 9.0.1 Fix Pack 5 Interim Fix 1, when using TLS and AES GCM, uses rando
IBM Tivoli Key Lifecycle Manager 2.5, and 2.6 could allow a remote attacker to upload arbitrary files, caused by the imp
IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 allows web pages to be stored locally which can be read by another
IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 is vulnerable to cross-site scripting. This vulnerability allows us
IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 generates an error message that includes sensitive information abou
IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 stores user credentials in plain in clear text which can be read by
IBM Security Access Manager for Web 7.0.0, 8.0.0, and 9.0.0 could allow a remote attacker to bypass security restriction
IBM AIX 6.1, 7.1, and 7.2 could allow a local user to exploit a vulnerability in the bellmail binary to gain root privil
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 could allow a remote attacker to obtain sensitive information, caused by th
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 is vulnerable to cross-site request forgery which could allow an attacker t
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 discloses sensitive information to unauthorized users. The information can
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 uses an inadequate account lockout setting that could allow a remote attack
IBM Jazz for Service Management could allow a remote attacker to obtain sensitive information, caused by the failure to
IBM Security Identity Manager Virtual Appliance stores user credentials in plain in clear text which can be read by a lo
IBM Security Identity Manager Virtual Appliance is vulnerable to cross-site scripting. This vulnerability allows users t
IBM Security Identity Manager Virtual Appliance does not invalidate session tokens which could allow an unauthorized use
IBM UrbanCode Deploy could allow a malicious user to access the Agent Relay ActiveMQ Broker JMX interface and run plugin
IBM InfoSphere DataStage is vulnerable to cross-frame scripting, caused by insufficient HTML iframe protection. A remote
IBM InfoSphere Information Server contains a Path-relative stylesheet import vulnerability that allows attackers to rend
IBM InfoSphere Information Server stores sensitive information in URL parameters. This may lead to information disclosur
IBM BigFix Inventory v9 could disclose sensitive information to an unauthorized user using HTTP GET requests. This infor
IBM BigFix Inventory v9 stores potentially sensitive information in log files that could be read by a local user.
IBM UrbanCode Deploy could allow a user to execute code using a specially crafted file upload that would replace code on
IBM Kenexa LMS on Cloud could allow a remote attacker to traverse directories on the system. An attacker could send a sp
IBM Kenexa LMS on Cloud could allow a remote attacker to upload arbitrary files, which could allow the attacker to execu
IBM Kenexa LMS on Cloud could allow a remote attacker to upload arbitrary files, which could allow the attacker to execu
IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, w
IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, w
IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, w
IBM WebSphere Application Server may be vulnerable to a denial of service, caused by allowing serialized objects from un
IBM General Parallel File System is vulnerable to a buffer overflow. A remote authenticated attacker could overflow a bu
IBM Tivoli Storage Manager discloses unencrypted login credentials to Vmware vCenter that could be obtained by a local u
IBM UrbanCode Deploy could allow an authenticated user with access to the REST endpoints to access API and CLI getResour
IBM Forms Experience Builder could be susceptible to a server-side request forgery (SSRF) from the application design in
IBM Sterling Order Management transmits the session identifier within the URL. When a user is unable to view a certain v
IBM Kenexa LMS on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaSc
IBM Kenexa LMS on Cloud could allow a remote attacker to traverse directories on the system. An attacker could send a sp
IBM Kenexa LMS on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaSc
IBM Kenexa LMS on Cloud allows web pages to be stored locally which can be read by another user on the system.
Frequently Asked Questions
How many CVEs affect Ibm?
Ibm has 13,901 CVE records in our database, including 535 critical and 3690 high severity vulnerabilities. 6 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Ibm vulnerabilities?
Ibm has 535 critical severity (CVSS 9.0+) and 3690 high severity (CVSS 7.0-8.9) vulnerabilities. 6 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Ibm vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Ibm products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Ibm Vulnerabilities
CyberStrike scans your infrastructure for Ibm vulnerabilities and provides real-time remediation guidance.
Get Started