Ibm
13,901 known vulnerabilities
Top Products
IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in
IBM Infosphere BigInsights is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav
IBM UrbanCode Deploy could allow an authenticated attacker with special permissions to craft a script on the server in a
IBM UrbanCode Deploy creates temporary files during step execution that could contain sensitive information including pa
IBM Infosphere BigInsights is vulnerable to cross-site scripting, caused by improper validation of user-supplied input.
IBM UrbanCode Deploy could allow an authenticated user to modify Ucd objects due to multiple REST endpoints not properly
IBM Cognos Business Intelligence and IBM Cognos Analytics are vulnerable to cross-site scripting, caused by improper val
IBM Cognos Business Intelligence and IBM Cognos Analytics are vulnerable to stored cross-site scripting, caused by impro
IBM BigFix Inventory v9 9.2 stores user credentials in plain in clear text which can be read by a local user.
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 can be deployed with active debugging code that can disclose sensitive info
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 do not perform an authentication check for a critical resource or functiona
The Tivoli Storage Manager (TSM) password may be displayed in plain text via application trace output while application
IBM Business Process Manager is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary J
IBM BigFix Inventory v9 allows web pages to be stored locally which can be read by another user on the system.
IBM BigFix Inventory v9 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error whe
IBM BigFix Inventory v9 could allow a remote attacker to obtain sensitive information, caused by the failure to properly
IBM BigFix Inventory v9 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By per
IBM Tivoli Storage Productivity Center is vulnerable to cross-site scripting. This vulnerability allows users to embed a
IBM Tivoli Storage Productivity Center could allow an authenticated user with intimate knowledge of the system to edit a
IBM Tivoli Storage Productivity Center is vulnerable to cross-site request forgery which could allow an attacker to exec
IBM Social Rendering Templates for Digital Data Connector is vulnerable to cross-site scripting. This vulnerability allo
IBM WebSphere Application Server is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra
Exphox WebRadar is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript cod
IBM FileNet WorkPlace XT could allow a remote attacker to upload arbitrary files, which could allow the attacker to exec
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to
IBM Integration Bus, under non default configurations, could allow a remote user to authenticate without providing valid
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to traverse directories on the system. An a
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 stores potentially sensitive information in in log files that could be re
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to hijack the clicking action of the victim
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to traverse directories on the system. An a
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to upload arbitrary files, which could allo
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 discloses answers to security questions in a response to authenticated us
IBM Verse is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t
IBM WebSphere Commerce contains an unspecified vulnerability that could allow disclosure of user personal data, performi
IBM BigFix Platform could allow an attacker on the local network to crash the BES and relay servers.
IBM BigFix Platform could allow an attacker on the local network to crash the BES server using a specially crafted XMLSc
IBM BigFix Platform could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free ra
The WebAdmin context for WebSphere Message Broker allows directory listings which could disclose sensitive information t
IBM Maximo Asset Management is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Ja
IBM Security Guardium Database Activity Monitor appliance could allow a local user to inject commands that would be exec
IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript
IBM InfoSphere Information Server is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE)
IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript
IBM Jazz Reporting Service (JRS) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra
IBM Tivoli Storage Manager Operations Center is vulnerable to cross-site scripting. This vulnerability allows users to e
IBM Tivoli Storage Manager Operations Center is vulnerable to cross-site request forgery which could allow an attacker t
IBM Tivoli Storage Manager Operations Center could allow an authenticated attacker to enable or disable the application'
Tivoli Storage Manager Operations Center could allow a local user to take over a previously logged in user due to sessio
Frequently Asked Questions
How many CVEs affect Ibm?
Ibm has 13,901 CVE records in our database, including 535 critical and 3690 high severity vulnerabilities. 6 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Ibm vulnerabilities?
Ibm has 535 critical severity (CVSS 9.0+) and 3690 high severity (CVSS 7.0-8.9) vulnerabilities. 6 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Ibm vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Ibm products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Ibm Vulnerabilities
CyberStrike scans your infrastructure for Ibm vulnerabilities and provides real-time remediation guidance.
Get Started