IBM Cloud Pak for Data System是美国国际商业机器(IBM)公司的一个企业数据与AI一体化平台。 IBM Cloud Pak for Data System 11.3.0.2版本至Interim Fix 002版本存在SQL注入漏洞,该漏洞源于容易受到SQL注入攻击,可能导致远程攻击者发送特制SQL语句,从而查看、添加、修改或删除后端数据库中的信息。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| IBM | Cloud Pak for Data System - Cyclops | 11.3.0.2≤ Interim Fix 002 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| IBM | Cloud Pak for Data System - Cyclops | 11.3.0.2 ~ Interim Fix 002 |
cpe:2.3:a:ibm:cloud_pak_for_data_system___cyclops:11.3.0.2:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-3660 | 9.8 CRITICAL | IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to Authentication Byp |
| CVE-2026-8633 | 9.8 CRITICAL | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by |
| CVE-2026-8855 | 8.1 HIGH | IBM HTTP Server is affected by multiple vulnerabilities |
| CVE-2026-8834 | 8.0 HIGH | IBM HTTP Server is affected by multiple vulnerabilities |
| CVE-2026-8856 | 7.7 HIGH | IBM HTTP Server is affected by multiple vulnerabilities |
| CVE-2026-8854 | 7.5 HIGH | IBM HTTP Server is affected by multiple vulnerabilities |
| CVE-2026-8620 | 7.5 HIGH | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by |
| CVE-2026-8850 | 7.5 HIGH | IBM HTTP Server is affected by multiple vulnerabilities |
| CVE-2026-8835 | 7.3 HIGH | IBM HTTP Server is affected by multiple vulnerabilities |
| CVE-2026-4051 | 7.2 HIGH | IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to Server Post-Auth R |
| CVE-2026-3603 | 7.1 HIGH | IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to XML external entit |
| CVE-2025-36126 | 6.4 MEDIUM | IBM Cognos Analytics is affected by Cross-site scripting. |
| CVE-2026-8852 | 6.2 MEDIUM | IBM HTTP Server is affected by multiple vulnerabilities |
| CVE-2025-13755 | 5.5 MEDIUM | IBM® Db2® is vulnerable to credential exposure in db2diag when executing specific testcase |
| CVE-2025-36148 | 5.4 MEDIUM | IBM Financial Transaction Manager for SWIFT Services for Multiplatforms is vulnerable to c |
| CVE-2025-36145 | 5.4 MEDIUM | Multiple Vulnerabilities in watsonx.data |
| CVE-2025-14290 | 5.4 MEDIUM | IBM webMethods Integration Sever is vulnerable to server-side request forgery |
| CVE-2025-36221 | 5.3 MEDIUM | Vulnerabilities exists in IBM Cloud Pak for Data System (CPDS 1.0) - Cyclops. |
| CVE-2026-9170 | IBM HTTP Server is affected by multiple vulnerabilities |
No comments yet