Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

IBM — Vulnerabilities & Security Advisories 5248

Browse all 5248 CVE security advisories affecting IBM. AI-powered Chinese analysis, POCs, and references for each vulnerability.

IBM operates as a multinational technology and consulting corporation, primarily providing enterprise software, hybrid cloud services, and artificial intelligence solutions. Its extensive portfolio, including the Red Hat OpenShift platform and Watson AI suite, creates a broad attack surface that has historically been associated with Remote Code Execution (RCE) vulnerabilities, particularly within web application frameworks and middleware. Cross-site scripting (XSS) and privilege escalation flaws also frequently appear in its legacy enterprise applications and containerized environments. While the company maintains robust security protocols, past incidents have included data breaches affecting customer information and supply chain compromises. The high volume of recorded Common Vulnerabilities and Exposures (CVEs) reflects the complexity and scale of its global infrastructure rather than inherent systemic failure, though it necessitates rigorous patch management and continuous monitoring for enterprise clients relying on its diverse technological stack.

CVE ID Title CVSS Severity Published
CVE-2020-4897 IBM Emptoris Contract Management and IBM Emptoris Spend Analysis 安全漏洞 — Emptoris Contract Management 5.3 - 2021-01-07
CVE-2020-4895 IBM Emptoris Strategic Supply Management 跨站脚本漏洞 — Emptoris Sourcing 5.4 - 2021-01-07
CVE-2020-4896 IBM Emptoris Sourcing 环境问题漏洞 — Emptoris Sourcing 6.5 - 2021-01-07
CVE-2020-4893 IBM Emptoris Strategic Supply Management 信息泄露漏洞 — Emptoris Strategic Supply Management 5.9 - 2021-01-07
CVE-2020-4892 IBM Emptoris Contract Management 跨站脚本漏洞 — Emptoris Contract Management 5.4 - 2021-01-07
CVE-2020-4336 IBM WebSphere eXtreme Scale 信息泄露漏洞 — WebSphere eXtreme Scale 3.7 - 2021-01-06
CVE-2020-4899 IBM API Connect 安全漏洞 — API Connect 9.1 - 2021-01-05
CVE-2020-4762 IBM Sterling B2B Integrator 安全漏洞 — Sterling B2B Integrator 8.8 - 2021-01-05
CVE-2019-4728 IBM Sterling B2B Integrator 代码问题漏洞 — Sterling B2B Integrator 8.8 - 2021-01-05
CVE-2020-4761 IBM Sterling B2B Integrator 信息泄露漏洞 — Sterling B2B Integrator 5.3 - 2021-01-05
CVE-2020-4942 IBM Cúram Social Program Management 跨站请求伪造漏洞 — Curam SPM 8.8 - 2021-01-04
CVE-2020-4928 IBM Cloud Pak System 代码问题漏洞 — Cloud Pak System 6.7 - 2021-01-04
CVE-2020-4918 IBM Cloud Pak System 代码问题漏洞 — Cloud Pak System 4.4 - 2021-01-04
CVE-2020-4919 IBM Cloud Pak System 安全漏洞 — Cloud Pak System 6.5 - 2021-01-04
CVE-2020-4917 IBM Cloud Pak System 跨站请求伪造漏洞 — Cloud Pak System 8.8 - 2021-01-04
CVE-2020-4913 IBM Cloud Pak System 信息泄露漏洞 — Cloud Pak System 4.4 - 2021-01-04
CVE-2020-4916 IBM Cloud Pak System 跨站脚本漏洞 — Cloud Pak System 4.8 - 2021-01-04
CVE-2020-4912 IBM Cloud Pak System 安全漏洞 — Cloud Pak System 7.2 - 2021-01-04
CVE-2020-4910 IBM Cloud Pak System 跨站脚本漏洞 — Cloud Pak System 4.8 - 2021-01-04
CVE-2020-4909 IBM Cloud Pak System 跨站脚本漏洞 — Cloud Pak System 4.8 - 2021-01-04
CVE-2020-4642 IBM DB2 安全漏洞 — DB2 for Linux- UNIX and Windows 5.5 - 2020-12-23
CVE-2020-4843 IBM Security Secret Server 信息泄露漏洞 — Security Secret Server 4.3 - 2020-12-21
CVE-2020-4841 IBM Security Secret Server 信息泄露漏洞 — Security Secret Server 5.9 - 2020-12-21
CVE-2020-4842 IBM Security Secret Server 信息泄露漏洞 — Security Secret Server 5.3 - 2020-12-21
CVE-2020-4840 IBM Security Secret Server 输入验证错误漏洞 — Security Secret Server 6.1 - 2020-12-21
CVE-2020-4870 IBM MQ 安全漏洞 — MQ 6.5 - 2020-12-21
CVE-2020-4794 IBM多款产品授权问题漏洞 — Automation Workstream Services 5.4 - 2020-12-21
CVE-2020-4757 IBM Content Navigator和IBM FileNet Content Manager 跨站脚本漏洞 — Content Navigator 5.4 - 2020-12-21
CVE-2020-4555 IBM Financial Transaction Manager 授权问题漏洞 — Financial Transaction Manager 8.3 - 2020-12-21
CVE-2020-4764 IBM Planning Analytics 跨站请求伪造漏洞 — Planning Analytics 8.8 - 2020-12-18

This page lists every published CVE security advisory associated with IBM. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.