Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

IBM — Vulnerabilities & Security Advisories 5232

Browse all 5232 CVE security advisories affecting IBM. AI-powered Chinese analysis, POCs, and references for each vulnerability.

IBM operates as a multinational technology and consulting corporation, primarily providing enterprise software, hybrid cloud services, and artificial intelligence solutions. Its extensive portfolio, including the Red Hat OpenShift platform and Watson AI suite, creates a broad attack surface that has historically been associated with Remote Code Execution (RCE) vulnerabilities, particularly within web application frameworks and middleware. Cross-site scripting (XSS) and privilege escalation flaws also frequently appear in its legacy enterprise applications and containerized environments. While the company maintains robust security protocols, past incidents have included data breaches affecting customer information and supply chain compromises. The high volume of recorded Common Vulnerabilities and Exposures (CVEs) reflects the complexity and scale of its global infrastructure rather than inherent systemic failure, though it necessitates rigorous patch management and continuous monitoring for enterprise clients relying on its diverse technological stack.

CVE ID Title CVSS Severity Published
CVE-2026-11594 IBM WebSphere Application Server is affected by multiple cross-site scripting vulnerabilities — WebSphere Application Server CWE-79 8.5 High 2026-06-30
CVE-2025-12530 Vulnerabilities found in Watson Data Intelligence — watsonx.data intelligence CWE-319 5.9 Medium 2026-06-30
CVE-2025-36319 Vulnerabilities found in Watson Data Intelligence — watsonx.data intelligence CWE-770 4.3 Medium 2026-06-30
CVE-2025-36320 Vulnerabilities found in Watson Data Intelligence — watsonx.data intelligence CWE-79 6.4 Medium 2026-06-30
CVE-2025-36321 Vulnerabilities found in Watson Data Intelligence — watsonx.data intelligence CWE-80 5.7 Medium 2026-06-30
CVE-2025-36323 Vulnerabilities found in Watson Data Intelligence — watsonx.data intelligence CWE-79 5.4 Medium 2026-06-30
CVE-2025-36324 Vulnerabilities found in Watson Data Intelligence — watsonx.data intelligence CWE-918 4.3 Medium 2026-06-30
CVE-2025-36327 Vulnerabilities found in Watson Data Intelligence — watsonx.data intelligence CWE-602 6.5 Medium 2026-06-30
CVE-2025-36328 Error Message Containing Sensitive Information found in Watson Data Intelligence — watsonx.data intelligence CWE-209 4.3 Medium 2026-06-30
CVE-2025-36333 Vulnerabilities found in Watson Data Intelligence — watsonx.data intelligence CWE-841 4.3 Medium 2026-06-30
CVE-2025-36336 Cleartext Transmission of Sensitive Information in Watson Data Intelligence — watsonx.data intelligence CWE-319 5.9 Medium 2026-06-30
CVE-2025-36359 IBM DevOps Loop is susceptible to an Insufficient Session Expiration vulnerability. — DevOps Automation CWE-613 8.1 High 2026-06-30
CVE-2025-36372 IBM® Db2® could disclose sensitive information to an authenticated user from the monitoring and event tables — Db2 CWE-538 5.5 Medium 2026-06-30
CVE-2026-10109 IBM® Db2® is vulnerable to remote code execution due to improper pre-auth DRDA handshake handling — Db2 CWE-94 9.8 Critical 2026-06-30
CVE-2026-10129 SSRF via HTTP Redirect Following in Langflow API Request Component — Langflow OSS CWE-918 8.5 High 2026-06-30
CVE-2026-10134 Unauthenticated Server-Side RCE via PythonCodeStructuredTool in Public Flows — Langflow OSS CWE-94 10.0 Critical 2026-06-30
CVE-2026-10140 Cross-Tenant API Key Reuse and Billing Fraud in Langflow Voice Mode Subsystem — Langflow OSS CWE-639 9.6 Critical 2026-06-30
CVE-2026-10546 DNS Rebinding TOCTOU Bypass of SSRF Protection in Langflow OSS URL Component — Langflow OSS CWE-918 7.1 High 2026-06-30
CVE-2026-10560 Unauthenticated Access to Private Flow Build Events and Cancellation in Langflow OSS — Langflow OSS CWE-287 8.2 High 2026-06-30
CVE-2026-10564 SSRF Vulnerability in Langflow OSS Legacy Components Bypasses Protection — Langflow OSS CWE-918 8.2 High 2026-06-30
CVE-2026-11546 IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability — WebSphere Application Server - Liberty CWE-918 7.1 High 2026-06-30
CVE-2026-11595 IBM WebSphere Application Server is affected by a Path Traversal vulnerability — WebSphere Application Server CWE-22 4.3 Medium 2026-06-30
CVE-2026-11708 IBM WebSphere Application Server is affected by a cross-site scripting vulnerability — WebSphere Application Server CWE-79 9.3 Critical 2026-06-30
CVE-2026-11712 IBM WebSphere Application Server is affected by a cross-site scripting vulnerability — WebSphere Application Server CWE-79 9.3 Critical 2026-06-30
CVE-2026-11714 IBM WebSphere Application Server Liberty is affected by an authorization bypass vulnerability — WebSphere Application Server - Liberty CWE-918 8.5 High 2026-06-30
CVE-2026-11806 IBM WebSphere Application Server Liberty is affected by a an arbitrary file read vulnerability — WebSphere Application Server - Liberty CWE-444 7.2 High 2026-06-30
CVE-2026-11906 IBM® Db2® federated server is vulnerable to a denial of service due to improper neutralization of special elements in the data query logic of XMLTable-derived columns by autheticated user — Db2 CWE-1284 6.5 Medium 2026-06-30
CVE-2026-12084 IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to a Permissive Cross-domain Security Policy with Untrusted Domains — UCD - IBM DevOps Deploy CWE-942 5.4 Medium 2026-06-30
CVE-2026-12085 IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptable to an Insertion of Sensitive Information Into Sent Data vulnerability — UCD - IBM UrbanCode Deploy CWE-201 6.5 Medium 2026-06-30
CVE-2026-12086 IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to a Insertion of Sensitive Information into Log File Vulnerability — UCD - IBM UrbanCode Deploy CWE-532 6.2 Medium 2026-06-30

This page lists every published CVE security advisory associated with IBM. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.