Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

IBM — Vulnerabilities & Security Advisories 5232

Browse all 5232 CVE security advisories affecting IBM. AI-powered Chinese analysis, POCs, and references for each vulnerability.

IBM operates as a multinational technology and consulting corporation, primarily providing enterprise software, hybrid cloud services, and artificial intelligence solutions. Its extensive portfolio, including the Red Hat OpenShift platform and Watson AI suite, creates a broad attack surface that has historically been associated with Remote Code Execution (RCE) vulnerabilities, particularly within web application frameworks and middleware. Cross-site scripting (XSS) and privilege escalation flaws also frequently appear in its legacy enterprise applications and containerized environments. While the company maintains robust security protocols, past incidents have included data breaches affecting customer information and supply chain compromises. The high volume of recorded Common Vulnerabilities and Exposures (CVEs) reflects the complexity and scale of its global infrastructure rather than inherent systemic failure, though it necessitates rigorous patch management and continuous monitoring for enterprise clients relying on its diverse technological stack.

CVE ID Title CVSS Severity Published
CVE-2026-13449 XXE attack in IBM Business Automation Manager Open Editions — Business Automation Manager Open Editions CWE-611 7.6 High 2026-06-30
CVE-2026-13759 IBM WebSphere eXtreme Scale is affected by Insecure Deserilization — WebSphere Extreme Scale CWE-502 7.5 High 2026-06-30
CVE-2026-13772 IBM WebSphere eXtreme Scale's OQL is affected by remote code execution — WebSphere Extreme Scale CWE-470 7.5 High 2026-06-30
CVE-2026-13773 IBM WebSphere eXtreme Scale is affected by server side request forgery when ORB is used as Transport Protocol — WebSphere Extreme Scale CWE-918 6.0 Medium 2026-06-30
CVE-2026-3602 IBM App Connect Enterprise and IBM Integration Bus for z/OS toolkit is vulnerable to an sql injection — App Connect Enterprise CWE-73 4.7 Medium 2026-06-30
CVE-2026-7663 Unauthenticated Cross-User MCP Resource Access and Tool Execution via Streamable Transport Authorization Bypass — Langflow OSS CWE-285 9.1 Critical 2026-06-30
CVE-2026-7803 Flow Validation Bypass via Empty Component Type Field — Langflow OSS CWE-20 9.8 Critical 2026-06-30
CVE-2026-7871 Insecure Deserialization in Redis Cache Backend — Langflow OSS CWE-502 9.8 Critical 2026-06-30
CVE-2026-7873 Code Injection Vulnerability in Code Validation Endpoint — Langflow OSS CWE-94 9.9 Critical 2026-06-30
CVE-2026-7874 Weak Cryptographic Key Derivation Exposed All Stored Credentials — Langflow OSS CWE-338 9.1 Critical 2026-06-30
CVE-2026-9002 IBM WebSphere eXtremes Scale is affected by uncontrolled resource consumption when XDF is enabled — WebSphere Extreme Scale CWE-400 6.5 Medium 2026-06-30
CVE-2026-9836 IBM DataStage Flow Designer application is affected by an information disclosure vulnerability — InfoSphere Information Server CWE-200 3.5 Low 2026-06-30
CVE-2026-10852 Websphere Application Server is Affected By a Denial of Service — WebSphere Application Server CWE-476 5.9 Medium 2026-06-22
CVE-2026-7253 IBM Sterling File Gateway SQL Injection — Sterling B2B Integrator CWE-89 6.0 Medium 2026-06-22
CVE-2026-9320 IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities — WebSphere Application Server CWE-400 5.9 Medium 2026-06-22
CVE-2026-9071 IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by Uncontrolled Resource Consumption — WebSphere Application Server CWE-400 7.5 High 2026-06-22
CVE-2026-9006 IBM WebSphere Application Server is affected by server-side request forgery — WebSphere Application Server CWE-918 7.4 High 2026-06-22
CVE-2026-8646 IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities — WebSphere Application Server CWE-444 7.4 High 2026-06-22
CVE-2026-10845 IBM WebSphere Application Server is affected by an authentication bypass vulnerability — WebSphere Application Server CWE-287 - - 2026-06-22
CVE-2024-51454 IBM Engineering Lifecycle Management - Engineering Workflow Management is impacted by vulnerabilities Host Header Injection observed — Engineering Workflow Management CWE-644 6.5 Medium 2026-06-22
CVE-2023-33854 Multiple vulnerabilities affect IBM Db2® on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data. — Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data CWE-294 5.3 Medium 2026-06-22
CVE-2026-9610 Multiple Vulnerabilities in IBM Datacap — Datacap CWE-425 2.3 Low 2026-06-22
CVE-2026-9072 WebSphere Application Server Remote Code Execution — WebSphere Application Server CWE-94 8.1 High 2026-06-22
CVE-2026-8858 WebSphere Application Server Remote Code Execution — WebSphere Application Server CWE-94 7.5 High 2026-06-22
CVE-2026-8636 Multiple Vulnerabilities in IBM Datacap — Datacap CWE-316 5.5 Medium 2026-06-22
CVE-2026-8059 Multiple Vulnerabilities in IBM Datacap — Datacap CWE-79 6.1 Medium 2026-06-22
CVE-2026-7664 Unauthenticated Flow Execution via Webhook Endpoint in Langflow OSS — Langflow OSS CWE-287 9.8 Critical 2026-06-22
CVE-2026-11372 IBM TRIRIGA Cross-Site Scripting Vulnerability — TRIRIGA Application Platform CWE-79 5.4 Medium 2026-06-22
CVE-2026-12628 Hardcoded credential in the IBM Storage Protect Snapshot For Windows leads to unauthorized access to system — Storage Protect Client CWE-798 9.1 Critical 2026-06-22
CVE-2026-10561 Unauthenticated Remote Code Execution in Langflow OSS PythonREPLComponent via Builtins Injection — Langflow OSS CWE-94 10.0 Critical 2026-06-22

This page lists every published CVE security advisory associated with IBM. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.