Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

IBM — Vulnerabilities & Security Advisories 5232

Browse all 5232 CVE security advisories affecting IBM. AI-powered Chinese analysis, POCs, and references for each vulnerability.

IBM operates as a multinational technology and consulting corporation, primarily providing enterprise software, hybrid cloud services, and artificial intelligence solutions. Its extensive portfolio, including the Red Hat OpenShift platform and Watson AI suite, creates a broad attack surface that has historically been associated with Remote Code Execution (RCE) vulnerabilities, particularly within web application frameworks and middleware. Cross-site scripting (XSS) and privilege escalation flaws also frequently appear in its legacy enterprise applications and containerized environments. While the company maintains robust security protocols, past incidents have included data breaches affecting customer information and supply chain compromises. The high volume of recorded Common Vulnerabilities and Exposures (CVEs) reflects the complexity and scale of its global infrastructure rather than inherent systemic failure, though it necessitates rigorous patch management and continuous monitoring for enterprise clients relying on its diverse technological stack.

CVE ID Title CVSS Severity Published
CVE-2025-33128 IBM Engineering Lifecycle Management - Engineering Workflow Management is impacted by vulnerabilities HTML / XSS Injection observed — Engineering Workflow Management CWE-79 5.4 Medium 2026-06-22
CVE-2025-2669 Multiple vulnerabilities affect IBM Db2® on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data. — Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data CWE-295 6.0 Medium 2026-06-22
CVE-2024-54178 Multiple vulnerabilities affect IBM Db2® on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data. — Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data CWE-770 6.5 Medium 2026-06-22
CVE-2026-4870 Qiskit SDK is vulnerable to specific functions may recurse too deeply and overflow the available stack space, when encountering certain classical expressions. — Qiskit SDK 7.5 High 2026-06-12
CVE-2024-45636 IBM Security QRadar EDR Software has a vulnerability where user credentials may be stored in plain text, potentially exposing sensitive information. — Security QRadar EDR CWE-256 4.1 Medium 2026-06-11
CVE-2026-3341 IBM Langflow Desktop 1.0.0 - 1.9.2 DNS Rebinding Bypasses SSRF Protection Allowing Access to Internal Services — Langflow Desktop CWE-918 5.4 Medium 2026-06-11
CVE-2026-4096 A vulnerability has been identified in IBM DevOps Plan that allows a Host Header Injection attack due to improper handling of the Host header in HTTP requests. — DevOps Plan CWE-644 6.5 Medium 2026-06-11
CVE-2026-7787 Unauthenticated Session History Access via Public Flow Execution — Langflow OSS CWE-639 7.5 High 2026-06-11
CVE-2026-7870 IBM i is Affected by Privilege Escalation [] — i CWE-427 8.8 High 2026-06-11
CVE-2026-9330 IBM WebSphere Application Server is affected by remote code execution — WebSphere Application Server CWE-502 8.5 High 2026-06-01
CVE-2026-9319 IBM WebSphere Application Server is affected by a remote code execution vulnerability — WebSphere Application Server CWE-502 9.0 Critical 2026-06-01
CVE-2026-9311 IBM WebSphere Application Server is affected by remote code execution — WebSphere Application Server CWE-94 9.0 Critical 2026-06-01
CVE-2026-8644 IBM WebSphere Application Server is affected by an identity spoofing vulnerability — WebSphere Application Server CWE-290 9.1 Critical 2026-06-01
CVE-2026-7770 IBM i Access Client Solutions (ACS) is vulnerable to remote code execution when configured to listen for requests from IBM i Navigator — i Access Family CWE-74 8.8 High 2026-06-01
CVE-2026-1248 IBM Business Automation Workflow information leak — Business Automation Workflow containers and traditional - - 2026-05-27
CVE-2026-7876 Authentication bypass vulnerability found in Aspera High-Speed Transfer Server for Cloud Pak for Integration — Aspera HSTS for CP4I CWE-287 - - 2026-05-27
CVE-2026-7365 IBM Operations Analytics - Log Analysis is affected by Information disclosure due to default passwords not being forced to be changed on post-installation — Operations Analytics - Log Analysis CWE-1392 8.4 High 2026-05-27
CVE-2024-56462 IBM QRadar SIEM is vulnerable to using components with known vulnerabilities — QRadar CWE-530 7.2 High 2026-05-27
CVE-2024-40684 IBM Operations Analytics - Log Analysis is affected by Weak Password Policy and Inadequate Account Lockout Mechanism — Operations Analytics - Log Analysis CWE-521 5.9 Medium 2026-05-27
CVE-2024-28765 Security vulnerability was found in IBM Security Directory Integrator — SDI CWE-209 5.3 Medium 2026-05-27
CVE-2026-9035 Multiple vulnerabilities in Aspera applications. — Aspera High-Speed Transfer Endpoint CWE-22 6.5 Medium 2026-05-27
CVE-2026-8405 IBM Guardium Data Protection is affected by Exposure of Sensitive Information vulnerability — Guardium Data Protection CWE-200 6.5 Medium 2026-05-27
CVE-2026-8180 Multiple vulnerabilities in Aspera applications. — Aspera High-Speed Transfer Endpoint CWE-476 7.5 High 2026-05-27
CVE-2026-8179 Multiple vulnerabilities in Aspera applications. — Aspera High-Speed Transfer Endpoint CWE-121 8.8 High 2026-05-27
CVE-2026-8175 Multiple vulnerabilities in Aspera applications. — Aspera High-Speed Transfer Endpoint CWE-122 9.8 Critical 2026-05-27
CVE-2026-7528 Unauthenticated File Upload Vulnerability Allows Disk Space Exhaustion and Path Disclosure in Langflow OSS — Langflow OSS CWE-400 7.1 High 2026-05-27
CVE-2026-7524 Path Traversal Vulnerability in File Processing Components Allows Unauthorized File System Access and Potential Remote Code Execution — Langflow OSS CWE-22 9.8 Critical 2026-05-27
CVE-2026-7254 Open BMC Denial of Service — OPENBMC CWE-1284 - - 2026-05-27
CVE-2026-6938 IBM® Db2® is vulnerable to authorization bypass when uploading to a remote object storage path with a special query — Db2 CWE-285 6.5 Medium 2026-05-27
CVE-2026-6936 IBM i is Affected by a Denial of Service Vulnerability [] — i CWE-674 6.5 Medium 2026-05-27

This page lists every published CVE security advisory associated with IBM. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.