Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

IBM — Vulnerabilities & Security Advisories 5232

Browse all 5232 CVE security advisories affecting IBM. AI-powered Chinese analysis, POCs, and references for each vulnerability.

IBM operates as a multinational technology and consulting corporation, primarily providing enterprise software, hybrid cloud services, and artificial intelligence solutions. Its extensive portfolio, including the Red Hat OpenShift platform and Watson AI suite, creates a broad attack surface that has historically been associated with Remote Code Execution (RCE) vulnerabilities, particularly within web application frameworks and middleware. Cross-site scripting (XSS) and privilege escalation flaws also frequently appear in its legacy enterprise applications and containerized environments. While the company maintains robust security protocols, past incidents have included data breaches affecting customer information and supply chain compromises. The high volume of recorded Common Vulnerabilities and Exposures (CVEs) reflects the complexity and scale of its global infrastructure rather than inherent systemic failure, though it necessitates rigorous patch management and continuous monitoring for enterprise clients relying on its diverse technological stack.

CVE ID Title CVSS Severity Published
CVE-2026-6053 IBM® Db2® is vulnerable to a denial of service when a specially crafted query is run with range partitioned tables — Db2 CWE-770 5.5 Medium 2026-05-27
CVE-2026-6052 IBM® Db2® is vulnerable to running out of memory when executing certain queries with MDC tables — Db2 6.5 Medium 2026-05-27
CVE-2026-6051 IBM® Db2® is vulnerable to a denial of service when executing a specially crafted query with a small statement heap — Db2 CWE-400 5.5 Medium 2026-05-27
CVE-2026-5516 IBM WebSphere Application Server Liberty is affected by a security bypass vulnerability — WebSphere Application Server - Liberty 4.4 Medium 2026-05-27
CVE-2026-5515 IBM App Connect Enterprise is vulnerable to a confidential disclosure — App Connect Enterprise 5.5 Medium 2026-05-27
CVE-2026-5065 IBM Controller is affected by vulnerabilities — Controller CWE-798 8.8 High 2026-05-27
CVE-2026-4410 IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a denial of service — WebSphere Application Server - Liberty 4.8 Medium 2026-05-27
CVE-2026-3676 There are multiple vulnerabilities in IBM DB2 bundled with IBM Application Performance Management products. — Cloud APM, Base Private CWE-1284 6.5 Medium 2026-05-27
CVE-2026-3623 Vulnerabilities exists in IBM Netezza Performance Server Replication Services — Netezza Performance Server Replication Services CWE-250 7.8 High 2026-05-27
CVE-2026-3366 InfoSphere Optim Test Data Fabrication is affected by Arbitrary File Read — InfoSphere Optim Test Data Fabrication CWE-22 7.5 High 2026-05-27
CVE-2026-2607 Multiple vulnerabilities in IBM MQ Operator and Queue manager container images — MQ Operator CWE-532 5.1 Medium 2026-05-27
CVE-2026-1718 IBM® Db2® is vulnerable to a denial of service with a specially crafted query when running an AUTONOMOUS procedure — Db2 CWE-770 7.1 High 2026-05-27
CVE-2025-3633 IBM Cognos Analytics is affected by multiple security vulnerabilities — Cognos Analytics CWE-79 5.4 Medium 2026-05-27
CVE-2026-3660 IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to Authentication Bypass — Engineering Lifecycle Management CWE-863 9.8 Critical 2026-05-26
CVE-2026-3603 IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to XML external entity injection (XXE) attack — Engineering Lifecycle Management CWE-611 7.1 High 2026-05-26
CVE-2026-4051 IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to Server Post-Auth Remote Code Execution — Engineering Lifecycle Management CWE-749 7.2 High 2026-05-26
CVE-2026-9170 IBM HTTP Server is affected by multiple vulnerabilities — HTTP Server CWE-94 - - 2026-05-26
CVE-2026-8633 IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities when using when using Web Server Plug-ins — Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty CWE-94 9.8 Critical 2026-05-26
CVE-2026-8620 IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities when using when using Web Server Plug-ins — Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty CWE-444 7.5 High 2026-05-26
CVE-2026-8835 IBM HTTP Server is affected by multiple vulnerabilities — HTTP Server CWE-822 7.3 High 2026-05-26
CVE-2026-8834 IBM HTTP Server is affected by multiple vulnerabilities — HTTP Server CWE-122 8.0 High 2026-05-26
CVE-2026-8855 IBM HTTP Server is affected by multiple vulnerabilities — HTTP Server CWE-94 8.1 High 2026-05-26
CVE-2026-8854 IBM HTTP Server is affected by multiple vulnerabilities — HTTP Server CWE-825 7.5 High 2026-05-26
CVE-2026-8856 IBM HTTP Server is affected by multiple vulnerabilities — HTTP Server CWE-400 7.7 High 2026-05-26
CVE-2026-8852 IBM HTTP Server is affected by multiple vulnerabilities — HTTP Server CWE-617 6.2 Medium 2026-05-26
CVE-2026-8850 IBM HTTP Server is affected by multiple vulnerabilities — HTTP Server CWE-476 7.5 High 2026-05-26
CVE-2025-36221 Vulnerabilities exists in IBM Cloud Pak for Data System (CPDS 1.0) - Cyclops. — Cloud Pak for Data System - Cyclops CWE-1392 5.3 Medium 2026-05-26
CVE-2025-36220 Vulnerabilities exists in IBM Cloud Pak for Data System (CPDS 1.0) - Cyclops. — Cloud Pak for Data System - Cyclops CWE-89 4.3 Medium 2026-05-26
CVE-2025-36126 IBM Cognos Analytics is affected by Cross-site scripting. — Cognos Analytics CWE-79 6.4 Medium 2026-05-26
CVE-2025-36148 IBM Financial Transaction Manager for SWIFT Services for Multiplatforms is vulnerable to cross-site scripting. — Financial Transaction Manager for SWIFT Services for Multiplatforms CWE-79 5.4 Medium 2026-05-26

This page lists every published CVE security advisory associated with IBM. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.