Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

IBM — Vulnerabilities & Security Advisories 5232

Browse all 5232 CVE security advisories affecting IBM. AI-powered Chinese analysis, POCs, and references for each vulnerability.

IBM operates as a multinational technology and consulting corporation, primarily providing enterprise software, hybrid cloud services, and artificial intelligence solutions. Its extensive portfolio, including the Red Hat OpenShift platform and Watson AI suite, creates a broad attack surface that has historically been associated with Remote Code Execution (RCE) vulnerabilities, particularly within web application frameworks and middleware. Cross-site scripting (XSS) and privilege escalation flaws also frequently appear in its legacy enterprise applications and containerized environments. While the company maintains robust security protocols, past incidents have included data breaches affecting customer information and supply chain compromises. The high volume of recorded Common Vulnerabilities and Exposures (CVEs) reflects the complexity and scale of its global infrastructure rather than inherent systemic failure, though it necessitates rigorous patch management and continuous monitoring for enterprise clients relying on its diverse technological stack.

CVE ID Title CVSS Severity Published
CVE-2025-64646 Multiple Vulnerabilities in IBM Concert Software — Concert CWE-14 6.2 Medium 2026-03-25
CVE-2025-36440 Multiple Vulnerabilities in IBM Concert Software — Concert CWE-522 5.1 Medium 2026-03-25
CVE-2025-36438 Multiple Vulnerabilities in IBM Concert Software — Concert CWE-923 5.1 Medium 2026-03-25
CVE-2025-36422 IBM InfoSphere Information Server is vulnerable to cross-site request forgery — InfoSphere Information Server CWE-352 4.3 Medium 2026-03-25
CVE-2025-36258 IBM InfoSphere Information Server is vulnerable due to plaintext storage of a password — InfoSphere Information Server CWE-256 7.1 High 2026-03-25
CVE-2026-2485 IBM InfoSphere Information Server Cross-Site Scripting — InfoSphere Information Server CWE-79 4.8 Medium 2026-03-25
CVE-2025-14974 IBM InfoSphere Information Server is vulnerable due to Insecure Direct Object Reference — InfoSphere Information Server CWE-639 5.7 Medium 2026-03-25
CVE-2026-1262 IBM InfoSphere Information Server Information Disclosure — InfoSphere Information Server CWE-209 4.3 Medium 2026-03-25
CVE-2025-14917 IBM WebSphere Application Server Liberty could provide weaker than expected security — WebSphere Application Server - Liberty CWE-1393 6.7 Medium 2026-03-25
CVE-2025-14912 IBM InfoSphere Information Server is vulnerable to server-side request forgery — InfoSphere Information Server CWE-918 5.4 Medium 2026-03-25
CVE-2025-14915 IBM WebSphere Application Server Liberty is affected by a privilege escalation vulnerability — WebSphere Application Server - Liberty CWE-200 6.5 Medium 2026-03-25
CVE-2025-14810 IBM InfoSphere Information Server is vulnerable due to insufficient session expiration — InfoSphere Information Server CWE-613 6.3 Medium 2026-03-25
CVE-2026-1561 IBM WebSphere Application Server Liberty Server-Side Request Forgery — WebSphere Application Server Liberty CWE-918 5.4 Medium 2026-03-25
CVE-2025-14808 IBM InfoSphere Information Server is vulnerable due to disclosure of sensitive information — InfoSphere Information Server CWE-598 3.1 Low 2026-03-25
CVE-2025-14790 IBM InfoSphere Information Server is vulnerable to disclosure of sensitive information — InfoSphere Information Server CWE-522 6.5 Medium 2026-03-25
CVE-2025-12708 Multiple Vulnerabilities in IBM Concert Software — Concert CWE-798 6.2 Medium 2026-03-25
CVE-2025-36051 IBM QRadar SIEM Information Disclosure — QRadar SIEM CWE-538 6.2 Medium 2026-03-19
CVE-2025-13995 IBM QRadar SIEM Information Disclosure — QRadar CWE-1286 5.0 Medium 2026-03-19
CVE-2025-15051 IBM QRadar SIEM Cross-Site Scripting — QRadar SIEM CWE-79 5.4 Medium 2026-03-19
CVE-2026-1276 IBM QRadar SIEM Cross-Site Scripting — QRadar SIEM CWE-79 5.4 Medium 2026-03-19
CVE-2026-1264 IBM Sterling B2B Integrator and IBM Sterling File Gateway Improper Access Controls — Sterling B2B Integrator CWE-306 7.1 High 2026-03-17
CVE-2025-14031 IBM Sterling B2B Integrator and IBM Sterling File Gateway Denial of Service — Sterling B2B Integrator CWE-77 7.5 High 2026-03-17
CVE-2026-3856 IBM Db2 Recovery Expert Missing Integrity Check — Db2 Recovery Expert CWE-353 5.3 Medium 2026-03-17
CVE-2026-1376 IBM i Denial of Service — i CWE-770 7.5 High 2026-03-17
CVE-2026-1267 IBM Planning Analytics Information Disclosure — Planning Analytics Local CWE-200 6.5 Medium 2026-03-17
CVE-2025-14806 IBM Planning Analytics Information Disclosure — Planning Analytics Local CWE-524 5.7 Medium 2026-03-17
CVE-2026-0977 IBM CICS Transaction Gateway for Multiplatforms Information Disclosure — CICS Transaction Gateway for Multiplatforms CWE-284 5.1 Medium 2026-03-13
CVE-2025-13212 IBM Aspera Console Denial of Service — Aspera Console CWE-799 5.3 Medium 2026-03-13
CVE-2025-13459 IBM Aspera Console Denial of Service — Aspera Console CWE-841 2.7 Low 2026-03-13
CVE-2025-13460 IBM Aspera Console Information Disclosure — Aspera Console CWE-204 5.3 Medium 2026-03-13

This page lists every published CVE security advisory associated with IBM. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.