Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

IBM — Vulnerabilities & Security Advisories 5232

Browse all 5232 CVE security advisories affecting IBM. AI-powered Chinese analysis, POCs, and references for each vulnerability.

IBM operates as a multinational technology and consulting corporation, primarily providing enterprise software, hybrid cloud services, and artificial intelligence solutions. Its extensive portfolio, including the Red Hat OpenShift platform and Watson AI suite, creates a broad attack surface that has historically been associated with Remote Code Execution (RCE) vulnerabilities, particularly within web application frameworks and middleware. Cross-site scripting (XSS) and privilege escalation flaws also frequently appear in its legacy enterprise applications and containerized environments. While the company maintains robust security protocols, past incidents have included data breaches affecting customer information and supply chain compromises. The high volume of recorded Common Vulnerabilities and Exposures (CVEs) reflects the complexity and scale of its global infrastructure rather than inherent systemic failure, though it necessitates rigorous patch management and continuous monitoring for enterprise clients relying on its diverse technological stack.

CVE ID Title CVSS Severity Published
CVE-2025-36364 IBM DevOps Plan REST APIs are vulnerable to exposure of sensitive data through request query parameters. — DevOps Plan CWE-525 6.2 Medium 2026-03-03
CVE-2026-1265 IBM InfoSphere Information Server is vulnerable due to sensitive information written to a log file — InfoSphere Information Server CWE-532 4.3 Medium 2026-03-03
CVE-2026-2606 IBM webMethods API Management fails to validate user input and enables unauthorized arbitrary file read — webMethods API Gateway (on-prem) CWE-22 6.5 Medium 2026-03-03
CVE-2025-13333 IBM WebSphere Application Server could provide weaker than expected security — WebSphere Application Server CWE-358 4.4 Medium 2026-02-17
CVE-2025-13689 DataStage on Cloud Pak for Data is vulnerable to arbitrary code injection due to runtime environment — DataStage on Cloud Pak CWE-434 8.8 High 2026-02-17
CVE-2023-38005 Improper Access Control and Exposure of Information Through Directory Listing vulnerabilities affect IBM Cloud Pak System[, ] — Cloud Pak System CWE-284 4.3 Medium 2026-02-17
CVE-2025-33135 IBM Financial Transaction Manager for ACH Services and Check Services is impacted by multiple vulnerabilities — Financial Transaction Manager for ACH Services and Check Services for Multi-Platform CWE-79 6.1 Medium 2026-02-17
CVE-2025-33088 Multiple Vulnerabilities in IBM Concert Software. — Concert CWE-732 7.4 High 2026-02-17
CVE-2025-36183 Privileged User File Upload Vulnerability Leading to Limited Server-Side Execution affects watsonx.data — watsonx.data CWE-434 3.8 Low 2026-02-17
CVE-2025-36348 The Dashboard of IBM Sterling B2B Integrator and IBM Sterling File Gateway is Vulnerable to Information Disclosure — Sterling B2B Integrator CWE-209 4.9 Medium 2026-02-17
CVE-2025-36376 IBM Security QRadar EDR Software has multiple vulnerabilities — Security QRadar EDR CWE-613 6.3 Medium 2026-02-17
CVE-2025-36377 IBM Security QRadar EDR Software has multiple vulnerabilities — Security QRadar EDR CWE-613 6.3 Medium 2026-02-17
CVE-2025-36379 IBM Security QRadar EDR Software has multiple vulnerabilities — Security QRadar EDR CWE-326 5.9 Medium 2026-02-17
CVE-2025-13691 DataStage on Cloud Pak for Data is vulnerable to sensitive information leaks due to HTTP processing — DataStage on Cloud Pak for Data CWE-497 8.1 High 2026-02-17
CVE-2025-14289 IBM webMethods Integration Server is vulnerable to HTML injection — webMethods Integration Server CWE-80 5.4 Medium 2026-02-17
CVE-2025-27898 Multiple vulnerabilities in IBM Java SDK affecting Db2 Recovery Expert for Linux, Unix and Windows — DB2 Recovery Expert for LUW CWE-613 6.3 Medium 2026-02-17
CVE-2025-27899 Multiple vulnerabilities in IBM Java SDK affecting Db2 Recovery Expert for Linux, Unix and Windows — DB2 Recovery Expert for LUW CWE-526 5.3 Medium 2026-02-17
CVE-2025-27900 Multiple vulnerabilities in IBM Java SDK affecting Db2 Recovery Expert for Linux, Unix and Windows — DB2 Recovery Expert for LUW CWE-601 6.8 Medium 2026-02-17
CVE-2025-27901 Multiple vulnerabilities in IBM Java SDK affecting Db2 Recovery Expert for Linux, Unix and Windows — DB2 Recovery Expert for LUW CWE-644 6.5 Medium 2026-02-17
CVE-2025-27903 Multiple vulnerabilities in IBM Java SDK affecting Db2 Recovery Expert for Linux, Unix and Windows — DB2 Recovery Expert for LUW CWE-319 5.9 Medium 2026-02-17
CVE-2025-27904 Multiple vulnerabilities in IBM Java SDK affecting Db2 Recovery Expert for Linux, Unix and Windows — DB2 Recovery Expert for LUW CWE-352 6.5 Medium 2026-02-17
CVE-2025-33130 Fixes to common vulnerabilities found in IBM Db2 Merge Backup for Linux, UNIX and Windows — DB2 Merge Backup for Linux, UNIX and Windows CWE-120 6.5 Medium 2026-02-17
CVE-2025-33124 Fixes to common vulnerabilities found in IBM Db2 Merge Backup for Linux, UNIX and Windows — DB2 Merge Backup for Linux, UNIX and Windows CWE-131 6.5 Medium 2026-02-17
CVE-2025-13108 Fixes to common vulnerabilities found in IBM Db2 Merge Backup for Linux, UNIX and Windows — DB2 Merge Backup for Linux, UNIX and Windows 5.5 Medium 2026-02-17
CVE-2023-38265 Improper Access Control and Exposure of Information Through Directory Listing vulnerabilities affect IBM Cloud Pak System[, ] — Cloud Pak System CWE-548 5.3 Medium 2026-02-17
CVE-2025-33101 Multiple Vulnerabilities in IBM Concert Software. — Concert CWE-244 5.9 Medium 2026-02-17
CVE-2025-33089 Multiple Vulnerabilities in IBM Concert Software. — Concert CWE-798 6.5 Medium 2026-02-17
CVE-2025-36243 Multiple Vulnerabilities in IBM Concert Software. — Concert CWE-918 5.4 Medium 2026-02-17
CVE-2024-43178 Multiple Vulnerabilities in IBM Concert Software. — Concert CWE-327 5.9 Medium 2026-02-17
CVE-2025-36018 Multiple Vulnerabilities in IBM Concert Software. — Concert CWE-352 6.5 Medium 2026-02-17

This page lists every published CVE security advisory associated with IBM. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.