Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

IBM — Vulnerabilities & Security Advisories 5232

Browse all 5232 CVE security advisories affecting IBM. AI-powered Chinese analysis, POCs, and references for each vulnerability.

IBM operates as a multinational technology and consulting corporation, primarily providing enterprise software, hybrid cloud services, and artificial intelligence solutions. Its extensive portfolio, including the Red Hat OpenShift platform and Watson AI suite, creates a broad attack surface that has historically been associated with Remote Code Execution (RCE) vulnerabilities, particularly within web application frameworks and middleware. Cross-site scripting (XSS) and privilege escalation flaws also frequently appear in its legacy enterprise applications and containerized environments. While the company maintains robust security protocols, past incidents have included data breaches affecting customer information and supply chain compromises. The high volume of recorded Common Vulnerabilities and Exposures (CVEs) reflects the complexity and scale of its global infrastructure rather than inherent systemic failure, though it necessitates rigorous patch management and continuous monitoring for enterprise clients relying on its diverse technological stack.

CVE ID Title CVSS Severity Published
CVE-2025-36019 Multiple Vulnerabilities in IBM Concert Software. — Concert CWE-79 6.1 Medium 2026-02-17
CVE-2025-12755 Multiple vulnerabilities in IBM MQ Operator and Queue manager container images — MQ Operator CWE-117 4.0 Medium 2026-02-17
CVE-2025-36247 IBM Db2 XML External Entity Reference — Db2 for Linux, UNIX and Windows CWE-611 7.1 High 2026-02-17
CVE-2025-36425 IBM Db2 Information Disclosure — Db2 for Linux, UNIX and Windows CWE-256 5.3 Medium 2026-02-17
CVE-2025-13867 IBM Db2 Denial of Service — Db2 for Linux, UNIX and Windows CWE-1284 6.5 Medium 2026-02-17
CVE-2025-14689 IBM Db2 Denial of Service — Db2 for Linux, UNIX and Windows CWE-1284 6.5 Medium 2026-02-17
CVE-2025-14150 IBM webMethods Integration Sever is affected by — webMethods Integration (on prem) - Integration Server CWE-497 6.5 Medium 2026-02-05
CVE-2025-13491 IBM App Connect Enterprise Certified Container Information Disclosure — App Connect Enterprise Certified Container CWE-426 5.1 Medium 2026-02-05
CVE-2025-13379 A SQL Injection vulnerability has been addressed in IBM Aspera Console — Aspera Console CWE-89 8.6 High 2026-02-05
CVE-2024-51451 Multiple Vulnerabilities in IBM Concert Software — Concert CWE-644 6.5 Medium 2026-02-04
CVE-2024-43181 Multiple Vulnerabilities in IBM Concert Software — Concert CWE-613 6.3 Medium 2026-02-04
CVE-2024-40685 IBM Operations Analytics - Log Analysis is affected by CSRF Token Replay Attack — Operations Analytics - Log Analysis CWE-352 4.3 Medium 2026-02-04
CVE-2025-2134 IBM Jazz Reporting Service Denial of Service — Jazz Reporting Service CWE-410 3.5 Low 2026-02-04
CVE-2025-27550 IBM Jazz Reporting Service Information Disclosure — Jazz Reporting Service CWE-497 3.5 Low 2026-02-04
CVE-2025-1823 IBM Jazz Reporting Service Denial of Service — Jazz Reporting Service CWE-770 3.5 Low 2026-02-04
CVE-2024-39724 IBM Db2 Big SQL on Cloud Pak for Data is vulnerable to a denial of service due to lack of throttling on an API — Db2 Big SQL on Cloud Pak for Data CWE-770 5.3 Medium 2026-02-04
CVE-2023-38281 Multiple Vulnerabilities in IBM Cloud Pak System — Cloud Pak System CWE-209 5.3 Medium 2026-02-04
CVE-2023-38017 Multiple Vulnerabilities in IBM Cloud Pak System — Cloud Pak System CWE-209 5.3 Medium 2026-02-04
CVE-2025-13375 IBM Common Cryptographic Architecture Arbitrary Command Execution — Common Cryptographic Architecture CWE-250 9.8 Critical 2026-02-04
CVE-2023-38010 Multiple Vulnerabilities in IBM Cloud Pak System — Cloud Pak System CWE-209 5.3 Medium 2026-02-04
CVE-2025-33081 Multiple Vulnerabilities in IBM Concert Software. — Concert CWE-312 3.3 Low 2026-02-03
CVE-2025-36033 IBM Engineering Lifecycle Management - Global Configuration Management is vulnerable to cross-site scripting — Engineering Lifecycle Management - Global Configuration Management CWE-79 5.4 Medium 2026-02-03
CVE-2025-36094 Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation iFixes for January 2026. — Cloud Pak for Business Automation CWE-1284 5.4 Medium 2026-02-03
CVE-2025-36194 This Power System update is being released to address — PowerVM Hypervisor CWE-1262 2.8 Low 2026-02-02
CVE-2025-36238 Power System Exposure of Sensitive System Information — PowerVM Hypervisor CWE-497 6.0 Medium 2026-02-02
CVE-2025-36253 Multiple Vulnerabilities in IBM Concert Software. — Concert CWE-759 5.9 Medium 2026-02-02
CVE-2025-36436 Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation iFixes for January 2026. — Cloud Pak for Business Automation CWE-79 6.4 Medium 2026-02-02
CVE-2025-13096 XML eXternal Entity injection (XXE) vulnerability affect IBM Business Automation Workflow - — Business Automation Workflow containers CWE-918 7.1 High 2026-02-02
CVE-2025-14914 IBM WebSphere Application Server Liberty Path Traversal — WebSphere Application Server Liberty CWE-22 7.6 High 2026-02-02
CVE-2025-15395 IBM Jazz Foundation access control violation — Jazz Foundation CWE-863 4.3 Medium 2026-02-02

This page lists every published CVE security advisory associated with IBM. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.