Browse all 5232 CVE security advisories affecting IBM. AI-powered Chinese analysis, POCs, and references for each vulnerability.
IBM operates as a multinational technology and consulting corporation, primarily providing enterprise software, hybrid cloud services, and artificial intelligence solutions. Its extensive portfolio, including the Red Hat OpenShift platform and Watson AI suite, creates a broad attack surface that has historically been associated with Remote Code Execution (RCE) vulnerabilities, particularly within web application frameworks and middleware. Cross-site scripting (XSS) and privilege escalation flaws also frequently appear in its legacy enterprise applications and containerized environments. While the company maintains robust security protocols, past incidents have included data breaches affecting customer information and supply chain compromises. The high volume of recorded Common Vulnerabilities and Exposures (CVEs) reflects the complexity and scale of its global infrastructure rather than inherent systemic failure, though it necessitates rigorous patch management and continuous monitoring for enterprise clients relying on its diverse technological stack.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2021-39013 | IBM Cloud Pak for Security 信息泄露漏洞 — Cloud Pak for Security | 6.5 | - | 2021-12-22 |
| CVE-2021-38966 | IBM Business Automation Workflow 跨站脚本漏洞 — Cloud Pak for Automation | 5.4 | - | 2021-12-21 |
| CVE-2021-38900 | IBM Business Process Manager和IBM Business Automation Workflow 安全漏洞 — Business Automation Workflow | 4.9 | - | 2021-12-21 |
| CVE-2021-38893 | IBM Business Automation Workflow 跨站脚本漏洞 — Cloud Pak for Automation | 5.4 | - | 2021-12-21 |
| CVE-2021-38883 | IBM Business Automation Workflow 跨站脚本漏洞 — Business Process Manager | 5.4 | - | 2021-12-17 |
| CVE-2021-29847 | IBM Power System安全漏洞 — Power System S821LC Server (8001-12C) | 5.9 | - | 2021-12-15 |
| CVE-2021-38950 | IBM MQ for HP NonStop 安全漏洞 — MQ for HPE NonStop | 7.8 | - | 2021-12-14 |
| CVE-2021-39063 | IBM Spectrum Protect Plus访问控制错误漏洞 — Spectrum Protect Plus | 8.2 | - | 2021-12-13 |
| CVE-2021-39057 | IBM Spectrum Protect Plus 代码问题漏洞 — Spectrum Protect Plus | 7.1 | - | 2021-12-13 |
| CVE-2021-39050 | IBM i 缓冲区错误漏洞 — i2 Analyst's Notebook | 7.8 | - | 2021-12-13 |
| CVE-2021-39049 | IBM i 缓冲区错误漏洞 — i2 Analyst's Notebook | 7.8 | - | 2021-12-13 |
| CVE-2021-39048 | IBM Spectrum Protect 缓冲区错误漏洞 — Spectrum Protect | 5.5 | - | 2021-12-13 |
| CVE-2021-38901 | IBM Spectrum Protect Operations Center信息泄露漏洞 — Spectrum Protect Operations Center | 5.5 | - | 2021-12-13 |
| CVE-2020-4496 | IBM Spectrum Protect Plus 信任管理问题漏洞 — Spectrum Protect Plus | 5.9 | - | 2021-12-13 |
| CVE-2021-39065 | IBM Spectrum Copy Data Management 操作系统命令注入漏洞 — Spectrum Copy Data Management | 9.8 | - | 2021-12-13 |
| CVE-2021-39064 | IBM Spectrum Copy Data Management授权问题漏洞 — Spectrum Copy Data Management | 7.5 | - | 2021-12-13 |
| CVE-2021-39058 | IBM Spectrum Copy Data Management加密问题漏洞 — Spectrum Copy Data Management | 7.5 | - | 2021-12-13 |
| CVE-2021-39054 | IBM Spectrum Copy Data Management安全漏洞 — Spectrum Copy Data Management | 5.4 | - | 2021-12-13 |
| CVE-2021-39053 | IBM Spectrum Copy Data Management安全漏洞 — Spectrum Copy Data Management | 7.5 | - | 2021-12-13 |
| CVE-2021-39052 | IBM Spectrum Copy Data Management 安全漏洞 — Spectrum Copy Data Management | 9.8 | - | 2021-12-13 |
| CVE-2021-38947 | IBM Spectrum Copy Data Management 加密问题漏洞 — Spectrum Copy Data Management | 7.5 | - | 2021-12-13 |
| CVE-2021-38937 | IBM PowerVM Hypervisor 安全漏洞 — PowerVM Hypervisor | 6.5 | - | 2021-12-10 |
| CVE-2021-38917 | IBM PowerVM Hypervisor 安全漏洞 — PowerVM Hypervisor | 10.0 | - | 2021-12-10 |
| CVE-2021-39002 | IBM DB2 加密问题漏洞 — DB2 for Linux, UNIX and Windows | 7.5 | - | 2021-12-09 |
| CVE-2021-38951 | IBM WebSphere Application Server 资源管理错误漏洞 — WebSphere Application Server | 7.5 | - | 2021-12-09 |
| CVE-2021-38931 | IBM DB2 授权问题漏洞 — DB2 for Linux, UNIX and Windows | 6.5 | - | 2021-12-09 |
| CVE-2021-38926 | IBM DB2 权限许可和访问控制问题漏洞 — DB2 for Linux, UNIX and Windows | 7.1 | - | 2021-12-09 |
| CVE-2021-29678 | IBM Db2 安全漏洞 — DB2 for Linux, UNIX and Windows | 8.7 | - | 2021-12-09 |
| CVE-2021-20373 | IBM DB2 权限许可和访问控制问题漏洞 — DB2 for Linux, UNIX and Windows | 4.3 | - | 2021-12-09 |
| CVE-2021-38909 | IBM Cognos Analytics 跨站脚本漏洞 — Cognos Analytics | 5.4 | - | 2021-12-03 |
This page lists every published CVE security advisory associated with IBM. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.