Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

IBM — Vulnerabilities & Security Advisories 5232

Browse all 5232 CVE security advisories affecting IBM. AI-powered Chinese analysis, POCs, and references for each vulnerability.

IBM operates as a multinational technology and consulting corporation, primarily providing enterprise software, hybrid cloud services, and artificial intelligence solutions. Its extensive portfolio, including the Red Hat OpenShift platform and Watson AI suite, creates a broad attack surface that has historically been associated with Remote Code Execution (RCE) vulnerabilities, particularly within web application frameworks and middleware. Cross-site scripting (XSS) and privilege escalation flaws also frequently appear in its legacy enterprise applications and containerized environments. While the company maintains robust security protocols, past incidents have included data breaches affecting customer information and supply chain compromises. The high volume of recorded Common Vulnerabilities and Exposures (CVEs) reflects the complexity and scale of its global infrastructure rather than inherent systemic failure, though it necessitates rigorous patch management and continuous monitoring for enterprise clients relying on its diverse technological stack.

Found 42 results / 5232 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-10534 IBM® Db2® is vulnerable to buffer overflow in the IXF IMPORT parser — Db2 CWE-121 8.4 High 2026-08-12
CVE-2026-10543 IBM® Db2® is vulnerable to privilege escalation with a specially crafted query — Db2 CWE-285 8.2 High 2026-08-12
CVE-2026-16480 IBM® Db2® is affected by an improper authorization vulnerability in the certain command, allowing a non-privileged user to bypass authority checks and modify database catalog data. — Db2 CWE-602 4.3 Medium 2026-08-12
CVE-2026-18097 IBM® Db2® federated server could allow a local attacker to obtain sensitive information due to the logging of plain text passwords in trace files. — Db2 CWE-532 5.5 Medium 2026-08-12
CVE-2026-18096 IBM® Db2® could allow a local attacker to cause a denial of service due to a memory leak — Db2 CWE-770 3.3 Low 2026-08-12
CVE-2026-10535 IBM® Db2® is vulnerable to buffer overflow in setgid helper db2flacc which can lead to privilege escalation and instance compromise from an unprivileged shell — Db2 CWE-121 8.4 High 2026-07-30
CVE-2026-10695 IBM® Db2® is vulnerable to a denial of service when running non fenced federated queries — Db2 CWE-400 6.2 Medium 2026-07-30
CVE-2026-7771 IBM® Db2® is vulnerable to a trap when compiling specially crafted statements containing subqueries could lead to a denial of service — Db2 CWE-835 5.5 Medium 2026-07-17
CVE-2026-9762 IBM® Data Server driver for JDBC and SQLJ is vulnerable to remote code execution when jdbc url is under user control — Db2 CWE-94 7.8 High 2026-07-17
CVE-2025-36372 IBM® Db2® could disclose sensitive information to an authenticated user from the monitoring and event tables — Db2 CWE-538 5.5 Medium 2026-06-30
CVE-2026-10109 IBM® Db2® is vulnerable to remote code execution due to improper pre-auth DRDA handshake handling — Db2 CWE-94 9.8 Critical 2026-06-30
CVE-2026-11906 IBM® Db2® federated server is vulnerable to a denial of service due to improper neutralization of special elements in the data query logic of XMLTable-derived columns by autheticated user — Db2 CWE-1284 6.5 Medium 2026-06-30
CVE-2026-6938 IBM® Db2® is vulnerable to authorization bypass when uploading to a remote object storage path with a special query — Db2 CWE-285 6.5 Medium 2026-05-27
CVE-2026-6053 IBM® Db2® is vulnerable to a denial of service when a specially crafted query is run with range partitioned tables — Db2 CWE-770 5.5 Medium 2026-05-27
CVE-2026-6052 IBM® Db2® is vulnerable to running out of memory when executing certain queries with MDC tables — Db2 6.5 Medium 2026-05-27
CVE-2026-6051 IBM® Db2® is vulnerable to a denial of service when executing a specially crafted query with a small statement heap — Db2 CWE-400 5.5 Medium 2026-05-27
CVE-2026-1718 IBM® Db2® is vulnerable to a denial of service with a specially crafted query when running an AUTONOMOUS procedure — Db2 CWE-770 7.1 High 2026-05-27
CVE-2025-13755 IBM® Db2® is vulnerable to credential exposure in db2diag when executing specific testcase buckets — Db2 CWE-532 5.5 Medium 2026-05-26
CVE-2026-1577 IBM® Db2® is vulnerable to a denial of service with a specially crafted query involving multiple subqueries — Db2 6.5 Medium 2026-04-30
CVE-2025-36122 IBM® Db2® is vulnerable to a denial of service with a specially crafted query when stmtheap is set to automatic — Db2 CWE-770 6.5 Medium 2026-04-30
CVE-2025-14688 IBM® Db2® is vulnerable to a denial of service when fetching from certain tables under specific configurations — Db2 CWE-1284 5.3 Medium 2026-04-30
CVE-2026-1352 IBM® Db2® is vulnerable to a trap or return SQLCODE -901 when compiling a specially crafted query with a defined index — Db2 CWE-1284 6.5 Medium 2026-04-22
CVE-2025-36006 IBM Db2 denial of service — Db2 CWE-404 6.5 Medium 2025-11-07
CVE-2025-36008 IBM Db2 denial of service — Db2 CWE-770 6.5 Medium 2025-11-07
CVE-2025-36131 IBM Db2 information disclosure — Db2 CWE-359 4.6 Medium 2025-11-07
CVE-2025-36136 IBM denial of service — Db2 CWE-770 5.1 Medium 2025-11-07
CVE-2025-36185 IBM Db2 denial of service — Db2 CWE-943 6.2 Medium 2025-11-07
CVE-2025-36186 IBM Db2 privilege escalation — Db2 CWE-250 7.4 High 2025-11-07
CVE-2025-33012 IBM Db2 improper account lockout — Db2 CWE-324 6.3 Medium 2025-11-07
CVE-2025-2534 IBM Db2 denial of service — Db2 CWE-789 5.3 Medium 2025-11-07

This page lists every published CVE security advisory associated with IBM. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.