Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

IBM — Vulnerabilities & Security Advisories 5232

Browse all 5232 CVE security advisories affecting IBM. AI-powered Chinese analysis, POCs, and references for each vulnerability.

IBM operates as a multinational technology and consulting corporation, primarily providing enterprise software, hybrid cloud services, and artificial intelligence solutions. Its extensive portfolio, including the Red Hat OpenShift platform and Watson AI suite, creates a broad attack surface that has historically been associated with Remote Code Execution (RCE) vulnerabilities, particularly within web application frameworks and middleware. Cross-site scripting (XSS) and privilege escalation flaws also frequently appear in its legacy enterprise applications and containerized environments. While the company maintains robust security protocols, past incidents have included data breaches affecting customer information and supply chain compromises. The high volume of recorded Common Vulnerabilities and Exposures (CVEs) reflects the complexity and scale of its global infrastructure rather than inherent systemic failure, though it necessitates rigorous patch management and continuous monitoring for enterprise clients relying on its diverse technological stack.

Found 146 results / 5232 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-9836 IBM DataStage Flow Designer application is affected by an information disclosure vulnerability — InfoSphere Information Server CWE-200 3.5 Low 2026-06-30
CVE-2025-14807 IBM InfoSphere Information Server is vulnerable to HTTP header injection — InfoSphere Information Server CWE-644 6.5 Medium 2026-03-25
CVE-2026-1015 IBM InfoSphere Information Server is vulnerable to server-side request forgery — InfoSphere Information Server CWE-918 5.4 Medium 2026-03-25
CVE-2026-1014 IBM InfoSphere Information Server is vulnerable due to disclosure of sensitive information — InfoSphere Information Server CWE-319 6.5 Medium 2026-03-25
CVE-2026-2483 IBM InfoSphere Information Server Cross-Site Scripting — InfoSphere Information Server CWE-79 5.4 Medium 2026-03-25
CVE-2026-2484 IBM InfoSphere Information Server Information Disclosure — InfoSphere Information Server CWE-209 4.3 Medium 2026-03-25
CVE-2025-36422 IBM InfoSphere Information Server is vulnerable to cross-site request forgery — InfoSphere Information Server CWE-352 4.3 Medium 2026-03-25
CVE-2025-36258 IBM InfoSphere Information Server is vulnerable due to plaintext storage of a password — InfoSphere Information Server CWE-256 7.1 High 2026-03-25
CVE-2026-2485 IBM InfoSphere Information Server Cross-Site Scripting — InfoSphere Information Server CWE-79 4.8 Medium 2026-03-25
CVE-2025-14974 IBM InfoSphere Information Server is vulnerable due to Insecure Direct Object Reference — InfoSphere Information Server CWE-639 5.7 Medium 2026-03-25
CVE-2026-1262 IBM InfoSphere Information Server Information Disclosure — InfoSphere Information Server CWE-209 4.3 Medium 2026-03-25
CVE-2025-14912 IBM InfoSphere Information Server is vulnerable to server-side request forgery — InfoSphere Information Server CWE-918 5.4 Medium 2026-03-25
CVE-2025-14810 IBM InfoSphere Information Server is vulnerable due to insufficient session expiration — InfoSphere Information Server CWE-613 6.3 Medium 2026-03-25
CVE-2025-14808 IBM InfoSphere Information Server is vulnerable due to disclosure of sensitive information — InfoSphere Information Server CWE-598 3.1 Low 2026-03-25
CVE-2025-14790 IBM InfoSphere Information Server is vulnerable to disclosure of sensitive information — InfoSphere Information Server CWE-522 6.5 Medium 2026-03-25
CVE-2026-1567 IBM InfoSphere Information Server is affected by an XML external entity injection (XXE) vulnerability — InfoSphere Information Server CWE-611 7.1 High 2026-03-03
CVE-2026-1265 IBM InfoSphere Information Server is vulnerable due to sensitive information written to a log file — InfoSphere Information Server CWE-532 4.3 Medium 2026-03-03
CVE-2025-12832 IBM InfoSphere Information Server Server-Side Request Forgery — InfoSphere Information Server CWE-918 4.6 Medium 2025-12-08
CVE-2025-12531 IBM InfoSphere Information Server is affected by an XML external entity injection (XXE) vulnerability — InfoSphere Information Server CWE-611 7.1 High 2025-11-03
CVE-2025-33003 IBM InfoSphere Information Server is vulnerable to privilege escalation — InfoSphere Information Server CWE-250 7.8 High 2025-10-31
CVE-2025-36245 IBM InfoSphere Information Server command execution — InfoSphere Information Server CWE-78 8.8 High 2025-09-29
CVE-2025-36034 IBM InfoSphere DataStage Flow Designer information disclosure — InfoSphere Information Server CWE-319 5.3 Medium 2025-06-26
CVE-2025-0966 IBM InfoSphere Information Server SQL injection — InfoSphere Information Server CWE-89 7.6 High 2025-06-25
CVE-2025-3629 IBM InfoSphere Information Server file manipulation — InfoSphere Information Server CWE-282 4.3 Medium 2025-06-21
CVE-2025-3221 IBM InfoSphere Information Server denial of service — InfoSphere Information Server CWE-770 7.5 High 2025-06-21
CVE-2025-1499 IBM InfoSphere Information Server information disclosure — InfoSphere Information Server CWE-312 6.5 Medium 2025-06-01
CVE-2025-1138 IBM Information Server information disclosure — InfoSphere Information Server CWE-548 4.3 Medium 2025-05-15
CVE-2025-25046 IBM InfoSphere Information Server information disclosure — InfoSphere Information Server CWE-319 3.7 Low 2025-04-23
CVE-2025-25045 IBM InfoSphere Information Server information disclosure — InfoSphere Information Server CWE-209 4.3 Medium 2025-04-23
CVE-2024-22351 IBM InfoSphere Information Server session fixation — InfoSphere Information Server CWE-613 6.3 Medium 2025-04-23

This page lists every published CVE security advisory associated with IBM. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.