Support Us — Your donation helps us keep running

Goal: 1000 CNY,Raised: 1000 CNY

100.0%

IBM — Vulnerabilities & Security Advisories 4615

Browse all 4615 CVE security advisories affecting IBM. AI-powered Chinese analysis, POCs, and references for each vulnerability.

CVE IDTitleCVSSSeverityPaused
CVE-2025-13686 DataStage on Cloud Pak for Data is vulnerable to arbitrary code injection due to runtime environment — DataStage on Cloud Pak for DataCWE-78 6.3 Medium2026-03-03
CVE-2025-13687 DataStage on Cloud Pak for Data is vulnerable to arbitrary code injection due to runtime environment — DataStage on Cloud Pak for DataCWE-78 6.3 Medium2026-03-03
CVE-2025-13688 DataStage on Cloud Pak for Data is vulnerable to arbitrary code injection due to runtime environment — DataStage on Cloud Pak for DataCWE-78 6.3 Medium2026-03-03
CVE-2025-14456 IBM MQ Appliance uses weaker than expected cryptographic algorithms — MQ ApplianceCWE-327 6.5AIMediumAI2026-03-03
CVE-2025-14480 IBM Aspera faspio Gateway 1.3.7 has addressed a vulnerability affected by weak cryptographic algorithms — Aspera faspio GatewayCWE-327 5.1 Medium2026-03-03
CVE-2026-1567 IBM InfoSphere Information Server is affected by an XML external entity injection (XXE) vulnerability — InfoSphere Information ServerCWE-611 7.1 High2026-03-03
CVE-2026-1713 IBM MQ is affected by an authority vulnerablility — MQCWE-305 6.8AIMediumAI2026-03-03
CVE-2025-13490 IBM App Connect Enterprise Certified Container IntegrationServer and IntegrationRuntime operands that report metrics are vulnerable to loss of confidentiality — App Connect Operator 5.9 Medium2026-03-03
CVE-2025-13616 DataStage on Cloud Pak for Data is vulnerable to sensitive information leak due to HTTP response — DataStage on Cloud Pak for DataCWE-497 6.5 Medium2026-03-03
CVE-2025-13734 IBM Engineering Requirements Management DOORS Next could allow an authenticated user to access and modify data beyond authorized permissions — Engineering Requirements Management DOORS NextCWE-862 5.4 Medium2026-03-03
CVE-2025-14604 The following vulnerabilities, which may affect IBM Storage Scale when a directory has a specific ACL composition and could lead to improper execute permissions, have been remediated in Storage Scale versions 5.2.3.6 and 6.0.0.2 — Storage ScaleCWE-732 6.6 Medium2026-03-03
CVE-2025-14923 IBM WebSphere Application Server Liberty could provide weaker than expected security — WebSphere Application Server - LibertyCWE-321 4.7 Medium2026-03-03
CVE-2025-36363 IBM DevOps Plan is vulnerable to Excessive Authentication Attempts — DevOps PlanCWE-307 5.9 Medium2026-03-03
CVE-2025-36364 IBM DevOps Plan REST APIs are vulnerable to exposure of sensitive data through request query parameters. — DevOps PlanCWE-525 6.2 Medium2026-03-03
CVE-2026-1265 IBM InfoSphere Information Server is vulnerable due to sensitive information written to a log file — InfoSphere Information ServerCWE-532 4.3 Medium2026-03-03
CVE-2026-2606 IBM webMethods API Management fails to validate user input and enables unauthorized arbitrary file read — webMethods API Gateway (on-prem)CWE-22 6.5 Medium2026-03-03
CVE-2025-13333 IBM WebSphere Application Server could provide weaker than expected security — WebSphere Application ServerCWE-358 4.4 Medium2026-02-17
CVE-2025-13689 DataStage on Cloud Pak for Data is vulnerable to arbitrary code injection due to runtime environment — DataStage on Cloud PakCWE-434 8.8 High2026-02-17
CVE-2023-38005 Improper Access Control and Exposure of Information Through Directory Listing vulnerabilities affect IBM Cloud Pak System[, ] — Cloud Pak SystemCWE-284 4.3 Medium2026-02-17
CVE-2025-33135 IBM Financial Transaction Manager for ACH Services and Check Services is impacted by multiple vulnerabilities — Financial Transaction Manager for ACH Services and Check Services for Multi-PlatformCWE-79 6.1 Medium2026-02-17
CVE-2025-33088 Multiple Vulnerabilities in IBM Concert Software. — ConcertCWE-732 7.4 High2026-02-17
CVE-2025-36183 Privileged User File Upload Vulnerability Leading to Limited Server-Side Execution affects watsonx.data — watsonx.dataCWE-434 3.8 Low2026-02-17
CVE-2025-36348 The Dashboard of IBM Sterling B2B Integrator and IBM Sterling File Gateway is Vulnerable to Information Disclosure — Sterling B2B IntegratorCWE-209 4.9 Medium2026-02-17
CVE-2025-36376 IBM Security QRadar EDR Software has multiple vulnerabilities — Security QRadar EDRCWE-613 6.3 Medium2026-02-17
CVE-2025-36377 IBM Security QRadar EDR Software has multiple vulnerabilities — Security QRadar EDRCWE-613 6.3 Medium2026-02-17
CVE-2025-36379 IBM Security QRadar EDR Software has multiple vulnerabilities — Security QRadar EDRCWE-326 5.9 Medium2026-02-17
CVE-2025-13691 DataStage on Cloud Pak for Data is vulnerable to sensitive information leaks due to HTTP processing — DataStage on Cloud Pak for DataCWE-497 8.1 High2026-02-17
CVE-2025-14289 IBM webMethods Integration Server is vulnerable to HTML injection — webMethods Integration ServerCWE-80 5.4 Medium2026-02-17
CVE-2025-27898 Multiple vulnerabilities in IBM Java SDK affecting Db2 Recovery Expert for Linux, Unix and Windows — DB2 Recovery Expert for LUWCWE-613 6.3 Medium2026-02-17
CVE-2025-27899 Multiple vulnerabilities in IBM Java SDK affecting Db2 Recovery Expert for Linux, Unix and Windows — DB2 Recovery Expert for LUWCWE-526 5.3 Medium2026-02-17

This page lists every published CVE security advisory associated with IBM. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.