By vendor

Ibm vulnerabilities

Known CVEs affecting Ibm products, prioritized by severity, with SEC.co remediation and detection guidance.

53 published vulnerabilities

  • CVE-2026-7870HIGH 8.8

    IBM i versions 7.3 through 7.6 contain a privilege escalation vulnerability arising from improper library resolution. An authenticated user can exploit unqualified library calls to execute arbitrary code with administrator privileges, effectively bypassing access controls. The vulnerability requires valid system access but can be triggered without user interaction, making it a significant risk in environments where IBM i hosts business-critical applications.

  • CVE-2026-11594HIGH 8.5

    IBM WebSphere Application Server versions 8.5 and 9.0 contain a cross-site scripting (XSS) flaw in their administrative console. An attacker can inject malicious scripts that execute in the context of an administrator's browser session, potentially allowing unauthorized actions on the application server. The vulnerability requires network access to the console and user interaction, but once triggered, could compromise administrative functions and server integrity.

  • CVE-2026-11714HIGH 8.5

    IBM WebSphere Application Server Liberty contains a server-side request forgery (SSRF) vulnerability when the apiDiscovery feature is enabled. This flaw allows an authenticated attacker to make the affected server issue requests to arbitrary internal or external systems on behalf of the attacker, potentially accessing sensitive resources or data that should not be directly reachable. The vulnerability requires valid user credentials to exploit but can affect the confidentiality of data and the integrity of internal systems.

  • CVE-2026-9330HIGH 8.5

    IBM WebSphere Application Server versions 8.5 and 9.0 contain a flaw in how they validate incoming data during user authentication via SAML (Security Assertion Markup Language) web single sign-on. An attacker with valid login credentials can send a specially crafted request that, when processed through a vulnerable deserialization pathway, may execute arbitrary code on the server. This risk is elevated because it requires only basic authentication and can impact systems across an organization's trust boundary.

  • CVE-2025-36359HIGH 8.1

    IBM DevOps Automation 1.0.1 and IBM DevOps Loop 1.0.2 contain a session management flaw that fails to invalidate user session IDs once they expire. This allows an authenticated attacker who gains access to an expired session token to impersonate another user without needing their credentials. The vulnerability requires initial authentication access but poses a serious lateral movement and privilege escalation risk within DevOps environments where automation tools often have broad system permissions.

  • CVE-2026-3144HIGH 8.1

    IBM API Connect versions 12.1.0.0 through 12.1.0.3 ship with hardcoded default credentials that remain active until administrators manually enforce a password change. An attacker with network access can use these credentials to gain full unauthorized access to the API management platform before credential enforcement takes effect, potentially compromising API infrastructure, traffic, and data.

  • CVE-2026-9072HIGH 8.1

    IBM WebSphere Application Server and WebSphere Application Server Liberty face a critical remote code execution vulnerability when Intelligent Management is enabled with the WebServer Plug-in component. An attacker who can intercept or impersonate backend server communications can send malicious responses that execute arbitrary code on the affected application server or cause it to crash. The attack requires network access but no user interaction or authentication, making it a serious threat in production environments.

  • CVE-2026-13449HIGH 7.6

    IBM Business Automation Manager Open Editions versions 9.0.0 through 9.4.2 contain an XML external entity injection (XXE) vulnerability. An authenticated attacker can submit specially crafted XML to the application, allowing them to extract sensitive data from the system or trigger resource exhaustion attacks that degrade availability. The vulnerability requires valid credentials but poses meaningful risk in environments where internal users or compromised accounts could be leveraged.

  • CVE-2026-13759HIGH 7.5

    IBM WebSphere Extreme Scale versions 8.6.1.0 through 8.6.1.6 contain a deserialization vulnerability that allows attackers to execute arbitrary code on affected systems. The vulnerability exists because three internal classes fail to implement Java's standard class-filtering protections when deserializing untrusted data. When the Apache Coherence library is present on the classpath, attackers can exploit well-known gadget chains to achieve remote code execution. Two attack paths are possible: an authenticated attacker with the ability to inject malicious session attributes, or a network-adjacent attacker positioned on the grid replication communications channel. Both scenarios bypass normal deserialization safety mechanisms.

  • CVE-2026-13772HIGH 7.5

    IBM WebSphere Extreme Scale versions 8.6.1.0 through 8.6.1.6 contain a critical vulnerability in their Object Query Language (OQL) engine that allows authenticated attackers to execute arbitrary code on affected application servers. The vulnerability stems from unsafe handling of class names in OQL queries—the system dynamically loads and instantiates classes based on user input without any validation or blocklist. An attacker with valid credentials who can influence OQL query strings used by an application can trigger execution of arbitrary constructors within the WebSphere JVM. Additionally, a serialization variant can bypass Java's standard security filters when data moves between grid nodes, expanding the attack surface.

  • CVE-2026-4870HIGH 7.5

    IBM Qiskit SDK versions 0.43.0 through 2.5.0 contain a parser vulnerability that allows remote attackers to cause the application to crash by triggering excessive recursion. An attacker can send specially crafted input that forces the parser into a recursive loop, ultimately causing a segmentation fault and denying service to legitimate users. No authentication is required, and the attack can be launched over the network.

  • CVE-2026-8858HIGH 7.5

    IBM WebSphere Application Server and WebSphere Application Server Liberty contain a flaw in their Web Server Plug-in component that allows attackers to execute arbitrary code or trigger denial of service. The vulnerability is triggered when an attacker impersonates a legitimate application server and delivers specially crafted responses to the plug-in. This represents a meaningful risk to organizations deploying these products in network environments where an attacker could position themselves on the communication path.

  • CVE-2026-9071HIGH 7.5

    IBM WebSphere Application Server versions 9.0, 8.5, and Liberty versions 17.0.0.3 through 26.0.0.6 contain a vulnerability that allows remote attackers to crash or severely degrade server performance by sending specially crafted requests. The vulnerability causes the affected server to consume excessive memory, leading to denial of service. No authentication is required to exploit this issue, and attackers can trigger it over the network.

  • CVE-2026-11541HIGH 7.4

    IBM's WebSphere Application Server and CICS Transaction Gateway contain a flaw that allows attackers to craft specially formed HTTP requests that confuse how the server parses incoming traffic. By exploiting inconsistencies in request interpretation, an attacker can smuggle malicious requests past security controls, potentially accessing sensitive data or modifying information without proper authorization. This affects multiple versions of WebSphere Application Server and CICS Transaction Gateway deployed across enterprise environments.

  • CVE-2026-8646HIGH 7.4

    IBM WebSphere Application Server versions 9.0, 8.5, and Liberty versions 17.0.0.3 through 26.0.0.6 contain a flaw that allows attackers to craft malicious HTTP requests that bypass normal request processing. These smuggled requests can circumvent security controls, impersonate legitimate users, gain elevated privileges, and access sensitive data. The vulnerability requires specific conditions to exploit but poses significant risk to organizations relying on these servers.

  • CVE-2026-9006HIGH 7.4

    IBM WebSphere Application Server versions 8.5 and 9.0 contain a server-side request forgery (SSRF) flaw when the Ajax Proxy feature is enabled. An attacker can exploit this to make unauthorized requests from the vulnerable server, potentially accessing internal resources, bypassing security controls, or extracting sensitive information. The vulnerability requires specific network conditions but does not require user interaction or authentication.

  • CVE-2026-10845HIGH 7.3

    IBM WebSphere Application Server versions 8.5 and 9.0 contain an authentication bypass vulnerability in their JAX-WS (Java API for XML Web Services) implementations. An attacker on the network can exploit this flaw to bypass login controls and gain unauthorized access to affected applications without providing valid credentials. The vulnerability requires no user interaction and can be triggered remotely, making it a practical threat to organizations running these older WebSphere versions.

  • CVE-2026-11806HIGH 7.2

    IBM WebSphere Application Server Liberty versions 17.0.0.3 through 26.0.0.6 contain a vulnerability that allows an authenticated administrator to read arbitrary files from the server when the restConnector-2.0 feature is enabled. This is a high-severity issue because it bypasses normal file access controls and can expose sensitive configuration data, credentials, or application source code. The vulnerability requires high-level privileges to exploit, limiting its immediate blast radius but making it a serious concern for organizations where administrative accounts may be compromised or where insider threats are a consideration.

  • CVE-2026-11546HIGH 7.1

    IBM WebSphere Application Server Liberty versions 17.0.0.3 through 26.0.0.7 contain a server-side request forgery (SSRF) vulnerability that becomes exploitable when the adminCenter-1.0 feature is enabled. An authenticated attacker can abuse this flaw to make the vulnerable server perform unintended requests to internal or external systems, potentially compromising confidentiality and service availability. The vulnerability requires valid credentials to exploit, limiting the immediate blast radius but remaining a serious concern for organizations running affected Liberty versions with admin center enabled.

  • CVE-2024-51454MEDIUM 6.5

    IBM Engineering Workflow Management versions 7.0.2, 7.0.3, and 7.1 (up to specific interim fixes) contain a flaw in how they validate HTTP HOST headers. An attacker can inject malicious content into these headers to manipulate how the application processes requests. This could enable attackers to steal session credentials, poison cached content, or execute JavaScript in users' browsers. The vulnerability requires no authentication and can be triggered remotely over the network.

  • CVE-2024-54178MEDIUM 6.5

    IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data contain a resource allocation flaw that allows authenticated users to trigger a denial of service condition when creating new databases. An attacker with valid credentials can exhaust system resources during database creation, making the service unavailable to legitimate users. This is not a remote unauthenticated attack—the threat actor must first obtain valid authentication credentials.

  • CVE-2025-36327MEDIUM 6.5

    IBM watsonx.data intelligence contains a client-side security enforcement flaw that allows authenticated users to circumvent server-side protections. An attacker who has legitimate access to the system can manipulate client-side controls to perform actions they should not be authorized to perform, potentially modifying data or accessing functionality restricted by policy. This is a privilege escalation vulnerability requiring existing user credentials.

  • CVE-2026-11906MEDIUM 6.5

    IBM Db2 contains a vulnerability that allows authenticated users to crash the database by submitting specially crafted queries involving XMLTable-derived columns. An attacker with valid database credentials can trigger a denial of service condition, making the database unavailable to legitimate users. This requires authentication, so it is not exploitable by anonymous attackers, but it represents a risk from insider threats or compromised accounts.

  • CVE-2026-12085MEDIUM 6.5

    IBM's UrbanCode Deploy and DevOps Deploy products contain a vulnerability that allows authenticated users to access sensitive configuration data and secrets through API responses. An attacker with valid credentials could extract this information and use it to mount further attacks on the system. The issue affects specific versions of both products and requires authentication, limiting immediate exposure but creating meaningful risk for organizations using these deployment tools.

  • CVE-2026-4096MEDIUM 6.5

    IBM DevOps Plan versions 3.0.0 through 3.0.6 contain a flaw in how they validate HTTP HOST headers, allowing attackers to inject malicious header content. This could lead to several attack vectors including stealing user session data, poisoning cached content, or executing code in users' browsers through cross-site scripting (XSS). The vulnerability requires network access but no authentication or user interaction to exploit.

  • CVE-2026-9002MEDIUM 6.5

    IBM WebSphere Extreme Scale versions 8.6.1.0 through 8.6.1.6 contain a vulnerability that allows attackers on the same network to crash the application server. The flaw exists in how the system handles deeply nested Protocol Buffers messages without proper size limits, enabling an attacker to exploit this by sending specially crafted network packets that cause the Java Virtual Machine to run out of memory or exhaust the call stack, bringing down the service.

  • CVE-2025-36320MEDIUM 6.4

    IBM watsonx.data intelligence contains a stored cross-site scripting (XSS) vulnerability that allows authenticated users to inject malicious JavaScript into the web interface. Once injected, the script persists and executes in the browsers of other users who access the affected page, potentially enabling attackers to steal session credentials or manipulate application behavior. The vulnerability affects versions 5.2.0 through 5.3.0 and requires valid user credentials to exploit.

  • CVE-2026-12086MEDIUM 6.2

    IBM UrbanCode Deploy and DevOps Deploy store sensitive information—such as credentials, API keys, or other authentication material—in log files that are readable by any local user on the system. An attacker with local access can read these logs to extract secrets without needing elevated privileges. This is a local-only attack vector with no network component, but the confidentiality impact is significant because it can expose credentials used to access other systems.

  • CVE-2026-8059MEDIUM 6.1

    IBM Datacap and IBM Datacap Navigator versions 9.1.7, 9.1.8, and 9.1.9 contain a cross-site scripting (XSS) vulnerability in their Web UI. An unauthenticated attacker can inject malicious JavaScript code that executes in the browser of a legitimate user, potentially stealing credentials or modifying the application's behavior without the user's knowledge.

  • CVE-2025-2669MEDIUM 6.0

    IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data contain a token validation flaw that allows privileged users to exceed their intended permissions. A user with elevated credentials can bypass authorization controls to perform unauthorized operations and access sensitive data they shouldn't be able to reach. The vulnerability requires existing elevated privileges to exploit, limiting the immediate attack surface but posing significant risk to organizations where privileged accounts may be compromised or where insider threats are a concern.

  • CVE-2026-13773MEDIUM 6.0

    IBM WebSphere Extreme Scale versions 8.6.1.0 through 8.6.1.6 contain a deserialization flaw in approximately 50 auto-generated CORBA stub classes within the ogclient.jar file. When application code deserializes untrusted data using ObjectInputStream, an attacker can inject a malicious IOR (Interoperable Object Reference) string that causes the application to make outbound network connections to an attacker-controlled host. This server-side request forgery (SSRF) becomes particularly dangerous when combined with a separate flaw in IBM's Object Request Broker (ORB) that allows arbitrary class instantiation, potentially leading to remote code execution on the vulnerable JVM.

  • CVE-2026-7253MEDIUM 6.0

    IBM Sterling B2B Integrator and IBM Sterling File Gateway contain a SQL injection vulnerability that requires an attacker to hold privileged user credentials. Once authenticated, a malicious insider or compromised privileged account can craft SQL statements to read, insert, modify, or delete data directly from the backend database. This is a classic database access control failure that elevates an authenticated user's power far beyond their intended scope.

  • CVE-2025-12530MEDIUM 5.9

    IBM watsonx.data intelligence versions 5.2.2, 5.3.0, 5.3.1, and 5.3.1 through Patch 1 transmit sensitive data over unencrypted channels. An attacker positioned to intercept network traffic—such as on a shared network segment or through DNS/routing manipulation—could eavesdrop on communications and extract confidential information. This is a classic man-in-the-middle (MITM) vulnerability where encryption is either absent or improperly configured.

  • CVE-2025-36336MEDIUM 5.9

    IBM watsonx.data intelligence versions 5.2.0 through 5.3.0 transmit sensitive data without encryption, exposing it to interception by attackers positioned on the network path between clients and servers. An attacker could eavesdrop on this unencrypted traffic to steal confidential information. The vulnerability requires specific network conditions (high complexity attack) but affects a data intelligence platform where confidentiality breaches carry real business risk.

  • CVE-2026-10852MEDIUM 5.9

    IBM WebSphere Application Server and WebSphere Application Server Liberty contain a denial-of-service vulnerability in their WebServer Plug-in component. An attacker who can send specially crafted requests to a web server running this software can cause it to become unavailable or unresponsive. The vulnerability does not allow unauthorized access to data or system compromise—it is purely an availability impact. Exploitation requires network access but no special privileges or user interaction.

  • CVE-2026-9320MEDIUM 5.9

    IBM WebSphere Application Server versions 9.0 and 8.5, along with WebSphere Liberty versions 17.0.0.3 through 26.0.0.6, contain a denial-of-service vulnerability triggered by specially-crafted network requests. An attacker can exploit this remotely without authentication to exhaust server memory, causing service degradation or outages. The vulnerability does not compromise confidentiality or integrity—its impact is purely on availability.

  • CVE-2025-36321MEDIUM 5.7

    IBM watsonx.data intelligence versions 5.2.0 through 5.3.0 contain an HTML injection vulnerability that allows authenticated users to inject malicious HTML code into the application. When other users view the affected pages, the injected HTML executes in their browsers within the security context of the hosting site, potentially enabling credential theft, session hijacking, or malware distribution. The vulnerability requires an authenticated attacker and user interaction (viewing the injected content), but poses a meaningful risk in shared or collaborative environments.

  • CVE-2025-36372MEDIUM 5.5

    IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4 contain a flaw that allows authenticated database users to access sensitive information from internal monitoring and event tables they should not be able to view. An attacker with valid database credentials could exploit this to extract confidential data, though they cannot modify information or disrupt service. This affects Db2 installations on Linux, Unix, and Windows platforms, including Db2 Connect Server deployments.

  • CVE-2026-8636MEDIUM 5.5

    IBM Datacap and Datacap Navigator versions 9.1.7, 9.1.8, and 9.1.9 contain a memory exposure vulnerability that allows authenticated local users to extract sensitive credentials and encryption keys from the application's memory space. Once extracted, an attacker can use these keys to decrypt stored passwords, gain unauthorized access to the application, and retrieve sensitive data from the backend database. This is a local-privilege attack that requires existing system access but yields high-value credentials.

  • CVE-2025-33128MEDIUM 5.4

    IBM Engineering Workflow Management contains a stored cross-site scripting (XSS) vulnerability that allows authenticated users to inject malicious JavaScript into the Web UI. An attacker with valid credentials could craft a payload that executes in the browser of other users viewing the same application, potentially stealing session credentials or performing unauthorized actions on their behalf. The vulnerability requires user interaction (a victim must view the attacker's injected content) but spreads through a trusted application interface, making it a meaningful risk in collaborative engineering environments.

  • CVE-2025-36323MEDIUM 5.4

    IBM watsonx.data intelligence versions 5.2.0 through 5.3.0 contain a cross-site scripting (XSS) vulnerability that allows authenticated users to inject malicious JavaScript into the Web UI. An attacker with valid credentials could craft a payload that executes in the browser of other users viewing the application, potentially stealing session credentials or manipulating application behavior within that trusted session. This requires user interaction—the victim must click a malicious link or visit a compromised page—but operates within the security perimeter of an already-authenticated application.

  • CVE-2026-11372MEDIUM 5.4

    IBM TRIRIGA Application Platform versions 5.0.2 and 5.0.3 contain a cross-site scripting (XSS) vulnerability that allows authenticated users to inject malicious JavaScript into the web interface. An attacker with valid credentials can manipulate the application's behavior and potentially steal session credentials from other users. This requires an existing account but does not need user interaction to execute once injected.

  • CVE-2026-12084MEDIUM 5.4

    IBM DevOps Deploy (UCD) contains a Cross-Origin Resource Sharing (CORS) misconfiguration that allows attackers to trick authenticated users into performing unauthorized actions or exposing sensitive data. The vulnerability affects versions 8.1 through 8.1.2.6 and 8.2 through 8.2.1.0. Because CORS policies are not properly restricting trusted domains, an attacker can host a malicious webpage that, when visited by a logged-in DevOps Deploy user, silently executes privileged operations or exfiltrates information in the user's security context.

  • CVE-2023-33854MEDIUM 5.3

    IBM's Db2 database platform, when deployed on Cloud Pak for Data, contains a weakness that allows authenticated users to bypass client-side security checks and alter input data through man-in-the-middle (MITM) attacks. The vulnerability affects Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data across versions 4.8 through 5.3. While this requires an attacker to already have valid credentials and network positioning, successful exploitation could lead to unauthorized data modification without detection by client-side safeguards.

  • CVE-2026-3602MEDIUM 4.7

    IBM App Connect Enterprise and Integration Bus contain a SQL injection vulnerability that could allow a remote attacker to trick users into inadvertently creating files on their systems. While the attack requires user interaction and operates with local system access constraints, successful exploitation could result in unauthorized file creation or modification. The vulnerability affects multiple versions across IBM's integration middleware stack.

  • CVE-2025-36319MEDIUM 4.3

    IBM watsonx.data intelligence versions 5.2.0 through 5.3.0 contain a denial-of-service vulnerability accessible to authenticated users. An attacker with valid credentials can send a specially crafted HTTP request that exploits improper resource throttling controls, temporarily disrupting service availability. The vulnerability does not compromise confidentiality or integrity—only availability is at risk.

  • CVE-2025-36324MEDIUM 4.3

    IBM watsonx.data intelligence contains a server-side request forgery (SSRF) vulnerability that allows authenticated users to make unauthorized requests from the affected system. An attacker with valid credentials could potentially probe internal network resources, discover services running on the local network, or use the compromised system as a pivot point for further attacks. The vulnerability affects versions 5.2.0 through 5.3.0.

  • CVE-2025-36328MEDIUM 4.3

    IBM watsonx.data intelligence versions 5.2.0 through 5.3.0 leak sensitive information through verbose error messages displayed in web browsers. An attacker with valid credentials can trigger these detailed error responses to extract system details that could facilitate further attacks. This is an information disclosure vulnerability requiring authentication to exploit.

  • CVE-2025-36333MEDIUM 4.3

    IBM watsonx.data intelligence versions 5.2.0 through 5.3.0 contain a flaw that allows authenticated users to bypass intended workflow restrictions and perform actions they should not be permitted to execute. An attacker with valid credentials could exploit this to make unauthorized changes within the platform, though the vulnerability does not enable data theft or system unavailability. The issue stems from inadequate enforcement of behavioral workflow controls during user action validation.

  • CVE-2026-11595MEDIUM 4.3

    IBM WebSphere Application Server versions 9.0 and 8.5 contain a vulnerability in their administrative console's help system that could leak sensitive information to an attacker on the same network. The attacker needs network-adjacent access but no credentials or user interaction to exploit it. While the information disclosure is limited in scope, the flaw affects widely-deployed enterprise application servers and warrants timely patching.

  • CVE-2024-45636MEDIUM 4.1

    IBM Security QRadar EDR versions 3.12 through 3.12.24 contain a credential storage flaw where user passwords and authentication tokens are stored in plain text on disk. A local attacker with elevated system privileges can read these credentials directly, potentially gaining unauthorized access to QRadar EDR or downstream systems that those credentials protect. This is a local-only attack requiring existing high-level access to the affected system.

  • CVE-2026-9836LOW 3.5

    IBM InfoSphere Information Server versions 11.7.0.0 through 11.7.1.6 contain a vulnerability that allows authenticated users on the same network segment to access sensitive information they should not be able to view. The flaw requires an attacker to already have valid credentials and local network access, making opportunistic exploitation unlikely. This is a low-severity disclosure issue rather than a critical system compromise vector.

  • CVE-2026-9610LOW 2.3

    IBM Datacap and Datacap Navigator versions 9.1.7, 9.1.8, and 9.1.9 contain a flaw where certain features or data are accessible directly via URL without proper authorization checks, even though those features are not advertised in the user interface. An attacker with local access and elevated privileges could bypass intended security boundaries to view sensitive information.