ibm
538 known vulnerabilities affecting ibm products.
Products
aix 167
vios 149
i 133
websphere_application_server 40
power_system_e1180_\(9080-heu\) 29
power_system_e1180_\(9080-heu\)_firmware 29
power_system_e1080_\(9080-hex\) 28
power_system_e1080_\(9080-hex\)_firmware 28
power_system_e1150_\(9043-mru\) 25
power_system_e1150_\(9043-mru\)_firmware 25
power_system_e1050_\(9043-mrx\) 25
power_system_e1050_\(9043-mrx\)_firmware 25
power_system_l1022_\(9786-22h\) 25
power_system_l1022_\(9786-22h\)_firmware 25
power_system_l1024_\(9786-42h\) 25
power_system_l1024_\(9786-42h\)_firmware 25
power_system_l1122_\(9856-22h\) 25
power_system_l1122_\(9856-22h\)_firmware 25
power_system_l1124_\(9856-42h\) 25
power_system_l1124_\(9856-42h\)_firmware 25
power_system_s1012_\(9028-21b\) 25
power_system_s1012_\(9028-21b\)_firmware 25
power_system_s1014_\(9105-41b\) 25
power_system_s1014_\(9105-41b\)_firmware 25
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-7868 | Low | 0.2% | 6.5 | IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 allows … | |
| CVE-2025-12530 | Low | 0.2% | 5.9 | IBM watsonx.data intelligence 5.2.2, 5.3.0, 5.3.1, 5.3.1 through Patch 1 transmi… | |
| CVE-2026-17227 | Low | 0.2% | 5.4 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attack… | |
| CVE-2026-18681 | Low | 0.2% | 6.8 | IBM Server Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW… | |
| CVE-2026-16849 | Low | 0.2% | 4.3 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to c… | |
| CVE-2026-16886 | Low | 0.2% | 4.3 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to c… | |
| CVE-2026-14514 | Low | 0.2% | 6.5 | IBM Reliable Scalable Cluster Technology (RSCT) 3.0 could allow a remote attacke… | |
| CVE-2026-8852 | Low | 0.2% | 6.2 | IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional… | |
| CVE-2026-9745 | Low | 0.2% | 6.5 | IBM Netezza Software 11.3.0.3 through Interim Fix 002 has operations that are pe… | |
| CVE-2025-36148 | Low | 0.2% | 5.4 | IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 … | |
| CVE-2026-17028 | Low | 0.2% | 6.5 | IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through… | |
| CVE-2026-18246 | Low | 0.2% | 3.0 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypa… | |
| CVE-2026-17079 | Low | 0.2% | 6.3 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attack… | |
| CVE-2025-36398 | Low | 0.2% | 5.4 | IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0… | |
| CVE-2025-36126 | Low | 0.2% | 6.4 | IBM Cognos Analytics 11.2.0, 12.0, and 12.1.0 and IBM Cognos Transformer 12.0, 1… | |
| CVE-2025-14290 | Low | 0.2% | 5.4 | IBM webMethods Integration (on prem) -Integration Server 10.15 through IS_10.15_… | |
| CVE-2026-16829 | Low | 0.2% | 5.3 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to c… | |
| CVE-2026-10569 | Low | 0.2% | 4.3 | IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.23, and 7.3 through 7.3.2.18 an… | |
| CVE-2026-3158 | Low | 0.2% | 4.3 | IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2… | |
| CVE-2026-14515 | Low | 0.2% | 6.1 | IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote a… | |
| CVE-2026-7362 | Low | 0.2% | 4.3 | IBM Sterling B2B Integrator 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2… | |
| CVE-2026-9736 | Low | 0.2% | 5.3 | IBM Netezza Software 11.3.0.3 through Interim Fix 002 could allow an unauthorize… | |
| CVE-2026-16724 | Low | 0.2% | 4.5 | IBM Virtualization Management Interface FW1110.00 through FW1110.30, FW1120.00 t… | |
| CVE-2026-18150 | Low | 0.2% | 4.3 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obta… | |
| CVE-2025-36145 | Low | 0.2% | 5.4 | IBM watsonx.data 2.2 through 2.3.1 IBM Lakehouse does not properly restrict inbo… | |
| CVE-2026-11383 | Low | 0.2% | 5.4 | IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Applicati… | |
| CVE-2025-36298 | Low | 0.2% | 5.4 | IBM Sterling B2B Integrator 6.1.2.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_2… | |
| CVE-2025-36431 | Low | 0.2% | 5.4 | IBM Sterling B2B Integrator 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gate… | |
| CVE-2026-16694 | Low | 0.2% | 6.4 | IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to stored cross-site scripting. This … | |
| CVE-2025-0152 | Low | 0.2% | 6.1 | IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 throu… | |
| CVE-2025-36271 | Low | 0.2% | 5.9 | IBM Integrated Analytics System 1.0.0.0 through 1.0.31.0 uses weaker than expect… | |
| CVE-2026-18250 | Low | 0.2% | 6.3 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obta… | |
| CVE-2025-36290 | Low | 0.2% | 5.9 | IBM Integrated Analytics System 1.0.0.0 through 1.0.31.0 does not validate or im… | |
| CVE-2024-40683 | Low | 0.2% | 6.3 | IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.… | |
| CVE-2026-17483 | Low | 0.2% | 4.3 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 IBM i could allow a local attacker to del… | |
| CVE-2026-7771 | Low | 0.1% | 5.5 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a trap… | |
| CVE-2026-12086 | Low | 0.1% | 6.2 | IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.23, and 7.3 through 7.3.2.18 an… | |
| CVE-2025-13044 | Low | 0.1% | 6.2 | IBM Concert 1.0.0 through 2.2.0 creates temporary files with predictable names, … | |
| CVE-2026-7775 | Low | 0.1% | 5.5 | IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.6, 6.2.1.0 through 6.2.1.1_2, … | |
| CVE-2026-16938 | Low | 0.1% | 6.9 | IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 thr… | |
| CVE-2026-16914 | Low | 0.1% | 6.7 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to ex… | |
| CVE-2026-16826 | Low | 0.1% | 5.3 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary c… | |
| CVE-2026-16693 | Low | 0.1% | 4.4 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obta… | |
| CVE-2026-16951 | Low | 0.1% | 6.7 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local authenticated … | |
| CVE-2026-9036 | Low | 0.1% | 5.9 | IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or impro… | |
| CVE-2026-17499 | Low | 0.1% | 4.4 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary c… | |
| CVE-2026-16944 | Low | 0.1% | 6.7 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to ex… | |
| CVE-2025-36192 | Low | 0.1% | 6.7 | IBM DS8A00( R10.1) 10.10.106.0 and IBM DS8A00 ( R10.0) 10.1.3.010.2.45.0 and IBM… | |
| CVE-2026-15656 | Low | 0.1% | 4.3 | IBM Maximo Application Suite 9.2, 9.1, and 9.0 does not set the secure attribute… | |
| CVE-2026-16883 | Low | 0.1% | 5.5 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to ob… |