ibm
538 known vulnerabilities affecting ibm products.
Products
aix 167
vios 149
i 133
websphere_application_server 40
power_system_e1180_\(9080-heu\) 29
power_system_e1180_\(9080-heu\)_firmware 29
power_system_e1080_\(9080-hex\) 28
power_system_e1080_\(9080-hex\)_firmware 28
power_system_e1150_\(9043-mru\) 25
power_system_e1150_\(9043-mru\)_firmware 25
power_system_e1050_\(9043-mrx\) 25
power_system_e1050_\(9043-mrx\)_firmware 25
power_system_l1022_\(9786-22h\) 25
power_system_l1022_\(9786-22h\)_firmware 25
power_system_l1024_\(9786-42h\) 25
power_system_l1024_\(9786-42h\)_firmware 25
power_system_l1122_\(9856-22h\) 25
power_system_l1122_\(9856-22h\)_firmware 25
power_system_l1124_\(9856-42h\) 25
power_system_l1124_\(9856-42h\)_firmware 25
power_system_s1012_\(9028-21b\) 25
power_system_s1012_\(9028-21b\)_firmware 25
power_system_s1014_\(9105-41b\) 25
power_system_s1014_\(9105-41b\)_firmware 25
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-13460 | Medium | 0.3% | 7.5 | IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 GUI conta… | |
| CVE-2026-16722 | Medium | 0.3% | 8.8 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obta… | |
| CVE-2026-17082 | Medium | 0.3% | 8.8 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain… | |
| CVE-2026-18249 | Medium | 0.3% | 8.4 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain… | |
| CVE-2026-8620 | Medium | 0.3% | 7.5 | IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8… | |
| CVE-2026-13361 | Medium | 0.3% | 8.8 | IBM Informix oninit sq_sgkprepare RCE via unchecked SQL Interface length field. | |
| CVE-2026-81832 | Medium | 0.3% | 7.7 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.… | |
| CVE-2026-7769 | Medium | 0.3% | 8.1 | IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2… | |
| CVE-2026-10543 | Medium | 0.3% | 8.2 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to privil… | |
| CVE-2026-80436 | Medium | 0.3% | 8.5 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated a… | |
| CVE-2026-8400 | Medium | 0.3% | 8.1 | IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Serv… | |
| CVE-2026-16815 | Medium | 0.3% | 8.6 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of … | |
| CVE-2026-16847 | Medium | 0.3% | 8.8 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to e… | |
| CVE-2026-80378 | Medium | 0.3% | 8.5 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated a… | |
| CVE-2026-14970 | Medium | 0.3% | 7.5 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM server process is crashing dur… | |
| CVE-2026-16837 | Medium | 0.3% | 7.5 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to c… | |
| CVE-2026-17276 | Medium | 0.3% | 9.6 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to esca… | |
| CVE-2024-25039 | Medium | 0.3% | 7.5 | IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 throu… | |
| CVE-2026-14981 | Medium | 0.3% | 7.5 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Serv… | |
| CVE-2026-15057 | Medium | 0.3% | 7.5 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerab… | |
| CVE-2026-16192 | Medium | 0.3% | 7.1 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected… | |
| CVE-2025-36255 | Medium | 0.3% | 7.5 | IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0… | |
| CVE-2026-8834 | Medium | 0.3% | 8.0 | IBM HTTP Server 8.5, and 9.0 contains a buffer overflow vulnerability. A privile… | |
| CVE-2026-18489 | Medium | 0.3% | 7.4 | IBM ContextForge MCP Gateway - Translate utility <= 1.0.8 MCP Context Forge coul… | |
| CVE-2026-16967 | Medium | 0.3% | 8.5 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain… | |
| CVE-2026-8835 | Medium | 0.3% | 7.3 | IBM HTTP Server 8.5, and 9.0 is vulnerable to invalid pointer dereference. A pri… | |
| CVE-2026-17024 | Medium | 0.3% | 7.7 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to e… | |
| CVE-2026-17111 | Medium | 0.3% | 7.6 | IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to SQL injection. A remote attacker co… | |
| CVE-2026-16814 | Medium | 0.3% | 8.8 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to e… | |
| CVE-2026-13267 | Medium | 0.2% | 8.1 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access … | |
| CVE-2026-16708 | Medium | 0.2% | 8.3 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain s… | |
| CVE-2026-11923 | Medium | 0.2% | 7.4 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access … | |
| CVE-2026-14980 | Medium | 0.2% | 8.3 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerab… | |
| CVE-2026-17445 | Medium | 0.2% | 8.2 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypa… | |
| CVE-2026-15078 | Medium | 0.2% | 8.1 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote attacker … | |
| CVE-2026-12947 | Medium | 0.2% | 7.5 | IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.… | |
| CVE-2026-8862 | Medium | 0.2% | 7.5 | IBM Netezza Software 11.3.0.3 through Interim Fix 002 has credentials that are h… | |
| CVE-2026-16932 | Medium | 0.2% | 8.8 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to ex… | |
| CVE-2026-15328 | Medium | 0.2% | 7.4 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Serv… | |
| CVE-2026-17617 | Medium | 0.2% | 8.5 | IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side… | |
| CVE-2026-1346 | Medium | 0.2% | 9.3 | IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify… | |
| CVE-2026-80434 | Medium | 0.2% | 7.4 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated a… | |
| CVE-2026-10534 | Medium | 0.2% | 8.4 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer… | |
| CVE-2026-14996 | Medium | 0.2% | 8.2 | IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 has addressed a vulnerability related… | |
| CVE-2026-81207 | Medium | 0.2% | 8.5 | IBM DataStage on Cloud Pak for Data 5.4.0.0 allows any authenticated tenant — wi… | |
| CVE-2026-13463 | Medium | 0.2% | 7.5 | IBM Cloud Pak System 2.3.5.0 could allow a local attacker to obtain sensitive in… | |
| CVE-2026-10545 | Medium | 0.2% | 7.5 | IBM Planning Analytics Local 2.1.0 through 2.1.21 is vulnerable to an open redir… | |
| CVE-2026-15064 | Medium | 0.2% | 8.7 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Serv… | |
| CVE-2026-11707 | Medium | 0.2% | 9.3 | IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Applicati… | |
| CVE-2026-16835 | Medium | 0.2% | 9.6 | IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 thr… |