Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

IBM — Vulnerabilities & Security Advisories 4629

Browse all 4629 CVE security advisories affecting IBM. AI-powered Chinese analysis, POCs, and references for each vulnerability.

IBM operates as a multinational technology and consulting corporation, primarily providing enterprise software, hybrid cloud services, and artificial intelligence solutions. Its extensive portfolio, including the Red Hat OpenShift platform and Watson AI suite, creates a broad attack surface that has historically been associated with Remote Code Execution (RCE) vulnerabilities, particularly within web application frameworks and middleware. Cross-site scripting (XSS) and privilege escalation flaws also frequently appear in its legacy enterprise applications and containerized environments. While the company maintains robust security protocols, past incidents have included data breaches affecting customer information and supply chain compromises. The high volume of recorded Common Vulnerabilities and Exposures (CVEs) reflects the complexity and scale of its global infrastructure rather than inherent systemic failure, though it necessitates rigorous patch management and continuous monitoring for enterprise clients relying on its diverse technological stack.

CVE IDTitleCVSSSeverityPublished
CVE-2025-0823 IBM MQ path traversal — Cognos AnalyticsCWE-22 6.5 Medium2025-02-28
CVE-2025-23225 IBM MQ denial of service — MQCWE-230 6.5 Medium2025-02-28
CVE-2024-54173 IBM MQ information disclosure — MQCWE-1323 4.7 Medium2025-02-28
CVE-2025-0975 IBM MQ code execution — MQCWE-150 8.8 High2025-02-28
CVE-2024-54170 IBM EntireX denial of service — EntireXCWE-1333 5.5 Medium2025-02-27
CVE-2024-54169 IBM EntireX path traversal — EntireXCWE-22 6.5 Medium2025-02-27
CVE-2025-0759 IBM EntireX race condition — EntireXCWE-367 3.3 Low2025-02-27
CVE-2024-56810 IBM EntireX information disclosure — EntireXCWE-209 3.3 Low2025-02-27
CVE-2024-56496 IBM EntireX information disclosure — EntireXCWE-209 3.3 Low2025-02-27
CVE-2024-56495 IBM EntireX information disclosure — EntireXCWE-209 3.3 Low2025-02-27
CVE-2024-56811 IBM EntireX information disclosure — EntireXCWE-209 3.3 Low2025-02-27
CVE-2024-56493 IBM EntireX information disclosure — EntireXCWE-209 3.3 Low2025-02-27
CVE-2024-56494 IBM EntireX information disclosure — EntireXCWE-209 3.3 Low2025-02-27
CVE-2024-56812 IBM EntireX information disclosure — EntireXCWE-209 3.3 Low2025-02-27
CVE-2025-0719 IBM Cloud Pak for Data cross-site scripting — Cloud Pak for DataCWE-79 6.1 Medium2025-02-26
CVE-2024-55898 IBM i privilege escalation — iCWE-427 8.5 High2025-02-24
CVE-2024-22341 IBM Watson Query on Cloud Pak for Data information disclosure — Watson Query on Cloud Pak for DataCWE-73 5.3 Medium2025-02-22
CVE-2024-45674 IBM Security Verify Bridge information disclosure — Security Verify Bridge Directory SyncCWE-532 3.3 Low2025-02-21
CVE-2025-1403 Qiskit SDK denial of service — Qiskit SDKCWE-502 8.6 High2025-02-21
CVE-2024-45673 IBM Security Verify Bridge information disclosure — Security Verify Bridge Directory SyncCWE-260 5.5 Medium2025-02-21
CVE-2025-0161 IBM Security Verify Access Appliance code injection — Security Verify AccessCWE-94 7.8 High2025-02-20
CVE-2024-49337 IBM OpenPages HTML injection — OpenPages with WatsonCWE-80 5.4 Medium2025-02-20
CVE-2024-49344 IBM OpenPages session fixation — OpenPages with WatsonCWE-384 4.3 Medium2025-02-20
CVE-2024-49779 IBM OpenPages cross-site request forgery — OpenPages with WatsonCWE-352 4.3 Medium2025-02-20
CVE-2024-49781 IBM OpenPages XML external entity injection — OpenPages with WatsonCWE-611 7.1 High2025-02-20
CVE-2024-49780 IBM OpenPages path traversal — OpenPages with WatsonCWE-22 5.3 Medium2025-02-20
CVE-2024-49782 IBM OpenPages improper certificate validation — OpenPages with WatsonCWE-297 6.8 Medium2025-02-20
CVE-2024-43196 IBM OpenPages data manipulation — OpenPages with WatsonCWE-296 4.3 Medium2025-02-20
CVE-2024-49355 IBM OpenPages log manipulation — OpenPages with WatsonCWE-117 5.3 Medium2025-02-20
CVE-2023-47160 IBM Cognos Controller XML external entity injection — Cognos ControllerCWE-611 8.2 High2025-02-19

This page lists every published CVE security advisory associated with IBM. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.