Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

IBM — Vulnerabilities & Security Advisories 4790

Browse all 4790 CVE security advisories affecting IBM. AI-powered Chinese analysis, POCs, and references for each vulnerability.

IBM operates as a multinational technology and consulting corporation, primarily providing enterprise software, hybrid cloud services, and artificial intelligence solutions. Its extensive portfolio, including the Red Hat OpenShift platform and Watson AI suite, creates a broad attack surface that has historically been associated with Remote Code Execution (RCE) vulnerabilities, particularly within web application frameworks and middleware. Cross-site scripting (XSS) and privilege escalation flaws also frequently appear in its legacy enterprise applications and containerized environments. While the company maintains robust security protocols, past incidents have included data breaches affecting customer information and supply chain compromises. The high volume of recorded Common Vulnerabilities and Exposures (CVEs) reflects the complexity and scale of its global infrastructure rather than inherent systemic failure, though it necessitates rigorous patch management and continuous monitoring for enterprise clients relying on its diverse technological stack.

CVE IDTitleCVSSSeverityPublished
CVE-2026-11708 IBM WebSphere Application Server is affected by a cross-site scripting vulnerability — WebSphere Application ServerCWE-79 9.3 Critical2026-06-30
CVE-2026-11712 IBM WebSphere Application Server is affected by a cross-site scripting vulnerability — WebSphere Application ServerCWE-79 9.3 Critical2026-06-30
CVE-2026-11714 IBM WebSphere Application Server Liberty is affected by an authorization bypass vulnerability — WebSphere Application Server - LibertyCWE-918 8.5 High2026-06-30
CVE-2026-11806 IBM WebSphere Application Server Liberty is affected by a an arbitrary file read vulnerability — WebSphere Application Server - LibertyCWE-444 7.2 High2026-06-30
CVE-2026-11906 IBM® Db2® federated server is vulnerable to a denial of service due to improper neutralization of special elements in the data query logic of XMLTable-derived columns by autheticated user — Db2CWE-1284 6.5 Medium2026-06-30
CVE-2026-12084 IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to a Permissive Cross-domain Security Policy with Untrusted Domains — UCD - IBM DevOps DeployCWE-942 5.4 Medium2026-06-30
CVE-2026-12085 IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptable to an Insertion of Sensitive Information Into Sent Data vulnerability — UCD - IBM UrbanCode DeployCWE-201 6.5 Medium2026-06-30
CVE-2026-12086 IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to a Insertion of Sensitive Information into Log File Vulnerability — UCD - IBM UrbanCode DeployCWE-532 6.2 Medium2026-06-30
CVE-2026-13449 XXE attack in IBM Business Automation Manager Open Editions — Business Automation Manager Open EditionsCWE-611 7.6 High2026-06-30
CVE-2026-13759 IBM WebSphere eXtreme Scale is affected by Insecure Deserilization — WebSphere Extreme ScaleCWE-502 7.5 High2026-06-30
CVE-2026-13772 IBM WebSphere eXtreme Scale's OQL is affected by remote code execution — WebSphere Extreme ScaleCWE-470 7.5 High2026-06-30
CVE-2026-13773 IBM WebSphere eXtreme Scale is affected by server side request forgery when ORB is used as Transport Protocol — WebSphere Extreme ScaleCWE-918 6.0 Medium2026-06-30
CVE-2026-3602 IBM App Connect Enterprise and IBM Integration Bus for z/OS toolkit is vulnerable to an sql injection — App Connect EnterpriseCWE-73 4.7 Medium2026-06-30
CVE-2026-7663 Unauthenticated Cross-User MCP Resource Access and Tool Execution via Streamable Transport Authorization Bypass — Langflow OSSCWE-285 9.1 Critical2026-06-30
CVE-2026-7803 Flow Validation Bypass via Empty Component Type Field — Langflow OSSCWE-20 9.8 Critical2026-06-30
CVE-2026-7871 Insecure Deserialization in Redis Cache Backend — Langflow OSSCWE-502 9.8 Critical2026-06-30
CVE-2026-7873 Code Injection Vulnerability in Code Validation Endpoint — Langflow OSSCWE-94 9.9 Critical2026-06-30
CVE-2026-7874 Weak Cryptographic Key Derivation Exposed All Stored Credentials — Langflow OSSCWE-338 9.1 Critical2026-06-30
CVE-2026-9002 IBM WebSphere eXtremes Scale is affected by uncontrolled resource consumption when XDF is enabled — WebSphere Extreme ScaleCWE-400 6.5 Medium2026-06-30
CVE-2026-9836 IBM DataStage Flow Designer application is affected by an information disclosure vulnerability — InfoSphere Information ServerCWE-200 3.5 Low2026-06-30
CVE-2026-10852 Websphere Application Server is Affected By a Denial of Service — WebSphere Application ServerCWE-476 5.9 Medium2026-06-22
CVE-2026-7253 IBM Sterling File Gateway SQL Injection — Sterling B2B IntegratorCWE-89 6.0 Medium2026-06-22
CVE-2026-9320 IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities — WebSphere Application ServerCWE-400 5.9 Medium2026-06-22
CVE-2026-9071 IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by Uncontrolled Resource Consumption — WebSphere Application ServerCWE-400 7.5 High2026-06-22
CVE-2026-9006 IBM WebSphere Application Server is affected by server-side request forgery — WebSphere Application ServerCWE-918 7.4 High2026-06-22
CVE-2026-8646 IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities — WebSphere Application ServerCWE-444 7.4 High2026-06-22
CVE-2026-10845 IBM WebSphere Application Server is affected by an authentication bypass vulnerability — WebSphere Application ServerCWE-287--2026-06-22
CVE-2024-51454 IBM Engineering Lifecycle Management - Engineering Workflow Management is impacted by vulnerabilities Host Header Injection observed — Engineering Workflow ManagementCWE-644 6.5 Medium2026-06-22
CVE-2023-33854 Multiple vulnerabilities affect IBM Db2® on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data. — Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for DataCWE-294 5.3 Medium2026-06-22
CVE-2026-9610 Multiple Vulnerabilities in IBM Datacap — DatacapCWE-425 2.3 Low2026-06-22

This page lists every published CVE security advisory associated with IBM. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.