Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

IBM — Vulnerabilities & Security Advisories 4629

Browse all 4629 CVE security advisories affecting IBM. AI-powered Chinese analysis, POCs, and references for each vulnerability.

IBM operates as a multinational technology and consulting corporation, primarily providing enterprise software, hybrid cloud services, and artificial intelligence solutions. Its extensive portfolio, including the Red Hat OpenShift platform and Watson AI suite, creates a broad attack surface that has historically been associated with Remote Code Execution (RCE) vulnerabilities, particularly within web application frameworks and middleware. Cross-site scripting (XSS) and privilege escalation flaws also frequently appear in its legacy enterprise applications and containerized environments. While the company maintains robust security protocols, past incidents have included data breaches affecting customer information and supply chain compromises. The high volume of recorded Common Vulnerabilities and Exposures (CVEs) reflects the complexity and scale of its global infrastructure rather than inherent systemic failure, though it necessitates rigorous patch management and continuous monitoring for enterprise clients relying on its diverse technological stack.

CVE IDTitleCVSSSeverityPublished
CVE-2024-41776 IBM Cognos Controller cross-site request forgery — Cognos ControllerCWE-352 6.5 Medium2024-12-03
CVE-2024-41777 IBM Cognos Controller hard coded credentials — Cognos ControllerCWE-798 7.5 High2024-12-03
CVE-2024-45676 IBM Cognos Controller file upload — Cognos ControllerCWE-351 4.3 Medium2024-12-03
CVE-2024-25036 IBM Cognos Controller authentication bypass — Cognos ControllerCWE-288 4.3 Medium2024-12-03
CVE-2024-25035 IBM Cognos Controller information disclosure — Cognos ControllerCWE-497 5.3 Medium2024-12-03
CVE-2024-40691 IBM Cognos Controller file upload — Cognos ControllerCWE-434 8.0 High2024-12-03
CVE-2024-25019 IBM Cognos Controller file upload — Cognos ControllerCWE-434 5.5 Medium2024-12-03
CVE-2021-29892 IBM Cognos Controller information disclosure — Cognos ControllerCWE-319 5.9 Medium2024-12-03
CVE-2024-49804 IBM Security Verify Access Appliance privilege escalation — Security Verify AccessCWE-250 7.8 High2024-11-29
CVE-2024-49806 IBM Security Verify Access Appliance hard coded credentials — Security Verify AccessCWE-798 9.4 Critical2024-11-29
CVE-2024-49805 IBM Security Verify Access Appliance hard coded credentials — Security Verify AccessCWE-798 9.4 Critical2024-11-29
CVE-2024-49803 IBM Security Verify Access Appliance command execution — Security Verify AccessCWE-78 9.8 Critical2024-11-29
CVE-2024-49353 IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data denial of service — Watson Speech Services Cartridge for IBM Cloud Pak for DataCWE-362 7.5 High2024-11-26
CVE-2024-49351 IBM Workload Scheduler information disclosure — Workload SchedulerCWE-256 5.5 Medium2024-11-26
CVE-2024-52899 IBM Data Virtualization Manager code execution — Data Virtualization Manager for z/OSCWE-94 8.5 High2024-11-26
CVE-2023-26280 IBM Jazz Foundation improper access control — Jazz FoundationCWE-266 5.3 Medium2024-11-25
CVE-2023-45181 IBM Jazz Foundation cross-site scripting — Jazz FoundationCWE-79 6.1 Medium2024-11-25
CVE-2024-35160 IBM Watson Query on Cloud Pak for Data and IBM Db2 Big SQL on Cloud Pak for Data information disclosure — Watson Query for Cloud Pak for DataCWE-613 4.3 Medium2024-11-23
CVE-2024-41761 IBM Db2 denial of service — Db2 for Linux, UNIX and WindowsCWE-789 5.3 Medium2024-11-23
CVE-2024-41779 IBM Engineering Systems Design Rhapsody - Model Manager — Engineering Systems Design Rhapsody - Model ManagerCWE-367 9.8 Critical2024-11-22
CVE-2024-41781 IBM PowerVM Hypervisor information disclosure — PowerVM HypervisorCWE-497 5.1 Medium2024-11-22
CVE-2024-45663 IBM Db2 denial of service — Db2 for Linux, UNIX and Windows 6.5 Medium2024-11-21
CVE-2024-52359 IBM Concert Software improper access controls — Concert SoftwareCWE-286 4.3 Medium2024-11-19
CVE-2024-52360 IBM Concert Software SQL injection — Concert SoftwareCWE-89 7.6 High2024-11-19
CVE-2024-37070 IBM Concert Software information disclosure — Concert SoftwareCWE-497 4.3 Medium2024-11-19
CVE-2024-39726 IBM Engineering Insights XML external entity injection — Engineering InsightsCWE-611 8.2 High2024-11-15
CVE-2024-41784 IBM Sterling Secure Proxy directory traversal — Sterling Secure ProxyCWE-32 7.5 High2024-11-15
CVE-2024-43189 IBM Concert Software information disclosure — Concert SoftwareCWE-327 5.9 Medium2024-11-15
CVE-2024-41785 IBM Concert cross-site scripting — Concert SoftwareCWE-79 6.1 Medium2024-11-15
CVE-2024-45642 IBM Security ReaQta information disclosure — Security ReaQtaCWE-942 5.3 Medium2024-11-14

This page lists every published CVE security advisory associated with IBM. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.