Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

IBM — Vulnerabilities & Security Advisories 4858

Browse all 4858 CVE security advisories affecting IBM. AI-powered Chinese analysis, POCs, and references for each vulnerability.

IBM operates as a multinational technology and consulting corporation, primarily providing enterprise software, hybrid cloud services, and artificial intelligence solutions. Its extensive portfolio, including the Red Hat OpenShift platform and Watson AI suite, creates a broad attack surface that has historically been associated with Remote Code Execution (RCE) vulnerabilities, particularly within web application frameworks and middleware. Cross-site scripting (XSS) and privilege escalation flaws also frequently appear in its legacy enterprise applications and containerized environments. While the company maintains robust security protocols, past incidents have included data breaches affecting customer information and supply chain compromises. The high volume of recorded Common Vulnerabilities and Exposures (CVEs) reflects the complexity and scale of its global infrastructure rather than inherent systemic failure, though it necessitates rigorous patch management and continuous monitoring for enterprise clients relying on its diverse technological stack.

CVE IDTitleCVSSSeverityPublished
CVE-2026-9320 IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities — WebSphere Application ServerCWE-400 5.9 Medium2026-06-22
CVE-2026-9071 IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by Uncontrolled Resource Consumption — WebSphere Application ServerCWE-400 7.5 High2026-06-22
CVE-2026-9006 IBM WebSphere Application Server is affected by server-side request forgery — WebSphere Application ServerCWE-918 7.4 High2026-06-22
CVE-2026-8646 IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities — WebSphere Application ServerCWE-444 7.4 High2026-06-22
CVE-2026-10845 IBM WebSphere Application Server is affected by an authentication bypass vulnerability — WebSphere Application ServerCWE-287--2026-06-22
CVE-2024-51454 IBM Engineering Lifecycle Management - Engineering Workflow Management is impacted by vulnerabilities Host Header Injection observed — Engineering Workflow ManagementCWE-644 6.5 Medium2026-06-22
CVE-2023-33854 Multiple vulnerabilities affect IBM Db2® on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data. — Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for DataCWE-294 5.3 Medium2026-06-22
CVE-2026-9610 Multiple Vulnerabilities in IBM Datacap — DatacapCWE-425 2.3 Low2026-06-22
CVE-2026-9072 WebSphere Application Server Remote Code Execution — WebSphere Application ServerCWE-94 8.1 High2026-06-22
CVE-2026-8858 WebSphere Application Server Remote Code Execution — WebSphere Application ServerCWE-94 7.5 High2026-06-22
CVE-2026-8636 Multiple Vulnerabilities in IBM Datacap — DatacapCWE-316 5.5 Medium2026-06-22
CVE-2026-8059 Multiple Vulnerabilities in IBM Datacap — DatacapCWE-79 6.1 Medium2026-06-22
CVE-2026-7664 Unauthenticated Flow Execution via Webhook Endpoint in Langflow OSS — Langflow OSSCWE-287 9.8 Critical2026-06-22
CVE-2026-11372 IBM TRIRIGA Cross-Site Scripting Vulnerability — TRIRIGA Application PlatformCWE-79 5.4 Medium2026-06-22
CVE-2026-12628 Hardcoded credential in the IBM Storage Protect Snapshot For Windows leads to unauthorized access to system — Storage Protect ClientCWE-798 9.1 Critical2026-06-22
CVE-2026-10561 Unauthenticated Remote Code Execution in Langflow OSS PythonREPLComponent via Builtins Injection — Langflow OSSCWE-94 10.0 Critical2026-06-22
CVE-2025-33128 IBM Engineering Lifecycle Management - Engineering Workflow Management is impacted by vulnerabilities HTML / XSS Injection observed — Engineering Workflow ManagementCWE-79 5.4 Medium2026-06-22
CVE-2025-2669 Multiple vulnerabilities affect IBM Db2® on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data. — Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for DataCWE-295 6.0 Medium2026-06-22
CVE-2024-54178 Multiple vulnerabilities affect IBM Db2® on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data. — Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for DataCWE-770 6.5 Medium2026-06-22
CVE-2026-4870 Qiskit SDK is vulnerable to specific functions may recurse too deeply and overflow the available stack space, when encountering certain classical expressions. — Qiskit SDK 7.5 High2026-06-12
CVE-2024-45636 IBM Security QRadar EDR Software has a vulnerability where user credentials may be stored in plain text, potentially exposing sensitive information. — Security QRadar EDRCWE-256 4.1 Medium2026-06-11
CVE-2026-3341 IBM Langflow Desktop 1.0.0 - 1.9.2 DNS Rebinding Bypasses SSRF Protection Allowing Access to Internal Services — Langflow DesktopCWE-918 5.4 Medium2026-06-11
CVE-2026-4096 A vulnerability has been identified in IBM DevOps Plan that allows a Host Header Injection attack due to improper handling of the Host header in HTTP requests. — DevOps PlanCWE-644 6.5 Medium2026-06-11
CVE-2026-7787 Unauthenticated Session History Access via Public Flow Execution — Langflow OSSCWE-639 7.5 High2026-06-11
CVE-2026-7870 IBM i is Affected by Privilege Escalation [] — iCWE-427 8.8 High2026-06-11
CVE-2026-9330 IBM WebSphere Application Server is affected by remote code execution — WebSphere Application ServerCWE-502 8.5 High2026-06-01
CVE-2026-9319 IBM WebSphere Application Server is affected by a remote code execution vulnerability — WebSphere Application ServerCWE-502 9.0 Critical2026-06-01
CVE-2026-9311 IBM WebSphere Application Server is affected by remote code execution — WebSphere Application ServerCWE-94 9.0 Critical2026-06-01
CVE-2026-8644 IBM WebSphere Application Server is affected by an identity spoofing vulnerability — WebSphere Application ServerCWE-290 9.1 Critical2026-06-01
CVE-2026-7770 IBM i Access Client Solutions (ACS) is vulnerable to remote code execution when configured to listen for requests from IBM i Navigator — i Access FamilyCWE-74 8.8 High2026-06-01

This page lists every published CVE security advisory associated with IBM. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.