Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

IBM — Vulnerabilities & Security Advisories 4629

Browse all 4629 CVE security advisories affecting IBM. AI-powered Chinese analysis, POCs, and references for each vulnerability.

IBM operates as a multinational technology and consulting corporation, primarily providing enterprise software, hybrid cloud services, and artificial intelligence solutions. Its extensive portfolio, including the Red Hat OpenShift platform and Watson AI suite, creates a broad attack surface that has historically been associated with Remote Code Execution (RCE) vulnerabilities, particularly within web application frameworks and middleware. Cross-site scripting (XSS) and privilege escalation flaws also frequently appear in its legacy enterprise applications and containerized environments. While the company maintains robust security protocols, past incidents have included data breaches affecting customer information and supply chain compromises. The high volume of recorded Common Vulnerabilities and Exposures (CVEs) reflects the complexity and scale of its global infrastructure rather than inherent systemic failure, though it necessitates rigorous patch management and continuous monitoring for enterprise clients relying on its diverse technological stack.

Found 145 results / 4629Clear Filters
CVE IDTitleCVSSSeverityPublished
CVE-2025-14807 IBM InfoSphere Information Server is vulnerable to HTTP header injection — InfoSphere Information ServerCWE-644 6.5 Medium2026-03-25
CVE-2026-1015 IBM InfoSphere Information Server is vulnerable to server-side request forgery — InfoSphere Information ServerCWE-918 5.4 Medium2026-03-25
CVE-2026-1014 IBM InfoSphere Information Server is vulnerable due to disclosure of sensitive information — InfoSphere Information ServerCWE-319 6.5 Medium2026-03-25
CVE-2026-2483 IBM InfoSphere Information Server Cross-Site Scripting — InfoSphere Information ServerCWE-79 5.4 Medium2026-03-25
CVE-2026-2484 IBM InfoSphere Information Server Information Disclosure — InfoSphere Information ServerCWE-209 4.3 Medium2026-03-25
CVE-2025-36422 IBM InfoSphere Information Server is vulnerable to cross-site request forgery — InfoSphere Information ServerCWE-352 4.3 Medium2026-03-25
CVE-2025-36258 IBM InfoSphere Information Server is vulnerable due to plaintext storage of a password — InfoSphere Information ServerCWE-256 7.1 High2026-03-25
CVE-2026-2485 IBM InfoSphere Information Server Cross-Site Scripting — InfoSphere Information ServerCWE-79 4.8 Medium2026-03-25
CVE-2025-14974 IBM InfoSphere Information Server is vulnerable due to Insecure Direct Object Reference — InfoSphere Information ServerCWE-639 5.7 Medium2026-03-25
CVE-2026-1262 IBM InfoSphere Information Server Information Disclosure — InfoSphere Information ServerCWE-209 4.3 Medium2026-03-25
CVE-2025-14912 IBM InfoSphere Information Server is vulnerable to server-side request forgery — InfoSphere Information ServerCWE-918 5.4 Medium2026-03-25
CVE-2025-14810 IBM InfoSphere Information Server is vulnerable due to insufficient session expiration — InfoSphere Information ServerCWE-613 6.3 Medium2026-03-25
CVE-2025-14808 IBM InfoSphere Information Server is vulnerable due to disclosure of sensitive information — InfoSphere Information ServerCWE-598 3.1 Low2026-03-25
CVE-2025-14790 IBM InfoSphere Information Server is vulnerable to disclosure of sensitive information — InfoSphere Information ServerCWE-522 6.5 Medium2026-03-25
CVE-2026-1567 IBM InfoSphere Information Server is affected by an XML external entity injection (XXE) vulnerability — InfoSphere Information ServerCWE-611 7.1 High2026-03-03
CVE-2026-1265 IBM InfoSphere Information Server is vulnerable due to sensitive information written to a log file — InfoSphere Information ServerCWE-532 4.3 Medium2026-03-03
CVE-2025-12832 IBM InfoSphere Information Server Server-Side Request Forgery — InfoSphere Information ServerCWE-918 4.6 Medium2025-12-08
CVE-2025-12531 IBM InfoSphere Information Server is affected by an XML external entity injection (XXE) vulnerability — InfoSphere Information ServerCWE-611 7.1 High2025-11-03
CVE-2025-33003 IBM InfoSphere Information Server is vulnerable to privilege escalation — InfoSphere Information ServerCWE-250 7.8 High2025-10-31
CVE-2025-36245 IBM InfoSphere Information Server command execution — InfoSphere Information ServerCWE-78 8.8 High2025-09-29
CVE-2025-36034 IBM InfoSphere DataStage Flow Designer information disclosure — InfoSphere Information ServerCWE-319 5.3 Medium2025-06-26
CVE-2025-0966 IBM InfoSphere Information Server SQL injection — InfoSphere Information ServerCWE-89 7.6 High2025-06-25
CVE-2025-3629 IBM InfoSphere Information Server file manipulation — InfoSphere Information ServerCWE-282 4.3 Medium2025-06-21
CVE-2025-3221 IBM InfoSphere Information Server denial of service — InfoSphere Information ServerCWE-770 7.5 High2025-06-21
CVE-2025-1499 IBM InfoSphere Information Server information disclosure — InfoSphere Information ServerCWE-312 6.5 Medium2025-06-01
CVE-2025-1138 IBM Information Server information disclosure — InfoSphere Information ServerCWE-548 4.3 Medium2025-05-15
CVE-2025-25046 IBM InfoSphere Information Server information disclosure — InfoSphere Information ServerCWE-319 3.7 Low2025-04-23
CVE-2025-25045 IBM InfoSphere Information Server information disclosure — InfoSphere Information ServerCWE-209 4.3 Medium2025-04-23
CVE-2024-22351 IBM InfoSphere Information Server session fixation — InfoSphere Information ServerCWE-613 6.3 Medium2025-04-23
CVE-2024-55895 IBM InfoSphere Information Server information disclosure — InfoSphere Information ServerCWE-209 2.7 Low2025-03-29

This page lists every published CVE security advisory associated with IBM. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.