I

Ibm Security Vulnerabilities (CVE)

Explore vulnerabilities and security advisories affecting Ibm products.

14 known CVE vulnerabilities tracked

Critical
1
High
2
Medium
9
Low
2
None
0

Vulnerabilities By Year

Products Affected

All Ibm CVEs

CVE-2026-2311
6.4 medium

IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 s vulnerable to privilege escalation caused by an invalid IBM i Web Administration GUI authorization check.  A malicious actor could cause user-controlled code to run with administrator privilege.

I Apr 30, 2026
CVE-2026-1577
6.5 medium

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic.

Db2 Apr 30, 2026
CVE-2025-36122
6.5 medium

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user to cause a denial of service using a specially crafted SQL query due to improper allocation of system resources.

Db2 Apr 30, 2026
CVE-2025-14688
5.3 medium

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic when certain configurations exist.

Db2 Apr 30, 2026
CVE-2025-64645
7.7 high

IBM Concert 1.0.0 through 2.1.0 could allow a local user to escalate their privileges due to a race condition of a symbolic link.

Concert Dec 26, 2025
CVE-2025-36230
5.4 medium

IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.

Aspera Faspex Dec 26, 2025
CVE-2025-36229
3.1 low

IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 could allow authenticated users to enumerate sensitive information of data due by enumerating package identifiers.

Aspera Faspex Dec 26, 2025
CVE-2025-36228
3.8 low

IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 may allow inconsistent permissions between the user interface and backend API allowed users to access features that appeared disabled, potentially leading to misuse.

Aspera Faspex Dec 26, 2025
CVE-2025-36192
6.7 medium

IBM DS8A00( R10.1) 10.10.106.0 and IBM DS8A00 ( R10.0) 10.1.3.010.2.45.0 and IBM DS8900F ( R9.4) 89.40.83.089.42.18.089.44.5.0 IBM System Storage DS8000 could allow a local user with authorized CCW update permissions to delete or corrupt backups due to missing authorization in IBM Safeguarded Copy /

Ds8A00 Firmware Dec 26, 2025
CVE-2025-14687
4.3 medium

IBM Db2 Intelligence Center 1.1.0, 1.1.1, 1.1.2 could allow an authenticated user to perform unauthorized actions due to client-side enforcement of sever side security mechanisms.

Db2 Intelligence Center Dec 26, 2025
CVE-2025-13915
9.8 critical

IBM API Connect 10.0.8.0 through 10.0.8.5, and 10.0.11.0 could allow a remote attacker to bypass authentication mechanisms and gain unauthorized access to the application.

Api Connect Dec 26, 2025
CVE-2025-1721
5.9 medium

IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.

Concert Dec 26, 2025
CVE-2025-12771
7.8 high

IBM Concert 1.0.0 through 2.1.0 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local user could overflow the buffer and execute arbitrary code on the system.

Concert Dec 26, 2025
CVE-2025-36154
6.2 medium

IBM Concert 1.0.0 through 2.1.0 stores sensitive information in cleartext during recursive docker builds which could be obtained by a local user.

Concert Dec 24, 2025