-Infinity
0

Vendor Risk Score

See how ibm compares to other vendors in security performance

View Risk Score →

Software

ibm aix
1020
ibm concert software
569
ibm security verify governance
492
ibm websphere application server feature pack for web services
465
ibm cognos analytics
439
ibm security verify governance identity manager container
434
ibm security verify governance, identity manager software stack
434
ibm security verify governance, identity manager virtual appliance
434
ibm security verify access
308
ibm i
288
ibm netezza software
268
ibm db2 universal database
238
ibm maximo asset management
233
ibm db2
218
ibm verify identity access
206
ibm b2b sterling integrator
205
ibm rational quality manager
202
ibm security verify access container
200
ibm verify identity access container
196
ibm langflow oss
189
ibm rational team concert
186
ibm qradar security information and event manager
184
ibm infosphere information server
183
ibm vios
183
ibm infosphere guardium z/os
182
ibm data risk manager
177
ibm guardium data protection
171
ibm powervm vios
169
ibm cloud pak for security
161
ibm websphere application server
147
ibm websphere mq appliance
147
ibm infosphere data architect
143
ibm collaborative lifecycle management
130
ibm websphere portal
128
ibm sterling file gateway
123
ibm watsonx.data intelligence
118
ibm iseries as/400
116
ibm rational doors next generation
111
ibm engineering lifecycle manager
110
ibm cics transaction server for z/os
109
ibm engineering requirements management doors next generation
109
ibm business process manager
105
ibm security verify governance, identity manager virtual appliance component
104
ibm ibm® db2®
97
ibm security verify governance, identity manager software component
97
ibm engineering requirements management doors and doors web access
94
ibm virtual i/o server (vios)
92
ibm qradar siem
91
ibm business automation workflow
89
ibm security guardium
87
Severity
7.1
AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

IBM Server Firmware FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the ASMI web interface. An unauthenticated attacker on the management network can send a malformed HTTPS request to ASMI, causing the web server to crash with possible memory corruption and generate an error log. The ASMI web interface will restart automatically; however, repeated exploitation could result in a sustained loss of access to the ASMI management interface, resulting in an integrity and availability impact.

First published (updated )
First published (updated )
Advisory
IBM-7289253
Severity
3.4
AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:L

IBM OPENBMC FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, and FW1060.00 through FW1060.81 is affected by a vulnerability in the BMC firmware management interface. The host system can cause the BMC firmware management service to crash or allow a limited amount of BMC internal memory to be read, resulting in a confidentiality and availability impact to the managed system.

1 / 2
Source: MITRE
First published (updated )
Severity
4.9
Path Traversal
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

IBM ContextForge Gateway was vulnerable to path traversal in its Admin API log-download endpoint (GET /v1/admin/logs/file). The path confinement check uses str.startswith() rather than proper boundary validation, allowing an authenticated admin to read .log, .jsonl, and .json files outside the configured LOGFOLDER by supplying a filename that resolves into a sibling directory whose absolute path shares the log directory's string prefix.

1 / 2
Source: IBM
First published (updated )
First published (updated )
Advisory
IBM-7289331
First published (updated )
Advisory
IBM-7289124
Severity
5.1
Out-of-bounds Read
AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H

IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the RTAS firmware-to-OS interface. An attacker with administrator-level (root) access to a logical partition can send a specially crafted request to partition firmware, causing the partition to crash and become unavailable. Other partitions on the same managed system are not affected.

1 / 2
Source: MITRE
First published (updated )
First published (updated )
Advisory
IBM-7289246
Severity
3.3
AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

IBM Db2 Mirror for i 7.6, 7.5, and 7.4 could allow a local attacker to obtain sensitive information due to the use of the AES Electronic Codebook (ECB) mode for encryption.

1 / 2
Source: MITRE
First published (updated )
First published (updated )
Advisory
IBM-7289132
Severity
3.4
AV:A/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N

IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the partition resource dump interface. An attacker with authenticated administrator-level access to the HMC or service processor can obtain a limited snapshot of partition processor state. Successful exploitation results in a confidentiality impact to the managed system.

1 / 2
Source: MITRE
First published (updated )
First published (updated )
Advisory
IBM-7289133
Severity
5.1
Input Validation
AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H

IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the partition firmware runtime boot configuration. An attacker with root access to a partition can maliciously alter partition nvram, causing the partition to fail to boot. This condition persists until operator intervention — deleting and recreating the partition configuration — to restore normal operation. Successful exploitation results in an integrity and availability impact.

1 / 2
Source: MITRE
First published (updated )
First published (updated )
Advisory
IBM-7289130
Severity
5.1
Integer Underflow
AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H

IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the partition firmware runtime. An attacker with root access to a partition can send a specially crafted request to the partition firmware runtime, causing it to crash with possible memory corruption.

1 / 2
Source: MITRE
First published (updated )
First published (updated )
Advisory
IBM-7289135
Severity
4.3
AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read.

1 / 2
Source: MITRE
First published (updated )
First published (updated )
Advisory
IBM-7289137
Severity
3.2
AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N

IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, and FW1060.00 through FW1060.81 is affected by a vulnerability in a hypervisor call interface. An attacker with root access to a guest partition can read a limited amount of hypervisor memory, potentially exposing sensitive data belonging to the hypervisor or other guest partitions hosted on the same system, resulting in a confidentiality impact. The attacker has no control over which memory contents are returned. This vulnerability is of particular concern in multi-tenant environments where guests may run arbitrary OS images.

1 / 2
Source: MITRE
First published (updated )
Severity
8.6
SQL Injection
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L

IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL injection. A remote unauthenticated attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

1 / 2
Source: MITRE
First published (updated )
First published (updated )
Advisory
IBM-7288830
Severity
6.2
AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

IBM Concert 1.0.0 through 3.0.0 could allow a local attacker to obtain sensitive information due to recursive copying of build context directories into container images.

1 / 2
Source: MITRE
First published (updated )
Severity
5.9
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

IBM Concert 1.0.0 through 3.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

1 / 2
Source: MITRE
First published (updated )
Severity
5.3
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to cause a denial of service using a specially crafted regular expression that would cause excessive resource consumption.

1 / 2
Source: MITRE
First published (updated )
Severity
7.8
Double Free
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

IBM Concert 1.0.0 through 3.0.0 has a double free vulnerability that exists due to incorrect memory management. A local attacker can exploit this flaw to corrupt heap memory and execute arbitrary code in the context of the affected process.

1 / 2
Source: MITRE
First published (updated )
Severity
5.3
Path Traversal
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot " sequences ( /.. /) to view arbitrary files on the system.

First published (updated )
Severity
9.6
AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

IBM Concert 1.0.0 through 3.0.0 could allow a remote authenticated attacker to access or modify unauthorized resources due to the use of wildcards in RBAC permission definitions.

1 / 2
Source: MITRE
First published (updated )
Severity
6.5
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

IBM Concert 1.0.0 through 3.0.0 could allow a remote authenticated attacker to cause a denial of service due to improper enforcement of storage limits.

1 / 2
Source: MITRE
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203