Where
AND
-Infinity
0

Vendor Risk Score

See how ibm compares to other vendors in security performance

View Risk Score →

Software

ibm aix
373
ibm websphere application server feature pack for web services
245
ibm security verify governance
234
ibm security verify governance identity manager container
211
ibm security verify governance, identity manager software stack
211
ibm security verify governance, identity manager virtual appliance
211
ibm rational quality manager
185
ibm cognos analytics
181
ibm rational team concert
135
ibm maximo asset management
130
ibm security verify access
128
ibm collaborative lifecycle management
118
ibm qradar security information and event manager
107
ibm b2b sterling integrator
104
ibm db2 universal database
103
ibm engineering lifecycle manager
100
ibm engineering requirements management doors next generation
97
ibm websphere portal
97
ibm infosphere information server
89
ibm infosphere guardium z/os
86
ibm concert software
84
ibm security verify access container
84
ibm verify identity access
81
ibm verify identity access container
81
ibm rational doors next generation
78
ibm data risk manager
76
ibm sterling file gateway
75
ibm db2
72
ibm business process manager
69
ibm rational rhapsody
67
ibm websphere mq appliance
62
ibm watsonx.data intelligence
58
ibm cloud pak for security
57
ibm rational software architect
55
ibm i
54
ibm business automation workflow
51
ibm engineering requirements management doors and doors web access
49
ibm sterling b2b integrator
45
ibm jazz reporting service
44
ibm cognos controller
43
ibm engineering lifecycle management
41
ibm security qradar
38
ibm iseries as/400
36
ibm control desk
34
ibm rational collaborative lifecycle management
34
ibm eni
33
ibm security verify governance - identity manager
31
ibm urbancode
31
ibm maximo for utilities
30
ibm virtual i/o server (vios)
30
Severity
6.8
Path Traversal
AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

IBM OpenBMC FW1060.00 through FW1060.80 is affected by a vulnerability in the BMC firmware update process. An attacker with authenticated administrator-level access to the BMC can, under specific conditions, execute arbitrary code, resulting in a confidentiality, integrity, and availability impact.

1 / 2
Source: MITRE
First published (updated )
Severity
5.1
AV:A/AC:H/PR:H/UI:R/S:C/C:H/I:N/A:N

IBM PowerVM Hypervisor Platform KeyStore (PKS) and virtual TPM FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H2 use persistent storage key seeds that result in an AES key with reduced strength. An attacker with access to the service processor or HMC could exploit this weakness to derive the encryption key and access the data.

1 / 2
Source: MITRE
First published (updated )
Severity
5.3
AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N

IBM PowerVM Hypervisor FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H2 could allow a local attacker with administrative privileges to decrypt encrypted data due to certain hypervisor calls utilizing less entropy than requested.

1 / 2
Source: MITRE
First published (updated )
Severity
6.7
AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

AIX could allow a local attacker to execute arbitrary code due to an out-of-bounds write.

1 / 2
Source: IBM
First published (updated )
Severity
4.4
Divide by Zero
AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

AIX could allow a local attacker to cause a denial of service due to an out-of-bounds write.

1 / 2
Source: IBM
First published (updated )
Severity
4.3
AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

AIX could allow a remote attacker to cause a denial of service due to an out-of-bounds write.

1 / 2
Source: IBM
First published (updated )
Severity
6.5
AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in partition firmware during network boot. An unauthenticated attacker with access to the same network as a partition undergoing iSCSI SAN network boot can prevent that partition from completing its boot sequence. Other partitions and the managed system are not affected. Only partitions actively performing an iSCSI SAN network boot are affected, resulting in an availability impact.

1 / 2
Source: MITRE
First published (updated )
Severity
5.5
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AIX could allow a local attacker to obtain sensitive information due to an out-of-bounds read.

1 / 2
Source: IBM
First published (updated )
Severity
4.5
Integer Overflow
AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

IBM Virtualization Management Interface FW1110.00 through FW1110.30, FW1120.00 through FW1120.00, and FW1060.00 through FW1060.80 is affected by a vulnerability in the Virtualization Management Interface (VMI). An attacker with authenticated administrator-level access can cause the VMI to crash. The VMI will restart automatically; however, repeated exploitation could result in a sustained availability impact.

1 / 2
Source: MITRE
First published (updated )
Severity
4.8
AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L

AIX could allow a remote attacker to cause a denial of service due to an out-of-bounds read.

1 / 2
Source: IBM
First published (updated )
Severity
5.5
Buffer Overflow
AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

AIX could allow a local attacker to cause a denial of service due to a heap buffer overflow.

1 / 2
Source: IBM
First published (updated )
Severity
4.3
Out-of-bounds Read
AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

AIX could allow a remote attacker to cause a denial of service due to an improper check for an array index boundary.

1 / 2
Source: IBM
First published (updated )
Severity
6.5
Null Pointer Dereference
AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AIX could allow a remote attacker to cause a denial of service due to a null pointer dereference.

1 / 2
Source: IBM
First published (updated )
Severity
5.3
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AIX could allow a remote attacker to disclose kernel memory due to an out-of-bounds read.

1 / 2
Source: IBM
First published (updated )
Severity
5.3
Null Pointer Dereference
AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

AIX could allow a remote attacker to cause a denial of service due to a NULL pointer dereference.

1 / 2
Source: IBM
First published (updated )
Severity
5.9
AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

AIX could allow a remote attacker to cause a denial of service due to the use of an uninitialized stack pointer.

1 / 2
Source: IBM
First published (updated )
Severity
4.2
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:L

AIX could allow a remote authenticated attacker to obtain sensitive information and cause a denial of service due to an out-of-bounds write.

1 / 2
Source: IBM
First published (updated )
Severity
6.9
AV:A/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:H

IBM Server Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in access controls over privileged system configuration operations on the FSP. An attacker with authenticated administrator-level access to the FSP can place the managed system into a non-production operational mode, allowing certain system components to be disabled. This condition persists across FSP resets and requires explicit operator intervention — clearing the affected configuration — to restore normal operation. Successful exploitation results in an availability impact to the managed system.

1 / 2
Source: MITRE
First published (updated )
Severity
6.8
AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

IBM Server Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the FSP firmware update process. An attacker with authenticated administrator-level access to the FSP can, under specific conditions, execute arbitrary code, resulting in a confidentiality, integrity, and availability impact.

1 / 2
Source: MITRE
First published (updated )
Severity
6.7
Integer Overflow
AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:H

IBM Power Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerability in the host firmware. An attacker with service access to the service processor can supply a carefully crafted command that could leak the contents of hardware registers that should be inaccessible to the service processor. Successful exploitation could result in limited confidentiality or availability impacts to the affected host system.

1 / 2
Source: MITRE
First published (updated )
Severity
6.5
AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to improper handling of memory page table configurations.

1 / 2
Source: MITRE
First published (updated )
Severity
5.3
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to the use of an uninitialized variable.

1 / 2
Source: MITRE
First published (updated )
Severity
5.3
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to resource exhaustion.

1 / 2
Source: MITRE
First published (updated )
Severity
4.3
Path Traversal
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a path traversal vulnerability.

1 / 2
Source: MITRE
First published (updated )
Severity
5.3
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds read.

1 / 2
Source: MITRE
First published (updated )
Severity
5.3
Integer Overflow
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an integer error when processing DRDA large-object headers.

1 / 2
Source: MITRE
First published (updated )
Severity
5.4
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information or cause a denial of service due to an out-of-bounds read.

1 / 2
Source: MITRE
First published (updated )
Severity
4.4
AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to obtain sensitive information or modify data due to improper privilege management.

1 / 2
Source: MITRE
First published (updated )
Severity
5.3
AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an improper buffer write.

1 / 2
Source: MITRE
First published (updated )
Severity
5.3
AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary code or cause a denial of service due to improper bounds checking.

1 / 2
Source: MITRE
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203