ibm
538 known vulnerabilities affecting ibm products.
Products
aix 167
vios 149
i 133
websphere_application_server 40
power_system_e1180_\(9080-heu\) 29
power_system_e1180_\(9080-heu\)_firmware 29
power_system_e1080_\(9080-hex\) 28
power_system_e1080_\(9080-hex\)_firmware 28
power_system_e1150_\(9043-mru\) 25
power_system_e1150_\(9043-mru\)_firmware 25
power_system_e1050_\(9043-mrx\) 25
power_system_e1050_\(9043-mrx\)_firmware 25
power_system_l1022_\(9786-22h\) 25
power_system_l1022_\(9786-22h\)_firmware 25
power_system_l1024_\(9786-42h\) 25
power_system_l1024_\(9786-42h\)_firmware 25
power_system_l1122_\(9856-22h\) 25
power_system_l1122_\(9856-22h\)_firmware 25
power_system_l1124_\(9856-42h\) 25
power_system_l1124_\(9856-42h\)_firmware 25
power_system_s1012_\(9028-21b\) 25
power_system_s1012_\(9028-21b\)_firmware 25
power_system_s1014_\(9105-41b\) 25
power_system_s1014_\(9105-41b\)_firmware 25
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-9330 | Medium | 0.5% | 8.5 | IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validat… | |
| CVE-2026-15322 | Medium | 0.5% | 7.5 | IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to … | |
| CVE-2026-17184 | Medium | 0.5% | 9.8 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute … | |
| CVE-2026-3627 | Medium | 0.5% | 9.1 | IBM Concert 1.0.0 through 2.3.1 is vulnerable to SQL injection. A remote attacke… | |
| CVE-2026-18669 | Medium | 0.5% | 8.8 | IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to a privilege escalation as the resu… | |
| CVE-2026-9311 | Medium | 0.5% | 9.0 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execu… | |
| CVE-2026-18713 | Medium | 0.5% | 8.8 | IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to privilege escalation via Navigator … | |
| CVE-2026-17145 | Medium | 0.5% | 9.8 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to e… | |
| CVE-2026-17110 | Medium | 0.5% | 8.8 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to exec… | |
| CVE-2026-15435 | Medium | 0.5% | 9.8 | IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.… | |
| CVE-2026-16862 | Medium | 0.5% | 9.8 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to e… | |
| CVE-2026-16845 | Medium | 0.5% | 9.8 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to e… | |
| CVE-2026-16816 | Medium | 0.5% | 9.9 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated… | |
| CVE-2026-86093 | Medium | 0.5% | 7.5 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker… | |
| CVE-2026-15065 | Medium | 0.5% | 9.1 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote attacker … | |
| CVE-2026-81551 | Medium | 0.5% | 8.8 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated a… | |
| CVE-2026-17138 | Medium | 0.5% | 8.1 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to e… | |
| CVE-2026-19437 | Medium | 0.5% | 8.1 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to e… | |
| CVE-2026-13473 | Medium | 0.5% | 8.1 | IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 throu… | |
| CVE-2026-16877 | Medium | 0.5% | 8.8 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated… | |
| CVE-2026-16872 | Medium | 0.5% | 9.8 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to e… | |
| CVE-2026-17083 | Medium | 0.5% | 9.8 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary … | |
| CVE-2026-17473 | Medium | 0.5% | 7.5 | IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to r… | |
| CVE-2026-16834 | Medium | 0.5% | 9.8 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to c… | |
| CVE-2026-9319 | Medium | 0.5% | 9.0 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote … | |
| CVE-2026-8855 | Medium | 0.5% | 8.1 | IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial o… | |
| CVE-2026-16864 | Medium | 0.5% | 9.8 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to e… | |
| CVE-2026-17040 | Medium | 0.5% | 9.8 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to e… | |
| CVE-2026-82099 | Medium | 0.4% | 8.8 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated a… | |
| CVE-2026-7770 | Medium | 0.4% | 8.8 | IBM i Access Family 1.1.5.0 through 1.1.9.12 IBM i Access Client Solutions (ACS)… | |
| CVE-2026-17118 | Medium | 0.4% | 9.8 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to e… | |
| CVE-2026-17168 | Medium | 0.4% | 8.5 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated… | |
| CVE-2026-17182 | Medium | 0.4% | 9.8 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass a… | |
| CVE-2026-17223 | Medium | 0.4% | 8.8 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to exec… | |
| CVE-2026-15061 | Medium | 0.4% | 8.2 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 's nimesis registration service co… | |
| CVE-2026-17642 | Medium | 0.4% | 8.8 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to exec… | |
| CVE-2026-16656 | Medium | 0.4% | 9.8 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to g… | |
| CVE-2026-17417 | Medium | 0.4% | 8.8 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to exec… | |
| CVE-2026-11541 | Medium | 0.4% | 7.4 | IBM CICS Transaction Gateway for Multiplatforms 9.1, 9.2, 9.3, and 10.1 IBM WebS… | |
| CVE-2026-14519 | Medium | 0.4% | 7.5 | IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.… | |
| CVE-2026-17000 | Medium | 0.4% | 8.1 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to e… | |
| CVE-2026-16674 | Medium | 0.4% | 8.8 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to exec… | |
| CVE-2026-16867 | Medium | 0.4% | 8.1 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to access server reso… | |
| CVE-2026-17101 | Medium | 0.4% | 8.3 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary … | |
| CVE-2026-82100 | Medium | 0.4% | 9.6 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated a… | |
| CVE-2026-18824 | Medium | 0.4% | 8.4 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated… | |
| CVE-2026-16907 | Medium | 0.4% | 7.6 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to exec… | |
| CVE-2026-16908 | Medium | 0.4% | 8.5 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain… | |
| CVE-2026-16836 | Medium | 0.4% | 7.5 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to c… | |
| CVE-2026-16824 | Medium | 0.4% | 7.5 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to c… |