IBM records
8,915 published records for vendor ibm.
Researcher profile
- Entered KEV
- 10 · 0.1%
- Weaponized
- 60 · 0.7%
- Pre-auth RCE
- 464
- With a fix record
- 1.9%
- Median publish → KEV
- 1193 days
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1,555
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor712
- CWE-264 Permissions, Privileges, and Access Controls336
- CWE-20 Improper Input Validation329
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer264
- CWE-352 Cross-Site Request Forgery (CSRF)229
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
8,915 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2014-6271Weaponized | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attacgnu · bash · CWE-78 | Critical9.8 | KEV | 100.0% | Sep 24, 2014 |
99Now | CVE-2017-5638Weaponized | The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-mesapache · struts · CWE-755 | Critical9.8 | KEV | 100.0% | Mar 10, 2017 |
99Now | CVE-2022-47986Weaponized | IBM Aspera Faspex code executionibm · aspera faspex · CWE-502 | Critical9.8 | KEV | 100.0% | Feb 17, 2023 |
99Now | CVE-2014-7169Weaponized | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variablgnu · bash · CWE-78 | Critical9.8 | KEV | 99.9% | Sep 24, 2014 |
98Now | CVE-2015-7450Weaponized | Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products alloibm · sterling b2b integrator · CWE-502 | Critical9.8 | KEV | 97.8% | Jan 2, 2016 |
95Now | CVE-2019-4716Weaponized | IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "adminibm · planning analytics · CWE-94 | Critical9.8 | KEV | 86.4% | Dec 18, 2019 |
90Now | CVE-2020-4427Weaponized | IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configibm · data risk manager · CWE-287 | Critical9.8 | KEV | 70.0% | May 7, 2020 |
85Now | CVE-2020-4428Weaponized | IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary commands on the systemibm · data risk manager · CWE-78 | Critical9.1 | KEV | 61.7% | May 7, 2020 |
68This week | CVE-2001-0797Weaponized | Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large numbesgi · irix | Critical10.0 | — | 94.9% | Dec 12, 2001 |
68This week | CVE-2015-0235Weaponized | Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-depengnu · glibc · CWE-787 | Critical10.0 | — | 94.6% | Jan 28, 2015 |
68This week | CVE-2010-0425Weaponized | modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, wapache · http server | Critical10.0 | — | 94.2% | Mar 5, 2010 |
68This week | CVE-2020-4430Weaponized | IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to traverse directories on the system.ibm · data risk manager · CWE-22 | Medium4.3 | KEV | 68.5% | May 7, 2020 |
63This week | CVE-2019-4279Weaponized | IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted ibm · websphere application server · CWE-502 | Critical9.8 | — | 79.9% | May 17, 2019 |
63This week | CVE-2007-4880Weaponized | Buffer overflow in the Client Acceptor Daemon (CAD), dsmcad.exe, in certain IBM Tivoli Storage Manager (TSM) clients 5.1 before 5.1.8.1, 5.2ibm · tivoli storage manager client · CWE-119 | Critical10.0 | — | 75.9% | Sep 27, 2007 |
62This week | CVE-2024-22319Proof of concept | IBM Operational Decision Manager JDNI injectionibm · operational decision manager · CWE-74 | Critical9.8 | — | 76.4% | Feb 1, 2024 |
62This week | CVE-2017-1092Weaponized | IBM Informix Open Admin Tool 11.5, 11.7, and 12.1 could allow an unauthorized user to execute arbitrary code as system admin on Windows servibm · informix open admin tool | Critical9.8 | — | 75.8% | May 22, 2017 |
61This week | CVE-2020-4429Weaponized | IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 contains a default password for an IDRM administrative account.ibm · data risk manager · CWE-798 | Critical9.8 | — | 72.0% | May 7, 2020 |
61This week | CVE-2008-4828Weaponized | Multiple stack-based buffer overflows in dsmagent.exe in the Remote Agent Service in the IBM Tivoli Storage Manager (TSM) client 5.1.0.0 thribm · tivoli storage manager client · CWE-119 | Critical10.0 | — | 71.5% | May 5, 2009 |
60This week | CVE-2020-4211No exploit | IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system.ibm · spectrum protect · CWE-78 | Critical9.8 | — | 71.1% | Feb 24, 2020 |
60This week | CVE-2003-0694Weaponized | The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated usingsendmail · advanced message server | Critical10.0 | — | 66.2% | Oct 6, 2003 |
59Plan | CVE-2008-2240Weaponized | Stack-based buffer overflow in the Web Server service in IBM Lotus Domino before 7.0.3 FP1, and 8.x before 8.0.1, allows remote attackers toibm · lotus domino · CWE-119 | Critical10.0 | — | 64.8% | May 22, 2008 |
59Plan | CVE-2009-3699Weaponized | Stack-based buffer overflow in libcsa.a (aka the calendar daemon library) in IBM AIX 5.x through 5.3.10 and 6.x through 6.1.3, and VIOS 2.1 ibm · vios · CWE-119 | Critical10.0 | — | 62.3% | Oct 15, 2009 |
58Plan | CVE-2007-1675Proof of concept | Buffer overflow in the CRAM-MD5 authentication mechanism in the IMAP server (nimap.exe) in IBM Lotus Domino before 6.5.6 and 7.x before 7.0.ibm · lotus domino | Critical10.0 | — | 61.2% | Mar 28, 2007 |
58Plan | CVE-2007-1868Weaponized | The management service in IBM Tivoli Provisioning Manager for OS Deployment before 5.1 Fix Pack 2 does not properly handle multipart/form-daibm · tivoli provisioning manager os deployment | Critical10.0 | — | 59.3% | Apr 4, 2007 |
57Plan | CVE-2024-22320Proof of concept | IBM Operational Decision Manager code executionibm · operational decision manager · CWE-502 | High8.8 | — | 73.4% | Feb 1, 2024 |
- CVE-2014-627199Now
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac
CriticalCVSS 9.8KEVWeaponizedEPSS 100%gnu · bashSep 24, 2014
- CVE-2017-563899Now
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-mes
CriticalCVSS 9.8KEVWeaponizedEPSS 100%apache · strutsMar 10, 2017
- CVE-2022-4798699Now
IBM Aspera Faspex code execution
CriticalCVSS 9.8KEVWeaponizedEPSS 100%ibm · aspera faspexFeb 17, 2023
- CVE-2014-716999Now
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl
CriticalCVSS 9.8KEVWeaponizedEPSS 100%gnu · bashSep 24, 2014
- CVE-2015-745098Now
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allo
CriticalCVSS 9.8KEVWeaponizedEPSS 98%ibm · sterling b2b integratorJan 2, 2016
- CVE-2019-471695Now
IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin
CriticalCVSS 9.8KEVWeaponizedEPSS 86%ibm · planning analyticsDec 18, 2019
- CVE-2020-442790Now
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when config
CriticalCVSS 9.8KEVWeaponizedEPSS 70%ibm · data risk managerMay 7, 2020
- CVE-2020-442885Now
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary commands on the system
CriticalCVSS 9.1KEVWeaponizedEPSS 62%ibm · data risk managerMay 7, 2020
- CVE-2001-079768This week
Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large numbe
CriticalCVSS 10.0WeaponizedEPSS 95%sgi · irixDec 12, 2001
- CVE-2015-023568This week
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-depen
CriticalCVSS 10.0WeaponizedEPSS 95%gnu · glibcJan 28, 2015
- CVE-2010-042568This week
modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, w
CriticalCVSS 10.0WeaponizedEPSS 94%apache · http serverMar 5, 2010
- CVE-2020-443068This week
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to traverse directories on the system.
MediumCVSS 4.3KEVWeaponizedEPSS 69%ibm · data risk managerMay 7, 2020
- CVE-2019-427963This week
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted
CriticalCVSS 9.8WeaponizedEPSS 80%ibm · websphere application serverMay 17, 2019
- CVE-2007-488063This week
Buffer overflow in the Client Acceptor Daemon (CAD), dsmcad.exe, in certain IBM Tivoli Storage Manager (TSM) clients 5.1 before 5.1.8.1, 5.2
CriticalCVSS 10.0WeaponizedEPSS 76%ibm · tivoli storage manager clientSep 27, 2007
- CVE-2024-2231962This week
IBM Operational Decision Manager JDNI injection
CriticalCVSS 9.8Proof of conceptEPSS 76%ibm · operational decision managerFeb 1, 2024
- CVE-2017-109262This week
IBM Informix Open Admin Tool 11.5, 11.7, and 12.1 could allow an unauthorized user to execute arbitrary code as system admin on Windows serv
CriticalCVSS 9.8WeaponizedEPSS 76%ibm · informix open admin toolMay 22, 2017
- CVE-2020-442961This week
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 contains a default password for an IDRM administrative account.
CriticalCVSS 9.8WeaponizedEPSS 72%ibm · data risk managerMay 7, 2020
- CVE-2008-482861This week
Multiple stack-based buffer overflows in dsmagent.exe in the Remote Agent Service in the IBM Tivoli Storage Manager (TSM) client 5.1.0.0 thr
CriticalCVSS 10.0WeaponizedEPSS 71%ibm · tivoli storage manager clientMay 5, 2009
- CVE-2020-421160This week
IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system.
CriticalCVSS 9.8No exploitEPSS 71%ibm · spectrum protectFeb 24, 2020
- CVE-2003-069460This week
The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using
CriticalCVSS 10.0WeaponizedEPSS 66%sendmail · advanced message serverOct 6, 2003
- CVE-2008-224059Plan
Stack-based buffer overflow in the Web Server service in IBM Lotus Domino before 7.0.3 FP1, and 8.x before 8.0.1, allows remote attackers to
CriticalCVSS 10.0WeaponizedEPSS 65%ibm · lotus dominoMay 22, 2008
- CVE-2009-369959Plan
Stack-based buffer overflow in libcsa.a (aka the calendar daemon library) in IBM AIX 5.x through 5.3.10 and 6.x through 6.1.3, and VIOS 2.1
CriticalCVSS 10.0WeaponizedEPSS 62%ibm · viosOct 15, 2009
- CVE-2007-167558Plan
Buffer overflow in the CRAM-MD5 authentication mechanism in the IMAP server (nimap.exe) in IBM Lotus Domino before 6.5.6 and 7.x before 7.0.
CriticalCVSS 10.0Proof of conceptEPSS 61%ibm · lotus dominoMar 28, 2007
- CVE-2007-186858Plan
The management service in IBM Tivoli Provisioning Manager for OS Deployment before 5.1 Fix Pack 2 does not properly handle multipart/form-da
CriticalCVSS 10.0WeaponizedEPSS 59%ibm · tivoli provisioning manager os deploymentApr 4, 2007
- CVE-2024-2232057Plan
IBM Operational Decision Manager code execution
HighCVSS 8.8Proof of conceptEPSS 73%ibm · operational decision managerFeb 1, 2024