Skip to content
Noroxi

IBM records

8,915 published records for vendor ibm.

Bug bounty scope

The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.

All records

8,915 records
  • GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    gnu · bashSep 24, 2014

  • The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-mes

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    apache · strutsMar 10, 2017

  • IBM Aspera Faspex code execution

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    ibm · aspera faspexFeb 17, 2023

  • GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    gnu · bashSep 24, 2014

  • Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allo

    CriticalCVSS 9.8KEVWeaponizedEPSS 98%

    ibm · sterling b2b integratorJan 2, 2016

  • IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin

    CriticalCVSS 9.8KEVWeaponizedEPSS 86%

    ibm · planning analyticsDec 18, 2019

  • IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when config

    CriticalCVSS 9.8KEVWeaponizedEPSS 70%

    ibm · data risk managerMay 7, 2020

  • IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary commands on the system

    CriticalCVSS 9.1KEVWeaponizedEPSS 62%

    ibm · data risk managerMay 7, 2020

  • CVE-2001-0797
    68This week

    Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large numbe

    CriticalCVSS 10.0WeaponizedEPSS 95%

    sgi · irixDec 12, 2001

  • CVE-2015-0235
    68This week

    Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-depen

    CriticalCVSS 10.0WeaponizedEPSS 95%

    gnu · glibcJan 28, 2015

  • CVE-2010-0425
    68This week

    modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, w

    CriticalCVSS 10.0WeaponizedEPSS 94%

    apache · http serverMar 5, 2010

  • CVE-2020-4430
    68This week

    IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to traverse directories on the system.

    MediumCVSS 4.3KEVWeaponizedEPSS 69%

    ibm · data risk managerMay 7, 2020

  • CVE-2019-4279
    63This week

    IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted

    CriticalCVSS 9.8WeaponizedEPSS 80%

    ibm · websphere application serverMay 17, 2019

  • CVE-2007-4880
    63This week

    Buffer overflow in the Client Acceptor Daemon (CAD), dsmcad.exe, in certain IBM Tivoli Storage Manager (TSM) clients 5.1 before 5.1.8.1, 5.2

    CriticalCVSS 10.0WeaponizedEPSS 76%

    ibm · tivoli storage manager clientSep 27, 2007

  • CVE-2024-22319
    62This week

    IBM Operational Decision Manager JDNI injection

    CriticalCVSS 9.8Proof of conceptEPSS 76%

    ibm · operational decision managerFeb 1, 2024

  • CVE-2017-1092
    62This week

    IBM Informix Open Admin Tool 11.5, 11.7, and 12.1 could allow an unauthorized user to execute arbitrary code as system admin on Windows serv

    CriticalCVSS 9.8WeaponizedEPSS 76%

    ibm · informix open admin toolMay 22, 2017

  • CVE-2020-4429
    61This week

    IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 contains a default password for an IDRM administrative account.

    CriticalCVSS 9.8WeaponizedEPSS 72%

    ibm · data risk managerMay 7, 2020

  • CVE-2008-4828
    61This week

    Multiple stack-based buffer overflows in dsmagent.exe in the Remote Agent Service in the IBM Tivoli Storage Manager (TSM) client 5.1.0.0 thr

    CriticalCVSS 10.0WeaponizedEPSS 71%

    ibm · tivoli storage manager clientMay 5, 2009

  • CVE-2020-4211
    60This week

    IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system.

    CriticalCVSS 9.8No exploitEPSS 71%

    ibm · spectrum protectFeb 24, 2020

  • CVE-2003-0694
    60This week

    The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using

    CriticalCVSS 10.0WeaponizedEPSS 66%

    sendmail · advanced message serverOct 6, 2003

  • Stack-based buffer overflow in the Web Server service in IBM Lotus Domino before 7.0.3 FP1, and 8.x before 8.0.1, allows remote attackers to

    CriticalCVSS 10.0WeaponizedEPSS 65%

    ibm · lotus dominoMay 22, 2008

  • Stack-based buffer overflow in libcsa.a (aka the calendar daemon library) in IBM AIX 5.x through 5.3.10 and 6.x through 6.1.3, and VIOS 2.1

    CriticalCVSS 10.0WeaponizedEPSS 62%

    ibm · viosOct 15, 2009

  • Buffer overflow in the CRAM-MD5 authentication mechanism in the IMAP server (nimap.exe) in IBM Lotus Domino before 6.5.6 and 7.x before 7.0.

    CriticalCVSS 10.0Proof of conceptEPSS 61%

    ibm · lotus dominoMar 28, 2007

  • The management service in IBM Tivoli Provisioning Manager for OS Deployment before 5.1 Fix Pack 2 does not properly handle multipart/form-da

    CriticalCVSS 10.0WeaponizedEPSS 59%

    ibm · tivoli provisioning manager os deploymentApr 4, 2007

  • IBM Operational Decision Manager code execution

    HighCVSS 8.8Proof of conceptEPSS 73%

    ibm · operational decision managerFeb 1, 2024