VendorsIBMaixany version
Vulnerabilities

IBM AIX any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

620CVEs
CVE-2016-8977
IBM BigFix Inventory v9 could disclose sensitive information to an unauthorized user using HTTP GET requests. This information could be used to mount further attacks against the system.
Published 2017-02-01 · Modified
5.3EPSS 0.011
CVE-2022-22473
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sensitive information caused by improper handling of Administrative Console data. This information could be used in further attacks against the system. IBM X-Force ID: 225347.
Published 2022-07-14 · Modified
5.3EPSS 0.011
CVE-2019-4741
IBM Content Navigator 3.0CD is vulnerable to Server Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 172815.
Published 2020-02-12 · Modified
5.3EPSS 0.010
CVE-2021-39086
IBM Sterling File Gateway 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 215889.
Published 2022-08-16 · Modified
5.3EPSS 0.009
CVE-2021-29681
IBM InfoSphere Information Server 11.7 could allow an attacker to obtain sensitive information by injecting parameters into an HTML query. This information could be used in further attacks against the system. IBM X-Force ID: 199918.
Published 2021-05-21 · Modified
5.3EPSS 0.009
CVE-2023-47703
IBM Security Guardium Key Lifecycle Manager information disclosure
Published 2023-12-20 · Modified
5.3EPSS 0.008
CVE-2023-43021
IBM InfoSphere Information Server information disclosure
Published 2023-12-01 · Modified
5.3EPSS 0.007
CVE-2023-33857
IBM InfoSphere Information Server information disclosure
Published 2023-07-16 · Modified
5.3EPSS 0.007
CVE-2023-45177
IBM MQ denial of service
Published 2024-03-20 · Analyzed
5.3EPSS 0.006
CVE-2022-43872
IBM Financial Transaction Manager information disclosure
Published 2022-12-20 · Modified
5.3EPSS 0.005
CVE-2023-29259
IBM Sterling Connect:Express for UNIX information disclosure
Published 2023-07-19 · Modified
5.3EPSS 0.005
CVE-2026-3482
IBM Sterling B2B Integrator and IBM Sterling File Gateway Authorization Bypass
Published 2026-07-22 · Analyzed
5.3EPSS 0.005
CVE-2026-16833
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
5.3EPSS 0.004
CVE-2024-40706
IBM InfoSphere Information Server information disclosure
Published 2025-01-24 · Analyzed
5.3EPSS 0.004
CVE-2024-55895
IBM InfoSphere Information Server information disclosure
Published 2025-03-29 · Analyzed
5.3EPSS 0.003
CVE-2024-56476
IBM TXSeries for Multiplatforms information disclosure
Published 2025-04-02 · Analyzed
5.3EPSS 0.003
CVE-2024-47109
IBM Sterling File Gateway information disclosure
Published 2025-03-10 · Analyzed
5.3EPSS 0.003
CVE-2026-16829
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
5.3EPSS 0.003
CVE-2021-29827
IBM InfoSphere Information Server clickjacking
Published 2024-12-18 · Analyzed
5.2EPSS 0.003
CVE-2021-29763
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 under very specific conditions, could allow a local user to keep running a procedure that could cause the system to run out of memory.and cause a denial of service. IBM X-Force ID: 202267.
Published 2021-09-16 · Modified
5.1EPSS 0.003
CVE-2003-0285
IBM AIX 5.2 and earlier distributes Sendmail with a configuration file (sendmail.cf) with the (1) promiscuous_relay, (2) accept_unresolvable_domains, and (3) accept_unqualified_senders features enabled, which allows Sendmail to be used as an open mail relay for sending spam e-mail.
Published 2003-05-14 · Modified
5.0EPSS 0.050
CVE-2010-4622
Directory traversal vulnerability in WebSEAL in IBM Tivoli Access Manager for e-business 6.1.1 before 6.1.1-TIV-AWS-FP0001 on AIX allows remote attackers to read arbitrary files via a %uff0e%uff0e (encoded dot dot) in a URI.
Published 2010-12-30 · Modified
5.0EPSS 0.029
CVE-2007-1918
The RFC_SET_REG_SERVER_PROPERTY function in the SAP RFC Library 6.40 and 7.00 before 20070109 implements an option for exclusive access to an RFC server, which allows remote attackers to cause a denial of service (client lockout) via unspecified vectors. NOTE: This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended.
Published 2007-04-10 · Modified
5.0EPSS 0.025
CVE-2007-1913
The TRUSTED_SYSTEM_SECURITY function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to verify the existence of users and groups on systems and domains via unspecified vectors, a different vulnerability than CVE-2006-6010. NOTE: This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended.
Published 2007-04-10 · Modified
5.0EPSS 0.022
CVE-2010-2090
The npb_protocol_error function in sna V5router64 in IBM Communications Server for Windows 6.1.3 and Communications Server for AIX (aka CSAIX or CS/AIX) in sna.rte before 6.3.1.2 allows remote attackers to cause a denial of service (daemon crash) via APPC data containing a GDSID variable with a GDS length that is too small.
Published 2010-05-27 · Modified
5.0EPSS 0.017
CVE-2004-0243
AIX 4.3.3 through AIX 5.1, when direct remote login is disabled, displays a different message if the password is correct, which allows remote attackers to guess the password via brute force methods.
Published 2004-03-18 · Modified
5.0EPSS 0.017
CVE-1999-0566
An attacker can write to syslog files from any location, causing a denial of service by filling up the logs, and hiding activities.
Published 1999-09-29 · Modified
5.0EPSS 0.013
CVE-2007-1223
Unspecified vulnerability in Hitachi OSAS/FT/W before 20070223 allows attackers to cause a denial of service (responder control processing halt) by sending "data unexpectedly through the port".
Published 2007-03-02 · Modified
5.0EPSS 0.012
CVE-2002-1040
Unknown vulnerability in the WebSecure (DFSWeb) configuration utilities in AIX 4.x, possibly related to relative pathnames.
Published 2002-08-31 · Modified
5.0EPSS 0.011
CVE-2002-1041
Unknown vulnerability in DCE (1) SMIT panels and (2) configuration commands, possibly related to relative pathnames.
Published 2002-08-31 · Modified
5.0EPSS 0.011
CVE-2008-7288
IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0007 on AIX allows remote attackers to cause a denial of service (server destabilization) via an anonymous DIGEST-MD5 LDAP Bind operation.
Published 2011-04-21 · Modified
5.0EPSS 0.011
CVE-2023-42031
IBM CICS TX denial of service
Published 2023-10-24 · Modified
4.9EPSS 0.010
CVE-2021-29728
IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 201160.
Published 2021-08-30 · Modified
4.9EPSS 0.010
CVE-2024-49338
IBM App Connect Enterprise information disclosure
Published 2025-01-18 · Analyzed
4.9EPSS 0.004
CVE-2026-16866
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
4.8EPSS 0.003
CVE-2024-45073
IBM WebSphere Application Server cross-site scripting
Published 2024-09-30 · Analyzed
4.8EPSS 0.002
CVE-2026-2485
IBM InfoSphere Information Server Cross-Site Scripting
Published 2026-03-25 · Analyzed
4.8EPSS 0.002
CVE-2018-1882
In a certain atypical IBM Spectrum Protect 7.1 and 8.1 configurations, the node password could be displayed in plain text in the IBM Spectrum Protect client trace file. IBM X-Force ID: 151968.
Published 2019-04-08 · Modified
4.7EPSS 0.002
CVE-2011-4834
The GetInstalledPackages function in the configuration tool in HP Application Lifestyle Management (ALM) 11 on AIX, HP-UX, and Solaris allows local users to gain privileges via (1) a Trojan horse /tmp/tmp.txt FIFO or (2) a symlink attack on /tmp/tmp.txt.
Published 2011-12-15 · Modified
4.61 PoCEPSS 0.012
CVE-2015-3316
CA Common Services, as used in CA Client Automation r12.5 SP01, r12.8, and r12.9; CA Network and Systems Management r11.0, r11.1, and r11.2; CA NSM Job Management Option r11.0, r11.1, and r11.2; CA Universal Job Management Agent; CA Virtual Assurance for Infrastructure Managers (aka SystemEDGE) 12.6, 12.7, 12.8, and 12.9; and CA Workload Automation AE r11, r11.3, r11.3.5, and r11.3.6 on UNIX, allows local users to gain privileges via an unspecified environment variable.
Published 2015-06-17 · Modified
4.6EPSS 0.005
← Prev14 / 16Next →