VendorsIBMaixall versions
Vulnerabilities

IBM AIX

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

992CVEs
CVE-2022-42439
IBM App Connect Enterprise information disclosure
Published 2023-02-06 · Modified
6.8EPSS 0.007
CVE-2023-38729
IBM Db2 information disclosure
Published 2024-04-03 · Analyzed
6.8EPSS 0.006
CVE-2010-3405
Buffer overflow in sa_snap in the bos.esagent fileset in IBM AIX 6.1, 5.3, and earlier and VIOS 2.1, 1.5, and earlier allows local users to leverage system group membership and gain privileges via unspecified vectors.
Published 2010-09-16 · Modified
6.8EPSS 0.004
CVE-2020-4230
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1 and 11.5 is vulnerable to an escalation of privilege when an authenticated local attacker with special permissions executes specially crafted Db2 commands. IBM X-Force ID: 175212.
Published 2020-02-19 · Modified
6.7EPSS 0.004
CVE-2021-20515
IBM Informix Dynamic Server 14.10 is vulnerable to a stack based buffer overflow, caused by improper bounds checking. A local privileged user could overflow a buffer and execute arbitrary code on the system or cause a denial of service condition. IBM X-Force ID: 198366.
Published 2021-04-30 · Modified
6.7EPSS 0.003
CVE-2023-35012
IBM Db2 code execution
Published 2023-07-17 · Modified
6.7EPSS 0.002
CVE-2026-16914
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
6.7EPSS 0.002
CVE-2026-16951
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-20 · Analyzed
6.7EPSS 0.002
CVE-2007-4798
Unspecified vulnerability in invscout in Inventory Scout in invscout.rte in IBM AIX 5.2 and 5.3 allows local users to delete system files that have names matching the final substring of a hostname alias, as demonstrated by hostnames ending in "unix".
Published 2007-09-10 · Modified
6.6EPSS 0.003
CVE-2008-0585
sysmgt.websm.webaccess in IBM AIX 5.2 and 5.3 has world writable permissions for unspecified WebSM Remote Client files, which allows local users to "alter the behavior of" this client by overwriting these files.
Published 2008-02-05 · Modified
6.6EPSS 0.003
CVE-2007-2996
Unspecified vulnerability in perl.rte 5.8.0.10 through 5.8.0.95 on IBM AIX 5.2, and 5.8.2.10 through 5.8.2.50 on AIX 5.3, allows local users to gain privileges via unspecified vectors related to the installation and "waiting for a legitimate user to execute a binary that ships with Perl."
Published 2007-06-04 · Modified
6.6EPSS 0.003
CVE-2019-4386
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1 could allow an authenticated user to execute a function that would cause the server to crash. IBM X-Force ID: 162714.
Published 2019-07-01 · Modified
6.5EPSS 0.021
CVE-2014-0899
ftpd in IBM AIX 7.1.1 before SP10 and 7.1.2 before SP5, when a Workload Partition (aka WPAR) for AIX 5.2 or 5.3 is used, allows remote authenticated users to bypass intended permission settings and modify arbitrary files via FTP commands.
Published 2014-03-11 · Modified
6.5EPSS 0.019
CVE-2016-6038
Directory traversal vulnerability in Eclipse Help in IBM Tivoli Lightweight Infrastructure (aka LWI), as used in AIX 5.3, 6.1, and 7.1, allows remote authenticated users to read arbitrary files via a crafted URL.
Published 2016-09-26 · Modified
6.5EPSS 0.017
CVE-2020-4200
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 could allow an authenticated attacker to send specially crafted commands to cause a denial of service. IBM X-Force ID: 174914.
Published 2020-02-19 · Modified
6.5EPSS 0.016
CVE-2016-0215
IBM DB2 9.7, 10.1 before FP6, and 10.5 before FP8 on AIX, Linux, HP, Solaris and Windows allow remote authenticated users to cause a denial of service (daemon crash) via a SELECT statement with a subquery containing the AVG OLAP function on an Oracle compatible database.
Published 2018-01-16 · Modified
6.5EPSS 0.016
CVE-2019-4656
IBM MQ and IBM MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD is vulnerable to a denial of service attack that would allow an authenticated user to crash the queue and require a restart due to an error processing error messages. IBM X-Force ID: 170967.
Published 2020-03-16 · Modified
6.5EPSS 0.014
CVE-2020-4161
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5 could allow an authenticated attacker to cause a denial of service due to incorrect handling of certain commands. IBM X-Force ID: 174341.
Published 2020-02-19 · Modified
6.5EPSS 0.014
CVE-2021-29777
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5, under specific circumstance of a table being dropped while being accessed in another session, could allow an authenticated user to cause a denial of srevice IBM X-Force ID: 203031.
Published 2021-06-24 · Modified
6.5EPSS 0.014
CVE-2022-35637
IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a denial of service after entering a malformed SQL statement into the Db2expln tool. IBM X-Force ID: 230823.
Published 2022-09-13 · Modified
6.5EPSS 0.013
CVE-2021-38931
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1, and 11.5 is vulnerable to an information disclosure as a result of a connected user having indirect read access to a table where they are not authorized to select from. IBM X-Force ID: 210418.
Published 2021-12-09 · Modified
6.5EPSS 0.012
CVE-2021-20480
IBM WebSphere Application Server 7.0, 8.0, and 8.5 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, a remote authenticated attacker could exploit this vulnerability to obtain sensitive data. IBM X-Force ID: 197502.
Published 2021-04-08 · Modified
6.5EPSS 0.012
CVE-2022-42444
IBM App Connect Enterprise denial of service
Published 2023-02-06 · Modified
6.5EPSS 0.011
CVE-2021-20579
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a user who can create a view or inline SQL function to obtain sensitive information when AUTO_REVAL is set to DEFFERED_FORCE. IBM X-Force ID: 199283.
Published 2021-06-24 · Modified
6.5EPSS 0.011
CVE-2022-22483
IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to an information disclosure in some scenarios due to unauthorized access caused by improper privilege management when CREATE OR REPLACE command is used. IBM X-Force ID: 225979.
Published 2022-09-13 · Modified
6.5EPSS 0.011
CVE-2021-39033
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5 and 6.1.0.0 through 6.1.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 213963.
Published 2022-04-19 · Modified
6.5EPSS 0.010
CVE-2022-22310
IBM WebSphere Application Server Liberty 21.0.0.10 through 21.0.0.12 could provide weaker than expected security. A remote attacker could exploit this weakness to obtain sensitive information and gain unauthorized access to JAX-WS applications. IBM X-Force ID: 217224.
Published 2022-01-19 · Modified
6.5EPSS 0.010
CVE-2021-38974
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow an authenticated user to cause a denial of service using specially crafted HTTP requests. IBM X-Force ID: 212779.
Published 2021-11-15 · Modified
6.5EPSS 0.010
CVE-2023-27859
IBM Db2 code execution
Published 2024-01-22 · Modified
6.5EPSS 0.010
CVE-2021-38975
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow an authenticated user to to obtain sensitive information from a specially crafted HTTP request. IBM X-Force ID: 212780.
Published 2021-11-15 · Modified
6.5EPSS 0.010
CVE-2021-20483
IBM Security Identity Manager 6.0.2 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, a remote authenticated attacker could exploit this vulnerability to obtain sensitive data. IBM X-Force ID: 197591.
Published 2021-06-16 · Modified
6.5EPSS 0.009
CVE-2023-29256
IBM Db2 information disclosure
Published 2023-07-09 · Modified
6.5EPSS 0.008
CVE-2023-33848
IBM CICS TX information disclosure
Published 2023-06-07 · Modified
6.5EPSS 0.008
CVE-2023-50308
IBM Db2 denial of service
Published 2024-01-22 · Modified
6.5EPSS 0.008
CVE-2020-4259
IBM Sterling File Gateway 2.2.0.0 through 6.0.3.1 could allow an authenticated user could manipulate cookie information and remove or add modules from the cookie to access functionality not authorized to. IBM X-Force ID: 175638.
Published 2020-05-14 · Modified
6.5EPSS 0.008
CVE-2022-31772
IBM MQ denial of service
Published 2022-11-11 · Modified
6.5EPSS 0.008
CVE-2023-47141
IBM Db2 denial of service
Published 2024-01-22 · Modified
6.5EPSS 0.007
CVE-2023-47158
IBM Db2 denial of service
Published 2024-01-22 · Modified
6.5EPSS 0.007
CVE-2023-47746
IBM Db2 denial of service
Published 2024-01-22 · Modified
6.5EPSS 0.007
CVE-2023-47747
IBM Db2 denial of service
Published 2024-01-22 · Modified
6.5EPSS 0.007
← Prev15 / 25Next →