VendorsIBMaixany version
Vulnerabilities

IBM AIX any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

620CVEs
CVE-2002-1551
Buffer overflow in nslookup in IBM AIX may allow attackers to cause a denial of service or execute arbitrary code.
Published 2003-03-18 · Modified
4.6EPSS 0.004
CVE-2015-3317
CA Common Services, as used in CA Client Automation r12.5 SP01, r12.8, and r12.9; CA Network and Systems Management r11.0, r11.1, and r11.2; CA NSM Job Management Option r11.0, r11.1, and r11.2; CA Universal Job Management Agent; CA Virtual Assurance for Infrastructure Managers (aka SystemEDGE) 12.6, 12.7, 12.8, and 12.9; and CA Workload Automation AE r11, r11.3, r11.3.5, and r11.3.6 on UNIX, does not properly perform bounds checking, which allows local users to gain privileges via unspecified vectors.
Published 2015-06-17 · Modified
4.6EPSS 0.004
CVE-2015-3318
CA Common Services, as used in CA Client Automation r12.5 SP01, r12.8, and r12.9; CA Network and Systems Management r11.0, r11.1, and r11.2; CA NSM Job Management Option r11.0, r11.1, and r11.2; CA Universal Job Management Agent; CA Virtual Assurance for Infrastructure Managers (aka SystemEDGE) 12.6, 12.7, 12.8, and 12.9; and CA Workload Automation AE r11, r11.3, r11.3.5, and r11.3.6 on UNIX, does not properly validate an unspecified variable, which allows local users to gain privileges via unknown vectors.
Published 2015-06-17 · Modified
4.6EPSS 0.004
CVE-2022-34362
IBM Sterling Secure Proxy HOST header injection
Published 2023-02-08 · Modified
4.6EPSS 0.004
CVE-2023-23475
IBM Infosphere Information Server cross-site scripting
Published 2023-02-08 · Modified
4.6EPSS 0.003
CVE-2002-1550
dump_smutil.sh in IBM AIX allows local users to overwrite arbitrary files via a symlink attack on temporary files.
Published 2004-09-01 · Modified
4.6EPSS 0.003
CVE-2026-16897
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
4.4EPSS 0.001
CVE-2020-4934
IBM Content Navigator 3.0.CD could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 191752.
Published 2021-02-02 · Modified
4.3EPSS 0.018
CVE-2007-6232
Cross-site scripting (XSS) vulnerability in index.php in FTP Admin 0.1.0 allows remote attackers to inject arbitrary web script or HTML via the error parameter in an error page action.
Published 2007-12-04 · Modified
4.32 PoCEPSS 0.016
CVE-2019-4377
IBM Sterling B2B Integrator 6.0.0.0 and 6.0.0.1 reveals sensitive information from a stack trace that could be used in further attacks against the system. IBM X-Force ID: 162803.
Published 2019-06-25 · Modified
4.3EPSS 0.013
CVE-2008-3860
Multiple cross-site scripting (XSS) vulnerabilities (1) in the WYSIWYG editors, (2) during local group creation, (3) during HTML redirects, (4) in the HTML import, (5) in the Rich text editor, and (6) in link-page in IBM Lotus Quickr 8.1 services for Lotus Domino before Hotfix 15 allow remote attackers to inject arbitrary web script or HTML via unknown vectors, including (7) the Imported Page. NOTE: the vulnerability in the WYSIWYG editors may exist because of an incomplete fix for CVE-2008-2163.
Published 2008-08-29 · Modified
4.3EPSS 0.013
CVE-2008-2163
Cross-site scripting (XSS) vulnerability in IBM Lotus Quickr 8.1 before Hotfix 5 for Windows and AIX, and before Hotfix 3 for i5/OS, allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to "WYSIWYG editors."
Published 2008-05-13 · Modified
4.3EPSS 0.012
CVE-2020-4687
IBM Content Navigator 3.0.7 and 3.0.8 could allow an authenticated user to view cached content of another user that they should not have access to. IBM X-Force ID: 186679.
Published 2020-08-20 · Modified
4.3EPSS 0.010
CVE-2020-4299
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.3.1 could expose sensitive information to a user through a specially crafted HTTP request. IBM X-Force ID: 176606.
Published 2020-05-14 · Modified
4.3EPSS 0.010
CVE-2021-20552
IBM Sterling File Gateway 6.0.0.0 through 6.1.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 199170.
Published 2021-10-07 · Modified
4.3EPSS 0.010
CVE-2023-23487
IBM Db2 audit logging
Published 2023-07-09 · Modified
4.3EPSS 0.008
CVE-2020-4548
IBM Content Navigator 3.0.7 and 3.0.8 is vulnerable to improper input validation. A malicious administrator could bypass the user interface and send requests to the IBM Content Navigator server with illegal characters that could be stored in the IBM Content Navigator database. IBM X-Force ID: 183316.
Published 2020-08-20 · Modified
4.3EPSS 0.007
CVE-2021-38954
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5 and 6.1.0.0 through 6.1.1.0 could disclose sensitive version information that could aid in future attacks against the system. IBM X-Force ID: 211414.
Published 2022-06-30 · Modified
4.3EPSS 0.007
CVE-2021-38977
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 212782.
Published 2021-11-15 · Modified
4.3EPSS 0.005
CVE-2023-47705
IBM Security Guardium Key Lifecycle Manager improper input validation
Published 2023-12-20 · Modified
4.3EPSS 0.005
CVE-2025-25045
IBM InfoSphere Information Server information disclosure
Published 2025-04-23 · Analyzed
4.3EPSS 0.003
CVE-2026-16886
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
4.3EPSS 0.003
CVE-2026-16849
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
4.3EPSS 0.003
CVE-2026-1262
IBM InfoSphere Information Server Information Disclosure
Published 2026-03-25 · Analyzed
4.3EPSS 0.002
CVE-2025-2827
IBM Sterling File Gateway information disclosure
Published 2025-07-08 · Analyzed
4.3EPSS 0.002
CVE-2025-3629
IBM InfoSphere Information Server file manipulation
Published 2025-06-21 · Analyzed
4.3EPSS 0.002
CVE-2024-39744
IBM Sterling Connect:Direct Web Services cross-site request forgery
Published 2024-08-22 · Analyzed
4.3EPSS 0.002
CVE-2025-36422
IBM InfoSphere Information Server is vulnerable to cross-site request forgery
Published 2026-03-25 · Analyzed
4.3EPSS 0.001
CVE-2024-54172
IBM Sterling B2B Integrator and IBM Sterling File Gateway cross-site request forgery
Published 2025-06-18 · Analyzed
4.3EPSS 0.001
CVE-2026-16825
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
4.2EPSS 0.003
CVE-2025-27907
IBM WebSphere Application Server server-side request forgery
Published 2025-04-22 · Analyzed
4.1EPSS 0.003
CVE-1999-0524
ICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts.
Published 2000-02-04 · Modified
4.0EPSS 0.322
CVE-2011-1384
The (1) bin/invscoutClient_VPD_Survey and (2) sbin/invscout_lsvpd programs in invscout.rte before 2.2.0.19 on IBM AIX 7.1, 6.1, 5.3, and earlier allow local users to delete arbitrary files, or trigger inventory scout operations on arbitrary files, via a symlink attack on an unspecified file.
Published 2012-01-04 · Modified
4.0EPSS 0.003
CVE-2022-42436
IBM MQ information disclosure
Published 2023-02-08 · Modified
4.0EPSS 0.002
CVE-2023-43035
IBM Sterling Control Center information disclosure
Published 2025-04-10 · Analyzed
4.0EPSS 0.002
CVE-2025-1348
IBM Sterling B2B Integrator and IBM Sterling File Gateway information disclosure
Published 2025-06-18 · Analyzed
4.0EPSS 0.001
CVE-2023-33847
IBM CICS TX information disclosure
Published 2023-06-08 · Modified
3.7EPSS 0.006
CVE-2026-0989
Libxml2: unbounded relaxng include recursion leading to stack overflow
Published 2026-01-15 · Analyzed
3.7EPSS 0.005
CVE-2026-16888
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
3.7EPSS 0.005
CVE-2023-33855
IBM Common Cryptographic Architecture information disclosure
Published 2024-03-26 · Analyzed
3.7EPSS 0.005
← Prev15 / 16Next →