VendorsIBMaixall versions
Vulnerabilities

IBM AIX

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

992CVEs
CVE-2022-35721
IBM Jazz for Service Management 1.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 231380.
Published 2022-09-23 · Modified
6.4EPSS 0.007
CVE-2021-29810
IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204279.
Published 2021-09-23 · Modified
6.4EPSS 0.005
CVE-2021-29812
IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204330.
Published 2021-09-23 · Modified
6.4EPSS 0.005
CVE-2021-29814
IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204334.
Published 2021-09-23 · Modified
6.4EPSS 0.005
CVE-2021-29815
IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204340.
Published 2021-09-23 · Modified
6.4EPSS 0.005
CVE-2021-29813
IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204331.
Published 2021-09-23 · Modified
6.4EPSS 0.005
CVE-2021-29832
IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204824.
Published 2021-09-23 · Modified
6.4EPSS 0.005
CVE-2021-29833
IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204825.
Published 2021-09-23 · Modified
6.4EPSS 0.005
CVE-2021-38877
IBM Jazz for Service Management 1.1.3.10 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 208405.
Published 2021-09-23 · Modified
6.4EPSS 0.005
CVE-2024-31914
IBM Sterling B2B Integrator cross-site scripting
Published 2025-01-06 · Analyzed
6.4EPSS 0.002
CVE-2025-23227
IBM Tivoli Application Dependency Discovery Manager cross-site scripting
Published 2025-01-23 · Analyzed
6.4EPSS 0.002
CVE-2024-49339
IBM Financial Transaction Manager cross-site scripting
Published 2025-01-31 · Analyzed
6.4EPSS 0.002
CVE-2025-3630
IBM Sterling B2B Integrator and IBM Sterling File Gateway cross-site scripting
Published 2025-07-08 · Analyzed
6.4EPSS 0.002
CVE-2024-22351
IBM InfoSphere Information Server session fixation
Published 2025-04-23 · Analyzed
6.3EPSS 0.002
CVE-2026-16980
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-20 · Analyzed
6.3EPSS 0.001
CVE-2008-5387
Buffer overflow in autoconf6 in IBM AIX 6.1.0 through 6.1.2, when Role-Based Access Control is enabled, allows local users with aix.network.config.tcpip authorization to gain privileges via unspecified vectors.
Published 2008-12-09 · Modified
6.2EPSS 0.003
CVE-2020-4832
IBM PowerHA 7.2 could allow a local attacker to obtain sensitive information from temporary directories after a discovery failure occurs. IBM X-Force ID: 189969.
Published 2021-02-05 · Modified
6.2EPSS 0.003
CVE-2004-2634
The (1) bos.rte.serv_aid or (2) bos.rte.console filesets in IBM AIX 5.1 and 5.2 allow local users to overwrite arbitrary files via a symlink attack on temporary files via unknown attack vectors.
Published 2005-12-04 · Modified
6.2EPSS 0.003
CVE-2020-4887
IBM AIX 7.1, 7.2 and AIX VIOS 3.1 could allow a local user to exploit a vulnerability in the gencore user command to create arbitrary files in any directory. IBM X-Force ID: 190911.
Published 2021-01-20 · Modified
6.2EPSS 0.003
CVE-2020-4885
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow a local user to access and change the configuration of Db2 due to a race condition of a symbolic link,. IBM X-Force ID: 190909.
Published 2021-06-24 · Modified
6.2EPSS 0.003
CVE-2021-39048
IBM Spectrum Protect Client 7.1 and 8.1 is vulnerable to a stack based buffer overflow, caused by improper bounds checking. A local attacker could exploit this vulnerability and cause a denial of service. IBM X-Force ID: 214438.
Published 2021-12-13 · Modified
6.2EPSS 0.003
CVE-2021-29860
IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the libc.a library to expose sensitive information. IBM X-Force ID: 206084.
Published 2021-11-17 · Modified
6.2EPSS 0.003
CVE-2021-29861
IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in EFS to expose sensitive information. IBM X-Force ID: 206085.
Published 2021-11-17 · Modified
6.2EPSS 0.003
CVE-2023-45167
IBM AIX denial of service
Published 2023-11-10 · Modified
6.2EPSS 0.003
CVE-2021-38976
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 stores user credentials in plain clear text which can be read by a local user. X-Force ID: 212781.
Published 2021-11-15 · Modified
6.2EPSS 0.002
CVE-2023-45172
IBM AIX denial of service
Published 2023-12-19 · Modified
6.2EPSS 0.002
CVE-2022-22444
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a local user to exploit a vulnerability in the lpd daemon to cause a denial of service. IBM X-Force ID: 224444.
Published 2022-06-15 · Modified
6.2EPSS 0.002
CVE-2021-38994
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 213072.
Published 2022-02-24 · Modified
6.2EPSS 0.002
CVE-2021-38995
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 213073.
Published 2022-02-24 · Modified
6.2EPSS 0.002
CVE-2021-29862
IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 206086.
Published 2021-08-26 · Modified
6.2EPSS 0.002
CVE-2021-29727
IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 201106.
Published 2021-08-26 · Modified
6.2EPSS 0.002
CVE-2021-38988
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 212950.
Published 2022-03-07 · Modified
6.2EPSS 0.002
CVE-2021-38989
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 212951.
Published 2022-03-07 · Modified
6.2EPSS 0.002
CVE-2021-38996
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 213076.
Published 2022-03-02 · Modified
6.2EPSS 0.002
CVE-2022-22350
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in CAA to cause a denial of service. IBM X-Force ID: 220394.
Published 2022-03-02 · Modified
6.2EPSS 0.002
CVE-2021-38993
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the smbcd daemon to cause a denial of service. IBM X-Force ID: 212962.
Published 2022-02-25 · Modified
6.2EPSS 0.002
CVE-2022-43381
IBM AIX denial of service
Published 2022-12-23 · Modified
6.2EPSS 0.002
CVE-2023-28514
IBM MQ information disclosure
Published 2023-05-19 · Modified
6.2EPSS 0.002
CVE-2022-40233
IBM AIX denial of service
Published 2022-12-23 · Modified
6.2EPSS 0.002
CVE-2022-39165
IBM AIX denial of service
Published 2022-12-23 · Modified
6.2EPSS 0.002
← Prev17 / 25Next →