VendorsIBMaixall versions
Vulnerabilities

IBM AIX

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

992CVEs
CVE-2023-28514
IBM MQ information disclosure
Published 2023-05-19 · Modified
6.2EPSS 0.002
CVE-2022-39164
IBM AIX denial of service
Published 2022-12-23 · Modified
6.2EPSS 0.002
CVE-2022-40233
IBM AIX denial of service
Published 2022-12-23 · Modified
6.2EPSS 0.002
CVE-2022-43848
IBM AIX denial of service
Published 2022-12-23 · Modified
6.2EPSS 0.002
CVE-2022-43875
IBM Financial Transaction Manager for SWIFT Services for Multiplatforms denial of service
Published 2022-12-20 · Modified
6.2EPSS 0.002
CVE-2022-43382
IBM AIX denial of service
Published 2022-12-20 · Modified
6.2EPSS 0.002
CVE-2023-45165
IBM AIX denial of service
Published 2023-12-22 · Modified
6.2EPSS 0.002
CVE-2023-45175
IBM AIX denial of service
Published 2024-01-11 · Modified
6.2EPSS 0.002
CVE-2023-45171
IBM AIX denial of service
Published 2024-01-11 · Modified
6.2EPSS 0.002
CVE-2023-45169
IBM AIX denial of service
Published 2024-01-11 · Modified
6.2EPSS 0.002
CVE-2023-45173
IBM AIX denial of service
Published 2024-01-11 · Modified
6.2EPSS 0.002
CVE-2021-29904
IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI displays user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 207610.
Published 2021-09-23 · Modified
6.2EPSS 0.002
CVE-2021-38949
IBM MQ 7.5, 8.0, 9.0 LTS, 9.1 CD, and 9.1 LTS stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 211403.
Published 2021-11-16 · Modified
6.2EPSS 0.002
CVE-2022-22478
IBM Spectrum Protect Client 8.1.0.0 through 8.1.14.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 225886.
Published 2022-06-30 · Modified
6.2EPSS 0.002
CVE-2023-50945
IBM Common Licensing information disclosure
Published 2025-01-26 · Analyzed
6.2EPSS 0.001
CVE-2023-33832
IBM Storage Protect denial of service
Published 2023-07-19 · Modified
6.2EPSS 0.001
CVE-2023-24964
IBM InfoSphere Information Server information disclosure
Published 2023-02-17 · Modified
6.2EPSS 0.001
CVE-2023-22878
IBM InfoSphere Information Server information disclosure
Published 2023-05-19 · Modified
6.2EPSS 0.001
CVE-2023-40371
IBM AIX information disclosure
Published 2023-08-24 · Modified
6.2EPSS 0.001
CVE-2018-1853
IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 151014.
Published 2019-04-08 · Modified
6.1EPSS 0.012
CVE-2022-25256
SAS Web Report Studio 4.4 allows XSS. /SASWebReportStudio/logonAndRender.do has two parameters: saspfs_request_backlabel_list and saspfs_request_backurl_list. The first one affects the content of the button placed in the top left. The second affects the page to which the user is directed after pressing the button, e.g., a malicious web page. In addition, the second parameter executes JavaScript, which means XSS is possible by adding a javascript: URL.
Published 2022-02-19 · Modified
6.1EPSS 0.012
CVE-2016-8961
IBM BigFix Inventory v9 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.
Published 2017-02-01 · Modified
6.1EPSS 0.009
CVE-2019-4681
IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 171734.
Published 2020-03-24 · Modified
6.1EPSS 0.007
CVE-2020-4657
IBM Sterling B2B Integrator 5.2.0.0 through 6.0.3.2 Standard Edition is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186094.
Published 2020-12-16 · Modified
6.1EPSS 0.007
CVE-2020-4658
IBM Sterling File Gateway 2.2.0.0 through 6.0.3.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186095.
Published 2020-12-16 · Modified
6.1EPSS 0.007
CVE-2021-29712
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 200966.
Published 2021-07-09 · Modified
6.1EPSS 0.007
CVE-2015-9281
Logon Manager in SAS Web Infrastructure Platform before 9.4M3 allows reflected XSS on the Timeout page.
Published 2019-01-17 · Modified
6.1EPSS 0.006
CVE-2022-22477
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 225605.
Published 2022-07-14 · Modified
6.1EPSS 0.006
CVE-2022-34330
IBM Sterling B2B Integrator cross-site scripting
Published 2023-01-04 · Modified
6.1EPSS 0.004
CVE-2024-49349
IBM Financial Transaction Manager cross-site scripting
Published 2025-01-31 · Analyzed
6.1EPSS 0.002
CVE-2025-33014
IBM Sterling B2B Integrator and IBM Sterling File Gateway link injection
Published 2025-07-18 · Analyzed
6.1EPSS 0.002
CVE-2019-4568
IBM MQ and IBM MQ Appliance 8.0 and 9.0 LTS could allow a remote attacker with intimate knowledge of the server to cause a denial of service when receiving data on the channel. IBM X-Force ID: 166629.
Published 2020-01-28 · Modified
5.9EPSS 0.013
CVE-2016-8966
IBM BigFix Inventory v9 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
Published 2017-02-01 · Modified
5.9EPSS 0.012
CVE-2019-4102
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 158092.
Published 2019-07-01 · Modified
5.9EPSS 0.012
CVE-2021-29692
IBM Security Identity Manager 7.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 200253.
Published 2021-05-20 · Modified
5.9EPSS 0.010
CVE-2026-0990
Libxml2: libxml2: denial of service via uncontrolled recursion in xml catalog processing
Published 2026-01-15 · Analyzed
5.9EPSS 0.010
CVE-2021-38978
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 212783.
Published 2021-11-15 · Modified
5.9EPSS 0.009
CVE-2023-42019
IBM InfoSphere Information Server information disclosure
Published 2023-12-01 · Modified
5.9EPSS 0.005
CVE-2022-38712
"IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Web services could allow a man-in-the-middle attacker to conduct SOAPAction spoofing to execute unwanted or unauthorized operations. IBM X-Force ID: 234762."
Published 2022-11-03 · Modified
5.9EPSS 0.005
CVE-2026-16827
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
5.9EPSS 0.004
← Prev18 / 25Next →