VendorsIBMaixall versions
Vulnerabilities

IBM AIX

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

992CVEs
CVE-2022-35646
IBM Security Verify Governance, Identity Manager security bypass
Published 2022-12-22 · Modified
5.9EPSS 0.004
CVE-2024-39746
IBM Sterling Connect:Direct Web Services information disclosure
Published 2024-08-22 · Modified
5.9EPSS 0.003
CVE-2026-10571
IBM WebSphere Application Server Liberty is affected by a denial of service
Published 2026-08-13 · Analyzed
5.7EPSS 0.006
CVE-2025-2140
IBM Engineering Requirements Management Doors Next spoofing
Published 2025-10-12 · Analyzed
5.7EPSS 0.001
CVE-2022-22373
An improper validation vulnerability in IBM InfoSphere Information Server 11.7 Pack for SAP Apps and BW Packs may lead to creation of directories and files on the server file system that may contain non-sensitive debugging information like stack traces. IBM X-Force ID: 221323.
Published 2022-07-01 · Modified
5.5EPSS 0.005
CVE-2021-29738
IBM InfoSphere Data Flow Designer (IBM InfoSphere Information Server 11.7 ) is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 201302.
Published 2021-11-02 · Modified
5.5EPSS 0.005
CVE-2024-45072
IBM WebSphere Application Server XML external entity injection
Published 2024-10-16 · Analyzed
5.5EPSS 0.004
CVE-2018-1655
IBM AIX 5.3, 6.1, 7.1, and 7.2 contains a vulnerability in the rmsock command that may be used to expose kernel memory. IBM X-Force ID: 144748.
Published 2018-06-22 · Modified
5.5EPSS 0.004
CVE-2023-28529
IBM InfoSphere Information Server 11.7
Published 2023-05-19 · Modified
5.5EPSS 0.004
CVE-2016-8944
IBM AIX 7.1 and 7.2 allows a local user to open a file with a specially crafted argument that would crash the system. IBM APARs: IV91488, IV91487, IV91456, IV90234.
Published 2017-02-15 · Modified
5.5EPSS 0.004
CVE-2016-0371
The Tivoli Storage Manager (TSM) password may be displayed in plain text via application trace output while application tracing is enabled.
Published 2017-02-01 · Modified
5.5EPSS 0.003
CVE-2016-8981
IBM BigFix Inventory v9 allows web pages to be stored locally which can be read by another user on the system.
Published 2017-02-01 · Modified
5.5EPSS 0.003
CVE-2021-38926
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to gain privileges due to allowing modification of columns of existing tasks. IBM X-Force ID: 210321.
Published 2021-12-09 · Modified
5.5EPSS 0.003
CVE-2019-4619
IBM MQ and IBM MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD could allow a local attacker to obtain sensitive information by inclusion of sensitive data within trace. IBM X-Force ID: 168862.
Published 2020-03-16 · Modified
5.5EPSS 0.003
CVE-2019-4719
IBM MQ and IBM MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD could allow a local attacker to obtain sensitive information by inclusion of sensitive data within runmqras data.
Published 2020-03-16 · Modified
5.5EPSS 0.003
CVE-2016-8963
IBM BigFix Inventory v9 stores potentially sensitive information in log files that could be read by a local user.
Published 2017-02-01 · Modified
5.5EPSS 0.003
CVE-2016-8967
IBM BigFix Inventory v9 9.2 stores user credentials in plain in clear text which can be read by a local user.
Published 2017-02-01 · Modified
5.5EPSS 0.003
CVE-2024-45071
IBM WebSphere Application Server cross-site scripting
Published 2024-10-16 · Analyzed
5.5EPSS 0.002
CVE-2025-1349
IBM Sterling B2B Integrator and IBM Sterling File Gateway cross-site scripting
Published 2025-06-18 · Analyzed
5.5EPSS 0.002
CVE-2023-28950
IBM MQ information disclosure
Published 2023-05-19 · Modified
5.5EPSS 0.002
CVE-2022-22484
IBM Spectrum Protect Operations Center 8.1.12 and 8.1.13 could allow a local attacker to obtain sensitive information, caused by plain text user account passwords potentially being stored in the browser's application command history. By accessing browser history, an attacker could exploit this vulnerability to obtain other user accounts' passwords. IBM X-Force ID: 226322.
Published 2022-05-17 · Modified
5.5EPSS 0.002
CVE-2025-36002
IBM Sterling B2B Integrator information disclosure
Published 2025-10-16 · Modified
5.5EPSS 0.002
CVE-2026-16883
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
5.5EPSS 0.001
CVE-2024-47102
IBM AIX denial of service
Published 2024-12-25 · Modified
5.5EPSS 0.001
CVE-2026-16973
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-20 · Analyzed
5.5EPSS 0.001
CVE-2026-6053
IBM® Db2® is vulnerable to a denial of service when a specially crafted query is run with range partitioned tables
Published 2026-05-27 · Analyzed
5.5EPSS 0.001
CVE-2026-16855
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
5.5EPSS 0.001
CVE-2026-16952
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-20 · Analyzed
5.5EPSS 0.001
CVE-2024-52906
IBM AIX denial of service
Published 2024-12-25 · Analyzed
5.5EPSS 0.001
CVE-2022-35720
IBM Sterling External Authentication Server information disclosure
Published 2023-02-08 · Modified
5.5EPSS 0.001
CVE-2026-18822
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-20 · Analyzed
5.5EPSS 0.001
CVE-2026-17009
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-20 · Analyzed
5.5EPSS 0.001
CVE-2021-20562
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_3 and 6.1.0.0 through 6.1.0.2 vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199232.
Published 2021-07-27 · Modified
5.4EPSS 0.009
CVE-2020-4406
IBM Spectrum Protect Client 8.1.7.0 through 8.1.9.1 (Linux and Windows), 8.1.9.0 trough 8.1.9.1 (AIX) and IBM Spectrum Protect for Space Management 8.1.7.0 through 8.1.9.1 (Linux), 8.1.9.0 through 8.1.9.1 (AIX) web user interfaces could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 179488.
Published 2020-06-15 · Modified
5.4EPSS 0.008
CVE-2020-4578
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 184433.
Published 2020-09-10 · Modified
5.4EPSS 0.007
CVE-2022-40748
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 236586.
Published 2022-09-23 · Modified
5.4EPSS 0.007
CVE-2021-20560
IBM Sterling Connect:Direct Browser User Interface 1.4.1.1 and 1.5.0.2 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 199229.
Published 2021-07-26 · Modified
5.4EPSS 0.006
CVE-2022-34165
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.9 are vulnerable to HTTP header injection, caused by improper validation. This could allow an attacker to conduct various attacks against the vulnerable system, including cache poisoning and cross-site scripting. IBM X-Force ID: 229429.
Published 2022-09-09 · Modified
5.4EPSS 0.006
CVE-2023-35020
IBM Sterling Control Center directory traversal
Published 2024-01-19 · Modified
5.4EPSS 0.005
CVE-2021-38982
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 212791.
Published 2021-11-15 · Modified
5.4EPSS 0.005
← Prev19 / 25Next →