VendorsIBMaixall versions
Vulnerabilities

IBM AIX

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

992CVEs
CVE-2021-38981
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 212788.
Published 2021-11-15 · Modified
5.3EPSS 0.014
CVE-2020-4412
The Spectrum Scale 4.2.0.0 through 4.2.3.21 and 5.0.0.0 through 5.0.4.3 file system component is affected by a denial of service security vulnerability. An attacker can force the Spectrum Scale mmfsd/mmsdrserv daemons to unexpectedly exit, impacting the functionality of the Spectrum Scale cluster and the availability of file systems managed by Spectrum Scale. IBM X-Force ID: 179987.
Published 2020-05-19 · Modified
5.3EPSS 0.013
CVE-2020-4761
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_2, 6.0.0.0 through 6.0.3.2, and 6.1.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 188895.
Published 2021-01-05 · Modified
5.3EPSS 0.013
CVE-2021-29682
IBM Security Identity Manager 7.0.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 199997
Published 2021-05-20 · Modified
5.3EPSS 0.013
CVE-2021-29687
IBM Security Identity Manager 7.0.2 could allow a remote user to enumerate usernames due to a difference of responses from valid and invalid login attempts. IBM X-Force ID: 200018
Published 2021-05-20 · Modified
5.3EPSS 0.013
CVE-2021-38980
IBM Tivoli Key Lifecycle Manager (IBM Security Guardium Key Lifecycle Manager) 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 212786.
Published 2021-11-23 · Modified
5.3EPSS 0.012
CVE-2016-8977
IBM BigFix Inventory v9 could disclose sensitive information to an unauthorized user using HTTP GET requests. This information could be used to mount further attacks against the system.
Published 2017-02-01 · Modified
5.3EPSS 0.011
CVE-2022-22473
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sensitive information caused by improper handling of Administrative Console data. This information could be used in further attacks against the system. IBM X-Force ID: 225347.
Published 2022-07-14 · Modified
5.3EPSS 0.011
CVE-2019-4741
IBM Content Navigator 3.0CD is vulnerable to Server Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 172815.
Published 2020-02-12 · Modified
5.3EPSS 0.010
CVE-2021-39086
IBM Sterling File Gateway 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 215889.
Published 2022-08-16 · Modified
5.3EPSS 0.009
CVE-2021-29681
IBM InfoSphere Information Server 11.7 could allow an attacker to obtain sensitive information by injecting parameters into an HTML query. This information could be used in further attacks against the system. IBM X-Force ID: 199918.
Published 2021-05-21 · Modified
5.3EPSS 0.009
CVE-2023-47703
IBM Security Guardium Key Lifecycle Manager information disclosure
Published 2023-12-20 · Modified
5.3EPSS 0.008
CVE-2023-43021
IBM InfoSphere Information Server information disclosure
Published 2023-12-01 · Modified
5.3EPSS 0.007
CVE-2023-33857
IBM InfoSphere Information Server information disclosure
Published 2023-07-16 · Modified
5.3EPSS 0.007
CVE-2023-45177
IBM MQ denial of service
Published 2024-03-20 · Analyzed
5.3EPSS 0.006
CVE-2022-43872
IBM Financial Transaction Manager information disclosure
Published 2022-12-20 · Modified
5.3EPSS 0.005
CVE-2023-29259
IBM Sterling Connect:Express for UNIX information disclosure
Published 2023-07-19 · Modified
5.3EPSS 0.005
CVE-2026-3482
IBM Sterling B2B Integrator and IBM Sterling File Gateway Authorization Bypass
Published 2026-07-22 · Analyzed
5.3EPSS 0.005
CVE-2026-16833
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
5.3EPSS 0.004
CVE-2024-40706
IBM InfoSphere Information Server information disclosure
Published 2025-01-24 · Analyzed
5.3EPSS 0.004
CVE-2024-55895
IBM InfoSphere Information Server information disclosure
Published 2025-03-29 · Analyzed
5.3EPSS 0.003
CVE-2024-56476
IBM TXSeries for Multiplatforms information disclosure
Published 2025-04-02 · Analyzed
5.3EPSS 0.003
CVE-2024-47109
IBM Sterling File Gateway information disclosure
Published 2025-03-10 · Analyzed
5.3EPSS 0.003
CVE-2026-16829
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
5.3EPSS 0.003
CVE-2021-29827
IBM InfoSphere Information Server clickjacking
Published 2024-12-18 · Analyzed
5.2EPSS 0.003
CVE-2020-4788
IBM Power9 (AIX 7.1, 7.2, and VIOS 3.1) processors could allow a local user to obtain sensitive information from the data in the L1 cache under extenuating circumstances. IBM X-Force ID: 189296.
Published 2020-11-20 · Modified
5.1EPSS 0.004
CVE-2021-29763
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 under very specific conditions, could allow a local user to keep running a procedure that could cause the system to run out of memory.and cause a denial of service. IBM X-Force ID: 202267.
Published 2021-09-16 · Modified
5.1EPSS 0.003
CVE-1999-0128
Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death.
Published 1999-09-29 · Modified
5.01 PoCEPSS 0.745
CVE-1999-0513
ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denial of service.
Published 1999-09-29 · Modified
5.01 PoCEPSS 0.709
CVE-2012-4817
The NFSv4 client implementation in IBM AIX 5.3, 6.1, and 7.1, and VIOS before 2.2.1.4-FP-25 SP-02, does not properly handle GID values, which allows remote attackers to cause a denial of service via unspecified vectors.
Published 2012-09-14 · Modified
5.0EPSS 0.076
CVE-1999-0116
Denial of service when an attacker sends many SYN packets to create multiple connections without ever sending an ACK to complete the connection, aka SYN flood.
Published 1999-09-29 · Modified
5.01 PoCEPSS 0.056
CVE-2003-0285
IBM AIX 5.2 and earlier distributes Sendmail with a configuration file (sendmail.cf) with the (1) promiscuous_relay, (2) accept_unresolvable_domains, and (3) accept_unqualified_senders features enabled, which allows Sendmail to be used as an open mail relay for sending spam e-mail.
Published 2003-05-14 · Modified
5.0EPSS 0.050
CVE-1999-0024
DNS cache poisoning via BIND, by predictable query IDs.
Published 1999-09-29 · Modified
5.0EPSS 0.050
CVE-2010-4622
Directory traversal vulnerability in WebSEAL in IBM Tivoli Access Manager for e-business 6.1.1 before 6.1.1-TIV-AWS-FP0001 on AIX allows remote attackers to read arbitrary files via a %uff0e%uff0e (encoded dot dot) in a URI.
Published 2010-12-30 · Modified
5.0EPSS 0.029
CVE-2001-0998
IBM HACMP 4.4 allows remote attackers to cause a denial of service via a completed TCP connection to HACMP ports (e.g., using a port scan) that does not send additional data, which causes a failure in snmpd.
Published 2002-03-09 · Modified
5.0EPSS 0.029
CVE-2007-1918
The RFC_SET_REG_SERVER_PROPERTY function in the SAP RFC Library 6.40 and 7.00 before 20070109 implements an option for exclusive access to an RFC server, which allows remote attackers to cause a denial of service (client lockout) via unspecified vectors. NOTE: This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended.
Published 2007-04-10 · Modified
5.0EPSS 0.025
CVE-1999-0010
Denial of Service vulnerability in BIND 8 Releases via maliciously formatted DNS messages.
Published 1999-09-29 · Modified
5.0EPSS 0.024
CVE-2002-1619
Buffer overflow in the FC client for IBM AIX 4.3.x allows remote attackers to cause a denial of service (crash and core dump).
Published 2005-03-26 · Modified
5.0EPSS 0.022
CVE-2007-1913
The TRUSTED_SYSTEM_SECURITY function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to verify the existence of users and groups on systems and domains via unspecified vectors, a different vulnerability than CVE-2006-6010. NOTE: This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended.
Published 2007-04-10 · Modified
5.0EPSS 0.022
CVE-1999-0086
AIX routed allows remote users to modify sensitive files.
Published 2000-02-04 · Modified
5.0EPSS 0.021
← Prev21 / 25Next →