VendorsIBMaixall versions
Vulnerabilities

IBM AIX

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

992CVEs
CVE-2020-4548
IBM Content Navigator 3.0.7 and 3.0.8 is vulnerable to improper input validation. A malicious administrator could bypass the user interface and send requests to the IBM Content Navigator server with illegal characters that could be stored in the IBM Content Navigator database. IBM X-Force ID: 183316.
Published 2020-08-20 · Modified
4.3EPSS 0.007
CVE-2021-38954
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5 and 6.1.0.0 through 6.1.1.0 could disclose sensitive version information that could aid in future attacks against the system. IBM X-Force ID: 211414.
Published 2022-06-30 · Modified
4.3EPSS 0.007
CVE-2021-38977
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 212782.
Published 2021-11-15 · Modified
4.3EPSS 0.005
CVE-2023-47705
IBM Security Guardium Key Lifecycle Manager improper input validation
Published 2023-12-20 · Modified
4.3EPSS 0.005
CVE-2025-25045
IBM InfoSphere Information Server information disclosure
Published 2025-04-23 · Analyzed
4.3EPSS 0.003
CVE-2026-16886
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
4.3EPSS 0.003
CVE-2026-16849
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
4.3EPSS 0.003
CVE-2026-1262
IBM InfoSphere Information Server Information Disclosure
Published 2026-03-25 · Analyzed
4.3EPSS 0.002
CVE-2025-2827
IBM Sterling File Gateway information disclosure
Published 2025-07-08 · Analyzed
4.3EPSS 0.002
CVE-2025-3629
IBM InfoSphere Information Server file manipulation
Published 2025-06-21 · Analyzed
4.3EPSS 0.002
CVE-2024-39744
IBM Sterling Connect:Direct Web Services cross-site request forgery
Published 2024-08-22 · Analyzed
4.3EPSS 0.002
CVE-2025-36422
IBM InfoSphere Information Server is vulnerable to cross-site request forgery
Published 2026-03-25 · Analyzed
4.3EPSS 0.001
CVE-2024-54172
IBM Sterling B2B Integrator and IBM Sterling File Gateway cross-site request forgery
Published 2025-06-18 · Analyzed
4.3EPSS 0.001
CVE-2026-16825
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
4.2EPSS 0.003
CVE-2025-27907
IBM WebSphere Application Server server-side request forgery
Published 2025-04-22 · Analyzed
4.1EPSS 0.003
CVE-1999-0524
ICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts.
Published 2000-02-04 · Modified
4.0EPSS 0.322
CVE-2006-6915
ftpd in IBM AIX 5.2.0 and 5.3.0 allows remote authenticated users to cause a denial of service (port exhaustion) via unspecified vectors. NOTE: some details were obtained from third party sources.
Published 2007-01-10 · Modified
4.0EPSS 0.014
CVE-2011-1384
The (1) bin/invscoutClient_VPD_Survey and (2) sbin/invscout_lsvpd programs in invscout.rte before 2.2.0.19 on IBM AIX 7.1, 6.1, 5.3, and earlier allow local users to delete arbitrary files, or trigger inventory scout operations on arbitrary files, via a symlink attack on an unspecified file.
Published 2012-01-04 · Modified
4.0EPSS 0.003
CVE-2022-42436
IBM MQ information disclosure
Published 2023-02-08 · Modified
4.0EPSS 0.002
CVE-2023-43035
IBM Sterling Control Center information disclosure
Published 2025-04-10 · Analyzed
4.0EPSS 0.002
CVE-2025-1348
IBM Sterling B2B Integrator and IBM Sterling File Gateway information disclosure
Published 2025-06-18 · Analyzed
4.0EPSS 0.001
CVE-2023-33847
IBM CICS TX information disclosure
Published 2023-06-08 · Modified
3.7EPSS 0.006
CVE-2026-0989
Libxml2: unbounded relaxng include recursion leading to stack overflow
Published 2026-01-15 · Analyzed
3.7EPSS 0.005
CVE-2026-16888
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
3.7EPSS 0.005
CVE-2023-33855
IBM Common Cryptographic Architecture information disclosure
Published 2024-03-26 · Analyzed
3.7EPSS 0.005
CVE-2023-33849
IBM CICS TX information disclosure
Published 2023-06-07 · Modified
3.7EPSS 0.004
CVE-2024-41760
IBM Common Cryptographic Architecture information disclosure
Published 2025-03-11 · Analyzed
3.7EPSS 0.003
CVE-2006-0133
Multiple directory traversal vulnerabilities in AIX 5.3 ML03 allow local users to determine the existence of files and read partial contents of certain files via a .. (dot dot) in the argument to (1) getCommand.new (aka getCommand) and (2) getShell, a different vulnerability than CVE-2005-4273.
Published 2006-01-09 · Modified
3.62 PoCEPSS 0.010
CVE-2001-1079
create_keyfiles in PSSP 3.2 with DCE 3.1 authentication on AIX creates keyfile directories with world-writable permissions, which could allow a local user to delete key files and cause a denial of service.
Published 2002-06-25 · Modified
3.6EPSS 0.003
CVE-2026-16890
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
3.6EPSS 0.001
CVE-2009-5062
IBM Lotus Quickr 8.1 before 8.1.0.15 services for Lotus Domino on AIX allows remote authenticated users to cause a denial of service (daemon crash) by subscribing to an Atom feed, aka SPR JRIE7VKMP9.
Published 2011-03-22 · Modified
3.5EPSS 0.008
CVE-2025-2138
IBM Engineering Requirements Management Doors Next data modification
Published 2025-10-12 · Analyzed
3.5EPSS 0.002
CVE-2025-2139
IBM Engineering Requirements Management Doors Next security bypass
Published 2025-10-12 · Analyzed
3.5EPSS 0.002
CVE-2006-1247
rm_mlcache_file in bos.rte.install in AIX 5.1.0 through 5.3.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files.
Published 2006-04-19 · Modified
3.3EPSS 0.004
CVE-2013-6335
The Backup-Archive client in IBM Tivoli Storage Manager (TSM) for Space Management 5.x and 6.x before 6.2.5.3, 6.3.x before 6.3.2, 6.4.x before 6.4.2, and 7.1.x before 7.1.0.3 on Linux and AIX, and 5.x and 6.x before 6.1.5.6 on Solaris and HP-UX, does not preserve file permissions across backup and restore operations, which allows local users to bypass intended access restrictions via standard filesystem operations.
Published 2014-08-26 · Modified
3.3EPSS 0.003
CVE-2020-4629
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local user with specialized access to obtain sensitive information from a detailed technical error message. This information could be used in further attacks against the system. IBM X-Force ID: 185370.
Published 2020-09-30 · Modified
3.3EPSS 0.003
CVE-2025-8732
libxml2 xmlcatalog xmlParseSGMLCatalog recursion
Published 2025-08-08 · Analyzed
3.3EPSS 0.002
CVE-2020-4591
IBM Spectrum Protect Server 8.1.0.000 through 8.1.10.000 could disclose sensitive information in nondefault settings due to occasionally not encrypting the second chunk of an object in an encrypted container pool. IBM X-Force ID: 184746.
Published 2020-08-28 · Modified
3.3EPSS 0.002
CVE-2026-16891
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
3.3EPSS 0.001
CVE-2011-4160
Unspecified vulnerability in HP Operations Agent 11.00 and Performance Agent 4.73 and 5.0 on AIX, HP-UX, Linux, and Solaris allows local users to bypass intended directory-access restrictions via unknown vectors.
Published 2011-11-24 · Modified
3.2EPSS 0.003
← Prev24 / 25Next →