VendorsIBMaixany version
Vulnerabilities

IBM AIX any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

620CVEs
CVE-2024-56474
IBM TXSeries for Multiplatforms cross-site request forgery
Published 2025-04-02 · Analyzed
8.8EPSS 0.002
CVE-2026-16996
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-20 · Analyzed
8.8EPSS 0.002
CVE-2026-16936
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-20 · Analyzed
8.8EPSS 0.002
CVE-2026-16934
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-20 · Analyzed
8.8EPSS 0.002
CVE-2026-19449
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-20 · Analyzed
8.8EPSS 0.001
CVE-2026-19442
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-20 · Analyzed
8.8EPSS 0.001
CVE-2021-29678
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a user with DBADM authority to access other databases and read or modify files. IBM X-Force ID: 199914.
Published 2021-12-09 · Modified
8.7EPSS 0.011
CVE-2022-22351
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged trusted host user to exploit a vulnerability in the nimsh daemon to cause a denial of service in the nimsh daemon on another trusted host. IBM X-Force ID: 220396
Published 2022-03-07 · Modified
8.6EPSS 0.012
CVE-2020-4204
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code on the system with root privileges. IBM X-Force ID: 174960.
Published 2020-02-19 · Modified
8.4EPSS 0.006
CVE-2019-4154
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-Force ID: 158519.
Published 2019-07-01 · Modified
8.4EPSS 0.005
CVE-2019-4322
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-Force ID: 161202.
Published 2019-07-01 · Modified
8.4EPSS 0.005
CVE-2023-30431
IBM Db2 buffer overflow
Published 2023-07-09 · Modified
8.4EPSS 0.003
CVE-2024-51459
IBM InfoSphere Server Information command execution
Published 2025-03-19 · Analyzed
8.4EPSS 0.001
CVE-2026-18842
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-20 · Analyzed
8.4EPSS 0.001
CVE-2020-4949
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 192025.
Published 2021-01-26 · Modified
8.2EPSS 0.048
CVE-2023-25926
IBM Security Guardium Key Lifecycle Manager XML external entity injection
Published 2024-02-29 · Analyzed
8.2EPSS 0.014
CVE-2026-16857
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
8.2EPSS 0.006
CVE-2026-15061
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
8.2EPSS 0.006
CVE-2026-16686
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
8.2EPSS 0.005
CVE-2026-18840
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-20 · Analyzed
8.2EPSS 0.001
CVE-2026-16943
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-20 · Analyzed
8.2EPSS 0.001
CVE-2016-10086
RESTful web services in CA Service Desk Manager 12.9 and CA Service Desk Management 14.1 might allow remote authenticated users to read or modify task information by leveraging incorrect permissions applied to a RESTful request.
Published 2017-01-18 · Modified
8.1EPSS 0.016
CVE-2016-8980
IBM BigFix Inventory v9 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources.
Published 2017-02-01 · Modified
8.1EPSS 0.015
CVE-2020-4945
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated user to overwrite arbirary files due to improper group permissions. IBM X-Force ID: 191945.
Published 2021-06-24 · Modified
8.1EPSS 0.010
CVE-2023-40363
IBM InfoSphere Information Server privilege escalation
Published 2023-11-18 · Modified
8.1EPSS 0.006
CVE-2026-15078
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
8.1EPSS 0.003
CVE-2026-8834
IBM HTTP Server is affected by multiple vulnerabilities
Published 2026-05-26 · Analyzed
8.0EPSS 0.003
CVE-2021-20354
IBM WebSphere Application Server 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 194883.
Published 2021-02-18 · Modified
7.8EPSS 0.041
CVE-2009-3900
Unspecified vulnerability in the Cluster Management component in IBM PowerHA 5.4, 5.4.1, 5.5, and 6.1 on AIX allows remote attackers to modify the operating-system configuration via packets to the godm port (6177/tcp).
Published 2009-11-06 · Modified
7.8EPSS 0.026
CVE-2016-3053
IBM AIX contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges.
Published 2017-02-01 · Modified
7.81 PoCEPSS 0.025
CVE-2007-3626
Unspecified vulnerability in the ADM daemon in Hitachi TPBroker before 20070706 allows remote attackers to cause a denial of service (daemon crash) via a certain request.
Published 2007-07-09 · Modified
7.8EPSS 0.019
CVE-2022-35717
"IBM InfoSphere Information Server 11.7 could allow a locally authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-"Force ID: 231361.
Published 2022-11-03 · Modified
7.8EPSS 0.006
CVE-2016-9795
The casrvc program in CA Common Services, as used in CA Client Automation 12.8, 12.9, and 14.0; CA SystemEDGE 5.8.2 and 5.9; CA Systems Performance for Infrastructure Managers 12.8 and 12.9; CA Universal Job Management Agent 11.2; CA Virtual Assurance for Infrastructure Managers 12.8 and 12.9; CA Workload Automation AE 11, 11.3, 11.3.5, and 11.3.6 on AIX, HP-UX, Linux, and Solaris allows local users to modify arbitrary files and consequently gain root privileges via vectors related to insufficient validation.
Published 2017-01-27 · Modified
7.8EPSS 0.005
CVE-2016-5985
The IBM Tivoli Storage Manager (IBM Spectrum Protect) AIX client is vulnerable to a buffer overflow when Journal-Based Backup is enabled. A local attacker could overflow a buffer and execute arbitrary code on the system or cause a system crash.
Published 2017-02-01 · Modified
7.8EPSS 0.004
CVE-2022-22454
IBM InfoSphere Information Server 11.7 could allow a locally authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.
Published 2022-05-10 · Modified
7.8EPSS 0.004
CVE-2026-16875
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
7.8EPSS 0.002
CVE-2026-16997
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-20 · Analyzed
7.8EPSS 0.002
CVE-2026-17171
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-20 · Analyzed
7.8EPSS 0.002
CVE-2026-16874
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
7.8EPSS 0.002
CVE-2026-16869
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
7.8EPSS 0.002
← Prev4 / 16Next →