VendorsIBMaixall versions
Vulnerabilities

IBM AIX

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

992CVEs
CVE-2025-33112
IBM AIX command execution
Published 2025-06-10 · Analyzed
8.4EPSS 0.002
CVE-2022-41290
IBM AIX privilege escalation
Published 2022-12-23 · Modified
8.4EPSS 0.002
CVE-2024-51459
IBM InfoSphere Server Information command execution
Published 2025-03-19 · Analyzed
8.4EPSS 0.001
CVE-2026-18842
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-20 · Analyzed
8.4EPSS 0.001
CVE-2020-4949
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 192025.
Published 2021-01-26 · Modified
8.2EPSS 0.048
CVE-2023-25926
IBM Security Guardium Key Lifecycle Manager XML external entity injection
Published 2024-02-29 · Analyzed
8.2EPSS 0.014
CVE-2026-16857
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
8.2EPSS 0.006
CVE-2026-15061
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
8.2EPSS 0.006
CVE-2026-16686
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
8.2EPSS 0.005
CVE-2026-18840
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-20 · Analyzed
8.2EPSS 0.001
CVE-2026-16943
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-20 · Analyzed
8.2EPSS 0.001
CVE-2016-10086
RESTful web services in CA Service Desk Manager 12.9 and CA Service Desk Management 14.1 might allow remote authenticated users to read or modify task information by leveraging incorrect permissions applied to a RESTful request.
Published 2017-01-18 · Modified
8.1EPSS 0.016
CVE-2016-8980
IBM BigFix Inventory v9 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources.
Published 2017-02-01 · Modified
8.1EPSS 0.015
CVE-2020-4945
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated user to overwrite arbirary files due to improper group permissions. IBM X-Force ID: 191945.
Published 2021-06-24 · Modified
8.1EPSS 0.010
CVE-2023-40363
IBM InfoSphere Information Server privilege escalation
Published 2023-11-18 · Modified
8.1EPSS 0.006
CVE-2026-15078
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
8.1EPSS 0.003
CVE-2024-27273
IBM AIX privilege escalation
Published 2024-05-07 · Analyzed
8.1EPSS 0.001
CVE-2026-8834
IBM HTTP Server is affected by multiple vulnerabilities
Published 2026-05-26 · Analyzed
8.0EPSS 0.003
CVE-2021-20354
IBM WebSphere Application Server 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 194883.
Published 2021-02-18 · Modified
7.8EPSS 0.041
CVE-2011-1385
IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.1.x and 2.2.x, allows remote attackers to cause a denial of service (system crash) via an ICMP Echo Reply packet that contains 1 in the Identifier field, a different vulnerability than CVE-2012-0194.
Published 2012-03-02 · Modified
7.8EPSS 0.035
CVE-2009-3900
Unspecified vulnerability in the Cluster Management component in IBM PowerHA 5.4, 5.4.1, 5.5, and 6.1 on AIX allows remote attackers to modify the operating-system configuration via packets to the godm port (6177/tcp).
Published 2009-11-06 · Modified
7.8EPSS 0.026
CVE-2016-6079
IBM AIX 5.3, 6.1, 7.1, and 7.2 contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges. IBM APARs: IV88658, IV87981, IV88419, IV87640, IV88053.
Published 2017-02-15 · Modified
7.81 PoCEPSS 0.025
CVE-2016-3053
IBM AIX contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges.
Published 2017-02-01 · Modified
7.81 PoCEPSS 0.025
CVE-2007-3626
Unspecified vulnerability in the ADM daemon in Hitachi TPBroker before 20070706 allows remote attackers to cause a denial of service (daemon crash) via a certain request.
Published 2007-07-09 · Modified
7.8EPSS 0.019
CVE-2016-8972
IBM AIX 6.1, 7.1, and 7.2 could allow a local user to gain root privileges using a specially crafted command within the bellmail client. IBM APARs: IV91006, IV91007, IV91008, IV91010, IV91011.
Published 2017-02-15 · Modified
7.81 PoCEPSS 0.014
CVE-2010-0922
Unspecified vulnerability in secldapclntd in IBM AIX 5.3 with SP 5300-11-02 allows attackers to cause a denial of service (LDAP login failure) via unknown vectors. NOTE: some of these details are obtained from third party information. NOTE: there may be no attacker role, and the issue may be triggered entirely by an administrator's installation of an official service pack.
Published 2010-03-03 · Modified
7.8EPSS 0.013
CVE-2009-1954
Unspecified vulnerability in portmapper (aka portmap) in IBM AIX 5.3 allows attackers to cause a denial of service (daemon hang) via unknown vectors, related to libtli.
Published 2009-06-06 · Modified
7.8EPSS 0.013
CVE-2010-1124
bos.rte.libc 5.3.9.4 on IBM AIX 5.3 does not properly support reading a certain address field after a successful getaddrinfo function call, which allows context-dependent attackers to cause a denial of service (application crash) via unspecified vectors, as demonstrated by IBM DB2 crashes on "systems with databases cataloged with alternate servers using IP addresses."
Published 2010-03-26 · Modified
7.8EPSS 0.010
CVE-2022-35717
"IBM InfoSphere Information Server 11.7 could allow a locally authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-"Force ID: 231361.
Published 2022-11-03 · Modified
7.8EPSS 0.006
CVE-2016-9795
The casrvc program in CA Common Services, as used in CA Client Automation 12.8, 12.9, and 14.0; CA SystemEDGE 5.8.2 and 5.9; CA Systems Performance for Infrastructure Managers 12.8 and 12.9; CA Universal Job Management Agent 11.2; CA Virtual Assurance for Infrastructure Managers 12.8 and 12.9; CA Workload Automation AE 11, 11.3, 11.3.5, and 11.3.6 on AIX, HP-UX, Linux, and Solaris allows local users to modify arbitrary files and consequently gain root privileges via vectors related to insufficient validation.
Published 2017-01-27 · Modified
7.8EPSS 0.005
CVE-1999-0022
Local user gains root privileges via buffer overflow in rdist, via expstr() function.
Published 1999-09-29 · Modified
7.8EPSS 0.005
CVE-2016-5985
The IBM Tivoli Storage Manager (IBM Spectrum Protect) AIX client is vulnerable to a buffer overflow when Journal-Based Backup is enabled. A local attacker could overflow a buffer and execute arbitrary code on the system or cause a system crash.
Published 2017-02-01 · Modified
7.8EPSS 0.004
CVE-2017-1093
IBM AIX 6.1, 7.1, and 7.2 could allow a local user to exploit a vulnerability in the bellmail binary to gain root privileges.
Published 2017-02-02 · Modified
7.8EPSS 0.004
CVE-2017-1692
IBM AIX 5.3, 6.1, 7.1, and 7.2 contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges. IBM X-Force ID: 134067.
Published 2018-02-07 · Modified
7.8EPSS 0.004
CVE-2022-22454
IBM InfoSphere Information Server 11.7 could allow a locally authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.
Published 2022-05-10 · Modified
7.8EPSS 0.004
CVE-2024-47115
IBM AIX command execution
Published 2024-12-07 · Analyzed
7.8EPSS 0.002
CVE-2026-16875
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
7.8EPSS 0.002
CVE-2022-47990
IBM AIX denial of service
Published 2023-01-18 · Modified
7.8EPSS 0.002
CVE-2026-16997
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-20 · Analyzed
7.8EPSS 0.002
CVE-2026-17171
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-20 · Analyzed
7.8EPSS 0.002
← Prev6 / 25Next →