VendorsIBMaixall versions
Vulnerabilities

IBM AIX

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

992CVEs
CVE-2003-0119
The secldapclntd daemon in AIX 4.3, 5.1 and 5.2 uses an Internet socket when communicating with the loadmodule, which allows remote attackers to directly connect to the daemon and conduct unauthorized activities.
Published 2004-01-14 · Modified
7.5EPSS 0.021
CVE-2019-4193
IBM Jazz for Service Management 1.1.3 and 1.1.3.2 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-force ID: 159032.
Published 2019-07-11 · Modified
7.5EPSS 0.021
CVE-2007-0618
Unspecified vulnerability in (1) pop3d, (2) pop3ds, (3) imapd, and (4) imapds in IBM AIX 5.3.0 has unspecified impact and attack vectors, involving an "authentication vulnerability."
Published 2007-01-31 · Modified
7.5EPSS 0.021
CVE-2021-29688
IBM Security Identity Manager 7.0.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 200102.
Published 2021-05-20 · Modified
7.5EPSS 0.020
CVE-1999-0337
AIX batch queue (bsh) allows local and remote users to gain additional privileges when network printing is enabled.
Published 1999-09-29 · Modified
7.5EPSS 0.020
CVE-1999-0017
FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP client, aka FTP bounce.
Published 1999-09-29 · Modified
7.5EPSS 0.020
CVE-2021-29747
IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain highly sensitive information due to a vulnerability in the authentication mechanism. IBM X-Force ID: 201775.
Published 2021-05-17 · Modified
7.5EPSS 0.019
CVE-2021-29702
Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1.4 and 11.5.5 is vulnerable to a denial of service as the server terminates abnormally when executing a specially crafted SELECT statement. IBM X-Force ID: 200658.
Published 2021-06-16 · Modified
7.5EPSS 0.019
CVE-2020-4870
IBM MQ 9.2 CD and LTS are vulnerable to a denial of service attack caused by an error processing connecting applications. IBM X-Force ID: 190833.
Published 2020-12-21 · Modified
7.5EPSS 0.017
CVE-2021-29703
Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of service as the server terminates abnormally when executing a specially crafted SELECT statement. IBM X-Force ID: 200659.
Published 2021-06-24 · Modified
7.5EPSS 0.017
CVE-2021-38890
IBM Sterling Connect:Direct Web Services 1.0 and 6.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 209507.
Published 2021-11-23 · Modified
7.5EPSS 0.016
CVE-2020-4310
IBM MQ and MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 C are vulnerable to a denial of service attack due to an error within the Data Conversion logic. IBM X-Force ID: 177081.
Published 2020-06-16 · Modified
7.5EPSS 0.016
CVE-2021-38951
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume all available CPU resources. IBM X-Force ID: 211405.
Published 2021-12-09 · Modified
7.5EPSS 0.015
CVE-1999-0903
genfilt in the AIX Packet Filtering Module does not properly filter traffic to destination ports greater than 32767.
Published 2000-04-18 · Modified
7.5EPSS 0.015
CVE-2017-1541
A flaw in the AIX 5.3, 6.1, 7.1, and 7.2 JRE/SDK installp and updatep packages prevented the java.security, java.policy and javaws.policy files from being updated correctly. IBM X-Force ID: 130809.
Published 2017-10-03 · Modified
7.5EPSS 0.015
CVE-2021-29825
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could disclose sensitive information when using ADMIN_CMD with LOAD or BACKUP. IBM X-Force ID: 204470.
Published 2021-09-16 · Modified
7.5EPSS 0.015
CVE-2018-8049
The Stealth endpoint in Unisys Stealth SVG 2.8.x, 3.0.x before 3.0.1999, 3.1.x, 3.2.x before 3.2.030, and 3.3.x before 3.3.016, when running on Linux and AIX, allows remote attackers to cause a denial of service (crash) via crafted packets.
Published 2018-04-03 · Modified
7.5EPSS 0.015
CVE-2021-20373
IBM Db2 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an Information Disclosure when using the LOAD utility as under certain circumstances the LOAD utility does not enforce directory restrictions. IBM X-Force ID: 199521.
Published 2021-12-09 · Modified
7.5EPSS 0.015
CVE-2001-1529
Buffer overflow in rpc.yppasswdd (yppasswd server) in AIX allows attackers to gain unauthorized access via a long string. NOTE: due to lack of details in the vendor advisory, it is not clear if this is the same issue as CVE-2001-0779.
Published 2005-07-14 · Modified
7.5EPSS 0.014
CVE-2023-24960
IBM InfoSphere Information Server information disclosure
Published 2023-02-17 · Modified
7.5EPSS 0.014
CVE-2007-1945
Unspecified vulnerability in the Servlet Engine/Web Container in IBM WebSphere Application Server (WAS) before 6.1.0.7 has unknown impact and attack vectors.
Published 2007-04-11 · Modified
7.5EPSS 0.014
CVE-2023-30445
IBM Db2 denial of service
Published 2023-07-08 · Modified
7.5EPSS 0.014
CVE-2023-30449
IBM Db2 denial of service
Published 2023-07-08 · Modified
7.5EPSS 0.014
CVE-2023-30448
IBM Db2 denial of service
Published 2023-07-08 · Modified
7.5EPSS 0.014
CVE-2023-30446
IBM Db2 denial of service
Published 2023-07-08 · Modified
7.5EPSS 0.013
CVE-2023-30447
IBM Db2 denial of service
Published 2023-07-08 · Modified
7.5EPSS 0.013
CVE-2020-4559
IBM Spectrum Protect 7.1 and 8.1 could allow an attacker to cause a denial of service due ti improper validation of user-supplied input. IBM X-Force ID: 183613.
Published 2020-08-28 · Modified
7.5EPSS 0.013
CVE-2018-1751
IBM Security Key Lifecycle Manager 3.0 through 3.0.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 148512.
Published 2019-01-23 · Modified
7.5EPSS 0.013
CVE-2023-30442
IBM Db2 denial of service
Published 2023-07-10 · Modified
7.5EPSS 0.013
CVE-2001-1557
Buffer overflow in ftpd in IBM AIX 4.3 and 5.1 allows attackers to gain privileges.
Published 2005-07-14 · Modified
7.5EPSS 0.012
CVE-2023-33850
IBM GSKit-Crypto information disclosure
Published 2023-08-22 · Modified
7.5EPSS 0.012
CVE-2018-20733
BI Web Services in SAS Web Infrastructure Platform before 9.4M6 allows XXE.
Published 2019-01-17 · Modified
7.5EPSS 0.011
CVE-2023-26281
IBM HTTP Server denial of service
Published 2023-02-28 · Modified
7.5EPSS 0.011
CVE-2006-7034
SQL injection vulnerability in directory.php in Super Link Exchange Script 1.0 might allow remote attackers to execute arbitrary SQL queries via the cat parameter.
Published 2007-02-23 · Modified
7.5EPSS 0.011
CVE-2023-40699
IBM InfoSphere Information Server denial of service
Published 2023-12-01 · Modified
7.5EPSS 0.011
CVE-2026-19446
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-20 · Analyzed
7.5EPSS 0.010
CVE-2023-38741
IBM TXSeries for Multiplatforms denial of service
Published 2023-08-14 · Modified
7.5EPSS 0.010
CVE-2022-35715
IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in a stack trace. This information could be used in further attacks against the system. IBM X-Force ID: 231202.
Published 2022-08-10 · Modified
7.5EPSS 0.010
CVE-2023-28513
IBM MQ denial of service
Published 2023-07-19 · Modified
7.5EPSS 0.010
CVE-2026-6732
Libxml2: libxml2: denial of service via crafted xsd-validated document
Published 2026-04-23 · Analyzed
7.5EPSS 0.009
← Prev8 / 25Next →