VendorsIBMaixany version
Vulnerabilities

IBM AIX any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

620CVEs
CVE-2024-7577
IBM InfoSphere Information Server information disclosure
Published 2025-03-28 · Analyzed
7.5EPSS 0.003
CVE-2022-38391
IBM Spectrum Control information disclosure
Published 2022-12-20 · Modified
7.5EPSS 0.003
CVE-2025-33142
IBM WebSphere Application Server information disclosure
Published 2025-08-14 · Analyzed
7.5EPSS 0.003
CVE-2026-19448
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-20 · Analyzed
7.5EPSS 0.002
CVE-2024-38320
IBM Storage Protect for Virtual Environments: Data Protection for VMware information disclosure
Published 2025-01-27 · Analyzed
7.5EPSS 0.002
CVE-2026-16851
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
7.4EPSS 0.003
CVE-2025-36244
IBM AIX privilege escalation
Published 2025-09-16 · Analyzed
7.4EPSS 0.001
CVE-2026-10845
IBM WebSphere Application Server is affected by an authentication bypass vulnerability
Published 2026-06-22 · Analyzed
7.3EPSS 0.005
CVE-2026-13476
IBM Informix Wire Listener Vulnerable to Unauthenticated Remote Code Execution
Published 2026-08-12 · Analyzed
7.3EPSS 0.004
CVE-2016-5995
Untrusted search path vulnerability in IBM DB2 9.7 through FP11, 10.1 through FP5, 10.5 before FP8, and 11.1 GA on Linux, AIX, and HP-UX allows local users to gain privileges via a Trojan horse library that is accessed by a setuid or setgid program.
Published 2016-10-01 · Modified
7.3EPSS 0.004
CVE-2026-8835
IBM HTTP Server is affected by multiple vulnerabilities
Published 2026-05-26 · Analyzed
7.3EPSS 0.003
CVE-2025-62231
Xorg: xmayland: value overflow in xkbsetcompatmap()
Published 2025-10-30 · Analyzed
7.3EPSS 0.003
CVE-2025-62230
Xorg: xwayland: use-after-free in xkb client resource removal
Published 2025-10-30 · Analyzed
7.3EPSS 0.003
CVE-2026-16927
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-20 · Analyzed
7.3EPSS 0.001
CVE-1999-1121
The default configuration for UUCP in AIX before 3.2 allows local users to gain root privileges.
Published 2002-03-09 · Modified
7.2EPSS 0.009
CVE-1999-0033
Command execution in Sun systems via buffer overflow in the at program.
Published 2000-02-04 · Modified
7.2EPSS 0.006
CVE-2025-14915
IBM WebSphere Application Server Liberty is affected by a privilege escalation vulnerability
Published 2026-03-25 · Analyzed
7.2EPSS 0.006
CVE-2011-1222
Buffer overflow in the Journal Based Backup (JBB) feature in the backup-archive client in IBM Tivoli Storage Manager (TSM) before 5.4.3.4, 5.5.x before 5.5.3, 6.x before 6.1.4, and 6.2.x before 6.2.2 on Windows and AIX allows local users to gain privileges via unspecified vectors.
Published 2011-07-17 · Modified
7.2EPSS 0.004
CVE-2007-1086
Unspecified binaries in IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 allow local users to create or modify arbitrary files via unspecified environment variables related to "unsafe file access."
Published 2007-02-23 · Modified
7.2EPSS 0.004
CVE-2010-1347
Director Agent 6.1 before 6.1.2.3 in IBM Systems Director on AIX and Linux uses incorrect permissions for the (1) diruninstall and (2) opt/ibm/director/bin/wcitinst scripts, which allows local users to gain privileges by executing these scripts.
Published 2010-04-12 · Modified
7.2EPSS 0.004
CVE-1999-1552
dpsexec (DPS Server) when running under XDM in IBM AIX 3.2.5 and earlier does not properly check privileges, which allows local users to overwrite arbitrary files and gain privileges.
Published 2001-09-12 · Modified
7.2EPSS 0.003
CVE-2000-1222
AIX sysback before 4.2.1.13 uses a relative path to find and execute the hostname program, which allows local users to gain privileges by modifying the path to point to a malicious hostname program.
Published 2005-04-21 · Modified
7.2EPSS 0.003
CVE-2012-1796
Unspecified vulnerability in IBM Tivoli Monitoring Agent (ITMA), as used in IBM DB2 9.5 before FP9 on UNIX, allows local users to gain privileges via unknown vectors.
Published 2012-03-20 · Modified
7.2EPSS 0.003
CVE-2013-4002
XMLscanner.java in Apache Xerces2 Java Parser before 2.12.0, as used in the Java Runtime Environment (JRE) in IBM Java 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 as well as Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, Java SE Embedded 7u40 and earlier, and possibly other products allows remote attackers to cause a denial of service via vectors related to XML attribute names.
Published 2013-07-23 · Modified
7.1EPSS 0.247
CVE-2009-1522
The IBM Tivoli Storage Manager (TSM) client 5.5.0.0 through 5.5.1.17 on AIX and Windows, when SSL is used, allows remote attackers to conduct unspecified man-in-the-middle attacks and read arbitrary files via unknown vectors.
Published 2009-05-05 · Modified
7.1EPSS 0.021
CVE-2018-1845
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 150905.
Published 2019-06-17 · Modified
7.1EPSS 0.020
CVE-2020-4411
The Spectrum Scale 4.2.0.0 through 4.2.3.21 and 5.0.0.0 through 5.0.4.3 file system component is affected by a denial of service vulnerability in its kernel module that could allow an attacker to cause a denial of service condition on the affected system. To exploit this vulnerability, a local attacker could invoke a subset of ioctls on the Spectrum Scale device with non-valid arguments. This could allow the attacker to crash the kernel. IBM X-Force ID: 179986.
Published 2020-05-19 · Modified
7.1EPSS 0.003
CVE-2025-36258
IBM InfoSphere Information Server is vulnerable due to plaintext storage of a password
Published 2026-03-25 · Analyzed
7.1EPSS 0.002
CVE-2026-17007
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-20 · Analyzed
7.1EPSS 0.001
CVE-2026-16922
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-20 · Analyzed
7.0EPSS 0.001
CVE-2026-16838
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
7.0EPSS 0.001
CVE-2007-2191
Multiple cross-site scripting (XSS) vulnerabilities in freePBX 2.2.x allow remote attackers to inject arbitrary web script or HTML via the (1) From, (2) To, (3) Call-ID, (4) User-Agent, and unspecified other SIP protocol fields, which are stored in /var/log/asterisk/full and displayed by admin/modules/logfiles/asterisk-full-log.php.
Published 2007-04-24 · Modified
6.81 PoCEPSS 0.045
CVE-2010-2594
Multiple cross-site request forgery (CSRF) vulnerabilities in the web management interface in InterSect Alliance Snare Agent 3.2.3 and earlier on Solaris, Snare Agent 3.1.7 and earlier on Windows, Snare Agent 1.5.0 and earlier on Linux and AIX, Snare Agent 1.4 and earlier on IRIX, Snare Epilog 1.5.3 and earlier on Windows, and Snare Epilog 1.2 and earlier on UNIX allow remote attackers to hijack the authentication of administrators for requests that (1) change the password or (2) change the listening port.
Published 2010-07-01 · Modified
6.8EPSS 0.015
CVE-2022-42439
IBM App Connect Enterprise information disclosure
Published 2023-02-06 · Modified
6.8EPSS 0.007
CVE-2023-38729
IBM Db2 information disclosure
Published 2024-04-03 · Analyzed
6.8EPSS 0.006
CVE-2020-4230
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1 and 11.5 is vulnerable to an escalation of privilege when an authenticated local attacker with special permissions executes specially crafted Db2 commands. IBM X-Force ID: 175212.
Published 2020-02-19 · Modified
6.7EPSS 0.004
CVE-2021-20515
IBM Informix Dynamic Server 14.10 is vulnerable to a stack based buffer overflow, caused by improper bounds checking. A local privileged user could overflow a buffer and execute arbitrary code on the system or cause a denial of service condition. IBM X-Force ID: 198366.
Published 2021-04-30 · Modified
6.7EPSS 0.003
CVE-2023-35012
IBM Db2 code execution
Published 2023-07-17 · Modified
6.7EPSS 0.002
CVE-2026-16914
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
6.7EPSS 0.002
CVE-2026-16951
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-20 · Analyzed
6.7EPSS 0.002
← Prev8 / 16Next →