VendorsIBMaixany version
Vulnerabilities

IBM AIX any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

620CVEs
CVE-2010-1039
Format string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; IBM VIOS 2.1, 1.5, and earlier; NFS/ONCplus B.11.31_09 and earlier on HP HP-UX B.11.11, B.11.23, and B.11.31; and SGI IRIX 6.5 allows remote attackers to execute arbitrary code via an RPC request containing format string specifiers in an invalid directory name.
Published 2010-05-20 · Modified
10.01 PoCEPSS 0.202
CVE-2010-3187
Buffer overflow in ftpd in IBM AIX 5.3 and earlier allows remote attackers to execute arbitrary code via a long NLST command.
Published 2010-08-30 · Modified
10.02 PoCEPSS 0.200
CVE-2007-1916
Buffer overflow in the RFC_START_GUI function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended.
Published 2007-04-10 · Modified
10.0EPSS 0.067
CVE-2007-1917
Buffer overflow in the SYSTEM_CREATE_INSTANCE function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended.
Published 2007-04-10 · Modified
10.0EPSS 0.067
CVE-2010-4773
Unspecified vulnerability in Hitachi EUR Form Client before 05-10 -/D 2010.11.15 and 05-10-CA (* 2) 2010.11.15; Hitachi EUR Form Service before 05-10 -/D 2010.11.15; and uCosminexus EUR Form Service before 07-60 -/D 2010.11.15 on Windows, before 05-10 -/D 2010.11.15 and 07-50 -/D 2010.11.15 on Linux, and before 07-50 -/C 2010.11.15 on AIX; allows remote attackers to execute arbitrary code via unknown attack vectors.
Published 2011-03-23 · Modified
10.0EPSS 0.053
CVE-1999-1119
FTP installation script anon.ftp in AIX insecurely configures anonymous FTP, which allows remote attackers to execute arbitrary commands.
Published 2002-03-09 · Modified
10.0EPSS 0.042
CVE-2019-14678
SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multiple ways. Examples are Local File Reading, Out Of Band File Exfiltration, Server Side Request Forgery, and/or Potential Denial of Service attacks. This vulnerability also affects the XMLV2 LIBNAME engine when the AUTOMAP option is used.
Published 2019-11-14 · Modified
10.0EPSS 0.030
CVE-2007-3794
Buffer overflow in Hitachi Cosminexus V4 through V7, Processing Kit for XML before 20070511, Developer's Kit for Java before 20070312, and third-party products that use this software, allows attackers to have an unknown impact via certain GIF images, related to use of GIF image processing APIs by a Java application.
Published 2007-07-15 · Modified
10.0EPSS 0.022
CVE-2001-1061
Vulnerability in lsmcode in unknown versions of AIX, possibly related to a usage error.
Published 2002-02-02 · Modified
10.0EPSS 0.018
CVE-2002-1686
Buffer overflow in lscfg of unknown versions of AIX has unknown impact.
Published 2005-06-21 · Modified
10.0EPSS 0.014
CVE-2024-56346
IBM AIX command execution
Published 2025-03-18 · Analyzed
10.0EPSS 0.011
CVE-2026-15068
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
9.9EPSS 0.011
CVE-2026-16816
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
9.9EPSS 0.008
CVE-2026-18835
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-20 · Analyzed
9.9EPSS 0.008
CVE-2025-36038
IBM WebSphere Application Server code execution
Published 2025-06-25 · Analyzed
9.8EPSS 0.108
CVE-2018-20732
SAS Web Infrastructure Platform before 9.4M6 allows remote attackers to execute arbitrary code via a Java deserialization variant.
Published 2019-01-17 · Modified
9.8EPSS 0.040
CVE-2020-4693
IBM Spectrum Protect Operations Center 7.1.0.000 through 7.1.10 and 8.1.0.000 through 8.1.9 may allow an attacker to execute arbitrary code on the system, caused by improper validation of data prior to export. IBM X-Force ID: 186782.
Published 2020-09-02 · Modified
9.8EPSS 0.025
CVE-2023-23477
IBM WebSphere Application Server code execution
Published 2023-02-03 · Modified
9.8EPSS 0.019
CVE-2022-40752
IBM InfoSphere DataStage 11.7 is vulnerable to a command injection vulnerability due to improper neutralization of special elements. IBM X-Force ID:  236687.
Published 2022-11-16 · Modified
9.8EPSS 0.018
CVE-2022-22487
An IBM Spectrum Protect storage agent could allow a remote attacker to perform a brute force attack by allowing unlimited attempts to login to the storage agent without locking the administrative ID. A remote attacker could exploit this vulnerability using brute force techniques to gain unauthorized administrative access to both the IBM Spectrum Protect storage agent and the IBM Spectrum Protect Server 8.1.0.000 through 8.1.14 with which it communicates. IBM X-Force ID: 226326.
Published 2022-06-30 · Modified
9.8EPSS 0.015
CVE-2023-32336
IBM InfoSphere Information Server code execution
Published 2023-05-22 · Modified
9.8EPSS 0.014
CVE-2022-22425
"IBM InfoSphere Information Server 11.7 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 223598."
Published 2022-11-03 · Modified
9.8EPSS 0.012
CVE-2021-29798
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 203734.
Published 2021-10-06 · Modified
9.8EPSS 0.011
CVE-2022-22485
In some cases, an unsuccessful attempt to log into IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14.000 does not cause the administrator's invalid sign-on count to be incremented on the IBM Spectrum Protect Server. An attacker could exploit this vulnerability using brute force techniques to gain unauthorized administrative access to the IBM Spectrum Protect Server. IBM X-Force ID: 226325.
Published 2022-06-17 · Modified
9.8EPSS 0.011
CVE-2021-39085
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 215888.
Published 2022-08-16 · Modified
9.8EPSS 0.009
CVE-2026-17142
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-20 · Analyzed
9.8EPSS 0.009
CVE-2026-16882
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
9.8EPSS 0.009
CVE-2026-8855
IBM HTTP Server is affected by multiple vulnerabilities
Published 2026-05-26 · Analyzed
9.8EPSS 0.008
CVE-2026-16872
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
9.8EPSS 0.008
CVE-2026-16894
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
9.8EPSS 0.008
CVE-2026-16864
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
9.8EPSS 0.008
CVE-2026-16845
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
9.8EPSS 0.008
CVE-2026-17157
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-20 · Analyzed
9.8EPSS 0.008
CVE-2026-17152
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-20 · Analyzed
9.8EPSS 0.008
CVE-2026-17141
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-20 · Analyzed
9.8EPSS 0.008
CVE-2026-16862
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
9.8EPSS 0.008
CVE-2026-17040
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-20 · Analyzed
9.8EPSS 0.008
CVE-2026-17122
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-20 · Analyzed
9.8EPSS 0.008
CVE-2026-16913
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
9.8EPSS 0.008
CVE-2026-16885
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
9.8EPSS 0.008
1 / 16Next →