VendorsIBMcloud_pak_for_dataall versions
Vulnerabilities

IBM Cloud Pak

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

17CVEs
CVE-2025-14754
IBM Cloud Pak for Data is vulnerable to OS command injection
Published 2026-09-18 · Analyzed
8.8EPSS 0.004
CVE-2023-42005
IBM Db2 on Cloud Pak for Data privilege escalation
Published 2024-05-29 · Analyzed
8.8EPSS 0.003
CVE-2023-27540
IBM Watson CP4D Data Stores denial of service
Published 2023-07-10 · Modified
7.5EPSS 0.013
CVE-2023-26023
IBM Planning Analytics Cartridge for Cloud Pak for Data information disclosure
Published 2023-07-19 · Modified
7.5EPSS 0.007
CVE-2023-26026
IBM Planning Analytics Cartridge for Cloud Pak for Data information disclosure
Published 2023-07-19 · Modified
7.5EPSS 0.006
CVE-2023-27877
IBM Planning Analytics Cartridge for Cloud Pak for Data information disclosure
Published 2023-07-19 · Modified
7.5EPSS 0.005
CVE-2025-14753
IBM Cloud Pak for Data is vulnerable to path traversal
Published 2026-09-18 · Analyzed
7.5EPSS 0.005
CVE-2022-36769
IBM Cloud Pak for Data file upload
Published 2023-04-26 · Modified
7.2EPSS 0.009
CVE-2022-22353
IBM Big SQL on IBM Cloud Pak for Data 7.1.0, 7.1.1, 7.2.0, and 7.2.3 could allow an authenticated user with appropriate permissions to obtain sensitive information by bypassing data masking rules using a CREATE TABLE SELECT statement. IBM X-Force ID: 220480.
Published 2022-03-14 · Modified
6.5EPSS 0.009
CVE-2021-20486
IBM Cloud Pak for Data 3.0 could allow an authenticated user to obtain sensitive information when installed with additional plugins. IBM X-Force ID: 197668.
Published 2021-05-26 · Modified
6.5EPSS 0.009
CVE-2024-54178
Multiple vulnerabilities affect IBM Db2® on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data.
Published 2026-06-22 · Analyzed
6.5EPSS 0.004
CVE-2025-2669
Multiple vulnerabilities affect IBM Db2® on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data.
Published 2026-06-22 · Analyzed
6.5EPSS 0.003
CVE-2025-0719
IBM Cloud Pak for Data cross-site scripting
Published 2025-02-26 · Analyzed
6.1EPSS 0.003
CVE-2023-27545
IBM Watson CloudPak for Data Data Stores information disclosure
Published 2024-02-29 · Analyzed
5.5EPSS 0.002
CVE-2023-33854
Multiple vulnerabilities affect IBM Db2® on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data.
Published 2026-06-22 · Analyzed
5.3EPSS 0.003
CVE-2022-38714
IBM DataStage on Cloud Pak for Data information disclosure
Published 2024-02-12 · Modified
4.9EPSS 0.006
CVE-2021-38899
IBM Cloud Pak for Data 2.5 could allow a local user with special privileges to obtain highly sensitive information. IBM X-Force ID: 209575.
Published 2021-09-20 · Modified
4.4EPSS 0.003