IBM Corporation

First CVE: Jan 18, 2012Active for: 15 years
6,951
CVEs Published
More CVEs Published than 98% of tracked CNAs
463.4
Avg CVEs / Year
More Avg CVEs / Year than 98% of tracked CNAs
6.1
Avg CVSS Score
Higher Avg CVSS Score than 12% of tracked CNAs
0.1%
In CISA KEV
Higher KEV Rate than 78% of tracked CNAs

Self-Reporting Analysis

Of all the CVEs published by IBM Corporation as a CNA, 98.4% affect products that IBM Corporation develops as a vendor.

98.4%
Self-reported: 6,838Third-party: 113

Of all the CVEs published that affect products developed by IBM Corporation, 82.2% are self-published by IBM Corporation as a CNA.

82.2%
17.8%
Self-published: 6,838Published by other CNAs: 1,476

Trends Over Time

The number and severity of CVEs published by IBM Corporation over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 18, 2012
14 years ago
Most Recent CVE
Jul 22, 2026
2 days ago

Top CVEs

All CVEs published by IBM Corporation as a CNA, regardless of affected vendor or product.

6,951 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary
Jan 2, 20169.899YESYES
IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserialization flaw. By sending a special
Feb 17, 20239.898YESYES
IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYST
Dec 18, 20199.898YESYES
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sendin
May 7, 20209.896YESYES
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary commands on the system. IBM X-Force ID: 180533.
May 7, 20209.191YESYES
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects from untr
May 17, 20199.887NOYES
IBM Informix Open Admin Tool 11.5, 11.7, and 12.1 could allow an unauthorized user to execute arbitrary code as system admin on Windows servers. IBM X-Force ID: 120390.
May 22, 20179.886NOYES
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to traverse directories on the system. An attacker could send a specially-crafted U
May 7, 20204.384YESNO
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 contains a default password for an IDRM administrative account. A remote attacker could exploit this vulnerabilit
May 7, 20209.883NOYES
IBM Operational Decision Manager 8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, 8.11.1 and 8.12.0.1 is susceptible to remote code execution attack via JNDI injection when passing an
Feb 2, 20249.880NOYES

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA6,951 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local943 (13.6%)
Network4,614 (66.4%)
Unknown1,287 (18.5%)
Physical41 (0.6%)
Adjacent Network66 (0.9%)
Attack Complexity
Low5,251 (75.5%)
High413 (5.9%)
Unknown1,287 (18.5%)
User Interaction
None4,072 (58.6%)
Unknown1,287 (18.5%)
Required1,592 (22.9%)
Privileges Required
Low3,007 (43.3%)
High336 (4.8%)
None2,321 (33.4%)
Unknown1,287 (18.5%)

Exploit Exposure

Signals from CVEs in this cna scope (6951 CVEs).

CISA KEV
7 CVEs
0.1% of CVEs· 78th percentile
Metasploit
29 CVEs
0.4% of CVEs· 82nd percentile
Nuclei
9 CVEs
0.1% of CVEs· 70th percentile
ExploitDB
71 CVEs
1.0% of CVEs· 82nd percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by IBM Corporation as a CNA.

Media Mentions

Media articles that mention a CVE ID published by IBM Corporation as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs