IBM Corporation
First CVE: Jan 18, 2012Active for: 15 years
6,951
CVEs Published
More CVEs Published than 98% of tracked CNAs
463.4
Avg CVEs / Year
More Avg CVEs / Year than 98% of tracked CNAs
6.1
Avg CVSS Score
Higher Avg CVSS Score than 12% of tracked CNAs
0.1%
In CISA KEV
Higher KEV Rate than 78% of tracked CNAs
Self-Reporting Analysis
Of all the CVEs published by IBM Corporation as a CNA, 98.4% affect products that IBM Corporation develops as a vendor.
98.4%
Self-reported: 6,838Third-party: 113
Of all the CVEs published that affect products developed by IBM Corporation, 82.2% are self-published by IBM Corporation as a CNA.
82.2%
17.8%
Self-published: 6,838Published by other CNAs: 1,476
Trends Over Time
The number and severity of CVEs published by IBM Corporation over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 18, 2012
14 years ago
Most Recent CVE
Jul 22, 2026
2 days ago
Top CVEs
All CVEs published by IBM Corporation as a CNA, regardless of affected vendor or product.
6,951 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-7450CRITICAL Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary | Jan 2, 2016 | 9.8 | 99 | YES | YES |
CVE-2022-47986CRITICAL IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserialization flaw. By sending a special | Feb 17, 2023 | 9.8 | 98 | YES | YES |
CVE-2019-4716CRITICAL IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYST | Dec 18, 2019 | 9.8 | 98 | YES | YES |
CVE-2020-4427CRITICAL IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sendin | May 7, 2020 | 9.8 | 96 | YES | YES |
CVE-2020-4428CRITICAL IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary commands on the system. IBM X-Force ID: 180533. | May 7, 2020 | 9.1 | 91 | YES | YES |
CVE-2019-4279CRITICAL IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects from untr | May 17, 2019 | 9.8 | 87 | NO | YES |
CVE-2017-1092CRITICAL IBM Informix Open Admin Tool 11.5, 11.7, and 12.1 could allow an unauthorized user to execute arbitrary code as system admin on Windows servers. IBM X-Force ID: 120390. | May 22, 2017 | 9.8 | 86 | NO | YES |
CVE-2020-4430MEDIUM IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to traverse directories on the system. An attacker could send a specially-crafted U | May 7, 2020 | 4.3 | 84 | YES | NO |
CVE-2020-4429CRITICAL IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 contains a default password for an IDRM administrative account. A remote attacker could exploit this vulnerabilit | May 7, 2020 | 9.8 | 83 | NO | YES |
CVE-2024-22319CRITICAL
IBM Operational Decision Manager 8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, 8.11.1 and 8.12.0.1 is susceptible to remote code execution attack via JNDI injection when passing an | Feb 2, 2024 | 9.8 | 80 | NO | YES |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA6,951 CVEs
8%
60%
26%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local943 (13.6%)
Network4,614 (66.4%)
Unknown1,287 (18.5%)
Physical41 (0.6%)
Adjacent Network66 (0.9%)
Attack Complexity
Low5,251 (75.5%)
High413 (5.9%)
Unknown1,287 (18.5%)
User Interaction
None4,072 (58.6%)
Unknown1,287 (18.5%)
Required1,592 (22.9%)
Privileges Required
Low3,007 (43.3%)
High336 (4.8%)
None2,321 (33.4%)
Unknown1,287 (18.5%)
Exploit Exposure
Signals from CVEs in this cna scope (6951 CVEs).
CISA KEV
7 CVEs
0.1% of CVEs· 78th percentile
Metasploit
29 CVEs
0.4% of CVEs· 82nd percentile
Nuclei
9 CVEs
0.1% of CVEs· 70th percentile
ExploitDB
71 CVEs
1.0% of CVEs· 82nd percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by IBM Corporation as a CNA.
Media Mentions
Media articles that mention a CVE ID published by IBM Corporation as a CNA — matched by CVE ID, not by organization name.