Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

IBM Corporation

First CVE: Mar 1, 1992Active for: 34 yearsTotal CVEs: 8,314
43.7
VTI Score
High

IBM Corporation maintains one of the broadest vulnerability footprints in the landscape, spanning enterprise operating systems, application servers, databases, and integration middleware that serve mission-critical infrastructure across financial, manufacturing, and logistics sectors. The vendor's disclosures encompass a very large and highly prominent product portfolio including AIX, WebSphere Application Server, DB2, Rational Quality Manager, and Sterling B2B Integrator, reflecting the scale and complexity of deeply embedded enterprise software stacks. The recurring weakness classes—cross-site scripting, input validation flaws, and sensitive information exposure—are characteristic of large, web-facing and data-intensive platforms where integration breadth and legacy compatibility constraints complicate defense-in-depth. Defenders should maintain systematic tracking of IBM's quarterly security updates and prioritize remediation of internet-reachable components such as application servers and integration gateways; current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
8,314
Total CVEs
More Total CVEs than 100% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
6.1
Avg CVSS Score
Higher Avg CVSS Score than 35% of tracked vendors
0.1%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by IBM Corporation over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 1, 1992
34 years ago
Most Recent CVE
Jul 17, 2026
7 days ago

Self-Reporting Analysis

Of all the CVEs published by IBM Corporation as a CNA, 98.4% affect products that IBM Corporation develops as a vendor.

98.4%
Self-reported: 6,838 (98.4%)
Third-party: 113 (1.6%)

Of all the CVEs published that affect products developed by IBM Corporation, 82.2% are self-published by IBM Corporation as a CNA.

82.2%
17.8%
Self-published: 6,838 (82.2%)
Other CNAs: 1,476 (17.8%)

Products(1,576 total)

Top CVEs

Signals from CVEs in this vendor scope (8314 CVEs).

8,314 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-5638CRITICAL
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attem
Mar 11, 20179.899YESYES
CVE-2015-7450CRITICAL
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary
Jan 2, 20169.899YESYES
CVE-2014-6271CRITICAL
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a cra
Sep 24, 20149.899YESYES
CVE-2022-47986CRITICAL
IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserialization flaw. By sending a special
Feb 17, 20239.898YESYES
CVE-2019-4716CRITICAL
IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYST
Dec 18, 20199.898YESYES
CVE-2014-7169CRITICAL
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to wri
Sep 25, 20149.898YESYES
CVE-2020-4427CRITICAL
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sendin
May 7, 20209.896YESYES
CVE-2015-0235HIGH
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code
Jan 28, 201510.092NOYES
CVE-2020-4428CRITICAL
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary commands on the system. IBM X-Force ID: 180533.
May 7, 20209.191YESYES
CVE-2010-0425HIGH
modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure
Mar 5, 201010.091NOYES
View all 8,314 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products8,314 CVEs
8%
58%
29%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local949 (11.4%)
Network4,606 (55.4%)
Unknown2,649 (31.9%)
Physical42 (0.5%)
Adjacent Network68 (0.8%)
Attack Complexity
Low5,245 (63.1%)
High420 (5.1%)
Unknown2,649 (31.9%)
User Interaction
None4,070 (49.0%)
Unknown2,649 (31.9%)
Required1,595 (19.2%)
Privileges Required
Low2,993 (36.0%)
High339 (4.1%)
None2,333 (28.1%)
Unknown2,649 (31.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (8314 CVEs).

CISA KEV
10 CVEs
0.1% of CVEs· 99th percentile
Metasploit
56 CVEs
0.7% of CVEs· 97th percentile
Nuclei
12 CVEs
0.1% of CVEs· 95th percentile
ExploitDB
265 CVEs
3.2% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by IBM Corporation.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by IBM Corporation — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For IBM Corporation's Products

View all 21 CNAs →

Top CWEs