IBM Corporation maintains one of the broadest vulnerability footprints in the landscape, spanning enterprise operating systems, application servers, databases, and integration middleware that serve mission-critical infrastructure across financial, manufacturing, and logistics sectors. The vendor's disclosures encompass a very large and highly prominent product portfolio including AIX, WebSphere Application Server, DB2, Rational Quality Manager, and Sterling B2B Integrator, reflecting the scale and complexity of deeply embedded enterprise software stacks. The recurring weakness classes—cross-site scripting, input validation flaws, and sensitive information exposure—are characteristic of large, web-facing and data-intensive platforms where integration breadth and legacy compatibility constraints complicate defense-in-depth. Defenders should maintain systematic tracking of IBM's quarterly security updates and prioritize remediation of internet-reachable components such as application servers and integration gateways; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by IBM Corporation over time
Of all the CVEs published by IBM Corporation as a CNA, 98.4% affect products that IBM Corporation develops as a vendor.
Of all the CVEs published that affect products developed by IBM Corporation, 82.2% are self-published by IBM Corporation as a CNA.
Signals from CVEs in this vendor scope (8314 CVEs).
8,314 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-5638CRITICAL The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attem | Mar 11, 2017 | 9.8 | 99 | YES | YES |
CVE-2015-7450CRITICAL Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary | Jan 2, 2016 | 9.8 | 99 | YES | YES |
CVE-2014-6271CRITICAL GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a cra | Sep 24, 2014 | 9.8 | 99 | YES | YES |
CVE-2022-47986CRITICAL IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserialization flaw. By sending a special | Feb 17, 2023 | 9.8 | 98 | YES | YES |
CVE-2019-4716CRITICAL IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYST | Dec 18, 2019 | 9.8 | 98 | YES | YES |
CVE-2014-7169CRITICAL GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to wri | Sep 25, 2014 | 9.8 | 98 | YES | YES |
CVE-2020-4427CRITICAL IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sendin | May 7, 2020 | 9.8 | 96 | YES | YES |
CVE-2015-0235HIGH Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code | Jan 28, 2015 | 10.0 | 92 | NO | YES |
CVE-2020-4428CRITICAL IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary commands on the system. IBM X-Force ID: 180533. | May 7, 2020 | 9.1 | 91 | YES | YES |
CVE-2010-0425HIGH modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure | Mar 5, 2010 | 10.0 | 91 | NO | YES |
Signals from CVEs in this vendor scope (8314 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by IBM Corporation.
Media articles that mention a CVE ID that affects a product developed by IBM Corporation — matched by CVE ID, not by vendor name.