IBM IBM

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any IBM product.

RSS Feeds for IBM security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in IBM products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by IBM Sorted by Most Security Vulnerabilities since 2018

IBM I436 vulnerabilities

IBM Aix269 vulnerabilities

IBM Db2155 vulnerabilities

IBM Powervm Vios144 vulnerabilities

IBM Sterling B2b Integrator144 vulnerabilities

IBM Rational Quality Manager132 vulnerabilities

IBM Langflow Oss117 vulnerabilities

IBM Security Verify Access107 vulnerabilities

IBM Cognos Analytics102 vulnerabilities

IBM Mq89 vulnerabilities

IBM Security Guardium84 vulnerabilities

IBM Maximo Asset Management78 vulnerabilities

IBM Api Connect77 vulnerabilities

IBM Vios74 vulnerabilities

IBM Concert71 vulnerabilities

IBM Rational Team Concert65 vulnerabilities

IBM Sterling File Gateway65 vulnerabilities

IBM Guardium Data Protection57 vulnerabilities

IBM Security Access Manager49 vulnerabilities

IBM Cloud Pak For Security48 vulnerabilities

IBM Cognos Controller48 vulnerabilities

IBM Aspera Faspex44 vulnerabilities

IBM Mq Appliance42 vulnerabilities

IBM Planning Analytics42 vulnerabilities

IBM Spectrum Scale42 vulnerabilities

IBM Urbancode Deploy42 vulnerabilities

IBM Verify Identity Access40 vulnerabilities

IBM Robotic Process Automation40 vulnerabilities

IBM App Connect Enterprise36 vulnerabilities

IBM Maximo Application Suite34 vulnerabilities

IBM Business Process Manager33 vulnerabilities

IBM Planning Analytics Local32 vulnerabilities

IBM Cics Tx31 vulnerabilities

IBM Jazz Reporting Service29 vulnerabilities

IBM Qradar Siem29 vulnerabilities

IBM Db2 Mirror For I28 vulnerabilities

IBM Power Systems Firmware28 vulnerabilities

IBM Cloud Pak System28 vulnerabilities

IBM Spectrum Protect Plus27 vulnerabilities

IBM Content Navigator27 vulnerabilities

IBM Powervm Hypervisor25 vulnerabilities

IBM Controller24 vulnerabilities

IBM Qradar Suite23 vulnerabilities

IBM Concert Software23 vulnerabilities

IBM Openpages With Watson22 vulnerabilities

IBM Security Identity Manager22 vulnerabilities

IBM Sterling Secure Proxy21 vulnerabilities

IBM Informix Dynamic Server21 vulnerabilities

IBM Spectrum Protect21 vulnerabilities

IBM Bigfix Platform20 vulnerabilities

IBM Websphere Mq19 vulnerabilities

IBM Datacap19 vulnerabilities

IBM Security Secret Server18 vulnerabilities

IBM Aspera Console18 vulnerabilities

IBM Websphere Portal18 vulnerabilities

IBM Security Verify Governance18 vulnerabilities

IBM Datacap Navigator18 vulnerabilities

IBM Security Qradar Edr17 vulnerabilities

IBM Security Directory Server16 vulnerabilities

IBM Aspera Shares16 vulnerabilities

Known Exploited IBM Vulnerabilities

The following IBM vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.

Title Description Added
IBM Langflow Code Injection Vulnerability Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.
CVE-2026-9198
August 4, 2026
IBM Aspera Faspex Code Execution Vulnerability IBM Aspera Faspex could allow a remote attacker to execute code on the system, caused by a YAML deserialization flaw.
CVE-2022-47986 Exploit Probability: 100.0%
February 21, 2023
IBM InfoSphere BigInsights Invalid Input Vulnerability Certain APIs within BigInsights can take invalid input that might allow attackers unauthorized access to read, write, modify, or delete data.
CVE-2013-3993 Exploit Probability: 4.8%
May 25, 2022
IBM WebSphere Application Server and Server Hypervisor Edition Code Injection. Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands
CVE-2015-7450 Exploit Probability: 97.8%
January 10, 2022
IBM Data Risk Manager Arbritary File Download IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to traverse directories on the system. An attacker could send a specially-crafted URL request to download arbitrary files from the system. IBM X-Force ID: 180535.
CVE-2020-4430 Exploit Probability: 68.5%
November 3, 2021
IBM Data Risk Manager Authentication Bypass IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to bypass the authentication process and gain full administrative access to the system. IBM X-Force ID: 180532.
CVE-2020-4427 Exploit Probability: 70.0%
November 3, 2021
IBM Data Risk Manager Command Injection IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary commands on the system. IBM X-Force ID: 180533.
CVE-2020-4428 Exploit Probability: 61.7%
November 3, 2021
IBM Planning Analytics configuration overwrite vulnerability IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting. IBM X-Force ID: 172094.
CVE-2019-4716 Exploit Probability: 86.4%
November 3, 2021

Of the known exploited vulnerabilities above, 6 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings.

By the Year

In 2026 there have been 1232 vulnerabilities in IBM with an average score of 7.0 out of ten. Last year, in 2025 IBM had 563 security vulnerabilities published. That is, 669 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.77.




Year Vulnerabilities Average Score
2026 1232 7.03
2025 563 6.26
2024 503 6.44
2023 357 6.80
2022 327 6.36
2021 443 6.10
2020 353 6.19
2019 454 6.14
2018 451 6.24

It may take a day or so for new IBM vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent IBM Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-93030 Sep 25, 2026
XEE in FTM 4.x Allows Remote Authenticated Sensitive Data Exfiltration FTM 4.x ALL could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity injection flaw.
I
CVE-2026-93306 Sep 25, 2026
IBM ASMI Web Crash via Malformed HTTPS (FW1120.00-1120.01, FW1110.00-1110.31) IBM Server Firmware FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the ASMI web interface. An unauthenticated attacker on the management network can send a malformed HTTPS request to ASMI, causing the web server to crash with possible memory corruption and generate an error log. The ASMI web interface will restart automatically; however, repeated exploitation could result in a sustained loss of access to the ASMI management interface, resulting in an integrity and availability impact.
Server Firmware
CVE-2026-84862 Sep 25, 2026
IBM Guardium 12.2 insecure deserialization in Quartz JDBC job store IBM Guardium Data Protection 12.2 is vulnerable to insecure deserialization in the Quartz JDBC job store. An authenticated attacker could exploit this vulnerability to execute arbitrary code on the affected system.
Guardium Data Protection
CVE-2026-84882 Sep 25, 2026
IBM Guardium 12.2 UC Oracle Wallet Path Traversal Write Arbitrary Files IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the Universal Connector Oracle Wallet upload component. An authenticated remote attacker could exploit this vulnerability to write arbitrary files to the system.
Guardium Data Protection
CVE-2026-84884 Sep 25, 2026
IBM Guardium 12.2 REST Service-Account Password Stored in Reversible Plaintext IBM Guardium Data Protection 12.2 stores internal REST service-account passwords in a reversible plaintext-equivalent format. An authenticated attacker who gains access to the stored credential could recover the password and obtain an administrative REST access token.
Guardium Data Protection
CVE-2026-84893 Sep 25, 2026
IBM Guardium Data Protection 12.2 SQL Injection in PESI Service IBM Guardium Data Protection 12.2 is vulnerable to SQL injection in the PESI service. An authenticated attacker could exploit this vulnerability to access sensitive information in the internal database.
Guardium Data Protection
CVE-2026-85029 Sep 25, 2026
IBM Guardium 12.2 Pathname Traversal Enables Arbitrary File Delete/Exec IBM Guardium Data Protection 12.2 could allow a remote attacker to obtain sensitive information, delete arbitrary files, or execute arbitrary code due to improper limitation of a pathname to a restricted directory.
Guardium Data Protection
CVE-2026-85542 Sep 25, 2026
IBM Guardium Data Protection 12.2 GIM Bundle Import Command Injection IBM Guardium Data Protection 12.2 is affected by a command injection vulnerability in the GIM bundle import functionality. An authenticated attacker can provide a crafted GIM bundle that causes attacker-controlled arguments to be passed to the tar command, resulting in arbitrary command execution with elevated privileges on the Central Manager.
Guardium Data Protection
CVE-2026-82094 Sep 24, 2026
IBM DataStage on Cloud Pak 5.4.0.0 Directory Traversal via Pathname IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to traverse directories on the system due to improper limitation of a pathname to a restricted directory.
Datastage On Cloud Pak Data
CVE-2026-82093 Sep 24, 2026
IBM DataStage 5.4.0.0 - Unsafe Deserialization Enables Remote Code Execution IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to unsafe deserialization of untrusted data.
Datastage On Cloud Pak Data
CVE-2026-81552 Sep 24, 2026
IBM DataStage Cloud Pak 5.4.0.0 Remote Auth Cmd Exec via Env Vars IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of environment variables.
Datastage On Cloud Pak Data
CVE-2026-81549 Sep 24, 2026
IBM DataStage 5.4.0.0 Remote Authenticated ID via X-Forwarded-Proto IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of the X-Forwarded-Proto header.
Datastage On Cloud Pak Data
CVE-2026-81548 Sep 24, 2026
IBM DataStage 5.4.0.0 Remote Auth Cmd Exec via OS Cmd Injection IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
Datastage On Cloud Pak Data
CVE-2026-81547 Sep 24, 2026
IBM DataStage 5.4.0.0 Remote Authenticated Cmd Exec via Path Traversal IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to path traversal.
Datastage On Cloud Pak Data
CVE-2026-81545 Sep 24, 2026
IBM DataStage CPK 5.4.0.0 OS Command Exec via Improper Sanit IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
Datastage On Cloud Pak Data
CVE-2026-81539 Sep 24, 2026
IBM DataStage CSP 5.4 RCE via OS command injection IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
Datastage On Cloud Pak Data
CVE-2026-77874 Sep 24, 2026
IBM Quarkus 3.27.1-3.27.5.SP1 SQL Injection Vulnerability IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL injection. A remote unauthenticated attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
Enterprise Build Of Quarkus
CVE-2026-77825 Sep 24, 2026
IBM ContextForge MCP Gateway 1.0.0-1.0.8 Path Traversal in Admin API log-download IBM ContextForge MCP Gateway 1.0.0 through 1.0.8 was vulnerable to path traversal in its Admin API log-download endpoint (`GET /v1/admin/logs/file`). The path confinement check uses `str.startswith()` rather than proper boundary validation, allowing an authenticated admin to read `.log`, `.jsonl`, and `.json` files outside the configured `LOG_FOLDER` by supplying a filename that resolves into a sibling directory whose absolute path shares the log directory's string prefix.
Contextforge Mcp Gateway
CVE-2026-6544 Sep 24, 2026
IBM Concert <3.0.0: Recursive Dir Copy Leak Vulnerability IBM Concert 1.0.0 through 3.0.0 allows recursive copying of directories without proper controls which can lead to unintentional inclusion of sensitive or unnecessary files and increased attack surface.
Concert
CVE-2026-19492 Sep 24, 2026
IBM PowerVM 1120/1110/1060 FW Mem Leak via Hypervisor Call CVE-2026-19492 IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, and FW1060.00 through FW1060.81 is affected by a vulnerability in a hypervisor call interface. An attacker with root access to a guest partition can read a limited amount of hypervisor memory, potentially exposing sensitive data belonging to the hypervisor or other guest partitions hosted on the same system, resulting in a confidentiality impact. The attacker has no control over which memory contents are returned. This vulnerability is of particular concern in multi-tenant environments where guests may run arbitrary OS images.
Powervm Hypervisor
CVE-2026-18870 Sep 24, 2026
IBM PowerVM Hypervisor OOB Read CVE-2026-18870 (FW950.00FW1120.01) IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read.
Powervm Hypervisor
CVE-2026-18857 Sep 24, 2026
IBM OpenBMC BMC Fw mgmt Crash/Leak (FW1060-1120) IBM OPENBMC FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, and FW1060.00 through FW1060.81 is affected by a vulnerability in the BMC firmware management interface. The host system can cause the BMC firmware management service to crash or allow a limited amount of BMC internal memory to be read, resulting in a confidentiality and availability impact to the managed system.
Openbmc
CVE-2026-18104 Sep 24, 2026
IBM Db2 Mirror for i 7.6/7.5/7.4 AES-ECB Local Info Disclosure IBM Db2 Mirror for i 7.6, 7.5, and 7.4 could allow a local attacker to obtain sensitive information due to the use of the AES Electronic Codebook (ECB) mode for encryption.
Db2 Mirror For I
CVE-2026-17511 Sep 24, 2026
CVE-2026-17511 IBM PowerVM Hypervisor 1120/1110/1060/950 Dump Leak IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the partition resource dump interface. An attacker with authenticated administrator-level access to the HMC or service processor can obtain a limited snapshot of partition processor state. Successful exploitation results in a confidentiality impact to the managed system.
Powervm Hypervisor
CVE-2026-17504 Sep 24, 2026
IBM PowerVM Hypervisor FW1120.00FW1120.01 Runtime Crash & Mem Corruption IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the partition firmware runtime. An attacker with root access to a partition can send a specially crafted request to the partition firmware runtime, causing it to crash with possible memory corruption.
Powervm Hypervisor
CVE-2026-17503 Sep 24, 2026
IBM PowerVM Hypervisor FW1120.00-FW950.H3 Boot Config Integrity Flaw IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the partition firmware runtime boot configuration. An attacker with root access to a partition can maliciously alter partition nvram, causing the partition to fail to boot. This condition persists until operator intervention deleting and recreating the partition configuration to restore normal operation. Successful exploitation results in an integrity and availability impact.
Powervm Hypervisor
CVE-2026-17413 Sep 24, 2026
IBM PowerVM Hypervisor RTAS Firmware Crash (FW1120.00-1120.01) IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the RTAS firmware-to-OS interface. An attacker with administrator-level (root) access to a logical partition can send a specially crafted request to partition firmware, causing the partition to crash and become unavailable. Other partitions on the same managed system are not affected.
Powervm Hypervisor
CVE-2026-81537 Sep 23, 2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 OS CI RCE IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to OS command injection.
Datastage On Cloud Pak Data
CVE-2026-81536 Sep 23, 2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 XXE Remote Att Info Disclosure IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection.
Datastage On Cloud Pak Data
CVE-2026-81208 Sep 23, 2026
IBM DataStage Cloud Pak 5.4.0.0 Improper Credential Handling (CVE-2026-81208) IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow an authenticated user to access sensitive information due to improper handling of encrypted credentials. An attacker could exploit this vulnerability to obtain credentials intended for other users or environments.
Datastage On Cloud Pak Data
CVE-2026-80423 Sep 23, 2026
Remote Auth Secret Leak via File Mounts in IBM DataStage 5.4.0 IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to the exposure of namespace-wide secrets via accessible file mounts.
Datastage On Cloud Pak Data
CVE-2026-80425 Sep 23, 2026
IBM DataStage 5.4.0.0 Remote Auth Cmd Exec via OS Cmd Injection IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
Datastage On Cloud Pak Data
CVE-2026-80412 Sep 23, 2026
IBM DataStage Cloud Pak for Data 5.4.0.0 RCE via Connector Prop Escaping IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper escaping of connector property values during OSH script generation.
Datastage On Cloud Pak Data
CVE-2026-80379 Sep 23, 2026
IBM DataStage on Cloud Pak 5.4.0.0 Remote Auth Cmd Exec via OS Injection IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
Datastage On Cloud Pak Data
CVE-2026-6935 Sep 23, 2026
IBM Concert 1.0.0-3.0.0 Local Command Execution via Unqualified Paths IBM Concert 1.0.0 through 3.0.0 invokes operating system commands without fully qualifying executable paths or adequately restricting search path resolution. As a result, an attacker with local system access can manipulate the search path environment to execute untrusted or malicious code.
Concert
CVE-2026-6928 Sep 23, 2026
IBM Concert 1.x-3.x Memory Corruption via Use-After-Free (CVE-2026-6928) IBM Concert 1.0.0 through 3.0.0 references or accesses memory after it has been freed. This allows an attacker who can influence program execution or input may exploit this condition to corrupt memory, cause application crashes, or execute arbitrary code.
Concert
CVE-2026-6925 Sep 23, 2026
IBM Concert 1.0.0-3.0.0 Directory Traversal via URL /.. IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot " sequences ( /.. /) to view arbitrary files on the system.
Concert
CVE-2026-6794 Sep 23, 2026
IBM Concert 1.0.03.0.0 Double Free Heap Corruption IBM Concert 1.0.0 through 3.0.0 has a double free vulnerability that exists due to incorrect memory management. A local attacker can exploit this flaw to corrupt heap memory and execute arbitrary code in the context of the affected process.
Concert
CVE-2026-6730 Sep 23, 2026
IBM Concert 1.0.0-3.0.0 Buffer Overflow (CVE-2026-6730) IBM Concert 1.0.0 through 3.0.0 is vulnerable to a buffer overflow, caused by improper bounds checking. A local user could overflow the buffer and execute arbitrary code on the system.
Concert
CVE-2026-6721 Sep 23, 2026
IBM Concert <=3.0.0 Command Injection RCE IBM Concert 1.0.0 through 3.0.0 allows an unauthenticated remote attacker can supply specially crafted input that is incorporated into OS commands, resulting in arbitrary command execution on the underlying system. Successful exploitation allows remote code execution with the privileges of the affected application.
Concert
CVE-2026-6718 Sep 23, 2026
Improper Access Control in IBM Concert 1.0.0-3.0.0 Enables Unauthorized File Mod IBM Concert 1.0.0 through 3.0.0 is vulnerable to improper access control which allows unauthorized modification of application files.
Concert
CVE-2026-6327 Sep 23, 2026
IBM Concert 1.0.0-3.0.0 Log Injection via Improper Log Neutralization IBM Concert 1.0.0 through 3.0.0 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.
Concert
CVE-2026-4921 Sep 23, 2026
IBM Guardium Data Protection 12.2 could IBM Guardium Data Protection 12.2 could allow an administrative user to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
Guardium Data Protection
CVE-2026-3626 Sep 23, 2026
IBM Concert 1.0.0 through 3.0.0 could IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
Concert
CVE-2026-19267 Sep 23, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to missing authentication on the Business Rules Manager commands REST endpoint (`CommandsResource.java:31`) IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to missing authentication on the Business Rules Manager commands REST endpoint (`CommandsResource.java:31`). A local actor can invoke unauthenticated commands to cause resource exhaustionand halt business-rule management functions.
Financial Transaction Manager Ftmfor Redhat Openshift
CVE-2026-19179 Sep 23, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to manipulate database queries due to improper neutralization of special elements in a boolean expression.
Financial Transaction Manager Ftmfor Redhat Openshift
CVE-2026-19087 Sep 23, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to achieve privilege escalation within the container due to improper privilege management.
Financial Transaction Manager Ftmfor Redhat Openshift
CVE-2026-18875 Sep 23, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to RAG poisoning IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to RAG poisoning via unauthenticated runbook upsert (CWE-74) in the FTM AI agent server (api.vectordb.runbooks.js:51). An unauthenticated attacker can insert malicious runbook content into the agent's vector database to steer AI-driven MCP tool calls, potentially triggering unauthorized payment actions or exfiltrating payment data.
Financial Transaction Manager Ftmfor Redhat Openshift
CVE-2026-18872 Sep 23, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to stored cross-site scripting (CWE-79) in the FTM UI NetworkAcknowledgement React component (NetworkAcknowledgement.jsx:42) IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to stored cross-site scripting (CWE-79) in the FTM UI NetworkAcknowledgement React component (NetworkAcknowledgement.jsx:42). A malicious actor can inject script into stored network acknowledgement data that executes in authenticated operator browsers, enabling session hijacking and unauthorized operator-level payment actions.
Financial Transaction Manager Ftmfor Redhat Openshift
CVE-2026-18505 Sep 23, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to open redirect in the PMP `HostHeaderFilter` (`HostHeaderFilter.java:151`) IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to open redirect in the PMP `HostHeaderFilter` (`HostHeaderFilter.java:151`). An unauthenticated attacker can craft a request with a manipulated `Host` header to redirect authenticated operators to attacker-controlled sites, enabling credential phishing.
Financial Transaction Manager Ftmfor Redhat Openshift
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.