ibm

4 records · 0 with a public proof-of-concept

Disclosed vulnerabilities where the NVD names ibm as an affected vendor, highest CVSS first.

  1. HIGH 8.2CVE-2026-10025

    IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulnerability resides in the parseXmlPayload() function within the event processing pipeline ( q1labs_core.jar ). Wh

    qradar security information and event manager

    AI risk analysis on Exploit-DB.ai →

  2. MEDIUM 5.3CVE-2026-12762

    IBM Cloud Pak For Business Automation 24.0.0, 24.0.1, 25.0.0, and 26.0.0 could allow a remote attacker to obtain sensitive information exposed in manifest files.

    business automation insights

    AI risk analysis on Exploit-DB.ai →

  3. MEDIUM 4.7CVE-2026-13477

    IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privileged user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input.

    qradar security information and event manager

    AI risk analysis on Exploit-DB.ai →

  4. LOW 3.8CVE-2026-12730

    IBM Business Automation Workflow containers and traditional 26.0.0, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 007, and 24.0.0 through 24.0.0 Interim Fix 009 IBM Business Automation Workflow fails to properly verify that the hostn

    business automation workflow

    AI risk analysis on Exploit-DB.ai →