Vulnerabilities
Vulnerable Software
Ibm:  Security Vulnerabilities
IBM Concert Software 1.0.0 through 1.1.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
CVSS Score
6.2
EPSS Score
0.0
Published
2025-08-18
IBM Storage Virtualize 8.4, 8.5, 8.6, and 8.7 could allow an authenticated user to escalate their privileges in an SSH session due to incorrect authorization checks to access resources.
CVSS Score
8.8
EPSS Score
0.0
Published
2025-08-18
IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to excessive data exposure, allowing attackers to access sensitive information without proper filtering.
CVSS Score
3.7
EPSS Score
0.0
Published
2025-08-18
IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.
CVSS Score
5.9
EPSS Score
0.0
Published
2025-08-18
IBM Concert Software 1.0.0 through 1.1.0 uses cross-origin resource sharing (CORS) which could allow an attacker to carry out privileged actions as the domain name is not being limited to only trusted domains.
CVSS Score
5.4
EPSS Score
0.0
Published
2025-08-18
IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to cause a denial of service using a specially crafted regular expression that would cause excessive resource consumption.
CVSS Score
7.5
EPSS Score
0.001
Published
2025-08-18
IBM WebSphere Application Server Liberty 18.0.0.2 through 25.0.0.8 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.
CVSS Score
5.3
EPSS Score
0.001
Published
2025-08-14
IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security for TLS connections.
CVSS Score
5.3
EPSS Score
0.0
Published
2025-08-14
IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.8 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS Score
4.4
EPSS Score
0.0
Published
2025-08-12
IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.8 could allow a remote attacker to bypass security restrictions caused by a failure to honor JMS messaging configuration
CVSS Score
5.9
EPSS Score
0.001
Published
2025-08-12


Contact Us

Shodan ® - All rights reserved