Skip to content
COOEY

FAIL › dossier

IBM

COMPANY FEDRAMP MARKET

FedRAMP provider · · dossier confidence 20%

IBM is a major public technology vendor with a significant security footprint in enterprise software. Recent 2026 data reveals a pattern of critical RCE and XXE vulnerabilities across WebSphere, API Connect, and IBM i, indicating a need for rigorous patch management.

PROFILE
CategoryTechnology VendorWhat they doIBM is a multinational technology corporation that develops, manufactures, and supports hardware, software, and related services. Websitehttps://www.ibm.com ↗
SECURITY POSTURE

IBM demonstrates a high volume of critical and high-severity vulnerabilities across its enterprise software portfolio (WebSphere, API Connect, IBM i) in 2026, with multiple RCE and XXE flaws affecting widely deployed components.

Notable failures
  • CVE-2026-9074: Unauthenticated SQL injection in API Connect password reset
  • CVE-2026-13772: RCE in WebSphere Extreme Scale via Class.forName()
  • CVE-2026-13449: XXE in Business Automation Manager Open Editions
  • CVE-2026-11541: HTTP request smuggling in WebSphere Application Server
  • CVE-2026-11714: SSRF in WebSphere Liberty apiDiscovery-1.0
  • CVE-2026-11546: SSRF in WebSphere Liberty adminCenter-1.0
Patterns: Repeated unpatched edge-device RCEs; Default credentials in API Connect; XXE in XML processing components; SSRF in Liberty features
FAILURE HISTORY · 32
DATEEVENTSEVSUMMARY
2023-02-21 CVE-2022-47986 critical A YAML deserialization flaw in IBM Aspera Faspex allowed remote attackers to execute code, leading to ransomware-linked incidents.
2022-05-25 CVE-2013-3993 critical IBM InfoSphere BigInsights APIs accepted invalid input allowing attackers to read, write, modify, or delete data.
2026-08-04 CVE-2026-9198 high IBM Langflow Code Injection Vulnerability allows RCE.
2022-01-10 CVE-2015-7450 high Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands
2021-11-03 CVE-2019-4716 high IBM Planning Analytics is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting.
2021-11-03 CVE-2020-4428 high IBM Data Risk Manager contains an unspecified vulnerability which could allow a remote, authenticated attacker to execute commands on the system.�
2021-11-03 CVE-2020-4427 high IBM Data Risk Manager contains a security bypass vulnerability that could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to bypass the auth
2021-11-03 CVE-2020-4430 high IBM Data Risk Manager contains a directory traversal vulnerability that could allow a remote authenticated attacker to traverse directories and send a specially crafted URL request to download arbitrary files from the system.
2026-07-08 CVE-2026-9074 critical IBM API Connect versions 10.0.8.0–10.0.8.9 and 12.1.0.0–12.1.0.3 contain an unauthenticated SQL injection vulnerability in the password reset functionality.
2026-06-30 CVE-2026-13772 high IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 's Object Query Language engine resolves attacker-supplied class names via Class.forName() and invokes their constructors with no allow-list at three distinct sinks (SELECT NEW, enum literals, and reflection-based comparators);
2026-06-22 CVE-2026-9072 high IBM WebSphere Application Server and IBM WebSphere Application Server Liberty - when using Intelligent Management with the WebSphere WebServer Plug-in component - are vulnerable to remote code execution and denial of service. This vulnerability can be exploited when an attacker i
2026-06-30 CVE-2026-13773 medium IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 Approximately 50 generated CORBA stub classes in WebSphere eXtreme Scale's ogclient.jar call ORB.string_to_object() on an attacker-controlled IOR string during Java deserialization, turning any unfiltered ObjectInputStream sink
2026-07-08 CVE-2026-3144 high IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized access to the application before the system enforces a credential update.
2026-06-30 CVE-2026-11541 high IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are affected by an HTTP request smuggling vulnerability.
2026-06-30 CVE-2026-13449 high IBM Business Automation Manager Open Editions 9.0.0 through 9.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
2026-06-30 CVE-2026-11714 high IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the apiDiscovery-1.0 feature enabled.
2026-06-30 CVE-2026-11546 high IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the adminCenter-1.0 feature enabled.
2026-08-12 CVE-2026-17276 critical CVE-2026-17276: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to esca
2026-08-12 CVE-2026-16860 critical CVE-2026-16860: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to exec
2026-08-05 CVE-2026-17617 high CVE-2026-17617: IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side
2026-08-05 CVE-2026-8400 high CVE-2026-8400: IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Serv
2026-08-05 CVE-2026-10025 high CVE-2026-10025: IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 00
2026-07-30 CVE-2026-14522 high CVE-2026-14522: IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.
2026-07-29 CVE-2026-14529 critical CVE-2026-14529: IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Serv
2026-07-28 CVE-2026-16184 high CVE-2026-16184: IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to b
2026-07-28 CVE-2026-14976 high CVE-2026-14976: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected
2026-07-28 CVE-2026-14974 high CVE-2026-14974: IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote a
2026-07-17 CVE-2026-14501 medium CVE-2026-14501: IBM Db2 Genius Hub 1.1, 1.1.1, 1.1.2 and IBM Agentics 1.0 could allow an attacke
2026-07-17 CVE-2026-13473 high CVE-2026-13473: IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 throu
2026-05-26 CVE-2026-8855 high CVE-2026-8855: IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial o
2026-05-26 CVE-2026-8856 high CVE-2026-8856: IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configuration
2026-05-26 CVE-2025-36220 medium CVE-2025-36220: IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cl
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.80
IBM's vulnerability in Data Risk Manager was widely recognized as critical, with the CVE listed in NVD and CISA KEV, indicating severe security impact and vendor responsibility.
synthesissevere-fallout-0.80
IBM Data Risk Manager vulnerability allows remote authenticated attackers to execute commands, representing a critical security failure.
synthesissevere-fallout-0.80
Critical vulnerability allowing unauthenticated admin access and code execution as root
synthesissevere-fallout-0.80
IBM Data Risk Manager vulnerability allows remote attackers to bypass SAML authentication and gain full administrative access via specially crafted HTTP requests, representing a critical security fail
support.apple.com ↗severe-fallout+0.00
Irrelevant to IBM
"This document lists security updates for Apple software."
www.cvefind.com ↗severe-fallout-0.50
Vulnerability tracked in CVE database
"CVE 2020-4430 is listed in the database of publicly disclosed computer security flaws."
cvedb.shodan.io ↗severe-fallout-0.50
Vulnerability tracked in Shodan CVEDB
"The CVEDB API offers a quick way to check information about vulnerabilities in a service."
xposedornot.com ↗severe-fallout+0.00
Irrelevant to IBM
"Data Breach Directory & Database: Browse 760+ Known Breaches"
app.opencve.io ↗severe-fallout-0.50
Vulnerability tracked in OpenCVE
"CVEs and Security Vulnerabilities - OpenCVE"
CISA ↗severe-fallout-0.80
Vulnerability tracked in CISA ICS Advisories
"ICS Advisories | CISA"
cooey ↗severe-fallout-0.80
Critical vulnerability allowing unauthenticated admin access and code execution as root
"IBM Planning Analytics is vulnerable to a configuration overwrite that allows an unauthenticated user to login as 'admin', and then execute code as root or SYSTEM via TM1 scripting."
cooey ↗severe-fallout-0.80
Critical vulnerability allows remote attackers to bypass SAML authentication and gain full administrative access.
"IBM Data Risk Manager contains a security bypass vulnerability that could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to bypass the authentication process and gain full administrative access to the system."
cooey ↗severe-fallout-0.80
Critical vulnerability allows remote command execution
"IBM Data Risk Manager contains an unspecified vulnerability which could allow a remote, authenticated attacker to execute commands on the system."
cooey ↗severe-fallout-0.90
Critical vulnerability disclosed
"IBM Data Risk Manager contains a directory traversal vulnerability that could allow a remote authenticated attacker to traverse directories and send a specially crafted URL request to download arbitrary files from the system."
FEDRAMP CATALOG PRODUCTS · 5
Open questions: IBM's remediation timeline for the 2026-06-30 batch of vulnerabilities · Whether these vulnerabilities are currently in CISA KEV
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-14 03:49:47.027259+00:00