FAIL › dossier
IBM
COMPANY FEDRAMP MARKETFedRAMP provider · · dossier confidence 20%
IBM is a major public technology vendor with a significant security footprint in enterprise software. Recent 2026 data reveals a pattern of critical RCE and XXE vulnerabilities across WebSphere, API Connect, and IBM i, indicating a need for rigorous patch management.
PROFILE
CategoryTechnology VendorWhat they doIBM is a multinational technology corporation that develops, manufactures, and supports hardware, software, and related services.
Websitehttps://www.ibm.com ↗
SECURITY POSTURE
IBM demonstrates a high volume of critical and high-severity vulnerabilities across its enterprise software portfolio (WebSphere, API Connect, IBM i) in 2026, with multiple RCE and XXE flaws affecting widely deployed components.
Notable failures
- CVE-2026-9074: Unauthenticated SQL injection in API Connect password reset
- CVE-2026-13772: RCE in WebSphere Extreme Scale via Class.forName()
- CVE-2026-13449: XXE in Business Automation Manager Open Editions
- CVE-2026-11541: HTTP request smuggling in WebSphere Application Server
- CVE-2026-11714: SSRF in WebSphere Liberty apiDiscovery-1.0
- CVE-2026-11546: SSRF in WebSphere Liberty adminCenter-1.0
Patterns: Repeated unpatched edge-device RCEs; Default credentials in API Connect; XXE in XML processing components; SSRF in Liberty features
FAILURE HISTORY · 32
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2023-02-21 | CVE-2022-47986 | critical | A YAML deserialization flaw in IBM Aspera Faspex allowed remote attackers to execute code, leading to ransomware-linked incidents. |
| 2022-05-25 | CVE-2013-3993 | critical | IBM InfoSphere BigInsights APIs accepted invalid input allowing attackers to read, write, modify, or delete data. |
| 2026-08-04 | CVE-2026-9198 | high | IBM Langflow Code Injection Vulnerability allows RCE. |
| 2022-01-10 | CVE-2015-7450 | high | Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands |
| 2021-11-03 | CVE-2019-4716 | high | IBM Planning Analytics is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting. |
| 2021-11-03 | CVE-2020-4428 | high | IBM Data Risk Manager contains an unspecified vulnerability which could allow a remote, authenticated attacker to execute commands on the system.� |
| 2021-11-03 | CVE-2020-4427 | high | IBM Data Risk Manager contains a security bypass vulnerability that could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to bypass the auth |
| 2021-11-03 | CVE-2020-4430 | high | IBM Data Risk Manager contains a directory traversal vulnerability that could allow a remote authenticated attacker to traverse directories and send a specially crafted URL request to download arbitrary files from the system. |
| 2026-07-08 | CVE-2026-9074 | critical | IBM API Connect versions 10.0.8.0–10.0.8.9 and 12.1.0.0–12.1.0.3 contain an unauthenticated SQL injection vulnerability in the password reset functionality. |
| 2026-06-30 | CVE-2026-13772 | high | IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 's Object Query Language engine resolves attacker-supplied class names via Class.forName() and invokes their constructors with no allow-list at three distinct sinks (SELECT NEW, enum literals, and reflection-based comparators); |
| 2026-06-22 | CVE-2026-9072 | high | IBM WebSphere Application Server and IBM WebSphere Application Server Liberty - when using Intelligent Management with the WebSphere WebServer Plug-in component - are vulnerable to remote code execution and denial of service. This vulnerability can be exploited when an attacker i |
| 2026-06-30 | CVE-2026-13773 | medium | IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 Approximately 50 generated CORBA stub classes in WebSphere eXtreme Scale's ogclient.jar call ORB.string_to_object() on an attacker-controlled IOR string during Java deserialization, turning any unfiltered ObjectInputStream sink |
| 2026-07-08 | CVE-2026-3144 | high | IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized access to the application before the system enforces a credential update. |
| 2026-06-30 | CVE-2026-11541 | high | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are affected by an HTTP request smuggling vulnerability. |
| 2026-06-30 | CVE-2026-13449 | high | IBM Business Automation Manager Open Editions 9.0.0 through 9.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. |
| 2026-06-30 | CVE-2026-11714 | high | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the apiDiscovery-1.0 feature enabled. |
| 2026-06-30 | CVE-2026-11546 | high | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the adminCenter-1.0 feature enabled. |
| 2026-08-12 | CVE-2026-17276 | critical | CVE-2026-17276: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to esca |
| 2026-08-12 | CVE-2026-16860 | critical | CVE-2026-16860: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to exec |
| 2026-08-05 | CVE-2026-17617 | high | CVE-2026-17617: IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side |
| 2026-08-05 | CVE-2026-8400 | high | CVE-2026-8400: IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Serv |
| 2026-08-05 | CVE-2026-10025 | high | CVE-2026-10025: IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 00 |
| 2026-07-30 | CVE-2026-14522 | high | CVE-2026-14522: IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0. |
| 2026-07-29 | CVE-2026-14529 | critical | CVE-2026-14529: IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Serv |
| 2026-07-28 | CVE-2026-16184 | high | CVE-2026-16184: IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to b |
| 2026-07-28 | CVE-2026-14976 | high | CVE-2026-14976: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected |
| 2026-07-28 | CVE-2026-14974 | high | CVE-2026-14974: IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote a |
| 2026-07-17 | CVE-2026-14501 | medium | CVE-2026-14501: IBM Db2 Genius Hub 1.1, 1.1.1, 1.1.2 and IBM Agentics 1.0 could allow an attacke |
| 2026-07-17 | CVE-2026-13473 | high | CVE-2026-13473: IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 throu |
| 2026-05-26 | CVE-2026-8855 | high | CVE-2026-8855: IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial o |
| 2026-05-26 | CVE-2026-8856 | high | CVE-2026-8856: IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configuration |
| 2026-05-26 | CVE-2025-36220 | medium | CVE-2025-36220: IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cl |
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.80
IBM's vulnerability in Data Risk Manager was widely recognized as critical, with the CVE listed in NVD and CISA KEV, indicating severe security impact and vendor responsibility.
synthesissevere-fallout-0.80
IBM Data Risk Manager vulnerability allows remote authenticated attackers to execute commands, representing a critical security failure.
synthesissevere-fallout-0.80
Critical vulnerability allowing unauthenticated admin access and code execution as root
synthesissevere-fallout-0.80
IBM Data Risk Manager vulnerability allows remote attackers to bypass SAML authentication and gain full administrative access via specially crafted HTTP requests, representing a critical security fail
Irrelevant to IBM
"This document lists security updates for Apple software."
Vulnerability tracked in CVE database
"CVE 2020-4430 is listed in the database of publicly disclosed computer security flaws."
Vulnerability tracked in Shodan CVEDB
"The CVEDB API offers a quick way to check information about vulnerabilities in a service."
Irrelevant to IBM
"Data Breach Directory & Database: Browse 760+ Known Breaches"
Vulnerability tracked in OpenCVE
"CVEs and Security Vulnerabilities - OpenCVE"
Critical vulnerability allowing unauthenticated admin access and code execution as root
"IBM Planning Analytics is vulnerable to a configuration overwrite that allows an unauthenticated user to login as 'admin', and then execute code as root or SYSTEM via TM1 scripting."
Critical vulnerability allows remote attackers to bypass SAML authentication and gain full administrative access.
"IBM Data Risk Manager contains a security bypass vulnerability that could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to bypass the authentication process and gain full administrative access to the system."
Critical vulnerability allows remote command execution
"IBM Data Risk Manager contains an unspecified vulnerability which could allow a remote, authenticated attacker to execute commands on the system."
Critical vulnerability disclosed
"IBM Data Risk Manager contains a directory traversal vulnerability that could allow a remote authenticated attacker to traverse directories and send a specially crafted URL request to download arbitrary files from the system."
FEDRAMP CATALOG PRODUCTS · 5
| PRODUCT | STATUS | IMPACT |
|---|---|---|
| IBM Cloud for Government | Authorized | High |
| IBM Federal HR Cloud | Authorized | Moderate |
| IBM Maximo and TRIRIGA on Cloud for U.S. Federal | Authorized | Moderate |
| MaaS360 Enterprise Mobility Management | Authorized | Moderate |
| SmartCloud for Government | Authorized | High |
DOSSIER SOURCES
- IBM (IBM) Company Profile, CEO, Owner, Founder, Headquarters, Market ... · www.gizbot.com
- Security Bulletin: IBM WebSphere Application Server Liberty, which is ... · www.ibm.com
- Security Bulletin: Due to use of IBM Storage Protect, IBM Cloud Pak ... · www.ibm.com
- IBM i 関連の脆弱性情報 | iWorld · iworldweb.info
- Security Bulletin: IBM Application Modernization Accelerator is ... · www.ibm.com
- Security Bulletin: IBM Operational Decision Manager for May 2026 ... · www.ibm.com
- Vulnerability Report Archives • Daily CyberSecurity · securityonline.info
Open questions: IBM's remediation timeline for the 2026-06-30 batch of vulnerabilities · Whether these vulnerabilities are currently in CISA KEV
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-14 03:49:47.027259+00:00