Skip to content
COOEY

FEDRAMP CATALOG › SmartCloud for Government

SmartCloud for Government

IBM · package F1206081363

Current status Authorized · High impact · since 2026-07-07 Service modelIaaS MarketplaceRev5 · source: marketplace Security posture 6 critical 23 high 8 on KEV · 32 correlated CVEs
STATUS TIMELINE · SCD2
STATUSFROMTO
Authorized2026-07-07current
AUTHORIZATIONS
AGENCYTYPEDATE
JAB AuthorizationJAB2019-11-14
EXPOSED CVEs · CORRELATED TO THIS PRODUCT all exposures
SEVERITYCVETITLE
CRITICALCVE-2026-16860CVE-2026-16860: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to exec
CRITICALCVE-2026-17276CVE-2026-17276: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to esca
HIGHCVE-2026-10025CVE-2026-10025: IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 00
HIGHCVE-2026-17617CVE-2026-17617: IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side
HIGHCVE-2026-8400CVE-2026-8400: IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Serv
HIGHCVE-2026-9198IBM Langflow Code Injection Vulnerability
HIGHCVE-2026-14522CVE-2026-14522: IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.
CRITICALCVE-2026-14529CVE-2026-14529: IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Serv
HIGHCVE-2026-14974CVE-2026-14974: IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote a
HIGHCVE-2026-14976CVE-2026-14976: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected
HIGHCVE-2026-16184CVE-2026-16184: IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to b
HIGHCVE-2026-13473CVE-2026-13473: IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 throu
MEDIUMCVE-2026-14501CVE-2026-14501: IBM Db2 Genius Hub 1.1, 1.1.1, 1.1.2 and IBM Agentics 1.0 could allow an attacke
HIGHCVE-2026-3144CVE-2026-3144: IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could a
CRITICALCVE-2026-9074CVE-2026-9074: IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains
HIGHCVE-2026-11541CVE-2026-11541: IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Serv
HIGHCVE-2026-11546CVE-2026-11546: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected
HIGHCVE-2026-11714CVE-2026-11714: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected
HIGHCVE-2026-13449CVE-2026-13449: IBM Business Automation Manager Open Editions 9.0.0 through 9.4.2 is vulnerable
HIGHCVE-2026-13772CVE-2026-13772: IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 's Object Query Language eng
MEDIUMCVE-2026-13773CVE-2026-13773: IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 Approximately 50 generated C
HIGHCVE-2026-9072CVE-2026-9072: IBM WebSphere Application Server and IBM WebSphere Application Server Liberty -
MEDIUMCVE-2025-36220CVE-2025-36220: IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cl
HIGHCVE-2026-8855CVE-2026-8855: IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial o
HIGHCVE-2026-8856CVE-2026-8856: IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configuration
CRITICALCVE-2022-47986IBM Aspera Faspex Code Execution Vulnerability
CRITICALCVE-2013-3993IBM InfoSphere BigInsights Invalid Input Vulnerability
HIGHCVE-2015-7450IBM WebSphere Application Server and Server Hypervisor Edition Code Injection.
HIGHCVE-2019-4716IBM Planning Analytics Remote Code Execution Vulnerability
HIGHCVE-2020-4427IBM Data Risk Manager Security Bypass Vulnerability
HIGHCVE-2020-4428IBM Data Risk Manager Remote Code Execution Vulnerability
HIGHCVE-2020-4430IBM Data Risk Manager Directory Traversal Vulnerability