Skip to content
COOEY

FEDRAMP CATALOG › SmartCloud for Government

SmartCloud for Government

IBM · package F1206081363

Current status Authorized · High impact · since 2026-07-07 Service modelIaaS MarketplaceRev5 · source: marketplace Security posture 7 critical 49 high 8 on KEV · 60 correlated CVEs
STATUS TIMELINE · SCD2
STATUSFROMTO
Authorized2026-07-07current
AUTHORIZATIONS
AGENCYTYPEDATE
JAB AuthorizationJAB2019-11-14
EXPOSED CVEs · CORRELATED TO THIS PRODUCT all exposures
SEVERITYCVETITLE
HIGHCVE-2026-17000CVE-2026-17000: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to e
HIGHCVE-2026-17003CVE-2026-17003: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to c
HIGHCVE-2026-17006CVE-2026-17006: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to e
HIGHCVE-2026-17024CVE-2026-17024: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to e
HIGHCVE-2026-17060CVE-2026-17060: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to o
HIGHCVE-2026-17138CVE-2026-17138: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to e
HIGHCVE-2026-17423CVE-2026-17423: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to o
HIGHCVE-2026-17436CVE-2026-17436: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to e
HIGHCVE-2026-18670CVE-2026-18670: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to c
HIGHCVE-2026-18716CVE-2026-18716: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated
HIGHCVE-2026-18832CVE-2026-18832: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to e
HIGHCVE-2026-19437CVE-2026-19437: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to e
CRITICALCVE-2026-16919CVE-2026-16919: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to e
HIGHCVE-2026-16815CVE-2026-16815: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of
HIGHCVE-2026-16867CVE-2026-16867: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to access server reso
HIGHCVE-2026-16961CVE-2026-16961: IBM i 7.6, 7.5, and 7.4 s vulnerable to SQL injection. A remote attacker could s
HIGHCVE-2026-17101CVE-2026-17101: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary
HIGHCVE-2026-17197CVE-2026-17197: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security re
HIGHCVE-2026-17206CVE-2026-17206: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary
HIGHCVE-2026-17481CVE-2026-17481: IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to e
HIGHCVE-2026-18193CVE-2026-18193: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security re
HIGHCVE-2026-18249CVE-2026-18249: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain
HIGHCVE-2026-10534CVE-2026-10534: IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer
HIGHCVE-2026-10543CVE-2026-10543: IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to privil
HIGHCVE-2026-13433CVE-2026-13433: IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 (ACS) is vulnerable to do
CRITICALCVE-2026-16860CVE-2026-16860: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to exec
HIGHCVE-2026-17111CVE-2026-17111: IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to SQL injection. A remote attacker co
CRITICALCVE-2026-17276CVE-2026-17276: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to esca
MEDIUMCVE-2026-17616CVE-2026-17616: IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access
HIGHCVE-2026-18847CVE-2026-18847: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to ha
HIGHCVE-2026-10025CVE-2026-10025: IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 00
HIGHCVE-2026-17617CVE-2026-17617: IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side
HIGHCVE-2026-8400CVE-2026-8400: IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Serv
HIGHCVE-2026-9198IBM Langflow Code Injection Vulnerability
HIGHCVE-2026-14522CVE-2026-14522: IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.
CRITICALCVE-2026-14529CVE-2026-14529: IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Serv
HIGHCVE-2026-14974CVE-2026-14974: IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote a
HIGHCVE-2026-14976CVE-2026-14976: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected
HIGHCVE-2026-16184CVE-2026-16184: IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to b
HIGHCVE-2026-13473CVE-2026-13473: IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 throu
MEDIUMCVE-2026-14501CVE-2026-14501: IBM Db2 Genius Hub 1.1, 1.1.1, 1.1.2 and IBM Agentics 1.0 could allow an attacke
HIGHCVE-2026-3144CVE-2026-3144: IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could a
CRITICALCVE-2026-9074CVE-2026-9074: IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains
HIGHCVE-2026-11541CVE-2026-11541: IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Serv
HIGHCVE-2026-11546CVE-2026-11546: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected
HIGHCVE-2026-11714CVE-2026-11714: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected
HIGHCVE-2026-13449CVE-2026-13449: IBM Business Automation Manager Open Editions 9.0.0 through 9.4.2 is vulnerable
HIGHCVE-2026-13772CVE-2026-13772: IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 's Object Query Language eng
MEDIUMCVE-2026-13773CVE-2026-13773: IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 Approximately 50 generated C
HIGHCVE-2026-9072CVE-2026-9072: IBM WebSphere Application Server and IBM WebSphere Application Server Liberty -
MEDIUMCVE-2025-36220CVE-2025-36220: IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cl
HIGHCVE-2026-8855CVE-2026-8855: IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial o
HIGHCVE-2026-8856CVE-2026-8856: IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configuration
CRITICALCVE-2022-47986IBM Aspera Faspex Code Execution Vulnerability
CRITICALCVE-2013-3993IBM InfoSphere BigInsights Invalid Input Vulnerability
HIGHCVE-2015-7450IBM WebSphere Application Server and Server Hypervisor Edition Code Injection.
HIGHCVE-2019-4716IBM Planning Analytics Remote Code Execution Vulnerability
HIGHCVE-2020-4427IBM Data Risk Manager Security Bypass Vulnerability
HIGHCVE-2020-4428IBM Data Risk Manager Remote Code Execution Vulnerability
HIGHCVE-2020-4430IBM Data Risk Manager Directory Traversal Vulnerability