Current status
Authorized · High impact · since 2026-07-07
Service modelIaaS
MarketplaceRev5 · source: marketplace
Security posture
6 critical
23 high
8 on KEV
· 32 correlated CVEs
CMMC DOMAINS ADDRESSED
STATUS TIMELINE · SCD2
| STATUS | FROM | TO |
|---|---|---|
| Authorized | 2026-07-07 | current |
AUTHORIZATIONS
| AGENCY | TYPE | DATE |
|---|---|---|
| JAB Authorization | JAB | 2019-11-14 |
EXPOSED CVEs · CORRELATED TO THIS PRODUCT
all exposures
| SEVERITY | CVE | TITLE |
|---|---|---|
| CRITICAL | CVE-2026-16860 | CVE-2026-16860: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to exec |
| CRITICAL | CVE-2026-17276 | CVE-2026-17276: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to esca |
| HIGH | CVE-2026-10025 | CVE-2026-10025: IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 00 |
| HIGH | CVE-2026-17617 | CVE-2026-17617: IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side |
| HIGH | CVE-2026-8400 | CVE-2026-8400: IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Serv |
| HIGH | CVE-2026-9198 | IBM Langflow Code Injection Vulnerability |
| HIGH | CVE-2026-14522 | CVE-2026-14522: IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0. |
| CRITICAL | CVE-2026-14529 | CVE-2026-14529: IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Serv |
| HIGH | CVE-2026-14974 | CVE-2026-14974: IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote a |
| HIGH | CVE-2026-14976 | CVE-2026-14976: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected |
| HIGH | CVE-2026-16184 | CVE-2026-16184: IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to b |
| HIGH | CVE-2026-13473 | CVE-2026-13473: IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 throu |
| MEDIUM | CVE-2026-14501 | CVE-2026-14501: IBM Db2 Genius Hub 1.1, 1.1.1, 1.1.2 and IBM Agentics 1.0 could allow an attacke |
| HIGH | CVE-2026-3144 | CVE-2026-3144: IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could a |
| CRITICAL | CVE-2026-9074 | CVE-2026-9074: IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains |
| HIGH | CVE-2026-11541 | CVE-2026-11541: IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Serv |
| HIGH | CVE-2026-11546 | CVE-2026-11546: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected |
| HIGH | CVE-2026-11714 | CVE-2026-11714: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected |
| HIGH | CVE-2026-13449 | CVE-2026-13449: IBM Business Automation Manager Open Editions 9.0.0 through 9.4.2 is vulnerable |
| HIGH | CVE-2026-13772 | CVE-2026-13772: IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 's Object Query Language eng |
| MEDIUM | CVE-2026-13773 | CVE-2026-13773: IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 Approximately 50 generated C |
| HIGH | CVE-2026-9072 | CVE-2026-9072: IBM WebSphere Application Server and IBM WebSphere Application Server Liberty - |
| MEDIUM | CVE-2025-36220 | CVE-2025-36220: IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cl |
| HIGH | CVE-2026-8855 | CVE-2026-8855: IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial o |
| HIGH | CVE-2026-8856 | CVE-2026-8856: IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configuration |
| CRITICAL | CVE-2022-47986 | IBM Aspera Faspex Code Execution Vulnerability |
| CRITICAL | CVE-2013-3993 | IBM InfoSphere BigInsights Invalid Input Vulnerability |
| HIGH | CVE-2015-7450 | IBM WebSphere Application Server and Server Hypervisor Edition Code Injection. |
| HIGH | CVE-2019-4716 | IBM Planning Analytics Remote Code Execution Vulnerability |
| HIGH | CVE-2020-4427 | IBM Data Risk Manager Security Bypass Vulnerability |
| HIGH | CVE-2020-4428 | IBM Data Risk Manager Remote Code Execution Vulnerability |
| HIGH | CVE-2020-4430 | IBM Data Risk Manager Directory Traversal Vulnerability |