IBM Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for IBM products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
11
In CISA KEV
7
Beyond CISA KEV
4
Sensor Observed
0
Virtual Patch Available
0
IBM KEVs Added by Year
11 IBM KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2020-4463
IBM Maximo Asset Management 7.6.0.1 and 7.6.0.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote... |
Maximo Asset Management | High | Not in CISA | 31 Aug 2025 |
|
CVE-2024-22319
IBM Operational Decision Manager JDNI injection |
Operational Decision Manager | High | Not in CISA | 26 Jun 2025 |
|
CVE-2019-4716
IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and... |
Planning Analytics | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-4428
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary commands on the system. IBM... |
Data Risk Manager | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-4427
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured... |
Data Risk Manager | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-4430
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to traverse directories on the system. An attacker... |
Data Risk Manager | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2015-7450
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow... |
WebSphere | Confirmed | In CISA | 10 Jan 2022 |
|
CVE-2013-3993
IBM InfoSphere BigInsights before 2.1.0.3 allows remote authenticated users to bypass intended file and directory restrictions, or access untrusted... |
InfoSphere BigInsights | Confirmed | In CISA | 25 May 2022 |
|
CVE-2022-47986
IBM Aspera Faspex code execution |
Aspera Faspex | Confirmed | In CISA | 21 Feb 2023 |
|
CVE-2024-22320
IBM Operational Decision Manager code execution |
Operational Decision Manager | High | Not in CISA | 02 Feb 2024 |
|
CVE-2019-4061
IBM BigFix Platform 9.2 and 9.5 could allow an attacker to query the relay remotely and gather information about the updates and fixlets deployed... |
BigFix Platform | High | Not in CISA | 27 Feb 2019 |
Common Vulnerability Classes (CWE)
- CWE-502 — Deserialization of Untrusted Data 3
- CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 2
- CWE-611 — Improper Restriction of XML External Entity Reference 1
- CWE-74 — Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') 1
- CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 1
- CWE-200 — Exposure of Sensitive Information to an Unauthorized Actor 1
- CWE-94 — Improper Control of Generation of Code ('Code Injection') 1
- CWE-287 — Improper Authentication 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology