IBM Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for IBM products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

11

In CISA KEV

7

Beyond CISA KEV

4

Sensor Observed

0

Virtual Patch Available

0

IBM KEVs Added by Year

Loading...

11 IBM KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2020-4463

IBM Maximo Asset Management 7.6.0.1 and 7.6.0.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote...

High Not in CISA 31 Aug 2025
CVE-2024-22319

IBM Operational Decision Manager JDNI injection

High Not in CISA 26 Jun 2025
CVE-2019-4716

IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and...

Confirmed In CISA 03 Nov 2021
CVE-2020-4428

IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary commands on the system. IBM...

Confirmed In CISA 03 Nov 2021
CVE-2020-4427

IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured...

Confirmed In CISA 03 Nov 2021
CVE-2020-4430

IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to traverse directories on the system. An attacker...

Confirmed In CISA 03 Nov 2021
CVE-2015-7450

Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow...

Confirmed In CISA 10 Jan 2022
CVE-2013-3993

IBM InfoSphere BigInsights before 2.1.0.3 allows remote authenticated users to bypass intended file and directory restrictions, or access untrusted...

Confirmed In CISA 25 May 2022
CVE-2022-47986

IBM Aspera Faspex code execution

Confirmed In CISA 21 Feb 2023
CVE-2024-22320

IBM Operational Decision Manager code execution

High Not in CISA 02 Feb 2024
CVE-2019-4061

IBM BigFix Platform 9.2 and 9.5 could allow an attacker to query the relay remotely and gather information about the updates and fixlets deployed...

High Not in CISA 27 Feb 2019

Common Vulnerability Classes (CWE)

  • CWE-502 — Deserialization of Untrusted Data 3
  • CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 2
  • CWE-611 — Improper Restriction of XML External Entity Reference 1
  • CWE-74 — Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') 1
  • CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 1
  • CWE-200 — Exposure of Sensitive Information to an Unauthorized Actor 1
  • CWE-94 — Improper Control of Generation of Code ('Code Injection') 1
  • CWE-287 — Improper Authentication 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology