Known vulnerabilities in IBM Cloud Application Performance Management (APM)

Software CPE: cpe:2.3:a:ibm_corporation:apm:*:*:*:*:*:*:*:*
Total vulnerabilities: 504
Public exploits: 30
Known exploited (KEV): 5
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting IBM Cloud Application Performance Management (APM) IBM Cloud Application Performance Management (APM) is affected by 504 known vulnerabilities: 2 critical, 125 high, 240 medium, 137 low Critical High Medium Low

Vulnerabilities (504)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU123672 - Improper Control of Generation of Code ('Code Injection')
CVE-2025-33042
CWE-94 Medium
No
No
8.1.4.0.19 10.03.2026 SB2026031037
SB2026031038
SB2026031135
and 8 more
#VU122748 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-14914
CWE-22 Low
No
No
8.1.4.0.19 12.02.2026 SB2026021209
SB2026021210
SB2026021212
and 23 more
#VU121007 - Exposure of sensitive information to an unauthorized actor
CVE-2025-66566
CWE-200 Medium
No
No
8.1.4.0.19 07.01.2026 SB2026010702
SB2026010705
SB2026010706
and 28 more
#VU121006 - Out-of-bounds read
CVE-2025-12183
CWE-125 Medium
No
No
8.1.4.0.19 07.01.2026 SB2026010701
SB2026010705
SB2026010706
and 14 more
#VU117483 - Improper input validation
CVE-2025-53066
CWE-20 Medium
No
No
8.1.4.0.19 22.10.2025 SB20251022107
SB20251022108
SB20251022109
and 118 more
#VU117484 - Improper input validation
CVE-2025-53057
CWE-20 Medium
No
No
8.1.4.0.19 22.10.2025 SB20251022107
SB20251022108
SB20251022109
and 121 more
#VU115571 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2025-36000
CWE-79 Low
No
No
8.1.4.0.19 16.09.2025 SB20250916311
SB20250916316
SB2025092515
and 25 more
#VU114346 - Command injection
CVE-2025-7962
CWE-77 Medium
No
No
8.1.4.0.19 21.08.2025 SB2025082145
SB2025082146
SB2025082147
and 54 more
#VU114006 - Privilege Chaining
CVE-2025-36124
CWE-268 High
No
No
8.1.4.0.19 13.08.2025 SB2025081354
SB2025082918
SB2025082921
and 23 more
#VU113085 - Interpretation Conflict
CVE-2024-56339
CWE-436 Medium
No
No
8.1.4.0.19 21.07.2025 SB2025072116
SB2025072130
SB2025072305
and 45 more
#VU113074 - Stack-based buffer overflow
CVE-2025-36097
CWE-121 High
No
No
8.1.4.0.19 18.07.2025 SB20250718100
SB2025072128
SB2025072307
and 43 more
#VU111162 - Resource exhaustion
CVE-2025-48976
CWE-400 Medium
Available
No
8.1.4.0.19 16.06.2025 SB2025061634
SB2025061635
SB2025061927
and 156 more
#VU97294 - Exposure of sensitive information to an unauthorized actor
CVE-2019-10246
CWE-200 Medium
No
No
8.1.4.0.19 16.09.2024 SB2019051138
SB2024091613
SB2025082547
and 1 more
#VU83992 - Use of Insufficiently Random Values
CVE-2020-36732
CWE-330 Medium
No
No
8.1.4.0.19 08.12.2023 SB2023120804
SB2024030742
SB2025091116
and 26 more
#VU69467 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2022-39135
CWE-611 High
No
No
8.1.4.0.19 21.11.2022 SB2022112141
SB2022112142
SB2023040701
and 4 more
#VU49378 - Deserialization of Untrusted Data
CVE-2020-35728
CWE-502 High
Available
No
8.1.4.0.19 27.12.2020 SB2021011105
SB2021042826
SB2021050708
and 15 more
#VU49379 - Deserialization of Untrusted Data
CVE-2020-35490
CWE-502 High
No
No
8.1.4.0.19 17.12.2020 SB2021011105
SB2021042826
SB2021050708
and 16 more
#VU49380 - Deserialization of Untrusted Data
CVE-2020-35491
CWE-502 High
No
No
8.1.4.0.19 17.12.2020 SB2021011105
SB2021042826
SB2021050708
and 15 more
#VU13530 - Exposure of sensitive information to an unauthorized actor
CVE-2018-12536
CWE-200 Low
No
No
8.1.4.0.19 02.07.2018 SB2018070205
SB2022032830
SB2022032831
and 8 more
#VU9654 - Information Exposure Through Timing Discrepancy
CVE-2017-9735
CWE-208 Low
No
No
8.1.4.0.19 17.06.2017 SB2017061704
SB2021072132
SB2023042803
and 12 more


Showing elements 1 - 20 out of 504