Known vulnerabilities in IBM Cloud Pak for Multicloud Management - page 3

Software CPE: cpe:2.3:a:ibm_corporation:cp-management:*:*:*:*:*:*:*:*
Total vulnerabilities: 345
Public exploits: 20
Known exploited (KEV): 7
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting IBM Cloud Pak for Multicloud Management IBM Cloud Pak for Multicloud Management is affected by 345 known vulnerabilities: 8 critical, 97 high, 161 medium, 79 low Critical High Medium Low

Vulnerabilities (345)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU113515 - Insufficient Verification of Data Authenticity
CVE-2025-43240
CWE-345 Medium
No
No
2.3 Fix Pack 12 30.07.2025 SB2025073052
SB2025073053
SB2025073156
and 25 more
#VU113514 - Memory corruption
CVE-2025-31273
CWE-119 High
No
No
2.3 Fix Pack 12 30.07.2025 SB2025073052
SB2025073053
SB2025073151
and 32 more
#VU113512 - Memory corruption
CVE-2025-31278
CWE-119 High
No
No
2.3 Fix Pack 12 30.07.2025 SB2025073052
SB2025073053
SB2025073151
and 33 more
#VU113506 - Use After Free
CVE-2025-43216
CWE-416 Low
No
No
2.3 Fix Pack 12 30.07.2025 SB2025073053
SB2025073151
SB2025073152
and 31 more
#VU113504 - Memory corruption
CVE-2025-43211
CWE-119 Low
No
No
2.3 Fix Pack 12 30.07.2025 SB2025073052
SB2025073053
SB2025073151
and 30 more
#VU113503 - Memory corruption
CVE-2025-43212
CWE-119 Low
No
No
2.3 Fix Pack 12 30.07.2025 SB2025073052
SB2025073053
SB2025073151
and 30 more
#VU113500 - State Issues
CVE-2025-43227
CWE-371 Medium
No
No
2.3 Fix Pack 12 30.07.2025 SB2025073052
SB2025073053
SB2025073151
and 29 more
#VU112940 - Improper input validation
CVE-2025-30761
CWE-20 Medium
No
No
2.3 Fix Pack 12 16.07.2025 SB2025071686
SB2025071687
SB2025071688
and 77 more
#VU112941 - Improper input validation
CVE-2025-30754
CWE-20 Medium
No
No
2.3 Fix Pack 12 16.07.2025 SB2025071686
SB2025071692
SB2025071783
and 108 more
#VU112146 - Server-Side Request Forgery (SSRF)
CVE-2025-27817
CWE-918 High
Available
No
2.3 Fix Pack 12 03.07.2025 SB2025070339
SB2025070340
SB2025070345
and 42 more
#VU109838 - NULL Pointer Dereference
CVE-2025-32913
CWE-476 High
No
No
2.3 Fix Pack 12 27.05.2025 SB2025052718
SB2025052723
SB2025052997
and 33 more
#VU109834 - Out-of-bounds read
CVE-2025-32906
CWE-125 Medium
No
No
2.3 Fix Pack 12 27.05.2025 SB2025052715
SB2025052723
SB2025052994
and 37 more
#VU103771 - Improper Authentication
CVE-2024-12797
CWE-287 Medium
No
No
2.3 Fix Pack 12 11.02.2025 SB2025021187
SB20250211108
SB20250211159
and 60 more
#VU102739 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2024-12747
CWE-362 Low
No
No
2.3 Fix Pack 12 14.01.2025 SB2025011495
SB2025011504
SB2025011530
and 56 more
#VU102736 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-12088
CWE-22 Medium
No
No
2.3 Fix Pack 12 14.01.2025 SB2025011495
SB2025011504
SB2025011530
and 65 more
#VU102734 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-12087
CWE-22 Medium
No
No
2.3 Fix Pack 12 14.01.2025 SB2025011495
SB2025011504
SB2025011530
and 74 more
#VU101767 - Resource exhaustion
CVE-2024-43380
CWE-400 Medium
No
No
2.3 Fix Pack 12 13.12.2024 SB2024121314
SB2025032112
SB2025032126
and 2 more
#VU99975 - Authentication Bypass by Spoofing
CVE-2024-51504
CWE-290 High
No
No
2.3 Fix Pack 12 06.11.2024 SB2024110667
SB2024121231
SB2024122015
and 12 more
#VU88173 - Resource exhaustion
CVE-2023-51775
CWE-400 Medium
No
No
2.3 Fix Pack 12 05.04.2024 SB2024040525
SB2024041129
SB2024041130
and 83 more
#VU69506 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')
CVE-2021-33621
CWE-113 Medium
No
No
2.3 Fix Pack 12 22.11.2022 SB2022112239
SB2022112439
SB2023011730
and 31 more


Showing elements 41 - 60 out of 345