Known vulnerabilities in IBM Cloud Pak for Multicloud Management - page 7

Software CPE: cpe:2.3:a:ibm_corporation:cp-management:*:*:*:*:*:*:*:*
Total vulnerabilities: 345
Public exploits: 20
Known exploited (KEV): 7
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting IBM Cloud Pak for Multicloud Management IBM Cloud Pak for Multicloud Management is affected by 345 known vulnerabilities: 8 critical, 97 high, 161 medium, 79 low Critical High Medium Low

Vulnerabilities (345)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU107638 - Improper Control of Generation of Code ('Code Injection')
CVE-2025-1302
CWE-94 Critical
Available
No
2.3 FP11 22.04.2025 SB2025042218
SB2025042219
SB2025050906
and 8 more
#VU105796 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-27610
CWE-22 Medium
No
No
2.3 FP11 17.03.2025 SB2025031756
SB20250317118
SB20250317119
and 15 more
#VU105715 - Out-of-bounds write
CVE-2025-27363
CWE-787 Critical
Available
Exploited
2.3 FP11 14.03.2025 SB2025031402
SB2025031502
SB2025031750
and 97 more
#VU105387 - Improper input validation
CVE-2025-27516
CWE-20 Low
No
No
2.3 FP11 06.03.2025 SB2025030628
SB2025031001
SB2025031002
and 83 more
#VU104117 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-1244
CWE-78 High
No
No
2.3 FP11 21.02.2025 SB2025022110
SB2025022111
SB2025022112
and 31 more
#VU103436 - Resource exhaustion
CVE-2024-11187
CWE-400 Medium
No
No
2.3 FP11 29.01.2025 SB2025012962
SB2025012964
SB2025012965
and 83 more
#VU101971 - Security Features
CVE-2024-56201
CWE-254 Low
No
No
2.3 FP11 27.12.2024 SB2024122789
SB2025010203
SB2025010322
and 62 more
#VU101216 - Stack-based buffer overflow
CVE-2024-47607
CWE-121 High
No
No
2.3 FP11 04.12.2024 SB2024120472
SB2024121365
SB2024121366
and 26 more
#VU101206 - Stack-based buffer overflow
CVE-2024-47538
CWE-121 High
No
No
2.3 FP11 04.12.2024 SB2024120472
SB2024121365
SB2024121366
and 26 more
#VU100117 - Improper input validation
CVE-2024-21534
CWE-20 High
Available
No
- 08.11.2024 SB2024110840
SB2024110841
SB2024111516
and 17 more
#VU97923 - Exposure of sensitive information to an unauthorized actor
CVE-2024-9398
CWE-200 Low
No
No
- 01.10.2024 SB2024100154
SB2024100155
SB2024100156
and 40 more
#VU97917 - Permissions, Privileges, and Access Controls
CVE-2024-9393
CWE-264 Medium
No
No
- 01.10.2024 SB2024100154
SB2024100155
SB2024100156
and 43 more
#VU97916 - Security Features
CVE-2024-9392
CWE-254 Medium
No
No
- 01.10.2024 SB2024100154
SB2024100155
SB2024100156
and 46 more
#VU96741 - Improper Restriction of Rendered UI Layers or Frames
CVE-2024-8386
CWE-1021 Low
No
No
- 03.09.2024 SB2024090361
SB2024090501
SB2024090647
and 34 more
#VU96740 - Memory corruption
CVE-2024-8387
CWE-119 High
No
No
- 03.09.2024 SB2024090361
SB2024090501
SB2024090647
and 32 more
#VU96596 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2024-8088
CWE-835 Medium
No
No
2.3 FP11 28.08.2024 SB2024082860
SB2024082861
SB2024082862
and 82 more
#VU93118 - Use of Potentially Dangerous Function
CVE-2024-39331
CWE-676 High
No
No
2.3 FP11 24.06.2024 SB2024062429
SB2024062430
SB2024062431
and 46 more
#VU87808 - Insufficient Verification of Data Authenticity
CVE-2024-30203
CWE-345 High
No
No
2.3 FP11 26.03.2024 SB2024032628
SB2024032629
SB2024032630
and 30 more
#VU87804 - Insufficient Verification of Data Authenticity
CVE-2024-30205
CWE-345 High
No
No
2.3 FP11 26.03.2024 SB2024032628
SB2024032629
SB2024032630
and 32 more
#VU64863 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-30123
CWE-78 High
No
No
2.3 FP11 02.07.2022 SB2022070222
SB2022070430
SB2022072530
and 14 more


Showing elements 121 - 140 out of 345