Known vulnerabilities in Data Product Hub

Software CPE: cpe:2.3:a:ibm_corporation:data_product_hub:*:*:*:*:*:*:*:*
Total vulnerabilities: 51
Public exploits: 2
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.2

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Data Product Hub Data Product Hub is affected by 51 known vulnerabilities: 2 high, 29 medium, 20 low Critical High Medium Low

Vulnerabilities (51)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU135090 - Improper Privilege Management
CVE-2026-3621
CWE-269 Medium
No
No
5.3.1 Patch 7, 5.4.0 24.06.2026 SB2026062429
SB2026062430
SB20260626104
and 8 more
#VU130954 - Out-of-bounds read
CVE-2026-6918
CWE-125 Medium
No
No
5.3.1 Patch 7, 5.4.0 11.05.2026 SB2026051152
SB20260528261
SB2026060168
and 10 more
#VU126877 - Uncontrolled Recursion
CVE-2026-41680
CWE-674 Medium
Available
No
5.3.1 Patch 7, 5.4.0 23.04.2026 SB2026042317
SB2026062221
SB2026062430
and 1 more
#VU126758 - Improper input validation
CVE-2026-22016
CWE-20 Medium
No
No
5.3.1 Patch 7, 5.4.0 22.04.2026 SB20260422123
SB20260422124
SB20260422125
and 71 more
#VU126759 - Improper input validation
CVE-2026-34282
CWE-20 Medium
No
No
5.3.1 Patch 7, 5.4.0 22.04.2026 SB20260422123
SB20260422124
SB20260422125
and 31 more
#VU126761 - Improper input validation
CVE-2026-22021
CWE-20 Medium
No
No
5.3.1 Patch 7, 5.4.0 22.04.2026 SB20260422123
SB20260422124
SB20260422125
and 72 more
#VU126762 - Improper input validation
CVE-2026-22013
CWE-20 Medium
No
No
5.3.1 Patch 7, 5.4.0 22.04.2026 SB20260422123
SB20260422124
SB20260422125
and 70 more
#VU126763 - Improper input validation
CVE-2026-22008
CWE-20 Low
No
No
5.3.1 Patch 7, 5.4.0 22.04.2026 SB20260422123
SB2026050683
SB20260513117
and 15 more
#VU126764 - Improper input validation
CVE-2026-22018
CWE-20 Low
No
No
5.3.1 Patch 7, 5.4.0 22.04.2026 SB20260422123
SB20260422124
SB20260422125
and 70 more
#VU126765 - Improper input validation
CVE-2026-22007
CWE-20 Low
No
No
5.3.1 Patch 7, 5.4.0 22.04.2026 SB20260422123
SB20260422124
SB20260422125
and 70 more
#VU126766 - Improper input validation
CVE-2026-34268
CWE-20 Low
No
No
5.3.1 Patch 7, 5.4.0 22.04.2026 SB20260422123
SB20260422124
SB20260422125
and 70 more
#VU124833 - Server-Side Request Forgery (SSRF)
CVE-2026-1561
CWE-918 Low
No
No
5.3.1 Patch 7, 5.4.0 02.04.2026 SB2026040252
SB2026040325
SB2026040331
and 9 more
#VU124831 - Weak Password Requirements
CVE-2025-14917
CWE-521 Low
No
No
5.3.1 Patch 7, 5.4.0 02.04.2026 SB2026040252
SB2026040327
SB2026040328
and 12 more
#VU124829 - Exposure of sensitive information to an unauthorized actor
CVE-2025-14915
CWE-200 Low
No
No
5.3.1 Patch 7, 5.4.0 02.04.2026 SB2026040252
SB2026040326
SB2026040329
and 9 more
#VU124825 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2026-29063
CWE-1321 Medium
No
No
5.3.1 Patch 7, 5.4.0 02.04.2026 SB2026040246
SB2026040612
SB2026040627
and 29 more
#VU123884 - Integer overflow
CVE-2026-23865
CWE-190 Medium
No
No
5.3.1 Patch 7, 5.4.0 11.03.2026 SB2026031140
SB2026031141
SB2026031523
and 45 more
#VU121666 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2025-64718
CWE-1321 Medium
No
No
5.3.0 19.01.2026 SB2026011995
SB2026011999
SB20260119100
and 25 more
#VU117483 - Improper input validation
CVE-2025-53066
CWE-20 Medium
No
No
5.3.0 22.10.2025 SB20251022107
SB20251022108
SB20251022109
and 118 more
#VU117484 - Improper input validation
CVE-2025-53057
CWE-20 Medium
No
No
5.3.0 22.10.2025 SB20251022107
SB20251022108
SB20251022109
and 121 more
#VU112130 - Heap-based Buffer Overflow
CVE-2025-2900
CWE-122 High
No
No
5.2.1 03.07.2025 SB2025070313
SB2025070316
SB2025070318
and 22 more


Showing elements 1 - 20 out of 51