Known vulnerabilities in IBM Automation Decision Services

Software CPE: cpe:2.3:a:ibm_corporation:ibm_automation_decision_services:*:*:*:*:*:*:*:*
Total vulnerabilities: 117
Public exploits: 15
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting IBM Automation Decision Services IBM Automation Decision Services is affected by 117 known vulnerabilities: 1 critical, 8 high, 74 medium, 34 low Critical High Medium Low

Vulnerabilities (117)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU144038 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2026-1002
CWE-444 Low
No
No
24.0.0.0.9, 24.0.1.0.8, 25.0.0.0.4 18.08.2026 SB2026081830
SB2026081831
SB2026081835
and 2 more
#VU143925 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2026-33672
CWE-1321 Medium
No
No
24.0.0.0.9, 24.0.1.0.8, 25.0.0.0.4 18.08.2026 SB2026081815
SB2026081816
SB2026081831
and 1 more
#VU139384 - Inefficient Regular Expression Complexity
CVE-2026-33671
CWE-1333 Medium
No
No
24.0.0.0.9, 24.0.1.0.8, 25.0.0.0.4 26.07.2026 SB2026072609
SB2026072616
SB2026081816
and 2 more
#VU127582 - Allocation of Resources Without Limits or Throttling
CVE-2026-22036
CWE-770 Medium
No
No
24.0.0.0.9, 24.0.1.0.8, 25.0.0.0.4 24.04.2026 SB20260424138
SB20260424156
SB20260424157
and 6 more
#VU125981 - Exposure of sensitive information to an unauthorized actor
CVE-2026-40895
CWE-200 Medium
No
No
24.0.0.0.9, 24.0.1.0.8, 25.0.0.0.4 14.04.2026 SB20260414106
SB2026062434
SB20260625284
and 13 more
#VU124825 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2026-29063
CWE-1321 Medium
No
No
24.0.0.0.9, 24.0.1.0.8, 25.0.0.0.4 02.04.2026 SB2026040246
SB2026040612
SB2026040627
and 32 more
#VU124423 - Allocation of Resources Without Limits or Throttling
CVE-2026-33871
CWE-770 Medium
No
No
24.0.0.0.9, 24.0.1.0.8, 25.0.0.0.4 25.03.2026 SB2026032533
SB20260415180
SB20260422237
and 15 more
#VU124422 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2026-33870
CWE-444 Medium
Available
No
24.0.0.0.9, 24.0.1.0.8, 25.0.0.0.4 25.03.2026 SB2026032533
SB20260415180
SB2026042043
and 20 more
#VU123491 - Memory corruption
CVE-2026-29062
CWE-119 Medium
No
No
24.0.0.0.9, 24.0.1.0.8, 25.0.0.0.4 04.03.2026 SB2026030413
SB2026060232
SB2026060234
and 3 more
#VU120254 - Improper Handling of Length Parameter Inconsistency
CVE-2025-14847
CWE-130 High
Available
Exploited
24.0.0.0.8, 24.0.1.0.8 23.12.2025 SB2025122318
SB2026011607
SB2026012973
and 9 more
#VU119966 - Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVE-2025-67735
CWE-93 Medium
No
No
24.0.0.0.9, 24.0.1.0.8, 25.0.0.0.4 15.12.2025 SB2025121552
SB2025121974
SB2026012079
and 23 more
#VU118717 - Improper input validation
CVE-2025-47913
CWE-20 Low
No
No
23.0.1.0.6, 24.0.0.0.8, 25.0.0.0.3 24.11.2025 SB2025112448
SB2025112455
SB2025112456
and 53 more
#VU117334 - Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
CVE-2025-46653
CWE-338 Low
No
No
- 17.10.2025 SB2025101708
SB2025101766
SB2025120330
and 4 more
#VU115828 - Resource exhaustion
CVE-2025-6493
CWE-400 Medium
No
No
- 18.09.2025 SB20250918111
SB20250918112
SB2025112530
and 9 more
#VU113811 - Exposure of resource to wrong sphere
CVE-2025-49574
CWE-668 Low
No
No
23.0.1.0.6, 24.0.0.0.8, 25.0.0.0.3 12.08.2025 SB2025081226
SB2025100107
SB2025100114
and 9 more
#VU113173 - Use of Insufficiently Random Values
CVE-2025-7783
CWE-330 Medium
Available
No
23.0.1.0.6, 24.0.0.0.8, 25.0.0.0.3 23.07.2025 SB2025072332
SB2025072333
SB2025081876
and 62 more
#VU110251 - Exposure of sensitive information to an unauthorized actor
CVE-2025-4673
CWE-200 Low
No
No
- 07.06.2025 SB2025060701
SB2025060702
SB2025061002
and 35 more
#VU103322 - Out-of-bounds read
CVE-2024-36124
CWE-125 Medium
No
No
23.0.1.0.6, 24.0.0.0.8, 25.0.0.0.3 27.01.2025 SB2025012734
SB2025012735
SB2025013120
and 7 more
#VU89861 - Use After Free
CVE-2024-4741
CWE-416 Medium
No
No
- 29.05.2024 SB2024052912
SB2024060803
SB2024060804
and 88 more
#VU85808 - NULL Pointer Dereference
CVE-2024-0727
CWE-476 Medium
No
No
- 25.01.2024 SB2024012552
SB2024020525
SB2024021323
and 100 more


Showing elements 1 - 20 out of 117