Known vulnerabilities in IBM Cloud Object Storage Systems
Vendor:
IBM Corporation
Software:
IBM Cloud Object Storage Systems
Software CPE:
cpe:2.3:a:ibm_corporation:ibm_cloud_object_storage_systems:*:*:*:*:*:*:*:*
Website:
https://www.ibm.com/us-en
Total vulnerabilities:
147
Public exploits:
9
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
3.20.0.91
3.20.1.84
3.20.0.43
3.20.0.69
3.19.2.72
3.19.0.54
3.18.5.48
3.19.1.36
3.19.0.40
3.18.5.40
3.18.0.84
3.18.0.75
3.18.4.45
3.18.2.45
3.18.0.50
3.18.1.45
3.18.0.40
3.18.0.21
3.17.0.131
3.17.0.128
3.17.5.100
3.17.0.124
3.17.5.86
3.17.0.121
3.17.5.79
3.16.0.127
3.16.7.63
3.16.7.62
3.16.7.61
3.16.7.60
3.16.7.59
3.16.7.58
3.16.7.57
3.16.7.56
3.16.7.54
3.16.7.53
3.16.7.52
3.16.7.51
3.16.7.50
3.16.7.49
3.16.7.48
3.16.7.47
3.16.7.46
3.16.7.45
3.16.7.44
3.16.7.43
3.16.7.42
3.16.7.41
3.16.7.40
3.16.7.39
3.16.7.38
3.16.7.37
3.16.7.36
3.16.7.35
3.16.7.34
3.16.7.33
3.16.7.32
3.16.7.31
3.16.7.30
3.16.7.29
3.16.7.28
3.16.7.27
3.16.7.26
3.16.7.25
3.16.7.24
3.16.7.23
3.16.7.22
3.16.7.21
3.16.7.20
3.16.7.19
3.16.7.18
3.16.7.17
3.16.7.16
3.16.7.15
3.16.7.14
3.16.7.13
3.16.7.12
3.16.7.11
3.16.7.10
3.16.7.9
3.16.7.8
3.16.7.7
3.16.7.6
3.16.7.5
3.16.7.4
3.16.7.3
3.16.7.2
3.16.7.1
3.16.7.0
3.16.0.121
3.16.7.55
3.16.5.58
3.16.5.50
3.16.3.36
Vulnerabilities (147)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU132273 - Incorrect Calculation CVE-2025-14813 |
CWE-682 | Medium | 3.20.0.91, 3.20.1.84 | 25.05.2026 |
SB2026052529 SB2026052540 SB2026052541 and 14 more |
||
| #VU132259 - Covert Timing Channel CVE-2026-5598 |
CWE-385 | Medium | 3.20.0.91, 3.20.1.84 | 25.05.2026 |
SB2026052530 SB2026052544 SB2026052931 and 12 more |
||
| #VU128324 - Insertion of Sensitive Information Into Sent Data CVE-2025-67721 |
CWE-201 | Medium | 3.20.0.43, 3.20.0.69 | 28.04.2026 |
SB2026042867 SB2026052714 |
||
| #VU125339 - Out-of-bounds read CVE-2026-39892 |
CWE-125 | Low | 3.20.0.91, 3.20.1.84 | 08.04.2026 |
SB2026040897 SB20260408162 SB20260408163 and 10 more |
||
| #VU124874 - Insufficient Verification of Data Authenticity CVE-2026-26007 |
CWE-345 | Medium | 3.20.0.43, 3.20.0.69 | 06.04.2026 |
SB2026040616 SB2026040617 SB2026040618 and 28 more |
||
| #VU124872 - Use of Cache Containing Sensitive Information CVE-2026-27205 |
CWE-524 | Medium | 3.20.0.43, 3.20.0.69 | 06.04.2026 |
SB2026040613 SB2026040615 SB2026040617 and 13 more |
||
| #VU122270 - Resource exhaustion CVE-2026-23490 |
CWE-400 | Medium | 3.20.0.43, 3.20.0.69 | 03.02.2026 |
SB2026020365 SB2026020366 SB2026020370 and 51 more |
||
| #VU121008 - Insecure Automated Optimizations CVE-2023-52971 |
CWE-1038 | Low | 3.20.0.43, 3.20.0.69 | 07.01.2026 |
SB2025122915 SB2026010703 SB2026010704 and 5 more |
||
| #VU120623 - Insecure Automated Optimizations CVE-2023-52970 |
CWE-1038 | Low | 3.20.0.43, 3.20.0.69 | 29.12.2025 |
SB2025122915 SB2025122918 SB2025122926 and 12 more |
||
| #VU120622 - Insecure Automated Optimizations CVE-2023-52969 |
CWE-1038 | Low | 3.20.0.43, 3.20.0.69 | 29.12.2025 |
SB2025122915 SB2025122918 SB2025122920 and 16 more |
||
| #VU120607 - Stack-based buffer overflow CVE-2025-68615 |
CWE-121 | Critical | 3.20.0.43, 3.20.0.69 | 26.12.2025 |
SB20251226349 SB2026010785 SB2026011301 and 43 more |
||
| #VU120231 - Improper Validation of Certificate with Host Mismatch CVE-2025-68161 |
CWE-297 | Medium | 3.20.0.43, 3.20.0.69 | 22.12.2025 |
SB2025122245 SB2026012084 SB2026012087 and 98 more |
||
| #VU119966 - Improper Neutralization of CRLF Sequences ('CRLF Injection') CVE-2025-67735 |
CWE-93 | Medium | 3.20.0.43, 3.20.0.69 | 15.12.2025 |
SB2025121552 SB2025121974 SB2026012079 and 21 more |
||
| #VU119150 - Integer overflow CVE-2025-55753 |
CWE-190 | Low | 3.20.0.43, 3.20.0.69 | 04.12.2025 |
SB2025120441 SB2025121923 SB2025121940 and 31 more |
||
| #VU119148 - Server-Side Request Forgery (SSRF) CVE-2025-59775 |
CWE-918 | Medium | 3.20.0.43, 3.20.0.69 | 04.12.2025 |
SB2025120441 SB2026010820 SB20260114117 and 10 more |
||
| #VU119146 - Improper input validation CVE-2025-66200 |
CWE-20 | Low | 3.20.0.43, 3.20.0.69 | 04.12.2025 |
SB2025120441 SB2025121923 SB2025122202 and 30 more |
||
| #VU117436 - Allocation of Resources Without Limits or Throttling CVE-2025-8916 |
CWE-770 | Medium | 3.20.0.43, 3.20.0.69 | 21.10.2025 |
SB2025102223 SB2025102241 SB2025102248 and 35 more |
||
| #VU101896 - Resource exhaustion CVE-2023-50572 |
CWE-400 | Medium | 3.20.0.43, 3.20.0.69 | 23.12.2024 |
SB2024122307 SB2024122308 SB2025070404 and 2 more |
||
| #VU87744 - Out-of-bounds write CVE-2024-29133 |
CWE-787 | High | 3.20.0.43, 3.20.0.69 | 22.03.2024 |
SB2024032169 SB2024032283 SB20240417122 and 40 more |
||
| #VU87706 - Out-of-bounds write CVE-2024-29131 |
CWE-787 | High | 3.20.0.43, 3.20.0.69 | 21.03.2024 |
SB2024032169 SB2024032283 SB20240417122 and 36 more |
Showing elements 1 - 20 out of 147