Known vulnerabilities in IBM Cloud Pak for Data System

Software CPE: cpe:2.3:a:ibm_corporation:ibm_cloud_pak_for_data_system:*:*:*:*:*:*:*:*
Total vulnerabilities: 98
Public exploits: 9
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting IBM Cloud Pak for Data System IBM Cloud Pak for Data System is affected by 98 known vulnerabilities: 1 critical, 14 high, 58 medium, 24 low Critical High Medium Low

Vulnerabilities (98)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU132104 - Resource exhaustion
CVE-2026-48525
CWE-400 Medium
No
No
8.10.26.06.SP2 21.05.2026 SB2026052164
SB2026061959
SB2026061972
and 3 more
#VU132103 - Improper Cleanup on Thrown Exception
CVE-2026-48524
CWE-460 Low
No
No
8.10.26.06.SP2 21.05.2026 SB2026052164
SB2026061959
SB2026061972
and 2 more
#VU132101 - Server-Side Request Forgery (SSRF)
CVE-2026-48522
CWE-918 Low
No
No
8.10.26.06.SP2 21.05.2026 SB2026052164
SB2026061959
SB2026061972
and 3 more
#VU132100 - Improper Verification of Cryptographic Signature
CVE-2026-48523
CWE-347 Low
No
No
8.10.26.06.SP2 21.05.2026 SB2026052164
SB2026061959
SB2026061972
and 3 more
#VU131979 - Use of a Broken or Risky Cryptographic Algorithm
CVE-2026-44405
CWE-327 Low
No
No
8.10.26.06.SP2 20.05.2026 SB2026052061
SB2026052062
SB20260715112
and 2 more
#VU130907 - Exposure of sensitive information to an unauthorized actor
CVE-2026-44431
CWE-200 Medium
No
No
8.10.26.06.SP2 09.05.2026 SB20260509126
SB2026051588
SB2026051589
and 36 more
#VU130906 - Improper Handling of Highly Compressed Data (Data Amplification)
CVE-2026-44432
CWE-409 Medium
No
No
8.10.26.06.SP2 09.05.2026 SB20260509126
SB2026052935
SB2026060609
and 12 more
#VU125339 - Out-of-bounds read
CVE-2026-39892
CWE-125 Low
No
No
- 08.04.2026 SB2026040897
SB20260408162
SB20260408163
and 10 more
#VU125338 - Improper Certificate Validation
CVE-2026-34073
CWE-295 Medium
No
No
- 08.04.2026 SB2026040896
SB20260408119
SB20260408120
and 9 more
#VU123428 - Stack-based buffer overflow
CVE-2026-28422
CWE-121 High
No
No
- 03.03.2026 SB2026030330
SB2026030546
SB2026030620
and 9 more
#VU123427 - Heap-based Buffer Overflow
CVE-2026-28421
CWE-122 High
No
No
- 03.03.2026 SB2026030329
SB2026030546
SB2026030620
and 25 more
#VU123426 - Heap-based Buffer Overflow
CVE-2026-28420
CWE-122 Medium
No
No
- 03.03.2026 SB2026030326
SB2026030546
SB2026030620
and 9 more
#VU123425 - Heap-based Buffer Overflow
CVE-2026-28419
CWE-122 High
No
No
- 03.03.2026 SB2026030322
SB2026030546
SB2026030620
and 9 more
#VU123424 - Heap-based Buffer Overflow
CVE-2026-28418
CWE-122 High
No
No
- 03.03.2026 SB2026030318
SB2026030546
SB2026030620
and 9 more
#VU123423 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2026-28417
CWE-78 High
No
No
- 03.03.2026 SB2026030317
SB2026030620
SB2026030621
and 28 more
#VU121072 - Improper Handling of Highly Compressed Data (Data Amplification)
CVE-2026-21441
CWE-409 Medium
No
No
1.0.10.0 07.01.2026 SB2026010780
SB2026011269
SB2026011328
and 89 more
#VU112141 - Improper input validation
CVE-2024-6844
CWE-20
No
No
1.0.10.0 03.07.2025 SB2025070336
SB2025070342
SB2025080147
and 6 more
#VU112140 - Security Features
CVE-2024-6839
CWE-254 Medium
No
No
1.0.10.0 03.07.2025 SB2025070336
SB2025070342
SB2025080147
and 6 more
#VU99567 - Resource exhaustion
CVE-2024-49767
CWE-400 Medium
No
No
1.0.10.0 31.10.2024 SB2024103173
SB2024103176
SB2024110601
and 30 more
#VU99566 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-49766
CWE-22 Medium
No
No
1.0.10.0 31.10.2024 SB2024103173
SB2024121313
SB2024121851
and 16 more


Showing elements 1 - 20 out of 98