Known vulnerabilities in IBM Cloud Pak System - page 4

Software CPE: cpe:2.3:a:ibm_corporation:ibm_cloud_pak_system:*:*:*:*:*:*:*:*
Total vulnerabilities: 653
Public exploits: 48
Known exploited (KEV): 16
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting IBM Cloud Pak System IBM Cloud Pak System is affected by 653 known vulnerabilities: 8 critical, 80 high, 388 medium, 177 low Critical High Medium Low

Vulnerabilities (653)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU131921 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')
CVE-2026-40175
CWE-113 Medium
No
No
2.3.5.1 20.05.2026 SB2026052045
SB2026052051
SB2026052052
and 21 more
#VU127606 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')
CVE-2026-42035
CWE-113 Medium
No
No
2.3.5.1 24.04.2026 SB20260424169
SB2026061912
SB2026061913
and 15 more
#VU127603 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2026-42033
CWE-1321 Medium
No
No
2.3.5.1 24.04.2026 SB20260424169
SB2026061954
SB2026061992
and 11 more
#VU127602 - Allocation of Resources Without Limits or Throttling
CVE-2026-42034
CWE-770 Medium
No
No
2.3.5.1 24.04.2026 SB20260424169
SB2026062221
SB2026062508
and 5 more
#VU127601 - Allocation of Resources Without Limits or Throttling
CVE-2026-42036
CWE-770 Medium
No
No
2.3.5.1 24.04.2026 SB20260424169
SB2026062221
SB2026062508
and 5 more
#VU127599 - Improper Access Control
CVE-2026-42038
CWE-284 Medium
No
No
2.3.5.1 24.04.2026 SB20260424169
SB2026061992
SB2026061993
and 9 more
#VU127598 - Uncontrolled Recursion
CVE-2026-42039
CWE-674 Medium
No
No
2.3.5.1 24.04.2026 SB20260424169
SB2026061954
SB2026062221
and 6 more
#VU127597 - Null Byte Interaction Error (Poison Null Byte)
CVE-2026-42040
CWE-626 Low
No
No
2.3.5.1 24.04.2026 SB20260424169
SB2026062221
SB2026062508
and 5 more
#VU127596 - Permissive List of Allowed Inputs
CVE-2026-42042
CWE-183 Medium
No
No
2.3.5.1 24.04.2026 SB20260424169
SB2026062221
SB2026062508
and 5 more
#VU127595 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2026-42041
CWE-1321 Medium
No
No
2.3.5.1 24.04.2026 SB20260424169
SB2026061954
SB2026062221
and 8 more
#VU127594 - Permissive List of Allowed Inputs
CVE-2026-42043
CWE-183 Medium
No
No
2.3.5.1 24.04.2026 SB20260424169
SB2026061954
SB2026061999
and 10 more
#VU127593 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2026-42044
CWE-1321 Medium
No
No
2.3.5.1 24.04.2026 SB20260424168
SB2026062221
SB2026062508
and 8 more
#VU127592 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2026-42264
CWE-1321 Medium
No
No
2.3.5.1 24.04.2026 SB20260424168
SB2026061999
SB20260619101
and 9 more
#VU125750 - Server-Side Request Forgery (SSRF)
CVE-2025-62718
CWE-918 High
No
No
2.3.5.1 10.04.2026 SB2026041001
SB2026050419
SB2026050715
and 29 more
#VU122452 - Improper Check for Unusual or Exceptional Conditions
CVE-2026-25639
CWE-754 Medium
Available
No
2.3.5.1 09.02.2026 SB2026020914
SB2026022201
SB2026022202
and 23 more
#VU116193 - Improper input validation
CVE-2025-41250
CWE-20 Medium
No
No
2.3.6.1 30.09.2025 SB2025093031
SB2026021319
#VU114124 - Stack-based buffer overflow
CVE-2025-33092
CWE-121 Medium
No
No
2.3.6.1 15.08.2025 SB20250815114
SB2025081836
SB2025090308
and 5 more
#VU114105 - Stack-based buffer overflow
CVE-2024-51473
CWE-121 High
No
No
2.3.6.1 15.08.2025 SB2025081511
SB2025081836
SB2025090308
and 4 more
#VU113509 - Improper input validation
CVE-2025-41241
CWE-20 Low
No
No
2.3.6.1 30.07.2025 SB2025073050
SB2026021319
#VU111225 - Integer overflow
CVE-2025-6021
CWE-190 High
No
No
2.3.6.1 17.06.2025 SB2025061921
SB2025062408
SB2025062747
and 63 more


Showing elements 61 - 80 out of 653