Known vulnerabilities in IBM Cloud Pak System - page 9

Software CPE: cpe:2.3:a:ibm_corporation:ibm_cloud_pak_system:*:*:*:*:*:*:*:*
Total vulnerabilities: 653
Public exploits: 48
Known exploited (KEV): 16
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting IBM Cloud Pak System IBM Cloud Pak System is affected by 653 known vulnerabilities: 8 critical, 80 high, 388 medium, 177 low Critical High Medium Low

Vulnerabilities (653)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU103053 - Inefficient Regular Expression Complexity
CVE-2021-3777
CWE-1333 Medium
No
No
2.3.3.5 20.01.2025 SB2025012074
SB2025012076
#VU98810 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2024-45072
CWE-611 Medium
No
No
- 18.10.2024 SB2024101807
SB2024101813
SB20241022399
and 11 more
#VU98730 - Improper input validation
CVE-2024-45085
CWE-20 Medium
No
No
- 16.10.2024 SB2024101654
SB2024101816
SB2024101820
and 8 more
#VU98137 - Allocation of Resources Without Limits or Throttling
CVE-2024-40094
CWE-770 Medium
Available
No
2.3.4.1 iFix 1, 2.3.5.0 08.10.2024 SB2024100835
SB2024100936
SB2024101593
and 27 more
#VU98136 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-45073
CWE-79 Low
No
No
- 08.10.2024 SB2024100833
SB2024100834
SB2024100942
and 12 more
#VU96897 - Buffer Underwrite ('Buffer Underflow')
CVE-2024-45490
CWE-124 High
No
No
2.3.4.1 iFix 1 05.09.2024 SB20240905100
SB20240905101
SB20240905102
and 113 more
#VU96059 - Exposure of sensitive information to an unauthorized actor
CVE-2023-50315
CWE-200 Low
No
No
- 15.08.2024 SB2024081567
SB2024082831
SB2024082846
and 9 more
#VU95625 - Improper input validation
CVE-2024-35154
CWE-20 Low
No
No
2.3.4.1 iFix 1 09.08.2024 SB2024080941
SB2024081324
SB2024081439
and 11 more
#VU94637 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2024-37532
CWE-451 Medium
No
No
2.3.4.1 iFix 1 22.07.2024 SB2024072221
SB2024072222
SB2024072306
and 14 more
#VU92222 - Permissions, Privileges, and Access Controls
CVE-2024-37081
CWE-264 Low
Available
No
2.3.4.1 18.06.2024 SB20240618111
SB2024072918
SB2025012104
and 1 more
#VU92221 - Heap-based Buffer Overflow
CVE-2024-37080
CWE-122 High
No
No
2.3.4.1 18.06.2024 SB20240618111
SB2024072918
SB2025012104
and 1 more
#VU92220 - Heap-based Buffer Overflow
CVE-2024-37079
CWE-122 High
No
Exploited
2.3.4.1 18.06.2024 SB20240618111
SB2024072918
SB2025012104
and 1 more
#VU89711 - NULL Pointer Dereference
CVE-2024-33600
CWE-476 Medium
No
No
2.3.5.0 21.05.2024 SB2024052147
SB2024052148
SB2024052305
and 83 more
#VU89710 - Allocation of Resources Without Limits or Throttling
CVE-2024-33601
CWE-770 Low
No
No
2.3.5.0 21.05.2024 SB2024052147
SB2024052148
SB2024052305
and 82 more
#VU89292 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2024-26026
CWE-89 High
Available
No
2.3.4.1, 2.3.5.0 09.05.2024 SB2024050926
SB2025030416
#VU88977 - Resource exhaustion
CVE-2024-25026
CWE-400 Medium
No
No
2.3.4.1, 2.3.5.0 24.04.2024 SB2024042458
SB2024042525
SB2024042626
and 68 more
#VU88136 - Resource exhaustion
CVE-2024-27268
CWE-400 Medium
No
No
2.3.4.1, 2.3.5.0 04.04.2024 SB2024040437
SB2024050803
SB2024052003
and 40 more
#VU67253 - Authorization Bypass Through User-Controlled Key
CVE-2022-0639
CWE-639 Medium
No
No
2.3.3.5 13.09.2022 SB2022021730
SB2022091358
SB2023032938
and 3 more
#VU57967 - Improper input validation
CVE-2021-3807
CWE-20 Medium
No
No
2.3.3.5 05.11.2021 SB2021110513
SB2021112603
SB2022042257
and 51 more
#VU52986 - Incorrect Regular Expression
CVE-2021-28092
CWE-185 Low
No
No
2.3.3.5 10.05.2021 SB2021051003
SB2021051004
SB2023092211
and 1 more


Showing elements 161 - 180 out of 653