Known vulnerabilities in InfoSphere Optim Archive Viewer

Software CPE: cpe:2.3:a:ibm_corporation:infosphere_optim_archive_viewer:*:*:*:*:*:*:*:*
Total vulnerabilities: 24
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.2

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting InfoSphere Optim Archive Viewer InfoSphere Optim Archive Viewer is affected by 24 known vulnerabilities: 5 high, 16 medium, 3 low Critical High Medium Low

Vulnerabilities (24)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU132376 - Out-of-bounds write
CVE-2026-41907
CWE-787 High
No
No
11.7.0.14 27.05.2026 SB2026052766
SB2026052768
SB2026060118
and 6 more
#VU128398 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-41205
CWE-22 Medium
No
No
11.7.0.14 28.04.2026 SB20260428216
SB2026050603
SB2026051399
and 2 more
#VU128397 - Improper input validation
CVE-2026-33750
CWE-20 Medium
No
No
11.7.0.14 28.04.2026 SB20260428215
SB20260428223
SB2026042934
and 6 more
#VU127969 - Improper Control of Generation of Code ('Code Injection')
CVE-2026-25755
CWE-94 High
No
No
11.7.0.14 27.04.2026 SB2026042735
SB2026060121
#VU127968 - Allocation of Resources Without Limits or Throttling
CVE-2026-25535
CWE-770 Medium
No
No
11.7.0.14 27.04.2026 SB2026042735
SB2026060121
#VU127967 - Improper Encoding or Escaping of Output
CVE-2026-25940
CWE-116 High
No
No
11.7.0.14 27.04.2026 SB2026042735
SB2026060121
#VU127966 - Allocation of Resources Without Limits or Throttling
CVE-2026-24133
CWE-770 Medium
No
No
1.7.0.13 FixPack 13 27.04.2026 SB2026042734
SB2026052633
#VU127963 - Improper Encoding or Escaping of Output
CVE-2026-24737
CWE-116 High
No
No
1.7.0.13 FixPack 13 27.04.2026 SB2026042734
SB2026052633
#VU126548 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2026-41066
CWE-611 Medium
No
No
11.7.0.14 20.04.2026 SB2026042075
SB2026051813
SB2026060115
and 7 more
#VU125804 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2026-2950
CWE-1321 Medium
No
No
11.7.0.14 10.04.2026 SB2026041094
SB2026042049
SB2026042720
and 11 more
#VU125803 - Improper Control of Generation of Code ('Code Injection')
CVE-2026-4800
CWE-94 High
No
No
11.7.0.14 10.04.2026 SB2026041094
SB20260410101
SB20260410102
and 53 more
#VU123997 - Improper input validation
CVE-2026-2391
CWE-20 Medium
No
No
11.7.0.14 13.03.2026 SB2026031335
SB2026031336
SB2026032417
and 11 more
#VU123607 - Creation of Temporary File in Directory with Insecure Permissions
CVE-2025-71176
CWE-379 Low
No
No
11.7.0.14 06.03.2026 SB2026030623
SB2026030633
SB20260507304
and 2 more
#VU123140 - Inefficient Regular Expression Complexity
CVE-2026-26996
CWE-1333 Medium
No
No
11.7.0.14 23.02.2026 SB2026022345
SB2026030633
SB2026032328
and 31 more
#VU121928 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2025-13465
CWE-1321 Medium
No
No
11.7.0.14 22.01.2026 SB2026012209
SB2026012701
SB2026012744
and 65 more
#VU121159 - Resource exhaustion
CVE-2025-15284
CWE-400 Medium
No
No
11.7.0.14 12.01.2026 SB2026011229
SB2026011326
SB2026011926
and 36 more
#VU114574 - Use of Cache Containing Sensitive Information
CVE-2025-57752
CWE-524 Medium
No
No
11.7.0.14 30.08.2025 SB2025083005
SB2025101766
SB2025120245
and 7 more
#VU114573 - Improper input validation
CVE-2025-55173
CWE-20 Low
No
No
11.7.0.14 30.08.2025 SB2025083004
SB2025101766
SB2025120245
and 7 more
#VU109922 - Missing Origin Validation in WebSockets
CVE-2025-48068
CWE-1385 Low
No
No
11.7.0.14 29.05.2025 SB2025052970
SB2025122227
SB2026010925
and 4 more
#VU53202 - Command injection
CVE-2021-23337
CWE-77 Medium
No
No
11.7.0.14 12.05.2021 SB2021021525
SB2021051230
SB2021062703
and 56 more


Showing elements 1 - 20 out of 24