Known vulnerabilities in watsonx Orchestrate Developer Edition

Software CPE: cpe:2.3:a:ibm_corporation:watsonx_orchestrate_developer_edition:*:*:*:*:*:*:*:*
Total vulnerabilities: 51
Public exploits: 3
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting watsonx Orchestrate Developer Edition watsonx Orchestrate Developer Edition is affected by 51 known vulnerabilities: 10 high, 29 medium, 12 low Critical High Medium Low

Vulnerabilities (51)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU123981 - Resource exhaustion
CVE-2025-58181
CWE-400 Medium
No
No
2.3.0 13.03.2026 SB2025122903
SB2026031315
SB2026031321
and 16 more
#VU123885 - Insecure Default Initialization of Resource
CVE-2025-66414
CWE-1188 High
No
No
2.3.0 11.03.2026 SB2026031142
SB2026032627
#VU123307 - Incomplete Filtering of Special Elements
CVE-2025-12758
CWE-791 High
No
No
2.3.0 26.02.2026 SB2026022657
SB2026022658
SB2026032627
and 1 more
#VU121666 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2025-64718
CWE-1321 Medium
No
No
2.3.0 19.01.2026 SB2026011995
SB2026011999
SB20260119100
and 25 more
#VU121638 - Improper Verification of Cryptographic Signature
CVE-2025-65945
CWE-347 Medium
No
No
2.3.0 19.01.2026 SB2026011925
SB2026011926
SB2026012034
and 14 more
#VU120612 - Out-of-bounds read
CVE-2025-47914
CWE-125 Medium
No
No
2.3.0 29.12.2025 SB2025122903
SB2025122904
SB2025123103
and 14 more
#VU119401 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-64756
CWE-78 Medium
No
No
2.3.0 09.12.2025 SB2025120922
SB2025120932
SB20251210178
and 18 more
#VU119133 - Integer overflow
CVE-2025-66030
CWE-190 Medium
No
No
2.3.0 04.12.2025 SB2025120419
SB2025122219
SB2026012115
and 9 more
#VU119132 - Uncontrolled Recursion
CVE-2025-66031
CWE-674 Medium
No
No
2.3.0 04.12.2025 SB2025120419
SB2025120930
SB20251210178
and 15 more
#VU119131 - Interpretation Conflict
CVE-2025-12816
CWE-436 Medium
No
No
2.3.0 04.12.2025 SB2025120419
SB2025122219
SB20260116128
and 19 more
#VU118717 - Improper input validation
CVE-2025-47913
CWE-20 Low
No
No
2.3.0 24.11.2025 SB2025112448
SB2025112455
SB2025112456
and 53 more
#VU118206 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2025-57319
CWE-1321 Medium
No
No
2.3.0 07.11.2025 SB2025110782
SB2025121603
SB2026010606
and 4 more
#VU107611 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2024-6827
CWE-444 High
No
No
2.0.0 18.04.2025 SB2025041831
SB2025041832
SB2025041834
and 15 more
#VU105783 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2025-26791
CWE-79 Low
No
No
1.15.0 17.03.2025 SB2025031740
SB2025031741
SB2025031771
and 35 more
#VU100921 - Incorrect Regular Expression
CVE-2024-21538
CWE-185 Medium
No
No
2.3.0 26.11.2024 SB2024112627
SB2024112629
SB2024120325
and 67 more
#VU89167 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2024-1135
CWE-444 Medium
No
No
2.3.0 06.05.2024 SB2024050631
SB2024050632
SB2024050633
and 40 more
#VU87734 - Resource exhaustion
CVE-2024-28863
CWE-400 Medium
No
No
1.15.0 22.03.2024 SB2024032234
SB2024052306
SB2024061114
and 30 more
#VU81307 - Improper input validation
CVE-2023-44270
CWE-20 Low
No
No
1.15.0 02.10.2023 SB2023100210
SB2023111710
SB2023112080
and 28 more
#VU76185 - Incorrect Regular Expression
CVE-2021-3803
CWE-185 Medium
No
No
1.15.0 16.05.2023 SB2021091716
SB2023051651
SB2023053029
and 12 more
#VU19305 - Improper Control of Generation of Code ('Code Injection')
CVE-2018-16487
CWE-94 High
No
No
2.0.0 22.07.2019 SB2019020111
SB2022062806
SB2022101801
and 13 more


Showing elements 1 - 20 out of 51