IBM
Top 1K siteProgram Details
- Handle
- ibm
- Managed
- No
Response Metrics
- Response Time
- 65 days
- Resolution Time
- 766 days
Scope (3 targets)
other: 3 In Scope
- IBM Products other recognition only
- IBM Tokens & Secrets other recognition only
- IBM Websites other recognition only
Known Exploited Vulnerabilities 8CVEs
2 linked to ransomware campaigns
Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.
IBM Aspera Faspex could allow a remote attacker to execute code on the system, caused by a YAML deserialization flaw.
Certain APIs within BigInsights can take invalid input that might allow attackers unauthorized access to read, write, modify, or delete data.
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands
IBM Data Risk Manager contains a directory traversal vulnerability that could allow a remote authenticated attacker to traverse directories and send a specially crafted URL request to download arbitrary files from the system.
IBM Data Risk Manager contains a security bypass vulnerability that could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to bypass the authentication process and gain full administrative access to the system.
IBM Data Risk Manager contains an unspecified vulnerability which could allow a remote, authenticated attacker to execute commands on the system.�
IBM Planning Analytics is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting.
security.txt
- Contact
- https://www.ibm.com/trust/security-psirt, https://hackerone.com/ibm?type=team, mailto:[email protected]
- Encryption
- https://www.ibm.com/downloads/documents/us-en/15db45ee46d2037d
- Acknowledgments
- https://www.ibm.com/blogs/psirt/ibm-acknowledgement/
- Expires
- Oct 21, 2026