IBM

IBM

Top 1K site
RecognitionPartial Safe Harbor

Program Details

Handle
ibm
Managed
No

Response Metrics

Response Time
59 days
Resolution Time
823 days
Response Efficiency
90%

Scope (3 targets)

other: 3

Bounty splitting: No

In Scope

  • IBM Products other recognition only
  • IBM Tokens & Secrets other recognition only
  • IBM Websites other recognition only

Known Exploited Vulnerabilities 8CVEs

2 linked to ransomware campaigns

  • CVE-2026-9198LangflowAug 4, 202660.6% EPSS

    Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.

  • CVE-2022-47986Aspera FaspexFeb 21, 2023100.0% EPSS

    IBM Aspera Faspex could allow a remote attacker to execute code on the system, caused by a YAML deserialization flaw.

  • CVE-2013-3993InfoSphere BigInsightsMay 25, 20225.2% EPSS

    Certain APIs within BigInsights can take invalid input that might allow attackers unauthorized access to read, write, modify, or delete data.

  • CVE-2015-7450WebSphere Application Server and Server Hypervisor EditionJan 10, 202297.7% EPSS

    Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands

  • CVE-2020-4430Data Risk ManagerNov 3, 202168.5% EPSS

    IBM Data Risk Manager contains a directory traversal vulnerability that could allow a remote authenticated attacker to traverse directories and send a specially crafted URL request to download arbitrary files from the system.

  • CVE-2020-4427Data Risk ManagerNov 3, 202170.0% EPSS

    IBM Data Risk Manager contains a security bypass vulnerability that could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to bypass the authentication process and gain full administrative access to the system.

  • CVE-2020-4428Data Risk ManagerNov 3, 202161.7% EPSS

    IBM Data Risk Manager contains an unspecified vulnerability which could allow a remote, authenticated attacker to execute commands on the system.�

  • CVE-2019-4716Planning AnalyticsNov 3, 202186.4% EPSS

    IBM Planning Analytics is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting.

security.txt

Contact
https://www.ibm.com/trust/security-psirt, https://hackerone.com/ibm?type=team, mailto:[email protected]
Encryption
https://www.ibm.com/downloads/documents/us-en/15db45ee46d2037d
Acknowledgments
https://www.ibm.com/blogs/psirt/ibm-acknowledgement/
Expires
Oct 15, 2026
View raw security.txt →