6.3
CVE-2025-36063 - Multiple vulnerabilities were addressed in IBM Sterling Connect:Express for UNIX.
IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0 5.2.0.00 through 5.2.0.12 does not invalidate session after a logout which could allow an authenticated user to impersonate another user on the system.
5.5
CVE-2025-36058 - Multiple security vulnerabilities are addressed in IBM Business Automation Workflow Containers fixeโฆ
IBM Business Automation Workflow containers 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 Interim Fix 006. IBM Cloud Pak for Business Automation and IBM Business Automation Workflow containers may disclose sensitve configuration information โฆ
4.7
CVE-2025-36059 - Multiple security vulnerabilities are addressed in IBM Business Automation Workflow Containers fixeโฆ
IBM Business Automation Workflow containers 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 Interim Fix 006. IBM Cloud Pak for Business Automation could allow a local user with access to the container to execute OS system calls.
8.8
CVE-2025-33015 - Multiple Vulnerabilities in IBM Concert Software
IBM Concert 1.0.0 through 2.1.0 is vulnerable to malicious file upload by not validating the content of the file uploaded to the web interface.
5.9
CVE-2025-1722 - Multiple Vulnerabilities in IBM Concert Software
IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.
5.9
CVE-2025-1719 - Multiple Vulnerabilities in IBM Concert Software
IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.
8.4
CVE-2025-14115 - IBM Sterling Connect:Direct for UNIX Container is affected by vulnerability where hard-coded credenโฆ
IBM Sterling Connect:Direct for UNIX Container 6.3.0.0 through 6.3.0.6 Interim Fix 016, and 6.4.0.0 through 6.4.0.3 Interim Fix 019 IBMยฎ Sterling Connect:Direct for UNIX contains hard-coded credentials, such as a password or cryptographic key, which it uses forย its own inbound authentication, outboโฆ
4.9
CVE-2025-13925 - Multiple vulnerabilities in IBM Aspera Console
IBM Aspera Console 3.4.7 stores potentially sensitive information in log files that could be read by a local privileged user.
8.4
CVE-2025-12985 - License Service: Privilege escalation vulnerability
IBM Licensing Operator incorrectly assigns privileges to security critical files which could allow a local root escalation inside a container running the IBM Licensing Operator image.
6.1
CVE-2025-54817 -
A reflected cross-site scripting (xss) vulnerability exists in the autoPurge functionality of MedDream PACS Premium 7.3.6.870. A specially crafted malicious url can lead to arbitrary javascript code execution. An attacker can provide a URL to a malicious website to trigger this vulnerability.