
CVE-2025-0986 – IBM PowerVM Hypervisor data manipulation
https://notcve.org/view.php?id=CVE-2025-0986
28 Mar 2025 — IBM PowerVM Hypervisor FW1050.00 through FW1050.30 and FW1060.00 through FW1060.20 could allow a local user, under certain Linux processor combability mode configurations, to cause undetected data loss or errors when performing gzip compression using HW acceleration. • https://www.ibm.com/support/pages/node/7229349 • CWE-409: Improper Handling of Highly Compressed Data (Data Amplification) •

CVE-2023-38272 – IBM Cloud Pak System information disclosure
https://notcve.org/view.php?id=CVE-2023-38272
27 Mar 2025 — IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.36 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, 2.3.4.0, and 2.3.4.1 could allow a user with access to the network to obtain sensitive information from CLI arguments. • https://www.ibm.com/support/pages/node/7229212 • CWE-300: Channel Accessible by Non-Endpoint •

CVE-2023-37405 – IBM Cloud Pak System information disclosure
https://notcve.org/view.php?id=CVE-2023-37405
27 Mar 2025 — IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.36 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, 2.3.4.0, and 2.3.4.1 stores sensitive data in memory, that could be obtained by an unauthorized user. • https://www.ibm.com/support/pages/node/7229212 • CWE-311: Missing Encryption of Sensitive Data •

CVE-2025-1998 – IBM UrbanCode Deploy (UCD) / IBM DevOps Deploy information disclosure
https://notcve.org/view.php?id=CVE-2025-1998
27 Mar 2025 — IBM UrbanCode Deploy (UCD) through 7.1.2.21, 7.2 through 7.2.3.14, and 7.3 through 7.3.2.0 / IBM DevOps Deploy 8.0 through 8.0.1.4 and 8.1 through 8.1 stores potentially sensitive authentication token information in log files that could be read by a local user. • https://www.ibm.com/support/pages/node/7229034 • CWE-532: Insertion of Sensitive Information into Log File •

CVE-2025-1997 – IBM UrbanCode Deploy (UCD) / IBM DevOps Deploy HTML injection
https://notcve.org/view.php?id=CVE-2025-1997
27 Mar 2025 — IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.25, 7.1 through 7.1.2.21, 7.2 through 7.2.3.14, and 7.3 through 7.3.2.0 / IBM DevOps Deploy 8.0 through 8.0.1.4 and 8.1 through 8.1 could allow unauthorized access to other services or potential exposure of sensitive data due to missing authentication in its Agent Relay service. • https://www.ibm.com/support/pages/node/7229035 • CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) •

CVE-2024-56469 – IBM UrbanCode Deploy (UCD) / IBM DevOps Deploy missing authentication
https://notcve.org/view.php?id=CVE-2024-56469
27 Mar 2025 — IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.22, 7.2 through 7.2.3.15, and 7.3 through 7.3.2.10 / IBM DevOps Deploy 8.0 through 8.0.1.5 and 8.1 through 8.1.0.1 could allow unauthorized access to other services or potential exposure of sensitive data due to missing authentication in its Agent Relay service. • https://www.ibm.com/support/pages/node/7229031 • CWE-306: Missing Authentication for Critical Function •

CVE-2022-39163 – IBM Cognos Controller HTTP response smuggling
https://notcve.org/view.php?id=CVE-2022-39163
26 Mar 2025 — IBM Cognos Controller 11.0.0 through 11.1.0 is vulnerable to a Client-Side Desync (CSD) attack where an attacker could exploit a desynchronized browser connection that could lead to further cross-site scripting (XSS) attacks. • https://www.ibm.com/support/pages/node/7192746 • CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') •

CVE-2024-31896 – IBM SPSS Statistics information disclosure
https://notcve.org/view.php?id=CVE-2024-31896
25 Mar 2025 — IBM SPSS Statistics 26.0, 27.0.1, 28.0.1, and 29.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM SPSS Statistics 26.0, 27.0.1, 28.0.1, and 29.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. • https://www.ibm.com/support/pages/node/7228971 • CWE-327: Use of a Broken or Risky Cryptographic Algorithm •

CVE-2023-43029 – IBM Storage Virtualize vSphere Remote Plug-in information disclosure
https://notcve.org/view.php?id=CVE-2023-43029
21 Mar 2025 — IBM Storage Virtualize vSphere Remote Plug-in 1.0 and 1.1 could allow a remote user to obtain sensitive credential information after deployment. • https://www.ibm.com/support/pages/node/7228722 • CWE-526: Cleartext Storage of Sensitive Information in an Environment Variable •

CVE-2024-51459 – IBM InfoSphere Server Information command execution
https://notcve.org/view.php?id=CVE-2024-51459
19 Mar 2025 — IBM InfoSphere Information Server 11.7 could allow a local user to execute privileged commands due to the improper handling of permissions. • https://www.ibm.com/support/pages/node/7185056 • CWE-280: Improper Handling of Insufficient Permissions or Privileges •