IBM
Security Scorecard
Score
20F
Total CVEs
318
Patch Rate
23%
73 patched
Avg Response
1733d
days to patch
Critical Gaps
38
exploitable, no detection
Severity Breakdown
Critical3
High151
Medium127
Low31
Patch Status
Patched73 (23%)
Partial/Workaround3 (1%)
Unpatched242 (76%)
CVEs (322)
| CVE ID | Title | Severity | Score | Days | Patch |
|---|---|---|---|---|---|
| CVE-2025-12985 | IBM Licensing Operator Privilege Escalation | High | 8.4 | - | Patched |
| CVE-2025-14115 | IBM Sterling Connect:Direct for UNIX Container Hard-Coded Credentials Vulnerability | High | 8.4 | - | Patched |
| CVE-2025-1719 | Concert 1.x Data Breach | Medium | 5.9 | - | Patched |
| CVE-2025-1722 | IBM Concert Remote Information Disclosure | Medium | 5.9 | - | Patched |
| CVE-2025-36058 | IBM Business Automation Workflow Container Vulnerability | Medium | 5.5 | - | Patched |
| CVE-2025-36059 | IBM Business Automation Workflow Container Vulnerability | Medium | 4.7 | - | Patched |
| CVE-2025-36063 | IBM Sterling Connect:Express Adapter for Sterling B2B Integrator Remote Session Impersonation Vulnerability | Medium | 6.3 | - | Patched |
| CVE-2025-36065 | IBM Sterling Connect:Express Adapter for Sterling B2B Integrator | Medium | 6.3 | - | Patched |
| CVE-2025-36066 | IBM Sterling Connect:Express Adapter for Sterling B2B Integrator Cross-Site Scripting Vulnerability | Medium | 6.1 | - | Patched |
| CVE-2025-36113 | IBM Sterling Connect:Express Adapter for Sterling B2B Integrator Cross-Site Scripting Vulnerability | Medium | 5.4 | - | Patched |