Third Party Index

IBM

ibm.com

Transparency

Fair

Breakdown
Subprocessor listnot found0 / 30
Processing locationsno list0 / 8
Purposesno list0 / 7
Data processing addendum12 / 12
Trust center8 / 8
Privacy policy6 / 6
security.txt6 / 6
Security page5 / 5
Status pagenot found0 / 5
Vulnerability disclosurenot found0 / 5
Pages still reachable8 / 8
Total45 / 100

Only documents we can retrieve count: a page behind a login or a broken link scores nothing.

Badge

IBM transparency rating

For IBM's own site; it updates with the rating.

<a href="https://thirdpartyindex.com/vendors/ibm"><img src="https://thirdpartyindex.com/badge/ibm.svg" alt="IBM transparency rating on Third Party Index" height="20"></a>
[![IBM transparency rating on Third Party Index](https://thirdpartyindex.com/badge/ibm.svg)](https://thirdpartyindex.com/vendors/ibm)

Documents

DocumentVerifiedChangedEvidence
Trust center snapshot
Data processing addendum snapshot
Privacy policy snapshot
Terms snapshot
Security page snapshot
security.txt snapshot

Subprocessors

None extracted.

Listed as a subprocessor by (14)

Purposes as each company states them.

Security record

What public security catalogs list for IBM, in their words.

Known exploited vulnerabilities

8 vulnerabilities in IBM's software that CISA lists as exploited in the wild.

CVEProductVulnerabilityListed
CVE-2026-9198LangflowIBM Langflow Code Injection Vulnerability evidence
CVE-2022-47986Aspera FaspexIBM Aspera Faspex Code Execution Vulnerability used by ransomware evidence
CVE-2013-3993InfoSphere BigInsightsIBM InfoSphere BigInsights Invalid Input Vulnerability used by ransomware evidence
CVE-2015-7450WebSphere Application Server and Server Hypervisor EditionIBM WebSphere Application Server and Server Hypervisor Edition Code Injection. evidence
CVE-2019-4716Planning AnalyticsIBM Planning Analytics Remote Code Execution Vulnerability evidence
CVE-2020-4427Data Risk ManagerIBM Data Risk Manager Security Bypass Vulnerability evidence
CVE-2020-4428Data Risk ManagerIBM Data Risk Manager Remote Code Execution Vulnerability evidence
CVE-2020-4430Data Risk ManagerIBM Data Risk Manager Directory Traversal Vulnerability evidence

Source: CISA Known Exploited Vulnerabilities catalog.

Changes

None since tracking began.