Vulnerability index

Browse CVEs

385 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Spectrum Protect Plus CRITICAL 9.8
CVE-2020-4469EPSS 13%

IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted H…

Fix: after 10.1.5
Fix from $2,300 2020-06-15
Qradar Network Packet Capture CRITICAL 9.8
CVE-2019-4576

IBM QRadar Network Packet Capture 7.3.0 - 7.3.3 Patch 1 and 7.4.0 GA does not require that users should have strong passwords by default, which makes…

Fix: 7.3.2+
Fix from $2,300 2020-06-10
Websphere Application Server CRITICAL 9.8
CVE-2020-4448EPSS 12%

IBM WebSphere Application Server Network Deployment 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the system with…

Fix: 8.5.5.18 / 9.0.5.4+
Fix from $2,300 2020-06-05
Websphere Application Server CRITICAL 9.8
CVE-2020-4450EPSS 34%

IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially-craft…

Fix: 8.5.5.18 / 9.0.5.5+
Fix from $2,300 2020-06-05
Security Guardium CRITICAL 9.8
CVE-2020-4193

IBM Security Guardium 11.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Fo…

Mitigation only
Fix from $2,300 2020-06-04
Security Guardium CRITICAL 9.8
CVE-2020-4177

IBM Security Guardium 11.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication…

Patch available
Fix from $2,300 2020-06-03
Data Risk Manager CRITICAL 9.8
CVE-2020-4427 KEVEPSS 70%

IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured with…

Fix: after 2.0.6.1
Fix from $2,300 2020-05-07
Data Risk Manager CRITICAL 9.8
CVE-2020-4429EPSS 71%

IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 contains a default password for an IDRM administrative account. A remote attacker …

Patch available
Fix from $2,300 2020-05-07
Data Risk Manager CRITICAL 9.1
CVE-2020-4428 KEVEPSS 62%

IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary commands on the system. IBM X-F…

Fix: after 2.0.4
Fix from $2,300 2020-05-07
Spectrum Protect CRITICAL 9.8
CVE-2020-4415EPSS 8%

IBM Spectrum Protect 7.1 and 8.1 server is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. This could allow a remote…

Fix: after 8.1.9.200
Fix from $2,300 2020-04-23
Strongloop Nginx Controller CRITICAL 9.8
CVE-2020-7621

strong-nginx-controller through 1.0.2 is vulnerable to Command Injection. It allows execution of arbitrary command as part of the '_nginxCmd()' funct…

Fix: after 1.0.2
Fix from $2,300 2020-04-02
Spectrum Protect Plus CRITICAL 9.8
CVE-2020-4208

IBM Spectrum Protect Plus 10.1.0 through 10.1.5 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own i…

Fix: after 10.1.5
Fix from $2,300 2020-03-31
Spectrum Protect CRITICAL 9.8
CVE-2020-4210EPSS 15%

IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP …

Fix: 10.1.5+
Fix from $2,300 2020-02-24
Spectrum Protect CRITICAL 9.8
CVE-2020-4211EPSS 71%

IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP …

Fix: 10.1.5+
Fix from $2,300 2020-02-24
Spectrum Protect CRITICAL 9.8
CVE-2020-4212EPSS 15%

IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP …

Fix: 10.1.5+
Fix from $2,300 2020-02-24
Spectrum Protect CRITICAL 9.8
CVE-2020-4213EPSS 15%

IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP …

Fix: 10.1.5+
Fix from $2,300 2020-02-24
Spectrum Protect CRITICAL 9.8
CVE-2020-4222EPSS 15%

IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP …

Fix: 10.1.5+
Fix from $2,300 2020-02-24
Security Secret Server CRITICAL 9.8
CVE-2019-4640

IBM Security Secret Server 10.7 processes patches, image backups and other updates without sufficiently verifying the origin and integrity of the cod…

Mitigation only
Fix from $2,300 2020-02-19
Change And Configuration Management Database CRITICAL 9.8
CVE-2013-3323

A Privilege Escalation Vulnerability exists in IBM Maximo Asset Management 7.5, 7.1, and 6.2, when WebSeal with Basic Authentication is used, due to …

Mitigation only
Fix from $2,300 2020-02-18
Security Identity Manager CRITICAL 9.8
CVE-2019-4675

IBM Security Identity Manager 7.0.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authe…

Patch available
Fix from $2,300 2020-02-04
Iot Messagesight CRITICAL 9.8
CVE-2020-4207

IBM Watson IoT Message Gateway 2.0.0.x, 5.0.0.0, 5.0.0.1, and 5.0.0.2 is vulnerable to a buffer overflow, caused by improper bounds checking when han…

Fix: 2.0.0.2+
Fix from $2,300 2020-01-28
Jazz Reporting Service CRITICAL 9.8
CVE-2019-4651

IBM Jazz Reporting Service (JRS) 6.0.6.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could a…

Mitigation only
Fix from $2,300 2020-01-09
Planning Analytics CRITICAL 9.8
CVE-2019-4716 KEVEPSS 86%

IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and th…

Fix: after 2.0.8
Fix from $2,300 2019-12-18
Cloud Pak System CRITICAL 9.8
CVE-2019-4521

Platform System Manager in IBM Cloud Pak System 2.3 is potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on…

Mitigation only
Fix from $2,300 2019-12-10
Smartcloud Analytics Log Analysis CRITICAL 9.1
CVE-2019-4244

IBM SmartCloud Analytics 1.3.1 through 1.3.5 could allow a remote attacker to gain unauthorized information and unrestricted control over Zookeeper i…

Fix: after 1.3.5
Fix from $2,300 2019-12-10
Datapower Gateway CRITICAL 9.8
CVE-2019-4621

IBM DataPower Gateway 7.6.0.0-7 throug 6.0.14 and 2018.4.1.0 through 2018.4.1.5 have a default administrator account that is enabled if the IPMI LAN …

Fix: after 2018.4.1.5
Fix from $2,300 2019-12-09
Open Power CRITICAL 9.1
CVE-2019-4169

IBM Open Power Firmware OP910 and OP920 could allow access to BMC via IPMI using default OpenBMC password even after BMC password was changed away fr…

Mitigation only
Fix from $2,300 2019-08-26
Emptoris Contract Management CRITICAL 9.8
CVE-2019-4483

IBM Contract Management 10.1.0 through 10.1.3 and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 is vulnerable to SQL injection. A remote attacker…

Fix: after 10.1.3
Fix from $2,300 2019-08-20
Emptoris Contract Management CRITICAL 9.8
CVE-2019-4481

IBM Contract Management 10.1.0 through 10.1.3 and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 is vulnerable to SQL injection. A remote attacker…

Fix: after 10.1.3
Fix from $2,300 2019-08-20
Spectrum Protect Operations Center CRITICAL 9.8
CVE-2019-4087EPSS 7%

IBM Spectrum Protect Servers 7.1 and 8.1 and Storage Agents are vulnerable to a stack-based buffer overflow, caused by improper bounds checking by se…

Fix: after 8.1.7.000
Fix from $2,300 2019-07-02