Vulnerability index

Browse CVEs

385 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Robotic Process Automation With Automation Anywhere CRITICAL 9.8
CVE-2019-4336

IBM Robotic Process Automation with Automation Anywhere 11 uses an inadequate account lockout setting that could allow a remote attacker to brute for…

Fix: 11.0.0.5+
Fix from $2,300 2019-07-01
Websphere Application Server CRITICAL 9.8
CVE-2019-4279EPSS 80%

IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence …

Fix: after 9.0.0.11
Fix from $2,300 2019-05-17
Api Connect CRITICAL 10.0
CVE-2019-4202

IBM API Connect 5.0.0.0 and 5.0.8.6 Developer Portal is vulnerable to command injection. An attacker with a specially crafted request can run arbitra…

Fix: after 5.0.8.6
Fix from $2,300 2019-04-15
Bigfix Webui Profile Management CRITICAL 9.8
CVE-2019-4012

IBM BigFix WebUI Profile Management 6 and Software Distribution 23 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL…

Mitigation only
Fix from $2,300 2019-04-15
Api Connect CRITICAL 9.8
CVE-2019-4203

IBM API Connect 5.0.0.0 and 5.0.8.6 Developer Portal can be exploited by app developers to download arbitrary files from the host OS and potentially …

Fix: after 5.0.8.6
Fix from $2,300 2019-04-15
Cognos Analytics CRITICAL 9.1
CVE-2019-4178

IBM Cognos Analytics 11 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request t…

Fix: after 11.0.13.0
Fix from $2,300 2019-04-15
Bigfix Platform CRITICAL 9.9
CVE-2019-4013EPSS 13%

IBM BigFix Platform 9.5 could allow any authenticated user to upload any file to any location on the server with root privileges. This results in cod…

Fix: after 9.5.11
Fix from $2,300 2019-04-10
Infosphere Information Server On Cloud CRITICAL 9.8
CVE-2018-1994

IBM InfoSphere Information Server 11.5 and 11.7 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which …

Patch available
Fix from $2,300 2019-04-10
Api Connect CRITICAL 9.8
CVE-2019-4155

IBM API Connect's Developer Portal 2018.1 and 2018.4.1.3 is impacted by a privilege escalation vulnerability when integrated with an OpenID Connect (…

Fix: after 2018.4.1.3
Fix from $2,300 2019-04-08
Financial Transaction Manager CRITICAL 9.8
CVE-2019-4032

IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.1.0 is vulnerable to SQL injection. A remote attacker could send speciall…

Fix: after 3.1.0.3
Fix from $2,300 2019-03-05
Security Identity Governance And Intelligence CRITICAL 9.8
CVE-2018-1944

IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance contains hard-coded credentials, such as a password or crypto…

Fix: after 5.2.4.1
Fix from $2,300 2019-02-21
Rational Clearcase CRITICAL 9.8
CVE-2019-4059

IBM Rational ClearCase 1.0.0.0 GIT connector does not sufficiently protect the document database password. An attacker could obtain the password and …

Fix: 9.0.1.5+
Fix from $2,300 2019-02-15
Infosphere Information Server CRITICAL 9.1
CVE-2018-1727

IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A…

Mitigation only
Fix from $2,300 2019-02-15
Api Connect CRITICAL 9.8
CVE-2019-4008

API Connect V2018.1 through 2018.4.1.1 is impacted by access token leak. Authorization tokens in some URLs can result in the tokens being written to …

Fix: after 2018.4.1.1
Fix from $2,300 2019-02-07
Security Identity Manager CRITICAL 9.9
CVE-2018-1969

IBM Security Identity Manager 6.0.0 allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the…

Fix: after 6.0.0.20
Fix from $2,300 2019-01-14
Api Connect CRITICAL 9.8
CVE-2018-1784

IBM API Connect 5.0.0.0 and 5.0.8.4 is affected by a NoSQL Injection in MongoDB connector for the LoopBack framework. IBM X-Force ID: 148807.

Fix: after 5.0.8.4
Fix from $2,300 2018-12-20
Security Guardium CRITICAL 9.8
CVE-2018-1818

IBM Security Guardium 10 and 10.5 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authent…

Fix: after 10.5
Fix from $2,300 2018-12-13
Operational Decision Manager CRITICAL 9.1
CVE-2018-1821EPSS 13%

IBM Operational Decision Management 8.5, 8.6, 8.7, 8.8, and 8.9 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML dat…

Fix: 8.6.0.3 / 8.7.1.2+
Fix from $2,300 2018-12-13
Websphere Application Server CRITICAL 9.8
CVE-2018-1904

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbitrary Java code through an administrative client …

Fix: after 9.0.0.9
Fix from $2,300 2018-12-11
Websphere Application Server CRITICAL 9.8
CVE-2018-1851

IBM WebSphere Application Server Liberty OpenID Connect could allow a remote attacker to execute arbitrary code on the system, caused by improper des…

Fix: 18.0.0.3+
Fix from $2,300 2018-10-31
Flashsystem 900 Firmware CRITICAL 9.8
CVE-2018-1822

IBM FlashSystem 900 product GUI allows a specially crafted attack to bypass the authentication requirements of the system, resulting in the ability t…

Patch available
Fix from $2,300 2018-10-18
Qlogic 4 Gb Fibre Channel Expansion Card Firmware CRITICAL 9.8
CVE-2018-18202

The QLogic 4Gb Fibre Channel 5.5.2.6.0 and 4/8Gb SAN 7.10.1.20.0 modules for IBM BladeCenter have an undocumented support account with a support pass…

No fix yet
Fix from $2,300 2018-10-10
Security Key Lifecycle Manager CRITICAL 9.3
CVE-2018-1742

IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its ow…

Fix: after 3.0.0.1
Fix from $2,300 2018-10-08
Api Connect CRITICAL 9.9
CVE-2018-1789

IBM API Connect v2018.1.0 through v2018.3.4 could allow an attacker to send a specially crafted request to conduct a server side request forgery atta…

Fix: after 2018.3.4
Fix from $2,300 2018-09-07
Websphere Application Server CRITICAL 9.8
CVE-2018-1567

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbitrary Java code through the SOAP connector with a…

Fix: after 9.0.0.9
Fix from $2,300 2018-09-07
Security Access Manager CRITICAL 10.0
CVE-2018-1722EPSS 9%

IBM Security Access Manager Appliance 9.0.4.0 and 9.0.5.0 could allow remote code execution when Advanced Access Control or Federation services are r…

Mitigation only
Fix from $2,300 2018-08-24
Api Connect CRITICAL 9.9
CVE-2018-1712

IBM API Connect's Developer Portal 5.0.0.0 through 5.0.8.3 is vulnerable to Server Side Request Forgery. An attacker, using specially crafted input p…

Fix: after 5.0.8.3
Fix from $2,300 2018-08-16
Infosphere Data Replication Dashboard CRITICAL 9.8
CVE-2013-3000

SQL injection vulnerability in IBM InfoSphere Data Replication Dashboard 9.7 and 10.1 allows remote attackers to execute arbitrary SQL commands via u…

Mitigation only
Fix from $2,300 2018-07-09
Engineering Requirements Management Doors CRITICAL 9.8
CVE-2018-1457

An undisclosed vulnerability in IBM Rational DOORS 9.5.1 through 9.6.1.10 application allows an attacker to gain DOORS administrator privileges. IBM …

Fix: after 9.7.2
Fix from $2,300 2018-06-27
Security Guardium Database Activity Monitor CRITICAL 9.8
CVE-2017-1601

IBM Security Guardium 10.0, 10.0.1, and 10.1 through 10.1.4 Database Activity Monitor does not require that users should have strong passwords by def…

Patch available
Fix from $2,300 2018-05-02