Vulnerability index

Browse CVEs

385 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Storage Virtualize CRITICAL 9.1
CVE-2025-0159

IBM FlashSystem (IBM Storage Virtualize (8.5.0.0 through 8.5.0.13, 8.5.1.0, 8.5.2.0 through 8.5.2.3, 8.5.3.0 through 8.5.3.1, 8.5.4.0, 8.6.0.0 throug…

Fix: 8.5.0.14 / 8.6.0.6+
Fix from $2,300 2025-02-28
App Connect Enterprise Certified Container CRITICAL 9.1
CVE-2022-43916

IBM App Connect Enterprise Certified Container 7.1, 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12…

Fix: 12.8+
Fix from $2,300 2025-01-30
Aspera Faspex CRITICAL 9.8
CVE-2023-35907

IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes it easier for attackers to co…

Fix: after 5.0.10
Fix from $2,300 2025-01-29
Aspera Faspex CRITICAL 9.8
CVE-2023-37398

IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes it easier for attackers to co…

Fix: after 5.0.10
Fix from $2,300 2025-01-29
Sterling B2b Integrator CRITICAL 9.8
CVE-2023-50316

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 is vulnerable to SQL injection. A remote attacker could send speciall…

Fix: after 6.2.0.1
Fix from $2,300 2025-01-28
Security Verify Access CRITICAL 9.8
CVE-2024-45647

IBM Security Verify Access 10.0.0 through 10.0.8 and IBM Security Verify Access Docker 10.0.0 through 10.0.8 could allow could an unverified user to …

Fix: after 10.0.8
Fix from $2,300 2025-01-20
Sterling Secure Proxy CRITICAL 9.1
CVE-2024-41783

IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow a privileged user to inject commands into the underlyi…

Fix: 6.0.3.1+
Fix from $2,300 2025-01-19
Sterling Secure Proxy CRITICAL 9.1
CVE-2024-38337

IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow an unauthorized attacker to retrieve or alter sensitiv…

Fix: 6.0.3.1+
Fix from $2,300 2025-01-19
Voice Gateway CRITICAL 9.1
CVE-2024-47113

IBM ICP - Voice Gateway 1.0.2, 1.0.2.4, 1.0.3, 1.0.4, 1.0.5, 1.0.6. 1.0.7, 1.0.7.1, and 1.0.8 could allow remote attacker to send specially crafted X…

Mitigation only
Fix from $2,300 2025-01-18
Engineering Lifecycle Optimization Engineering Insights CRITICAL 9.8
CVE-2024-39727

IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 uses a web link with untrusted references to an external site. A remote…

Mitigation only
Fix from $2,300 2024-12-25
Cognos Analytics CRITICAL 9.0
CVE-2024-51466

IBM Cognos Analytics 11.2.0 through 11.2.4 FP4 and 12.0.0 through 12.0.4 is vulnerable to an Expression Language (EL) Injection vulnerability. A r…

Fix: 11.2.4 / 12.0.4+
Fix from $2,300 2024-12-20
Cognos Controller CRITICAL 9.8
CVE-2024-25020

IBM Cognos Controller 11.0.0 and 11.0.1 is vulnerable to malicious file upload by allowing unrestricted filetype attachments in the Jou…

Mitigation only
Fix from $2,300 2024-12-03
Cognos Controller CRITICAL 9.8
CVE-2024-40691

IBM Cognos Controller 11.0.0 and 11.0.1 could be vulnerable to malicious file upload by not validating the content of the file uploaded to the web …

Mitigation only
Fix from $2,300 2024-12-03
Cognos Controller CRITICAL 9.8
CVE-2024-25019

IBM Cognos Controller 11.0.0 and 11.0.1 could be vulnerable to malicious file upload by not validating the type of file uploaded to Journal entry a…

Mitigation only
Fix from $2,300 2024-12-03
Security Verify Access CRITICAL 9.8
CVE-2024-49805

IBM Security Verify Access Appliance 10.0.0 through 10.0.8 contains hard-coded credentials, such as a password or cryptographic key, which it uses …

Fix: after 10.0.8
Fix from $2,300 2024-11-29
Security Verify Access CRITICAL 9.8
CVE-2024-49806

IBM Security Verify Access Appliance 10.0.0 through 10.0.8 contains hard-coded credentials, such as a password or cryptographic key, which it uses …

Fix: after 10.0.8
Fix from $2,300 2024-11-29
Concert CRITICAL 9.8
CVE-2024-52360

IBM Concert Software 1.0.0, 1.0.1, 1.0.2, and 1.0.2.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, …

Mitigation only
Fix from $2,300 2024-11-19
Power System E1080 \(9080 Hex\) Firmware CRITICAL 9.8
CVE-2024-45656

IBM Flexible Service Processor (FSP) FW860.00 through FW860.B3, FW950.00 through FW950.C0, FW1030.00 through FW1030.61, FW1050.00 through FW1050.21, …

Mitigation only
Fix from $2,300 2024-10-29
Concert CRITICAL 9.8
CVE-2024-43177

IBM Concert 1.0.0 and 1.0.1 vulnerable to attacks that rely on the use of cookies without the SameSite attribute.

Mitigation only
Fix from $2,300 2024-10-22
Webmethods Integration CRITICAL 9.9
CVE-2024-45076

IBM webMethods Integration 10.15 could allow an authenticated user to upload and execute arbitrary files which could be executed on the underlying op…

Mitigation only
Fix from $2,300 2024-09-04
Sterling Connect Direct Web Services CRITICAL 9.8
CVE-2024-39747

IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 uses default credentials for potentially critical functionality.

Fix: 6.1.0.25 / 6.2.0.24+
Fix from $2,300 2024-08-31
Security Directory Integrator CRITICAL 9.8
CVE-2022-33162

IBM Security Directory Integrator 7.2.0 and Security Verify Directory Integrator 10.0.0 does not perform any authentication for functionality that re…

Mitigation only
Fix from $2,300 2024-08-16
Planning Analytics Workspace CRITICAL 9.1
CVE-2024-35143

IBM Planning Analytics Local 2.0 and 2.1 connects to a MongoDB server. MongoDB, a document-oriented database system, is listening on the remote port,…

Fix: 2.0.97 / 2.1.4+
Fix from $2,300 2024-08-04
Infosphere Information Server CRITICAL 9.8
CVE-2024-40689

IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could all…

Mitigation only
Fix from $2,300 2024-07-26
Datacap CRITICAL 9.8
CVE-2024-39736

IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 is vulnerable to HTTP header injection, caused by improper validation of input by the HOS…

Mitigation only
Fix from $2,300 2024-07-15
Mq Operator CRITICAL 9.8
CVE-2024-39742

IBM MQ Operator 3.2.2 and IBM MQ Operator 2.0.24 could allow a user to bypass authentication under certain configurations due to a partial string com…

Fix: 2.0.24 / 3.2.2+
Fix from $2,300 2024-07-08
Engineering Lifecycle Optimization Publishing CRITICAL 9.8
CVE-2023-45188

IBM Engineering Lifecycle Optimization Publishing 7.0.2 and 7.03 could allow a remote attacker to upload arbitrary files, caused by the improper vali…

Mitigation only
Fix from $2,300 2024-06-09
Storage Fusion Hci CRITICAL 9.8
CVE-2023-43040

IBM Spectrum Fusion HCI 2.5.2 through 2.7.2 could allow an attacker to perform unauthorized actions in RGW for Ceph due to improper bucket access. I…

Fix: 2.8.0+
Fix from $2,300 2024-05-14
Cognos Controller CRITICAL 9.8
CVE-2023-38724

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which…

Mitigation only
Fix from $2,300 2024-05-03
Personal Communications CRITICAL 10.0
CVE-2024-25029

IBM Personal Communications 14.0.6 through 15.0.1 includes a Windows service that is vulnerable to remote code execution (RCE) and local privilege es…

Fix: after 15.0.1
Fix from $2,300 2024-04-06