Vulnerability index

Browse CVEs

385 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Application Gateway CRITICAL 10.0
CVE-2024-28787

IBM Security Verify Access 10.0.0 through 10.0.7 and IBM Application Gateway 20.01 through 24.03 could allow a remote attacker to obtain highly sensi…

Fix: after 24.03
Fix from $2,300 2024-04-04
Cloud Pak For Business Automation CRITICAL 9.8
CVE-2023-35899

IBM Cloud Pak for Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 is po…

Mitigation only
Fix from $2,300 2024-03-21
Ds8900f Firmware CRITICAL 9.8
CVE-2023-46172

IBM DS8900F HMC 89.21.19.0, 89.21.31.0, 89.30.68.0, 89.32.40.0, and 89.33.48.0 could allow a remote attacker to bypass authentication restrictions fo…

Mitigation only
Fix from $2,300 2024-03-07
Aspera Console CRITICAL 9.1
CVE-2022-43842

IBM Aspera Console 3.4.0 through 3.4.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could all…

Fix: 3.4.2+
Fix from $2,300 2024-02-23
Trusteer Android Sdk For Mobile CRITICAL 9.8
CVE-2022-42443

An undisclosed issue in Trusteer iOS SDK for mobile versions prior to 5.7 and Trusteer Android SDK for mobile versions prior to 5.7 may allow uploadi…

Fix: 5.7+
Fix from $2,300 2024-02-17
Security Verify Access CRITICAL 9.8
CVE-2023-32328

IBM Security Verify Access 10.0.0.0 through 10.0.6.1 uses insecure protocols in some instances that could allow an attacker on the network to take co…

Fix: after 10.0.6.1
Fix from $2,300 2024-02-07
Security Verify Access CRITICAL 9.8
CVE-2023-32330

IBM Security Verify Access 10.0.0.0 through 10.0.6.1 uses insecure calls that could allow an attacker on the network to take control of the server. …

Fix: after 10.0.6.1
Fix from $2,300 2024-02-07
Security Verify Access CRITICAL 9.0
CVE-2023-31004

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 …

Fix: after 10.0.6.1
Fix from $2,300 2024-02-03
Tivoli Application Dependency Discovery Manager CRITICAL 9.8
CVE-2023-47143

IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 is vulnerable to HTTP header injection, caused by improper validation of…

Fix: 7.3.0.11+
Fix from $2,300 2024-02-02
Operational Decision Manager CRITICAL 9.8
CVE-2024-22319EPSS 76%

IBM Operational Decision Manager 8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, 8.11.1 and 8.12.0.1 is susceptible to remote code execution attack via JND…

Patch available
Fix from $2,300 2024-02-02
Maximo Asset Management CRITICAL 9.8
CVE-2023-32333

IBM Maximo Asset Management 7.6.1.3 could allow a remote attacker to log into the admin panel due to improper access controls. IBM X-Force ID: 2550…

Patch available
Fix from $2,300 2024-02-02
Powersc CRITICAL 9.8
CVE-2023-50940

IBM PowerSC 1.3, 2.0, and 2.1 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve se…

Patch available
Fix from $2,300 2024-02-02
Merge Efilm Workstation CRITICAL 9.8
CVE-2024-23622

A stack-based buffer overflow exists in IBM Merge Healthcare eFilm Workstation license server. A remote, unauthenticated attacker can exploit this vu…

Fix: after 4.2
Fix from $2,300 2024-01-26
Merge Efilm Workstation CRITICAL 9.8
CVE-2024-23619

A hardcoded credential vulnerability exists in IBM Merge Healthcare eFilm Workstation. A remote, unauthenticated attacker can exploit this vulnerabil…

Fix: after 4.2
Fix from $2,300 2024-01-26
Merge Efilm Workstation CRITICAL 9.8
CVE-2024-23621

A buffer overflow exists in IBM Merge Healthcare eFilm Workstation license server. A remote, unauthenticated attacker can exploit this vulnerability …

Fix: after 4.2
Fix from $2,300 2024-01-26
App Connect Enterprise CRITICAL 9.1
CVE-2024-22317

IBM App Connect Enterprise 11.0.0.1 through 11.0.0.24 and 12.0.1.0 through 12.0.11.0 could allow a remote attacker to obtain sensitive information or…

Fix: after 12.0.11.0
Fix from $2,300 2024-01-18
Storage Fusion Hci CRITICAL 9.8
CVE-2023-50948

IBM Storage Fusion HCI 2.1.0 through 2.6.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inboun…

Fix: 2.7.1+
Fix from $2,300 2024-01-08
Planning Analytics CRITICAL 9.8
CVE-2023-42017

IBM Planning Analytics Local 2.0 could allow a remote attacker to upload arbitrary files, caused by the improper validation of file extensions. By s…

Mitigation only
Fix from $2,300 2023-12-22
Informix Jdbc CRITICAL 9.8
CVE-2023-35895

IBM Informix JDBC Driver 4.10 and 4.50 is susceptible to remote code execution attack via JNDI injection when passing an unchecked argument to a cert…

Mitigation only
Fix from $2,300 2023-12-20
Security Guardium Key Lifecycle Manager CRITICAL 9.1
CVE-2023-47702

IBM Security Guardium Key Lifecycle Manager 4.3 could allow a remote attacker to traverse directories on the system. An attacker could send a special…

Fix: 4.2.0.2+
Fix from $2,300 2023-12-20
Websphere Application Server Liberty CRITICAL 9.8
CVE-2023-46158

IBM WebSphere Application Server Liberty 23.0.0.9 through 23.0.0.10 could provide weaker than expected security due to improper resource expiration h…

Fix: 23.0.0.11+
Fix from $2,300 2023-10-25
Security Verify Governance CRITICAL 9.8
CVE-2022-22466

IBM Security Verify Governance 10.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authe…

Fix: 10.0.2+
Fix from $2,300 2023-10-23
Security Verify Governance CRITICAL 9.8
CVE-2023-33836

IBM Security Verify Governance 10.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authe…

Fix: 10.0.2+
Fix from $2,300 2023-10-16
Security Directory Server CRITICAL 9.1
CVE-2022-32755

IBM Security Directory Server 6.4.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could …

Patch available
Fix from $2,300 2023-10-14
Robotic Process Automation CRITICAL 9.8
CVE-2023-43058

IBM Robotic Process Automation 23.0.9 is vulnerable to privilege escalation that affects ownership of projects. IBM X-Force ID: 247527.

Patch available
Fix from $2,300 2023-10-06
Observability With Instana CRITICAL 9.8
CVE-2023-37404

IBM Observability with Instana 1.0.243 through 1.0.254 could allow an attacker on the network to execute arbitrary code on the host after a successfu…

Fix: 1.0.255+
Fix from $2,300 2023-10-04
Security Directory Server CRITICAL 9.1
CVE-2022-33164

IBM Security Directory Server 7.2.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted U…

Patch available
Fix from $2,300 2023-09-08
Financial Transaction Manager CRITICAL 9.1
CVE-2023-35892

IBM Financial Transaction Manager for SWIFT Services 3.2.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A…

Mitigation only
Fix from $2,300 2023-09-05
Guardium Cloud Key Manager CRITICAL 9.8
CVE-2023-26270

IBM Security Guardium Data Encryption (IBM Guardium Cloud Key Manager (GCKM) 1.10.3)) could allow a remote attacker to execute arbitrary code on the …

Fix: after 1.10.3
Fix from $2,300 2023-08-28
Robotic Process Automation CRITICAL 9.8
CVE-2023-38734

IBM Robotic Process Automation 21.0.0 through 21.0.7.1 and 23.0.0 through 23.0.1 is vulnerable to incorrect privilege assignment when importing users…

Fix: after 21.0.7.1
Fix from $2,300 2023-08-22