Vulnerability index

Browse CVEs

385 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Sdk CRITICAL 9.8
CVE-2022-40609

IBM SDK, Java Technology Edition 7.1.5.18 and 8.0.8.0 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe dese…

Fix: 7.1.5.19 / 8.0.8.5+
Fix from $2,300 2023-08-02
I CRITICAL 9.8
CVE-2023-30990

IBM i 7.2, 7.3, 7.4, and 7.5 could allow a remote attacker to execute CL commands as QUSER, caused by an exploitation of DDM architecture. IBM X-For…

Patch available
Fix from $2,300 2023-07-04
Informix Jdbc Driver CRITICAL 9.8
CVE-2023-27866

IBM Informix JDBC Driver 4.10 and 4.50 is susceptible to remote code execution attack via JNDI injection when driver code or the application using th…

Fix: 4.50.10+
Fix from $2,300 2023-06-28
Sterling Partner Engagement Manager CRITICAL 9.6
CVE-2023-23482

IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading …

Fix: 6.1.2.8 / 6.2.0.6+
Fix from $2,300 2023-06-08
Infosphere Information Server CRITICAL 9.8
CVE-2023-32336

IBM InfoSphere Information Server 11.7 is affected by a remote code execution vulnerability due to insecure deserialization in an RMI service. IBM X…

Mitigation only
Fix from $2,300 2023-05-22
Infosphere Information Server CRITICAL 9.8
CVE-2022-47984

IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could all…

Patch available
Fix from $2,300 2023-05-19
Aspera Cargo CRITICAL 9.8
CVE-2023-27284

IBM Aspera Cargo 4.2.5 and IBM Aspera Connect 4.2.5 are vulnerable to a buffer overflow, caused by improper bounds checking. An attacker could overfl…

Fix: 4.2.5+
Fix from $2,300 2023-04-02
Aspera Cargo CRITICAL 9.8
CVE-2023-27286

IBM Aspera Cargo 4.2.5 and IBM Aspera Connect 4.2.5 are vulnerable to a buffer overflow, caused by improper bounds checking. An attacker could overfl…

Fix: 4.2.5+
Fix from $2,300 2023-04-02
Security Key Lifecycle Manager CRITICAL 9.8
CVE-2023-25684

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 is vulnerable to SQL injection. A remote attacker could send specially cr…

Patch available
Fix from $2,300 2023-03-21
Observability With Instana CRITICAL 9.1
CVE-2023-27290EPSS 9%

Docker based datastores for IBM Instana (IBM Observability with Instana 239-0 through 239-2, 241-0 through 241-2, and 243-0) do not currently require…

Fix: after 241-2
Fix from $2,300 2023-03-03
Aspera Faspex CRITICAL 9.8
CVE-2022-47986 KEVEPSS 100%

IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserializa…

Fix: after 4.4.1
Fix from $2,300 2023-02-17
Watson Knowledge Catalog On Cloud Pak For Data CRITICAL 9.8
CVE-2022-41731

IBM Watson Knowledge Catalog on Cloud Pak for Data 4.5.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statement…

Mitigation only
Fix from $2,300 2023-02-12
Websphere Application Server CRITICAL 9.8
CVE-2023-23477

IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially craft…

Mitigation only
Fix from $2,300 2023-02-03
Tivoli Workload Scheduler CRITICAL 9.1
CVE-2022-38389

IBM Tivoli Workload Scheduler 9.4, 9.5, and 10.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote at…

Mitigation only
Fix from $2,300 2023-02-03
Tivoli Workload Scheduler CRITICAL 9.1
CVE-2022-22486

IBM Tivoli Workload Scheduler 9.4, 9.5, and 10.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote at…

Mitigation only
Fix from $2,300 2023-02-03
Sterling Partner Engagement Manager CRITICAL 9.8
CVE-2022-40615

IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statem…

Patch available
Fix from $2,300 2023-01-11
Sterling B2b Integrator CRITICAL 9.8
CVE-2022-22338

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 is vulnerable to SQL injection. A remote attacker could send specially crafted S…

Fix: 6.0.3.7 / 6.1.0.6+
Fix from $2,300 2023-01-04
Cognos Analytics CRITICAL 9.1
CVE-2022-38708

IBM Cognos Analytics 11.1.7 11.2.0, and 11.2.1 could be vulnerable to a Server-Side Request Forgery Attack (SSRF) attack by constructing URLs from us…

Fix: after 11.2.3
Fix from $2,300 2022-12-19
Infosphere Information Server CRITICAL 9.8
CVE-2022-40752

IBM InfoSphere DataStage 11.7 is vulnerable to a command injection vulnerability due to improper neutralization of special elements. IBM X-Force ID: …

Patch available
Fix from $2,300 2022-11-16
Powervm Hypervisor CRITICAL 9.8
CVE-2022-34331

After performing a sequence of Power FW950, FW1010 maintenance operations a SRIOV network adapter can be improperly configured leading to desired VE…

Mitigation only
Fix from $2,300 2022-11-11
Infosphere Information Server CRITICAL 9.1
CVE-2022-40747

"IBM InfoSphere Information Server 11.7 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker co…

Patch available
Fix from $2,300 2022-11-03
Infosphere Information Server CRITICAL 9.8
CVE-2022-22425

"IBM InfoSphere Information Server 11.7 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system,…

Patch available
Fix from $2,300 2022-11-03
Mq CRITICAL 9.1
CVE-2022-22489

IBM MQ 8.0, (9.0, 9.1, 9.2 LTS), and (9.1 and 9.2 CD) are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A rem…

Patch available
Fix from $2,300 2022-08-19
Security Verify Governance CRITICAL 9.8
CVE-2022-22455

IBM Security Verify Governance Identity Manager 10.0 virtual appliance component performs an operation at a privilege level that is higher than the m…

Patch available
Fix from $2,300 2022-08-17
Sterling B2b Integrator CRITICAL 9.8
CVE-2021-39085

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 is vulnerable to SQL injec…

Fix: 6.0.3.6 / 6.1.0.5+
Fix from $2,300 2022-08-16
Robotic Process Automation For Cloud Pak CRITICAL 9.8
CVE-2022-35280

IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 does not require that users should have strong passwords by default, which makes it easier …

Mitigation only
Fix from $2,300 2022-08-10
Datapower Gateway CRITICAL 9.1
CVE-2022-31775

IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21 is vulnerable to an XML Exte…

Fix: 10.0.1.8 / 10.5.0.1+
Fix from $2,300 2022-08-01
Powervm Virtual I\/o Server CRITICAL 9.1
CVE-2022-35643

IBM PowerVM VIOS 3.1 could allow a remote attacker to tamper with system configuration or cause a denial of service. IBM X-Force ID: 230956.

Patch available
Fix from $2,300 2022-07-29
Security Siteprotector System CRITICAL 9.8
CVE-2020-4150

IBM SiteProtector Appliance 3.1.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authent…

Mitigation only
Fix from $2,300 2022-07-11
Spectrum Protect Server CRITICAL 9.8
CVE-2022-22487

An IBM Spectrum Protect storage agent could allow a remote attacker to perform a brute force attack by allowing unlimited attempts to login to the st…

Fix: after 8.1.14
Fix from $2,300 2022-06-30