Vulnerability index

Browse CVEs

385 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Cics Tx CRITICAL 9.8
CVE-2022-31767EPSS 5%

IBM CICS TX Standard and Advanced 11.1 could allow a remote attacker to execute arbitrary commands on the system by sending a specially crafted reque…

Fix: 11.1+
Fix from $2,300 2022-06-24
Cognos Analytics CRITICAL 9.8
CVE-2021-38945

IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 could allow a remote attacker to upload arbitrary files, caused by improper content validation. IBM X…

Fix: 11.1.7+
Fix from $2,300 2022-06-24
Curam Social Program Management CRITICAL 9.8
CVE-2022-22317

IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate a…

Patch available
Fix from $2,300 2022-06-20
Curam Social Program Management CRITICAL 9.8
CVE-2022-22318

IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate a…

Patch available
Fix from $2,300 2022-06-20
Spectrum Protect Operations Center CRITICAL 9.8
CVE-2022-22485

In some cases, an unsuccessful attempt to log into IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14.000 does not cause the administrat…

Fix: after 8.1.14.000
Fix from $2,300 2022-06-17
Financial Transaction Manager CRITICAL 9.8
CVE-2019-4575

IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.2.0 through 3.2.9 is vulnerable to SQL injection. A remote attacker could…

Fix: after 3.2.9
Fix from $2,300 2022-06-15
Infosphere Information Server CRITICAL 9.8
CVE-2022-31768

IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could all…

Patch available
Fix from $2,300 2022-06-06
Elastic Storage System CRITICAL 9.1
CVE-2020-4926

A vulnerability in the Spectrum Scale 5.1 core component and IBM Elastic Storage System 6.1 could allow unauthorized access to user data or injection…

Fix: 5.1.3.0 / 6.1.3.0+
Fix from $2,300 2022-05-24
Robotic Process Automation CRITICAL 9.8
CVE-2022-22413

IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statemen…

Mitigation only
Fix from $2,300 2022-05-12
Spectrum Virtualize CRITICAL 9.8
CVE-2021-38969

IBM Spectrum Virtualize 8.2, 8.3, and 8.4 could allow an attacker to allow unauthorized access due to the reuse of support generated credentials. IBM…

Mitigation only
Fix from $2,300 2022-05-11
Qradar Security Information And Event Manager CRITICAL 9.8
CVE-2021-38869

IBM QRadar SIEM 7.3, 7.4, and 7.5 in some situations may not automatically log users out after they exceede their idle timeout. IBM X-Force ID: 20834…

Fix: 7.3.3 / 7.4.3+
Fix from $2,300 2022-04-27
Iss Blackice Pc Protection CRITICAL 9.8
CVE-2003-5001

A vulnerability was found in ISS BlackICE PC Protection and classified as critical. Affected by this issue is the component Cross Site Scripting Dete…

Mitigation only
Fix from $2,300 2022-03-28
Power 9 Ac922 Firmware CRITICAL 9.1
CVE-2022-22374

The BMC (IBM Power 9 AC922 OP910, OP920, OP930, and OP940) may be subject to a firmware downgrade attack which may affect its ability to operate its …

Mitigation only
Fix from $2,300 2022-03-24
Security Verify Access CRITICAL 9.8
CVE-2021-39070

IBM Security Verify Access 10.0.0.0, 10.0.1.0 and 10.0.2.0 with the advanced access control authentication service enabled could allow an attacker to…

Mitigation only
Fix from $2,300 2022-02-02
Cognos Controller CRITICAL 9.8
CVE-2020-4877

IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could be vulnerable to unauthorized modifications by using public fields in public classes. IBM X-Fo…

Mitigation only
Fix from $2,300 2022-01-21
Cognos Controller CRITICAL 9.8
CVE-2020-4879

IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could allow a remote attacker to bypass security restrictions, caused by improper validation of auth…

Mitigation only
Fix from $2,300 2022-01-21
Spectrum Protect Plus CRITICAL 9.1
CVE-2021-39063

IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged a…

Fix: 10.1.9+
Fix from $2,300 2021-12-13
Spectrum Copy Data Management CRITICAL 9.8
CVE-2021-39052

IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to access the Spring Boot console without authorization. IBM X-For…

Fix: after 2.2.13
Fix from $2,300 2021-12-13
Spectrum Copy Data Management CRITICAL 9.8
CVE-2021-39065

IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to execute arbitrary commands on the system, caused by improper va…

Fix: after 2.2.13
Fix from $2,300 2021-12-13
Powervm Hypervisor CRITICAL 9.1
CVE-2021-38917

IBM PowerVM Hypervisor FW860, FW940, and FW950 could allow an attacker that gains service access to the FSP can read and write arbitrary host system …

Mitigation only
Fix from $2,300 2021-12-10
Infosphere Information Server CRITICAL 9.1
CVE-2021-38948

IBM InfoSphere Information Server 11.7 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker cou…

Patch available
Fix from $2,300 2021-11-02
Ts7700 Firmware CRITICAL 9.8
CVE-2021-29908

The IBM TS7700 Management Interface is vulnerable to unauthenticated access. By accessing a specially-crafted URL, an attacker may gain administrativ…

Mitigation only
Fix from $2,300 2021-10-06
Powervm Hypervisor Firmware CRITICAL 9.1
CVE-2021-38923

IBM PowerVM Hypervisor FW1010 could allow a privileged user to gain access to another VM due to assigning duplicate WWPNs. IBM X-Force ID: 210162.

Mitigation only
Fix from $2,300 2021-10-06
Sterling B2b Integrator CRITICAL 9.8
CVE-2021-29798

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted S…

Fix: after 6.1.0.3
Fix from $2,300 2021-10-06
Sterling B2b Integrator CRITICAL 9.8
CVE-2021-29903

IBM Sterling B2B Integrator Standard Edition 5.2.6.0 through 6.1.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted S…

Fix: after 6.1.0.3
Fix from $2,300 2021-10-06
Cloud Pak For Security CRITICAL 9.8
CVE-2021-20578

IBM Cloud Pak for Security (CP4S) 1.7.0.0, 1.7.1.0, 1.7.2.0, and 1.8.0.0 could allow an attacker to perform unauthorized actions due to improper or m…

Patch available
Fix from $2,300 2021-09-30
Security Guardium CRITICAL 9.8
CVE-2020-4690

IBM Security Guardium 11.3 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication…

Patch available
Fix from $2,300 2021-09-23
Api Connect CRITICAL 9.8
CVE-2021-29772

IBM API Connect 5.0.0.0 through 5.0.8.11 could allow a user to potentially inject code due to unsanitized user input. IBM X-Force ID: 202774.

Fix: after 5.0.8.11
Fix from $2,300 2021-08-26
Api Connect CRITICAL 9.1
CVE-2021-29715

IBM API Connect 5.0.0.0 through 5.0.8.11 could alllow a remote user to obtain sensitive information or conduct denial of serivce attacks due to open …

Fix: after 5.0.8.11
Fix from $2,300 2021-08-26
Maximo Asset Management CRITICAL 9.8
CVE-2021-20509

IBM Maximo Asset Management 7.6.0 and 7.6.1 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the sys…

Fix: 7.6.1.2+
Fix from $2,300 2021-08-12