Vulnerability index

Browse CVEs

385 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Security Guardium CRITICAL 9.8
CVE-2021-20418

IBM Security Guardium 11.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise use…

Mitigation only
Fix from $2,300 2021-08-11
Partner Engagement Manager CRITICAL 9.8
CVE-2021-29781

IBM Partner Engagement Manager 2.0 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization flaw. B…

Patch available
Fix from $2,300 2021-07-30
Qradar Security Information And Event Manager CRITICAL 9.1
CVE-2021-20399

IBM Qradar SIEM 7.3.0 to 7.3.3 Patch 8 and 7.4.0 to 7.4.3 GA is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data.…

Fix: 7.3.3 / 7.4.3+
Fix from $2,300 2021-07-27
Infosphere Data Replication CRITICAL 9.8
CVE-2020-4821

IBM InfoSphere Data Replication 11.4 and IBM InfoSphere Change Data Capture for z/OS 10.2.1, under certain configurations, could allow a user to bypa…

Patch available
Fix from $2,300 2021-07-16
Financial Transaction Manager CRITICAL 9.1
CVE-2020-5003

IBM Financial Transaction Manager 3.2.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker co…

Mitigation only
Fix from $2,300 2021-06-11
Cognos Analytics CRITICAL 10.0
CVE-2020-4561

IBM Cognos Analytics 11.0 and 11.1 DQM API allows submitting of all control requests in unauthenticated sessions. This allows a remote attacker who c…

Patch available
Fix from $2,300 2021-06-01
Power9 System Firmware CRITICAL 9.1
CVE-2021-20487

IBM Power9 Self Boot Engine(SBE) could allow a privileged user to inject malicious code and compromise the integrity of the host firmware bypassing t…

Mitigation only
Fix from $2,300 2021-05-26
Security Guardium CRITICAL 9.8
CVE-2021-20426

IBM Security Guardium 11.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication…

Patch available
Fix from $2,300 2021-05-24
Planning Analytics Cloud CRITICAL 9.1
CVE-2020-4669

IBM Planning Analytics Local 2.0 connects to a MongoDB server. MongoDB, a document-oriented database system, is listening on the remote port, and it …

Patch available
Fix from $2,300 2021-05-17
Planning Analytics Cloud CRITICAL 9.1
CVE-2020-4670

IBM Planning Analytics Local 2.0 connects to a Redis server. The Redis server, an in-memory data structure store, running on the remote host is not p…

Patch available
Fix from $2,300 2021-05-17
Cloud Pak For Security CRITICAL 9.1
CVE-2021-20538

IBM Cloud Pak for Security (CP4S) 1.5.0.0 and 1.5.0.1 could allow a user to obtain sensitive information or perform actions they should not have acce…

Mitigation only
Fix from $2,300 2021-05-10
Qradar Security Information And Event Manager CRITICAL 9.8
CVE-2020-4979

IBM QRadar SIEM 7.3 and 7.4 is vulnerable to insecure inter-deployment communication. An attacker that is able to comprimise or spoof traffic between…

Fix: 7.3.3 / 7.4.2+
Fix from $2,300 2021-05-05
Mq CRITICAL 9.8
CVE-2020-4682EPSS 8%

IBM MQ 7.5, 8.0, 9.0, 9.1, 9.2 LTS, and 9.2 CD could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserializa…

Patch available
Fix from $2,300 2021-01-28
Infosphere Information Server CRITICAL 9.8
CVE-2020-27583

IBM InfoSphere Information Server 8.5.0.0 is affected by deserialization of untrusted data which could allow remote unauthenticated attackers to exec…

No fix yet
Fix from $2,300 2021-01-26
Security Identity Governance And Intelligence CRITICAL 9.8
CVE-2020-4958

IBM Security Identity Governance and Intelligence 5.2.6 does not perform any authentication for functionality that requires a provable user identity …

Mitigation only
Fix from $2,300 2021-01-21
Api Connect CRITICAL 9.1
CVE-2020-4899

IBM API Connect 5.0.0.0 through 5.0.8.10 could potentially leak sensitive information or allow for data corruption due to plain text transmission of …

Fix: after 5.0.8.10
Fix from $2,300 2021-01-05
Loopback CRITICAL 9.8
CVE-2020-4988

Loopback 8.0.0 contains a vulnerability that could allow an attacker to manipulate or pollute Javascript values and cause a denial of service or poss…

Mitigation only
Fix from $2,300 2020-12-21
Connect\ CRITICAL 9.8
CVE-2020-4747

IBM Connect:Direct for UNIX 6.1.0, 6.0.0, 4.3.0, and 4.2.0 can allow a local or remote user to obtain an authenticated CLI session due to improper au…

Mitigation only
Fix from $2,300 2020-12-15
Cloud Pak For Security CRITICAL 9.0
CVE-2020-4627

IBM Cloud Pak for Security 1.3.0.1(CP4S) potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, c…

Patch available
Fix from $2,300 2020-11-30
Spectrum Protect Plus CRITICAL 9.8
CVE-2020-4854

IBM Spectrum Protect Plus 10.1.0 thorugh 10.1.6 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own i…

Fix: after 10.1.6
Fix from $2,300 2020-11-23
Security Access Manager CRITICAL 9.8
CVE-2020-4499

IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an unauthorized public Oauth client to bypass some or all of the …

Fix: 9.0.7.2 / 10.0.0.1+
Fix from $2,300 2020-10-15
Maximo Asset Management CRITICAL 9.8
CVE-2020-4493

IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow an attacker to bypass authentication and issue commands using a specially crafted HTTP comman…

Fix: 7.6.0.10 / 7.6.1.2+
Fix from $2,300 2020-10-05
Spectrum Protect Operations Center CRITICAL 9.8
CVE-2020-4693

IBM Spectrum Protect Operations Center 7.1.0.000 through 7.1.10 and 8.1.0.000 through 8.1.9 may allow an attacker to execute arbitrary code on the sy…

Fix: after 8.1.9.000
Fix from $2,300 2020-09-02
Guardium Data Encryption CRITICAL 9.8
CVE-2019-4694

IBM Security Guardium Data Encryption (GDE) 3.0.0.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its o…

Fix: 1.7.0+
Fix from $2,300 2020-08-26
Websphere Application Server CRITICAL 9.8
CVE-2020-4589EPSS 8%

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafte…

Fix: after 9.0.5.4
Fix from $2,300 2020-08-13
Security Secret Server CRITICAL 9.8
CVE-2020-4459

IBM Security Verify Access 10.7 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentic…

Fix: 10.8+
Fix from $2,300 2020-08-04
Cognos Analytics CRITICAL 9.1
CVE-2020-4377

IBM Cognos Anaytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could ex…

Mitigation only
Fix from $2,300 2020-08-03
Security Key Lifecycle Manager CRITICAL 9.8
CVE-2020-4567

IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account c…

Patch available
Fix from $2,300 2020-07-29
Verify Gateway CRITICAL 9.8
CVE-2020-4385

IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound …

Patch available
Fix from $2,300 2020-07-22
Spectrum Protect Plus CRITICAL 9.8
CVE-2020-4216

IBM Spectrum Protect Plus 10.1.0 through 10.1.5 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own i…

Fix: after 10.1.5
Fix from $2,300 2020-06-15