Vulnerability index

Browse CVEs

385 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2025-0159 IBM FlashSystem (IBM Storage Virtualize (8.5.0.0 through 8.5.0.13, 8.5.1.0, 8.5.2.0 through 8.5.2.3, 8.5.3.0 through 8.5.3.1, 8.5.4.0, 8.6.0.0 throug… Storage Virtualize 8.5.0.14 / 8.6.0.6+ Fix from $2,3002025-02-28 CRITICAL 9.1 CVE-2022-43916 IBM App Connect Enterprise Certified Container 7.1, 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12… App Connect Enterprise Certified Container 12.8+ Fix from $2,3002025-01-30 CRITICAL 9.8 CVE-2023-35907 IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes it easier for attackers to co… Aspera Faspex after 5.0.10 Fix from $2,3002025-01-29 CRITICAL 9.8 CVE-2023-37398 IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes it easier for attackers to co… Aspera Faspex after 5.0.10 Fix from $2,3002025-01-29 CRITICAL 9.8 CVE-2023-50316 IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 is vulnerable to SQL injection. A remote attacker could send speciall… Sterling B2b Integrator after 6.2.0.1 Fix from $2,3002025-01-28 CRITICAL 9.8 CVE-2024-45647 IBM Security Verify Access 10.0.0 through 10.0.8 and IBM Security Verify Access Docker 10.0.0 through 10.0.8 could allow could an unverified user to … Security Verify Access after 10.0.8 Fix from $2,3002025-01-20 CRITICAL 9.1 CVE-2024-41783 IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow a privileged user to inject commands into the underlyi… Sterling Secure Proxy 6.0.3.1+ Fix from $2,3002025-01-19 CRITICAL 9.1 CVE-2024-38337 IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow an unauthorized attacker to retrieve or alter sensitiv… Sterling Secure Proxy 6.0.3.1+ Fix from $2,3002025-01-19 CRITICAL 9.1 CVE-2024-47113 IBM ICP - Voice Gateway 1.0.2, 1.0.2.4, 1.0.3, 1.0.4, 1.0.5, 1.0.6. 1.0.7, 1.0.7.1, and 1.0.8 could allow remote attacker to send specially crafted X… Voice Gateway Mitigation only Fix from $2,3002025-01-18 CRITICAL 9.8 CVE-2024-39727 IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 uses a web link with untrusted references to an external site. A remote… Engineering Lifecycle Optimization Engineering Insights Mitigation only Fix from $2,3002024-12-25 CRITICAL 9.0 CVE-2024-51466 IBM Cognos Analytics 11.2.0 through 11.2.4 FP4 and 12.0.0 through 12.0.4 is vulnerable to an Expression Language (EL) Injection vulnerability. A r… Cognos Analytics 11.2.4 / 12.0.4+ Fix from $2,3002024-12-20 CRITICAL 9.8 CVE-2024-25020 IBM Cognos Controller 11.0.0 and 11.0.1 is vulnerable to malicious file upload by allowing unrestricted filetype attachments in the Jou… Cognos Controller Mitigation only Fix from $2,3002024-12-03 CRITICAL 9.8 CVE-2024-40691 IBM Cognos Controller 11.0.0 and 11.0.1 could be vulnerable to malicious file upload by not validating the content of the file uploaded to the web … Cognos Controller Mitigation only Fix from $2,3002024-12-03 CRITICAL 9.8 CVE-2024-25019 IBM Cognos Controller 11.0.0 and 11.0.1 could be vulnerable to malicious file upload by not validating the type of file uploaded to Journal entry a… Cognos Controller Mitigation only Fix from $2,3002024-12-03 CRITICAL 9.8 CVE-2024-49805 IBM Security Verify Access Appliance 10.0.0 through 10.0.8 contains hard-coded credentials, such as a password or cryptographic key, which it uses … Security Verify Access after 10.0.8 Fix from $2,3002024-11-29 CRITICAL 9.8 CVE-2024-49806 IBM Security Verify Access Appliance 10.0.0 through 10.0.8 contains hard-coded credentials, such as a password or cryptographic key, which it uses … Security Verify Access after 10.0.8 Fix from $2,3002024-11-29 CRITICAL 9.8 CVE-2024-52360 IBM Concert Software 1.0.0, 1.0.1, 1.0.2, and 1.0.2.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, … Concert Mitigation only Fix from $2,3002024-11-19 CRITICAL 9.8 CVE-2024-45656 IBM Flexible Service Processor (FSP) FW860.00 through FW860.B3, FW950.00 through FW950.C0, FW1030.00 through FW1030.61, FW1050.00 through FW1050.21, … Power System E1080 \(9080 Hex\) Firmware Mitigation only Fix from $2,3002024-10-29 CRITICAL 9.8 CVE-2024-43177 IBM Concert 1.0.0 and 1.0.1 vulnerable to attacks that rely on the use of cookies without the SameSite attribute. Concert Mitigation only Fix from $2,3002024-10-22 CRITICAL 9.9 CVE-2024-45076 IBM webMethods Integration 10.15 could allow an authenticated user to upload and execute arbitrary files which could be executed on the underlying op… Webmethods Integration Mitigation only Fix from $2,3002024-09-04 CRITICAL 9.8 CVE-2024-39747 IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 uses default credentials for potentially critical functionality. Sterling Connect Direct Web Services 6.1.0.25 / 6.2.0.24+ Fix from $2,3002024-08-31 CRITICAL 9.8 CVE-2022-33162 IBM Security Directory Integrator 7.2.0 and Security Verify Directory Integrator 10.0.0 does not perform any authentication for functionality that re… Security Directory Integrator Mitigation only Fix from $2,3002024-08-16 CRITICAL 9.1 CVE-2024-35143 IBM Planning Analytics Local 2.0 and 2.1 connects to a MongoDB server. MongoDB, a document-oriented database system, is listening on the remote port,… Planning Analytics Workspace 2.0.97 / 2.1.4+ Fix from $2,3002024-08-04 CRITICAL 9.8 CVE-2024-40689 IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could all… Infosphere Information Server Mitigation only Fix from $2,3002024-07-26 CRITICAL 9.8 CVE-2024-39736 IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 is vulnerable to HTTP header injection, caused by improper validation of input by the HOS… Datacap Mitigation only Fix from $2,3002024-07-15 CRITICAL 9.8 CVE-2024-39742 IBM MQ Operator 3.2.2 and IBM MQ Operator 2.0.24 could allow a user to bypass authentication under certain configurations due to a partial string com… Mq Operator 2.0.24 / 3.2.2+ Fix from $2,3002024-07-08 CRITICAL 9.8 CVE-2023-45188 IBM Engineering Lifecycle Optimization Publishing 7.0.2 and 7.03 could allow a remote attacker to upload arbitrary files, caused by the improper vali… Engineering Lifecycle Optimization Publishing Mitigation only Fix from $2,3002024-06-09 CRITICAL 9.8 CVE-2023-43040 IBM Spectrum Fusion HCI 2.5.2 through 2.7.2 could allow an attacker to perform unauthorized actions in RGW for Ceph due to improper bucket access. I… Storage Fusion Hci 2.8.0+ Fix from $2,3002024-05-14 CRITICAL 9.8 CVE-2023-38724 IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which… Cognos Controller Mitigation only Fix from $2,3002024-05-03 CRITICAL 10.0 CVE-2024-25029 IBM Personal Communications 14.0.6 through 15.0.1 includes a Windows service that is vulnerable to remote code execution (RCE) and local privilege es… Personal Communications after 15.0.1 Fix from $2,3002024-04-06