Vulnerability index

Browse CVEs

385 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2022-31767EPSS 5% IBM CICS TX Standard and Advanced 11.1 could allow a remote attacker to execute arbitrary commands on the system by sending a specially crafted reque… Cics Tx 11.1+ Fix from $2,3002022-06-24 CRITICAL 9.8 CVE-2021-38945 IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 could allow a remote attacker to upload arbitrary files, caused by improper content validation. IBM X… Cognos Analytics 11.1.7+ Fix from $2,3002022-06-24 CRITICAL 9.8 CVE-2022-22317 IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate a… Curam Social Program Management Patch available Fix from $2,3002022-06-20 CRITICAL 9.8 CVE-2022-22318 IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate a… Curam Social Program Management Patch available Fix from $2,3002022-06-20 CRITICAL 9.8 CVE-2022-22485 In some cases, an unsuccessful attempt to log into IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14.000 does not cause the administrat… Spectrum Protect Operations Center after 8.1.14.000 Fix from $2,3002022-06-17 CRITICAL 9.8 CVE-2019-4575 IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.2.0 through 3.2.9 is vulnerable to SQL injection. A remote attacker could… Financial Transaction Manager after 3.2.9 Fix from $2,3002022-06-15 CRITICAL 9.8 CVE-2022-31768 IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could all… Infosphere Information Server Patch available Fix from $2,3002022-06-06 CRITICAL 9.1 CVE-2020-4926 A vulnerability in the Spectrum Scale 5.1 core component and IBM Elastic Storage System 6.1 could allow unauthorized access to user data or injection… Elastic Storage System 5.1.3.0 / 6.1.3.0+ Fix from $2,3002022-05-24 CRITICAL 9.8 CVE-2022-22413 IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statemen… Robotic Process Automation Mitigation only Fix from $2,3002022-05-12 CRITICAL 9.8 CVE-2021-38969 IBM Spectrum Virtualize 8.2, 8.3, and 8.4 could allow an attacker to allow unauthorized access due to the reuse of support generated credentials. IBM… Spectrum Virtualize Mitigation only Fix from $2,3002022-05-11 CRITICAL 9.8 CVE-2021-38869 IBM QRadar SIEM 7.3, 7.4, and 7.5 in some situations may not automatically log users out after they exceede their idle timeout. IBM X-Force ID: 20834… Qradar Security Information And Event Manager 7.3.3 / 7.4.3+ Fix from $2,3002022-04-27 CRITICAL 9.8 CVE-2003-5001 A vulnerability was found in ISS BlackICE PC Protection and classified as critical. Affected by this issue is the component Cross Site Scripting Dete… Iss Blackice Pc Protection Mitigation only Fix from $2,3002022-03-28 CRITICAL 9.1 CVE-2022-22374 The BMC (IBM Power 9 AC922 OP910, OP920, OP930, and OP940) may be subject to a firmware downgrade attack which may affect its ability to operate its … Power 9 Ac922 Firmware Mitigation only Fix from $2,3002022-03-24 CRITICAL 9.8 CVE-2021-39070 IBM Security Verify Access 10.0.0.0, 10.0.1.0 and 10.0.2.0 with the advanced access control authentication service enabled could allow an attacker to… Security Verify Access Mitigation only Fix from $2,3002022-02-02 CRITICAL 9.8 CVE-2020-4877 IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could be vulnerable to unauthorized modifications by using public fields in public classes. IBM X-Fo… Cognos Controller Mitigation only Fix from $2,3002022-01-21 CRITICAL 9.8 CVE-2020-4879 IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could allow a remote attacker to bypass security restrictions, caused by improper validation of auth… Cognos Controller Mitigation only Fix from $2,3002022-01-21 CRITICAL 9.1 CVE-2021-39063 IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged a… Spectrum Protect Plus 10.1.9+ Fix from $2,3002021-12-13 CRITICAL 9.8 CVE-2021-39052 IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to access the Spring Boot console without authorization. IBM X-For… Spectrum Copy Data Management after 2.2.13 Fix from $2,3002021-12-13 CRITICAL 9.8 CVE-2021-39065 IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to execute arbitrary commands on the system, caused by improper va… Spectrum Copy Data Management after 2.2.13 Fix from $2,3002021-12-13 CRITICAL 9.1 CVE-2021-38917 IBM PowerVM Hypervisor FW860, FW940, and FW950 could allow an attacker that gains service access to the FSP can read and write arbitrary host system … Powervm Hypervisor Mitigation only Fix from $2,3002021-12-10 CRITICAL 9.1 CVE-2021-38948 IBM InfoSphere Information Server 11.7 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker cou… Infosphere Information Server Patch available Fix from $2,3002021-11-02 CRITICAL 9.8 CVE-2021-29908 The IBM TS7700 Management Interface is vulnerable to unauthenticated access. By accessing a specially-crafted URL, an attacker may gain administrativ… Ts7700 Firmware Mitigation only Fix from $2,3002021-10-06 CRITICAL 9.1 CVE-2021-38923 IBM PowerVM Hypervisor FW1010 could allow a privileged user to gain access to another VM due to assigning duplicate WWPNs. IBM X-Force ID: 210162. Powervm Hypervisor Firmware Mitigation only Fix from $2,3002021-10-06 CRITICAL 9.8 CVE-2021-29798 IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted S… Sterling B2b Integrator after 6.1.0.3 Fix from $2,3002021-10-06 CRITICAL 9.8 CVE-2021-29903 IBM Sterling B2B Integrator Standard Edition 5.2.6.0 through 6.1.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted S… Sterling B2b Integrator after 6.1.0.3 Fix from $2,3002021-10-06 CRITICAL 9.8 CVE-2021-20578 IBM Cloud Pak for Security (CP4S) 1.7.0.0, 1.7.1.0, 1.7.2.0, and 1.8.0.0 could allow an attacker to perform unauthorized actions due to improper or m… Cloud Pak For Security Patch available Fix from $2,3002021-09-30 CRITICAL 9.8 CVE-2020-4690 IBM Security Guardium 11.3 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication… Security Guardium Patch available Fix from $2,3002021-09-23 CRITICAL 9.8 CVE-2021-29772 IBM API Connect 5.0.0.0 through 5.0.8.11 could allow a user to potentially inject code due to unsanitized user input. IBM X-Force ID: 202774. Api Connect after 5.0.8.11 Fix from $2,3002021-08-26 CRITICAL 9.1 CVE-2021-29715 IBM API Connect 5.0.0.0 through 5.0.8.11 could alllow a remote user to obtain sensitive information or conduct denial of serivce attacks due to open … Api Connect after 5.0.8.11 Fix from $2,3002021-08-26 CRITICAL 9.8 CVE-2021-20509 IBM Maximo Asset Management 7.6.0 and 7.6.1 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the sys… Maximo Asset Management 7.6.1.2+ Fix from $2,3002021-08-12