Vulnerability index

Browse CVEs

228 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Db2 HIGH 7.5
CVE-2023-27555

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5 is vulnerable to a denial of service when attempting to use ACR client affinit…

Fix: 11.1.4 / 11.5.8+
Fix from $1,950 2023-04-28
Db2 MEDIUM 5.9
CVE-2023-25930

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.1, 11.1, and 11.5 is vulnerable to a denial of service. Under rare conditions, …

Fix: 11.1.4 / 11.5.8+
Fix from $1,600 2023-04-28
Db2 HIGH 7.5
CVE-2023-29255

IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as it may trap when compi…

Fix: 11.1.4 / 11.5.8+
Fix from $1,950 2023-04-27
Db2 HIGH 7.5
CVE-2023-27559

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may crash w…

Fix: 11.1.4 / 11.5.8+
Fix from $1,950 2023-04-26
Qradar Security Information And Event Manager HIGH 7.2
CVE-2022-43863

IBM QRadar SIEM 7.4 and 7.5 is vulnerable to privilege escalation, allowing a user with some admin capabilities to gain additional admin capabilities…

Fix: 7.4.3+
Fix from $1,950 2023-03-22
Spectrum Symphony MEDIUM 6.1
CVE-2023-24975

IBM Spectrum Symphony 7.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an att…

Mitigation only
Fix from $1,600 2023-03-10
Financial Transaction Manager HIGH 8.8
CVE-2020-5002

IBM Financial Transaction Manager 3.2.0 through 3.2.10 could allow an authenticated user to perform unauthorized actions due to improper validation. …

Fix: 3.2.11+
Fix from $1,950 2023-03-10
HTTP Server HIGH 7.5
CVE-2023-26281

IBM HTTP Server 8.5 used by IBM WebSphere Application Server could allow a remote user to cause a denial of service using a specially crafted URL. I…

Patch available
Fix from $1,950 2023-03-01
Mq For Hpe Nonstop HIGH 7.5
CVE-2022-40237

IBM MQ for HPE NonStop 8.1.0 is vulnerable to a denial of service attack due to an error within the CCDT and channel synchronization logic. IBM X-Fo…

Patch available
Fix from $1,950 2023-02-27
Db2 HIGH 7.5
CVE-2022-43929

IBM Db2 for Linux, UNIX and Windows 11.1 and 11.5 may be vulnerable to a Denial of Service when executing a specially crafted 'Load' command. IBM X-F…

Patch available
Fix from $1,950 2023-02-17
Api Connect HIGH 7.5
CVE-2022-34350

IBM API Connect 10.0.0.0 through 10.0.5.0, 10.0.1.0 through 10.0.1.7, and 2018.4.1.0 through 2018.4.1.20 is vulnerable to External Service Interactio…

Fix: after 2018.4.1.20
Fix from $1,950 2023-02-08
Infosphere Information Server MEDIUM 5.3
CVE-2022-41733

IBM InfoSphere Information Server 11.7 could allow a remote attacked to cause some of the components to be unusable until the process is restarted. I…

Fix: 11.7.1.4+
Fix from $1,600 2023-01-20
Vios MEDIUM 6.2
CVE-2022-43848

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX perfstat kernel extension to cause …

Patch available
Fix from $1,600 2022-12-23
Vios MEDIUM 6.2
CVE-2022-43849

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a non-privileged local user to exploit a vulnerability in the AIX pfcdd kernel extension to cause a de…

Patch available
Fix from $1,600 2022-12-23
Vios MEDIUM 6.2
CVE-2022-40233

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX TCP/IP kernel extension to cause a …

Patch available
Fix from $1,600 2022-12-23
Financial Transaction Manager MEDIUM 5.5
CVE-2022-43875

IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 could allow an authenticated user to lock additional RM authorizations,…

Patch available
Fix from $1,600 2022-12-20
Cloud Pak For Security HIGH 8.1
CVE-2022-38385

IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.2.0 could allow an authenticated user to obtain highly sensitive information or perform unaut…

Fix: after 1.10.2.0
Fix from $1,950 2022-11-15
Mq MEDIUM 6.5
CVE-2022-31772

IBM MQ 8.0, 9.0 LTS, 9.1 CD, 9.1 LTS, 9.2 CD, and 9.2 LTS could allow an authenticated and authorized user to cause a denial of service to the MQTT c…

Patch available
Fix from $1,600 2022-11-11
Infosphere Information Server MEDIUM 6.5
CVE-2022-40235

"IBM InfoSphere Information Server 11.7 could allow a user to cause a denial of service by removing the ability to run jobs due to improper input val…

Patch available
Fix from $1,600 2022-11-03
Common Cryptographic Architecture MEDIUM 5.5
CVE-2022-22423

IBM Common Cryptographic Architecture (CCA 5.x MTM for 4767 and CCA 7.x MTM for 4769) could allow a local user to cause a denial of service due to im…

Fix: 5.7.12 / 7.3.44+
Fix from $1,600 2022-09-23
Cics Tx MEDIUM 5.5
CVE-2022-34164

IBM CICS TX 11.1 could allow a local user to impersonate another legitimate user due to improper input validation. IBM X-Force ID: 229338.

Patch available
Fix from $1,600 2022-08-01
Robotic Process Automation HIGH 7.5
CVE-2022-22433

IBM Robotic Process Automation 21.0.1 and 21.0.2 is vulnerable to External Service Interaction attack, caused by improper validation of user-supplied…

Fix: 21.0.1.5+
Fix from $1,950 2022-05-05
Security Verify Access MEDIUM 6.5
CVE-2022-22311

IBM Security Verify Access could allow a user, using man in the middle techniques, to obtain sensitive information or possibly change some informatio…

Patch available
Fix from $1,600 2022-03-31
Datapower Gateway MEDIUM 5.3
CVE-2021-38910

IBM DataPower Gateway V10CD, 10.0.1, and 2108.4.1 could allow a remote attacker to bypass security restrictions, caused by the improper validation of…

Fix: after 2018.4.1.18
Fix from $1,600 2022-03-10
Security Guardium Insights HIGH 8.8
CVE-2021-29845

IBM Security Guardium Insights 3.0 could allow an authenticated user to perform unauthorized actions due to improper input validation. IBM X-Force ID…

Patch available
Fix from $1,950 2022-01-26
Security Verify Access HIGH 7.5
CVE-2021-38957

IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 could disclose sensitive information due to hazardous input validation during QR code generation. …

Patch available
Fix from $1,950 2022-01-10
Security Secret Server MEDIUM 5.3
CVE-2021-20569

IBM Security Secret Server up to 11.0 could allow an attacker to enumerate usernames due to improper input validation. IBM X-Force ID: 199243.

Fix: 11.0+
Fix from $1,600 2021-09-14
Content Navigator MEDIUM 6.5
CVE-2021-29714

IBM Content Navigator 3.0.CD could allow a malicious user to cause a denial of service due to improper input validation. IBM X-Force ID: 200968.

Mitigation only
Fix from $1,600 2021-08-09
I2 Analyze MEDIUM 6.5
CVE-2021-29770

IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) could allow an authenticated user to perform unauthorized actions due to h…

Patch available
Fix from $1,600 2021-07-26
Spectrum Scale MEDIUM 6.0
CVE-2020-4981

IBM Spectrum Scale 5.0.4.1 through 5.1.0.3 could allow a local privileged user to overwrite files due to improper input validation. IBM X-Force ID: 1…

Fix: after 5.1.0.3
Fix from $1,600 2021-04-27