Vulnerability index

Browse CVEs

228 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Security Identity Governance And Intelligence MEDIUM 6.5
CVE-2020-4790

IBM Security Identity Governance and Intelligence 5.2.6 could allow a user to cause a denial of service due to improperly validating a supplied URL, …

Patch available
Fix from $1,600 2021-02-09
Api Connect MEDIUM 6.5
CVE-2020-4828

IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 is vulnerable to web cache poisoning, caused by improper input validatio…

Fix: after 2018.4.1.13
Fix from $1,600 2021-02-04
Emptoris Sourcing MEDIUM 6.5
CVE-2020-4896

IBM Emptoris Sourcing 10.1.0, 10.1.1, and 10.1.3 is vulnerable to web cache poisoning, caused by improper input validation by modifying HTTP request …

Fix: 10.1.0.38 / 10.1.1.35+
Fix from $1,600 2021-01-07
Resilient Security Orchestration Automation And Response HIGH 8.8
CVE-2020-4633

IBM Resilient SOAR V38.0 could allow a remote attacker to execute arbitrary code on the system, caused by formula injection due to improper input val…

Mitigation only
Fix from $1,950 2020-12-11
Curam Social Program Management MEDIUM 6.5
CVE-2020-4781

An improper input validation before calling java readLine() method may impact IBM Curam Social Program Management 7.0.9 and 7.0.10, which could resul…

Mitigation only
Fix from $1,600 2020-10-12
Security Verify Privilege Vault Remote On Premises HIGH 7.8
CVE-2020-4607

IBM Security Secret Server (IBM Security Verify Privilege Vault Remote 1.2 ) could allow a local user to bypass security restrictions due to improper…

Patch available
Fix from $1,950 2020-09-29
Spectrum Protect Operations Center CRITICAL 9.8
CVE-2020-4693

IBM Spectrum Protect Operations Center 7.1.0.000 through 7.1.10 and 8.1.0.000 through 8.1.9 may allow an attacker to execute arbitrary code on the sy…

Fix: after 8.1.9.000
Fix from $2,300 2020-09-02
Infosphere Guardium MEDIUM 5.3
CVE-2012-3338

IBM InfoSphere Guardium 8.0, 8.01, and 8.2 could allow a remote attacker to bypass security restrictions, caused by improper restrictions on the crea…

Mitigation only
Fix from $1,600 2020-09-01
Spectrum Protect HIGH 7.5
CVE-2020-4559

IBM Spectrum Protect 7.1 and 8.1 could allow an attacker to cause a denial of service due ti improper validation of user-supplied input. IBM X-Force …

Fix: after 8.1.10.000
Fix from $1,950 2020-08-28
Aspera Application Platform On Demand HIGH 7.5
CVE-2020-4433EPSS 5%

Certain IBM Aspera applications are vulnerable to a stack-based buffer overflow, caused by improper bounds checking. This could allow a remote attack…

Fix: after 3.9.10
Fix from $1,950 2020-06-10
Security Identity Governance And Intelligence MEDIUM 6.5
CVE-2020-4231

IBM Security Identity Governance and Intelligence 5.2.6 could allow an authenticated user to perform unauthorized commands due to hazardous input val…

Patch available
Fix from $1,600 2020-05-28
Spectrum Scale HIGH 7.1
CVE-2020-4411

The Spectrum Scale 4.2.0.0 through 4.2.3.21 and 5.0.0.0 through 5.0.4.3 file system component is affected by a denial of service vulnerability in its…

Fix: after 5.0.4.3
Fix from $1,950 2020-05-19
Spectrum Protect CRITICAL 9.8
CVE-2020-4415EPSS 8%

IBM Spectrum Protect 7.1 and 8.1 server is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. This could allow a remote…

Fix: after 8.1.9.200
Fix from $2,300 2020-04-23
Qradar Security Information And Event Manager MEDIUM 6.5
CVE-2020-4151

IBM QRadar SIEM 7.3.0 through 7.3.3 could allow an authenticated attacker to perform unauthorized actions due to improper input validation. IBM X-For…

Fix: after 7.3.3
Fix from $1,600 2020-04-14
Spectrum Protect Plus HIGH 7.5
CVE-2020-4214

IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to arbitrary delete a directory caused by improper validation of user-s…

Fix: after 10.1.5
Fix from $1,950 2020-03-31
Spectrum Protect Plus HIGH 8.8
CVE-2020-4206

IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to execute arbitrary commands on the system in the context of root user…

Fix: after 10.1.5
Fix from $1,950 2020-03-31
Spectrum Protect CRITICAL 9.8
CVE-2020-4212EPSS 15%

IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP …

Fix: 10.1.5+
Fix from $2,300 2020-02-24
Mq Appliance HIGH 7.8
CVE-2019-4620

IBM MQ Appliance 8.0 and 9.0 LTS could allow a local attacker to bypass security restrictions caused by improper validation of environment variables.…

Fix: 8.0.0.14 / 9.1.0.4+
Fix from $1,950 2020-01-28
Api Connect MEDIUM 6.1
CVE-2018-2015

IBM API Connect 2018.1 and 2018.4.1.4 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a ma…

Fix: after 2018.4.1.4
Fix from $1,600 2019-05-02
Security Privileged Identity Manager HIGH 8.8
CVE-2018-1640

IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 could allow a remote authenticated attacker to execute arbitrary commands on the sys…

Mitigation only
Fix from $1,950 2019-04-02
Rational Collaborative Lifecycle Management MEDIUM 5.4
CVE-2018-1658

IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 through 6.0.6) is vulnerable to HTTP header injection, caused by improper va…

Fix: after 6.0.6
Fix from $1,600 2019-03-14
Security Identity Governance And Intelligence MEDIUM 6.1
CVE-2018-1945

IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance could allow a remote attacker to hijack the clicking action o…

Fix: after 5.2.4.1
Fix from $1,600 2019-02-21
Db2 MEDIUM 6.5
CVE-2018-1977

IBM DB2 for Linux, UNIX and Windows 11.1 (includes DB2 Connect Server) contains a denial of service vulnerability. A remote, authenticated DB2 user c…

Patch available
Fix from $1,600 2018-12-14
Bigfix Platform MEDIUM 6.1
CVE-2018-1478

IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 could allow a remote attacker to hijack the clicking action of the victim. By persuadi…

Fix: after 9.5.9
Fix from $1,600 2018-12-12
Datapower Gateway MEDIUM 5.5
CVE-2018-1652

IBM DataPower Gateway 7.1.0.0 through 7.1.0.19, 7.2.0.0 through 7.2.0.16, 7.5.0.0 through 7.5.0.10, 7.5.1.0 through 7.5.1.9, 7.5.2.0 through 7.5.2.9,…

Fix: after 9.0.5
Fix from $1,600 2018-12-11
I2 Enterprise Insight Analysis MEDIUM 6.1
CVE-2018-1504

IBM i2 Enterprise Insight Analysis 2.1.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a…

Mitigation only
Fix from $1,600 2018-12-06
Api Connect MEDIUM 5.4
CVE-2018-1599

IBM API Connect 5.0.0.0 through 5.0.8.3 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a …

Fix: after 2018.3.4
Fix from $1,600 2018-08-22
Websphere Mq MEDIUM 6.5
CVE-2018-1374

An IBM WebSphere MQ (Maintenance levels 7.1.0.0 - 7.1.0.9, 7.5.0.0 - 7.5.0.8, 8.0.0.0 - 8.0.0.8, 9.0.0.0 - 9.0.0.2, and 9.0.0 - 9.0.4) client connect…

Mitigation only
Fix from $1,600 2018-06-26
Websphere Mq MEDIUM 6.5
CVE-2017-1747

A specially crafted message could cause a denial of service in IBM WebSphere MQ 9.0, 9.0.0.1, 9.0.0.2, 9.0.1, 9.0.2, 9.0.3, and 9.0.4 applications co…

Patch available
Fix from $1,600 2018-03-30
Financial Transaction Manager MEDIUM 6.3
CVE-2016-0276

IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial Transaction Manager (FTM) fo…

Fix: after 3.0.0.12
Fix from $1,600 2018-03-09