Vulnerability index

Browse CVEs

379 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Infosphere Information Server HIGH 7.5
CVE-2026-9836

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is affected by an information disclosure vulnerability.

Fix: after 11.7.1.6
Fix from $1,950 2026-06-30
Guardium Data Protection MEDIUM 6.5
CVE-2026-8405

IBM Guardium Data Protection 12.2.1, and 12.2.2 's add-on feature of Guardium Data Protection named "Long Term Retention" (LTR) can expose sensitive …

Mitigation only
Fix from $1,600 2026-05-27
Websphere Application Server HIGH 7.2
CVE-2025-14915

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty is affected by privilege escalation. A …

Fix: 26.0.0.4+
Fix from $1,950 2026-03-25
Planning Analytics Local MEDIUM 6.5
CVE-2026-1267

IBM Planning Analytics Local 2.1.0 through 2.1.17 could allow an unauthorized access to sensitive application data and administrative functionalities…

Fix: 2.1.18+
Fix from $1,600 2026-03-17
Db2 MEDIUM 6.5
CVE-2023-38729

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to sensitive information disclosure when using A…

Mitigation only
Fix from $1,600 2024-04-03
Security Verify Directory MEDIUM 5.3
CVE-2022-32751

IBM Security Verify Directory 10.0.0 could disclose sensitive server information that could be used in further attacks against the system. IBM X-For…

Mitigation only
Fix from $1,600 2024-03-22
Storage Protect Plus MEDIUM 5.5
CVE-2024-27277

The private key for the IBM Storage Protect Plus Server 10.1.0 through 10.1.16 certificate can be disclosed, undermining the security of the certific…

Fix: after 10.1.6
Fix from $1,600 2024-03-21
Security Verify Privilege On Premises HIGH 7.5
CVE-2022-43890

IBM Security Verify Privilege On-Premises 11.5 could disclose sensitive information through an HTTP request that could aid an attacker in further att…

Fix: after 11.5
Fix from $1,950 2024-03-04
Cognos Command Center MEDIUM 5.3
CVE-2023-50324

IBM Cognos Command Center 10.2.4.1 and 10.2.5 exposes details the X-AspNet-Version Response Header that could allow an attacker to obtain information…

Mitigation only
Fix from $1,600 2024-03-01
Urbancode Deploy MEDIUM 5.5
CVE-2024-22331

IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.19, 7.1 through 7.1.2.15, 7.2 through 7.2.3.8, 7.3 through 7.3.2.3, and IBM UrbanCode Deploy (UCD) - IBM…

Fix: 7.0.5.20 / 7.1.2.16+
Fix from $1,600 2024-02-06
Qradar Security Information And Event Manager MEDIUM 5.3
CVE-2023-50950

IBM QRadar SIEM 7.5 could disclose sensitive email information in responses from offense rules. IBM X-Force ID: 275709.

Patch available
Fix from $1,600 2024-01-17
Qradar Security Information And Event Manager MEDIUM 6.5
CVE-2023-47146

IBM Qradar SIEM 7.5 could allow a privileged user to obtain sensitive domain information due to data being misidentified. IBM X-Force ID: 270372.

Patch available
Fix from $1,600 2023-12-19
Cloud Pak For Security MEDIUM 6.5
CVE-2022-36777

IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.16.0could allow an authenticated us…

Fix: 1.10.17.0+
Fix from $1,600 2023-11-22
Robotic Process Automation For Cloud Pak MEDIUM 6.5
CVE-2023-45189

A vulnerability in IBM Robotic Process Automation and IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.10, 23.0.0 through 23.0.10 m…

Fix: after 23.0.10
Fix from $1,600 2023-11-03
Security Verify Privilege On Premises MEDIUM 5.3
CVE-2021-38859

IBM Security Verify Privilege On-Premises 11.5 could allow a user to obtain version number information using a specially crafted HTTP request that co…

Fix: 11.5+
Fix from $1,600 2023-10-17
Security Verify Privilege On Premises MEDIUM 5.3
CVE-2022-43889

IBM Security Verify Privilege On-Premises 11.5 could disclose sensitive information through an HTTP request that could aid an attacker in further att…

Fix: 11.5+
Fix from $1,600 2023-10-17
Security Verify Access Oidc Provider MEDIUM 5.3
CVE-2022-43868

IBM Security Verify Access OIDC Provider could disclose directory information that could aid attackers in further attacks against the system. IBM X-…

Patch available
Fix from $1,600 2023-10-14
Collaborative Lifecycle Management MEDIUM 5.5
CVE-2022-34355

IBM Jazz Foundation (IBM Engineering Lifecycle Management 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2) could disclose sensitive version information to a us…

Mitigation only
Fix from $1,600 2023-10-06
Disconnected Log Collector HIGH 7.5
CVE-2022-22447

IBM Disconnected Log Collector 1.0 through 1.8.2 is vulnerable to potential security misconfigurations that could disclose unintended information. I…

Fix: 1.8.3+
Fix from $1,950 2023-10-04
Robotic Process Automation MEDIUM 5.3
CVE-2023-38718

IBM Robotic Process Automation 21.0.0 through 21.0.7.8 could disclose sensitive information from access to RPA scripts, workflows and related data. …

Fix: after 23.0.8
Fix from $1,600 2023-09-20
Aspera Faspex MEDIUM 5.3
CVE-2022-22409

IBM Aspera Faspex 5.0.5 could allow a remote attacker to gather sensitive information about the web application, caused by an insecure configuration.…

Fix: after 5.0.5
Fix from $1,600 2023-09-08
Infosphere Information Server HIGH 7.5
CVE-2023-24959

IBM InfoSphere Information Systems 11.7 could expose information about the host system and environment configuration. IBM X-Force ID: 246332.

Fix: 11.7.1.0 / 11.7.1.4+
Fix from $1,950 2023-08-28
Cloud Pak For Data HIGH 7.5
CVE-2023-26026

Planning Analytics Cartridge for Cloud Pak for Data 4.0 exposes sensitive information in logs which could lead an attacker to exploit this vulnerabil…

Patch available
Fix from $1,950 2023-07-19
Cloud Pak For Data HIGH 7.5
CVE-2023-27877

IBM Planning Analytics Cartridge for Cloud Pak for Data 4.0 connects to a CouchDB server. An attacker can exploit an insecure password policy to the …

Patch available
Fix from $1,950 2023-07-19
Infosphere Information Server MEDIUM 6.5
CVE-2023-35898

IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information due to an insecure security configuration in…

Patch available
Fix from $1,600 2023-07-19
Robotic Process Automation MEDIUM 5.3
CVE-2023-35900

IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.4 and 23.0.0 through 23.0.5 is vulnerable to disclosing server version information…

Fix: after 23.0.5
Fix from $1,600 2023-07-19
Infosphere Information Server MEDIUM 5.3
CVE-2023-33857

IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain system information using a specially crafted query that could aid in f…

Patch available
Fix from $1,600 2023-07-17
Cloud Pak For Security HIGH 7.5
CVE-2023-30993

IBM Cloud Pak for Security (CP4S) 1.9.0.0 through 1.9.2.0 could allow an attacker with a valid API key for one tenant to access data from another ten…

Fix: after 1.9.2.0
Fix from $1,950 2023-06-27
Qradar Security Information And Event Manager MEDIUM 6.5
CVE-2022-34352

IBM QRadar SIEM 7.5.0 is vulnerable to information exposure allowing a delegated Admin tenant user with a specific domain security profile assigned t…

Patch available
Fix from $1,600 2023-06-27
Security Directory Suite Va MEDIUM 6.5
CVE-2022-33159

IBM Security Directory Suite VA 8.0.1 through 8.0.1.19 stores user credentials in plain clear text which can be read by an authenticated user. IBM X…

Fix: after 8.0.1.19
Fix from $1,600 2023-06-15