Vulnerability index

Browse CVEs

379 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Powervm Hypervisor HIGH 7.5
CVE-2023-25683

IBM PowerVM Hypervisor FW950.00 through FW950.71, FW1010.00 through FW1010.40, FW1020.00 through FW1020.20, and FW1030.00 through FW1030.11 could all…

Mitigation only
Fix from $1,950 2023-06-15
Cics Tx MEDIUM 6.5
CVE-2023-33848

IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11.1 could allow a privileged user to obtain highly…

Mitigation only
Fix from $1,600 2023-06-07
Spectrum Virtualize MEDIUM 5.9
CVE-2023-27870

IBM Spectrum Virtualize 8.5, under certain circumstances, could disclose sensitive credential information while a download from Fix Central is in pro…

Patch available
Fix from $1,600 2023-05-11
Robotic Process Automation MEDIUM 6.5
CVE-2023-25680

IBM Robotic Process Automation 21.0.1 through 21.0.5 is vulnerable to insufficiently protecting credentials. Queue Provider credentials are not obf…

Fix: 21.0.6+
Fix from $1,600 2023-03-15
Spectrum Scale HIGH 8.2
CVE-2020-4927

A vulnerability in the Spectrum Scale 5.0.5.0 through 5.1.6.1 core component could allow unauthorized access to user data or injection of arbitrary d…

Fix: 5.1.7.0+
Fix from $1,950 2023-03-15
Sterling B2b Integrator MEDIUM 6.5
CVE-2023-22876

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.1 could allow a privileged user to obtain sensitive in…

Fix: 6.0.3.8 / 6.1.2.2+
Fix from $1,600 2023-03-15
Qradar Security Information And Event Manager HIGH 7.5
CVE-2022-34351

IBM QRadar SIEM 7.4 and 7.5 is vulnerable to information exposure allowing a non-tenant user with a specific domain security profile assigned to see …

Fix: 7.4.3+
Fix from $1,950 2023-02-17
Maximo Application Suite HIGH 7.5
CVE-2022-41734

IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message…

Patch available
Fix from $1,950 2023-02-17
Db2 HIGH 7.5
CVE-2022-43930

IBM Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 is vulnerable to an Information Disclosure as sensitive information may be included in a log…

Patch available
Fix from $1,950 2023-02-17
Db2 HIGH 7.5
CVE-2022-43927

IBM Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 is vulnerable to information Disclosure due to improper privilege management when a speciall…

Patch available
Fix from $1,950 2023-02-17
Cloud Pak For Security MEDIUM 6.5
CVE-2021-39089

IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.6.0 could allow an authenticated user to obtain sensitive information from a specially crafte…

Fix: after 1.10.6.0
Fix from $1,600 2023-01-20
Spectrum Virtualize MEDIUM 5.9
CVE-2022-39167

IBM Spectrum Virtualize 8.5, 8.4, 8.3, 8.2, and 7.8, under certain configurations, could disclose sensitive information to an attacker using man-in-t…

Patch available
Fix from $1,600 2023-01-19
Qradar Security Information And Event Manager HIGH 7.5
CVE-2023-22875

IBM QRadar SIEM 7.4 and 7.5copies certificate key files used for SSL/TLS in the QRadar web user interface to managed hosts in the deployment that do …

Mitigation only
Fix from $1,950 2023-01-17
Robotic Process Automation MEDIUM 5.3
CVE-2022-43573

IBM Robotic Process Automation 20.12 through 21.0.6 is vulnerable to exposure of the name and email for the creator/modifier of platform level object…

Fix: 21.0.7+
Fix from $1,600 2023-01-05
Sterling B2b Integrator MEDIUM 6.5
CVE-2022-22337

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 could disclose sensitive information to an authenticated user. IBM X-Force ID: …

Fix: 6.0.3.7 / 6.1.0.6+
Fix from $1,600 2023-01-04
Websphere Automation For Ibm Cloud Pak For Watson Aiops MEDIUM 5.5
CVE-2022-43901

IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps 1.4.3 could disclose sensitive information. An authenticated local attacker could exploit…

Fix: 1.4.3+
Fix from $1,600 2022-12-01
Cics Tx MEDIUM 5.3
CVE-2022-34329

IBM CICS TX 11.7 could allow an attacker to obtain sensitive information from HTTP response headers. IBM X-Force ID: 229467.

Patch available
Fix from $1,600 2022-11-14
Infosphere Information Server HIGH 7.5
CVE-2022-35715

IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is retur…

Mitigation only
Fix from $1,950 2022-08-10
Engineering Lifecycle Optimization Publishing MEDIUM 6.5
CVE-2021-39019

IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could disclose highly sensitive information through an HTTP…

Patch available
Fix from $1,600 2022-07-14
Qradar Network Security HIGH 7.5
CVE-2020-4159

IBM QRadar Network Security 5.4.0 and 5.5.0 discloses sensitive information to unauthorized users which could be used to mount further attacks agains…

Patch available
Fix from $1,950 2022-07-12
Robotic Process Automation MEDIUM 6.5
CVE-2022-30607

IBM Robotic Process Automation 20.10.0, 20.12.5, 21.0.0, 21.0.1, and 21.0.2 contains a vulnerability that could allow a user to obtain sensitive info…

Patch available
Fix from $1,600 2022-06-17
Security Identity Governance And Intelligence MEDIUM 5.3
CVE-2020-4957

IBM Security Identity Governance and Intelligence 5.2.6 could disclose sensitive information in URL parameters that could aid in future attacks again…

Patch available
Fix from $1,600 2022-05-17
Guardium Data Encryption MEDIUM 5.3
CVE-2021-39020

IBM Guardium Data Encryption (GDE) 4.0.0.7 and lower stores sensitive information in URL parameters. This may lead to information disclosure if unaut…

Fix: after 4.0.0.7
Fix from $1,600 2022-05-05
Power System Ac922 \(8335 Gtx\) Firmware HIGH 7.5
CVE-2021-38960

IBM OPENBMC OP920, OP930, and OP940 could allow an unauthenticated user to obtain sensitive information. IBM X-Force ID: 212047.

Mitigation only
Fix from $1,950 2022-02-04
Security Guardium Insights MEDIUM 5.9
CVE-2021-29838

IBM Security Guardium Insights 3.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Stric…

Patch available
Fix from $1,600 2022-01-26
Security Verify Access MEDIUM 5.3
CVE-2021-38956

IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 could disclose sensitive version information in HTTP response headers that could aid in further at…

Patch available
Fix from $1,600 2022-01-10
Cloud Pak For Security MEDIUM 6.5
CVE-2021-39013

IBM Cloud Pak for Security (CP4S) 1.7.2.0, 1.7.1.0, and 1.7.0.0 could allow an authenticated user to obtain sensitive information in HTTP responses t…

Mitigation only
Fix from $1,600 2021-12-22
Spectrum Protect Operations Center MEDIUM 5.5
CVE-2021-38901

IBM Spectrum Protect Operations Center 7.1, under special configurations, could allow a local user to obtain highly sensitive information. IBM X-Forc…

Fix: 7.1.14+
Fix from $1,600 2021-12-13
Mq Appliance MEDIUM 5.5
CVE-2021-38999

IBM MQ Appliance could allow a local attacker to obtain sensitive information by inclusion of sensitive data within trace.

Patch available
Fix from $1,600 2021-11-30
Mq Appliance MEDIUM 5.5
CVE-2021-39000

IBM MQ Appliance 9.2 CD and 9.2 LTS could allow a local attacker to obtain sensitive information by inclusion of sensitive data within diagnostics. I…

Patch available
Fix from $1,600 2021-11-30