Vulnerability index

Browse CVEs

379 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Security Secret Server MEDIUM 5.3
CVE-2021-20582

IBM Security Secret Server up to 11.0 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties…

Fix: 11.0+
Fix from $1,600 2021-09-14
Security Verify Access MEDIUM 5.3
CVE-2021-20498

IBM Security Verify Access Docker 10.0.0 reveals version information in HTTP requests that could be used in further attacks against the system. IBM X…

Patch available
Fix from $1,600 2021-07-15
Security Verify Access MEDIUM 5.3
CVE-2021-20585

IBM Security Verify Access 20.07 could disclose sensitive information in HTTP server headers that could be used in further attacks against the system…

Mitigation only
Fix from $1,600 2021-06-01
Cloud Pak For Security MEDIUM 5.3
CVE-2020-4815

IBM Cloud Pak for Security (CP4S) 1.4.0.0 could allow a remote user to obtain sensitive information from HTTP response headers that could be used in …

Patch available
Fix from $1,600 2021-01-27
Websphere Extreme Scale MEDIUM 5.3
CVE-2020-4336

IBM WebSphere eXtreme Scale 8.6.1 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties hav…

Fix: 8.6.1.4+
Fix from $1,600 2021-01-06
Financial Transaction Manager For Multiplatform MEDIUM 5.3
CVE-2020-4908

IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 returns the product version and release information on the login dialog…

Patch available
Fix from $1,600 2020-12-16
Security Guardium Insights MEDIUM 5.3
CVE-2020-4172

IBM Security Guardium Insights 2.0.1 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties …

Patch available
Fix from $1,600 2020-08-27
Security Guardium MEDIUM 5.3
CVE-2020-4186

IBM Security Guardium 10.5, 10.6, and 11.1 could disclose sensitive information on the login page that could aid in further attacks against the syste…

Patch available
Fix from $1,600 2020-07-30
Mq Appliance MEDIUM 5.5
CVE-2019-4731

IBM MQ Appliance 9.1.4.CD could allow a local attacker to obtain highly sensitive information by inclusion of sensitive data within trace. IBM X-Forc…

Patch available
Fix from $1,600 2020-07-28
Spectrum Protect Plus MEDIUM 5.9
CVE-2020-4565

IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow an attacker to obtain sensitive information due to insecure communications being used bet…

Fix: after 10.1.5
Fix from $1,600 2020-06-26
Mobilefirst Platform Foundation HIGH 7.5
CVE-2020-4226

IBM MobileFirst Platform Foundation 8.0.0.0 stores highly sensitive information in URL parameters. This may lead to information disclosure if unautho…

Patch available
Fix from $1,950 2020-05-27
Cloud App Management MEDIUM 5.3
CVE-2019-4751

IBM Cloud App Management 2019.3.0 and 2019.4.0 reveals a stack trace on certain API requests which can allow an attacker further information about th…

Mitigation only
Fix from $1,600 2020-04-24
Mq MEDIUM 5.5
CVE-2020-4338

IBM MQ 9.1.4 could allow a local attacker to obtain sensitive information by inclusion of sensitive data within runmqras data. IBM X-Force ID: 177937.

Fix: 9.1.5+
Fix from $1,600 2020-04-16
Content Navigator MEDIUM 5.3
CVE-2020-4309

IBM Content Navigator 3.0CD could disclose sensitive information to an unauthenticated user which could be used to aid in further attacks against the…

Patch available
Fix from $1,600 2020-03-24
Security Directory Server MEDIUM 5.3
CVE-2019-4562

IBM Security Directory Server 6.4.0 stores sensitive information in URLs. This may lead to information disclosure if unauthorized parties have access…

Fix: 6.4.0.20+
Fix from $1,600 2020-02-04
Qradar Security Information And Event Manager MEDIUM 5.3
CVE-2019-4559

IBM QRadar SIEM 7.3.0 through 7.3.3 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on th…

Fix: after 7.3.3
Fix from $1,600 2020-01-10
Watston Studio Local MEDIUM 5.3
CVE-2018-1682

IBM Watson Studio Local 1.2.3 could disclose sensitive information over the network that an attacked could use in further attacks against the system.…

Patch available
Fix from $1,600 2019-12-30
Api Connect MEDIUM 5.5
CVE-2019-4444

IBM API Connect 2018.1 through 2018.4.1.7 Developer Portal's user registration page does not disable password autocomplete. An attacker with access t…

Fix: after 2018.4.1.7
Fix from $1,600 2019-12-16
Cognos Controller MEDIUM 5.3
CVE-2019-4412

IBM Cognos Controller stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to …

Patch available
Fix from $1,600 2019-11-09
Cloud Orchestrator MEDIUM 6.5
CVE-2019-4397

IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.5 through 2.5.0.9 and 2.4 through 2.4.0.5 stores sensitive information in URL paramete…

Fix: after 2.5.0.9
Fix from $1,600 2019-10-24
Security Key Lifecycle Manager MEDIUM 5.3
CVE-2019-4514

IBM Security Key Lifecycle Manager 2.6, 2.7, 3.0, and 3.0.1 discloses sensitive information to unauthorized users. The information can be used to mou…

Fix: after 3.0.1.1
Fix from $1,600 2019-10-04
Api Connect MEDIUM 5.3
CVE-2019-4437

IBM API Connect 2018.1 through 2018.4.1.6 may inadvertently leak sensitive details about internal servers and network via API swagger. IBM X-force ID…

Fix: after 2018.4.1.6
Fix from $1,600 2019-08-20
Qradar Security Information And Event Manager MEDIUM 5.3
CVE-2018-2022

IBM QRadar SIEM 7.2 and 7.3 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system…

Fix: 7.2.8+
Fix from $1,600 2019-07-17
Jazz For Service Management HIGH 7.5
CVE-2019-4193

IBM Jazz for Service Management 1.1.3 and 1.1.3.2 stores sensitive information in URL parameters. This may lead to information disclosure if unauthor…

Fix: after 1.1.3.2
Fix from $1,950 2019-07-11
Security Identity Manager Virtual Appliance MEDIUM 5.3
CVE-2018-1968

IBM Security Identity Manager 7.0.1 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on th…

Fix: after 7.0.1.12
Fix from $1,600 2019-07-11
Spectrum Protect HIGH 7.1
CVE-2019-4140

IBM Tivoli Storage Manager Server (IBM Spectrum Protect 7.1 and 8.1) could allow a local user to replace existing databases by restoring old data. IB…

Fix: 7.1.9.300 / 8.1.8.0+
Fix from $1,950 2019-07-02
Api Connect MEDIUM 5.3
CVE-2018-2011

IBM API Connect 2018.1 through 2018.4.1.5 could allow an attacker to obtain sensitive information from a specially crafted HTTP request that could ai…

Fix: after 2018.4.1.5
Fix from $1,600 2019-06-25
Api Connect MEDIUM 5.3
CVE-2018-2013

IBM API Connect 2018.1 through 2018.4.1.5 could disclose sensitive information to an unauthorized user that could aid in further attacks against the …

Fix: after 2018.4.1.5
Fix from $1,600 2019-06-25
Cognos Controller MEDIUM 6.5
CVE-2019-4173

IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 could allow a remote attacker to obtain sensitive information, caused by a flaw in t…

Patch available
Fix from $1,600 2019-06-17
Cloud App Management MEDIUM 5.3
CVE-2018-1990

IBM Cloud App Management V2018.2.0, V2018.4.0, and V2018.4.1 could allow an attacker to obtain sensitive configuration information using a specially …

Patch available
Fix from $1,600 2019-05-10