Vulnerability index

Browse CVEs

48 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Robotic Process Automation MEDIUM 6.5
CVE-2022-34338

IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could disclose sensitive information due to improper privilege management for storage provi…

Fix: 21.0.3+
Fix from $1,600 2022-08-01
Db2 HIGH 7.5
CVE-2022-22390

IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an information disclosure caused by improper privilege manag…

Mitigation only
Fix from $1,950 2022-06-24
Iss Blackice Pc Protection CRITICAL 9.8
CVE-2003-5001

A vulnerability was found in ISS BlackICE PC Protection and classified as critical. Affected by this issue is the component Cross Site Scripting Dete…

Mitigation only
Fix from $2,300 2022-03-28
Resilient Security Orchestration Automation And Response HIGH 7.5
CVE-2021-29802

IBM Security SOAR performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifie…

Fix: 1.6.1+
Fix from $1,950 2021-08-23
Event Streams HIGH 7.2
CVE-2021-29792

IBM Event Streams 10.0, 10.1, 10.2, and 10.3 could allow a user the CA private key to create their own certificates and deploy them in the cluster an…

Mitigation only
Fix from $1,950 2021-07-12
Security Guardium HIGH 7.3
CVE-2020-4184

IBM Security Guardium 11.2 performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or…

No fix yet
Fix from $1,950 2021-03-15
Security Guardium Insights HIGH 7.2
CVE-2020-4603

IBM Security Guardium Insights 2.0.1 performs an operation at a privilege level that is higher than the minimum level required, which creates new wea…

Patch available
Fix from $1,950 2020-08-27
Change And Configuration Management Database CRITICAL 9.8
CVE-2013-3323

A Privilege Escalation Vulnerability exists in IBM Maximo Asset Management 7.5, 7.1, and 6.2, when WebSeal with Basic Authentication is used, due to …

Mitigation only
Fix from $2,300 2020-02-18
Maximo For Oil And Gas HIGH 8.8
CVE-2019-4546

After installing the IBM Maximo Health- Safety and Environment Manager 7.6.1, a user is granted additional privileges that they are not normally allo…

Mitigation only
Fix from $1,950 2019-10-29
Websphere Application Server MEDIUM 6.5
CVE-2019-4477

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a user with access to audit logs to obtain sensitive information, caused by impro…

Fix: after 9.0.5.0
Fix from $1,600 2019-09-17
I MEDIUM 6.3
CVE-2019-4536

IBM i 7.4 users who have done a Restore User Profile (RSTUSRPRF) on a system which has been configured with Db2 Mirror for i might have user profiles…

Patch available
Fix from $1,600 2019-08-29
Db2 High Performance Unload Load HIGH 7.8
CVE-2019-4448

IBM DB2 High Performance Unload load for LUW 6.1, 6.1.0.1, 6.1.0.1 IF1, 6.1.0.2, 6.1.0.2 IF1, and 6.1.0.1 IF2 db2hpum and db2hpum_debug binaries are …

Patch available
Fix from $1,950 2019-08-26
Api Connect HIGH 7.2
CVE-2018-1973

IBM API Connect 5.0.0.0 through 5.0.8.4 allows a user with limited 'API Administrator level access to give themselves full 'Administrator' level acce…

Fix: after 5.0.8.4
Fix from $1,950 2018-12-20
Campaign HIGH 7.8
CVE-2018-1941

IBM Campaign 9.1.0 and 9.1.2 could allow a local user to obtain admini privileges due to the application not validating access permissions. IBM X-For…

Fix: 9.1.0.13 / 9.1.2.7+
Fix from $1,950 2018-12-05
Tivoli Storage Manager MEDIUM 5.5
CVE-2018-1550

IBM Spectrum Protect 7.1 and 8.1 could allow a local user to corrupt or delete highly sensitive information that would cause a denial of service to o…

Fix: after 8.1.4.1
Fix from $1,600 2018-09-26
Puredata System For Analytics HIGH 7.8
CVE-2018-1460

IBM Netezza Platform Software (IBM PureData System for Analytics 1.0.0) could allow a local user to modify a world writable file, which could be used…

No fix yet
Fix from $1,950 2018-06-15
Flashsystem 900 Firmware MEDIUM 6.5
CVE-2018-1495

IBM FlashSystem V840 and V900 products could allow an authenticated attacker with specialized access to overwrite arbitrary files which could cause a…

No fix yet
Fix from $1,600 2018-05-29
Urbancode Deploy MEDIUM 5.4
CVE-2017-1493

IBM UrbanCode Deploy (UCD) 6.1 and 6.2 could allow an authenticated user to edit objects that they should not have access to due to improper access c…

Mitigation only
Fix from $1,600 2018-01-09