Vulnerability index

Browse CVEs

16 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
Security Access Manager MEDIUM 5.5
CVE-2024-35139

IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain sensitive information from the container due to incor…

Fix: after 10.0.7.1
Fix from $1,600 2024-06-28
Security Access Manager MEDIUM 6.5
CVE-2023-38370

IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1, under certain configurations, could allow a user on the network to install malicious pa…

Fix: after 10.0.7.1
Fix from $1,600 2024-06-27
I HIGH 7.8
CVE-2024-27264

IBM Performance Tools for i 7.2, 7.3, 7.4, and 7.5 could allow a local user to gain elevated privileges due to an unqualified library call. A malici…

Mitigation only
Fix from $1,950 2024-05-22
Infosphere Information Server MEDIUM 6.5
CVE-2023-40363

IBM InfoSphere Information Server 11.7 could allow an authenticated user to change installation files due to incorrect file permission settings. IBM…

Mitigation only
Fix from $1,600 2023-11-18
Manage Application MEDIUM 6.5
CVE-2022-46774

IBM Manage Application 8.8.0 and 8.9.0 in the IBM Maximo Application Suite is vulnerable to incorrect default permissions which could give access to …

Mitigation only
Fix from $1,600 2023-03-15
Sterling B2b Integrator HIGH 8.8
CVE-2022-40232

IBM Sterling B2B Integrator Standard Edition 6.1.0.0 through 6.1.1.1, and 6.1.2.0 could allow an authenticated user to perform actions they should no…

Fix: after 6.1.1.1
Fix from $1,950 2023-02-17
Robotic Process Automation HIGH 7.5
CVE-2022-43574

"IBM Robotic Process Automation 21.0.1, 21.0.2, 21.0.3, 21.0.4, and 21.0.5 is vulnerable to incorrect permission assignment which could allow access …

Fix: 21.0.6+
Fix from $1,950 2022-11-03
Sterling B2b Integrator MEDIUM 6.5
CVE-2021-39087

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 could allow an authenticat…

Fix: 6.0.3.6 / 6.1.0.5+
Fix from $1,600 2022-08-16
Qradar Security Information And Event Manager MEDIUM 5.5
CVE-2022-22424

IBM QRadar SIEM 7.3, 7.4, and 7.5 could allow a local user to obtain sensitive information from the TLS key file due to incorrect file permissions. I…

Fix: 7.3.3 / 7.4.3+
Fix from $1,600 2022-07-20
Spectrum Protect Plus MEDIUM 5.5
CVE-2021-20490

IBM Spectrum Protect Plus 10.1.0 through 10.1.8 could allow a local user to cause a denial of service due to insecure file permission settings. IBM X…

Fix: after 10.1.8
Fix from $1,600 2021-06-29
Spectrum Protect Backup Archive Client HIGH 7.8
CVE-2021-20532

IBM Spectrum Protect Client 8.1.0.0 through 8.1.11.0 could allow a local user to escalate their privileges to take full control of the system due to …

Fix: after 8.1.11.0
Fix from $1,950 2021-04-26
Sterling File Gateway MEDIUM 6.5
CVE-2020-4259

IBM Sterling File Gateway 2.2.0.0 through 6.0.3.1 could allow an authenticated user could manipulate cookie information and remove or add modules fro…

Fix: after 6.0.3.1
Fix from $1,600 2020-05-14
Qradar Security Information And Event Manager HIGH 7.8
CVE-2020-4270

IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow a local user to gain escalated privileges due to weak file permissions. IBM X-ForceID: 175846.

Fix: 7.3.3+
Fix from $1,950 2020-04-15
Qradar Security Information And Event Manager MEDIUM 5.4
CVE-2020-4274

IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow an authenticated user to access data and perform unauthorized actions due to inadequate permission chec…

Fix: 7.3.3+
Fix from $1,600 2020-04-15
Spectrum Protect Plus HIGH 7.1
CVE-2019-4652

IBM Spectrum Protect Plus 10.1.0 through 10.1.4 uses insecure file permissions on restored files and directories in Windows which could allow a local…

Fix: after 10.1.4
Fix from $1,950 2019-11-12
Websphere Application Server HIGH 7.1
CVE-2017-1382

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 might create files using the default permissions instead of the customized permissions when c…

Fix: after 9.0.0.4
Fix from $1,950 2017-07-24