Vulnerability index

Browse CVEs

79 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Informix Dynamic Server HIGH 7.8
CVE-2026-13367

IBM Informix Dynamic Server 14.10, and 15.0 contain a local privilege escalation vulnerability in the oninit setuid-root utility.

No fix yet
Fix from $4,900 2026-08-12
Sterling B2b Integrator MEDIUM 6.5
CVE-2026-7362

IBM Sterling B2B Integrator 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.1.0 through 6.2.1.1_2, and 6.2…

Fix: after 6.2.2.0_1
Fix from $1,600 2026-07-28
I CRITICAL 9.8
CVE-2026-2311

IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 s vulnerable to privilege escalation caused by an invalid IBM i Web Administration GUI authorization check.  A mali…

Mitigation only
Fix from $2,300 2026-04-30
Cics Transaction Gateway HIGH 7.1
CVE-2026-0977

IBM CICS Transaction Gateway for Multiplatforms 9.3 and 10.1 could allow a user to transfer or view files due to improper access controls.

Mitigation only
Fix from $1,950 2026-03-16
Transformation Extender Advanced MEDIUM 6.2
CVE-2023-50300

IBM Transformation Extender Advanced 10.0.1 could allow a local user to perform unauthorized actions due to improper access controls.

Mitigation only
Fix from $1,600 2025-10-01
I HIGH 7.8
CVE-2024-27264

IBM Performance Tools for i 7.2, 7.3, 7.4, and 7.5 could allow a local user to gain elevated privileges due to an unqualified library call. A malici…

Mitigation only
Fix from $1,950 2024-05-22
Soar Qradar Plugin App HIGH 8.8
CVE-2023-38263

IBM SOAR QRadar Plugin App 1.0 through 5.0.3 could allow an authenticated user to perform unauthorized actions due to improper access controls. IBM …

Fix: 5.0.3+
Fix from $1,950 2024-02-02
Maximo Asset Management CRITICAL 9.8
CVE-2023-32333

IBM Maximo Asset Management 7.6.1.3 could allow a remote attacker to log into the admin panel due to improper access controls. IBM X-Force ID: 2550…

Patch available
Fix from $2,300 2024-02-02
Aspera Faspex HIGH 7.5
CVE-2023-27875

IBM Aspera Faspex 5.0.4 could allow a user to change other user's credentials due to improper access controls. IBM X-Force ID: 249847.

Patch available
Fix from $1,950 2023-03-16
Infosphere Information Server MEDIUM 6.5
CVE-2022-22442

"IBM InfoSphere Information Server 11.7 could allow an authenticated user to access information restricted to users with elevated privileges due to i…

Patch available
Fix from $1,600 2022-11-03
Navigator Mobile MEDIUM 5.5
CVE-2022-38388

IBM Navigator Mobile Android 3.4.1.1 and 3.4.1.2 app could allow a local user to obtain sensitive information due to improper access control. IBM X-F…

Patch available
Fix from $1,600 2022-10-11
Qradar User Behavior Analytics MEDIUM 6.5
CVE-2022-36771

IBM QRadar User Behavior Analytics could allow an authenticated user to obtain sensitive information from that they should not have access to. IBM X-…

Fix: 4.1.9+
Fix from $1,600 2022-09-28
Websphere Cast Iron Cloud Integration HIGH 7.5
CVE-2013-2972

IBM WebSphere Cast Iron 6.3 allows remote attackers to bypass intended access restrictions via unspecified vectors. IBM X-Force ID: 83868.

Patch available
Fix from $1,950 2018-07-11
Spss Modeler MEDIUM 5.4
CVE-2013-6739

IBM SPSS Modeler before 16 on UNIX allows remote authenticated users to bypass intended access restrictions via an SSO token. IBM X-Force ID: 89855.

Fix: 16.0.0.0+
Fix from $1,600 2018-04-27
Integrated Management Module Firmware HIGH 7.4
CVE-2014-0881

The TPM on Integrated Management Module II (IMM2) on IBM Flex System x222 servers with firmware 1.00 through 3.56 allows remote attackers to obtain s…

Fix: after 3.56
Fix from $1,950 2018-04-25
Security Identity Manager MEDIUM 5.3
CVE-2014-6109

IBM Tivoli Identity Manager 5.1.x before 5.1.0.15-ISS-TIM-IF0057 and Security Identity Manager 6.0.x before 6.0.0.4-ISS-SIM-IF0001 and 7.0.x before 7…

Patch available
Fix from $1,600 2018-04-20
Tririga Application Platform MEDIUM 5.4
CVE-2016-0342

IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote authenticated users to read or modify a…

Fix: 3.3.2.6 / 3.4.2.3+
Fix from $1,600 2018-02-02
Business Process Manager MEDIUM 6.5
CVE-2015-0110

IBM Business Process Manager (aka BPM) 7.5.x, 8.0.x, and 8.5.x and WebSphere Lombardi Edition (aka WLE) 7.2.x allow remote authenticated users to byp…

Mitigation only
Fix from $1,600 2017-09-15
Security Key Lifecycle Manager HIGH 8.1
CVE-2016-6098

IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 specifies permissions for a security-critical resource in a way that allows that resource to be …

Patch available
Fix from $1,950 2017-06-08
Websphere Mq MEDIUM 5.5
CVE-2016-6089

IBM WebSphere MQ 9.0.0.1 and 9.0.2 could allow a local user to write to a file or delete files in a directory they should not have access to due to i…

Patch available
Fix from $1,600 2017-06-07
Maximo Asset Management HIGH 8.4
CVE-2016-9976

IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-craf…

Patch available
Fix from $1,950 2017-05-03
Bigfix Remote Control HIGH 7.5
CVE-2016-2930

IBM BigFix Remote Control 9.1.3 could allow a remote attacker to perform actions reserved for an administrator without authentication. IBM X-Force ID…

Patch available
Fix from $1,950 2017-05-03
Change And Configuration Management Database HIGH 8.8
CVE-2015-0104EPSS 7%

IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration Management Database 7.1 through 7.1.1.8 and 7.2 a…

Patch available
Fix from $1,950 2017-04-24
Websphere Mq MEDIUM 6.5
CVE-2016-8915

IBM WebSphere MQ 8.0 could allow an authenticated user with access to the queue manager and queue, to deny service to other channels running under th…

Patch available
Fix from $1,600 2017-02-22
Websphere Mq MEDIUM 6.5
CVE-2016-8986

IBM WebSphere MQ 8.0 could allow an authenticated user with access to the queue manager to bring down MQ channels using specially crafted HTTP reques…

Patch available
Fix from $1,600 2017-02-22
Cognos Disclosure Management MEDIUM 5.3
CVE-2016-6077

IBM Cognos Disclosure Management 10.2 could allow a malicious attacker to execute commands as a lower privileged user that opens a malicious document…

Patch available
Fix from $1,600 2017-02-15
System Storage Ts3100 Ts3200 Tape Library CRITICAL 9.8
CVE-2016-9005

IBM System Storage TS3100-TS3200 Tape Library could allow an unauthenticated user with access to the company network, to change a user's password and…

Mitigation only
Fix from $2,300 2017-02-08
Bigfix Platform HIGH 7.8
CVE-2016-0214

IBM Tivoli Endpoint Manager could allow a remote attacker to upload arbitrary files. A remote attacker could exploit this vulnerability to upload a m…

Patch available
Fix from $1,950 2017-02-08
Security Directory Server MEDIUM 5.5
CVE-2015-1976

IBM Security Directory Server could allow an authenticated user to execute commands into the web administration tool that would cause the tool to cra…

Fix: after 6.4.0.6
Fix from $1,600 2017-02-08
Security Access Manager For Web 7.0 Firmware MEDIUM 5.5
CVE-2016-3020

IBM Security Access Manager for Web 7.0.0, 8.0.0, and 9.0.0 could allow a remote attacker to bypass security restrictions, caused by improper content…

Patch available
Fix from $1,600 2017-02-07