Vulnerability index

Browse CVEs

93 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Connect\ CRITICAL 9.8
CVE-2020-4747

IBM Connect:Direct for UNIX 6.1.0, 6.0.0, 4.3.0, and 4.2.0 can allow a local or remote user to obtain an authenticated CLI session due to improper au…

Mitigation only
Fix from $2,300 2020-12-15
Spectrum Protect Operations Center MEDIUM 5.3
CVE-2020-4771

IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.10.and 7.1.0.000 through 7.1.11 could allow a remote attacker to obtain sensitive inform…

Fix: after 8.1.10
Fix from $1,600 2020-11-23
Curam Social Program Management HIGH 8.1
CVE-2020-4779

A HTTP Verb Tampering vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10. By sending a specially-crafted request, an attac…

Mitigation only
Fix from $1,950 2020-10-12
Security Guardium Insights MEDIUM 6.5
CVE-2020-4167

IBM Security Guardium Insights 2.0.1 could allow an attacker to obtain sensitive information or perform unauthorized actions due to improper authenci…

Patch available
Fix from $1,600 2020-08-27
Event Streams HIGH 8.8
CVE-2020-4662

IBM Event Streams 10.0.0 could allow an authenticated user to perform tasks to a schema due to improper authentication validation. IBM X-Force ID: 18…

Patch available
Fix from $1,950 2020-08-14
Spectrum Protect Client HIGH 7.5
CVE-2020-4494

IBM Spectrum Protect Client 8.1.7.0 through 8.1.9.1 (Linux and Windows), 8.1.9.0 trough 8.1.9.1 (AIX) and IBM Spectrum Protect for Space Management 8…

Fix: after 8.1.9.1
Fix from $1,950 2020-06-15
Data Risk Manager CRITICAL 9.8
CVE-2020-4427 KEVEPSS 70%

IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured with…

Fix: after 2.0.6.1
Fix from $2,300 2020-05-07
Datapower Gateway MEDIUM 6.3
CVE-2020-4205

IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.8 could allow an authenticated user to bypass security restrictions, and continue to access the ser…

Fix: after 2018.4.1.8
Fix from $1,600 2020-03-19
Workflow HIGH 8.1
CVE-2015-0102

IBM Workflow for Bluemix does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to captu…

Mitigation only
Fix from $1,950 2020-02-05
Data Protection HIGH 7.8
CVE-2018-1987

IBM Spectrum Protect for Enterprise Resource Planning 7.1 and 8.1, if tracing is activated, the IBM Spectrum Protect node password may be displayed i…

Fix: after 8.1.6.0
Fix from $1,950 2019-08-02
Datapower Gateway HIGH 7.5
CVE-2018-1668

IBM DataPower Gateway 7.5.0.0 through 7.5.0.19, 7.5.1.0 through 7.5.1.18, 7.5.2.0 through 7.5.2.18, and 7.6.0.0 through 7.6.0.11 appliances allows "n…

Fix: after 7.6.0.11
Fix from $1,950 2019-01-29
Api Connect HIGH 8.1
CVE-2018-1778

IBM LoopBack (IBM API Connect 2018.1, 2018.4.1, 5.0.8.0, and 5.0.8.4) could allow an attacker to bypass authentication if the AccessToken Model is ex…

Fix: after 2018.4.1.0
Fix from $1,950 2018-12-20
Flashsystem 900 Firmware CRITICAL 9.8
CVE-2018-1822

IBM FlashSystem 900 product GUI allows a specially crafted attack to bypass the authentication requirements of the system, resulting in the ability t…

Patch available
Fix from $2,300 2018-10-18
Security Key Lifecycle Manager HIGH 7.1
CVE-2018-1738

IBM Security Key Lifecycle Manager 2.6, 2.7, 3.0 could allow an authenticated user to obtain highly sensitive information or jeopardize system integr…

Fix: after 3.0.0.1
Fix from $1,950 2018-10-11
Websphere Portal MEDIUM 6.3
CVE-2018-1672

IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 may fail to set the correct user context in certain impersonation scenarios, which can allow a user to ac…

Patch available
Fix from $1,600 2018-10-01
Rational Engineering Lifecycle Manager MEDIUM 6.5
CVE-2018-1539

IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 could allow remote attackers to bypass authentication via a direct …

Fix: after 6.0.6
Fix from $1,600 2018-09-25
Api Connect HIGH 8.1
CVE-2018-1638

IBM API Connect 5.0.0.0-5.0.8.3 Developer Portal does not enforce Two Factor Authentication (TFA) while resetting a user password but enforces it for…

Fix: after 5.0.8.3
Fix from $1,950 2018-07-31
Qradar Security Information And Event Manager HIGH 8.8
CVE-2018-1418EPSS 52%

IBM Security QRadar SIEM 7.2 and 7.3 could allow a user to bypass authentication which could lead to code execution. IBM X-Force ID: 138824.

Fix: 7.2.8+
Fix from $1,950 2018-04-26
Sterling B2b Integrator HIGH 8.1
CVE-2014-0927

The ActiveMQ admin user interface in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allows remote attackers to bypass …

Patch available
Fix from $1,950 2018-04-20
Tealeaf Customer Experience MEDIUM 6.5
CVE-2015-4987

The search and replay servers in IBM Tealeaf Customer Experience 8.0 through 9.0.2 allow remote attackers to bypass authentication via unspecified ve…

Fix: after 9.0.2
Fix from $1,600 2018-03-27
Security Access Manager MEDIUM 5.9
CVE-2018-1443

An XML parsing vulnerability affects IBM SAML-based single sign-on (SSO) systems (IBM Security Access Manager 9.0.0 - 9.0.4 and IBM Tivoli Federated …

Fix: after 9.0.4
Fix from $1,600 2018-03-08
Bigfix Platform MEDIUM 6.5
CVE-2017-1222

IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) does not perform an authentication check for a critical resource or functionality allow…

Patch available
Fix from $1,600 2017-10-26
Tivoli Storage Manager CRITICAL 9.8
CVE-2016-8937

The IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) default authentication protocol is vulnerable to a brute force attack due to disclo…

Patch available
Fix from $2,300 2017-10-05
Emptoris Strategic Supply Management HIGH 7.5
CVE-2016-8951

IBM Emptoris Strategic Supply Management Platform 10.0.0.x through 10.1.1.x is vulnerable to a denial of service attack. An attacker can exploit a vu…

Patch available
Fix from $1,950 2017-07-13
Security Guardium HIGH 7.5
CVE-2017-1264

IBM Security Guardium 10.0 does not prove or insufficiently proves that the actors identity is correct which can lead to exposure of resources or fun…

Mitigation only
Fix from $1,950 2017-07-05
Security Guardium MEDIUM 6.5
CVE-2017-1258

IBM Security Guardium 10.0 and 10.1 does not perform an authentication check for a critical resource or functionality allowing anonymous users access…

Mitigation only
Fix from $1,600 2017-07-05
Qradar Security Information And Event Manager MEDIUM 6.5
CVE-2016-9729

IBM QRadar 7.2 does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. …

Patch available
Fix from $1,600 2017-03-07
Bigfix Remote Control CRITICAL 9.8
CVE-2016-2944

IBM BigFix Remote Control before 9.1.3 does not properly restrict failed login attempts, which makes it easier for remote attackers to obtain access …

Fix: after 9.1.2
Fix from $2,300 2016-11-30
General Parallel File System HIGH 10.0
CVE-2015-0198

IBM General Parallel File System (GPFS) 3.4 before 3.4.0.32, 3.5 before 3.5.0.24, and 4.1 before 4.1.0.7 in certain cipherList configurations allows …

Patch available
Fix from $1,950 2015-03-24
Qradar Risk Manager MEDIUM 5.8
CVE-2014-4831

IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2…

Patch available
Fix from $1,600 2014-11-28