Vulnerability index

Browse CVEs

43 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
Db2 MEDIUM 6.5
CVE-2025-2669

IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, 5.3 could allow a privileged user to perform opera…

Fix: 5.4+
Fix from $1,600 2026-06-22
Concert MEDIUM 5.9
CVE-2025-33099

IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to perform unauthorized actions using man in the middle techniques due to impr…

Fix: 2.0.0+
Fix from $1,600 2025-09-01
Websphere Application Server HIGH 7.5
CVE-2025-33142

IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security for TLS connections.

Fix: 8.5.5.29 / 9.0.5.25+
Fix from $1,950 2025-08-14
Mq Operator MEDIUM 6.5
CVE-2025-36005

IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1, 3.6.0, and MQ Operator…

Fix: after 3.6.0
Fix from $1,600 2025-07-24
Mq Operator CRITICAL 9.8
CVE-2025-36041

IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1 through 3.5.3, and MQ O…

Fix: after 3.5.3
Fix from $2,300 2025-06-15
Security Qradar Edr MEDIUM 6.5
CVE-2024-45641

IBM Security ReaQta EDR 3.12 could allow an attacker to perform unauthorized actions due to improper SSL certificate validation.

Fix: 3.12.17+
Fix from $1,600 2025-05-20
Security Qradar Edr MEDIUM 6.5
CVE-2023-33861

IBM Security ReaQta EDR 3.12 could allow an attacker to spoof a trusted entity by interfering with the communication path between the host and client.

Fix: 3.12.17+
Fix from $1,600 2025-05-20
I MEDIUM 5.4
CVE-2025-3218

IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 is vulnerable to authentication and authorization attacks due to incorrect validation processing in IBM i Netserver…

Mitigation only
Fix from $1,600 2025-05-07
Openpages With Watson HIGH 8.2
CVE-2024-49782

IBM OpenPages with Watson 8.3 and 9.0  could allow a remote attacker to spoof mail server identity when using SSL/TLS security. An attacker could …

Fix: 8.3.0.3 / 9.0.0.5+
Fix from $1,950 2025-02-20
Cognos Analytics MEDIUM 5.9
CVE-2023-38009

IBM Cognos Mobile Client 1.1 iOS may be vulnerable to information disclosure through man in the middle techniques due to the lack of certificate pinn…

Mitigation only
Fix from $1,600 2025-01-26
Cognos Controller HIGH 8.2
CVE-2024-40702

IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow an unauthorized user to obtain valid tokens to gain access to prote…

Fix: after 11.0.1
Fix from $1,950 2025-01-07
Storage Defender Resiliency Service HIGH 7.5
CVE-2024-47119

IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9 does not properly validate a certificate which could allow an attacker to spoof a trust…

Fix: after 2.0.9
Fix from $1,950 2024-12-18
Concert CRITICAL 9.8
CVE-2024-43177

IBM Concert 1.0.0 and 1.0.1 vulnerable to attacks that rely on the use of cookies without the SameSite attribute.

Mitigation only
Fix from $2,300 2024-10-22
Storage Defender MEDIUM 6.5
CVE-2024-38324

IBM Storage Defender 2.0.0 through 2.0.7 on-prem defender-sensor-cmd CLI does not validate server name during registration and unregistration operati…

Fix: 2.0.8+
Fix from $1,600 2024-09-25
Websphere Application Server HIGH 7.5
CVE-2023-50314

IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.8 could allow an attacker with access to the network to conduct spoofing attacks. A…

Fix: after 24.0.0.8
Fix from $1,950 2024-08-14
Websphere Application Server MEDIUM 5.9
CVE-2023-50315

IBM WebSphere Application Server 8.5 and 9.0 could allow an attacker with access to the network to conduct spoofing attacks. An attacker could explo…

Mitigation only
Fix from $1,600 2024-08-14
Cognos Analytics MEDIUM 5.9
CVE-2024-25053

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, and 12.0.2 is vulnerable to improper certificate validation when using t…

Mitigation only
Fix from $1,600 2024-06-28
Security Verify Access Docker HIGH 7.8
CVE-2024-35140

IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to improper certificate validation.…

Fix: 10.0.7+
Fix from $1,950 2024-05-31
Qradar Security Information And Event Manager HIGH 8.1
CVE-2023-50949

IBM QRadar SIEM 7.5 could allow an unauthorized user to perform unauthorized actions due to improper certificate validation. IBM X-Force ID: 275706.

Mitigation only
Fix from $1,950 2024-04-11
Security Verify Access HIGH 8.1
CVE-2024-31871

IBM Security Verify Access Appliance 10.0.0 through 10.0.7 could allow a malicious actor to conduct a man in the middle attack when deploying Python …

Fix: after 10.0.7
Fix from $1,950 2024-04-10
Security Verify Access HIGH 8.1
CVE-2024-31872

IBM Security Verify Access Appliance 10.0.0 through 10.0.7 could allow a malicious actor to conduct a man in the middle attack when deploying Open So…

Fix: after 10.0.7
Fix from $1,950 2024-04-10
Cloud Pak For Security MEDIUM 5.9
CVE-2023-47742

IBM QRadar Suite Products 1.10.12.0 through 1.10.18.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could disclose sensitive information …

Fix: after 1.10.18.0
Fix from $1,600 2024-03-03
Storage Virtualize HIGH 7.5
CVE-2023-47700

IBM SAN Volume Controller, IBM Storwize, IBM FlashSystem and IBM Storage Virtualize 8.6 products could allow a remote attacker to spoof a trusted sys…

Mitigation only
Fix from $1,950 2024-02-07
Security Verify Access HIGH 7.2
CVE-2023-43017

IBM Security Verify Access 10.0.0.0 through 10.0.6.1 could allow a privileged user to install a configuration file that could allow remote access. I…

Fix: after 10.0.6.1
Fix from $1,950 2024-02-07
Security Verify Access CRITICAL 9.8
CVE-2023-32330

IBM Security Verify Access 10.0.0.0 through 10.0.6.1 uses insecure calls that could allow an attacker on the network to take control of the server. …

Fix: after 10.0.6.1
Fix from $2,300 2024-02-07
Security Verify Privilege On Premises MEDIUM 5.3
CVE-2022-43892

IBM Security Verify Privilege On-Premises 11.5 does not validate, or incorrectly validates, a certificate which could disclose sensitive information …

Fix: 11.5+
Fix from $1,600 2023-10-17
Websphere Application Server MEDIUM 5.3
CVE-2022-39161

IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0, and IBM WebSphere Application Server Liberty, when configured to communicate with the Web Server…

Mitigation only
Fix from $1,600 2023-05-03
Qradar Security Information And Event Manager HIGH 7.5
CVE-2021-29755

IBM QRadar SIEM 7.3, 7.4, and 7.5 does not preform proper certificate validation for some inter-host communications. IBM X-Force ID: 202015.

Fix: 7.3.3 / 7.4.3+
Fix from $1,950 2022-07-20
Secure External Authentication Server MEDIUM 5.3
CVE-2021-29726

IBM Sterling Secure Proxy 6.0.3 and IBM Secure External Authentication Server 6.0.3 does not properly ensure that a certificate is actually associate…

Patch available
Fix from $1,600 2022-05-17
Spectrum Protect Plus MEDIUM 5.9
CVE-2020-4496

The IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x server connection to an IBM Spectrum Protect Plus workload agent is subject to a man-in-the-m…

Fix: after 10.1.8.1
Fix from $1,600 2021-12-13