Vulnerability index

Browse CVEs

43 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
Infosphere Information Server HIGH 7.5
CVE-2021-29737

IBM InfoSphere Data Flow Designer Engine (IBM InfoSphere Information Server 11.7 ) component has improper validation of the REST API server certifica…

Patch available
Fix from $1,950 2021-11-02
Security Verify Bridge HIGH 7.5
CVE-2021-38864

IBM Security Verify Bridge 1.0.5.0 could allow a user to obtain sensitive information due to improper certificate validation. IBM X-Force ID: 208155.

Fix: 1.0.7+
Fix from $1,950 2021-09-23
Security Verify Bridge MEDIUM 5.5
CVE-2021-20435

IBM Security Verify Bridge 1.0.5.0 does not properly validate a certificate which could allow a local attacker to obtain sensitive information that c…

Fix: 1.0.7+
Fix from $1,600 2021-09-23
Security Identity Governance And Intelligence MEDIUM 5.3
CVE-2020-4791

IBM Security Identity Governance and Intelligence 5.2.6 could allow an attacker to obtain sensitive information using main in the middle attacks due …

Patch available
Fix from $1,600 2021-02-09
Mq MEDIUM 6.5
CVE-2020-4320

IBM MQ Appliance and IBM MQ AMQP Channels 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD do not correctly block or allow clients based on the certificate distingu…

Fix: 8.0.0.15 / 9.0.0.10+
Fix from $1,600 2020-06-16
Qradar Security Information And Event Manager MEDIUM 5.9
CVE-2019-4264

IBM QRadar SIEM 7.2.8 WinCollect could allow an attacker to obtain sensitive information by spoofing a trusted entity using man in the middle techniq…

Fix: 7.2.8+
Fix from $1,600 2019-05-29
Bigfix Compliance MEDIUM 5.9
CVE-2017-1200

IBM BigFix Compliance 1.7 through 1.9.91 (TEMA SUAv1 SCA SCM) does not validate, or incorrectly validates, a certificate.This weakness might allow an…

Fix: after 1.9.91
Fix from $1,600 2019-02-05
Security Guardium MEDIUM 5.9
CVE-2017-1265

IBM Security Guardium 10.0, 10.0.1, 10.1, 10.1.2, 10.1.3, 10.1.4, and 10.5 does not validate, or incorrectly validates, a certificate. This weakness …

Fix: after 10.5
Fix from $1,600 2018-12-17
Qradar Incident Forensics HIGH 7.4
CVE-2017-1622

IBM QRadar SIEM 7.2.8 and 7.3 does not validate, or incorrectly validates, a certificate. This weakness might allow an attacker to spoof a trusted en…

Fix: 7.2.8 / 7.3.1+
Fix from $1,950 2018-12-05
Security Guardium HIGH 7.4
CVE-2018-1509

IBM Security Guardium EcoSystem 10.5 does not validate, or incorrectly validates, a certificate.This weakness might allow an attacker to spoof a trus…

Mitigation only
Fix from $1,950 2018-10-02
Rational Clearquest MEDIUM 5.9
CVE-2016-2922

IBM Rational ClearQuest 8.0 through 8.0.1.9 and 9.0 through 9.0.1.3 (CQ OSLC linkages, EmailRelay) fails to check the SSL certificate against the req…

Fix: after 9.0.1.3
Fix from $1,600 2018-08-13
Websphere Mq MEDIUM 5.9
CVE-2018-1543

IBM WebSphere MQ 8.0 and 9.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly validate the SSL certif…

Mitigation only
Fix from $1,600 2018-06-27
Bigfix Remote Control MEDIUM 5.9
CVE-2015-4954

IBM BigFix Remote Control before Interim Fix pack 9.1.2-TIV-IBRC912-IF0001 improperly allows self-signed certificates, which might allow remote attac…

Patch available
Fix from $1,600 2018-03-27