Vulnerability index

Browse CVEs

31 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Websphere Application Server CRITICAL 9.4
CVE-2026-14525

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is vulnerable to an authentication bypa…

No fix yet
Fix from $5,750 2026-08-13
Websphere Application Server CRITICAL 9.8
CVE-2026-14529

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to s…

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $2,300 2026-07-29
Websphere Application Server CRITICAL 9.8
CVE-2026-14976

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code execution with the collectiveController-1.0 feature e…

Fix: 26.0.0.9+
Fix from $2,300 2026-07-28
Websphere Application Server CRITICAL 9.8
CVE-2026-14446

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the administrative console.

Fix: 8.5.5.30 / 9.0.5.28+
Fix from $2,300 2026-07-28
Sterling B2b Integrator MEDIUM 6.5
CVE-2026-1264

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.…

Fix: 6.1.2.8 / 6.2.0.5_2+
Fix from $1,600 2026-03-17
Spectrum Protect Server CRITICAL 9.8
CVE-2025-3319

IBM Spectrum Protect Server 8.1 through 8.1.26 could allow attacker to bypass authentication due to improper session authentication which can result …

Fix: after 8.1.26
Fix from $2,300 2025-06-20
Devops Deploy MEDIUM 6.3
CVE-2024-56469

IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.22, 7.2 through 7.2.3.15, and 7.3 through 7.3.2.10 / IBM DevOps Deploy 8.0 through 8.0.1.5 and 8.1 throu…

Fix: 7.1.2.23 / 7.2.3.16+
Fix from $1,600 2025-03-27
Storage Virtualize CRITICAL 9.1
CVE-2025-0159

IBM FlashSystem (IBM Storage Virtualize (8.5.0.0 through 8.5.0.13, 8.5.1.0, 8.5.2.0 through 8.5.2.3, 8.5.3.0 through 8.5.3.1, 8.5.4.0, 8.6.0.0 throug…

Fix: 8.5.0.14 / 8.6.0.6+
Fix from $2,300 2025-02-28
Devops Deploy MEDIUM 6.5
CVE-2024-54176

IBM DevOps Deploy 8.0 through 8.0.1.4, 8.1 through 8.1.0.0 and IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.25, 7.1 through 7.1.2.21, 7.2 through 7.2…

Fix: 7.0.5.26 / 7.1.2.22+
Fix from $1,600 2025-02-08
Webmethods Integration HIGH 8.8
CVE-2024-45075

IBM webMethods Integration 10.15 could allow an authenticated user to create scheduler tasks that would allow them to escalate their privileges to ad…

Mitigation only
Fix from $1,950 2024-09-04
Openpages Grc Platform MEDIUM 6.5
CVE-2024-35151

IBM OpenPages with Watson 8.3 and 9.0 could allow authenticated users access to sensitive information through improper authorization controls on APIs.

Mitigation only
Fix from $1,600 2024-08-22
Openbmc HIGH 7.5
CVE-2024-35124

A vulnerability in the combination of the OpenBMC's FW1050.00 through FW1050.10, FW1030.00 through FW1030.50, and FW1020.00 through FW1020.60 default…

Mitigation only
Fix from $1,950 2024-08-13
Planning Analytics Workspace CRITICAL 9.1
CVE-2024-35143

IBM Planning Analytics Local 2.0 and 2.1 connects to a MongoDB server. MongoDB, a document-oriented database system, is listening on the remote port,…

Fix: 2.0.97 / 2.1.4+
Fix from $2,300 2024-08-04
Openbmc HIGH 7.5
CVE-2024-31916

IBM OpenBMC FW1050.00 through FW1050.10 BMCWeb HTTPS server component could disclose sensitive URI content to an unauthorized actor that bypasses aut…

Mitigation only
Fix from $1,950 2024-06-27
Ds8900f Firmware MEDIUM 6.3
CVE-2024-22326

IBM System Storage DS8900F 89.22.19.0, 89.30.68.0, 89.32.40.0, 89.33.48.0, 89.40.83.0, and 89.40.93.0 could allow a remote user to create an LDAP con…

Mitigation only
Fix from $1,600 2024-06-06
Sterling Partner Engagement Manager HIGH 7.5
CVE-2023-43045

IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.2 could allow a remote user to perform unauthorized actions due to improper authenticat…

Patch available
Fix from $1,950 2023-10-23
Observability With Instana CRITICAL 9.1
CVE-2023-27290EPSS 9%

Docker based datastores for IBM Instana (IBM Observability with Instana 239-0 through 239-2, 241-0 through 241-2, and 243-0) do not currently require…

Fix: after 241-2
Fix from $2,300 2023-03-03
Power System S922 Firmware MEDIUM 6.8
CVE-2022-22309

The POWER systems FSP is vulnerable to unauthenticated logins through the serial port/TTY interface. This vulnerability can be more critical if the s…

Fix: 860.b0 / 940.60+
Fix from $1,600 2022-05-24
Guardium Data Encryption HIGH 7.5
CVE-2021-20474

IBM Guardium Data Encryption (GDE) 3.0.0.2 and 4.0.0.4 does not perform any authentication for functionality that requires a provable user identity o…

Patch available
Fix from $1,950 2021-07-07
Planning Analytics Cloud CRITICAL 9.1
CVE-2020-4670

IBM Planning Analytics Local 2.0 connects to a Redis server. The Redis server, an in-memory data structure store, running on the remote host is not p…

Patch available
Fix from $2,300 2021-05-17
Security Identity Governance And Intelligence CRITICAL 9.8
CVE-2020-4958

IBM Security Identity Governance and Intelligence 5.2.6 does not perform any authentication for functionality that requires a provable user identity …

Mitigation only
Fix from $2,300 2021-01-21
Spectrum Protect Plus MEDIUM 5.3
CVE-2020-5022

IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may allow unauthenticated and unauthorized access to VDAP proxy which can result in an attacker obtai…

Fix: 10.1.7+
Fix from $1,600 2021-01-08
Security Guardium HIGH 7.5
CVE-2018-1501

IBM Security Guardium 10.5, 10.6, and 11.0 could allow an unauthorized user to obtain sensitive information due to missing security controls. IBM X-F…

Patch available
Fix from $1,950 2020-08-26
Spectrum Protect Plus MEDIUM 6.5
CVE-2020-4471

IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow an unauthenticated attacker to cause a denial of service or hijack DNS sessions by send a…

Fix: after 10.1.5
Fix from $1,600 2020-06-15
Security Directory Server MEDIUM 5.3
CVE-2019-4551

IBM Security Directory Server 6.4.0 does not perform an authentication check for a critical resource or functionality allowing anonymous users access…

Fix: 6.4.0.20+
Fix from $1,600 2020-02-04
Smartcloud Analytics Log Analysis CRITICAL 9.1
CVE-2019-4244

IBM SmartCloud Analytics 1.3.1 through 1.3.5 could allow a remote attacker to gain unauthorized information and unrestricted control over Zookeeper i…

Fix: after 1.3.5
Fix from $2,300 2019-12-10
Robotic Process Automation With Automation Anywhere MEDIUM 5.3
CVE-2019-4337

IBM Robotic Process Automation with Automation Anywhere 11 could allow an attacker to obtain sensitive information due to missing authentication in I…

Fix: 11.0.0.4+
Fix from $1,600 2019-07-01
Security Key Lifecycle Manager HIGH 7.5
CVE-2018-1745

IBM Security Key Lifecycle Manager 2.7 and 3.0 could allow an unauthenticated user to restart the SKLM server due to missing authentication. IBM X-Fo…

Fix: after 3.0.0.1
Fix from $1,950 2018-10-11
Security Identity Governance And Intelligence MEDIUM 5.3
CVE-2018-1757

IBM Security Identity Governance and Intelligence 5.2.3.2 and 5.2.4 could allow an attacker to obtain sensitive information due to missing authentica…

Patch available
Fix from $1,600 2018-09-07
Infosphere Master Data Management HIGH 7.5
CVE-2017-1523

IBM InfoSphere Master Data Management - Collaborative Edition 11.5 could allow an unauthorized user to download reports without authentication. IBM X…

Mitigation only
Fix from $1,950 2017-10-24