Vulnerability index

Browse CVEs

61 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cleartext TransmissionCWE-319 × clear
Watsonx.data Intelligence MEDIUM 5.9
CVE-2025-36336

IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 transmits data in clear text that could allow an attacker to obtain sensitive information us…

Mitigation only
Fix from $1,600 2026-06-30
Watsonx.data Intelligence MEDIUM 5.9
CVE-2025-12530

IBM watsonx.data intelligence 5.2.2, 5.3.0, 5.3.1, 5.3.1 through Patch 1 transmits data in clear text that could allow an attacker to obtain sensitiv…

Mitigation only
Fix from $1,600 2026-06-30
Infosphere Information Server MEDIUM 6.5
CVE-2026-1014

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to exposure of sensitive information via JSON server response manipulation.

Fix: after 11.7.1.6
Fix from $1,600 2026-03-25
Concert MEDIUM 5.9
CVE-2025-64648

IBM Concert 1.0.0 through 2.2.0 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle tec…

Fix: after 2.2.0
Fix from $1,600 2026-03-25
Sterling Partner Engagement Manager HIGH 7.5
CVE-2025-13718

IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow a remote attacker to obtain sensitive informa…

Fix: 6.2.3.6 / 6.2.4.3+
Fix from $1,950 2026-03-13
App Connect Enterprise Certified Containers Operands MEDIUM 5.9
CVE-2025-13490

IBM App Connect Operator versions CD 11.3.0 through 11.6.0 and 12.1.0 through 12.20.0, LTS versions 12.0.0 through 12.0.20, and IBM App Connect Enter…

Fix: after 12.20.1
Fix from $1,600 2026-03-03
Db2 Recovery Expert MEDIUM 5.9
CVE-2025-27903

IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 IBM Db2 Recovery Expert for Linux, UNIX and Windows transmits data in a cleartext communication c…

Mitigation only
Fix from $1,600 2026-02-17
Devops Deploy MEDIUM 5.9
CVE-2025-13489

IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.3 IBM DevOps Deploy transmits data in clear text that could allow an attacker to obtain sensitive infor…

Fix: 8.1.2.4+
Fix from $1,600 2025-12-15
Aspera Http Gateway HIGH 7.5
CVE-2025-36274

IBM Aspera HTTP Gateway 2.0.0 through 2.3.1 stores sensitive information in clear text in easily obtainable files which can be read by an unauthentic…

Fix: 2.3.2+
Fix from $1,950 2025-09-26
Guardium Data Protection HIGH 7.5
CVE-2025-36020

IBM Guardium Data Protection could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive credential info…

Mitigation only
Fix from $1,950 2025-08-06
Cognos Analytics Mobile HIGH 7.5
CVE-2025-36107

IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 could allow malicious actors to obtain sensitive information due to the cleartext transmission…

Fix: 1.1.23+
Fix from $1,950 2025-07-21
Infosphere Information Server MEDIUM 5.9
CVE-2025-36034

IBM InfoSphere DataStage Flow Designer in IBM InfoSphere Information Server 11.7 discloses sensitive user information in API requests in clear text t…

Mitigation only
Fix from $1,600 2025-06-26
Security Verify Access HIGH 7.5
CVE-2024-43187

IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 transmits sensitive or security-critical data in cleartext in a communicatio…

Fix: 10.0.9.0+
Fix from $1,950 2025-02-04
Security Verify Governance MEDIUM 5.9
CVE-2023-35017

IBM Security Verify Governance 10.0.2 Identity Manager can transmit user credentials in clear text that could be obtained by an attacker using man in…

Mitigation only
Fix from $1,600 2025-01-29
Qradar Security Information And Event Manager MEDIUM 6.5
CVE-2024-28786

IBM QRadar SIEM 7.5 transmits sensitive or security-critical data in cleartext in a communication channel that could be obtained by an unauthorized a…

Mitigation only
Fix from $1,600 2025-01-28
Concert MEDIUM 5.9
CVE-2024-41757

IBM Concert Software 1.0.0 and 1.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Str…

Mitigation only
Fix from $1,600 2025-01-24
Cognos Analytics Mobile HIGH 7.5
CVE-2021-39081

IBM Cognos Analytics Mobile for Android 1.1.14 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sens…

Mitigation only
Fix from $1,950 2024-12-19
Security Guardium Key Lifecycle Manager HIGH 7.5
CVE-2024-49819

IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information in cleartext i…

Mitigation only
Fix from $1,950 2024-12-17
Cognos Controller MEDIUM 5.9
CVE-2021-29892

IBM Cognos Controller 11.0.0 and 11.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP …

Mitigation only
Fix from $1,600 2024-12-03
Sterling Connect Direct Web Services MEDIUM 5.9
CVE-2024-39746

IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 could allow a remote attacker to obtain sensitive information, caused by the failure …

Mitigation only
Fix from $1,600 2024-08-22
Qradar Network Packet Capture MEDIUM 5.9
CVE-2024-31905

IBM QRadar Network Packet Capture 7.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP St…

Mitigation only
Fix from $1,600 2024-08-15
Watson Cp4d Data Stores HIGH 7.5
CVE-2023-27291

IBM Watson CP4D Data Stores 4.6.0, 4.6.1, 4.6.2, and 4.6.3 does not encrypt sensitive or critical information before storage or transmission which co…

Mitigation only
Fix from $1,950 2024-03-03
Mq Operator MEDIUM 5.5
CVE-2023-47745

IBM MQ Operator 2.0.0 LTS, 2.0.18 LTS, 3.0.0 CD, 3.0.1 CD, 2.4.0 through 2.4.7, 2.3.0 through 2.3.3, 2.2.0 through 2.2.2, and 2.3.0 through 2.3.3 sto…

Fix: after 2.4.7
Fix from $1,600 2024-03-03
Cloud Pak For Security MEDIUM 5.9
CVE-2021-39090

IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.6.0 could allow a remote attacker to obtain sensitive information, caused by the failure to p…

Fix: 1.10.7.0+
Fix from $1,600 2024-02-29
Security Verify Access CRITICAL 9.8
CVE-2023-32328

IBM Security Verify Access 10.0.0.0 through 10.0.6.1 uses insecure protocols in some instances that could allow an attacker on the network to take co…

Fix: after 10.0.6.1
Fix from $2,300 2024-02-07
Powersc HIGH 7.5
CVE-2023-50962

IBM PowerSC 1.3, 2.0, and 2.1 MFA does not implement the "HTTP Strict Transport Security" (HSTS) web security policy mechanism. IBM X-Force ID: 276…

Mitigation only
Fix from $1,950 2024-02-02
Security Verify Governance HIGH 7.5
CVE-2023-33837

IBM Security Verify Governance 10.0 does not encrypt sensitive or critical information before storage or transmission. IBM X-Force ID: 256020.

Patch available
Fix from $1,950 2023-10-23
Cognos Dashboards On Cloud Pak For Data HIGH 7.5
CVE-2023-38276

IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 exposes sensitive information in environment variables which could aid in further attacks against t…

Patch available
Fix from $1,950 2023-10-22
Cognos Dashboards On Cloud Pak For Data HIGH 7.5
CVE-2023-38275

IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 exposes sensitive information in container images which could lead to further attacks against the s…

Patch available
Fix from $1,950 2023-10-22
Security Verify Privilege On Premises HIGH 7.5
CVE-2022-22385

IBM Security Verify Privilege On-Premises 11.5 could disclose sensitive information to an attacked due to the transmission of data in clear text. IB…

Fix: 11.5+
Fix from $1,950 2023-10-17