Vulnerability index

Browse CVEs

61 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cleartext TransmissionCWE-319 × clear
Aspera Faspex MEDIUM 5.9
CVE-2023-22870

IBM Aspera Faspex 5.0.5 transmits sensitive information in cleartext which could be obtained by an attacker using man in the middle techniques. IBM …

Fix: after 5.0.5
Fix from $1,600 2023-09-05
Maximo Application Suite MEDIUM 5.9
CVE-2023-27861

IBM Maximo Application Suite - Manage Component 8.8.0 and 8.9.0 transmits sensitive information in cleartext that could be intercepted by an attacker…

Mitigation only
Fix from $1,600 2023-06-05
Robotic Process Automation MEDIUM 5.9
CVE-2023-22863

IBM Robotic Process Automation 20.12.0 through 21.0.2 defaults to HTTP in some RPA commands when the prefix is not explicitly specified in the URL. …

Fix: 21.0.3+
Fix from $1,600 2023-01-18
Spectrum Protect Plus MEDIUM 5.9
CVE-2020-4497

IBM Spectrum Protect Plus 10.1.0 through 10.1.12 discloses sensitive information due to unencrypted data being used in the communication flow between…

Fix: 10.1.13+
Fix from $1,600 2022-12-14
Security Identity Manager MEDIUM 5.9
CVE-2020-4970

IBM Security Identity Governance and Intelligence 5.2.4, 5.2.5, and 5.2.6 could allow a remote attacker to obtain sensitive information, caused by th…

Mitigation only
Fix from $1,600 2022-05-19
Iss Blackice Pc Protection MEDIUM 5.3
CVE-2003-5002

A vulnerability was found in ISS BlackICE PC Protection. It has been declared as problematic. Affected by this vulnerability is the component Update …

Mitigation only
Fix from $1,600 2022-03-28
Guardium Data Encryption MEDIUM 5.9
CVE-2021-39026

IBM Guardium Data Encryption (GDE) 5.0.0.2 and 5.0.0.3 could allow a remote attacker to obtain sensitive information, caused by the failure to proper…

Patch available
Fix from $1,600 2022-02-18
Security Guardium Key Lifecycle Manager MEDIUM 5.9
CVE-2021-38978

IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensitive information, caused by the failure to pro…

Fix: after 4.0.0.3
Fix from $1,600 2021-11-15
Qradar Network Security MEDIUM 5.9
CVE-2020-4152

IBM QRadar Network Security 5.4.0 and 5.5.0 transmits sensitive or security-critical data in cleartext in a communication channel that can be obtaine…

Fix: 5.4.0.14 / 5.5.0.9+
Fix from $1,600 2021-11-08
Business Automation Workflow MEDIUM 5.9
CVE-2021-29753

IBM Business Automation Workflow 18. 19, 20, 21, and IBM Business Process Manager 8.5 and d8.6 transmits or stores authentication credentials, but it…

Mitigation only
Fix from $1,600 2021-11-05
Qradar Security Information And Event Manager MEDIUM 6.5
CVE-2020-4980

IBM QRadar SIEM 7.3 and 7.4 uses less secure methods for protecting data in transit between hosts when encrypt host connections is not enabled as wel…

Fix: 7.3.3 / 7.4.3+
Fix from $1,600 2021-07-16
Cloud Pak For Security MEDIUM 5.9
CVE-2021-20564

IBM Cloud Pak for Security (CP4S) 1.4.0.0, 1.5.0.0, 1.5.0.1, 1.6.0.0, and 1.6.0.1 could allow a remote attacker to obtain sensitive information, caus…

Mitigation only
Fix from $1,600 2021-05-14
Api Connect HIGH 7.5
CVE-2020-4695

IBM API Connect V10 is impacted by insecure communications during database replication. As the data replication happens over insecure communication c…

Fix: after 10.0.1.0
Fix from $1,950 2021-03-08
Security Verify Information Queue HIGH 7.5
CVE-2021-20409

IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a remote attacker to obtain sensitive information, caused by the failure to properl…

Patch available
Fix from $1,950 2021-02-12
Security Identity Governance And Intelligence MEDIUM 5.9
CVE-2020-4969

IBM Security Identity Governance and Intelligence 5.2.6 could allow a remote attacker to obtain sensitive information, caused by the failure to prope…

Patch available
Fix from $1,600 2021-01-21
Emptoris Strategic Supply Management MEDIUM 5.9
CVE-2020-4893

IBM Emptoris Strategic Supply Management 10.1.0, 10.1.1, and 10.1.3 transmits sensitive information in HTTP GET request parameters. This may lead to …

Fix: 10.1.0.38 / 10.1.1.35+
Fix from $1,600 2021-01-07
Api Connect CRITICAL 9.1
CVE-2020-4899

IBM API Connect 5.0.0.0 through 5.0.8.10 could potentially leak sensitive information or allow for data corruption due to plain text transmission of …

Fix: after 5.0.8.10
Fix from $2,300 2021-01-05
Guardium Data Encryption HIGH 7.5
CVE-2019-4689

IBM Security Guardium Data Encryption (GDE) 3.0.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly …

Fix: 1.7.0 / 4.0.0.3+
Fix from $1,950 2020-08-26
Verify Gateway MEDIUM 5.9
CVE-2020-4397

IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 transmits sensitive information in plain text which could be obtained by an attacker using man in the middle…

Patch available
Fix from $1,600 2020-07-22
Urbancode Deploy MEDIUM 5.9
CVE-2019-4667

IBM UrbanCode Deploy (UCD) 7.0.5.2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Stric…

Mitigation only
Fix from $1,600 2020-05-11
Qradar Security Information And Event Manager MEDIUM 5.9
CVE-2019-4594

IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict…

Fix: 7.3.3+
Fix from $1,600 2020-04-15
Sterling File Gateway MEDIUM 5.3
CVE-2019-4280

IBM Sterling File Gateway 2.2.0.0 through 6.0.1.0 displays sensitive information in HTTP requests which could be used in further attacks against the …

Fix: after 6.0.1.0
Fix from $1,600 2019-09-30
Api Connect MEDIUM 5.3
CVE-2019-4382EPSS 8%

IBM API Connect 5.0.0.0 through 5.0.8.6 could allow an unauthorized user to obtain sensitive information about the system users using specially craft…

Fix: after 5.0.8.6
Fix from $1,600 2019-06-25
Security Information Queue HIGH 7.5
CVE-2019-4162

IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, and 1.0.2 is missing the HTTP Strict Transport Security header. Users can navigate by mistake to …

Patch available
Fix from $1,950 2019-06-06
Sterling B2b Integrator MEDIUM 5.9
CVE-2019-4063

IBM Sterling B2B Integrator 5.2.0.1 through 6.0.0.0 Standard Edition could allow highly sensitive information to be transmitted in plain text. An att…

Fix: after 6.0.0.0
Fix from $1,600 2019-03-05
I2 Enterprise Insight Analysis MEDIUM 5.9
CVE-2018-1525

IBM i2 Enterprise Insight Analysis 2.1.7 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP…

Mitigation only
Fix from $1,600 2018-12-06
Infosphere Information Server MEDIUM 5.9
CVE-2018-1454

IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow a remote attacker to obtain sensitive information, caused by the failure to proper…

Mitigation only
Fix from $1,600 2018-06-05
Bigfix Platform HIGH 7.5
CVE-2018-1600

IBM BigFix Platform 9.2 and 9.5 transmits sensitive or security-critical data in clear text in a communication channel that can be sniffed by unautho…

Fix: after 9.5.8
Fix from $1,950 2018-06-04
Integration Bus HIGH 8.1
CVE-2017-1694

IBM Integration Bus 9.0 and 10.0 transmits user credentials in plain in clear text which can be read by an attacker using man in the middle technique…

Mitigation only
Fix from $1,950 2017-12-20
Bigfix Platform MEDIUM 5.9
CVE-2017-1232

IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) transmits sensitive or security-critical data in cleartext in a communication channel t…

Patch available
Fix from $1,600 2017-10-26