Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.9
CVE-2023-22870
IBM Aspera Faspex 5.0.5 transmits sensitive information in cleartext which could be obtained by an attacker using man in the middle techniques. IBM …
Aspera Faspex
after 5.0.5
MEDIUM 5.9
CVE-2023-27861
IBM Maximo Application Suite - Manage Component 8.8.0 and 8.9.0 transmits sensitive information in cleartext that could be intercepted by an attacker…
Maximo Application Suite
Mitigation only
MEDIUM 5.9
CVE-2023-22863
IBM Robotic Process Automation 20.12.0 through 21.0.2 defaults to HTTP in some RPA commands when the prefix is not explicitly specified in the URL. …
Robotic Process Automation
21.0.3+
MEDIUM 5.9
CVE-2020-4497
IBM Spectrum Protect Plus 10.1.0 through 10.1.12 discloses sensitive information due to unencrypted data being used in the communication flow between…
Spectrum Protect Plus
10.1.13+
MEDIUM 5.9
CVE-2020-4970
IBM Security Identity Governance and Intelligence 5.2.4, 5.2.5, and 5.2.6 could allow a remote attacker to obtain sensitive information, caused by th…
Security Identity Manager
Mitigation only
MEDIUM 5.3
CVE-2003-5002
A vulnerability was found in ISS BlackICE PC Protection. It has been declared as problematic. Affected by this vulnerability is the component Update …
Iss Blackice Pc Protection
Mitigation only
MEDIUM 5.9
CVE-2021-39026
IBM Guardium Data Encryption (GDE) 5.0.0.2 and 5.0.0.3 could allow a remote attacker to obtain sensitive information, caused by the failure to proper…
Guardium Data Encryption
Patch available
MEDIUM 5.9
CVE-2021-38978
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensitive information, caused by the failure to pro…
Security Guardium Key Lifecycle Manager
after 4.0.0.3
MEDIUM 5.9
CVE-2020-4152
IBM QRadar Network Security 5.4.0 and 5.5.0 transmits sensitive or security-critical data in cleartext in a communication channel that can be obtaine…
Qradar Network Security
5.4.0.14 / 5.5.0.9+
MEDIUM 5.9
CVE-2021-29753
IBM Business Automation Workflow 18. 19, 20, 21, and IBM Business Process Manager 8.5 and d8.6 transmits or stores authentication credentials, but it…
Business Automation Workflow
Mitigation only
MEDIUM 6.5
CVE-2020-4980
IBM QRadar SIEM 7.3 and 7.4 uses less secure methods for protecting data in transit between hosts when encrypt host connections is not enabled as wel…
Qradar Security Information And Event Manager
7.3.3 / 7.4.3+
MEDIUM 5.9
CVE-2021-20564
IBM Cloud Pak for Security (CP4S) 1.4.0.0, 1.5.0.0, 1.5.0.1, 1.6.0.0, and 1.6.0.1 could allow a remote attacker to obtain sensitive information, caus…
Cloud Pak For Security
Mitigation only
HIGH 7.5
CVE-2020-4695
IBM API Connect V10 is impacted by insecure communications during database replication. As the data replication happens over insecure communication c…
Api Connect
after 10.0.1.0
HIGH 7.5
CVE-2021-20409
IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a remote attacker to obtain sensitive information, caused by the failure to properl…
Security Verify Information Queue
Patch available
MEDIUM 5.9
CVE-2020-4969
IBM Security Identity Governance and Intelligence 5.2.6 could allow a remote attacker to obtain sensitive information, caused by the failure to prope…
Security Identity Governance And Intelligence
Patch available
MEDIUM 5.9
CVE-2020-4893
IBM Emptoris Strategic Supply Management 10.1.0, 10.1.1, and 10.1.3 transmits sensitive information in HTTP GET request parameters. This may lead to …
Emptoris Strategic Supply Management
10.1.0.38 / 10.1.1.35+
CRITICAL 9.1
CVE-2020-4899
IBM API Connect 5.0.0.0 through 5.0.8.10 could potentially leak sensitive information or allow for data corruption due to plain text transmission of …
Api Connect
after 5.0.8.10
HIGH 7.5
CVE-2019-4689
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly …
Guardium Data Encryption
1.7.0 / 4.0.0.3+
MEDIUM 5.9
CVE-2020-4397
IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 transmits sensitive information in plain text which could be obtained by an attacker using man in the middle…
Verify Gateway
Patch available
MEDIUM 5.9
CVE-2019-4667
IBM UrbanCode Deploy (UCD) 7.0.5.2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Stric…
Urbancode Deploy
Mitigation only
MEDIUM 5.9
CVE-2019-4594
IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict…
Qradar Security Information And Event Manager
7.3.3+
MEDIUM 5.3
CVE-2019-4280
IBM Sterling File Gateway 2.2.0.0 through 6.0.1.0 displays sensitive information in HTTP requests which could be used in further attacks against the …
Sterling File Gateway
after 6.0.1.0
MEDIUM 5.3
CVE-2019-4382EPSS 8%
IBM API Connect 5.0.0.0 through 5.0.8.6 could allow an unauthorized user to obtain sensitive information about the system users using specially craft…
Api Connect
after 5.0.8.6
HIGH 7.5
CVE-2019-4162
IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, and 1.0.2 is missing the HTTP Strict Transport Security header. Users can navigate by mistake to …
Security Information Queue
Patch available
MEDIUM 5.9
CVE-2019-4063
IBM Sterling B2B Integrator 5.2.0.1 through 6.0.0.0 Standard Edition could allow highly sensitive information to be transmitted in plain text. An att…
Sterling B2b Integrator
after 6.0.0.0
MEDIUM 5.9
CVE-2018-1525
IBM i2 Enterprise Insight Analysis 2.1.7 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP…
I2 Enterprise Insight Analysis
Mitigation only
MEDIUM 5.9
CVE-2018-1454
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow a remote attacker to obtain sensitive information, caused by the failure to proper…
Infosphere Information Server
Mitigation only
HIGH 7.5
CVE-2018-1600
IBM BigFix Platform 9.2 and 9.5 transmits sensitive or security-critical data in clear text in a communication channel that can be sniffed by unautho…
Bigfix Platform
after 9.5.8
HIGH 8.1
CVE-2017-1694
IBM Integration Bus 9.0 and 10.0 transmits user credentials in plain in clear text which can be read by an attacker using man in the middle technique…
Integration Bus
Mitigation only
MEDIUM 5.9
CVE-2017-1232
IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) transmits sensitive or security-critical data in cleartext in a communication channel t…
Bigfix Platform
Patch available