Vulnerability index

Browse CVEs

199 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
I HIGH 7.3
CVE-2026-17069

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper validation of anti-CSRF toke…

No fix yet
Fix from $4,900 2026-08-13
Planning Analytics Local MEDIUM 6.5
CVE-2026-13365

IBM Planning Analytics 2.0, and 2.1 Local is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthor…

No fix yet
Fix from $4,000 2026-08-13
Websphere Application Server HIGH 8.8
CVE-2026-2482

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to exe…

Fix: 26.0.0.9+
Fix from $1,950 2026-07-29
Datapower Gateway HIGH 8.8
CVE-2025-36375

IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and IBM DataPower Gateway 10.6.0 1…

Fix: 10.5.0.21 / 10.6.0.9+
Fix from $1,950 2026-04-01
Db2 Recovery Expert MEDIUM 6.5
CVE-2025-27904

IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 IBM Db2 Recovery Expert for Linux, UNIX and Windows is vulnerable to cross-site request forgery w…

Patch available
Fix from $1,600 2026-02-17
Concert MEDIUM 6.5
CVE-2025-36018

IBM Concert 1.0.0 through 2.1.0 for Z hub component is vulnerable to cross-site request forgery which could allow an attacker to execute malicious an…

Fix: 2.2.0+
Fix from $1,600 2026-02-17
Storage Ts4500 Library Firmware HIGH 8.8
CVE-2024-43192

IBM Storage TS4500 Library 1.11.0.0 and 2.11.0.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and u…

Mitigation only
Fix from $1,950 2025-09-27
Txseries For Multiplatforms HIGH 8.8
CVE-2024-56474

IBM TXSeries for Multiplatforms 9.1 and 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unaut…

Mitigation only
Fix from $1,950 2025-04-02
Openpages With Watson HIGH 8.8
CVE-2024-49779

IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages could allow a remote attacker to bypass security restrictions, caused by improper validation an…

Fix: 8.3.0.3 / 9.0.0.5+
Fix from $1,950 2025-02-20
Security Verify Access MEDIUM 6.5
CVE-2024-35138

IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 is vulnerable to cross-site request forgery which could allow an attacker to…

Fix: after 10.0.8
Fix from $1,600 2025-02-04
Sterling B2b Integrator HIGH 8.8
CVE-2023-38739

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 is vulnerable to cross-site request forgery which could allow an atta…

Fix: after 6.2.0.3
Fix from $1,950 2025-01-31
Cognos Controller MEDIUM 6.5
CVE-2024-41776

IBM Cognos Controller 11.0.0 and 11.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious an…

Mitigation only
Fix from $1,600 2024-12-03
Cics Tx HIGH 8.8
CVE-2024-41744

IBM CICS TX Standard 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions tra…

Mitigation only
Fix from $1,950 2024-11-01
Watson Studio Local HIGH 8.8
CVE-2024-49340

IBM Watson Studio Local 1.2.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions…

Mitigation only
Fix from $1,950 2024-10-16
Aspera Orchestrator MEDIUM 6.5
CVE-2023-38001

IBM Aspera Orchestrator 4.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions…

Mitigation only
Fix from $1,600 2024-07-30
Infosphere Information Server HIGH 8.8
CVE-2024-31902

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorize…

Mitigation only
Fix from $1,950 2024-06-30
Integration Bus MEDIUM 6.5
CVE-2024-27265

IBM Integration Bus for z/OS 10.1 through 10.1.0.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and…

Fix: after 10.1.0.3
Fix from $1,600 2024-03-14
Engineering Requirements Management Doors MEDIUM 6.5
CVE-2023-28949

IBM Engineering Requirements Management DOORS 9.7.2.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious …

Mitigation only
Fix from $1,600 2024-03-01
Maximo Application Suite HIGH 8.8
CVE-2023-47718

IBM Maximo Asset Management 7.6.1.3 and Manage Component 8.10 through 8.11 is vulnerable to cross-site request forgery which could allow an attacker …

Fix: 8.10.6+
Fix from $1,950 2024-01-19
Infosphere Information Server HIGH 8.8
CVE-2023-38268

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorize…

Fix: 11.7.1.0 / 11.7.1.4+
Fix from $1,950 2023-12-01
Sterling B2b Integrator HIGH 8.8
CVE-2022-35638

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.1 is vulnerable to cross-site request forgery which co…

Fix: 6.0.3.9 / 6.1.2.3+
Fix from $1,950 2023-11-22
Txseries For Multiplatforms HIGH 8.8
CVE-2023-42027

IBM CICS TX Standard 11.1, Advanced 10.1, 11.1, and TXSeries for Multiplatforms 8.1, 8.2, 9.1 are vulnerable to cross-site request forgery which coul…

Patch available
Fix from $1,950 2023-11-03
Infosphere Information Server HIGH 8.8
CVE-2023-23473

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorize…

Fix: 11.7.1.0 / 11.7.1.4+
Fix from $1,950 2023-08-28
Business Automation Workflow HIGH 8.8
CVE-2022-42435

IBM Business Automation Workflow 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, and 22.0.1 is vulner…

Patch available
Fix from $1,950 2023-01-04
Db2 HIGH 8.8
CVE-2022-41296

IBM Db2U 3.5, 4.0, and 4.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions tr…

Mitigation only
Fix from $1,950 2022-12-12
Db2 On Cloud Pak For Data MEDIUM 6.5
CVE-2022-41297

IBM Db2U 3.5, 4.0, and 4.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions tr…

Fix: 4.6+
Fix from $1,600 2022-12-01
Infosphere Information Server HIGH 8.8
CVE-2022-30608

"IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthoriz…

Patch available
Fix from $1,950 2022-11-03
Websphere Automation For Ibm Cloud Pak For Watson Aiops HIGH 8.8
CVE-2022-22493

IBM WebSphere Automation for Cloud Pak for Watson AIOps 1.4.2 is vulnerable to cross-site request forgery, caused by improper cookie attribute settin…

Fix: 1.4.3+
Fix from $1,950 2022-10-07
Cognos Analytics MEDIUM 6.5
CVE-2020-4301

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and un…

Fix: 11.1.7 / 11.2.3+
Fix from $1,600 2022-09-01
Cognos Analytics MEDIUM 6.5
CVE-2021-20468

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and un…

Fix: 11.1.7 / 11.2.3+
Fix from $1,600 2022-09-01