Vulnerability index

Browse CVEs

199 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Cognos Analytics MEDIUM 6.5
CVE-2021-29823

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and un…

Fix: 11.1.7 / 11.2.3+
Fix from $1,600 2022-09-01
Datapower Gateway HIGH 8.8
CVE-2022-31773

IBM DataPower Gateway V10CD, 10.0.1, and 2018.4.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and …

Fix: 10.5.0+
Fix from $1,950 2022-08-26
Cics Tx HIGH 8.8
CVE-2022-34161

IBM CICS TX 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted …

Patch available
Fix from $1,950 2022-08-01
Security Verify Information Queue HIGH 8.8
CVE-2022-35286

IBM Security Verify Information Queue 10.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unaut…

Patch available
Fix from $1,950 2022-07-26
Security Verify Information Queue HIGH 8.8
CVE-2022-35285

IBM Security Verify Information Queue 10.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unaut…

Patch available
Fix from $1,950 2022-07-25
Partner Engagement Manager MEDIUM 6.5
CVE-2022-22359

IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to cross-site request forgery which could allow an attacker to …

Fix: 6.1.2.5 / 6.2.0.3+
Fix from $1,600 2022-07-19
Engineering Requirements Quality Assistant On Premises MEDIUM 6.5
CVE-2021-38868

IBM Engineering Requirements Quality Assistant On-Premises (All versions) is vulnerable to cross-site request forgery which could allow an attacker t…

Mitigation only
Fix from $1,600 2022-07-18
Spectrum Copy Data Management HIGH 8.8
CVE-2022-22479

IBM Spectrum Copy Data Management 2.2.0.0through 2.2.15.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malici…

Fix: after 2.2.15.0
Fix from $1,950 2022-06-10
Business Automation Workflow MEDIUM 6.5
CVE-2022-22361

IBM Business Automation Workflow traditional 21.0.1 through 21.0.3, 20.0.0.1 through 20.0.0.2, 19.0.0.1 through 19.0.0.3, 18.0.0.0 through 18.0.0.1, …

Fix: after 21.0.3
Fix from $1,600 2022-05-31
Cognos Analytics HIGH 8.8
CVE-2021-38886

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and un…

Patch available
Fix from $1,950 2022-04-22
Sterling B2b Integrator HIGH 8.8
CVE-2020-4668

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.3, and 6.1.1.0 is vulnerable to cross-site request forger…

Fix: after 6.1.0.3
Fix from $1,950 2022-04-08
Spectrum Protect Operations Center HIGH 8.8
CVE-2022-22346

IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.13.xxx is vulnerable to cross-site request forgery which could allow an attacker to exec…

Fix: 8.1.14.000+
Fix from $1,950 2022-03-14
Financial Transaction Manager HIGH 8.8
CVE-2021-39044

IBM Financial Transaction Manager 3.2.4 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthoriz…

Mitigation only
Fix from $1,950 2022-02-02
Cognos Analytics HIGH 8.8
CVE-2021-29756

IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site request forgery (CSRF) in the My Inbox page which could allow an attacker to execu…

Fix: 11.1.7+
Fix from $1,950 2021-12-03
Infosphere Information Server HIGH 8.8
CVE-2021-29888

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorize…

Patch available
Fix from $1,950 2021-11-02
Sterling File Gateway HIGH 8.8
CVE-2021-20489

IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and …

Fix: after 6.1.0.3
Fix from $1,950 2021-10-07
Sterling B2b Integrator HIGH 8.8
CVE-2021-29837

IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 is vulnerable to cross-site request forgery which could allow an attacker to exe…

Fix: after 6.1.0.3
Fix from $1,950 2021-10-06
Jazz For Service Management MEDIUM 6.5
CVE-2021-29816

IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to cross-site request forgery which could allow an attacker…

Patch available
Fix from $1,600 2021-09-23
Datapower Gateway MEDIUM 6.5
CVE-2020-4992

IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.16 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious a…

Fix: after 2018.4.1.16
Fix from $1,600 2021-08-17
Qradar User Behavior Analytics HIGH 8.8
CVE-2021-29757

IBM QRadar User Behavior Analytics 4.1.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthori…

Patch available
Fix from $1,950 2021-08-02
Infosphere Master Data Management Server MEDIUM 6.5
CVE-2020-4675

IBM InfoSphere Master Data Management Server 11.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and …

Mitigation only
Fix from $1,600 2021-07-16
Mq Appliance HIGH 8.8
CVE-2020-4938

IBM MQ Appliance 9.1 and 9.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions …

Fix: 9.1.0.8 / 9.2.0.2+
Fix from $1,950 2021-07-12
Security Verify Information Queue HIGH 8.8
CVE-2021-20403

IBM Security Verify Information Queue 1.0.6 and 1.0.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious …

Mitigation only
Fix from $1,950 2021-02-11
Curam Social Program Management HIGH 8.8
CVE-2020-4942

IBM Curam Social Program Management 7.0.9 and 7.0.11 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious a…

Mitigation only
Fix from $1,950 2021-01-04
Cloud Pak System HIGH 8.8
CVE-2020-4917

IBM Cloud Pak System 2.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions tran…

Fix: 2.3.3.3+
Fix from $1,950 2021-01-04
Planning Analytics MEDIUM 6.5
CVE-2020-4764

IBM Planning Analytics 2.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions tr…

Patch available
Fix from $1,600 2020-12-18
Financial Transaction Manager For Multiplatform MEDIUM 6.5
CVE-2020-4904

IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 is vulnerable to cross-site request forgery which could allow an attack…

Patch available
Fix from $1,600 2020-12-16
Curam Social Program Management MEDIUM 6.5
CVE-2020-4773

A cross-site request forgery (CSRF) vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10, which is an attack that forces a u…

Mitigation only
Fix from $1,600 2020-10-12
Data Risk Manager HIGH 8.1
CVE-2020-4617

IBM Data Risk Manager (iDNA) 2.0.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized ac…

Fix: 2.0.6.4+
Fix from $1,950 2020-09-22
Infosphere Information Server MEDIUM 6.5
CVE-2020-4286

IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious…

Patch available
Fix from $1,600 2020-05-19