Vulnerability index

Browse CVEs

199 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Cloud App Management HIGH 8.8
CVE-2019-4750

IBM Cloud App Management 2019.3.0 and 2019.4.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and una…

Mitigation only
Fix from $1,950 2020-04-24
Tivoli Netcool\/impact HIGH 8.8
CVE-2020-4238

IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and…

Fix: after 7.1.0.17
Fix from $1,950 2020-03-31
Tivoli Netcool\/impact HIGH 8.8
CVE-2020-4237

IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and…

Fix: after 7.1.0.17
Fix from $1,950 2020-03-31
Planning Analytics HIGH 8.8
CVE-2019-4613

IBM Planning Analytics 2.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions tr…

Mitigation only
Fix from $1,950 2020-02-05
Cognos Business Intelligence HIGH 8.8
CVE-2018-1934

IBM Cognos Business Intelligence 10.2.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthoriz…

Mitigation only
Fix from $1,950 2019-12-20
Security Key Lifecycle Manager MEDIUM 6.5
CVE-2019-4515

IBM Security Key Lifecycle Manager 3.0 and 3.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and u…

Fix: after 3.0.1.1
Fix from $1,600 2019-09-24
Storediq MEDIUM 6.5
CVE-2019-4167

IBM StoredIQ 7.6.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitte…

Fix: after 7.6.0.18
Fix from $1,600 2019-08-20
Cloud Private HIGH 8.8
CVE-2019-4117

IBM Cloud Private 3.1.1 and 3.1.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized act…

Fix: after 2.1.0.3
Fix from $1,950 2019-08-20
Qradar Security Information And Event Manager HIGH 8.8
CVE-2019-4212

IBM QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions t…

Fix: 7.2.8 / 7.3.2+
Fix from $1,950 2019-07-25
Api Connect HIGH 8.8
CVE-2018-1858

IBM API Connect 5.0.0.0 through 5.0.8.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthoriz…

Fix: after 5.0.8.6
Fix from $1,950 2019-06-25
Cloud Private HIGH 8.8
CVE-2019-4142

IBM Cloud Private 2.1.0, 3.1.0, 3.1.1, and 3.1.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and u…

Fix: after 2.1.0.3
Fix from $1,950 2019-06-18
Financial Transaction Manager HIGH 8.8
CVE-2018-1790

IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.0.2 is vulnerable to cross-site request forgery which could allow an atta…

Fix: after 3.0.2.1
Fix from $1,950 2019-05-10
Curam Social Program Management HIGH 8.8
CVE-2018-2001

IBM Cram Social Program Management 6.1.1, 6.2.0, 7.0.4, and 7.0.5 is vulnerable to cross-site request forgery which could allow an attacker to execut…

Fix: after 7.0.4.0
Fix from $1,950 2019-05-07
Business Automation Workflow HIGH 8.8
CVE-2018-2000

IBM Business Automation Workflow 18.0.0.0 and 18.0.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious…

Patch available
Fix from $1,950 2019-04-08
Security Privileged Identity Manager HIGH 8.8
CVE-2018-1622

IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute…

Mitigation only
Fix from $1,950 2019-04-02
Datapower Gateway HIGH 8.8
CVE-2018-1661

IBM DataPower Gateways 7.5, 7.5.1, 7.5.2, and 7.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and …

Fix: after 7.6.0.9
Fix from $1,950 2018-12-20
Websphere Application Server HIGH 8.8
CVE-2018-1926

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Admin Console is vulnerable to cross-site request forgery, caused by improper validation of u…

Fix: after 9.0.0.9
Fix from $1,950 2018-12-12
Storediq HIGH 8.8
CVE-2018-1927

IBM StoredIQ 7.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted …

Fix: 7.6.0.17+
Fix from $1,950 2018-11-30
Api Connect CRITICAL 9.9
CVE-2018-1712

IBM API Connect's Developer Portal 5.0.0.0 through 5.0.8.3 is vulnerable to Server Side Request Forgery. An attacker, using specially crafted input p…

Fix: after 5.0.8.3
Fix from $2,300 2018-08-16
Tivoli Application Dependency Discovery Manager HIGH 8.8
CVE-2018-1455

IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 is vulnerable to cross-site request forgery which could allow an attacker to execut…

Mitigation only
Fix from $1,950 2018-08-15
Robotic Process Automation With Automation Anywhere HIGH 8.8
CVE-2018-1514

IBM Robotic Process Automation with Automation Anywhere 10.0 is vulnerable to cross-site request forgery which could allow an attacker to execute mal…

Patch available
Fix from $1,950 2018-06-07
Infosphere Information Server MEDIUM 6.1
CVE-2018-1432

IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 is vulnerable to cross-frame scripting which is a vulnerability that allows an attacker t…

Mitigation only
Fix from $1,600 2018-06-05
Storwize V7000 Firmware HIGH 8.8
CVE-2018-1434

IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6…

Fix: 7.5.0.14 / 7.7.1.9+
Fix from $1,950 2018-05-17
Bigfix Platform HIGH 8.8
CVE-2018-1479

IBM BigFix Platform 9.2 and 9.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actio…

Fix: after 9.5.8
Fix from $1,950 2018-04-27
Qradar Security Information And Event Manager HIGH 8.8
CVE-2015-2009

Cross-site request forgery (CSRF) vulnerability in the xmlrpc.cgi service in IBM QRadar SIEM 7.1 before MR2 Patch 11 Interim Fix 02 and 7.2.x before …

Fix: 7.2.5+
Fix from $1,950 2018-03-29
Financial Transaction Manager HIGH 8.0
CVE-2016-0272

Cross-site request forgery (CSRF) vulnerability in IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x be…

Fix: after 3.0.0.12
Fix from $1,950 2018-03-09
Monitoring HIGH 8.8
CVE-2018-1442

IBM Application Performance Management - Response Time Monitoring Agent (IBM Monitoring 8.1.4) is vulnerable to cross-site request forgery which coul…

Mitigation only
Fix from $1,950 2018-03-08
Bigfix Platform HIGH 8.8
CVE-2016-0295

Cross-site request forgery (CSRF) vulnerability in the IBM BigFix Platform 9.0, 9.1, 9.2, and 9.5 before 9.5.2 allows remote attackers to hijack the …

Fix: 9.5.2+
Fix from $1,950 2018-02-28
Tririga Application Platform HIGH 8.0
CVE-2016-0348

Cross-site request forgery (CSRF) vulnerability in IBM TRIRIGA Application Platform 3.3, 3.3.1, 3.3.2, and 3.4 allows remote attackers to hijack the …

Mitigation only
Fix from $1,950 2018-02-21
Business Process Manager HIGH 8.8
CVE-2017-1769

IBM Business Process Manager 8.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized acti…

Patch available
Fix from $1,950 2018-01-24