Vulnerability index

Browse CVEs

50 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Security Verify Directory HIGH 7.2
CVE-2025-36074

IBM Security Verify Directory (Container) 10.0.0 through 10.0.0.3 IBM Security Verify Directory could be vulnerable to malicious file upload by not v…

Fix: after 10.0.3
Fix from $1,950 2026-04-23
Datastage On Cloud Pak For Data HIGH 8.8
CVE-2025-13689

IBM DataStage on Cloud Pak for Data could allow an authenticated user to execute arbitrary commands and gain access to sensitive information due to u…

Fix: 5.3.1+
Fix from $1,950 2026-02-17
Concert HIGH 8.8
CVE-2025-33015

IBM Concert 1.0.0 through 2.1.0 is vulnerable to malicious file upload by not validating the content of the file uploaded to the web interface.

Fix: 2.2.0+
Fix from $1,950 2026-01-20
Integrated Analytics System HIGH 8.0
CVE-2025-36174

IBM Integrated Analytics System 1.0.0.0 through 1.0.30.0 could allow an authenticated user to upload a file with dangerous types that could be execut…

Fix: after 1.0.31.0
Fix from $1,950 2025-08-24
Analytics Content Hub CRITICAL 9.8
CVE-2024-39752

IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could be vulnerable to malicious file upload by not validating the type of file uploaded to Explore …

Fix: 2.4+
Fix from $2,300 2025-07-10
Maximo Application Suite HIGH 8.0
CVE-2025-1500

IBM Maximo Application Suite 9.0 could allow an authenticated user to upload a file with dangerous types that could be executed by another user if op…

Fix: 9.0.7+
Fix from $1,950 2025-04-05
Planning Analytics HIGH 8.0
CVE-2024-40693

IBM Planning Analytics 2.0 and 2.1 could be vulnerable to malicious file upload by not validating the content of the file uploaded to the web interfa…

Mitigation only
Fix from $1,950 2025-01-24
Planning Analytics HIGH 8.8
CVE-2024-25034

IBM Planning Analytics 2.0 and 2.1 could be vulnerable to malicious file upload by not validating the type of file in the File Manager T1 process. At…

Mitigation only
Fix from $1,950 2025-01-24
Cognos Analytics HIGH 8.0
CVE-2024-40695

IBM Cognos Analytics 11.2.0 through 11.2.4 FP4 and 12.0.0 through 12.0.4 could be vulnerable to malicious file upload by not validating the cont…

Fix: 11.2.4 / 12.0.4+
Fix from $1,950 2024-12-20
Cognos Controller CRITICAL 9.8
CVE-2024-25020

IBM Cognos Controller 11.0.0 and 11.0.1 is vulnerable to malicious file upload by allowing unrestricted filetype attachments in the Jou…

Mitigation only
Fix from $2,300 2024-12-03
Cognos Controller CRITICAL 9.8
CVE-2024-40691

IBM Cognos Controller 11.0.0 and 11.0.1 could be vulnerable to malicious file upload by not validating the content of the file uploaded to the web …

Mitigation only
Fix from $2,300 2024-12-03
Cognos Controller CRITICAL 9.8
CVE-2024-25019

IBM Cognos Controller 11.0.0 and 11.0.1 could be vulnerable to malicious file upload by not validating the type of file uploaded to Journal entry a…

Mitigation only
Fix from $2,300 2024-12-03
Webmethods Integration CRITICAL 9.9
CVE-2024-45076

IBM webMethods Integration 10.15 could allow an authenticated user to upload and execute arbitrary files which could be executed on the underlying op…

Mitigation only
Fix from $2,300 2024-09-04
Engineering Lifecycle Optimization Publishing CRITICAL 9.8
CVE-2023-45188

IBM Engineering Lifecycle Optimization Publishing 7.0.2 and 7.03 could allow a remote attacker to upload arbitrary files, caused by the improper vali…

Mitigation only
Fix from $2,300 2024-06-09
Security Guardium MEDIUM 6.5
CVE-2023-47711

IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow an authenticated user to upload files that would cause a denial of service. IBM X-Force…

Mitigation only
Fix from $1,600 2024-05-14
Security Guardium Key Lifecycle Manager HIGH 8.8
CVE-2023-25921

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 allows the attacker to upload or transfer files of dangerous types that c…

Fix: 4.1.1.7+
Fix from $1,950 2024-02-29
Security Guardium Key Lifecycle Manager HIGH 8.8
CVE-2023-25922

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 allows the attacker to upload or transfer files of dangerous types that c…

Fix: 4.1.1.7+
Fix from $1,950 2024-02-28
Trusteer Android Sdk For Mobile CRITICAL 9.8
CVE-2022-42443

An undisclosed issue in Trusteer iOS SDK for mobile versions prior to 5.7 and Trusteer Android SDK for mobile versions prior to 5.7 may allow uploadi…

Fix: 5.7+
Fix from $2,300 2024-02-17
Planning Analytics CRITICAL 9.8
CVE-2023-42017

IBM Planning Analytics Local 2.0 could allow a remote attacker to upload arbitrary files, caused by the improper validation of file extensions. By s…

Mitigation only
Fix from $2,300 2023-12-22
Security Guardium Key Lifecycle Manager HIGH 8.8
CVE-2023-47706

IBM Security Guardium Key Lifecycle Manager 4.3 could allow an authenticated user to upload files of a dangerous file type. IBM X-Force ID: 271341.

Fix: 4.2.0.2+
Fix from $1,950 2023-12-20
Security Verify Privilege On Premises HIGH 8.8
CVE-2022-22375

IBM Security Verify Privilege On-Premises 11.5 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a s…

Fix: 11.5+
Fix from $1,950 2023-10-17
Security Verify Governance HIGH 7.2
CVE-2023-35018

IBM Security Verify Governance 10.0 could allow a privileged use to upload arbitrary files due to improper file validation. IBM X-Force ID: 259382.

Fix: 10.0.2+
Fix from $1,950 2023-10-16
Security Directory Suite Va HIGH 7.2
CVE-2022-33166

IBM Security Directory Suite VA 8.0.1 through 8.0.1.19 could allow a privileged user to upload malicious files of dangerous types that can be automat…

Fix: after 8.0.1.19
Fix from $1,950 2023-06-15
Cloud Pak For Data HIGH 7.2
CVE-2022-36769

IBM Cloud Pak for Data 4.5 and 4.6 could allow a privileged user to upload malicious files of dangerous types that can be automatically processed wit…

Mitigation only
Fix from $1,950 2023-04-26
Cognos Analytics CRITICAL 9.8
CVE-2021-38945

IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 could allow a remote attacker to upload arbitrary files, caused by improper content validation. IBM X…

Fix: 11.1.7+
Fix from $2,300 2022-06-24
Sterling B2b Integrator MEDIUM 6.5
CVE-2022-22482

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5 and 6.1.0.0 through 6.1.1.0 could allow an authenticated user to upload files th…

Fix: after 6.1.1.0
Fix from $1,600 2022-05-17
Planning Analytics Workspace HIGH 7.8
CVE-2022-22392

IBM Planning Analytics Local 2.0 could allow an attacker to upload arbitrary executable files which, when executed by an unsuspecting victim could re…

Mitigation only
Fix from $1,950 2022-04-25
Planning Analytics Workspace HIGH 8.0
CVE-2021-39040

IBM Planning Analytics Workspace 2.0 could be vulnerable to malicious file upload by not validating the file types or sizes. Attackers can make use o…

Mitigation only
Fix from $1,950 2022-04-25
Openpages With Watson HIGH 8.8
CVE-2021-29907

IBM OpenPages with Watson 8.1 and 8.2 could allow an authenticated user to upload a file that could execute arbitrary code on the system. IBM X-Force…

Fix: 8.1.0.2.1 / 8.2.0.2+
Fix from $1,950 2021-08-31
Security Verify Access MEDIUM 6.8
CVE-2021-29699

IBM Security Verify Access Docker 10.0.0 could allow a remote priviled user to upload arbitrary files with a dangerous file type that could be excute…

Patch available
Fix from $1,600 2021-07-15