Vulnerability index

Browse CVEs

47 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Maximo Asset Management HIGH 8.8
CVE-2020-4521EPSS 6%

IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unsafe …

Fix: 7.6.0.10 / 7.6.1.2+
Fix from $1,950 2020-09-15
Websphere Application Server CRITICAL 9.8
CVE-2020-4589EPSS 8%

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafte…

Fix: after 9.0.5.4
Fix from $2,300 2020-08-13
Websphere Application Server HIGH 8.8
CVE-2020-4464EPSS 13%

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code on a system with a specia…

Fix: after 9.0.5.4
Fix from $1,950 2020-07-17
Infosphere Information Server HIGH 8.8
CVE-2020-4305

IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow a remote attacker to execute arbitrary code on the system, caused by the deseriali…

Fix: after 11.7.1.1
Fix from $1,950 2020-07-09
Websphere Application Server CRITICAL 9.8
CVE-2020-4448EPSS 12%

IBM WebSphere Application Server Network Deployment 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the system with…

Fix: 8.5.5.18 / 9.0.5.4+
Fix from $2,300 2020-06-05
Websphere Application Server CRITICAL 9.8
CVE-2020-4450EPSS 34%

IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially-craft…

Fix: 8.5.5.18 / 9.0.5.5+
Fix from $2,300 2020-06-05
Websphere Application Server HIGH 7.5
CVE-2020-4449

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to obtain sensitive information with a specially-cr…

Fix: after 9.0.5.4
Fix from $1,950 2020-06-05
Qradar Security Information And Event Manager HIGH 8.8
CVE-2020-4272

IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-crafted request …

Fix: 7.3.3+
Fix from $1,950 2020-04-15
Qradar Security Information And Event Manager MEDIUM 6.3
CVE-2020-4271

IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow an authenticated user to send a specially crafted command which would be executed as a lower privileged…

Fix: 7.3.3+
Fix from $1,600 2020-04-15
Security Identity Manager HIGH 8.8
CVE-2019-4561

IBM Security Identity Manager 6.0.0 could allow a remote attacker to execute arbitrary code on the system, caused by the deserialization of untrusted…

Mitigation only
Fix from $1,950 2019-11-20
Websphere Application Server CRITICAL 9.8
CVE-2019-4279EPSS 80%

IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence …

Fix: after 9.0.0.11
Fix from $2,300 2019-05-17
Websphere Application Server CRITICAL 9.8
CVE-2018-1904

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbitrary Java code through an administrative client …

Fix: after 9.0.0.9
Fix from $2,300 2018-12-11
Websphere Application Server CRITICAL 9.8
CVE-2018-1851

IBM WebSphere Application Server Liberty OpenID Connect could allow a remote attacker to execute arbitrary code on the system, caused by improper des…

Fix: 18.0.0.3+
Fix from $2,300 2018-10-31
Websphere Application Server CRITICAL 9.8
CVE-2018-1567

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbitrary Java code through the SOAP connector with a…

Fix: after 9.0.0.9
Fix from $2,300 2018-09-07
Db2 HIGH 7.8
CVE-2017-1677

IBM Data Server Driver for JDBC and SQLJ (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) deserializes the contents of /tmp/connlicj.b…

Mitigation only
Fix from $1,950 2018-03-22
Websphere Mq Jms CRITICAL 9.8
CVE-2016-0360

IBM Websphere MQ JMS 7.0.1, 7.1, 7.5, 8.0, and 9.0 client provides classes that deserialize objects from untrusted sources which could allow a malici…

Mitigation only
Fix from $2,300 2017-02-15
Sterling B2b Integrator CRITICAL 9.8
CVE-2015-7450 KEVEPSS 98%

Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote …

Fix: after 10.0.0.2
Fix from $2,300 2016-01-02