Vulnerability index

Browse CVEs

61 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
Concert MEDIUM 5.5
CVE-2025-36440

IBM Concert 1.0.0 through 2.2.0 could allow a local user to obtain sensitive information due to missing function level access control.

Fix: after 2.2.0
Fix from $1,600 2026-03-25
Infosphere Information Server MEDIUM 6.5
CVE-2025-14790

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an attacker to obtain sensitive information due to insufficiently protected c…

Fix: after 11.7.1.6
Fix from $1,600 2026-03-25
Devops Deploy MEDIUM 6.5
CVE-2025-14148

IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.3 could allow an authenticated user with LLM integration configuration privileges to recover a previous…

Fix: 8.1.2.4+
Fix from $1,600 2025-12-15
Vios HIGH 8.1
CVE-2025-36096

IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 stores NIM private keys used in NIM environments in an insecure way which is susceptible to unauthoriz…

Mitigation only
Fix from $1,950 2025-11-13
Cognos Controller MEDIUM 6.5
CVE-2025-33079

IBM Controller 11.0.0, 11.0.1, and 11.1.0 application could allow an authenticated user to obtain sensitive credentials that may be inadvertently inc…

Mitigation only
Fix from $1,600 2025-05-27
Sterling Partner Engagement Manager HIGH 7.5
CVE-2025-33093

IBM Sterling Partner Engagement Manager 6.1.0, 6.2.0, 6.2.2 JWT secret is stored in public Helm Charts and is not stored as a Kubernetes secret.

Mitigation only
Fix from $1,950 2025-05-07
Sterling File Gateway MEDIUM 5.3
CVE-2024-47109

IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 UI could disclosure the installation path of the server which could aid…

Fix: 6.1.2.7 / 6.2.0.4+
Fix from $1,600 2025-03-10
Engineering Requirements Management Doors Next HIGH 7.5
CVE-2024-41771

IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7.1 could allow a remote attacker to download temporary files which could expose…

Mitigation only
Fix from $1,950 2025-03-03
Engineering Requirements Management Doors Next HIGH 7.5
CVE-2024-41770

IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7.1 could allow a remote attacker to download temporary files which could expose…

Mitigation only
Fix from $1,950 2025-03-03
Common Licensing MEDIUM 5.5
CVE-2023-50945

IBM Common Licensing 9.0 stores user credentials in plain clear text which can be read by a local user.

Mitigation only
Fix from $1,600 2025-01-26
Cics Transaction Gateway HIGH 7.5
CVE-2023-50310

IBM CICS Transaction Gateway for Multiplatforms 9.2 and 9.3 transmits or stores authentication credentials, but it uses an insecure method that is su…

Mitigation only
Fix from $1,950 2024-10-23
Cognos Analytics MEDIUM 5.5
CVE-2024-40703

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and IBM Cognos Analytics Reports for iOS 11.0.0.7 could …

Fix: 12.0.3+
Fix from $1,600 2024-09-22
Datacap MEDIUM 5.5
CVE-2024-39733

IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 stores user credentials in plain clear text which can be read by a local user. IBM X-For…

Mitigation only
Fix from $1,600 2024-07-14
Txseries For Multiplatform HIGH 7.5
CVE-2024-22345

IBM TXSeries for Multiplatforms 8.2 transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorize…

Mitigation only
Fix from $1,950 2024-05-14
Aspera Faspex HIGH 7.8
CVE-2023-37400

IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to escalate their privileges due to insecure credential storage. IBM X-Force ID: 259…

Fix: 5.0.8+
Fix from $1,950 2024-04-19
Host Access Transformation Services MEDIUM 5.5
CVE-2021-38938

IBM Host Access Transformation Services (HATS) 9.6 through 9.6.1.4 and 9.7 through 9.7.0.3 stores user credentials in plain clear text which can be r…

Fix: after 9.7.0.3
Fix from $1,600 2024-03-15
Storage Defender Resiliency Service MEDIUM 5.5
CVE-2024-22312

IBM Storage Defender - Resiliency Service 2.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 278748.

Patch available
Fix from $1,600 2024-02-10
Db2 Mirror For I MEDIUM 5.3
CVE-2023-47741

IBM i 7.3, 7.4, 7.5, IBM i Db2 Mirror for i 7.4 and 7.5 web browser clients may leave clear-text passwords in browser memory that can be viewed using…

Patch available
Fix from $1,600 2023-12-18
Api Connect MEDIUM 5.5
CVE-2023-47722

IBM API Connect V10.0.5.3 and V10.0.6.0 stores user credentials in browser cache which can be read by a local user. IBM X-Force ID: 271912.

Mitigation only
Fix from $1,600 2023-12-09
Sterling External Authentication Server MEDIUM 5.5
CVE-2023-32338

IBM Sterling Secure Proxy and IBM Sterling External Authentication Server 6.0.3 and 6.1.0 stores user credentials in plain clear text which can be re…

Mitigation only
Fix from $1,600 2023-09-05
Aspera Cargo HIGH 7.5
CVE-2023-22862

IBM Aspera Connect 4.2.5 and IBM Aspera Cargo 4.2.5 transmits authentication credentials, but it uses an insecure method that is susceptible to unaut…

Fix: 4.2.6+
Fix from $1,950 2023-06-05
Security Key Lifecycle Manager MEDIUM 5.5
CVE-2023-25686

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 stores user credentials in plain clear text which can be read by a local …

Patch available
Fix from $1,600 2023-03-21
Security Verify Governance MEDIUM 6.5
CVE-2022-22458

IBM Security Verify Governance, Identity Manager 10.0.1 stores user credentials in plain clear text which can be read by a remote authenticated user.…

Patch available
Fix from $1,600 2022-12-22
Maximo Application Suite MEDIUM 5.5
CVE-2022-41732

IBM Maximo Mobile 8.7 and 8.8 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 237407.

Mitigation only
Fix from $1,600 2022-11-28
Robotic Process Automation HIGH 7.5
CVE-2022-39168

IBM Robotic Process Automation Clients are vulnerable to proxy credentials being exposed in upgrade logs. IBM X-Force ID: 235422.

Patch available
Fix from $1,950 2022-09-29
Cognos Analytics MEDIUM 5.5
CVE-2021-39045

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a local attacker to obtain information due to the autocomplete feature on password input …

Fix: 11.1.7 / 11.2.3+
Fix from $1,600 2022-09-01
Robotic Process Automation MEDIUM 6.5
CVE-2022-33169

IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to insufficiently protected credentials for users created via a bulk upload. …

Fix: after 21.0.3
Fix from $1,600 2022-08-01
Spectrum Protect Plus HIGH 7.5
CVE-2022-22396

Credentials are printed in clear text in the IBM Spectrum Protect Plus 10.1.0.0 through 10.1.9.3 virgo log file in certain cases. Credentials could b…

Fix: 10.1.10+
Fix from $1,950 2022-06-06
Security Guardium Key Lifecycle Manager MEDIUM 5.5
CVE-2021-38976

IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 stores user credentials in plain clear text which can be read by a local user. X-Force ID: …

Fix: after 4.0.0.3
Fix from $1,600 2021-11-15
Security Verify Bridge MEDIUM 5.5
CVE-2021-38863

IBM Security Verify Bridge 1.0.5.0 stores user credentials in plain clear text which can be read by a locally authenticated user. IBM X-Force ID: 208…

Fix: 1.0.7+
Fix from $1,600 2021-09-23