Vulnerability index

Browse CVEs

61 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
Security Access Manager HIGH 7.5
CVE-2021-20439

IBM Security Access Manager 9.0 and IBM Security Verify Access Docker 10.0.0 stores user credentials in plain clear text which can be read by an unau…

Patch available
Fix from $1,950 2021-07-15
Cognos Analytics HIGH 7.5
CVE-2019-4723

IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain credentials from a user's browser via incorrect autocomplete settings in N…

Patch available
Fix from $1,950 2021-06-01
Cognos Analytics HIGH 7.5
CVE-2019-4724

IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain credentials from a user's browser via incorrect autocomplete settings in N…

Patch available
Fix from $1,950 2021-06-01
Security Guardium HIGH 7.8
CVE-2021-20389

IBM Security Guardium 11.2 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 195770.

Patch available
Fix from $1,950 2021-05-24
Maximo For Civil Infrastructure MEDIUM 6.5
CVE-2021-20445

IBM Maximo for Civil Infrastructure 7.6.2 could allow a user to obtain sensitive information due to insecure storeage of authentication credentials. …

Patch available
Fix from $1,600 2021-02-18
Security Verify Information Queue MEDIUM 5.3
CVE-2021-20410

IBM Security Verify Information Queue 1.0.6 and 1.0.7 sends user credentials in plain clear text which can be read by an authenticated user using man…

Patch available
Fix from $1,600 2021-02-12
Security Key Lifecycle Manager MEDIUM 5.5
CVE-2020-4568

IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, and 4.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID…

Patch available
Fix from $1,600 2020-11-10
Bladecenter Advanced Management Module Firmware MEDIUM 6.1
CVE-2020-8339

A cross-site scripting inclusion (XSSI) vulnerability was reported in the legacy IBM BladeCenter Advanced Management Module (AMM) web interface prior…

Fix: 3.68n+
Fix from $1,600 2020-09-15
Guardium Data Encryption MEDIUM 6.5
CVE-2019-4697

IBM Security Guardium Data Encryption (GDE) 3.0.0.2 stores user credentials in plain in clear text which can be read by an authenticated user. IBM X-…

Fix: 1.7.0+
Fix from $1,600 2020-08-26
Verify Gateway HIGH 7.8
CVE-2020-4372

IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 179009

Patch available
Fix from $1,950 2020-07-22
Urbancode Deploy MEDIUM 5.5
CVE-2019-4668

IBM UrbanCode Deploy (UCD) 7.0.4.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 171250.

Fix: 7.0.4.0+
Fix from $1,600 2020-04-23
Qradar Security Information And Event Manager HIGH 7.8
CVE-2019-4508

IBM QRadar SIEM 7.3.0 through 7.3.3 uses weak credential storage in some instances which could be decrypted by a local attacker. IBM X-Force ID: 1644…

Fix: after 7.3.3
Fix from $1,950 2020-01-10
Watson Studio Local MEDIUM 5.5
CVE-2019-4335

IBM Watson Studio Local 1.2.3 stores key files in the user's home directory which could be obtained by another local user. IBM X-Force ID: 161413.

Patch available
Fix from $1,600 2019-12-30
Security Guardium Big Data Intelligence MEDIUM 5.5
CVE-2019-4307

IBM Security Guardium Big Data Intelligence (SonarG) 4.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Forc…

Patch available
Fix from $1,600 2019-10-29
Spectrum Protect Plus MEDIUM 6.5
CVE-2019-4385

IBM Spectrum Protect Plus 10.1.2 may display the vSnap CIFS password in the IBM Spectrum Protect Plus Joblog. This can result in an attacker gaining …

Fix: after 10.1.2.303
Fix from $1,600 2019-06-19
Cloud Private MEDIUM 5.5
CVE-2019-4239

IBM MQ Advanced Cloud Pak (IBM Cloud Private 1.0.0 through 3.0.1) stores user credentials in plain in clear text which can be read by a local user. I…

Fix: after 3.0.1
Fix from $1,600 2019-06-14
Spectrum Control MEDIUM 5.9
CVE-2019-4138

IBM Tivoli Storage Productivity Center 5.2.13 through 5.3.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to…

Fix: after 5.3.2.0
Fix from $1,600 2019-05-29
Rational Clearcase CRITICAL 9.8
CVE-2019-4059

IBM Rational ClearCase 1.0.0.0 GIT connector does not sufficiently protect the document database password. An attacker could obtain the password and …

Fix: 9.0.1.5+
Fix from $2,300 2019-02-15
Bigfix Platform HIGH 7.8
CVE-2017-1231

IBM BigFix Platform 9.5 - 9.5.9 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 123910.

Fix: after 9.5.9
Fix from $1,950 2018-10-12
Security Guardium HIGH 7.8
CVE-2018-1498

IBM Security Guardium EcoSystem 10.5 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 141223.

Mitigation only
Fix from $1,950 2018-10-02
Security Identity Governance And Intelligence HIGH 7.5
CVE-2017-1411

IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 does not require that users should have strong passwords by default, which mak…

Patch available
Fix from $1,950 2018-08-06
Cognos Business Intelligence HIGH 7.0
CVE-2017-1764

IBM Cognos Business Intelligence 10.2, 10.2.1, 10.2.1.1, and 10.2.2, under specialized circumstances, could expose plain text credentials to a local …

No fix yet
Fix from $1,950 2018-04-23
Security Guardium Big Data Intelligence HIGH 7.8
CVE-2018-1377

IBM Security Guardium Big Data Intelligence (SonarG) 3.1 stores user credentials in plain in clear text which can be read by a local user. IBM X-Forc…

Mitigation only
Fix from $1,950 2018-02-26
Cognos Analytics HIGH 7.8
CVE-2017-1779

IBM Cognos Analytics 11.0 could store cached credentials locally that could be obtained by a local user. IBM X-Force ID: 136824.

Patch available
Fix from $1,950 2018-01-29
Bigfix Security Compliance Analytics HIGH 7.8
CVE-2017-1201

IBM BigFix Compliance Analytics 1.9.79 (TEMA SUAv1 SCA SCM) stores user credentials in clear text which can be read by a local user. IBM X-Force ID: …

Mitigation only
Fix from $1,950 2017-10-05
Tivoli Storage Manager HIGH 7.8
CVE-2017-1378

IBM Spectrum Protect 7.1 and 8.1 (formerly Tivoli Storage Manager) disclosed unencrypted login credentials to Vmware vCenter in the application trace…

Patch available
Fix from $1,950 2017-10-05
Security Identity Manager HIGH 7.8
CVE-2017-1362

IBM Security Identity Manager Adapters 6.0 and 7.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: …

Patch available
Fix from $1,950 2017-09-25
Websphere Mq HIGH 8.1
CVE-2017-1337

IBM WebSphere MQ 9.0.1 and 9.0.2 Java/JMS application can incorrectly transmit user credentials in plain text. IBM X-Force ID: 126245.

Mitigation only
Fix from $1,950 2017-07-10
Websphere Message Broker MEDIUM 5.5
CVE-2017-1207

IBM WebSphere Message Broker stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 123777.

Mitigation only
Fix from $1,600 2017-07-05
Security Access Manager For Web 8.0 Firmware MEDIUM 5.5
CVE-2015-5013

The IBM Security Access Manager appliance includes configuration files that contain obfuscated plaintext-passwords which authenticated users can acce…

Patch available
Fix from $1,600 2017-02-08