Vulnerability index

Browse CVEs

61 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
MEDIUM 5.5 CVE-2025-36440 IBM Concert 1.0.0 through 2.2.0 could allow a local user to obtain sensitive information due to missing function level access control. Concert after 2.2.0 Fix from $1,6002026-03-25 MEDIUM 6.5 CVE-2025-14790 IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an attacker to obtain sensitive information due to insufficiently protected c… Infosphere Information Server after 11.7.1.6 Fix from $1,6002026-03-25 MEDIUM 6.5 CVE-2025-14148 IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.3 could allow an authenticated user with LLM integration configuration privileges to recover a previous… Devops Deploy 8.1.2.4+ Fix from $1,6002025-12-15 HIGH 8.1 CVE-2025-36096 IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 stores NIM private keys used in NIM environments in an insecure way which is susceptible to unauthoriz… Vios Mitigation only Fix from $1,9502025-11-13 MEDIUM 6.5 CVE-2025-33079 IBM Controller 11.0.0, 11.0.1, and 11.1.0 application could allow an authenticated user to obtain sensitive credentials that may be inadvertently inc… Cognos Controller Mitigation only Fix from $1,6002025-05-27 HIGH 7.5 CVE-2025-33093 IBM Sterling Partner Engagement Manager 6.1.0, 6.2.0, 6.2.2 JWT secret is stored in public Helm Charts and is not stored as a Kubernetes secret. Sterling Partner Engagement Manager Mitigation only Fix from $1,9502025-05-07 MEDIUM 5.3 CVE-2024-47109 IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 UI could disclosure the installation path of the server which could aid… Sterling File Gateway 6.1.2.7 / 6.2.0.4+ Fix from $1,6002025-03-10 HIGH 7.5 CVE-2024-41771 IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7.1 could allow a remote attacker to download temporary files which could expose… Engineering Requirements Management Doors Next Mitigation only Fix from $1,9502025-03-03 HIGH 7.5 CVE-2024-41770 IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7.1 could allow a remote attacker to download temporary files which could expose… Engineering Requirements Management Doors Next Mitigation only Fix from $1,9502025-03-03 MEDIUM 5.5 CVE-2023-50945 IBM Common Licensing 9.0 stores user credentials in plain clear text which can be read by a local user. Common Licensing Mitigation only Fix from $1,6002025-01-26 HIGH 7.5 CVE-2023-50310 IBM CICS Transaction Gateway for Multiplatforms 9.2 and 9.3 transmits or stores authentication credentials, but it uses an insecure method that is su… Cics Transaction Gateway Mitigation only Fix from $1,9502024-10-23 MEDIUM 5.5 CVE-2024-40703 IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and IBM Cognos Analytics Reports for iOS 11.0.0.7 could … Cognos Analytics 12.0.3+ Fix from $1,6002024-09-22 MEDIUM 5.5 CVE-2024-39733 IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 stores user credentials in plain clear text which can be read by a local user. IBM X-For… Datacap Mitigation only Fix from $1,6002024-07-14 HIGH 7.5 CVE-2024-22345 IBM TXSeries for Multiplatforms 8.2 transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorize… Txseries For Multiplatform Mitigation only Fix from $1,9502024-05-14 HIGH 7.8 CVE-2023-37400 IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to escalate their privileges due to insecure credential storage. IBM X-Force ID: 259… Aspera Faspex 5.0.8+ Fix from $1,9502024-04-19 MEDIUM 5.5 CVE-2021-38938 IBM Host Access Transformation Services (HATS) 9.6 through 9.6.1.4 and 9.7 through 9.7.0.3 stores user credentials in plain clear text which can be r… Host Access Transformation Services after 9.7.0.3 Fix from $1,6002024-03-15 MEDIUM 5.5 CVE-2024-22312 IBM Storage Defender - Resiliency Service 2.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 278748. Storage Defender Resiliency Service Patch available Fix from $1,6002024-02-10 MEDIUM 5.3 CVE-2023-47741 IBM i 7.3, 7.4, 7.5, IBM i Db2 Mirror for i 7.4 and 7.5 web browser clients may leave clear-text passwords in browser memory that can be viewed using… Db2 Mirror For I Patch available Fix from $1,6002023-12-18 MEDIUM 5.5 CVE-2023-47722 IBM API Connect V10.0.5.3 and V10.0.6.0 stores user credentials in browser cache which can be read by a local user. IBM X-Force ID: 271912. Api Connect Mitigation only Fix from $1,6002023-12-09 MEDIUM 5.5 CVE-2023-32338 IBM Sterling Secure Proxy and IBM Sterling External Authentication Server 6.0.3 and 6.1.0 stores user credentials in plain clear text which can be re… Sterling External Authentication Server Mitigation only Fix from $1,6002023-09-05 HIGH 7.5 CVE-2023-22862 IBM Aspera Connect 4.2.5 and IBM Aspera Cargo 4.2.5 transmits authentication credentials, but it uses an insecure method that is susceptible to unaut… Aspera Cargo 4.2.6+ Fix from $1,9502023-06-05 MEDIUM 5.5 CVE-2023-25686 IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 stores user credentials in plain clear text which can be read by a local … Security Key Lifecycle Manager Patch available Fix from $1,6002023-03-21 MEDIUM 6.5 CVE-2022-22458 IBM Security Verify Governance, Identity Manager 10.0.1 stores user credentials in plain clear text which can be read by a remote authenticated user.… Security Verify Governance Patch available Fix from $1,6002022-12-22 MEDIUM 5.5 CVE-2022-41732 IBM Maximo Mobile 8.7 and 8.8 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 237407. Maximo Application Suite Mitigation only Fix from $1,6002022-11-28 HIGH 7.5 CVE-2022-39168 IBM Robotic Process Automation Clients are vulnerable to proxy credentials being exposed in upgrade logs. IBM X-Force ID: 235422. Robotic Process Automation Patch available Fix from $1,9502022-09-29 MEDIUM 5.5 CVE-2021-39045 IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a local attacker to obtain information due to the autocomplete feature on password input … Cognos Analytics 11.1.7 / 11.2.3+ Fix from $1,6002022-09-01 MEDIUM 6.5 CVE-2022-33169 IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to insufficiently protected credentials for users created via a bulk upload. … Robotic Process Automation after 21.0.3 Fix from $1,6002022-08-01 HIGH 7.5 CVE-2022-22396 Credentials are printed in clear text in the IBM Spectrum Protect Plus 10.1.0.0 through 10.1.9.3 virgo log file in certain cases. Credentials could b… Spectrum Protect Plus 10.1.10+ Fix from $1,9502022-06-06 MEDIUM 5.5 CVE-2021-38976 IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 stores user credentials in plain clear text which can be read by a local user. X-Force ID: … Security Guardium Key Lifecycle Manager after 4.0.0.3 Fix from $1,6002021-11-15 MEDIUM 5.5 CVE-2021-38863 IBM Security Verify Bridge 1.0.5.0 stores user credentials in plain clear text which can be read by a locally authenticated user. IBM X-Force ID: 208… Security Verify Bridge 1.0.7+ Fix from $1,6002021-09-23