Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.5
CVE-2025-36440
IBM Concert 1.0.0 through 2.2.0 could allow a local user to obtain sensitive information due to missing function level access control.
Concert
after 2.2.0
MEDIUM 6.5
CVE-2025-14790
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an attacker to obtain sensitive information due to insufficiently protected c…
Infosphere Information Server
after 11.7.1.6
MEDIUM 6.5
CVE-2025-14148
IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.3 could allow an authenticated user with LLM integration configuration privileges to recover a previous…
Devops Deploy
8.1.2.4+
HIGH 8.1
CVE-2025-36096
IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 stores NIM private keys used in NIM environments in an insecure way which is susceptible to unauthoriz…
Vios
Mitigation only
MEDIUM 6.5
CVE-2025-33079
IBM Controller 11.0.0, 11.0.1, and 11.1.0 application could allow an authenticated user to obtain sensitive credentials that may be inadvertently inc…
Cognos Controller
Mitigation only
HIGH 7.5
CVE-2025-33093
IBM Sterling Partner Engagement Manager 6.1.0, 6.2.0, 6.2.2 JWT secret is stored in public Helm Charts and is not stored as a Kubernetes secret.
Sterling Partner Engagement Manager
Mitigation only
MEDIUM 5.3
CVE-2024-47109
IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 UI could disclosure the installation path of the server which could aid…
Sterling File Gateway
6.1.2.7 / 6.2.0.4+
HIGH 7.5
CVE-2024-41771
IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7.1 could allow a remote attacker to download temporary files which could expose…
Engineering Requirements Management Doors Next
Mitigation only
HIGH 7.5
CVE-2024-41770
IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7.1 could allow a remote attacker to download temporary files which could expose…
Engineering Requirements Management Doors Next
Mitigation only
MEDIUM 5.5
CVE-2023-50945
IBM Common Licensing 9.0 stores user credentials in plain clear text which can be read by a local user.
Common Licensing
Mitigation only
HIGH 7.5
CVE-2023-50310
IBM CICS Transaction Gateway for Multiplatforms 9.2 and 9.3 transmits or stores authentication credentials, but it uses an insecure method that is su…
Cics Transaction Gateway
Mitigation only
MEDIUM 5.5
CVE-2024-40703
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and IBM Cognos Analytics Reports for iOS 11.0.0.7 could …
Cognos Analytics
12.0.3+
MEDIUM 5.5
CVE-2024-39733
IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 stores user credentials in plain clear text which can be read by a local user. IBM X-For…
Datacap
Mitigation only
HIGH 7.5
CVE-2024-22345
IBM TXSeries for Multiplatforms 8.2 transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorize…
Txseries For Multiplatform
Mitigation only
HIGH 7.8
CVE-2023-37400
IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to escalate their privileges due to insecure credential storage. IBM X-Force ID: 259…
Aspera Faspex
5.0.8+
MEDIUM 5.5
CVE-2021-38938
IBM Host Access Transformation Services (HATS) 9.6 through 9.6.1.4 and 9.7 through 9.7.0.3 stores user credentials in plain clear text which can be r…
Host Access Transformation Services
after 9.7.0.3
MEDIUM 5.5
CVE-2024-22312
IBM Storage Defender - Resiliency Service 2.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 278748.
Storage Defender Resiliency Service
Patch available
MEDIUM 5.3
CVE-2023-47741
IBM i 7.3, 7.4, 7.5, IBM i Db2 Mirror for i 7.4 and 7.5 web browser clients may leave clear-text passwords in browser memory that can be viewed using…
Db2 Mirror For I
Patch available
MEDIUM 5.5
CVE-2023-47722
IBM API Connect V10.0.5.3 and V10.0.6.0 stores user credentials in browser cache which can be read by a local user. IBM X-Force ID: 271912.
Api Connect
Mitigation only
MEDIUM 5.5
CVE-2023-32338
IBM Sterling Secure Proxy and IBM Sterling External Authentication Server 6.0.3 and 6.1.0 stores user credentials in plain clear text which can be re…
Sterling External Authentication Server
Mitigation only
HIGH 7.5
CVE-2023-22862
IBM Aspera Connect 4.2.5 and IBM Aspera Cargo 4.2.5 transmits authentication credentials, but it uses an insecure method that is susceptible to unaut…
Aspera Cargo
4.2.6+
MEDIUM 5.5
CVE-2023-25686
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 stores user credentials in plain clear text which can be read by a local …
Security Key Lifecycle Manager
Patch available
MEDIUM 6.5
CVE-2022-22458
IBM Security Verify Governance, Identity Manager 10.0.1 stores user credentials in plain clear text which can be read by a remote authenticated user.…
Security Verify Governance
Patch available
MEDIUM 5.5
CVE-2022-41732
IBM Maximo Mobile 8.7 and 8.8 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 237407.
Maximo Application Suite
Mitigation only
HIGH 7.5
CVE-2022-39168
IBM Robotic Process Automation Clients are vulnerable to proxy credentials being exposed in upgrade logs. IBM X-Force ID: 235422.
Robotic Process Automation
Patch available
MEDIUM 5.5
CVE-2021-39045
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a local attacker to obtain information due to the autocomplete feature on password input …
Cognos Analytics
11.1.7 / 11.2.3+
MEDIUM 6.5
CVE-2022-33169
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to insufficiently protected credentials for users created via a bulk upload. …
Robotic Process Automation
after 21.0.3
HIGH 7.5
CVE-2022-22396
Credentials are printed in clear text in the IBM Spectrum Protect Plus 10.1.0.0 through 10.1.9.3 virgo log file in certain cases. Credentials could b…
Spectrum Protect Plus
10.1.10+
MEDIUM 5.5
CVE-2021-38976
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 stores user credentials in plain clear text which can be read by a local user. X-Force ID: …
Security Guardium Key Lifecycle Manager
after 4.0.0.3
MEDIUM 5.5
CVE-2021-38863
IBM Security Verify Bridge 1.0.5.0 stores user credentials in plain clear text which can be read by a locally authenticated user. IBM X-Force ID: 208…
Security Verify Bridge
1.0.7+