Vulnerability index

Browse CVEs

51 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
Cloud Pak For Data HIGH 7.5
CVE-2023-26026

Planning Analytics Cartridge for Cloud Pak for Data 4.0 exposes sensitive information in logs which could lead an attacker to exploit this vulnerabil…

Patch available
Fix from $1,950 2023-07-19
Maximo Application Suite MEDIUM 5.5
CVE-2022-43923

IBM Maximo Application Suite 8.8.0 and 8.9.0 stores potentially sensitive information that could be read by a local user. IBM X-Force ID: 241584.

Mitigation only
Fix from $1,600 2023-02-24
Spectrum Virtualize MEDIUM 6.5
CVE-2022-43870

IBM Spectrum Virtualize 8.3, 8.4, and 8.5 could disclose SNMPv3 server credentials to an authenticated user in log files. IBM X-Force ID: 239540.

Mitigation only
Fix from $1,600 2023-02-22
Db2 HIGH 7.5
CVE-2022-43930

IBM Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 is vulnerable to an Information Disclosure as sensitive information may be included in a log…

Patch available
Fix from $1,950 2023-02-17
Cognos Analytics MEDIUM 5.3
CVE-2022-43887

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could be vulnerable to sensitive information exposure by passing API keys to log files. If these keys…

Fix: 11.1.7+
Fix from $1,600 2022-12-19
Mq Internet Pass Thru MEDIUM 5.5
CVE-2022-35719

IBM MQ Internet Pass-Thru 2.1, 9.2 LTS and 9.2 CD stores potentially sensitive information in trace files that could be read by a local user.

Patch available
Fix from $1,600 2022-11-14
Qradar Security Information And Event Manager MEDIUM 5.3
CVE-2021-38939

IBM QRadar SIEM 7.3, 7.4, and 7.5 stores potentially sensitive information in log files that could be read by an user with access to creating domains…

Fix: 7.3.3 / 7.4.3+
Fix from $1,600 2022-04-27
Sterling Gentran MEDIUM 5.5
CVE-2021-39032

IBM Sterling Gentran:Server for Microsoft Windows 5.3 stores potentially sensitive information in log files that could be read by a local user. IBM X…

Patch available
Fix from $1,600 2022-01-14
Spectrum Protect Plus MEDIUM 6.2
CVE-2021-20536

IBM Spectrum Protect Plus File Systems Agent 10.1.6 and 10.1.7 stores potentially sensitive information in log files that could be read by a local us…

Mitigation only
Fix from $1,600 2021-04-26
Cloud Pak For Automation MEDIUM 6.5
CVE-2021-20359

IBM Cloud Pak for Automation 20.0.3, 20.0.2-IF002 - Business Automation Application Designer Component stores potentially sensitive information in lo…

Mitigation only
Fix from $1,600 2021-02-08
Business Automation Workflow MEDIUM 5.5
CVE-2020-4900

IBM Business Automation Workflow 19.0.0.3 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 1…

Patch available
Fix from $1,600 2020-11-30
Sterling B2b Integrator MEDIUM 6.5
CVE-2020-4671

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 stores potentially sensitive information in log file…

Fix: after 6.0.3.2
Fix from $1,600 2020-11-16
Spectrum Protect Plus MEDIUM 6.5
CVE-2020-4477

IBM Spectrum Protect Plus 10.1.0 through 10.1.5 discloses highly sensitive information in plain text in the virgo log file which could be used in fur…

Fix: after 10.1.5
Fix from $1,600 2020-06-15
Robotic Process Automation With Automation Anywhere MEDIUM 5.5
CVE-2019-4299

IBM Robotic Process Automation with Automation Anywhere 11 could allow a local user to obtain highly sensitive information from log files when debugg…

Fix: 11.0.0.5+
Fix from $1,600 2019-07-01
Cloud Private MEDIUM 5.5
CVE-2019-4143

The IBM Cloud Private Key Management Service (IBM Cloud Private 3.1.1 and 3.1.2) could allow a local user to obtain sensitive from the KMS plugin con…

Mitigation only
Fix from $1,600 2019-04-08
Api Connect CRITICAL 9.8
CVE-2019-4008

API Connect V2018.1 through 2018.4.1.1 is impacted by access token leak. Authorization tokens in some URLs can result in the tokens being written to …

Fix: after 2018.4.1.1
Fix from $2,300 2019-02-07
Bigfix Compliance MEDIUM 5.3
CVE-2017-1198

IBM BigFix Compliance 1.7 through 1.9.91 (TEMA SUAv1 SCA SCM) stores sensitive information in URL parameters. This may lead to information disclosure…

Fix: after 1.9.91
Fix from $1,600 2019-02-05
Robotic Process Automation With Automation Anywhere MEDIUM 5.5
CVE-2018-1876

IBM Robotic Process Automation with Automation Anywhere 11 could under certain cases, display the password in a Control Room log file after installat…

Patch available
Fix from $1,600 2018-11-02
Spectrum Protect Plus HIGH 7.8
CVE-2018-1768

IBM Spectrum Protect Plus 10.1.0 and 10.1.1 could disclose sensitive information when an authorized user executes a test operation, the user id an pa…

Patch available
Fix from $1,950 2018-09-26
Cognos Business Intelligence MEDIUM 5.5
CVE-2016-9985

IBM Cognos Server 10.1.1 and 10.2 stores highly sensitive information in log files that could be read by a local user. IBM Reference #: 1999671.

Patch available
Fix from $1,600 2017-03-08
Rational Asset Analyzer MEDIUM 5.5
CVE-2016-5967

The installation component in IBM Rational Asset Analyzer (RAA) 6.1.0 before FP10 allows local users to discover the WAS Admin password by reading IM…

Mitigation only
Fix from $1,600 2016-11-25