Vulnerability index

Browse CVEs

47 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
Storage Scale HIGH 7.8
CVE-2025-14604

IBM Storage Scale IBM S through rage Scale 5.2.3.0 - 5.2.3.5, and IBM S through rage Scale 6.0.0.0 - 6.0.0.1 could allow a local user to unintentiona…

Fix: 5.2.3.6 / 6.0.0.2+
Fix from $1,950 2026-03-03
Concert HIGH 7.4
CVE-2025-33088

IBM Concert 1.0.0 through 2.1.0 could allow a local user with specific knowledge about the system's architecture to escalate their privileges due to …

Fix: 2.2.0+
Fix from $1,950 2026-02-17
Transformation Advisor MEDIUM 6.7
CVE-2025-36193

IBM Transformation Advisor 2.0.1 through 4.3.1 incorrectly assigns privileges to security critical files which could allow a local root escalation in…

Fix: 4.3.2+
Fix from $1,600 2025-09-03
Storage Scale MEDIUM 6.5
CVE-2025-36104

IBM Storage Scale 5.2.3.0 and 5.2.3.1 could allow an authenticated user to obtain sensitive information from files due to the insecure permissions in…

Mitigation only
Fix from $1,600 2025-07-12
Application Gateway MEDIUM 5.5
CVE-2024-45655

IBM Application Gateway 19.12 through 24.09 could allow a local privileged user to perform unauthorized actions due to incorrect permissions assignme…

Fix: after 24.09
Fix from $1,600 2025-06-03
Security Verify Access MEDIUM 6.7
CVE-2024-45657

IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a local privileged user to perform unauthorized actions due to i…

Fix: 10.0.9.0+
Fix from $1,600 2025-02-04
Sterling Secure Proxy CRITICAL 9.1
CVE-2024-38337

IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow an unauthorized attacker to retrieve or alter sensitiv…

Fix: 6.0.3.1+
Fix from $2,300 2025-01-19
Robotic Process Automation MEDIUM 6.7
CVE-2024-51448

IBM Robotic Process Automation 21.0.0 through 21.0.7.17 and 23.0.0 through 23.0.18 could allow a local user to escalate their privileges. All files i…

Fix: after 23.0.18
Fix from $1,600 2025-01-18
I MEDIUM 6.8
CVE-2024-47104

IBM i 7.4 and 7.5 is vulnerable to an authenticated user gaining elevated privilege to a physical file. A user with authority to a view can alter the…

Mitigation only
Fix from $1,600 2024-12-18
Aspera Console HIGH 7.5
CVE-2022-43845

IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag.…

Fix: 3.4.5+
Fix from $1,950 2024-09-25
App Connect Enterprise Certified Container HIGH 8.1
CVE-2022-43915

IBM App Connect Enterprise Certified Container 5.0, 7.1, 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.…

Mitigation only
Fix from $1,950 2024-08-24
Security Directory Integrator HIGH 7.5
CVE-2022-33167

IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 could allow a remote attacker to obtain sensitive informa…

Mitigation only
Fix from $1,950 2024-07-30
Security Guardium HIGH 7.8
CVE-2023-47712

IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a local user to gain elevated privileges on the system due to improper permissions contr…

Mitigation only
Fix from $1,950 2024-05-14
Security Directory Suite Va HIGH 8.1
CVE-2022-33163

IBM Security Directory Suite VA 8.0.1 specifies permissions for a security-critical resource in a way that allows that resource to be read or modifie…

Patch available
Fix from $1,950 2023-06-15
Api Connect HIGH 8.8
CVE-2023-28522

IBM API Connect V10 could allow an authenticated user to perform actions that they should not have access to. IBM X-Force ID: 250585.

Fix: 10.0.1.11 / 10.0.5.2+
Fix from $1,950 2023-05-12
Robotic Process Automation For Cloud Pak HIGH 7.8
CVE-2023-22592

IBM Robotic Process Automation for Cloud Pak 21.0.1 through 21.0.4 could allow a local user to perform unauthorized actions due to insufficient permi…

Fix: 21.0.5+
Fix from $1,950 2023-01-18
Control Desk MEDIUM 5.3
CVE-2022-22330

IBM Control Desk 7.6.1 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attack…

Mitigation only
Fix from $1,600 2022-09-13
Spectrum Scale Data Access Services MEDIUM 6.5
CVE-2022-22411

IBM Spectrum Scale Data Access Services (DAS) 5.1.3.1 could allow an authenticated user to insert code which could allow the attacker to manipulate c…

Patch available
Fix from $1,600 2022-08-10
Jazz Team Server MEDIUM 5.3
CVE-2021-38879

IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to se…

Patch available
Fix from $1,600 2022-06-24
Jazz Team Server MEDIUM 5.3
CVE-2021-20355

IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to se…

Patch available
Fix from $1,600 2022-06-24
Security Siteprotector System MEDIUM 5.3
CVE-2020-4146

IBM Security SiteProtector System 3.1.1 could allow a remote attacker to obtain sensitive information, caused by missing 'HttpOnly' flag. A remote at…

Mitigation only
Fix from $1,600 2021-11-12
Planning Analytics MEDIUM 5.3
CVE-2021-20526

IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote at…

Patch available
Fix from $1,600 2021-10-27
Cloud Pak For Applications HIGH 8.8
CVE-2021-20423

IBM Cloud Pak for Applications 4.3 could allow an authenticated user gain escalated privilesges due to improper application permissions. IBM X-Force …

Fix: 4.3.1+
Fix from $1,950 2021-07-13
Guardium Data Encryption MEDIUM 5.3
CVE-2021-20416

IBM Guardium Data Encryption (GDE) 3.0.0.3 and 4.0.0.4 could allow a remote attacker to obtain sensitive information, caused by the failure to set th…

Patch available
Fix from $1,600 2021-07-07
Db2 HIGH 8.1
CVE-2020-4945

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated user to overwrite arbirary files due to improper …

Patch available
Fix from $1,950 2021-06-24
Security Guardium Data Encryption HIGH 8.1
CVE-2019-4702

IBM Security Guardium Data Encryption (GDE) 3.0.0.2 specifies permissions for a security-critical resource in a way that allows that resource to be r…

Patch available
Fix from $1,950 2021-01-13
Cloud Pak For Security MEDIUM 5.3
CVE-2020-4625

IBM Cloud Pak for Security 1.3.0.1(CP4S) could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly fla…

Patch available
Fix from $1,600 2020-11-30
Spectrum Protect Plus MEDIUM 5.5
CVE-2020-4631

IBM Spectrum Protect Plus 10.1.0 through 10.1.6 agent files, in non-default configurations, on Windows are assigned access to everyone with full cont…

Fix: after 10.1.6
Fix from $1,600 2020-08-04
Tivoli Monitoring HIGH 7.0
CVE-2020-4311

IBM Tivoli Monitoring 6.3.0 could allow a local attacker to execute arbitrary code on the system. By placing a specially crafted file, an attacker co…

Patch available
Fix from $1,950 2020-04-23
Infosphere Information Server HIGH 7.3
CVE-2020-4347

IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could be subject to attacks based on privilege escalation due to inappropriate file permission…

Mitigation only
Fix from $1,950 2020-04-16