Vulnerability index

Browse CVEs

47 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
HIGH 7.8 CVE-2025-14604 IBM Storage Scale IBM S through rage Scale 5.2.3.0 - 5.2.3.5, and IBM S through rage Scale 6.0.0.0 - 6.0.0.1 could allow a local user to unintentiona… Storage Scale 5.2.3.6 / 6.0.0.2+ Fix from $1,9502026-03-03 HIGH 7.4 CVE-2025-33088 IBM Concert 1.0.0 through 2.1.0 could allow a local user with specific knowledge about the system's architecture to escalate their privileges due to … Concert 2.2.0+ Fix from $1,9502026-02-17 MEDIUM 6.7 CVE-2025-36193 IBM Transformation Advisor 2.0.1 through 4.3.1 incorrectly assigns privileges to security critical files which could allow a local root escalation in… Transformation Advisor 4.3.2+ Fix from $1,6002025-09-03 MEDIUM 6.5 CVE-2025-36104 IBM Storage Scale 5.2.3.0 and 5.2.3.1 could allow an authenticated user to obtain sensitive information from files due to the insecure permissions in… Storage Scale Mitigation only Fix from $1,6002025-07-12 MEDIUM 5.5 CVE-2024-45655 IBM Application Gateway 19.12 through 24.09 could allow a local privileged user to perform unauthorized actions due to incorrect permissions assignme… Application Gateway after 24.09 Fix from $1,6002025-06-03 MEDIUM 6.7 CVE-2024-45657 IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a local privileged user to perform unauthorized actions due to i… Security Verify Access 10.0.9.0+ Fix from $1,6002025-02-04 CRITICAL 9.1 CVE-2024-38337 IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow an unauthorized attacker to retrieve or alter sensitiv… Sterling Secure Proxy 6.0.3.1+ Fix from $2,3002025-01-19 MEDIUM 6.7 CVE-2024-51448 IBM Robotic Process Automation 21.0.0 through 21.0.7.17 and 23.0.0 through 23.0.18 could allow a local user to escalate their privileges. All files i… Robotic Process Automation after 23.0.18 Fix from $1,6002025-01-18 MEDIUM 6.8 CVE-2024-47104 IBM i 7.4 and 7.5 is vulnerable to an authenticated user gaining elevated privilege to a physical file. A user with authority to a view can alter the… I Mitigation only Fix from $1,6002024-12-18 HIGH 7.5 CVE-2022-43845 IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag.… Aspera Console 3.4.5+ Fix from $1,9502024-09-25 HIGH 8.1 CVE-2022-43915 IBM App Connect Enterprise Certified Container 5.0, 7.1, 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.… App Connect Enterprise Certified Container Mitigation only Fix from $1,9502024-08-24 HIGH 7.5 CVE-2022-33167 IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 could allow a remote attacker to obtain sensitive informa… Security Directory Integrator Mitigation only Fix from $1,9502024-07-30 HIGH 7.8 CVE-2023-47712 IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a local user to gain elevated privileges on the system due to improper permissions contr… Security Guardium Mitigation only Fix from $1,9502024-05-14 HIGH 8.1 CVE-2022-33163 IBM Security Directory Suite VA 8.0.1 specifies permissions for a security-critical resource in a way that allows that resource to be read or modifie… Security Directory Suite Va Patch available Fix from $1,9502023-06-15 HIGH 8.8 CVE-2023-28522 IBM API Connect V10 could allow an authenticated user to perform actions that they should not have access to. IBM X-Force ID: 250585. Api Connect 10.0.1.11 / 10.0.5.2+ Fix from $1,9502023-05-12 HIGH 7.8 CVE-2023-22592 IBM Robotic Process Automation for Cloud Pak 21.0.1 through 21.0.4 could allow a local user to perform unauthorized actions due to insufficient permi… Robotic Process Automation For Cloud Pak 21.0.5+ Fix from $1,9502023-01-18 MEDIUM 5.3 CVE-2022-22330 IBM Control Desk 7.6.1 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attack… Control Desk Mitigation only Fix from $1,6002022-09-13 MEDIUM 6.5 CVE-2022-22411 IBM Spectrum Scale Data Access Services (DAS) 5.1.3.1 could allow an authenticated user to insert code which could allow the attacker to manipulate c… Spectrum Scale Data Access Services Patch available Fix from $1,6002022-08-10 MEDIUM 5.3 CVE-2021-38879 IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to se… Jazz Team Server Patch available Fix from $1,6002022-06-24 MEDIUM 5.3 CVE-2021-20355 IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to se… Jazz Team Server Patch available Fix from $1,6002022-06-24 MEDIUM 5.3 CVE-2020-4146 IBM Security SiteProtector System 3.1.1 could allow a remote attacker to obtain sensitive information, caused by missing 'HttpOnly' flag. A remote at… Security Siteprotector System Mitigation only Fix from $1,6002021-11-12 MEDIUM 5.3 CVE-2021-20526 IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote at… Planning Analytics Patch available Fix from $1,6002021-10-27 HIGH 8.8 CVE-2021-20423 IBM Cloud Pak for Applications 4.3 could allow an authenticated user gain escalated privilesges due to improper application permissions. IBM X-Force … Cloud Pak For Applications 4.3.1+ Fix from $1,9502021-07-13 MEDIUM 5.3 CVE-2021-20416 IBM Guardium Data Encryption (GDE) 3.0.0.3 and 4.0.0.4 could allow a remote attacker to obtain sensitive information, caused by the failure to set th… Guardium Data Encryption Patch available Fix from $1,6002021-07-07 HIGH 8.1 CVE-2020-4945 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated user to overwrite arbirary files due to improper … Db2 Patch available Fix from $1,9502021-06-24 HIGH 8.1 CVE-2019-4702 IBM Security Guardium Data Encryption (GDE) 3.0.0.2 specifies permissions for a security-critical resource in a way that allows that resource to be r… Security Guardium Data Encryption Patch available Fix from $1,9502021-01-13 MEDIUM 5.3 CVE-2020-4625 IBM Cloud Pak for Security 1.3.0.1(CP4S) could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly fla… Cloud Pak For Security Patch available Fix from $1,6002020-11-30 MEDIUM 5.5 CVE-2020-4631 IBM Spectrum Protect Plus 10.1.0 through 10.1.6 agent files, in non-default configurations, on Windows are assigned access to everyone with full cont… Spectrum Protect Plus after 10.1.6 Fix from $1,6002020-08-04 HIGH 7.0 CVE-2020-4311 IBM Tivoli Monitoring 6.3.0 could allow a local attacker to execute arbitrary code on the system. By placing a specially crafted file, an attacker co… Tivoli Monitoring Patch available Fix from $1,9502020-04-23 HIGH 7.3 CVE-2020-4347 IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could be subject to attacks based on privilege escalation due to inappropriate file permission… Infosphere Information Server Mitigation only Fix from $1,9502020-04-16