Vulnerability index

Browse CVEs

29 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
Security Verify Access HIGH 7.2
CVE-2026-12618

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 thr…

No fix yet
Fix from $4,900 2026-08-12
Db2 MEDIUM 6.5
CVE-2024-31882

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to a denial of service, under specific non default conf…

Fix: after 11.5.9
Fix from $1,600 2024-08-14
Operational Decision Manager CRITICAL 9.8
CVE-2024-22319EPSS 76%

IBM Operational Decision Manager 8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, 8.11.1 and 8.12.0.1 is susceptible to remote code execution attack via JND…

Patch available
Fix from $2,300 2024-02-02
Informix Jdbc CRITICAL 9.8
CVE-2023-35895

IBM Informix JDBC Driver 4.10 and 4.50 is susceptible to remote code execution attack via JNDI injection when passing an unchecked argument to a cert…

Mitigation only
Fix from $2,300 2023-12-20
Security Verify Access MEDIUM 6.5
CVE-2022-36775

IBM Security Verify Access 10.0.0.0, 10.0.1.0, 10.0.2.0, 10.0.3.0, and10.0.4.0 is vulnerable to HTTP header injection, caused by improper validation …

Patch available
Fix from $1,600 2023-02-17
Websphere Application Server MEDIUM 5.4
CVE-2022-34165

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.9 are vulnerable to HTTP…

Fix: 22.0.0.9+
Fix from $1,600 2022-09-09
Partner Engagement Manager HIGH 8.8
CVE-2022-22360

IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 could allow a remote authenticated attacker to conduct an LDAP injection. By …

Fix: 6.1.2.5 / 6.2.0.3+
Fix from $1,950 2022-07-19
Engineering Lifecycle Optimization Publishing MEDIUM 5.4
CVE-2021-39028

IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to HTTP header injection, caused by improper …

Patch available
Fix from $1,600 2022-07-14
Sevone Network Performance Management HIGH 8.8
CVE-2020-36531

A vulnerability, which was classified as critical, has been found in SevOne Network Management System up to 5.7.2.22. This issue affects the Device M…

Fix: after 5.7.2.22
Fix from $1,950 2022-06-07
Spectrum Copy Data Management MEDIUM 6.1
CVE-2022-22344

IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST…

Fix: 2.2.15.0+
Fix from $1,600 2022-03-14
Websphere Application Server HIGH 8.8
CVE-2021-39031

IBM WebSphere Application Server - Liberty 17.0.0.3 through 22.0.0.1 could allow a remote authenticated attacker to conduct an LDAP injection. By usi…

Fix: after 22.0.0.1
Fix from $1,950 2022-01-25
Planning Analytics HIGH 7.8
CVE-2021-38873

IBM Planning Analytics 2.0 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by im…

Patch available
Fix from $1,950 2021-11-24
Powervm Hypervisor MEDIUM 6.0
CVE-2021-29795

IBM PowerVM Hypervisor FW860, FW930, FW940, and FW950 could allow a local user to create a specially crafted sequence of hypervisor calls from a part…

Patch available
Fix from $1,600 2021-09-21
Maximo Asset Management CRITICAL 9.8
CVE-2021-20509

IBM Maximo Asset Management 7.6.0 and 7.6.1 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the sys…

Fix: 7.6.1.2+
Fix from $2,300 2021-08-12
Security Identity Manager Adapter HIGH 8.8
CVE-2021-20574

IBM Security Identity Manager Adapters 6.0 and 7.0 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially cra…

Patch available
Fix from $1,950 2021-06-28
Security Verify MEDIUM 5.4
CVE-2021-29676

IBM Security Verify (IBM Security Verify Privilege Vault 10.9.66) is vulnerable to link injection. By persuading a victim to click on a specially-cra…

Fix: 10.9.66+
Fix from $1,600 2021-06-25
Db2 HIGH 7.5
CVE-2021-29702

Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1.4 and 11.5.5 is vulnerable to a denial of service as the server terminates abnorma…

Fix: after 11.5.5.0
Fix from $1,950 2021-06-16
Spectrum Scale MEDIUM 5.5
CVE-2020-4851

IBM Spectrum Scale 5.0.0 through 5.0.5.5 and 5.1.0 through 5.1.0.2 could allow a local user to poison log files which could impact support and develo…

Fix: 5.0.5.5 / 5.1.0.2+
Fix from $1,600 2021-03-16
Spectrum Protect Plus MEDIUM 6.5
CVE-2020-5019

IBM Spectrum Protect Plus 10.1.0 through 10.1.6 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. B…

Fix: 10.1.7+
Fix from $1,600 2021-01-08
Cloud Orchestrator MEDIUM 5.4
CVE-2019-4396

IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 is vulnerable to HTTP response splitting attacks, caused by improper validation of…

Fix: after 2.5.0.9
Fix from $1,600 2019-10-25
Cloud Orchestrator MEDIUM 5.4
CVE-2019-4461

IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 is vulnerable to HTTP Response Splitting caused by improper caching of content. Th…

Fix: after 2.5.0.9
Fix from $1,600 2019-10-25
Spectrum Scale HIGH 7.8
CVE-2019-4558

A security vulnerability has been identified in all levels of IBM Spectrum Scale V5.0.0.0 through V5.0.3.2 and IBM Spectrum Scale V4.2.0.0 through V4…

Fix: after 5.0.3.2
Fix from $1,950 2019-10-09
Cloud Private MEDIUM 5.4
CVE-2018-1943

IBM Cloud Private 3.1.0 and 3.1.1 is vulnerable to HTTP HOST header injection, caused by improper validation of input. By persuading a victim to visi…

Patch available
Fix from $1,600 2019-04-08
Bigfix Compliance MEDIUM 5.4
CVE-2017-1202

IBM BigFix Compliance 1.7 through 1.9.91 (TEMA SUAv1 SCA SCM) is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, wh…

Fix: after 1.9.91
Fix from $1,600 2019-02-05
Connections MEDIUM 5.4
CVE-2018-1896

IBM Connections 5.0, 5.5, and 6.0 is vulnerable to possible host header injection attack that could cause navigation to the attacker's domain. IBM X-…

Patch available
Fix from $1,600 2018-12-07
Campaign MEDIUM 5.4
CVE-2017-1115

IBM Campaign 9.1, 9.1.2, and 10 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be exec…

Patch available
Fix from $1,600 2018-09-07
Rational Quality Manager MEDIUM 5.4
CVE-2018-1549

IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to HTTP response splitting attacks. A remote attacker could explo…

Fix: after 6.0.5
Fix from $1,600 2018-07-10
Tivoli Directory Server HIGH 7.8
CVE-2015-1975

The web administration tool in IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, and 6.3 before iFix 3…

Mitigation only
Fix from $1,950 2018-04-03
Sametime MEDIUM 6.3
CVE-2016-2980

The Sametime WebPlayer 8.5.2 and 9.0 is vulnerable to a script injection where a malicious site can inject their own script by exploiting a vulnerabi…

Patch available
Fix from $1,600 2017-08-29