Vulnerability index

Browse CVEs

28 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Sterling B2b Integrator HIGH 7.5
CVE-2025-14031

IBM Sterling B2B Integrator and and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.…

Fix: 6.1.2.8 / 6.2.0.5_2+
Fix from $1,950 2026-03-17
Sterling Secure Proxy CRITICAL 9.1
CVE-2024-41783

IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow a privileged user to inject commands into the underlyi…

Fix: 6.0.3.1+
Fix from $2,300 2025-01-19
Cloud Pak For Data HIGH 7.2
CVE-2022-36769

IBM Cloud Pak for Data 4.5 and 4.6 could allow a privileged user to upload malicious files of dangerous types that can be automatically processed wit…

Mitigation only
Fix from $1,950 2023-04-26
I Access Client Solutions MEDIUM 6.7
CVE-2022-40746

IBM i Access Family 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.0 could allow a local authenticated attacker to execute arbitrary code on the syste…

Fix: after 1.1.9.0
Fix from $1,600 2022-11-21
Infosphere Information Server CRITICAL 9.8
CVE-2022-40752

IBM InfoSphere DataStage 11.7 is vulnerable to a command injection vulnerability due to improper neutralization of special elements. IBM X-Force ID: …

Patch available
Fix from $2,300 2022-11-16
Sevone Network Performance Management HIGH 8.8
CVE-2020-36529

A vulnerability classified as critical has been found in SevOne Network Management System up to 5.7.2.22. This affects the file traceroute.php of the…

Fix: after 5.7.2.22
Fix from $1,950 2022-06-07
Resilient HIGH 7.2
CVE-2021-20527

IBM Resilient SOAR V38.0 could allow a privileged user to create create malicious scripts that could be executed as another user. IBM X-Force ID: 198…

Fix: 38.2.41 / 39.0.6536+
Fix from $1,950 2021-04-19
Security Guardium HIGH 7.8
CVE-2020-4688

IBM Security Guardium 10.6 and 11.2 could allow a local attacker to execute arbitrary commands on the system as an unprivileged user, caused by comma…

Mitigation only
Fix from $1,950 2021-01-20
Resilient Security Orchestration Automation And Response HIGH 7.2
CVE-2020-4636

IBM Resilient OnPrem 38.2 could allow a privileged user to inject malicious commands through Python3 scripting. IBM X-Force ID: 185503.

Mitigation only
Fix from $1,950 2020-10-16
Aspera Application Platform On Demand HIGH 7.5
CVE-2020-4432

Certain IBM Aspera applications are vulnerable to command injection after valid authentication, which could allow an attacker with intimate knowledge…

Fix: after 3.9.10
Fix from $1,950 2020-06-10
Rational Appscan Source CRITICAL 9.8
CVE-2014-6120EPSS 5%

IBM Rational AppScan Source 8.0 through 8.0.0.2 and 8.5 through 8.5.0.1 and Security AppScan Source 8.6 through 8.6.0.2, 8.7 through 8.7.0.1, 8.8, 9.…

Mitigation only
Fix from $2,300 2018-04-12
Notes MEDIUM 5.3
CVE-2017-1720

IBM Notes 8.5 and 9.0 could allow a local attacker to execute arbitrary commands by carefully crafting a command line sent via the shared memory IPC.…

Patch available
Fix from $1,600 2018-02-13
Security Identity Manager Virtual Appliance HIGH 8.8
CVE-2016-0324

IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows remote authenticated users to execu…

Patch available
Fix from $1,950 2018-01-12
Security Identity Governance And Intelligence HIGH 8.8
CVE-2017-1407

IBM Security Identity Manager Virtual Appliance 6.0 and 7.0 could allow a remote authenticated attacker to execute arbitrary commands on the system. …

Patch available
Fix from $1,950 2017-09-28
Maximo Asset Management MEDIUM 5.5
CVE-2017-1352

IBM Maximo Asset Management 7.5 and 7.6 could allow an authenticated user to inject commands into work orders that could be executed by another user …

Mitigation only
Fix from $1,600 2017-09-12
Curam Social Program Management HIGH 8.8
CVE-2014-8903

IBM Curam Social Program Management 6.0 SP2 before EP26, 6.0.4 before 6.0.4.5iFix10 and 6.0.5 before 6.0.5.6 allows remote authenticated users to loa…

Mitigation only
Fix from $1,950 2017-08-02
Bigfix Platform HIGH 8.1
CVE-2016-0396

IBM Tivoli Endpoint Manager could allow a user under special circumstances to inject commands that would be executed with unnecessary higher privileg…

Patch available
Fix from $1,950 2017-02-01
Security Guardium Database Activity Monitor HIGH 7.8
CVE-2016-0328

IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows local users to…

Patch available
Fix from $1,950 2016-10-22
Rational Collaborative Lifecycle Management HIGH 8.8
CVE-2016-0326

IBM Rational Quality Manager (RQM) and Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.x before 4.0.7 iFix11, 5.x before 5.0.2 iF…

Patch available
Fix from $1,950 2016-10-22
Security Guardium Database Activity Monitor HIGH 8.8
CVE-2016-0236

IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote authent…

Patch available
Fix from $1,950 2016-10-21
Qradar Security Information And Event Manager HIGH 8.8
CVE-2016-2875

IBM Security QRadar SIEM 7.1.x and 7.2.x before 7.2.7 allows remote authenticated users to execute arbitrary OS commands as root via unspecified vect…

Patch available
Fix from $1,950 2016-08-08
Tivoli Monitoring HIGH 8.5
CVE-2015-5003

The portal in IBM Tivoli Monitoring (ITM) 6.2.2 through FP9, 6.2.3 through FP5, and 6.3.0 before FP7 allows remote authenticated users to execute arb…

Mitigation only
Fix from $1,950 2016-01-03
General Parallel File System HIGH 7.2
CVE-2015-4974

IBM General Parallel File System (GPFS) 3.5.x before 3.5.0.27 and 4.1.x before 4.1.1.2 and Spectrum Scale 4.1.1.x before 4.1.1.2 allow local users to…

Patch available
Fix from $1,950 2015-10-26
Qradar Security Information And Event Manager HIGH 9.0
CVE-2015-4930

IBM QRadar SIEM 7.1 MR2 before Patch 11 IF02 and 7.2.x before 7.2.5 Patch 4 allows remote authenticated users to execute arbitrary commands with root…

Patch available
Fix from $1,950 2015-10-04
Qradar Security Information And Event Manager HIGH 9.0
CVE-2015-2011

The xmlrpc.cgi Webmin script in IBM QRadar SIEM 7.1 MR2 before Patch 11 IF02 and 7.2.x before 7.2.5 Patch 4 allows remote authenticated users to exec…

Patch available
Fix from $1,950 2015-10-04
Tivoli Storage Manager Fastback HIGH 10.0
CVE-2015-1986EPSS 8%

The server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to execute arbitrary commands via unspecified vectors, a …

Mitigation only
Fix from $1,950 2015-06-30
Tivoli Storage Manager Fastback HIGH 10.0
CVE-2015-1949EPSS 6%

The server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to execute arbitrary commands with SYSTEM privileges via …

Mitigation only
Fix from $1,950 2015-06-30
Tivoli Storage Manager Fastback HIGH 10.0
CVE-2015-1938EPSS 6%

The server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to execute arbitrary commands via unspecified vectors, a …

Mitigation only
Fix from $1,950 2015-06-30