Vulnerability index

Browse CVEs

58 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Txseries For Multiplatforms HIGH 7.5
CVE-2024-41743

IBM TXSeries for Multiplatforms 10.1 could allow a remote attacker to cause a denial of service using persistent connections due to improper allocati…

Mitigation only
Fix from $1,950 2025-01-19
Safer Payments HIGH 7.5
CVE-2024-45662

IBM Safer Payments 6.4.0.00 through 6.4.2.07, 6.5.0.00 through 6.5.0.05, and 6.6.0.00 through 6.6.0.03 could allow a remote attacker to cause a denia…

Fix: 6.4.2.08 / 6.5.0.06+
Fix from $1,950 2025-01-18
App Connect Enterprise Certified Container MEDIUM 5.5
CVE-2022-22491

IBM App Connect Enterprise Certified Container 7.1, 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12…

Fix: after 12.4
Fix from $1,600 2025-01-09
Db2 MEDIUM 6.5
CVE-2023-30443

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted qu…

Mitigation only
Fix from $1,600 2024-12-19
Db2 MEDIUM 6.5
CVE-2024-41762

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may crash u…

Fix: after 11.5.9
Fix from $1,600 2024-12-07
Db2 MEDIUM 5.3
CVE-2024-41761

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may crash u…

Mitigation only
Fix from $1,600 2024-11-23
Db2 MEDIUM 6.5
CVE-2024-31880

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service, under specific configura…

Fix: after 11.5.9
Fix from $1,600 2024-10-23
Mq Operator MEDIUM 5.5
CVE-2024-40680

IBM MQ 9.3 CD and 9.4 LTS/CD could allow a local user to cause a denial of service due to improper memory allocation causing a segmentation fault.

Mitigation only
Fix from $1,600 2024-09-07
Mq HIGH 7.5
CVE-2024-35116

IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS, and 9.3 CD is vulnerable to a denial of service attack caused by an error applying configuration changes. …

Fix: 9.0.0.26 / 9.1.0.22+
Fix from $1,950 2024-06-28
Mq HIGH 7.5
CVE-2024-31919

IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS and 9.3 CD, in certain configurations, is vulnerable to a denial of service attack caused by an error proce…

Mitigation only
Fix from $1,950 2024-06-28
Db2 MEDIUM 6.5
CVE-2024-31881

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may crash w…

Mitigation only
Fix from $1,600 2024-06-12
Db2 MEDIUM 6.5
CVE-2024-28762

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted qu…

Mitigation only
Fix from $1,600 2024-06-12
Websphere Application Server HIGH 7.5
CVE-2024-25026

IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.4 are vulnerable to a denial of servic…

Fix: after 24.0.0.4
Fix from $1,950 2024-04-25
Websphere Application Server HIGH 7.5
CVE-2024-27268

IBM WebSphere Application Server Liberty 18.0.0.2 through 24.0.0.4 is vulnerable to a denial of service, caused by sending a specially crafted reques…

Fix: 24.0.0.5+
Fix from $1,950 2024-04-04
Websphere Application Server HIGH 7.5
CVE-2024-22353

IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.4 is vulnerable to a denial of service, caused by sending a specially crafted reques…

Fix: after 24.0.0.3
Fix from $1,950 2024-03-31
Db2 MEDIUM 6.5
CVE-2023-47746

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow an authenticated user with CONNECT privileges to c…

Fix: after 11.5.9
Fix from $1,600 2024-01-22
Cloud Pak For Data HIGH 7.5
CVE-2023-27540

IBM Watson CP4D Data Stores 4.6.0 does not properly allocate resources without limits or throttling which could allow a remote attacker with informat…

Mitigation only
Fix from $1,950 2023-07-10
Mq Appliance MEDIUM 5.9
CVE-2023-26285

IBM MQ 9.2 CD, 9.2 LTS, 9.3 CD, and 9.3 LTS could allow a remote attacker to cause a denial of service due to an error processing invalid data. IBM …

Fix: 9.2.0.11 / 9.2.5.7+
Fix from $1,600 2023-05-05
Safer Payments HIGH 7.5
CVE-2023-27556

IBM Counter Fraud Management for Safer Payments 6.1.0.00, 6.2.0.00, 6.3.0.00 through 6.3.1.03, 6.4.0.00 through 6.4.2.02 and 6.5.0.00 does not proper…

Fix: 6.3.1.04 / 6.4.2.03+
Fix from $1,950 2023-04-28
Cics Tx MEDIUM 5.5
CVE-2022-34308

IBM CICS TX 11.1 could allow a local user to cause a denial of service due to improper load handling. IBM X-Force ID: 229437.

Patch available
Fix from $1,600 2022-10-07
App Connect Enterprise Certified Container MEDIUM 6.5
CVE-2022-22404

IBM App Connect Enterprise Certified Container Dashboard UI (IBM App Connect Enterprise Certified Container 1.5, 2.0, 2.1, 3.0, and 3.1) may be vulne…

Fix: 4.0.0+
Fix from $1,600 2022-04-01
Db2 MEDIUM 5.1
CVE-2021-29763

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 under very specific conditions, could allow a local user to keep runn…

Mitigation only
Fix from $1,600 2021-09-16
Secure External Authentication Server HIGH 7.5
CVE-2021-29725

IBM Secure External Authentication Server 2.4.3.2, 6.0.1, 6.0.2 and IBM Secure Proxy 3.4.3.2, 6.0.1, 6.0.2 could allow a remote user to consume resou…

Patch available
Fix from $1,950 2021-07-15
Websphere Application Server HIGH 7.5
CVE-2019-4720

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote…

Fix: 20.0.0.2+
Fix from $1,950 2020-01-31
Security Guardium Big Data Intelligence HIGH 7.5
CVE-2019-4338

IBM Security Guardium Big Data Intelligence 4.0 (SonarG) does not properly restrict the size or amount of resources that are requested or influenced …

Mitigation only
Fix from $1,950 2019-08-20
Api Connect HIGH 7.5
CVE-2018-1779

IBM API Connect 2018.1 through 2018.3.7 could allow an unauthenticated attacker to cause a denial of service due to not setting limits on JSON payloa…

Fix: after 2018.3.7
Fix from $1,950 2018-11-20
Qradar Incident Forensics HIGH 7.5
CVE-2018-1647

IBM QRadar Incident Forensics 7.2 and 7.3 does not properly restrict the size or amount of resources requested which could allow an unauthenticated u…

Fix: after 7.3.1
Fix from $1,950 2018-10-05
Bigfix Platform HIGH 7.5
CVE-2017-1227

IBM Tivoli Endpoint Manager could allow a unauthorized user to consume all resources and crash the system. IBM X-Force ID: 123906.

Patch available
Fix from $1,950 2017-07-31