Vulnerability index

Browse CVEs

91 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Security Directory Integrator HIGH 8.8
CVE-2024-28767

IBM Security Directory Integrator 7.2.0 through 7.2.0.13 and 10.0.0 through 10.0.3 could allow a remote authenticated attacker to execute arbitrary c…

Fix: after 10.0.3
Fix from $1,950 2024-12-20
Vios HIGH 7.8
CVE-2024-47115

IBM AIX 7.2, 7.3 and VIOS 3.1 and 4.1 could allow a local user to execute arbitrary commands on the system due to improper neutralization of input.

Mitigation only
Fix from $1,950 2024-12-07
App Connect Enterprise Certified Container HIGH 8.8
CVE-2024-51465

IBM App Connect Enterprise Certified Container 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, and 12.3 could allow a remote authenticated attacker to execute ar…

Fix: 12.4+
Fix from $1,950 2024-12-04
Security Verify Access HIGH 8.8
CVE-2024-49803

IBM Security Verify Access Appliance 10.0.0 through 10.0.8 could allow a remote authenticated attacker to execute arbitrary commands on the system by…

Fix: after 10.0.8
Fix from $1,950 2024-11-29
Security Guardium HIGH 8.8
CVE-2023-47709

IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a…

Mitigation only
Fix from $1,950 2024-05-14
Aspera Orchestrator HIGH 8.8
CVE-2023-37407

IBM Aspera Orchestrator 4.0.1 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted …

Mitigation only
Fix from $1,950 2024-05-03
Security Guardium Key Lifecycle Manager HIGH 8.8
CVE-2023-25925

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow a remote authenticated attacker to execute arbitrary commands…

Fix: 4.1.1.7+
Fix from $1,950 2024-02-28
Informix Jdbc CRITICAL 9.8
CVE-2023-35895

IBM Informix JDBC Driver 4.10 and 4.50 is susceptible to remote code execution attack via JNDI injection when passing an unchecked argument to a cert…

Mitigation only
Fix from $2,300 2023-12-20
Security Verify Governance HIGH 8.8
CVE-2023-33839

IBM Security Verify Governance 10.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially cr…

Patch available
Fix from $1,950 2023-10-23
Security Guardium HIGH 8.8
CVE-2022-43907

IBM Security Guardium 11.4 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted req…

Patch available
Fix from $1,950 2023-08-27
Security Guardium HIGH 8.8
CVE-2023-35893

IBM Security Guardium 10.6, 11.3, 11.4, and 11.5 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a…

Patch available
Fix from $1,950 2023-08-16
Security Verify Governance HIGH 8.8
CVE-2023-35019

IBM Security Verify Governance, Identity Manager 10.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by send…

Mitigation only
Fix from $1,950 2023-07-31
Security Directory Suite Va HIGH 8.8
CVE-2022-32752

IBM Security Directory Suite VA 8.0.1 through 8.0.1.19 could allow a remote authenticated attacker to execute arbitrary commands on the system by sen…

Fix: after 8.0.1.19
Fix from $1,950 2023-06-15
3957 Vec Firmware HIGH 8.8
CVE-2023-24958

A vulnerability in the IBM TS7700 Management Interface 8.51.2.12, 8.52.200.111, 8.52.102.13, and 8.53.0.63 could allow an authenticated user to submi…

Fix: 8.51.2.12 / 8.52.102.13+
Fix from $1,950 2023-05-04
Vios HIGH 7.8
CVE-2023-28528

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the invscout command to execute arbitrary c…

Patch available
Fix from $1,950 2023-04-28
Spectrum Scale Container Native Storage Access HIGH 7.8
CVE-2022-43867

IBM Spectrum Scale 5.1.0.1 through 5.1.4.1 could allow a local attacker to execute arbitrary commands in the container. IBM X-Force ID: 239437.

Fix: after 5.1.4.1
Fix from $1,950 2022-12-06
Cloud Pak For Security HIGH 8.8
CVE-2022-38387

IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.2.0 could allow a remote authenticated attacker to execute arbitrary commands on the system b…

Fix: after 1.10.2.0
Fix from $1,950 2022-11-11
Infosphere Information Server HIGH 7.8
CVE-2022-35717

"IBM InfoSphere Information Server 11.7 could allow a locally authenticated attacker to execute arbitrary commands on the system by sending a special…

Patch available
Fix from $1,950 2022-11-03
Infosphere Information Server MEDIUM 5.4
CVE-2022-35642

"IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in …

Patch available
Fix from $1,600 2022-11-03
Cics Tx MEDIUM 6.8
CVE-2022-33955

IBM CICS TX 11.1 could allow allow an attacker with physical access to the system to execute code due using a back and refresh attack. IBM X-Force ID…

Patch available
Fix from $1,600 2022-08-01
Cics Tx CRITICAL 9.8
CVE-2022-31767EPSS 5%

IBM CICS TX Standard and Advanced 11.1 could allow a remote attacker to execute arbitrary commands on the system by sending a specially crafted reque…

Fix: 11.1+
Fix from $2,300 2022-06-24
Infosphere Information Server On Cloud HIGH 7.8
CVE-2022-22454

IBM InfoSphere Information Server 11.7 could allow a locally authenticated attacker to execute arbitrary commands on the system by sending a speciall…

Patch available
Fix from $1,950 2022-05-10
Filenet Content Manager HIGH 8.8
CVE-2021-38965

IBM FileNet Content Manager 5.5.4, 5.5.6, and 5.5.7 could allow a remote authenticated attacker to execute arbitrary commands on the system by sendin…

Patch available
Fix from $1,950 2022-01-17
Spectrum Copy Data Management CRITICAL 9.8
CVE-2021-39065

IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to execute arbitrary commands on the system, caused by improper va…

Fix: after 2.2.13
Fix from $2,300 2021-12-13
System X3550 M3 Firmware HIGH 8.8
CVE-2021-3723

A command injection vulnerability was reported in the Integrated Management Module (IMM) of legacy IBM System x 3550 M3 and IBM System x 3650 M3 serv…

Mitigation only
Fix from $1,950 2021-11-12
Security Guardium HIGH 7.2
CVE-2021-20557

IBM Security Guardium 11.2 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted req…

Patch available
Fix from $1,950 2021-05-24
Qradar Security Information And Event Manager HIGH 7.2
CVE-2020-4512

IBM QRadar SIEM 7.3 and 7.4 could allow a remote privileged user to execute commands.

Fix: after 7.3.2
Fix from $1,950 2020-07-14
Spectrum Protect Plus CRITICAL 9.8
CVE-2020-4469EPSS 13%

IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted H…

Fix: after 10.1.5
Fix from $2,300 2020-06-15
Security Guardium HIGH 8.8
CVE-2020-4180

IBM Security Guardium 11.1 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted re…

Patch available
Fix from $1,950 2020-06-03
Data Risk Manager CRITICAL 9.1
CVE-2020-4428 KEVEPSS 62%

IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary commands on the system. IBM X-F…

Fix: after 2.0.4
Fix from $2,300 2020-05-07