Vulnerability index

Browse CVEs

91 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Strongloop Nginx Controller CRITICAL 9.8
CVE-2020-7621

strong-nginx-controller through 1.0.2 is vulnerable to Command Injection. It allows execution of arbitrary command as part of the '_nginxCmd()' funct…

Fix: after 1.0.2
Fix from $2,300 2020-04-02
Spectrum Protect Plus HIGH 8.8
CVE-2020-4241EPSS 66%

IBM Spectrum Scale and IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote authenticated attacker to execute arbitrary commands on t…

Fix: after 10.1.5
Fix from $1,950 2020-03-31
Spectrum Protect Plus HIGH 8.8
CVE-2020-4242

IBM Spectrum Scale and IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote authenticated attacker to execute arbitrary commands on t…

Fix: after 10.1.5
Fix from $1,950 2020-03-31
Spectrum Protect Plus HIGH 8.8
CVE-2020-4206

IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to execute arbitrary commands on the system in the context of root user…

Fix: after 10.1.5
Fix from $1,950 2020-03-31
Spectrum Protect CRITICAL 9.8
CVE-2020-4210EPSS 15%

IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP …

Fix: 10.1.5+
Fix from $2,300 2020-02-24
Spectrum Protect CRITICAL 9.8
CVE-2020-4211EPSS 71%

IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP …

Fix: 10.1.5+
Fix from $2,300 2020-02-24
Spectrum Protect CRITICAL 9.8
CVE-2020-4213EPSS 15%

IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP …

Fix: 10.1.5+
Fix from $2,300 2020-02-24
Spectrum Protect CRITICAL 9.8
CVE-2020-4222EPSS 15%

IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP …

Fix: 10.1.5+
Fix from $2,300 2020-02-24
Sterling External Authentication Server HIGH 7.8
CVE-2013-0517

A Command Execution Vulnerability exists in IBM Sterling External Authentication Server 2.2.0, 2.3.01, 2.4.0, and 2.4.1 via an unspecified OS command…

Mitigation only
Fix from $1,950 2020-02-11
Spectrum Scale HIGH 8.8
CVE-2019-4715

IBM Spectrum Scale 4.2 and 5.0 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafte…

Fix: after 5.0.4.0
Fix from $1,950 2019-12-11
Datapower Gateway HIGH 7.8
CVE-2019-4294

IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.6, 7.6.0.0 through 7.6.0.15 and IBM MQ Appliance 8.0.0.0 through 8.0.0.12, 9.1.0.0 through 9.1.0.2,…

Fix: 2018.4.1.7+
Fix from $1,950 2019-08-20
Api Connect CRITICAL 10.0
CVE-2019-4202

IBM API Connect 5.0.0.0 and 5.0.8.6 Developer Portal is vulnerable to command injection. An attacker with a specially crafted request can run arbitra…

Fix: after 5.0.8.6
Fix from $2,300 2019-04-15
Websphere Mq HIGH 7.8
CVE-2018-1998

IBM WebSphere MQ 8.0.0.0 through 9.1.1 could allow a local user to inject code that could be executed with root privileges. This is due to an incompl…

Fix: after 9.1.0.1
Fix from $1,950 2019-03-11
Bigfix Platform HIGH 8.8
CVE-2016-0291

IBM BigFix Platform 9.0, 9.1 before 9.1.8, and 9.2 before 9.2.8 allow remote authenticated users to execute arbitrary commands by leveraging report s…

Fix: 9.1.8 / 9.2.8+
Fix from $1,950 2018-02-28
Security Access Manager 9.0 Firmware HIGH 8.8
CVE-2017-1453

IBM Security Access Manager Appliance 9.0.3 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a spe…

Mitigation only
Fix from $1,950 2017-11-13
Mq Appliance HIGH 8.8
CVE-2017-1318

IBM MQ Appliance 8.0 and 9.0 could allow an authenticated messaging administrator to execute arbitrary commands on the system, caused by command exec…

Mitigation only
Fix from $1,950 2017-07-18
Security Guardium CRITICAL 9.9
CVE-2017-1253

IBM Security Guardium 10.0 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted re…

Mitigation only
Fix from $2,300 2017-07-05
Security Guardium HIGH 7.8
CVE-2016-6065

IBM Security Guardium Database Activity Monitor appliance could allow a local user to inject commands that would be executed as root.

Patch available
Fix from $1,950 2017-02-01
Qradar Security Information And Event Manager HIGH 7.5
CVE-2016-2876

IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 executes unspecified processes at an incorrect privilege level, which makes it easier fo…

Fix: after 7.1.0
Fix from $1,950 2016-11-30
Security Access Manager CRITICAL 9.1
CVE-2016-3028

IBM Security Access Manager for Web 7.0 before IF2 and 8.0 before 8.0.1.4 IF3 and Security Access Manager 9.0 before 9.0.1.0 IF5 allow remote authent…

Mitigation only
Fix from $2,300 2016-11-25
Rational Team Concert MEDIUM 6.3
CVE-2016-0325

IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; R…

Mitigation only
Fix from $1,600 2016-11-24
Qradar Security Information And Event Manager HIGH 7.4
CVE-2015-4956

The Web UI in IBM Security QRadar SIEM 7.1.x before 7.1 MR2 Patch 12 allows remote authenticated users to execute unspecified OS commands via unknown…

Mitigation only
Fix from $1,950 2016-02-15
Spectrum Protect For Virtual Environments CRITICAL 10.0
CVE-2015-7426

The Data Protection extension in the VMware GUI in IBM Tivoli Storage Manager for Virtual Environments: Data Protection for VMware (aka Spectrum Prot…

Mitigation only
Fix from $2,300 2016-01-02
Security Access Manager 9.0 Firmware HIGH 8.0
CVE-2015-5018

IBM Security Access Manager for Web 7.0.0 before FP19 and 8.0 before 8.0.1.3 IF3, and Security Access Manager 9.0 before 9.0.0.0 IF1, allows remote a…

Mitigation only
Fix from $1,950 2016-01-02
Security Access Manager For Web 7.0 Firmware HIGH 10.0
CVE-2014-4823

The administration console in IBM Security Access Manager for Web 7.x before 7.0.0-ISS-WGA-IF0009 and 8.x before 8.0.0-ISS-WGA-FP0005, and Security A…

Patch available
Fix from $1,950 2014-10-03
Global Console Manager 16 Firmware HIGH 7.1
CVE-2014-3085EPSS 8%

systest.php on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allows remote authenticated users to execute ar…

Fix: after 1.20.0.22575
Fix from $1,950 2014-08-17
Lotus Protector For Mail Security HIGH 7.1
CVE-2014-0886

The Admin Web UI in IBM Lotus Protector for Mail Security 2.8.x before 2.8.1-22905 allows remote authenticated users to bypass intended access restri…

Mitigation only
Fix from $1,950 2014-03-25
Lotus Protector For Mail Security HIGH 7.1
CVE-2014-0887

The Admin Web UI in IBM Lotus Protector for Mail Security 2.8.x before 2.8.1-22905 allows remote authenticated users to execute arbitrary commands wi…

Mitigation only
Fix from $1,950 2014-03-25
Tealeaf Cx MEDIUM 6.0
CVE-2013-6719EPSS 27%

delivery.php in the Passive Capture Application (PCA) web console in IBM Tealeaf CX 7.x, 8.x through 8.6, 8.7 before FP2, and 8.8 before FP2 allows r…

No fix yet
Fix from $1,600 2014-03-06
Tivoli Storage Manager Fastback HIGH 10.0
CVE-2010-3754

The FXCLI_OraBR_Exec_Command function in FastBackServer.exe in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.…

Mitigation only
Fix from $1,950 2010-10-05