Vulnerability index

Browse CVEs

62 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
Storage Scale HIGH 7.5
CVE-2026-13460

IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 GUI contains a hardcoded token in the source code, which was used for inter-no…

No fix yet
Fix from $4,900 2026-08-13
I Access Client Solutions HIGH 7.1
CVE-2026-14866

IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to injection of rogue certificate authority due to publicly writeable truststore.

No fix yet
Fix from $4,900 2026-08-12
Storage Protect CRITICAL 9.1
CVE-2026-12628

IBM Storage Protect Client 8.1.0.0 through 8.2.1.0 and IBM Storage Protect Snapshot For Windows 8.1.0.0 through 8.2.1.0 could allow a remote attacker…

Fix: 8.2.1.1+
Fix from $2,300 2026-06-22
Controller HIGH 8.8
CVE-2026-5065

IBM Controller 11.0.1, 11.1.0, 11.1.1, and 11.1.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own…

Fix: 11.1.3+
Fix from $1,950 2026-05-27
Concert MEDIUM 5.5
CVE-2025-12708

IBM Concert 1.0.0 through 2.2.0 contains hard-coded credentials that could be obtained by a local user.

Fix: after 2.2.0
Fix from $1,600 2026-03-25
Websphere Application Server CRITICAL 9.8
CVE-2025-14923

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.2 IBM WebSphere Application Server Liberty could provide weaker than expected secu…

Fix: 26.0.0.3+
Fix from $2,300 2026-03-03
Concert CRITICAL 9.8
CVE-2025-33089

IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information or perform unauthorized actions due to the use of hard …

Fix: 2.2.0+
Fix from $2,300 2026-02-17
Security Verify Access CRITICAL 9.8
CVE-2025-36087

IBM Security Verify Access 10.0.0 through 10.0.9, 11.0.0, IBM Verify Identity Access Container 10.0.0 through 10.0.9, and 11.0.0, under certain confi…

Fix: after 10.0.9
Fix from $2,300 2025-10-13
Concert HIGH 7.5
CVE-2025-33100

IBM Concert Software 1.0.0 through 1.1.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inboun…

Fix: 2.0.0+
Fix from $1,950 2025-08-18
Cognos Controller HIGH 8.8
CVE-2024-52902

IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 client application contains hard coded database passwords in source code wh…

Fix: 11.0.1.4+
Fix from $1,950 2025-02-19
Cognos Controller MEDIUM 6.5
CVE-2024-28778

IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 is vulnerable to exposure of Artifactory API keys. This vulnerability allows us…

Fix: after 11.0.1
Fix from $1,600 2025-01-07
Cognos Controller HIGH 7.5
CVE-2024-41777

IBM Cognos Controller 11.0.0 and 11.0.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own…

Mitigation only
Fix from $1,950 2024-12-03
Security Verify Access CRITICAL 9.8
CVE-2024-49805

IBM Security Verify Access Appliance 10.0.0 through 10.0.8 contains hard-coded credentials, such as a password or cryptographic key, which it uses …

Fix: after 10.0.8
Fix from $2,300 2024-11-29
Security Verify Access CRITICAL 9.8
CVE-2024-49806

IBM Security Verify Access Appliance 10.0.0 through 10.0.8 contains hard-coded credentials, such as a password or cryptographic key, which it uses …

Fix: after 10.0.8
Fix from $2,300 2024-11-29
Power System E1080 \(9080 Hex\) Firmware CRITICAL 9.8
CVE-2024-45656

IBM Flexible Service Processor (FSP) FW860.00 through FW860.B3, FW950.00 through FW950.C0, FW1030.00 through FW1030.61, FW1050.00 through FW1050.21, …

Mitigation only
Fix from $2,300 2024-10-29
Security Verify Access HIGH 7.5
CVE-2024-31873

IBM Security Verify Access Appliance 10.0.0 through 10.0.7 contains hard-coded credentials which it uses for its own inbound authentication that coul…

Fix: after 10.0.7
Fix from $1,950 2024-04-10
Storage Defender Resiliency Service HIGH 7.8
CVE-2024-22313

IBM Storage Defender - Resiliency Service 2.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inb…

Patch available
Fix from $1,950 2024-02-10
Merge Efilm Workstation CRITICAL 9.8
CVE-2024-23619

A hardcoded credential vulnerability exists in IBM Merge Healthcare eFilm Workstation. A remote, unauthenticated attacker can exploit this vulnerabil…

Fix: after 4.2
Fix from $2,300 2024-01-26
Storage Fusion Hci CRITICAL 9.8
CVE-2023-50948

IBM Storage Fusion HCI 2.1.0 through 2.6.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inboun…

Fix: 2.7.1+
Fix from $2,300 2024-01-08
Security Guardium Key Lifecycle Manager HIGH 7.5
CVE-2023-47704

IBM Security Guardium Key Lifecycle Manager 4.3 contains plain text hard-coded credentials or other secrets in source code repository. IBM X-Force I…

Fix: 4.2.0.2+
Fix from $1,950 2023-12-20
Security Verify Governance CRITICAL 9.8
CVE-2022-22466

IBM Security Verify Governance 10.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authe…

Fix: 10.0.2+
Fix from $2,300 2023-10-23
Security Verify Governance CRITICAL 9.8
CVE-2023-33836

IBM Security Verify Governance 10.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authe…

Fix: 10.0.2+
Fix from $2,300 2023-10-16
Security Verify Information Queue HIGH 7.5
CVE-2022-35287

IBM Security Verify Information Queue 10.0.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbo…

Patch available
Fix from $1,950 2022-07-25
Qradar Network Security HIGH 7.5
CVE-2020-4157

IBM QRadar Network Security 5.4.0 and 5.5.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbou…

Patch available
Fix from $1,950 2022-07-12
Security Siteprotector System CRITICAL 9.8
CVE-2020-4150

IBM SiteProtector Appliance 3.1.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authent…

Mitigation only
Fix from $2,300 2022-07-11
Spectrum Virtualize CRITICAL 9.8
CVE-2021-38969

IBM Spectrum Virtualize 8.2, 8.3, and 8.4 could allow an attacker to allow unauthorized access due to the reuse of support generated credentials. IBM…

Mitigation only
Fix from $2,300 2022-05-11
Security Guardium CRITICAL 9.8
CVE-2020-4690

IBM Security Guardium 11.3 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication…

Patch available
Fix from $2,300 2021-09-23
Security Verify Access MEDIUM 6.5
CVE-2021-20537

IBM Security Verify Access Docker 10.0.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound …

Patch available
Fix from $1,600 2021-07-15
Security Guardium CRITICAL 9.8
CVE-2021-20426

IBM Security Guardium 11.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication…

Patch available
Fix from $2,300 2021-05-24
Security Identity Manager HIGH 7.5
CVE-2021-29691

IBM Security Identity Manager 7.0.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authe…

Patch available
Fix from $1,950 2021-05-20