Vulnerability index

Browse CVEs

18 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Websphere Application Server CRITICAL 9.8
CVE-2026-16184

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafted unauthenticated request.

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $2,300 2026-07-28
Engineering Requirements Management Doors Next MEDIUM 5.4
CVE-2025-13734

IBM Engineering Requirements Management DOORS Next 7.1, and 7.2 could allow an authenticated user to view and edit data beyond their authorized acces…

Mitigation only
Fix from $1,600 2026-03-03
Ds8a00 Firmware HIGH 7.1
CVE-2025-36192

IBM DS8A00( R10.1) 10.10.106.0 and IBM DS8A00 ( R10.0) 10.1.3.010.2.45.0 and IBM DS8900F ( R9.4) 89.40.83.089.42.18.089.44.5.0 IBM System Storage DS8…

Mitigation only
Fix from $1,950 2025-12-26
I HIGH 8.8
CVE-2025-36367

IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 is vulnerable to privilege escalation caused by an invalid IBM i SQL services authorization check. A malicious acto…

Mitigation only
Fix from $1,950 2025-11-01
App Connect Enterprise HIGH 8.8
CVE-2025-36361

IBM App Connect Enterprise 13.0.1.0 through 13.0.4.2, and 12.0.1.0 through 12.0.12.17 could allow an authenticated user to perform unauthorized actio…

Fix: after 13.0.4.2
Fix from $1,950 2025-10-24
Spectrum Protect Plus HIGH 7.5
CVE-2023-47148

IBM Storage Protect Plus Server 10.1.0 through 10.1.15.2 Admin Console could allow a remote attacker to obtain sensitive information due to improper …

Fix: 10.1.15.3+
Fix from $1,950 2024-02-02
Urbancode Deploy MEDIUM 6.5
CVE-2023-40376

IBM UrbanCode Deploy (UCD) 7.1 - 7.1.2.12, 7.2 through 7.2.3.5, and 7.3 through 7.3.2.0 under certain configurations could allow an authenticated use…

Fix: after 7.3.2.0
Fix from $1,600 2023-10-04
Content Navigator HIGH 8.8
CVE-2022-43581

IBM Content Navigator 3.0.0, 3.0.1, 3.0.2, 3.0.3, 3.0.4, 3.0.5, 3.0.6, 3.0.7, 3.0.8, 3.0.9, 3.0.10, 3.0.11, and 3.0.12 is vulnerable to missing autho…

Fix: after 3.0.12
Fix from $1,950 2022-12-07
Elastic Storage System CRITICAL 9.1
CVE-2020-4926

A vulnerability in the Spectrum Scale 5.1 core component and IBM Elastic Storage System 6.1 could allow unauthorized access to user data or injection…

Fix: 5.1.3.0 / 6.1.3.0+
Fix from $2,300 2022-05-24
Planning Analytics Cloud CRITICAL 9.1
CVE-2020-4669

IBM Planning Analytics Local 2.0 connects to a MongoDB server. MongoDB, a document-oriented database system, is listening on the remote port, and it …

Patch available
Fix from $2,300 2021-05-17
Cloud Pak For Security MEDIUM 5.9
CVE-2020-4816

IBM Cloud Pak for Security (CP4S) 1.4.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTT…

Patch available
Fix from $1,600 2021-01-27
Spectrum Protect Plus MEDIUM 5.3
CVE-2020-5022

IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may allow unauthenticated and unauthorized access to VDAP proxy which can result in an attacker obtai…

Fix: 10.1.7+
Fix from $1,600 2021-01-08
Security Secret Server MEDIUM 5.9
CVE-2020-4841

IBM Security Secret Server 10.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict T…

Patch available
Fix from $1,600 2020-12-21
Spectrum Protect Plus MEDIUM 5.9
CVE-2020-4783

IBM Spectrum Protect Plus 10.1.0 through 10.1.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enab…

Fix: after 10.1.6
Fix from $1,600 2020-11-23
Security Guardium Insights MEDIUM 5.9
CVE-2020-4175

IBM Security Guardium Insights 2.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Str…

Patch available
Fix from $1,600 2020-08-27
Security Secret Server MEDIUM 5.9
CVE-2020-4413

IBM Security Secret Server 10.7 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict T…

Fix: 10.8+
Fix from $1,600 2020-06-24
Spectrum Scale MEDIUM 6.5
CVE-2020-4348

IBM Spectrum Scale 4.2.0.0 through 4.2.3.21 and 5.0.0.0 through 5.0.4.4 could allow an authenticated GUI user to perform unauthorized actions due to …

Fix: after 5.0.4.4
Fix from $1,600 2020-05-27
Security Access Manager MEDIUM 5.4
CVE-2019-4158

IBM Security Access Manager 9.0.1 through 9.0.6 does not prove that a user's identity is correct which can lead to the exposure of resources or funct…

Fix: after 9.0.6
Fix from $1,600 2019-06-25