Vulnerability index

Browse CVEs

41 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Security Verify Access MEDIUM 6.5
CVE-2026-4938

IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 thr…

Fix: after 11.0.2.0
Fix from $1,600 2026-07-17
Engineering Lifecycle Management CRITICAL 9.8
CVE-2026-3660

IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an unauthenticated remote attacker to update server property files that woul…

Mitigation only
Fix from $2,300 2026-05-26
Engineering Requirements Management Doors Next MEDIUM 5.4
CVE-2025-13734

IBM Engineering Requirements Management DOORS Next 7.1, and 7.2 could allow an authenticated user to view and edit data beyond their authorized acces…

Mitigation only
Fix from $1,600 2026-03-03
Jazz Foundation MEDIUM 5.4
CVE-2025-15395

IBM Jazz Foundation 7.0.3 through 7.0.3 iFix019 and 7.1.0 through 7.1.0 iFix005 is vulnerable to access control violations that allows the users to v…

Mitigation only
Fix from $1,600 2026-02-02
Jazz Foundation CRITICAL 9.1
CVE-2025-36157

IBM Jazz Foundation 7.0.2 to 7.0.2 iFix035, 7.0.3 to 7.0.3 iFix018, and 7.1.0 to 7.1.0 iFix004 could allow an unauthenticated remote attacker to upda…

Patch available
Fix from $2,300 2025-08-24
Storage Virtualize HIGH 8.8
CVE-2025-36120

IBM Storage Virtualize 8.4, 8.5, 8.6, and 8.7 could allow an authenticated user to escalate their privileges in an SSH session due to incorrect autho…

Fix: 8.4.0.18 / 8.5.0.16+
Fix from $1,950 2025-08-18
Sterling Connect Direct Web Services MEDIUM 6.5
CVE-2024-49808

IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 could allow an authenticated user to spoof the identity of another user due to impro…

Fix: 6.1.0.28 / 6.2.0.27+
Fix from $1,600 2025-04-18
Cognos Controller MEDIUM 6.5
CVE-2024-45081

IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 could allow an authenticated user to modify restricted content due to i…

Fix: 11.0.1.4+
Fix from $1,600 2025-02-19
Common Licensing MEDIUM 6.5
CVE-2023-50946

IBM Common Licensing 9.0 could allow an authenticated user to modify a configuration file that they should not have access to due to a broken author…

Mitigation only
Fix from $1,600 2025-01-26
Vios MEDIUM 5.5
CVE-2024-47102

IBM AIX 7.2, 7.3, VIOS 3.1, and 4.1 could allow a non-privileged local user to exploit a vulnerability in the AIX perfstat kernel extension to cause…

Mitigation only
Fix from $1,600 2024-12-25
Security Access Manager MEDIUM 5.5
CVE-2023-38368

IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could disclose sensitive information to a local user to do improper permission controls.…

Fix: after 10.0.7.1
Fix from $1,600 2024-06-27
Storage Protect For Virtual Environments HIGH 7.7
CVE-2024-38329

IBM Storage Protect for Virtual Environments: Data Protection for VMware 8.1.0.0 through 8.1.22.0 could allow a remote authenticated attacker to bypa…

Fix: 8.1.23.0+
Fix from $1,950 2024-06-19
Cp4ba Filenet Content Manager HIGH 8.8
CVE-2023-47716

IBM CP4BA - Filenet Content Manager Component 5.5.8.0, 5.5.10.0, and 5.5.11.0 could allow a user to gain the privileges of another user under unusual…

Mitigation only
Fix from $1,950 2024-03-01
Tivoli Application Dependency Discovery Manager HIGH 8.8
CVE-2023-47142

IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 could allow an attacker on the organization's local network to escalate …

Fix: after 7.3.0.10
Fix from $1,950 2024-02-02
I Access Client Solutions HIGH 8.8
CVE-2023-45185

IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 could allow an attacker to execute remote code. Due to improper author…

Fix: 1.1.9.4+
Fix from $1,950 2023-12-14
I MEDIUM 5.5
CVE-2023-42006

IBM Administration Runtime Expert for i 7.2, 7.3, 7.4, and 7.5 could allow a local user to obtain sensitive information caused by improper authority …

Mitigation only
Fix from $1,600 2023-12-01
Aspera Faspex HIGH 7.5
CVE-2023-30995

IBM Aspera Faspex 4.0 through 4.4.2 and 5.0 through 5.0.5 could allow a malicious actor to bypass IP whitelist restrictions using a specially crafted…

Fix: after 5.0.5
Fix from $1,950 2023-09-08
Robotic Process Automation MEDIUM 6.5
CVE-2023-23476

IBM Robotic Process Automation 21.0.0 through 21.0.7.latest is vulnerable to unauthorized access to data due to insufficient authorization validation…

Fix: 23.0.0+
Fix from $1,600 2023-08-02
Robotic Process Automation HIGH 7.8
CVE-2023-22593

IBM Robotic Process Automation for Cloud Pak 21.0.1 through 21.0.7.3 and 23.0.0 through 23.0.3 is vulnerable to security misconfiguration of the Redi…

Fix: after 23.0.3
Fix from $1,950 2023-06-27
Security Guardium HIGH 7.8
CVE-2022-22307

IBM Security Guardium 11.3, 11.4, and 11.5 could allow a local user to obtain elevated privileges due to incorrect authorization checks. IBM X-Force…

Patch available
Fix from $1,950 2023-06-15
Security Key Lifecycle Manager HIGH 8.8
CVE-2023-25924

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an authenticated user to perform actions that they should not…

Patch available
Fix from $1,950 2023-03-22
Security Key Lifecycle Manager HIGH 7.5
CVE-2023-25923

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an attacker to upload files that could be used in a denial of…

Patch available
Fix from $1,950 2023-03-21
Financial Transaction Manager MEDIUM 5.3
CVE-2022-43872

IBM Financial Transaction Manager 3.2.4 authorization checks are done incorrectly for some HTTP requests which allows getting unauthorized technical …

Patch available
Fix from $1,600 2022-12-20
Urbancode Deploy MEDIUM 6.5
CVE-2022-35716

IBM UrbanCode Deploy (UCD) 6.2.0.0 through 6.2.7.16, 7.0.0.0 through 7.0.5.11, 7.1.0.0 through 7.1.2.7, and 7.2.0.0 through 7.2.3.0 could allow an au…

Fix: 6.2.7.17 / 7.0.5.12+
Fix from $1,600 2022-08-01
Cognos Controller CRITICAL 9.8
CVE-2020-4877

IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could be vulnerable to unauthorized modifications by using public fields in public classes. IBM X-Fo…

Mitigation only
Fix from $2,300 2022-01-21
Db2 HIGH 8.7
CVE-2021-29678

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a user with DBADM authority to access o…

Mitigation only
Fix from $1,950 2021-12-09
Qradar User Behavior Analytics MEDIUM 5.3
CVE-2021-20429

IBM QRadar User Behavior Analytics 1.0.0 through 4.1.0 could disclose sensitive information due an overly permissive cross-domain policy. IBM X-Force…

Fix: 4.1.1+
Fix from $1,600 2021-05-14
Cloud Pak For Security CRITICAL 9.1
CVE-2021-20538

IBM Cloud Pak for Security (CP4S) 1.5.0.0 and 1.5.0.1 could allow a user to obtain sensitive information or perform actions they should not have acce…

Mitigation only
Fix from $2,300 2021-05-10
Planning Analytics MEDIUM 5.3
CVE-2020-4873

IBM Planning Analytics 2.0 could allow an attacker to obtain sensitive information due to an overly permissive CORS policy. IBM X-Force ID: 190836.

Patch available
Fix from $1,600 2021-01-19
Automation Workstream Services MEDIUM 5.4
CVE-2020-4794

IBM Automation Workstream Services 19.0.3, 20.0.1, 20.0.2, IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.6…

Patch available
Fix from $1,600 2020-12-21