Vulnerability index

Browse CVEs

41 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Data Risk Manager HIGH 8.8
CVE-2020-4621

IBM Data Risk Manager (iDNA) 2.0.6 could allow an authenticated user to escalate their privileges to administrator due to insufficient authorization …

Fix: 2.0.6.4+
Fix from $1,950 2020-09-22
Security Identity Governance And Intelligence MEDIUM 6.5
CVE-2020-4249

IBM Security Identity Governance and Intelligence 5.2.6 could disclose highly sensitive information to other authenticated users on the sytem due to …

Patch available
Fix from $1,600 2020-05-28
Cognos Analytics MEDIUM 6.5
CVE-2019-4343

IBM Cognos Analytics 11.0 and 11.1 allows overly permissive cross-origin resource sharing which could allow an attacker to transfer private informati…

Mitigation only
Fix from $1,600 2019-12-30
Security Guardium Big Data Intelligence MEDIUM 5.3
CVE-2019-4311

IBM Security Guardium Big Data Intelligence (SonarG) 4.0 discloses sensitive information to unauthorized users. The information can be used to mount …

Patch available
Fix from $1,600 2019-10-29
Storwize V7000 Firmware HIGH 7.6
CVE-2018-1462

IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6…

Fix: 7.5.0.14 / 7.7.1.9+
Fix from $1,950 2018-05-17
Storwize V7000 Firmware MEDIUM 6.5
CVE-2018-1463

IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6…

Fix: 7.5.0.14 / 7.7.1.9+
Fix from $1,600 2018-05-17
Rational Collaborative Lifecycle Management MEDIUM 6.5
CVE-2017-1700

IBM Jazz Team Server affecting the following IBM Rational Products: Collaborative Lifecycle Management (CLM), Rational DOORS Next Generation (RDNG), …

Fix: after 6.0.5
Fix from $1,600 2018-04-24
Bigfix Remote Control MEDIUM 6.7
CVE-2017-1233

IBM Remote Control v9 could allow a local user to use the component to replace files to which he does not have write access and which he can cause to…

Patch available
Fix from $1,600 2018-01-31
Business Process Manager MEDIUM 6.5
CVE-2017-1628

IBM Business Process Manager 8.6.0.0 allows authenticated users to stop and resume the Event Manager by calling a REST API with incorrect authorizati…

Mitigation only
Fix from $1,600 2017-11-27
Websphere Application Server MEDIUM 6.8
CVE-2013-0543

IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2 on Linux, Solaris, and HP…

Mitigation only
Fix from $1,600 2013-04-24
Rational System Architect HIGH 9.3
CVE-2011-1207EPSS 5%

The ActiveBar1 ActiveX control in the Data Dynamics ActiveBar ActiveX controls, as distributed in ActBar.ocx 1.0.6.5 in IBM Rational System Architect…

Fix: after 11.4.0.2
Fix from $1,950 2011-05-05