Vulnerability index

Browse CVEs

138 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
I CRITICAL 9.8
CVE-2026-16961

IBM i 7.6, 7.5, and 7.4 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker …

No fix yet
Fix from $5,750 2026-08-13
I CRITICAL 9.8
CVE-2026-17111

IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the atta…

No fix yet
Fix from $5,750 2026-08-12
I HIGH 7.8
CVE-2026-17418

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to improper neutralization of special elemen…

Fix: after 7.6
Fix from $4,900 2026-08-12
I MEDIUM 6.5
CVE-2026-17419

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to modify SQL tables due to improper neutralization of special elements used…

Fix: after 7.6
Fix from $4,000 2026-08-12
Sterling B2b Integrator HIGH 8.1
CVE-2026-7769

IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0…

Fix: after 6.2.2.0_1
Fix from $1,950 2026-07-28
Api Connect CRITICAL 9.8
CVE-2026-9074

IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection vulnerability in the password reset…

Fix: 10.0.8.10 / 12.1.1.0+
Fix from $2,300 2026-07-08
App Connect Enterprise MEDIUM 5.5
CVE-2026-3602

IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.26 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 is v…

Fix: 12.0.12.27 / 13.0.8.0+
Fix from $1,600 2026-06-30
Watson Speech Services Cartridge MEDIUM 6.0
CVE-2026-7253

IBM Sterling B2B Integrator and IBM Sterling File Gateway are vulnerable to SQL injection. A privileged user could send specially crafted SQL stateme…

Fix: 5.3.1+
Fix from $1,600 2026-06-22
Cloud Pak For Data System Cyclops CRITICAL 9.8
CVE-2025-36220

IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System is vulnerable to SQL injection. A remote atta…

Fix: 11.3.0.2+
Fix from $2,300 2026-05-26
Storage Protect Server HIGH 8.8
CVE-2025-13855

IBM Storage Protect Server 8.2.0 IBM Storage Protect Plus Server is vulnerable to SQL injection. A remote attacker could send specially crafted SQL s…

Mitigation only
Fix from $1,950 2026-04-01
Sterling B2b Integrator HIGH 7.2
CVE-2025-36368

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, and 6.2.1.0 through 6.2.1.1_1 are vul…

Fix: 6.1.2.8 / 6.2.0.5_2+
Fix from $1,950 2026-03-13
Aspera Console HIGH 8.6
CVE-2025-13379

IBM Aspera Console 3.4.0 through 3.4.8 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could all…

Fix: after 3.4.8
Fix from $1,950 2026-02-05
Aspera Orchestrator HIGH 8.8
CVE-2025-13214

IBM Aspera Orchestrator 4.0.0 through 4.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which coul…

Fix: 4.1.1+
Fix from $1,950 2025-12-11
Watsonx Orchestrate Cartridge For Ibm Cloud Pak For Data CRITICAL 9.8
CVE-2025-0165

IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data 4.8.4, 4.8.5, and 5.0.0 through 5.2.0 is vulnerable to SQL injection. A remote attacker …

Fix: 5.2.0.1+
Fix from $2,300 2025-08-30
Infosphere Information Server HIGH 7.6
CVE-2025-0966

IBM InfoSphere Information Server 11.7 vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow …

Fix: 11.7.1+
Fix from $1,950 2025-06-25
Sterling B2b Integrator CRITICAL 9.8
CVE-2023-50316

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 is vulnerable to SQL injection. A remote attacker could send speciall…

Fix: after 6.2.0.1
Fix from $2,300 2025-01-28
Maximo Application Suite HIGH 8.8
CVE-2024-35148

IBM Maximo Application Suite 8.10.10, 8.11.7, and 9.0 - Monitor Component is vulnerable to SQL injection. A remote attacker could send specially craf…

Mitigation only
Fix from $1,950 2025-01-25
Engineering Lifecycle Optimization Publishing HIGH 7.3
CVE-2024-41767

IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 is vulnerable to SQL injection. A remote attacker could send specially crafted SQ…

Mitigation only
Fix from $1,950 2025-01-04
Storage Scale HIGH 7.5
CVE-2024-31892

IBM Storage Scale GUI 5.1.9.0 through 5.1.9.6 and 5.2.0.0 through 5.2.1.1 could allow a user to perform unauthorized actions after intercepting and m…

Fix: 5.1.9.7 / 5.2.2.0+
Fix from $1,950 2024-12-14
Concert CRITICAL 9.8
CVE-2024-52360

IBM Concert Software 1.0.0, 1.0.1, 1.0.2, and 1.0.2.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, …

Mitigation only
Fix from $2,300 2024-11-19
Infosphere Information Server CRITICAL 9.8
CVE-2024-40689

IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could all…

Mitigation only
Fix from $2,300 2024-07-26
Cognos Controller HIGH 7.2
CVE-2021-20451

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which…

Mitigation only
Fix from $1,950 2024-05-03
Cognos Controller CRITICAL 9.8
CVE-2023-38724

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which…

Mitigation only
Fix from $2,300 2024-05-03
Aspera Console CRITICAL 9.1
CVE-2022-43842

IBM Aspera Console 3.4.0 through 3.4.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could all…

Fix: 3.4.2+
Fix from $2,300 2024-02-23
Security Guardium MEDIUM 5.4
CVE-2023-33852

IBM Security Guardium 11.4 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attac…

Patch available
Fix from $1,600 2023-08-27
Infosphere Information Server CRITICAL 9.8
CVE-2022-47984

IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could all…

Patch available
Fix from $2,300 2023-05-19
I MEDIUM 6.4
CVE-2023-23470

IBM i 7.2, 7.3, 7.4, and 7.5 could allow an authenticated privileged administrator to gain elevated privileges in non-default configurations, as a re…

Mitigation only
Fix from $1,600 2023-05-04
Security Key Lifecycle Manager CRITICAL 9.8
CVE-2023-25684

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 is vulnerable to SQL injection. A remote attacker could send specially cr…

Patch available
Fix from $2,300 2023-03-21
Aspera Faspex HIGH 7.5
CVE-2023-27871

IBM Aspera Faspex 4.4.2 could allow a remote attacker to obtain sensitive credential information for an external user, using a specially crafted SQL …

Fix: after 4.4.2
Fix from $1,950 2023-03-21
Watson Knowledge Catalog On Cloud Pak For Data CRITICAL 9.8
CVE-2022-41731

IBM Watson Knowledge Catalog on Cloud Pak for Data 4.5.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statement…

Mitigation only
Fix from $2,300 2023-02-12