Vulnerability index

Browse CVEs

138 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Emptoris Contract Management CRITICAL 9.8
CVE-2019-4483

IBM Contract Management 10.1.0 through 10.1.3 and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 is vulnerable to SQL injection. A remote attacker…

Fix: after 10.1.3
Fix from $2,300 2019-08-20
Emptoris Contract Management CRITICAL 9.8
CVE-2019-4481

IBM Contract Management 10.1.0 through 10.1.3 and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 is vulnerable to SQL injection. A remote attacker…

Fix: after 10.1.3
Fix from $2,300 2019-08-20
Pureapplication System HIGH 8.8
CVE-2019-4224

IBM PureApplication System 2.2.3.0 through 2.2.5.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, whi…

Fix: after 2.2.5.3
Fix from $1,950 2019-06-26
Bigfix Webui Profile Management CRITICAL 9.8
CVE-2019-4012

IBM BigFix WebUI Profile Management 6 and Software Distribution 23 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL…

Mitigation only
Fix from $2,300 2019-04-15
Infosphere Information Server On Cloud CRITICAL 9.8
CVE-2018-1994

IBM InfoSphere Information Server 11.5 and 11.7 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which …

Patch available
Fix from $2,300 2019-04-10
Financial Transaction Manager CRITICAL 9.8
CVE-2019-4032

IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.1.0 is vulnerable to SQL injection. A remote attacker could send speciall…

Fix: after 3.1.0.3
Fix from $2,300 2019-03-05
Financial Transaction Manager HIGH 8.8
CVE-2018-1819

IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.0.2, 3.0.4, 3.0.6, and 3.2.0 is vulnerable to SQL injection. A remote att…

Patch available
Fix from $1,950 2018-10-04
Business Automation Workflow HIGH 8.8
CVE-2018-1674

IBM Business Process Manager 8.5 through 8.6 and 18.0.0.0 through 18.0.0.1 are vulnerable to SQL injection. A remote attacker could send specially-cr…

Fix: after 8.5.0.2
Fix from $1,950 2018-09-20
Security Identity Governance And Intelligence HIGH 7.5
CVE-2018-1756EPSS 11%

IBM Security Identity Governance and Intelligence 5.2.3.2 and 5.2.4 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQ…

Patch available
Fix from $1,950 2018-09-07
Maximo Asset Management HIGH 8.8
CVE-2018-1699

IBM Maximo Asset Management 7.6 through 7.6.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which co…

Fix: after 7.6.3
Fix from $1,950 2018-08-24
Infosphere Data Replication Dashboard CRITICAL 9.8
CVE-2013-3000

SQL injection vulnerability in IBM InfoSphere Data Replication Dashboard 9.7 and 10.1 allows remote attackers to execute arbitrary SQL commands via u…

Mitigation only
Fix from $2,300 2018-07-09
Qradar Security Information And Event Manager MEDIUM 6.3
CVE-2017-1722

IBM Security QRadar SIEM 7.2 and 7.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow…

Fix: 7.2.8+
Fix from $1,600 2018-04-26
Maximo Asset Management HIGH 8.8
CVE-2018-1414

IBM Maximo Asset Management 7.5 and 7.6 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could al…

Patch available
Fix from $1,950 2018-02-22
Security Key Lifecycle Manager CRITICAL 9.8
CVE-2017-1670

IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, whi…

Patch available
Fix from $2,300 2018-01-09
Security Guardium HIGH 8.8
CVE-2017-1757

IBM Security Guardium 10.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attac…

Mitigation only
Fix from $1,950 2017-12-20
Financial Transaction Manager HIGH 8.8
CVE-2017-1606

IBM Financial Transaction Manager (FTM) for Multi-Platform (MP) 3.0.0.0 through 3.0.0.7 is vulnerable to SQL injection. A remote attacker could send …

Mitigation only
Fix from $1,950 2017-12-11
Atlas Ediscovery Process Management HIGH 8.8
CVE-2017-1356

IBM Atlas eDiscovery Process Management 6.0.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which co…

Mitigation only
Fix from $1,950 2017-12-07
Insights Foundation For Energy HIGH 8.8
CVE-2017-1311

IBM Insights Foundation for Energy 2.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could all…

Mitigation only
Fix from $1,950 2017-10-03
Sterling B2b Integrator HIGH 8.8
CVE-2017-1174

IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which…

Mitigation only
Fix from $1,950 2017-08-10
Tivoli Monitoring HIGH 7.5
CVE-2017-1183

IBM Tivoli Monitoring Portal v6 could allow a local (network adjacent) attacker to modify SQL commands to the Portal Server, when default client-serv…

Patch available
Fix from $1,950 2017-07-17
Maximo Asset Management CRITICAL 9.8
CVE-2017-1175

IBM Maximo Asset Management 7.1, 7.5, and 7.6 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which co…

Mitigation only
Fix from $2,300 2017-07-05
Security Guardium CRITICAL 9.8
CVE-2017-1269

IBM Security Guardium 10.0 and 10.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow …

Mitigation only
Fix from $2,300 2017-07-05
Sterling B2b Integrator HIGH 8.8
CVE-2017-1347

IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which…

Patch available
Fix from $1,950 2017-06-23
Qradar Security Information And Event Manager HIGH 7.5
CVE-2016-9728

IBM Qradar 7.2 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view,…

Patch available
Fix from $1,950 2017-03-07
Kenexa Lcms Premier HIGH 7.1
CVE-2016-9992

IBM Kenexa LCMS Premier on Cloud 9.0, and 10.0.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which…

Patch available
Fix from $1,950 2017-03-01
Kenexa Lcms Premier HIGH 7.1
CVE-2016-9993

IBM Kenexa LCMS Premier on Cloud 9.0, and 10.0.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which…

Patch available
Fix from $1,950 2017-03-01
Kenexa Lcms Premier HIGH 7.1
CVE-2016-9994

IBM Kenexa LCMS Premier on Cloud 9.0, and 10.0.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which…

Patch available
Fix from $1,950 2017-03-01
Kenexa Lms HIGH 7.6
CVE-2016-8928

IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker…

Patch available
Fix from $1,950 2017-02-01
Kenexa Lms HIGH 7.6
CVE-2016-8930

IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker…

Patch available
Fix from $1,950 2017-02-01
Kenexa Lms MEDIUM 5.4
CVE-2016-8929

IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker…

Patch available
Fix from $1,600 2017-02-01