Vulnerability index

Browse CVEs

56 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Partner Engagement Manager MEDIUM 5.4
CVE-2022-22416

IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to server-side request forgery (SSRF). This may allow an authen…

Fix: 6.1.2.5 / 6.2.0.3+
Fix from $1,600 2022-07-19
Planning Analytics HIGH 7.3
CVE-2022-22339

IBM Planning Analytics 2.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized request…

Patch available
Fix from $1,950 2022-04-08
Spectrum Copy Data Management MEDIUM 6.5
CVE-2021-39051

IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 is vulnerable to server-side request forgery, caused by improper input of application serv…

Fix: 2.2.15.0+
Fix from $1,600 2022-03-14
Spectrum Protect Plus HIGH 8.1
CVE-2021-39057

IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to …

Fix: 10.1.9+
Fix from $1,950 2021-12-13
Infosphere Information Server MEDIUM 5.4
CVE-2021-29738

IBM InfoSphere Data Flow Designer (IBM InfoSphere Information Server 11.7 ) is vulnerable to server-side request forgery (SSRF). This may allow an au…

Patch available
Fix from $1,600 2021-11-02
Engineering Lifecycle Optimization HIGH 8.8
CVE-2021-29844

IBM Jazz Team Server products is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requ…

Patch available
Fix from $1,950 2021-10-27
Engineering Lifecycle Optimization Engineering Insights MEDIUM 6.3
CVE-2020-4974

IBM Jazz Foundation products are vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requ…

No fix yet
Fix from $1,600 2021-07-28
Secure External Authentication Server MEDIUM 5.4
CVE-2021-29749

IBM Secure External Authentication Server 6.0.2 and IBM Secure Proxy 6.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an aut…

Patch available
Fix from $1,600 2021-07-15
Security Identity Manager MEDIUM 6.5
CVE-2021-20483

IBM Security Identity Manager 6.0.2 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, a remote authenticat…

Patch available
Fix from $1,600 2021-06-16
Collaborative Lifecycle Management MEDIUM 5.4
CVE-2021-20343

IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to se…

Patch available
Fix from $1,600 2021-06-02
Collaborative Lifecycle Management MEDIUM 5.4
CVE-2021-20345

IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to se…

Patch available
Fix from $1,600 2021-06-02
Collaborative Lifecycle Management MEDIUM 5.4
CVE-2021-20346

IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to se…

Patch available
Fix from $1,600 2021-06-02
Collaborative Lifecycle Management MEDIUM 5.4
CVE-2021-20347

IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to se…

Patch available
Fix from $1,600 2021-06-02
Collaborative Lifecycle Management MEDIUM 5.4
CVE-2021-20348

IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to se…

Patch available
Fix from $1,600 2021-06-02
Jazz Reporting Service MEDIUM 5.4
CVE-2021-20535

IBM Jazz Reporting Service 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attack…

Mitigation only
Fix from $1,600 2021-05-13
Websphere Application Server MEDIUM 6.5
CVE-2021-20480

IBM WebSphere Application Server 7.0, 8.0, and 8.5 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, a rem…

Fix: after 8.5.5.19
Fix from $1,600 2021-04-08
Planning Analytics MEDIUM 6.1
CVE-2020-4882

IBM Planning Analytics 2.0 could be vulnerable to a Server-Side Request Forgery (SSRF) attack by constucting URLs from user-controlled data . This co…

Mitigation only
Fix from $1,600 2021-03-22
Datapower Gateway MEDIUM 6.7
CVE-2020-5014

IBM DataPower Gateway V10 and V2018 could allow a local attacker with administrative privileges to execute arbitrary code on the system using a serve…

Fix: after 2018.4.1.14
Fix from $1,600 2021-03-08
Infosphere Metadata Asset Manager MEDIUM 6.5
CVE-2020-4632

IBM InfoSphere Metadata Asset Manager 11.7 is vulnerable to server-side request forgery. By sending a specially crafted request, a remote authenticat…

Mitigation only
Fix from $1,600 2020-09-04
Maximo Asset Management HIGH 7.4
CVE-2020-4529

IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send una…

Patch available
Fix from $1,950 2020-06-08
Qradar Security Information And Event Manager MEDIUM 6.3
CVE-2020-4294

IBM QRadar 7.3.0 to 7.3.3 Patch 2 is vulnerable to Server Side Request Forgery (SSRF). This may allow an authenticated attacker to send unauthorized …

Fix: 7.3.3+
Fix from $1,600 2020-04-15
Content Navigator MEDIUM 5.3
CVE-2019-4741

IBM Content Navigator 3.0CD is vulnerable to Server Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requ…

Mitigation only
Fix from $1,600 2020-02-12
Qradar Security Information And Event Manager MEDIUM 5.3
CVE-2019-4262

IBM QRadar SIEM 7.2 and 7.3 is vulnerable to Server Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requ…

Fix: 7.2.8 / 7.3.2+
Fix from $1,600 2019-09-26
Api Connect CRITICAL 9.8
CVE-2019-4203

IBM API Connect 5.0.0.0 and 5.0.8.6 Developer Portal can be exploited by app developers to download arbitrary files from the host OS and potentially …

Fix: after 5.0.8.6
Fix from $2,300 2019-04-15
Api Connect CRITICAL 9.9
CVE-2018-1789

IBM API Connect v2018.1.0 through v2018.3.4 could allow an attacker to send a specially crafted request to conduct a server side request forgery atta…

Fix: after 2018.3.4
Fix from $2,300 2018-09-07
Tealeaf Customer Experience MEDIUM 5.3
CVE-2016-5968

The Replay Server in IBM Tealeaf Customer Experience 8.x before 8.7.1.8847 FP10, 8.8.x before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, …

Fix: after 8.6
Fix from $1,600 2016-11-25