Vulnerability index

Browse CVEs

56 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
MEDIUM 5.4 CVE-2022-22416 IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to server-side request forgery (SSRF). This may allow an authen… Partner Engagement Manager 6.1.2.5 / 6.2.0.3+ Fix from $1,6002022-07-19 HIGH 7.3 CVE-2022-22339 IBM Planning Analytics 2.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized request… Planning Analytics Patch available Fix from $1,9502022-04-08 MEDIUM 6.5 CVE-2021-39051 IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 is vulnerable to server-side request forgery, caused by improper input of application serv… Spectrum Copy Data Management 2.2.15.0+ Fix from $1,6002022-03-14 HIGH 8.1 CVE-2021-39057 IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to … Spectrum Protect Plus 10.1.9+ Fix from $1,9502021-12-13 MEDIUM 5.4 CVE-2021-29738 IBM InfoSphere Data Flow Designer (IBM InfoSphere Information Server 11.7 ) is vulnerable to server-side request forgery (SSRF). This may allow an au… Infosphere Information Server Patch available Fix from $1,6002021-11-02 HIGH 8.8 CVE-2021-29844 IBM Jazz Team Server products is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requ… Engineering Lifecycle Optimization Patch available Fix from $1,9502021-10-27 MEDIUM 6.3 CVE-2020-4974 IBM Jazz Foundation products are vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requ… Engineering Lifecycle Optimization Engineering Insights No fix yet Fix from $1,6002021-07-28 MEDIUM 5.4 CVE-2021-29749 IBM Secure External Authentication Server 6.0.2 and IBM Secure Proxy 6.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an aut… Secure External Authentication Server Patch available Fix from $1,6002021-07-15 MEDIUM 6.5 CVE-2021-20483 IBM Security Identity Manager 6.0.2 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, a remote authenticat… Security Identity Manager Patch available Fix from $1,6002021-06-16 MEDIUM 5.4 CVE-2021-20343 IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to se… Collaborative Lifecycle Management Patch available Fix from $1,6002021-06-02 MEDIUM 5.4 CVE-2021-20345 IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to se… Collaborative Lifecycle Management Patch available Fix from $1,6002021-06-02 MEDIUM 5.4 CVE-2021-20346 IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to se… Collaborative Lifecycle Management Patch available Fix from $1,6002021-06-02 MEDIUM 5.4 CVE-2021-20347 IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to se… Collaborative Lifecycle Management Patch available Fix from $1,6002021-06-02 MEDIUM 5.4 CVE-2021-20348 IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to se… Collaborative Lifecycle Management Patch available Fix from $1,6002021-06-02 MEDIUM 5.4 CVE-2021-20535 IBM Jazz Reporting Service 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attack… Jazz Reporting Service Mitigation only Fix from $1,6002021-05-13 MEDIUM 6.5 CVE-2021-20480 IBM WebSphere Application Server 7.0, 8.0, and 8.5 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, a rem… Websphere Application Server after 8.5.5.19 Fix from $1,6002021-04-08 MEDIUM 6.1 CVE-2020-4882 IBM Planning Analytics 2.0 could be vulnerable to a Server-Side Request Forgery (SSRF) attack by constucting URLs from user-controlled data . This co… Planning Analytics Mitigation only Fix from $1,6002021-03-22 MEDIUM 6.7 CVE-2020-5014 IBM DataPower Gateway V10 and V2018 could allow a local attacker with administrative privileges to execute arbitrary code on the system using a serve… Datapower Gateway after 2018.4.1.14 Fix from $1,6002021-03-08 MEDIUM 6.5 CVE-2020-4632 IBM InfoSphere Metadata Asset Manager 11.7 is vulnerable to server-side request forgery. By sending a specially crafted request, a remote authenticat… Infosphere Metadata Asset Manager Mitigation only Fix from $1,6002020-09-04 HIGH 7.4 CVE-2020-4529 IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send una… Maximo Asset Management Patch available Fix from $1,9502020-06-08 MEDIUM 6.3 CVE-2020-4294 IBM QRadar 7.3.0 to 7.3.3 Patch 2 is vulnerable to Server Side Request Forgery (SSRF). This may allow an authenticated attacker to send unauthorized … Qradar Security Information And Event Manager 7.3.3+ Fix from $1,6002020-04-15 MEDIUM 5.3 CVE-2019-4741 IBM Content Navigator 3.0CD is vulnerable to Server Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requ… Content Navigator Mitigation only Fix from $1,6002020-02-12 MEDIUM 5.3 CVE-2019-4262 IBM QRadar SIEM 7.2 and 7.3 is vulnerable to Server Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requ… Qradar Security Information And Event Manager 7.2.8 / 7.3.2+ Fix from $1,6002019-09-26 CRITICAL 9.8 CVE-2019-4203 IBM API Connect 5.0.0.0 and 5.0.8.6 Developer Portal can be exploited by app developers to download arbitrary files from the host OS and potentially … Api Connect after 5.0.8.6 Fix from $2,3002019-04-15 CRITICAL 9.9 CVE-2018-1789 IBM API Connect v2018.1.0 through v2018.3.4 could allow an attacker to send a specially crafted request to conduct a server side request forgery atta… Api Connect after 2018.3.4 Fix from $2,3002018-09-07 MEDIUM 5.3 CVE-2016-5968 The Replay Server in IBM Tealeaf Customer Experience 8.x before 8.7.1.8847 FP10, 8.8.x before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, … Tealeaf Customer Experience after 8.6 Fix from $1,6002016-11-25