Vulnerability index

Browse CVEs

2,256 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Security Verify Governance CRITICAL 9.8
CVE-2024-22330

IBM Security Verify Governance 10.0.2 does not require that users should have strong passwords by default, which makes it easier for attackers to com…

Mitigation only
Fix from $2,300 2025-06-06
Verify Identity Access Digital Credentials MEDIUM 6.5
CVE-2024-56343

IBM Verify Identity Access Digital Credentials 24.06 could allow an authenticated user to crash the service with a specially crafted POST request.

Mitigation only
Fix from $1,600 2025-06-06
Verify Identity Access Digital Credentials MEDIUM 5.3
CVE-2024-56342

IBM Verify Identity Access Digital Credentials 24.06 could allow a remote attacker to obtain sensitive information when a detailed technical error me…

Mitigation only
Fix from $1,600 2025-06-06
Planning Analytics Local HIGH 8.8
CVE-2025-33005

IBM Planning Analytics Local 2.0 and 2.1 does not invalidate session after a logout which could allow an authenticated user to impersonate another us…

Mitigation only
Fix from $1,950 2025-06-01
Planning Analytics Local MEDIUM 6.5
CVE-2025-33004

IBM Planning Analytics Local 2.0 and 2.1 could allow a privileged user to delete files from directories due to improper pathname restriction.

Mitigation only
Fix from $1,600 2025-06-01
Planning Analytics Local MEDIUM 5.4
CVE-2025-25044

IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary Ja…

Mitigation only
Fix from $1,600 2025-06-01
Planning Analytics Local MEDIUM 5.4
CVE-2025-2896

IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary Ja…

Mitigation only
Fix from $1,600 2025-06-01
Infosphere Information Server MEDIUM 6.5
CVE-2025-1499

IBM InfoSphere Information Server 11.7 stores credential information for database authentication in a cleartext parameter file that could be viewed b…

Mitigation only
Fix from $1,600 2025-06-01
Tivoli Monitoring CRITICAL 9.8
CVE-2025-3357

IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 19 could allow a remote attacker to execute arbitrary code due to improper validation of a…

Mitigation only
Fix from $2,300 2025-05-28
Security Guardium MEDIUM 6.5
CVE-2025-25029

IBM Security Guardium 12.0 could allow a privileged user to download any file on the system due to improper escaping of input.

Mitigation only
Fix from $1,600 2025-05-28
Security Guardium MEDIUM 5.3
CVE-2025-25025

IBM Security Guardium 12.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the b…

Mitigation only
Fix from $1,600 2025-05-28
Hardware Management Console R10.0 Firmware MEDIUM 5.4
CVE-2024-45094

IBM DS8900F and DS8A00 Hardware Management Console (HMC) is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to…

Mitigation only
Fix from $1,600 2025-05-27
Cognos Controller MEDIUM 6.5
CVE-2025-33079

IBM Controller 11.0.0, 11.0.1, and 11.1.0 application could allow an authenticated user to obtain sensitive credentials that may be inadvertently inc…

Mitigation only
Fix from $1,600 2025-05-27
I HIGH 8.8
CVE-2025-33103

IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 product IBM TCP/IP Connectivity Utilities for i contains a privilege escalation vulnerability. A malicious actor wi…

Mitigation only
Fix from $1,950 2025-05-17
Content Navigator MEDIUM 6.1
CVE-2024-51475

IBM Content Navigator 3.0.11, 3.0.15, and 3.1.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewe…

Mitigation only
Fix from $1,600 2025-05-16
Security Guardium MEDIUM 5.5
CVE-2025-3440

IBM Security Guardium 11.5 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript co…

Mitigation only
Fix from $1,600 2025-05-15
Storage Scale HIGH 8.8
CVE-2025-1137

IBM Storage Scale 5.2.2.0 and 5.2.2.1, under certain configurations, could allow an authenticated user to execute privileged commands due to improper…

Mitigation only
Fix from $1,950 2025-05-10
Cics Tx HIGH 7.8
CVE-2025-1330

IBM CICS TX Standard 11.1 and IBM CICS TX Advanced 10.1 and 11.1  could allow a local user to execute arbitrary code on the system due to failure to …

Mitigation only
Fix from $1,950 2025-05-08
Cics Tx HIGH 7.8
CVE-2025-1331

IBM CICS TX Standard 11.1 and IBM CICS TX Advanced 10.1 and 11.1 could allow a local user to execute arbitrary code on the system due to the use of u…

Mitigation only
Fix from $1,950 2025-05-08
Cics Tx HIGH 7.8
CVE-2025-1329

IBM CICS TX Standard 11.1 and IBM CICS TX Advanced 10.1 and 11.1 could allow a local user to execute arbitrary code on the system due to failure to h…

Mitigation only
Fix from $1,950 2025-05-08
Sterling Partner Engagement Manager HIGH 7.5
CVE-2025-33093

IBM Sterling Partner Engagement Manager 6.1.0, 6.2.0, 6.2.2 JWT secret is stored in public Helm Charts and is not stored as a Kubernetes secret.

Mitigation only
Fix from $1,950 2025-05-07
I MEDIUM 5.4
CVE-2025-3218

IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 is vulnerable to authentication and authorization attacks due to incorrect validation processing in IBM i Netserver…

Mitigation only
Fix from $1,600 2025-05-07
Maximo Application Suite HIGH 8.8
CVE-2025-2898

IBM Maximo Application Suite 9.0 could allow an attacker with some level of access to elevate their privileges due to a security configuration vulner…

Mitigation only
Fix from $1,950 2025-05-06
Cloud Pak For Business Automation MEDIUM 6.5
CVE-2025-1838

IBM Cloud Pak for Business Automation 24.0.0 and 24.0.1 through 24.0.1 IF001 Authoring allows an authenticated user to bypass client-side data va…

Mitigation only
Fix from $1,600 2025-05-03
Cloud Pak For Business Automation MEDIUM 6.1
CVE-2024-41753

IBM Cloud Pak for Business Automation 24.0.0 through 24.0.0 IF004 and 24.0.1 through 24.0.1 IF001 is vulnerable to cross-site scripting. This vulnera…

Mitigation only
Fix from $1,600 2025-05-03
Operational Decision Manager MEDIUM 6.1
CVE-2025-1551

IBM Operational Decision Manager 8.11.0.1, 8.11.1.0, 8.12.0.1, and 9.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows an unauth…

Mitigation only
Fix from $1,600 2025-04-29
Maximo Asset Management MEDIUM 5.4
CVE-2025-2986

IBM Maximo Asset Management 7.6.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary Java…

Mitigation only
Fix from $1,600 2025-04-25
Hardware Management Console HIGH 7.8
CVE-2025-1950

IBM Hardware Management Console - Power Systems V10.2.1030.0 and V10.3.1050.0 could allow a local user to execute commands locally due to improper va…

Mitigation only
Fix from $1,950 2025-04-22
Hardware Management Console MEDIUM 6.7
CVE-2025-1951

IBM Hardware Management Console - Power Systems V10.2.1030.0 and V10.3.1050.0 could allow a local user to execute commands as a privileged user due t…

Mitigation only
Fix from $1,600 2025-04-22
Maximo Asset Management MEDIUM 5.4
CVE-2025-2987

IBM Maximo Asset Management 7.6.1.3 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorize…

Mitigation only
Fix from $1,600 2025-04-22