Vulnerability index

Browse CVEs

2,216 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Cloud Pak For Business Automation MEDIUM 6.5
CVE-2024-49348

IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.…

Mitigation only
Fix from $1,600 2025-02-05
Cloud Pak For Business Automation MEDIUM 5.4
CVE-2024-52364

IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.…

Mitigation only
Fix from $1,600 2025-02-05
Cloud Pak For Business Automation MEDIUM 5.4
CVE-2024-52365

IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.…

Mitigation only
Fix from $1,600 2025-02-05
Security Verify Governance MEDIUM 5.9
CVE-2023-35017

IBM Security Verify Governance 10.0.2 Identity Manager can transmit user credentials in clear text that could be obtained by an attacker using man in…

Mitigation only
Fix from $1,600 2025-01-29
Qradar Security Information And Event Manager MEDIUM 6.5
CVE-2024-28786

IBM QRadar SIEM 7.5 transmits sensitive or security-critical data in cleartext in a communication channel that could be obtained by an unauthorized a…

Mitigation only
Fix from $1,600 2025-01-28
Data Virtualization On Cloud Pak For Data MEDIUM 6.5
CVE-2024-37526

IBM Watson Query on Cloud Pak for Data (IBM Data Virtualization 1.8, 2.0, 2.1, 2.2, and 3.0.0) could allow an authenticated user to obtain sensitive …

No fix yet
Fix from $1,600 2025-01-27
Security Directory Integrator HIGH 7.5
CVE-2024-28766

IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 could disclose sensitive information about directory cont…

Mitigation only
Fix from $1,950 2025-01-27
Security Directory Integrator MEDIUM 6.5
CVE-2024-28770

IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attribute on authorization tokens…

Mitigation only
Fix from $1,600 2025-01-27
Security Directory Integrator MEDIUM 6.5
CVE-2024-28771

IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attribute on authorization tokens…

Mitigation only
Fix from $1,600 2025-01-27
Infosphere Master Data Management MEDIUM 5.4
CVE-2023-46187

IBM InfoSphere Master Data Management 11.6, 12.0, and 14.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arb…

Mitigation only
Fix from $1,600 2025-01-27
Common Licensing MEDIUM 6.5
CVE-2023-50946

IBM Common Licensing 9.0 could allow an authenticated user to modify a configuration file that they should not have access to due to a broken author…

Mitigation only
Fix from $1,600 2025-01-26
Cognos Analytics MEDIUM 5.9
CVE-2023-38009

IBM Cognos Mobile Client 1.1 iOS may be vulnerable to information disclosure through man in the middle techniques due to the lack of certificate pinn…

Mitigation only
Fix from $1,600 2025-01-26
Common Licensing MEDIUM 5.5
CVE-2023-50945

IBM Common Licensing 9.0 stores user credentials in plain clear text which can be read by a local user.

Mitigation only
Fix from $1,600 2025-01-26
Automation Decision Services MEDIUM 6.2
CVE-2024-31906

IBM Automation Decision Services 23.0.2 allows web pages to be stored locally which can be read by another user on the system.

Mitigation only
Fix from $1,600 2025-01-26
Maximo Application Suite HIGH 8.8
CVE-2024-35148

IBM Maximo Application Suite 8.10.10, 8.11.7, and 9.0 - Monitor Component is vulnerable to SQL injection. A remote attacker could send specially craf…

Mitigation only
Fix from $1,950 2025-01-25
Maximo Application Suite MEDIUM 6.1
CVE-2024-35145

IBM Maximo Application Suite 9.0.0 - Monitor Component is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker t…

Mitigation only
Fix from $1,600 2025-01-25
Control Center MEDIUM 6.5
CVE-2024-35113

IBM Control Center 6.2.1 and 6.3.1 could allow an authenticated user to obtain sensitive information exposed through a directory listing.

Mitigation only
Fix from $1,600 2025-01-25
Control Center MEDIUM 5.3
CVE-2024-35114

IBM Control Center 6.2.1 and 6.3.1 could allow a remote attacker to enumerate usernames due to an observable discrepancy between login attempts.

Mitigation only
Fix from $1,600 2025-01-25
Cloud Pak System HIGH 7.5
CVE-2023-38713

IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, and 2.3.3.7 iFix1 could discl…

Mitigation only
Fix from $1,950 2025-01-25
Cloud Pak System HIGH 7.5
CVE-2023-38714

IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, and 2.3.3.7 iFix1 could discl…

Mitigation only
Fix from $1,950 2025-01-25
Cloud Pak System HIGH 7.5
CVE-2023-38716

IBM Cloud Pak System 2.3.3.6, 2.3.36 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, and 2.3.4.0 could disclose sensitive information about the system …

No fix yet
Fix from $1,950 2025-01-25
Cloud Pak System MEDIUM 6.5
CVE-2023-38271

IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, and 2.3.3.7 iFix1 could allow…

Mitigation only
Fix from $1,600 2025-01-25
Cloud Pak System HIGH 7.5
CVE-2023-38013

IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, and 2.3.3.7 iFix1 could discl…

Mitigation only
Fix from $1,950 2025-01-25
Cloud Pak System MEDIUM 5.3
CVE-2023-38012

IBM Cloud Pak System 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, and 2.3.4.0 could allow a remote attacker to traverse directories…

Mitigation only
Fix from $1,600 2025-01-25
Planning Analytics HIGH 8.0
CVE-2024-40693

IBM Planning Analytics 2.0 and 2.1 could be vulnerable to malicious file upload by not validating the content of the file uploaded to the web interfa…

Mitigation only
Fix from $1,950 2025-01-24
Maximo Asset Management MEDIUM 6.5
CVE-2024-45077

IBM Maximo Asset Management 7.6.1.3 MXAPIASSET API is vulnerable to unrestricted file upload which allows authenticated low privileged user to upload…

Mitigation only
Fix from $1,600 2025-01-24
Concert MEDIUM 5.9
CVE-2024-41757

IBM Concert Software 1.0.0 and 1.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Str…

Mitigation only
Fix from $1,600 2025-01-24
Planning Analytics HIGH 8.8
CVE-2024-25034

IBM Planning Analytics 2.0 and 2.1 could be vulnerable to malicious file upload by not validating the type of file in the File Manager T1 process. At…

Mitigation only
Fix from $1,950 2025-01-24
Cognos Dashboards On Cloud Pak For Data HIGH 8.8
CVE-2024-41739

IBM Cognos Dashboards 4.0.7 and 5.0.0 on Cloud Pak for Data could allow a remote attacker to perform unauthorized actions due to dependency confusion.

Mitigation only
Fix from $1,950 2025-01-24
Txseries For Multiplatforms HIGH 7.5
CVE-2024-41742

IBM TXSeries for Multiplatforms 10.1 is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual read operation…

Mitigation only
Fix from $1,950 2025-01-19