Vulnerability index

Browse CVEs

2,216 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Txseries For Multiplatforms HIGH 7.5
CVE-2024-41743

IBM TXSeries for Multiplatforms 10.1 could allow a remote attacker to cause a denial of service using persistent connections due to improper allocati…

Mitigation only
Fix from $1,950 2025-01-19
Maximo Asset Management HIGH 7.5
CVE-2024-45652

IBM Maximo MXAPIASSET API 7.6.1.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL…

Mitigation only
Fix from $1,950 2025-01-19
Concert HIGH 7.5
CVE-2024-49354

IBM Concert 1.0.0, 1.0.1, and 1.0.2 is vulnerable to sensitive information disclosure through specially crafted API Calls.

Mitigation only
Fix from $1,950 2025-01-18
Voice Gateway CRITICAL 9.1
CVE-2024-47113

IBM ICP - Voice Gateway 1.0.2, 1.0.2.4, 1.0.3, 1.0.4, 1.0.5, 1.0.6. 1.0.7, 1.0.7.1, and 1.0.8 could allow remote attacker to send specially crafted X…

Mitigation only
Fix from $2,300 2025-01-18
Infosphere Information Server HIGH 7.5
CVE-2024-52363

IBM InfoSphere Information Server 11.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafte…

Mitigation only
Fix from $1,950 2025-01-17
Cics Tx MEDIUM 6.1
CVE-2024-41746

IBM CICS TX Advanced 10.1, 11.1, and Standard 11.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary J…

Mitigation only
Fix from $1,600 2025-01-16
Jazz Foundation MEDIUM 5.4
CVE-2021-29669

IBM Jazz Foundation 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary J…

Mitigation only
Fix from $1,600 2025-01-12
Doors Next HIGH 8.1
CVE-2024-41787

IBM Engineering Requirements Management DOORS Next 7.0.2 and 7.0.3 could allow a remote attacker to bypass security restrictions, caused by a race co…

Mitigation only
Fix from $1,950 2025-01-10
Openpages With Watson MEDIUM 5.4
CVE-2024-43176

IBM OpenPages 9.0 could allow an authenticated user to obtain sensitive information such as configurations that should only be available to privilege…

Mitigation only
Fix from $1,600 2025-01-09
Db2 MEDIUM 5.5
CVE-2024-40679

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to an information disclosure vulnerability as sensitive informat…

Mitigation only
Fix from $1,600 2025-01-08
Concert MEDIUM 5.4
CVE-2024-52891

IBM Concert Software 1.0.0, 1.0.1, 1.0.2, 1.0.2.1, and 1.0.3 could allow an authenticated user to inject malicious information or obtain informatio…

Mitigation only
Fix from $1,600 2025-01-07
Concert MEDIUM 5.3
CVE-2024-52893

IBM Concert Software 1.0.0, 1.0.1, 1.0.2, 1.0.2.1, and 1.0.3  could allow a remote attacker to obtain sensitive information when a detailed technica…

Mitigation only
Fix from $1,600 2025-01-07
Concert HIGH 7.5
CVE-2024-52367

IBM Concert Software 1.0.0, 1.0.1, 1.0.2, 1.0.2.1, and 1.0.3 could disclose sensitive system information to an unauthorized actor that could be used …

Mitigation only
Fix from $1,950 2025-01-07
Concert MEDIUM 5.9
CVE-2024-52366

IBM Concert Software 1.0.0, 1.0.1, 1.0.2, 1.0.2.1, and 1.0.3 could allow a remote attacker to obtain sensitive information, caused by the failure to …

Mitigation only
Fix from $1,600 2025-01-07
Engineering Lifecycle Optimization Publishing MEDIUM 6.5
CVE-2024-41768

IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 could allow a remote attacker to cause an unhandled SSL exception which could lea…

Mitigation only
Fix from $1,600 2025-01-04
Engineering Lifecycle Optimization Publishing HIGH 7.5
CVE-2024-41763

IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 uses weaker than expected cryptographic algorithms that could allow an attacker …

Mitigation only
Fix from $1,950 2025-01-04
Engineering Lifecycle Optimization Publishing HIGH 7.5
CVE-2024-41766

IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 could allow a remote attacker to cause a denial of service using a complex regul…

Mitigation only
Fix from $1,950 2025-01-04
Engineering Lifecycle Optimization Publishing HIGH 7.3
CVE-2024-41767

IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 is vulnerable to SQL injection. A remote attacker could send specially crafted SQ…

Mitigation only
Fix from $1,950 2025-01-04
Engineering Lifecycle Optimization Publishing MEDIUM 6.5
CVE-2024-41765

IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 could allow a remote attacker to traverse directories on the system. An attacker …

Mitigation only
Fix from $1,600 2025-01-04
I MEDIUM 5.4
CVE-2024-55896

IBM PowerHA SystemMirror for i 7.4 and 7.5 contains improper restrictions when rendering content via iFrames.  This vulnerability could allow an atta…

Mitigation only
Fix from $1,600 2025-01-03
Websphere Automation HIGH 7.2
CVE-2024-54181

IBM WebSphere Automation 1.7.5 could allow a remote privileged user, who has authorized access to the swagger UI, to execute arbitrary code. Using sp…

Mitigation only
Fix from $1,950 2024-12-30
Vios MEDIUM 5.5
CVE-2024-52906

IBM AIX 7.2, 7.3, VIOS 3.1, and 4.1 could allow a non-privileged local user to exploit a vulnerability in the TCP/IP kernel extension to cause a d…

Mitigation only
Fix from $1,600 2024-12-25
Vios MEDIUM 5.5
CVE-2024-47102

IBM AIX 7.2, 7.3, VIOS 3.1, and 4.1 could allow a non-privileged local user to exploit a vulnerability in the AIX perfstat kernel extension to cause…

Mitigation only
Fix from $1,600 2024-12-25
Engineering Lifecycle Optimization Engineering Insights CRITICAL 9.8
CVE-2024-39727

IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 uses a web link with untrusted references to an external site. A remote…

Mitigation only
Fix from $2,300 2024-12-25
Engineering Lifecycle Optimization Engineering Insights MEDIUM 5.3
CVE-2024-39725

IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 could allow a remote attacker to obtain sensitive information when a de…

Mitigation only
Fix from $1,600 2024-12-25
I MEDIUM 5.4
CVE-2024-51463

IBM i 7.3, 7.4, and 7.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests…

Mitigation only
Fix from $1,600 2024-12-21
Security Guardium MEDIUM 5.4
CVE-2024-49336

IBM Security Guardium 11.5 and 12.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorize…

Mitigation only
Fix from $1,600 2024-12-19
Db2 MEDIUM 6.5
CVE-2023-30443

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted qu…

Mitigation only
Fix from $1,600 2024-12-19
Cognos Analytics Mobile HIGH 7.5
CVE-2021-39081

IBM Cognos Analytics Mobile for Android 1.1.14 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sens…

Mitigation only
Fix from $1,950 2024-12-19
Infosphere Information Server MEDIUM 5.2
CVE-2021-29827

IBM InfoSphere Information Server 11.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a m…

Mitigation only
Fix from $1,600 2024-12-19