Vulnerability index

Browse CVEs

2,216 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Cics Tx MEDIUM 6.1
CVE-2024-41745

IBM CICS TX Standard is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code …

Mitigation only
Fix from $1,600 2024-11-01
Txseries For Multiplatforms MEDIUM 5.9
CVE-2024-41738

IBM TXSeries for Multiplatforms 10.1 could allow an attacker to obtain sensitive information from the query string of an HTTP GET method to process a…

Mitigation only
Fix from $1,600 2024-11-01
Txseries For Multiplatforms MEDIUM 5.3
CVE-2024-41741

IBM TXSeries for Multiplatforms 10.1 could allow an attacker to determine valid usernames due to an observable timing discrepancy which could be used…

Mitigation only
Fix from $1,600 2024-11-01
Power System E1080 \(9080 Hex\) Firmware CRITICAL 9.8
CVE-2024-45656

IBM Flexible Service Processor (FSP) FW860.00 through FW860.B3, FW950.00 through FW950.C0, FW1030.00 through FW1030.61, FW1050.00 through FW1050.21, …

Mitigation only
Fix from $2,300 2024-10-29
Cics Transaction Gateway HIGH 7.5
CVE-2023-50310

IBM CICS Transaction Gateway for Multiplatforms 9.2 and 9.3 transmits or stores authentication credentials, but it uses an insecure method that is su…

Mitigation only
Fix from $1,950 2024-10-23
Concert CRITICAL 9.8
CVE-2024-43177

IBM Concert 1.0.0 and 1.0.1 vulnerable to attacks that rely on the use of cookies without the SameSite attribute.

Mitigation only
Fix from $2,300 2024-10-22
Watson Studio Local HIGH 8.8
CVE-2024-49340

IBM Watson Studio Local 1.2.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions…

Mitigation only
Fix from $1,950 2024-10-16
Cloud Pak For Multicloud Management Monitoring HIGH 8.8
CVE-2024-43191

IBM ManageIQ could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted yaml file request.

Mitigation only
Fix from $1,950 2024-09-26
Maximo Application Suite HIGH 7.5
CVE-2024-37068

IBM Maximo Application Suite - Manage Component 8.10, 8.11, and 9.0 uses weaker than expected cryptographic algorithms that could allow an attacker t…

Mitigation only
Fix from $1,950 2024-09-07
Mq Operator MEDIUM 5.5
CVE-2024-40680

IBM MQ 9.3 CD and 9.4 LTS/CD could allow a local user to cause a denial of service due to improper memory allocation causing a segmentation fault.

Mitigation only
Fix from $1,600 2024-09-07
Webmethods Integration CRITICAL 9.9
CVE-2024-45076

IBM webMethods Integration 10.15 could allow an authenticated user to upload and execute arbitrary files which could be executed on the underlying op…

Mitigation only
Fix from $2,300 2024-09-04
Webmethods Integration HIGH 8.8
CVE-2024-45075

IBM webMethods Integration 10.15 could allow an authenticated user to create scheduler tasks that would allow them to escalate their privileges to ad…

Mitigation only
Fix from $1,950 2024-09-04
Webmethods Integration MEDIUM 6.5
CVE-2024-45074

IBM webMethods Integration 10.15 could allow an authenticated user to traverse directories on the system. An attacker could send a specially crafted …

Mitigation only
Fix from $1,600 2024-09-04
App Connect Enterprise Certified Container HIGH 8.1
CVE-2022-43915

IBM App Connect Enterprise Certified Container 5.0, 7.1, 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.…

Mitigation only
Fix from $1,950 2024-08-24
Sterling Connect Direct Web Services HIGH 7.5
CVE-2024-39745

IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 uses weaker than expected cryptographic algorithms that could allow an attacker to de…

Mitigation only
Fix from $1,950 2024-08-22
Openpages Grc Platform MEDIUM 6.5
CVE-2024-35151

IBM OpenPages with Watson 8.3 and 9.0 could allow authenticated users access to sensitive information through improper authorization controls on APIs.

Mitigation only
Fix from $1,600 2024-08-22
Sterling Connect Direct Web Services MEDIUM 5.9
CVE-2024-39746

IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 could allow a remote attacker to obtain sensitive information, caused by the failure …

Mitigation only
Fix from $1,600 2024-08-22
Global Configuration Management MEDIUM 6.5
CVE-2024-41773

IBM Global Configuration Management 7.0.2 and 7.0.3 could allow an authenticated user to archive a global baseline due to improper access controls.

Mitigation only
Fix from $1,600 2024-08-20
Security Directory Integrator CRITICAL 9.8
CVE-2022-33162

IBM Security Directory Integrator 7.2.0 and Security Verify Directory Integrator 10.0.0 does not perform any authentication for functionality that re…

Mitigation only
Fix from $2,300 2024-08-16
Infosphere Information Server MEDIUM 6.5
CVE-2024-40705

IBM InfoSphere Information Server could allow an authenticated user to consume file space resources due to unrestricted file uploads. IBM X-Force ID…

Mitigation only
Fix from $1,600 2024-08-15
Qradar Network Packet Capture MEDIUM 5.9
CVE-2024-31905

IBM QRadar Network Packet Capture 7.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP St…

Mitigation only
Fix from $1,600 2024-08-15
Db2 MEDIUM 6.5
CVE-2024-35152

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated user to cause a denial of service with a speciall…

Mitigation only
Fix from $1,600 2024-08-14
Websphere Application Server MEDIUM 5.9
CVE-2023-50315

IBM WebSphere Application Server 8.5 and 9.0 could allow an attacker with access to the network to conduct spoofing attacks. An attacker could explo…

Mitigation only
Fix from $1,600 2024-08-14
Openbmc HIGH 7.5
CVE-2024-35124

A vulnerability in the combination of the OpenBMC's FW1050.00 through FW1050.10, FW1030.00 through FW1030.50, and FW1020.00 through FW1020.60 default…

Mitigation only
Fix from $1,950 2024-08-13
Common Licensing HIGH 7.5
CVE-2024-40697

IBM Common Licensing 9.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user …

Mitigation only
Fix from $1,950 2024-08-13
Aspera Shares MEDIUM 5.4
CVE-2023-38018

IBM Aspera Shares 1.10.0 PL2 does not invalidate session after a password change which could allow an authenticated user to impersonate another user …

Mitigation only
Fix from $1,600 2024-08-12
Aspera Orchestrator MEDIUM 6.5
CVE-2023-38001

IBM Aspera Orchestrator 4.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions…

Mitigation only
Fix from $1,600 2024-07-30
Aspera Orchestrator MEDIUM 5.4
CVE-2023-26289

IBM Aspera Orchestrator 4.0.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow a…

Mitigation only
Fix from $1,600 2024-07-30
Aspera Orchestrator MEDIUM 5.5
CVE-2023-26288

IBM Aspera Orchestrator 4.0.1 does not invalidate session after a password change which could allow an authenticated user to impersonate another user…

Mitigation only
Fix from $1,600 2024-07-30
Security Directory Integrator HIGH 7.5
CVE-2022-33167

IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 could allow a remote attacker to obtain sensitive informa…

Mitigation only
Fix from $1,950 2024-07-30