Vulnerability index

Browse CVEs

2,216 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Infosphere Information Server CRITICAL 9.8
CVE-2024-40689

IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could all…

Mitigation only
Fix from $2,300 2024-07-26
Security Directory Integrator MEDIUM 5.4
CVE-2024-28772

IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 is vulnerable to stored cross-site scripting. This vulner…

Mitigation only
Fix from $1,600 2024-07-25
Security Directory Integrator HIGH 7.5
CVE-2022-32759

IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 uses insufficient session expiration which could allow an…

Mitigation only
Fix from $1,950 2024-07-25
Engineering Requirements Management Doors HIGH 8.2
CVE-2023-50304

IBM Engineering Requirements Management DOORS Web Access 9.7.2.8 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML d…

Mitigation only
Fix from $1,950 2024-07-18
Sterling Partner Engagement Manager MEDIUM 5.5
CVE-2022-35640

IBM Sterling Partner Engagement Manager 6.2.2 could allow a local attacker to obtain sensitive information when a detailed technical error message is…

Mitigation only
Fix from $1,600 2024-07-16
Datacap MEDIUM 5.4
CVE-2024-39735

IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to…

Mitigation only
Fix from $1,600 2024-07-15
Datacap MEDIUM 5.3
CVE-2024-39740

IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 displays version information in HTTP requests that could allow an attacker to gather info…

Mitigation only
Fix from $1,600 2024-07-15
Datacap MEDIUM 5.3
CVE-2024-39741

IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 could allow a remote attacker to traverse directories on the system. An attacker could se…

Mitigation only
Fix from $1,600 2024-07-15
Datacap MEDIUM 5.3
CVE-2024-39737

IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 could allow a remote attacker to obtain sensitive information when a detailed technical e…

Mitigation only
Fix from $1,600 2024-07-15
Datacap CRITICAL 9.8
CVE-2024-39736

IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 is vulnerable to HTTP header injection, caused by improper validation of input by the HOS…

Mitigation only
Fix from $2,300 2024-07-15
Datacap HIGH 7.5
CVE-2024-39731

IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 uses weaker than expected cryptographic algorithms that could allow an attacker to decryp…

Mitigation only
Fix from $1,950 2024-07-15
Datacap MEDIUM 5.4
CVE-2024-39728

IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed ar…

Mitigation only
Fix from $1,600 2024-07-15
Datacap MEDIUM 5.5
CVE-2024-39733

IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 stores user credentials in plain clear text which can be read by a local user. IBM X-For…

Mitigation only
Fix from $1,600 2024-07-14
Datacap HIGH 7.5
CVE-2024-39732

IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 temporarily stores data from different environments that could be obtained by a malicious…

Mitigation only
Fix from $1,950 2024-07-14
Infosphere Information Server MEDIUM 5.4
CVE-2024-40690

IBM InfoSphere Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code …

Mitigation only
Fix from $1,600 2024-07-12
Security Qradar Edr MEDIUM 5.4
CVE-2023-35006

IBM Security QRadar EDR 3.12 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be execute…

Mitigation only
Fix from $1,600 2024-07-10
Security Qradar Edr MEDIUM 5.3
CVE-2023-33860

IBM Security QRadar EDR 3.12 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie va…

Mitigation only
Fix from $1,600 2024-07-10
Security Qradar Edr MEDIUM 5.3
CVE-2023-33859

IBM Security QRadar EDR 3.12 could disclose sensitive information due to an observable login response discrepancy. IBM X-Force ID: 257697.

Mitigation only
Fix from $1,600 2024-07-10
I HIGH 7.8
CVE-2024-38330

IBM System Management for i 7.2, 7.3, and 7.4 could allow a local user to gain elevated privileges due to an unqualified library program call. A mal…

Mitigation only
Fix from $1,950 2024-07-08
Infosphere Information Server MEDIUM 5.4
CVE-2023-50964

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…

Mitigation only
Fix from $1,600 2024-06-30
Infosphere Information Server MEDIUM 5.4
CVE-2024-28794

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…

Mitigation only
Fix from $1,600 2024-06-30
Infosphere Information Server MEDIUM 5.4
CVE-2024-28797

IBM InfoSphere Information Server 11.7 is vulnerable stored to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript co…

Mitigation only
Fix from $1,600 2024-06-30
Infosphere Information Server MEDIUM 5.4
CVE-2024-31898

IBM InfoSphere Information Server 11.7 could allow an authenticated user to read or modify sensitive information by bypassing authentication using in…

Mitigation only
Fix from $1,600 2024-06-30
Infosphere Information Server MEDIUM 5.4
CVE-2023-50952

IBM InfoSphere Information Server 11.7 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthor…

Mitigation only
Fix from $1,600 2024-06-30
Infosphere Information Server MEDIUM 5.3
CVE-2024-35119

IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is retur…

Mitigation only
Fix from $1,600 2024-06-30
Infosphere Information Server HIGH 8.8
CVE-2024-31902

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorize…

Mitigation only
Fix from $1,950 2024-06-30
Infosphere Information Server MEDIUM 6.1
CVE-2024-28798

IBM InfoSphere Information Server 11.7 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript co…

Mitigation only
Fix from $1,600 2024-06-30
Infosphere Information Server MEDIUM 5.3
CVE-2023-50954

IBM InfoSphere Information Server 11.7 returns sensitive information in URL information that could be used in further attacks against the system. IB…

Mitigation only
Fix from $1,600 2024-06-30
Infosphere Information Server MEDIUM 5.4
CVE-2024-28795

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…

Mitigation only
Fix from $1,600 2024-06-30
Cognos Analytics MEDIUM 5.9
CVE-2024-25053

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, and 12.0.2 is vulnerable to improper certificate validation when using t…

Mitigation only
Fix from $1,600 2024-06-28