Vulnerability index

Browse CVEs

2,216 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Mq MEDIUM 6.5
CVE-2024-35155

IBM MQ Console 9.3 LTS and 9.3 CD could disclose could allow a remote attacker to obtain sensitive information when a detailed technical error messag…

Mitigation only
Fix from $1,600 2024-06-28
Mq HIGH 8.8
CVE-2024-31912

IBM MQ 9.3 LTS and 9.3 CD could allow an authenticated user to escalate their privileges under certain configurations due to incorrect privilege assi…

Mitigation only
Fix from $1,950 2024-06-28
Mq HIGH 7.5
CVE-2024-31919

IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS and 9.3 CD, in certain configurations, is vulnerable to a denial of service attack caused by an error proce…

Mitigation only
Fix from $1,950 2024-06-28
Openbmc HIGH 7.5
CVE-2024-31916

IBM OpenBMC FW1050.00 through FW1050.10 BMCWeb HTTPS server component could disclose sensitive URI content to an unauthorized actor that bypasses aut…

Mitigation only
Fix from $1,950 2024-06-27
Sterling B2b Integrator MEDIUM 5.4
CVE-2023-42011

IBM Sterling B2B Integrator Standard Edition 6.1 and 6.2 does not restrict or incorrectly restricts frame objects or UI layers that belong to another…

Mitigation only
Fix from $1,600 2024-06-27
Websphere Application Server HIGH 8.8
CVE-2024-37532

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to identity spoofing by an authenticated user due to improper signature validation. IBM X…

Mitigation only
Fix from $1,950 2024-06-20
I HIGH 7.8
CVE-2024-27275

IBM i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability caused by an insufficient authority requirement. A local user withou…

Mitigation only
Fix from $1,950 2024-06-15
Db2 MEDIUM 6.5
CVE-2023-29267

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5is vulnerable to a denial of service, under specific configurat…

Mitigation only
Fix from $1,600 2024-06-12
Db2 MEDIUM 6.5
CVE-2024-31881

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may crash w…

Mitigation only
Fix from $1,600 2024-06-12
Db2 MEDIUM 6.5
CVE-2024-28762

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted qu…

Mitigation only
Fix from $1,600 2024-06-12
Engineering Lifecycle Optimization Publishing CRITICAL 9.8
CVE-2023-45188

IBM Engineering Lifecycle Optimization Publishing 7.0.2 and 7.03 could allow a remote attacker to upload arbitrary files, caused by the improper vali…

Mitigation only
Fix from $2,300 2024-06-09
I MEDIUM 5.3
CVE-2024-31878

IBM i 7.2, 7.3, 7.4, and 7.5 Service Tools Server (SST) is vulnerable to SST user enumeration by a remote attacker. This vulnerability can be used b…

Mitigation only
Fix from $1,600 2024-06-07
Ds8900f Firmware MEDIUM 6.3
CVE-2024-22326

IBM System Storage DS8900F 89.22.19.0, 89.30.68.0, 89.32.40.0, 89.33.48.0, 89.40.83.0, and 89.40.93.0 could allow a remote user to create an LDAP con…

Mitigation only
Fix from $1,600 2024-06-06
Doors Next HIGH 8.2
CVE-2023-45192

IBM Engineering Requirements Management DOORS Next 7.0.2 and 7.0.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML…

Mitigation only
Fix from $1,950 2024-06-06
Planning Analytics Local MEDIUM 5.4
CVE-2024-31889

IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in…

Mitigation only
Fix from $1,600 2024-05-31
Planning Analytics Local MEDIUM 5.4
CVE-2024-31907

IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in…

Mitigation only
Fix from $1,600 2024-05-31
Planning Analytics Local MEDIUM 5.4
CVE-2024-31908

IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript …

Mitigation only
Fix from $1,600 2024-05-31
Db2 HIGH 8.8
CVE-2023-42005

IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data 3.5, 4.0, 4.5, 4.6, 4.7, and 4.8 could allow a user with access to the Kubernet…

Mitigation only
Fix from $1,950 2024-05-29
Engineering Workflow Management MEDIUM 5.4
CVE-2024-28793

IBM Engineering Workflow Management 7.0.2 and 7.0.3 is vulnerable to stored cross-site scripting. Under certain configurations, this vulnerability al…

Mitigation only
Fix from $1,600 2024-05-28
Security Guardium MEDIUM 5.4
CVE-2023-47710

IBM Security Guardium 11.4, 11.5, and 12.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code …

Mitigation only
Fix from $1,600 2024-05-24
I HIGH 7.8
CVE-2024-27264

IBM Performance Tools for i 7.2, 7.3, 7.4, and 7.5 could allow a local user to gain elevated privileges due to an unqualified library call. A malici…

Mitigation only
Fix from $1,950 2024-05-22
I HIGH 7.5
CVE-2024-31879

IBM i 7.2, 7.3, and 7.4 could allow a remote attacker to execute arbitrary code leading to a denial of service of network ports on the system, caused…

Mitigation only
Fix from $1,950 2024-05-18
Vios HIGH 8.4
CVE-2024-27260

IBM AIX could 7.2, 7.3, VIOS 3.1, and VIOS 4.1 allow a non-privileged local user to exploit a vulnerability in the invscout command to execute arbitr…

Mitigation only
Fix from $1,950 2024-05-16
Qradar Security Information And Event Manager MEDIUM 6.8
CVE-2024-27269

IBM QRadar SIEM 7.5 could allow a privileged user to configure user management that would disclose unintended sensitive information across tenants. …

Mitigation only
Fix from $1,600 2024-05-14
Txseries For Multiplatform HIGH 7.5
CVE-2024-22345

IBM TXSeries for Multiplatforms 8.2 transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorize…

Mitigation only
Fix from $1,950 2024-05-14
Txseries For Multiplatform MEDIUM 6.1
CVE-2024-22344

IBM TXSeries for Multiplatforms 8.2 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be …

Mitigation only
Fix from $1,600 2024-05-14
Security Guardium HIGH 7.8
CVE-2023-47712

IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a local user to gain elevated privileges on the system due to improper permissions contr…

Mitigation only
Fix from $1,950 2024-05-14
Security Guardium MEDIUM 6.5
CVE-2023-47711

IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow an authenticated user to upload files that would cause a denial of service. IBM X-Force…

Mitigation only
Fix from $1,600 2024-05-14
Security Guardium HIGH 8.8
CVE-2023-47709

IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a…

Mitigation only
Fix from $1,950 2024-05-14
Vios HIGH 7.8
CVE-2024-27273

IBM AIX's Unix domain (AIX 7.2, 7.3, VIOS 3.1, and VIOS 4.1) datagram socket implementation could potentially expose applications using Unix domain d…

Mitigation only
Fix from $1,950 2024-05-07