Vulnerability index

Browse CVEs

2,216 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Aspera Orchestrator MEDIUM 5.3
CVE-2023-27283

IBM Aspera Orchestrator 4.0.1 could allow a remote attacker to enumerate usernames due to observable response discrepancies. IBM X-Force ID: 248545.

Mitigation only
Fix from $1,600 2024-05-04
Cognos Controller HIGH 8.8
CVE-2023-40695

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 does not invalidate session after logout which could allow an authenticated user to impersonate anot…

Mitigation only
Fix from $1,950 2024-05-03
Cognos Controller HIGH 7.2
CVE-2021-20451

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which…

Mitigation only
Fix from $1,950 2024-05-03
Cognos Controller MEDIUM 5.3
CVE-2022-22364

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to external service interaction attack, caused by improper validation of user-supplied…

Mitigation only
Fix from $1,600 2024-05-03
Cognos Controller HIGH 7.5
CVE-2023-40696

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly se…

Mitigation only
Fix from $1,950 2024-05-03
Cognos Controller CRITICAL 9.8
CVE-2023-38724

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which…

Mitigation only
Fix from $2,300 2024-05-03
Cognos Controller MEDIUM 5.3
CVE-2023-23474

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 could allow a remote attacker to obtain sensitive information when a stack trace is returned in the …

Mitigation only
Fix from $1,600 2024-05-03
Cognos Controller MEDIUM 5.3
CVE-2023-28952

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to injection attacks in application logging by not sanitizing user provided data. IBM…

Mitigation only
Fix from $1,600 2024-05-03
Cognos Controller MEDIUM 5.3
CVE-2021-20556

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 could allow a remote user to enumerate usernames due to differentiating error messages on existing u…

Mitigation only
Fix from $1,600 2024-05-03
Cognos Controller HIGH 7.5
CVE-2020-4874

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly se…

Mitigation only
Fix from $1,950 2024-05-03
Aspera Orchestrator HIGH 8.8
CVE-2023-37407

IBM Aspera Orchestrator 4.0.1 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted …

Mitigation only
Fix from $1,950 2024-05-03
Websphere Automation HIGH 7.8
CVE-2024-28764

IBM WebSphere Automation 1.7.0 could allow an attacker with privileged access to the network to conduct a CSV injection. An attacker could execute a…

Mitigation only
Fix from $1,950 2024-05-01
Websphere Automation MEDIUM 5.4
CVE-2024-28775

IBM WebSphere Automation 1.7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web U…

Mitigation only
Fix from $1,600 2024-05-01
Rational Developer For I HIGH 7.8
CVE-2024-25050

IBM i 7.2, 7.3, 7.4, 7.5 and IBM Rational Development Studio for i 7.2, 7.3, 7.4, 7.5 networking and compiler infrastructure could allow a local user…

Mitigation only
Fix from $1,950 2024-04-28
Security Verify Privilege On Premises HIGH 7.5
CVE-2024-31887

IBM Security Verify Privilege 11.6.25 could allow an unauthenticated actor to obtain sensitive information from the SOAP API. IBM X-Force ID: 2876…

Mitigation only
Fix from $1,950 2024-04-16
Qradar Security Information And Event Manager HIGH 8.1
CVE-2023-50949

IBM QRadar SIEM 7.5 could allow an unauthorized user to perform unauthorized actions due to improper certificate validation. IBM X-Force ID: 275706.

Mitigation only
Fix from $1,950 2024-04-11
Maximo Application Suite HIGH 7.5
CVE-2024-22328

IBM Maximo Application Suite 8.10 and 8.11 could allow a remote attacker to traverse directories on the system. An attacker could send a specially cr…

Mitigation only
Fix from $1,950 2024-04-06
Db2 MEDIUM 6.5
CVE-2024-27254

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 federated server is vulnerable to denial of service with a spe…

Mitigation only
Fix from $1,600 2024-04-03
Db2 MEDIUM 6.5
CVE-2024-22360

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to a denial of service with a specially crafted query on certain…

Mitigation only
Fix from $1,600 2024-04-03
Db2 MEDIUM 6.5
CVE-2024-25046

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to a denial of service by an authenticated user using a…

Mitigation only
Fix from $1,600 2024-04-03
Db2 MEDIUM 5.5
CVE-2024-25030

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 stores potentially sensitive information in log files that could be read by a …

Mitigation only
Fix from $1,600 2024-04-03
Db2 MEDIUM 6.5
CVE-2023-38729

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to sensitive information disclosure when using A…

Mitigation only
Fix from $1,600 2024-04-03
Db2 MEDIUM 5.3
CVE-2023-52296

IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to denial of service when querying a specific UDF built-in funct…

Mitigation only
Fix from $1,600 2024-04-03
Websphere Application Server MEDIUM 6.5
CVE-2023-50313

IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security for outbound TLS connections caused by a failure to honor us…

Mitigation only
Fix from $1,600 2024-04-02
Cloud Pak For Business Automation MEDIUM 6.5
CVE-2023-50959

IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2,19.0.1, 19.0.2, 19.0.3,20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1,2 2.0.2, 2…

Mitigation only
Fix from $1,600 2024-03-31
Qradar Security Information And Event Manager MEDIUM 5.4
CVE-2024-28784

IBM QRadar SIEM 7.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alte…

Mitigation only
Fix from $1,600 2024-03-27
Qradar Security Information And Event Manager MEDIUM 5.4
CVE-2023-50961

IBM QRadar SIEM 7.5 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI th…

Mitigation only
Fix from $1,600 2024-03-27
Security Verify Directory MEDIUM 6.5
CVE-2022-32753

IBM Security Verify Directory 10.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive info…

Mitigation only
Fix from $1,600 2024-03-22
Security Verify Directory MEDIUM 5.3
CVE-2022-32751

IBM Security Verify Directory 10.0.0 could disclose sensitive server information that could be used in further attacks against the system. IBM X-For…

Mitigation only
Fix from $1,600 2024-03-22
Infosphere Information Server MEDIUM 5.5
CVE-2024-22352

IBM InfoSphere Information Server 11.7 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 28…

Mitigation only
Fix from $1,600 2024-03-21