Vulnerability index

Browse CVEs

2,216 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Cloud Pak For Business Automation CRITICAL 9.8
CVE-2023-35899

IBM Cloud Pak for Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 is po…

Mitigation only
Fix from $2,300 2024-03-21
Security Verify Governance MEDIUM 5.9
CVE-2023-35888

IBM Security Verify Governance 10.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP St…

Mitigation only
Fix from $1,600 2024-03-20
Sterling Secure Proxy MEDIUM 6.1
CVE-2023-47699

IBM Sterling Secure Proxy 6.0.3 and 6.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code i…

Mitigation only
Fix from $1,600 2024-03-15
Sterling Secure Proxy MEDIUM 5.4
CVE-2023-46182

IBM Sterling Secure Proxy 6.0.3 and 6.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code i…

Mitigation only
Fix from $1,600 2024-03-15
Maximo Application Suite HIGH 7.5
CVE-2023-32335

IBM Maximo Application Suite 8.10, 8.11 and IBM Maximo Asset Management 7.6.1.3 stores sensitive information in URL parameters. This may lead to info…

Mitigation only
Fix from $1,950 2024-03-13
Maximo Application Suite MEDIUM 6.4
CVE-2023-38723

IBM Maximo Application Suite 7.6.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code…

Mitigation only
Fix from $1,600 2024-03-13
Maximo Mobile For Eam MEDIUM 5.5
CVE-2023-43043

IBM Maximo Application Suite - Maximo Mobile for EAM 8.10 and 8.11 could disclose sensitive information to a local user. IBM X-Force ID: 266875.

Mitigation only
Fix from $1,600 2024-03-13
Sterling Partner Engagement Manager MEDIUM 5.4
CVE-2023-28517

IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbit…

Mitigation only
Fix from $1,600 2024-03-13
Spss Statistics MEDIUM 5.5
CVE-2022-43855

IBM SPSS Statistics 26.0, 27.0.1, and 28.0 IO Module could allow a local user to create multiple files that could exhaust the file handles capacity a…

Mitigation only
Fix from $1,600 2024-03-08
Ds8900f Firmware CRITICAL 9.8
CVE-2023-46172

IBM DS8900F HMC 89.21.19.0, 89.21.31.0, 89.30.68.0, 89.32.40.0, and 89.33.48.0 could allow a remote attacker to bypass authentication restrictions fo…

Mitigation only
Fix from $2,300 2024-03-07
Ds8900f Firmware MEDIUM 6.5
CVE-2023-46169

IBM DS8900F HMC 89.21.19.0, 89.21.31.0, 89.30.68.0, 89.32.40.0, and 89.33.48.0 could allow an authenticated user to arbitrarily delete a file. IBM X…

Mitigation only
Fix from $1,600 2024-03-07
Ds8900f Firmware MEDIUM 6.5
CVE-2023-46170

IBM DS8900F HMC 89.21.19.0, 89.21.31.0, 89.30.68.0, 89.32.40.0, and 89.33.48.0 could allow an authenticated user to arbitrarily read files after enum…

Mitigation only
Fix from $1,600 2024-03-07
Aspera Faspex MEDIUM 6.5
CVE-2022-22399

IBM Aspera Faspex 5.0.0 and 5.0.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could all…

Mitigation only
Fix from $1,600 2024-03-05
Spectrum Virtualize MEDIUM 6.5
CVE-2023-25681

LDAP users on IBM Spectrum Virtualize 8.5 which are configured to require multifactor authentication can still authenticate to the CIM interface usin…

Mitigation only
Fix from $1,600 2024-03-05
Sterling Connect\ HIGH 7.5
CVE-2023-32331

IBM Connect:Express for UNIX 1.5.0 is vulnerable to a buffer overflow that could allow a remote attacker to cause a denial of service through its bro…

Mitigation only
Fix from $1,950 2024-03-04
Cics Tx MEDIUM 6.1
CVE-2023-38360

IBM CICS TX Advanced 10.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thu…

Mitigation only
Fix from $1,600 2024-03-04
Cics Tx MEDIUM 5.3
CVE-2023-38362

IBM CICS TX Advanced 10.1 could disclose sensitive information to a remote attacker due to observable discrepancy in HTTP responses. IBM X-Force ID:…

Mitigation only
Fix from $1,600 2024-03-04
Watson Cp4d Data Stores HIGH 7.5
CVE-2023-27291

IBM Watson CP4D Data Stores 4.6.0, 4.6.1, 4.6.2, and 4.6.3 does not encrypt sensitive or critical information before storage or transmission which co…

Mitigation only
Fix from $1,950 2024-03-03
Watson Cp4d Data Stores MEDIUM 5.9
CVE-2023-28512

IBM Watson CP4D Data Stores 4.6.0, 4.6.1, and 4.6.2 could allow an attacker with specific knowledge about the system to manipulate data due to improp…

Mitigation only
Fix from $1,600 2024-03-03
Engineering Test Management MEDIUM 5.4
CVE-2023-43054

IBM Engineering Test Management 7.0.2 and 7.0.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary Java…

Mitigation only
Fix from $1,600 2024-03-03
Cp4ba Filenet Content Manager HIGH 8.8
CVE-2023-47716

IBM CP4BA - Filenet Content Manager Component 5.5.8.0, 5.5.10.0, and 5.5.11.0 could allow a user to gain the privileges of another user under unusual…

Mitigation only
Fix from $1,950 2024-03-01
Filenet Content Manager MEDIUM 5.3
CVE-2023-38366

IBM Filenet Content Manager Component 5.5.8.0, 5.5.10.0, and 5.5.11.0 could allow a remote attacker to traverse directories on the system. An attacke…

Mitigation only
Fix from $1,600 2024-03-01
Engineering Requirements Management Doors MEDIUM 6.5
CVE-2023-28949

IBM Engineering Requirements Management DOORS 9.7.2.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious …

Mitigation only
Fix from $1,600 2024-03-01
Cognos Command Center MEDIUM 5.3
CVE-2023-50324

IBM Cognos Command Center 10.2.4.1 and 10.2.5 exposes details the X-AspNet-Version Response Header that could allow an attacker to obtain information…

Mitigation only
Fix from $1,600 2024-03-01
Engineering Requirements Management Doors MEDIUM 5.1
CVE-2023-50305

IBM Engineering Requirements Management DOORS 9.7.2.7 does not require that users should have strong passwords by default, which makes it easier for …

Mitigation only
Fix from $1,600 2024-03-01
Cloud Pak For Business Automation MEDIUM 6.5
CVE-2023-38367

IBM Cloud Pak Foundational Services Identity Provider (idP) API (IBM Cloud Pak for Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1,…

Mitigation only
Fix from $1,600 2024-02-29
Cloud Pak For Data MEDIUM 5.5
CVE-2023-27545

IBM Watson CloudPak for Data Data Stores information disclosure 4.6.0 allows web pages to be stored locally which can be read by another user on the …

Mitigation only
Fix from $1,600 2024-02-29
Watson Iot Platform HIGH 7.5
CVE-2023-38372

An unauthorized attacker who has obtained an IBM Watson IoT Platform 1.0 security authentication token can use it to impersonate an authorized platfo…

Mitigation only
Fix from $1,950 2024-02-29
Infosphere Information Server MEDIUM 6.1
CVE-2023-50303

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…

Mitigation only
Fix from $1,600 2024-02-28
Vios HIGH 8.4
CVE-2024-25021

IBM AIX 7.3, VIOS 4.1's Perl implementation could allow a non-privileged local user to exploit a vulnerability to execute arbitrary commands. IBM X-…

Mitigation only
Fix from $1,950 2024-02-22