Vulnerability index

Browse CVEs

2,216 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Infosphere Information Server MEDIUM 5.4
CVE-2023-33843

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…

Mitigation only
Fix from $1,600 2024-02-21
Jazz For Service Management HIGH 7.5
CVE-2023-46186

IBM Jazz for Service Management 1.1.3.20 could allow an unauthorized user to obtain sensitive file information using forced browsing due to improper …

Mitigation only
Fix from $1,950 2024-02-14
Cics Tx HIGH 7.5
CVE-2022-34309

IBM CICS TX Standard and Advanced 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive in…

Mitigation only
Fix from $1,950 2024-02-12
Storage Virtualize HIGH 7.5
CVE-2023-47700

IBM SAN Volume Controller, IBM Storwize, IBM FlashSystem and IBM Storage Virtualize 8.6 products could allow a remote attacker to spoof a trusted sys…

Mitigation only
Fix from $1,950 2024-02-07
Powersc HIGH 7.5
CVE-2023-50962

IBM PowerSC 1.3, 2.0, and 2.1 MFA does not implement the "HTTP Strict Transport Security" (HSTS) web security policy mechanism. IBM X-Force ID: 276…

Mitigation only
Fix from $1,950 2024-02-02
Vios MEDIUM 5.5
CVE-2023-45171

IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the kernel to cause a denial of service. IBM X-…

Mitigation only
Fix from $1,600 2024-01-11
Vios MEDIUM 5.5
CVE-2023-45169

IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the pmsvcs kernel extension to cause a denial of…

Mitigation only
Fix from $1,600 2024-01-11
Vios MEDIUM 5.5
CVE-2023-45175

IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the TCP/IP kernel extension to cause a denial of…

Mitigation only
Fix from $1,600 2024-01-11
Vios MEDIUM 5.5
CVE-2023-45173

IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the NFS kernel extension to cause a denial of se…

Mitigation only
Fix from $1,600 2024-01-11
Cics Transaction Gateway HIGH 8.1
CVE-2023-47140

IBM CICS Transaction Gateway 9.3 could allow a user to transfer or view files due to improper access controls.

Mitigation only
Fix from $1,950 2024-01-08
Financial Transaction Manager HIGH 7.5
CVE-2023-49880

In the Message Entry and Repair (MER) facility of IBM Financial Transaction Manager for SWIFT Services 3.2.4 the sending address and the message type…

Mitigation only
Fix from $1,950 2023-12-25
Aix MEDIUM 5.5
CVE-2023-45165

IBM AIX 7.2 and 7.3 could allow a non-privileged local user to exploit a vulnerability in the AIX SMB client to cause a denial of service. IBM X-For…

Mitigation only
Fix from $1,600 2023-12-22
Planning Analytics CRITICAL 9.8
CVE-2023-42017

IBM Planning Analytics Local 2.0 could allow a remote attacker to upload arbitrary files, caused by the improper validation of file extensions. By s…

Mitigation only
Fix from $2,300 2023-12-22
Informix Jdbc CRITICAL 9.8
CVE-2023-35895

IBM Informix JDBC Driver 4.10 and 4.50 is susceptible to remote code execution attack via JNDI injection when passing an unchecked argument to a cert…

Mitigation only
Fix from $2,300 2023-12-20
Spectrum Scale HIGH 7.5
CVE-2022-43843

IBM Spectrum Scale 5.1.5.0 through 5.1.5.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitiv…

Mitigation only
Fix from $1,950 2023-12-14
Storage Virtualize HIGH 7.5
CVE-2023-43042

IBM SAN Volume Controller, IBM Storwize, IBM FlashSystem and IBM Storage Virtualize 8.3 products use default passwords for a privileged user. IBM X-…

Mitigation only
Fix from $1,950 2023-12-14
Vios HIGH 7.8
CVE-2023-45170

IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the piobe command to escalate privileges or caus…

Mitigation only
Fix from $1,950 2023-12-13
Vios HIGH 7.8
CVE-2023-45174

IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a privileged local user to exploit a vulnerability in the qdaemon command to escalate privileges or cause …

Mitigation only
Fix from $1,950 2023-12-13
Vios HIGH 7.8
CVE-2023-45166

IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the piodmgrsu command to obtain elevated privile…

Mitigation only
Fix from $1,950 2023-12-13
Informix Dynamic Server MEDIUM 5.5
CVE-2023-28526

IBM Informix Dynamic Server 12.10 and 14.10 archecker is vulnerable to a heap buffer overflow, caused by improper bounds checking which could allow a…

Mitigation only
Fix from $1,600 2023-12-09
Informix Dynamic Server MEDIUM 5.5
CVE-2023-28527

IBM Informix Dynamic Server 12.10 and 14.10 cdr is vulnerable to a heap buffer overflow, caused by improper bounds checking which could allow a local…

Mitigation only
Fix from $1,600 2023-12-09
Api Connect MEDIUM 5.5
CVE-2023-47722

IBM API Connect V10.0.5.3 and V10.0.6.0 stores user credentials in browser cache which can be read by a local user. IBM X-Force ID: 271912.

Mitigation only
Fix from $1,600 2023-12-09
Informix Dynamic Server HIGH 7.8
CVE-2023-28523

IBM Informix Dynamic Server 12.10 and 14.10 onsmsync is vulnerable to a heap buffer overflow, caused by improper bounds checking which could allow an…

Mitigation only
Fix from $1,950 2023-12-09
Planning Analytics On Cloud Pak For Data MEDIUM 6.5
CVE-2023-26024

IBM Planning Analytics on Cloud Pak for Data 4.0 could allow an attacker on a shared network to obtain sensitive information caused by insecure netwo…

Mitigation only
Fix from $1,600 2023-12-01
I MEDIUM 5.5
CVE-2023-42006

IBM Administration Runtime Expert for i 7.2, 7.3, 7.4, and 7.5 could allow a local user to obtain sensitive information caused by improper authority …

Mitigation only
Fix from $1,600 2023-12-01
Vios HIGH 7.8
CVE-2023-45168

IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the invscout command to execute arbitrary comman…

Mitigation only
Fix from $1,950 2023-12-01
Security Guardium HIGH 8.8
CVE-2023-42004

IBM Security Guardium 11.3, 11.4, and 11.5 is potentially vulnerable to CSV injection. A remote attacker could execute malicious commands due to imp…

Mitigation only
Fix from $1,950 2023-11-28
Infosphere Information Server MEDIUM 6.5
CVE-2023-40363

IBM InfoSphere Information Server 11.7 could allow an authenticated user to change installation files due to incorrect file permission settings. IBM…

Mitigation only
Fix from $1,600 2023-11-18
Qradar Security Information And Event Manager MEDIUM 5.4
CVE-2023-43057

IBM QRadar SIEM 7.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus al…

Mitigation only
Fix from $1,600 2023-11-11
Vios MEDIUM 5.5
CVE-2023-45167

IBM AIX's 7.3 Python implementation could allow a non-privileged local user to exploit a vulnerability to cause a denial of service. IBM X-Force ID:…

No fix yet
Fix from $1,600 2023-11-10