Vulnerability index

Browse CVEs

2,216 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Collaborative Lifecycle Management MEDIUM 5.5
CVE-2022-34355

IBM Jazz Foundation (IBM Engineering Lifecycle Management 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2) could disclose sensitive version information to a us…

Mitigation only
Fix from $1,600 2023-10-06
Content Navigator MEDIUM 5.4
CVE-2023-40684

IBM Content Navigator 3.0.11, 3.0.13, and 3.0.14 with IBM Daeja ViewOne Virtual is vulnerable to cross-site scripting. This vulnerability allows user…

Mitigation only
Fix from $1,600 2023-10-04
Maximo Application Suite MEDIUM 5.4
CVE-2023-32332

IBM Maximo Application Suite 8.9, 8.10 and IBM Maximo Asset Management 7.6.1.2, 7.6.1.3 are vulnerable to HTML injection. A remote attacker could inj…

Mitigation only
Fix from $1,600 2023-09-08
Sterling External Authentication Server MEDIUM 5.5
CVE-2023-29261

IBM Sterling Secure Proxy 6.0.3 and 6.1.0 could allow a local user with specific information about the system to obtain privileged information due to…

Mitigation only
Fix from $1,600 2023-09-05
Financial Transaction Manager CRITICAL 9.1
CVE-2023-35892

IBM Financial Transaction Manager for SWIFT Services 3.2.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A…

Mitigation only
Fix from $2,300 2023-09-05
Sterling External Authentication Server MEDIUM 5.5
CVE-2023-32338

IBM Sterling Secure Proxy and IBM Sterling External Authentication Server 6.0.3 and 6.1.0 stores user credentials in plain clear text which can be re…

Mitigation only
Fix from $1,600 2023-09-05
Vios MEDIUM 5.5
CVE-2023-40371

IBM AIX 7.2, 7.3, VIOS 3.1's OpenSSH implementation could allow a non-privileged local user to access files outside of those allowed due to improper …

Mitigation only
Fix from $1,600 2023-08-24
Txseries For Multiplatform HIGH 7.5
CVE-2023-33850

IBM GSKit-Crypto could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in the RSA Decryption implement…

Mitigation only
Fix from $1,950 2023-08-22
Txseries For Multiplatform HIGH 7.5
CVE-2023-38741

IBM TXSeries for Multiplatforms 8.1, 8.2, and 9.1 is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual r…

Mitigation only
Fix from $1,950 2023-08-14
Security Verify Governance HIGH 8.8
CVE-2023-35019

IBM Security Verify Governance, Identity Manager 10.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by send…

Mitigation only
Fix from $1,950 2023-07-31
Security Verify Governance MEDIUM 6.5
CVE-2023-35016

IBM Security Verify Governance, Identity Manager 10.0 could allow a remote attacker to traverse directories on the system. An attacker could send a s…

Mitigation only
Fix from $1,600 2023-07-31
Security Verify Access MEDIUM 5.4
CVE-2023-30433

IBM Security Verify Access 10.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to v…

Mitigation only
Fix from $1,600 2023-07-19
Db2 MEDIUM 6.7
CVE-2023-35012

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 with a Federated configuration is vulnerable to a stack-based buffer overflow,…

Mitigation only
Fix from $1,600 2023-07-17
Db2 MEDIUM 6.5
CVE-2023-29256

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to an information disclosure due to improper pri…

Mitigation only
Fix from $1,600 2023-07-10
Cloud Pak For Data HIGH 7.5
CVE-2023-27540

IBM Watson CP4D Data Stores 4.6.0 does not properly allocate resources without limits or throttling which could allow a remote attacker with informat…

Mitigation only
Fix from $1,950 2023-07-10
Websphere Application Server MEDIUM 5.5
CVE-2023-35890

IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security, caused by the improper encoding in a local configuration fi…

No fix yet
Fix from $1,600 2023-07-07
Powervm Hypervisor HIGH 7.5
CVE-2023-25683

IBM PowerVM Hypervisor FW950.00 through FW950.71, FW1010.00 through FW1010.40, FW1020.00 through FW1020.20, and FW1030.00 through FW1030.11 could all…

Mitigation only
Fix from $1,950 2023-06-15
Cics Tx MEDIUM 6.5
CVE-2023-33848

IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11.1 could allow a privileged user to obtain highly…

Mitigation only
Fix from $1,600 2023-06-07
Maximo Application Suite MEDIUM 5.9
CVE-2023-27861

IBM Maximo Application Suite - Manage Component 8.8.0 and 8.9.0 transmits sensitive information in cleartext that could be intercepted by an attacker…

Mitigation only
Fix from $1,600 2023-06-05
Powervm Hypervisor HIGH 7.9
CVE-2023-30440

IBM PowerVM Hypervisor FW860.00 through FW860.B3, FW950.00 through FW950.70, FW1010.00 through FW1010.50, FW1020.00 through FW1020.30, and FW1030.00 …

Mitigation only
Fix from $1,950 2023-05-23
Infosphere Information Server CRITICAL 9.8
CVE-2023-32336

IBM InfoSphere Information Server 11.7 is affected by a remote code execution vulnerability due to insecure deserialization in an RMI service. IBM X…

Mitigation only
Fix from $2,300 2023-05-22
Powervm Hypervisor HIGH 8.8
CVE-2023-30438

An internally discovered vulnerability in PowerVM on IBM Power9 and Power10 systems could allow an attacker with privileged user access to a logical …

Mitigation only
Fix from $1,950 2023-05-17
Security Verify Access HIGH 7.5
CVE-2023-25927

IBM Security Verify Access 10.0.0, 10.0.1, 10.0.2, 10.0.3, 10.0.4, and 10.0.5 could allow an attacker to crash the webseald process using specially c…

Mitigation only
Fix from $1,950 2023-05-12
Cognos Analytics MEDIUM 6.1
CVE-2021-39036

IBM Cognos Analytics 11.1 and 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the W…

Mitigation only
Fix from $1,600 2023-05-12
Maximo Asset Management MEDIUM 5.4
CVE-2022-43866

IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript …

Mitigation only
Fix from $1,600 2023-05-05
I MEDIUM 6.4
CVE-2023-23470

IBM i 7.2, 7.3, 7.4, and 7.5 could allow an authenticated privileged administrator to gain elevated privileges in non-default configurations, as a re…

Mitigation only
Fix from $1,600 2023-05-04
Websphere Application Server MEDIUM 5.3
CVE-2022-39161

IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0, and IBM WebSphere Application Server Liberty, when configured to communicate with the Web Server…

Mitigation only
Fix from $1,600 2023-05-03
Financial Transaction Manager For Multiplatform MEDIUM 5.4
CVE-2022-43871

IBM Financial Transaction Manager for SWIFT Services 3.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary …

Mitigation only
Fix from $1,600 2023-04-29
Vios HIGH 7.8
CVE-2023-26286

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX runtime services library to execute…

Mitigation only
Fix from $1,950 2023-04-26
Cloud Pak For Data HIGH 7.2
CVE-2022-36769

IBM Cloud Pak for Data 4.5 and 4.6 could allow a privileged user to upload malicious files of dangerous types that can be automatically processed wit…

Mitigation only
Fix from $1,950 2023-04-26