Vulnerability index

Browse CVEs

2,216 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Sterling Order Management HIGH 8.1
CVE-2022-33959

IBM Sterling Order Management 10.0 could allow a user to bypass validation and perform unauthorized actions on behalf of other users. IBM X-Force ID…

Mitigation only
Fix from $1,950 2023-04-07
Sterling Order Management HIGH 7.5
CVE-2022-34333

IBM Sterling Order Management 10.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compro…

Mitigation only
Fix from $1,950 2023-04-07
Manage Application MEDIUM 6.5
CVE-2022-46774

IBM Manage Application 8.8.0 and 8.9.0 in the IBM Maximo Application Suite is vulnerable to incorrect default permissions which could give access to …

Mitigation only
Fix from $1,600 2023-03-15
App Connect Enterprise Certified Container MEDIUM 6.1
CVE-2022-43874

IBM App Connect Enterprise Certified Container 4.1, 4.2, 5.0, 5.1, 5.2, 6.0, 6.1, 6.2, and 7.0 is vulnerable to cross-site scripting. This vulnerabil…

Mitigation only
Fix from $1,600 2023-03-15
Spectrum Symphony MEDIUM 6.1
CVE-2023-24975

IBM Spectrum Symphony 7.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an att…

Mitigation only
Fix from $1,600 2023-03-10
Maximo Application Suite MEDIUM 5.5
CVE-2022-43923

IBM Maximo Application Suite 8.8.0 and 8.9.0 stores potentially sensitive information that could be read by a local user. IBM X-Force ID: 241584.

Mitigation only
Fix from $1,600 2023-02-24
Spectrum Virtualize HIGH 8.8
CVE-2022-43873

An authenticated user can exploit a vulnerability in the IBM Spectrum Virtualize 8.2, 8.3, 8.4, and 8.5 GUI to execute code and escalate their privil…

Mitigation only
Fix from $1,950 2023-02-22
Spectrum Virtualize MEDIUM 6.5
CVE-2022-43870

IBM Spectrum Virtualize 8.3, 8.4, and 8.5 could disclose SNMPv3 server credentials to an authenticated user in log files. IBM X-Force ID: 239540.

Mitigation only
Fix from $1,600 2023-02-22
Watson Knowledge Catalog On Cloud Pak For Data CRITICAL 9.8
CVE-2022-41731

IBM Watson Knowledge Catalog on Cloud Pak for Data 4.5.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statement…

Mitigation only
Fix from $2,300 2023-02-12
Websphere Application Server CRITICAL 9.8
CVE-2023-23477

IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially craft…

Mitigation only
Fix from $2,300 2023-02-03
Tivoli Workload Scheduler CRITICAL 9.1
CVE-2022-38389

IBM Tivoli Workload Scheduler 9.4, 9.5, and 10.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote at…

Mitigation only
Fix from $2,300 2023-02-03
Tivoli Workload Scheduler CRITICAL 9.1
CVE-2022-22486

IBM Tivoli Workload Scheduler 9.4, 9.5, and 10.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote at…

Mitigation only
Fix from $2,300 2023-02-03
Qradar Security Information And Event Manager HIGH 7.5
CVE-2023-22875

IBM QRadar SIEM 7.4 and 7.5copies certificate key files used for SSL/TLS in the QRadar web user interface to managed hosts in the deployment that do …

Mitigation only
Fix from $1,950 2023-01-17
Maximo Application Suite HIGH 8.8
CVE-2022-35281

IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, 7.6.1.3 and the IBM Maximo Manage 8.3, 8.4 application in IBM Maximo Application Suite are vulnerable t…

Mitigation only
Fix from $1,950 2023-01-09
Db2 HIGH 8.8
CVE-2022-41296

IBM Db2U 3.5, 4.0, and 4.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions tr…

Mitigation only
Fix from $1,950 2022-12-12
Maximo Application Suite MEDIUM 5.5
CVE-2022-41732

IBM Maximo Mobile 8.7 and 8.8 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 237407.

Mitigation only
Fix from $1,600 2022-11-28
Powervm Hypervisor CRITICAL 9.8
CVE-2022-34331

After performing a sequence of Power FW950, FW1010 maintenance operations a SRIOV network adapter can be improperly configured leading to desired VE…

Mitigation only
Fix from $2,300 2022-11-11
Infosphere Information Server MEDIUM 6.5
CVE-2012-4818

IBM InfoSphere Information Server 8.1, 8.5, and 8,7 could allow a remote authenticated attacker to obtain sensitive information, caused by improper r…

Mitigation only
Fix from $1,600 2022-09-29
Websphere Mq HIGH 7.5
CVE-2012-2201

IBM WebSphere MQ 7.1 is vulnerable to a denial of service, caused by an error when handling user ids. A remote attacker could exploit this vulnerabil…

Mitigation only
Fix from $1,950 2022-09-29
Infosphere Information Server MEDIUM 5.4
CVE-2022-40748

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…

Mitigation only
Fix from $1,600 2022-09-23
Maximo Asset Management HIGH 8.1
CVE-2022-40616

IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, and 7.6.1.3 could allow a user to bypass authentication and obtain sensitive information or perform tas…

Mitigation only
Fix from $1,950 2022-09-21
Control Desk MEDIUM 5.3
CVE-2022-22330

IBM Control Desk 7.6.1 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attack…

Mitigation only
Fix from $1,600 2022-09-13
Security Identity Manager MEDIUM 6.1
CVE-2021-29864

IBM Security Identity Manager 6.0 and 6.0.2 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a…

Mitigation only
Fix from $1,600 2022-08-30
Engineering Test Management MEDIUM 5.4
CVE-2021-38934

IBM Engineering Test Management 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaS…

Mitigation only
Fix from $1,600 2022-08-29
Robotic Process Automation For Cloud Pak CRITICAL 9.8
CVE-2022-35280

IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 does not require that users should have strong passwords by default, which makes it easier …

Mitigation only
Fix from $2,300 2022-08-10
Infosphere Information Server HIGH 7.5
CVE-2022-35715

IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is retur…

Mitigation only
Fix from $1,950 2022-08-10
Workload Scheduler HIGH 7.1
CVE-2022-22369

IBM Workload Scheduler 9.4 and 9.5 could allow a local user to overwrite key system files which would cause the system to crash. IBM X-Force ID: 2211…

Mitigation only
Fix from $1,950 2022-08-10
Cics Tx MEDIUM 6.1
CVE-2022-34162

IBM CICS TX 11.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a r…

Mitigation only
Fix from $1,600 2022-08-01
Engineering Requirements Quality Assistant On Premises MEDIUM 6.5
CVE-2021-29799

IBM Engineering Requirements Quality Assistant On-Premises (All versions) could allow an authenticated user to obtain sensitive information due to im…

Mitigation only
Fix from $1,600 2022-07-18
Engineering Requirements Quality Assistant On Premises MEDIUM 6.5
CVE-2021-38868

IBM Engineering Requirements Quality Assistant On-Premises (All versions) is vulnerable to cross-site request forgery which could allow an attacker t…

Mitigation only
Fix from $1,600 2022-07-18