Vulnerability index

Browse CVEs

2,216 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Powervm Hypervisor MEDIUM 6.5
CVE-2022-22445

An attacker that gains service access to the FSP (POWER9 only) or gains admin authority to a partition can compromise partition firmware.

Mitigation only
Fix from $1,600 2022-07-18
Engineering Requirements Quality Assistant On Premises MEDIUM 5.4
CVE-2021-29788

IBM Engineering Requirements Quality Assistant On-Premises (All versions) is vulnerable to cross-site scripting. This vulnerability allows users to e…

Mitigation only
Fix from $1,600 2022-07-18
Engineering Requirements Quality Assistant On Premises MEDIUM 5.4
CVE-2021-29790

IBM Engineering Requirements Quality Assistant On-Premises (All versions) is vulnerable to cross-site scripting. This vulnerability allows users to e…

Mitigation only
Fix from $1,600 2022-07-18
Security Siteprotector System CRITICAL 9.8
CVE-2020-4150

IBM SiteProtector Appliance 3.1.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authent…

Mitigation only
Fix from $2,300 2022-07-11
Security Siteprotector System MEDIUM 5.5
CVE-2020-4138

IBM SiteProtector Appliance 3.1.1 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 174049.

Mitigation only
Fix from $1,600 2022-07-11
Security Guardium MEDIUM 6.1
CVE-2021-39074

IBM Security Guardium 11.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI th…

Mitigation only
Fix from $1,600 2022-06-29
Db2 HIGH 7.5
CVE-2022-22390

IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an information disclosure caused by improper privilege manag…

Mitigation only
Fix from $1,950 2022-06-24
Db2 MEDIUM 6.5
CVE-2022-22389

IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may terminate abnormally when …

Mitigation only
Fix from $1,600 2022-06-24
Qradar Wincollect MEDIUM 5.3
CVE-2021-39006

IBM QRadar WinCollect Agent 10.0 and 10.0.1 could allow an attacker to obtain sensitive information due to missing best practices. IBM X-Force ID: 21…

No fix yet
Fix from $1,600 2022-06-21
Jazz Team Server MEDIUM 5.4
CVE-2021-39043

IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arb…

Mitigation only
Fix from $1,600 2022-05-20
Security Identity Manager MEDIUM 5.9
CVE-2020-4970

IBM Security Identity Governance and Intelligence 5.2.4, 5.2.5, and 5.2.6 could allow a remote attacker to obtain sensitive information, caused by th…

Mitigation only
Fix from $1,600 2022-05-19
Robotic Process Automation CRITICAL 9.8
CVE-2022-22413

IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statemen…

Mitigation only
Fix from $2,300 2022-05-12
Spectrum Virtualize CRITICAL 9.8
CVE-2021-38969

IBM Spectrum Virtualize 8.2, 8.3, and 8.4 could allow an attacker to allow unauthorized access due to the reuse of support generated credentials. IBM…

Mitigation only
Fix from $2,300 2022-05-11
Jazz Foundation MEDIUM 5.4
CVE-2021-39059

IBM Jazz Foundation (IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2) is vulnerable to cross-site scripting. This vulnerability allows use…

Mitigation only
Fix from $1,600 2022-05-11
Robotic Process Automation MEDIUM 5.4
CVE-2022-22319

IBM Robotic Process Automation 21.0.1 could allow a register user on the system to physically delete a queue that could cause disruption for any scri…

Mitigation only
Fix from $1,600 2022-05-09
Guardium Data Encryption MEDIUM 5.0
CVE-2021-39027

IBM Guardium Data Encryption (GDE) 4.0.0 and 5.0.0 prepares a structured message for communication with another component, but encoding or escaping o…

No fix yet
Fix from $1,600 2022-05-06
Robotic Process Automation MEDIUM 6.5
CVE-2022-22415

A vulnerability exists where an IBM Robotic Process Automation 21.0.1 regular user is able to obtain view-only access to some admin pages in the Cont…

Mitigation only
Fix from $1,600 2022-05-05
Maximo Application Suite HIGH 7.2
CVE-2021-29854

IBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. B…

Mitigation only
Fix from $1,950 2022-05-03
Cloud Pak For Business Automation MEDIUM 6.8
CVE-2021-29859

IBM ICP4A - User Management System Component (IBM Cloud Pak for Business Automation V21.0.3 through V21.0.3-IF008, V21.0.2 through V21.0.2-IF009, and…

Mitigation only
Fix from $1,600 2022-05-02
Infosphere Information Server MEDIUM 6.5
CVE-2022-22441

IBM InfoSphere Information Server 11.7 could allow an authenticated user to view information of higher privileged users and groups due to a privilege…

Mitigation only
Fix from $1,600 2022-04-28
Infosphere Information Server MEDIUM 6.1
CVE-2022-22427

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…

Mitigation only
Fix from $1,600 2022-04-28
Infosphere Information Server MEDIUM 5.4
CVE-2022-22322

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…

Mitigation only
Fix from $1,600 2022-04-28
Infosphere Information Server MEDIUM 5.4
CVE-2022-22443

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…

Mitigation only
Fix from $1,600 2022-04-28
Infosphere Information Server MEDIUM 5.4
CVE-2021-38952

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…

No fix yet
Fix from $1,600 2022-04-28
Planning Analytics Workspace HIGH 7.8
CVE-2022-22392

IBM Planning Analytics Local 2.0 could allow an attacker to upload arbitrary executable files which, when executed by an unsuspecting victim could re…

Mitigation only
Fix from $1,950 2022-04-25
Planning Analytics Workspace HIGH 8.0
CVE-2021-39040

IBM Planning Analytics Workspace 2.0 could be vulnerable to malicious file upload by not validating the file types or sizes. Attackers can make use o…

Mitigation only
Fix from $1,950 2022-04-25
Security Guardium HIGH 7.5
CVE-2021-39076

IBM Security Guardium 10.5 and 11.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive information.…

Mitigation only
Fix from $1,950 2022-04-19
Security Guardium MEDIUM 5.9
CVE-2021-39072

IBM Security Guardium 11.3 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transp…

Mitigation only
Fix from $1,600 2022-04-19
System Storage Ds8000 Management Console Firmware HIGH 7.5
CVE-2021-38929

IBM System Storage DS8000 Management Console (HMC) R8.5 88.5x.x.x, R9.1 89.1x.0.0, and R9.2 89.2x.0.0 could allow a remote attacker to obtain sensiti…

Mitigation only
Fix from $1,950 2022-04-11
System Storage Ds8000 Management Console Firmware HIGH 7.5
CVE-2021-38930

IBM System Storage DS8000 Management Console (HMC) R8.5 88.5x.x.x, R9.1 89.1x.0.0, and R9.2 89.2x.0.0 could allow a remote attacker to obtain sensiti…

Mitigation only
Fix from $1,950 2022-04-11