Vulnerability index

Browse CVEs

2,216 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Watson Query HIGH 7.2
CVE-2022-22410

IBM Watson Query with Cloud Pak for Data as a Service could allow an authenticated user to obtain sensitive information that would allow them to exam…

Mitigation only
Fix from $1,950 2022-04-06
Iss Blackice Pc Protection CRITICAL 9.8
CVE-2003-5001

A vulnerability was found in ISS BlackICE PC Protection and classified as critical. Affected by this issue is the component Cross Site Scripting Dete…

Mitigation only
Fix from $2,300 2022-03-28
Iss Blackice Pc Protection MEDIUM 6.1
CVE-2003-5003

A vulnerability was found in ISS BlackICE PC Protection. It has been rated as problematic. Affected by this issue is the Update Handler. The manipula…

Mitigation only
Fix from $1,600 2022-03-28
Iss Blackice Pc Protection MEDIUM 5.3
CVE-2003-5002

A vulnerability was found in ISS BlackICE PC Protection. It has been declared as problematic. Affected by this vulnerability is the component Update …

Mitigation only
Fix from $1,600 2022-03-28
Power 9 Ac922 Firmware CRITICAL 9.1
CVE-2022-22374

The BMC (IBM Power 9 AC922 OP910, OP920, OP930, and OP940) may be subject to a firmware downgrade attack which may affect its ability to operate its …

Mitigation only
Fix from $2,300 2022-03-24
Vios MEDIUM 5.5
CVE-2021-38996

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service…

Mitigation only
Fix from $1,600 2022-03-02
Vios MEDIUM 5.5
CVE-2022-22350

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in CAA to cause a denial of service. IBM X-For…

Mitigation only
Fix from $1,600 2022-03-02
Sterling External Authentication Server HIGH 7.5
CVE-2022-22336

IBM Sterling External Authentication Server and IBM Sterling Secure Proxy 6.0.3.0, 6.0.2.0, and 3.4.3.2 could allow a remote user to consume resource…

Mitigation only
Fix from $1,950 2022-02-23
Maximo Anywhere MEDIUM 6.5
CVE-2019-4291

IBM Maximo Anywhere 7.6.4.0 could allow an attacker to reverse engineer the application due to the lack of binary protection precautions. IBM X-Force…

Mitigation only
Fix from $1,600 2022-02-16
Power System Ac922 \(8335 Gtx\) Firmware HIGH 7.5
CVE-2021-38960

IBM OPENBMC OP920, OP930, and OP940 could allow an unauthenticated user to obtain sensitive information. IBM X-Force ID: 212047.

Mitigation only
Fix from $1,950 2022-02-04
Guardium Data Encryption MEDIUM 5.3
CVE-2021-39021

IBM Guardium Data Encryption (GDE) 5.0.0.2 behaves differently or sends different responses under different circumstances in a way that is observable…

Mitigation only
Fix from $1,600 2022-02-02
Security Verify Access CRITICAL 9.8
CVE-2021-39070

IBM Security Verify Access 10.0.0.0, 10.0.1.0 and 10.0.2.0 with the advanced access control authentication service enabled could allow an attacker to…

Mitigation only
Fix from $2,300 2022-02-02
Financial Transaction Manager HIGH 8.8
CVE-2021-39044

IBM Financial Transaction Manager 3.2.4 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthoriz…

Mitigation only
Fix from $1,950 2022-02-02
Financial Transaction Manager HIGH 8.8
CVE-2021-39066

IBM Financial Transaction Manager 3.2.4 does not invalidate session any existing session identifier gives an attacker the opportunity to steal authen…

Mitigation only
Fix from $1,950 2022-02-02
Cognos Controller CRITICAL 9.8
CVE-2020-4877

IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could be vulnerable to unauthorized modifications by using public fields in public classes. IBM X-Fo…

Mitigation only
Fix from $2,300 2022-01-21
Cognos Controller CRITICAL 9.8
CVE-2020-4879

IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could allow a remote attacker to bypass security restrictions, caused by improper validation of auth…

Mitigation only
Fix from $2,300 2022-01-21
Cognos Controller HIGH 8.2
CVE-2020-4875

IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote at…

Mitigation only
Fix from $1,950 2022-01-21
Cognos Controller HIGH 8.2
CVE-2020-4876

IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote at…

Mitigation only
Fix from $1,950 2022-01-21
Vios HIGH 7.8
CVE-2021-38990

IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the mount command which could lead to code execu…

Mitigation only
Fix from $1,950 2022-01-10
Powervm Hypervisor HIGH 7.5
CVE-2021-38918

IBM PowerVM Hypervisor FW860, FW940, FW950, and FW1010, through a specific sequence of VM management operations could lead to a violation of the isol…

Mitigation only
Fix from $1,950 2022-01-05
Power System Ac922 \(8335 Gtg\) Firmware MEDIUM 6.1
CVE-2021-38961

IBM OPENBMC OP910 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alteri…

Mitigation only
Fix from $1,600 2021-12-27
Cloud Pak For Security MEDIUM 6.5
CVE-2021-39013

IBM Cloud Pak for Security (CP4S) 1.7.2.0, 1.7.1.0, and 1.7.0.0 could allow an authenticated user to obtain sensitive information in HTTP responses t…

Mitigation only
Fix from $1,600 2021-12-22
Cloud Pak For Automation MEDIUM 5.4
CVE-2021-38966

IBM Cloud Pak for Automation 21.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the …

Mitigation only
Fix from $1,600 2021-12-21
Power Hardware Management Console \(7063 Cr1\) Firmware MEDIUM 5.9
CVE-2021-29847

BMC firmware (IBM Power System S821LC Server (8001-12C) OP825.50) configuration changed to allow an authenticated user to open an insecure communicat…

Mitigation only
Fix from $1,600 2021-12-15
I2 Analysts Notebook HIGH 7.8
CVE-2021-39050

IBM i2 Analyst's Notebook 9.2.0, 9.2.1, and 9.2.2 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local attacke…

Mitigation only
Fix from $1,950 2021-12-13
I2 Analysts Notebook HIGH 7.8
CVE-2021-39049

IBM i2 Analyst's Notebook 9.2.0, 9.2.1, and 9.2.2 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local attacke…

Mitigation only
Fix from $1,950 2021-12-13
Powervm Hypervisor MEDIUM 6.5
CVE-2021-38937

IBM PowerVM Hypervisor FW940, FW950, and FW1010 could allow an authenticated user to cause the system to crash using a specially crafted IBMi Hypervi…

Mitigation only
Fix from $1,600 2021-12-10
Powervm Hypervisor CRITICAL 9.1
CVE-2021-38917

IBM PowerVM Hypervisor FW860, FW940, and FW950 could allow an attacker that gains service access to the FSP can read and write arbitrary host system …

Mitigation only
Fix from $2,300 2021-12-10
Db2 HIGH 8.7
CVE-2021-29678

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a user with DBADM authority to access o…

Mitigation only
Fix from $1,950 2021-12-09
Websphere Application Server HIGH 7.5
CVE-2021-38951

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote…

Mitigation only
Fix from $1,950 2021-12-09