Vulnerability index

Browse CVEs

2,216 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Db2 HIGH 7.5
CVE-2021-39002

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 uses weaker than expected cryptographic algorithms …

Mitigation only
Fix from $1,950 2021-12-09
Db2 MEDIUM 6.5
CVE-2021-38931

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1, and 11.5 is vulnerable to an information disclosure as a result of a connecte…

Mitigation only
Fix from $1,600 2021-12-09
Db2 MEDIUM 5.5
CVE-2021-38926

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to gain privileges due to …

Mitigation only
Fix from $1,600 2021-12-09
Vios MEDIUM 6.2
CVE-2021-29861

IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in EFS to expose sensitive information. IBM X-Force…

Mitigation only
Fix from $1,600 2021-11-17
Spss Statistics MEDIUM 5.5
CVE-2021-38959

IBM SPSS Statistics for Windows 24.0, 25.0, 26.0, 27.0, 27.0.1, and 28.0 could allow a local user to cause a denial of service by writing arbitrary f…

Mitigation only
Fix from $1,600 2021-11-17
Vios MEDIUM 6.2
CVE-2021-29860

IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the libc.a library to expose sensitive informati…

Mitigation only
Fix from $1,600 2021-11-17
System X3550 M3 Firmware HIGH 8.8
CVE-2021-3723

A command injection vulnerability was reported in the Integrated Management Module (IMM) of legacy IBM System x 3550 M3 and IBM System x 3650 M3 serv…

Mitigation only
Fix from $1,950 2021-11-12
Security Siteprotector System MEDIUM 5.3
CVE-2020-4146

IBM Security SiteProtector System 3.1.1 could allow a remote attacker to obtain sensitive information, caused by missing 'HttpOnly' flag. A remote at…

Mitigation only
Fix from $1,600 2021-11-12
Security Guardium MEDIUM 5.4
CVE-2021-29735

IBM Security Guardium 10.5, 10.6, 11.0, 11.1, 11.2, and 11.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar…

Mitigation only
Fix from $1,600 2021-11-08
Business Automation Workflow MEDIUM 5.9
CVE-2021-29753

IBM Business Automation Workflow 18. 19, 20, 21, and IBM Business Process Manager 8.5 and d8.6 transmits or stores authentication credentials, but it…

Mitigation only
Fix from $1,600 2021-11-05
Data Risk Manager HIGH 7.5
CVE-2021-38862

IBM Data Risk Manager (iDNA) 2.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive inform…

Mitigation only
Fix from $1,950 2021-10-12
Data Risk Manager MEDIUM 6.5
CVE-2021-38915

IBM Data Risk Manager 2.0.6 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 209947.

Mitigation only
Fix from $1,600 2021-10-12
App Connect Enterprise Certified Container MEDIUM 5.5
CVE-2021-29906

IBM App Connect Enterprise Certified Container 1.0, 1.1, 1.2, 1.3, 1.4 and 1.5 could disclose sensitive information to a local user when it is config…

Mitigation only
Fix from $1,600 2021-10-08
Ts7700 Firmware CRITICAL 9.8
CVE-2021-29908

The IBM TS7700 Management Interface is vulnerable to unauthenticated access. By accessing a specially-crafted URL, an attacker may gain administrativ…

Mitigation only
Fix from $2,300 2021-10-06
Powervm Hypervisor Firmware CRITICAL 9.1
CVE-2021-38923

IBM PowerVM Hypervisor FW1010 could allow a privileged user to gain access to another VM due to assigning duplicate WWPNs. IBM X-Force ID: 210162.

Mitigation only
Fix from $2,300 2021-10-06
Aspera On Cloud MEDIUM 5.4
CVE-2021-38870

IBM Aspera Cloud is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus …

Mitigation only
Fix from $1,600 2021-09-23
Db2 HIGH 7.5
CVE-2021-29825

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could disclose sensitive information when using ADMIN_CMD with LOAD or BACKUP. IBM …

Mitigation only
Fix from $1,950 2021-09-16
Db2 MEDIUM 5.1
CVE-2021-29763

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 under very specific conditions, could allow a local user to keep runn…

Mitigation only
Fix from $1,600 2021-09-16
Security Guardium MEDIUM 6.5
CVE-2021-20433

IBM Security Guardium 11.3 could allow a an authenticated user to obtain sensitive information that could be used in further attacks against the syst…

Mitigation only
Fix from $1,600 2021-09-15
Financial Transaction Manager MEDIUM 5.4
CVE-2021-29841

IBM Financial Transaction Manager 3.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in …

Mitigation only
Fix from $1,600 2021-09-14
Security Guardium CRITICAL 9.8
CVE-2021-20418

IBM Security Guardium 11.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise use…

Mitigation only
Fix from $2,300 2021-08-11
Security Guardium HIGH 7.5
CVE-2021-20427

IBM Security Guardium 11.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Fo…

Mitigation only
Fix from $1,950 2021-08-11
Content Navigator MEDIUM 6.5
CVE-2021-29714

IBM Content Navigator 3.0.CD could allow a malicious user to cause a denial of service due to improper input validation. IBM X-Force ID: 200968.

Mitigation only
Fix from $1,600 2021-08-09
Tivoli Workload Scheduler MEDIUM 5.3
CVE-2021-20349

IBM Tivoli Workload Scheduler 9.4 and 9.5 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local attacker could …

Mitigation only
Fix from $1,600 2021-08-09
Powervm HIGH 7.5
CVE-2021-29765

IBM PowerVM Hypervisor FW940 and FW950 could allow an attacker to obtain sensitive information if they gain service access to the FSP. IBM X-Force ID…

Mitigation only
Fix from $1,950 2021-08-04
Cloud Pak For Security HIGH 7.2
CVE-2021-29696

IBM Cloud Pak for Security (CP4S) 1.5.0.0, 1.5.1.0, 1.6.0.0, 1.6.1.0, 1.7.0.0, and 1.7.1.0 could allow a remote authenticated attacker to execute arb…

Mitigation only
Fix from $1,950 2021-08-02
Engineering Lifecycle Optimization Engineering Insights MEDIUM 6.3
CVE-2020-4974

IBM Jazz Foundation products are vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requ…

No fix yet
Fix from $1,600 2021-07-28
Engineering Lifecycle Optimization Engineering Insights MEDIUM 5.4
CVE-2020-5004

IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI…

Mitigation only
Fix from $1,600 2021-07-28
Hardware Management Console HIGH 7.8
CVE-2021-29707

IBM HMC (Hardware Management Console) V9.1.910.0 and V9.2.950.0 could allow a local user to escalate their privileges to root access on a restricted …

Mitigation only
Fix from $1,950 2021-07-19
Engineering Lifecycle Optimization MEDIUM 5.4
CVE-2020-5031

IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScrip…

Mitigation only
Fix from $1,600 2021-07-19