Vulnerability index

Browse CVEs

2,216 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Engineering Lifecycle Optimization MEDIUM 5.4
CVE-2021-20507

IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScrip…

Mitigation only
Fix from $1,600 2021-07-19
Infosphere Master Data Management Server MEDIUM 6.5
CVE-2020-4675

IBM InfoSphere Master Data Management Server 11.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and …

Mitigation only
Fix from $1,600 2021-07-16
Cloud Pak For Applications MEDIUM 5.4
CVE-2021-20361

IBM Cloud Pak for Applications 4.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the W…

Mitigation only
Fix from $1,600 2021-07-13
Cloud Pak For Applications MEDIUM 5.4
CVE-2021-20362

IBM Cloud Pak for Applications 4.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the W…

Mitigation only
Fix from $1,600 2021-07-13
Cloud Pak For Applications MEDIUM 5.4
CVE-2021-20363

IBM Cloud Pak for Applications 4.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the W…

Mitigation only
Fix from $1,600 2021-07-13
Cloud Pak For Applications MEDIUM 5.4
CVE-2021-20364

IBM Cloud Pak for Applications 4.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the W…

Mitigation only
Fix from $1,600 2021-07-13
Cloud Pak For Applications MEDIUM 5.4
CVE-2021-20365

IBM Cloud Pak for Applications 4.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the W…

Mitigation only
Fix from $1,600 2021-07-13
Cloud Pak For Applications HIGH 7.5
CVE-2021-20360

IBM Cloud Pak for Applications 4.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive inform…

Mitigation only
Fix from $1,950 2021-07-13
Event Streams HIGH 7.2
CVE-2021-29792

IBM Event Streams 10.0, 10.1, 10.2, and 10.3 could allow a user the CA private key to create their own certificates and deploy them in the cluster an…

Mitigation only
Fix from $1,950 2021-07-12
Planning Analytics MEDIUM 5.4
CVE-2021-20477

IBM Planning Analytics 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI th…

Mitigation only
Fix from $1,600 2021-06-29
Financial Transaction Manager CRITICAL 9.1
CVE-2020-5003

IBM Financial Transaction Manager 3.2.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker co…

Mitigation only
Fix from $2,300 2021-06-11
Security Verify Access HIGH 7.8
CVE-2021-29665

IBM Security Verify Access 20.07 is vulnerable to a stack based buffer overflow, caused by improper bounds checking which could allow a local attacke…

Mitigation only
Fix from $1,950 2021-06-01
Security Verify Access MEDIUM 5.3
CVE-2021-20585

IBM Security Verify Access 20.07 could disclose sensitive information in HTTP server headers that could be used in further attacks against the system…

Mitigation only
Fix from $1,600 2021-06-01
Power9 System Firmware CRITICAL 9.1
CVE-2021-20487

IBM Power9 Self Boot Engine(SBE) could allow a privileged user to inject malicious code and compromise the integrity of the host firmware bypassing t…

Mitigation only
Fix from $2,300 2021-05-26
Db2 HIGH 7.8
CVE-2019-4588

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to execute arbitrary code …

Mitigation only
Fix from $1,950 2021-05-26
Spectrum Scale MEDIUM 6.7
CVE-2021-29708

IBM Spectrum Scale 5.1.0.1 could allow a local with access to the GUI pod container to obtain sensitive cryptographic keys that could allow them to e…

Mitigation only
Fix from $1,600 2021-05-25
8335 Gca Firmware MEDIUM 6.5
CVE-2021-29695

IBM Host firmware for LC-class Systems could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafte…

Mitigation only
Fix from $1,600 2021-05-25
Infosphere Information Server MEDIUM 5.3
CVE-2021-29681

IBM InfoSphere Information Server 11.7 could allow an attacker to obtain sensitive information by injecting parameters into an HTML query. This infor…

Mitigation only
Fix from $1,600 2021-05-21
Security Identity Manager HIGH 8.8
CVE-2021-29686

IBM Security Identity Manager 7.0.2 could allow an authenticated user to bypass security and perform actions that they should not have access to. IBM…

Mitigation only
Fix from $1,950 2021-05-20
Gpfs.tct.server HIGH 7.5
CVE-2020-4850

IBM Spectrum Scale 1.1.1.0 through 1.1.8.4 Transparent Cloud Tiering could allow a remote attacker to obtain sensitive information, caused by the lef…

Mitigation only
Fix from $1,950 2021-05-20
Security Identity Manager MEDIUM 6.5
CVE-2021-29683

IBM Security Identity Manager 7.0.2 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 199998.

Mitigation only
Fix from $1,600 2021-05-20
Security Identity Manager MEDIUM 5.3
CVE-2021-29682

IBM Security Identity Manager 7.0.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned…

Mitigation only
Fix from $1,600 2021-05-20
Security Identity Manager MEDIUM 5.3
CVE-2021-29687

IBM Security Identity Manager 7.0.2 could allow a remote user to enumerate usernames due to a difference of responses from valid and invalid login at…

Mitigation only
Fix from $1,600 2021-05-20
Infosphere Information Server HIGH 7.5
CVE-2021-29747

IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain highly sensitive information due to a vulnerability in the authenticat…

Mitigation only
Fix from $1,950 2021-05-17
Planning Analytics Local HIGH 7.5
CVE-2020-4985

IBM Planning Analytics Local 2.0 could allow an attacker to obtain sensitive information due to accepting body parameters in a query. IBM X-Force ID:…

Mitigation only
Fix from $1,950 2021-05-14
Cloud Pak For Security MEDIUM 5.9
CVE-2021-20564

IBM Cloud Pak for Security (CP4S) 1.4.0.0, 1.5.0.0, 1.5.0.1, 1.6.0.0, and 1.6.0.1 could allow a remote attacker to obtain sensitive information, caus…

Mitigation only
Fix from $1,600 2021-05-14
Cloud Pak For Security MEDIUM 5.3
CVE-2021-20565

IBM Cloud Pak for Security (CP4S) 1.4.0.0, 1.5.0.0, 1.5.0.1, 1.6.0.0, and 1.6.0.1 uses a protection mechanism that relies on the existence or values …

Mitigation only
Fix from $1,600 2021-05-14
Jazz Reporting Service MEDIUM 5.4
CVE-2021-20535

IBM Jazz Reporting Service 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attack…

Mitigation only
Fix from $1,600 2021-05-13
Cloud Pak For Security CRITICAL 9.1
CVE-2021-20538

IBM Cloud Pak for Security (CP4S) 1.5.0.0 and 1.5.0.1 could allow a user to obtain sensitive information or perform actions they should not have acce…

Mitigation only
Fix from $2,300 2021-05-10
Tivoli Storage Manager HIGH 7.0
CVE-2020-28198

The 'id' parameter of IBM Tivoli Storage Manager Version 5 Release 2 (Command Line Administrative Interface, dsmadmc.exe) is vulnerable to an exploit…

No fix yet
Fix from $1,950 2021-05-06