Vulnerability index

Browse CVEs

2,216 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Content Navigator MEDIUM 5.4
CVE-2021-20549

IBM Content Navigator 3.0.CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI …

Mitigation only
Fix from $1,600 2021-04-27
Content Navigator MEDIUM 5.4
CVE-2021-20550

IBM Content Navigator 3.0.CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI …

Mitigation only
Fix from $1,600 2021-04-27
Spectrum Protect Plus MEDIUM 6.2
CVE-2021-20536

IBM Spectrum Protect Plus File Systems Agent 10.1.6 and 10.1.7 stores potentially sensitive information in log files that could be read by a local us…

Mitigation only
Fix from $1,600 2021-04-26
Planning Analytics MEDIUM 5.3
CVE-2020-4562

IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information by allowing cross-window communication with unrestricted tar…

Mitigation only
Fix from $1,600 2021-04-26
I HIGH 8.2
CVE-2021-20501

IBM i 7.1, 7.2, 7.3, and 7.4 SMTP allows a network attacker to send emails to non-existent local-domain recipients to the SMTP server, caused by usin…

Mitigation only
Fix from $1,950 2021-04-21
Cloud Pak For Automation HIGH 7.1
CVE-2021-20482

IBM Cloud Pak for Automation 20.0.2 and 20.0.3 IF002 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remo…

Mitigation only
Fix from $1,950 2021-03-30
Urbancode Deploy MEDIUM 5.5
CVE-2020-4884

IBM UrbanCode Deploy (UCD) 6.2.7.9, 7.0.5.4, and 7.1.1.1 stores user credentials in plain in clear text which can be read by a local user. IBM X-Forc…

Mitigation only
Fix from $1,600 2021-03-30
Urbancode Deploy MEDIUM 5.5
CVE-2020-4944

IBM UrbanCode Deploy (UCD) 7.0.3.0, 7.0.4.0, 7.0.5.3, 7.0.5.4, 7.1.0.0, 7.1.1.0, 7.1.1.1, and 7.1.1.2, stores keystore passwords in plain text after …

Mitigation only
Fix from $1,600 2021-03-30
Urbancode Deploy MEDIUM 5.4
CVE-2020-4848

IBM UrbanCode Deploy (UCD) 6.2.7.9, 7.0.5.4, and 7.1.1.1 could allow an authenticated user to initiate a plugin or compare process resources that the…

Mitigation only
Fix from $1,600 2021-03-30
Planning Analytics MEDIUM 6.1
CVE-2020-4882

IBM Planning Analytics 2.0 could be vulnerable to a Server-Side Request Forgery (SSRF) attack by constucting URLs from user-controlled data . This co…

Mitigation only
Fix from $1,600 2021-03-22
Security Guardium HIGH 7.3
CVE-2020-4184

IBM Security Guardium 11.2 performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or…

No fix yet
Fix from $1,950 2021-03-15
Tivoli Netcool\/omnibus Webgui MEDIUM 5.4
CVE-2021-20336

IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code…

Mitigation only
Fix from $1,600 2021-03-11
Spss Modeler MEDIUM 5.5
CVE-2020-4717

A vulnerability exists in IBM SPSS Modeler Subscription Installer that allows a user with create symbolic link permission to write arbitrary file in …

Mitigation only
Fix from $1,600 2021-03-10
Security Verify Information Queue HIGH 8.8
CVE-2021-20403

IBM Security Verify Information Queue 1.0.6 and 1.0.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious …

Mitigation only
Fix from $1,950 2021-02-11
Security Verify Information Queue HIGH 7.5
CVE-2021-20405

IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a user to perform unauthorized activities due to improper encoding of output. IBM X…

Mitigation only
Fix from $1,950 2021-02-11
Security Verify Information Queue MEDIUM 5.3
CVE-2021-20404

IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a user on the network to cause a denial of service due to an invalid cookie value t…

Mitigation only
Fix from $1,600 2021-02-11
Cloud Pak For Automation MEDIUM 6.5
CVE-2021-20358

IBM Cloud Pak for Automation 20.0.3, 20.0.2-IF002 stores potentially sensitive information in clear text in API connection log files. This informatio…

Mitigation only
Fix from $1,600 2021-02-08
Cloud Pak For Automation MEDIUM 6.5
CVE-2021-20359

IBM Cloud Pak for Automation 20.0.3, 20.0.2-IF002 - Business Automation Application Designer Component stores potentially sensitive information in lo…

Mitigation only
Fix from $1,600 2021-02-08
Infosphere Information Server CRITICAL 9.8
CVE-2020-27583

IBM InfoSphere Information Server 8.5.0.0 is affected by deserialization of untrusted data which could allow remote unauthenticated attackers to exec…

No fix yet
Fix from $2,300 2021-01-26
Security Identity Governance And Intelligence CRITICAL 9.8
CVE-2020-4958

IBM Security Identity Governance and Intelligence 5.2.6 does not perform any authentication for functionality that requires a provable user identity …

Mitigation only
Fix from $2,300 2021-01-21
Security Guardium HIGH 8.8
CVE-2020-4921

IBM Security Guardium 10.6 and 11.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow …

Mitigation only
Fix from $1,950 2021-01-20
Security Guardium HIGH 7.8
CVE-2020-4688

IBM Security Guardium 10.6 and 11.2 could allow a local attacker to execute arbitrary commands on the system as an unprivileged user, caused by comma…

Mitigation only
Fix from $1,950 2021-01-20
Vios MEDIUM 5.5
CVE-2020-4887

IBM AIX 7.1, 7.2 and AIX VIOS 3.1 could allow a local user to exploit a vulnerability in the gencore user command to create arbitrary files in any di…

Mitigation only
Fix from $1,600 2021-01-20
Collaborative Lifecycle Management MEDIUM 5.4
CVE-2020-4691

IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI…

Mitigation only
Fix from $1,600 2021-01-08
Collaborative Lifecycle Management MEDIUM 5.4
CVE-2020-4697

IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI…

Mitigation only
Fix from $1,600 2021-01-08
Collaborative Lifecycle Management MEDIUM 5.4
CVE-2020-4733

IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI…

Mitigation only
Fix from $1,600 2021-01-08
Curam Social Program Management HIGH 8.8
CVE-2020-4942

IBM Curam Social Program Management 7.0.9 and 7.0.11 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious a…

Mitigation only
Fix from $1,950 2021-01-04
Db2 MEDIUM 5.5
CVE-2020-4642

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow local attacker to cause a denial of ser…

Mitigation only
Fix from $1,600 2020-12-23
Loopback CRITICAL 9.8
CVE-2020-4988

Loopback 8.0.0 contains a vulnerability that could allow an attacker to manipulate or pollute Javascript values and cause a denial of service or poss…

Mitigation only
Fix from $2,300 2020-12-21
Connect\ CRITICAL 9.8
CVE-2020-4747

IBM Connect:Direct for UNIX 6.1.0, 6.0.0, 4.3.0, and 4.2.0 can allow a local or remote user to obtain an authenticated CLI session due to improper au…

Mitigation only
Fix from $2,300 2020-12-15