Vulnerability index

Browse CVEs

2,216 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Resilient Security Orchestration Automation And Response HIGH 8.8
CVE-2020-4633

IBM Resilient SOAR V38.0 could allow a remote attacker to execute arbitrary code on the system, caused by formula injection due to improper input val…

Mitigation only
Fix from $1,950 2020-12-11
Content Navigator MEDIUM 5.4
CVE-2020-4704

IBM Content Navigator 3.0CD is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the W…

Mitigation only
Fix from $1,600 2020-11-10
Content Navigator MEDIUM 5.4
CVE-2020-4760

IBM Content Navigator 3.0CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI t…

Mitigation only
Fix from $1,600 2020-11-10
Security Guardium Big Data Intelligence HIGH 7.5
CVE-2020-4254

IBM Security Guardium Big Data Intelligence 1.0 (SonarG) uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt h…

Mitigation only
Fix from $1,950 2020-10-16
Resilient Security Orchestration Automation And Response HIGH 7.2
CVE-2020-4636

IBM Resilient OnPrem 38.2 could allow a privileged user to inject malicious commands through Python3 scripting. IBM X-Force ID: 185503.

Mitigation only
Fix from $1,950 2020-10-16
Curam Social Program Management HIGH 8.1
CVE-2020-4779

A HTTP Verb Tampering vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10. By sending a specially-crafted request, an attac…

Mitigation only
Fix from $1,950 2020-10-12
Curam Social Program Management HIGH 7.5
CVE-2020-4778

IBM Curam Social Program Management 7.0.9 and 7.0.10 uses MD5 algorithm for hashing token in a single instance which less safe than default SHA-256 c…

Mitigation only
Fix from $1,950 2020-10-12
Curam Social Program Management MEDIUM 6.5
CVE-2020-4781

An improper input validation before calling java readLine() method may impact IBM Curam Social Program Management 7.0.9 and 7.0.10, which could resul…

Mitigation only
Fix from $1,600 2020-10-12
Curam Social Program Management MEDIUM 5.3
CVE-2020-4780

OOTB build scripts does not set the secure attribute on session cookie which may impact IBM Curam Social Program Management 7.0.9 and 7.0,10. The pur…

Mitigation only
Fix from $1,600 2020-10-12
Curam Social Program Management HIGH 8.1
CVE-2020-4772

An XML External Entity Injection (XXE) vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10. A remote attacker could exploit…

Mitigation only
Fix from $1,950 2020-10-12
Curam Social Program Management HIGH 7.5
CVE-2020-4776

A path traversal vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10, which could allow a remote attacker to traverse direc…

Mitigation only
Fix from $1,950 2020-10-12
Curam Social Program Management MEDIUM 6.5
CVE-2020-4773

A cross-site request forgery (CSRF) vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10, which is an attack that forces a u…

Mitigation only
Fix from $1,600 2020-10-12
Curam Social Program Management MEDIUM 5.4
CVE-2020-4774

An XPath vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10, caused by the improper handling of user-supplied input. By se…

Mitigation only
Fix from $1,600 2020-10-12
Curam Social Program Management MEDIUM 5.4
CVE-2020-4775

A cross-site scripting (XSS) vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10. This vulnerability allows attackers to in…

Mitigation only
Fix from $1,600 2020-10-12
Security Access Manager MEDIUM 5.3
CVE-2020-4660

IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive using timing side channel attacks…

Mitigation only
Fix from $1,600 2020-10-12
Security Access Manager MEDIUM 5.3
CVE-2020-4661

IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive using timing side channel attacks…

Mitigation only
Fix from $1,600 2020-10-12
Security Access Manager MEDIUM 5.3
CVE-2020-4699

IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive using timing side channel attacks…

Mitigation only
Fix from $1,600 2020-10-12
Infosphere Information Server MEDIUM 6.1
CVE-2020-4727

IBM InfoSphere Information Server 11.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a m…

Mitigation only
Fix from $1,600 2020-09-25
Business Automation Workflow MEDIUM 5.3
CVE-2020-4531

IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.0, 8.5, and 8.6 could allow a remote attacker to obtain sens…

Mitigation only
Fix from $1,600 2020-09-25
Infosphere Metadata Asset Manager MEDIUM 6.5
CVE-2020-4632

IBM InfoSphere Metadata Asset Manager 11.7 is vulnerable to server-side request forgery. By sending a specially crafted request, a remote authenticat…

Mitigation only
Fix from $1,600 2020-09-04
Infosphere Information Server MEDIUM 5.4
CVE-2020-4702

IBM InfoSphere Information Server 11.7 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript co…

Mitigation only
Fix from $1,600 2020-09-04
Doors Next MEDIUM 5.4
CVE-2020-4445

IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in…

Mitigation only
Fix from $1,600 2020-09-02
Doors Next MEDIUM 5.4
CVE-2020-4522

IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in…

Mitigation only
Fix from $1,600 2020-09-02
Doors Next MEDIUM 5.4
CVE-2020-4546

IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in…

Mitigation only
Fix from $1,600 2020-09-02
Infosphere Guardium MEDIUM 5.4
CVE-2012-3341

IBM InfoSphere Guardium 7.0, 8.0, 8.01, and 8.2 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote…

Mitigation only
Fix from $1,600 2020-09-01
Infosphere Guardium MEDIUM 5.3
CVE-2012-3338

IBM InfoSphere Guardium 8.0, 8.01, and 8.2 could allow a remote attacker to bypass security restrictions, caused by improper restrictions on the crea…

Mitigation only
Fix from $1,600 2020-09-01
Infosphere Guardium MEDIUM 5.3
CVE-2012-3337

IBM InfoSphere Guardium 8.0, 8.01, and 8.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-cr…

Mitigation only
Fix from $1,600 2020-09-01
Infosphere Guardium HIGH 8.8
CVE-2012-3336

IBM InfoSphere Guardium 8.0, 8.01, and 8.2 is vulnerable to SQL injection. A remote authenticated attacker could send specially-crafted SQL statement…

Mitigation only
Fix from $1,950 2020-09-01
Connect\ HIGH 7.8
CVE-2020-4587

IBM Sterling Connect:Direct for UNIX 4.2.0, 4.3.0, 6.0.0, and 6.1.0 is vulnerable to a stack based buffer ovreflow, caused by improper bounds checkin…

Mitigation only
Fix from $1,950 2020-08-24
Security Guardium Insights MEDIUM 6.1
CVE-2020-4598

IBM Security Guardium Insights 2.0.1 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim…

Mitigation only
Fix from $1,600 2020-08-24