Vulnerability index

Browse CVEs

2,216 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Security Guardium Insights MEDIUM 5.4
CVE-2020-4165

IBM Security Guardium Insights 2.0.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a mal…

Mitigation only
Fix from $1,600 2020-08-24
Urbancode Deploy HIGH 8.2
CVE-2020-4481

IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML …

Mitigation only
Fix from $1,950 2020-08-05
Financial Transaction Manager MEDIUM 6.1
CVE-2020-4560

IBM Financial Transaction Manager 3.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in …

Mitigation only
Fix from $1,600 2020-08-03
Cognos Analytics CRITICAL 9.1
CVE-2020-4377

IBM Cognos Anaytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could ex…

Mitigation only
Fix from $2,300 2020-08-03
Websphere Application Server HIGH 8.8
CVE-2020-4534

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local authenticated attacker to gain elevated privileges on the system, caused …

Mitigation only
Fix from $1,950 2020-08-03
I2 Analysts Notebook HIGH 7.8
CVE-2020-4549

IBM i2 Analyst Notebook 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a vi…

Mitigation only
Fix from $1,950 2020-08-03
I2 Analysts Notebook HIGH 7.8
CVE-2020-4550

IBM i2 Analyst Notebook 9.2.1 and 9.2.2 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persu…

Mitigation only
Fix from $1,950 2020-08-03
I2 Analysts Notebook HIGH 7.8
CVE-2020-4551

IBM i2 Analyst Notebook 9.2.1 and 9.2.2 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persu…

Mitigation only
Fix from $1,950 2020-08-03
I2 Analysts Notebook HIGH 7.8
CVE-2020-4552

IBM i2 Analyst Notebook 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a vi…

Mitigation only
Fix from $1,950 2020-08-03
I2 Analysts Notebook HIGH 7.8
CVE-2020-4553

IBM i2 Analyst Notebook 9.2.1 and 9.2.2 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persu…

Mitigation only
Fix from $1,950 2020-08-03
I2 Analysts Notebook HIGH 7.8
CVE-2020-4554

IBM i2 Analyst Notebook 9.2.1 and 9.2.2 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persu…

Mitigation only
Fix from $1,950 2020-08-03
Financial Transaction Manager For Multiplatform MEDIUM 6.3
CVE-2020-4328

IBM Financial Transaction Manager 3.2.4 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could al…

Mitigation only
Fix from $1,600 2020-08-03
Cognos Analytics MEDIUM 5.3
CVE-2019-4366

IBM Cognos Analytics 11.0 and 11.1 is susceptible to an information disclosure vulnerability where an attacker could gain access to cached browser da…

Mitigation only
Fix from $1,600 2020-08-03
Sterling External Authentication Server HIGH 8.2
CVE-2020-4462

IBM Sterling External Authentication Server 6.0.1, 6.0.0, 2.4.3.2, and 2.4.2 and IBM Sterling Secure Proxy 6.0.1, 6.0.0, 3.4.3, and 3.4.2 are vulnera…

Mitigation only
Fix from $1,950 2020-07-16
Business Automation Workflow MEDIUM 5.4
CVE-2020-4557

IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.5 and 8.6 are vulnerable to cross-site scripting. This vulne…

Mitigation only
Fix from $1,600 2020-06-29
Maximo Asset Management MEDIUM 6.3
CVE-2019-4650

IBM Maximo Asset Management 7.6.1.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow …

Mitigation only
Fix from $1,600 2020-06-26
Maximo Asset Management MEDIUM 5.4
CVE-2020-4223

IBM Maximo Asset Management 7.6.0.10 and 7.6.1.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript…

Mitigation only
Fix from $1,600 2020-06-26
Security Guardium MEDIUM 5.3
CVE-2020-4188

IBM Security Guardium 10.6 and 11.1 may use insufficiently random numbers or values in a security context that depends on unpredictable numbers. IBM …

Mitigation only
Fix from $1,600 2020-06-23
Doors Next MEDIUM 5.4
CVE-2020-4281

IBM DOORS Next Generation (DNG/RRC) 6.0.2, 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed ar…

Mitigation only
Fix from $1,600 2020-06-19
Doors Next MEDIUM 5.4
CVE-2020-4295

IBM DOORS Next Generation (DNG/RRC) 6.0.2, 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed ar…

Mitigation only
Fix from $1,600 2020-06-19
Doors Next MEDIUM 5.4
CVE-2020-4297

IBM DOORS Next Generation (DNG/RRC) 6.0.2, 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed ar…

Mitigation only
Fix from $1,600 2020-06-19
Workload Scheduler MEDIUM 5.4
CVE-2020-4380

IBM Workload Scheduler 9.3.0.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web U…

Mitigation only
Fix from $1,600 2020-06-11
Security Guardium CRITICAL 9.8
CVE-2020-4193

IBM Security Guardium 11.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Fo…

Mitigation only
Fix from $2,300 2020-06-04
Qradar Security Information And Event Manager HIGH 7.6
CVE-2020-4509

IBM QRadar SIEM 7.3 and 7.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit …

Mitigation only
Fix from $1,950 2020-06-04
Security Guardium MEDIUM 6.1
CVE-2020-4183

IBM Security Guardium 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI th…

Mitigation only
Fix from $1,600 2020-06-04
Mq For Hpe Nonstop HIGH 7.0
CVE-2020-4352

IBM MQ on HPE NonStop 8.0.4 and 8.1.0 is vulnerable to a privilege escalation attack when running in restricted mode. IBM X-Force ID: 178427.

Mitigation only
Fix from $1,950 2020-05-29
Business Automation Workflow MEDIUM 6.1
CVE-2020-4490

IBM Business Automation Workflow 18 and 19, and IBM Business Process Manager 8.0, 8.5, and 8.6 could allow a remote attacker to bypass security restr…

Mitigation only
Fix from $1,600 2020-05-29
I2 Analysts Notebook HIGH 7.8
CVE-2020-4266

IBM i2 Intelligent Analyis Platform 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By per…

Mitigation only
Fix from $1,950 2020-05-14
I2 Analysts Notebook HIGH 7.8
CVE-2020-4285

IBM i2 Intelligent Analyis Platform 9.2.1 could allow a remote attacker to execute arbitrary code on the system, caused by a memory corruption error.…

Mitigation only
Fix from $1,950 2020-05-14
I2 Analysts Notebook HIGH 7.8
CVE-2020-4287

IBM i2 Intelligent Analyis Platform 9.2.1 could allow a remote attacker to execute arbitrary code on the system, caused by a memory corruption error.…

Mitigation only
Fix from $1,950 2020-05-14