Vulnerability index

Browse CVEs

2,216 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Content Navigator MEDIUM 5.3
CVE-2019-4741

IBM Content Navigator 3.0CD is vulnerable to Server Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requ…

Mitigation only
Fix from $1,600 2020-02-12
Sterling External Authentication Server HIGH 7.8
CVE-2013-0517

A Command Execution Vulnerability exists in IBM Sterling External Authentication Server 2.2.0, 2.3.01, 2.4.0, and 2.4.1 via an unspecified OS command…

Mitigation only
Fix from $1,950 2020-02-11
Infosphere Guardium MEDIUM 5.5
CVE-2012-2204

InfoSphere Guardium aix_ktap module: DoS

No fix yet
Fix from $1,600 2020-02-10
Workflow HIGH 8.1
CVE-2015-0102

IBM Workflow for Bluemix does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to captu…

Mitigation only
Fix from $1,950 2020-02-05
Planning Analytics HIGH 8.8
CVE-2019-4613

IBM Planning Analytics 2.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions tr…

Mitigation only
Fix from $1,950 2020-02-05
Infosphere Information Server HIGH 8.1
CVE-2013-0507

IBM InfoSphere Information Server 8.1, 8.5, 8.7, 9.1 has a Session Fixation Vulnerability

Mitigation only
Fix from $1,950 2020-02-05
Security Access Manager HIGH 7.1
CVE-2019-4707

IBM Security Access Manager Appliance 9.0.7.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attac…

Mitigation only
Fix from $1,950 2020-01-28
Jazz Reporting Service CRITICAL 9.8
CVE-2019-4651

IBM Jazz Reporting Service (JRS) 6.0.6.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could a…

Mitigation only
Fix from $2,300 2020-01-09
Cognos Analytics MEDIUM 6.5
CVE-2019-4343

IBM Cognos Analytics 11.0 and 11.1 allows overly permissive cross-origin resource sharing which could allow an attacker to transfer private informati…

Mitigation only
Fix from $1,600 2019-12-30
Cognos Analytics MEDIUM 5.4
CVE-2019-4623

IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the W…

Mitigation only
Fix from $1,600 2019-12-30
Cognos Business Intelligence HIGH 8.8
CVE-2018-1934

IBM Cognos Business Intelligence 10.2.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthoriz…

Mitigation only
Fix from $1,950 2019-12-20
Api Connect HIGH 7.5
CVE-2019-4609

IBM API Connect 2018.4.1.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. I…

Mitigation only
Fix from $1,950 2019-12-18
Db2 High Performance Unload Load HIGH 7.8
CVE-2019-4606

IBM DB2 High Performance Unload load for LUW 6.1 and 6.5 could allow a local attacker to execute arbitrary code on the system, caused by an untrusted…

Mitigation only
Fix from $1,950 2019-12-12
Cloud Pak System CRITICAL 9.8
CVE-2019-4521

Platform System Manager in IBM Cloud Pak System 2.3 is potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on…

Mitigation only
Fix from $2,300 2019-12-10
Planning Analytics HIGH 8.8
CVE-2019-4612

IBM Planning Analytics 2.0 is vulnerable to malicious file upload in the My Account Portal. Attackers can make use of this weakness and upload malici…

Mitigation only
Fix from $1,950 2019-12-09
Security Identity Manager HIGH 8.8
CVE-2019-4561

IBM Security Identity Manager 6.0.0 could allow a remote attacker to execute arbitrary code on the system, caused by the deserialization of untrusted…

Mitigation only
Fix from $1,950 2019-11-20
Maximo Asset Management MEDIUM 6.5
CVE-2019-4530

IBM Maximo Asset Management 7.6, 7.6.1, and 7.6.1.1 could allow an authenticated user to delete a record that they should not normally be able to. IB…

Mitigation only
Fix from $1,600 2019-11-20
Maximo For Oil And Gas HIGH 8.8
CVE-2019-4546

After installing the IBM Maximo Health- Safety and Environment Manager 7.6.1, a user is granted additional privileges that they are not normally allo…

Mitigation only
Fix from $1,950 2019-10-29
Security Access Manager HIGH 7.5
CVE-2019-4036

IBM Security Access Manager Appliance could allow unauthenticated attacker to cause a denial of service in the reverse proxy component. IBM X-Force I…

Mitigation only
Fix from $1,950 2019-10-25
Db2 High Performance Unload Load HIGH 7.8
CVE-2019-4523

IBM DB2 High Performance Unload load for LUW 6.1 and 6.5 is vulnerable to a buffer overflow, caused by improper bounds checking which could allow a l…

Mitigation only
Fix from $1,950 2019-10-22
Tivoli Workload Scheduler HIGH 7.8
CVE-2019-4031

IBM Workload Scheduler Distributed 9.2, 9.3, 9.4, and 9.5 contains a vulnerability that could allow a local user to write files as root in the file s…

Mitigation only
Fix from $1,950 2019-10-16
Content Navigator MEDIUM 5.4
CVE-2019-4571

IBM Content Navigator 3.0CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI t…

Mitigation only
Fix from $1,600 2019-09-25
Jazz For Service Management MEDIUM 6.1
CVE-2019-4186

IBM Jazz for Service Management 1.1.3 is vulnerable to HTTP header injection, caused by incorrect trust in the HTTP Host header during caching. By se…

Mitigation only
Fix from $1,600 2019-09-05
Cloud Automation Manager MEDIUM 5.2
CVE-2019-4133

IBM Cloud Automation Manager 3.1.2 could allow a malicious user on the client side (with access to client computer) to run a custom script. IBM X-For…

Mitigation only
Fix from $1,600 2019-08-29
Open Power CRITICAL 9.1
CVE-2019-4169

IBM Open Power Firmware OP910 and OP920 could allow access to BMC via IPMI using default OpenBMC password even after BMC password was changed away fr…

Mitigation only
Fix from $2,300 2019-08-26
Security Access Manager For Enterprise Single Sign On HIGH 8.2
CVE-2019-4513

IBM Security Access Manager for Enterprise Single Sign-On 8.2.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML da…

Mitigation only
Fix from $1,950 2019-08-26
Security Guardium Big Data Intelligence HIGH 8.2
CVE-2019-4340

IBM Security Guardium Big Data Intelligence 4.0 (SonarG) is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A r…

Mitigation only
Fix from $1,950 2019-08-20
Security Guardium Big Data Intelligence HIGH 7.5
CVE-2019-4338

IBM Security Guardium Big Data Intelligence 4.0 (SonarG) does not properly restrict the size or amount of resources that are requested or influenced …

Mitigation only
Fix from $1,950 2019-08-20
Infosphere Global Name Management HIGH 8.2
CVE-2019-4433

IBM InfoSphere Global Name Management 5.0 and 6.0 and IBM InfoSphere Identity Insight 8.1 and 9.0 is vulnerable to an XML External Entity Injection (…

Mitigation only
Fix from $1,950 2019-08-20
Informix Dynamic Server HIGH 7.8
CVE-2019-4253

IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local privileged Informix user to load a malicious shared library and gain root acc…

Mitigation only
Fix from $1,950 2019-08-20