Vulnerability index

Browse CVEs

2,216 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Security Guardium Big Data Intelligence HIGH 7.5
CVE-2019-4310

IBM Security Guardium Big Data Intelligence 4.0 (SonarG) uses an inadequate account lockout setting that could allow a remote attacker to brute force…

Mitigation only
Fix from $1,950 2019-08-20
Informix Dynamic Server HIGH 7.8
CVE-2018-1796

IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user to load malicious libraries and gain root privileges. IBM X-Force ID: 14…

Mitigation only
Fix from $1,950 2019-08-20
Informix Dynamic Server MEDIUM 6.7
CVE-2018-1632

IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges throu…

Mitigation only
Fix from $1,600 2019-08-20
Informix Dynamic Server MEDIUM 6.7
CVE-2018-1633

IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges throu…

Mitigation only
Fix from $1,600 2019-08-20
Informix Dynamic Server MEDIUM 6.7
CVE-2018-1634

IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges throu…

Mitigation only
Fix from $1,600 2019-08-20
Informix Dynamic Server MEDIUM 6.7
CVE-2018-1635

Stack-based buffer overflow in oninit in IBM Informix Dynamic Server Enterprise Edition 12.1 allows an authenticated user to execute predefined code …

Mitigation only
Fix from $1,600 2019-08-20
Informix Dynamic Server MEDIUM 6.7
CVE-2018-1636

Stack-based buffer overflow in oninit in IBM Informix Dynamic Server Enterprise Edition 12.1 allows an authenticated user to execute predefined code …

Mitigation only
Fix from $1,600 2019-08-20
Informix Dynamic Server MEDIUM 6.7
CVE-2018-1630

IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges throu…

Mitigation only
Fix from $1,600 2019-08-20
Informix Dynamic Server MEDIUM 6.7
CVE-2018-1631

IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges throu…

Mitigation only
Fix from $1,600 2019-08-20
Java HIGH 7.8
CVE-2019-4473

Multiple binaries in IBM SDK, Java Technology Edition 7, 7R, and 8 on the AIX platform use insecure absolute RPATHs, which may facilitate code inject…

Mitigation only
Fix from $1,950 2019-08-05
Jazz For Service Management MEDIUM 5.5
CVE-2019-4275

IBM Jazz for Service Management 1.1.3, 1.1.3.1, and 1.1.3.2 could allow an unauthorized local user to create unique catalog names that could cause a …

Mitigation only
Fix from $1,600 2019-08-02
Cloud Private HIGH 7.8
CVE-2019-4415

IBM Cloud Private 3.1.1 and 3.1.2 could allow a local user to obtain elevated privileges due to improper security context constraints. IBM X-Force ID…

Mitigation only
Fix from $1,950 2019-07-25
Cloud Private MEDIUM 5.5
CVE-2019-4116

IBM Cloud Private 2.1.0, 3.1.0, and 3.1.1 could disclose highly sensitive information in installer logs that could be use for further attacks against…

Mitigation only
Fix from $1,600 2019-07-25
Campaign MEDIUM 5.4
CVE-2018-1921

IBM Campaign 9.1.0, 9.1.2, 10.1, and 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code i…

Mitigation only
Fix from $1,600 2019-07-17
Planning Analytics MEDIUM 6.1
CVE-2019-4134

IBM Planning Analytics 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI th…

Mitigation only
Fix from $1,600 2019-07-02
Spectrum Protect Plus MEDIUM 6.7
CVE-2019-4357

When using IBM Spectrum Protect Plus 10.1.0, 10.1.2, and 10.1.3 to protect Oracle, DB2 or MongoDB databases, a redirected restore operation specifyin…

Mitigation only
Fix from $1,600 2019-07-01
Db2 MEDIUM 5.5
CVE-2019-4101

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.1, 10.5, and 11.1 is vulnerable to a denial of service. Users that have both EXE…

Mitigation only
Fix from $1,600 2019-07-01
Infosphere Information Server MEDIUM 5.4
CVE-2019-4237

A Cross-Frame Scripting vulnerability in IBM InfoSphere Information Server 11.3, 11.5, and 11.7 can allow an attacker to load the vulnerable applicat…

Mitigation only
Fix from $1,600 2019-07-01
Db2 MEDIUM 6.7
CVE-2019-4057

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow malicious user with access to the DB2 instanc…

Mitigation only
Fix from $1,600 2019-07-01
Maximo Asset Management HIGH 8.0
CVE-2019-4364

IBM Maximo Asset Management 7.6 is vulnerable to CSV injection, which could allow a remote authenticated attacker to execute arbirary commands on the…

Mitigation only
Fix from $1,950 2019-06-19
Maximo Asset Management MEDIUM 5.4
CVE-2019-4303

IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web …

Mitigation only
Fix from $1,600 2019-06-19
Connections MEDIUM 5.4
CVE-2019-4403

IBM Connections 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alte…

Mitigation only
Fix from $1,600 2019-06-14
Security Information Queue MEDIUM 5.3
CVE-2019-4219

IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, and 1.0.2 generates an error message that includes sensitive information that could be used in fu…

Mitigation only
Fix from $1,600 2019-06-06
Infosphere Information Server HIGH 8.3
CVE-2019-4185

IBM InfoSphere Information Server 11.7.1 containers are vulnerable to privilege escalation due to an insecurely configured component. IBM X-Force ID:…

No fix yet
Fix from $1,950 2019-06-06
Infosphere Information Server On Cloud MEDIUM 5.5
CVE-2019-4220

IBM InfoSphere Information Server 11.7.1.0 stores a common hard coded encryption key that could be used to decrypt sensitive information. IBM X-Force…

Mitigation only
Fix from $1,600 2019-06-06
Sterling B2b Integrator MEDIUM 5.4
CVE-2019-4258

IBM Sterling B2B Integrator 6.0.0.0 and 6.0.0.1 Standard Edition is vulnerable to cross-site scripting. This vulnerability allows users to embed arbi…

Mitigation only
Fix from $1,600 2019-05-01
Content Navigator MEDIUM 6.1
CVE-2019-4092

IBM Content Navigator 2.0.3 and 3.0CD could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victi…

Mitigation only
Fix from $1,600 2019-04-25
Sterling B2b Integrator MEDIUM 5.4
CVE-2019-4148

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbi…

Mitigation only
Fix from $1,600 2019-04-25
Infosphere Information Server MEDIUM 5.4
CVE-2019-4238

IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Java…

Mitigation only
Fix from $1,600 2019-04-25
Sterling B2b Integrator HIGH 7.5
CVE-2018-1720

IBM Sterling B2B Integrator Standard Edition 5.2.0.1, 5.2.6.3_6, 6.0.0.0, and 6.0.0.1 uses weaker than expected cryptographic algorithms that could a…

Mitigation only
Fix from $1,950 2019-04-25