Vulnerability index

Browse CVEs

2,216 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Content Navigator MEDIUM 5.4
CVE-2019-4033

IBM Content Navigator 2.0.3 and 3.0CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in th…

Mitigation only
Fix from $1,600 2019-04-25
Sterling B2b Integrator MEDIUM 5.4
CVE-2019-4073

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbi…

Mitigation only
Fix from $1,600 2019-04-25
Sterling B2b Integrator MEDIUM 5.4
CVE-2019-4074

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbi…

Mitigation only
Fix from $1,600 2019-04-25
Sterling B2b Integrator MEDIUM 5.4
CVE-2019-4075

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbi…

Mitigation only
Fix from $1,600 2019-04-25
Sterling B2b Integrator MEDIUM 5.4
CVE-2019-4076

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbi…

Mitigation only
Fix from $1,600 2019-04-25
Sterling B2b Integrator MEDIUM 5.4
CVE-2019-4077

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbi…

Mitigation only
Fix from $1,600 2019-04-25
Bigfix Webui Profile Management CRITICAL 9.8
CVE-2019-4012

IBM BigFix WebUI Profile Management 6 and Software Distribution 23 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL…

Mitigation only
Fix from $2,300 2019-04-15
Qradar Security Information And Event Manager HIGH 8.1
CVE-2019-4210

IBM QRadar SIEM 7.3.2 could allow a user to bypass authentication exposing certain functionality which could lead to information disclosure or modifi…

Mitigation only
Fix from $1,950 2019-04-08
Cloud Private MEDIUM 5.5
CVE-2019-4143

The IBM Cloud Private Key Management Service (IBM Cloud Private 3.1.1 and 3.1.2) could allow a local user to obtain sensitive from the KMS plugin con…

Mitigation only
Fix from $1,600 2019-04-08
Security Privileged Identity Manager HIGH 8.8
CVE-2018-1622

IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute…

Mitigation only
Fix from $1,950 2019-04-02
Security Privileged Identity Manager HIGH 8.8
CVE-2018-1640

IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 could allow a remote authenticated attacker to execute arbitrary commands on the sys…

Mitigation only
Fix from $1,950 2019-04-02
Security Privileged Identity Manager HIGH 7.5
CVE-2018-1618

IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 could allow a remote attacker to traverse directories on the system. An attacker cou…

Mitigation only
Fix from $1,950 2019-04-02
Security Privileged Identity Manager HIGH 7.5
CVE-2018-1680

IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 does not require that users should have strong passwords by default, which makes it …

Mitigation only
Fix from $1,950 2019-04-02
Infosphere Information Server MEDIUM 6.5
CVE-2018-1906

IBM InfoSphere Information Server 11.3, 11.5, and 11.7could allow an authenticated user to download code using a specially crafted HTTP request. IBM …

Mitigation only
Fix from $1,600 2019-04-02
Infosphere Information Server MEDIUM 6.5
CVE-2018-1917

IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow an authenticated user to access JSP files and disclose sensitive information. IBM …

Mitigation only
Fix from $1,600 2019-04-02
Content Navigator MEDIUM 5.4
CVE-2019-4035

IBM Content Navigator 3.0CD could allow attackers to direct web traffic to a malicious site. If attackers make a fake IBM Content Navigator site, the…

Mitigation only
Fix from $1,600 2019-03-22
Power System S922 \(9009 22a\) Firmware MEDIUM 6.4
CVE-2018-1992

The IBM Power 9 OP910, OP920, and FW910 boot firmware's bootloader is responsible for loading and validating the initial boot firmware image that dri…

Mitigation only
Fix from $1,600 2019-03-21
Content Navigator HIGH 8.8
CVE-2019-4034

IBM Content Navigator 3.0CD is could allow an attacker to execute arbitrary code on a user's workstation. When editing an executable file in ICN with…

Mitigation only
Fix from $1,950 2019-03-14
Infosphere Information Governance Catalog MEDIUM 6.1
CVE-2018-1875

IBM InfoSphere Information Governance Catalog 11.3, 11.5, and 11.7 could allow a remote attacker to conduct phishing attacks, using an open redirect …

Mitigation only
Fix from $1,600 2019-03-05
Cloud Private MEDIUM 6.1
CVE-2018-1939

IBM Cloud Private 3.1.1 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a s…

Mitigation only
Fix from $1,600 2019-03-05
Infosphere Information Server CRITICAL 9.1
CVE-2018-1727

IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A…

Mitigation only
Fix from $2,300 2019-02-15
Infosphere Information Governance Catalog MEDIUM 5.4
CVE-2018-1895

IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Java…

Mitigation only
Fix from $1,600 2019-02-15
I MEDIUM 6.1
CVE-2019-4040

IBM I 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alteri…

Mitigation only
Fix from $1,600 2019-01-31
Spss Analytic Server MEDIUM 5.4
CVE-2018-1772

IBM SPSS Analytic Server 3.1.1.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web…

Mitigation only
Fix from $1,600 2019-01-15
Event Streams MEDIUM 5.3
CVE-2018-1833

IBM Event Streams 2018.3.0 could allow a remote attacker to submit an API request with a fake Host request header. An attacker, who has already gaine…

Mitigation only
Fix from $1,600 2018-12-18
Marketing Platform HIGH 7.1
CVE-2018-1424

IBM Marketing Platform 9.1.0, 9.1.2, and 10.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attack…

Mitigation only
Fix from $1,950 2018-12-07
Marketing Platform HIGH 7.1
CVE-2018-1920

IBM Marketing Platform 9.1.0, 9.1.2 and 10.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacke…

Mitigation only
Fix from $1,950 2018-12-07
I2 Enterprise Insight Analysis MEDIUM 6.1
CVE-2018-1504

IBM i2 Enterprise Insight Analysis 2.1.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a…

Mitigation only
Fix from $1,600 2018-12-06
I2 Enterprise Insight Analysis MEDIUM 5.9
CVE-2018-1525

IBM i2 Enterprise Insight Analysis 2.1.7 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP…

Mitigation only
Fix from $1,600 2018-12-06
Cloud Private MEDIUM 5.5
CVE-2018-1841

IBM Cloud Private 2.1.0 could allow a local user to obtain the CA Private Key due to it being world readable in boot/master node. IBM X-Force ID: 150…

Mitigation only
Fix from $1,600 2018-11-19