Vulnerability index

Browse CVEs

2,216 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2024-35155 IBM MQ Console 9.3 LTS and 9.3 CD could disclose could allow a remote attacker to obtain sensitive information when a detailed technical error messag… Mq Mitigation only Fix from $1,6002024-06-28 HIGH 8.8 CVE-2024-31912 IBM MQ 9.3 LTS and 9.3 CD could allow an authenticated user to escalate their privileges under certain configurations due to incorrect privilege assi… Mq Mitigation only Fix from $1,9502024-06-28 HIGH 7.5 CVE-2024-31919 IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS and 9.3 CD, in certain configurations, is vulnerable to a denial of service attack caused by an error proce… Mq Mitigation only Fix from $1,9502024-06-28 HIGH 7.5 CVE-2024-31916 IBM OpenBMC FW1050.00 through FW1050.10 BMCWeb HTTPS server component could disclose sensitive URI content to an unauthorized actor that bypasses aut… Openbmc Mitigation only Fix from $1,9502024-06-27 MEDIUM 5.4 CVE-2023-42011 IBM Sterling B2B Integrator Standard Edition 6.1 and 6.2 does not restrict or incorrectly restricts frame objects or UI layers that belong to another… Sterling B2b Integrator Mitigation only Fix from $1,6002024-06-27 HIGH 8.8 CVE-2024-37532 IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to identity spoofing by an authenticated user due to improper signature validation. IBM X… Websphere Application Server Mitigation only Fix from $1,9502024-06-20 HIGH 7.8 CVE-2024-27275 IBM i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability caused by an insufficient authority requirement. A local user withou… I Mitigation only Fix from $1,9502024-06-15 MEDIUM 6.5 CVE-2023-29267 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5is vulnerable to a denial of service, under specific configurat… Db2 Mitigation only Fix from $1,6002024-06-12 MEDIUM 6.5 CVE-2024-31881 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may crash w… Db2 Mitigation only Fix from $1,6002024-06-12 MEDIUM 6.5 CVE-2024-28762 IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted qu… Db2 Mitigation only Fix from $1,6002024-06-12 CRITICAL 9.8 CVE-2023-45188 IBM Engineering Lifecycle Optimization Publishing 7.0.2 and 7.03 could allow a remote attacker to upload arbitrary files, caused by the improper vali… Engineering Lifecycle Optimization Publishing Mitigation only Fix from $2,3002024-06-09 MEDIUM 5.3 CVE-2024-31878 IBM i 7.2, 7.3, 7.4, and 7.5 Service Tools Server (SST) is vulnerable to SST user enumeration by a remote attacker. This vulnerability can be used b… I Mitigation only Fix from $1,6002024-06-07 MEDIUM 6.3 CVE-2024-22326 IBM System Storage DS8900F 89.22.19.0, 89.30.68.0, 89.32.40.0, 89.33.48.0, 89.40.83.0, and 89.40.93.0 could allow a remote user to create an LDAP con… Ds8900f Firmware Mitigation only Fix from $1,6002024-06-06 HIGH 8.2 CVE-2023-45192 IBM Engineering Requirements Management DOORS Next 7.0.2 and 7.0.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML… Doors Next Mitigation only Fix from $1,9502024-06-06 MEDIUM 5.4 CVE-2024-31889 IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in… Planning Analytics Local Mitigation only Fix from $1,6002024-05-31 MEDIUM 5.4 CVE-2024-31907 IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in… Planning Analytics Local Mitigation only Fix from $1,6002024-05-31 MEDIUM 5.4 CVE-2024-31908 IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript … Planning Analytics Local Mitigation only Fix from $1,6002024-05-31 HIGH 8.8 CVE-2023-42005 IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data 3.5, 4.0, 4.5, 4.6, 4.7, and 4.8 could allow a user with access to the Kubernet… Db2 Mitigation only Fix from $1,9502024-05-29 MEDIUM 5.4 CVE-2024-28793 IBM Engineering Workflow Management 7.0.2 and 7.0.3 is vulnerable to stored cross-site scripting. Under certain configurations, this vulnerability al… Engineering Workflow Management Mitigation only Fix from $1,6002024-05-28 MEDIUM 5.4 CVE-2023-47710 IBM Security Guardium 11.4, 11.5, and 12.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code … Security Guardium Mitigation only Fix from $1,6002024-05-24 HIGH 7.8 CVE-2024-27264 IBM Performance Tools for i 7.2, 7.3, 7.4, and 7.5 could allow a local user to gain elevated privileges due to an unqualified library call. A malici… I Mitigation only Fix from $1,9502024-05-22 HIGH 7.5 CVE-2024-31879 IBM i 7.2, 7.3, and 7.4 could allow a remote attacker to execute arbitrary code leading to a denial of service of network ports on the system, caused… I Mitigation only Fix from $1,9502024-05-18 HIGH 8.4 CVE-2024-27260 IBM AIX could 7.2, 7.3, VIOS 3.1, and VIOS 4.1 allow a non-privileged local user to exploit a vulnerability in the invscout command to execute arbitr… Vios Mitigation only Fix from $1,9502024-05-16 MEDIUM 6.8 CVE-2024-27269 IBM QRadar SIEM 7.5 could allow a privileged user to configure user management that would disclose unintended sensitive information across tenants. … Qradar Security Information And Event Manager Mitigation only Fix from $1,6002024-05-14 HIGH 7.5 CVE-2024-22345 IBM TXSeries for Multiplatforms 8.2 transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorize… Txseries For Multiplatform Mitigation only Fix from $1,9502024-05-14 MEDIUM 6.1 CVE-2024-22344 IBM TXSeries for Multiplatforms 8.2 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be … Txseries For Multiplatform Mitigation only Fix from $1,6002024-05-14 HIGH 7.8 CVE-2023-47712 IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a local user to gain elevated privileges on the system due to improper permissions contr… Security Guardium Mitigation only Fix from $1,9502024-05-14 MEDIUM 6.5 CVE-2023-47711 IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow an authenticated user to upload files that would cause a denial of service. IBM X-Force… Security Guardium Mitigation only Fix from $1,6002024-05-14 HIGH 8.8 CVE-2023-47709 IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a… Security Guardium Mitigation only Fix from $1,9502024-05-14 HIGH 7.8 CVE-2024-27273 IBM AIX's Unix domain (AIX 7.2, 7.3, VIOS 3.1, and VIOS 4.1) datagram socket implementation could potentially expose applications using Unix domain d… Vios Mitigation only Fix from $1,9502024-05-07