Vulnerability index

Browse CVEs

2,216 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.5 CVE-2022-34355 IBM Jazz Foundation (IBM Engineering Lifecycle Management 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2) could disclose sensitive version information to a us… Collaborative Lifecycle Management Mitigation only Fix from $1,6002023-10-06 MEDIUM 5.4 CVE-2023-40684 IBM Content Navigator 3.0.11, 3.0.13, and 3.0.14 with IBM Daeja ViewOne Virtual is vulnerable to cross-site scripting. This vulnerability allows user… Content Navigator Mitigation only Fix from $1,6002023-10-04 MEDIUM 5.4 CVE-2023-32332 IBM Maximo Application Suite 8.9, 8.10 and IBM Maximo Asset Management 7.6.1.2, 7.6.1.3 are vulnerable to HTML injection. A remote attacker could inj… Maximo Application Suite Mitigation only Fix from $1,6002023-09-08 MEDIUM 5.5 CVE-2023-29261 IBM Sterling Secure Proxy 6.0.3 and 6.1.0 could allow a local user with specific information about the system to obtain privileged information due to… Sterling External Authentication Server Mitigation only Fix from $1,6002023-09-05 CRITICAL 9.1 CVE-2023-35892 IBM Financial Transaction Manager for SWIFT Services 3.2.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A… Financial Transaction Manager Mitigation only Fix from $2,3002023-09-05 MEDIUM 5.5 CVE-2023-32338 IBM Sterling Secure Proxy and IBM Sterling External Authentication Server 6.0.3 and 6.1.0 stores user credentials in plain clear text which can be re… Sterling External Authentication Server Mitigation only Fix from $1,6002023-09-05 MEDIUM 5.5 CVE-2023-40371 IBM AIX 7.2, 7.3, VIOS 3.1's OpenSSH implementation could allow a non-privileged local user to access files outside of those allowed due to improper … Vios Mitigation only Fix from $1,6002023-08-24 HIGH 7.5 CVE-2023-33850 IBM GSKit-Crypto could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in the RSA Decryption implement… Txseries For Multiplatform Mitigation only Fix from $1,9502023-08-22 HIGH 7.5 CVE-2023-38741 IBM TXSeries for Multiplatforms 8.1, 8.2, and 9.1 is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual r… Txseries For Multiplatform Mitigation only Fix from $1,9502023-08-14 HIGH 8.8 CVE-2023-35019 IBM Security Verify Governance, Identity Manager 10.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by send… Security Verify Governance Mitigation only Fix from $1,9502023-07-31 MEDIUM 6.5 CVE-2023-35016 IBM Security Verify Governance, Identity Manager 10.0 could allow a remote attacker to traverse directories on the system. An attacker could send a s… Security Verify Governance Mitigation only Fix from $1,6002023-07-31 MEDIUM 5.4 CVE-2023-30433 IBM Security Verify Access 10.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to v… Security Verify Access Mitigation only Fix from $1,6002023-07-19 MEDIUM 6.7 CVE-2023-35012 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 with a Federated configuration is vulnerable to a stack-based buffer overflow,… Db2 Mitigation only Fix from $1,6002023-07-17 MEDIUM 6.5 CVE-2023-29256 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to an information disclosure due to improper pri… Db2 Mitigation only Fix from $1,6002023-07-10 HIGH 7.5 CVE-2023-27540 IBM Watson CP4D Data Stores 4.6.0 does not properly allocate resources without limits or throttling which could allow a remote attacker with informat… Cloud Pak For Data Mitigation only Fix from $1,9502023-07-10 MEDIUM 5.5 CVE-2023-35890 IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security, caused by the improper encoding in a local configuration fi… Websphere Application Server No fix yet Fix from $1,6002023-07-07 HIGH 7.5 CVE-2023-25683 IBM PowerVM Hypervisor FW950.00 through FW950.71, FW1010.00 through FW1010.40, FW1020.00 through FW1020.20, and FW1030.00 through FW1030.11 could all… Powervm Hypervisor Mitigation only Fix from $1,9502023-06-15 MEDIUM 6.5 CVE-2023-33848 IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11.1 could allow a privileged user to obtain highly… Cics Tx Mitigation only Fix from $1,6002023-06-07 MEDIUM 5.9 CVE-2023-27861 IBM Maximo Application Suite - Manage Component 8.8.0 and 8.9.0 transmits sensitive information in cleartext that could be intercepted by an attacker… Maximo Application Suite Mitigation only Fix from $1,6002023-06-05 HIGH 7.9 CVE-2023-30440 IBM PowerVM Hypervisor FW860.00 through FW860.B3, FW950.00 through FW950.70, FW1010.00 through FW1010.50, FW1020.00 through FW1020.30, and FW1030.00 … Powervm Hypervisor Mitigation only Fix from $1,9502023-05-23 CRITICAL 9.8 CVE-2023-32336 IBM InfoSphere Information Server 11.7 is affected by a remote code execution vulnerability due to insecure deserialization in an RMI service. IBM X… Infosphere Information Server Mitigation only Fix from $2,3002023-05-22 HIGH 8.8 CVE-2023-30438 An internally discovered vulnerability in PowerVM on IBM Power9 and Power10 systems could allow an attacker with privileged user access to a logical … Powervm Hypervisor Mitigation only Fix from $1,9502023-05-17 HIGH 7.5 CVE-2023-25927 IBM Security Verify Access 10.0.0, 10.0.1, 10.0.2, 10.0.3, 10.0.4, and 10.0.5 could allow an attacker to crash the webseald process using specially c… Security Verify Access Mitigation only Fix from $1,9502023-05-12 MEDIUM 6.1 CVE-2021-39036 IBM Cognos Analytics 11.1 and 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the W… Cognos Analytics Mitigation only Fix from $1,6002023-05-12 MEDIUM 5.4 CVE-2022-43866 IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript … Maximo Asset Management Mitigation only Fix from $1,6002023-05-05 MEDIUM 6.4 CVE-2023-23470 IBM i 7.2, 7.3, 7.4, and 7.5 could allow an authenticated privileged administrator to gain elevated privileges in non-default configurations, as a re… I Mitigation only Fix from $1,6002023-05-04 MEDIUM 5.3 CVE-2022-39161 IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0, and IBM WebSphere Application Server Liberty, when configured to communicate with the Web Server… Websphere Application Server Mitigation only Fix from $1,6002023-05-03 MEDIUM 5.4 CVE-2022-43871 IBM Financial Transaction Manager for SWIFT Services 3.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary … Financial Transaction Manager For Multiplatform Mitigation only Fix from $1,6002023-04-29 HIGH 7.8 CVE-2023-26286 IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX runtime services library to execute… Vios Mitigation only Fix from $1,9502023-04-26 HIGH 7.2 CVE-2022-36769 IBM Cloud Pak for Data 4.5 and 4.6 could allow a privileged user to upload malicious files of dangerous types that can be automatically processed wit… Cloud Pak For Data Mitigation only Fix from $1,9502023-04-26