Vulnerability index

Browse CVEs

2,216 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2022-22445 An attacker that gains service access to the FSP (POWER9 only) or gains admin authority to a partition can compromise partition firmware. Powervm Hypervisor Mitigation only Fix from $1,6002022-07-18 MEDIUM 5.4 CVE-2021-29788 IBM Engineering Requirements Quality Assistant On-Premises (All versions) is vulnerable to cross-site scripting. This vulnerability allows users to e… Engineering Requirements Quality Assistant On Premises Mitigation only Fix from $1,6002022-07-18 MEDIUM 5.4 CVE-2021-29790 IBM Engineering Requirements Quality Assistant On-Premises (All versions) is vulnerable to cross-site scripting. This vulnerability allows users to e… Engineering Requirements Quality Assistant On Premises Mitigation only Fix from $1,6002022-07-18 CRITICAL 9.8 CVE-2020-4150 IBM SiteProtector Appliance 3.1.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authent… Security Siteprotector System Mitigation only Fix from $2,3002022-07-11 MEDIUM 5.5 CVE-2020-4138 IBM SiteProtector Appliance 3.1.1 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 174049. Security Siteprotector System Mitigation only Fix from $1,6002022-07-11 MEDIUM 6.1 CVE-2021-39074 IBM Security Guardium 11.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI th… Security Guardium Mitigation only Fix from $1,6002022-06-29 HIGH 7.5 CVE-2022-22390 IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an information disclosure caused by improper privilege manag… Db2 Mitigation only Fix from $1,9502022-06-24 MEDIUM 6.5 CVE-2022-22389 IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may terminate abnormally when … Db2 Mitigation only Fix from $1,6002022-06-24 MEDIUM 5.3 CVE-2021-39006 IBM QRadar WinCollect Agent 10.0 and 10.0.1 could allow an attacker to obtain sensitive information due to missing best practices. IBM X-Force ID: 21… Qradar Wincollect No fix yet Fix from $1,6002022-06-21 MEDIUM 5.4 CVE-2021-39043 IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arb… Jazz Team Server Mitigation only Fix from $1,6002022-05-20 MEDIUM 5.9 CVE-2020-4970 IBM Security Identity Governance and Intelligence 5.2.4, 5.2.5, and 5.2.6 could allow a remote attacker to obtain sensitive information, caused by th… Security Identity Manager Mitigation only Fix from $1,6002022-05-19 CRITICAL 9.8 CVE-2022-22413 IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statemen… Robotic Process Automation Mitigation only Fix from $2,3002022-05-12 CRITICAL 9.8 CVE-2021-38969 IBM Spectrum Virtualize 8.2, 8.3, and 8.4 could allow an attacker to allow unauthorized access due to the reuse of support generated credentials. IBM… Spectrum Virtualize Mitigation only Fix from $2,3002022-05-11 MEDIUM 5.4 CVE-2021-39059 IBM Jazz Foundation (IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2) is vulnerable to cross-site scripting. This vulnerability allows use… Jazz Foundation Mitigation only Fix from $1,6002022-05-11 MEDIUM 5.4 CVE-2022-22319 IBM Robotic Process Automation 21.0.1 could allow a register user on the system to physically delete a queue that could cause disruption for any scri… Robotic Process Automation Mitigation only Fix from $1,6002022-05-09 MEDIUM 5.0 CVE-2021-39027 IBM Guardium Data Encryption (GDE) 4.0.0 and 5.0.0 prepares a structured message for communication with another component, but encoding or escaping o… Guardium Data Encryption No fix yet Fix from $1,6002022-05-06 MEDIUM 6.5 CVE-2022-22415 A vulnerability exists where an IBM Robotic Process Automation 21.0.1 regular user is able to obtain view-only access to some admin pages in the Cont… Robotic Process Automation Mitigation only Fix from $1,6002022-05-05 HIGH 7.2 CVE-2021-29854 IBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. B… Maximo Application Suite Mitigation only Fix from $1,9502022-05-03 MEDIUM 6.8 CVE-2021-29859 IBM ICP4A - User Management System Component (IBM Cloud Pak for Business Automation V21.0.3 through V21.0.3-IF008, V21.0.2 through V21.0.2-IF009, and… Cloud Pak For Business Automation Mitigation only Fix from $1,6002022-05-02 MEDIUM 6.5 CVE-2022-22441 IBM InfoSphere Information Server 11.7 could allow an authenticated user to view information of higher privileged users and groups due to a privilege… Infosphere Information Server Mitigation only Fix from $1,6002022-04-28 MEDIUM 6.1 CVE-2022-22427 IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t… Infosphere Information Server Mitigation only Fix from $1,6002022-04-28 MEDIUM 5.4 CVE-2022-22322 IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t… Infosphere Information Server Mitigation only Fix from $1,6002022-04-28 MEDIUM 5.4 CVE-2022-22443 IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t… Infosphere Information Server Mitigation only Fix from $1,6002022-04-28 MEDIUM 5.4 CVE-2021-38952 IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t… Infosphere Information Server No fix yet Fix from $1,6002022-04-28 HIGH 7.8 CVE-2022-22392 IBM Planning Analytics Local 2.0 could allow an attacker to upload arbitrary executable files which, when executed by an unsuspecting victim could re… Planning Analytics Workspace Mitigation only Fix from $1,9502022-04-25 HIGH 8.0 CVE-2021-39040 IBM Planning Analytics Workspace 2.0 could be vulnerable to malicious file upload by not validating the file types or sizes. Attackers can make use o… Planning Analytics Workspace Mitigation only Fix from $1,9502022-04-25 HIGH 7.5 CVE-2021-39076 IBM Security Guardium 10.5 and 11.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive information.… Security Guardium Mitigation only Fix from $1,9502022-04-19 MEDIUM 5.9 CVE-2021-39072 IBM Security Guardium 11.3 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transp… Security Guardium Mitigation only Fix from $1,6002022-04-19 HIGH 7.5 CVE-2021-38929 IBM System Storage DS8000 Management Console (HMC) R8.5 88.5x.x.x, R9.1 89.1x.0.0, and R9.2 89.2x.0.0 could allow a remote attacker to obtain sensiti… System Storage Ds8000 Management Console Firmware Mitigation only Fix from $1,9502022-04-11 HIGH 7.5 CVE-2021-38930 IBM System Storage DS8000 Management Console (HMC) R8.5 88.5x.x.x, R9.1 89.1x.0.0, and R9.2 89.2x.0.0 could allow a remote attacker to obtain sensiti… System Storage Ds8000 Management Console Firmware Mitigation only Fix from $1,9502022-04-11