Vulnerability index

Browse CVEs

2,216 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2021-20549 IBM Content Navigator 3.0.CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI … Content Navigator Mitigation only Fix from $1,6002021-04-27 MEDIUM 5.4 CVE-2021-20550 IBM Content Navigator 3.0.CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI … Content Navigator Mitigation only Fix from $1,6002021-04-27 MEDIUM 6.2 CVE-2021-20536 IBM Spectrum Protect Plus File Systems Agent 10.1.6 and 10.1.7 stores potentially sensitive information in log files that could be read by a local us… Spectrum Protect Plus Mitigation only Fix from $1,6002021-04-26 MEDIUM 5.3 CVE-2020-4562 IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information by allowing cross-window communication with unrestricted tar… Planning Analytics Mitigation only Fix from $1,6002021-04-26 HIGH 8.2 CVE-2021-20501 IBM i 7.1, 7.2, 7.3, and 7.4 SMTP allows a network attacker to send emails to non-existent local-domain recipients to the SMTP server, caused by usin… I Mitigation only Fix from $1,9502021-04-21 HIGH 7.1 CVE-2021-20482 IBM Cloud Pak for Automation 20.0.2 and 20.0.3 IF002 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remo… Cloud Pak For Automation Mitigation only Fix from $1,9502021-03-30 MEDIUM 5.5 CVE-2020-4884 IBM UrbanCode Deploy (UCD) 6.2.7.9, 7.0.5.4, and 7.1.1.1 stores user credentials in plain in clear text which can be read by a local user. IBM X-Forc… Urbancode Deploy Mitigation only Fix from $1,6002021-03-30 MEDIUM 5.5 CVE-2020-4944 IBM UrbanCode Deploy (UCD) 7.0.3.0, 7.0.4.0, 7.0.5.3, 7.0.5.4, 7.1.0.0, 7.1.1.0, 7.1.1.1, and 7.1.1.2, stores keystore passwords in plain text after … Urbancode Deploy Mitigation only Fix from $1,6002021-03-30 MEDIUM 5.4 CVE-2020-4848 IBM UrbanCode Deploy (UCD) 6.2.7.9, 7.0.5.4, and 7.1.1.1 could allow an authenticated user to initiate a plugin or compare process resources that the… Urbancode Deploy Mitigation only Fix from $1,6002021-03-30 MEDIUM 6.1 CVE-2020-4882 IBM Planning Analytics 2.0 could be vulnerable to a Server-Side Request Forgery (SSRF) attack by constucting URLs from user-controlled data . This co… Planning Analytics Mitigation only Fix from $1,6002021-03-22 HIGH 7.3 CVE-2020-4184 IBM Security Guardium 11.2 performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or… Security Guardium No fix yet Fix from $1,9502021-03-15 MEDIUM 5.4 CVE-2021-20336 IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code… Tivoli Netcool\/omnibus Webgui Mitigation only Fix from $1,6002021-03-11 MEDIUM 5.5 CVE-2020-4717 A vulnerability exists in IBM SPSS Modeler Subscription Installer that allows a user with create symbolic link permission to write arbitrary file in … Spss Modeler Mitigation only Fix from $1,6002021-03-10 HIGH 8.8 CVE-2021-20403 IBM Security Verify Information Queue 1.0.6 and 1.0.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious … Security Verify Information Queue Mitigation only Fix from $1,9502021-02-11 HIGH 7.5 CVE-2021-20405 IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a user to perform unauthorized activities due to improper encoding of output. IBM X… Security Verify Information Queue Mitigation only Fix from $1,9502021-02-11 MEDIUM 5.3 CVE-2021-20404 IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a user on the network to cause a denial of service due to an invalid cookie value t… Security Verify Information Queue Mitigation only Fix from $1,6002021-02-11 MEDIUM 6.5 CVE-2021-20358 IBM Cloud Pak for Automation 20.0.3, 20.0.2-IF002 stores potentially sensitive information in clear text in API connection log files. This informatio… Cloud Pak For Automation Mitigation only Fix from $1,6002021-02-08 MEDIUM 6.5 CVE-2021-20359 IBM Cloud Pak for Automation 20.0.3, 20.0.2-IF002 - Business Automation Application Designer Component stores potentially sensitive information in lo… Cloud Pak For Automation Mitigation only Fix from $1,6002021-02-08 CRITICAL 9.8 CVE-2020-27583 IBM InfoSphere Information Server 8.5.0.0 is affected by deserialization of untrusted data which could allow remote unauthenticated attackers to exec… Infosphere Information Server No fix yet Fix from $2,3002021-01-26 CRITICAL 9.8 CVE-2020-4958 IBM Security Identity Governance and Intelligence 5.2.6 does not perform any authentication for functionality that requires a provable user identity … Security Identity Governance And Intelligence Mitigation only Fix from $2,3002021-01-21 HIGH 8.8 CVE-2020-4921 IBM Security Guardium 10.6 and 11.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow … Security Guardium Mitigation only Fix from $1,9502021-01-20 HIGH 7.8 CVE-2020-4688 IBM Security Guardium 10.6 and 11.2 could allow a local attacker to execute arbitrary commands on the system as an unprivileged user, caused by comma… Security Guardium Mitigation only Fix from $1,9502021-01-20 MEDIUM 5.5 CVE-2020-4887 IBM AIX 7.1, 7.2 and AIX VIOS 3.1 could allow a local user to exploit a vulnerability in the gencore user command to create arbitrary files in any di… Vios Mitigation only Fix from $1,6002021-01-20 MEDIUM 5.4 CVE-2020-4691 IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI… Collaborative Lifecycle Management Mitigation only Fix from $1,6002021-01-08 MEDIUM 5.4 CVE-2020-4697 IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI… Collaborative Lifecycle Management Mitigation only Fix from $1,6002021-01-08 MEDIUM 5.4 CVE-2020-4733 IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI… Collaborative Lifecycle Management Mitigation only Fix from $1,6002021-01-08 HIGH 8.8 CVE-2020-4942 IBM Curam Social Program Management 7.0.9 and 7.0.11 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious a… Curam Social Program Management Mitigation only Fix from $1,9502021-01-04 MEDIUM 5.5 CVE-2020-4642 IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow local attacker to cause a denial of ser… Db2 Mitigation only Fix from $1,6002020-12-23 CRITICAL 9.8 CVE-2020-4988 Loopback 8.0.0 contains a vulnerability that could allow an attacker to manipulate or pollute Javascript values and cause a denial of service or poss… Loopback Mitigation only Fix from $2,3002020-12-21 CRITICAL 9.8 CVE-2020-4747 IBM Connect:Direct for UNIX 6.1.0, 6.0.0, 4.3.0, and 4.2.0 can allow a local or remote user to obtain an authenticated CLI session due to improper au… Connect\ Mitigation only Fix from $2,3002020-12-15