Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.3
CVE-2019-4741
IBM Content Navigator 3.0CD is vulnerable to Server Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requ…
Content Navigator
Mitigation only
HIGH 7.8
CVE-2013-0517
A Command Execution Vulnerability exists in IBM Sterling External Authentication Server 2.2.0, 2.3.01, 2.4.0, and 2.4.1 via an unspecified OS command…
Sterling External Authentication Server
Mitigation only
MEDIUM 5.5
CVE-2012-2204
InfoSphere Guardium aix_ktap module: DoS
Infosphere Guardium
No fix yet
HIGH 8.1
CVE-2015-0102
IBM Workflow for Bluemix does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to captu…
Workflow
Mitigation only
HIGH 8.8
CVE-2019-4613
IBM Planning Analytics 2.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions tr…
Planning Analytics
Mitigation only
HIGH 8.1
CVE-2013-0507
IBM InfoSphere Information Server 8.1, 8.5, 8.7, 9.1 has a Session Fixation Vulnerability
Infosphere Information Server
Mitigation only
HIGH 7.1
CVE-2019-4707
IBM Security Access Manager Appliance 9.0.7.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attac…
Security Access Manager
Mitigation only
CRITICAL 9.8
CVE-2019-4651
IBM Jazz Reporting Service (JRS) 6.0.6.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could a…
Jazz Reporting Service
Mitigation only
MEDIUM 6.5
CVE-2019-4343
IBM Cognos Analytics 11.0 and 11.1 allows overly permissive cross-origin resource sharing which could allow an attacker to transfer private informati…
Cognos Analytics
Mitigation only
MEDIUM 5.4
CVE-2019-4623
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the W…
Cognos Analytics
Mitigation only
HIGH 8.8
CVE-2018-1934
IBM Cognos Business Intelligence 10.2.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthoriz…
Cognos Business Intelligence
Mitigation only
HIGH 7.5
CVE-2019-4609
IBM API Connect 2018.4.1.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. I…
Api Connect
Mitigation only
HIGH 7.8
CVE-2019-4606
IBM DB2 High Performance Unload load for LUW 6.1 and 6.5 could allow a local attacker to execute arbitrary code on the system, caused by an untrusted…
Db2 High Performance Unload Load
Mitigation only
CRITICAL 9.8
CVE-2019-4521
Platform System Manager in IBM Cloud Pak System 2.3 is potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on…
Cloud Pak System
Mitigation only
HIGH 8.8
CVE-2019-4612
IBM Planning Analytics 2.0 is vulnerable to malicious file upload in the My Account Portal. Attackers can make use of this weakness and upload malici…
Planning Analytics
Mitigation only
HIGH 8.8
CVE-2019-4561
IBM Security Identity Manager 6.0.0 could allow a remote attacker to execute arbitrary code on the system, caused by the deserialization of untrusted…
Security Identity Manager
Mitigation only
MEDIUM 6.5
CVE-2019-4530
IBM Maximo Asset Management 7.6, 7.6.1, and 7.6.1.1 could allow an authenticated user to delete a record that they should not normally be able to. IB…
Maximo Asset Management
Mitigation only
HIGH 8.8
CVE-2019-4546
After installing the IBM Maximo Health- Safety and Environment Manager 7.6.1, a user is granted additional privileges that they are not normally allo…
Maximo For Oil And Gas
Mitigation only
HIGH 7.5
CVE-2019-4036
IBM Security Access Manager Appliance could allow unauthenticated attacker to cause a denial of service in the reverse proxy component. IBM X-Force I…
Security Access Manager
Mitigation only
HIGH 7.8
CVE-2019-4523
IBM DB2 High Performance Unload load for LUW 6.1 and 6.5 is vulnerable to a buffer overflow, caused by improper bounds checking which could allow a l…
Db2 High Performance Unload Load
Mitigation only
HIGH 7.8
CVE-2019-4031
IBM Workload Scheduler Distributed 9.2, 9.3, 9.4, and 9.5 contains a vulnerability that could allow a local user to write files as root in the file s…
Tivoli Workload Scheduler
Mitigation only
MEDIUM 5.4
CVE-2019-4571
IBM Content Navigator 3.0CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI t…
Content Navigator
Mitigation only
MEDIUM 6.1
CVE-2019-4186
IBM Jazz for Service Management 1.1.3 is vulnerable to HTTP header injection, caused by incorrect trust in the HTTP Host header during caching. By se…
Jazz For Service Management
Mitigation only
MEDIUM 5.2
CVE-2019-4133
IBM Cloud Automation Manager 3.1.2 could allow a malicious user on the client side (with access to client computer) to run a custom script. IBM X-For…
Cloud Automation Manager
Mitigation only
CRITICAL 9.1
CVE-2019-4169
IBM Open Power Firmware OP910 and OP920 could allow access to BMC via IPMI using default OpenBMC password even after BMC password was changed away fr…
Open Power
Mitigation only
HIGH 8.2
CVE-2019-4513
IBM Security Access Manager for Enterprise Single Sign-On 8.2.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML da…
Security Access Manager For Enterprise Single Sign On
Mitigation only
HIGH 8.2
CVE-2019-4340
IBM Security Guardium Big Data Intelligence 4.0 (SonarG) is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A r…
Security Guardium Big Data Intelligence
Mitigation only
HIGH 7.5
CVE-2019-4338
IBM Security Guardium Big Data Intelligence 4.0 (SonarG) does not properly restrict the size or amount of resources that are requested or influenced …
Security Guardium Big Data Intelligence
Mitigation only
HIGH 8.2
CVE-2019-4433
IBM InfoSphere Global Name Management 5.0 and 6.0 and IBM InfoSphere Identity Insight 8.1 and 9.0 is vulnerable to an XML External Entity Injection (…
Infosphere Global Name Management
Mitigation only
HIGH 7.8
CVE-2019-4253
IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local privileged Informix user to load a malicious shared library and gain root acc…
Informix Dynamic Server
Mitigation only