Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Infosphere Information Server MEDIUM 6.5
CVE-2020-4286

IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious…

Patch available
Fix from $1,600 2020-05-19
Infosphere Information Server MEDIUM 5.4
CVE-2020-4298

IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Java…

Patch available
Fix from $1,600 2020-05-19
Spectrum Scale MEDIUM 5.3
CVE-2020-4412

The Spectrum Scale 4.2.0.0 through 4.2.3.21 and 5.0.0.0 through 5.0.4.3 file system component is affected by a denial of service security vulnerabili…

Fix: after 5.0.4.3
Fix from $1,600 2020-05-19
I2 Analysts Notebook HIGH 7.8
CVE-2020-4266

IBM i2 Intelligent Analyis Platform 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By per…

Mitigation only
Fix from $1,950 2020-05-14
I2 Analysts Notebook HIGH 7.8
CVE-2020-4285

IBM i2 Intelligent Analyis Platform 9.2.1 could allow a remote attacker to execute arbitrary code on the system, caused by a memory corruption error.…

Mitigation only
Fix from $1,950 2020-05-14
I2 Analysts Notebook HIGH 7.8
CVE-2020-4287

IBM i2 Intelligent Analyis Platform 9.2.1 could allow a remote attacker to execute arbitrary code on the system, caused by a memory corruption error.…

Mitigation only
Fix from $1,950 2020-05-14
I2 Analysts Notebook HIGH 7.8
CVE-2020-4288

IBM i2 Intelligent Analyis Platform 9.2.1 could allow a remote attacker to execute arbitrary code on the system, caused by a memory corruption error.…

Mitigation only
Fix from $1,950 2020-05-14
I2 Analysts Notebook HIGH 7.8
CVE-2020-4343

IBM i2 Intelligent Analyis Platform 9.2.1 could allow a remote attacker to execute arbitrary code on the system, caused by a memory corruption. By pe…

Mitigation only
Fix from $1,950 2020-05-14
I2 Analysts Notebook HIGH 7.8
CVE-2020-4422

IBM i2 Intelligent Analyis Platform 9.2.1 could allow a remote attacker to execute arbitrary code on the system, caused by a memory corruption. By pe…

Mitigation only
Fix from $1,950 2020-05-14
I2 Analysts Notebook HIGH 7.8
CVE-2020-4467

IBM i2 Intelligent Analyis Platform 9.2.1 could allow a remote attacker to execute arbitrary code on the system, caused by memory corruption. By pers…

Mitigation only
Fix from $1,950 2020-05-14
I2 Analysts Notebook HIGH 7.8
CVE-2020-4468

IBM i2 Intelligent Analyis Platform 9.2.1 could allow a remote attacker to execute arbitrary code on the system, caused by memory corruption. By pers…

Mitigation only
Fix from $1,950 2020-05-14
I2 Analysts Notebook HIGH 7.8
CVE-2020-4257

IBM i2 Intelligent Analyis Platform 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By per…

Mitigation only
Fix from $1,950 2020-05-14
I2 Analysts Notebook HIGH 7.8
CVE-2020-4258

IBM i2 Intelligent Analyis Platform 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By per…

Mitigation only
Fix from $1,950 2020-05-14
I2 Analysts Notebook HIGH 7.8
CVE-2020-4261

IBM i2 Intelligent Analyis Platform 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By per…

Mitigation only
Fix from $1,950 2020-05-14
I2 Analysts Notebook HIGH 7.8
CVE-2020-4262

IBM i2 Intelligent Analyis Platform 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By per…

Mitigation only
Fix from $1,950 2020-05-14
I2 Analysts Notebook HIGH 7.8
CVE-2020-4263

IBM i2 Intelligent Analyis Platform 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By per…

Mitigation only
Fix from $1,950 2020-05-14
I2 Analysts Notebook HIGH 7.8
CVE-2020-4264

IBM i2 Intelligent Analyis Platform 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By per…

Mitigation only
Fix from $1,950 2020-05-14
I2 Analysts Notebook HIGH 7.3
CVE-2020-4265

IBM i2 Intelligent Analyis Platform 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By per…

Mitigation only
Fix from $1,950 2020-05-14
Sterling File Gateway MEDIUM 6.5
CVE-2020-4259

IBM Sterling File Gateway 2.2.0.0 through 6.0.3.1 could allow an authenticated user could manipulate cookie information and remove or add modules fro…

Fix: after 6.0.3.1
Fix from $1,600 2020-05-14
Maximo Asset Management MEDIUM 6.5
CVE-2019-4478

IBM Maximo Asset Management 7.6.0, and 7.6.1 could allow an authenticated user to obtain highly sensitive information that they should not normally h…

Patch available
Fix from $1,600 2020-05-12
Api Connect MEDIUM 5.4
CVE-2020-4195

IBM API Connect V2018.4.1.0 through 2018.4.1.10 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to …

Fix: after 2018.4.1.10
Fix from $1,600 2020-05-12
Api Connect MEDIUM 5.3
CVE-2020-4346

IBM API Connect's V2018.4.1.0 through 2018.4.1.10 management server has an unsecured api which can be exploited by an unauthenticated attacker to obt…

Fix: after 2018.4.1.10
Fix from $1,600 2020-05-12
Urbancode Deploy MEDIUM 5.9
CVE-2019-4667

IBM UrbanCode Deploy (UCD) 7.0.5.2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Stric…

Mitigation only
Fix from $1,600 2020-05-11
Data Risk Manager CRITICAL 9.8
CVE-2020-4427 KEVEPSS 70%

IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured with…

Fix: after 2.0.6.1
Fix from $2,300 2020-05-07
Data Risk Manager CRITICAL 9.8
CVE-2020-4429EPSS 71%

IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 contains a default password for an IDRM administrative account. A remote attacker …

Patch available
Fix from $2,300 2020-05-07
Data Risk Manager CRITICAL 9.1
CVE-2020-4428 KEVEPSS 62%

IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary commands on the system. IBM X-F…

Fix: after 2.0.4
Fix from $2,300 2020-05-07
Infosphere Information Server On Cloud MEDIUM 5.4
CVE-2020-4384

IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Java…

Mitigation only
Fix from $1,600 2020-05-06
Websphere Application Server MEDIUM 5.4
CVE-2020-4421

IBM WebSphere Application Liberty 19.0.0.5 through 20.0.0.4 could allow an authenticated user using openidconnect to spoof another users identify. IB…

Fix: 20.0.0.5+
Fix from $1,600 2020-05-06
Spectrum Protect Plus MEDIUM 5.4
CVE-2020-4209

IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to traverse directories on the system. An attacker could send a special…

Fix: after 10.1.5
Fix from $1,600 2020-05-04
Cloud App Management HIGH 8.8
CVE-2019-4750

IBM Cloud App Management 2019.3.0 and 2019.4.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and una…

Mitigation only
Fix from $1,950 2020-04-24