Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Doors Next Generation MEDIUM 5.4
CVE-2019-4746

IBM DOORS Next Generation (DNG/RRC) 6.0.2. 6.0.6, and 6.0.61 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar…

Patch available
Fix from $1,600 2020-04-08
Spectrum Scale HIGH 7.8
CVE-2020-4273

IBM Spectrum Scale 4.2 and 5.0 could allow a local unprivileged attacker with intimate knowledge of the enviornment to execute commands as root using…

Fix: after 5.0.4.2
Fix from $1,950 2020-04-03
Strongloop Nginx Controller CRITICAL 9.8
CVE-2020-7621

strong-nginx-controller through 1.0.2 is vulnerable to Command Injection. It allows execution of arbitrary command as part of the '_nginxCmd()' funct…

Fix: after 1.0.2
Fix from $2,300 2020-04-02
Cloud Pak For Automation MEDIUM 6.5
CVE-2020-4325

The IBM Process Federation Server 18.0.0.1, 18.0.0.2, 19.0.0.1, 19.0.0.2, and 19.0.0.3 Global Teams REST API does not properly shutdown the thread po…

Fix: after 19.0.0.3
Fix from $1,600 2020-04-02
Websphere Application Server MEDIUM 6.1
CVE-2020-4303

IBM WebSphere Application Server - Liberty 17.0.0.3 through 20.0.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed …

Fix: after 20.0.0.3
Fix from $1,600 2020-04-02
Websphere Application Server MEDIUM 6.1
CVE-2020-4304

IBM WebSphere Application Server - Liberty 17.0.0.3 through 20.0.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed …

Fix: after 20.0.0.3
Fix from $1,600 2020-04-02
Spectrum Protect Plus HIGH 8.8
CVE-2020-4241EPSS 66%

IBM Spectrum Scale and IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote authenticated attacker to execute arbitrary commands on t…

Fix: after 10.1.5
Fix from $1,950 2020-03-31
Spectrum Protect Plus HIGH 8.8
CVE-2020-4242

IBM Spectrum Scale and IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote authenticated attacker to execute arbitrary commands on t…

Fix: after 10.1.5
Fix from $1,950 2020-03-31
Tivoli Netcool\/impact HIGH 8.8
CVE-2020-4238

IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and…

Fix: after 7.1.0.17
Fix from $1,950 2020-03-31
Spectrum Protect Plus MEDIUM 6.5
CVE-2020-4240

IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to traverse directories on the system. An attacker could send a special…

Fix: after 10.1.5
Fix from $1,600 2020-03-31
Tivoli Netcool\/impact MEDIUM 5.3
CVE-2020-4239

IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 could allow a remote attacker to obtain sensitive information when a detailed technical error mess…

Fix: after 7.1.0.17
Fix from $1,600 2020-03-31
Tivoli Netcool\/impact HIGH 8.8
CVE-2020-4237

IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and…

Fix: after 7.1.0.17
Fix from $1,950 2020-03-31
Tivoli Netcool\/impact MEDIUM 6.5
CVE-2020-4236

IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 could allow an authenticated user to cause a denial of service due to improper content parsing in …

Fix: after 7.1.0.17
Fix from $1,600 2020-03-31
Tivoli Netcool\/impact MEDIUM 5.4
CVE-2020-4235

IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScri…

Fix: after 7.1.0.17
Fix from $1,600 2020-03-31
Spectrum Protect Plus CRITICAL 9.8
CVE-2020-4208

IBM Spectrum Protect Plus 10.1.0 through 10.1.5 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own i…

Fix: after 10.1.5
Fix from $2,300 2020-03-31
Spectrum Protect Plus HIGH 7.5
CVE-2020-4214

IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to arbitrary delete a directory caused by improper validation of user-s…

Fix: after 10.1.5
Fix from $1,950 2020-03-31
Spectrum Protect Plus HIGH 8.8
CVE-2020-4206

IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to execute arbitrary commands on the system in the context of root user…

Fix: after 10.1.5
Fix from $1,950 2020-03-31
Websphere Application Server HIGH 7.5
CVE-2020-4276

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional is vulnerable to a privilege escalation vulnerability when using token-based auth…

Fix: after 9.0.5.3
Fix from $1,950 2020-03-26
Content Navigator HIGH 8.8
CVE-2020-4253

IBM Content Navigator 3.0CD does not invalidate session after logout which could allow an authenticated user to impersonate another user on the syste…

Patch available
Fix from $1,950 2020-03-24
Api Connect HIGH 7.5
CVE-2019-4553

IBM API Connect V5.0.0.0 through 5.0.8.7iFix3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensi…

Fix: after 5.0.8.73
Fix from $1,950 2020-03-24
Tivoli Netcool\/impact MEDIUM 6.1
CVE-2019-4681

IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScri…

Fix: after 7.1.0.17
Fix from $1,600 2020-03-24
Content Navigator MEDIUM 5.3
CVE-2020-4309

IBM Content Navigator 3.0CD could disclose sensitive information to an unauthenticated user which could be used to aid in further attacks against the…

Patch available
Fix from $1,600 2020-03-24
Jazz For Service Management MEDIUM 5.4
CVE-2019-4718

IBM Jazz for Service Management 3.13 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the…

Patch available
Fix from $1,600 2020-03-23
Datapower Gateway MEDIUM 6.3
CVE-2020-4205

IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.8 could allow an authenticated user to bypass security restrictions, and continue to access the ser…

Fix: after 2018.4.1.8
Fix from $1,600 2020-03-19
Mq MEDIUM 6.5
CVE-2019-4656

IBM MQ and IBM MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD is vulnerable to a denial of service attack that would allow an authenticated…

Fix: 8.0.0.14 / 9.1.0.4+
Fix from $1,600 2020-03-16
Mq MEDIUM 5.5
CVE-2019-4619

IBM MQ and IBM MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD could allow a local attacker to obtain sensitive information by inclusion of …

Fix: 8.0.0.14 / 9.1.0.4+
Fix from $1,600 2020-03-16
Mq MEDIUM 5.5
CVE-2019-4719

IBM MQ and IBM MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD could allow a local attacker to obtain sensitive information by inclusion of …

Fix: 8.0.0.14 / 9.1.0.4+
Fix from $1,600 2020-03-16
Tivoli Workload Scheduler MEDIUM 5.4
CVE-2019-4608

IBM Tivoli Workload Scheduler 9.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the We…

Mitigation only
Fix from $1,600 2020-03-10
Infosphere Information Server MEDIUM 5.4
CVE-2020-4162

IBM InfoSphere Information Server 11.5 and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript …

Patch available
Fix from $1,600 2020-03-10
Spectrum Scale HIGH 7.5
CVE-2020-4217

The IBM Spectrum Scale 4.2 and 5.0 file system component is affected by a denial of service security vulnerability. An attacker can force the Spectru…

Fix: after 5.0.4.2
Fix from $1,950 2020-03-09