Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Platform Lsf HIGH 7.8
CVE-2020-4278

IBM Platform LSF 9.1 and 10.1, IBM Spectrum LSF Suite 10.2, and IBM Spectrum Suite for HPA 10.2 could allow a local user to escalate their privileges…

Patch available
Fix from $1,950 2020-03-05
Tivoli Netcool\/omnibus MEDIUM 5.4
CVE-2020-4196

IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the…

Patch available
Fix from $1,600 2020-03-03
Tivoli Netcool\/omnibus MEDIUM 5.4
CVE-2020-4198

IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the…

Patch available
Fix from $1,600 2020-03-03
Security Information Queue HIGH 8.6
CVE-2020-4283

IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, and 1.0.4 contains hard-coded credentials, such as a password or cryptographic key,…

Mitigation only
Fix from $1,950 2020-03-02
Security Information Queue MEDIUM 5.3
CVE-2020-4292

IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, and 1.0.4 uses a cross-domain policy file that includes domains that should not be …

Mitigation only
Fix from $1,600 2020-03-02
Business Process Manager MEDIUM 6.3
CVE-2019-4669

IBM Business Process Manager 8.5.7.0 through 8.5.7.0 2017.06, 8.6.0.0 through 8.6.0.0 CF2018.03, and IBM Business Automation Workflow 18.0.0.1 throug…

Fix: after 19.0.0.3
Fix from $1,600 2020-02-27
Sterling B2b Integrator MEDIUM 6.3
CVE-2019-4597

IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 is vulnerable to SQL injection. A remote attacker could send specially-crafted S…

Fix: after 5.2.6.5
Fix from $1,600 2020-02-26
Sterling B2b Integrator MEDIUM 6.3
CVE-2019-4598

IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 is vulnerable to SQL injection. A remote attacker could send specially-crafted S…

Fix: after 5.2.6.5
Fix from $1,600 2020-02-26
Sterling B2b Integrator MEDIUM 5.4
CVE-2019-4596

IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed …

Fix: after 5.2.6.5
Fix from $1,600 2020-02-26
Websphere Service Registry And Repository MEDIUM 5.3
CVE-2019-4537

IBM WebSphere Service Registry and Repository 8.5 could allow a user to obtain sensitive version information that could be used in further attacks ag…

Patch available
Fix from $1,600 2020-02-26
Qradar Advisor HIGH 7.5
CVE-2019-4557

IBM Qradar Advisor 1.1 through 2.5 with Watson uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sens…

Fix: 2.5.1+
Fix from $1,950 2020-02-25
Qradar Advisor MEDIUM 5.3
CVE-2019-4672

IBM QRadar Advisor 1.1 through 2.5 could allow an unauthorized attacker to obtain sensitive information from specially crafted HTTP requests that cou…

Fix: 2.5.1+
Fix from $1,600 2020-02-25
Spectrum Protect CRITICAL 9.8
CVE-2020-4210EPSS 15%

IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP …

Fix: 10.1.5+
Fix from $2,300 2020-02-24
Spectrum Protect CRITICAL 9.8
CVE-2020-4211EPSS 71%

IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP …

Fix: 10.1.5+
Fix from $2,300 2020-02-24
Spectrum Protect CRITICAL 9.8
CVE-2020-4212EPSS 15%

IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP …

Fix: 10.1.5+
Fix from $2,300 2020-02-24
Spectrum Protect CRITICAL 9.8
CVE-2020-4213EPSS 15%

IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP …

Fix: 10.1.5+
Fix from $2,300 2020-02-24
Spectrum Protect CRITICAL 9.8
CVE-2020-4222EPSS 15%

IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP …

Fix: 10.1.5+
Fix from $2,300 2020-02-24
Sterling B2b Integrator MEDIUM 6.1
CVE-2019-4595

IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 could allow a remote attacker to conduct phishing attacks, using an open redirec…

Fix: after 5.2.6.5
Fix from $1,600 2020-02-24
Spectrum Protect Plus MEDIUM 5.3
CVE-2019-4703

IBM Spectrum Protect Plus 10.1.0 and 10.5.0, when protecting Microsoft SQL or Microsoft Exchange, could allow an attacker with intimate knowledge of …

Fix: after 10.1.5
Fix from $1,600 2020-02-24
Emptoris Spend Analysis HIGH 8.8
CVE-2019-4752

IBM Emptoris Spend Analysis and IBM Emptoris Strategic Supply Management Platform 10.1.0.x, 10.1.1.x, and 10.1.3.x is vulnerable to SQL injection. A …

Fix: 10.1.0.34 / 10.1.1.33+
Fix from $1,950 2020-02-20
Db2 MEDIUM 6.7
CVE-2020-4230

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1 and 11.5 is vulnerable to an escalation of privilege when an authenticated loc…

Mitigation only
Fix from $1,600 2020-02-19
Security Secret Server CRITICAL 9.8
CVE-2019-4640

IBM Security Secret Server 10.7 processes patches, image backups and other updates without sufficiently verifying the origin and integrity of the cod…

Mitigation only
Fix from $2,300 2020-02-19
Db2 HIGH 7.8
CVE-2020-4204

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a buffer overflow, caused by impro…

Mitigation only
Fix from $1,950 2020-02-19
Db2 HIGH 7.5
CVE-2020-4135

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow an unauthenticated user to send special…

Mitigation only
Fix from $1,950 2020-02-19
Jazz Foundation MEDIUM 6.5
CVE-2019-4457

IBM Jazz Foundation 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 could allow an authenticated user to obtain sensitive information that…

Fix: after 6.0.6.1
Fix from $1,600 2020-02-19
Db2 MEDIUM 6.5
CVE-2020-4161

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5 could allow an authenticated attacker to cause a denial of service due to inco…

Mitigation only
Fix from $1,600 2020-02-19
Db2 MEDIUM 6.5
CVE-2020-4200

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 could allow an authenticated attacker to send specially crafte…

Mitigation only
Fix from $1,600 2020-02-19
Control Desk MEDIUM 5.4
CVE-2019-4429

IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code…

Patch available
Fix from $1,600 2020-02-19
Tivoli Endpoint Manager MEDIUM 5.4
CVE-2012-0718

IBM Tivoli Endpoint Manager 8 does not set the HttpOnly flag on cookies.

Mitigation only
Fix from $1,600 2020-02-18
Change And Configuration Management Database CRITICAL 9.8
CVE-2013-3323

A Privilege Escalation Vulnerability exists in IBM Maximo Asset Management 7.5, 7.1, and 6.2, when WebSeal with Basic Authentication is used, due to …

Mitigation only
Fix from $2,300 2020-02-18