Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Websphere Mq MEDIUM 6.5
CVE-2012-4863

IBM WebSphere MQ 7.1 and 7.5: Queue manager has a DoS vulnerability

Fix: 7.1.0.2 / 7.5.0.1+
Fix from $1,600 2020-01-23
Chatbot With Ibm Watson MEDIUM 6.1
CVE-2020-7239

The conversation-watson plugin before 0.8.21 for WordPress has a DOM-based XSS vulnerability that is executed when a chat message containing JavaScri…

Fix: 0.8.21+
Fix from $1,600 2020-01-21
Qradar Security Information And Event Manager HIGH 7.8
CVE-2019-4508

IBM QRadar SIEM 7.3.0 through 7.3.3 uses weak credential storage in some instances which could be decrypted by a local attacker. IBM X-Force ID: 1644…

Fix: after 7.3.3
Fix from $1,950 2020-01-10
Qradar Security Information And Event Manager MEDIUM 5.3
CVE-2019-4559

IBM QRadar SIEM 7.3.0 through 7.3.3 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on th…

Fix: after 7.3.3
Fix from $1,600 2020-01-10
Jazz Reporting Service CRITICAL 9.8
CVE-2019-4651

IBM Jazz Reporting Service (JRS) 6.0.6.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could a…

Mitigation only
Fix from $2,300 2020-01-09
Cognos Analytics MEDIUM 6.5
CVE-2019-4343

IBM Cognos Analytics 11.0 and 11.1 allows overly permissive cross-origin resource sharing which could allow an attacker to transfer private informati…

Mitigation only
Fix from $1,600 2019-12-30
Watson Studio Local MEDIUM 5.5
CVE-2019-4335

IBM Watson Studio Local 1.2.3 stores key files in the user's home directory which could be obtained by another local user. IBM X-Force ID: 161413.

Patch available
Fix from $1,600 2019-12-30
Cognos Analytics MEDIUM 5.4
CVE-2019-4623

IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the W…

Mitigation only
Fix from $1,600 2019-12-30
Watston Studio Local MEDIUM 5.3
CVE-2018-1682

IBM Watson Studio Local 1.2.3 could disclose sensitive information over the network that an attacked could use in further attacks against the system.…

Patch available
Fix from $1,600 2019-12-30
Financial Transaction Manager For Multiplatform MEDIUM 6.1
CVE-2019-4742

IBM Financial Transaction Manager 3.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a ma…

Patch available
Fix from $1,600 2019-12-20
Financial Transaction Manager For Multiplatform MEDIUM 6.1
CVE-2019-4744

IBM Financial Transaction Manager 3.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in th…

Patch available
Fix from $1,600 2019-12-20
Cognos Analytics MEDIUM 5.4
CVE-2019-4555

IBM Cognos Analytics 11.0 and 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the W…

Fix: 11.1.4+
Fix from $1,600 2019-12-20
Cognos Business Intelligence HIGH 8.8
CVE-2018-1934

IBM Cognos Business Intelligence 10.2.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthoriz…

Mitigation only
Fix from $1,950 2019-12-20
Planning Analytics CRITICAL 9.8
CVE-2019-4716 KEVEPSS 86%

IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and th…

Fix: after 2.0.8
Fix from $2,300 2019-12-18
Api Connect HIGH 7.5
CVE-2019-4609

IBM API Connect 2018.4.1.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. I…

Mitigation only
Fix from $1,950 2019-12-18
Mq Appliance MEDIUM 6.5
CVE-2019-4560

IBM MQ and IBM MQ Appliance 9.1 CD, 9.1 LTS, 9.0 LTS, and 8.0 is vulnerable to a denial of service attack caused by channels processing poorly format…

Fix: 8.0.0.13 / 9.0.0.8+
Fix from $1,600 2019-12-16
Api Connect MEDIUM 5.5
CVE-2019-4444

IBM API Connect 2018.1 through 2018.4.1.7 Developer Portal's user registration page does not disable password autocomplete. An attacker with access t…

Fix: after 2018.4.1.7
Fix from $1,600 2019-12-16
Business Automation Workflow MEDIUM 5.4
CVE-2019-4426

The Case Builder component shipped with 18.0.0.1 through 19.0.0.2 and IBM Case Manager 5.1.1 through 5.3 is vulnerable to cross-site scripting. This …

Fix: 5.3.2+
Fix from $1,600 2019-12-13
Db2 High Performance Unload Load HIGH 7.8
CVE-2019-4606

IBM DB2 High Performance Unload load for LUW 6.1 and 6.5 could allow a local attacker to execute arbitrary code on the system, caused by an untrusted…

Mitigation only
Fix from $1,950 2019-12-12
Spectrum Scale HIGH 8.8
CVE-2019-4715

IBM Spectrum Scale 4.2 and 5.0 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafte…

Fix: after 5.0.4.0
Fix from $1,950 2019-12-11
Spectrum Scale MEDIUM 5.4
CVE-2019-4665

IBM Spectrum Scale 4.2 and 5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web U…

Fix: after 5.0.4.0
Fix from $1,600 2019-12-11
Cloud Pak System CRITICAL 9.8
CVE-2019-4521

Platform System Manager in IBM Cloud Pak System 2.3 is potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on…

Mitigation only
Fix from $2,300 2019-12-10
Smartcloud Analytics Log Analysis CRITICAL 9.1
CVE-2019-4244

IBM SmartCloud Analytics 1.3.1 through 1.3.5 could allow a remote attacker to gain unauthorized information and unrestricted control over Zookeeper i…

Fix: after 1.3.5
Fix from $2,300 2019-12-10
Websphere Application Server MEDIUM 5.4
CVE-2019-4663

IBM WebSphere Application Server - Liberty is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code …

Fix: 19.0.0.11+
Fix from $1,600 2019-12-10
Datapower Gateway CRITICAL 9.8
CVE-2019-4621

IBM DataPower Gateway 7.6.0.0-7 throug 6.0.14 and 2018.4.1.0 through 2018.4.1.5 have a default administrator account that is enabled if the IPMI LAN …

Fix: after 2018.4.1.5
Fix from $2,300 2019-12-09
Planning Analytics HIGH 8.8
CVE-2019-4612

IBM Planning Analytics 2.0 is vulnerable to malicious file upload in the My Account Portal. Attackers can make use of this weakness and upload malici…

Mitigation only
Fix from $1,950 2019-12-09
Watson Assistant For Ibm Cloud Pak For Data MEDIUM 5.4
CVE-2019-4428

IBM Watson Assistant for IBM Cloud Pak for Data 1.0.0 through 1.3.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed a…

Fix: after 1.3.0
Fix from $1,600 2019-12-09
Planning Analytics MEDIUM 5.4
CVE-2019-4611

IBM Planning Analytics 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI th…

Patch available
Fix from $1,600 2019-12-09
Cloud Pak System HIGH 8.8
CVE-2019-4130

IBM Cloud Pak System 2.3 and 2.3.0.1 could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary cod…

Patch available
Fix from $1,950 2019-12-03
Cloud Pak System MEDIUM 5.4
CVE-2019-4098

IBM Cloud Pak System 2.3 and 2.3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the…

Patch available
Fix from $1,600 2019-12-03