Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Security Key Lifecycle Manager MEDIUM 6.5
CVE-2019-4515

IBM Security Key Lifecycle Manager 3.0 and 3.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and u…

Fix: after 3.0.1.1
Fix from $1,600 2019-09-24
Security Key Lifecycle Manager MEDIUM 5.5
CVE-2019-4566

IBM Security Key Lifecycle Manager 3.0 and 3.0.1 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 16…

Fix: after 3.0.1.1
Fix from $1,600 2019-09-24
Security Key Lifecycle Manager HIGH 7.5
CVE-2019-4565

IBM Security Key Lifecycle Manager 3.0 and 3.0.1 does not require that users should have strong passwords by default, which makes it easier for attac…

Fix: after 3.0.1.1
Fix from $1,950 2019-09-20
Websphere Application Server MEDIUM 5.3
CVE-2019-4505

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Network Deployment could allow a remote attacker to obtain sensitive information, caused by s…

Fix: after 9.0.5.0
Fix from $1,600 2019-09-20
Financial Transaction Manager For Multiplatform MEDIUM 6.5
CVE-2018-1847

IBM Financial Transaction Manager (FTM) for Multi-Platform (MP) v2.0.0.0 through 2.0.0.5, v2.1.0.0 through 2.1.0.4, v2.1.1.0 through 2.1.1.4, and v3.…

Fix: after 3.0.0.8
Fix from $1,600 2019-09-18
Cognos Controller HIGH 7.5
CVE-2019-4175

IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, and 10.4.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt h…

Patch available
Fix from $1,950 2019-09-17
Cognos Analytics HIGH 7.5
CVE-2019-4183

IBM Cognos Analytics 11.0, and 11.1 is vulnerable to a denial of service attack that could allow a remote user to send specially crafted requests tha…

Patch available
Fix from $1,950 2019-09-17
Websphere Application Server MEDIUM 6.5
CVE-2019-4477

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a user with access to audit logs to obtain sensitive information, caused by impro…

Fix: after 9.0.5.0
Fix from $1,600 2019-09-17
Websphere Application Server MEDIUM 5.4
CVE-2019-4270

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Admin Console is vulnerable to cross-site scripting. This vulnerability allows users to embed…

Fix: after 9.0.5.0
Fix from $1,600 2019-09-17
Cognos Analytics MEDIUM 5.4
CVE-2019-4342

IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the W…

Patch available
Fix from $1,600 2019-09-17
Websphere Application Server MEDIUM 5.3
CVE-2019-4268

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the system. An attacker could send a…

Fix: after 9.0.5.0
Fix from $1,600 2019-09-17
Application Performance Management MEDIUM 6.1
CVE-2019-4086

IBM Cloud Application Performance Management 8.1.4 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim …

Patch available
Fix from $1,600 2019-09-17
Sterling File Gateway HIGH 7.2
CVE-2019-4147

IBM Sterling File Gateway 2.2.0.0 through 6.0.1.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, whic…

Fix: after 6.0.1.0
Fix from $1,950 2019-09-16
Intelligent Operations Center HIGH 7.5
CVE-2019-4321

IBM Intelligent Operations Center V5.1.0 - V5.2.0, IBM Intelligent Operations Center for Emergency Management V5.1.0 - V5.1.0.6, and IBM Water Operat…

Fix: after 5.2.1.1
Fix from $1,950 2019-09-05
Jazz For Service Management MEDIUM 6.1
CVE-2019-4186

IBM Jazz for Service Management 1.1.3 is vulnerable to HTTP header injection, caused by incorrect trust in the HTTP Host header during caching. By se…

Mitigation only
Fix from $1,600 2019-09-05
Business Automation Workflow MEDIUM 5.4
CVE-2019-4149

IBM Business Automation Workflow V18.0.0.0 through V18.0.0.2 and IBM Business Process Manager V8.6.0.0 through V8.6.0.0 Cumulative Fix 2018.03, V8.5.…

Fix: after 18.0.0.2
Fix from $1,600 2019-09-05
I MEDIUM 6.3
CVE-2019-4536

IBM i 7.4 users who have done a Restore User Profile (RSTUSRPRF) on a system which has been configured with Db2 Mirror for i might have user profiles…

Patch available
Fix from $1,600 2019-08-29
Cloud Automation Manager MEDIUM 5.2
CVE-2019-4133

IBM Cloud Automation Manager 3.1.2 could allow a malicious user on the client side (with access to client computer) to run a custom script. IBM X-For…

Mitigation only
Fix from $1,600 2019-08-29
Open Power CRITICAL 9.1
CVE-2019-4169

IBM Open Power Firmware OP910 and OP920 could allow access to BMC via IPMI using default OpenBMC password even after BMC password was changed away fr…

Mitigation only
Fix from $2,300 2019-08-26
Security Access Manager For Enterprise Single Sign On HIGH 8.2
CVE-2019-4513

IBM Security Access Manager for Enterprise Single Sign-On 8.2.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML da…

Mitigation only
Fix from $1,950 2019-08-26
Db2 High Performance Unload Load HIGH 7.8
CVE-2019-4447

IBM DB2 High Performance Unload load for LUW 6.1, 6.1.0.1, 6.1.0.1 IF1, 6.1.0.2, 6.1.0.2 IF1, and 6.1.0.1 IF2 db2hpum_debug is a setuid root binary w…

Patch available
Fix from $1,950 2019-08-26
Db2 High Performance Unload Load HIGH 7.8
CVE-2019-4448

IBM DB2 High Performance Unload load for LUW 6.1, 6.1.0.1, 6.1.0.1 IF1, 6.1.0.2, 6.1.0.2 IF1, and 6.1.0.1 IF2 db2hpum and db2hpum_debug binaries are …

Patch available
Fix from $1,950 2019-08-26
Emptoris Spend Analysis MEDIUM 5.4
CVE-2019-4482

IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScrip…

Fix: after 10.1.3
Fix from $1,600 2019-08-20
Security Guardium Big Data Intelligence HIGH 8.2
CVE-2019-4340

IBM Security Guardium Big Data Intelligence 4.0 (SonarG) is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A r…

Mitigation only
Fix from $1,950 2019-08-20
Business Automation Workflow HIGH 8.2
CVE-2019-4424

IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, and 19.0.0.2 is vulnerable to an XML External Entity Injection (XXE) attack …

Fix: after 19.0.0.2
Fix from $1,950 2019-08-20
Security Guardium Big Data Intelligence HIGH 7.5
CVE-2019-4338

IBM Security Guardium Big Data Intelligence 4.0 (SonarG) does not properly restrict the size or amount of resources that are requested or influenced …

Mitigation only
Fix from $1,950 2019-08-20
Storediq MEDIUM 6.5
CVE-2019-4167

IBM StoredIQ 7.6.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitte…

Fix: after 7.6.0.18
Fix from $1,600 2019-08-20
Cloud Private MEDIUM 5.4
CVE-2019-4120

IBM Cloud Private 3.1.1 and 3.1.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the We…

Fix: after 3.1.2
Fix from $1,600 2019-08-20
Api Connect MEDIUM 5.3
CVE-2019-4437

IBM API Connect 2018.1 through 2018.4.1.6 may inadvertently leak sensitive details about internal servers and network via API swagger. IBM X-force ID…

Fix: after 2018.4.1.6
Fix from $1,600 2019-08-20
Emptoris Contract Management CRITICAL 9.8
CVE-2019-4483

IBM Contract Management 10.1.0 through 10.1.3 and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 is vulnerable to SQL injection. A remote attacker…

Fix: after 10.1.3
Fix from $2,300 2019-08-20