Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Websphere Mq HIGH 7.8
CVE-2019-4078

IBM WebSphere MQ 8.0.0.0 through 8.0.0.9 and 9.0.0.0 through 9.1.1 could allow a local non privileged user to execute code as an administrator due to…

Fix: after 9.1.0.1
Fix from $1,950 2019-05-23
Websphere Mq MEDIUM 5.5
CVE-2019-4039

IBM WebSphere MQ 8.0.0.0 through 8.0.0.9 and 9.0.0.0 through 9.1.1 could allow a local attacker to cause a denial of service within the error log rep…

Fix: after 9.1.1
Fix from $1,600 2019-05-23
Bigfix Platform MEDIUM 6.5
CVE-2019-4058

IBM BigFix Platform 9.2 and 9.5 could allow a low-privilege user to manipulate the UI into exposing interface elements and information normally restr…

Fix: after 9.5.12
Fix from $1,600 2019-05-20
Bigfix Platform MEDIUM 5.4
CVE-2019-4011

IBM BigFix Platform 9.2 and 9.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web …

Fix: after 9.5.12
Fix from $1,600 2019-05-20
Storwize Unified V7000 Software MEDIUM 5.3
CVE-2019-4293

IBM Storwize V7000 Unified (2073) 1.6 configuration may allow an attacker to reveal the server version in default installation, which could be used i…

Fix: after 1.6.2.5
Fix from $1,600 2019-05-20
Websphere Application Server CRITICAL 9.8
CVE-2019-4279EPSS 80%

IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence …

Fix: after 9.0.0.11
Fix from $2,300 2019-05-17
Cloud Private MEDIUM 5.3
CVE-2019-4119

IBM Cloud Private Kubernetes API server 2.1.0, 3.1.0, 3.1.1, and 3.1.2 can be used as an HTTP proxy to not only cluster internal but also external ta…

Fix: after 2.1.0.3
Fix from $1,600 2019-05-17
Rational Doors Web Access MEDIUM 5.4
CVE-2018-1975

IBM Rational DOORS Web Access 9.5.1 through 9.5.2.9, and 9.6 through 9.6.1.9 is vulnerable to cross-site scripting. This vulnerability allows users t…

Fix: 9.5.1.11 / 9.5.2.10+
Fix from $1,600 2019-05-16
Spectrum Scale MEDIUM 5.5
CVE-2019-4259

A security vulnerability has been identified in IBM Spectrum Scale 4.1.1, 4.2.0, 4.2.1, 4.2.2, 4.2.3, and 5.0.0 with CES stack enabled that could all…

Fix: after 5.0.2.3
Fix from $1,600 2019-05-13
Financial Transaction Manager HIGH 8.8
CVE-2018-1790

IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.0.2 is vulnerable to cross-site request forgery which could allow an atta…

Fix: after 3.0.2.1
Fix from $1,950 2019-05-10
Business Automation Workflow MEDIUM 5.4
CVE-2019-4204

IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, and 19.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to…

Fix: after 19.0.0.1
Fix from $1,600 2019-05-10
Cloud App Management MEDIUM 5.3
CVE-2018-1990

IBM Cloud App Management V2018.2.0, V2018.4.0, and V2018.4.1 could allow an attacker to obtain sensitive configuration information using a specially …

Patch available
Fix from $1,600 2019-05-10
Spectrum Control HIGH 8.8
CVE-2019-4071

IBM Tivoli Storage Productivity Center (IBM Spectrum Control Standard Edition 5.2.1 through 5.2.17) could allow a remote attacker to execute arbitrar…

Fix: after 5.3.1
Fix from $1,950 2019-05-09
Spectrum Control MEDIUM 6.3
CVE-2019-4072

IBM Tivoli Storage Productivity Center (IBM Spectrum Control Standard Edition 5.2.1 through 5.2.17) allows users to remain idle within the applicatio…

Fix: after 5.3.1
Fix from $1,600 2019-05-09
Tririga Application Platform HIGH 7.1
CVE-2019-4208

IBM TRIRIGA Application Platform 3.5.3 and 3.6.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote at…

Fix: 3.5.3.6 / 3.6.0.3+
Fix from $1,950 2019-05-07
Curam Social Program Management HIGH 8.8
CVE-2018-2001

IBM Cram Social Program Management 6.1.1, 6.2.0, 7.0.4, and 7.0.5 is vulnerable to cross-site request forgery which could allow an attacker to execut…

Fix: after 7.0.4.0
Fix from $1,950 2019-05-07
Api Connect MEDIUM 6.1
CVE-2018-2015

IBM API Connect 2018.1 and 2018.4.1.4 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a ma…

Fix: after 2018.4.1.4
Fix from $1,600 2019-05-02
Sterling B2b Integrator MEDIUM 5.4
CVE-2019-4258

IBM Sterling B2B Integrator 6.0.0.0 and 6.0.0.1 Standard Edition is vulnerable to cross-site scripting. This vulnerability allows users to embed arbi…

Mitigation only
Fix from $1,600 2019-05-01
Rational Engineering Lifecycle Manager HIGH 7.5
CVE-2018-1608

IBM Rational Engineering Lifecycle Manager 6.0 through 6.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decry…

Fix: after 6.0.6
Fix from $1,950 2019-05-01
Planning Analytics MEDIUM 5.4
CVE-2018-1933

IBM Planning Analytics 2.0 through 2.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in…

Fix: after 2.0.6
Fix from $1,600 2019-05-01
Storediq MEDIUM 6.1
CVE-2019-4166

IBM StoredIQ 7.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a speciall…

Fix: after 7.6.0.18
Fix from $1,600 2019-04-30
Api Connect HIGH 7.5
CVE-2018-2007

IBM API Connect 2018.1 and 2018.4.1.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive inf…

Fix: after 2018.4.1.2
Fix from $1,950 2019-04-29
Jazz Reporting Service MEDIUM 5.4
CVE-2018-2004

IBM Jazz Reporting Service (JRS) 6.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScri…

Fix: after 6.0.6
Fix from $1,600 2019-04-29
Emptoris Contract Management MEDIUM 5.3
CVE-2018-1961

IBM Emptoris Contract Management 10.0.0 and 10.1.3.0 could disclose sensitive information from detailed information from error messages. IBM X-Force …

Fix: after 10.1.3.0
Fix from $1,600 2019-04-29
Content Navigator MEDIUM 6.1
CVE-2019-4092

IBM Content Navigator 2.0.3 and 3.0CD could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victi…

Mitigation only
Fix from $1,600 2019-04-25
Sterling B2b Integrator MEDIUM 5.4
CVE-2019-4148

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbi…

Mitigation only
Fix from $1,600 2019-04-25
Infosphere Information Server MEDIUM 5.4
CVE-2019-4238

IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Java…

Mitigation only
Fix from $1,600 2019-04-25
Sterling B2b Integrator HIGH 7.5
CVE-2018-1720

IBM Sterling B2B Integrator Standard Edition 5.2.0.1, 5.2.6.3_6, 6.0.0.0, and 6.0.0.1 uses weaker than expected cryptographic algorithms that could a…

Mitigation only
Fix from $1,950 2019-04-25
Content Navigator MEDIUM 5.4
CVE-2019-4033

IBM Content Navigator 2.0.3 and 3.0CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in th…

Mitigation only
Fix from $1,600 2019-04-25
Sterling B2b Integrator MEDIUM 5.4
CVE-2019-4073

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbi…

Mitigation only
Fix from $1,600 2019-04-25