Vulnerability index

Browse CVEs

6,286 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Jazz Foundation MEDIUM 6.5
CVE-2025-25048

IBM Jazz Foundation 7.0.2 through 7.0.2 iFix033, 7.0.3 through 7.0.3 iFix012, and 7.1.0 through 7.1.0 iFix002 could allow an authenticated user to up…

Patch available
Fix from $1,600 2025-09-04
Jazz Foundation MEDIUM 6.1
CVE-2024-43184

IBM Jazz Foundation 7.0.2 through 7.0.2 iFix033, 7.0.3 through 7.0.3 iFix012, and 7.1.0 through 7.1.0 iFix002 is vulnerable to cross-site scripting. …

Patch available
Fix from $1,600 2025-09-04
Transformation Advisor MEDIUM 6.7
CVE-2025-36193

IBM Transformation Advisor 2.0.1 through 4.3.1 incorrectly assigns privileges to security critical files which could allow a local root escalation in…

Fix: 4.3.2+
Fix from $1,600 2025-09-03
Concert HIGH 7.5
CVE-2025-33102

IBM Concert Software 1.0.0 through 1.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive …

Fix: 2.0.0+
Fix from $1,950 2025-09-01
Concert MEDIUM 5.9
CVE-2025-33099

IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to perform unauthorized actions using man in the middle techniques due to impr…

Fix: 2.0.0+
Fix from $1,600 2025-09-01
Concert MEDIUM 5.9
CVE-2025-33084

IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP…

Fix: 2.0.0+
Fix from $1,600 2025-09-01
Concert MEDIUM 5.4
CVE-2025-33082

IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary Ja…

Fix: 2.0.0+
Fix from $1,600 2025-09-01
Concert MEDIUM 5.4
CVE-2025-33083

IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary Ja…

Fix: 2.0.0+
Fix from $1,600 2025-09-01
Concert MEDIUM 6.1
CVE-2025-0656

IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated user to embed arbitrary …

Fix: 2.0.0+
Fix from $1,600 2025-09-01
App Connect Enterprise Certified Containers Operands MEDIUM 5.5
CVE-2025-36133

IBM App Connect Enterprise Certified Container CD: 9.2.0 through 11.6.0, 12.1.0 through 12.14.0, and 12.0 LTS: 12.0.0 through 12.0.14stores potential…

Fix: 12.15.0+
Fix from $1,600 2025-09-01
Watsonx Orchestrate Cartridge For Ibm Cloud Pak For Data CRITICAL 9.8
CVE-2025-0165

IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data 4.8.4, 4.8.5, and 5.0.0 through 5.2.0 is vulnerable to SQL injection. A remote attacker …

Fix: 5.2.0.1+
Fix from $2,300 2025-08-30
Watson Assistant For Ibm Cloud Pak For Data MEDIUM 5.4
CVE-2024-49790

IBM Watson Studio on Cloud Pak for Data 4.0 and 5.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed a…

Fix: 5.2.0+
Fix from $1,600 2025-08-28
Security Verify Governance MEDIUM 5.3
CVE-2025-36003

IBM Security Verify Governance Identity Manager 10.0.2 could allow a remote attacker to obtain sensitive information when detailed technical error me…

Mitigation only
Fix from $1,600 2025-08-28
Cognos Command Center CRITICAL 9.3
CVE-2025-2697

IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuadi…

Mitigation only
Fix from $2,300 2025-08-26
Cognos Command Center HIGH 7.8
CVE-2025-1994

IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a local user to execute arbitrary code on the system due to the use of unsafe use of th…

Mitigation only
Fix from $1,950 2025-08-26
Cognos Command Center MEDIUM 6.1
CVE-2025-1494

IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to vi…

Mitigation only
Fix from $1,600 2025-08-26
Integrated Analytics System HIGH 8.0
CVE-2025-36174

IBM Integrated Analytics System 1.0.0.0 through 1.0.30.0 could allow an authenticated user to upload a file with dangerous types that could be execut…

Fix: after 1.0.31.0
Fix from $1,950 2025-08-24
Jazz Foundation CRITICAL 9.1
CVE-2025-36157

IBM Jazz Foundation 7.0.2 to 7.0.2 iFix035, 7.0.3 to 7.0.3 iFix018, and 7.1.0 to 7.1.0 iFix004 could allow an unauthenticated remote attacker to upda…

Patch available
Fix from $2,300 2025-08-24
Qradar Incident Forensics HIGH 7.8
CVE-2025-33120

IBM QRadar SIEM 7.5 through 7.5.0 UP13 could allow an authenticated user to escalate their privileges via a misconfigured cronjob due to execution wi…

Mitigation only
Fix from $1,950 2025-08-22
Qradar Incident Forensics MEDIUM 5.4
CVE-2025-36042

IBM QRadar SIEM 7.5 through 7.5.0 Dashboard is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary…

Mitigation only
Fix from $1,600 2025-08-22
Soar Qradar Plugin App HIGH 7.5
CVE-2025-36114

IBM QRadar SOAR Plugin App 1.0.0 through 5.6.0 could allow a remote attacker to traverse directories on the system. An attacker could send a speciall…

Fix: after 5.6.0
Fix from $1,950 2025-08-20
Edge Application Manager MEDIUM 5.4
CVE-2025-1142

IBM Edge Application Manager 4.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized r…

Mitigation only
Fix from $1,600 2025-08-20
Sterling B2b Integrator MEDIUM 6.5
CVE-2025-2988

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7, 6.2.0.0 through 6.2.0.4, and 6.2.1.0 could disclose sensitive serv…

Fix: 6.1.2.7_1 / 6.2.0.5+
Fix from $1,600 2025-08-19
Sterling B2b Integrator MEDIUM 5.4
CVE-2025-33008

IBM Sterling B2B Integrator 6.2.1.0 and IBM Sterling File Gateway 6.2.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authent…

Mitigation only
Fix from $1,600 2025-08-19
Storage Virtualize HIGH 8.8
CVE-2025-36120

IBM Storage Virtualize 8.4, 8.5, 8.6, and 8.7 could allow an authenticated user to escalate their privileges in an SSH session due to incorrect autho…

Fix: 8.4.0.18 / 8.5.0.16+
Fix from $1,950 2025-08-18
Concert HIGH 7.5
CVE-2025-33100

IBM Concert Software 1.0.0 through 1.1.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inboun…

Fix: 2.0.0+
Fix from $1,950 2025-08-18
Concert CRITICAL 9.8
CVE-2025-27909

IBM Concert Software 1.0.0 through 1.1.0 uses cross-origin resource sharing (CORS) which could allow an attacker to carry out privileged actions as t…

Fix: 2.0.0+
Fix from $2,300 2025-08-18
Concert HIGH 7.5
CVE-2024-49827

IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to excessive data exposure, allowing attackers to access sensitive information without proper …

Fix: 2.0.0+
Fix from $1,950 2025-08-18
Concert HIGH 7.5
CVE-2025-1759

IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing…

Fix: 2.0.0+
Fix from $1,950 2025-08-18
Concert HIGH 7.5
CVE-2025-33090

IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to cause a denial of service using a specially crafted regular expression that…

Fix: 2.0.0+
Fix from $1,950 2025-08-18