Vulnerability index

Browse CVEs

6,286 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Semeru Runtime HIGH 7.5
CVE-2025-2900

IBM Semeru Runtime 8.0.302.0 through 8.0.442.0, 11.0.12.0 through 11.0.26.0, 17.0.0.0 through 17.0.14.0, and 21.0.0.0 through 12.0.6.0 is vulnerable …

Fix: after 21.0.6.0
Fix from $1,950 2025-05-14
4769 Developers Toolkit HIGH 7.5
CVE-2025-3632

IBM 4769 Developers Toolkit 7.0.0 through 7.5.52 could allow a remote attacker to cause a denial of service in the Hardware Security Module (HSM) due…

Fix: 7.5.62+
Fix from $1,950 2025-05-12
Storage Scale HIGH 8.8
CVE-2025-1137

IBM Storage Scale 5.2.2.0 and 5.2.2.1, under certain configurations, could allow an authenticated user to execute privileged commands due to improper…

Mitigation only
Fix from $1,950 2025-05-10
App Connect Enterprise Certified Containers Operands MEDIUM 5.5
CVE-2025-1993

IBM App Connect Enterprise Certified Container 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, 12.3,…

Fix: after 12.10.0
Fix from $1,600 2025-05-09
Cics Tx HIGH 7.8
CVE-2025-1330

IBM CICS TX Standard 11.1 and IBM CICS TX Advanced 10.1 and 11.1  could allow a local user to execute arbitrary code on the system due to failure to …

Mitigation only
Fix from $1,950 2025-05-08
Cics Tx HIGH 7.8
CVE-2025-1331

IBM CICS TX Standard 11.1 and IBM CICS TX Advanced 10.1 and 11.1 could allow a local user to execute arbitrary code on the system due to the use of u…

Mitigation only
Fix from $1,950 2025-05-08
Cics Tx HIGH 7.8
CVE-2025-1329

IBM CICS TX Standard 11.1 and IBM CICS TX Advanced 10.1 and 11.1 could allow a local user to execute arbitrary code on the system due to failure to h…

Mitigation only
Fix from $1,950 2025-05-08
Sterling Partner Engagement Manager HIGH 7.5
CVE-2025-33093

IBM Sterling Partner Engagement Manager 6.1.0, 6.2.0, 6.2.2 JWT secret is stored in public Helm Charts and is not stored as a Kubernetes secret.

Mitigation only
Fix from $1,950 2025-05-07
I MEDIUM 5.4
CVE-2025-3218

IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 is vulnerable to authentication and authorization attacks due to incorrect validation processing in IBM i Netserver…

Mitigation only
Fix from $1,600 2025-05-07
Maximo Application Suite HIGH 8.8
CVE-2025-2898

IBM Maximo Application Suite 9.0 could allow an attacker with some level of access to elevate their privileges due to a security configuration vulner…

Mitigation only
Fix from $1,950 2025-05-06
Db2 MEDIUM 6.5
CVE-2025-1000

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 could allow an authenticated user…

Fix: after 12.1.1
Fix from $1,600 2025-05-05
Db2 MEDIUM 5.3
CVE-2025-1493

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 12.1.0 through 12.1.1 could allow an authenticated user to cause a denial of …

Fix: after 12.1.1
Fix from $1,600 2025-05-05
Db2 MEDIUM 6.5
CVE-2025-0915

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 under specific configurations c…

Fix: after 12.1.1
Fix from $1,600 2025-05-05
Db2 MEDIUM 6.5
CVE-2025-1992

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 could allow an authenticated user i…

Fix: after 11.5.9
Fix from $1,600 2025-05-05
Cloud Pak For Business Automation MEDIUM 6.5
CVE-2025-1838

IBM Cloud Pak for Business Automation 24.0.0 and 24.0.1 through 24.0.1 IF001 Authoring allows an authenticated user to bypass client-side data va…

Mitigation only
Fix from $1,600 2025-05-03
Cloud Pak For Business Automation MEDIUM 6.1
CVE-2024-41753

IBM Cloud Pak for Business Automation 24.0.0 through 24.0.0 IF004 and 24.0.1 through 24.0.1 IF001 is vulnerable to cross-site scripting. This vulnera…

Mitigation only
Fix from $1,600 2025-05-03
Concert MEDIUM 5.9
CVE-2024-55912

IBM Concert Software 1.0.0 through 1.0.5 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive …

Fix: 1.1.0+
Fix from $1,600 2025-05-02
Concert MEDIUM 5.3
CVE-2024-55913

IBM Concert Software 1.0.0 through 1.0.5 could allow a remote attacker to traverse directories on the system. An attacker could send a specially craf…

Fix: 1.1.0+
Fix from $1,600 2025-05-02
Concert MEDIUM 6.5
CVE-2024-55910

IBM Concert Software 1.0.0 through 1.0.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauth…

Fix: 1.1.0+
Fix from $1,600 2025-05-02
Concert MEDIUM 6.5
CVE-2024-55909

IBM Concert Software 1.0.0 through 1.0.5 could allow an authenticated user to cause a denial of service due to the expansion of archive files without…

Fix: 1.1.0+
Fix from $1,600 2025-05-02
Db2 HIGH 7.5
CVE-2024-52903

IBM Db2 for Linux, UNIX and Windows 12.1.0 and 12.1.1 is vulnerable to a denial of service as the server may crash under certain conditions with a sp…

Fix: after 12.1.1
Fix from $1,950 2025-05-01
Mq Operator MEDIUM 6.5
CVE-2025-27365

IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1, and MQ Operator SC2 3.…

Fix: after 3.2.10
Fix from $1,600 2025-05-01
Mq Operator MEDIUM 6.5
CVE-2025-1333

IBM MQ Container when used with the IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, …

Fix: after 3.2.10
Fix from $1,600 2025-05-01
Operational Decision Manager MEDIUM 6.1
CVE-2025-1551

IBM Operational Decision Manager 8.11.0.1, 8.11.1.0, 8.12.0.1, and 9.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows an unauth…

Mitigation only
Fix from $1,600 2025-04-29
Maximo Asset Management MEDIUM 5.4
CVE-2025-2986

IBM Maximo Asset Management 7.6.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary Java…

Mitigation only
Fix from $1,600 2025-04-25
Infosphere Information Server MEDIUM 6.3
CVE-2024-22351

IBM InfoSphere Information 11.7 Server does not invalidate session after logout which could allow an authenticated user to impersonate another user o…

Fix: 11.7.1+
Fix from $1,600 2025-04-23
Hardware Management Console HIGH 7.8
CVE-2025-1950

IBM Hardware Management Console - Power Systems V10.2.1030.0 and V10.3.1050.0 could allow a local user to execute commands locally due to improper va…

Mitigation only
Fix from $1,950 2025-04-22
Hardware Management Console MEDIUM 6.7
CVE-2025-1951

IBM Hardware Management Console - Power Systems V10.2.1030.0 and V10.3.1050.0 could allow a local user to execute commands as a privileged user due t…

Mitigation only
Fix from $1,600 2025-04-22
Maximo Asset Management MEDIUM 5.4
CVE-2025-2987

IBM Maximo Asset Management 7.6.1.3 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorize…

Mitigation only
Fix from $1,600 2025-04-22
I MEDIUM 5.4
CVE-2025-2950

IBM i 7.3, 7.4, 7.5, and 7.5 is vulnerable to a host header injection attack caused by improper neutralization of HTTP header content by IBM Navigato…

Mitigation only
Fix from $1,600 2025-04-18