Vulnerability index

Browse CVEs

6,286 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Sterling Connect Direct Web Services MEDIUM 6.5
CVE-2024-49808

IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 could allow an authenticated user to spoof the identity of another user due to impro…

Fix: 6.1.0.28 / 6.2.0.27+
Fix from $1,600 2025-04-18
Sterling Connect Direct Web Services MEDIUM 6.5
CVE-2024-45651

IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 does not invalidate session after a browser closure which could allow an authentic…

Fix: 6.1.0.28 / 6.2.0.27+
Fix from $1,600 2025-04-18
I CRITICAL 9.8
CVE-2025-2947

IBM i 7.6  contains a privilege escalation vulnerability due to incorrect profile swapping in an OS command.  A malicious actor can use the command …

Mitigation only
Fix from $2,300 2025-04-17
Storage Defender Resiliency Service HIGH 7.5
CVE-2024-22314

IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.12 uses weaker than expected cryptographic algorithms that could allow an attacker to dec…

Fix: 2.0.13+
Fix from $1,950 2025-04-16
Aspera Console HIGH 8.8
CVE-2023-27272

IBM Aspera Console 3.4.0 through 3.4.4 allows passwords to be reused when a new user logs into the system.

Fix: 3.4.5+
Fix from $1,950 2025-04-14
Aspera Console HIGH 7.5
CVE-2022-43851

IBM Aspera Console 3.4.0 through 3.4.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive i…

Fix: 3.4.5+
Fix from $1,950 2025-04-14
Aspera Console MEDIUM 5.3
CVE-2022-43852

IBM Aspera Console 3.4.0 through 3.4.4 could disclose sensitive information in HTTP headers that could be used in further attacks against the system.

Fix: 3.4.5+
Fix from $1,600 2025-04-14
Aspera Console MEDIUM 5.4
CVE-2022-43847

IBM Aspera Console 3.4.0 through 3.4.4 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This cou…

Fix: 3.4.5+
Fix from $1,600 2025-04-14
Aspera Console MEDIUM 5.4
CVE-2022-43850

IBM Aspera Console 3.4.0 through 3.4.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in …

Fix: 3.4.5+
Fix from $1,600 2025-04-14
Aspera Faspex MEDIUM 5.4
CVE-2025-3423

IBM Aspera Faspex 5.0.0 through 5.0.11 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary Java…

Fix: 5.0.12+
Fix from $1,600 2025-04-13
Qradar Wincollect MEDIUM 6.5
CVE-2024-51461

IBM QRadar WinCollect Agent 10.0 through 10.1.13 could allow a remote attacker to cause a denial of service by interrupting an HTTP request that coul…

Fix: 10.1.14+
Fix from $1,600 2025-04-11
Maximo Application Suite MEDIUM 6.5
CVE-2023-43037

IBM Maximo Application Suite 8.11 and 9.0 could allow an authenticated user to perform unauthorized actions due to improper input validation.

Fix: 8.11.13+
Fix from $1,600 2025-04-10
Sterling Control Center MEDIUM 5.4
CVE-2023-42007

IBM Sterling Control Center 6.2.1, 6.3.1, and 6.4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScr…

Mitigation only
Fix from $1,600 2025-04-10
Security Verify Governance MEDIUM 5.4
CVE-2023-33844

IBM Security Verify Governance 10.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in th…

Mitigation only
Fix from $1,600 2025-04-09
Personal Communications HIGH 7.8
CVE-2025-1095

IBM Personal Communications v14 and v15 include a Windows service that is vulnerable to local privilege escalation (LPE). The vulnerability allows an…

Mitigation only
Fix from $1,950 2025-04-08
Maximo Application Suite HIGH 8.0
CVE-2025-1500

IBM Maximo Application Suite 9.0 could allow an authenticated user to upload a file with dangerous types that could be executed by another user if op…

Fix: 9.0.7+
Fix from $1,950 2025-04-05
Txseries For Multiplatforms HIGH 7.5
CVE-2025-0154

IBM TXSeries for Multiplatforms 9.1 and 11.1 could disclose sensitive information to a remote attacker due to improper neutralization of HTTP headers.

Mitigation only
Fix from $1,950 2025-04-02
Txseries For Multiplatforms MEDIUM 5.3
CVE-2024-56476

IBM TXSeries for Multiplatforms 9.1 and 11.1 could allow an attacker to enumerate usernames due to an observable login attempt response discrepancy.

Mitigation only
Fix from $1,600 2025-04-02
Txseries For Multiplatforms HIGH 8.8
CVE-2024-56474

IBM TXSeries for Multiplatforms 9.1 and 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unaut…

Mitigation only
Fix from $1,950 2025-04-02
Txseries For Multiplatforms MEDIUM 5.4
CVE-2024-56475

IBM TXSeries for Multiplatforms 9.1 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrar…

Mitigation only
Fix from $1,600 2025-04-02
Content Navigator MEDIUM 5.4
CVE-2024-56341

IBM Content Navigator 3.0.11, 3.0.15, and 3.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbit…

Mitigation only
Fix from $1,600 2025-04-02
Jazz Reporting Service HIGH 7.2
CVE-2024-25051

IBM Jazz Reporting Service 7.0.2 and 7.0.3 does not invalidate session after logout which could allow an authenticated privileged user to impersonate…

Mitigation only
Fix from $1,950 2025-04-02
Infosphere Information Server MEDIUM 5.3
CVE-2024-55895

IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is retur…

Fix: 11.7.1+
Fix from $1,600 2025-03-29
Infosphere Information Server HIGH 7.5
CVE-2024-7577

IBM InfoSphere Information Server 11.7 could disclose sensitive user credentials from log files during new installation of the product.

Fix: 11.7.1+
Fix from $1,950 2025-03-29
Infosphere Information Server MEDIUM 6.5
CVE-2024-43186

IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information that is stored locally under certain conditi…

Fix: 11.7.1+
Fix from $1,600 2025-03-29
Infosphere Information Server MEDIUM 6.5
CVE-2024-51477

IBM InfoSphere Information Server 11.7 could allow an authenticated to obtain sensitive username information due to an observable response discrepa…

Fix: 11.7.1+
Fix from $1,600 2025-03-29
Cloud Pak System HIGH 7.5
CVE-2023-38272

IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.36 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, 2.3.4.0, and 2.…

Mitigation only
Fix from $1,950 2025-03-27
Cloud Pak System MEDIUM 6.5
CVE-2023-37405

IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.36 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, 2.3.4.0, and 2.…

Mitigation only
Fix from $1,600 2025-03-27
Devops Deploy MEDIUM 5.5
CVE-2025-1998

IBM UrbanCode Deploy (UCD) through 7.1.2.21, 7.2 through 7.2.3.14, and 7.3 through 7.3.2.0 / IBM DevOps Deploy 8.0 through 8.0.1.4 and 8.1 through 8.…

Fix: 7.1.2.22 / 7.2.3.15+
Fix from $1,600 2025-03-27
Devops Deploy MEDIUM 6.3
CVE-2024-56469

IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.22, 7.2 through 7.2.3.15, and 7.3 through 7.3.2.10 / IBM DevOps Deploy 8.0 through 8.0.1.5 and 8.1 throu…

Fix: 7.1.2.23 / 7.2.3.16+
Fix from $1,600 2025-03-27