Vulnerability index

Browse CVEs

6,286 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Spss Statistics HIGH 7.5
CVE-2024-31896

IBM SPSS Statistics 26.0, 27.0.1, 28.0.1, and 29.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highl…

Mitigation only
Fix from $1,950 2025-03-25
Storage Virtualize Plugin For Vsphere MEDIUM 6.8
CVE-2023-43029

IBM Storage Virtualize vSphere Remote Plug-in 1.0 and 1.1 could allow a remote user to obtain sensitive credential information after deployment.

Mitigation only
Fix from $1,600 2025-03-21
Infosphere Information Server HIGH 7.8
CVE-2024-51459

IBM InfoSphere Information Server 11.7 could allow a local user to execute privileged commands due to the improper handling of permissions.

Fix: 11.7.1.136+
Fix from $1,950 2025-03-19
Aix CRITICAL 10.0
CVE-2024-56346

IBM AIX 7.2 and 7.3 nimesis NIM master service could allow a remote attacker to execute arbitrary commands due to improper process controls.

Mitigation only
Fix from $2,300 2025-03-18
Aix CRITICAL 9.6
CVE-2024-56347

IBM AIX 7.2 and 7.3 nimsh service SSL/TLS protection mechanisms could allow a remote attacker to execute arbitrary commands due to improper process c…

Mitigation only
Fix from $2,300 2025-03-18
Security Qradar Edr HIGH 7.5
CVE-2024-45643

IBM Security QRadar 3.12 EDR uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive credential informat…

Fix: 3.12.16+
Fix from $1,950 2025-03-14
Qiskit CRITICAL 9.8
CVE-2025-2000

A maliciously crafted QPY file can potential execute arbitrary-code embedded in the payload without privilege escalation when deserialising QPY forma…

Fix: 1.4.2+
Fix from $2,300 2025-03-14
App Connect Enterprise Certified Containers Operands MEDIUM 6.5
CVE-2024-52362

IBM App Connect Enterprise Certified Container 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12.1, 1…

Fix: 12.9.0+
Fix from $1,600 2025-03-12
Common Cryptographic Architecture MEDIUM 6.5
CVE-2024-22340

IBM Common Cryptographic Architecture 7.0.0 through 7.5.51 could allow a remote attacker to obtain sensitive information during the creation of E…

Fix: 7.5.52+
Fix from $1,600 2025-03-11
Common Cryptographic Architecture MEDIUM 6.5
CVE-2024-49823

IBM Common Cryptographic Architecture 7.0.0 through 7.5.51 could allow an authenticated user to cause a denial of service in the Hardware Security Mo…

Fix: 7.5.52+
Fix from $1,600 2025-03-11
Sterling File Gateway MEDIUM 5.3
CVE-2024-47109

IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 UI could disclosure the installation path of the server which could aid…

Fix: 6.1.2.7 / 6.2.0.4+
Fix from $1,600 2025-03-10
Aspera Shares HIGH 7.1
CVE-2025-0162

IBM Aspera Shares 1.9.9 through 1.10.0 PL7 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenti…

Fix: 1.10.0+
Fix from $1,950 2025-03-07
Control Center MEDIUM 5.3
CVE-2023-43052

IBM Control Center 6.2.1 through 6.3.1 is vulnerable to an external service interaction attack, caused by improper validation of user-supplied input.…

Mitigation only
Fix from $1,600 2025-03-07
Sterling Control Center MEDIUM 6.1
CVE-2023-35894

IBM Control Center 6.2.1 through 6.3.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could…

Mitigation only
Fix from $1,600 2025-03-07
Concert Software HIGH 7.5
CVE-2024-51476

IBM Concert Software 1.0.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.

Mitigation only
Fix from $1,950 2025-03-06
Engineering Requirements Management Doors Next HIGH 7.5
CVE-2024-41771

IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7.1 could allow a remote attacker to download temporary files which could expose…

Mitigation only
Fix from $1,950 2025-03-03
Engineering Requirements Management Doors Next MEDIUM 6.5
CVE-2024-43169

IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7.1 could allow a user to download a malicious file without verifying the integr…

Mitigation only
Fix from $1,600 2025-03-03
Engineering Requirements Management Doors Next HIGH 7.5
CVE-2024-41770

IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7.1 could allow a remote attacker to download temporary files which could expose…

Mitigation only
Fix from $1,950 2025-03-03
Business Automation Workflow MEDIUM 5.4
CVE-2024-54179

IBM Business Automation Workflow and IBM Business Automation Workflow Enterprise Service Bus 24.0.0, 24.0.1 and earlier unsupported versions are vuln…

Fix: after 24.0.1
Fix from $1,600 2025-03-03
Cognos Analytics Mobile MEDIUM 5.3
CVE-2024-55907

IBM Cognos Analytics Mobile 1.1 for iOS application could allow an attacker to reverse engineer the codebase to gain knowledge about the programming …

Fix: 1.1.21+
Fix from $1,600 2025-03-02
Controller MEDIUM 6.5
CVE-2024-41778

IBM Controller 11.0.0 through 11.0.1 and 11.1.0 does not require that users should have strong passwords by default, which makes it easier for attack…

Mitigation only
Fix from $1,600 2025-03-01
Storage Virtualize CRITICAL 9.8
CVE-2025-0160

IBM FlashSystem (IBM Storage Virtualize (8.5.0.0 through 8.5.0.13, 8.5.1.0, 8.5.2.0 through 8.5.2.3, 8.5.3.0 through 8.5.3.1, 8.5.4.0, 8.6.0.0 throug…

Fix: 8.5.0.14 / 8.6.0.6+
Fix from $2,300 2025-02-28
Storage Virtualize CRITICAL 9.1
CVE-2025-0159

IBM FlashSystem (IBM Storage Virtualize (8.5.0.0 through 8.5.0.13, 8.5.1.0, 8.5.2.0 through 8.5.2.3, 8.5.3.0 through 8.5.3.1, 8.5.4.0, 8.6.0.0 throug…

Fix: 8.5.0.14 / 8.6.0.6+
Fix from $2,300 2025-02-28
Mq MEDIUM 5.5
CVE-2024-54175

IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow a local user to cause a denial of service due to an improper check for unusual or exception…

Mitigation only
Fix from $1,600 2025-02-28
Mq MEDIUM 5.5
CVE-2025-0985

IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD stores potentially sensitive information in environment variables that could be obtained by a local use…

Mitigation only
Fix from $1,600 2025-02-28
Mq Appliance HIGH 8.8
CVE-2025-0975

IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD console could allow an authenticated user to execute code due to improper neutralization of escape charac…

Fix: after 9.4.2
Fix from $1,950 2025-02-28
Cognos Analytics MEDIUM 6.5
CVE-2024-56340

IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 is vulnerable to local file inclusion vulnerability, allowing an attacker to access sensitive files by…

Fix: 11.2.4 / 12.0.4+
Fix from $1,600 2025-02-28
Cognos Analytics MEDIUM 6.5
CVE-2025-0823

IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 and 12.0.0 through 12.0.4 could allow a remote attacker to traverse directories on the system. An atta…

Fix: 11.2.4 / 12.0.4+
Fix from $1,600 2025-02-28
Mq Appliance MEDIUM 6.5
CVE-2025-23225

IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow an authenticated user to cause a denial of service due to the improper handling of invalid he…

Fix: after 9.4.2
Fix from $1,600 2025-02-28
Entirex MEDIUM 5.5
CVE-2024-56812

IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information coul…

Mitigation only
Fix from $1,600 2025-02-27