Vulnerability index

Browse CVEs

6,286 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Entirex MEDIUM 6.5
CVE-2024-54169

IBM EntireX 11.1 could allow an authenticated attacker to traverse directories on the system. An attacker could send a specially crafted URL request …

Mitigation only
Fix from $1,600 2025-02-27
Entirex MEDIUM 5.5
CVE-2024-54170

IBM EntireX 11.1 could allow a local user to cause a denial of service due to use of a regular expression with an inefficient complexity that consume…

Mitigation only
Fix from $1,600 2025-02-27
Cloud Pak For Data MEDIUM 6.1
CVE-2025-0719

IBM Cloud Pak for Data 4.0.0 through 4.8.5 and 5.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to …

Fix: after 4.8.5
Fix from $1,600 2025-02-26
I HIGH 8.5
CVE-2024-55898

IBM i 7.2, 7.3, 7.4, and 7.5 could allow a user with the capability to compile or restore a program to gain elevated privileges due to an unqualified…

Mitigation only
Fix from $1,950 2025-02-24
Watson Query With Cloud Pak For Data HIGH 7.5
CVE-2024-22341

IBM Watson Query on Cloud Pak for Data 4.0.0 through 4.0.9, 4.5.0 through 4.5.3, 4.6.0 through 4.6.6, 4.7.0 through 4.7.4, and 4.8.0 through 4.8.7 co…

Fix: after 4.8.7
Fix from $1,950 2025-02-22
Qiskit HIGH 8.6
CVE-2025-1403

Qiskit SDK 0.45.0 through 1.2.4 could allow a remote attacker to cause a denial of service using a maliciously crafted QPY file containing a malforme…

Fix: after 1.2.4
Fix from $1,950 2025-02-21
Security Verify Bridge Directory Sync MEDIUM 5.5
CVE-2024-45673

IBM Security Verify Bridge Directory Sync 1.0.1 through 1.0.12, IBM Security Verify Gateway for Windows Login 1.0.1 through 1.0.10, and IBM Security …

Fix: after 1.0.12
Fix from $1,600 2025-02-21
Security Verify Access HIGH 7.8
CVE-2025-0161

IBM Security Verify Access Appliance 10.0.0.0 through 10.0.0.9 and 11.0.0.0 could allow a local user to execute arbitrary code due to improper restri…

Fix: after 10.0.0.9
Fix from $1,950 2025-02-20
Openpages With Watson HIGH 8.8
CVE-2024-49779

IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages could allow a remote attacker to bypass security restrictions, caused by improper validation an…

Fix: 8.3.0.3 / 9.0.0.5+
Fix from $1,950 2025-02-20
Openpages With Watson HIGH 7.1
CVE-2024-49781

IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote…

Fix: 8.3.0.3 / 9.0.0.5+
Fix from $1,950 2025-02-20
Openpages With Watson MEDIUM 5.4
CVE-2024-49337

IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages is vulnerable to HTML injection, caused by improper validation of user-supplied input of te…

Fix: 8.3.0.3 / 9.0.0.5+
Fix from $1,600 2025-02-20
Openpages With Watson HIGH 8.2
CVE-2024-49782

IBM OpenPages with Watson 8.3 and 9.0  could allow a remote attacker to spoof mail server identity when using SSL/TLS security. An attacker could …

Fix: 8.3.0.3 / 9.0.0.5+
Fix from $1,950 2025-02-20
Openpages With Watson MEDIUM 6.5
CVE-2024-49355

IBM OpenPages with Watson 8.3 and 9.0 may write improperly neutralized data to server log files when the tracing is enabled per the System Tracing fe…

Fix: 8.3.0.3 / 9.0.0.5+
Fix from $1,600 2025-02-20
Openpages With Watson MEDIUM 6.5
CVE-2024-49780

IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages could allow a remote attacker to traverse directories on the system. An attacker with privileges …

Fix: 8.3.0.3 / 9.0.0.5+
Fix from $1,600 2025-02-20
Cognos Controller HIGH 8.2
CVE-2023-47160

IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to an XML External Entity Injection (XXE) attack when p…

Fix: 11.0.1.4+
Fix from $1,950 2025-02-19
Cognos Controller HIGH 8.8
CVE-2024-28777

IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to unrestricted deserialization. This vulnerability allow…

Fix: 11.0.1.4+
Fix from $1,950 2025-02-19
Cognos Controller HIGH 8.0
CVE-2024-45084

IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 could allow an authenticated attacker to conduct formula injection. An at…

Fix: 11.0.1.4+
Fix from $1,950 2025-02-19
Cognos Controller MEDIUM 6.5
CVE-2024-45081

IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 could allow an authenticated user to modify restricted content due to i…

Fix: 11.0.1.4+
Fix from $1,600 2025-02-19
Cognos Controller MEDIUM 5.9
CVE-2024-28780

IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 Rich Client  uses weaker than expected cryptographic algorithms that c…

Fix: 11.0.1.4+
Fix from $1,600 2025-02-19
Cognos Controller MEDIUM 5.4
CVE-2024-28776

IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to…

Fix: 11.0.1.4+
Fix from $1,600 2025-02-19
Cognos Controller HIGH 8.8
CVE-2024-52902

IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 client application contains hard coded database passwords in source code wh…

Fix: 11.0.1.4+
Fix from $1,950 2025-02-19
Power Hardware Management Console MEDIUM 6.5
CVE-2024-56477

IBM Power Hardware Management Console V10.3.1050.0 could allow an authenticated user to traverse directories on the system. An attacker could send a …

Mitigation only
Fix from $1,600 2025-02-14
I MEDIUM 6.5
CVE-2024-52895

IBM i 7.4 and 7.5 is vulnerable to a database access denial of service caused by a bypass of a database capabilities restriction check. A privileged …

Mitigation only
Fix from $1,600 2025-02-14
Devops Deploy HIGH 7.2
CVE-2024-55904

IBM DevOps Deploy 8.0 through 8.0.1.4, 8.1 through 8.1.0.0 / IBM UrbanCode Deploy 7.0 through 7.0.5.25, 7.1 through 7.1.2.21, 7.2 through 7.2.3.14, a…

Fix: 7.0.5.26 / 7.1.2.22+
Fix from $1,950 2025-02-14
Devops Deploy MEDIUM 6.5
CVE-2024-54176

IBM DevOps Deploy 8.0 through 8.0.1.4, 8.1 through 8.1.0.0 and IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.25, 7.1 through 7.1.2.21, 7.2 through 7.2…

Fix: 7.0.5.26 / 7.1.2.22+
Fix from $1,600 2025-02-08
Entirex HIGH 7.1
CVE-2024-54171

IBM EntireX 11.1 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. An authenticated attacker could exploit thi…

Mitigation only
Fix from $1,950 2025-02-06
Entirex MEDIUM 5.5
CVE-2025-0158

IBM EntireX 11.1 could allow a local user to cause a denial of service due to an unhandled error and fault isolation.

Mitigation only
Fix from $1,600 2025-02-06
Jazz For Service Management MEDIUM 6.1
CVE-2024-52892

IBM Jazz for Service Management 1.1.3 through 1.1.3.23 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker t…

Fix: 1.1.3.24+
Fix from $1,600 2025-02-06
Security Verify Directory HIGH 8.8
CVE-2024-51450

IBM Security Verify Directory 10.0.0 through 10.0.3 could allow a remote authenticated attacker to execute arbitrary commands on the system by sendin…

Fix: after 10.0.3
Fix from $1,950 2025-02-06
App Connect Enterprise MEDIUM 6.5
CVE-2025-0799

IBM App Connect enterprise 12.0.1.0 through 12.0.12.10 and 13.0.1.0 through 13.0.2.1 could allow an authenticated user to write to an arbitrary file …

Fix: after 13.0.2.1
Fix from $1,600 2025-02-06