Vulnerability index

Browse CVEs

6,286 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Security Verify Access HIGH 7.8
CVE-2024-49814

IBM Security Verify Access Appliance 10.0.0 through 10.0.3 could allow a locally authenticated user to increase their privileges due to execution wit…

Fix: after 10.0.3
Fix from $1,950 2025-02-06
Applinx MEDIUM 6.5
CVE-2024-49800

IBM ApplinX 11.1 stores sensitive information in cleartext in memory that could be obtained by an authenticated user.

Mitigation only
Fix from $1,600 2025-02-06
Applinx MEDIUM 5.9
CVE-2024-49797

IBM ApplinX 11.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Securi…

Mitigation only
Fix from $1,600 2025-02-06
Applinx MEDIUM 5.4
CVE-2024-49796

IBM ApplinX 11.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a r…

Mitigation only
Fix from $1,600 2025-02-06
Applinx MEDIUM 5.4
CVE-2024-49791

IBM ApplinX 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web…

Mitigation only
Fix from $1,600 2025-02-06
Applinx MEDIUM 5.4
CVE-2024-49792

IBM ApplinX 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web…

Mitigation only
Fix from $1,600 2025-02-06
Applinx MEDIUM 5.4
CVE-2024-49793

IBM ApplinX 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web…

Mitigation only
Fix from $1,600 2025-02-06
Aspera Shares MEDIUM 5.4
CVE-2024-56472

IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbi…

Fix: 1.10.0+
Fix from $1,600 2025-02-05
Aspera Shares MEDIUM 5.3
CVE-2024-56473

IBM Aspera Shares 1.9.0 through 1.10.0 PL6 could allow an attacker to spoof their IP address, which is written to log files, due to improper verific…

Fix: 1.10.0+
Fix from $1,600 2025-02-05
Aspera Shares MEDIUM 6.1
CVE-2024-38318

IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, wo…

Fix: 1.10.0+
Fix from $1,600 2025-02-05
Aspera Shares MEDIUM 5.4
CVE-2024-56470

IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send una…

Fix: 1.10.0+
Fix from $1,600 2025-02-05
Aspera Shares MEDIUM 5.4
CVE-2024-56471

IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send una…

Fix: 1.10.0+
Fix from $1,600 2025-02-05
Aspera Shares MEDIUM 6.5
CVE-2024-38316

IBM Aspera Shares 1.9.0 through 1.10.0 PL6 does not properly rate limit the frequency that an authenticated user can send emails, which could result …

Fix: 1.10.0+
Fix from $1,600 2025-02-05
Cloud Pak For Business Automation MEDIUM 6.5
CVE-2024-49348

IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.…

Mitigation only
Fix from $1,600 2025-02-05
Cloud Pak For Business Automation MEDIUM 5.4
CVE-2024-52364

IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.…

Mitigation only
Fix from $1,600 2025-02-05
Cloud Pak For Business Automation MEDIUM 5.4
CVE-2024-52365

IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.…

Mitigation only
Fix from $1,600 2025-02-05
Cognos Analytics HIGH 7.1
CVE-2024-49352

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 is vulnerable to an XML External Entity Injec…

Fix: 11.2.4 / 12.0.4+
Fix from $1,950 2025-02-05
Security Verify Access HIGH 7.5
CVE-2024-43187

IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 transmits sensitive or security-critical data in cleartext in a communicatio…

Fix: 10.0.9.0+
Fix from $1,950 2025-02-04
Security Verify Access MEDIUM 6.7
CVE-2024-45657

IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a local privileged user to perform unauthorized actions due to i…

Fix: 10.0.9.0+
Fix from $1,600 2025-02-04
Security Verify Access MEDIUM 6.5
CVE-2024-35138

IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 is vulnerable to cross-site request forgery which could allow an attacker to…

Fix: after 10.0.8
Fix from $1,600 2025-02-04
Security Verify Access MEDIUM 6.1
CVE-2024-40700

IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 is vulnerable to cross-site scripting. This vulnerability allows an unauthen…

Fix: 10.0.9.0+
Fix from $1,600 2025-02-04
Security Verify Access MEDIUM 5.3
CVE-2024-45658

IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a remote attacker to obtain sensitive information when a detaile…

Fix: after 10.0.8
Fix from $1,600 2025-02-04
Security Verify Access MEDIUM 5.3
CVE-2024-45659

IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a remote attacker to obtain sensitive information when a detaile…

Fix: 10.0.9.0+
Fix from $1,600 2025-02-04
Financial Transaction Manager For Multiplatform MEDIUM 5.4
CVE-2024-49339

IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.1 is vulnerable to stored cross-site scripting. This vu…

Fix: after 3.2.4.13
Fix from $1,600 2025-01-31
Financial Transaction Manager For Multiplatform MEDIUM 5.4
CVE-2024-49349

IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.1 is vulnerable to stored cross-site scripting. This vu…

Fix: after 3.2.4.13
Fix from $1,600 2025-01-31
Sterling B2b Integrator MEDIUM 5.4
CVE-2024-47103

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to cross-site scripting. This vulnerab…

Fix: after 6.2.0.3
Fix from $1,600 2025-01-31
Sterling B2b Integrator MEDIUM 5.4
CVE-2024-47116

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to cross-site scripting. This vulnerab…

Fix: after 6.2.0.3
Fix from $1,600 2025-01-31
Sterling B2b Integrator MEDIUM 5.4
CVE-2024-49807

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to stored cross-site scripting. This v…

Fix: after 6.2.0.3
Fix from $1,600 2025-01-31
Sterling B2b Integrator MEDIUM 5.4
CVE-2024-40696

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to cross-site scripting. This vulnerab…

Fix: after 6.2.0.3
Fix from $1,600 2025-01-31
Sterling B2b Integrator HIGH 8.8
CVE-2023-38739

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 is vulnerable to cross-site request forgery which could allow an atta…

Fix: after 6.2.0.3
Fix from $1,950 2025-01-31