Vulnerability index

Browse CVEs

6,286 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Security Verify Directory HIGH 7.5
CVE-2024-45650

IBM Security Verify Directory 10.0 through 10.0.3 is vulnerable to a denial of service when sending an LDAP extended operation.

Fix: after 10.0.3
Fix from $1,950 2025-01-31
App Connect Enterprise Certified Container CRITICAL 9.1
CVE-2022-43916

IBM App Connect Enterprise Certified Container 7.1, 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12…

Fix: 12.8+
Fix from $2,300 2025-01-30
Aspera Faspex CRITICAL 9.8
CVE-2023-35907

IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes it easier for attackers to co…

Fix: after 5.0.10
Fix from $2,300 2025-01-29
Aspera Faspex CRITICAL 9.8
CVE-2023-37398

IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes it easier for attackers to co…

Fix: after 5.0.10
Fix from $2,300 2025-01-29
Aspera Faspex MEDIUM 5.3
CVE-2023-37413

IBM Aspera Faspex 5.0.0 through 5.0.10 could disclose sensitive username information due to an observable response discrepancy.

Fix: after 5.0.10
Fix from $1,600 2025-01-29
Security Verify Governance MEDIUM 5.9
CVE-2023-35017

IBM Security Verify Governance 10.0.2 Identity Manager can transmit user credentials in clear text that could be obtained by an attacker using man in…

Mitigation only
Fix from $1,600 2025-01-29
Storage Fusion MEDIUM 6.5
CVE-2024-22315

IBM Fusion and IBM Fusion HCI 2.3.0 through 2.8.2 is vulnerable to insecure network connection by allowing an attacker who gains access to a Fusion c…

Fix: 2.9.0+
Fix from $1,600 2025-01-28
Sterling B2b Integrator CRITICAL 9.8
CVE-2023-50316

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 is vulnerable to SQL injection. A remote attacker could send speciall…

Fix: after 6.2.0.1
Fix from $2,300 2025-01-28
Sterling B2b Integrator MEDIUM 5.3
CVE-2024-27263

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an authenticated user to obtain sensitive information fro…

Fix: after 6.2.0.1
Fix from $1,600 2025-01-28
Qradar Security Information And Event Manager MEDIUM 6.5
CVE-2024-28786

IBM QRadar SIEM 7.5 transmits sensitive or security-critical data in cleartext in a communication channel that could be obtained by an unauthorized a…

Mitigation only
Fix from $1,600 2025-01-28
Data Virtualization On Cloud Pak For Data MEDIUM 6.5
CVE-2024-37526

IBM Watson Query on Cloud Pak for Data (IBM Data Virtualization 1.8, 2.0, 2.1, 2.2, and 3.0.0) could allow an authenticated user to obtain sensitive …

No fix yet
Fix from $1,600 2025-01-27
Mq Operator HIGH 7.5
CVE-2024-27256

IBM MQ Container 3.0.0, 3.0.1, 3.1.0 through 3.1.3 CD, 2.0.0 LTS through 2.0.22 LTS and 2.4.0 through 2.4.8, 2.3.0 through 2.3.3, 2.2.0 through 2.2.2…

Fix: after 3.1.3
Fix from $1,950 2025-01-27
Storage Defender HIGH 7.5
CVE-2024-38325

IBM Storage Defender 2.0.0 through 2.0.7 on-prem defender-sensor-cmd CLI could allow a remote attacker to obtain sensitive information, caused by s…

Fix: 2.0.8+
Fix from $1,950 2025-01-27
Storage Protect For Virtual Environments HIGH 7.5
CVE-2024-38320

IBM Storage Protect for Virtual Environments: Data Protection for VMware and Storage Protect Backup-Archive Client 8.1.0.0 through 8.1.23.0 uses weak…

Fix: 8.1.24.0+
Fix from $1,950 2025-01-27
Openpages With Watson MEDIUM 5.4
CVE-2024-37527

IBM OpenPages with Watson 8.3 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaS…

Fix: 8.3.0.3 / 9.0.0.4+
Fix from $1,600 2025-01-27
Sterling File Gateway MEDIUM 5.4
CVE-2023-52292

IBM Sterling File Gateway 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 is vulnerable to stored cross-site scripting. This vulnerability allows…

Fix: after 6.2.0.3
Fix from $1,600 2025-01-27
Security Directory Integrator HIGH 7.5
CVE-2024-28766

IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 could disclose sensitive information about directory cont…

Mitigation only
Fix from $1,950 2025-01-27
Security Directory Integrator MEDIUM 6.5
CVE-2024-28770

IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attribute on authorization tokens…

Mitigation only
Fix from $1,600 2025-01-27
Security Directory Integrator MEDIUM 6.5
CVE-2024-28771

IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attribute on authorization tokens…

Mitigation only
Fix from $1,600 2025-01-27
Infosphere Master Data Management MEDIUM 5.4
CVE-2023-46187

IBM InfoSphere Master Data Management 11.6, 12.0, and 14.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arb…

Mitigation only
Fix from $1,600 2025-01-27
Common Licensing MEDIUM 6.5
CVE-2023-50946

IBM Common Licensing 9.0 could allow an authenticated user to modify a configuration file that they should not have access to due to a broken author…

Mitigation only
Fix from $1,600 2025-01-26
Cognos Analytics MEDIUM 5.9
CVE-2023-38009

IBM Cognos Mobile Client 1.1 iOS may be vulnerable to information disclosure through man in the middle techniques due to the lack of certificate pinn…

Mitigation only
Fix from $1,600 2025-01-26
Common Licensing MEDIUM 5.5
CVE-2023-50945

IBM Common Licensing 9.0 stores user credentials in plain clear text which can be read by a local user.

Mitigation only
Fix from $1,600 2025-01-26
Automation Decision Services MEDIUM 6.2
CVE-2024-31906

IBM Automation Decision Services 23.0.2 allows web pages to be stored locally which can be read by another user on the system.

Mitigation only
Fix from $1,600 2025-01-26
Maximo Application Suite HIGH 8.8
CVE-2024-35148

IBM Maximo Application Suite 8.10.10, 8.11.7, and 9.0 - Monitor Component is vulnerable to SQL injection. A remote attacker could send specially craf…

Mitigation only
Fix from $1,950 2025-01-25
Maximo Application Suite MEDIUM 6.1
CVE-2024-35145

IBM Maximo Application Suite 9.0.0 - Monitor Component is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker t…

Mitigation only
Fix from $1,600 2025-01-25
Maximo Application Suite MEDIUM 5.3
CVE-2024-35150

IBM Maximo Application Suite 8.10.12, 8.11.0, 9.0.1, and 9.1.0 - Monitor Component does not neutralize output that is written to logs, which could al…

Fix: 8.10.15 / 8.11.13+
Fix from $1,600 2025-01-25
Maximo Application Suite MEDIUM 5.3
CVE-2024-35144

IBM Maximo Application Suite 8.10, 8.11, and 9.0 - Monitor Component stores source code on the web server that could aid in further attacks against t…

Fix: 8.10.14 / 8.11.11+
Fix from $1,600 2025-01-25
Analytics Content Hub HIGH 8.8
CVE-2024-39750

IBM Analytics Content Hub 2.0 is vulnerable to a buffer overflow due to improper return length checking. A remote authenticated attacker could overfl…

Fix: 2.3+
Fix from $1,950 2025-01-25
Control Center MEDIUM 6.5
CVE-2024-35113

IBM Control Center 6.2.1 and 6.3.1 could allow an authenticated user to obtain sensitive information exposed through a directory listing.

Mitigation only
Fix from $1,600 2025-01-25