Vulnerability index

Browse CVEs

6,286 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Control Center MEDIUM 5.3
CVE-2024-35114

IBM Control Center 6.2.1 and 6.3.1 could allow a remote attacker to enumerate usernames due to an observable discrepancy between login attempts.

Mitigation only
Fix from $1,600 2025-01-25
Analytics Content Hub MEDIUM 5.3
CVE-2024-35134

IBM Analytics Content Hub 2.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in th…

Fix: 2.3+
Fix from $1,600 2025-01-25
Cloud Pak System HIGH 7.5
CVE-2023-38713

IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, and 2.3.3.7 iFix1 could discl…

Mitigation only
Fix from $1,950 2025-01-25
Cloud Pak System HIGH 7.5
CVE-2023-38714

IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, and 2.3.3.7 iFix1 could discl…

Mitigation only
Fix from $1,950 2025-01-25
Cloud Pak System HIGH 7.5
CVE-2023-38716

IBM Cloud Pak System 2.3.3.6, 2.3.36 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, and 2.3.4.0 could disclose sensitive information about the system …

No fix yet
Fix from $1,950 2025-01-25
Cloud Pak System MEDIUM 6.5
CVE-2023-38271

IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, and 2.3.3.7 iFix1 could allow…

Mitigation only
Fix from $1,600 2025-01-25
Cloud Pak System HIGH 7.5
CVE-2023-38013

IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, and 2.3.3.7 iFix1 could discl…

Mitigation only
Fix from $1,950 2025-01-25
Cloud Pak System MEDIUM 5.3
CVE-2023-38012

IBM Cloud Pak System 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, and 2.3.4.0 could allow a remote attacker to traverse directories…

Mitigation only
Fix from $1,600 2025-01-25
Planning Analytics HIGH 8.0
CVE-2024-40693

IBM Planning Analytics 2.0 and 2.1 could be vulnerable to malicious file upload by not validating the content of the file uploaded to the web interfa…

Mitigation only
Fix from $1,950 2025-01-24
Maximo Asset Management MEDIUM 6.5
CVE-2024-45077

IBM Maximo Asset Management 7.6.1.3 MXAPIASSET API is vulnerable to unrestricted file upload which allows authenticated low privileged user to upload…

Mitigation only
Fix from $1,600 2025-01-24
Concert MEDIUM 5.9
CVE-2024-41757

IBM Concert Software 1.0.0 and 1.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Str…

Mitigation only
Fix from $1,600 2025-01-24
Planning Analytics HIGH 8.8
CVE-2024-25034

IBM Planning Analytics 2.0 and 2.1 could be vulnerable to malicious file upload by not validating the type of file in the File Manager T1 process. At…

Mitigation only
Fix from $1,950 2025-01-24
Cognos Dashboards On Cloud Pak For Data HIGH 8.8
CVE-2024-41739

IBM Cognos Dashboards 4.0.7 and 5.0.0 on Cloud Pak for Data could allow a remote attacker to perform unauthorized actions due to dependency confusion.

Mitigation only
Fix from $1,950 2025-01-24
Tivoli Application Dependency Discovery Manager MEDIUM 5.4
CVE-2025-23227

IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.11 is vulnerable to stored cross-site scripting. This vulnerability allows …

Fix: after 7.3.0.11
Fix from $1,600 2025-01-23
Security Verify Bridge MEDIUM 6.0
CVE-2024-45672

IBM Security Verify Bridge 1.0.0 through 1.0.15 could allow a local privileged user to overwrite files due to excessive privileges granted to the age…

Fix: 1.0.16+
Fix from $1,600 2025-01-23
Sterling B2b Integrator MEDIUM 5.4
CVE-2023-32340

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbit…

Fix: after 6.1.2.5
Fix from $1,600 2025-01-23
Sterling B2b Integrator MEDIUM 5.4
CVE-2023-50309

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embe…

Fix: after 6.1.2.5
Fix from $1,600 2025-01-23
Robotic Process Automation For Cloud Pak MEDIUM 5.4
CVE-2024-51457

IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.19 and 23.0.0 through 23.0.19 is vulnerable to cross-site scripting. This vulnerab…

Fix: 21.0.7.20 / 23.0.20+
Fix from $1,600 2025-01-22
Sterling B2b Integrator HIGH 8.8
CVE-2024-31903

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 allow an attacker on the local network to execute ar…

Fix: after 6.2.0.2
Fix from $1,950 2025-01-22
Urbancode Deploy MEDIUM 5.5
CVE-2024-45091

IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.24, 7.1 through 7.1.2.10, and 7.2 through 7.2.3.13 stores potentially sensitive information in log files…

Fix: 7.0.5.25 / 7.1.2.21+
Fix from $1,600 2025-01-21
Security Verify Access CRITICAL 9.8
CVE-2024-45647

IBM Security Verify Access 10.0.0 through 10.0.8 and IBM Security Verify Access Docker 10.0.0 through 10.0.8 could allow could an unverified user to …

Fix: after 10.0.8
Fix from $2,300 2025-01-20
Sterling Secure Proxy CRITICAL 9.1
CVE-2024-41783

IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow a privileged user to inject commands into the underlyi…

Fix: 6.0.3.1+
Fix from $2,300 2025-01-19
Txseries For Multiplatforms HIGH 7.5
CVE-2024-41742

IBM TXSeries for Multiplatforms 10.1 is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual read operation…

Mitigation only
Fix from $1,950 2025-01-19
Txseries For Multiplatforms HIGH 7.5
CVE-2024-41743

IBM TXSeries for Multiplatforms 10.1 could allow a remote attacker to cause a denial of service using persistent connections due to improper allocati…

Mitigation only
Fix from $1,950 2025-01-19
Sterling Secure Proxy CRITICAL 9.1
CVE-2024-38337

IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow an unauthorized attacker to retrieve or alter sensitiv…

Fix: 6.0.3.1+
Fix from $2,300 2025-01-19
Maximo Asset Management HIGH 7.5
CVE-2024-45652

IBM Maximo MXAPIASSET API 7.6.1.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL…

Mitigation only
Fix from $1,950 2025-01-19
Safer Payments HIGH 7.5
CVE-2024-45662

IBM Safer Payments 6.4.0.00 through 6.4.2.07, 6.5.0.00 through 6.5.0.05, and 6.6.0.00 through 6.6.0.03 could allow a remote attacker to cause a denia…

Fix: 6.4.2.08 / 6.5.0.06+
Fix from $1,950 2025-01-18
Concert HIGH 7.5
CVE-2024-49354

IBM Concert 1.0.0, 1.0.1, and 1.0.2 is vulnerable to sensitive information disclosure through specially crafted API Calls.

Mitigation only
Fix from $1,950 2025-01-18
Robotic Process Automation MEDIUM 6.5
CVE-2024-49824

IBM Robotic Process Automation 21.0.0 through 21.0.7.18 and 23.0.0 through 23.0.18 and IBM Robotic Process Automation for Cloud Pak 21.0.0 through …

Fix: 21.0.7.19 / 23.0.19+
Fix from $1,600 2025-01-18
Voice Gateway CRITICAL 9.1
CVE-2024-47113

IBM ICP - Voice Gateway 1.0.2, 1.0.2.4, 1.0.3, 1.0.4, 1.0.5, 1.0.6. 1.0.7, 1.0.7.1, and 1.0.8 could allow remote attacker to send specially crafted X…

Mitigation only
Fix from $2,300 2025-01-18