Vulnerability index

Browse CVEs

6,286 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Jazz For Service Management HIGH 7.5
CVE-2024-47106

IBM Jazz for Service Management 1.1.3 through 1.1.3.22 could allow a remote attacker to obtain sensitive information from improper access restriction…

Fix: after 1.1.3.22
Fix from $1,950 2025-01-18
Robotic Process Automation MEDIUM 6.7
CVE-2024-51448

IBM Robotic Process Automation 21.0.0 through 21.0.7.17 and 23.0.0 through 23.0.18 could allow a local user to escalate their privileges. All files i…

Fix: after 23.0.18
Fix from $1,600 2025-01-18
Qradar Wincollect MEDIUM 5.3
CVE-2024-51462

IBM QRadar WinCollect Agent 10.0.0 through 10.1.12 could allow a remote attacker to inject XML data into parameter values due to improper input valid…

Fix: after 10.1.12
Fix from $1,600 2025-01-17
Infosphere Information Server HIGH 7.5
CVE-2024-52363

IBM InfoSphere Information Server 11.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafte…

Mitigation only
Fix from $1,950 2025-01-17
Cics Tx MEDIUM 6.1
CVE-2024-41746

IBM CICS TX Advanced 10.1, 11.1, and Standard 11.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary J…

Mitigation only
Fix from $1,600 2025-01-16
Mq MEDIUM 6.2
CVE-2024-52898

IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a local user to obtain sensitive information when a detailed technical error mess…

Fix: after 9.4.1.1
Fix from $1,600 2025-01-14
Robotic Process Automation MEDIUM 5.9
CVE-2024-51456

IBM Robotic Process Automation 21.0.0 through 21.0.7.19 and 23.0.0 through 23.0.19 could allow a remote attacker to obtain sensitive data that may be…

Fix: after 23.0.19
Fix from $1,600 2025-01-12
Jazz Foundation MEDIUM 5.4
CVE-2021-29669

IBM Jazz Foundation 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary J…

Mitigation only
Fix from $1,600 2025-01-12
Watsonx.ai MEDIUM 5.4
CVE-2024-49785

IBM watsonx.ai 1.1 through 2.0.3 and IBM watsonx.ai on Cloud Pak for Data 4.8 through 5.0.3 is vulnerable to cross-site scripting. This vulnerability…

Fix: 2.1.0 / 5.1.0+
Fix from $1,600 2025-01-12
Doors Next HIGH 8.1
CVE-2024-41787

IBM Engineering Requirements Management DOORS Next 7.0.2 and 7.0.3 could allow a remote attacker to bypass security restrictions, caused by a race co…

Mitigation only
Fix from $1,950 2025-01-10
Openpages With Watson MEDIUM 5.4
CVE-2024-43176

IBM OpenPages 9.0 could allow an authenticated user to obtain sensitive information such as configurations that should only be available to privilege…

Mitigation only
Fix from $1,600 2025-01-09
App Connect Enterprise Certified Container MEDIUM 5.5
CVE-2022-22491

IBM App Connect Enterprise Certified Container 7.1, 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12…

Fix: after 12.4
Fix from $1,600 2025-01-09
Db2 MEDIUM 5.5
CVE-2024-40679

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to an information disclosure vulnerability as sensitive informat…

Mitigation only
Fix from $1,600 2025-01-08
Cognos Controller HIGH 8.2
CVE-2024-40702

IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow an unauthorized user to obtain valid tokens to gain access to prote…

Fix: after 11.0.1
Fix from $1,950 2025-01-07
Cognos Controller MEDIUM 6.5
CVE-2024-28778

IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 is vulnerable to exposure of Artifactory API keys. This vulnerability allows us…

Fix: after 11.0.1
Fix from $1,600 2025-01-07
Security Qradar Edr MEDIUM 5.3
CVE-2024-45640

IBM Security ReaQta 3.12 returns sensitive information in an HTTP response that could be used in further attacks against the system.

Fix: 3.12.14+
Fix from $1,600 2025-01-07
Concert MEDIUM 5.4
CVE-2024-52891

IBM Concert Software 1.0.0, 1.0.1, 1.0.2, 1.0.2.1, and 1.0.3 could allow an authenticated user to inject malicious information or obtain informatio…

Mitigation only
Fix from $1,600 2025-01-07
Concert MEDIUM 5.3
CVE-2024-52893

IBM Concert Software 1.0.0, 1.0.1, 1.0.2, 1.0.2.1, and 1.0.3  could allow a remote attacker to obtain sensitive information when a detailed technica…

Mitigation only
Fix from $1,600 2025-01-07
Concert HIGH 7.5
CVE-2024-52367

IBM Concert Software 1.0.0, 1.0.1, 1.0.2, 1.0.2.1, and 1.0.3 could disclose sensitive system information to an unauthorized actor that could be used …

Mitigation only
Fix from $1,950 2025-01-07
Concert MEDIUM 5.9
CVE-2024-52366

IBM Concert Software 1.0.0, 1.0.1, 1.0.2, 1.0.2.1, and 1.0.3 could allow a remote attacker to obtain sensitive information, caused by the failure to …

Mitigation only
Fix from $1,600 2025-01-07
Sterling B2b Integrator MEDIUM 6.4
CVE-2024-31914

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 is vulnerable to stored cross-site scripting. This v…

Fix: after 6.2.0.2
Fix from $1,600 2025-01-06
Sterling B2b Integrator MEDIUM 5.4
CVE-2024-31913

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 is vulnerable to stored cross-site scripting. This v…

Fix: after 6.2.0.2
Fix from $1,600 2025-01-06
Engineering Lifecycle Optimization Publishing MEDIUM 6.5
CVE-2024-41768

IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 could allow a remote attacker to cause an unhandled SSL exception which could lea…

Mitigation only
Fix from $1,600 2025-01-04
Engineering Lifecycle Optimization Publishing HIGH 7.5
CVE-2024-41763

IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 uses weaker than expected cryptographic algorithms that could allow an attacker …

Mitigation only
Fix from $1,950 2025-01-04
Engineering Lifecycle Optimization Publishing HIGH 7.5
CVE-2024-41766

IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 could allow a remote attacker to cause a denial of service using a complex regul…

Mitigation only
Fix from $1,950 2025-01-04
Engineering Lifecycle Optimization Publishing HIGH 7.3
CVE-2024-41767

IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 is vulnerable to SQL injection. A remote attacker could send specially crafted SQ…

Mitigation only
Fix from $1,950 2025-01-04
Engineering Lifecycle Optimization Publishing MEDIUM 6.5
CVE-2024-41765

IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 could allow a remote attacker to traverse directories on the system. An attacker …

Mitigation only
Fix from $1,600 2025-01-04
I MEDIUM 5.4
CVE-2024-55896

IBM PowerHA SystemMirror for i 7.4 and 7.5 contains improper restrictions when rendering content via iFrames.  This vulnerability could allow an atta…

Mitigation only
Fix from $1,600 2025-01-03
Websphere Automation HIGH 7.2
CVE-2024-54181

IBM WebSphere Automation 1.7.5 could allow a remote privileged user, who has authorized access to the swagger UI, to execute arbitrary code. Using sp…

Mitigation only
Fix from $1,950 2024-12-30
Vios MEDIUM 5.5
CVE-2024-52906

IBM AIX 7.2, 7.3, VIOS 3.1, and 4.1 could allow a non-privileged local user to exploit a vulnerability in the TCP/IP kernel extension to cause a d…

Mitigation only
Fix from $1,600 2024-12-25