Vulnerability index

Browse CVEs

6,286 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Vios MEDIUM 5.5
CVE-2024-47102

IBM AIX 7.2, 7.3, VIOS 3.1, and 4.1 could allow a non-privileged local user to exploit a vulnerability in the AIX perfstat kernel extension to cause…

Mitigation only
Fix from $1,600 2024-12-25
Engineering Lifecycle Optimization Engineering Insights CRITICAL 9.8
CVE-2024-39727

IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 uses a web link with untrusted references to an external site. A remote…

Mitigation only
Fix from $2,300 2024-12-25
Engineering Lifecycle Optimization Engineering Insights MEDIUM 5.3
CVE-2024-39725

IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 could allow a remote attacker to obtain sensitive information when a de…

Mitigation only
Fix from $1,600 2024-12-25
I MEDIUM 5.4
CVE-2024-51463

IBM i 7.3, 7.4, and 7.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests…

Mitigation only
Fix from $1,600 2024-12-21
Cognos Analytics CRITICAL 9.0
CVE-2024-51466

IBM Cognos Analytics 11.2.0 through 11.2.4 FP4 and 12.0.0 through 12.0.4 is vulnerable to an Expression Language (EL) Injection vulnerability. A r…

Fix: 11.2.4 / 12.0.4+
Fix from $2,300 2024-12-20
Cognos Analytics HIGH 8.0
CVE-2024-40695

IBM Cognos Analytics 11.2.0 through 11.2.4 FP4 and 12.0.0 through 12.0.4 could be vulnerable to malicious file upload by not validating the cont…

Fix: 11.2.4 / 12.0.4+
Fix from $1,950 2024-12-20
Security Directory Integrator HIGH 8.8
CVE-2024-28767

IBM Security Directory Integrator 7.2.0 through 7.2.0.13 and 10.0.0 through 10.0.3 could allow a remote authenticated attacker to execute arbitrary c…

Fix: after 10.0.3
Fix from $1,950 2024-12-20
Mq MEDIUM 6.2
CVE-2024-52897

IBM MQ 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a remote attacker to obtain sensitive information when a detailed techni…

Fix: 9.2.0.30 / 9.3.0.26+
Fix from $1,600 2024-12-19
Mq Appliance MEDIUM 5.3
CVE-2024-51471

IBM MQ Appliance 9.3 LTS, 9.3 CD, and 9.4 LTS web console could allow an authenticated user to cause a denial-of-service when trace is enabled due to…

Fix: after 9.4.0.7
Fix from $1,600 2024-12-19
Security Guardium MEDIUM 5.4
CVE-2024-49336

IBM Security Guardium 11.5 and 12.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorize…

Mitigation only
Fix from $1,600 2024-12-19
Mq MEDIUM 6.2
CVE-2024-52896

IBM MQ 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a remote attacker to obtain sensitive information when a detailed techni…

Fix: 9.2.0.30 / 9.3.0.26+
Fix from $1,600 2024-12-19
Security Verify Access Docker HIGH 7.8
CVE-2024-35141

IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to execution of unnecessary privile…

Fix: after 10.0.7
Fix from $1,950 2024-12-19
Db2 MEDIUM 6.5
CVE-2023-30443

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted qu…

Mitigation only
Fix from $1,600 2024-12-19
Cognos Analytics Mobile HIGH 7.5
CVE-2021-39081

IBM Cognos Analytics Mobile for Android 1.1.14 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sens…

Mitigation only
Fix from $1,950 2024-12-19
Sterling B2b Integrator MEDIUM 5.4
CVE-2021-20553

IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed …

Fix: after 6.1.1.0
Fix from $1,600 2024-12-19
Infosphere Information Server MEDIUM 5.2
CVE-2021-29827

IBM InfoSphere Information Server 11.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a m…

Mitigation only
Fix from $1,600 2024-12-19
Mq Appliance MEDIUM 6.5
CVE-2024-51470

IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, 9.4 CD, IBM MQ Appliance 9.3 LTS, 9.3 CD, 9.4 LTS, and IBM MQ for HPE NonStop 8.1.0 through 8.1.0.…

Fix: 8.1.0.26 / 9.1.0.26+
Fix from $1,600 2024-12-18
Cognos Analytics MEDIUM 6.1
CVE-2024-25042

IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 is potentially vulnerable to Cross Site Scripting (XSS). A remote attacker c…

Fix: after 12.0.3
Fix from $1,600 2024-12-18
Cognos Analytics MEDIUM 6.1
CVE-2024-41752

IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 is vulnerable to HTML injection. A remote attacker could inject malicious HTML c…

Fix: after 12.0.3
Fix from $1,600 2024-12-18
Cognos Analytics MEDIUM 5.2
CVE-2024-45082

IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 could allow a remote attacker to conduct phishing attacks, using an open redir…

Fix: after 12.0.3
Fix from $1,600 2024-12-18
Storage Defender Resiliency Service HIGH 7.5
CVE-2024-47119

IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9 does not properly validate a certificate which could allow an attacker to spoof a trust…

Fix: after 2.0.9
Fix from $1,950 2024-12-18
Storage Defender Resiliency Service MEDIUM 5.7
CVE-2024-52361

IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9  stores user credentials in plain text which can be read by an authenticated user w…

Fix: after 2.0.9
Fix from $1,600 2024-12-18
I MEDIUM 6.8
CVE-2024-47104

IBM i 7.4 and 7.5 is vulnerable to an authenticated user gaining elevated privilege to a physical file. A user with authority to a view can alter the…

Mitigation only
Fix from $1,600 2024-12-18
Security Guardium Key Lifecycle Manager HIGH 7.5
CVE-2024-49819

IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information in cleartext i…

Mitigation only
Fix from $1,950 2024-12-17
Storage Scale HIGH 7.5
CVE-2024-31892

IBM Storage Scale GUI 5.1.9.0 through 5.1.9.6 and 5.2.0.0 through 5.2.1.1 could allow a user to perform unauthorized actions after intercepting and m…

Fix: 5.1.9.7 / 5.2.2.0+
Fix from $1,950 2024-12-14
Storage Scale HIGH 7.8
CVE-2024-31891

IBM Storage Scale GUI 5.1.9.0 through 5.1.9.6 and 5.2.0.0 through 5.2.1.1 contains a local privilege escalation vulnerability. A malicious actor wi…

Fix: 5.1.9.7 / 5.2.2.0+
Fix from $1,950 2024-12-14
Infosphere Information Server MEDIUM 6.5
CVE-2024-52901

IBM InfoSphere Information Server 11.7 could allow an authenticated user to GUI to not load or stop working due to improper input validation.

Mitigation only
Fix from $1,600 2024-12-12
Infosphere Information Server MEDIUM 6.5
CVE-2023-23472

IBM InfoSphere DataStage Flow Designer (InfoSphere Information Server 11.7) could allow an authenticated user to obtain sensitive information that co…

Mitigation only
Fix from $1,600 2024-12-11
Carbon Charts MEDIUM 5.4
CVE-2024-47117

IBM Carbon Design System (Carbon Charts 0.4.0 through 1.13.16) is vulnerable to cross-site scripting. This vulnerability allows an authenticated user…

Fix: 1.13.17+
Fix from $1,600 2024-12-10
Qradar Security Information And Event Manager MEDIUM 5.4
CVE-2024-47107

IBM QRadar SIEM 7.5 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in…

Mitigation only
Fix from $1,600 2024-12-07