Vulnerability index

Browse CVEs

6,286 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Db2 MEDIUM 6.5
CVE-2024-41762

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may crash u…

Fix: after 11.5.9
Fix from $1,600 2024-12-07
Vios HIGH 7.8
CVE-2024-47115

IBM AIX 7.2, 7.3 and VIOS 3.1 and 4.1 could allow a local user to execute arbitrary commands on the system due to improper neutralization of input.

Mitigation only
Fix from $1,950 2024-12-07
Db2 MEDIUM 6.5
CVE-2024-37071

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow an authenticated user to cause a denial of service…

Fix: after 11.5.9
Fix from $1,600 2024-12-07
App Connect Enterprise Certified Container HIGH 8.8
CVE-2024-51465

IBM App Connect Enterprise Certified Container 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, and 12.3 could allow a remote authenticated attacker to execute ar…

Fix: 12.4+
Fix from $1,950 2024-12-04
Cognos Controller HIGH 7.5
CVE-2024-41777

IBM Cognos Controller 11.0.0 and 11.0.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own…

Mitigation only
Fix from $1,950 2024-12-03
Cognos Controller MEDIUM 6.5
CVE-2024-41776

IBM Cognos Controller 11.0.0 and 11.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious an…

Mitigation only
Fix from $1,600 2024-12-03
Cognos Controller HIGH 7.5
CVE-2024-41775

IBM Cognos Controller 11.0.0 and 11.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive i…

Mitigation only
Fix from $1,950 2024-12-03
Cognos Controller CRITICAL 9.8
CVE-2024-25020

IBM Cognos Controller 11.0.0 and 11.0.1 is vulnerable to malicious file upload by allowing unrestricted filetype attachments in the Jou…

Mitigation only
Fix from $2,300 2024-12-03
Cognos Controller CRITICAL 9.8
CVE-2024-40691

IBM Cognos Controller 11.0.0 and 11.0.1 could be vulnerable to malicious file upload by not validating the content of the file uploaded to the web …

Mitigation only
Fix from $2,300 2024-12-03
Cognos Controller CRITICAL 9.8
CVE-2024-25019

IBM Cognos Controller 11.0.0 and 11.0.1 could be vulnerable to malicious file upload by not validating the type of file uploaded to Journal entry a…

Mitigation only
Fix from $2,300 2024-12-03
Cognos Controller MEDIUM 5.3
CVE-2024-25035

IBM Cognos Controller 11.0.0 and 11.0.1 exposes server details that could allow an attacker to obtain information of the application environment …

No fix yet
Fix from $1,600 2024-12-03
Cognos Controller MEDIUM 5.9
CVE-2021-29892

IBM Cognos Controller 11.0.0 and 11.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP …

Mitigation only
Fix from $1,600 2024-12-03
Security Verify Access CRITICAL 9.8
CVE-2024-49805

IBM Security Verify Access Appliance 10.0.0 through 10.0.8 contains hard-coded credentials, such as a password or cryptographic key, which it uses …

Fix: after 10.0.8
Fix from $2,300 2024-11-29
Security Verify Access CRITICAL 9.8
CVE-2024-49806

IBM Security Verify Access Appliance 10.0.0 through 10.0.8 contains hard-coded credentials, such as a password or cryptographic key, which it uses …

Fix: after 10.0.8
Fix from $2,300 2024-11-29
Security Verify Access HIGH 8.8
CVE-2024-49803

IBM Security Verify Access Appliance 10.0.0 through 10.0.8 could allow a remote authenticated attacker to execute arbitrary commands on the system by…

Fix: after 10.0.8
Fix from $1,950 2024-11-29
Security Verify Access HIGH 7.8
CVE-2024-49804

IBM Security Verify Access Appliance 10.0.0 through 10.0.8 could allow a locally authenticated non-administrative user to escalate their privileges…

Fix: after 10.0.8
Fix from $1,950 2024-11-29
Watson Assistant For Ibm Cloud Pak For Data MEDIUM 5.9
CVE-2024-49353

IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data 4.0.0 through 5.0.2 does not properly check inputs to resources that are used concurr…

Fix: 5.0.3+
Fix from $1,600 2024-11-26
Workload Scheduler MEDIUM 5.5
CVE-2024-49351

IBM Workload Scheduler 9.5, 10.1, and 10.2 stores user credentials in plain text which can be read by a local user.

Mitigation only
Fix from $1,600 2024-11-26
Data Virtualization Manager For Z\/os HIGH 8.8
CVE-2024-52899

IBM Data Virtualization Manager for z/OS 1.1 and 1.2 could allow an authenticated user to inject malicious JDBC URL parameters and execute code on th…

Mitigation only
Fix from $1,950 2024-11-26
Jazz Foundation MEDIUM 6.1
CVE-2023-45181

IBM Jazz Foundation 7.0.2 and below are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the…

Fix: 7.0.3+
Fix from $1,600 2024-11-25
Jazz Foundation MEDIUM 5.3
CVE-2023-26280

IBM Jazz Foundation 7.0.2 and 7.0.3 could allow a user to change their dashboard using a specially crafted HTTP request due to improper access contro…

Mitigation only
Fix from $1,600 2024-11-25
Big Sql MEDIUM 6.5
CVE-2024-35160

IBM Watson Query on Cloud Pak for Data 1.8, 2.0, 2.1, 2.2 and IBM Db2 Big SQL on Cloud Pak for Data 7.3, 7.4, 7.5, and 7.6 could allow an authenticat…

Mitigation only
Fix from $1,600 2024-11-23
Db2 MEDIUM 5.3
CVE-2024-41761

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may crash u…

Mitigation only
Fix from $1,600 2024-11-23
Powervm Hypervisor MEDIUM 5.9
CVE-2024-41781

IBM PowerVM Platform KeyStore (IBM PowerVM Hypervisor FW950.00 through FW950.90, FW1030.00 through FW1030.60, FW1050.00 through FW1050.20, and FW1060…

Mitigation only
Fix from $1,600 2024-11-22
Engineering Systems Design Rhapsody HIGH 8.1
CVE-2024-41779

IBM Engineering Systems Design Rhapsody - Model Manager 7.0.2 and 7.0.3 could allow a remote attacker to bypass security restrictions, caused by a ra…

Mitigation only
Fix from $1,950 2024-11-22
Db2 HIGH 7.5
CVE-2024-45663

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1, 11.5, and 12.1 is vulnerable to a denial of service as the server may crash u…

Fix: after 11.5.9
Fix from $1,950 2024-11-21
Concert CRITICAL 9.8
CVE-2024-52360

IBM Concert Software 1.0.0, 1.0.1, 1.0.2, and 1.0.2.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, …

Mitigation only
Fix from $2,300 2024-11-19
Concert HIGH 8.8
CVE-2024-52359

IBM Concert Software 1.0.0, 1.0.1, 1.0.2, and 1.0.2.1 could allow an authenticated user to perform unauthorized actions that should be reserved to ad…

No fix yet
Fix from $1,950 2024-11-19
Concert MEDIUM 6.5
CVE-2024-37070

IBM Concert Software 1.0.0, 1.0.1, 1.0.2, and 1.0.2.1 could allow an authenticated user to obtain sensitive information that could aid in further att…

Fix: after 1.0.2.1
Fix from $1,600 2024-11-19
Engineering Lifecycle Optimization Engineering Insights HIGH 8.2
CVE-2024-39726

IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 is vulnerable to an XML External Entity Injection (XXE) attack when pro…

Mitigation only
Fix from $1,950 2024-11-15