Vulnerability index

Browse CVEs

6,286 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Sterling Secure Proxy HIGH 7.5
CVE-2024-41784

IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, and 6.1.0.0 could allow a remote attacker to traverse directories on the system. An att…

Mitigation only
Fix from $1,950 2024-11-15
Concert MEDIUM 6.1
CVE-2024-41785

IBM Concert Software 1.0.0 through 1.0.1 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitr…

Mitigation only
Fix from $1,600 2024-11-15
Concert MEDIUM 5.9
CVE-2024-43189

IBM Concert Software 1.0.0 through 1.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP…

Mitigation only
Fix from $1,600 2024-11-15
Soar HIGH 8.1
CVE-2024-45670

IBM Security SOAR 51.0.1.0 and earlier contains a mechanism for users to recover or change their passwords without knowing the original password, but…

Fix: 51.0.2.0+
Fix from $1,950 2024-11-14
Security Qradar Edr MEDIUM 5.3
CVE-2024-45642

IBM Security ReaQta 3.12 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the…

Fix: 3.12.12+
Fix from $1,600 2024-11-14
Maximo Asset Management MEDIUM 5.4
CVE-2024-45088

IBM Maximo Asset Management 7.6.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary Ja…

Mitigation only
Fix from $1,600 2024-11-11
Maximo Application Suite MEDIUM 5.4
CVE-2024-35146

IBM Maximo Application Suite - Monitor Component 8.10.11, 8.11.8, and 9.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unaut…

Mitigation only
Fix from $1,600 2024-11-06
Websphere Application Server MEDIUM 5.5
CVE-2024-45086

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privileged us…

Fix: 8.5.5.27 / 9.0.5.22+
Fix from $1,600 2024-11-04
Cics Tx HIGH 8.8
CVE-2024-41744

IBM CICS TX Standard 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions tra…

Mitigation only
Fix from $1,950 2024-11-01
Cics Tx MEDIUM 6.1
CVE-2024-41745

IBM CICS TX Standard is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code …

Mitigation only
Fix from $1,600 2024-11-01
Txseries For Multiplatforms MEDIUM 5.9
CVE-2024-41738

IBM TXSeries for Multiplatforms 10.1 could allow an attacker to obtain sensitive information from the query string of an HTTP GET method to process a…

Mitigation only
Fix from $1,600 2024-11-01
Txseries For Multiplatforms MEDIUM 5.3
CVE-2024-41741

IBM TXSeries for Multiplatforms 10.1 could allow an attacker to determine valid usernames due to an observable timing discrepancy which could be used…

Mitigation only
Fix from $1,600 2024-11-01
Power System E1080 \(9080 Hex\) Firmware CRITICAL 9.8
CVE-2024-45656

IBM Flexible Service Processor (FSP) FW860.00 through FW860.B3, FW950.00 through FW950.C0, FW1030.00 through FW1030.61, FW1050.00 through FW1050.21, …

Mitigation only
Fix from $2,300 2024-10-29
Maximo Application Suite MEDIUM 5.9
CVE-2024-38314

IBM Maximo Application Suite - Monitor Component 8.10, 8.11, and 9.0 could disclose information in the form of the hard-coded cryptographic key to an…

Fix: 8.10.15 / 8.11.12+
Fix from $1,600 2024-10-24
Cics Transaction Gateway HIGH 7.5
CVE-2023-50310

IBM CICS Transaction Gateway for Multiplatforms 9.2 and 9.3 transmits or stores authentication credentials, but it uses an insecure method that is su…

Mitigation only
Fix from $1,950 2024-10-23
Db2 MEDIUM 6.5
CVE-2024-31880

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service, under specific configura…

Fix: after 11.5.9
Fix from $1,600 2024-10-23
Concert CRITICAL 9.8
CVE-2024-43177

IBM Concert 1.0.0 and 1.0.1 vulnerable to attacks that rely on the use of cookies without the SameSite attribute.

Mitigation only
Fix from $2,300 2024-10-22
Websphere Application Server MEDIUM 5.5
CVE-2024-45072

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A privileged us…

Fix: after 9.0.5.21
Fix from $1,600 2024-10-16
Watson Studio Local HIGH 8.8
CVE-2024-49340

IBM Watson Studio Local 1.2.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions…

Mitigation only
Fix from $1,950 2024-10-16
Websphere Application Server HIGH 7.5
CVE-2024-45085

IBM WebSphere Application Server 8.5 is vulnerable to a denial of service, under certain configurations, caused by an unexpected specially crafted re…

Fix: 8.5.5.27+
Fix from $1,950 2024-10-15
Cloud Pak For Multicloud Management Monitoring HIGH 8.8
CVE-2024-43191

IBM ManageIQ could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted yaml file request.

Mitigation only
Fix from $1,950 2024-09-26
Storage Defender MEDIUM 6.5
CVE-2024-38324

IBM Storage Defender 2.0.0 through 2.0.7 on-prem defender-sensor-cmd CLI does not validate server name during registration and unregistration operati…

Fix: 2.0.8+
Fix from $1,600 2024-09-25
Aspera Console HIGH 7.5
CVE-2022-43845

IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag.…

Fix: 3.4.5+
Fix from $1,950 2024-09-25
Aspera Console HIGH 8.0
CVE-2021-38963

IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by a CSV injection…

Fix: 3.4.5+
Fix from $1,950 2024-09-25
Cognos Analytics MEDIUM 5.5
CVE-2024-40703

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and IBM Cognos Analytics Reports for iOS 11.0.0.7 could …

Fix: 12.0.3+
Fix from $1,600 2024-09-22
Aspera Shares MEDIUM 6.5
CVE-2024-38315

IBM Aspera Shares 1.0 through 1.10.0 PL3 does not invalidate session after a password reset which could allow an authenticated user to impersonate an…

Fix: 1.10.0+
Fix from $1,600 2024-09-16
Mq Operator HIGH 8.8
CVE-2024-40681

IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow an authenticated user in a specifically defined role, to bypass security re…

Fix: after 3.2.3
Fix from $1,950 2024-09-07
Maximo Application Suite HIGH 7.5
CVE-2024-37068

IBM Maximo Application Suite - Manage Component 8.10, 8.11, and 9.0 uses weaker than expected cryptographic algorithms that could allow an attacker t…

Mitigation only
Fix from $1,950 2024-09-07
Mq Operator MEDIUM 5.5
CVE-2024-40680

IBM MQ 9.3 CD and 9.4 LTS/CD could allow a local user to cause a denial of service due to improper memory allocation causing a segmentation fault.

Mitigation only
Fix from $1,600 2024-09-07
Aspera Faspex HIGH 8.1
CVE-2024-45098

IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user to bypass intended access restrictions and conduct resource modification.

Fix: 5.0.10+
Fix from $1,950 2024-09-05