Vulnerability index

Browse CVEs

6,286 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Aspera Faspex HIGH 7.1
CVE-2024-45097

IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user to bypass intended access restrictions and conduct resource modification.

Fix: 5.0.10+
Fix from $1,950 2024-09-05
Aspera Faspex MEDIUM 6.5
CVE-2024-45096

IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user with access to the package to obtain sensitive information through a directory listing.

Fix: 5.0.10+
Fix from $1,600 2024-09-05
Webmethods Integration CRITICAL 9.9
CVE-2024-45076

IBM webMethods Integration 10.15 could allow an authenticated user to upload and execute arbitrary files which could be executed on the underlying op…

Mitigation only
Fix from $2,300 2024-09-04
Webmethods Integration HIGH 8.8
CVE-2024-45075

IBM webMethods Integration 10.15 could allow an authenticated user to create scheduler tasks that would allow them to escalate their privileges to ad…

Mitigation only
Fix from $1,950 2024-09-04
Webmethods Integration MEDIUM 6.5
CVE-2024-45074

IBM webMethods Integration 10.15 could allow an authenticated user to traverse directories on the system. An attacker could send a specially crafted …

Mitigation only
Fix from $1,600 2024-09-04
Sterling Connect Direct Web Services CRITICAL 9.8
CVE-2024-39747

IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 uses default credentials for potentially critical functionality.

Fix: 6.1.0.25 / 6.2.0.24+
Fix from $2,300 2024-08-31
Security Verify Access HIGH 8.2
CVE-2024-35133

IBM Security Verify Access 10.0.0 through 10.0.8 OIDC Provider could allow a remote authenticated attacker to conduct phishing attacks, using an open…

Fix: after 10.0.8
Fix from $1,950 2024-08-29
App Connect Enterprise Certified Container HIGH 8.1
CVE-2022-43915

IBM App Connect Enterprise Certified Container 5.0, 7.1, 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.…

Mitigation only
Fix from $1,950 2024-08-24
Sterling Connect Direct Web Services HIGH 7.5
CVE-2024-39745

IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 uses weaker than expected cryptographic algorithms that could allow an attacker to de…

Mitigation only
Fix from $1,950 2024-08-22
Openpages Grc Platform MEDIUM 6.5
CVE-2024-35151

IBM OpenPages with Watson 8.3 and 9.0 could allow authenticated users access to sensitive information through improper authorization controls on APIs.

Mitigation only
Fix from $1,600 2024-08-22
Sterling Connect Direct Web Services MEDIUM 5.9
CVE-2024-39746

IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 could allow a remote attacker to obtain sensitive information, caused by the failure …

Mitigation only
Fix from $1,600 2024-08-22
Global Configuration Management MEDIUM 6.5
CVE-2024-41773

IBM Global Configuration Management 7.0.2 and 7.0.3 could allow an authenticated user to archive a global baseline due to improper access controls.

Mitigation only
Fix from $1,600 2024-08-20
Cloud Pak For Security MEDIUM 6.5
CVE-2023-47728

IBM QRadar Suite Software 1.10.12.0 through 1.10.22.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow a remote attacker to obta…

Fix: 1.10.23.0+
Fix from $1,600 2024-08-16
Security Directory Integrator CRITICAL 9.8
CVE-2022-33162

IBM Security Directory Integrator 7.2.0 and Security Verify Directory Integrator 10.0.0 does not perform any authentication for functionality that re…

Mitigation only
Fix from $2,300 2024-08-16
Infosphere Information Server MEDIUM 6.5
CVE-2024-40705

IBM InfoSphere Information Server could allow an authenticated user to consume file space resources due to unrestricted file uploads. IBM X-Force ID…

Mitigation only
Fix from $1,600 2024-08-15
Qradar Network Packet Capture MEDIUM 5.9
CVE-2024-31905

IBM QRadar Network Packet Capture 7.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP St…

Mitigation only
Fix from $1,600 2024-08-15
Cloud Pak For Security MEDIUM 5.5
CVE-2024-25024

IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores user credentials in plain clea…

Fix: 1.10.24.0+
Fix from $1,600 2024-08-15
Db2 MEDIUM 6.5
CVE-2024-35152

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated user to cause a denial of service with a speciall…

Mitigation only
Fix from $1,600 2024-08-14
Db2 MEDIUM 6.5
CVE-2024-37529

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 could allow an authenticated user to cause a denial of service with a…

Fix: after 11.5.9
Fix from $1,600 2024-08-14
Db2 MEDIUM 6.5
CVE-2024-35136

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) federated server 10.5, 11.1, and 11.5 is vulnerable to denial of service with a spe…

Fix: after 11.5.9
Fix from $1,600 2024-08-14
Db2 MEDIUM 6.5
CVE-2024-31882

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to a denial of service, under specific non default conf…

Fix: after 11.5.9
Fix from $1,600 2024-08-14
Websphere Application Server HIGH 7.5
CVE-2023-50314

IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.8 could allow an attacker with access to the network to conduct spoofing attacks. A…

Fix: after 24.0.0.8
Fix from $1,950 2024-08-14
Websphere Application Server MEDIUM 5.9
CVE-2023-50315

IBM WebSphere Application Server 8.5 and 9.0 could allow an attacker with access to the network to conduct spoofing attacks. An attacker could explo…

Mitigation only
Fix from $1,600 2024-08-14
Cloud Pak For Security HIGH 7.5
CVE-2024-28799

IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 displays sensitive data improperly to…

Fix: after 1.10.23.0
Fix from $1,950 2024-08-14
Java Sdk MEDIUM 5.9
CVE-2024-27267

The Object Request Broker (ORB) in IBM SDK, Java Technology Edition 7.1.0.0 through 7.1.5.18 and 8.0.0.0 through 8.0.8.26 is vulnerable to remote den…

Fix: after 8.0.8.26
Fix from $1,600 2024-08-14
Openbmc HIGH 7.5
CVE-2024-35124

A vulnerability in the combination of the OpenBMC's FW1050.00 through FW1050.10, FW1030.00 through FW1030.50, and FW1020.00 through FW1020.60 default…

Mitigation only
Fix from $1,950 2024-08-13
Common Licensing HIGH 7.5
CVE-2024-40697

IBM Common Licensing 9.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user …

Mitigation only
Fix from $1,950 2024-08-13
Aspera Shares MEDIUM 5.4
CVE-2023-38018

IBM Aspera Shares 1.10.0 PL2 does not invalidate session after a password change which could allow an authenticated user to impersonate another user …

Mitigation only
Fix from $1,600 2024-08-12
Planning Analytics Workspace CRITICAL 9.1
CVE-2024-35143

IBM Planning Analytics Local 2.0 and 2.1 connects to a MongoDB server. MongoDB, a document-oriented database system, is listening on the remote port,…

Fix: 2.0.97 / 2.1.4+
Fix from $2,300 2024-08-04
Business Automation Workflow MEDIUM 6.5
CVE-2024-38321

IBM Business Automation Workflow 22.0.2, 23.0.1, 23.0.2, and 24.0.0 stores potentially sensitive information in log files under certain situations th…

Fix: after 22.0.2
Fix from $1,600 2024-08-03