Vulnerability index

Browse CVEs

6,286 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Aspera Orchestrator MEDIUM 6.5
CVE-2023-38001

IBM Aspera Orchestrator 4.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions…

Mitigation only
Fix from $1,600 2024-07-30
Aspera Orchestrator MEDIUM 5.4
CVE-2023-26289

IBM Aspera Orchestrator 4.0.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow a…

Mitigation only
Fix from $1,600 2024-07-30
Aspera Orchestrator MEDIUM 5.5
CVE-2023-26288

IBM Aspera Orchestrator 4.0.1 does not invalidate session after a password change which could allow an authenticated user to impersonate another user…

Mitigation only
Fix from $1,600 2024-07-30
Security Directory Integrator HIGH 7.5
CVE-2022-33167

IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 could allow a remote attacker to obtain sensitive informa…

Mitigation only
Fix from $1,950 2024-07-30
Infosphere Information Server CRITICAL 9.8
CVE-2024-40689

IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could all…

Mitigation only
Fix from $2,300 2024-07-26
Security Directory Integrator MEDIUM 5.4
CVE-2024-28772

IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 is vulnerable to stored cross-site scripting. This vulner…

Mitigation only
Fix from $1,600 2024-07-25
Security Directory Integrator HIGH 7.5
CVE-2022-32759

IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 uses insufficient session expiration which could allow an…

Mitigation only
Fix from $1,950 2024-07-25
Engineering Requirements Management Doors HIGH 8.2
CVE-2023-50304

IBM Engineering Requirements Management DOORS Web Access 9.7.2.8 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML d…

Mitigation only
Fix from $1,950 2024-07-18
Rational Clearquest MEDIUM 5.4
CVE-2024-28796

IBM ClearQuest (CQ) 9.1 through 9.1.0.6 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript c…

Fix: 9.1.0.7+
Fix from $1,600 2024-07-17
Sterling Partner Engagement Manager MEDIUM 5.5
CVE-2022-35640

IBM Sterling Partner Engagement Manager 6.2.2 could allow a local attacker to obtain sensitive information when a detailed technical error message is…

Mitigation only
Fix from $1,600 2024-07-16
Datacap MEDIUM 5.4
CVE-2024-39735

IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to…

Mitigation only
Fix from $1,600 2024-07-15
Datacap MEDIUM 5.3
CVE-2024-39740

IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 displays version information in HTTP requests that could allow an attacker to gather info…

Mitigation only
Fix from $1,600 2024-07-15
Datacap MEDIUM 5.3
CVE-2024-39741

IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 could allow a remote attacker to traverse directories on the system. An attacker could se…

Mitigation only
Fix from $1,600 2024-07-15
Datacap MEDIUM 5.3
CVE-2024-39737

IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 could allow a remote attacker to obtain sensitive information when a detailed technical e…

Mitigation only
Fix from $1,600 2024-07-15
Datacap CRITICAL 9.8
CVE-2024-39736

IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 is vulnerable to HTTP header injection, caused by improper validation of input by the HOS…

Mitigation only
Fix from $2,300 2024-07-15
Datacap HIGH 7.5
CVE-2024-39731

IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 uses weaker than expected cryptographic algorithms that could allow an attacker to decryp…

Mitigation only
Fix from $1,950 2024-07-15
Datacap MEDIUM 5.4
CVE-2024-39728

IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed ar…

Mitigation only
Fix from $1,600 2024-07-15
Datacap MEDIUM 5.5
CVE-2024-39733

IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 stores user credentials in plain clear text which can be read by a local user. IBM X-For…

Mitigation only
Fix from $1,600 2024-07-14
Datacap HIGH 7.5
CVE-2024-39732

IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 temporarily stores data from different environments that could be obtained by a malicious…

Mitigation only
Fix from $1,950 2024-07-14
Infosphere Information Server MEDIUM 5.4
CVE-2024-40690

IBM InfoSphere Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code …

Mitigation only
Fix from $1,600 2024-07-12
Security Qradar Edr MEDIUM 5.4
CVE-2023-35006

IBM Security QRadar EDR 3.12 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be execute…

Mitigation only
Fix from $1,600 2024-07-10
Security Qradar Edr MEDIUM 5.3
CVE-2023-33860

IBM Security QRadar EDR 3.12 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie va…

Mitigation only
Fix from $1,600 2024-07-10
Security Qradar Edr MEDIUM 5.3
CVE-2023-33859

IBM Security QRadar EDR 3.12 could disclose sensitive information due to an observable login response discrepancy. IBM X-Force ID: 257697.

Mitigation only
Fix from $1,600 2024-07-10
Cloud Pak For Security MEDIUM 5.5
CVE-2024-25023

IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.22.0 stores potentially sensitive informat…

Fix: 1.10.23.0+
Fix from $1,600 2024-07-10
Websphere Application Server HIGH 7.2
CVE-2024-35154

IBM WebSphere Application Server 8.5 and 9.0 could allow a remote authenticated attacker, who has authorized access to the administrative console, to…

Fix: after 9.0.5.20
Fix from $1,950 2024-07-09
Mq Operator CRITICAL 9.8
CVE-2024-39742

IBM MQ Operator 3.2.2 and IBM MQ Operator 2.0.24 could allow a user to bypass authentication under certain configurations due to a partial string com…

Fix: 2.0.24 / 3.2.2+
Fix from $2,300 2024-07-08
Mq Operator HIGH 7.5
CVE-2024-39743

IBM MQ Operator 3.2.2 and IBM MQ Operator 2.0.24 IBM MQ Container Developer Edition is vulnerable to denial of service caused by incorrect memory de-…

Fix: 2.0.24 / 3.2.2+
Fix from $1,950 2024-07-08
Cloud Pak For Business Automation MEDIUM 5.4
CVE-2024-37528

IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, 22.0.2,…

Fix: after 20.0.3
Fix from $1,600 2024-07-08
I HIGH 7.8
CVE-2024-38330

IBM System Management for i 7.2, 7.3, and 7.4 could allow a local user to gain elevated privileges due to an unqualified library program call. A mal…

Mitigation only
Fix from $1,950 2024-07-08
Infosphere Information Server MEDIUM 5.4
CVE-2023-50964

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…

Mitigation only
Fix from $1,600 2024-06-30