Vulnerability index

Browse CVEs

6,286 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Infosphere Information Server MEDIUM 5.4
CVE-2024-28794

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…

Mitigation only
Fix from $1,600 2024-06-30
Infosphere Information Server MEDIUM 5.4
CVE-2024-28797

IBM InfoSphere Information Server 11.7 is vulnerable stored to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript co…

Mitigation only
Fix from $1,600 2024-06-30
Infosphere Information Server MEDIUM 5.4
CVE-2024-31898

IBM InfoSphere Information Server 11.7 could allow an authenticated user to read or modify sensitive information by bypassing authentication using in…

Mitigation only
Fix from $1,600 2024-06-30
Infosphere Information Server MEDIUM 5.4
CVE-2023-50952

IBM InfoSphere Information Server 11.7 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthor…

Mitigation only
Fix from $1,600 2024-06-30
Infosphere Information Server MEDIUM 5.3
CVE-2024-35119

IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is retur…

Mitigation only
Fix from $1,600 2024-06-30
Infosphere Information Server HIGH 8.8
CVE-2024-31902

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorize…

Mitigation only
Fix from $1,950 2024-06-30
Infosphere Information Server MEDIUM 6.1
CVE-2024-28798

IBM InfoSphere Information Server 11.7 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript co…

Mitigation only
Fix from $1,600 2024-06-30
Infosphere Information Server MEDIUM 5.3
CVE-2023-50954

IBM InfoSphere Information Server 11.7 returns sensitive information in URL information that could be used in further attacks against the system. IB…

Mitigation only
Fix from $1,600 2024-06-30
Infosphere Information Server MEDIUM 5.4
CVE-2024-28795

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…

Mitigation only
Fix from $1,600 2024-06-30
Storage Defender Resiliency Service HIGH 7.5
CVE-2024-38322

IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.4 agent username and password error response discrepancy exposes product to brute force e…

Fix: after 2.0.4
Fix from $1,950 2024-06-28
Mq HIGH 7.5
CVE-2024-35116

IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS, and 9.3 CD is vulnerable to a denial of service attack caused by an error applying configuration changes. …

Fix: 9.0.0.26 / 9.1.0.22+
Fix from $1,950 2024-06-28
Mq MEDIUM 6.5
CVE-2024-35156

IBM MQ 9.3 LTS and 9.3 CD could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the br…

Fix: 9.3.0.20 / 9.4.0.0+
Fix from $1,600 2024-06-28
Storage Defender MEDIUM 6.5
CVE-2024-25031

IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.4 uses an inadequate account lockout setting that could allow an attacker on the network …

Fix: after 2.0.4
Fix from $1,600 2024-06-28
Cognos Analytics MEDIUM 5.9
CVE-2024-25053

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, and 12.0.2 is vulnerable to improper certificate validation when using t…

Mitigation only
Fix from $1,600 2024-06-28
Cognos Analytics MEDIUM 5.4
CVE-2024-25041

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, and 12.0.2 is potentially vulnerable to cross site scripting (XSS). A re…

Fix: after 12.0.2
Fix from $1,600 2024-06-28
Mq MEDIUM 6.5
CVE-2024-35155

IBM MQ Console 9.3 LTS and 9.3 CD could disclose could allow a remote attacker to obtain sensitive information when a detailed technical error messag…

Mitigation only
Fix from $1,600 2024-06-28
Mq HIGH 8.8
CVE-2024-31912

IBM MQ 9.3 LTS and 9.3 CD could allow an authenticated user to escalate their privileges under certain configurations due to incorrect privilege assi…

Mitigation only
Fix from $1,950 2024-06-28
Mq HIGH 7.5
CVE-2024-31919

IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS and 9.3 CD, in certain configurations, is vulnerable to a denial of service attack caused by an error proce…

Mitigation only
Fix from $1,950 2024-06-28
Security Access Manager MEDIUM 6.2
CVE-2024-35137

IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to possibly elevate their privileges due to sensitive configura…

Fix: after 10.0.7.1
Fix from $1,600 2024-06-28
Security Access Manager MEDIUM 5.5
CVE-2024-35139

IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain sensitive information from the container due to incor…

Fix: after 10.0.7.1
Fix from $1,600 2024-06-28
Security Access Manager HIGH 7.8
CVE-2023-30998

IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain root access due to improper access controls. IBM X-F…

Fix: after 10.0.7.1
Fix from $1,950 2024-06-27
Security Access Manager MEDIUM 6.5
CVE-2023-38370

IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1, under certain configurations, could allow a user on the network to install malicious pa…

Fix: after 10.0.7.1
Fix from $1,600 2024-06-27
Security Access Manager MEDIUM 5.5
CVE-2023-38368

IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could disclose sensitive information to a local user to do improper permission controls.…

Fix: after 10.0.7.1
Fix from $1,600 2024-06-27
Security Access Manager HIGH 7.8
CVE-2023-30997

IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain root access due to improper access controls. IBM X-F…

Fix: after 10.0.7.1
Fix from $1,950 2024-06-27
Openbmc HIGH 7.5
CVE-2024-31916

IBM OpenBMC FW1050.00 through FW1050.10 BMCWeb HTTPS server component could disclose sensitive URI content to an unauthorized actor that bypasses aut…

Mitigation only
Fix from $1,950 2024-06-27
Sterling B2b Integrator MEDIUM 5.4
CVE-2023-42011

IBM Sterling B2B Integrator Standard Edition 6.1 and 6.2 does not restrict or incorrectly restricts frame objects or UI layers that belong to another…

Mitigation only
Fix from $1,600 2024-06-27
Sterling B2b Integrator MEDIUM 5.4
CVE-2023-42014

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.2.0.2 is vulnerable to cross-site scripting. This vulnerability allows an authenticate…

Fix: after 6.2.0.2
Fix from $1,600 2024-06-27
Security Access Manager HIGH 7.5
CVE-2023-38371

IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decry…

Fix: after 10.0.7.1
Fix from $1,950 2024-06-27
Security Verify Access MEDIUM 5.9
CVE-2024-31883

IBM Security Verify Access 10.0.0.0 through 10.0.7.1, under certain configurations, could allow an unauthenticated attacker to cause a denial of serv…

Fix: after 10.0.7.1
Fix from $1,600 2024-06-27
Security Verify Access MEDIUM 5.5
CVE-2023-30430

IBM Security Verify Access 10.0.0 through 10.0.7.1 could allow a local user to obtain sensitive information from trace logs. IBM X-Force ID: 252183.

Fix: after 10.0.7.1
Fix from $1,600 2024-06-27