Vulnerability index

Browse CVEs

6,286 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Soar HIGH 8.8
CVE-2024-38319

IBM Security SOAR 51.0.2.0 could allow an authenticated user to execute malicious code loaded from a specially crafted script. IBM X-Force ID: 2948…

Fix: after 51.0.2.0
Fix from $1,950 2024-06-22
I HIGH 7.8
CVE-2024-31890

IBM i 7.3, 7.4, and 7.5 product IBM TCP/IP Connectivity Utilities for i contains a local privilege escalation vulnerability. A malicious actor with c…

Fix: after 7.5
Fix from $1,950 2024-06-21
Websphere Application Server HIGH 8.8
CVE-2024-37532

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to identity spoofing by an authenticated user due to improper signature validation. IBM X…

Mitigation only
Fix from $1,950 2024-06-20
Storage Protect For Virtual Environments HIGH 7.7
CVE-2024-38329

IBM Storage Protect for Virtual Environments: Data Protection for VMware 8.1.0.0 through 8.1.22.0 could allow a remote authenticated attacker to bypa…

Fix: 8.1.23.0+
Fix from $1,950 2024-06-19
Cloud Pak For Security HIGH 8.8
CVE-2023-47726

IBM QRadar Suite Software 1.10.12.0 through 1.10.21.0 and IBM Cloud Pak for Security 1.10.12.0 through 1.10.21.0 could allow an authenticated user to…

Fix: after 1.10.21.0
Fix from $1,950 2024-06-18
I HIGH 7.8
CVE-2024-27275

IBM i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability caused by an insufficient authority requirement. A local user withou…

Mitigation only
Fix from $1,950 2024-06-15
Db2 MEDIUM 6.5
CVE-2023-29267

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5is vulnerable to a denial of service, under specific configurat…

Mitigation only
Fix from $1,600 2024-06-12
Db2 MEDIUM 6.5
CVE-2024-31881

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may crash w…

Mitigation only
Fix from $1,600 2024-06-12
Db2 MEDIUM 6.5
CVE-2024-28762

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted qu…

Mitigation only
Fix from $1,600 2024-06-12
Engineering Lifecycle Optimization Publishing CRITICAL 9.8
CVE-2023-45188

IBM Engineering Lifecycle Optimization Publishing 7.0.2 and 7.03 could allow a remote attacker to upload arbitrary files, caused by the improper vali…

Mitigation only
Fix from $2,300 2024-06-09
I MEDIUM 5.3
CVE-2024-31878

IBM i 7.2, 7.3, 7.4, and 7.5 Service Tools Server (SST) is vulnerable to SST user enumeration by a remote attacker. This vulnerability can be used b…

Mitigation only
Fix from $1,600 2024-06-07
Ds8900f Firmware MEDIUM 6.3
CVE-2024-22326

IBM System Storage DS8900F 89.22.19.0, 89.30.68.0, 89.32.40.0, 89.33.48.0, 89.40.83.0, and 89.40.93.0 could allow a remote user to create an LDAP con…

Mitigation only
Fix from $1,600 2024-06-06
Doors Next HIGH 8.2
CVE-2023-45192

IBM Engineering Requirements Management DOORS Next 7.0.2 and 7.0.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML…

Mitigation only
Fix from $1,950 2024-06-06
Security Verify Access Docker HIGH 7.8
CVE-2024-35142

IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to execution of unnecessary privile…

Fix: 10.0.7+
Fix from $1,950 2024-05-31
Security Verify Access Docker HIGH 7.8
CVE-2024-35140

IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to improper certificate validation.…

Fix: 10.0.7+
Fix from $1,950 2024-05-31
Planning Analytics Local MEDIUM 5.4
CVE-2024-31889

IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in…

Mitigation only
Fix from $1,600 2024-05-31
Planning Analytics Local MEDIUM 5.4
CVE-2024-31907

IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in…

Mitigation only
Fix from $1,600 2024-05-31
Planning Analytics Local MEDIUM 5.4
CVE-2024-31908

IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript …

Mitigation only
Fix from $1,600 2024-05-31
Security Verify Access Oidc Provider MEDIUM 5.5
CVE-2024-22338

IBM Security Verify Access OIDC Provider 22.09 through 23.03 could disclose sensitive information to a local user due to hazardous input validation. …

Fix: after 23.03
Fix from $1,600 2024-05-31
Aspera Console MEDIUM 5.4
CVE-2022-43384

IBM Aspera Console 3.4.0 through 3.4.2 PL5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code …

Fix: after 3.4.2
Fix from $1,600 2024-05-30
Aspera Console MEDIUM 5.4
CVE-2022-43575

IBM Aspera Console 3.4.0 through 3.4.2 PL5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code …

Fix: after 3.4.2
Fix from $1,600 2024-05-30
Db2 HIGH 8.8
CVE-2023-42005

IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data 3.5, 4.0, 4.5, 4.6, 4.7, and 4.8 could allow a user with access to the Kubernet…

Mitigation only
Fix from $1,950 2024-05-29
Aspera Faspex MEDIUM 5.4
CVE-2023-37411

IBM Aspera Faspex 5.0.0 through 5.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in th…

Fix: after 5.0.6
Fix from $1,600 2024-05-28
Engineering Workflow Management MEDIUM 5.4
CVE-2024-28793

IBM Engineering Workflow Management 7.0.2 and 7.0.3 is vulnerable to stored cross-site scripting. Under certain configurations, this vulnerability al…

Mitigation only
Fix from $1,600 2024-05-28
Security Guardium MEDIUM 5.4
CVE-2023-47710

IBM Security Guardium 11.4, 11.5, and 12.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code …

Mitigation only
Fix from $1,600 2024-05-24
I HIGH 7.8
CVE-2024-27264

IBM Performance Tools for i 7.2, 7.3, 7.4, and 7.5 could allow a local user to gain elevated privileges due to an unqualified library call. A malici…

Mitigation only
Fix from $1,950 2024-05-22
App Connect Enterprise MEDIUM 6.5
CVE-2024-31895

IBM App Connect Enterprise 12.0.1.0 through 12.0.12.1 could allow an authenticated user to obtain sensitive user information using an expired access …

Fix: 12.0.12.2+
Fix from $1,600 2024-05-22
App Connect Enterprise MEDIUM 6.5
CVE-2024-31904

IBM App Connect Enterprise 11.0.0.1 through 11.0.0.25 and 12.0.1.0 through 12.0.12.0 integration nodes could allow an authenticated user to cause a d…

Fix: 11.0.0.26 / 12.0.12.1+
Fix from $1,600 2024-05-22
I HIGH 7.5
CVE-2024-31879

IBM i 7.2, 7.3, and 7.4 could allow a remote attacker to execute arbitrary code leading to a denial of service of network ports on the system, caused…

Mitigation only
Fix from $1,950 2024-05-18
Vios HIGH 8.4
CVE-2024-27260

IBM AIX could 7.2, 7.3, VIOS 3.1, and VIOS 4.1 allow a non-privileged local user to exploit a vulnerability in the invscout command to execute arbitr…

Mitigation only
Fix from $1,950 2024-05-16