Vulnerability index

Browse CVEs

6,330 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Planning Analytics Local MEDIUM 5.4
CVE-2024-31907

IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in…

Mitigation only
Fix from $1,600 2024-05-31
Planning Analytics Local MEDIUM 5.4
CVE-2024-31908

IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript …

Mitigation only
Fix from $1,600 2024-05-31
Security Verify Access Oidc Provider MEDIUM 5.5
CVE-2024-22338

IBM Security Verify Access OIDC Provider 22.09 through 23.03 could disclose sensitive information to a local user due to hazardous input validation. …

Fix: after 23.03
Fix from $1,600 2024-05-31
Aspera Console MEDIUM 5.4
CVE-2022-43384

IBM Aspera Console 3.4.0 through 3.4.2 PL5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code …

Fix: after 3.4.2
Fix from $1,600 2024-05-30
Aspera Console MEDIUM 5.4
CVE-2022-43575

IBM Aspera Console 3.4.0 through 3.4.2 PL5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code …

Fix: after 3.4.2
Fix from $1,600 2024-05-30
Db2 HIGH 8.8
CVE-2023-42005

IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data 3.5, 4.0, 4.5, 4.6, 4.7, and 4.8 could allow a user with access to the Kubernet…

Mitigation only
Fix from $1,950 2024-05-29
Aspera Faspex MEDIUM 5.4
CVE-2023-37411

IBM Aspera Faspex 5.0.0 through 5.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in th…

Fix: after 5.0.6
Fix from $1,600 2024-05-28
Engineering Workflow Management MEDIUM 5.4
CVE-2024-28793

IBM Engineering Workflow Management 7.0.2 and 7.0.3 is vulnerable to stored cross-site scripting. Under certain configurations, this vulnerability al…

Mitigation only
Fix from $1,600 2024-05-28
Security Guardium MEDIUM 5.4
CVE-2023-47710

IBM Security Guardium 11.4, 11.5, and 12.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code …

Mitigation only
Fix from $1,600 2024-05-24
I HIGH 7.8
CVE-2024-27264

IBM Performance Tools for i 7.2, 7.3, 7.4, and 7.5 could allow a local user to gain elevated privileges due to an unqualified library call. A malici…

Mitigation only
Fix from $1,950 2024-05-22
App Connect Enterprise MEDIUM 6.5
CVE-2024-31895

IBM App Connect Enterprise 12.0.1.0 through 12.0.12.1 could allow an authenticated user to obtain sensitive user information using an expired access …

Fix: 12.0.12.2+
Fix from $1,600 2024-05-22
App Connect Enterprise MEDIUM 6.5
CVE-2024-31904

IBM App Connect Enterprise 11.0.0.1 through 11.0.0.25 and 12.0.1.0 through 12.0.12.0 integration nodes could allow an authenticated user to cause a d…

Fix: 11.0.0.26 / 12.0.12.1+
Fix from $1,600 2024-05-22
I HIGH 7.5
CVE-2024-31879

IBM i 7.2, 7.3, and 7.4 could allow a remote attacker to execute arbitrary code leading to a denial of service of network ports on the system, caused…

Mitigation only
Fix from $1,950 2024-05-18
Vios HIGH 8.4
CVE-2024-27260

IBM AIX could 7.2, 7.3, VIOS 3.1, and VIOS 4.1 allow a non-privileged local user to exploit a vulnerability in the invscout command to execute arbitr…

Mitigation only
Fix from $1,950 2024-05-16
App Connect Enterprise MEDIUM 5.4
CVE-2024-28761

IBM App Connect Enterprise 11.0.0.1 through 11.0.0.25 and 12.0.1.0 through 12.0.12.0 is vulnerable to HTML injection. A remote attacker could inject …

Fix: 11.0.0.26 / 12.0.12.1+
Fix from $1,600 2024-05-14
Devops Deploy MEDIUM 5.4
CVE-2024-28781

IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4, and 8.0 through 8.0.0.1 is vulnerabl…

Fix: 7.0.5.21 / 7.1.2.17+
Fix from $1,600 2024-05-14
Qradar Security Information And Event Manager MEDIUM 6.8
CVE-2024-27269

IBM QRadar SIEM 7.5 could allow a privileged user to configure user management that would disclose unintended sensitive information across tenants. …

Mitigation only
Fix from $1,600 2024-05-14
Txseries For Multiplatform HIGH 7.5
CVE-2024-22345

IBM TXSeries for Multiplatforms 8.2 transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorize…

Mitigation only
Fix from $1,950 2024-05-14
Txseries For Multiplatform MEDIUM 6.1
CVE-2024-22344

IBM TXSeries for Multiplatforms 8.2 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be …

Mitigation only
Fix from $1,600 2024-05-14
Security Guardium HIGH 7.8
CVE-2023-47712

IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a local user to gain elevated privileges on the system due to improper permissions contr…

Mitigation only
Fix from $1,950 2024-05-14
Security Guardium MEDIUM 6.5
CVE-2023-47711

IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow an authenticated user to upload files that would cause a denial of service. IBM X-Force…

Mitigation only
Fix from $1,600 2024-05-14
Security Guardium HIGH 8.8
CVE-2023-47709

IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a…

Mitigation only
Fix from $1,950 2024-05-14
Storage Fusion Hci CRITICAL 9.8
CVE-2023-43040

IBM Spectrum Fusion HCI 2.5.2 through 2.7.2 could allow an attacker to perform unauthorized actions in RGW for Ceph due to improper bucket access. I…

Fix: 2.8.0+
Fix from $2,300 2024-05-14
Java Software Development Kit HIGH 7.5
CVE-2023-38264

The IBM SDK, Java Technology Edition's Object Request Broker (ORB) 7.1.0.0 through 7.1.5.21 and 8.0.0.0 through 8.0.8.21 is vulnerable to a denial of…

Fix: 7.1.5.22 / 8.0.8.25+
Fix from $1,950 2024-05-14
Vios HIGH 7.8
CVE-2024-27273

IBM AIX's Unix domain (AIX 7.2, 7.3, VIOS 3.1, and VIOS 4.1) datagram socket implementation could potentially expose applications using Unix domain d…

Mitigation only
Fix from $1,950 2024-05-07
Watson Cp4d Data Stores MEDIUM 5.5
CVE-2023-40694

IBM Watson CP4D Data Stores 4.0.0 through 4.8.4 stores potentially sensitive information in log files that could be read by a local user. IBM X-Forc…

Fix: 4.8.5+
Fix from $1,600 2024-05-07
Aspera Orchestrator MEDIUM 5.3
CVE-2023-27283

IBM Aspera Orchestrator 4.0.1 could allow a remote attacker to enumerate usernames due to observable response discrepancies. IBM X-Force ID: 248545.

Mitigation only
Fix from $1,600 2024-05-04
Cognos Controller HIGH 8.8
CVE-2023-40695

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 does not invalidate session after logout which could allow an authenticated user to impersonate anot…

Mitigation only
Fix from $1,950 2024-05-03
Cognos Controller HIGH 7.2
CVE-2021-20451

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which…

Mitigation only
Fix from $1,950 2024-05-03
Cognos Controller MEDIUM 5.3
CVE-2022-22364

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to external service interaction attack, caused by improper validation of user-supplied…

Mitigation only
Fix from $1,600 2024-05-03