Vulnerability index

Browse CVEs

6,330 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cognos Controller HIGH 7.5
CVE-2023-40696

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly se…

Mitigation only
Fix from $1,950 2024-05-03
Cognos Controller CRITICAL 9.8
CVE-2023-38724

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which…

Mitigation only
Fix from $2,300 2024-05-03
Cognos Controller MEDIUM 5.3
CVE-2023-23474

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 could allow a remote attacker to obtain sensitive information when a stack trace is returned in the …

Mitigation only
Fix from $1,600 2024-05-03
Cognos Controller MEDIUM 5.3
CVE-2023-28952

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to injection attacks in application logging by not sanitizing user provided data. IBM…

Mitigation only
Fix from $1,600 2024-05-03
Cognos Controller MEDIUM 5.3
CVE-2021-20556

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 could allow a remote user to enumerate usernames due to differentiating error messages on existing u…

Mitigation only
Fix from $1,600 2024-05-03
Cognos Controller HIGH 7.5
CVE-2020-4874

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly se…

Mitigation only
Fix from $1,950 2024-05-03
Aspera Orchestrator HIGH 8.8
CVE-2023-37407

IBM Aspera Orchestrator 4.0.1 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted …

Mitigation only
Fix from $1,950 2024-05-03
Cognos Analytics HIGH 8.6
CVE-2024-25047

IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.2 is vulnerable to injection attacks in application logging by not sanitizing user…

Fix: 11.2.4 / 12.0.3+
Fix from $1,950 2024-05-02
Websphere Automation HIGH 7.8
CVE-2024-28764

IBM WebSphere Automation 1.7.0 could allow an attacker with privileged access to the network to conduct a CSV injection. An attacker could execute a…

Mitigation only
Fix from $1,950 2024-05-01
Mq HIGH 7.5
CVE-2024-25015

IBM MQ 9.2 LTS, 9.3 LTS, and 9.3 CD Internet Pass-Thru could allow a remote user to cause a denial of service by sending HTTP requests that would con…

Fix: 9.2.0.25 / 9.3.0.17+
Fix from $1,950 2024-05-01
Websphere Automation MEDIUM 5.4
CVE-2024-28775

IBM WebSphere Automation 1.7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web U…

Mitigation only
Fix from $1,600 2024-05-01
Cloud Pak For Security MEDIUM 5.9
CVE-2022-38386

IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite for Software 1.10.12.0 through 1.10.19.0 does not set the SameSite …

Fix: after 1.10.19.0
Fix from $1,600 2024-05-01
Storage Scale HIGH 8.8
CVE-2023-38002

IBM Storage Scale 5.1.0.0 through 5.1.9.2 could allow an authenticated user to steal or manipulate an active session to gain access to the system. I…

Fix: 5.2.0.0+
Fix from $1,950 2024-04-30
Rational Developer For I HIGH 7.8
CVE-2024-25050

IBM i 7.2, 7.3, 7.4, 7.5 and IBM Rational Development Studio for i 7.2, 7.3, 7.4, 7.5 networking and compiler infrastructure could allow a local user…

Mitigation only
Fix from $1,950 2024-04-28
Mq Appliance HIGH 7.5
CVE-2024-25048

IBM MQ Appliance 9.3 CD and LTS are vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote authenticated attacker c…

Fix: 9.3.0.17 / 9.3.5+
Fix from $1,950 2024-04-27
Websphere Application Server HIGH 7.5
CVE-2024-25026

IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.4 are vulnerable to a denial of servic…

Fix: after 24.0.0.4
Fix from $1,950 2024-04-25
Cloud Pak For Security MEDIUM 5.4
CVE-2023-47731

IBM QRadar Suite Software 1.10.12.0 through 1.10.19.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 is vulnerable to stored cross-site sc…

Fix: after 1.10.19.0
Fix from $1,600 2024-04-23
Aspera Faspex MEDIUM 6.5
CVE-2023-27279

IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a user to cause a denial of service due to missing API rate limiting. IBM X-Force ID: 248533.

Fix: after 5.0.7
Fix from $1,600 2024-04-19
Aspera Faspex MEDIUM 5.5
CVE-2022-40745

IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain sensitive information due to weaker than expected security. IBM X-Force ID:…

Fix: after 5.0.7
Fix from $1,600 2024-04-19
Aspera Faspex MEDIUM 5.5
CVE-2023-22869

IBM Aspera Faspex 5.0.0 through 5.0.7 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 244…

Fix: 5.0.8+
Fix from $1,600 2024-04-19
Aspera Faspex MEDIUM 5.5
CVE-2023-37396

IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain sensitive information due to improper encryption of certain data. IBM X-For…

Fix: 5.0.8+
Fix from $1,600 2024-04-19
Aspera Faspex HIGH 7.8
CVE-2023-37400

IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to escalate their privileges due to insecure credential storage. IBM X-Force ID: 259…

Fix: 5.0.8+
Fix from $1,950 2024-04-19
Websphere Application Server HIGH 7.0
CVE-2024-22354

IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.5 are vulnerable to an XML External En…

Fix: 8.5.5.26 / 9.0.5.20+
Fix from $1,950 2024-04-17
Security Verify Privilege On Premises HIGH 7.5
CVE-2024-31887

IBM Security Verify Privilege 11.6.25 could allow an unauthenticated actor to obtain sensitive information from the SOAP API. IBM X-Force ID: 2876…

Mitigation only
Fix from $1,950 2024-04-16
Devops Deploy HIGH 8.8
CVE-2024-22358

IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4 and IBM DevOps Deploy 8.0 through 8.…

Fix: 7.0.5.21 / 7.1.2.17+
Fix from $1,950 2024-04-12
Devops Deploy MEDIUM 6.1
CVE-2024-22359

IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4 and IBM DevOps Deploy 8.0 through 8.…

Fix: 7.0.5.21 / 7.1.2.17+
Fix from $1,600 2024-04-12
Storage Defender Resiliency Service MEDIUM 6.8
CVE-2024-27261

IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.2 could allow a privileged user to install a potentially dangerous tar file, which could …

Fix: 2.0.3+
Fix from $1,600 2024-04-12
Sterling File Gateway MEDIUM 5.4
CVE-2023-47714

IBM Sterling File Gateway 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6.1.2.3, and 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability all…

Fix: after 6.1.2.3
Fix from $1,600 2024-04-12
Sterling B2b Integrator MEDIUM 5.4
CVE-2023-45186

IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6.1.2.3, and 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability a…

Fix: after 6.1.2.3
Fix from $1,600 2024-04-12
Sterling B2b Integrator MEDIUM 5.4
CVE-2023-50307

IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6.1.2.3, and 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability a…

Fix: after 6.1.2.3
Fix from $1,600 2024-04-12