Vulnerability index

Browse CVEs

6,330 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Sterling B2b Integrator MEDIUM 5.4
CVE-2024-22357

IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6.1.2.3, and 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability a…

Fix: after 6.1.2.3
Fix from $1,600 2024-04-12
Qradar Security Information And Event Manager HIGH 8.1
CVE-2023-50949

IBM QRadar SIEM 7.5 could allow an unauthorized user to perform unauthorized actions due to improper certificate validation. IBM X-Force ID: 275706.

Mitigation only
Fix from $1,950 2024-04-11
Security Verify Access HIGH 8.1
CVE-2024-31871

IBM Security Verify Access Appliance 10.0.0 through 10.0.7 could allow a malicious actor to conduct a man in the middle attack when deploying Python …

Fix: after 10.0.7
Fix from $1,950 2024-04-10
Security Verify Access HIGH 8.1
CVE-2024-31872

IBM Security Verify Access Appliance 10.0.0 through 10.0.7 could allow a malicious actor to conduct a man in the middle attack when deploying Open So…

Fix: after 10.0.7
Fix from $1,950 2024-04-10
Security Verify Access HIGH 7.5
CVE-2024-31873

IBM Security Verify Access Appliance 10.0.0 through 10.0.7 contains hard-coded credentials which it uses for its own inbound authentication that coul…

Fix: after 10.0.7
Fix from $1,950 2024-04-10
Security Verify Access MEDIUM 5.5
CVE-2024-31874

IBM Security Verify Access Appliance 10.0.0 through 10.0.7 uses uninitialized variables when deploying that could allow a local user to cause a denia…

Fix: after 10.0.7
Fix from $1,600 2024-04-10
Personal Communications CRITICAL 10.0
CVE-2024-25029

IBM Personal Communications 14.0.6 through 15.0.1 includes a Windows service that is vulnerable to remote code execution (RCE) and local privilege es…

Fix: after 15.0.1
Fix from $2,300 2024-04-06
Maximo Application Suite HIGH 7.5
CVE-2024-22328

IBM Maximo Application Suite 8.10 and 8.11 could allow a remote attacker to traverse directories on the system. An attacker could send a specially cr…

Mitigation only
Fix from $1,950 2024-04-06
Application Gateway CRITICAL 10.0
CVE-2024-28787

IBM Security Verify Access 10.0.0 through 10.0.7 and IBM Application Gateway 20.01 through 24.03 could allow a remote attacker to obtain highly sensi…

Fix: after 24.03
Fix from $2,300 2024-04-04
Websphere Application Server HIGH 7.5
CVE-2024-27268

IBM WebSphere Application Server Liberty 18.0.0.2 through 24.0.0.4 is vulnerable to a denial of service, caused by sending a specially crafted reques…

Fix: 24.0.0.5+
Fix from $1,950 2024-04-04
Db2 MEDIUM 6.5
CVE-2024-27254

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 federated server is vulnerable to denial of service with a spe…

Mitigation only
Fix from $1,600 2024-04-03
Db2 MEDIUM 6.5
CVE-2024-22360

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to a denial of service with a specially crafted query on certain…

Mitigation only
Fix from $1,600 2024-04-03
Db2 MEDIUM 6.5
CVE-2024-25046

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to a denial of service by an authenticated user using a…

Mitigation only
Fix from $1,600 2024-04-03
Db2 MEDIUM 5.5
CVE-2024-25030

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 stores potentially sensitive information in log files that could be read by a …

Mitigation only
Fix from $1,600 2024-04-03
Db2 MEDIUM 6.5
CVE-2023-38729

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to sensitive information disclosure when using A…

Mitigation only
Fix from $1,600 2024-04-03
Db2 MEDIUM 5.3
CVE-2023-52296

IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to denial of service when querying a specific UDF built-in funct…

Mitigation only
Fix from $1,600 2024-04-03
Cloud Pak For Security MEDIUM 6.5
CVE-2024-28782

IBM QRadar Suite Software 1.10.12.0 through 1.10.18.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores user credentials in plain clea…

Fix: after 1.10.18.0
Fix from $1,600 2024-04-03
Websphere Application Server MEDIUM 6.5
CVE-2023-50313

IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security for outbound TLS connections caused by a failure to honor us…

Mitigation only
Fix from $1,600 2024-04-02
Websphere Application Server HIGH 7.5
CVE-2024-22353

IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.4 is vulnerable to a denial of service, caused by sending a specially crafted reques…

Fix: after 24.0.0.3
Fix from $1,950 2024-03-31
Cloud Pak For Business Automation MEDIUM 6.5
CVE-2023-50959

IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2,19.0.1, 19.0.2, 19.0.3,20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1,2 2.0.2, 2…

Mitigation only
Fix from $1,600 2024-03-31
Security Verify Access MEDIUM 5.5
CVE-2024-25027

IBM Security Verify Access 10.0.6 could disclose sensitive snapshot information due to missing encryption. IBM X-Force ID: 281607.

Patch available
Fix from $1,600 2024-03-31
Websphere Application Server MEDIUM 6.1
CVE-2024-27270

IBM WebSphere Application Server Liberty 23.0.0.3 through 24.0.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed ar…

Fix: 24.0.0.4+
Fix from $1,600 2024-03-27
Qradar Security Information And Event Manager MEDIUM 5.4
CVE-2024-28784

IBM QRadar SIEM 7.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alte…

Mitigation only
Fix from $1,600 2024-03-27
Qradar Security Information And Event Manager MEDIUM 5.4
CVE-2023-50961

IBM QRadar SIEM 7.5 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI th…

Mitigation only
Fix from $1,600 2024-03-27
Common Cryptographic Architecture HIGH 7.5
CVE-2023-47150

IBM Common Cryptographic Architecture (CCA) 7.0.0 through 7.5.36 could allow a remote user to cause a denial of service due to incorrect data handlin…

Fix: 7.5.37+
Fix from $1,950 2024-03-26
Security Verify Directory MEDIUM 6.5
CVE-2022-32753

IBM Security Verify Directory 10.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive info…

Mitigation only
Fix from $1,600 2024-03-22
Security Verify Directory MEDIUM 5.3
CVE-2022-32751

IBM Security Verify Directory 10.0.0 could disclose sensitive server information that could be used in further attacks against the system. IBM X-For…

Mitigation only
Fix from $1,600 2024-03-22
Storage Protect Plus MEDIUM 5.5
CVE-2024-27277

The private key for the IBM Storage Protect Plus Server 10.1.0 through 10.1.16 certificate can be disclosed, undermining the security of the certific…

Fix: after 10.1.6
Fix from $1,600 2024-03-21
Infosphere Information Server MEDIUM 5.5
CVE-2024-22352

IBM InfoSphere Information Server 11.7 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 28…

Mitigation only
Fix from $1,600 2024-03-21
Cloud Pak For Business Automation CRITICAL 9.8
CVE-2023-35899

IBM Cloud Pak for Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 is po…

Mitigation only
Fix from $2,300 2024-03-21