Vulnerability index

Browse CVEs

6,330 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Qiskit Ibm Runtime HIGH 7.8
CVE-2024-29032

Qiskit IBM Runtime is an environment that streamlines quantum computations and provides optimal implementations of the Qiskit quantum computing SDK. …

Fix: 0.21.2+
Fix from $1,950 2024-03-20
Mq MEDIUM 5.3
CVE-2023-45177

IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS and 9.3 CD is vulnerable to a denial-of-service attack due to an error within the MQ clustering logic. IBM…

Fix: 9.0.0.21 / 9.1.0.18+
Fix from $1,600 2024-03-20
Security Verify Governance MEDIUM 5.9
CVE-2023-35888

IBM Security Verify Governance 10.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP St…

Mitigation only
Fix from $1,600 2024-03-20
Sterling Secure Proxy MEDIUM 6.1
CVE-2023-47699

IBM Sterling Secure Proxy 6.0.3 and 6.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code i…

Mitigation only
Fix from $1,600 2024-03-15
Sterling Secure Proxy MEDIUM 5.3
CVE-2023-47147

IBM Sterling Secure Proxy 6.0.3 and 6.1.0 could allow an attacker to overwrite a log message under specific conditions. IBM X-Force ID: 270598.

Patch available
Fix from $1,600 2024-03-15
Host Access Transformation Services MEDIUM 5.5
CVE-2021-38938

IBM Host Access Transformation Services (HATS) 9.6 through 9.6.1.4 and 9.7 through 9.7.0.3 stores user credentials in plain clear text which can be r…

Fix: after 9.7.0.3
Fix from $1,600 2024-03-15
Sterling Secure Proxy MEDIUM 6.1
CVE-2023-47162

IBM Sterling Secure Proxy 6.0.3 and 6.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code i…

Patch available
Fix from $1,600 2024-03-15
Sterling Secure Proxy MEDIUM 5.4
CVE-2023-46182

IBM Sterling Secure Proxy 6.0.3 and 6.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code i…

Mitigation only
Fix from $1,600 2024-03-15
Maximo Application Suite HIGH 8.2
CVE-2024-27266

IBM Maximo Application Suite 7.6.1.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could…

Patch available
Fix from $1,950 2024-03-14
Integration Bus MEDIUM 6.5
CVE-2024-27265

IBM Integration Bus for z/OS 10.1 through 10.1.0.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and…

Fix: after 10.1.0.3
Fix from $1,600 2024-03-14
I HIGH 7.8
CVE-2024-22346

Db2 for IBM i 7.2, 7.3, 7.4, and 7.5 infrastructure could allow a local user to gain elevated privileges due to an unqualified library call. A malici…

Patch available
Fix from $1,950 2024-03-14
Maximo Application Suite HIGH 7.5
CVE-2023-32335

IBM Maximo Application Suite 8.10, 8.11 and IBM Maximo Asset Management 7.6.1.3 stores sensitive information in URL parameters. This may lead to info…

Mitigation only
Fix from $1,950 2024-03-13
Maximo Application Suite MEDIUM 6.4
CVE-2023-38723

IBM Maximo Application Suite 7.6.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code…

Mitigation only
Fix from $1,600 2024-03-13
Maximo Mobile For Eam MEDIUM 5.5
CVE-2023-43043

IBM Maximo Application Suite - Maximo Mobile for EAM 8.10 and 8.11 could disclose sensitive information to a local user. IBM X-Force ID: 266875.

Mitigation only
Fix from $1,600 2024-03-13
Sterling Partner Engagement Manager MEDIUM 5.4
CVE-2023-28517

IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbit…

Mitigation only
Fix from $1,600 2024-03-13
Spss Statistics MEDIUM 5.5
CVE-2022-43855

IBM SPSS Statistics 26.0, 27.0.1, and 28.0 IO Module could allow a local user to create multiple files that could exhaust the file handles capacity a…

Mitigation only
Fix from $1,600 2024-03-08
Ds8900f Firmware CRITICAL 9.8
CVE-2023-46172

IBM DS8900F HMC 89.21.19.0, 89.21.31.0, 89.30.68.0, 89.32.40.0, and 89.33.48.0 could allow a remote attacker to bypass authentication restrictions fo…

Mitigation only
Fix from $2,300 2024-03-07
Ds8900f Firmware MEDIUM 6.5
CVE-2023-46169

IBM DS8900F HMC 89.21.19.0, 89.21.31.0, 89.30.68.0, 89.32.40.0, and 89.33.48.0 could allow an authenticated user to arbitrarily delete a file. IBM X…

Mitigation only
Fix from $1,600 2024-03-07
Ds8900f Firmware MEDIUM 6.5
CVE-2023-46170

IBM DS8900F HMC 89.21.19.0, 89.21.31.0, 89.30.68.0, 89.32.40.0, and 89.33.48.0 could allow an authenticated user to arbitrarily read files after enum…

Mitigation only
Fix from $1,600 2024-03-07
Aspera Faspex MEDIUM 6.5
CVE-2022-22399

IBM Aspera Faspex 5.0.0 and 5.0.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could all…

Mitigation only
Fix from $1,600 2024-03-05
Spectrum Virtualize MEDIUM 6.5
CVE-2023-25681

LDAP users on IBM Spectrum Virtualize 8.5 which are configured to require multifactor authentication can still authenticate to the CIM interface usin…

Mitigation only
Fix from $1,600 2024-03-05
Sterling Connect\ HIGH 7.5
CVE-2023-32331

IBM Connect:Express for UNIX 1.5.0 is vulnerable to a buffer overflow that could allow a remote attacker to cause a denial of service through its bro…

Mitigation only
Fix from $1,950 2024-03-04
Cics Tx MEDIUM 6.1
CVE-2023-38360

IBM CICS TX Advanced 10.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thu…

Mitigation only
Fix from $1,600 2024-03-04
Cics Tx MEDIUM 5.3
CVE-2023-38362

IBM CICS TX Advanced 10.1 could disclose sensitive information to a remote attacker due to observable discrepancy in HTTP responses. IBM X-Force ID:…

Mitigation only
Fix from $1,600 2024-03-04
Security Verify Privilege On Premises HIGH 7.5
CVE-2022-43890

IBM Security Verify Privilege On-Premises 11.5 could disclose sensitive information through an HTTP request that could aid an attacker in further att…

Fix: after 11.5
Fix from $1,950 2024-03-04
Watson Cp4d Data Stores HIGH 7.5
CVE-2023-27291

IBM Watson CP4D Data Stores 4.6.0, 4.6.1, 4.6.2, and 4.6.3 does not encrypt sensitive or critical information before storage or transmission which co…

Mitigation only
Fix from $1,950 2024-03-03
Watson Cp4d Data Stores MEDIUM 5.9
CVE-2023-28512

IBM Watson CP4D Data Stores 4.6.0, 4.6.1, and 4.6.2 could allow an attacker with specific knowledge about the system to manipulate data due to improp…

Mitigation only
Fix from $1,600 2024-03-03
Cloud Pak For Security MEDIUM 5.9
CVE-2023-47742

IBM QRadar Suite Products 1.10.12.0 through 1.10.18.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could disclose sensitive information …

Fix: after 1.10.18.0
Fix from $1,600 2024-03-03
Cloud Pak For Security MEDIUM 5.9
CVE-2024-22355

IBM QRadar Suite Products 1.10.12.0 through 1.10.18.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 does not require that users should ha…

Fix: after 1.10.18.0
Fix from $1,600 2024-03-03
Engineering Test Management MEDIUM 5.4
CVE-2023-43054

IBM Engineering Test Management 7.0.2 and 7.0.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary Java…

Mitigation only
Fix from $1,600 2024-03-03