Vulnerability index

Browse CVEs

6,330 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mq Operator HIGH 7.5
CVE-2024-27255

IBM MQ Operator 2.0.0 LTS, 2.0.18 LTS, 3.0.0 CD, 3.0.1 CD, 2.4.0 through 2.4.7, 2.3.0 through 2.3.3, 2.2.0 through 2.2.2, and 2.3.0 through 2.3.3 use…

Fix: after 2.4.7
Fix from $1,950 2024-03-03
Mq Operator MEDIUM 5.5
CVE-2023-47745

IBM MQ Operator 2.0.0 LTS, 2.0.18 LTS, 3.0.0 CD, 3.0.1 CD, 2.4.0 through 2.4.7, 2.3.0 through 2.3.3, 2.2.0 through 2.2.2, and 2.3.0 through 2.3.3 sto…

Fix: after 2.4.7
Fix from $1,600 2024-03-03
Mq HIGH 7.5
CVE-2024-25016

IBM MQ and IBM MQ Appliance 9.0, 9.1, 9.2, 9.3 LTS and 9.3 CD could allow a remote unauthenticated attacker to cause a denial of service due to incor…

Fix: 9.0.0.23 / 9.1.0.20+
Fix from $1,950 2024-03-03
Cp4ba Filenet Content Manager HIGH 8.8
CVE-2023-47716

IBM CP4BA - Filenet Content Manager Component 5.5.8.0, 5.5.10.0, and 5.5.11.0 could allow a user to gain the privileges of another user under unusual…

Mitigation only
Fix from $1,950 2024-03-01
Websphere Application Server MEDIUM 6.5
CVE-2023-50312

IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.2 could provide weaker than expected security for outbound TLS connections caused by…

Fix: 24.0.0.3+
Fix from $1,600 2024-03-01
Filenet Content Manager MEDIUM 5.3
CVE-2023-38366

IBM Filenet Content Manager Component 5.5.8.0, 5.5.10.0, and 5.5.11.0 could allow a remote attacker to traverse directories on the system. An attacke…

Mitigation only
Fix from $1,600 2024-03-01
Engineering Requirements Management Doors MEDIUM 6.5
CVE-2023-28949

IBM Engineering Requirements Management DOORS 9.7.2.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious …

Mitigation only
Fix from $1,600 2024-03-01
Cognos Command Center MEDIUM 5.3
CVE-2023-50324

IBM Cognos Command Center 10.2.4.1 and 10.2.5 exposes details the X-AspNet-Version Response Header that could allow an attacker to obtain information…

Mitigation only
Fix from $1,600 2024-03-01
Engineering Requirements Management Doors MEDIUM 5.1
CVE-2023-50305

IBM Engineering Requirements Management DOORS 9.7.2.7 does not require that users should have strong passwords by default, which makes it easier for …

Mitigation only
Fix from $1,600 2024-03-01
Cloud Pak For Security MEDIUM 5.9
CVE-2021-39090

IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.6.0 could allow a remote attacker to obtain sensitive information, caused by the failure to p…

Fix: 1.10.7.0+
Fix from $1,600 2024-02-29
Cloud Pak For Business Automation MEDIUM 6.5
CVE-2023-38367

IBM Cloud Pak Foundational Services Identity Provider (idP) API (IBM Cloud Pak for Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1,…

Mitigation only
Fix from $1,600 2024-02-29
Cloud Pak For Data MEDIUM 5.5
CVE-2023-27545

IBM Watson CloudPak for Data Data Stores information disclosure 4.6.0 allows web pages to be stored locally which can be read by another user on the …

Mitigation only
Fix from $1,600 2024-02-29
Watson Iot Platform HIGH 7.5
CVE-2023-38372

An unauthorized attacker who has obtained an IBM Watson IoT Platform 1.0 security authentication token can use it to impersonate an authorized platfo…

Mitigation only
Fix from $1,950 2024-02-29
Security Guardium Key Lifecycle Manager HIGH 8.8
CVE-2023-25921

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 allows the attacker to upload or transfer files of dangerous types that c…

Fix: 4.1.1.7+
Fix from $1,950 2024-02-29
Security Guardium Key Lifecycle Manager HIGH 8.2
CVE-2023-25926

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 is vulnerable to an XML External Entity Injection (XXE) attack when proce…

Fix: 4.1.1.7+
Fix from $1,950 2024-02-29
Security Guardium Key Lifecycle Manager HIGH 8.8
CVE-2023-25922

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 allows the attacker to upload or transfer files of dangerous types that c…

Fix: 4.1.1.7+
Fix from $1,950 2024-02-28
Security Guardium Key Lifecycle Manager HIGH 8.8
CVE-2023-25925

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow a remote authenticated attacker to execute arbitrary commands…

Fix: 4.1.1.7+
Fix from $1,950 2024-02-28
Infosphere Information Server MEDIUM 6.1
CVE-2023-50303

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…

Mitigation only
Fix from $1,600 2024-02-28
Aspera Console CRITICAL 9.1
CVE-2022-43842

IBM Aspera Console 3.4.0 through 3.4.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could all…

Fix: 3.4.2+
Fix from $2,300 2024-02-23
Vios HIGH 8.4
CVE-2024-25021

IBM AIX 7.3, VIOS 4.1's Perl implementation could allow a non-privileged local user to exploit a vulnerability to execute arbitrary commands. IBM X-…

Mitigation only
Fix from $1,950 2024-02-22
Infosphere Information Server MEDIUM 5.4
CVE-2023-33843

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…

Mitigation only
Fix from $1,600 2024-02-21
Trusteer Android Sdk For Mobile CRITICAL 9.8
CVE-2022-42443

An undisclosed issue in Trusteer iOS SDK for mobile versions prior to 5.7 and Trusteer Android SDK for mobile versions prior to 5.7 may allow uploadi…

Fix: 5.7+
Fix from $2,300 2024-02-17
Spectrum Scale Container Native Storage Access HIGH 7.5
CVE-2022-41738

IBM Storage Scale Container Native Storage Access 5.1.2.1 -through 5.1.7.0 could allow an attacker to initiate connections to containers from externa…

Fix: after 5.1.7.0
Fix from $1,950 2024-02-17
Spectrum Scale Container Native Storage Access MEDIUM 6.5
CVE-2022-41737

IBM Storage Scale Container Native Storage Access 5.1.2.1 through 5.1.7.0 could allow a local attacker to initiate connections from a container outsi…

Fix: after 5.1.7.0
Fix from $1,600 2024-02-17
Cloud Pak For Security MEDIUM 5.5
CVE-2024-22335

IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores potentially sensitive information in lo…

Fix: 1.10.18.0+
Fix from $1,600 2024-02-17
Cloud Pak For Security MEDIUM 5.5
CVE-2024-22336

IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores potentially sensitive information in lo…

Fix: 1.10.18.0+
Fix from $1,600 2024-02-17
Cloud Pak For Security MEDIUM 5.5
CVE-2024-22337

IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores potentially sensitive information in lo…

Fix: 1.10.18.0+
Fix from $1,600 2024-02-17
Jazz For Service Management HIGH 7.5
CVE-2023-46186

IBM Jazz for Service Management 1.1.3.20 could allow an unauthorized user to obtain sensitive file information using forced browsing due to improper …

Mitigation only
Fix from $1,950 2024-02-14
Cics Tx HIGH 7.5
CVE-2022-34309

IBM CICS TX Standard and Advanced 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive in…

Mitigation only
Fix from $1,950 2024-02-12
Cics Tx HIGH 7.5
CVE-2022-34310

IBM CICS TX Standard and Advanced 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive in…

Fix: 11.1.0.0+
Fix from $1,950 2024-02-12