Vulnerability index

Browse CVEs

6,330 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Storage Defender Resiliency Service HIGH 7.8
CVE-2024-22313

IBM Storage Defender - Resiliency Service 2.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inb…

Patch available
Fix from $1,950 2024-02-10
Storage Defender Resiliency Service MEDIUM 5.5
CVE-2024-22312

IBM Storage Defender - Resiliency Service 2.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 278748.

Patch available
Fix from $1,600 2024-02-10
Storage Defender Resiliency Service HIGH 7.2
CVE-2023-50957

IBM Storage Defender - Resiliency Service 2.0 could allow a privileged user to perform unauthorized actions after obtaining encrypted data from clear…

Patch available
Fix from $1,950 2024-02-10
Semeru Runtime HIGH 7.5
CVE-2024-22361

IBM Semeru Runtime 8.0.302.0 through 8.0.392.0, 11.0.12.0 through 11.0.21.0, 17.0.1.0 - 17.0.9.0, and 21.0.1.0 uses weaker than expected cryptographi…

Fix: 8.0.402.0 / 11.0.22.0+
Fix from $1,950 2024-02-10
Integration Bus MEDIUM 6.5
CVE-2024-22332

The IBM Integration Bus for z/OS 10.1 through 10.1.0.2 AdminAPI is vulnerable to a denial of service due to file system exhaustion. IBM X-Force ID: …

Fix: after 10.1.0.2
Fix from $1,600 2024-02-09
I Access Client Solutions MEDIUM 5.5
CVE-2024-22318

IBM i Access Client Solutions (ACS) 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.4 is vulnerable to NT LAN Manager (NTLM) hash disclosure by an atta…

Fix: after 1.1.9.4
Fix from $1,600 2024-02-09
Engineering Lifecycle Optimization HIGH 8.8
CVE-2023-45187

IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 does not invalidate session after logout which could allow an authenticated user …

Patch available
Fix from $1,950 2024-02-09
Engineering Lifecycle Optimization HIGH 7.5
CVE-2023-45191

IBM Engineering Lifecycle Optimization 7.0.2 and 7.0.3 uses an inadequate account lockout setting that could allow a remote attacker to brute force a…

Patch available
Fix from $1,950 2024-02-09
Sterling B2b Integrator MEDIUM 6.5
CVE-2023-32341

IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.3 could allow an authenticated user to cause a denial of service due to…

Fix: after 6.1.2.3
Fix from $1,600 2024-02-09
Engineering Lifecycle Optimization MEDIUM 6.1
CVE-2023-45190

IBM Engineering Lifecycle Optimization 7.0.2 and 7.0.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST hea…

Patch available
Fix from $1,600 2024-02-09
Security Access Manager Container HIGH 7.5
CVE-2023-38369

IBM Security Access Manager Container 10.0.0.0 through 10.0.6.1 does not require that docker images should have strong passwords by default, which ma…

Fix: after 10.0.6.1
Fix from $1,950 2024-02-07
Storage Virtualize HIGH 7.5
CVE-2023-47700

IBM SAN Volume Controller, IBM Storwize, IBM FlashSystem and IBM Storage Virtualize 8.6 products could allow a remote attacker to spoof a trusted sys…

Mitigation only
Fix from $1,950 2024-02-07
Security Verify Access HIGH 7.2
CVE-2023-43017

IBM Security Verify Access 10.0.0.0 through 10.0.6.1 could allow a privileged user to install a configuration file that could allow remote access. I…

Fix: after 10.0.6.1
Fix from $1,950 2024-02-07
Security Verify Access CRITICAL 9.8
CVE-2023-32328

IBM Security Verify Access 10.0.0.0 through 10.0.6.1 uses insecure protocols in some instances that could allow an attacker on the network to take co…

Fix: after 10.0.6.1
Fix from $2,300 2024-02-07
Security Verify Access CRITICAL 9.8
CVE-2023-32330

IBM Security Verify Access 10.0.0.0 through 10.0.6.1 uses insecure calls that could allow an attacker on the network to take control of the server. …

Fix: after 10.0.6.1
Fix from $2,300 2024-02-07
Security Access Manager Container MEDIUM 5.5
CVE-2023-31002

IBM Security Access Manager Container 10.0.0.0 through 10.0.6.1 temporarily stores sensitive information in files that could be accessed by a local u…

Fix: after 10.0.6.1
Fix from $1,600 2024-02-07
Urbancode Deploy MEDIUM 5.5
CVE-2024-22331

IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.19, 7.1 through 7.1.2.15, 7.2 through 7.2.3.8, 7.3 through 7.3.2.3, and IBM UrbanCode Deploy (UCD) - IBM…

Fix: 7.0.5.20 / 7.1.2.16+
Fix from $1,600 2024-02-06
Business Automation Workflow MEDIUM 5.4
CVE-2023-50947

IBM Business Automation Workflow 22.0.2, 23.0.1, and 23.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary…

Fix: after 21.0.3.1
Fix from $1,600 2024-02-04
Security Verify Access HIGH 7.3
CVE-2023-43016

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 …

Fix: after 10.0.6.1
Fix from $1,950 2024-02-03
Security Verify Access CRITICAL 9.0
CVE-2023-31004

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 …

Fix: after 10.0.6.1
Fix from $2,300 2024-02-03
Security Verify Access HIGH 7.8
CVE-2023-31005

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 …

Fix: after 10.0.6.1
Fix from $1,950 2024-02-03
Security Verify Access HIGH 7.5
CVE-2023-31006

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 …

Fix: after 10.0.6.1
Fix from $1,950 2024-02-03
Security Verify Access HIGH 7.1
CVE-2023-32327

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 …

Fix: after 10.0.6.1
Fix from $1,950 2024-02-03
Security Verify Access MEDIUM 5.5
CVE-2023-32329

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 …

Fix: after 10.0.6.1
Fix from $1,600 2024-02-03
Security Verify Access HIGH 7.5
CVE-2023-30999

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 …

Fix: after 10.0.6.1
Fix from $1,950 2024-02-03
Cloud Pak System HIGH 7.5
CVE-2023-38273

IBM Cloud Pak System 2.3.1.1, 2.3.2.0, and 2.3.3.7 uses an inadequate account lockout setting that could allow a remote attacker to brute force accou…

Fix: after 2.3.3.6
Fix from $1,950 2024-02-02
Tivoli Application Dependency Discovery Manager HIGH 8.8
CVE-2023-47142

IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 could allow an attacker on the organization's local network to escalate …

Fix: after 7.3.0.10
Fix from $1,950 2024-02-02
Tivoli Application Dependency Discovery Manager CRITICAL 9.8
CVE-2023-47143

IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 is vulnerable to HTTP header injection, caused by improper validation of…

Fix: 7.3.0.11+
Fix from $2,300 2024-02-02
Spectrum Protect Plus HIGH 7.5
CVE-2023-47148

IBM Storage Protect Plus Server 10.1.0 through 10.1.15.2 Admin Console could allow a remote attacker to obtain sensitive information due to improper …

Fix: 10.1.15.3+
Fix from $1,950 2024-02-02
Tivoli Application Dependency Discovery Manager MEDIUM 6.1
CVE-2023-47144

IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 is vulnerable to cross-site scripting. This vulnerability allows users t…

Fix: 7.3.0.11+
Fix from $1,600 2024-02-02