Vulnerability index

Browse CVEs

6,330 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Soar Qradar Plugin App HIGH 8.8
CVE-2023-38263

IBM SOAR QRadar Plugin App 1.0 through 5.0.3 could allow an authenticated user to perform unauthorized actions due to improper access controls. IBM …

Fix: 5.0.3+
Fix from $1,950 2024-02-02
Soar Qradar Plugin App MEDIUM 6.5
CVE-2023-38019

IBM SOAR QRadar Plugin App 1.0 through 5.0.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially …

Fix: 5.0.3+
Fix from $1,600 2024-02-02
Aspera Faspex MEDIUM 5.4
CVE-2022-40744

IBM Aspera Faspex 5.0.6 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web U…

Fix: 5.0.7+
Fix from $1,600 2024-02-02
Operational Decision Manager CRITICAL 9.8
CVE-2024-22319EPSS 76%

IBM Operational Decision Manager 8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, 8.11.1 and 8.12.0.1 is susceptible to remote code execution attack via JND…

Patch available
Fix from $2,300 2024-02-02
Operational Decision Manager HIGH 8.8
CVE-2024-22320EPSS 73%

IBM Operational Decision Manager 8.10.3 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unsafe dese…

Patch available
Fix from $1,950 2024-02-02
Storage Ceph MEDIUM 6.5
CVE-2023-46159

IBM Storage Ceph 5.3z1, 5.3z5, and 6.1z1 could allow an authenticated user on the network to cause a denial of service from RGW. IBM X-Force ID: 26…

Patch available
Fix from $1,600 2024-02-02
Powersc HIGH 7.5
CVE-2023-50962

IBM PowerSC 1.3, 2.0, and 2.1 MFA does not implement the "HTTP Strict Transport Security" (HSTS) web security policy mechanism. IBM X-Force ID: 276…

Mitigation only
Fix from $1,950 2024-02-02
Powersc MEDIUM 6.5
CVE-2023-50935

IBM PowerSC 1.3, 2.0, and 2.1 fails to properly restrict access to a URL or resource, which may allow a remote attacker to obtain unauthorized access…

Patch available
Fix from $1,600 2024-02-02
Powersc MEDIUM 5.4
CVE-2023-50941

IBM PowerSC 1.3, 2.0, and 2.1 does not provide logout functionality, which could allow an authenticated user to gain access to an unauthorized user u…

Patch available
Fix from $1,600 2024-02-02
Maximo Asset Management CRITICAL 9.8
CVE-2023-32333

IBM Maximo Asset Management 7.6.1.3 could allow a remote attacker to log into the admin panel due to improper access controls. IBM X-Force ID: 2550…

Patch available
Fix from $2,300 2024-02-02
Powersc MEDIUM 5.3
CVE-2023-50328

IBM PowerSC 1.3, 2.0, and 2.1 may allow a remote attacker to view session identifiers passed via URL query strings. IBM X-Force ID: 275110.

Patch available
Fix from $1,600 2024-02-02
Powersc MEDIUM 5.3
CVE-2023-50934

IBM PowerSC 1.3, 2.0, and 2.1 uses single-factor authentication which can lead to unnecessary risk of compromise when compared with the benefits of a…

Patch available
Fix from $1,600 2024-02-02
Powersc CRITICAL 9.8
CVE-2023-50940

IBM PowerSC 1.3, 2.0, and 2.1 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve se…

Patch available
Fix from $2,300 2024-02-02
Powersc HIGH 8.8
CVE-2023-50936

IBM PowerSC 1.3, 2.0, and 2.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the sys…

Patch available
Fix from $1,950 2024-02-02
Powersc HIGH 7.5
CVE-2023-50937

IBM PowerSC 1.3, 2.0, and 2.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information…

Patch available
Fix from $1,950 2024-02-02
Powersc MEDIUM 6.1
CVE-2023-50933

IBM PowerSC 1.3, 2.0, and 2.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be execut…

Patch available
Fix from $1,600 2024-02-02
Powersc HIGH 7.5
CVE-2023-50326

IBM PowerSC 1.3, 2.0, and 2.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM …

Patch available
Fix from $1,950 2024-02-02
Powersc MEDIUM 5.3
CVE-2023-50327

IBM PowerSC 1.3, 2.0, and 2.1 uses insecure HTTP methods which could allow a remote attacker to perform unauthorized file request modification. IBM …

Patch available
Fix from $1,600 2024-02-02
Powersc HIGH 7.5
CVE-2023-50939

IBM PowerSC 1.3, 2.0, and 2.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information…

Patch available
Fix from $1,950 2024-02-02
Merge Efilm Workstation CRITICAL 9.8
CVE-2024-23622

A stack-based buffer overflow exists in IBM Merge Healthcare eFilm Workstation license server. A remote, unauthenticated attacker can exploit this vu…

Fix: after 4.2
Fix from $2,300 2024-01-26
Merge Efilm Workstation CRITICAL 9.8
CVE-2024-23619

A hardcoded credential vulnerability exists in IBM Merge Healthcare eFilm Workstation. A remote, unauthenticated attacker can exploit this vulnerabil…

Fix: after 4.2
Fix from $2,300 2024-01-26
Merge Efilm Workstation CRITICAL 9.8
CVE-2024-23621

A buffer overflow exists in IBM Merge Healthcare eFilm Workstation license server. A remote, unauthenticated attacker can exploit this vulnerability …

Fix: after 4.2
Fix from $2,300 2024-01-26
Merge Efilm Workstation HIGH 7.8
CVE-2024-23620

An improper privilege management vulnerability exists in IBM Merge Healthcare eFilm Workstation. A local, authenticated attacker can exploit this vul…

Fix: after 4.2
Fix from $1,950 2024-01-26
Db2 MEDIUM 6.5
CVE-2023-47141

IIBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated user with CONNECT privileges to cause a denial o…

Fix: 11.5.9+
Fix from $1,600 2024-01-22
Db2 MEDIUM 6.5
CVE-2023-47158

IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1 and 11.5 could allow an authenticated user with CONNECT privileges t…

Fix: after 11.5.9
Fix from $1,600 2024-01-22
Db2 MEDIUM 6.5
CVE-2023-47747

IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.1, 10.5, and 11.1 could allow an authenticated user with CONNECT privileges to c…

Fix: after 11.5.9
Fix from $1,600 2024-01-22
Db2 HIGH 7.5
CVE-2023-47152

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to an insecure cryptographic algorithm and to information disclo…

Fix: 11.5.9+
Fix from $1,950 2024-01-22
Db2 MEDIUM 6.5
CVE-2023-27859

IBM Db2 10.1, 10.5, and 11.1 could allow a remote user to execute arbitrary code caused by installing like named jar files across multiple databases.…

Fix: after 11.5.9
Fix from $1,600 2024-01-22
Db2 MEDIUM 6.5
CVE-2023-50308

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5 under certain circumstances could allow an authenticated user to the database …

Fix: 11.5.9+
Fix from $1,600 2024-01-22
Db2 HIGH 7.5
CVE-2023-45193

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 federated server is vulnerable to a denial of service when a specially crafted…

Fix: 11.5.9+
Fix from $1,950 2024-01-22