Vulnerability index

Browse CVEs

6,330 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Db2 MEDIUM 6.5
CVE-2023-47746

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow an authenticated user with CONNECT privileges to c…

Fix: after 11.5.9
Fix from $1,600 2024-01-22
Maximo Application Suite HIGH 8.8
CVE-2023-47718

IBM Maximo Asset Management 7.6.1.3 and Manage Component 8.10 through 8.11 is vulnerable to cross-site request forgery which could allow an attacker …

Fix: 8.10.6+
Fix from $1,950 2024-01-19
Maximo Application Suite MEDIUM 5.4
CVE-2023-32337

IBM Maximo Spatial Asset Management 8.10 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauth…

Fix: 8.10.6+
Fix from $1,600 2024-01-19
Storage Defender Data Protect MEDIUM 5.4
CVE-2023-50963

IBM Storage Defender - Data Protect 1.0.0 through 1.4.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST he…

Fix: after 1.4.1
Fix from $1,600 2024-01-19
Openpages With Watson HIGH 8.8
CVE-2023-40683

IBM OpenPages with Watson 8.3 and 9.0 could allow remote attacker to bypass security restrictions, caused by insufficient authorization checks. By au…

Fix: 8.3.0.2.7+
Fix from $1,950 2024-01-19
Openpages With Watson HIGH 8.1
CVE-2023-38738

IBM OpenPages with Watson 8.3 and 9.0 could provide weaker than expected security in a OpenPages environment using Native authentication. If OpenPage…

Fix: 8.3.0.2.7+
Fix from $1,950 2024-01-19
Sterling Control Center MEDIUM 5.3
CVE-2023-35020

IBM Sterling Control Center 6.3.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL…

Patch available
Fix from $1,600 2024-01-19
App Connect Enterprise CRITICAL 9.1
CVE-2024-22317

IBM App Connect Enterprise 11.0.0.1 through 11.0.0.24 and 12.0.1.0 through 12.0.11.0 could allow a remote attacker to obtain sensitive information or…

Fix: after 12.0.11.0
Fix from $2,300 2024-01-18
Qradar Security Information And Event Manager MEDIUM 5.3
CVE-2023-50950

IBM QRadar SIEM 7.5 could disclose sensitive email information in responses from offense rules. IBM X-Force ID: 275709.

Patch available
Fix from $1,600 2024-01-17
Vios MEDIUM 5.5
CVE-2023-45171

IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the kernel to cause a denial of service. IBM X-…

Mitigation only
Fix from $1,600 2024-01-11
Security Verify Access HIGH 7.8
CVE-2023-31003

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.6.1)…

Fix: 10.0.0.7+
Fix from $1,950 2024-01-11
Security Verify Access MEDIUM 5.5
CVE-2023-31001

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.6.1)…

Fix: 10.0.0.7+
Fix from $1,600 2024-01-11
Security Verify Access MEDIUM 5.5
CVE-2023-38267

IBM Security Access Manager Appliance (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.6.1)…

Fix: 10.0.0.7+
Fix from $1,600 2024-01-11
Vios MEDIUM 5.5
CVE-2023-45169

IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the pmsvcs kernel extension to cause a denial of…

Mitigation only
Fix from $1,600 2024-01-11
Vios MEDIUM 5.5
CVE-2023-45175

IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the TCP/IP kernel extension to cause a denial of…

Mitigation only
Fix from $1,600 2024-01-11
Vios MEDIUM 5.5
CVE-2023-45173

IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the NFS kernel extension to cause a denial of se…

Mitigation only
Fix from $1,600 2024-01-11
Cics Transaction Gateway HIGH 8.1
CVE-2023-47140

IBM CICS Transaction Gateway 9.3 could allow a user to transfer or view files due to improper access controls.

Mitigation only
Fix from $1,950 2024-01-08
Storage Fusion Hci CRITICAL 9.8
CVE-2023-50948

IBM Storage Fusion HCI 2.1.0 through 2.6.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inboun…

Fix: 2.7.1+
Fix from $2,300 2024-01-08
Db2 HIGH 7.8
CVE-2023-47145

IBM Db2 for Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow a local user to escalate their privileges to the SYSTEM user using…

Fix: 10.5.0.11 / 11.1.4.7+
Fix from $1,950 2024-01-07
I HIGH 7.8
CVE-2023-43064

Facsimile Support for IBM i 7.2, 7.3, 7.4, and 7.5 could allow a local user to gain elevated privileges due to an unqualified library call. A malici…

Patch available
Fix from $1,950 2023-12-25
Financial Transaction Manager HIGH 7.5
CVE-2023-49880

In the Message Entry and Repair (MER) facility of IBM Financial Transaction Manager for SWIFT Services 3.2.4 the sending address and the message type…

Mitigation only
Fix from $1,950 2023-12-25
Aspera Console MEDIUM 6.1
CVE-2021-38927

IBM Aspera Console 3.4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus…

Fix: 3.4.2+
Fix from $1,600 2023-12-25
Aix MEDIUM 5.5
CVE-2023-45165

IBM AIX 7.2 and 7.3 could allow a non-privileged local user to exploit a vulnerability in the AIX SMB client to cause a denial of service. IBM X-For…

Mitigation only
Fix from $1,600 2023-12-22
Planning Analytics CRITICAL 9.8
CVE-2023-42017

IBM Planning Analytics Local 2.0 could allow a remote attacker to upload arbitrary files, caused by the improper validation of file extensions. By s…

Mitigation only
Fix from $2,300 2023-12-22
Informix Jdbc CRITICAL 9.8
CVE-2023-35895

IBM Informix JDBC Driver 4.10 and 4.50 is susceptible to remote code execution attack via JNDI injection when passing an unchecked argument to a cert…

Mitigation only
Fix from $2,300 2023-12-20
Security Guardium Key Lifecycle Manager MEDIUM 5.4
CVE-2023-47707

IBM Security Guardium Key Lifecycle Manager 4.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript …

Fix: after 4.2.0.2
Fix from $1,600 2023-12-20
Security Guardium Key Lifecycle Manager MEDIUM 5.3
CVE-2023-47703

IBM Security Guardium Key Lifecycle Manager 4.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message…

Fix: 4.2.0.2+
Fix from $1,600 2023-12-20
Security Guardium Key Lifecycle Manager CRITICAL 9.1
CVE-2023-47702

IBM Security Guardium Key Lifecycle Manager 4.3 could allow a remote attacker to traverse directories on the system. An attacker could send a special…

Fix: 4.2.0.2+
Fix from $2,300 2023-12-20
Security Guardium Key Lifecycle Manager HIGH 8.8
CVE-2023-47706

IBM Security Guardium Key Lifecycle Manager 4.3 could allow an authenticated user to upload files of a dangerous file type. IBM X-Force ID: 271341.

Fix: 4.2.0.2+
Fix from $1,950 2023-12-20
Security Guardium Key Lifecycle Manager HIGH 7.5
CVE-2023-47704

IBM Security Guardium Key Lifecycle Manager 4.3 contains plain text hard-coded credentials or other secrets in source code repository. IBM X-Force I…

Fix: 4.2.0.2+
Fix from $1,950 2023-12-20