Vulnerability index

Browse CVEs

6,330 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Urbancode Deploy MEDIUM 6.5
CVE-2023-47161

IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.14, 7.2 through 7.2.3.7, and 7.3 through 7.3.2.2 may mishandle input validation of an uploaded archive f…

Fix: after 7.3.2.2
Fix from $1,600 2023-12-20
Urbancode Deploy MEDIUM 5.5
CVE-2023-42012

An IBM UrbanCode Deploy Agent 7.2 through 7.2.3.7, and 7.3 through 7.3.2.2 installed as a Windows service in a non-standard location could be subject…

Fix: after 7.3.2.2
Fix from $1,600 2023-12-20
Urbancode Deploy MEDIUM 5.3
CVE-2023-42013

IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.14, 7.2 through 7.2.3.7, and 7.3 through 7.3.2.2 could allow a remote attacker to obtain sensitive infor…

Fix: after 7.3.2.2
Fix from $1,600 2023-12-20
Vios MEDIUM 5.5
CVE-2023-45172

IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in AIX windows to cause a denial of service. IBM X…

Patch available
Fix from $1,600 2023-12-19
Qradar Security Information And Event Manager MEDIUM 6.5
CVE-2023-47146

IBM Qradar SIEM 7.5 could allow a privileged user to obtain sensitive domain information due to data being misidentified. IBM X-Force ID: 270372.

Patch available
Fix from $1,600 2023-12-19
Db2 Mirror For I MEDIUM 5.3
CVE-2023-47741

IBM i 7.3, 7.4, 7.5, IBM i Db2 Mirror for i 7.4 and 7.5 web browser clients may leave clear-text passwords in browser memory that can be viewed using…

Patch available
Fix from $1,600 2023-12-18
Mq Appliance HIGH 7.5
CVE-2023-46177

IBM MQ Appliance 9.3 LTS and 9.3 CD could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted …

Patch available
Fix from $1,950 2023-12-18
I Access Client Solutions HIGH 8.8
CVE-2023-45185

IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 could allow an attacker to execute remote code. Due to improper author…

Fix: 1.1.9.4+
Fix from $1,950 2023-12-14
I Access Client Solutions MEDIUM 6.5
CVE-2023-45182

IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 is vulnerable to having its key for an encrypted password decoded. By s…

Fix: 1.1.9.4+
Fix from $1,600 2023-12-14
I Access Client Solutions HIGH 7.5
CVE-2023-45184

IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 could allow an attacker to obtain a decryption key due to improper auth…

Fix: 1.1.9.4+
Fix from $1,950 2023-12-14
Spectrum Scale HIGH 7.5
CVE-2022-43843

IBM Spectrum Scale 5.1.5.0 through 5.1.5.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitiv…

Mitigation only
Fix from $1,950 2023-12-14
Storage Virtualize HIGH 7.5
CVE-2023-43042

IBM SAN Volume Controller, IBM Storwize, IBM FlashSystem and IBM Storage Virtualize 8.3 products use default passwords for a privileged user. IBM X-…

Mitigation only
Fix from $1,950 2023-12-14
Vios HIGH 7.8
CVE-2023-45170

IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the piobe command to escalate privileges or caus…

Mitigation only
Fix from $1,950 2023-12-13
Vios HIGH 7.8
CVE-2023-45174

IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a privileged local user to exploit a vulnerability in the qdaemon command to escalate privileges or cause …

Mitigation only
Fix from $1,950 2023-12-13
Vios HIGH 7.8
CVE-2023-45166

IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the piodmgrsu command to obtain elevated privile…

Mitigation only
Fix from $1,950 2023-12-13
Informix Dynamic Server MEDIUM 5.5
CVE-2023-28526

IBM Informix Dynamic Server 12.10 and 14.10 archecker is vulnerable to a heap buffer overflow, caused by improper bounds checking which could allow a…

Mitigation only
Fix from $1,600 2023-12-09
Informix Dynamic Server MEDIUM 5.5
CVE-2023-28527

IBM Informix Dynamic Server 12.10 and 14.10 cdr is vulnerable to a heap buffer overflow, caused by improper bounds checking which could allow a local…

Mitigation only
Fix from $1,600 2023-12-09
Api Connect MEDIUM 5.5
CVE-2023-47722

IBM API Connect V10.0.5.3 and V10.0.6.0 stores user credentials in browser cache which can be read by a local user. IBM X-Force ID: 271912.

Mitigation only
Fix from $1,600 2023-12-09
Informix Dynamic Server HIGH 7.8
CVE-2023-28523

IBM Informix Dynamic Server 12.10 and 14.10 onsmsync is vulnerable to a heap buffer overflow, caused by improper bounds checking which could allow an…

Mitigation only
Fix from $1,950 2023-12-09
Db2 HIGH 7.5
CVE-2023-40687

IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted RU…

Fix: after 11.5.9
Fix from $1,950 2023-12-04
Db2 HIGH 7.5
CVE-2023-29258

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1, and 11.5 is vulnerable to a denial of service through a specially crafted fed…

Fix: after 11.5.9
Fix from $1,950 2023-12-04
Db2 HIGH 7.5
CVE-2023-38727

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted SQ…

Fix: after 11.5.9
Fix from $1,950 2023-12-04
Db2 HIGH 7.5
CVE-2023-46167

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 federated server is vulnerable to a denial of service when a specially crafted…

Fix: after 11.5.8
Fix from $1,950 2023-12-04
Db2 HIGH 7.5
CVE-2023-47701

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted qu…

Fix: after 11.5.9
Fix from $1,950 2023-12-04
Db2 HIGH 7.2
CVE-2023-38003

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow a user with DATAACCESS privileges to execute routi…

Patch available
Fix from $1,950 2023-12-04
Db2 HIGH 7.5
CVE-2023-40692

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, 11.5 is vulnerable to denial of service under extreme stress conditions…

Patch available
Fix from $1,950 2023-12-04
Db2 HIGH 7.5
CVE-2023-45178

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5 CLI is vulnerable to a denial of service when a specially crafted request is u…

Patch available
Fix from $1,950 2023-12-03
Infosphere Information Server MEDIUM 5.9
CVE-2023-42019

IBM InfoSphere Information Server 11.7 could allow a remote attacker to cause a denial of service due to improper input validation. IBM X-Force ID: …

Fix: 11.7.1.0 / 11.7.1.4+
Fix from $1,600 2023-12-01
Infosphere Information Server MEDIUM 5.4
CVE-2023-42022

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…

Fix: 11.7.1.0 / 11.7.1.4+
Fix from $1,600 2023-12-01
Infosphere Information Server MEDIUM 5.4
CVE-2023-46174

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…

Fix: 11.7.1.0 / 11.7.1.4+
Fix from $1,600 2023-12-01