Vulnerability index

Browse CVEs

6,330 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Infosphere Information Server MEDIUM 5.3
CVE-2023-43021

IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is retur…

Fix: 11.7.1.0 / 11.7.1.4+
Fix from $1,600 2023-12-01
Infosphere Information Server HIGH 7.5
CVE-2023-40699

IBM InfoSphere Information Server 11.7 could allow a remote attacker to cause a denial of service due to improper input validation. IBM X-Force ID: …

Fix: 11.7.1.0 / 11.7.1.4+
Fix from $1,950 2023-12-01
Infosphere Information Server MEDIUM 5.4
CVE-2023-42009

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…

Fix: 11.7.1.0 / 11.7.1.4+
Fix from $1,600 2023-12-01
Infosphere Information Server HIGH 8.8
CVE-2023-38268

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorize…

Fix: 11.7.1.0 / 11.7.1.4+
Fix from $1,950 2023-12-01
Infosphere Information Server MEDIUM 5.4
CVE-2023-43015

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…

Fix: 11.7.1.0 / 11.7.1.4+
Fix from $1,600 2023-12-01
Planning Analytics On Cloud Pak For Data MEDIUM 6.5
CVE-2023-26024

IBM Planning Analytics on Cloud Pak for Data 4.0 could allow an attacker on a shared network to obtain sensitive information caused by insecure netwo…

Mitigation only
Fix from $1,600 2023-12-01
I MEDIUM 5.5
CVE-2023-42006

IBM Administration Runtime Expert for i 7.2, 7.3, 7.4, and 7.5 could allow a local user to obtain sensitive information caused by improper authority …

Mitigation only
Fix from $1,600 2023-12-01
Vios HIGH 7.8
CVE-2023-45168

IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the invscout command to execute arbitrary comman…

Mitigation only
Fix from $1,950 2023-12-01
Security Guardium HIGH 8.8
CVE-2023-42004

IBM Security Guardium 11.3, 11.4, and 11.5 is potentially vulnerable to CSV injection. A remote attacker could execute malicious commands due to imp…

Mitigation only
Fix from $1,950 2023-11-28
Qradar Wincollect HIGH 7.8
CVE-2023-26279

IBM QRadar WinCollect Agent 10.0 through 10.1.7 could allow a local user to perform unauthorized actions due to improper encoding. IBM X-Force ID: …

Fix: after 10.1.7
Fix from $1,950 2023-11-24
Sterling B2b Integrator MEDIUM 5.5
CVE-2023-25682

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.1 stores potentially sensitive information in log file…

Fix: 6.0.3.9 / 6.1.2.3+
Fix from $1,600 2023-11-22
Cloud Pak For Security MEDIUM 6.5
CVE-2022-36777

IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.16.0could allow an authenticated us…

Fix: 1.10.17.0+
Fix from $1,600 2023-11-22
Sterling B2b Integrator HIGH 8.8
CVE-2022-35638

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.1 is vulnerable to cross-site request forgery which co…

Fix: 6.0.3.9 / 6.1.2.3+
Fix from $1,950 2023-11-22
Infosphere Information Server MEDIUM 6.5
CVE-2023-40363

IBM InfoSphere Information Server 11.7 could allow an authenticated user to change installation files due to incorrect file permission settings. IBM…

Mitigation only
Fix from $1,600 2023-11-18
Cics Tx HIGH 7.5
CVE-2023-38361

IBM CICS TX Advanced 10.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. I…

Patch available
Fix from $1,950 2023-11-18
Cics Tx MEDIUM 6.1
CVE-2023-38364

IBM CICS TX Advanced 10.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thu…

Patch available
Fix from $1,600 2023-11-13
Qradar Security Information And Event Manager MEDIUM 5.4
CVE-2023-43057

IBM QRadar SIEM 7.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus al…

Mitigation only
Fix from $1,600 2023-11-11
Vios MEDIUM 5.5
CVE-2023-45167

IBM AIX's 7.3 Python implementation could allow a non-privileged local user to exploit a vulnerability to cause a denial of service. IBM X-Force ID:…

No fix yet
Fix from $1,600 2023-11-10
Robotic Process Automation For Cloud Pak MEDIUM 6.5
CVE-2023-45189

A vulnerability in IBM Robotic Process Automation and IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.10, 23.0.0 through 23.0.10 m…

Fix: after 23.0.10
Fix from $1,600 2023-11-03
Content Navigator MEDIUM 5.4
CVE-2023-35896

IBM Content Navigator 3.0.13 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized reque…

Patch available
Fix from $1,600 2023-11-03
Mq Appliance HIGH 7.8
CVE-2023-46176

IBM MQ Appliance 9.3 CD could allow a local attacker to gain elevated privileges on the system, caused by improper validation of security keys. IBM …

Patch available
Fix from $1,950 2023-11-03
Txseries For Multiplatforms HIGH 8.8
CVE-2023-42027

IBM CICS TX Standard 11.1, Advanced 10.1, 11.1, and TXSeries for Multiplatforms 8.1, 8.2, 9.1 are vulnerable to cross-site request forgery which coul…

Patch available
Fix from $1,950 2023-11-03
Cics Tx HIGH 7.5
CVE-2023-43018

IBM CICS TX Standard 11.1 and Advanced 10.1, 11.1 performs an operation at a privilege level that is higher than the minimum level required, which cr…

Patch available
Fix from $1,950 2023-11-03
Txseries For Multiplatforms MEDIUM 5.4
CVE-2023-42029

IBM CICS TX Standard 11.1, Advanced 10.1, 11.1, and TXSeries for Multiplatforms 8.1, 8.2, 9.1 are vulnerable to cross-site scripting. This vulnerabil…

Patch available
Fix from $1,600 2023-11-03
I HIGH 7.8
CVE-2023-40685

Management Central as part of IBM i 7.2, 7.3, 7.4, and 7.5 Navigator contains a local privilege escalation vulnerability. A malicious actor with com…

Patch available
Fix from $1,950 2023-10-29
I HIGH 7.8
CVE-2023-40686

Management Central as part of IBM i 7.2, 7.3, 7.4, and 7.5 Navigator contains a local privilege escalation vulnerability. A malicious actor with com…

Patch available
Fix from $1,950 2023-10-29
Websphere Application Server Liberty CRITICAL 9.8
CVE-2023-46158

IBM WebSphere Application Server Liberty 23.0.0.9 through 23.0.0.10 could provide weaker than expected security due to improper resource expiration h…

Fix: 23.0.0.11+
Fix from $2,300 2023-10-25
Security Verify Governance CRITICAL 9.8
CVE-2022-22466

IBM Security Verify Governance 10.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authe…

Fix: 10.0.2+
Fix from $2,300 2023-10-23
Security Verify Governance HIGH 8.8
CVE-2023-33839

IBM Security Verify Governance 10.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially cr…

Patch available
Fix from $1,950 2023-10-23
Security Verify Governance HIGH 7.5
CVE-2023-33837

IBM Security Verify Governance 10.0 does not encrypt sensitive or critical information before storage or transmission. IBM X-Force ID: 256020.

Patch available
Fix from $1,950 2023-10-23