Vulnerability index

Browse CVEs

6,330 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Sterling Partner Engagement Manager HIGH 7.5
CVE-2023-43045

IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.2 could allow a remote user to perform unauthorized actions due to improper authenticat…

Patch available
Fix from $1,950 2023-10-23
Sterling Partner Engagement Manager MEDIUM 5.4
CVE-2023-38722

IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.2 is vulnerable to stored cross-site scripting. This vulnerability allows users to embe…

Patch available
Fix from $1,600 2023-10-23
Cognos Dashboards On Cloud Pak For Data HIGH 7.5
CVE-2023-38276

IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 exposes sensitive information in environment variables which could aid in further attacks against t…

Patch available
Fix from $1,950 2023-10-22
Cognos Dashboards On Cloud Pak For Data MEDIUM 6.5
CVE-2023-38735

IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 could allow a remote attacker to bypass security restrictions, caused by a reverse tabnabbing flaw.…

Patch available
Fix from $1,600 2023-10-22
Cognos Dashboards On Cloud Pak For Data HIGH 7.5
CVE-2023-38275

IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 exposes sensitive information in container images which could lead to further attacks against the s…

Patch available
Fix from $1,950 2023-10-22
Security Verify Privilege On Premises MEDIUM 5.3
CVE-2022-43891

IBM Security Verify Privilege On-Premises 11.5 could allow a remote attacker to obtain sensitive information when a detailed technical error message …

Fix: 11.5+
Fix from $1,600 2023-10-17
Security Verify Privilege On Premises MEDIUM 5.3
CVE-2022-43892

IBM Security Verify Privilege On-Premises 11.5 does not validate, or incorrectly validates, a certificate which could disclose sensitive information …

Fix: 11.5+
Fix from $1,600 2023-10-17
Security Verify Privilege On Premises HIGH 8.8
CVE-2022-22375

IBM Security Verify Privilege On-Premises 11.5 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a s…

Fix: 11.5+
Fix from $1,950 2023-10-17
Security Verify Privilege On Premises HIGH 7.5
CVE-2022-22385

IBM Security Verify Privilege On-Premises 11.5 could disclose sensitive information to an attacked due to the transmission of data in clear text. IB…

Fix: 11.5+
Fix from $1,950 2023-10-17
Security Verify Privilege On Premises MEDIUM 5.9
CVE-2022-22386

IBM Security Verify Privilege On-Premises 11.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enabl…

Fix: 11.5+
Fix from $1,600 2023-10-17
Security Verify Privilege On Premises MEDIUM 5.3
CVE-2021-38859

IBM Security Verify Privilege On-Premises 11.5 could allow a user to obtain version number information using a specially crafted HTTP request that co…

Fix: 11.5+
Fix from $1,600 2023-10-17
Security Verify Privilege On Premises MEDIUM 5.3
CVE-2022-43889

IBM Security Verify Privilege On-Premises 11.5 could disclose sensitive information through an HTTP request that could aid an attacker in further att…

Fix: 11.5+
Fix from $1,600 2023-10-17
Security Verify Privilege On Premises HIGH 7.1
CVE-2021-29913

IBM Security Verify Privilege On-Premise 11.5 could allow an authenticated user to obtain sensitive information or perform unauthorized actions due t…

Fix: 11.5+
Fix from $1,950 2023-10-17
Security Verify Privilege On Premises MEDIUM 5.3
CVE-2022-22377

IBM Security Verify Privilege On-Premises 11.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enabl…

Fix: 11.5+
Fix from $1,600 2023-10-17
Db2 HIGH 7.5
CVE-2023-40372

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to denial of service with a specially crafted SQL statement usin…

Fix: after 11.5.8
Fix from $1,950 2023-10-17
Db2 HIGH 7.5
CVE-2023-40373

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to denial of service with a specially crafted query containing common…

Fix: after 11.5.8
Fix from $1,950 2023-10-17
Db2 HIGH 7.5
CVE-2023-30991

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to denial of service with a specially crafted query. I…

Fix: after 11.5.8
Fix from $1,950 2023-10-16
Db2 HIGH 7.5
CVE-2023-40374

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to denial of service with a specially crafted query statement. …

Fix: after 11.5.8
Fix from $1,950 2023-10-16
Db2 HIGH 7.5
CVE-2023-38740

IBM Db2 for Linux, UNIX, and Windows (includes Db2 Connect Server) 11.5 is vulnerable to a denial of service with a specially crafted SQL statement. …

Fix: after 11.5.8
Fix from $1,950 2023-10-16
Db2 HIGH 7.5
CVE-2023-38728

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted XM…

Fix: 11.5.8+
Fix from $1,950 2023-10-16
Db2 HIGH 7.5
CVE-2023-30987

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted qu…

Fix: 11.5.8+
Fix from $1,950 2023-10-16
Db2 HIGH 7.5
CVE-2023-38720

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 and 11.5 is vulnerable to denial of service with a specially crafted ALTER TAB…

Fix: 11.5.8+
Fix from $1,950 2023-10-16
Hardware Management Console HIGH 7.8
CVE-2023-38280

IBM HMC (Hardware Management Console) 10.1.1010.0 and 10.2.1030.0 could allow a local user to escalate their privileges to root access on a restricte…

Patch available
Fix from $1,950 2023-10-16
Security Verify Governance CRITICAL 9.8
CVE-2023-33836

IBM Security Verify Governance 10.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authe…

Fix: 10.0.2+
Fix from $2,300 2023-10-16
I HIGH 7.8
CVE-2023-40377

Backup, Recovery, and Media Services (BRMS) for IBM i 7.2, 7.3, and 7.4 contains a local privilege escalation vulnerability. A malicious actor with …

Patch available
Fix from $1,950 2023-10-16
Security Verify Governance HIGH 7.2
CVE-2023-35018

IBM Security Verify Governance 10.0 could allow a privileged use to upload arbitrary files due to improper file validation. IBM X-Force ID: 259382.

Fix: 10.0.2+
Fix from $1,950 2023-10-16
I HIGH 7.8
CVE-2023-40378

IBM Directory Server for IBM i contains a local privilege escalation vulnerability. A malicious actor with command line access to the host operating…

Patch available
Fix from $1,950 2023-10-15
Qradar Security Information And Event Manager HIGH 7.5
CVE-2023-30994

IBM QRadar SIEM 7.5.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X…

Patch available
Fix from $1,950 2023-10-14
Qradar Security Information And Event Manager MEDIUM 5.4
CVE-2023-40367

IBM QRadar SIEM 7.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus al…

Patch available
Fix from $1,600 2023-10-14
Cloud Pak For Business Automation HIGH 7.6
CVE-2023-35024

IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.…

Patch available
Fix from $1,950 2023-10-14