Vulnerability index

Browse CVEs

6,330 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Security Verify Access Oidc Provider HIGH 7.5
CVE-2022-43740

IBM Security Verify Access OIDC Provider could allow a remote user to cause a denial of service due to uncontrolled resource consumption. IBM X-Forc…

Patch available
Fix from $1,950 2023-10-14
App Connect Enterprise MEDIUM 5.5
CVE-2023-45176

IBM App Connect Enterprise 11.0.0.1 through 11.0.0.23, 12.0.1.0 through 12.0.10.0 and IBM Integration Bus 10.1 through 10.1.0.1 are vulnerable to a d…

Fix: after 12.0.10.0
Fix from $1,600 2023-10-14
Security Verify Access Oidc Provider MEDIUM 5.3
CVE-2022-43868

IBM Security Verify Access OIDC Provider could disclose directory information that could aid attackers in further attacks against the system. IBM X-…

Patch available
Fix from $1,600 2023-10-14
Security Directory Server CRITICAL 9.1
CVE-2022-32755

IBM Security Directory Server 6.4.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could …

Patch available
Fix from $2,300 2023-10-14
Security Directory Integrator HIGH 7.5
CVE-2022-33165

IBM Security Directory Server 6.4.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted U…

Patch available
Fix from $1,950 2023-10-14
Security Directory Integrator MEDIUM 5.9
CVE-2022-33161

IBM Security Directory Server 6.4.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Stri…

Patch available
Fix from $1,600 2023-10-14
Security Directory Suite Va HIGH 7.5
CVE-2022-33160

IBM Security Directory Suite 8.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive inform…

Patch available
Fix from $1,950 2023-10-06
Collaborative Lifecycle Management MEDIUM 5.5
CVE-2022-34355

IBM Jazz Foundation (IBM Engineering Lifecycle Management 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2) could disclose sensitive version information to a us…

Mitigation only
Fix from $1,600 2023-10-06
Robotic Process Automation CRITICAL 9.8
CVE-2023-43058

IBM Robotic Process Automation 23.0.9 is vulnerable to privilege escalation that affects ownership of projects. IBM X-Force ID: 247527.

Patch available
Fix from $2,300 2023-10-06
Storage Protect HIGH 7.8
CVE-2023-35897

IBM Spectrum Protect Client and IBM Storage Protect for Virtual Environments 8.1.0.0 through 8.1.19.0 could allow a local user to execute arbitrary c…

Fix: after 8.1.19.0
Fix from $1,950 2023-10-06
Urbancode Deploy MEDIUM 6.5
CVE-2023-40376

IBM UrbanCode Deploy (UCD) 7.1 - 7.1.2.12, 7.2 through 7.2.3.5, and 7.3 through 7.3.2.0 under certain configurations could allow an authenticated use…

Fix: after 7.3.2.0
Fix from $1,600 2023-10-04
Content Navigator MEDIUM 5.4
CVE-2023-40684

IBM Content Navigator 3.0.11, 3.0.13, and 3.0.14 with IBM Daeja ViewOne Virtual is vulnerable to cross-site scripting. This vulnerability allows user…

Mitigation only
Fix from $1,600 2023-10-04
Security Guardium MEDIUM 5.3
CVE-2022-43906

IBM Security Guardium 11.5 could disclose sensitive information due to a missing or insecure SameSite attribute for a sensitive cookie. IBM X-Force …

Patch available
Fix from $1,600 2023-10-04
Observability With Instana CRITICAL 9.8
CVE-2023-37404

IBM Observability with Instana 1.0.243 through 1.0.254 could allow an attacker on the network to execute arbitrary code on the host after a successfu…

Fix: 1.0.255+
Fix from $2,300 2023-10-04
Filenet Content Manager MEDIUM 5.4
CVE-2023-35905

IBM FileNet Content Manager 5.5.8, 5.5.10, and 5.5.11 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaS…

Patch available
Fix from $1,600 2023-10-04
Disconnected Log Collector HIGH 7.5
CVE-2022-22447

IBM Disconnected Log Collector 1.0 through 1.8.2 is vulnerable to potential security misconfigurations that could disclose unintended information. I…

Fix: 1.8.3+
Fix from $1,950 2023-10-04
I HIGH 7.8
CVE-2023-40375

Integrated application server for IBM i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability. A malicious actor with command l…

Patch available
Fix from $1,950 2023-09-28
License Metric Tool HIGH 7.5
CVE-2023-43044

IBM License Metric Tool 9.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL reque…

Fix: 9.2.33+
Fix from $1,950 2023-09-28
Person Communications HIGH 7.8
CVE-2023-37410

IBM Personal Communications 14.05, 14.06, and 15.0.0 could allow a local user to escalate their privileges to the SYSTEM user due to overly permissiv…

Patch available
Fix from $1,950 2023-09-20
Robotic Process Automation MEDIUM 5.3
CVE-2023-38718

IBM Robotic Process Automation 21.0.0 through 21.0.7.8 could disclose sensitive information from access to RPA scripts, workflows and related data. …

Fix: after 23.0.8
Fix from $1,600 2023-09-20
Aspera Faspex HIGH 7.5
CVE-2022-22401

IBM Aspera Faspex 5.0.5 could allow a remote attacker to gather or persuade a naive user to supply sensitive information. IBM X-Force ID: 222567.

Fix: after 5.0.5
Fix from $1,950 2023-09-08
Aspera Faspex MEDIUM 5.4
CVE-2022-22402

IBM Aspera Faspex 5.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus …

Fix: after 5.0.5
Fix from $1,600 2023-09-08
Aspera Faspex MEDIUM 5.3
CVE-2022-22409

IBM Aspera Faspex 5.0.5 could allow a remote attacker to gather sensitive information about the web application, caused by an insecure configuration.…

Fix: after 5.0.5
Fix from $1,600 2023-09-08
Aspera Faspex HIGH 7.5
CVE-2023-30995

IBM Aspera Faspex 4.0 through 4.4.2 and 5.0 through 5.0.5 could allow a malicious actor to bypass IP whitelist restrictions using a specially crafted…

Fix: after 5.0.5
Fix from $1,950 2023-09-08
Aspera Faspex MEDIUM 5.9
CVE-2022-22405

IBM Aspera Faspex 5.0.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport…

Fix: after 5.0.5
Fix from $1,600 2023-09-08
Aspera Faspex MEDIUM 5.3
CVE-2023-24965

IBM Aspera Faspex 5.0.5 does not restrict or incorrectly restricts access to a resource from an unauthorized actor. IBM X-Force ID: 246713.

Fix: after 5.0.5
Fix from $1,600 2023-09-08
Security Directory Server CRITICAL 9.1
CVE-2022-33164

IBM Security Directory Server 7.2.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted U…

Patch available
Fix from $2,300 2023-09-08
Maximo Application Suite MEDIUM 5.4
CVE-2023-32332

IBM Maximo Application Suite 8.9, 8.10 and IBM Maximo Asset Management 7.6.1.2, 7.6.1.3 are vulnerable to HTML injection. A remote attacker could inj…

Mitigation only
Fix from $1,600 2023-09-08
Qradar Wincollect HIGH 7.8
CVE-2023-38736

IBM QRadar WinCollect Agent 10.0 through 10.1.6, when installed to run as ADMIN or SYSTEM, is vulnerable to a local escalation of privilege attack th…

Fix: 10.1.7+
Fix from $1,950 2023-09-08
Aspera Faspex HIGH 7.5
CVE-2023-35906

IBM Aspera Faspex 5.0.5 could allow a remote attacked to bypass IP restrictions due to improper access controls. IBM X-Force ID: 259649.

Fix: after 5.0.5
Fix from $1,950 2023-09-05