Vulnerability index

Browse CVEs

6,330 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Aspera Faspex MEDIUM 5.9
CVE-2023-22870

IBM Aspera Faspex 5.0.5 transmits sensitive information in cleartext which could be obtained by an attacker using man in the middle techniques. IBM …

Fix: after 5.0.5
Fix from $1,600 2023-09-05
Sterling External Authentication Server MEDIUM 5.5
CVE-2023-29261

IBM Sterling Secure Proxy 6.0.3 and 6.1.0 could allow a local user with specific information about the system to obtain privileged information due to…

Mitigation only
Fix from $1,600 2023-09-05
Financial Transaction Manager CRITICAL 9.1
CVE-2023-35892

IBM Financial Transaction Manager for SWIFT Services 3.2.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A…

Mitigation only
Fix from $2,300 2023-09-05
Security Guardium MEDIUM 6.5
CVE-2022-43903

IBM Security Guardium 10.6, 11.3, and 11.4 could allow an authenticated user to cause a denial of service due to due to improper input validation. I…

Patch available
Fix from $1,600 2023-09-05
Sterling External Authentication Server MEDIUM 5.5
CVE-2023-32338

IBM Sterling Secure Proxy and IBM Sterling External Authentication Server 6.0.3 and 6.1.0 stores user credentials in plain clear text which can be re…

Mitigation only
Fix from $1,600 2023-09-05
Security Verify Information Queue HIGH 7.5
CVE-2023-33835

IBM Security Verify Information Queue 10.0.4 and 10.0.5 could allow a remote attacker to obtain sensitive information that could aid in further attac…

Patch available
Fix from $1,950 2023-08-31
Security Verify Information Queue MEDIUM 5.3
CVE-2023-33834

IBM Security Verify Information Queue 10.0.4 and 10.0.5 could allow a remote attacker to obtain sensitive information that could aid in further attac…

Patch available
Fix from $1,600 2023-08-31
Guardium Cloud Key Manager CRITICAL 9.8
CVE-2023-26270

IBM Security Guardium Data Encryption (IBM Guardium Cloud Key Manager (GCKM) 1.10.3)) could allow a remote attacker to execute arbitrary code on the …

Fix: after 1.10.3
Fix from $2,300 2023-08-28
Guardium Cloud Key Manager HIGH 7.5
CVE-2023-26271

IBM Security Guardium Data Encryption (IBM Guardium Cloud Key Manager (GCKM) 1.10.3)) uses an inadequate account lockout setting that could allow a r…

Fix: after 1.10.3
Fix from $1,950 2023-08-28
Guardium Cloud Key Manager MEDIUM 5.3
CVE-2023-26272

IBM Security Guardium Data Encryption (IBM Guardium Cloud Key Manager (GCKM) 1.10.3)) could allow a remote attacker to obtain sensitive information w…

Fix: after 1.10.3
Fix from $1,600 2023-08-28
Infosphere Information Server HIGH 8.8
CVE-2023-23473

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorize…

Fix: 11.7.1.0 / 11.7.1.4+
Fix from $1,950 2023-08-28
Infosphere Information Server HIGH 7.5
CVE-2023-24959

IBM InfoSphere Information Systems 11.7 could expose information about the host system and environment configuration. IBM X-Force ID: 246332.

Fix: 11.7.1.0 / 11.7.1.4+
Fix from $1,950 2023-08-28
Infosphere Information Server HIGH 8.8
CVE-2023-22877

IBM InfoSphere Information Server 11.7 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, …

Fix: 11.7.1.0 / 11.7.1.4+
Fix from $1,950 2023-08-28
Security Guardium HIGH 7.5
CVE-2022-43904

IBM Security Guardium 11.3 and 11.4 could disclose sensitive information to an attacker due to improper restriction of excessive authentication attem…

Patch available
Fix from $1,950 2023-08-28
Storage Copy Data Management HIGH 7.5
CVE-2023-38730

IBM Storage Copy Data Management 2.2.0.0 through 2.2.19.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt …

Fix: after 2.2.19.0
Fix from $1,950 2023-08-27
Security Guardium MEDIUM 5.4
CVE-2023-33852

IBM Security Guardium 11.4 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attac…

Patch available
Fix from $1,600 2023-08-27
Security Guardium MEDIUM 5.3
CVE-2023-30437

IBM Security Guardium 11.3, 11.4, and 11.5 could allow an unauthorized user to enumerate usernames by sending a specially crafted HTTP request. IBM …

Patch available
Fix from $1,600 2023-08-27
Security Guardium MEDIUM 5.4
CVE-2022-43909

IBM Security Guardium 11.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI th…

Patch available
Fix from $1,600 2023-08-27
Security Guardium MEDIUM 5.4
CVE-2023-30435

IBM Security Guardium 11.3, 11.4, and 11.5 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScrip…

Patch available
Fix from $1,600 2023-08-27
Security Guardium MEDIUM 5.4
CVE-2023-30436

IBM Security Guardium 11.3, 11.4, and 11.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code …

Patch available
Fix from $1,600 2023-08-27
Security Guardium HIGH 8.8
CVE-2022-43907

IBM Security Guardium 11.4 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted req…

Patch available
Fix from $1,950 2023-08-27
Vios MEDIUM 5.5
CVE-2023-40371

IBM AIX 7.2, 7.3, VIOS 3.1's OpenSSH implementation could allow a non-privileged local user to access files outside of those allowed due to improper …

Mitigation only
Fix from $1,600 2023-08-24
Robotic Process Automation CRITICAL 9.8
CVE-2023-38734

IBM Robotic Process Automation 21.0.0 through 21.0.7.1 and 23.0.0 through 23.0.1 is vulnerable to incorrect privilege assignment when importing users…

Fix: after 21.0.7.1
Fix from $2,300 2023-08-22
Robotic Process Automation MEDIUM 5.3
CVE-2023-40370

IBM Robotic Process Automation 21.0.0 through 21.0.7.1 runtime is vulnerable to information disclosure of script content if the remote REST request c…

Fix: after 21.0.7.1
Fix from $1,600 2023-08-22
Txseries For Multiplatform HIGH 7.5
CVE-2023-33850

IBM GSKit-Crypto could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in the RSA Decryption implement…

Mitigation only
Fix from $1,950 2023-08-22
Cognos Analytics MEDIUM 5.4
CVE-2023-35011

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send…

Fix: 11.1.7 / 11.2.4+
Fix from $1,600 2023-08-16
Cognos Analytics MEDIUM 5.3
CVE-2023-35009

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a remote attacker to obtain system information without authentication which could be used…

Fix: 11.1.7 / 11.2.4+
Fix from $1,600 2023-08-16
Security Guardium HIGH 8.8
CVE-2023-35893

IBM Security Guardium 10.6, 11.3, 11.4, and 11.5 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a…

Patch available
Fix from $1,950 2023-08-16
Websphere Application Server HIGH 7.5
CVE-2023-38737

IBM WebSphere Application Server Liberty 22.0.0.13 through 23.0.0.7 is vulnerable to a denial of service, caused by sending a specially-crafted reque…

Fix: after 23.0.0.7
Fix from $1,950 2023-08-16
I HIGH 7.8
CVE-2023-38721

The IBM i 7.2, 7.3, 7.4, and 7.5 product Facsimile Support for i contains a local privilege escalation vulnerability. A malicious actor could gain …

Patch available
Fix from $1,950 2023-08-14