Vulnerability index

Browse CVEs

6,330 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Txseries For Multiplatform HIGH 7.5
CVE-2023-38741

IBM TXSeries for Multiplatforms 8.1, 8.2, and 9.1 is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual r…

Mitigation only
Fix from $1,950 2023-08-14
Robotic Process Automation MEDIUM 6.5
CVE-2023-23476

IBM Robotic Process Automation 21.0.0 through 21.0.7.latest is vulnerable to unauthorized access to data due to insufficient authorization validation…

Fix: 23.0.0+
Fix from $1,600 2023-08-02
Sdk CRITICAL 9.8
CVE-2022-40609

IBM SDK, Java Technology Edition 7.1.5.18 and 8.0.8.0 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe dese…

Fix: 7.1.5.19 / 8.0.8.5+
Fix from $2,300 2023-08-02
B2b Advanced Communications MEDIUM 6.5
CVE-2023-24971

IBM B2B Advanced Communications 1.0.0.0 and IBM Multi-Enterprise Integration Gateway 1.0.0.1 could allow a user to cause a denial of service due to t…

Fix: 1.0.0.8+
Fix from $1,600 2023-07-31
B2b Advanced Communications MEDIUM 5.4
CVE-2023-22595

IBM B2B Advanced Communications 1.0.0.0 and IBM Multi-Enterprise Integration Gateway 1.0.0.1 are vulnerable to cross-site scripting. This vulnerabili…

Fix: 1.0.0.8+
Fix from $1,600 2023-07-31
Tririga Application Platform MEDIUM 5.3
CVE-2020-4868

IBM TRIRIGA 3.0, 4.0, and 4.4 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in th…

Fix: 4.5+
Fix from $1,600 2023-07-31
Security Verify Governance HIGH 8.8
CVE-2023-35019

IBM Security Verify Governance, Identity Manager 10.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by send…

Mitigation only
Fix from $1,950 2023-07-31
Spectrum Scale Container Native Storage Access HIGH 7.8
CVE-2022-43831

IBM Storage Scale Container Native Storage Access 5.1.2.1 through 5.1.6.1 could allow a local user to obtain escalated privileges on a host without p…

Fix: after 5.1.6.1
Fix from $1,950 2023-07-31
Security Verify Governance MEDIUM 6.5
CVE-2023-35016

IBM Security Verify Governance, Identity Manager 10.0 could allow a remote attacker to traverse directories on the system. An attacker could send a s…

Mitigation only
Fix from $1,600 2023-07-31
Cognos Analytics MEDIUM 5.4
CVE-2023-25929

IBM Cognos Analytics 11.1 and 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the W…

Fix: 11.1.7 / 11.2.4+
Fix from $1,600 2023-07-22
Cognos Analytics MEDIUM 5.4
CVE-2023-28530

IBM Cognos Analytics 11.1 and 11.2 is vulnerable to stored cross-site scripting, caused by improper validation of SVG Files in Custom Visualizations.…

Fix: 11.1.7 / 11.2.4+
Fix from $1,600 2023-07-22
Security Guardium HIGH 7.8
CVE-2022-43910

IBM Security Guardium 11.3 could allow a local user to escalate their privileges due to improper permission controls. IBM X-Force ID: 240908.

Patch available
Fix from $1,950 2023-07-19
Sterling Connect\ HIGH 7.5
CVE-2021-38933

IBM Sterling Connect:Direct for UNIX 1.5 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive …

Fix: 1.5.0.1609+
Fix from $1,950 2023-07-19
Cloud Pak For Data HIGH 7.5
CVE-2023-26023

Planning Analytics Cartridge for Cloud Pak for Data 4.0 exposes sensitive information in logs which could lead an attacker to exploit this vulnerabil…

Patch available
Fix from $1,950 2023-07-19
Cloud Pak For Data HIGH 7.5
CVE-2023-26026

Planning Analytics Cartridge for Cloud Pak for Data 4.0 exposes sensitive information in logs which could lead an attacker to exploit this vulnerabil…

Patch available
Fix from $1,950 2023-07-19
Cloud Pak For Data HIGH 7.5
CVE-2023-27877

IBM Planning Analytics Cartridge for Cloud Pak for Data 4.0 connects to a CouchDB server. An attacker can exploit an insecure password policy to the …

Patch available
Fix from $1,950 2023-07-19
Mq HIGH 7.5
CVE-2023-28513

IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.2 CD, and 9.3 CD and IBM MQ Appliance 9.2 LTS, 9.3 LTS, 9.2 CD, and 9.2 LTS, under certain configuration…

Patch available
Fix from $1,950 2023-07-19
Security Guardium MEDIUM 6.5
CVE-2022-43908

IBM Security Guardium 11.3 could allow an authenticated user to cause a denial of service due to improper input validation. IBM X-Force ID: 240903.

Patch available
Fix from $1,600 2023-07-19
Sterling Connect\ MEDIUM 5.4
CVE-2023-29260

IBM Sterling Connect:Express for UNIX 1.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unaut…

Patch available
Fix from $1,600 2023-07-19
Sterling Connect\ MEDIUM 5.3
CVE-2023-29259

IBM Sterling Connect:Express for UNIX 1.5 browser UI is vulnerable to attacks that rely on the use of cookies without the SameSite attribute. IBM X-…

Patch available
Fix from $1,600 2023-07-19
Infosphere Information Server MEDIUM 6.5
CVE-2023-35898

IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information due to an insecure security configuration in…

Patch available
Fix from $1,600 2023-07-19
Robotic Process Automation MEDIUM 5.3
CVE-2023-35900

IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.4 and 23.0.0 through 23.0.5 is vulnerable to disclosing server version information…

Fix: after 23.0.5
Fix from $1,600 2023-07-19
Security Verify Access MEDIUM 5.4
CVE-2023-30433

IBM Security Verify Access 10.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to v…

Mitigation only
Fix from $1,600 2023-07-19
Db2 MEDIUM 6.7
CVE-2023-35012

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 with a Federated configuration is vulnerable to a stack-based buffer overflow,…

Mitigation only
Fix from $1,600 2023-07-17
Infosphere Information Server MEDIUM 5.3
CVE-2023-33857

IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain system information using a specially crafted query that could aid in f…

Patch available
Fix from $1,600 2023-07-17
Robotic Process Automation MEDIUM 5.3
CVE-2023-35901

IBM Robotic Process Automation 21.0.0 through 21.0.7.6 and 23.0.0 through 23.0.6 is vulnerable to client side validation bypass which could allow inv…

Fix: after 23.0.6
Fix from $1,600 2023-07-17
I HIGH 7.8
CVE-2023-30988

The IBM i 7.2, 7.3, 7.4, and 7.5 product Facsimile Support for i contains a local privilege escalation vulnerability. A malicious actor with command…

Patch available
Fix from $1,950 2023-07-16
I HIGH 7.8
CVE-2023-30989

IBM Performance Tools for i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability. A malicious actor with command line access t…

Patch available
Fix from $1,950 2023-07-16
Db2 HIGH 7.5
CVE-2023-30446

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted qu…

Patch available
Fix from $1,950 2023-07-10
Db2 HIGH 7.5
CVE-2023-30447

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted qu…

Patch available
Fix from $1,950 2023-07-10