Vulnerability index

Browse CVEs

6,330 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Db2 HIGH 7.5
CVE-2023-30448

IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted qu…

Patch available
Fix from $1,950 2023-07-10
Db2 HIGH 7.5
CVE-2023-30449

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted qu…

Patch available
Fix from $1,950 2023-07-10
Db2 HIGH 7.8
CVE-2023-30431

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 db2set is vulnerable to a buffer overflow, caused by improper …

Patch available
Fix from $1,950 2023-07-10
Db2 HIGH 7.5
CVE-2023-30442

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 federated server is vulnerable to a denial of service as the server m…

Patch available
Fix from $1,950 2023-07-10
Db2 HIGH 7.5
CVE-2023-30445

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted qu…

Patch available
Fix from $1,950 2023-07-10
Db2 HIGH 8.8
CVE-2023-27867

IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote authenticated attacker to execute arbitrary code vi…

Patch available
Fix from $1,950 2023-07-10
Db2 HIGH 8.8
CVE-2023-27868

IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote authenticated attacker to execute arbitrary code on…

Patch available
Fix from $1,950 2023-07-10
Db2 HIGH 8.8
CVE-2023-27869

IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote authenticated attacker to execute arbitrary code on…

Patch available
Fix from $1,950 2023-07-10
Db2 HIGH 7.8
CVE-2023-27558

IBM Db2 on Windows 10.5, 11.1, and 11.5 may be vulnerable to a privilege escalation caused by at least one installed service using an unquoted servic…

Patch available
Fix from $1,950 2023-07-10
Watson Knowledge Catalog On Cloud Pak For Data HIGH 7.8
CVE-2023-28958

IBM Watson Knowledge Catalog on Cloud Pak for Data 4.0 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands…

Patch available
Fix from $1,950 2023-07-10
Watson Knowledge Catalog On Cloud Pak For Data MEDIUM 6.5
CVE-2023-28955

IBM Watson Knowledge Catalog on Cloud Pak for Data 4.0 could allow an authenticated user send a specially crafted request that could cause a denial o…

Fix: 4.7+
Fix from $1,600 2023-07-10
Db2 MEDIUM 6.5
CVE-2023-29256

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to an information disclosure due to improper pri…

Mitigation only
Fix from $1,600 2023-07-10
Cloud Pak For Data HIGH 7.5
CVE-2023-27540

IBM Watson CP4D Data Stores 4.6.0 does not properly allocate resources without limits or throttling which could allow a remote attacker with informat…

Mitigation only
Fix from $1,950 2023-07-10
Cloud Object Storage System MEDIUM 5.4
CVE-2021-39014

IBM Cloud Object System 3.15.8.97 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in…

Fix: 3.15.8.106 / 3.16.0.47+
Fix from $1,600 2023-07-07
Websphere Application Server MEDIUM 5.5
CVE-2023-35890

IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security, caused by the improper encoding in a local configuration fi…

No fix yet
Fix from $1,600 2023-07-07
I CRITICAL 9.8
CVE-2023-30990

IBM i 7.2, 7.3, 7.4, and 7.5 could allow a remote attacker to execute CL commands as QUSER, caused by an exploitation of DDM architecture. IBM X-For…

Patch available
Fix from $2,300 2023-07-04
Informix Jdbc Driver CRITICAL 9.8
CVE-2023-27866

IBM Informix JDBC Driver 4.10 and 4.50 is susceptible to remote code execution attack via JNDI injection when driver code or the application using th…

Fix: 4.50.10+
Fix from $2,300 2023-06-28
Cloud Pak For Security HIGH 7.5
CVE-2023-30993

IBM Cloud Pak for Security (CP4S) 1.9.0.0 through 1.9.2.0 could allow an attacker with a valid API key for one tenant to access data from another ten…

Fix: after 1.9.2.0
Fix from $1,950 2023-06-27
Robotic Process Automation HIGH 7.8
CVE-2023-22593

IBM Robotic Process Automation for Cloud Pak 21.0.1 through 21.0.7.3 and 23.0.0 through 23.0.3 is vulnerable to security misconfiguration of the Redi…

Fix: after 23.0.3
Fix from $1,950 2023-06-27
Robotic Process Automation MEDIUM 5.5
CVE-2023-23468

IBM Robotic Process Automation for Cloud Pak 21.0.1 through 21.0.7.3 and 23.0.0 through 23.0.3 is vulnerable to insufficient security configuration w…

Fix: after 23.0.3
Fix from $1,600 2023-06-27
Qradar Security Information And Event Manager HIGH 7.5
CVE-2023-26276

IBM QRadar SIEM 7.5.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X…

Patch available
Fix from $1,950 2023-06-27
Qradar Security Information And Event Manager MEDIUM 5.4
CVE-2023-26274

IBM QRadar SIEM 7.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus al…

Patch available
Fix from $1,600 2023-06-27
Qradar Security Information And Event Manager MEDIUM 6.5
CVE-2022-34352

IBM QRadar SIEM 7.5.0 is vulnerable to information exposure allowing a delegated Admin tenant user with a specific domain security profile assigned t…

Patch available
Fix from $1,600 2023-06-27
Cloud Pak For Business Automation MEDIUM 6.1
CVE-2023-32339

IBM Business Automation Workflow is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web…

Patch available
Fix from $1,600 2023-06-27
Spectrum Protect Backup Archive Client HIGH 7.8
CVE-2023-28956

IBM Spectrum Protect Backup-Archive Client 8.1.0.0 through 8.1.17.2 may allow a local user to escalate their privileges due to improper access contro…

Fix: after 8.1.17.2
Fix from $1,950 2023-06-22
Spss Modeler MEDIUM 5.5
CVE-2023-33842

IBM SPSS Modeler on Windows 17.0, 18.0, 18.2.2, 18.3, 18.4, and 18.5 requires the end user to have access to the server SSL key which could allow a l…

Patch available
Fix from $1,600 2023-06-22
Security Directory Suite Va HIGH 7.2
CVE-2022-33166

IBM Security Directory Suite VA 8.0.1 through 8.0.1.19 could allow a privileged user to upload malicious files of dangerous types that can be automat…

Fix: after 8.0.1.19
Fix from $1,950 2023-06-15
Security Directory Suite Va HIGH 8.8
CVE-2022-32752

IBM Security Directory Suite VA 8.0.1 through 8.0.1.19 could allow a remote authenticated attacker to execute arbitrary commands on the system by sen…

Fix: after 8.0.1.19
Fix from $1,950 2023-06-15
Security Directory Suite Va HIGH 7.5
CVE-2022-32757

IBM Security Directory Suite VA 8.0.1 through 8.0.1.19 uses an inadequate account lockout setting that could allow a remote attacker to brute force a…

Fix: after 8.0.1.19
Fix from $1,950 2023-06-15
Security Directory Suite Va HIGH 8.1
CVE-2022-33163

IBM Security Directory Suite VA 8.0.1 specifies permissions for a security-critical resource in a way that allows that resource to be read or modifie…

Patch available
Fix from $1,950 2023-06-15