Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Spectrum Protect Backup Archive Client HIGH 7.8
CVE-2023-28956

IBM Spectrum Protect Backup-Archive Client 8.1.0.0 through 8.1.17.2 may allow a local user to escalate their privileges due to improper access contro…

Fix: after 8.1.17.2
Fix from $1,950 2023-06-22
Spss Modeler MEDIUM 5.5
CVE-2023-33842

IBM SPSS Modeler on Windows 17.0, 18.0, 18.2.2, 18.3, 18.4, and 18.5 requires the end user to have access to the server SSL key which could allow a l…

Patch available
Fix from $1,600 2023-06-22
Security Directory Suite Va HIGH 7.2
CVE-2022-33166

IBM Security Directory Suite VA 8.0.1 through 8.0.1.19 could allow a privileged user to upload malicious files of dangerous types that can be automat…

Fix: after 8.0.1.19
Fix from $1,950 2023-06-15
Security Directory Suite Va HIGH 8.8
CVE-2022-32752

IBM Security Directory Suite VA 8.0.1 through 8.0.1.19 could allow a remote authenticated attacker to execute arbitrary commands on the system by sen…

Fix: after 8.0.1.19
Fix from $1,950 2023-06-15
Security Directory Suite Va HIGH 7.5
CVE-2022-32757

IBM Security Directory Suite VA 8.0.1 through 8.0.1.19 uses an inadequate account lockout setting that could allow a remote attacker to brute force a…

Fix: after 8.0.1.19
Fix from $1,950 2023-06-15
Security Directory Suite Va HIGH 8.1
CVE-2022-33163

IBM Security Directory Suite VA 8.0.1 specifies permissions for a security-critical resource in a way that allows that resource to be read or modifie…

Patch available
Fix from $1,950 2023-06-15
Security Directory Suite Va HIGH 7.5
CVE-2022-33168

IBM Security Directory Suite VA 8.0.1 could allow an attacker to cause a denial of service due to uncontrolled resource consumption. IBM X-Force ID:…

Patch available
Fix from $1,950 2023-06-15
Security Directory Suite Va MEDIUM 6.5
CVE-2022-33159

IBM Security Directory Suite VA 8.0.1 through 8.0.1.19 stores user credentials in plain clear text which can be read by an authenticated user. IBM X…

Fix: after 8.0.1.19
Fix from $1,600 2023-06-15
Powervm Hypervisor HIGH 7.5
CVE-2023-25683

IBM PowerVM Hypervisor FW950.00 through FW950.71, FW1010.00 through FW1010.40, FW1020.00 through FW1020.20, and FW1030.00 through FW1030.11 could all…

Mitigation only
Fix from $1,950 2023-06-15
Security Guardium HIGH 7.8
CVE-2022-22307

IBM Security Guardium 11.3, 11.4, and 11.5 could allow a local user to obtain elevated privileges due to incorrect authorization checks. IBM X-Force…

Patch available
Fix from $1,950 2023-06-15
Sterling Partner Engagement Manager CRITICAL 9.6
CVE-2023-23482

IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading …

Fix: 6.1.2.8 / 6.2.0.6+
Fix from $2,300 2023-06-08
Sterling Partner Engagement Manager MEDIUM 5.4
CVE-2023-23480

IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary…

Fix: 6.1.2.8 / 6.2.0.6+
Fix from $1,600 2023-06-08
Sterling Partner Engagement Manager MEDIUM 5.4
CVE-2023-23481

IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed ar…

Fix: 6.1.2.8 / 6.2.0.6+
Fix from $1,600 2023-06-08
Txseries For Multiplatform MEDIUM 5.4
CVE-2023-33846

IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11.1 is vulnerable to cross-site scripting. This vu…

Fix: 8.2.0.2 / 9.1.0.2+
Fix from $1,600 2023-06-08
Cics Tx MEDIUM 6.5
CVE-2023-33848

IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11.1 could allow a privileged user to obtain highly…

Mitigation only
Fix from $1,600 2023-06-07
Security Guardium HIGH 8.8
CVE-2023-0041

IBM Security Guardium 11.5 could allow a user to take over another user's session due to insufficient session expiration. IBM X-Force ID: 243657.

Patch available
Fix from $1,950 2023-06-05
Maximo Application Suite MEDIUM 5.9
CVE-2023-27861

IBM Maximo Application Suite - Manage Component 8.8.0 and 8.9.0 transmits sensitive information in cleartext that could be intercepted by an attacker…

Mitigation only
Fix from $1,600 2023-06-05
Maximo Application Suite MEDIUM 5.3
CVE-2023-32334

IBM Maximo Asset Management 7.6.1.2, 7.6.1.3 and IBM Maximo Application Suite 8.8.0 stores sensitive information in URL parameters. This may lead to …

Patch available
Fix from $1,600 2023-06-05
Aspera Cargo HIGH 7.8
CVE-2023-27285

IBM Aspera Connect 4.2.5 and IBM Aspera Cargo 4.2.5 is vulnerable to a buffer overflow, caused by improper bounds checking. An attacker could overflo…

Fix: 4.2.6+
Fix from $1,950 2023-06-05
Aspera Cargo HIGH 7.5
CVE-2023-22862

IBM Aspera Connect 4.2.5 and IBM Aspera Cargo 4.2.5 transmits authentication credentials, but it uses an insecure method that is susceptible to unaut…

Fix: 4.2.6+
Fix from $1,950 2023-06-05
Qradar Wincollect HIGH 7.8
CVE-2023-26278

IBM QRadar WinCollect Agent 10.0 through 10.1.3 could allow a local authenticated attacker to gain elevated privileges on the system. IBM X-Force ID…

Fix: after 10.1.3
Fix from $1,950 2023-05-31
Qradar Wincollect HIGH 7.8
CVE-2023-26277

IBM QRadar WinCollect Agent 10.0 though 10.1.3 could allow a local user to execute commands on the system due to execution with unnecessary privilege…

Fix: after 10.1.3
Fix from $1,950 2023-05-31
HTTP Server HIGH 7.5
CVE-2023-32342

IBM GSKit could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in the RSA Decryption implementation. …

Fix: 8.5.5.24 / 9.0.5.16+
Fix from $1,950 2023-05-30
Powervm Hypervisor HIGH 7.9
CVE-2023-30440

IBM PowerVM Hypervisor FW860.00 through FW860.B3, FW950.00 through FW950.70, FW1010.00 through FW1010.50, FW1020.00 through FW1020.30, and FW1030.00 …

Mitigation only
Fix from $1,950 2023-05-23
Infosphere Information Server CRITICAL 9.8
CVE-2023-32336

IBM InfoSphere Information Server 11.7 is affected by a remote code execution vulnerability due to insecure deserialization in an RMI service. IBM X…

Mitigation only
Fix from $2,300 2023-05-22
Mq MEDIUM 5.5
CVE-2023-28950

IBM MQ 8.0, 9.0, 9.1, 9.2, and 9.3 could disclose sensitive user information from a trace file if that functionality has been enabled. IBM X-Force I…

Patch available
Fix from $1,600 2023-05-19
Infosphere Information Server MEDIUM 5.4
CVE-2023-28529

IBM InfoSphere Information Server 11.7 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript co…

Patch available
Fix from $1,600 2023-05-19
Infosphere Information Server CRITICAL 9.8
CVE-2022-47984

IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could all…

Patch available
Fix from $2,300 2023-05-19
Infosphere Information Server MEDIUM 5.5
CVE-2023-22878

IBM InfoSphere Information Server 11.7 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 244373.

Patch available
Fix from $1,600 2023-05-19
Mq MEDIUM 5.5
CVE-2023-28514

IBM MQ 8.0, 9.0, and 9.1 could allow a local user to obtain sensitive credential information when a detailed technical error message is returned in a…

Patch available
Fix from $1,600 2023-05-19