Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Powervm Hypervisor HIGH 8.8
CVE-2023-30438

An internally discovered vulnerability in PowerVM on IBM Power9 and Power10 systems could allow an attacker with privileged user access to a logical …

Mitigation only
Fix from $1,950 2023-05-17
Security Verify Access HIGH 7.5
CVE-2023-25927

IBM Security Verify Access 10.0.0, 10.0.1, 10.0.2, 10.0.3, 10.0.4, and 10.0.5 could allow an attacker to crash the webseald process using specially c…

Mitigation only
Fix from $1,950 2023-05-12
Api Connect HIGH 8.8
CVE-2023-28522

IBM API Connect V10 could allow an authenticated user to perform actions that they should not have access to. IBM X-Force ID: 250585.

Fix: 10.0.1.11 / 10.0.5.2+
Fix from $1,950 2023-05-12
Planning Analytics Local MEDIUM 5.4
CVE-2023-28520

IBM Planning Analytics Local 2.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in …

Patch available
Fix from $1,600 2023-05-12
Cognos Analytics MEDIUM 6.1
CVE-2021-39036

IBM Cognos Analytics 11.1 and 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the W…

Mitigation only
Fix from $1,600 2023-05-12
Websphere Application Server MEDIUM 6.3
CVE-2023-27554

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attack…

Fix: 8.5.5.24 / 9.0.5.16+
Fix from $1,600 2023-05-11
Spectrum Virtualize MEDIUM 5.9
CVE-2023-27870

IBM Spectrum Virtualize 8.5, under certain circumstances, could disclose sensitive credential information while a download from Fix Central is in pro…

Patch available
Fix from $1,600 2023-05-11
Business Automation Workflow MEDIUM 5.4
CVE-2023-24957

IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, 19.0.0.2, 19.0.0.3, 20.0.0.1, 20.0.0.2, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 i…

Fix: 21.0.3 / 22.0.2+
Fix from $1,600 2023-05-06
Urbancode Deploy MEDIUM 5.1
CVE-2022-43877

IBM UrbanCode Deploy (UCD) versions up to 7.3.0.1 could disclose sensitive password information during a manual edit of the agentrelay.properties fil…

Fix: 6.2.7.20 / 7.0.5.15+
Fix from $1,600 2023-05-06
Qradar Data Synchronization HIGH 7.5
CVE-2022-22313

IBM QRadar Data Synchronization App 1.0 through 3.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt high…

Fix: 3.1.0+
Fix from $1,950 2023-05-06
Maximo Asset Management MEDIUM 5.4
CVE-2022-43866

IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript …

Mitigation only
Fix from $1,600 2023-05-05
Mq Appliance MEDIUM 5.9
CVE-2023-26285

IBM MQ 9.2 CD, 9.2 LTS, 9.3 CD, and 9.3 LTS could allow a remote attacker to cause a denial of service due to an error processing invalid data. IBM …

Fix: 9.2.0.11 / 9.2.5.7+
Fix from $1,600 2023-05-05
Elastic Storage System MEDIUM 5.5
CVE-2023-30434

IBM Storage Scale (IBM Spectrum Scale 5.1.0.0 through 5.1.2.9, 5.1.3.0 through 5.1.6.1 and IBM Elastic Storage Systems 6.1.0.0 through 6.1.2.5, 6.1.3…

Fix: 6.1.2.6 / 6.1.6.1+
Fix from $1,600 2023-05-05
Mq Appliance MEDIUM 6.5
CVE-2022-43919

IBM MQ 9.2 CD, 9.2 LTS, 9.3 CD, and 9.3 LTS could allow an authenticated attacker with authorization to craft messages to cause a denial of service. …

Fix: 9.2.0.10 / 9.2.5.7+
Fix from $1,600 2023-05-05
Mq Appliance MEDIUM 5.5
CVE-2023-22874

IBM MQ Clients 9.2 CD, 9.3 CD, and 9.3 LTS are vulnerable to a denial of service attack when processing configuration files. IBM X-Force ID: 244216.

Fix: 9.3.0.5 / 9.3.2+
Fix from $1,600 2023-05-05
Cognos Command Center MEDIUM 5.5
CVE-2022-38707

IBM Cognos Command Center 10.2.4.1 could allow a local attacker to obtain sensitive information due to insufficient session expiration. IBM X-Force …

Patch available
Fix from $1,600 2023-05-05
3957 Vec Firmware HIGH 8.8
CVE-2023-24958

A vulnerability in the IBM TS7700 Management Interface 8.51.2.12, 8.52.200.111, 8.52.102.13, and 8.53.0.63 could allow an authenticated user to submi…

Fix: 8.51.2.12 / 8.52.102.13+
Fix from $1,950 2023-05-04
I MEDIUM 6.4
CVE-2023-23470

IBM i 7.2, 7.3, 7.4, and 7.5 could allow an authenticated privileged administrator to gain elevated privileges in non-default configurations, as a re…

Mitigation only
Fix from $1,600 2023-05-04
Websphere Application Server MEDIUM 5.3
CVE-2022-39161

IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0, and IBM WebSphere Application Server Liberty, when configured to communicate with the Web Server…

Mitigation only
Fix from $1,600 2023-05-03
Infosphere Information Server HIGH 7.5
CVE-2023-30441

IBM Runtime Environment, Java Technology Edition IBMJCEPlus and JSSE 8.0.7.0 through 8.0.7.11 components could expose sensitive information using a c…

Fix: 8.0.7.15 / 8.5.5.23+
Fix from $1,950 2023-04-29
Spectrum Scale Container Native Storage Access HIGH 7.8
CVE-2022-41736

IBM Spectrum Scale Container Native Storage Access 5.1.2.1 through 5.1.6.0 contains an unspecified vulnerability that could allow a local user to …

Fix: 5.1.7.0+
Fix from $1,950 2023-04-29
Financial Transaction Manager For Multiplatform MEDIUM 5.4
CVE-2022-43871

IBM Financial Transaction Manager for SWIFT Services 3.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary …

Mitigation only
Fix from $1,600 2023-04-29
Db2 HIGH 7.5
CVE-2023-26021

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to a denial of service as the server may crash when com…

Fix: 11.1.4 / 11.5.8+
Fix from $1,950 2023-04-28
Db2 HIGH 7.5
CVE-2023-26022

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of service as the server may crash when an Out of Memory …

Fix: 11.1.4 / 11.5.8+
Fix from $1,950 2023-04-28
Db2 HIGH 7.5
CVE-2023-27555

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5 is vulnerable to a denial of service when attempting to use ACR client affinit…

Fix: 11.1.4 / 11.5.8+
Fix from $1,950 2023-04-28
Db2 MEDIUM 5.9
CVE-2023-25930

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.1, 11.1, and 11.5 is vulnerable to a denial of service. Under rare conditions, …

Fix: 11.1.4 / 11.5.8+
Fix from $1,600 2023-04-28
Maximo Asset Management MEDIUM 5.4
CVE-2023-27864

IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewe…

Patch available
Fix from $1,600 2023-04-28
Vios HIGH 7.8
CVE-2023-28528

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the invscout command to execute arbitrary c…

Patch available
Fix from $1,950 2023-04-28
Safer Payments HIGH 7.5
CVE-2023-27557

IBM Counter Fraud Management for Safer Payments 6.1.0.00 through 6.1.1.02, 6.2.0.00 through 6.2.2.02, 6.3.0.00 through 6.3.1.02, 6.4.0.00 through 6.4…

Fix: 6.1.1.03 / 6.2.2.03+
Fix from $1,950 2023-04-28
Safer Payments MEDIUM 5.3
CVE-2020-4729

IBM Counter Fraud Management for Safer Payments 5.7.0.00 through 5.7.0.10, 6.0.0.00 through 6.0.0.07, 6.1.0.00 through 6.1.0.05, and 6.2.0.00 through…

Fix: 5.7.0.11 / 6.0.0.08+
Fix from $1,600 2023-04-28