Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Safer Payments HIGH 7.5
CVE-2023-27556

IBM Counter Fraud Management for Safer Payments 6.1.0.00, 6.2.0.00, 6.3.0.00 through 6.3.1.03, 6.4.0.00 through 6.4.2.02 and 6.5.0.00 does not proper…

Fix: 6.3.1.04 / 6.4.2.03+
Fix from $1,950 2023-04-28
Maximo Asset Management MEDIUM 5.3
CVE-2023-27860

IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 could disclose sensitive information in an error message. This information could be used in further …

Patch available
Fix from $1,600 2023-04-27
Websphere Application Server MEDIUM 6.1
CVE-2023-24966

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript cod…

Fix: 8.5.5.24 / 9.0.5.16+
Fix from $1,600 2023-04-27
Db2 HIGH 7.5
CVE-2023-29255

IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as it may trap when compi…

Fix: 11.1.4 / 11.5.8+
Fix from $1,950 2023-04-27
Watson Machine Learning On Cloud Pak For Data MEDIUM 6.5
CVE-2023-30444

IBM Watson Machine Learning on Cloud Pak for Data 4.0 and 4.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated at…

Patch available
Fix from $1,600 2023-04-27
Db2 HIGH 7.5
CVE-2023-27559

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may crash w…

Fix: 11.1.4 / 11.5.8+
Fix from $1,950 2023-04-26
Db2 HIGH 7.2
CVE-2023-29257

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to remote code execution as a database administr…

Fix: 11.1.4 / 11.5.8+
Fix from $1,950 2023-04-26
Vios HIGH 7.8
CVE-2023-26286

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX runtime services library to execute…

Mitigation only
Fix from $1,950 2023-04-26
Spectrum Scale Container Native Storage Access HIGH 8.4
CVE-2022-41739

IBM Spectrum Scale (IBM Spectrum Scale Container Native Storage Access 5.1.2.1 through 5.1.6.0) could allow programs running inside the container to …

Fix: after 5.1.6.0
Fix from $1,950 2023-04-26
Cloud Pak For Data HIGH 7.2
CVE-2022-36769

IBM Cloud Pak for Data 4.5 and 4.6 could allow a privileged user to upload malicious files of dangerous types that can be automatically processed wit…

Mitigation only
Fix from $1,950 2023-04-26
Sterling Order Management HIGH 8.1
CVE-2022-33959

IBM Sterling Order Management 10.0 could allow a user to bypass validation and perform unauthorized actions on behalf of other users. IBM X-Force ID…

Mitigation only
Fix from $1,950 2023-04-07
Tririga Application Platform HIGH 7.1
CVE-2023-27876

IBM TRIRIGA 4.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnera…

Patch available
Fix from $1,950 2023-04-07
Db2 Mirror For I MEDIUM 6.5
CVE-2022-43928

The IBM Toolbox for Java (Db2 Mirror for i 7.4 and 7.5) could allow a user to obtain sensitive information, caused by utilizing a Java string for pro…

Patch available
Fix from $1,600 2023-04-07
Tririga Application Platform MEDIUM 5.4
CVE-2022-43914

IBM TRIRIGA Application Platform 4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the…

Fix: 4.0.3+
Fix from $1,600 2023-04-07
Sterling Order Management HIGH 7.5
CVE-2022-34333

IBM Sterling Order Management 10.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compro…

Mitigation only
Fix from $1,950 2023-04-07
Aspera Cargo CRITICAL 9.8
CVE-2023-27284

IBM Aspera Cargo 4.2.5 and IBM Aspera Connect 4.2.5 are vulnerable to a buffer overflow, caused by improper bounds checking. An attacker could overfl…

Fix: 4.2.5+
Fix from $2,300 2023-04-02
Aspera Cargo CRITICAL 9.8
CVE-2023-27286

IBM Aspera Cargo 4.2.5 and IBM Aspera Connect 4.2.5 are vulnerable to a buffer overflow, caused by improper bounds checking. An attacker could overfl…

Fix: 4.2.5+
Fix from $2,300 2023-04-02
Websphere Application Server MEDIUM 5.4
CVE-2023-26283

IBM WebSphere Application Server 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the…

Patch available
Fix from $1,600 2023-04-02
Qradar Security Information And Event Manager HIGH 7.2
CVE-2022-43863

IBM QRadar SIEM 7.4 and 7.5 is vulnerable to privilege escalation, allowing a user with some admin capabilities to gain additional admin capabilities…

Fix: 7.4.3+
Fix from $1,950 2023-03-22
Security Key Lifecycle Manager HIGH 8.8
CVE-2023-25924

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an authenticated user to perform actions that they should not…

Patch available
Fix from $1,950 2023-03-22
Security Key Lifecycle Manager MEDIUM 5.3
CVE-2023-25688

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1could allow a remote attacker to traverse directories on the system. An at…

Patch available
Fix from $1,600 2023-03-22
Security Key Lifecycle Manager CRITICAL 9.8
CVE-2023-25684

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 is vulnerable to SQL injection. A remote attacker could send specially cr…

Patch available
Fix from $2,300 2023-03-21
Security Key Lifecycle Manager HIGH 7.5
CVE-2023-25923

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an attacker to upload files that could be used in a denial of…

Patch available
Fix from $1,950 2023-03-21
Security Key Lifecycle Manager MEDIUM 5.5
CVE-2023-25686

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 stores user credentials in plain clear text which can be read by a local …

Patch available
Fix from $1,600 2023-03-21
Aspera Faspex HIGH 8.8
CVE-2023-27874

IBM Aspera Faspex 4.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker coul…

Fix: after 4.4.2
Fix from $1,950 2023-03-21
Aspera Faspex HIGH 7.5
CVE-2023-27871

IBM Aspera Faspex 4.4.2 could allow a remote attacker to obtain sensitive credential information for an external user, using a specially crafted SQL …

Fix: after 4.4.2
Fix from $1,950 2023-03-21
Aspera Faspex MEDIUM 6.5
CVE-2023-27873

IBM Aspera Faspex 4.4.2 could allow a remote authenticated attacker to obtain sensitive credential information using specially crafted XML input. IBM…

Fix: after 4.4.2
Fix from $1,600 2023-03-21
Security Key Lifecycle Manager MEDIUM 5.3
CVE-2023-25689

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1 , and 4.1.1 could allow a remote attacker to traverse directories on the system. An …

Patch available
Fix from $1,600 2023-03-21
Aspera Faspex HIGH 7.5
CVE-2023-27875

IBM Aspera Faspex 5.0.4 could allow a user to change other user's credentials due to improper access controls. IBM X-Force ID: 249847.

Patch available
Fix from $1,950 2023-03-16
Robotic Process Automation MEDIUM 6.5
CVE-2022-46773

IBM Robotic Process Automation 21.0.0 - 21.0.7 and 23.0.0 is vulnerable to client-side validation bypass for credential pools. Invalid credential poo…

Fix: 21.0.7.1 / 23.0.1+
Fix from $1,600 2023-03-15