Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Robotic Process Automation MEDIUM 6.5
CVE-2023-25680

IBM Robotic Process Automation 21.0.1 through 21.0.5 is vulnerable to insufficiently protecting credentials. Queue Provider credentials are not obf…

Fix: 21.0.6+
Fix from $1,600 2023-03-15
Spectrum Scale HIGH 8.2
CVE-2020-4927

A vulnerability in the Spectrum Scale 5.0.5.0 through 5.1.6.1 core component could allow unauthorized access to user data or injection of arbitrary d…

Fix: 5.1.7.0+
Fix from $1,950 2023-03-15
Manage Application MEDIUM 6.5
CVE-2022-46774

IBM Manage Application 8.8.0 and 8.9.0 in the IBM Maximo Application Suite is vulnerable to incorrect default permissions which could give access to …

Mitigation only
Fix from $1,600 2023-03-15
Sterling B2b Integrator MEDIUM 6.5
CVE-2023-22876

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.1 could allow a privileged user to obtain sensitive in…

Fix: 6.0.3.8 / 6.1.2.2+
Fix from $1,600 2023-03-15
Mq Certified Container HIGH 8.8
CVE-2023-26284

IBM MQ Certified Container 9.3.0.1 through 9.3.0.3 and 9.3.1.0 through 9.3.1.1 could allow authenticated users with the cluster to be granted adminis…

Fix: 9.3.0.4 / 9.3.2.0+
Fix from $1,950 2023-03-15
App Connect Enterprise Certified Container MEDIUM 6.1
CVE-2022-43874

IBM App Connect Enterprise Certified Container 4.1, 4.2, 5.0, 5.1, 5.2, 6.0, 6.1, 6.2, and 7.0 is vulnerable to cross-site scripting. This vulnerabil…

Mitigation only
Fix from $1,600 2023-03-15
Spectrum Symphony MEDIUM 6.1
CVE-2023-24975

IBM Spectrum Symphony 7.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an att…

Mitigation only
Fix from $1,600 2023-03-10
Mq Appliance HIGH 7.5
CVE-2022-43902

IBM MQ 9.2 CD, 9.2 LTS, 9.3 CD, and 9.3 LTS is vulnerable to a denial of service attack caused by specially crafted PCF or MQSC messages. IBM X-Forc…

Fix: 9.2.0.8 / 9.2.5+
Fix from $1,950 2023-03-10
Financial Transaction Manager HIGH 8.8
CVE-2020-5002

IBM Financial Transaction Manager 3.2.0 through 3.2.10 could allow an authenticated user to perform unauthorized actions due to improper validation. …

Fix: 3.2.11+
Fix from $1,950 2023-03-10
Observability With Instana CRITICAL 9.1
CVE-2023-27290EPSS 9%

Docker based datastores for IBM Instana (IBM Observability with Instana 239-0 through 239-2, 241-0 through 241-2, and 243-0) do not currently require…

Fix: after 241-2
Fix from $2,300 2023-03-03
Maximo Application Suite MEDIUM 5.4
CVE-2022-35645

IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, 7.6.1.3 and IBM Maximo Application Suite 8.8 and 8.9 is vulnerable to stored cross-site scripting. This…

Patch available
Fix from $1,600 2023-03-02
Financial Transaction Manager HIGH 7.5
CVE-2020-5026

IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.2.0 through 3.2.7 could allow a remote attacker to obtain sensitive infor…

Fix: after 3.2.7
Fix from $1,950 2023-03-01
Financial Transaction Manager HIGH 7.5
CVE-2020-5001

IBM Financial Transaction Manager 3.2.0 through 3.2.7 could allow a remote attacker to traverse directories on the system. An attacker could send a s…

Fix: after 3.2.7
Fix from $1,950 2023-03-01
HTTP Server HIGH 7.5
CVE-2023-26281

IBM HTTP Server 8.5 used by IBM WebSphere Application Server could allow a remote user to cause a denial of service using a specially crafted URL. I…

Patch available
Fix from $1,950 2023-03-01
Mq For Hpe Nonstop HIGH 7.5
CVE-2022-40237

IBM MQ for HPE NonStop 8.1.0 is vulnerable to a denial of service attack due to an error within the CCDT and channel synchronization logic. IBM X-Fo…

Patch available
Fix from $1,950 2023-02-27
Cloud Pak For Business Automation MEDIUM 5.4
CVE-2023-22860

IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.…

Patch available
Fix from $1,600 2023-02-27
Maximo Application Suite MEDIUM 5.5
CVE-2022-43923

IBM Maximo Application Suite 8.8.0 and 8.9.0 stores potentially sensitive information that could be read by a local user. IBM X-Force ID: 241584.

Mitigation only
Fix from $1,600 2023-02-24
Spectrum Virtualize HIGH 8.8
CVE-2022-43873

An authenticated user can exploit a vulnerability in the IBM Spectrum Virtualize 8.2, 8.3, 8.4, and 8.5 GUI to execute code and escalate their privil…

Mitigation only
Fix from $1,950 2023-02-22
Spectrum Virtualize MEDIUM 6.5
CVE-2022-43870

IBM Spectrum Virtualize 8.3, 8.4, and 8.5 could disclose SNMPv3 server credentials to an authenticated user in log files. IBM X-Force ID: 239540.

Mitigation only
Fix from $1,600 2023-02-22
Sterling B2b Integrator MEDIUM 5.4
CVE-2022-43578

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.0 is vulnerable to cross-site scripting. This vulnerab…

Fix: after 6.1.2.0
Fix from $1,600 2023-02-22
Infosphere Information Server MEDIUM 5.4
CVE-2023-25928

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…

Patch available
Fix from $1,600 2023-02-21
Sterling B2b Integrator HIGH 8.8
CVE-2022-40231

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.0 could allow an authenticated user to perform unautho…

Fix: after 6.1.2.0
Fix from $1,950 2023-02-17
Qradar Security Information And Event Manager HIGH 7.5
CVE-2022-34351

IBM QRadar SIEM 7.4 and 7.5 is vulnerable to information exposure allowing a non-tenant user with a specific domain security profile assigned to see …

Fix: 7.4.3+
Fix from $1,950 2023-02-17
Infosphere Information Server HIGH 7.5
CVE-2023-24960

IBM InfoSphere Information Server 11.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafte…

Patch available
Fix from $1,950 2023-02-17
Sterling B2b Integrator MEDIUM 5.4
CVE-2022-43579

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.0 is vulnerable to cross-site scripting. This vulnerab…

Fix: after 6.1.2.0
Fix from $1,600 2023-02-17
Sterling B2b Integrator HIGH 8.8
CVE-2022-40232

IBM Sterling B2B Integrator Standard Edition 6.1.0.0 through 6.1.1.1, and 6.1.2.0 could allow an authenticated user to perform actions they should no…

Fix: after 6.1.1.1
Fix from $1,950 2023-02-17
Maximo Application Suite HIGH 7.5
CVE-2022-41734

IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message…

Patch available
Fix from $1,950 2023-02-17
Db2 HIGH 7.5
CVE-2022-43930

IBM Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 is vulnerable to an Information Disclosure as sensitive information may be included in a log…

Patch available
Fix from $1,950 2023-02-17
Db2 HIGH 7.5
CVE-2022-43927

IBM Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 is vulnerable to information Disclosure due to improper privilege management when a speciall…

Patch available
Fix from $1,950 2023-02-17
Db2 HIGH 7.5
CVE-2022-43929

IBM Db2 for Linux, UNIX and Windows 11.1 and 11.5 may be vulnerable to a Denial of Service when executing a specially crafted 'Load' command. IBM X-F…

Patch available
Fix from $1,950 2023-02-17