Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Security Verify Access MEDIUM 6.5
CVE-2022-36775

IBM Security Verify Access 10.0.0.0, 10.0.1.0, 10.0.2.0, 10.0.3.0, and10.0.4.0 is vulnerable to HTTP header injection, caused by improper validation …

Patch available
Fix from $1,600 2023-02-17
Infosphere Information Server MEDIUM 5.5
CVE-2023-24964

IBM InfoSphere Information Server 11.7 could allow a local user to obtain sensitive information from a log files. IBM X-Force ID: 246463.

Patch available
Fix from $1,600 2023-02-17
Aspera Faspex MEDIUM 5.4
CVE-2023-22868

IBM Aspera Faspex 4.4.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus …

Fix: after 4.4.1
Fix from $1,600 2023-02-17
Aspera Faspex CRITICAL 9.8
CVE-2022-47986 KEVEPSS 100%

IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserializa…

Fix: after 4.4.1
Fix from $2,300 2023-02-17
Elastic Storage System MEDIUM 6.5
CVE-2022-43869

IBM Spectrum Scale (5.1.0.0 through 5.1.2.8 and 5.1.3.0 through 5.1.5.1) and IBM Elastic Storage System (6.1.0.0 through 6.1.2.4 and 6.1.3.0 through …

Fix: after 6.1.4.1
Fix from $1,600 2023-02-12
Watson Knowledge Catalog On Cloud Pak For Data CRITICAL 9.8
CVE-2022-41731

IBM Watson Knowledge Catalog on Cloud Pak for Data 4.5.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statement…

Mitigation only
Fix from $2,300 2023-02-12
App Connect Enterprise MEDIUM 6.5
CVE-2022-42444

IBM App Connect Enterprise 11.0.0.8 through 11.0.0.19 and 12.0.1.0 through 12.0.5.0 is vulnerable to a buffer overflow. A remote privileged user coul…

Fix: after 12.0.5.0
Fix from $1,600 2023-02-12
Api Connect HIGH 7.5
CVE-2022-34350

IBM API Connect 10.0.0.0 through 10.0.5.0, 10.0.1.0 through 10.0.1.7, and 2018.4.1.0 through 2018.4.1.20 is vulnerable to External Service Interactio…

Fix: after 2018.4.1.20
Fix from $1,950 2023-02-08
Cloud Pak For Multicloud Management Monitoring HIGH 8.8
CVE-2022-42438

IBM Cloud Pak for Multicloud Management Monitoring 2.0 and 2.3 allows users without admin roles access to admin functions by specifying direct URL pa…

Fix: 2.3.0+
Fix from $1,950 2023-02-08
Sterling External Authentication Server MEDIUM 5.5
CVE-2022-35720

IBM Sterling External Authentication Server 6.1.0 and IBM Sterling Secure Proxy 6.0.3 uses weaker than expected cryptographic algorithms during insta…

Patch available
Fix from $1,600 2023-02-08
Websphere Application Server CRITICAL 9.8
CVE-2023-23477

IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially craft…

Mitigation only
Fix from $2,300 2023-02-03
Tivoli Workload Scheduler CRITICAL 9.1
CVE-2022-38389

IBM Tivoli Workload Scheduler 9.4, 9.5, and 10.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote at…

Mitigation only
Fix from $2,300 2023-02-03
Tivoli Workload Scheduler CRITICAL 9.1
CVE-2022-22486

IBM Tivoli Workload Scheduler 9.4, 9.5, and 10.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote at…

Mitigation only
Fix from $2,300 2023-02-03
App Connect Enterprise Certified Container MEDIUM 6.5
CVE-2022-43922

IBM App Connect Enterprise Certified Container 4.1, 4.2, 5.0, 5.1, 5.2, 6.0, 6.1, and 6.2 could disclose sensitive information to an attacker due to …

Patch available
Fix from $1,600 2023-02-01
Infosphere Information Server MEDIUM 5.4
CVE-2022-47983

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…

Patch available
Fix from $1,600 2023-02-01
Websphere Application Server HIGH 7.5
CVE-2022-43917

IBM WebSphere Application Server 8.5 and 9.0 traditional container uses weaker than expected cryptographic keys that could allow an attacker to decry…

Patch available
Fix from $1,950 2023-01-26
Business Automation Workflow HIGH 7.5
CVE-2022-43864

IBM Business Automation Workflow 22.0.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially craft…

Fix: after 21.0.3.1
Fix from $1,950 2023-01-26
Security Verify Governance HIGH 7.5
CVE-2022-22462

IBM Security Verify Governance, Identity Manager virtual appliance component 10.0.1 uses weaker than expected cryptographic algorithms that could all…

Patch available
Fix from $1,950 2023-01-26
Infosphere Information Server MEDIUM 5.3
CVE-2022-41733

IBM InfoSphere Information Server 11.7 could allow a remote attacked to cause some of the components to be unusable until the process is restarted. I…

Fix: 11.7.1.4+
Fix from $1,600 2023-01-20
Cloud Pak For Security MEDIUM 6.5
CVE-2021-39089

IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.6.0 could allow an authenticated user to obtain sensitive information from a specially crafte…

Fix: after 1.10.6.0
Fix from $1,600 2023-01-20
Spectrum Virtualize MEDIUM 5.9
CVE-2022-39167

IBM Spectrum Virtualize 8.5, 8.4, 8.3, 8.2, and 7.8, under certain configurations, could disclose sensitive information to an attacker using man-in-t…

Patch available
Fix from $1,600 2023-01-19
Robotic Process Automation For Cloud Pak HIGH 7.8
CVE-2023-22592

IBM Robotic Process Automation for Cloud Pak 21.0.1 through 21.0.4 could allow a local user to perform unauthorized actions due to insufficient permi…

Fix: 21.0.5+
Fix from $1,950 2023-01-18
Robotic Process Automation MEDIUM 5.9
CVE-2023-22863

IBM Robotic Process Automation 20.12.0 through 21.0.2 defaults to HTTP in some RPA commands when the prefix is not explicitly specified in the URL. …

Fix: 21.0.3+
Fix from $1,600 2023-01-18
Robotic Process Automation MEDIUM 5.4
CVE-2023-22594

IBM Robotic Process Automation for Cloud Pak 20.12.0 through 21.0.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed a…

Fix: 21.0.5+
Fix from $1,600 2023-01-18
Vios HIGH 7.8
CVE-2022-47990

IBM AIX 7.1, 7.2, 7.3 and VIOS , 3.1 could allow a non-privileged local user to exploit a vulnerability in X11 to cause a buffer overflow that could …

Patch available
Fix from $1,950 2023-01-18
Qradar Security Information And Event Manager HIGH 7.5
CVE-2023-22875

IBM QRadar SIEM 7.4 and 7.5copies certificate key files used for SSL/TLS in the QRadar web user interface to managed hosts in the deployment that do …

Mitigation only
Fix from $1,950 2023-01-17
Sterling Partner Engagement Manager CRITICAL 9.8
CVE-2022-40615

IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statem…

Patch available
Fix from $2,300 2023-01-11
Sterling Partner Engagement Manager MEDIUM 6.5
CVE-2022-34335

IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.1 could allow an authenticated user to exhaust server resources which could lead to a d…

Patch available
Fix from $1,600 2023-01-11
Maximo Application Suite HIGH 8.8
CVE-2022-35281

IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, 7.6.1.3 and the IBM Maximo Manage 8.3, 8.4 application in IBM Maximo Application Suite are vulnerable t…

Mitigation only
Fix from $1,950 2023-01-09
Security Verify Governance MEDIUM 5.5
CVE-2022-22470

IBM Security Verify Governance 10.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 225232.

Patch available
Fix from $1,600 2023-01-09