Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Robotic Process Automation For Cloud Pak HIGH 8.8
CVE-2022-43844

IBM Robotic Process Automation for Cloud Pak 20.12 through 21.0.3 is vulnerable to broken access control. A user is not correctly redirected to the…

Fix: 21.0.3.1+
Fix from $1,950 2023-01-05
Robotic Process Automation MEDIUM 5.3
CVE-2022-43573

IBM Robotic Process Automation 20.12 through 21.0.6 is vulnerable to exposure of the name and email for the creator/modifier of platform level object…

Fix: 21.0.7+
Fix from $1,600 2023-01-05
Sterling B2b Integrator MEDIUM 6.5
CVE-2022-22371

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 does not invalidate session after a password change which could allow an authent…

Fix: after 6.1.1.1
Fix from $1,600 2023-01-05
Sterling B2b Integrator MEDIUM 6.1
CVE-2022-34330

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed …

Fix: after 6.1.1.2
Fix from $1,600 2023-01-05
Sterling B2b Integrator HIGH 8.8
CVE-2022-43920

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 could allow an authenticated user to gain privileges in a different group due to…

Fix: 6.0.3.7 / 6.1.0.6+
Fix from $1,950 2023-01-04
Sterling B2b Integrator CRITICAL 9.8
CVE-2022-22338

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 is vulnerable to SQL injection. A remote attacker could send specially crafted S…

Fix: 6.0.3.7 / 6.1.0.6+
Fix from $2,300 2023-01-04
Sterling B2b Integrator MEDIUM 6.5
CVE-2022-22337

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 could disclose sensitive information to an authenticated user. IBM X-Force ID: …

Fix: 6.0.3.7 / 6.1.0.6+
Fix from $1,600 2023-01-04
Sterling B2b Integrator MEDIUM 5.4
CVE-2021-38928

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry…

Fix: 6.0.3.7 / 6.1.0.6+
Fix from $1,600 2023-01-04
Sterling B2b Integrator MEDIUM 5.4
CVE-2022-22352

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed …

Fix: 6.0.3.7 / 6.1.0.6+
Fix from $1,600 2023-01-04
Business Automation Workflow HIGH 8.8
CVE-2022-42435

IBM Business Automation Workflow 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, and 22.0.1 is vulner…

Patch available
Fix from $1,950 2023-01-04
Security Verify Governance MEDIUM 5.3
CVE-2022-22449

IBM Security Verify Governance, Identity Manager 10.01 could allow a remote attacker to obtain sensitive information when a detailed technical error …

Patch available
Fix from $1,600 2022-12-24
Vios HIGH 8.4
CVE-2022-41290

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the rm_rlcache_file command to obtain root …

Patch available
Fix from $1,950 2022-12-23
Vios MEDIUM 6.2
CVE-2022-39164

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service.…

Patch available
Fix from $1,600 2022-12-23
Vios MEDIUM 6.2
CVE-2022-43848

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX perfstat kernel extension to cause …

Patch available
Fix from $1,600 2022-12-23
Vios MEDIUM 6.2
CVE-2022-43849

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a non-privileged local user to exploit a vulnerability in the AIX pfcdd kernel extension to cause a de…

Patch available
Fix from $1,600 2022-12-23
Vios MEDIUM 6.2
CVE-2022-40233

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX TCP/IP kernel extension to cause a …

Patch available
Fix from $1,600 2022-12-23
Vios MEDIUM 6.2
CVE-2022-43380

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX NFS kernel extension to cause a den…

Patch available
Fix from $1,600 2022-12-23
Vios MEDIUM 6.2
CVE-2022-43381

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a non-privileged local user to exploit a vulnerability in the AIX SMB client to cause a denial of serv…

Patch available
Fix from $1,600 2022-12-23
Vios MEDIUM 6.2
CVE-2022-39165

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a non-privileged local user to exploit a vulnerability in CAA to cause a denial of service. IBM X-For…

Patch available
Fix from $1,600 2022-12-23
Security Verify Governance MEDIUM 6.5
CVE-2022-22458

IBM Security Verify Governance, Identity Manager 10.0.1 stores user credentials in plain clear text which can be read by a remote authenticated user.…

Patch available
Fix from $1,600 2022-12-22
Security Verify Governance MEDIUM 6.1
CVE-2022-22456

IBM Security Verify Governance, Identity Manager 10.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav…

Patch available
Fix from $1,600 2022-12-22
Security Verify Governance MEDIUM 5.3
CVE-2022-35646

IBM Security Verify Governance, Identity Manager 10.0.1 software component could allow an authenticated user to modify or cancel any other user's acc…

Patch available
Fix from $1,600 2022-12-22
Security Verify Governance HIGH 7.5
CVE-2022-22461

IBM Security Verify Governance, Identity Manager 10.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt hi…

Patch available
Fix from $1,950 2022-12-22
Spectrum Control HIGH 7.5
CVE-2022-38391

IBM Spectrum Control 5.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM…

Patch available
Fix from $1,950 2022-12-20
Financial Transaction Manager MEDIUM 5.5
CVE-2022-43875

IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 could allow an authenticated user to lock additional RM authorizations,…

Patch available
Fix from $1,600 2022-12-20
Financial Transaction Manager MEDIUM 5.3
CVE-2022-43872

IBM Financial Transaction Manager 3.2.4 authorization checks are done incorrectly for some HTTP requests which allows getting unauthorized technical …

Patch available
Fix from $1,600 2022-12-20
Cognos Analytics CRITICAL 9.1
CVE-2022-38708

IBM Cognos Analytics 11.1.7 11.2.0, and 11.2.1 could be vulnerable to a Server-Side Request Forgery Attack (SSRF) attack by constructing URLs from us…

Fix: after 11.2.3
Fix from $2,300 2022-12-19
Cognos Analytics HIGH 7.5
CVE-2022-43883

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could be vulnerable to a Log Injection attack by constructing URLs from user-controlled data. This co…

Fix: after 11.2.3
Fix from $1,950 2022-12-19
Cognos Analytics MEDIUM 6.1
CVE-2022-39160

IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript …

Fix: 11.1.7+
Fix from $1,600 2022-12-19
Cognos Analytics MEDIUM 5.3
CVE-2022-43887

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could be vulnerable to sensitive information exposure by passing API keys to log files. If these keys…

Fix: 11.1.7+
Fix from $1,600 2022-12-19