Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Spectrum Scale MEDIUM 6.8
CVE-2022-40607

IBM Spectrum Scale 5.1 could allow users with permissions to create pod, persistent volume and persistent volume claim to access files and directorie…

Fix: after 5.1.4.0
Fix from $1,600 2022-12-19
Spectrum Protect Plus MEDIUM 5.9
CVE-2020-4497

IBM Spectrum Protect Plus 10.1.0 through 10.1.12 discloses sensitive information due to unencrypted data being used in the communication flow between…

Fix: 10.1.13+
Fix from $1,600 2022-12-14
Cics Tx MEDIUM 6.1
CVE-2022-34318

IBM CICS TX 11.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a r…

Patch available
Fix from $1,600 2022-12-12
Db2 HIGH 8.8
CVE-2022-41296

IBM Db2U 3.5, 4.0, and 4.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions tr…

Mitigation only
Fix from $1,950 2022-12-12
Api Connect MEDIUM 5.4
CVE-2021-38997

IBM API Connect V10.0.0.0 through V10.0.5.0, V10.0.1.0 through V10.0.1.7, and V2018.4.1.0 through 2018.4.1.19 is vulnerable to HTTP header injection,…

Fix: after 2018.4.1.19
Fix from $1,600 2022-12-12
Transformation Advisor MEDIUM 5.4
CVE-2022-41299

IBM Cloud Transformation Advisor 2.0.1 through 3.3.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaSc…

Fix: 3.4.0+
Fix from $1,600 2022-12-09
Content Navigator HIGH 8.8
CVE-2022-43581

IBM Content Navigator 3.0.0, 3.0.1, 3.0.2, 3.0.3, 3.0.4, 3.0.5, 3.0.6, 3.0.7, 3.0.8, 3.0.9, 3.0.10, 3.0.11, and 3.0.12 is vulnerable to missing autho…

Fix: after 3.0.12
Fix from $1,950 2022-12-07
Business Automation Workflow MEDIUM 6.1
CVE-2022-41735

IBM Business Process Manager 21.0.1 through 21.0.3.1, 20.0.0.1 through 20.0.0.2 19.0.0.1 through 19.0.0.3 is vulnerable to cross-site scripting. This…

Fix: after 21.0.3.1
Fix from $1,600 2022-12-07
Spectrum Scale Container Native Storage Access HIGH 7.8
CVE-2022-43867

IBM Spectrum Scale 5.1.0.1 through 5.1.4.1 could allow a local attacker to execute arbitrary commands in the container. IBM X-Force ID: 239437.

Fix: after 5.1.4.1
Fix from $1,950 2022-12-06
Sterling Secure Proxy HIGH 7.5
CVE-2022-34361

IBM Sterling Secure Proxy 6.0.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive informati…

Patch available
Fix from $1,950 2022-12-06
Websphere Automation For Ibm Cloud Pak For Watson Aiops MEDIUM 6.5
CVE-2022-43900

IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps 1.4.2 could provide a weaker than expected security. A local attacker can create an outbo…

Fix: 1.4.3+
Fix from $1,600 2022-12-01
Websphere Automation For Ibm Cloud Pak For Watson Aiops MEDIUM 5.5
CVE-2022-43901

IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps 1.4.3 could disclose sensitive information. An authenticated local attacker could exploit…

Fix: 1.4.3+
Fix from $1,600 2022-12-01
Db2 On Cloud Pak For Data MEDIUM 6.5
CVE-2022-41297

IBM Db2U 3.5, 4.0, and 4.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions tr…

Fix: 4.6+
Fix from $1,600 2022-12-01
Maximo Application Suite MEDIUM 5.5
CVE-2022-41732

IBM Maximo Mobile 8.7 and 8.8 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 237407.

Mitigation only
Fix from $1,600 2022-11-28
Datapower Gateway MEDIUM 5.4
CVE-2022-40228

IBM DataPower Gateway 10.0.3.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.9, 2018.4.1.0 through 2018.4.1.22, and 10.5.0.0 through 10.5.0.2 does not in…

Fix: after 2018.4.1.22
Fix from $1,600 2022-11-22
I Access Client Solutions MEDIUM 6.7
CVE-2022-40746

IBM i Access Family 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.0 could allow a local authenticated attacker to execute arbitrary code on the syste…

Fix: after 1.1.9.0
Fix from $1,600 2022-11-21
Business Automation Workflow MEDIUM 5.4
CVE-2022-38390

Multiple IBM Business Automation Workflow versions are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScr…

Fix: after 21.0.3.1
Fix from $1,600 2022-11-17
Infosphere Information Server CRITICAL 9.8
CVE-2022-40752

IBM InfoSphere DataStage 11.7 is vulnerable to a command injection vulnerability due to improper neutralization of special elements. IBM X-Force ID: …

Patch available
Fix from $2,300 2022-11-16
Infosphere Information Server MEDIUM 5.4
CVE-2022-40753

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…

Patch available
Fix from $1,600 2022-11-15
Cloud Pak For Security HIGH 8.1
CVE-2022-38385

IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.2.0 could allow an authenticated user to obtain highly sensitive information or perform unaut…

Fix: after 1.10.2.0
Fix from $1,950 2022-11-15
Cics Tx HIGH 7.5
CVE-2022-34320

IBM CICS TX 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force…

Patch available
Fix from $1,950 2022-11-14
Cics Tx MEDIUM 5.4
CVE-2022-34317

IBM CICS TX 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alterin…

Patch available
Fix from $1,600 2022-11-14
Cics Tx MEDIUM 5.3
CVE-2022-34316

IBM CICS TX 11.1 does not neutralize or incorrectly neutralizes web scripting syntax in HTTP headers that can be used by web browser components that …

Patch available
Fix from $1,600 2022-11-14
Cics Tx MEDIUM 5.4
CVE-2022-34315

IBM CICS TX 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alterin…

Patch available
Fix from $1,600 2022-11-14
Cics Tx HIGH 7.5
CVE-2022-34319

IBM CICS TX 11.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Forc…

Patch available
Fix from $1,950 2022-11-14
Cics Tx MEDIUM 6.1
CVE-2022-38705

IBM CICS TX 11.1 Standard and Advanced could allow a remote attacker to bypass security restrictions, caused by a reverse tabnabbing flaw. An attacke…

Patch available
Fix from $1,600 2022-11-14
Cics Tx MEDIUM 5.3
CVE-2022-34329

IBM CICS TX 11.7 could allow an attacker to obtain sensitive information from HTTP response headers. IBM X-Force ID: 229467.

Patch available
Fix from $1,600 2022-11-14
Mq Internet Pass Thru MEDIUM 5.5
CVE-2022-35719

IBM MQ Internet Pass-Thru 2.1, 9.2 LTS and 9.2 CD stores potentially sensitive information in trace files that could be read by a local user.

Patch available
Fix from $1,600 2022-11-14
Cloud Pak For Security HIGH 8.8
CVE-2022-38387

IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.2.0 could allow a remote authenticated attacker to execute arbitrary commands on the system b…

Fix: after 1.10.2.0
Fix from $1,950 2022-11-11
Websphere Application Server MEDIUM 5.4
CVE-2022-40750

IBM WebSphere Application Server 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript co…

Patch available
Fix from $1,600 2022-11-11