Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mq MEDIUM 6.5
CVE-2022-31772

IBM MQ 8.0, 9.0 LTS, 9.1 CD, 9.1 LTS, 9.2 CD, and 9.2 LTS could allow an authenticated and authorized user to cause a denial of service to the MQTT c…

Patch available
Fix from $1,600 2022-11-11
Cloud Pak For Security MEDIUM 5.4
CVE-2022-36776

IBM Cloud Pak for Security (CP4S) 1.10.0.0 79and 1.10.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary J…

Fix: after 1.10.2.0
Fix from $1,600 2022-11-11
Powervm Hypervisor CRITICAL 9.8
CVE-2022-34331

After performing a sequence of Power FW950, FW1010 maintenance operations a SRIOV network adapter can be improperly configured leading to desired VE…

Mitigation only
Fix from $2,300 2022-11-11
Robotic Process Automation HIGH 7.5
CVE-2022-43574

"IBM Robotic Process Automation 21.0.1, 21.0.2, 21.0.3, 21.0.4, and 21.0.5 is vulnerable to incorrect permission assignment which could allow access …

Fix: 21.0.6+
Fix from $1,950 2022-11-03
Infosphere Information Server CRITICAL 9.1
CVE-2022-40747

"IBM InfoSphere Information Server 11.7 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker co…

Patch available
Fix from $2,300 2022-11-03
Mq Appliance MEDIUM 6.5
CVE-2022-40230

"IBM MQ Appliance 9.2 CD, 9.2 LTS, 9.3 CD, and LTS 9.3 does not invalidate session after logout which could allow an authenticated user to impersonat…

Patch available
Fix from $1,600 2022-11-03
Infosphere Information Server MEDIUM 6.5
CVE-2022-40235

"IBM InfoSphere Information Server 11.7 could allow a user to cause a denial of service by removing the ability to run jobs due to improper input val…

Patch available
Fix from $1,600 2022-11-03
Infosphere Information Server HIGH 7.8
CVE-2022-35717

"IBM InfoSphere Information Server 11.7 could allow a locally authenticated attacker to execute arbitrary commands on the system by sending a special…

Patch available
Fix from $1,950 2022-11-03
Websphere Application Server MEDIUM 5.9
CVE-2022-38712

"IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Web services could allow a man-in-the-middle attacker to conduct SOAPAction spoofing to exec…

Fix: 7.0.0.45 / 8.0.0.15+
Fix from $1,600 2022-11-03
Robotic Process Automation MEDIUM 5.3
CVE-2022-38710

IBM Robotic Process Automation 21.0.1 and 21.0.2 could disclose sensitive version to an unauthorized control sphere information that could aid in fur…

Fix: 21.0.3+
Fix from $1,600 2022-11-03
Infosphere Information Server HIGH 8.8
CVE-2022-30608

"IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthoriz…

Patch available
Fix from $1,950 2022-11-03
Cognos Analytics MEDIUM 6.5
CVE-2022-34339

"IBM Cognos Analytics 11.2.1, 11.2.0, 11.1.7 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: …

Fix: 11.1.7+
Fix from $1,600 2022-11-03
Infosphere Information Server MEDIUM 5.4
CVE-2022-30615

"IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in …

Patch available
Fix from $1,600 2022-11-03
Infosphere Information Server MEDIUM 5.4
CVE-2022-35642

"IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in …

Patch available
Fix from $1,600 2022-11-03
Infosphere Information Server CRITICAL 9.8
CVE-2022-22425

"IBM InfoSphere Information Server 11.7 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system,…

Patch available
Fix from $2,300 2022-11-03
Infosphere Information Server MEDIUM 6.5
CVE-2022-22442

"IBM InfoSphere Information Server 11.7 could allow an authenticated user to access information restricted to users with elevated privileges due to i…

Patch available
Fix from $1,600 2022-11-03
Navigator Mobile MEDIUM 5.5
CVE-2022-38388

IBM Navigator Mobile Android 3.4.1.1 and 3.4.1.2 app could allow a local user to obtain sensitive information due to improper access control. IBM X-F…

Patch available
Fix from $1,600 2022-10-11
Sterling Partner Engagement Manager MEDIUM 6.5
CVE-2022-34334

IBM Sterling Partner Engagement Manager 2.0 does not invalidate session after logout which could allow an authenticated user to impersonate another u…

Patch available
Fix from $1,600 2022-10-10
Websphere Automation For Ibm Cloud Pak For Watson Aiops HIGH 8.8
CVE-2022-22493

IBM WebSphere Automation for Cloud Pak for Watson AIOps 1.4.2 is vulnerable to cross-site request forgery, caused by improper cookie attribute settin…

Fix: 1.4.3+
Fix from $1,950 2022-10-07
Infosphere Information Server MEDIUM 6.5
CVE-2022-36772

IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information that should only be available to a privilege…

Patch available
Fix from $1,600 2022-10-07
Infosphere Information Server MEDIUM 6.5
CVE-2022-41291

IBM InfoSphere Information Server 11.7 does not invalidate session after logout which could allow an authenticated user to impersonate another user o…

Patch available
Fix from $1,600 2022-10-07
Qradar Security Information And Event Manager MEDIUM 5.5
CVE-2022-30613

IBM QRadar SIEM 7.4 and 7.5 could disclose sensitive information via a local service to a privileged user. IBM X-Force ID: 227366.

Fix: 7.4.3+
Fix from $1,600 2022-10-07
Cics Tx MEDIUM 5.5
CVE-2022-34308

IBM CICS TX 11.1 could allow a local user to cause a denial of service due to improper load handling. IBM X-Force ID: 229437.

Patch available
Fix from $1,600 2022-10-07
Qradar Security Information And Event Manager HIGH 7.5
CVE-2022-22480

IBM QRadar SIEM 7.4 and 7.5 data node rebalancing does not function correctly when using encrypted hosts which could result in information disclosure…

Fix: 7.4.3+
Fix from $1,950 2022-10-07
Robotic Process Automation MEDIUM 6.5
CVE-2022-41294

IBM Robotic Process Automation 21.0.0, 21.0.1, 21.0.2, 21.0.3, and 21.0.4 is vulnerable to cross origin resource sharing using the bot api. IBM X-For…

Fix: after 21.0.4
Fix from $1,600 2022-10-06
Robotic Process Automation For Cloud Pak MEDIUM 6.1
CVE-2022-38709

IBM Robotic Process Automation 21.0.1, 21.0.2, and 21.0.3 for Cloud Pak is vulnerable to cross-site scripting. This vulnerability allows users to emb…

Fix: 21.0.4+
Fix from $1,600 2022-10-06
Robotic Process Automation MEDIUM 5.3
CVE-2022-36774

IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to man in the middle attacks through manipulation of the client proxy configu…

Fix: 21.0.3+
Fix from $1,600 2022-10-06
Robotic Process Automation MEDIUM 6.1
CVE-2022-22503

IBM Robotic Process Automation 21.0.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a ma…

Fix: 21.0.1+
Fix from $1,600 2022-10-06
Robotic Process Automation HIGH 7.5
CVE-2022-39168

IBM Robotic Process Automation Clients are vulnerable to proxy credentials being exposed in upgrade logs. IBM X-Force ID: 235422.

Patch available
Fix from $1,950 2022-09-29
Infosphere Information Server MEDIUM 6.5
CVE-2012-4818

IBM InfoSphere Information Server 8.1, 8.5, and 8,7 could allow a remote authenticated attacker to obtain sensitive information, caused by improper r…

Mitigation only
Fix from $1,600 2022-09-29