Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Websphere Mq HIGH 7.5
CVE-2012-2201

IBM WebSphere MQ 7.1 is vulnerable to a denial of service, caused by an error when handling user ids. A remote attacker could exploit this vulnerabil…

Mitigation only
Fix from $1,950 2022-09-29
Rational Change MEDIUM 6.1
CVE-2012-2160

IBM Rational Change 5.3 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit …

Patch available
Fix from $1,600 2022-09-29
Qradar User Behavior Analytics MEDIUM 6.5
CVE-2022-36771

IBM QRadar User Behavior Analytics could allow an authenticated user to obtain sensitive information from that they should not have access to. IBM X-…

Fix: 4.1.9+
Fix from $1,600 2022-09-28
Websphere Application Server MEDIUM 6.5
CVE-2022-35282

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, …

Fix: 7.0.0.45 / 8.0.0.15+
Fix from $1,600 2022-09-28
Jazz For Service Management MEDIUM 5.4
CVE-2022-35722

IBM Jazz for Service Management is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…

Fix: 1.1.3.16+
Fix from $1,600 2022-09-28
Application Gateway MEDIUM 5.4
CVE-2022-22387

IBM Application Gateway is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus …

Patch available
Fix from $1,600 2022-09-28
Infosphere Information Server MEDIUM 5.4
CVE-2022-40748

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…

Mitigation only
Fix from $1,600 2022-09-23
Sterling Partner Engagement Manager HIGH 7.1
CVE-2022-34348

IBM Sterling Partner Engagement Manager 6.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacke…

Fix: 6.1.2.6 / 6.2.0.4+
Fix from $1,950 2022-09-23
Common Cryptographic Architecture MEDIUM 5.5
CVE-2022-22423

IBM Common Cryptographic Architecture (CCA 5.x MTM for 4767 and CCA 7.x MTM for 4769) could allow a local user to cause a denial of service due to im…

Fix: 5.7.12 / 7.3.44+
Fix from $1,600 2022-09-23
Jazz For Service Management MEDIUM 5.4
CVE-2022-35721

IBM Jazz for Service Management 1.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript cod…

Patch available
Fix from $1,600 2022-09-23
Maximo Asset Management HIGH 8.1
CVE-2022-40616

IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, and 7.6.1.3 could allow a user to bypass authentication and obtain sensitive information or perform tas…

Mitigation only
Fix from $1,950 2022-09-21
Spectrum Protect Plus HIGH 7.5
CVE-2022-40608

IBM Spectrum Protect Plus 10.1.6 through 10.1.11 Microsoft File Systems restore operation can download any file on the target machine by manipulating…

Fix: after 10.1.11
Fix from $1,950 2022-09-19
Spectrum Protect Plus MEDIUM 5.9
CVE-2022-40234

Versions of IBM Spectrum Protect Plus prior to 10.1.12 (excluding 10.1.12) include the private key information for a certificate inside the generated…

Fix: 10.1.12+
Fix from $1,600 2022-09-19
Maximo Application Suite HIGH 7.5
CVE-2021-38924

IBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message…

Patch available
Fix from $1,950 2022-09-14
Vios HIGH 7.8
CVE-2022-34356

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to obtain root privileges. I…

Patch available
Fix from $1,950 2022-09-13
Vios HIGH 7.8
CVE-2022-36768

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the invscout command to obtain root privile…

Patch available
Fix from $1,950 2022-09-13
Db2 MEDIUM 6.5
CVE-2022-22483

IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to an information disclosure in some scenarios due to unauthorized …

Patch available
Fix from $1,600 2022-09-13
Db2 MEDIUM 6.5
CVE-2022-35637

IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a denial of service after entering a malformed SQL statement int…

Patch available
Fix from $1,600 2022-09-13
Websphere Application Server MEDIUM 5.4
CVE-2022-34336

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav…

Patch available
Fix from $1,600 2022-09-13
Control Desk MEDIUM 5.3
CVE-2022-22330

IBM Control Desk 7.6.1 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attack…

Mitigation only
Fix from $1,600 2022-09-13
Websphere Application Server MEDIUM 5.4
CVE-2022-34165

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.9 are vulnerable to HTTP…

Fix: 22.0.0.9+
Fix from $1,600 2022-09-09
Cognos Analytics HIGH 8.1
CVE-2022-36773

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote att…

Fix: 11.1.7 / 11.2.3+
Fix from $1,950 2022-09-01
Cognos Analytics HIGH 7.5
CVE-2022-30614

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to a denial of service via email flooding caused by sending a specially-crafted request…

Fix: 11.1.7 / 11.2.3+
Fix from $1,950 2022-09-01
Cognos Analytics MEDIUM 5.5
CVE-2021-39009

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 stores user credentials in plain clear text which can be read by a local privileged user. IBM X-Force…

Fix: 11.1.7 / 11.2.3+
Fix from $1,600 2022-09-01
Cognos Analytics MEDIUM 5.5
CVE-2021-39045

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a local attacker to obtain information due to the autocomplete feature on password input …

Fix: 11.1.7 / 11.2.3+
Fix from $1,600 2022-09-01
Cognos Analytics MEDIUM 6.5
CVE-2020-4301

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and un…

Fix: 11.1.7 / 11.2.3+
Fix from $1,600 2022-09-01
Cognos Analytics MEDIUM 6.5
CVE-2021-20468

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and un…

Fix: 11.1.7 / 11.2.3+
Fix from $1,600 2022-09-01
Cognos Analytics MEDIUM 6.5
CVE-2021-29823

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and un…

Fix: 11.1.7 / 11.2.3+
Fix from $1,600 2022-09-01
Security Identity Manager MEDIUM 6.1
CVE-2021-29864

IBM Security Identity Manager 6.0 and 6.0.2 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a…

Mitigation only
Fix from $1,600 2022-08-30
Engineering Test Management MEDIUM 5.4
CVE-2021-38934

IBM Engineering Test Management 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaS…

Mitigation only
Fix from $1,600 2022-08-29