Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Maximo Asset Management MEDIUM 5.4
CVE-2022-35714

IBM Maximo Asset Management 7.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the We…

Patch available
Fix from $1,600 2022-08-26
Datapower Gateway HIGH 8.8
CVE-2022-31773

IBM DataPower Gateway V10CD, 10.0.1, and 2018.4.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and …

Fix: 10.5.0+
Fix from $1,950 2022-08-26
Mq CRITICAL 9.1
CVE-2022-22489

IBM MQ 8.0, (9.0, 9.1, 9.2 LTS), and (9.1 and 9.2 CD) are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A rem…

Patch available
Fix from $2,300 2022-08-19
Security Verify Governance CRITICAL 9.8
CVE-2022-22455

IBM Security Verify Governance Identity Manager 10.0 virtual appliance component performs an operation at a privilege level that is higher than the m…

Patch available
Fix from $2,300 2022-08-17
Sterling B2b Integrator CRITICAL 9.8
CVE-2021-39085

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 is vulnerable to SQL injec…

Fix: 6.0.3.6 / 6.1.0.5+
Fix from $2,300 2022-08-16
Sterling B2b Integrator MEDIUM 6.5
CVE-2021-39087

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 could allow an authenticat…

Fix: 6.0.3.6 / 6.1.0.5+
Fix from $1,600 2022-08-16
Sterling B2b Integrator MEDIUM 5.4
CVE-2021-39035

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 is vulnerable to cross-sit…

Fix: 6.0.3.6 / 6.1.0.5+
Fix from $1,600 2022-08-16
Sterling File Gateway MEDIUM 5.3
CVE-2021-39086

IBM Sterling File Gateway 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 could allow a remote attacker to obtain sensi…

Fix: 6.0.3.6 / 6.1.0.5+
Fix from $1,600 2022-08-16
Robotic Process Automation For Cloud Pak CRITICAL 9.8
CVE-2022-35280

IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 does not require that users should have strong passwords by default, which makes it easier …

Mitigation only
Fix from $2,300 2022-08-10
Infosphere Information Server HIGH 7.5
CVE-2022-35715

IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is retur…

Mitigation only
Fix from $1,950 2022-08-10
Workload Scheduler HIGH 7.1
CVE-2022-22369

IBM Workload Scheduler 9.4 and 9.5 could allow a local user to overwrite key system files which would cause the system to crash. IBM X-Force ID: 2211…

Mitigation only
Fix from $1,950 2022-08-10
Spectrum Scale Data Access Services MEDIUM 6.5
CVE-2022-22411

IBM Spectrum Scale Data Access Services (DAS) 5.1.3.1 could allow an authenticated user to insert code which could allow the attacker to manipulate c…

Patch available
Fix from $1,600 2022-08-10
Cics Tx HIGH 8.8
CVE-2022-34161

IBM CICS TX 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted …

Patch available
Fix from $1,950 2022-08-01
Cics Tx MEDIUM 6.8
CVE-2022-33955

IBM CICS TX 11.1 could allow allow an attacker with physical access to the system to execute code due using a back and refresh attack. IBM X-Force ID…

Patch available
Fix from $1,600 2022-08-01
Cics Tx MEDIUM 6.1
CVE-2022-34162

IBM CICS TX 11.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a r…

Mitigation only
Fix from $1,600 2022-08-01
Cics Tx MEDIUM 6.1
CVE-2022-34163

IBM CICS TX 11.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to …

Patch available
Fix from $1,600 2022-08-01
Cics Tx MEDIUM 5.5
CVE-2022-34164

IBM CICS TX 11.1 could allow a local user to impersonate another legitimate user due to improper input validation. IBM X-Force ID: 229338.

Patch available
Fix from $1,600 2022-08-01
Robotic Process Automation MEDIUM 6.5
CVE-2022-34338

IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could disclose sensitive information due to improper privilege management for storage provi…

Fix: 21.0.3+
Fix from $1,600 2022-08-01
Urbancode Deploy MEDIUM 6.5
CVE-2022-35716

IBM UrbanCode Deploy (UCD) 6.2.0.0 through 6.2.7.16, 7.0.0.0 through 7.0.5.11, 7.1.0.0 through 7.1.2.7, and 7.2.0.0 through 7.2.3.0 could allow an au…

Fix: 6.2.7.17 / 7.0.5.12+
Fix from $1,600 2022-08-01
Datapower Gateway CRITICAL 9.1
CVE-2022-31775

IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21 is vulnerable to an XML Exte…

Fix: 10.0.1.8 / 10.5.0.1+
Fix from $2,300 2022-08-01
Datapower Gateway HIGH 8.8
CVE-2022-31776

IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21 is vulnerable to server-side…

Fix: 10.5.0.1+
Fix from $1,950 2022-08-01
Robotic Process Automation HIGH 7.5
CVE-2022-22505

IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 contains a vulnerability that could allow IBM tenant credentials to be exposed. IBM X-Force…

Fix: 21.0.3+
Fix from $1,950 2022-08-01
Robotic Process Automation HIGH 7.2
CVE-2022-30616

IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a privileged user to elevate their privilege to platform administrator through …

Fix: 21.0.3+
Fix from $1,950 2022-08-01
Robotic Process Automation MEDIUM 6.5
CVE-2022-33169

IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to insufficiently protected credentials for users created via a bulk upload. …

Fix: after 21.0.3
Fix from $1,600 2022-08-01
Datapower Gateway MEDIUM 5.4
CVE-2022-31774

IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21 is vulnerable to cross-site …

Fix: 10.5.0.1+
Fix from $1,600 2022-08-01
Datapower Gateway MEDIUM 5.4
CVE-2022-32750

IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21 is vulnerable to cross-site …

Fix: 10.5.0.1+
Fix from $1,600 2022-08-01
Powervm Virtual I\/o Server CRITICAL 9.1
CVE-2022-35643

IBM PowerVM VIOS 3.1 could allow a remote attacker to tamper with system configuration or cause a denial of service. IBM X-Force ID: 230956.

Patch available
Fix from $2,300 2022-07-29
Qradar Security Information And Event Manager HIGH 7.8
CVE-2021-39088

IBM QRadar SIEM 7.3, 7.4, and 7.5 is vulnerable to local privilege escalation if this could be combined with other unknown vulnerabilities then privi…

Fix: 7.3.3 / 7.4.3+
Fix from $1,950 2022-07-28
Security Verify Information Queue HIGH 8.8
CVE-2022-35286

IBM Security Verify Information Queue 10.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unaut…

Patch available
Fix from $1,950 2022-07-26
Sterling Partner Engagement Manager HIGH 7.5
CVE-2022-35639

IBM Sterling Partner Engagement Manager 6.1, 6.2, and Cloud 22.2 do not limit the length of a connection which could cause the server to become unres…

Fix: 6.1.2.5 / 6.2.0.3+
Fix from $1,950 2022-07-26