Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Security Siteprotector System CRITICAL 9.8
CVE-2020-4150

IBM SiteProtector Appliance 3.1.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authent…

Mitigation only
Fix from $2,300 2022-07-11
Security Siteprotector System MEDIUM 5.5
CVE-2020-4138

IBM SiteProtector Appliance 3.1.1 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 174049.

Mitigation only
Fix from $1,600 2022-07-11
Open Liberty HIGH 8.8
CVE-2022-22476

IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.7 and Open Liberty are vulnerable to identity spoofing by an authenticated user usin…

Fix: 22.0.0.8+
Fix from $1,950 2022-07-08
Security Verify Access HIGH 7.8
CVE-2022-22465

IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 could allow a local user to obtain elevated privileges due to improp…

Patch available
Fix from $1,950 2022-07-08
Security Verify Access HIGH 7.5
CVE-2022-22464

IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 uses weaker than expected cryptographic algorithms that could allow …

Patch available
Fix from $1,950 2022-07-08
Security Verify Access MEDIUM 6.5
CVE-2022-22463

IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 is vulnerable to SQL injection. A remote attacker could send special…

Patch available
Fix from $1,600 2022-07-08
Security Verify Access MEDIUM 5.4
CVE-2022-22370

IBM Security Verify Access 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed…

Patch available
Fix from $1,600 2022-07-08
Cics Tx MEDIUM 5.4
CVE-2022-34160

IBM CICS TX Standard and Advanced 11.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would …

Patch available
Fix from $1,600 2022-07-08
Cics Tx MEDIUM 5.4
CVE-2022-34166

IBM CICS TX Standard and Advanced 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…

Patch available
Fix from $1,600 2022-07-08
Cics Tx MEDIUM 5.4
CVE-2022-34167

IBM CICS TX Standard and Advanced 11.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript co…

Patch available
Fix from $1,600 2022-07-08
Cics Tx MEDIUM 5.4
CVE-2022-34306

IBM CICS TX Standard and Advanced 11.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could…

Patch available
Fix from $1,600 2022-07-08
Urbancode Deploy MEDIUM 5.5
CVE-2022-22367

IBM UrbanCode Deploy (UCD) 6.2.7.15, 7.0.5.10, 7.1.2.6, and 7.2.2.1 could disclose sensitive database information to a local user in plain text. IBM …

Patch available
Fix from $1,600 2022-07-01
Infosphere Information Server MEDIUM 5.4
CVE-2022-22373

An improper validation vulnerability in IBM InfoSphere Information Server 11.7 Pack for SAP Apps and BW Packs may lead to creation of directories and…

Patch available
Fix from $1,600 2022-07-01
Spectrum Protect Server CRITICAL 9.8
CVE-2022-22487

An IBM Spectrum Protect storage agent could allow a remote attacker to perform a brute force attack by allowing unlimited attempts to login to the st…

Fix: after 8.1.14
Fix from $2,300 2022-06-30
Spectrum Protect Plus Container Backup And Restore HIGH 8.8
CVE-2022-22472

IBM Spectrum Protect Plus Container Backup and Restore (10.1.5 through 10.1.10.2 for Kubernetes and 10.1.7 through 10.1.10.2 for Red Hat OpenShift) c…

Fix: 10.1.11+
Fix from $1,950 2022-06-30
Cloud Pak For Multicloud Management Monitoring HIGH 8.1
CVE-2021-38941

IBM CloudPak for Multicloud Monitoring 2.0 and 2.3 has a few containers running in privileged mode which is vulnerable to host information leakage or…

Patch available
Fix from $1,950 2022-06-30
Spectrum Protect Client HIGH 7.5
CVE-2022-22474

IBM Spectrum Protect 8.1.0.0 through 8.1.14.0 dsmcad, dsmc, and dsmcsvc processes incorrectly handle certain read operations on TCP/IP sockets. This …

Fix: after 8.1.14.0
Fix from $1,950 2022-06-30
Spectrum Protect Server MEDIUM 6.5
CVE-2022-22496

While a user account for the IBM Spectrum Protect Server 8.1.0.000 through 8.1.14 is being established, it may be configured to use SESSIONSECURITY=T…

Fix: after 8.1.14
Fix from $1,600 2022-06-30
Spectrum Protect Client MEDIUM 5.5
CVE-2022-22478

IBM Spectrum Protect Client 8.1.0.0 through 8.1.14.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 2…

Fix: after 8.1.14.0
Fix from $1,600 2022-06-30
Spectrum Protect Operations Center MEDIUM 5.3
CVE-2022-22494

IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14 could allow a remote attacker to gain details of the database, such as type and versi…

Fix: after 8.1.14.000
Fix from $1,600 2022-06-30
Security Guardium MEDIUM 6.1
CVE-2021-39074

IBM Security Guardium 11.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI th…

Mitigation only
Fix from $1,600 2022-06-29
Db2 HIGH 7.5
CVE-2022-22390

IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an information disclosure caused by improper privilege manag…

Mitigation only
Fix from $1,950 2022-06-24
Db2 MEDIUM 6.5
CVE-2022-22389

IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may terminate abnormally when …

Mitigation only
Fix from $1,600 2022-06-24
Jazz Team Server MEDIUM 5.4
CVE-2021-20543

IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which…

Patch available
Fix from $1,600 2022-06-24
Jazz Team Server MEDIUM 5.4
CVE-2021-29865

IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to hijack the clicking action of the victim. By persuading a…

Patch available
Fix from $1,600 2022-06-24
Jazz Team Server MEDIUM 5.4
CVE-2021-38871

IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary …

Patch available
Fix from $1,600 2022-06-24
Jazz Team Server MEDIUM 5.3
CVE-2021-38879

IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to se…

Patch available
Fix from $1,600 2022-06-24
Jazz Team Server MEDIUM 5.3
CVE-2021-20355

IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to se…

Patch available
Fix from $1,600 2022-06-24
Cics Tx CRITICAL 9.8
CVE-2022-31767EPSS 5%

IBM CICS TX Standard and Advanced 11.1 could allow a remote attacker to execute arbitrary commands on the system by sending a specially crafted reque…

Fix: 11.1+
Fix from $2,300 2022-06-24
Robotic Process Automation MEDIUM 5.4
CVE-2022-22502

IBM Robotic Process Automation 21.0.1 and 21.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript…

Fix: 21.0.1.5 / 21.0.2.2+
Fix from $1,600 2022-06-24