Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cognos Analytics CRITICAL 9.8
CVE-2021-38945

IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 could allow a remote attacker to upload arbitrary files, caused by improper content validation. IBM X…

Fix: 11.1.7+
Fix from $2,300 2022-06-24
Cognos Analytics MEDIUM 6.5
CVE-2021-29768

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a low level user to obtain sensitive information from the details of the 'Cloud Storage' …

Fix: 11.1.7+
Fix from $1,600 2022-06-24
Cognos Analytics MEDIUM 6.1
CVE-2021-39047

IBM Planning Analytics 2.0 and IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 are vulnerable to cross-site scripting. This vulnerability allows user…

Fix: 11.1.7+
Fix from $1,600 2022-06-24
Qradar Wincollect MEDIUM 5.3
CVE-2021-39006

IBM QRadar WinCollect Agent 10.0 and 10.0.1 could allow an attacker to obtain sensitive information due to missing best practices. IBM X-Force ID: 21…

No fix yet
Fix from $1,600 2022-06-21
Curam Social Program Management CRITICAL 9.8
CVE-2022-22317

IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate a…

Patch available
Fix from $2,300 2022-06-20
Curam Social Program Management CRITICAL 9.8
CVE-2022-22318

IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate a…

Patch available
Fix from $2,300 2022-06-20
Robotic Process Automation MEDIUM 5.5
CVE-2022-22414

IBM Robotic Process Automation 21.0.2 could allow a local user to obtain sensitive web service configuration credentials from system memory. IBM X-Fo…

Fix: 21.0.2.4+
Fix from $1,600 2022-06-20
Spectrum Protect Operations Center CRITICAL 9.8
CVE-2022-22485

In some cases, an unsuccessful attempt to log into IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14.000 does not cause the administrat…

Fix: after 8.1.14.000
Fix from $2,300 2022-06-17
Robotic Process Automation MEDIUM 6.5
CVE-2022-30607

IBM Robotic Process Automation 20.10.0, 20.12.5, 21.0.0, 21.0.1, and 21.0.2 contains a vulnerability that could allow a user to obtain sensitive info…

Patch available
Fix from $1,600 2022-06-17
Financial Transaction Manager CRITICAL 9.8
CVE-2019-4575

IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.2.0 through 3.2.9 is vulnerable to SQL injection. A remote attacker could…

Fix: after 3.2.9
Fix from $2,300 2022-06-15
Vios MEDIUM 5.5
CVE-2022-22444

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a local user to exploit a vulnerability in the lpd daemon to cause a denial of service. IBM X-Force I…

Patch available
Fix from $1,600 2022-06-15
Spectrum Copy Data Management MEDIUM 5.4
CVE-2022-30611

IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.15.0 is vulnerable to cross-site scripting, caused by improper validation of user-supplied inpu…

Fix: after 2.2.15.0
Fix from $1,600 2022-06-10
Spectrum Copy Data Management MEDIUM 5.3
CVE-2022-31769

IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.15.0 could allow a remote attacker to view product configuration information stored in PostgreS…

Fix: after 2.2.15.0
Fix from $1,600 2022-06-10
Spectrum Copy Data Management HIGH 8.8
CVE-2022-22479

IBM Spectrum Copy Data Management 2.2.0.0through 2.2.15.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malici…

Fix: after 2.2.15.0
Fix from $1,950 2022-06-10
Sevone Network Performance Management HIGH 8.8
CVE-2020-36529

A vulnerability classified as critical has been found in SevOne Network Management System up to 5.7.2.22. This affects the file traceroute.php of the…

Fix: after 5.7.2.22
Fix from $1,950 2022-06-07
Sevone Network Performance Management HIGH 8.8
CVE-2020-36530

A vulnerability classified as critical was found in SevOne Network Management System up to 5.7.2.22. This vulnerability affects the Alert Summary. Th…

Fix: after 5.7.2.22
Fix from $1,950 2022-06-07
Sevone Network Performance Management HIGH 8.8
CVE-2020-36531

A vulnerability, which was classified as critical, has been found in SevOne Network Management System up to 5.7.2.22. This issue affects the Device M…

Fix: after 5.7.2.22
Fix from $1,950 2022-06-07
Infosphere Information Server CRITICAL 9.8
CVE-2022-31768

IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could all…

Patch available
Fix from $2,300 2022-06-06
Spectrum Protect Plus HIGH 7.5
CVE-2022-22396

Credentials are printed in clear text in the IBM Spectrum Protect Plus 10.1.0.0 through 10.1.9.3 virgo log file in certain cases. Credentials could b…

Fix: 10.1.10+
Fix from $1,950 2022-06-06
Business Automation Workflow MEDIUM 6.5
CVE-2022-22361

IBM Business Automation Workflow traditional 21.0.1 through 21.0.3, 20.0.0.1 through 20.0.0.2, 19.0.0.1 through 19.0.0.3, 18.0.0.0 through 18.0.0.1, …

Fix: after 21.0.3
Fix from $1,600 2022-05-31
Aspera Faspex HIGH 7.5
CVE-2022-22497

IBM Aspera Faspex 4.4.1 and 5.0.0 could allow unauthorized access due to an incorrectly computed security token. IBM X-Force ID: 226951.

Patch available
Fix from $1,950 2022-05-24
I HIGH 8.8
CVE-2022-22495

IBM i 7.3, 7.4, and 7.5 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker…

Patch available
Fix from $1,950 2022-05-24
Power System S922 Firmware MEDIUM 6.8
CVE-2022-22309

The POWER systems FSP is vulnerable to unauthenticated logins through the serial port/TTY interface. This vulnerability can be more critical if the s…

Fix: 860.b0 / 940.60+
Fix from $1,600 2022-05-24
Elastic Storage System CRITICAL 9.1
CVE-2020-4926

A vulnerability in the Spectrum Scale 5.1 core component and IBM Elastic Storage System 6.1 could allow unauthorized access to user data or injection…

Fix: 5.1.3.0 / 6.1.3.0+
Fix from $2,300 2022-05-24
Websphere Application Server MEDIUM 5.9
CVE-2022-22365

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0, with the Ajax Proxy Web Application (AjaxProxy.war) deployed, is vulnerable to spoofing by a…

Fix: after 9.0.5.11
Fix from $1,600 2022-05-20
Jazz Team Server MEDIUM 5.4
CVE-2021-39043

IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arb…

Mitigation only
Fix from $1,600 2022-05-20
Security Identity Manager MEDIUM 5.9
CVE-2020-4970

IBM Security Identity Governance and Intelligence 5.2.4, 5.2.5, and 5.2.6 could allow a remote attacker to obtain sensitive information, caused by th…

Mitigation only
Fix from $1,600 2022-05-19
Datapower Gateway MEDIUM 6.1
CVE-2021-38944

IBM DataPower Gateway 10.0.2.0 through 1.0.3.0, 10.0.1.0 through 10.0.1.5, and 2018.4.1.0 through 2018.4.1.18 is vulnerable to HTTP header injection,…

Fix: after 2018.4.1.18
Fix from $1,600 2022-05-18
Open Liberty MEDIUM 6.5
CVE-2022-22475

IBM WebSphere Application Server Liberty and Open Liberty 17.0.0.3 through 22.0.0.5 are vulnerable to identity spoofing by an authenticated user. IBM…

Fix: after 22.0.0.5
Fix from $1,600 2022-05-17
Sterling B2b Integrator MEDIUM 6.5
CVE-2022-22482

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5 and 6.1.0.0 through 6.1.1.0 could allow an authenticated user to upload files th…

Fix: after 6.1.1.0
Fix from $1,600 2022-05-17