Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Datapower Gateway HIGH 7.5
CVE-2020-4994

IBM DataPower Gateway 10.0.1.0 through 10.0.1.4 and 2018.4.1.0 through 2018.4.1.17 could allow a remote user to cause a temporary denial of service b…

Fix: after 2018.4.1.17
Fix from $1,950 2022-05-17
Datapower Gateway HIGH 7.5
CVE-2021-38872

IBM DataPower Gateway 10.0.2.0, 10.0.3.0, 10.0.1.0 through 10.0.1.4, and 2018.4.1.0 through 2018.4.1.17 could allow a remote user to cause a denial o…

Fix: after 2018.4.1.17
Fix from $1,950 2022-05-17
Secure External Authentication Server MEDIUM 5.3
CVE-2021-29726

IBM Sterling Secure Proxy 6.0.3 and IBM Secure External Authentication Server 6.0.3 does not properly ensure that a certificate is actually associate…

Patch available
Fix from $1,600 2022-05-17
Spectrum Protect MEDIUM 5.5
CVE-2022-22484

IBM Spectrum Protect Operations Center 8.1.12 and 8.1.13 could allow a local attacker to obtain sensitive information, caused by plain text user acco…

Fix: 8.1.14+
Fix from $1,600 2022-05-17
Security Identity Governance And Intelligence MEDIUM 5.3
CVE-2020-4957

IBM Security Identity Governance and Intelligence 5.2.6 could disclose sensitive information in URL parameters that could aid in future attacks again…

Patch available
Fix from $1,600 2022-05-17
Websphere Application Server MEDIUM 6.5
CVE-2022-22393

IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.5 , with the adminCenter-1.0 feature configured, could allow an authenticated user t…

Fix: after 22.0.0.5
Fix from $1,600 2022-05-13
Mq For Hpe Nonstop MEDIUM 5.5
CVE-2022-22325

IBM MQ (IBM MQ for HPE NonStop 8.1.0) can inadvertently disclose sensitive information under certain circumstances to a local user from a stack trace…

Patch available
Fix from $1,600 2022-05-13
In Band Manageability HIGH 7.2
CVE-2021-0193

Improper authentication in the Intel(R) In-Band Manageability software before version 2.13.0 may allow a privileged user to potentially enable escala…

Fix: 2.13.0+
Fix from $1,950 2022-05-12
Robotic Process Automation CRITICAL 9.8
CVE-2022-22413

IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statemen…

Mitigation only
Fix from $2,300 2022-05-12
Spectrum Virtualize CRITICAL 9.8
CVE-2021-38969

IBM Spectrum Virtualize 8.2, 8.3, and 8.4 could allow an attacker to allow unauthorized access due to the reuse of support generated credentials. IBM…

Mitigation only
Fix from $2,300 2022-05-11
Jazz Foundation MEDIUM 5.4
CVE-2021-39059

IBM Jazz Foundation (IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2) is vulnerable to cross-site scripting. This vulnerability allows use…

Mitigation only
Fix from $1,600 2022-05-11
Infosphere Information Server On Cloud HIGH 7.8
CVE-2022-22454

IBM InfoSphere Information Server 11.7 could allow a locally authenticated attacker to execute arbitrary commands on the system by sending a speciall…

Patch available
Fix from $1,950 2022-05-10
Guardium Data Encryption MEDIUM 6.1
CVE-2021-39024

IBM Guardium Data Encryption (GDE) 4.0.0.0 and 5.0.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Java…

Patch available
Fix from $1,600 2022-05-10
Robotic Process Automation MEDIUM 5.4
CVE-2022-22319

IBM Robotic Process Automation 21.0.1 could allow a register user on the system to physically delete a queue that could cause disruption for any scri…

Mitigation only
Fix from $1,600 2022-05-09
I MEDIUM 5.3
CVE-2022-22481

IBM Navigator for i 7.2, 7.3, and 7.4 (heritage version) could allow a remote attacker to obtain access to the web interface without valid credential…

Patch available
Fix from $1,600 2022-05-09
Cloud Pak System HIGH 7.5
CVE-2021-20479

IBM Cloud Pak System 2.3.0 through 2.3.3.3 Interim Fix 1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt h…

Fix: 2.3.3.4+
Fix from $1,950 2022-05-09
Guardium Data Encryption HIGH 7.5
CVE-2021-39023

IBM Guardium Data Encryption (GDE) 4.0.0 and 5.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error mess…

Patch available
Fix from $1,950 2022-05-06
Guardium Data Encryption MEDIUM 5.0
CVE-2021-39027

IBM Guardium Data Encryption (GDE) 4.0.0 and 5.0.0 prepares a structured message for communication with another component, but encoding or escaping o…

No fix yet
Fix from $1,600 2022-05-06
Robotic Process Automation HIGH 7.5
CVE-2022-22433

IBM Robotic Process Automation 21.0.1 and 21.0.2 is vulnerable to External Service Interaction attack, caused by improper validation of user-supplied…

Fix: 21.0.1.5+
Fix from $1,950 2022-05-05
Robotic Process Automation MEDIUM 6.5
CVE-2022-22415

A vulnerability exists where an IBM Robotic Process Automation 21.0.1 regular user is able to obtain view-only access to some admin pages in the Cont…

Mitigation only
Fix from $1,600 2022-05-05
Guardium Data Encryption MEDIUM 5.3
CVE-2021-39020

IBM Guardium Data Encryption (GDE) 4.0.0.7 and lower stores sensitive information in URL parameters. This may lead to information disclosure if unaut…

Fix: after 4.0.0.7
Fix from $1,600 2022-05-05
Spectrum Scale HIGH 7.5
CVE-2022-22368

IBM Spectrum Scale 5.1.0 through 5.1.3.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive …

Fix: after 5.1.3.0
Fix from $1,950 2022-05-03
Maximo Application Suite HIGH 7.2
CVE-2021-29854

IBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. B…

Mitigation only
Fix from $1,950 2022-05-03
Cloud Pak For Business Automation MEDIUM 6.8
CVE-2021-29859

IBM ICP4A - User Management System Component (IBM Cloud Pak for Business Automation V21.0.3 through V21.0.3-IF008, V21.0.2 through V21.0.2-IF009, and…

Mitigation only
Fix from $1,600 2022-05-02
Urbancode Deploy HIGH 7.5
CVE-2021-39082

IBM UrbanCode Deploy (UCD) 7.1.1.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive inform…

Patch available
Fix from $1,950 2022-04-29
Infosphere Information Server MEDIUM 6.5
CVE-2022-22441

IBM InfoSphere Information Server 11.7 could allow an authenticated user to view information of higher privileged users and groups due to a privilege…

Mitigation only
Fix from $1,600 2022-04-28
Infosphere Information Server MEDIUM 6.1
CVE-2022-22427

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…

Mitigation only
Fix from $1,600 2022-04-28
Infosphere Information Server MEDIUM 5.4
CVE-2022-22322

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…

Mitigation only
Fix from $1,600 2022-04-28
Infosphere Information Server MEDIUM 5.4
CVE-2022-22443

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…

Mitigation only
Fix from $1,600 2022-04-28
Infosphere Information Server MEDIUM 5.4
CVE-2021-38952

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…

No fix yet
Fix from $1,600 2022-04-28