Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Urbancode Deploy HIGH 8.8
CVE-2022-22315

IBM UrbanCode Deploy (UCD) 7.2.2.1 could allow an authenticated user with special permissions to obtain elevated privileges due to improper handling …

Fix: 6.2.7.15 / 7.0.5.10+
Fix from $1,950 2022-04-27
Qradar Security Information And Event Manager CRITICAL 9.8
CVE-2021-38869

IBM QRadar SIEM 7.3, 7.4, and 7.5 in some situations may not automatically log users out after they exceede their idle timeout. IBM X-Force ID: 20834…

Fix: 7.3.3 / 7.4.3+
Fix from $2,300 2022-04-27
Qradar Security Information And Event Manager HIGH 7.5
CVE-2021-38878

IBM QRadar 7.3, 7.4, and 7.5 could allow a malicious actor to impersonate an actor due to key exchange without entity authentication. IBM X-Force ID:…

Fix: 7.3.3 / 7.4.3+
Fix from $1,950 2022-04-27
Qradar Security Information And Event Manager HIGH 7.5
CVE-2021-38919

IBM QRadar SIEM 7.3, 7.4, and 7.5 in some senarios may reveal authorized service tokens to other QRadar users. IBM X-Force ID: 210021

Fix: 7.3.3 / 7.4.3+
Fix from $1,950 2022-04-27
Security Verify Password Synchronization MEDIUM 6.5
CVE-2022-22312

IBM Security Identity Manager (IBM Security Verify Password Synchronization Plug-in for Windows AD 10.x) is vulnerable to a denial of service, caused…

Fix: 10.0.4+
Fix from $1,600 2022-04-27
Security Verify Password Synchronization MEDIUM 6.5
CVE-2022-22323

IBM Security Identity Manager (IBM Security Verify Password Synchronization Plug-in for Windows AD 10.x) is vulnerable to a denial of service, caused…

Fix: 10.0.4+
Fix from $1,600 2022-04-27
Qradar Security Information And Event Manager MEDIUM 5.3
CVE-2021-38939

IBM QRadar SIEM 7.3, 7.4, and 7.5 stores potentially sensitive information in log files that could be read by an user with access to creating domains…

Fix: 7.3.3 / 7.4.3+
Fix from $1,600 2022-04-27
Ibm Rational Lifecycle Integration Adapter For Windchill MEDIUM 5.3
CVE-2021-34587

In Bender/ebee Charge Controllers in multiple versions a long URL could lead to webserver crash. The URL is used as input of an sprintf to a stack va…

Fix: 5.11.2 / 5.12.5+
Fix from $1,600 2022-04-27
Planning Analytics Workspace HIGH 7.8
CVE-2022-22392

IBM Planning Analytics Local 2.0 could allow an attacker to upload arbitrary executable files which, when executed by an unsuspecting victim could re…

Mitigation only
Fix from $1,950 2022-04-25
Planning Analytics Workspace HIGH 8.0
CVE-2021-39040

IBM Planning Analytics Workspace 2.0 could be vulnerable to malicious file upload by not validating the file types or sizes. Attackers can make use o…

Mitigation only
Fix from $1,950 2022-04-25
Cognos Analytics HIGH 8.8
CVE-2021-38886

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and un…

Patch available
Fix from $1,950 2022-04-22
Cognos Analytics MEDIUM 6.5
CVE-2021-20464

IBM Cognos Analytics PowerPlay (IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7) could be vulnerable to an XML Bomb attack by a malicious authenticat…

Patch available
Fix from $1,600 2022-04-22
Cognos Analytics MEDIUM 6.5
CVE-2021-38904

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 could allow a remote attacker to obtain credentials from a user's browser via incorrect autocomplete …

Patch available
Fix from $1,600 2022-04-22
Cognos Analytics MEDIUM 5.4
CVE-2021-38903

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote…

Patch available
Fix from $1,600 2022-04-22
Cognos Analytics MEDIUM 5.4
CVE-2021-38946

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript …

Patch available
Fix from $1,600 2022-04-22
Maximo Asset Management MEDIUM 5.4
CVE-2022-22435

IBM Maximo Asset Management 7.6.1.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the …

Patch available
Fix from $1,600 2022-04-21
Maximo Asset Management MEDIUM 5.4
CVE-2022-22436

IBM Maximo Asset Management 7.6.1.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the …

Patch available
Fix from $1,600 2022-04-21
Security Guardium HIGH 7.5
CVE-2021-39076

IBM Security Guardium 10.5 and 11.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive information.…

Mitigation only
Fix from $1,950 2022-04-19
Security Guardium MEDIUM 5.9
CVE-2021-39072

IBM Security Guardium 11.3 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transp…

Mitigation only
Fix from $1,600 2022-04-19
Sterling B2b Integrator MEDIUM 6.5
CVE-2021-39033

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5 and 6.1.0.0 through 6.1.1.0 could allow a remote attacker to obtain sensitive in…

Fix: 6.0.3.6 / 6.1.1.1+
Fix from $1,600 2022-04-19
System Storage Ds8000 Management Console Firmware HIGH 7.5
CVE-2021-38929

IBM System Storage DS8000 Management Console (HMC) R8.5 88.5x.x.x, R9.1 89.1x.0.0, and R9.2 89.2x.0.0 could allow a remote attacker to obtain sensiti…

Mitigation only
Fix from $1,950 2022-04-11
System Storage Ds8000 Management Console Firmware HIGH 7.5
CVE-2021-38930

IBM System Storage DS8000 Management Console (HMC) R8.5 88.5x.x.x, R9.1 89.1x.0.0, and R9.2 89.2x.0.0 could allow a remote attacker to obtain sensiti…

Mitigation only
Fix from $1,950 2022-04-11
Curam Social Program Management MEDIUM 5.4
CVE-2021-39068

IBM Curam Social Program Management 8.0.1 and 7.0.11 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaSc…

Patch available
Fix from $1,600 2022-04-11
Sterling B2b Integrator HIGH 8.8
CVE-2020-4668

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.3, and 6.1.1.0 is vulnerable to cross-site request forger…

Fix: after 6.1.0.3
Fix from $1,950 2022-04-08
Planning Analytics HIGH 7.3
CVE-2022-22339

IBM Planning Analytics 2.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized request…

Patch available
Fix from $1,950 2022-04-08
Watson Query HIGH 7.2
CVE-2022-22410

IBM Watson Query with Cloud Pak for Data as a Service could allow an authenticated user to obtain sensitive information that would allow them to exam…

Mitigation only
Fix from $1,950 2022-04-06
Mq Appliance MEDIUM 6.5
CVE-2022-22356

IBM MQ Appliance 9.2 CD and 9.2 LTS could allow an attacker to enumerate account credentials due to an observable discrepancy in valid and invalid lo…

Patch available
Fix from $1,600 2022-04-05
Mq Appliance MEDIUM 5.3
CVE-2022-22355

IBM MQ Appliance 9.2 CD and 9.2 LTS are vulnerable to a denial of service in the Login component of the application which could allow an attacker to …

Patch available
Fix from $1,600 2022-04-05
Urbancode Deploy HIGH 7.5
CVE-2022-22327

IBM UrbanCode Deploy (UCD) 7.0.5, 7.1.0, 7.1.1, and 7.1.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt …

Fix: 7.0.5.9 / 7.1.2.5+
Fix from $1,950 2022-04-01
Partner Engagement Manager HIGH 7.5
CVE-2022-22332

IBM Sterling Partner Engagement Manager 6.2.0 could allow an attacker to impersonate another user due to missing revocation mechanism for the JWT tok…

Patch available
Fix from $1,950 2022-04-01