Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Partner Engagement Manager HIGH 7.1
CVE-2022-22331

IBM SterlingPartner Engagement Manager 6.2.0 could allow a remote authenticated attacker to obtain sensitive information or modify user details cause…

Patch available
Fix from $1,950 2022-04-01
App Connect Enterprise Certified Container MEDIUM 6.5
CVE-2022-22404

IBM App Connect Enterprise Certified Container Dashboard UI (IBM App Connect Enterprise Certified Container 1.5, 2.0, 2.1, 3.0, and 3.1) may be vulne…

Fix: 4.0.0+
Fix from $1,600 2022-04-01
Partner Engagement Manager MEDIUM 6.2
CVE-2022-22328

IBM SterlingPartner Engagement Manager 6.2.0 could allow a malicious user to elevate their privileges and perform unintended operations to another us…

Patch available
Fix from $1,600 2022-04-01
Security Verify Access MEDIUM 6.5
CVE-2022-22311

IBM Security Verify Access could allow a user, using man in the middle techniques, to obtain sensitive information or possibly change some informatio…

Patch available
Fix from $1,600 2022-03-31
Iss Blackice Pc Protection CRITICAL 9.8
CVE-2003-5001

A vulnerability was found in ISS BlackICE PC Protection and classified as critical. Affected by this issue is the component Cross Site Scripting Dete…

Mitigation only
Fix from $2,300 2022-03-28
Iss Blackice Pc Protection MEDIUM 6.1
CVE-2003-5003

A vulnerability was found in ISS BlackICE PC Protection. It has been rated as problematic. Affected by this issue is the Update Handler. The manipula…

Mitigation only
Fix from $1,600 2022-03-28
Iss Blackice Pc Protection MEDIUM 5.3
CVE-2003-5002

A vulnerability was found in ISS BlackICE PC Protection. It has been declared as problematic. Affected by this vulnerability is the component Update …

Mitigation only
Fix from $1,600 2022-03-28
Power 9 Ac922 Firmware CRITICAL 9.1
CVE-2022-22374

The BMC (IBM Power 9 AC922 OP910, OP920, OP930, and OP940) may be subject to a firmware downgrade attack which may affect its ability to operate its …

Mitigation only
Fix from $2,300 2022-03-24
Mq Appliance MEDIUM 6.5
CVE-2022-22316

IBM MQ Appliance 9.2 CD and 9.2 LTS could allow an authenticated and authorized user to cause a denial of service due to incorrectly configured autho…

Fix: 9.2.0.5 / 9.2.5+
Fix from $1,600 2022-03-23
Spectrum Protect HIGH 8.8
CVE-2022-22394

The IBM Spectrum Protect 8.1.14.000 server could allow a remote attacker to bypass security restrictions, caused by improper enforcement of access co…

Patch available
Fix from $1,950 2022-03-21
Engineering Requirements Quality Assistant On Premises MEDIUM 6.5
CVE-2021-29899

IBM Engineering Requirements Quality Assistant prior to 3.1.3 could allow an authenticated user to cause a denial of service. IBM X-Force ID: 207413.

Fix: 3.1.3+
Fix from $1,600 2022-03-18
Spectrum Copy Data Management HIGH 7.5
CVE-2022-22354

IBM Spectrum Protect Plus 10.1.0.0 through 10.1.9.2 and IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 do not limit the length of a conne…

Fix: 2.2.15 / 10.1.9.3+
Fix from $1,950 2022-03-14
Spectrum Protect Operations Center HIGH 8.8
CVE-2022-22346

IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.13.xxx is vulnerable to cross-site request forgery which could allow an attacker to exec…

Fix: 8.1.14.000+
Fix from $1,950 2022-03-14
Spectrum Copy Data Management MEDIUM 6.5
CVE-2021-39051

IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 is vulnerable to server-side request forgery, caused by improper input of application serv…

Fix: 2.2.15.0+
Fix from $1,600 2022-03-14
Big Sql MEDIUM 6.5
CVE-2022-22353

IBM Big SQL on IBM Cloud Pak for Data 7.1.0, 7.1.1, 7.2.0, and 7.2.3 could allow an authenticated user with appropriate permissions to obtain sensiti…

Fix: after 7.2.3
Fix from $1,600 2022-03-14
Spectrum Copy Data Management MEDIUM 6.1
CVE-2022-22344

IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST…

Fix: 2.2.15.0+
Fix from $1,600 2022-03-14
Spectrum Copy Data Management MEDIUM 5.4
CVE-2021-39055

IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary …

Fix: 2.2.15.0+
Fix from $1,600 2022-03-14
Guardium Data Encryption HIGH 8.8
CVE-2021-39022

IBM Guardium Data Encryption (GDE) 4.0.0.0 and 5.0.0.0 saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutr…

Patch available
Fix from $1,950 2022-03-10
Datapower Gateway MEDIUM 5.3
CVE-2021-38910

IBM DataPower Gateway V10CD, 10.0.1, and 2108.4.1 could allow a remote attacker to bypass security restrictions, caused by the improper validation of…

Fix: after 2018.4.1.18
Fix from $1,600 2022-03-10
Guardium Data Encryption MEDIUM 5.3
CVE-2021-39025

IBM Guardium Data Encryption (GDE) 4.0.0.0 and 5.0.0.0 could disclose internal IP address information when the web backend is down. IBM X-Force 21386…

Patch available
Fix from $1,600 2022-03-10
Vios HIGH 8.6
CVE-2022-22351

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged trusted host user to exploit a vulnerability in the nimsh daemon to cause a denial o…

Fix: 3.1.1.60 / 3.1.2.40+
Fix from $1,950 2022-03-07
Vios MEDIUM 5.5
CVE-2021-38989

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service…

Fix: 3.1.1.60 / 3.1.2.40+
Fix from $1,600 2022-03-07
Vios MEDIUM 5.5
CVE-2021-38988

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service…

Fix: 3.1.1.60 / 3.1.2.40+
Fix from $1,600 2022-03-07
Vios MEDIUM 5.5
CVE-2021-38996

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service…

Mitigation only
Fix from $1,600 2022-03-02
Vios MEDIUM 5.5
CVE-2022-22350

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in CAA to cause a denial of service. IBM X-For…

Mitigation only
Fix from $1,600 2022-03-02
Mq MEDIUM 5.5
CVE-2022-22321

IBM MQ Appliance 9.2 CD and 9.2 LTS local messaging users stored with a password hash that provides insufficient protection. IBM X-Force ID: 218368.

Fix: 9.2.0.5 / 9.2.5+
Fix from $1,600 2022-03-01
Mq MEDIUM 5.4
CVE-2021-38986

IBM MQ Appliance 9.2 CD and 9.2 LTS does not invalidate session after logout which could allow an authenticated user to impersonate another user on t…

Fix: 9.2.0.4 / 9.2.5+
Fix from $1,600 2022-03-01
Spectrum Scale MEDIUM 5.5
CVE-2020-4925

A security vulnerability in the Spectrum Scale 5.0 and 5.1 allows a non-root user to overflow the mmfsd daemon with requests and preventing the daemo…

Patch available
Fix from $1,600 2022-03-01
Vios MEDIUM 5.5
CVE-2021-38993

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the smbcd daemon to cause a denial of servi…

Patch available
Fix from $1,600 2022-02-25
Vios MEDIUM 5.5
CVE-2021-38994

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service…

Patch available
Fix from $1,600 2022-02-24