Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Vios MEDIUM 5.5
CVE-2021-38995

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service…

Patch available
Fix from $1,600 2022-02-24
Websphere Application Server MEDIUM 5.4
CVE-2021-39038

IBM WebSphere Application Server 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.2 could allow a remote attacker to hijack t…

Fix: 9.0.5.12+
Fix from $1,600 2022-02-24
Sterling External Authentication Server HIGH 7.5
CVE-2022-22336

IBM Sterling External Authentication Server and IBM Sterling Secure Proxy 6.0.3.0, 6.0.2.0, and 3.4.3.2 could allow a remote user to consume resource…

Mitigation only
Fix from $1,950 2022-02-23
Sterling External Authentication Server MEDIUM 6.5
CVE-2022-22333

IBM Sterling Secure Proxy 6.0.3.0, 6.0.2.0, and 3.4.3.2 and IBM Sterling External Authentication Server are vulnerable a buffer overflow, due to the …

Patch available
Fix from $1,600 2022-02-23
Planning Analytics HIGH 7.8
CVE-2022-22308

IBM Planning Analytics 2.0 is vulnerable to a Remote File Include (RFI) attack. User input could be passed into file include commands and the web app…

Patch available
Fix from $1,950 2022-02-21
Maximo Asset Management HIGH 7.5
CVE-2021-38935

IBM Maximo Asset Management 7.6.1.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compr…

Patch available
Fix from $1,950 2022-02-18
Guardium Data Encryption MEDIUM 5.9
CVE-2021-39026

IBM Guardium Data Encryption (GDE) 5.0.0.2 and 5.0.0.3 could allow a remote attacker to obtain sensitive information, caused by the failure to proper…

Patch available
Fix from $1,600 2022-02-18
Mq HIGH 7.5
CVE-2021-39034

IBM MQ 9.1 LTS is vulnerable to a denial of service attack caused by an issue within the channel process. IBM X-Force ID: 213964.

Fix: after 9.1.0.9
Fix from $1,950 2022-02-17
Maximo Anywhere MEDIUM 6.5
CVE-2019-4291

IBM Maximo Anywhere 7.6.4.0 could allow an attacker to reverse engineer the application due to the lack of binary protection precautions. IBM X-Force…

Mitigation only
Fix from $1,600 2022-02-16
Cognos Analytics Mobile MEDIUM 6.5
CVE-2021-39080

Due to weak obfuscation, IBM Cognos Analytics Mobile for Android application prior to version 1.1.14 , an attacker could be able to reverse engineer …

Fix: 1.1.14+
Fix from $1,600 2022-02-14
Cognos Analytics Mobile MEDIUM 5.4
CVE-2021-39079

IBM Cognos Analytics Mobile for Android applications prior to version 1.1.14 is vulnerable to cross-site scripting. This vulnerability allows users t…

Fix: 1.1.14+
Fix from $1,600 2022-02-14
Power System Ac922 \(8335 Gtx\) Firmware HIGH 7.5
CVE-2021-38960

IBM OPENBMC OP920, OP930, and OP940 could allow an unauthenticated user to obtain sensitive information. IBM X-Force ID: 212047.

Mitigation only
Fix from $1,950 2022-02-04
Guardium Data Encryption MEDIUM 5.3
CVE-2021-39021

IBM Guardium Data Encryption (GDE) 5.0.0.2 behaves differently or sends different responses under different circumstances in a way that is observable…

Mitigation only
Fix from $1,600 2022-02-02
Security Verify Access CRITICAL 9.8
CVE-2021-39070

IBM Security Verify Access 10.0.0.0, 10.0.1.0 and 10.0.2.0 with the advanced access control authentication service enabled could allow an attacker to…

Mitigation only
Fix from $2,300 2022-02-02
Financial Transaction Manager HIGH 8.8
CVE-2021-39044

IBM Financial Transaction Manager 3.2.4 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthoriz…

Mitigation only
Fix from $1,950 2022-02-02
Financial Transaction Manager HIGH 8.8
CVE-2021-39066

IBM Financial Transaction Manager 3.2.4 does not invalidate session any existing session identifier gives an attacker the opportunity to steal authen…

Mitigation only
Fix from $1,950 2022-02-02
Security Guardium Insights HIGH 8.8
CVE-2021-29845

IBM Security Guardium Insights 3.0 could allow an authenticated user to perform unauthorized actions due to improper input validation. IBM X-Force ID…

Patch available
Fix from $1,950 2022-01-26
Security Guardium Insights MEDIUM 5.9
CVE-2021-29838

IBM Security Guardium Insights 3.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Stric…

Patch available
Fix from $1,600 2022-01-26
Websphere Application Server HIGH 8.8
CVE-2021-39031

IBM WebSphere Application Server - Liberty 17.0.0.3 through 22.0.0.1 could allow a remote authenticated attacker to conduct an LDAP injection. By usi…

Fix: after 22.0.0.1
Fix from $1,950 2022-01-25
Cognos Controller CRITICAL 9.8
CVE-2020-4877

IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could be vulnerable to unauthorized modifications by using public fields in public classes. IBM X-Fo…

Mitigation only
Fix from $2,300 2022-01-21
Cognos Controller CRITICAL 9.8
CVE-2020-4879

IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could allow a remote attacker to bypass security restrictions, caused by improper validation of auth…

Mitigation only
Fix from $2,300 2022-01-21
Cognos Controller HIGH 8.2
CVE-2020-4875

IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote at…

Mitigation only
Fix from $1,950 2022-01-21
Cognos Controller HIGH 8.2
CVE-2020-4876

IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote at…

Mitigation only
Fix from $1,950 2022-01-21
Soar MEDIUM 5.9
CVE-2021-29785

IBM Security SOAR V42 and V43could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Tran…

Fix: 43.1.49+
Fix from $1,600 2022-01-20
Websphere Application Server MEDIUM 6.5
CVE-2022-22310

IBM WebSphere Application Server Liberty 21.0.0.10 through 21.0.0.12 could provide weaker than expected security. A remote attacker could exploit thi…

Fix: after 21.0.0.12
Fix from $1,600 2022-01-19
Cloud Pak For Automation MEDIUM 5.4
CVE-2021-29872

IBM Cloud Pak for Automation 21.0.1 and 21.0.2 - Business Automation Studio Component is vulnerable to HTTP header injection, caused by improper vali…

Fix: 21.0.1 / 21.0.2+
Fix from $1,600 2022-01-18
Filenet Content Manager HIGH 8.8
CVE-2021-38965

IBM FileNet Content Manager 5.5.4, 5.5.6, and 5.5.7 could allow a remote authenticated attacker to execute arbitrary commands on the system by sendin…

Patch available
Fix from $1,950 2022-01-17
Sterling Gentran MEDIUM 5.5
CVE-2021-39032

IBM Sterling Gentran:Server for Microsoft Windows 5.3 stores potentially sensitive information in log files that could be read by a local user. IBM X…

Patch available
Fix from $1,600 2022-01-14
I MEDIUM 6.5
CVE-2021-39056

The IBM i 7.1, 7.2, 7.3, and 7.4 Extended Dynamic Remote SQL server (EDRSQL) could allow a remote authenticated user to send a specially crafted requ…

Patch available
Fix from $1,600 2022-01-13
Vios HIGH 7.8
CVE-2021-38991

IBM AIX 7.0, 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the lscore command which could lead to code…

Patch available
Fix from $1,950 2022-01-11