Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Vios HIGH 7.8
CVE-2021-38990

IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the mount command which could lead to code execu…

Mitigation only
Fix from $1,950 2022-01-10
Security Verify Access HIGH 7.5
CVE-2021-38921

IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly …

Patch available
Fix from $1,950 2022-01-10
Security Verify Access HIGH 7.5
CVE-2021-38957

IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 could disclose sensitive information due to hazardous input validation during QR code generation. …

Patch available
Fix from $1,950 2022-01-10
Security Verify Access MEDIUM 5.4
CVE-2021-38895

IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScri…

Patch available
Fix from $1,600 2022-01-10
Security Verify Access MEDIUM 5.3
CVE-2021-38956

IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 could disclose sensitive version information in HTTP response headers that could aid in further at…

Patch available
Fix from $1,600 2022-01-10
Powervm Hypervisor HIGH 7.5
CVE-2021-38918

IBM PowerVM Hypervisor FW860, FW940, FW950, and FW1010, through a specific sequence of VM management operations could lead to a violation of the isol…

Mitigation only
Fix from $1,950 2022-01-05
I MEDIUM 6.1
CVE-2021-38876

IBM i 7.2, 7.3, and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus …

Patch available
Fix from $1,600 2021-12-30
Power System Ac922 \(8335 Gtg\) Firmware MEDIUM 6.1
CVE-2021-38961

IBM OPENBMC OP910 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alteri…

Mitigation only
Fix from $1,600 2021-12-27
Cloud Pak For Security MEDIUM 6.5
CVE-2021-39013

IBM Cloud Pak for Security (CP4S) 1.7.2.0, 1.7.1.0, and 1.7.0.0 could allow an authenticated user to obtain sensitive information in HTTP responses t…

Mitigation only
Fix from $1,600 2021-12-22
Business Automation Workflow MEDIUM 6.5
CVE-2021-38900

IBM Business Process Manager 8.5 and 8.6 and IBM Business Automation Workflow 18.0, 19.0, 20.0 and 21.0 could allow a privileged user to obtain highl…

Patch available
Fix from $1,600 2021-12-21
Business Automation Workflow MEDIUM 5.4
CVE-2021-38893

IBM Business Process Manager 8.5 and 8.6 and IBM Business Automation Workflow 18.0, 19.0, 20.0 and 21.0 are vulnerable to stored cross-site scripting…

Patch available
Fix from $1,600 2021-12-21
Cloud Pak For Automation MEDIUM 5.4
CVE-2021-38966

IBM Cloud Pak for Automation 21.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the …

Mitigation only
Fix from $1,600 2021-12-21
Business Automation Workflow MEDIUM 5.4
CVE-2021-38883

IBM Business Automation Workflow 18.0, 19.0, 20,0 and 21.0 and IBM Business Process Manager 8.5 and 8.6 are vulnerable to cross-site scripting. This …

Patch available
Fix from $1,600 2021-12-17
Power Hardware Management Console \(7063 Cr1\) Firmware MEDIUM 5.9
CVE-2021-29847

BMC firmware (IBM Power System S821LC Server (8001-12C) OP825.50) configuration changed to allow an authenticated user to open an insecure communicat…

Mitigation only
Fix from $1,600 2021-12-15
Mq For Hpe Nonstop HIGH 7.8
CVE-2021-38950

IBM MQ on HPE NonStop 8.0.4 and 8.1.0 is vulnerable to a privilege escalation attack when SharedBindingsUserId is set to effective. IBM X-ForceID: 21…

Patch available
Fix from $1,950 2021-12-14
Spectrum Protect Plus CRITICAL 9.1
CVE-2021-39063

IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged a…

Fix: 10.1.9+
Fix from $2,300 2021-12-13
Spectrum Protect Plus HIGH 8.1
CVE-2021-39057

IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to …

Fix: 10.1.9+
Fix from $1,950 2021-12-13
I2 Analysts Notebook HIGH 7.8
CVE-2021-39050

IBM i2 Analyst's Notebook 9.2.0, 9.2.1, and 9.2.2 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local attacke…

Mitigation only
Fix from $1,950 2021-12-13
I2 Analysts Notebook HIGH 7.8
CVE-2021-39049

IBM i2 Analyst's Notebook 9.2.0, 9.2.1, and 9.2.2 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local attacke…

Mitigation only
Fix from $1,950 2021-12-13
Spectrum Protect Plus MEDIUM 5.9
CVE-2020-4496

The IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x server connection to an IBM Spectrum Protect Plus workload agent is subject to a man-in-the-m…

Fix: after 10.1.8.1
Fix from $1,600 2021-12-13
Spectrum Protect Operations Center MEDIUM 5.5
CVE-2021-38901

IBM Spectrum Protect Operations Center 7.1, under special configurations, could allow a local user to obtain highly sensitive information. IBM X-Forc…

Fix: 7.1.14+
Fix from $1,600 2021-12-13
Spectrum Protect Backup Archive Client MEDIUM 5.5
CVE-2021-39048

IBM Spectrum Protect Client 7.1 and 8.1 is vulnerable to a stack based buffer overflow, caused by improper bounds checking. A local attacker could ex…

Fix: after 8.1.12.0
Fix from $1,600 2021-12-13
Spectrum Copy Data Management CRITICAL 9.8
CVE-2021-39052

IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to access the Spring Boot console without authorization. IBM X-For…

Fix: after 2.2.13
Fix from $2,300 2021-12-13
Spectrum Copy Data Management CRITICAL 9.8
CVE-2021-39065

IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to execute arbitrary commands on the system, caused by improper va…

Fix: after 2.2.13
Fix from $2,300 2021-12-13
Spectrum Copy Data Management HIGH 7.5
CVE-2021-38947

IBM Spectrum Copy Data Management 2.2.13 and earlier uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highl…

Fix: after 2.2.13
Fix from $1,950 2021-12-13
Spectrum Copy Data Management HIGH 7.5
CVE-2021-39053

IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to obtain sensitive information, caused by the improper handling o…

Fix: after 2.2.13
Fix from $1,950 2021-12-13
Spectrum Copy Data Management HIGH 7.5
CVE-2021-39058

IBM Spectrum Copy Data Management 2.2.13 and earlier uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highl…

Fix: after 2.2.13
Fix from $1,950 2021-12-13
Spectrum Copy Data Management HIGH 7.5
CVE-2021-39064

IBM Spectrum Copy Data Management 2.2.13 and earlier has weak authentication and password rules and incorrectly handles default credentials for the S…

Fix: after 2.2.13
Fix from $1,950 2021-12-13
Spectrum Copy Data Management MEDIUM 5.4
CVE-2021-39054

IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to hijack the clicking action of the victim. By persuading a victi…

Fix: after 2.2.13
Fix from $1,600 2021-12-13
Powervm Hypervisor MEDIUM 6.5
CVE-2021-38937

IBM PowerVM Hypervisor FW940, FW950, and FW1010 could allow an authenticated user to cause the system to crash using a specially crafted IBMi Hypervi…

Mitigation only
Fix from $1,600 2021-12-10