Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Engineering Lifecycle Optimization MEDIUM 5.4
CVE-2021-29713

IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web U…

Patch available
Fix from $1,600 2021-10-27
Planning Analytics MEDIUM 5.3
CVE-2021-20526

IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote at…

Patch available
Fix from $1,600 2021-10-27
Business Automation Workflow MEDIUM 6.1
CVE-2021-29835

IBM Business Automation Workflow 18.0, 19.0, 20.0, and 21.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary…

Patch available
Fix from $1,600 2021-10-22
Spectrum Virtualize HIGH 8.1
CVE-2021-29873

IBM Flash System 900 could allow an authenticated attacker to obtain sensitive information and cause a denial of service due to a restricted shell es…

Fix: 8.4.0.0+
Fix from $1,950 2021-10-21
Qradar Advisor MEDIUM 6.1
CVE-2021-38896

IBM QRadar Advisor 2.5 through 2.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the…

Fix: after 2.6.1
Fix from $1,600 2021-10-20
Security Risk Manager On Cp4s MEDIUM 5.4
CVE-2021-29912

IBM Security Risk Manager on CP4S 1.7.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code i…

Patch available
Fix from $1,600 2021-10-19
Business Automation Workflow MEDIUM 5.4
CVE-2021-29878

IBM Business Automation Workflow 18.0, 19.0, 20.0, and 21.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary…

Patch available
Fix from $1,600 2021-10-18
Cognos Analytics HIGH 8.8
CVE-2021-29679

IBM Cognos Analytics 11.1.7 and 11.2.0 could allow an authenticated user to execute code remotely due to incorrectly neutralizaing user-contrlled inp…

Patch available
Fix from $1,950 2021-10-15
Cognos Analytics HIGH 8.8
CVE-2021-29745

IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to priviledge escalation where a lower evel user could have access to the 'New Job' page to whic…

Patch available
Fix from $1,950 2021-10-15
Data Risk Manager HIGH 7.5
CVE-2021-38862

IBM Data Risk Manager (iDNA) 2.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive inform…

Mitigation only
Fix from $1,950 2021-10-12
Data Risk Manager MEDIUM 6.5
CVE-2021-38915

IBM Data Risk Manager 2.0.6 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 209947.

Mitigation only
Fix from $1,600 2021-10-12
Sterling File Gateway MEDIUM 6.5
CVE-2020-4654

IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated user to obtain sensitive information due to improper permission contro…

Fix: 5.2.6.5_4 / 6.0.3.5+
Fix from $1,600 2021-10-08
App Connect Enterprise Certified Container MEDIUM 5.5
CVE-2021-29906

IBM App Connect Enterprise Certified Container 1.0, 1.1, 1.2, 1.3, 1.4 and 1.5 could disclose sensitive information to a local user when it is config…

Mitigation only
Fix from $1,600 2021-10-08
Sterling File Gateway HIGH 8.8
CVE-2021-20489

IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and …

Fix: after 6.1.0.3
Fix from $1,950 2021-10-07
Sterling B2b Integrator HIGH 7.5
CVE-2021-20584

IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow a remote attacker to upload arbitrary files, caused by improper access controls. IBM X-…

Fix: after 6.1.0.2
Fix from $1,950 2021-10-07
Sterling File Gateway MEDIUM 6.1
CVE-2021-20481

IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScrip…

Fix: after 6.1.0.1
Fix from $1,600 2021-10-07
Sterling B2b Integrator MEDIUM 6.1
CVE-2021-20561

IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScrip…

Fix: after 6.1.0.2
Fix from $1,600 2021-10-07
Sterling B2b Integrator MEDIUM 5.4
CVE-2021-20571

IBM Sterling B2B Integrator 5.2.0.0 through 6.1.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary …

Fix: after 6.1.0.3
Fix from $1,600 2021-10-07
Sterling B2b Integrator MEDIUM 6.5
CVE-2021-20375

IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated user to intercept and replace a message sent by another user due to im…

Fix: after 6.1.0.1
Fix from $1,600 2021-10-07
Sterling File Gateway MEDIUM 6.5
CVE-2021-20473

IBM Sterling File Gateway User Interface 2.2.0.0 through 6.1.1.0 does not invalidate session after logout which could allow an authenticated user to …

Fix: after 6.1.0.1
Fix from $1,600 2021-10-07
Ts7700 Firmware CRITICAL 9.8
CVE-2021-29908

The IBM TS7700 Management Interface is vulnerable to unauthenticated access. By accessing a specially-crafted URL, an attacker may gain administrativ…

Mitigation only
Fix from $2,300 2021-10-06
Powervm Hypervisor Firmware CRITICAL 9.1
CVE-2021-38923

IBM PowerVM Hypervisor FW1010 could allow a privileged user to gain access to another VM due to assigning duplicate WWPNs. IBM X-Force ID: 210162.

Mitigation only
Fix from $2,300 2021-10-06
Sterling B2b Integrator CRITICAL 9.8
CVE-2021-29798

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted S…

Fix: after 6.1.0.3
Fix from $2,300 2021-10-06
Sterling B2b Integrator CRITICAL 9.8
CVE-2021-29903

IBM Sterling B2B Integrator Standard Edition 5.2.6.0 through 6.1.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted S…

Fix: after 6.1.0.3
Fix from $2,300 2021-10-06
Sterling B2b Integrator HIGH 8.8
CVE-2021-29837

IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 is vulnerable to cross-site request forgery which could allow an attacker to exe…

Fix: after 6.1.0.3
Fix from $1,950 2021-10-06
Sterling B2b Integrator HIGH 7.5
CVE-2021-38925

IBM Sterling B2B Integrator Standard Edition 5.2.0. 0 through 6.1.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker…

Fix: after 6.1.0.3
Fix from $1,950 2021-10-06
Sterling B2b Integrator MEDIUM 5.4
CVE-2021-29764

IBM Sterling B2B Integrator 5.2.0.0 through 6.1.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary …

Fix: after 6.1.0.3
Fix from $1,600 2021-10-06
Sterling B2b Integrator MEDIUM 5.4
CVE-2021-29836

IBM Sterling B2B Integrator Standard Edition 5.2.0.0. through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed…

Fix: after 6.1.0.3
Fix from $1,600 2021-10-06
Sterling B2b Integrator MEDIUM 5.4
CVE-2021-29855

IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed …

Fix: after 6.1.0.3
Fix from $1,600 2021-10-06
Cloud Pak For Security CRITICAL 9.8
CVE-2021-20578

IBM Cloud Pak for Security (CP4S) 1.7.0.0, 1.7.1.0, 1.7.2.0, and 1.8.0.0 could allow an attacker to perform unauthorized actions due to improper or m…

Patch available
Fix from $2,300 2021-09-30