Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Tivoli Netcool\/omnibus Webgui MEDIUM 5.4
CVE-2021-29819

IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to em…

Fix: 8.1.0.24+
Fix from $1,600 2021-09-20
Tivoli Netcool\/omnibus Webgui MEDIUM 5.4
CVE-2021-29820

IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to em…

Fix: 8.1.0.24+
Fix from $1,600 2021-09-20
Tivoli Netcool\/omnibus Webgui MEDIUM 5.4
CVE-2021-29821

IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to em…

Fix: 8.1.0.24+
Fix from $1,600 2021-09-20
Db2 HIGH 7.5
CVE-2021-29825

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could disclose sensitive information when using ADMIN_CMD with LOAD or BACKUP. IBM …

Mitigation only
Fix from $1,950 2021-09-16
Websphere Application Server MEDIUM 5.3
CVE-2021-29842

IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0 and Liberty 17.0.0.3 through 21.0.0.9 could allow a remote user to enumerate usernames due to a d…

Fix: after 21.0.0.9
Fix from $1,600 2021-09-16
Db2 MEDIUM 5.1
CVE-2021-29763

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 under very specific conditions, could allow a local user to keep runn…

Mitigation only
Fix from $1,600 2021-09-16
Qradar Security Information And Event Manager HIGH 7.5
CVE-2021-29750

IBM QRadar SIEM 7.3 and 7.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. …

Patch available
Fix from $1,950 2021-09-15
Security Guardium MEDIUM 5.4
CVE-2021-29773

IBM Security Guardium 10.6 and 11.3 could allow a remote authenticated attacker to obtain sensitive information or modify user details caused by an i…

Patch available
Fix from $1,600 2021-09-15
Security Guardium MEDIUM 6.5
CVE-2021-20433

IBM Security Guardium 11.3 could allow a an authenticated user to obtain sensitive information that could be used in further attacks against the syst…

Mitigation only
Fix from $1,600 2021-09-15
Financial Transaction Manager MEDIUM 5.4
CVE-2021-29841

IBM Financial Transaction Manager 3.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in …

Mitigation only
Fix from $1,600 2021-09-14
Security Secret Server MEDIUM 5.3
CVE-2021-20569

IBM Security Secret Server up to 11.0 could allow an attacker to enumerate usernames due to improper input validation. IBM X-Force ID: 199243.

Fix: 11.0+
Fix from $1,600 2021-09-14
Security Secret Server MEDIUM 5.3
CVE-2021-20582

IBM Security Secret Server up to 11.0 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties…

Fix: 11.0+
Fix from $1,600 2021-09-14
Planning Analytics MEDIUM 5.4
CVE-2021-29852

IBM Planning Analytics 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI th…

Patch available
Fix from $1,600 2021-09-01
Openpages With Watson HIGH 8.8
CVE-2021-29907

IBM OpenPages with Watson 8.1 and 8.2 could allow an authenticated user to upload a file that could execute arbitrary code on the system. IBM X-Force…

Fix: 8.1.0.2.1 / 8.2.0.2+
Fix from $1,950 2021-08-31
Sterling External Authentication Server HIGH 7.5
CVE-2021-29722

IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decry…

Patch available
Fix from $1,950 2021-08-30
Sterling External Authentication Server HIGH 7.5
CVE-2021-29723

IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decry…

Patch available
Fix from $1,950 2021-08-30
Maximo Application Suite MEDIUM 5.4
CVE-2021-29743

IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScri…

Fix: after 8.4
Fix from $1,600 2021-08-30
Maximo Application Suite MEDIUM 5.4
CVE-2021-29744

IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code…

Patch available
Fix from $1,600 2021-08-27
Api Connect CRITICAL 9.8
CVE-2021-29772

IBM API Connect 5.0.0.0 through 5.0.8.11 could allow a user to potentially inject code due to unsanitized user input. IBM X-Force ID: 202774.

Fix: after 5.0.8.11
Fix from $2,300 2021-08-26
Api Connect CRITICAL 9.1
CVE-2021-29715

IBM API Connect 5.0.0.0 through 5.0.8.11 could alllow a remote user to obtain sensitive information or conduct denial of serivce attacks due to open …

Fix: after 5.0.8.11
Fix from $2,300 2021-08-26
Vios HIGH 7.8
CVE-2021-29801

IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the kernel to gain root privileges. IBM X-Force …

Patch available
Fix from $1,950 2021-08-26
Vios MEDIUM 5.5
CVE-2021-29727

IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 20…

Patch available
Fix from $1,600 2021-08-26
Vios MEDIUM 5.5
CVE-2021-29862

IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM…

Patch available
Fix from $1,600 2021-08-26
Resilient Security Orchestration Automation And Response HIGH 7.5
CVE-2021-29802

IBM Security SOAR performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifie…

Fix: 1.6.1+
Fix from $1,950 2021-08-23
Resilient Security Orchestration Automation And Response HIGH 7.5
CVE-2021-29704

IBM Security SOAR uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

Fix: 42.0+
Fix from $1,950 2021-08-23
Datapower Gateway MEDIUM 6.5
CVE-2020-4992

IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.16 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious a…

Fix: after 2018.4.1.16
Fix from $1,600 2021-08-17
Api Connect MEDIUM 5.4
CVE-2020-4706

IBM API Connect 5.0.0.0 through 5.0.8.10 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. By sendi…

Fix: after 5.0.8.10
Fix from $1,600 2021-08-17
Qradar Security Information And Event Manager MEDIUM 6.5
CVE-2021-29880

IBM QRadar SIEM 7.4.3 GA - 7.4.3 Fix Pack 1 when using domains or multi-tenancy could be vulnerable to information disclosure between tenants by rout…

Patch available
Fix from $1,600 2021-08-13
Maximo Asset Management CRITICAL 9.8
CVE-2021-20509

IBM Maximo Asset Management 7.6.0 and 7.6.1 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the sys…

Fix: 7.6.1.2+
Fix from $2,300 2021-08-12
Security Guardium CRITICAL 9.8
CVE-2021-20418

IBM Security Guardium 11.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise use…

Mitigation only
Fix from $2,300 2021-08-11