Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Security Guardium HIGH 7.5
CVE-2021-20427

IBM Security Guardium 11.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Fo…

Mitigation only
Fix from $1,950 2021-08-11
Content Navigator MEDIUM 6.5
CVE-2021-29714

IBM Content Navigator 3.0.CD could allow a malicious user to cause a denial of service due to improper input validation. IBM X-Force ID: 200968.

Mitigation only
Fix from $1,600 2021-08-09
Tivoli Workload Scheduler MEDIUM 5.3
CVE-2021-20349

IBM Tivoli Workload Scheduler 9.4 and 9.5 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local attacker could …

Mitigation only
Fix from $1,600 2021-08-09
Powervm HIGH 7.5
CVE-2021-29765

IBM PowerVM Hypervisor FW940 and FW950 could allow an attacker to obtain sensitive information if they gain service access to the FSP. IBM X-Force ID…

Mitigation only
Fix from $1,950 2021-08-04
Api Connect MEDIUM 5.4
CVE-2020-4707

IBM API Connect 5.0.0.0 through 5.0.8.11 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in…

Fix: after 5.0.8.11
Fix from $1,600 2021-08-04
Cloud Pak For Security HIGH 7.2
CVE-2021-29696

IBM Cloud Pak for Security (CP4S) 1.5.0.0, 1.5.1.0, 1.6.0.0, 1.6.1.0, 1.7.0.0, and 1.7.1.0 could allow a remote authenticated attacker to execute arb…

Mitigation only
Fix from $1,950 2021-08-02
Cloud Pak For Security MEDIUM 5.3
CVE-2021-20539

IBM Cloud Pak for Security (CP4S) 1.5.0.0, 1.5.1.0, 1.6.0.0, 1.6.1.0, 1.7.0.0, and 1.7.1.0 could disclose sensitive information to an unauthorized us…

Patch available
Fix from $1,600 2021-08-02
Cloud Pak For Security MEDIUM 5.3
CVE-2021-20540

IBM Cloud Pak for Security (CP4S) 1.5.0.0, 1.5.1.0, 1.6.0.0, 1.6.1.0, 1.7.0.0, and 1.7.1.0 could disclose sensitive information to an unauthorized us…

Patch available
Fix from $1,600 2021-08-02
Cloud Pak For Security MEDIUM 5.3
CVE-2021-20541

IBM Cloud Pak for Security (CP4S) 1.5.0.0, 1.5.1.0, 1.6.0.0, 1.6.1.0, 1.7.0.0, and 1.7.1.0 could disclose sensitive information to an unauthorized us…

Patch available
Fix from $1,600 2021-08-02
Qradar User Behavior Analytics HIGH 8.8
CVE-2021-29757

IBM QRadar User Behavior Analytics 4.1.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthori…

Patch available
Fix from $1,950 2021-08-02
Vios HIGH 7.8
CVE-2021-29741

IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user to exploit a vulnerability in Korn Shell (ksh) to gain root privileges. IBM X-Force ID: 20147…

Patch available
Fix from $1,950 2021-08-02
Partner Engagement Manager CRITICAL 9.8
CVE-2021-29781

IBM Partner Engagement Manager 2.0 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization flaw. B…

Patch available
Fix from $2,300 2021-07-30
Websphere Application Server HIGH 8.8
CVE-2021-29736

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote user to gain elevated privileges on the system. IBM X-Force ID: 201300.

Fix: after 9.0.5.8
Fix from $1,950 2021-07-30
Engineering Lifecycle Optimization Engineering Insights MEDIUM 6.3
CVE-2020-4974

IBM Jazz Foundation products are vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requ…

No fix yet
Fix from $1,600 2021-07-28
Engineering Lifecycle Optimization Engineering Insights MEDIUM 5.4
CVE-2020-5004

IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI…

Mitigation only
Fix from $1,600 2021-07-28
Qradar Security Information And Event Manager CRITICAL 9.1
CVE-2021-20399

IBM Qradar SIEM 7.3.0 to 7.3.3 Patch 8 and 7.4.0 to 7.4.3 GA is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data.…

Fix: 7.3.3 / 7.4.3+
Fix from $2,300 2021-07-27
Sterling B2b Integrator MEDIUM 5.4
CVE-2021-20562

IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_3 and 6.1.0.0 through 6.1.0.2 vulnerable to cross-site scripting. This vulnerabi…

Fix: after 6.1.0.2
Fix from $1,600 2021-07-27
Qradar Security Information And Event Manager HIGH 7.5
CVE-2021-20337

IBM QRadar SIEM 7.3.0 to 7.3.3 Patch 8 and 7.4.0 to 7.4.3 GA uses weaker than expected cryptographic algorithms that could allow an attacker to decry…

Fix: 7.3.3 / 7.4.3+
Fix from $1,950 2021-07-26
I2 Ibase MEDIUM 6.5
CVE-2020-4623

IBM i2 iBase 8.9.13 could allow a local authenticated attacker to execute arbitrary code on the system, caused by a DLL search order hijacking flaw. …

Patch available
Fix from $1,600 2021-07-26
I2 Analysts Notebook MEDIUM 6.5
CVE-2021-20431

IBM i2 Analyst's Notebook Premium 9.2.0, 9.2.1, and 9.2.2 does not invalidate session after logout which could allow an an attacker to obtain sensiti…

Patch available
Fix from $1,600 2021-07-26
I2 Analyze MEDIUM 6.5
CVE-2021-29770

IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) could allow an authenticated user to perform unauthorized actions due to h…

Patch available
Fix from $1,600 2021-07-26
Sterling Connect Direct User Interface MEDIUM 5.4
CVE-2021-20560

IBM Sterling Connect:Direct Browser User Interface 1.4.1.1 and 1.5.0.2 could allow a remote attacker to hijack the clicking action of the victim. By …

Patch available
Fix from $1,600 2021-07-26
I2 Analyze MEDIUM 5.3
CVE-2021-20430

IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) could allow a remote attacker to obtain sensitive information when a detai…

Patch available
Fix from $1,600 2021-07-26
I2 Analyze MEDIUM 5.3
CVE-2021-29766

IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) could allow a remote attacker to obtain sensitive information when a detai…

Patch available
Fix from $1,600 2021-07-26
I2 Analysts Notebook MEDIUM 5.3
CVE-2021-29767

IBM i2 Analyst's Notebook Premium 9.2.0, 9.2.1, and 9.2.2 could allow a remote attacker to obtain sensitive information when a detailed technical err…

Patch available
Fix from $1,600 2021-07-26
Hardware Management Console HIGH 7.8
CVE-2021-29707

IBM HMC (Hardware Management Console) V9.1.910.0 and V9.2.950.0 could allow a local user to escalate their privileges to root access on a restricted …

Mitigation only
Fix from $1,950 2021-07-19
Engineering Lifecycle Optimization MEDIUM 5.4
CVE-2020-5031

IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScrip…

Mitigation only
Fix from $1,600 2021-07-19
Engineering Lifecycle Optimization MEDIUM 5.4
CVE-2021-20507

IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScrip…

Mitigation only
Fix from $1,600 2021-07-19
Qradar Security Information And Event Manager MEDIUM 6.5
CVE-2020-4980

IBM QRadar SIEM 7.3 and 7.4 uses less secure methods for protecting data in transit between hosts when encrypt host connections is not enabled as wel…

Fix: 7.3.3 / 7.4.3+
Fix from $1,600 2021-07-16
Infosphere Data Replication CRITICAL 9.8
CVE-2020-4821

IBM InfoSphere Data Replication 11.4 and IBM InfoSphere Change Data Capture for z/OS 10.2.1, under certain configurations, could allow a user to bypa…

Patch available
Fix from $2,300 2021-07-16