Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Guardium Data Encryption HIGH 8.8
CVE-2021-20378

IBM Guardium Data Encryption (GDE) 3.0.0.2 and 4.0.0.4 does not invalidate session after logout which could allow an authenticated user to impersonat…

Patch available
Fix from $1,950 2021-07-07
Guardium Data Encryption HIGH 7.5
CVE-2021-20379

IBM Guardium Data Encryption (GDE) 3.0.0.3 and 4.0.0.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt hig…

Patch available
Fix from $1,950 2021-07-07
Guardium Data Encryption HIGH 7.5
CVE-2021-20415

IBM Guardium Data Encryption (GDE) 4.0.0.4 uses an inadequate account lockout setting that could allow a remote attacker to brute force account crede…

Patch available
Fix from $1,950 2021-07-07
Guardium Data Encryption HIGH 7.5
CVE-2021-20474

IBM Guardium Data Encryption (GDE) 3.0.0.2 and 4.0.0.4 does not perform any authentication for functionality that requires a provable user identity o…

Patch available
Fix from $1,950 2021-07-07
Guardium Data Encryption MEDIUM 5.3
CVE-2021-20416

IBM Guardium Data Encryption (GDE) 3.0.0.3 and 4.0.0.4 could allow a remote attacker to obtain sensitive information, caused by the failure to set th…

Patch available
Fix from $1,600 2021-07-07
Datacap Navigator HIGH 8.8
CVE-2020-4902

IBM Datacap Taskmaster Capture (IBM Datacap Navigator 9.1.7) is vulnerable to SQL injection. A remote attacker could send specially crafted SQL state…

Patch available
Fix from $1,950 2021-07-01
Datacap Navigator MEDIUM 5.4
CVE-2020-4935

IBM Datacap Fastdoc Capture (IBM Datacap Navigator 9.1.7 ) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary …

Patch available
Fix from $1,600 2021-07-01
Cognos Analytics MEDIUM 6.5
CVE-2021-20461

IBM Cognos Analytics 10.0 and 11.1 is susceptible to a weakness in the implementation of the System Appearance configuration setting. An attacker cou…

Fix: 11.0.13 / 11.1.7+
Fix from $1,600 2021-06-30
Spectrum Protect Plus MEDIUM 5.5
CVE-2021-20490

IBM Spectrum Protect Plus 10.1.0 through 10.1.8 could allow a local user to cause a denial of service due to insecure file permission settings. IBM X…

Fix: after 10.1.8
Fix from $1,600 2021-06-29
Planning Analytics MEDIUM 5.4
CVE-2021-20477

IBM Planning Analytics 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI th…

Mitigation only
Fix from $1,600 2021-06-29
Security Identity Manager Adapter HIGH 8.8
CVE-2021-20574

IBM Security Identity Manager Adapters 6.0 and 7.0 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially cra…

Patch available
Fix from $1,950 2021-06-28
Security Identity Manager Adapter MEDIUM 6.5
CVE-2021-20494

IBM Security Identity Manager Adapters 6.0 and 7.0 are vulnerable to a heap based buffer overflow, caused by improper bounds. An authenticared user c…

Patch available
Fix from $1,600 2021-06-28
Security Identity Manager Adapter MEDIUM 6.5
CVE-2021-20572

IBM Security Identity Manager Adapters 6.0 and 7.0 are vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A remote auth…

Patch available
Fix from $1,600 2021-06-28
Security Identity Manager Adapter MEDIUM 6.5
CVE-2021-20573

IBM Security Identity Manager Adapters 6.0 and 7.0 are vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote authe…

Patch available
Fix from $1,600 2021-06-28
Business Automation Workflow MEDIUM 5.4
CVE-2021-29775

IBM Business Automation Workflow 19.0.03 and 20.0 and IBM Cloud Pak for Automation 20.0.3-IF002 and 21.0.1 are vulnerable to cross-site scripting. Th…

Patch available
Fix from $1,600 2021-06-28
Security Verify Privilege Manager HIGH 7.8
CVE-2020-4609

IBM Security Sevret Server (IBM Security Verify Privilege Manager 10.8.2) is vulnerable to a buffer overflow, caused by improper bounds checking. A l…

Fix: 11.0+
Fix from $1,950 2021-06-25
Security Verify Privilege Manager HIGH 7.8
CVE-2020-4610

IBM Security Secret Server (IBM Security Verify Privilege Manager 10.8.2 ) could allow a local user to execute code due to improper integrity checks.…

Fix: 11.0+
Fix from $1,950 2021-06-25
Security Verify MEDIUM 5.4
CVE-2021-29676

IBM Security Verify (IBM Security Verify Privilege Vault 10.9.66) is vulnerable to link injection. By persuading a victim to click on a specially-cra…

Fix: 10.9.66+
Fix from $1,600 2021-06-25
Security Verify MEDIUM 5.4
CVE-2021-29677

IBM Security Verify (IBM Security Verify Privilege Vault 10.9.66) is vulnerable to cross-site scripting. This vulnerability allows users to embed arb…

Fix: 10.9.66+
Fix from $1,600 2021-06-25
Db2 HIGH 8.1
CVE-2020-4945

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated user to overwrite arbirary files due to improper …

Patch available
Fix from $1,950 2021-06-24
Db2 HIGH 7.5
CVE-2021-29703

Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of service as the server terminates abnormally when executing…

Patch available
Fix from $1,950 2021-06-24
Db2 MEDIUM 6.5
CVE-2021-20579

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a user who can create a view or inline …

Patch available
Fix from $1,600 2021-06-24
Db2 MEDIUM 6.5
CVE-2021-29777

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5, under specific circumstance of a table being dropp…

Patch available
Fix from $1,600 2021-06-24
Aix HIGH 7.1
CVE-2021-29706

IBM AIX 7.1 could allow a non-privileged local user to exploit a vulnerability in the trace facility to expose sensitive information or cause a denia…

Patch available
Fix from $1,950 2021-06-17
Resilient Security Orchestration Automation And Response HIGH 7.5
CVE-2021-20566

IBM Resilient SOAR V38.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM…

Patch available
Fix from $1,950 2021-06-16
Db2 HIGH 7.5
CVE-2021-29702

Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1.4 and 11.5.5 is vulnerable to a denial of service as the server terminates abnorma…

Fix: after 11.5.5.0
Fix from $1,950 2021-06-16
Security Identity Manager MEDIUM 6.5
CVE-2021-20483

IBM Security Identity Manager 6.0.2 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, a remote authenticat…

Patch available
Fix from $1,600 2021-06-16
Security Identity Manager MEDIUM 6.5
CVE-2021-20488

IBM Security Identity Manager 6.0.2 could allow an authenticated malicious user to change the passwords of other users in the Windows AD environment …

Patch available
Fix from $1,600 2021-06-16
Financial Transaction Manager MEDIUM 5.4
CVE-2020-5000

IBM Financial Transaction Manager 3.2.0 through 3.2.8 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaS…

Patch available
Fix from $1,600 2021-06-15
Websphere Application Server HIGH 8.8
CVE-2021-29754

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a privilege escalation vulnerability when using the SAML Web Inbound Trust A…

Fix: 7.0.0.45 / 8.0.0.15+
Fix from $1,950 2021-06-11