Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Financial Transaction Manager CRITICAL 9.1
CVE-2020-5003

IBM Financial Transaction Manager 3.2.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker co…

Mitigation only
Fix from $2,300 2021-06-11
Websphere Application Server Nd HIGH 8.8
CVE-2021-20517

IBM WebSphere Application Server Network Deployment 8.5 and 9.0 could allow a remote authenticated attacker to traverse directories. An attacker coul…

Fix: 8.5.5.20 / 9.0.5.8+
Fix from $1,950 2021-06-07
Datapower Gateway MEDIUM 5.3
CVE-2020-5008

IBM DataPower Gateway 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.14 stores sensitive information in GET request parameters. This may l…

Fix: after 2018.4.1.14
Fix from $1,600 2021-06-07
Qradar Advisor With Watson HIGH 7.5
CVE-2021-20380

IBM QRadar Advisor With Watson App 1.1 through 2.5 as used on IBM QRadar SIEM 7.4 could allow a remote user to obtain sensitive information from HTTP…

Fix: 2.6.1+
Fix from $1,950 2021-06-03
Collaborative Lifecycle Management HIGH 8.8
CVE-2020-4495

IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to bypass security restrictions, caused by improper access control. By…

Patch available
Fix from $1,950 2021-06-02
Collaborative Lifecycle Management MEDIUM 6.5
CVE-2020-4732

IBM Jazz Foundation and IBM Engineering products could allow an authenticated user to obtain sensitive information due to lack of security restrictio…

Patch available
Fix from $1,600 2021-06-02
Collaborative Lifecycle Management MEDIUM 6.5
CVE-2021-20371

IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to obtain sensitive information when an error message is returned in t…

Patch available
Fix from $1,600 2021-06-02
Collaborative Lifecycle Management MEDIUM 5.4
CVE-2020-4977

IBM Engineering Lifecycle Optimization - Publishing is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary …

Patch available
Fix from $1,600 2021-06-02
Collaborative Lifecycle Management MEDIUM 5.4
CVE-2020-5030

IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScrip…

Patch available
Fix from $1,600 2021-06-02
Collaborative Lifecycle Management MEDIUM 5.4
CVE-2021-20338

IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScrip…

Patch available
Fix from $1,600 2021-06-02
Collaborative Lifecycle Management MEDIUM 5.4
CVE-2021-20343

IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to se…

Patch available
Fix from $1,600 2021-06-02
Collaborative Lifecycle Management MEDIUM 5.4
CVE-2021-20345

IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to se…

Patch available
Fix from $1,600 2021-06-02
Collaborative Lifecycle Management MEDIUM 5.4
CVE-2021-20346

IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to se…

Patch available
Fix from $1,600 2021-06-02
Collaborative Lifecycle Management MEDIUM 5.4
CVE-2021-20347

IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to se…

Patch available
Fix from $1,600 2021-06-02
Collaborative Lifecycle Management MEDIUM 5.4
CVE-2021-20348

IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to se…

Patch available
Fix from $1,600 2021-06-02
Collaborative Lifecycle Management MEDIUM 5.4
CVE-2021-29668

IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScrip…

Patch available
Fix from $1,600 2021-06-02
Collaborative Lifecycle Management MEDIUM 5.4
CVE-2021-29670

IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScrip…

Patch available
Fix from $1,600 2021-06-02
Security Verify Access HIGH 7.8
CVE-2021-29665

IBM Security Verify Access 20.07 is vulnerable to a stack based buffer overflow, caused by improper bounds checking which could allow a local attacke…

Mitigation only
Fix from $1,950 2021-06-01
Spectrum Scale HIGH 7.8
CVE-2021-29740

IBM Spectrum Scale 5.0.0 through 5.0.5.6 and 5.1.0 through 5.1.0.3 system core component is affected by a format string security vulnerability. An at…

Fix: 5.0.5.7 / 5.1.1.0+
Fix from $1,950 2021-06-01
Cognos Analytics CRITICAL 10.0
CVE-2020-4561

IBM Cognos Analytics 11.0 and 11.1 DQM API allows submitting of all control requests in unauthenticated sessions. This allows a remote attacker who c…

Patch available
Fix from $2,300 2021-06-01
Cognos Analytics HIGH 8.8
CVE-2020-4520

IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to inject malicious HTML code that when viewed by the authenticated victim would exe…

Patch available
Fix from $1,950 2021-06-01
Cognos Analytics HIGH 8.2
CVE-2020-4300

IBM Cognos Analytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could e…

Patch available
Fix from $1,950 2021-06-01
Cognos Analytics HIGH 7.5
CVE-2019-4723

IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain credentials from a user's browser via incorrect autocomplete settings in N…

Patch available
Fix from $1,950 2021-06-01
Cognos Analytics HIGH 7.5
CVE-2019-4724

IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain credentials from a user's browser via incorrect autocomplete settings in N…

Patch available
Fix from $1,950 2021-06-01
Application Gateway HIGH 7.5
CVE-2021-20576

IBM Security Verify Access 20.07 could allow a remote attacker to send a specially crafted HTTP GET request that could cause the application to crash.

Patch available
Fix from $1,950 2021-06-01
Cognos Analytics HIGH 7.1
CVE-2019-4730

IBM Cognos Analytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could e…

Patch available
Fix from $1,950 2021-06-01
Cognos Analytics MEDIUM 6.5
CVE-2019-4471

IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain sensitive information, caused by the failure to set the secure flag for a …

Patch available
Fix from $1,600 2021-06-01
Cognos Analytics MEDIUM 5.4
CVE-2019-4653

IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the W…

Patch available
Fix from $1,600 2021-06-01
Cognos Analytics MEDIUM 5.4
CVE-2020-4354

IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the W…

Patch available
Fix from $1,600 2021-06-01
Security Verify Access MEDIUM 5.3
CVE-2021-20585

IBM Security Verify Access 20.07 could disclose sensitive information in HTTP server headers that could be used in further attacks against the system…

Mitigation only
Fix from $1,600 2021-06-01