Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Power9 System Firmware CRITICAL 9.1
CVE-2021-20487

IBM Power9 Self Boot Engine(SBE) could allow a privileged user to inject malicious code and compromise the integrity of the host firmware bypassing t…

Mitigation only
Fix from $2,300 2021-05-26
Websphere Application Server HIGH 8.2
CVE-2021-20492

IBM WebSphere Application Server 8.0, 8.5, 9.0, and Liberty Java Batch is vulnerable to an XML External Entity Injection (XXE) attack when processing…

Fix: after 21.0.0.5
Fix from $1,950 2021-05-26
Db2 HIGH 7.8
CVE-2019-4588

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to execute arbitrary code …

Mitigation only
Fix from $1,950 2021-05-26
Cloud Pak For Data MEDIUM 6.5
CVE-2021-20486

IBM Cloud Pak for Data 3.0 could allow an authenticated user to obtain sensitive information when installed with additional plugins. IBM X-Force ID: …

Patch available
Fix from $1,600 2021-05-26
Spectrum Scale MEDIUM 6.7
CVE-2021-29708

IBM Spectrum Scale 5.1.0.1 could allow a local with access to the GUI pod container to obtain sensitive cryptographic keys that could allow them to e…

Mitigation only
Fix from $1,600 2021-05-25
8335 Gca Firmware MEDIUM 6.5
CVE-2021-29695

IBM Host firmware for LC-class Systems could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafte…

Mitigation only
Fix from $1,600 2021-05-25
Security Guardium CRITICAL 9.8
CVE-2021-20426

IBM Security Guardium 11.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication…

Patch available
Fix from $2,300 2021-05-24
Security Guardium HIGH 8.8
CVE-2020-4990

IBM Security Guardium 11.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attac…

Patch available
Fix from $1,950 2021-05-24
Security Guardium HIGH 7.8
CVE-2021-20389

IBM Security Guardium 11.2 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 195770.

Patch available
Fix from $1,950 2021-05-24
Security Guardium HIGH 7.5
CVE-2021-20419

IBM Security Guardium 11.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. I…

Patch available
Fix from $1,950 2021-05-24
Security Guardium HIGH 7.2
CVE-2021-20385

IBM Security Guardium 11.2 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted re…

Patch available
Fix from $1,950 2021-05-24
Security Guardium HIGH 7.2
CVE-2021-20557

IBM Security Guardium 11.2 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted req…

Patch available
Fix from $1,950 2021-05-24
Security Guardium MEDIUM 6.1
CVE-2021-20386

IBM Security Guardium 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI th…

Patch available
Fix from $1,600 2021-05-24
Security Guardium MEDIUM 5.3
CVE-2021-20428

IBM Security Guardium 11.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the b…

Patch available
Fix from $1,600 2021-05-24
Infosphere Information Server MEDIUM 5.3
CVE-2021-29681

IBM InfoSphere Information Server 11.7 could allow an attacker to obtain sensitive information by injecting parameters into an HTML query. This infor…

Mitigation only
Fix from $1,600 2021-05-21
Security Identity Manager HIGH 8.8
CVE-2021-29686

IBM Security Identity Manager 7.0.2 could allow an authenticated user to bypass security and perform actions that they should not have access to. IBM…

Mitigation only
Fix from $1,950 2021-05-20
Gpfs.tct.server HIGH 7.5
CVE-2020-4850

IBM Spectrum Scale 1.1.1.0 through 1.1.8.4 Transparent Cloud Tiering could allow a remote attacker to obtain sensitive information, caused by the lef…

Mitigation only
Fix from $1,950 2021-05-20
Security Identity Manager HIGH 7.5
CVE-2021-29688

IBM Security Identity Manager 7.0.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned…

Patch available
Fix from $1,950 2021-05-20
Security Identity Manager HIGH 7.5
CVE-2021-29691

IBM Security Identity Manager 7.0.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authe…

Patch available
Fix from $1,950 2021-05-20
Security Identity Manager MEDIUM 6.5
CVE-2021-29683

IBM Security Identity Manager 7.0.2 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 199998.

Mitigation only
Fix from $1,600 2021-05-20
Security Identity Manager MEDIUM 5.9
CVE-2021-29692

IBM Security Identity Manager 7.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Stri…

Patch available
Fix from $1,600 2021-05-20
Security Identity Manager MEDIUM 5.3
CVE-2021-29682

IBM Security Identity Manager 7.0.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned…

Mitigation only
Fix from $1,600 2021-05-20
Security Identity Manager MEDIUM 5.3
CVE-2021-29687

IBM Security Identity Manager 7.0.2 could allow a remote user to enumerate usernames due to a difference of responses from valid and invalid login at…

Mitigation only
Fix from $1,600 2021-05-20
Maximo Asset Management MEDIUM 5.4
CVE-2021-20374

IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScri…

Patch available
Fix from $1,600 2021-05-19
Control Center MEDIUM 5.4
CVE-2021-20528

IBM Control Center 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI th…

Patch available
Fix from $1,600 2021-05-19
Control Center MEDIUM 5.3
CVE-2021-20529

IBM Control Center 6.2.0.0 could allow a user to obtain sensitive version information that could be used in further attacks against the system. IBM X…

Patch available
Fix from $1,600 2021-05-19
Infosphere Information Server HIGH 7.5
CVE-2021-29747

IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain highly sensitive information due to a vulnerability in the authenticat…

Mitigation only
Fix from $1,950 2021-05-17
Planning Analytics Cloud CRITICAL 9.1
CVE-2020-4669

IBM Planning Analytics Local 2.0 connects to a MongoDB server. MongoDB, a document-oriented database system, is listening on the remote port, and it …

Patch available
Fix from $2,300 2021-05-17
Planning Analytics Cloud CRITICAL 9.1
CVE-2020-4670

IBM Planning Analytics Local 2.0 connects to a Redis server. The Redis server, an in-memory data structure store, running on the remote host is not p…

Patch available
Fix from $2,300 2021-05-17
Planning Analytics Local HIGH 7.5
CVE-2020-4985

IBM Planning Analytics Local 2.0 could allow an attacker to obtain sensitive information due to accepting body parameters in a query. IBM X-Force ID:…

Mitigation only
Fix from $1,950 2021-05-14