Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Qradar User Behavior Analytics HIGH 7.5
CVE-2021-20393

IBM QRadar User Behavior Analytics 1.0.0 through 4.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error …

Fix: 4.1.1+
Fix from $1,950 2021-05-14
Qradar User Behavior Analytics MEDIUM 6.1
CVE-2021-20392

IBM QRadar User Behavior Analytics 1.0.0 through 4.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Java…

Fix: 4.1.0+
Fix from $1,600 2021-05-14
Cloud Pak For Security MEDIUM 5.9
CVE-2021-20564

IBM Cloud Pak for Security (CP4S) 1.4.0.0, 1.5.0.0, 1.5.0.1, 1.6.0.0, and 1.6.0.1 could allow a remote attacker to obtain sensitive information, caus…

Mitigation only
Fix from $1,600 2021-05-14
Qradar User Behavior Analytics MEDIUM 5.3
CVE-2021-20429

IBM QRadar User Behavior Analytics 1.0.0 through 4.1.0 could disclose sensitive information due an overly permissive cross-domain policy. IBM X-Force…

Fix: 4.1.1+
Fix from $1,600 2021-05-14
Cloud Pak For Security MEDIUM 5.3
CVE-2021-20565

IBM Cloud Pak for Security (CP4S) 1.4.0.0, 1.5.0.0, 1.5.0.1, 1.6.0.0, and 1.6.0.1 uses a protection mechanism that relies on the existence or values …

Mitigation only
Fix from $1,600 2021-05-14
Jazz Reporting Service MEDIUM 5.4
CVE-2021-20535

IBM Jazz Reporting Service 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attack…

Mitigation only
Fix from $1,600 2021-05-13
Openpages Grc Platform MEDIUM 5.4
CVE-2020-4535

IBM OpenPages GRC Platform 8.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web U…

Fix: 8.1.0.2+
Fix from $1,600 2021-05-11
Cloud Pak For Security CRITICAL 9.1
CVE-2021-20538

IBM Cloud Pak for Security (CP4S) 1.5.0.0 and 1.5.0.1 could allow a user to obtain sensitive information or perform actions they should not have acce…

Mitigation only
Fix from $2,300 2021-05-10
Cloud Pak For Security MEDIUM 6.1
CVE-2021-20577

IBM Cloud Pak for Security (CP4S) 1.5.0.0 and 1.5.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaS…

Patch available
Fix from $1,600 2021-05-10
Control Desk MEDIUM 5.4
CVE-2021-20559

IBM Control Desk 7.6.1.2 and 7.6.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the…

Patch available
Fix from $1,600 2021-05-10
Robotic Process Automation With Automation Anywhere MEDIUM 6.5
CVE-2020-4901

IBM Robotic Process Automation with Automation Anywhere 11.0 could allow an attacker on the network to obtain sensitive information or cause a denial…

Fix: 11.0.0.10+
Fix from $1,600 2021-05-07
Tivoli Storage Manager HIGH 7.0
CVE-2020-28198

The 'id' parameter of IBM Tivoli Storage Manager Version 5 Release 2 (Command Line Administrative Interface, dsmadmc.exe) is vulnerable to an exploit…

No fix yet
Fix from $1,950 2021-05-06
Qradar Security Information And Event Manager CRITICAL 9.8
CVE-2020-4979

IBM QRadar SIEM 7.3 and 7.4 is vulnerable to insecure inter-deployment communication. An attacker that is able to comprimise or spoof traffic between…

Fix: 7.3.3 / 7.4.2+
Fix from $2,300 2021-05-05
Qradar Security Information And Event Manager HIGH 8.1
CVE-2020-5013

IBM QRadar SIEM 7.3 and 7.4 may vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit …

Fix: 7.3.3 / 7.4.2+
Fix from $1,950 2021-05-05
Qradar Security Information And Event Manager HIGH 7.8
CVE-2020-4932

IBM QRadar SIEM 7.3 and 7.4 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authenticatio…

Fix: 7.3.3 / 7.4.2+
Fix from $1,950 2021-05-05
Qradar Security Information And Event Manager HIGH 7.8
CVE-2021-20401

IBM QRadar SIEM 7.3 and 7.4 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authenticatio…

Fix: 7.3.3 / 7.4.2+
Fix from $1,950 2021-05-05
Qradar Security Information And Event Manager MEDIUM 6.5
CVE-2020-4883

IBM QRadar SIEM 7.3 and 7.4 could disclose sensitive information about other domains which could be used in further attacks against the system. IBM X…

Fix: 7.3.3 / 7.4.2+
Fix from $1,600 2021-05-05
Qradar Security Information And Event Manager MEDIUM 6.1
CVE-2021-20397

IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI t…

Fix: 7.3.3 / 7.4.2+
Fix from $1,600 2021-05-05
Qradar Security Information And Event Manager MEDIUM 5.4
CVE-2020-4929

IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI t…

Fix: 7.3.3 / 7.4.2+
Fix from $1,600 2021-05-05
Flashsystem 900 Firmware MEDIUM 5.4
CVE-2020-4987

The IBM FlashSystem 900 user management GUI is vulnerable to stored cross-site scripting in code versions 1.5.2.8 and prior and 1.6.1.2 and prior. Th…

Fix: 1.5.2.9 / 1.6.1.3+
Fix from $1,600 2021-05-04
Informix Dynamic Server MEDIUM 6.7
CVE-2021-20515

IBM Informix Dynamic Server 14.10 is vulnerable to a stack based buffer overflow, caused by improper bounds checking. A local privileged user could o…

Patch available
Fix from $1,600 2021-04-30
Spectrum Scale HIGH 7.8
CVE-2021-29667

IBM Spectrum Scale 5.0.0 through 5.0.5.6 and 5.1.0 through 5.1.0.2 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitr…

Fix: after 5.1.0.2
Fix from $1,950 2021-04-27
Spectrum Scale MEDIUM 6.0
CVE-2020-4981

IBM Spectrum Scale 5.0.4.1 through 5.1.0.3 could allow a local privileged user to overwrite files due to improper input validation. IBM X-Force ID: 1…

Fix: after 5.1.0.3
Fix from $1,600 2021-04-27
Content Navigator MEDIUM 5.4
CVE-2021-20448

IBM Content Navigator 3.0.CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI …

Patch available
Fix from $1,600 2021-04-27
Content Navigator MEDIUM 5.4
CVE-2021-20549

IBM Content Navigator 3.0.CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI …

Mitigation only
Fix from $1,600 2021-04-27
Content Navigator MEDIUM 5.4
CVE-2021-20550

IBM Content Navigator 3.0.CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI …

Mitigation only
Fix from $1,600 2021-04-27
Spectrum Scale MEDIUM 5.4
CVE-2021-29666

IBM Spectrum Scale 5.0.0 through 5.0.5.6 and 5.1.0 through 5.1.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed ar…

Fix: after 5.1.0.2
Fix from $1,600 2021-04-27
Spectrum Protect Client HIGH 7.8
CVE-2021-29672

IBM Spectrum Protect Client 8.1.0.0-8 through 1.11.0 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking when processi…

Fix: after 8.1.11.0
Fix from $1,950 2021-04-26
Spectrum Protect Plus HIGH 7.5
CVE-2021-29694

IBM Spectrum Protect Plus 10.1.0 through 10.1.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sen…

Fix: after 10.1.7
Fix from $1,950 2021-04-26
Spectrum Protect Plus MEDIUM 6.2
CVE-2021-20536

IBM Spectrum Protect Plus File Systems Agent 10.1.6 and 10.1.7 stores potentially sensitive information in log files that could be read by a local us…

Mitigation only
Fix from $1,600 2021-04-26