Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Spectrum Protect Client MEDIUM 5.5
CVE-2021-20546

IBM Spectrum Protect Client 8.1.0.0 through 8.1.11.0 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local atta…

Fix: after 8.1.11.0
Fix from $1,600 2021-04-26
Spectrum Protect Backup Archive Client HIGH 7.8
CVE-2021-20532

IBM Spectrum Protect Client 8.1.0.0 through 8.1.11.0 could allow a local user to escalate their privileges to take full control of the system due to …

Fix: after 8.1.11.0
Fix from $1,950 2021-04-26
Spectrum Protect Plus MEDIUM 6.5
CVE-2021-20432

IBM Spectrum Protect Plus 10.1.0 through 10.1.7 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actio…

Fix: after 10.1.7
Fix from $1,600 2021-04-26
Planning Analytics MEDIUM 5.3
CVE-2020-4562

IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information by allowing cross-window communication with unrestricted tar…

Mitigation only
Fix from $1,600 2021-04-26
Websphere Application Server HIGH 8.2
CVE-2021-20454

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A rem…

Fix: after 9.0.5.7
Fix from $1,950 2021-04-21
I HIGH 8.2
CVE-2021-20501

IBM i 7.1, 7.2, 7.3, and 7.4 SMTP allows a network attacker to send emails to non-existent local-domain recipients to the SMTP server, caused by usin…

Mitigation only
Fix from $1,950 2021-04-21
Websphere Application Server HIGH 8.2
CVE-2021-20453

IBM WebSphere Application Server 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote a…

Fix: 8.0.0.15 / 8.5.5.20+
Fix from $1,950 2021-04-20
Resilient HIGH 7.2
CVE-2021-20527

IBM Resilient SOAR V38.0 could allow a privileged user to create create malicious scripts that could be executed as another user. IBM X-Force ID: 198…

Fix: 38.2.41 / 39.0.6536+
Fix from $1,950 2021-04-19
Collaborative Lifecycle Management MEDIUM 5.4
CVE-2021-20519

IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web U…

Patch available
Fix from $1,600 2021-04-12
Collaborative Lifecycle Management HIGH 7.5
CVE-2020-4965

IBM Jazz Team Server products use weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.…

Patch available
Fix from $1,950 2021-04-12
Collaborative Lifecycle Management MEDIUM 5.4
CVE-2020-4920

IBM Jazz Team Server products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in th…

Patch available
Fix from $1,600 2021-04-12
Websphere Application Server MEDIUM 6.5
CVE-2021-20480

IBM WebSphere Application Server 7.0, 8.0, and 8.5 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, a rem…

Fix: after 8.5.5.19
Fix from $1,600 2021-04-08
Edge Application Manager MEDIUM 5.4
CVE-2020-4792

IBM Edge 4.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering th…

Patch available
Fix from $1,600 2021-04-05
Infosphere Information Server MEDIUM 5.4
CVE-2020-4997

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…

Patch available
Fix from $1,600 2021-04-05
Engineering Insights HIGH 7.1
CVE-2021-20502

IBM Jazz Foundation Products are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploi…

Patch available
Fix from $1,950 2021-03-30
Engineering Insights MEDIUM 5.4
CVE-2021-20352

IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI…

Patch available
Fix from $1,600 2021-03-30
Engineering Insights MEDIUM 5.4
CVE-2021-20447

IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI…

Patch available
Fix from $1,600 2021-03-30
Engineering Insights MEDIUM 5.4
CVE-2021-20503

IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI…

Patch available
Fix from $1,600 2021-03-30
Engineering Insights MEDIUM 5.4
CVE-2021-20504

IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI…

Patch available
Fix from $1,600 2021-03-30
Engineering Insights MEDIUM 5.4
CVE-2021-20506

IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI…

Patch available
Fix from $1,600 2021-03-30
Engineering Insights MEDIUM 5.4
CVE-2021-20518

IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI…

Patch available
Fix from $1,600 2021-03-30
Engineering Insights MEDIUM 5.4
CVE-2021-20520

IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI…

Patch available
Fix from $1,600 2021-03-30
Cloud Pak For Automation HIGH 7.1
CVE-2021-20482

IBM Cloud Pak for Automation 20.0.2 and 20.0.3 IF002 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remo…

Mitigation only
Fix from $1,950 2021-03-30
Urbancode Deploy MEDIUM 5.5
CVE-2020-4884

IBM UrbanCode Deploy (UCD) 6.2.7.9, 7.0.5.4, and 7.1.1.1 stores user credentials in plain in clear text which can be read by a local user. IBM X-Forc…

Mitigation only
Fix from $1,600 2021-03-30
Urbancode Deploy MEDIUM 5.5
CVE-2020-4944

IBM UrbanCode Deploy (UCD) 7.0.3.0, 7.0.4.0, 7.0.5.3, 7.0.5.4, 7.1.0.0, 7.1.1.0, 7.1.1.1, and 7.1.1.2, stores keystore passwords in plain text after …

Mitigation only
Fix from $1,600 2021-03-30
Urbancode Deploy MEDIUM 5.4
CVE-2020-4848

IBM UrbanCode Deploy (UCD) 6.2.7.9, 7.0.5.4, and 7.1.1.1 could allow an authenticated user to initiate a plugin or compare process resources that the…

Mitigation only
Fix from $1,600 2021-03-30
Elastic Storage Server HIGH 7.5
CVE-2020-5015

IBM Elastic Storage System 6.0.0 through 6.0.1.2 and IBM Elastic Storage Server 5.3.0 through 5.3.6.2 could allow a remote attacker to cause a denial…

Fix: after 6.0.1.2
Fix from $1,950 2021-03-24
Planning Analytics MEDIUM 6.1
CVE-2020-4882

IBM Planning Analytics 2.0 could be vulnerable to a Server-Side Request Forgery (SSRF) attack by constucting URLs from user-controlled data . This co…

Mitigation only
Fix from $1,600 2021-03-22
Soar MEDIUM 5.3
CVE-2020-4635

IBM Resilient SOAR 40 and earlier could disclose sensitive information by allowing a user to enumerate usernames.

Patch available
Fix from $1,600 2021-03-19
Spectrum Scale MEDIUM 5.5
CVE-2020-4851

IBM Spectrum Scale 5.0.0 through 5.0.5.5 and 5.1.0 through 5.1.0.2 could allow a local user to poison log files which could impact support and develo…

Fix: 5.0.5.5 / 5.1.0.2+
Fix from $1,600 2021-03-16