Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Spectrum Protect Operations Center MEDIUM 5.4
CVE-2020-4954

IBM Spectrum Protect Operations Center 7.1 and 8.1 could allow a remote attacker to bypass authentication restrictions, caused by improper session va…

Fix: 7.1.13.000 / 8.1.10.200+
Fix from $1,600 2021-02-15
Security Verify Information Queue HIGH 8.1
CVE-2021-20411

IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a user to impersonate another user on the system due to incorrectly updating the se…

Patch available
Fix from $1,950 2021-02-12
Security Verify Information Queue HIGH 7.5
CVE-2021-20412

IBM Security Verify Information Queue 1.0.6 and 1.0.7 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its…

Patch available
Fix from $1,950 2021-02-12
Security Verify Information Queue MEDIUM 5.3
CVE-2021-20410

IBM Security Verify Information Queue 1.0.6 and 1.0.7 sends user credentials in plain clear text which can be read by an authenticated user using man…

Patch available
Fix from $1,600 2021-02-12
Security Verify Information Queue HIGH 7.5
CVE-2021-20407

IBM Security Verify Information Queue 1.0.6 and 1.0.7 discloses sensitive information in source code that could be used in further attacks against th…

Patch available
Fix from $1,950 2021-02-12
Security Verify Information Queue HIGH 7.5
CVE-2021-20409

IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a remote attacker to obtain sensitive information, caused by the failure to properl…

Patch available
Fix from $1,950 2021-02-12
Security Verify Information Queue MEDIUM 5.5
CVE-2021-20408

IBM Security Verify Information Queue 1.0.6 and 1.0.7 could disclose highly sensitive information to a local user due to inproper storage of a plaint…

Patch available
Fix from $1,600 2021-02-12
Security Verify Information Queue HIGH 8.8
CVE-2021-20403

IBM Security Verify Information Queue 1.0.6 and 1.0.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious …

Mitigation only
Fix from $1,950 2021-02-11
Security Verify Information Queue HIGH 7.5
CVE-2021-20405

IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a user to perform unauthorized activities due to improper encoding of output. IBM X…

Mitigation only
Fix from $1,950 2021-02-11
Business Automation Workflow MEDIUM 5.4
CVE-2020-4768

IBM Case Manager 5.2 and 5.3 and IBM Business Automation Workflow 18.0, 19.0, and 20.0 are vulnerable to cross-site scripting. This vulnerability all…

Fix: after 20.0.0.2
Fix from $1,600 2021-02-11
Security Verify Information Queue MEDIUM 5.3
CVE-2021-20404

IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a user on the network to cause a denial of service due to an invalid cookie value t…

Mitigation only
Fix from $1,600 2021-02-11
Websphere Application Server HIGH 8.2
CVE-2021-20353EPSS 5%

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A re…

Fix: 7.0.0.45 / 8.0.0.15+
Fix from $1,950 2021-02-10
Spectrum Protect Plus HIGH 7.5
CVE-2020-5023

IBM Spectrum Protect Plus 10.1.0 through 10.1.7 could allow a remote user to inject arbitrary data iwhich could cause the serivce to crash due to exc…

Fix: after 10.1.7
Fix from $1,950 2021-02-10
Security Identity Governance And Intelligence HIGH 8.2
CVE-2020-4795

IBM Security Identity Governance and Intelligence 5.2.6 could disclose sensitive information to an unauthorized user using a specially crafted HTTP r…

Patch available
Fix from $1,950 2021-02-09
Security Identity Governance And Intelligence MEDIUM 6.5
CVE-2020-4790

IBM Security Identity Governance and Intelligence 5.2.6 could allow a user to cause a denial of service due to improperly validating a supplied URL, …

Patch available
Fix from $1,600 2021-02-09
Security Identity Governance And Intelligence MEDIUM 5.5
CVE-2020-4996

IBM Security Identity Governance and Intelligence 5.2.6 could allow a local user to obtain sensitive information via the capturing of screenshots of …

Patch available
Fix from $1,600 2021-02-09
Security Identity Governance And Intelligence MEDIUM 5.3
CVE-2020-4791

IBM Security Identity Governance and Intelligence 5.2.6 could allow an attacker to obtain sensitive information using main in the middle attacks due …

Patch available
Fix from $1,600 2021-02-09
Security Identity Governance And Intelligence MEDIUM 5.3
CVE-2020-4995

IBM Security Identity Governance and Intelligence 5.2.6 does not invalidate session after logout which could allow a user to obtain sensitive informa…

Patch available
Fix from $1,600 2021-02-09
Cloud Pak For Automation MEDIUM 6.5
CVE-2021-20358

IBM Cloud Pak for Automation 20.0.3, 20.0.2-IF002 stores potentially sensitive information in clear text in API connection log files. This informatio…

Mitigation only
Fix from $1,600 2021-02-08
Cloud Pak For Automation MEDIUM 6.5
CVE-2021-20359

IBM Cloud Pak for Automation 20.0.3, 20.0.2-IF002 - Business Automation Application Designer Component stores potentially sensitive information in lo…

Mitigation only
Fix from $1,600 2021-02-08
Powerha MEDIUM 5.5
CVE-2020-4832

IBM PowerHA 7.2 could allow a local attacker to obtain sensitive information from temporary directories after a discovery failure occurs. IBM X-Force…

Patch available
Fix from $1,600 2021-02-05
Api Connect MEDIUM 6.5
CVE-2020-4828

IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 is vulnerable to web cache poisoning, caused by improper input validatio…

Fix: after 2018.4.1.13
Fix from $1,600 2021-02-04
Api Connect MEDIUM 5.4
CVE-2020-4825

IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 is vulnerable to cross-site scripting. This vulnerability allows users t…

Fix: after 2018.4.1.13
Fix from $1,600 2021-02-04
Mq CRITICAL 9.8
CVE-2020-4682EPSS 8%

IBM MQ 7.5, 8.0, 9.0, 9.1, 9.2 LTS, and 9.2 CD could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserializa…

Patch available
Fix from $2,300 2021-01-28
Qradar Security Information And Event Manager HIGH 8.8
CVE-2020-4888EPSS 62%

IBM QRadar SIEM 7.4.0 to 7.4.2 Patch 1 and 7.3.0 to 7.3.3 Patch 7 could allow a remote attacker to execute arbitrary commands on the system, caused b…

Patch available
Fix from $1,950 2021-01-28
Collaborative Lifecycle Management MEDIUM 5.4
CVE-2021-20357

IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI …

Patch available
Fix from $1,600 2021-01-27
Security Guardium HIGH 8.8
CVE-2020-4952

IBM Security Guardium 11.2 could allow an authenticated user to gain root access due to improper access control. IBM X-Force ID: 192028.

Patch available
Fix from $1,950 2021-01-27
Collaborative Lifecycle Management MEDIUM 5.4
CVE-2020-4865

IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI …

Patch available
Fix from $1,600 2021-01-27
Qradar Security Information And Event Manager MEDIUM 6.5
CVE-2020-4789

IBM QRadar SIEM 7.4.2 GA to 7.4.2 Patch 1, 7.4.0 to 7.4.1 Patch 1, and 7.3.0 to 7.3.3 Patch 5 could allow a remote attacker to traverse directories o…

Patch available
Fix from $1,600 2021-01-27
Collaborative Lifecycle Management MEDIUM 5.4
CVE-2020-4855

IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI …

Patch available
Fix from $1,600 2021-01-27