Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Collaborative Lifecycle Management MEDIUM 5.4
CVE-2020-4524

IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI …

Patch available
Fix from $1,600 2021-01-27
Collaborative Lifecycle Management MEDIUM 5.4
CVE-2020-4547

IBM Jazz Foundation products could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious W…

Patch available
Fix from $1,600 2021-01-27
Cloud Pak For Security MEDIUM 6.1
CVE-2020-4820

IBM Cloud Pak for Security (CP4S) 1.4.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code i…

Patch available
Fix from $1,600 2021-01-27
Cloud Pak For Security MEDIUM 5.9
CVE-2020-4816

IBM Cloud Pak for Security (CP4S) 1.4.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTT…

Patch available
Fix from $1,600 2021-01-27
Cloud Pak For Security MEDIUM 5.3
CVE-2020-4815

IBM Cloud Pak for Security (CP4S) 1.4.0.0 could allow a remote user to obtain sensitive information from HTTP response headers that could be used in …

Patch available
Fix from $1,600 2021-01-27
Cloud Pak For Security MEDIUM 5.3
CVE-2020-4628

IBM Cloud Pak for Security (CP4S) 1.3.0.1 and 1.4.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error m…

Patch available
Fix from $1,600 2021-01-27
Infosphere Information Server CRITICAL 9.8
CVE-2020-27583

IBM InfoSphere Information Server 8.5.0.0 is affected by deserialization of untrusted data which could allow remote unauthenticated attackers to exec…

No fix yet
Fix from $2,300 2021-01-26
Websphere Application Server HIGH 8.2
CVE-2020-4949

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A re…

Fix: after 9.0.5.6
Fix from $1,950 2021-01-26
Mq Internet Pass Thru HIGH 7.5
CVE-2020-4766

IBM MQ Internet Pass-Thru 2.1 and 9.2 could allow a remote user to cause a denial of service by sending malformed MQ data requests which would consum…

Patch available
Fix from $1,950 2021-01-22
Security Identity Governance And Intelligence MEDIUM 6.5
CVE-2020-4968

IBM Security Identity Governance and Intelligence 5.2.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt hi…

Patch available
Fix from $1,600 2021-01-21
Security Identity Governance And Intelligence MEDIUM 5.9
CVE-2020-4969

IBM Security Identity Governance and Intelligence 5.2.6 could allow a remote attacker to obtain sensitive information, caused by the failure to prope…

Patch available
Fix from $1,600 2021-01-21
Security Identity Governance And Intelligence CRITICAL 9.8
CVE-2020-4958

IBM Security Identity Governance and Intelligence 5.2.6 does not perform any authentication for functionality that requires a provable user identity …

Mitigation only
Fix from $2,300 2021-01-21
Security Guardium HIGH 8.8
CVE-2020-4921

IBM Security Guardium 10.6 and 11.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow …

Mitigation only
Fix from $1,950 2021-01-20
Security Guardium HIGH 7.8
CVE-2020-4688

IBM Security Guardium 10.6 and 11.2 could allow a local attacker to execute arbitrary commands on the system as an unprivileged user, caused by comma…

Mitigation only
Fix from $1,950 2021-01-20
Spectrum Lsf HIGH 7.8
CVE-2020-4983

IBM Spectrum LSF 10.1 and IBM Spectrum LSF Suite 10.2 could allow a user on the local network who has privileges to submit LSF jobs to execute arbitr…

Patch available
Fix from $1,950 2021-01-20
Vios MEDIUM 5.5
CVE-2020-4887

IBM AIX 7.1, 7.2 and AIX VIOS 3.1 could allow a local user to exploit a vulnerability in the gencore user command to create arbitrary files in any di…

Mitigation only
Fix from $1,600 2021-01-20
Planning Analytics HIGH 7.5
CVE-2020-4881

IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information, caused by the lack of server hostname verification for SSL/…

Patch available
Fix from $1,950 2021-01-19
Planning Analytics MEDIUM 5.3
CVE-2020-4873

IBM Planning Analytics 2.0 could allow an attacker to obtain sensitive information due to an overly permissive CORS policy. IBM X-Force ID: 190836.

Patch available
Fix from $1,600 2021-01-19
Planning Analytics MEDIUM 5.5
CVE-2020-4871

IBM Planning Analytics 2.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 190834.

Patch available
Fix from $1,600 2021-01-19
Security Guardium Insights HIGH 7.5
CVE-2020-4594

IBM Security Guardium Insights 2.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive info…

Patch available
Fix from $1,950 2021-01-13
Security Guardium Insights HIGH 7.5
CVE-2020-4595

IBM Security Guardium Insights 2.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive info…

Patch available
Fix from $1,950 2021-01-13
Security Guardium Insights HIGH 7.5
CVE-2020-4596

IBM Security Guardium Insights 2.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive info…

Patch available
Fix from $1,950 2021-01-13
Security Guardium Insights MEDIUM 5.3
CVE-2020-4599

IBM Security Guardium Insights 2.0.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returne…

Patch available
Fix from $1,600 2021-01-13
Security Guardium Insights MEDIUM 5.3
CVE-2020-4600

IBM Security Guardium Insights 2.0.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returne…

Patch available
Fix from $1,600 2021-01-13
Security Guardium Data Encryption HIGH 8.1
CVE-2019-4702

IBM Security Guardium Data Encryption (GDE) 3.0.0.2 specifies permissions for a security-critical resource in a way that allows that resource to be r…

Patch available
Fix from $1,950 2021-01-13
Security Guardium Data Encryption HIGH 7.5
CVE-2019-4160

IBM Security Guardium Data Encryption (GDE) 3.0.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly…

Patch available
Fix from $1,950 2021-01-13
Security Guardium Data Encryption MEDIUM 5.3
CVE-2019-4687

IBM Security Guardium Data Encryption (GDE) 3.0.0.2 stores sensitive information in URL parameters. This may lead to information disclosure if unauth…

Patch available
Fix from $1,600 2021-01-13
Api Connect MEDIUM 5.4
CVE-2020-4838

IBM API Connect 5.0.0.0 through 5.0.8.10 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript …

Fix: after 5.0.8.10
Fix from $1,600 2021-01-12
Mq Appliance MEDIUM 6.5
CVE-2020-4869

IBM MQ Appliance 9.2 CD and 9.2 LTS is vulnerable to a denial of service, caused by a buffer overflow. A remote attacker could send a specially craft…

Patch available
Fix from $1,600 2021-01-11
Collaborative Lifecycle Management MEDIUM 5.4
CVE-2020-4691

IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI…

Mitigation only
Fix from $1,600 2021-01-08