Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Collaborative Lifecycle Management MEDIUM 5.4
CVE-2020-4697

IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI…

Mitigation only
Fix from $1,600 2021-01-08
Collaborative Lifecycle Management MEDIUM 5.4
CVE-2020-4733

IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI…

Mitigation only
Fix from $1,600 2021-01-08
Spectrum Protect Plus HIGH 7.5
CVE-2020-5018

IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may include sensitive information in its URLs increasing the risk of such information being caputured…

Fix: 10.1.7+
Fix from $1,950 2021-01-08
Spectrum Protect Plus MEDIUM 6.5
CVE-2020-5019

IBM Spectrum Protect Plus 10.1.0 through 10.1.6 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. B…

Fix: 10.1.7+
Fix from $1,600 2021-01-08
Spectrum Protect Plus MEDIUM 6.1
CVE-2020-5020

IBM Spectrum Protect Plus 10.1.0 through 10.1.6 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to …

Fix: 10.1.7+
Fix from $1,600 2021-01-08
Spectrum Protect MEDIUM 5.5
CVE-2020-5017

IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may allow a local user to obtain access to information beyond their intended role and permissions. IB…

Fix: 10.1.7+
Fix from $1,600 2021-01-08
Spectrum Protect Plus MEDIUM 5.3
CVE-2020-5022

IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may allow unauthenticated and unauthorized access to VDAP proxy which can result in an attacker obtai…

Fix: 10.1.7+
Fix from $1,600 2021-01-08
Engineering Requirements Quality Assistant On Premises MEDIUM 5.4
CVE-2020-4663

IBM Engineering Requirements Quality Assistant On-Premises is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary …

Patch available
Fix from $1,600 2021-01-08
Engineering Requirements Quality Assistant On Premises MEDIUM 5.4
CVE-2020-4664

IBM Engineering Requirements Quality Assistant On-Premises is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary …

Patch available
Fix from $1,600 2021-01-08
Engineering Requirements Quality Assistant On Premises MEDIUM 5.4
CVE-2020-4666

IBM Engineering Requirements Quality Assistant On-Premises is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary …

Patch available
Fix from $1,600 2021-01-08
Emptoris Strategic Supply Management HIGH 7.5
CVE-2020-4898

IBM Emptoris Strategic Supply Management 10.1.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sen…

Fix: 10.1.3.30+
Fix from $1,950 2021-01-07
Emptoris Sourcing MEDIUM 6.5
CVE-2020-4896

IBM Emptoris Sourcing 10.1.0, 10.1.1, and 10.1.3 is vulnerable to web cache poisoning, caused by improper input validation by modifying HTTP request …

Fix: 10.1.0.38 / 10.1.1.35+
Fix from $1,600 2021-01-07
Emptoris Strategic Supply Management MEDIUM 5.9
CVE-2020-4893

IBM Emptoris Strategic Supply Management 10.1.0, 10.1.1, and 10.1.3 transmits sensitive information in HTTP GET request parameters. This may lead to …

Fix: 10.1.0.38 / 10.1.1.35+
Fix from $1,600 2021-01-07
Emptoris Contract Management MEDIUM 5.4
CVE-2020-4892

IBM Emptoris Contract Management 10.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in …

Fix: 10.1.3.30+
Fix from $1,600 2021-01-07
Emptoris Strategic Supply Management MEDIUM 5.4
CVE-2020-4895

IBM Emptoris Strategic Supply Management 10.1.0, 10.1.1, and 10.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to …

Fix: 10.1.0.38 / 10.1.1.35+
Fix from $1,600 2021-01-07
Emptoris Contract Management MEDIUM 5.3
CVE-2020-4897

IBM Emptoris Contract Management and IBM Emptoris Spend Analysis 10.1.0, 10.1.1, and 10.1.3 could allow a remote attacker to obtain sensitive informa…

Fix: 10.1.0.38 / 10.1.1.35+
Fix from $1,600 2021-01-07
Websphere Extreme Scale MEDIUM 5.3
CVE-2020-4336

IBM WebSphere eXtreme Scale 8.6.1 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties hav…

Fix: 8.6.1.4+
Fix from $1,600 2021-01-06
Api Connect CRITICAL 9.1
CVE-2020-4899

IBM API Connect 5.0.0.0 through 5.0.8.10 could potentially leak sensitive information or allow for data corruption due to plain text transmission of …

Fix: after 5.0.8.10
Fix from $2,300 2021-01-05
Sterling B2b Integrator HIGH 8.8
CVE-2019-4728

IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_2, 6.0.0.0 through 6.0.3.2, and 6.1.0.0 could allow a remote attacker to execute…

Fix: after 6.0.3.2
Fix from $1,950 2021-01-05
Sterling B2b Integrator HIGH 8.8
CVE-2020-4762

IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_2, 6.0.0.0 through 6.0.3.2, and 6.1.0.0 could allow an authenticated user to cre…

Fix: after 6.0.3.2
Fix from $1,950 2021-01-05
Sterling B2b Integrator MEDIUM 5.3
CVE-2020-4761

IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_2, 6.0.0.0 through 6.0.3.2, and 6.1.0.0 could allow a remote attacker to obtain …

Fix: after 6.0.3.2
Fix from $1,600 2021-01-05
Curam Social Program Management HIGH 8.8
CVE-2020-4942

IBM Curam Social Program Management 7.0.9 and 7.0.11 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious a…

Mitigation only
Fix from $1,950 2021-01-04
Cloud Pak System MEDIUM 6.7
CVE-2020-4928

IBM Cloud Pak System 2.3 could allow a local privileged attacker to upload arbitrary files. By intercepting the request and modifying the file extent…

Fix: 2.3.3.3+
Fix from $1,600 2021-01-04
Cloud Pak System HIGH 8.8
CVE-2020-4917

IBM Cloud Pak System 2.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions tran…

Fix: 2.3.3.3+
Fix from $1,950 2021-01-04
Cloud Pak System HIGH 7.2
CVE-2020-4912

IBM Cloud Pak System 2.3 Self Service Console could allow a privilege escalation by capturing the user request URL when logged in as a privileged use…

Fix: 2.3.3.3+
Fix from $1,950 2021-01-04
Db2 MEDIUM 5.5
CVE-2020-4642

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow local attacker to cause a denial of ser…

Mitigation only
Fix from $1,600 2020-12-23
Loopback CRITICAL 9.8
CVE-2020-4988

Loopback 8.0.0 contains a vulnerability that could allow an attacker to manipulate or pollute Javascript values and cause a denial of service or poss…

Mitigation only
Fix from $2,300 2020-12-21
Mq HIGH 7.5
CVE-2020-4870

IBM MQ 9.2 CD and LTS are vulnerable to a denial of service attack caused by an error processing connecting applications. IBM X-Force ID: 190833.

Patch available
Fix from $1,950 2020-12-21
Security Secret Server MEDIUM 6.1
CVE-2020-4840

IBM Security Secret Server 10.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to v…

Patch available
Fix from $1,600 2020-12-21
Security Secret Server MEDIUM 5.9
CVE-2020-4841

IBM Security Secret Server 10.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict T…

Patch available
Fix from $1,600 2020-12-21