Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Automation Workstream Services MEDIUM 5.4
CVE-2020-4794

IBM Automation Workstream Services 19.0.3, 20.0.1, 20.0.2, IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.6…

Patch available
Fix from $1,600 2020-12-21
Content Navigator MEDIUM 6.4
CVE-2020-4757

IBM FileNet Content Manager and IBM Content Navigator 3.0.CD is vulnerable to stored cross-site scripting. This vulnerability allows users to embed a…

Patch available
Fix from $1,600 2020-12-21
Financial Transaction Manager MEDIUM 5.4
CVE-2020-4555

IBM Financial Transaction Manager 3.0.6 and 3.1.0 does not invalidate session after logout which could allow an authenticated user to impersonate ano…

Patch available
Fix from $1,600 2020-12-21
Planning Analytics MEDIUM 6.5
CVE-2020-4764

IBM Planning Analytics 2.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions tr…

Patch available
Fix from $1,600 2020-12-18
Security Key Lifecycle Manager MEDIUM 5.4
CVE-2020-4845

IBM Security Key Lifecycle Manager 3.0.1 and 4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript…

Fix: 3.0.1.5 / 4.0.0.2+
Fix from $1,600 2020-12-17
Financial Transaction Manager For Multiplatform MEDIUM 6.5
CVE-2020-4904

IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 is vulnerable to cross-site request forgery which could allow an attack…

Patch available
Fix from $1,600 2020-12-16
Sterling B2b Integrator MEDIUM 6.1
CVE-2020-4657

IBM Sterling B2B Integrator 5.2.0.0 through 6.0.3.2 Standard Edition is vulnerable to cross-site scripting. This vulnerability allows users to embed …

Fix: after 6.0.3.2
Fix from $1,600 2020-12-16
Sterling File Gateway MEDIUM 6.1
CVE-2020-4658

IBM Sterling File Gateway 2.2.0.0 through 6.0.3.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScrip…

Fix: after 6.0.3.2
Fix from $1,600 2020-12-16
Financial Transaction Manager For Multiplatform MEDIUM 5.9
CVE-2020-4905

IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 could allow an remote attacker to obtain sensitive information, caused …

Patch available
Fix from $1,600 2020-12-16
Financial Transaction Manager For Multiplatform MEDIUM 5.3
CVE-2020-4907

IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 could allow a remote attacker to obtain sensitive information when a de…

Patch available
Fix from $1,600 2020-12-16
Financial Transaction Manager For Multiplatform MEDIUM 5.3
CVE-2020-4908

IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 returns the product version and release information on the login dialog…

Patch available
Fix from $1,600 2020-12-16
Connect\ CRITICAL 9.8
CVE-2020-4747

IBM Connect:Direct for UNIX 6.1.0, 6.0.0, 4.3.0, and 4.2.0 can allow a local or remote user to obtain an authenticated CLI session due to improper au…

Mitigation only
Fix from $2,300 2020-12-15
Tivoli Netcool\/impact MEDIUM 6.1
CVE-2020-4849

IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.19 Interim Fix 7 could allow a remote attacker to bypass security restrictions, caused by a reverse t…

Fix: after 7.1.0.19
Fix from $1,600 2020-12-15
Resilient Security Orchestration Automation And Response HIGH 8.8
CVE-2020-4633

IBM Resilient SOAR V38.0 could allow a remote attacker to execute arbitrary code on the system, caused by formula injection due to improper input val…

Mitigation only
Fix from $1,950 2020-12-11
Vios HIGH 7.8
CVE-2020-4829

IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user to exploit a vulnerability in the ksu user command to gain root privileges. IBM X-Force ID: 1…

Patch available
Fix from $1,950 2020-12-10
Sterling B2b Integrator MEDIUM 6.5
CVE-2019-4738

IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 and 6.0.0.0 through 6.0.3.1 discloses sensitive information to an authenticated …

Fix: after 6.0.3.1
Fix from $1,600 2020-12-10
Cloud Pak For Security CRITICAL 9.0
CVE-2020-4627

IBM Cloud Pak for Security 1.3.0.1(CP4S) potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, c…

Patch available
Fix from $2,300 2020-11-30
Business Automation Workflow MEDIUM 5.5
CVE-2020-4900

IBM Business Automation Workflow 19.0.0.3 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 1…

Patch available
Fix from $1,600 2020-11-30
Cloud Pak For Security MEDIUM 5.3
CVE-2020-4624

IBM Cloud Pak for Security 1.3.0.1 (CP4S) uses weaker than expected cryptographic algorithms during negotiation could allow an attacker to decrypt se…

Patch available
Fix from $1,600 2020-11-30
Cloud Pak For Security MEDIUM 5.3
CVE-2020-4625

IBM Cloud Pak for Security 1.3.0.1(CP4S) could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly fla…

Patch available
Fix from $1,600 2020-11-30
Spectrum Protect Plus CRITICAL 9.8
CVE-2020-4854

IBM Spectrum Protect Plus 10.1.0 thorugh 10.1.6 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own i…

Fix: after 10.1.6
Fix from $2,300 2020-11-23
Spectrum Protect Plus MEDIUM 5.9
CVE-2020-4783

IBM Spectrum Protect Plus 10.1.0 through 10.1.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enab…

Fix: after 10.1.6
Fix from $1,600 2020-11-23
Spectrum Protect Operations Center MEDIUM 5.3
CVE-2020-4771

IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.10.and 7.1.0.000 through 7.1.11 could allow a remote attacker to obtain sensitive inform…

Fix: after 8.1.10
Fix from $1,600 2020-11-23
Sterling B2b Integrator HIGH 7.5
CVE-2020-4937

IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker …

Fix: after 6.0.3.2
Fix from $1,950 2020-11-20
Db2 HIGH 7.8
CVE-2020-4739

IBM DB2 Accessories Suite for Linux, UNIX, and Windows, DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5…

Fix: 11.5.5.0+
Fix from $1,950 2020-11-20
Jazz Reporting Service MEDIUM 5.4
CVE-2020-4718

IBM Jazz Reporting Service 6.0.6, 6.0.6.1, 7.0, and 7.0.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbi…

Patch available
Fix from $1,600 2020-11-19
Db2 HIGH 7.8
CVE-2020-4701

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a buffer overflow, caused by improper bounds …

Patch available
Fix from $1,950 2020-11-19
Mq Appliance MEDIUM 6.5
CVE-2020-4592

IBM MQ Appliance 9.1.CD and LTS could allow an authenticated user, under nondefault configuration to cause a data corruption attack due to an error w…

Patch available
Fix from $1,600 2020-11-18
Sterling B2b Integrator HIGH 8.8
CVE-2020-4700

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 could allow an authenticated user belonging to a spe…

Fix: after 6.0.3.2
Fix from $1,950 2020-11-16
Sterling File Gateway HIGH 8.8
CVE-2020-4647

IBM Sterling File Gateway 2.2.0.0 through 2.2.6.5 and 6.0.0.0 through 6.0.3.2 is vulnerable to SQL injection. A remote attacker could send specially …

Fix: after 6.0.3.2
Fix from $1,950 2020-11-16