Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Sterling B2b Integrator HIGH 8.8
CVE-2020-4655

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 is vulnerable to SQL injection. A remote attacker co…

Fix: after 6.0.3.2
Fix from $1,950 2020-11-16
Sterling File Gateway HIGH 7.5
CVE-2020-4476

IBM Sterling File Gateway 2.2.0.0 through 2.2.6.5 and 6.0.0.0 through 6.0.3.2 could allow a remote attacker to obtain sensitive information when a de…

Fix: after 6.0.3.2
Fix from $1,950 2020-11-16
Sterling B2b Integrator MEDIUM 6.5
CVE-2020-4475

IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 and 6.0.0.0 through 6.0.3.2 could allow a remote attacker to obtain sensitive in…

Fix: after 6.0.3.2
Fix from $1,600 2020-11-16
Sterling B2b Integrator MEDIUM 6.5
CVE-2020-4566

IBM Sterling B2B Integrator Standard Edition 5.2.6.0 through 5.2.6.5 and 6.0.0.0 through 6.0.3.2 stores potentially highly sensitive information in l…

Fix: after 6.0.3.2
Fix from $1,600 2020-11-16
Sterling B2b Integrator MEDIUM 6.5
CVE-2020-4671

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 stores potentially sensitive information in log file…

Fix: after 6.0.3.2
Fix from $1,600 2020-11-16
Sterling B2b Integrator MEDIUM 6.5
CVE-2020-4692

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 could allow an authenticated user to obtain sensitiv…

Fix: after 6.0.3.2
Fix from $1,600 2020-11-16
Business Automation Workflow MEDIUM 5.4
CVE-2020-4672

IBM Business Automation Workflow 20.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code i…

Patch available
Fix from $1,600 2020-11-16
Cognos Controller HIGH 7.2
CVE-2020-4685

A low level user of IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, 10.4.1, and 10.4.2 who has Administration rights to the server where the applicatio…

Patch available
Fix from $1,950 2020-11-11
Security Key Lifecycle Manager MEDIUM 5.5
CVE-2020-4568

IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, and 4.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID…

Patch available
Fix from $1,600 2020-11-10
Content Navigator MEDIUM 5.4
CVE-2020-4704

IBM Content Navigator 3.0CD is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the W…

Mitigation only
Fix from $1,600 2020-11-10
Content Navigator MEDIUM 5.4
CVE-2020-4760

IBM Content Navigator 3.0CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI t…

Mitigation only
Fix from $1,600 2020-11-10
Filenet Content Manager HIGH 7.8
CVE-2020-4759

IBM FileNet Content Manager 5.5.4 and 5.5.5 is potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the sys…

Patch available
Fix from $1,950 2020-11-09
Urbancode Deploy MEDIUM 6.5
CVE-2020-4482

IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 could allow an authenticated user to bypass security. A user with access to a snaps…

Patch available
Fix from $1,600 2020-11-06
App Connect Enterprise Certified Container MEDIUM 5.4
CVE-2020-4785

IBM App Connect Enterprise Certified Container 1.0.0, 1.0.1, 1.0.2, 1.0.3, and 1.0.4 could allow a remote attacker to hijack the clicking action of t…

Patch available
Fix from $1,600 2020-11-03
I2 Ibase HIGH 7.8
CVE-2020-4588

IBM i2 iBase 8.9.13 could allow an attacker to upload arbitrary executable files which, when executed by an unsuspecting victim could result in code …

Fix: after 8.9.13
Fix from $1,950 2020-10-30
I2 Ibase HIGH 7.5
CVE-2020-4584

IBM i2 iBase 8.9.13 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser.…

Fix: after 8.9.13
Fix from $1,950 2020-10-30
I2 Analysts Notebook HIGH 7.8
CVE-2020-4722

IBM i2 Analyst Notebook 9.2.0 and 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persu…

Patch available
Fix from $1,950 2020-10-29
I2 Analysts Notebook HIGH 7.8
CVE-2020-4723

IBM i2 Analyst Notebook 9.2.0 and 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persu…

Patch available
Fix from $1,950 2020-10-29
I2 Analysts Notebook HIGH 7.8
CVE-2020-4724

IBM i2 Analyst Notebook 9.2.0 and 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persu…

Patch available
Fix from $1,950 2020-10-29
I2 Analysts Notebook HIGH 7.8
CVE-2020-4721

IBM i2 Analyst Notebook 9.2.0 and 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persu…

Patch available
Fix from $1,950 2020-10-29
Security Directory Server MEDIUM 5.3
CVE-2019-4547

IBM Security Directory Server 6.4.0 generates an error message that includes sensitive information about its environment, users, or associated data. …

Patch available
Fix from $1,600 2020-10-29
Security Directory Server MEDIUM 5.3
CVE-2019-4563

IBM Security Directory Server 6.4.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the co…

Patch available
Fix from $1,600 2020-10-29
Websphere Application Server MEDIUM 6.5
CVE-2020-4782

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the system. An attacker could send a…

Fix: after 9.0.5.5
Fix from $1,600 2020-10-28
Sterling Connect\ HIGH 7.5
CVE-2020-4767

IBM Sterling Connect Direct for Microsoft Windows 4.7, 4.8, 6.0, and 6.1 could allow a remote attacker to cause a denial of service, caused by a buff…

Fix: 4.7.0.7 / 4.8.0.3+
Fix from $1,950 2020-10-28
Spectrum Scale MEDIUM 6.1
CVE-2020-4748

IBM Spectrum Scale 5.0.0 through 5.0.5.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in…

Fix: after 5.0.5.2
Fix from $1,600 2020-10-20
Elastic Storage Server MEDIUM 5.5
CVE-2020-4756

IBM Spectrum Scale V4.2.0.0 through V4.2.3.23 and V5.0.0.0 through V5.0.5.2 as well as IBM Elastic Storage System 6.0.0 through 6.0.1.0 could allow a…

Fix: after 6.0.1.0
Fix from $1,600 2020-10-20
Sterling B2b Integrator MEDIUM 5.4
CVE-2020-4564

IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.3.1 and IBM Sterling File Gateway 2.2.0.0 through 6.0.3.1 are vulnerable to cross-si…

Fix: after 6.0.3.1
Fix from $1,600 2020-10-20
Spectrum Scale MEDIUM 5.4
CVE-2020-4755

IBM Spectrum Scale 5.0.0 through 5.0.5.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in…

Fix: after 5.0.5.2
Fix from $1,600 2020-10-20
Sterling B2b Integrator HIGH 8.8
CVE-2019-4680

IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.2.2 is vulnerable to SQL injection. A remote attacker could send specially-crafted S…

Fix: after 6.0.2.2
Fix from $1,950 2020-10-20
Spectrum Scale MEDIUM 5.5
CVE-2020-4491

IBM Spectrum Scale V4.2.0.0 through V4.2.3.22 and V5.0.0.0 through V5.0.5 could allow a local attacker to cause a denial of service by sending a larg…

Fix: after 5.0.5
Fix from $1,600 2020-10-20