Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Security Guardium Big Data Intelligence HIGH 7.5
CVE-2020-4254

IBM Security Guardium Big Data Intelligence 1.0 (SonarG) uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt h…

Mitigation only
Fix from $1,950 2020-10-16
Resilient Security Orchestration Automation And Response HIGH 7.2
CVE-2020-4636

IBM Resilient OnPrem 38.2 could allow a privileged user to inject malicious commands through Python3 scripting. IBM X-Force ID: 185503.

Mitigation only
Fix from $1,950 2020-10-16
Security Access Manager CRITICAL 9.8
CVE-2020-4499

IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an unauthorized public Oauth client to bypass some or all of the …

Fix: 9.0.7.2 / 10.0.0.1+
Fix from $2,300 2020-10-15
Security Access Manager MEDIUM 6.1
CVE-2019-4552

IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 are vulnerable to HTTP response splitting attacks. A remote attacker could ex…

Fix: 9.0.7.2 / 10.0.0.1+
Fix from $1,600 2020-10-15
Security Access Manager Appliance MEDIUM 5.4
CVE-2020-4395

IBM Security Access Manager Appliance 9.0.7 does not invalidate session after logout which could allow an authenticated user to impersonate another u…

Patch available
Fix from $1,600 2020-10-14
Security Guardium MEDIUM 6.8
CVE-2020-4689

IBM Security Guardium 11.2 is vulnerable to CVS Injection. A remote privileged attacker could execute arbitrary commands on the system, caused by imp…

Patch available
Fix from $1,600 2020-10-12
Infosphere Information Server MEDIUM 5.4
CVE-2020-4741

IBM InfoSphere Information Server 11.5 and 11.7 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary Java…

Patch available
Fix from $1,600 2020-10-12
Infosphere Information Server MEDIUM 5.2
CVE-2020-4740

IBM InfoSphere Information Server 11.5 and 11.7 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewe…

Patch available
Fix from $1,600 2020-10-12
Cognos Analytics HIGH 8.2
CVE-2020-4388

IBM Cognos Analytics 11.0 and 11.1 could be vulnerable to a denial of service attack by failing to catch exceptions in a servlet also exposing debug …

Fix: 11.0.13+
Fix from $1,950 2020-10-12
Cognos Analytics HIGH 7.8
CVE-2020-4302

IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to execute arbitrary code on the system, caused by a CSV injection. By persuading a …

Fix: 11.0.13+
Fix from $1,950 2020-10-12
Security Guardium MEDIUM 5.4
CVE-2020-4680

IBM Security Guardium 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI th…

Patch available
Fix from $1,600 2020-10-12
Security Guardium MEDIUM 5.4
CVE-2020-4681

IBM Security Guardium 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI th…

Patch available
Fix from $1,600 2020-10-12
Curam Social Program Management HIGH 8.1
CVE-2020-4779

A HTTP Verb Tampering vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10. By sending a specially-crafted request, an attac…

Mitigation only
Fix from $1,950 2020-10-12
Curam Social Program Management HIGH 7.5
CVE-2020-4778

IBM Curam Social Program Management 7.0.9 and 7.0.10 uses MD5 algorithm for hashing token in a single instance which less safe than default SHA-256 c…

Mitigation only
Fix from $1,950 2020-10-12
Curam Social Program Management MEDIUM 6.5
CVE-2020-4781

An improper input validation before calling java readLine() method may impact IBM Curam Social Program Management 7.0.9 and 7.0.10, which could resul…

Mitigation only
Fix from $1,600 2020-10-12
Curam Social Program Management MEDIUM 5.3
CVE-2020-4780

OOTB build scripts does not set the secure attribute on session cookie which may impact IBM Curam Social Program Management 7.0.9 and 7.0,10. The pur…

Mitigation only
Fix from $1,600 2020-10-12
Curam Social Program Management HIGH 8.1
CVE-2020-4772

An XML External Entity Injection (XXE) vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10. A remote attacker could exploit…

Mitigation only
Fix from $1,950 2020-10-12
Curam Social Program Management HIGH 7.5
CVE-2020-4776

A path traversal vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10, which could allow a remote attacker to traverse direc…

Mitigation only
Fix from $1,950 2020-10-12
Curam Social Program Management MEDIUM 6.5
CVE-2020-4773

A cross-site request forgery (CSRF) vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10, which is an attack that forces a u…

Mitigation only
Fix from $1,600 2020-10-12
Curam Social Program Management MEDIUM 5.4
CVE-2020-4774

An XPath vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10, caused by the improper handling of user-supplied input. By se…

Mitigation only
Fix from $1,600 2020-10-12
Curam Social Program Management MEDIUM 5.4
CVE-2020-4775

A cross-site scripting (XSS) vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10. This vulnerability allows attackers to in…

Mitigation only
Fix from $1,600 2020-10-12
Security Access Manager MEDIUM 5.3
CVE-2020-4660

IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive using timing side channel attacks…

Mitigation only
Fix from $1,600 2020-10-12
Security Access Manager MEDIUM 5.3
CVE-2020-4661

IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive using timing side channel attacks…

Mitigation only
Fix from $1,600 2020-10-12
Security Access Manager MEDIUM 5.3
CVE-2020-4699

IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive using timing side channel attacks…

Mitigation only
Fix from $1,600 2020-10-12
Qradar Security Information And Event Manager HIGH 8.8
CVE-2020-4280EPSS 73%

IBM QRadar SIEM 7.3 and 7.4 could allow a remote attacker to execute arbitrary commands on the system, caused by insecure deserialization of user-sup…

Fix: after 7.4.1
Fix from $1,950 2020-10-08
Informix Dynamic Server HIGH 7.8
CVE-2020-4799

IBM Informix spatial 14.10 could allow a local user to execute commands as a privileged user due to an out of bounds write vulnerability. IBM X-Force…

Patch available
Fix from $1,950 2020-10-08
Qradar Security Information And Event Manager HIGH 7.5
CVE-2019-4545

IBM QRadar SIEM 7.3 and 7.4 when configured to use Active Directory Authentication may be susceptible to spoofing attacks. IBM X-Force ID: 165877.

Fix: after 7.4.1
Fix from $1,950 2020-10-08
Datapower Gateway MEDIUM 5.5
CVE-2020-4528

IBM MQ Appliance (IBM DataPower Gateway 10.0.0.0 and 2018.4.1.0 through 2018.4.1.12) could allow a local user, under special conditions, to obtain hi…

Fix: after 2018.4.1.12
Fix from $1,600 2020-10-06
Security Access Manager MEDIUM 6.1
CVE-2019-4725

IBM Security Access Manager Appliance 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code i…

Fix: 9.0.7.0+
Fix from $1,600 2020-10-06
Maximo Asset Management CRITICAL 9.8
CVE-2020-4493

IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow an attacker to bypass authentication and issue commands using a specially crafted HTTP comman…

Fix: 7.6.0.10 / 7.6.1.2+
Fix from $2,300 2020-10-05