Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Websphere Application Server HIGH 7.5
CVE-2020-4576

IBM WebSphere Application Server 7.5, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to obtain sensitive information with a specially-cr…

Fix: 7.0.0.45 / 8.0.0.15+
Fix from $1,950 2020-10-01
Security Verify Privilege Vault Remote On Premises HIGH 7.8
CVE-2020-4607

IBM Security Secret Server (IBM Security Verify Privilege Vault Remote 1.2 ) could allow a local user to bypass security restrictions due to improper…

Patch available
Fix from $1,950 2020-09-29
Infosphere Information Server MEDIUM 6.1
CVE-2020-4727

IBM InfoSphere Information Server 11.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a m…

Mitigation only
Fix from $1,600 2020-09-25
Business Automation Workflow MEDIUM 5.3
CVE-2020-4531

IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.0, 8.5, and 8.6 could allow a remote attacker to obtain sens…

Mitigation only
Fix from $1,600 2020-09-25
Data Risk Manager HIGH 8.8
CVE-2020-4620EPSS 5%

IBM Data Risk Manager (iDNA) 2.0.6 could allow a remote authenticated attacker to upload arbitrary files, caused by the improper validation of file e…

Fix: 2.0.6.4+
Fix from $1,950 2020-09-22
Data Risk Manager HIGH 8.8
CVE-2020-4621

IBM Data Risk Manager (iDNA) 2.0.6 could allow an authenticated user to escalate their privileges to administrator due to insufficient authorization …

Fix: 2.0.6.4+
Fix from $1,950 2020-09-22
Data Risk Manager HIGH 7.5
CVE-2020-4622

IBM Data Risk Manager (iDNA) 2.0.6 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authen…

Fix: 2.0.6.4+
Fix from $1,950 2020-09-22
Data Risk Manager MEDIUM 6.5
CVE-2020-4619

IBM Data Risk Manager (iDNA) 2.0.6 stores user credentials in plain in clear text which can be read by an authenticated user. IBM X-Force ID: 184976.

Fix: 2.0.6.4+
Fix from $1,600 2020-09-22
Data Risk Manager HIGH 8.8
CVE-2020-4611

IBM Data Risk Manager (iDNA) 2.0.6 could allow an authenticated user to bypass security and execute actions reserved for admins. IBM X-Force ID: 1849…

Fix: 2.0.6.4+
Fix from $1,950 2020-09-22
Data Risk Manager HIGH 8.1
CVE-2020-4617

IBM Data Risk Manager (iDNA) 2.0.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized ac…

Fix: 2.0.6.4+
Fix from $1,950 2020-09-22
Data Risk Manager HIGH 7.5
CVE-2020-4613

IBM Data Risk Manager (iDNA) 2.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive inform…

Fix: 2.0.6.4+
Fix from $1,950 2020-09-22
Data Risk Manager HIGH 7.5
CVE-2020-4614

IBM Data Risk Manager (iDNA) 2.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive information. …

Fix: 2.0.6.4+
Fix from $1,950 2020-09-22
Data Risk Manager MEDIUM 6.5
CVE-2020-4612

IBM Data Risk Manager (iDNA) 2.0.6 could allow an authenticated user to obtain sensitive information using a specially crafted HTTP request. IBM X-Fo…

Fix: 2.0.6.4+
Fix from $1,600 2020-09-22
Data Risk Manager MEDIUM 5.4
CVE-2020-4615

IBM Data Risk Manager (iDNA) 2.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the W…

Fix: 2.0.6.4+
Fix from $1,600 2020-09-22
Data Risk Manager MEDIUM 5.3
CVE-2020-4616

IBM Data Risk Manager (iDNA) 2.0.6 could disclose sensitive username information to an attacker using a specially crafted HTTP request. IBM X-Force I…

Fix: 2.0.6.4+
Fix from $1,600 2020-09-22
Websphere Application Server HIGH 7.5
CVE-2020-4643

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A re…

Fix: after 9.0.5.5
Fix from $1,950 2020-09-21
Websphere Application Server MEDIUM 6.5
CVE-2020-4590

IBM WebSphere Application Server Liberty 17.0.0.3 through 20.0.0.9 running oauth-2.0 or openidConnectServer-1.0 server features is vulnerable to a de…

Fix: after 20.0.0.9
Fix from $1,600 2020-09-21
Aspera Shares MEDIUM 6.1
CVE-2020-4731

IBM Aspera Web Application 1.9.14 PL1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in th…

Fix: after 1.9.14
Fix from $1,600 2020-09-21
Datapower Gateway HIGH 7.5
CVE-2020-4579

IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.12 could allow a remote attacker to cause a denial of service by sending a specially crafted HTTP/2…

Fix: after 2018.4.1.12
Fix from $1,950 2020-09-21
Datapower Gateway HIGH 7.5
CVE-2020-4580

IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.12 could allow a remote attacker to cause a denial of service by sending a specially crafted a JSON…

Fix: after 2018.4.1.12
Fix from $1,950 2020-09-21
Datapower Gateway HIGH 7.5
CVE-2020-4581

IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.12 could allow a remote attacker to cause a denial of service by sending a chunked transfer-encodin…

Fix: after 2018.4.1.12
Fix from $1,950 2020-09-21
Control Desk HIGH 8.2
CVE-2020-4409

IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote attacker to conduct phishing attacks, using a tabnabbing attack. By persuading a vic…

Fix: 7.6.1.2+
Fix from $1,950 2020-09-16
Security Trusteer Pinpoint Detect MEDIUM 5.3
CVE-2020-4708

IBM Security Trusteer Pinpoint Detect 11.6.5 could disclose some information due to using a wildcard in the Access-Control-Allow-Origin header. IBM X…

Fix: 11.6.5.2+
Fix from $1,600 2020-09-16
Bladecenter Advanced Management Module Firmware MEDIUM 6.1
CVE-2020-8339

A cross-site scripting inclusion (XSSI) vulnerability was reported in the legacy IBM BladeCenter Advanced Management Module (AMM) web interface prior…

Fix: 3.68n+
Fix from $1,600 2020-09-15
Maximo Asset Management HIGH 8.8
CVE-2020-4521EPSS 6%

IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unsafe …

Fix: 7.6.0.10 / 7.6.1.2+
Fix from $1,950 2020-09-15
Spectrum Protect Plus HIGH 8.0
CVE-2020-4703

IBM Spectrum Protect Plus 10.1.0 through 10.1.6 Administrative Console could allow an authenticated attacker to upload arbitrary files which could be…

Fix: after 10.1.6
Fix from $1,950 2020-09-15
Spectrum Protect Plus MEDIUM 6.5
CVE-2020-4711

IBM Spectrum Protect Plus 10.1.0 through 10.1.6 could allow a remote attacker to traverse directories on the system. An attacker could send a special…

Fix: after 10.1.6
Fix from $1,600 2020-09-15
Business Automation Workflow MEDIUM 5.4
CVE-2020-4530

IBM Business Automation Workflow C.D.0 and IBM Business Process Manager 8.0, 8.5, and 8.6 are vulnerable to cross-site scripting. This vulnerability …

Fix: 8.0.1.0 / 8.5.7.0+
Fix from $1,600 2020-09-15
Maximo Asset Management MEDIUM 6.3
CVE-2019-4671

IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which coul…

Fix: 7.6.0.10 / 7.6.1.2+
Fix from $1,600 2020-09-15
Websphere Application Server MEDIUM 5.4
CVE-2020-4578

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav…

Fix: after 9.0.5.5
Fix from $1,600 2020-09-10