Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Business Automation Workflow MEDIUM 5.4
CVE-2020-4516

IBM Business Process Manager 8.5, 8.6 and IBM Business Automation Workflow 18.0, 19.0, and 20.0 are vulnerable to cross-site scripting. This vulnerab…

Patch available
Fix from $1,600 2020-09-08
Business Automation Workflow MEDIUM 5.4
CVE-2020-4698

IBM Business Process Manager 8.5, 8.6 and IBM Business Automation Workflow 18.0, 19.0, and 20.0 are vulnerable to stored cross-site scripting. This v…

Patch available
Fix from $1,600 2020-09-08
Aspera Connect HIGH 7.8
CVE-2020-4545

IBM Aspera Connect 3.9.9 could allow a remote attacker to execute arbitrary code on the system, caused by improper loading of Dynamic Link Libraries …

Fix: after 3.9.9
Fix from $1,950 2020-09-04
Infosphere Metadata Asset Manager MEDIUM 6.5
CVE-2020-4632

IBM InfoSphere Metadata Asset Manager 11.7 is vulnerable to server-side request forgery. By sending a specially crafted request, a remote authenticat…

Mitigation only
Fix from $1,600 2020-09-04
Infosphere Information Server MEDIUM 5.4
CVE-2020-4702

IBM InfoSphere Information Server 11.7 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript co…

Mitigation only
Fix from $1,600 2020-09-04
Api Connect HIGH 7.2
CVE-2020-4638

IBM API Connect's API Manager 2018.4.1.0 through 2018.4.1.12 is vulnerable to privilege escalation. An invitee to an API Provider organization can es…

Fix: after 2018.4.1.12
Fix from $1,950 2020-09-03
Api Connect MEDIUM 6.5
CVE-2020-4337

IBM API Connect 2018.4.1.0 through 2018.4.1.12 could allow an attacker to launch phishing attacks by tricking the server to generate user registratio…

Fix: after 2018.4.1.12
Fix from $1,600 2020-09-03
Spectrum Protect Operations Center CRITICAL 9.8
CVE-2020-4693

IBM Spectrum Protect Operations Center 7.1.0.000 through 7.1.10 and 8.1.0.000 through 8.1.9 may allow an attacker to execute arbitrary code on the sy…

Fix: after 8.1.9.000
Fix from $2,300 2020-09-02
Doors Next MEDIUM 5.4
CVE-2020-4445

IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in…

Mitigation only
Fix from $1,600 2020-09-02
Doors Next MEDIUM 5.4
CVE-2020-4522

IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in…

Mitigation only
Fix from $1,600 2020-09-02
Doors Next MEDIUM 5.4
CVE-2020-4546

IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in…

Mitigation only
Fix from $1,600 2020-09-02
Infosphere Guardium MEDIUM 5.4
CVE-2012-3341

IBM InfoSphere Guardium 7.0, 8.0, 8.01, and 8.2 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote…

Mitigation only
Fix from $1,600 2020-09-01
Infosphere Guardium MEDIUM 5.3
CVE-2012-3338

IBM InfoSphere Guardium 8.0, 8.01, and 8.2 could allow a remote attacker to bypass security restrictions, caused by improper restrictions on the crea…

Mitigation only
Fix from $1,600 2020-09-01
Infosphere Guardium MEDIUM 5.3
CVE-2012-3337

IBM InfoSphere Guardium 8.0, 8.01, and 8.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-cr…

Mitigation only
Fix from $1,600 2020-09-01
Infosphere Guardium HIGH 8.8
CVE-2012-3336

IBM InfoSphere Guardium 8.0, 8.01, and 8.2 is vulnerable to SQL injection. A remote authenticated attacker could send specially-crafted SQL statement…

Mitigation only
Fix from $1,950 2020-09-01
Spectrum Scale MEDIUM 5.5
CVE-2020-4492

IBM Spectrum Scale V5.0.0.0 through V5.0.4.3 and V4.2.0.0 through V4.2.3.21 could allow a local attacker to cause a denial of service crashing the ke…

Fix: after 5.0.4.3
Fix from $1,600 2020-08-31
Spectrum Protect HIGH 7.5
CVE-2020-4559

IBM Spectrum Protect 7.1 and 8.1 could allow an attacker to cause a denial of service due ti improper validation of user-supplied input. IBM X-Force …

Fix: after 8.1.10.000
Fix from $1,950 2020-08-28
Security Guardium Insights HIGH 7.2
CVE-2020-4603

IBM Security Guardium Insights 2.0.1 performs an operation at a privilege level that is higher than the minimum level required, which creates new wea…

Patch available
Fix from $1,950 2020-08-27
Websphere Application Server MEDIUM 6.1
CVE-2020-4575

IBM WebSphere Application Server ND 8.5 and 9.0, and IBM WebSphere Virtual Enterprise 7.0 and 8.0 are vulnerable to cross-site scripting when High Av…

Fix: 8.5.5.18 / 9.0.5.5+
Fix from $1,600 2020-08-27
Security Guardium Insights MEDIUM 5.9
CVE-2020-4175

IBM Security Guardium Insights 2.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Str…

Patch available
Fix from $1,600 2020-08-27
Security Guardium Insights HIGH 7.5
CVE-2020-4169

IBM Security Guardium Insights 2.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive info…

Patch available
Fix from $1,950 2020-08-27
Security Guardium Insights HIGH 7.5
CVE-2020-4174

IBM Security Guardium Insights 2.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive info…

Patch available
Fix from $1,950 2020-08-27
Security Guardium Insights MEDIUM 6.5
CVE-2020-4167

IBM Security Guardium Insights 2.0.1 could allow an attacker to obtain sensitive information or perform unauthorized actions due to improper authenci…

Patch available
Fix from $1,600 2020-08-27
Security Guardium Insights MEDIUM 5.3
CVE-2020-4166

IBM Security Guardium Insights 2.0.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returne…

Patch available
Fix from $1,600 2020-08-27
Security Guardium Insights MEDIUM 5.3
CVE-2020-4172

IBM Security Guardium Insights 2.0.1 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties …

Patch available
Fix from $1,600 2020-08-27
Guardium Data Encryption CRITICAL 9.8
CVE-2019-4694

IBM Security Guardium Data Encryption (GDE) 3.0.0.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its o…

Fix: 1.7.0+
Fix from $2,300 2020-08-26
Guardium Data Encryption HIGH 8.8
CVE-2019-4713

IBM Security Guardium Data Encryption (GDE) 3.0.0.2 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sendi…

Fix: 1.7.0+
Fix from $1,950 2020-08-26
Guardium Data Encryption HIGH 7.5
CVE-2019-4698

IBM Security Guardium Data Encryption (GDE) 3.0.0.2 does not require that users should have strong passwords by default, which makes it easier for at…

Fix: 1.7.0+
Fix from $1,950 2020-08-26
Guardium Data Encryption MEDIUM 6.5
CVE-2019-4697

IBM Security Guardium Data Encryption (GDE) 3.0.0.2 stores user credentials in plain in clear text which can be read by an authenticated user. IBM X-…

Fix: 1.7.0+
Fix from $1,600 2020-08-26
Guardium Data Encryption MEDIUM 5.4
CVE-2019-4691

IBM Security Guardium Data Encryption (GDE) 3.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScr…

Fix: 1.7.0 / 4.0.0.3+
Fix from $1,600 2020-08-26