Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Guardium Data Encryption MEDIUM 5.3
CVE-2019-4692

IBM Security Guardium Data Encryption (GDE) 3.0.0.2 discloses sensitive information to unauthorized users. The information can be used to mount furth…

Fix: 1.6.2+
Fix from $1,600 2020-08-26
Guardium Data Encryption MEDIUM 5.3
CVE-2019-4701

IBM Security Guardium Data Encryption (GDE) 3.0.0.2 is deployed with active debugging code that can create unintended entry points. IBM X-Force ID: 1…

Fix: 1.7.0+
Fix from $1,600 2020-08-26
Security Guardium HIGH 7.5
CVE-2018-1501

IBM Security Guardium 10.5, 10.6, and 11.0 could allow an unauthorized user to obtain sensitive information due to missing security controls. IBM X-F…

Patch available
Fix from $1,950 2020-08-26
Guardium Data Encryption HIGH 7.5
CVE-2019-4689

IBM Security Guardium Data Encryption (GDE) 3.0.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly …

Fix: 1.7.0 / 4.0.0.3+
Fix from $1,950 2020-08-26
Guardium Data Encryption MEDIUM 5.3
CVE-2019-4686

IBM Security Guardium Data Encryption (GDE) 3.0.0.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be ab…

Fix: 1.7.0 / 4.0.0.3+
Fix from $1,600 2020-08-26
Connect\ HIGH 7.8
CVE-2020-4587

IBM Sterling Connect:Direct for UNIX 4.2.0, 4.3.0, 6.0.0, and 6.1.0 is vulnerable to a stack based buffer ovreflow, caused by improper bounds checkin…

Mitigation only
Fix from $1,950 2020-08-24
Elastic Storage Server MEDIUM 6.5
CVE-2020-4383

IBM Spectrum Scale for IBM Elastic Storage Server 5.3.0 through 5.3.5 could allow an authenticated user to cause a denial of service during deploymen…

Fix: after 5.3.5
Fix from $1,600 2020-08-24
Security Guardium Insights MEDIUM 6.1
CVE-2020-4598

IBM Security Guardium Insights 2.0.1 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim…

Mitigation only
Fix from $1,600 2020-08-24
Elastic Storage Server MEDIUM 5.5
CVE-2020-4382

IBM Spectrum Scale for IBM Elastic Storage Server 5.3.0 through 5.3.5 could allow an authenticated user to cause a denial of service during deploymen…

Fix: after 5.3.5
Fix from $1,600 2020-08-24
Security Guardium Insights MEDIUM 5.4
CVE-2020-4165

IBM Security Guardium Insights 2.0.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a mal…

Mitigation only
Fix from $1,600 2020-08-24
Elastic Storage Server MEDIUM 6.5
CVE-2020-4381

IBM Spectrum Scale for IBM Elastic Storage Server 5.3.0 through 5.3.6 could allow an authenticated user to cause a denial of service during deploymen…

Fix: after 5.3.6
Fix from $1,600 2020-08-19
Planning Analytics MEDIUM 6.5
CVE-2020-4648

A vulnerability exsists in IBM Planning Analytics 2.0 whereby avatars in Planning Analytics Workspace could be modified by other users without author…

Patch available
Fix from $1,600 2020-08-19
Planning Analytics MEDIUM 6.1
CVE-2020-4653

IBM Planning Analytics 2.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit …

Patch available
Fix from $1,600 2020-08-19
Spectrum Virtualize HIGH 8.1
CVE-2020-4686

IBM Spectrum Virtualize 8.3.1 could allow a remote user authenticated via LDAP to escalate their privileges and perform actions they should not have …

Patch available
Fix from $1,950 2020-08-17
Event Streams HIGH 8.8
CVE-2020-4662

IBM Event Streams 10.0.0 could allow an authenticated user to perform tasks to a schema due to improper authentication validation. IBM X-Force ID: 18…

Patch available
Fix from $1,950 2020-08-14
Websphere Application Server CRITICAL 9.8
CVE-2020-4589EPSS 8%

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafte…

Fix: after 9.0.5.4
Fix from $2,300 2020-08-13
Qradar Security Information And Event Manager HIGH 8.1
CVE-2020-4486

IBM QRadar 7.2.0 thorugh 7.2.9 could allow an authenticated user to overwrite or delete arbitrary files due to a flaw after WinCollect installation. …

Fix: after 7.2.9
Fix from $1,950 2020-08-11
Qradar Security Information And Event Manager MEDIUM 6.5
CVE-2020-4485

IBM QRadar 7.2.0 through 7.2.9 could allow an authenticated user to disable the Wincollect service which could aid an attacker in bypassing security …

Fix: after 7.2.9
Fix from $1,600 2020-08-11
Jazz Reporting Service MEDIUM 6.1
CVE-2020-4533

IBM Jazz Reporting Service 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScri…

Patch available
Fix from $1,600 2020-08-10
Jazz Reporting Service MEDIUM 6.1
CVE-2020-4539

IBM Jazz Reporting Service 6.0.2, 6.0.6, 6.0.6.1, 7.0, and 7.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbi…

Patch available
Fix from $1,600 2020-08-10
Jazz Reporting Service MEDIUM 6.1
CVE-2020-4541

IBM Jazz Reporting Service 7.0 and 7.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in…

Patch available
Fix from $1,600 2020-08-10
Urbancode Deploy HIGH 8.2
CVE-2020-4481

IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML …

Mitigation only
Fix from $1,950 2020-08-05
Security Secret Server CRITICAL 9.8
CVE-2020-4459

IBM Security Verify Access 10.7 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentic…

Fix: 10.8+
Fix from $2,300 2020-08-04
Spectrum Protect Plus MEDIUM 5.5
CVE-2020-4631

IBM Spectrum Protect Plus 10.1.0 through 10.1.6 agent files, in non-default configurations, on Windows are assigned access to everyone with full cont…

Fix: after 10.1.6
Fix from $1,600 2020-08-04
Engineering Test Management MEDIUM 5.4
CVE-2020-4396

IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScrip…

Patch available
Fix from $1,600 2020-08-04
Engineering Workflow Management MEDIUM 5.4
CVE-2020-4525

IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScrip…

Patch available
Fix from $1,600 2020-08-04
Engineering Requirements Management Doors Next MEDIUM 5.4
CVE-2020-4542

IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScrip…

Patch available
Fix from $1,600 2020-08-04
Financial Transaction Manager MEDIUM 6.1
CVE-2020-4560

IBM Financial Transaction Manager 3.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in …

Mitigation only
Fix from $1,600 2020-08-03
Cognos Analytics CRITICAL 9.1
CVE-2020-4377

IBM Cognos Anaytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could ex…

Mitigation only
Fix from $2,300 2020-08-03
Websphere Application Server HIGH 8.8
CVE-2020-4534

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local authenticated attacker to gain elevated privileges on the system, caused …

Mitigation only
Fix from $1,950 2020-08-03