Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

I2 Analysts Notebook HIGH 7.8
CVE-2020-4549

IBM i2 Analyst Notebook 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a vi…

Mitigation only
Fix from $1,950 2020-08-03
I2 Analysts Notebook HIGH 7.8
CVE-2020-4550

IBM i2 Analyst Notebook 9.2.1 and 9.2.2 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persu…

Mitigation only
Fix from $1,950 2020-08-03
I2 Analysts Notebook HIGH 7.8
CVE-2020-4551

IBM i2 Analyst Notebook 9.2.1 and 9.2.2 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persu…

Mitigation only
Fix from $1,950 2020-08-03
I2 Analysts Notebook HIGH 7.8
CVE-2020-4552

IBM i2 Analyst Notebook 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a vi…

Mitigation only
Fix from $1,950 2020-08-03
I2 Analysts Notebook HIGH 7.8
CVE-2020-4553

IBM i2 Analyst Notebook 9.2.1 and 9.2.2 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persu…

Mitigation only
Fix from $1,950 2020-08-03
I2 Analysts Notebook HIGH 7.8
CVE-2020-4554

IBM i2 Analyst Notebook 9.2.1 and 9.2.2 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persu…

Mitigation only
Fix from $1,950 2020-08-03
Financial Transaction Manager For Multiplatform MEDIUM 6.3
CVE-2020-4328

IBM Financial Transaction Manager 3.2.4 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could al…

Mitigation only
Fix from $1,600 2020-08-03
Cognos Analytics MEDIUM 5.3
CVE-2019-4366

IBM Cognos Analytics 11.0 and 11.1 is susceptible to an information disclosure vulnerability where an attacker could gain access to cached browser da…

Mitigation only
Fix from $1,600 2020-08-03
Security Guardium HIGH 7.5
CVE-2020-4185

IBM Security Guardium 10.5, 10.6, and 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitiv…

Patch available
Fix from $1,950 2020-07-30
Security Guardium MEDIUM 5.3
CVE-2020-4186

IBM Security Guardium 10.5, 10.6, and 11.1 could disclose sensitive information on the login page that could aid in further attacks against the syste…

Patch available
Fix from $1,600 2020-07-30
Security Key Lifecycle Manager CRITICAL 9.8
CVE-2020-4567

IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account c…

Patch available
Fix from $2,300 2020-07-29
Maximo Asset Management HIGH 8.2
CVE-2020-4463EPSS 32%

IBM Maximo Asset Management 7.6.0.1 and 7.6.0.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote att…

Patch available
Fix from $1,950 2020-07-29
Security Key Lifecycle Manager HIGH 7.5
CVE-2020-4574

IBM Tivoli Key Lifecycle Manager does not require that users should have strong passwords by default, which makes it easier for attackers to compromi…

Patch available
Fix from $1,950 2020-07-29
Security Key Lifecycle Manager MEDIUM 6.5
CVE-2020-4569

IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 uses a protection mechanism that relies on the existence or values of an input, but the input can be m…

Patch available
Fix from $1,600 2020-07-29
Planning Analytics Local MEDIUM 5.4
CVE-2020-4644

IBM Planning Analytics Local 2.0.0 through 2.0.9.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim …

Fix: after 2.0.9.1
Fix from $1,600 2020-07-29
Planning Analytics Local MEDIUM 5.4
CVE-2020-4645

IBM Planning Analytics Local 2.0.0 through 2.0.9.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScri…

Fix: after 2.0.9.1
Fix from $1,600 2020-07-29
Security Key Lifecycle Manager MEDIUM 5.3
CVE-2020-4572

IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message …

Patch available
Fix from $1,600 2020-07-29
Security Key Lifecycle Manager MEDIUM 5.3
CVE-2020-4573

IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 could disclose sensitive information due to responding to unauthenticated HTTP requests. IBM X-Force I…

Patch available
Fix from $1,600 2020-07-29
Mq Appliance HIGH 7.5
CVE-2020-4375

IBM MQ, IBM MQ Appliance, IBM MQ for HPE NonStop 8.0, 9.1 CD, and 9.1 LTS could allow an attacker to cause a denial of service due to a memory leak c…

Fix: 8.0.0.15 / 9.1.0.6+
Fix from $1,950 2020-07-28
Mq Appliance MEDIUM 6.5
CVE-2020-4465

IBM MQ, IBM MQ Appliance, and IBM MQ for HPE NonStop 8.0, 9.1 CD, and 9.1 LTS is vulnerable to a buffer overflow vulnerability due to an error within…

Fix: 8.0.0.15 / 9.1.0.6+
Fix from $1,600 2020-07-28
Intelligent Operations Center MEDIUM 5.4
CVE-2020-4317

IBM Intelligent Operations Center for Emergency Management, Intelligent Operations Center (IOC), and IBM Water Operations for Waternamics are vulnera…

Patch available
Fix from $1,600 2020-07-28
Intelligent Operations Center MEDIUM 5.4
CVE-2020-4318

IBM Intelligent Operations Center for Emergency Management, Intelligent Operations Center (IOC), and IBM Water Operations for Waternamics are vulnera…

Patch available
Fix from $1,600 2020-07-28
Mq Appliance MEDIUM 5.5
CVE-2019-4731

IBM MQ Appliance 9.1.4.CD could allow a local attacker to obtain highly sensitive information by inclusion of sensitive data within trace. IBM X-Forc…

Patch available
Fix from $1,600 2020-07-28
Filenet Content Manager MEDIUM 5.4
CVE-2020-4447

IBM FileNet Content Manager 5.5.3 and 5.5.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code…

Patch available
Fix from $1,600 2020-07-23
Verify Gateway CRITICAL 9.8
CVE-2020-4385

IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound …

Patch available
Fix from $2,300 2020-07-22
Verify Gateway HIGH 7.8
CVE-2020-4372

IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 179009

Patch available
Fix from $1,950 2020-07-22
Verify Gateway HIGH 7.5
CVE-2020-4400

IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credent…

Patch available
Fix from $1,950 2020-07-22
Verify Gateway MEDIUM 6.5
CVE-2020-4399

IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 could allow an authenticated user to send malformed requests to cause a denial of service against the server…

Patch available
Fix from $1,600 2020-07-22
Verify Gateway MEDIUM 5.9
CVE-2020-4397

IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 transmits sensitive information in plain text which could be obtained by an attacker using man in the middle…

Patch available
Fix from $1,600 2020-07-22
Verify Gateway MEDIUM 5.5
CVE-2020-4369

IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 stores highly sensitive information in cleartext that could be obtained by a user. IBM X-Force ID: 179004.

Patch available
Fix from $1,600 2020-07-22