Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Security Guardium MEDIUM 5.3
CVE-2020-4188

IBM Security Guardium 10.6 and 11.1 may use insufficiently random numbers or values in a security context that depends on unpredictable numbers. IBM …

Mitigation only
Fix from $1,600 2020-06-23
Doors Next MEDIUM 5.4
CVE-2020-4281

IBM DOORS Next Generation (DNG/RRC) 6.0.2, 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed ar…

Mitigation only
Fix from $1,600 2020-06-19
Doors Next MEDIUM 5.4
CVE-2020-4295

IBM DOORS Next Generation (DNG/RRC) 6.0.2, 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed ar…

Mitigation only
Fix from $1,600 2020-06-19
Doors Next MEDIUM 5.4
CVE-2020-4297

IBM DOORS Next Generation (DNG/RRC) 6.0.2, 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed ar…

Mitigation only
Fix from $1,600 2020-06-19
Business Automation Workflow MEDIUM 5.3
CVE-2020-4532

IBM Business Automation Workflow and IBM Business Process Manager (IBM Business Process Manager Express 8.5.5, 8.5.6, 8.5.7, and 8.6) could allow a r…

Fix: 8.5.7.0+
Fix from $1,600 2020-06-17
Mq HIGH 7.5
CVE-2020-4310

IBM MQ and MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 C are vulnerable to a denial of service attack due to an error within the Data Conve…

Fix: 8.0.0.15 / 9.0.0.10+
Fix from $1,950 2020-06-16
Mq MEDIUM 6.5
CVE-2020-4320

IBM MQ Appliance and IBM MQ AMQP Channels 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD do not correctly block or allow clients based on the certificate distingu…

Fix: 8.0.0.15 / 9.0.0.10+
Fix from $1,600 2020-06-16
Spectrum Protect Plus HIGH 8.0
CVE-2020-4470

IBM Spectrum Protect Plus 10.1.0 through 10.1.5 Administrative Console could allow an authenticated attacker to upload arbitrary files which could be…

Fix: after 10.1.5
Fix from $1,950 2020-06-15
Spectrum Protect Client HIGH 7.5
CVE-2020-4494

IBM Spectrum Protect Client 8.1.7.0 through 8.1.9.1 (Linux and Windows), 8.1.9.0 trough 8.1.9.1 (AIX) and IBM Spectrum Protect for Space Management 8…

Fix: after 8.1.9.1
Fix from $1,950 2020-06-15
Spectrum Protect Plus MEDIUM 6.5
CVE-2020-4471

IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow an unauthenticated attacker to cause a denial of service or hijack DNS sessions by send a…

Fix: after 10.1.5
Fix from $1,600 2020-06-15
Spectrum Protect Plus MEDIUM 6.5
CVE-2020-4477

IBM Spectrum Protect Plus 10.1.0 through 10.1.5 discloses highly sensitive information in plain text in the virgo log file which could be used in fur…

Fix: after 10.1.5
Fix from $1,600 2020-06-15
Spectrum Protect Plus CRITICAL 9.8
CVE-2020-4216

IBM Spectrum Protect Plus 10.1.0 through 10.1.5 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own i…

Fix: after 10.1.5
Fix from $2,300 2020-06-15
Spectrum Protect Plus CRITICAL 9.8
CVE-2020-4469EPSS 13%

IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted H…

Fix: after 10.1.5
Fix from $2,300 2020-06-15
Spectrum Protect Client MEDIUM 5.4
CVE-2020-4406

IBM Spectrum Protect Client 8.1.7.0 through 8.1.9.1 (Linux and Windows), 8.1.9.0 trough 8.1.9.1 (AIX) and IBM Spectrum Protect for Space Management 8…

Fix: after 8.1.9.1
Fix from $1,600 2020-06-15
Api Connect MEDIUM 5.4
CVE-2020-4251

IBM API Connect 5.0.0.0 through 5.0.8.8 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in …

Fix: after 5.0.8.8
Fix from $1,600 2020-06-12
Workload Scheduler MEDIUM 5.4
CVE-2020-4380

IBM Workload Scheduler 9.3.0.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web U…

Mitigation only
Fix from $1,600 2020-06-11
Aspera Application Platform On Demand HIGH 7.5
CVE-2020-4433EPSS 5%

Certain IBM Aspera applications are vulnerable to a stack-based buffer overflow, caused by improper bounds checking. This could allow a remote attack…

Fix: after 3.9.10
Fix from $1,950 2020-06-10
Aspera Application Platform On Demand HIGH 7.5
CVE-2020-4434

Certain IBM Aspera applications are vulnerable to buffer overflow based on the product configuration and valid authentication, which could allow an a…

Fix: after 3.9.10
Fix from $1,950 2020-06-10
Aspera Application Platform On Demand HIGH 7.5
CVE-2020-4435

Certain IBM Aspera applications are vulnerable to arbitrary memory corruption based on the product configuration, which could allow an attacker with …

Fix: after 3.9.10
Fix from $1,950 2020-06-10
Aspera Application Platform On Demand HIGH 7.5
CVE-2020-4436

Certain IBM Aspera applications are vulnerable to buffer overflow after valid authentication, which could allow an attacker with intimate knowledge o…

Fix: after 3.9.10
Fix from $1,950 2020-06-10
Aspera Application Platform On Demand HIGH 7.5
CVE-2020-4432

Certain IBM Aspera applications are vulnerable to command injection after valid authentication, which could allow an attacker with intimate knowledge…

Fix: after 3.9.10
Fix from $1,950 2020-06-10
Qradar Network Packet Capture CRITICAL 9.8
CVE-2019-4576

IBM QRadar Network Packet Capture 7.3.0 - 7.3.3 Patch 1 and 7.4.0 GA does not require that users should have strong passwords by default, which makes…

Fix: 7.3.2+
Fix from $2,300 2020-06-10
Maximo Asset Management HIGH 7.4
CVE-2020-4529

IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send una…

Patch available
Fix from $1,950 2020-06-08
Websphere Application Server CRITICAL 9.8
CVE-2020-4448EPSS 12%

IBM WebSphere Application Server Network Deployment 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the system with…

Fix: 8.5.5.18 / 9.0.5.4+
Fix from $2,300 2020-06-05
Websphere Application Server CRITICAL 9.8
CVE-2020-4450EPSS 34%

IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially-craft…

Fix: 8.5.5.18 / 9.0.5.5+
Fix from $2,300 2020-06-05
Websphere Application Server HIGH 7.5
CVE-2020-4449

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to obtain sensitive information with a specially-cr…

Fix: after 9.0.5.4
Fix from $1,950 2020-06-05
Mobile Foundation HIGH 7.3
CVE-2020-4229

IBM Worklight/MobileFoundation 8.0.0.0 does not properly invalidate session cookies when a user logs out of a session, which could allow another user…

Patch available
Fix from $1,950 2020-06-05
Security Guardium CRITICAL 9.8
CVE-2020-4193

IBM Security Guardium 11.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Fo…

Mitigation only
Fix from $2,300 2020-06-04
Qradar Security Information And Event Manager HIGH 7.6
CVE-2020-4509

IBM QRadar SIEM 7.3 and 7.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit …

Mitigation only
Fix from $1,950 2020-06-04
Security Guardium MEDIUM 6.1
CVE-2020-4183

IBM Security Guardium 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI th…

Mitigation only
Fix from $1,600 2020-06-04