Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Security Guardium CRITICAL 9.8
CVE-2020-4177

IBM Security Guardium 11.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication…

Patch available
Fix from $2,300 2020-06-03
Security Guardium HIGH 8.8
CVE-2020-4180

IBM Security Guardium 11.1 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted re…

Patch available
Fix from $1,950 2020-06-03
Security Guardium MEDIUM 6.7
CVE-2020-4190

IBM Security Guardium 10.6, 11.0, and 11.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inboun…

Patch available
Fix from $1,600 2020-06-03
Security Guardium MEDIUM 6.5
CVE-2020-4307

IBM Security Guardium 11.1 could allow an attacker on the same network to gain access to the Solr dashboard and cause a denial of service attack. IBM…

Patch available
Fix from $1,600 2020-06-03
Security Guardium MEDIUM 6.1
CVE-2020-4182

IBM Security Guardium 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI th…

Patch available
Fix from $1,600 2020-06-03
Security Guardium MEDIUM 5.3
CVE-2020-4187

IBM Security Guardium 11.1 could disclose sensitive information on the login page that could aid in further attacks against the system. IBM X-Force I…

Patch available
Fix from $1,600 2020-06-03
Planning Analytics Local HIGH 7.5
CVE-2020-4367

IBM Planning Analytics Local 2.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive informat…

Fix: 2.0.9.1+
Fix from $1,950 2020-06-02
Planning Analytics Local MEDIUM 6.1
CVE-2020-4503

IBM Planning Analytics Local 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web…

Fix: 2.0.9.1+
Fix from $1,600 2020-06-02
Planning Analytics Local MEDIUM 5.4
CVE-2020-4431

IBM Planning Analytics Local 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web…

Fix: 2.0.9.1+
Fix from $1,600 2020-06-02
Planning Analytics Local MEDIUM 6.1
CVE-2020-4366

IBM Planning Analytics Local 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web…

Fix: 2.0.9.1+
Fix from $1,600 2020-06-02
Planning Analytics Local MEDIUM 5.4
CVE-2020-4360

IBM Planning Analytics Local 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web…

Fix: 2.0.9.1+
Fix from $1,600 2020-06-02
Mq For Hpe Nonstop HIGH 7.0
CVE-2020-4352

IBM MQ on HPE NonStop 8.0.4 and 8.1.0 is vulnerable to a privilege escalation attack when running in restricted mode. IBM X-Force ID: 178427.

Mitigation only
Fix from $1,950 2020-05-29
Business Automation Workflow MEDIUM 6.1
CVE-2020-4490

IBM Business Automation Workflow 18 and 19, and IBM Business Process Manager 8.0, 8.5, and 8.6 could allow a remote attacker to bypass security restr…

Mitigation only
Fix from $1,600 2020-05-29
Planning Analytics Local MEDIUM 5.4
CVE-2020-4306

IBM Planning Analytics Local 2.0.0 through 2.0.9 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript…

Fix: after 2.0.9
Fix from $1,600 2020-05-29
Security Identity Governance And Intelligence HIGH 7.5
CVE-2020-4232

IBM Security Identity Governance and Intelligence 5.2.6 could allow an attacker to enumerate usernames to find valid login credentials which could be…

Patch available
Fix from $1,950 2020-05-28
Security Identity Governance And Intelligence HIGH 7.5
CVE-2020-4245

IBM Security Identity Governance and Intelligence 5.2.6 does not require that users should have strong passwords by default, which makes it easier fo…

Patch available
Fix from $1,950 2020-05-28
Security Identity Governance And Intelligence HIGH 7.1
CVE-2020-4246

IBM Security Identity Governance and Intelligence 5.2.6 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A re…

Patch available
Fix from $1,950 2020-05-28
Security Identity Governance And Intelligence MEDIUM 6.5
CVE-2020-4231

IBM Security Identity Governance and Intelligence 5.2.6 could allow an authenticated user to perform unauthorized commands due to hazardous input val…

Patch available
Fix from $1,600 2020-05-28
Security Identity Governance And Intelligence MEDIUM 6.5
CVE-2020-4249

IBM Security Identity Governance and Intelligence 5.2.6 could disclose highly sensitive information to other authenticated users on the sytem due to …

Patch available
Fix from $1,600 2020-05-28
Jazz Reporting Service MEDIUM 5.4
CVE-2020-4419

IBM Jazz Reporting Service 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScri…

Patch available
Fix from $1,600 2020-05-28
Security Identity Governance And Intelligence MEDIUM 5.3
CVE-2020-4233

IBM Security Identity Governance and Intelligence 5.2.6 could allow a remote attacker to obtain sensitive information, caused by the failure to set t…

Patch available
Fix from $1,600 2020-05-28
Security Identity Governance And Intelligence MEDIUM 5.3
CVE-2020-4244

IBM Security Identity Governance and Intelligence 5.2.6 could allow an unauthorized user to obtain sensitive information through user enumeration. IB…

Patch available
Fix from $1,600 2020-05-28
Mobilefirst Platform Foundation HIGH 7.5
CVE-2020-4226

IBM MobileFirst Platform Foundation 8.0.0.0 stores highly sensitive information in URL parameters. This may lead to information disclosure if unautho…

Patch available
Fix from $1,950 2020-05-27
Spectrum Scale HIGH 7.5
CVE-2020-4349

IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitiv…

Fix: after 5.0.4.4
Fix from $1,950 2020-05-27
Spectrum Scale HIGH 7.5
CVE-2020-4350

IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitiv…

Fix: after 5.0.4.4
Fix from $1,950 2020-05-27
Spectrum Scale HIGH 7.5
CVE-2020-4379

IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitiv…

Fix: after 5.0.4.4
Fix from $1,950 2020-05-27
Spectrum Scale MEDIUM 6.5
CVE-2020-4348

IBM Spectrum Scale 4.2.0.0 through 4.2.3.21 and 5.0.0.0 through 5.0.4.4 could allow an authenticated GUI user to perform unauthorized actions due to …

Fix: after 5.0.4.4
Fix from $1,600 2020-05-27
Spectrum Scale MEDIUM 5.4
CVE-2020-4358

IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code …

Fix: after 5.0.4.4
Fix from $1,600 2020-05-27
Security Access Manager MEDIUM 6.5
CVE-2020-4461

IBM Security Access Manager Appliance 9.0.7.1 could allow an authenticated user to bypass security by allowing id_token claims manipulation without v…

Fix: 9.0.7.1+
Fix from $1,600 2020-05-20
Spectrum Scale HIGH 7.1
CVE-2020-4411

The Spectrum Scale 4.2.0.0 through 4.2.3.21 and 5.0.0.0 through 5.0.4.3 file system component is affected by a denial of service vulnerability in its…

Fix: after 5.0.4.3
Fix from $1,950 2020-05-19