Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.1
CVE-2018-1727
IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A…
Infosphere Information Server
Mitigation only
HIGH 8.5
CVE-2018-1701
IBM InfoSphere Information Server 11.7 could allow an authenciated user under specialized conditions to inject commands into the installation process…
Infosphere Information Server
Patch available
HIGH 7.5
CVE-2017-1695
IBM QRadar SIEM 7.2 and 7.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. …
Qradar Security Information And Event Manager
after 7.3.1
MEDIUM 5.4
CVE-2018-1895
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Java…
Infosphere Information Governance Catalog
Mitigation only
CRITICAL 9.8
CVE-2019-4008
API Connect V2018.1 through 2018.4.1.1 is impacted by access token leak. Authorization tokens in some URLs can result in the tokens being written to …
Api Connect
after 2018.4.1.1
MEDIUM 5.9
CVE-2017-1200
IBM BigFix Compliance 1.7 through 1.9.91 (TEMA SUAv1 SCA SCM) does not validate, or incorrectly validates, a certificate.This weakness might allow an…
Bigfix Compliance
after 1.9.91
MEDIUM 5.4
CVE-2017-1202
IBM BigFix Compliance 1.7 through 1.9.91 (TEMA SUAv1 SCA SCM) is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, wh…
Bigfix Compliance
after 1.9.91
MEDIUM 5.3
CVE-2017-1177
IBM BigFix Compliance 1.7 through 1.9.91 discloses sensitive information to unauthorized users. The information can be used to mount further attacks …
Bigfix Compliance
after 1.9.91
MEDIUM 5.3
CVE-2017-1198
IBM BigFix Compliance 1.7 through 1.9.91 (TEMA SUAv1 SCA SCM) stores sensitive information in URL parameters. This may lead to information disclosure…
Bigfix Compliance
after 1.9.91
MEDIUM 6.2
CVE-2019-4038
IBM Security Identity Manager 6.0 and 7.0 could allow an attacker to create unexpected control flow paths through the application, potentially bypass…
Security Identity Manager
after 7.0.1.10
HIGH 7.5
CVE-2018-1675
IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 could expose password hashes in stored in system memory on target systems that are …
Tivoli Application Dependency Discovery Manager
after 7.3.0.5
HIGH 7.1
CVE-2018-1970
IBM Security Identity Manager 7.0.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could e…
Security Access Manager
after 7.0.1.10
MEDIUM 5.3
CVE-2018-1801
IBM App Connect V11.0.0.0 through V11.0.0.1, IBM Integration Bus V10.0.0.0 through V10.0.0.13, IBM Integration Bus V9.0.0.0 through V9.0.0.10, and We…
App Connect
after 11.0.0.1
MEDIUM 6.1
CVE-2019-4040
IBM I 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alteri…
I
Mitigation only
HIGH 7.5
CVE-2018-1668
IBM DataPower Gateway 7.5.0.0 through 7.5.0.19, 7.5.1.0 through 7.5.1.18, 7.5.2.0 through 7.5.2.18, and 7.6.0.0 through 7.6.0.11 appliances allows "n…
Datapower Gateway
after 7.6.0.11
MEDIUM 5.3
CVE-2018-1733
IBM QRadar SIEM 7.2 and 7.3 fails to adequately filter user-controlled input data for syntax that has control-plane implications which could allow an…
Qradar Security Information And Event Manager
after 7.3.1
HIGH 7.8
CVE-2018-1959
IBM Security Identity Manager 7.0.1 Virtual Appliance contains hard-coded credentials, such as a password or cryptographic key, which it uses for its…
Security Identity Manager
after 7.0.1.10
HIGH 7.5
CVE-2018-1751
IBM Security Key Lifecycle Manager 3.0 through 3.0.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt hig…
Security Key Lifecycle Manager
after 3.0.0.2
HIGH 7.1
CVE-2018-2019
IBM Security Identity Manager 6.0.0 Virtual Appliance is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remot…
Security Identity Manager
Patch available
MEDIUM 5.4
CVE-2018-1772
IBM SPSS Analytic Server 3.1.1.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web…
Spss Analytic Server
Mitigation only
CRITICAL 9.9
CVE-2018-1969
IBM Security Identity Manager 6.0.0 allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the…
Security Identity Manager
after 6.0.0.20
HIGH 7.5
CVE-2018-1956
IBM Security Identity Manager 6.0.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compr…
Security Identity Manager
after 6.0.0.20
MEDIUM 6.1
CVE-2018-1967
IBM Security Identity Manager 6.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the …
Security Identity Manager
after 6.0.0.20
MEDIUM 5.4
CVE-2018-1918
IBM Jazz Reporting Service (JRS) 6.0.3, 6.0.4, 6.0.5, and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbit…
Jazz Reporting Service
after 6.0.6
HIGH 7.8
CVE-2018-1888
An untrusted search path vulnerability in IBM i Access for Windows versions 7.1 and earlier on Windows can allow arbitrary code execution via a Troja…
I Access
after 7.1
MEDIUM 5.4
CVE-2018-1657
IBM Publishing Engine 2.1.2, 6.0.5, and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript co…
Engineering Lifecycle Optimization Publishing
Patch available
MEDIUM 5.4
CVE-2018-1951
IBM Publishing Engine 2.1.2, 6.0.5, and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript co…
Engineering Lifecycle Optimization Publishing
Patch available
CRITICAL 9.8
CVE-2018-1784
IBM API Connect 5.0.0.0 and 5.0.8.4 is affected by a NoSQL Injection in MongoDB connector for the LoopBack framework. IBM X-Force ID: 148807.
Api Connect
after 5.0.8.4
HIGH 8.8
CVE-2018-1661
IBM DataPower Gateways 7.5, 7.5.1, 7.5.2, and 7.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and …
Datapower Gateway
after 7.6.0.9
HIGH 8.1
CVE-2018-1778
IBM LoopBack (IBM API Connect 2018.1, 2018.4.1, 5.0.8.0, and 5.0.8.4) could allow an attacker to bypass authentication if the AccessToken Model is ex…
Api Connect
after 2018.4.1.0