Vulnerability index

Browse CVEs

6,286 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.3 CVE-2025-36116 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 GUI is affected by cross-site WebSocket hijacking vulnerability. By sending a specially crafted request, an u… Db2 Mirror For I Mitigation only Fix from $1,6002025-07-23 MEDIUM 6.3 CVE-2025-36117 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 does not disallow the session id after use which could allow an authenticated user to impersonate another user… Db2 Mirror For I Mitigation only Fix from $1,6002025-07-23 MEDIUM 5.5 CVE-2024-41751 IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 could allow a local, authenticated attacker to bypas… Smartcloud Analytics Log Analysis Mitigation only Fix from $1,6002025-07-23 MEDIUM 6.1 CVE-2024-40686 IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 is vulnerable to HTTP header injection, caused by im… Smartcloud Analytics Log Analysis Mitigation only Fix from $1,6002025-07-23 MEDIUM 5.5 CVE-2024-40682 IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 could allow a local user to cause a denial of servic… Smartcloud Analytics Log Analysis No fix yet Fix from $1,6002025-07-23 MEDIUM 5.5 CVE-2024-41750 IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 could allow a local, authenticated attacker to bypas… Smartcloud Analytics Log Analysis Mitigation only Fix from $1,6002025-07-23 HIGH 8.2 CVE-2025-36106 IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 could allow malicious actors to view and modify information coming to and from the application… Cognos Analytics Mobile 1.1.23+ Fix from $1,9502025-07-21 HIGH 7.5 CVE-2025-36062 IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 could be vulnerable to information exposure due to the use of unencrypted network traffic. Cognos Analytics Mobile 1.1.23+ Fix from $1,9502025-07-21 HIGH 7.5 CVE-2025-36107 IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 could allow malicious actors to obtain sensitive information due to the cleartext transmission… Cognos Analytics Mobile 1.1.23+ Fix from $1,9502025-07-21 MEDIUM 6.1 CVE-2025-33014 IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.4 uses a web link with untrusted referenc… Sterling B2b Integrator 6.1.2.7_1 / 6.2.0.5+ Fix from $1,6002025-07-18 HIGH 7.5 CVE-2025-36097 IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7 are vulnerable to a denial of service, caused… Websphere Application Server 9.0.5.24 / 25.0.0.8+ Fix from $1,9502025-07-16 MEDIUM 5.4 CVE-2025-33097 IBM QRadar SIEM 7.5 - 7.5.0 UP12 IF02 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary … Qradar Security Information And Event Manager Mitigation only Fix from $1,6002025-07-15 MEDIUM 6.5 CVE-2025-36104 IBM Storage Scale 5.2.3.0 and 5.2.3.1 could allow an authenticated user to obtain sensitive information from files due to the insecure permissions in… Storage Scale Mitigation only Fix from $1,6002025-07-12 HIGH 7.5 CVE-2025-3631 An IBM MQ 9.3 and 9.4 Client connecting to an MQ Queue Manager can cause a SIGSEGV in the AMQRMPPA channel process terminating it. Mq Appliance 9.4.0.12 / 9.4.3+ Fix from $1,9502025-07-11 CRITICAL 9.8 CVE-2024-39752 IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could be vulnerable to malicious file upload by not validating the type of file uploaded to Explore … Analytics Content Hub 2.4+ Fix from $2,3002025-07-10 MEDIUM 5.3 CVE-2025-36090 IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could allow a remote attacker to obtain information about the application framework which could be u… Analytics Content Hub 2.4+ Fix from $1,6002025-07-10 CRITICAL 9.8 CVE-2024-38327 IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 is vulnerable to information exposure and further attacks due to an exposed JavaScript source map wh… Analytics Content Hub 2.4+ Fix from $2,3002025-07-10 MEDIUM 5.3 CVE-2024-37524 IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could allow a remote attacker to obtain sensitive information when a detailed technical error messag… Analytics Content Hub 2.4+ Fix from $1,6002025-07-10 MEDIUM 6.5 CVE-2024-56468 IBM InfoSphere Data Replication VSAM for z/OS Remote Source 11.4 could allow a remote user to cause a denial of service by sending an invalid HTTP re… Infosphere Data Replication Mitigation only Fix from $1,6002025-07-08 MEDIUM 6.5 CVE-2025-27367 IBM OpenPages with Watson 8.3 and 9.0 is vulnerable to improper input validation due to bypassing of client-side validation for the data types … Openpages With Watson 8.3.0.3.2 / 9.0.0.5.3+ Fix from $1,6002025-07-08 MEDIUM 6.5 CVE-2024-49784 IBM OpenPages with Watson 8.3 and 9.0 could provide weaker than expected security in storage of encrypted data with AES encryption and CBC mode. If… Openpages With Watson 8.3.0.3.1 / 9.0.0.5+ Fix from $1,6002025-07-08 MEDIUM 6.5 CVE-2024-49783 IBM OpenPages with Watson 8.3 and 9.0 could provide weaker than expected security in storage of encrypted data. If an authenticated remote attack… Openpages With Watson 8.3.0.3.1 / 9.0.0.5+ Fix from $1,6002025-07-08 MEDIUM 6.1 CVE-2023-43039 IBM OpenPages with Watson 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI… Openpages With Watson 9.0.0.3+ Fix from $1,6002025-07-08 MEDIUM 5.4 CVE-2025-2793 IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.6, 6.2.0.0 through 6.2.0.4, IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6, and 6.2.0.0 throug… Sterling B2b Integrator 6.1.2.7_1 / 6.2.0.5+ Fix from $1,6002025-07-08 MEDIUM 5.4 CVE-2025-3630 IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.6, 6.2.0.0 through 6.2.0.4, IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6, and 6.2.0.0 throug… Sterling B2b Integrator 6.1.2.7_1 / 6.2.0.5+ Fix from $1,6002025-07-08 MEDIUM 5.9 CVE-2024-43190 IBM Engineering Requirements Management DOORS 9.7.2.9, under certain configurations, could allow a remote attacker to obtain password reset instructi… Engineering Requirements Management Doors after 9.6.1.13 Fix from $1,6002025-07-07 HIGH 7.0 CVE-2025-1351 IBM Storage Virtualize 8.5, 8.6, and 8.7 products could allow a user to escalate their privileges to that of another user logging in at the same time… Storage Virtualize Mitigation only Fix from $1,9502025-07-07 MEDIUM 6.7 CVE-2025-36014 IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.5 is vulnerable to code injection by a privileged user with access to the IIB install directory. Integration Bus after 10.1.0.5 Fix from $1,6002025-07-07 MEDIUM 5.4 CVE-2025-36056 IBM System Storage Virtualization Engine TS7700 3957 VED R5.4 8.54.2.17, R6.0 8.60.0.115, 3948 VED R5.4 8.54.2.17, R6.0 8.60.0.115, and 3948 VEF R6.0… 3957 Ved Firmware after 8.60.0.115 Fix from $1,6002025-07-01 MEDIUM 6.1 CVE-2025-2141 IBM System Storage Virtualization Engine TS7700 3957 VED R5.4 8.54.2.17, R6.0 8.60.0.115, 3948 VED R5.4 8.54.2.17, R6.0 8.60.0.115, and 3948 VEF R6.0… 3948 Vef Firmware after 8.60.0.115 Fix from $1,6002025-07-01