Vulnerability index

Browse CVEs

6,286 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.1 CVE-2024-45097 IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user to bypass intended access restrictions and conduct resource modification. Aspera Faspex 5.0.10+ Fix from $1,9502024-09-05 MEDIUM 6.5 CVE-2024-45096 IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user with access to the package to obtain sensitive information through a directory listing. Aspera Faspex 5.0.10+ Fix from $1,6002024-09-05 CRITICAL 9.9 CVE-2024-45076 IBM webMethods Integration 10.15 could allow an authenticated user to upload and execute arbitrary files which could be executed on the underlying op… Webmethods Integration Mitigation only Fix from $2,3002024-09-04 HIGH 8.8 CVE-2024-45075 IBM webMethods Integration 10.15 could allow an authenticated user to create scheduler tasks that would allow them to escalate their privileges to ad… Webmethods Integration Mitigation only Fix from $1,9502024-09-04 MEDIUM 6.5 CVE-2024-45074 IBM webMethods Integration 10.15 could allow an authenticated user to traverse directories on the system. An attacker could send a specially crafted … Webmethods Integration Mitigation only Fix from $1,6002024-09-04 CRITICAL 9.8 CVE-2024-39747 IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 uses default credentials for potentially critical functionality. Sterling Connect Direct Web Services 6.1.0.25 / 6.2.0.24+ Fix from $2,3002024-08-31 HIGH 8.2 CVE-2024-35133 IBM Security Verify Access 10.0.0 through 10.0.8 OIDC Provider could allow a remote authenticated attacker to conduct phishing attacks, using an open… Security Verify Access after 10.0.8 Fix from $1,9502024-08-29 HIGH 8.1 CVE-2022-43915 IBM App Connect Enterprise Certified Container 5.0, 7.1, 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.… App Connect Enterprise Certified Container Mitigation only Fix from $1,9502024-08-24 HIGH 7.5 CVE-2024-39745 IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 uses weaker than expected cryptographic algorithms that could allow an attacker to de… Sterling Connect Direct Web Services Mitigation only Fix from $1,9502024-08-22 MEDIUM 6.5 CVE-2024-35151 IBM OpenPages with Watson 8.3 and 9.0 could allow authenticated users access to sensitive information through improper authorization controls on APIs. Openpages Grc Platform Mitigation only Fix from $1,6002024-08-22 MEDIUM 5.9 CVE-2024-39746 IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 could allow a remote attacker to obtain sensitive information, caused by the failure … Sterling Connect Direct Web Services Mitigation only Fix from $1,6002024-08-22 MEDIUM 6.5 CVE-2024-41773 IBM Global Configuration Management 7.0.2 and 7.0.3 could allow an authenticated user to archive a global baseline due to improper access controls. Global Configuration Management Mitigation only Fix from $1,6002024-08-20 MEDIUM 6.5 CVE-2023-47728 IBM QRadar Suite Software 1.10.12.0 through 1.10.22.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow a remote attacker to obta… Cloud Pak For Security 1.10.23.0+ Fix from $1,6002024-08-16 CRITICAL 9.8 CVE-2022-33162 IBM Security Directory Integrator 7.2.0 and Security Verify Directory Integrator 10.0.0 does not perform any authentication for functionality that re… Security Directory Integrator Mitigation only Fix from $2,3002024-08-16 MEDIUM 6.5 CVE-2024-40705 IBM InfoSphere Information Server could allow an authenticated user to consume file space resources due to unrestricted file uploads. IBM X-Force ID… Infosphere Information Server Mitigation only Fix from $1,6002024-08-15 MEDIUM 5.9 CVE-2024-31905 IBM QRadar Network Packet Capture 7.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP St… Qradar Network Packet Capture Mitigation only Fix from $1,6002024-08-15 MEDIUM 5.5 CVE-2024-25024 IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores user credentials in plain clea… Cloud Pak For Security 1.10.24.0+ Fix from $1,6002024-08-15 MEDIUM 6.5 CVE-2024-35152 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated user to cause a denial of service with a speciall… Db2 Mitigation only Fix from $1,6002024-08-14 MEDIUM 6.5 CVE-2024-37529 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 could allow an authenticated user to cause a denial of service with a… Db2 after 11.5.9 Fix from $1,6002024-08-14 MEDIUM 6.5 CVE-2024-35136 IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) federated server 10.5, 11.1, and 11.5 is vulnerable to denial of service with a spe… Db2 after 11.5.9 Fix from $1,6002024-08-14 MEDIUM 6.5 CVE-2024-31882 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to a denial of service, under specific non default conf… Db2 after 11.5.9 Fix from $1,6002024-08-14 HIGH 7.5 CVE-2023-50314 IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.8 could allow an attacker with access to the network to conduct spoofing attacks. A… Websphere Application Server after 24.0.0.8 Fix from $1,9502024-08-14 MEDIUM 5.9 CVE-2023-50315 IBM WebSphere Application Server 8.5 and 9.0 could allow an attacker with access to the network to conduct spoofing attacks. An attacker could explo… Websphere Application Server Mitigation only Fix from $1,6002024-08-14 HIGH 7.5 CVE-2024-28799 IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 displays sensitive data improperly to… Cloud Pak For Security after 1.10.23.0 Fix from $1,9502024-08-14 MEDIUM 5.9 CVE-2024-27267 The Object Request Broker (ORB) in IBM SDK, Java Technology Edition 7.1.0.0 through 7.1.5.18 and 8.0.0.0 through 8.0.8.26 is vulnerable to remote den… Java Sdk after 8.0.8.26 Fix from $1,6002024-08-14 HIGH 7.5 CVE-2024-35124 A vulnerability in the combination of the OpenBMC's FW1050.00 through FW1050.10, FW1030.00 through FW1030.50, and FW1020.00 through FW1020.60 default… Openbmc Mitigation only Fix from $1,9502024-08-13 HIGH 7.5 CVE-2024-40697 IBM Common Licensing 9.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user … Common Licensing Mitigation only Fix from $1,9502024-08-13 MEDIUM 5.4 CVE-2023-38018 IBM Aspera Shares 1.10.0 PL2 does not invalidate session after a password change which could allow an authenticated user to impersonate another user … Aspera Shares Mitigation only Fix from $1,6002024-08-12 CRITICAL 9.1 CVE-2024-35143 IBM Planning Analytics Local 2.0 and 2.1 connects to a MongoDB server. MongoDB, a document-oriented database system, is listening on the remote port,… Planning Analytics Workspace 2.0.97 / 2.1.4+ Fix from $2,3002024-08-04 MEDIUM 6.5 CVE-2024-38321 IBM Business Automation Workflow 22.0.2, 23.0.1, 23.0.2, and 24.0.0 stores potentially sensitive information in log files under certain situations th… Business Automation Workflow after 22.0.2 Fix from $1,6002024-08-03