Vulnerability index

Browse CVEs

6,330 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.9 CVE-2023-22870 IBM Aspera Faspex 5.0.5 transmits sensitive information in cleartext which could be obtained by an attacker using man in the middle techniques. IBM … Aspera Faspex after 5.0.5 Fix from $1,6002023-09-05 MEDIUM 5.5 CVE-2023-29261 IBM Sterling Secure Proxy 6.0.3 and 6.1.0 could allow a local user with specific information about the system to obtain privileged information due to… Sterling External Authentication Server Mitigation only Fix from $1,6002023-09-05 CRITICAL 9.1 CVE-2023-35892 IBM Financial Transaction Manager for SWIFT Services 3.2.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A… Financial Transaction Manager Mitigation only Fix from $2,3002023-09-05 MEDIUM 6.5 CVE-2022-43903 IBM Security Guardium 10.6, 11.3, and 11.4 could allow an authenticated user to cause a denial of service due to due to improper input validation. I… Security Guardium Patch available Fix from $1,6002023-09-05 MEDIUM 5.5 CVE-2023-32338 IBM Sterling Secure Proxy and IBM Sterling External Authentication Server 6.0.3 and 6.1.0 stores user credentials in plain clear text which can be re… Sterling External Authentication Server Mitigation only Fix from $1,6002023-09-05 HIGH 7.5 CVE-2023-33835 IBM Security Verify Information Queue 10.0.4 and 10.0.5 could allow a remote attacker to obtain sensitive information that could aid in further attac… Security Verify Information Queue Patch available Fix from $1,9502023-08-31 MEDIUM 5.3 CVE-2023-33834 IBM Security Verify Information Queue 10.0.4 and 10.0.5 could allow a remote attacker to obtain sensitive information that could aid in further attac… Security Verify Information Queue Patch available Fix from $1,6002023-08-31 CRITICAL 9.8 CVE-2023-26270 IBM Security Guardium Data Encryption (IBM Guardium Cloud Key Manager (GCKM) 1.10.3)) could allow a remote attacker to execute arbitrary code on the … Guardium Cloud Key Manager after 1.10.3 Fix from $2,3002023-08-28 HIGH 7.5 CVE-2023-26271 IBM Security Guardium Data Encryption (IBM Guardium Cloud Key Manager (GCKM) 1.10.3)) uses an inadequate account lockout setting that could allow a r… Guardium Cloud Key Manager after 1.10.3 Fix from $1,9502023-08-28 MEDIUM 5.3 CVE-2023-26272 IBM Security Guardium Data Encryption (IBM Guardium Cloud Key Manager (GCKM) 1.10.3)) could allow a remote attacker to obtain sensitive information w… Guardium Cloud Key Manager after 1.10.3 Fix from $1,6002023-08-28 HIGH 8.8 CVE-2023-23473 IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorize… Infosphere Information Server 11.7.1.0 / 11.7.1.4+ Fix from $1,9502023-08-28 HIGH 7.5 CVE-2023-24959 IBM InfoSphere Information Systems 11.7 could expose information about the host system and environment configuration. IBM X-Force ID: 246332. Infosphere Information Server 11.7.1.0 / 11.7.1.4+ Fix from $1,9502023-08-28 HIGH 8.8 CVE-2023-22877 IBM InfoSphere Information Server 11.7 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, … Infosphere Information Server 11.7.1.0 / 11.7.1.4+ Fix from $1,9502023-08-28 HIGH 7.5 CVE-2022-43904 IBM Security Guardium 11.3 and 11.4 could disclose sensitive information to an attacker due to improper restriction of excessive authentication attem… Security Guardium Patch available Fix from $1,9502023-08-28 HIGH 7.5 CVE-2023-38730 IBM Storage Copy Data Management 2.2.0.0 through 2.2.19.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt … Storage Copy Data Management after 2.2.19.0 Fix from $1,9502023-08-27 MEDIUM 5.4 CVE-2023-33852 IBM Security Guardium 11.4 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attac… Security Guardium Patch available Fix from $1,6002023-08-27 MEDIUM 5.3 CVE-2023-30437 IBM Security Guardium 11.3, 11.4, and 11.5 could allow an unauthorized user to enumerate usernames by sending a specially crafted HTTP request. IBM … Security Guardium Patch available Fix from $1,6002023-08-27 MEDIUM 5.4 CVE-2022-43909 IBM Security Guardium 11.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI th… Security Guardium Patch available Fix from $1,6002023-08-27 MEDIUM 5.4 CVE-2023-30435 IBM Security Guardium 11.3, 11.4, and 11.5 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScrip… Security Guardium Patch available Fix from $1,6002023-08-27 MEDIUM 5.4 CVE-2023-30436 IBM Security Guardium 11.3, 11.4, and 11.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code … Security Guardium Patch available Fix from $1,6002023-08-27 HIGH 8.8 CVE-2022-43907 IBM Security Guardium 11.4 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted req… Security Guardium Patch available Fix from $1,9502023-08-27 MEDIUM 5.5 CVE-2023-40371 IBM AIX 7.2, 7.3, VIOS 3.1's OpenSSH implementation could allow a non-privileged local user to access files outside of those allowed due to improper … Vios Mitigation only Fix from $1,6002023-08-24 CRITICAL 9.8 CVE-2023-38734 IBM Robotic Process Automation 21.0.0 through 21.0.7.1 and 23.0.0 through 23.0.1 is vulnerable to incorrect privilege assignment when importing users… Robotic Process Automation after 21.0.7.1 Fix from $2,3002023-08-22 MEDIUM 5.3 CVE-2023-40370 IBM Robotic Process Automation 21.0.0 through 21.0.7.1 runtime is vulnerable to information disclosure of script content if the remote REST request c… Robotic Process Automation after 21.0.7.1 Fix from $1,6002023-08-22 HIGH 7.5 CVE-2023-33850 IBM GSKit-Crypto could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in the RSA Decryption implement… Txseries For Multiplatform Mitigation only Fix from $1,9502023-08-22 MEDIUM 5.4 CVE-2023-35011 IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send… Cognos Analytics 11.1.7 / 11.2.4+ Fix from $1,6002023-08-16 MEDIUM 5.3 CVE-2023-35009 IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a remote attacker to obtain system information without authentication which could be used… Cognos Analytics 11.1.7 / 11.2.4+ Fix from $1,6002023-08-16 HIGH 8.8 CVE-2023-35893 IBM Security Guardium 10.6, 11.3, 11.4, and 11.5 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a… Security Guardium Patch available Fix from $1,9502023-08-16 HIGH 7.5 CVE-2023-38737 IBM WebSphere Application Server Liberty 22.0.0.13 through 23.0.0.7 is vulnerable to a denial of service, caused by sending a specially-crafted reque… Websphere Application Server after 23.0.0.7 Fix from $1,9502023-08-16 HIGH 7.8 CVE-2023-38721 The IBM i 7.2, 7.3, 7.4, and 7.5 product Facsimile Support for i contains a local privilege escalation vulnerability. A malicious actor could gain … I Patch available Fix from $1,9502023-08-14