Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2023-27556 IBM Counter Fraud Management for Safer Payments 6.1.0.00, 6.2.0.00, 6.3.0.00 through 6.3.1.03, 6.4.0.00 through 6.4.2.02 and 6.5.0.00 does not proper… Safer Payments 6.3.1.04 / 6.4.2.03+ Fix from $1,9502023-04-28 MEDIUM 5.3 CVE-2023-27860 IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 could disclose sensitive information in an error message. This information could be used in further … Maximo Asset Management Patch available Fix from $1,6002023-04-27 MEDIUM 6.1 CVE-2023-24966 IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript cod… Websphere Application Server 8.5.5.24 / 9.0.5.16+ Fix from $1,6002023-04-27 HIGH 7.5 CVE-2023-29255 IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as it may trap when compi… Db2 11.1.4 / 11.5.8+ Fix from $1,9502023-04-27 MEDIUM 6.5 CVE-2023-30444 IBM Watson Machine Learning on Cloud Pak for Data 4.0 and 4.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated at… Watson Machine Learning On Cloud Pak For Data Patch available Fix from $1,6002023-04-27 HIGH 7.5 CVE-2023-27559 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may crash w… Db2 11.1.4 / 11.5.8+ Fix from $1,9502023-04-26 HIGH 7.2 CVE-2023-29257 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to remote code execution as a database administr… Db2 11.1.4 / 11.5.8+ Fix from $1,9502023-04-26 HIGH 7.8 CVE-2023-26286 IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX runtime services library to execute… Vios Mitigation only Fix from $1,9502023-04-26 HIGH 8.4 CVE-2022-41739 IBM Spectrum Scale (IBM Spectrum Scale Container Native Storage Access 5.1.2.1 through 5.1.6.0) could allow programs running inside the container to … Spectrum Scale Container Native Storage Access after 5.1.6.0 Fix from $1,9502023-04-26 HIGH 7.2 CVE-2022-36769 IBM Cloud Pak for Data 4.5 and 4.6 could allow a privileged user to upload malicious files of dangerous types that can be automatically processed wit… Cloud Pak For Data Mitigation only Fix from $1,9502023-04-26 HIGH 8.1 CVE-2022-33959 IBM Sterling Order Management 10.0 could allow a user to bypass validation and perform unauthorized actions on behalf of other users. IBM X-Force ID… Sterling Order Management Mitigation only Fix from $1,9502023-04-07 HIGH 7.1 CVE-2023-27876 IBM TRIRIGA 4.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnera… Tririga Application Platform Patch available Fix from $1,9502023-04-07 MEDIUM 6.5 CVE-2022-43928 The IBM Toolbox for Java (Db2 Mirror for i 7.4 and 7.5) could allow a user to obtain sensitive information, caused by utilizing a Java string for pro… Db2 Mirror For I Patch available Fix from $1,6002023-04-07 MEDIUM 5.4 CVE-2022-43914 IBM TRIRIGA Application Platform 4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the… Tririga Application Platform 4.0.3+ Fix from $1,6002023-04-07 HIGH 7.5 CVE-2022-34333 IBM Sterling Order Management 10.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compro… Sterling Order Management Mitigation only Fix from $1,9502023-04-07 CRITICAL 9.8 CVE-2023-27284 IBM Aspera Cargo 4.2.5 and IBM Aspera Connect 4.2.5 are vulnerable to a buffer overflow, caused by improper bounds checking. An attacker could overfl… Aspera Cargo 4.2.5+ Fix from $2,3002023-04-02 CRITICAL 9.8 CVE-2023-27286 IBM Aspera Cargo 4.2.5 and IBM Aspera Connect 4.2.5 are vulnerable to a buffer overflow, caused by improper bounds checking. An attacker could overfl… Aspera Cargo 4.2.5+ Fix from $2,3002023-04-02 MEDIUM 5.4 CVE-2023-26283 IBM WebSphere Application Server 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the… Websphere Application Server Patch available Fix from $1,6002023-04-02 HIGH 7.2 CVE-2022-43863 IBM QRadar SIEM 7.4 and 7.5 is vulnerable to privilege escalation, allowing a user with some admin capabilities to gain additional admin capabilities… Qradar Security Information And Event Manager 7.4.3+ Fix from $1,9502023-03-22 HIGH 8.8 CVE-2023-25924 IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an authenticated user to perform actions that they should not… Security Key Lifecycle Manager Patch available Fix from $1,9502023-03-22 MEDIUM 5.3 CVE-2023-25688 IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1could allow a remote attacker to traverse directories on the system. An at… Security Key Lifecycle Manager Patch available Fix from $1,6002023-03-22 CRITICAL 9.8 CVE-2023-25684 IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 is vulnerable to SQL injection. A remote attacker could send specially cr… Security Key Lifecycle Manager Patch available Fix from $2,3002023-03-21 HIGH 7.5 CVE-2023-25923 IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an attacker to upload files that could be used in a denial of… Security Key Lifecycle Manager Patch available Fix from $1,9502023-03-21 MEDIUM 5.5 CVE-2023-25686 IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 stores user credentials in plain clear text which can be read by a local … Security Key Lifecycle Manager Patch available Fix from $1,6002023-03-21 HIGH 8.8 CVE-2023-27874 IBM Aspera Faspex 4.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker coul… Aspera Faspex after 4.4.2 Fix from $1,9502023-03-21 HIGH 7.5 CVE-2023-27871 IBM Aspera Faspex 4.4.2 could allow a remote attacker to obtain sensitive credential information for an external user, using a specially crafted SQL … Aspera Faspex after 4.4.2 Fix from $1,9502023-03-21 MEDIUM 6.5 CVE-2023-27873 IBM Aspera Faspex 4.4.2 could allow a remote authenticated attacker to obtain sensitive credential information using specially crafted XML input. IBM… Aspera Faspex after 4.4.2 Fix from $1,6002023-03-21 MEDIUM 5.3 CVE-2023-25689 IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1 , and 4.1.1 could allow a remote attacker to traverse directories on the system. An … Security Key Lifecycle Manager Patch available Fix from $1,6002023-03-21 HIGH 7.5 CVE-2023-27875 IBM Aspera Faspex 5.0.4 could allow a user to change other user's credentials due to improper access controls. IBM X-Force ID: 249847. Aspera Faspex Patch available Fix from $1,9502023-03-16 MEDIUM 6.5 CVE-2022-46773 IBM Robotic Process Automation 21.0.0 - 21.0.7 and 23.0.0 is vulnerable to client-side validation bypass for credential pools. Invalid credential poo… Robotic Process Automation 21.0.7.1 / 23.0.1+ Fix from $1,6002023-03-15