Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2022-36775
IBM Security Verify Access 10.0.0.0, 10.0.1.0, 10.0.2.0, 10.0.3.0, and10.0.4.0 is vulnerable to HTTP header injection, caused by improper validation …
Security Verify Access
Patch available
MEDIUM 5.5
CVE-2023-24964
IBM InfoSphere Information Server 11.7 could allow a local user to obtain sensitive information from a log files. IBM X-Force ID: 246463.
Infosphere Information Server
Patch available
MEDIUM 5.4
CVE-2023-22868
IBM Aspera Faspex 4.4.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus …
Aspera Faspex
after 4.4.1
CRITICAL 9.8
CVE-2022-47986 KEVEPSS 100%
IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserializa…
Aspera Faspex
after 4.4.1
MEDIUM 6.5
CVE-2022-43869
IBM Spectrum Scale (5.1.0.0 through 5.1.2.8 and 5.1.3.0 through 5.1.5.1) and IBM Elastic Storage System (6.1.0.0 through 6.1.2.4 and 6.1.3.0 through …
Elastic Storage System
after 6.1.4.1
CRITICAL 9.8
CVE-2022-41731
IBM Watson Knowledge Catalog on Cloud Pak for Data 4.5.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statement…
Watson Knowledge Catalog On Cloud Pak For Data
Mitigation only
MEDIUM 6.5
CVE-2022-42444
IBM App Connect Enterprise 11.0.0.8 through 11.0.0.19 and 12.0.1.0 through 12.0.5.0 is vulnerable to a buffer overflow. A remote privileged user coul…
App Connect Enterprise
after 12.0.5.0
HIGH 7.5
CVE-2022-34350
IBM API Connect 10.0.0.0 through 10.0.5.0, 10.0.1.0 through 10.0.1.7, and 2018.4.1.0 through 2018.4.1.20 is vulnerable to External Service Interactio…
Api Connect
after 2018.4.1.20
HIGH 8.8
CVE-2022-42438
IBM Cloud Pak for Multicloud Management Monitoring 2.0 and 2.3 allows users without admin roles access to admin functions by specifying direct URL pa…
Cloud Pak For Multicloud Management Monitoring
2.3.0+
MEDIUM 5.5
CVE-2022-35720
IBM Sterling External Authentication Server 6.1.0 and IBM Sterling Secure Proxy 6.0.3 uses weaker than expected cryptographic algorithms during insta…
Sterling External Authentication Server
Patch available
CRITICAL 9.8
CVE-2023-23477
IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially craft…
Websphere Application Server
Mitigation only
CRITICAL 9.1
CVE-2022-38389
IBM Tivoli Workload Scheduler 9.4, 9.5, and 10.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote at…
Tivoli Workload Scheduler
Mitigation only
CRITICAL 9.1
CVE-2022-22486
IBM Tivoli Workload Scheduler 9.4, 9.5, and 10.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote at…
Tivoli Workload Scheduler
Mitigation only
MEDIUM 6.5
CVE-2022-43922
IBM App Connect Enterprise Certified Container 4.1, 4.2, 5.0, 5.1, 5.2, 6.0, 6.1, and 6.2 could disclose sensitive information to an attacker due to …
App Connect Enterprise Certified Container
Patch available
MEDIUM 5.4
CVE-2022-47983
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…
Infosphere Information Server
Patch available
HIGH 7.5
CVE-2022-43917
IBM WebSphere Application Server 8.5 and 9.0 traditional container uses weaker than expected cryptographic keys that could allow an attacker to decry…
Websphere Application Server
Patch available
HIGH 7.5
CVE-2022-43864
IBM Business Automation Workflow 22.0.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially craft…
Business Automation Workflow
after 21.0.3.1
HIGH 7.5
CVE-2022-22462
IBM Security Verify Governance, Identity Manager virtual appliance component 10.0.1 uses weaker than expected cryptographic algorithms that could all…
Security Verify Governance
Patch available
MEDIUM 5.3
CVE-2022-41733
IBM InfoSphere Information Server 11.7 could allow a remote attacked to cause some of the components to be unusable until the process is restarted. I…
Infosphere Information Server
11.7.1.4+
MEDIUM 6.5
CVE-2021-39089
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.6.0 could allow an authenticated user to obtain sensitive information from a specially crafte…
Cloud Pak For Security
after 1.10.6.0
MEDIUM 5.9
CVE-2022-39167
IBM Spectrum Virtualize 8.5, 8.4, 8.3, 8.2, and 7.8, under certain configurations, could disclose sensitive information to an attacker using man-in-t…
Spectrum Virtualize
Patch available
HIGH 7.8
CVE-2023-22592
IBM Robotic Process Automation for Cloud Pak 21.0.1 through 21.0.4 could allow a local user to perform unauthorized actions due to insufficient permi…
Robotic Process Automation For Cloud Pak
21.0.5+
MEDIUM 5.9
CVE-2023-22863
IBM Robotic Process Automation 20.12.0 through 21.0.2 defaults to HTTP in some RPA commands when the prefix is not explicitly specified in the URL. …
Robotic Process Automation
21.0.3+
MEDIUM 5.4
CVE-2023-22594
IBM Robotic Process Automation for Cloud Pak 20.12.0 through 21.0.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed a…
Robotic Process Automation
21.0.5+
HIGH 7.8
CVE-2022-47990
IBM AIX 7.1, 7.2, 7.3 and VIOS , 3.1 could allow a non-privileged local user to exploit a vulnerability in X11 to cause a buffer overflow that could …
Vios
Patch available
HIGH 7.5
CVE-2023-22875
IBM QRadar SIEM 7.4 and 7.5copies certificate key files used for SSL/TLS in the QRadar web user interface to managed hosts in the deployment that do …
Qradar Security Information And Event Manager
Mitigation only
CRITICAL 9.8
CVE-2022-40615
IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statem…
Sterling Partner Engagement Manager
Patch available
MEDIUM 6.5
CVE-2022-34335
IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.1 could allow an authenticated user to exhaust server resources which could lead to a d…
Sterling Partner Engagement Manager
Patch available
HIGH 8.8
CVE-2022-35281
IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, 7.6.1.3 and the IBM Maximo Manage 8.3, 8.4 application in IBM Maximo Application Suite are vulnerable t…
Maximo Application Suite
Mitigation only
MEDIUM 5.5
CVE-2022-22470
IBM Security Verify Governance 10.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 225232.
Security Verify Governance
Patch available