Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.8
CVE-2022-40607
IBM Spectrum Scale 5.1 could allow users with permissions to create pod, persistent volume and persistent volume claim to access files and directorie…
Spectrum Scale
after 5.1.4.0
MEDIUM 5.9
CVE-2020-4497
IBM Spectrum Protect Plus 10.1.0 through 10.1.12 discloses sensitive information due to unencrypted data being used in the communication flow between…
Spectrum Protect Plus
10.1.13+
MEDIUM 6.1
CVE-2022-34318
IBM CICS TX 11.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a r…
Cics Tx
Patch available
HIGH 8.8
CVE-2022-41296
IBM Db2U 3.5, 4.0, and 4.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions tr…
Db2
Mitigation only
MEDIUM 5.4
CVE-2021-38997
IBM API Connect V10.0.0.0 through V10.0.5.0, V10.0.1.0 through V10.0.1.7, and V2018.4.1.0 through 2018.4.1.19 is vulnerable to HTTP header injection,…
Api Connect
after 2018.4.1.19
MEDIUM 5.4
CVE-2022-41299
IBM Cloud Transformation Advisor 2.0.1 through 3.3.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaSc…
Transformation Advisor
3.4.0+
HIGH 8.8
CVE-2022-43581
IBM Content Navigator 3.0.0, 3.0.1, 3.0.2, 3.0.3, 3.0.4, 3.0.5, 3.0.6, 3.0.7, 3.0.8, 3.0.9, 3.0.10, 3.0.11, and 3.0.12 is vulnerable to missing autho…
Content Navigator
after 3.0.12
MEDIUM 6.1
CVE-2022-41735
IBM Business Process Manager 21.0.1 through 21.0.3.1, 20.0.0.1 through 20.0.0.2 19.0.0.1 through 19.0.0.3 is vulnerable to cross-site scripting. This…
Business Automation Workflow
after 21.0.3.1
HIGH 7.8
CVE-2022-43867
IBM Spectrum Scale 5.1.0.1 through 5.1.4.1 could allow a local attacker to execute arbitrary commands in the container. IBM X-Force ID: 239437.
Spectrum Scale Container Native Storage Access
after 5.1.4.1
HIGH 7.5
CVE-2022-34361
IBM Sterling Secure Proxy 6.0.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive informati…
Sterling Secure Proxy
Patch available
MEDIUM 6.5
CVE-2022-43900
IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps 1.4.2 could provide a weaker than expected security. A local attacker can create an outbo…
Websphere Automation For Ibm Cloud Pak For Watson Aiops
1.4.3+
MEDIUM 5.5
CVE-2022-43901
IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps 1.4.3 could disclose sensitive information. An authenticated local attacker could exploit…
Websphere Automation For Ibm Cloud Pak For Watson Aiops
1.4.3+
MEDIUM 6.5
CVE-2022-41297
IBM Db2U 3.5, 4.0, and 4.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions tr…
Db2 On Cloud Pak For Data
4.6+
MEDIUM 5.5
CVE-2022-41732
IBM Maximo Mobile 8.7 and 8.8 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 237407.
Maximo Application Suite
Mitigation only
MEDIUM 5.4
CVE-2022-40228
IBM DataPower Gateway 10.0.3.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.9, 2018.4.1.0 through 2018.4.1.22, and 10.5.0.0 through 10.5.0.2 does not in…
Datapower Gateway
after 2018.4.1.22
MEDIUM 6.7
CVE-2022-40746
IBM i Access Family 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.0 could allow a local authenticated attacker to execute arbitrary code on the syste…
I Access Client Solutions
after 1.1.9.0
MEDIUM 5.4
CVE-2022-38390
Multiple IBM Business Automation Workflow versions are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScr…
Business Automation Workflow
after 21.0.3.1
CRITICAL 9.8
CVE-2022-40752
IBM InfoSphere DataStage 11.7 is vulnerable to a command injection vulnerability due to improper neutralization of special elements. IBM X-Force ID: …
Infosphere Information Server
Patch available
MEDIUM 5.4
CVE-2022-40753
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…
Infosphere Information Server
Patch available
HIGH 8.1
CVE-2022-38385
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.2.0 could allow an authenticated user to obtain highly sensitive information or perform unaut…
Cloud Pak For Security
after 1.10.2.0
HIGH 7.5
CVE-2022-34320
IBM CICS TX 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force…
Cics Tx
Patch available
MEDIUM 5.4
CVE-2022-34317
IBM CICS TX 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alterin…
Cics Tx
Patch available
MEDIUM 5.3
CVE-2022-34316
IBM CICS TX 11.1 does not neutralize or incorrectly neutralizes web scripting syntax in HTTP headers that can be used by web browser components that …
Cics Tx
Patch available
MEDIUM 5.4
CVE-2022-34315
IBM CICS TX 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alterin…
Cics Tx
Patch available
HIGH 7.5
CVE-2022-34319
IBM CICS TX 11.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Forc…
Cics Tx
Patch available
MEDIUM 6.1
CVE-2022-38705
IBM CICS TX 11.1 Standard and Advanced could allow a remote attacker to bypass security restrictions, caused by a reverse tabnabbing flaw. An attacke…
Cics Tx
Patch available
MEDIUM 5.3
CVE-2022-34329
IBM CICS TX 11.7 could allow an attacker to obtain sensitive information from HTTP response headers. IBM X-Force ID: 229467.
Cics Tx
Patch available
MEDIUM 5.5
CVE-2022-35719
IBM MQ Internet Pass-Thru 2.1, 9.2 LTS and 9.2 CD stores potentially sensitive information in trace files that could be read by a local user.
Mq Internet Pass Thru
Patch available
HIGH 8.8
CVE-2022-38387
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.2.0 could allow a remote authenticated attacker to execute arbitrary commands on the system b…
Cloud Pak For Security
after 1.10.2.0
MEDIUM 5.4
CVE-2022-40750
IBM WebSphere Application Server 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript co…
Websphere Application Server
Patch available