Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2022-35287
IBM Security Verify Information Queue 10.0.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbo…
Security Verify Information Queue
Patch available
MEDIUM 6.5
CVE-2022-35288
IBM Security Verify Information Queue 10.0.2 could allow a user to obtain sensitive information that could be used in further attacks against the sys…
Security Verify Information Queue
Patch available
HIGH 8.8
CVE-2022-35285
IBM Security Verify Information Queue 10.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unaut…
Security Verify Information Queue
Patch available
HIGH 7.5
CVE-2022-35284
IBM Security Verify Information Queue 10.0.2 could disclose sensitive information due to a missing or insecure SameSite attribute for a sensitive coo…
Security Verify Information Queue
Patch available
HIGH 7.5
CVE-2021-29755
IBM QRadar SIEM 7.3, 7.4, and 7.5 does not preform proper certificate validation for some inter-host communications. IBM X-Force ID: 202015.
Qradar Security Information And Event Manager
7.3.3 / 7.4.3+
MEDIUM 5.5
CVE-2022-22424
IBM QRadar SIEM 7.3, 7.4, and 7.5 could allow a local user to obtain sensitive information from the TLS key file due to incorrect file permissions. I…
Qradar Security Information And Event Manager
7.3.3 / 7.4.3+
HIGH 8.8
CVE-2022-22360
IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 could allow a remote authenticated attacker to conduct an LDAP injection. By …
Partner Engagement Manager
6.1.2.5 / 6.2.0.3+
HIGH 7.1
CVE-2022-22358
IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to an XML External Entity Injection (XXE) attack when processin…
Partner Engagement Manager
6.1.2.5 / 6.2.0.3+
MEDIUM 6.5
CVE-2022-22359
IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to cross-site request forgery which could allow an attacker to …
Partner Engagement Manager
6.1.2.5 / 6.2.0.3+
MEDIUM 5.4
CVE-2022-22416
IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to server-side request forgery (SSRF). This may allow an authen…
Partner Engagement Manager
6.1.2.5 / 6.2.0.3+
MEDIUM 5.4
CVE-2022-22417
IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to cross-site scripting. This vulnerability allows users to emb…
Partner Engagement Manager
6.1.2.5 / 6.2.0.3+
MEDIUM 6.5
CVE-2021-29799
IBM Engineering Requirements Quality Assistant On-Premises (All versions) could allow an authenticated user to obtain sensitive information due to im…
Engineering Requirements Quality Assistant On Premises
Mitigation only
MEDIUM 6.5
CVE-2021-38868
IBM Engineering Requirements Quality Assistant On-Premises (All versions) is vulnerable to cross-site request forgery which could allow an attacker t…
Engineering Requirements Quality Assistant On Premises
Mitigation only
MEDIUM 6.5
CVE-2022-22445
An attacker that gains service access to the FSP (POWER9 only) or gains admin authority to a partition can compromise partition firmware.
Powervm Hypervisor
Mitigation only
MEDIUM 5.4
CVE-2021-29788
IBM Engineering Requirements Quality Assistant On-Premises (All versions) is vulnerable to cross-site scripting. This vulnerability allows users to e…
Engineering Requirements Quality Assistant On Premises
Mitigation only
MEDIUM 5.4
CVE-2021-29790
IBM Engineering Requirements Quality Assistant On-Premises (All versions) is vulnerable to cross-site scripting. This vulnerability allows users to e…
Engineering Requirements Quality Assistant On Premises
Mitigation only
HIGH 7.5
CVE-2022-22452
IBM Security Verify Identity Manager 10.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account creden…
Security Verify Governance
Patch available
HIGH 7.5
CVE-2022-22453
IBM Security Verify Identity Manager 10.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive…
Security Verify Governance
Patch available
HIGH 7.5
CVE-2022-22460
IBM Security Verify Identity Manager 10.0 contains sensitive information in the source code repository that could be used in further attacks against …
Security Verify Governance
Patch available
MEDIUM 6.5
CVE-2021-39017
IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to upload arbitrary files, ca…
Engineering Lifecycle Optimization Publishing
Patch available
MEDIUM 6.5
CVE-2021-39019
IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could disclose highly sensitive information through an HTTP…
Engineering Lifecycle Optimization Publishing
Patch available
MEDIUM 6.5
CVE-2022-35283
IBM Security Verify Information Queue 10.0.2 could allow an authenticated user to cause a denial of service with a specially crafted HTTP request.
Security Verify Information Queue
Patch available
MEDIUM 6.1
CVE-2022-22477
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript cod…
Websphere Application Server
Patch available
MEDIUM 5.4
CVE-2021-39015
IBM Engineering Lifecycle Optimization - Publishing 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to e…
Engineering Lifecycle Optimization Publishing
Patch available
MEDIUM 5.4
CVE-2021-39028
IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to HTTP header injection, caused by improper …
Engineering Lifecycle Optimization Publishing
Patch available
MEDIUM 5.3
CVE-2022-22473
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sensitive information caused by improper handling of …
Websphere Application Server
after 9.0.5.12
MEDIUM 5.4
CVE-2022-34358
IBM i 7.2, 7.3, 7.4, and 7.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI …
I
Patch available
HIGH 7.5
CVE-2020-4157
IBM QRadar Network Security 5.4.0 and 5.5.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbou…
Qradar Network Security
Patch available
HIGH 7.5
CVE-2020-4159
IBM QRadar Network Security 5.4.0 and 5.5.0 discloses sensitive information to unauthorized users which could be used to mount further attacks agains…
Qradar Network Security
Patch available
MEDIUM 5.3
CVE-2021-39041
IBM QRadar SIEM 7.3, 7.4, and 7.5 may be vulnerable to partial denial of service attack, resulting in some protocols not listening to specified ports…
Qradar Security Information And Event Manager
Patch available