Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2022-22315 IBM UrbanCode Deploy (UCD) 7.2.2.1 could allow an authenticated user with special permissions to obtain elevated privileges due to improper handling … Urbancode Deploy 6.2.7.15 / 7.0.5.10+ Fix from $1,9502022-04-27 CRITICAL 9.8 CVE-2021-38869 IBM QRadar SIEM 7.3, 7.4, and 7.5 in some situations may not automatically log users out after they exceede their idle timeout. IBM X-Force ID: 20834… Qradar Security Information And Event Manager 7.3.3 / 7.4.3+ Fix from $2,3002022-04-27 HIGH 7.5 CVE-2021-38878 IBM QRadar 7.3, 7.4, and 7.5 could allow a malicious actor to impersonate an actor due to key exchange without entity authentication. IBM X-Force ID:… Qradar Security Information And Event Manager 7.3.3 / 7.4.3+ Fix from $1,9502022-04-27 HIGH 7.5 CVE-2021-38919 IBM QRadar SIEM 7.3, 7.4, and 7.5 in some senarios may reveal authorized service tokens to other QRadar users. IBM X-Force ID: 210021 Qradar Security Information And Event Manager 7.3.3 / 7.4.3+ Fix from $1,9502022-04-27 MEDIUM 6.5 CVE-2022-22312 IBM Security Identity Manager (IBM Security Verify Password Synchronization Plug-in for Windows AD 10.x) is vulnerable to a denial of service, caused… Security Verify Password Synchronization 10.0.4+ Fix from $1,6002022-04-27 MEDIUM 6.5 CVE-2022-22323 IBM Security Identity Manager (IBM Security Verify Password Synchronization Plug-in for Windows AD 10.x) is vulnerable to a denial of service, caused… Security Verify Password Synchronization 10.0.4+ Fix from $1,6002022-04-27 MEDIUM 5.3 CVE-2021-38939 IBM QRadar SIEM 7.3, 7.4, and 7.5 stores potentially sensitive information in log files that could be read by an user with access to creating domains… Qradar Security Information And Event Manager 7.3.3 / 7.4.3+ Fix from $1,6002022-04-27 MEDIUM 5.3 CVE-2021-34587 In Bender/ebee Charge Controllers in multiple versions a long URL could lead to webserver crash. The URL is used as input of an sprintf to a stack va… Ibm Rational Lifecycle Integration Adapter For Windchill 5.11.2 / 5.12.5+ Fix from $1,6002022-04-27 HIGH 7.8 CVE-2022-22392 IBM Planning Analytics Local 2.0 could allow an attacker to upload arbitrary executable files which, when executed by an unsuspecting victim could re… Planning Analytics Workspace Mitigation only Fix from $1,9502022-04-25 HIGH 8.0 CVE-2021-39040 IBM Planning Analytics Workspace 2.0 could be vulnerable to malicious file upload by not validating the file types or sizes. Attackers can make use o… Planning Analytics Workspace Mitigation only Fix from $1,9502022-04-25 HIGH 8.8 CVE-2021-38886 IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and un… Cognos Analytics Patch available Fix from $1,9502022-04-22 MEDIUM 6.5 CVE-2021-20464 IBM Cognos Analytics PowerPlay (IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7) could be vulnerable to an XML Bomb attack by a malicious authenticat… Cognos Analytics Patch available Fix from $1,6002022-04-22 MEDIUM 6.5 CVE-2021-38904 IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 could allow a remote attacker to obtain credentials from a user's browser via incorrect autocomplete … Cognos Analytics Patch available Fix from $1,6002022-04-22 MEDIUM 5.4 CVE-2021-38903 IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote… Cognos Analytics Patch available Fix from $1,6002022-04-22 MEDIUM 5.4 CVE-2021-38946 IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript … Cognos Analytics Patch available Fix from $1,6002022-04-22 MEDIUM 5.4 CVE-2022-22435 IBM Maximo Asset Management 7.6.1.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the … Maximo Asset Management Patch available Fix from $1,6002022-04-21 MEDIUM 5.4 CVE-2022-22436 IBM Maximo Asset Management 7.6.1.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the … Maximo Asset Management Patch available Fix from $1,6002022-04-21 HIGH 7.5 CVE-2021-39076 IBM Security Guardium 10.5 and 11.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive information.… Security Guardium Mitigation only Fix from $1,9502022-04-19 MEDIUM 5.9 CVE-2021-39072 IBM Security Guardium 11.3 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transp… Security Guardium Mitigation only Fix from $1,6002022-04-19 MEDIUM 6.5 CVE-2021-39033 IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5 and 6.1.0.0 through 6.1.1.0 could allow a remote attacker to obtain sensitive in… Sterling B2b Integrator 6.0.3.6 / 6.1.1.1+ Fix from $1,6002022-04-19 HIGH 7.5 CVE-2021-38929 IBM System Storage DS8000 Management Console (HMC) R8.5 88.5x.x.x, R9.1 89.1x.0.0, and R9.2 89.2x.0.0 could allow a remote attacker to obtain sensiti… System Storage Ds8000 Management Console Firmware Mitigation only Fix from $1,9502022-04-11 HIGH 7.5 CVE-2021-38930 IBM System Storage DS8000 Management Console (HMC) R8.5 88.5x.x.x, R9.1 89.1x.0.0, and R9.2 89.2x.0.0 could allow a remote attacker to obtain sensiti… System Storage Ds8000 Management Console Firmware Mitigation only Fix from $1,9502022-04-11 MEDIUM 5.4 CVE-2021-39068 IBM Curam Social Program Management 8.0.1 and 7.0.11 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaSc… Curam Social Program Management Patch available Fix from $1,6002022-04-11 HIGH 8.8 CVE-2020-4668 IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.3, and 6.1.1.0 is vulnerable to cross-site request forger… Sterling B2b Integrator after 6.1.0.3 Fix from $1,9502022-04-08 HIGH 7.3 CVE-2022-22339 IBM Planning Analytics 2.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized request… Planning Analytics Patch available Fix from $1,9502022-04-08 HIGH 7.2 CVE-2022-22410 IBM Watson Query with Cloud Pak for Data as a Service could allow an authenticated user to obtain sensitive information that would allow them to exam… Watson Query Mitigation only Fix from $1,9502022-04-06 MEDIUM 6.5 CVE-2022-22356 IBM MQ Appliance 9.2 CD and 9.2 LTS could allow an attacker to enumerate account credentials due to an observable discrepancy in valid and invalid lo… Mq Appliance Patch available Fix from $1,6002022-04-05 MEDIUM 5.3 CVE-2022-22355 IBM MQ Appliance 9.2 CD and 9.2 LTS are vulnerable to a denial of service in the Login component of the application which could allow an attacker to … Mq Appliance Patch available Fix from $1,6002022-04-05 HIGH 7.5 CVE-2022-22327 IBM UrbanCode Deploy (UCD) 7.0.5, 7.1.0, 7.1.1, and 7.1.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt … Urbancode Deploy 7.0.5.9 / 7.1.2.5+ Fix from $1,9502022-04-01 HIGH 7.5 CVE-2022-22332 IBM Sterling Partner Engagement Manager 6.2.0 could allow an attacker to impersonate another user due to missing revocation mechanism for the JWT tok… Partner Engagement Manager Patch available Fix from $1,9502022-04-01