Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2021-38917 IBM PowerVM Hypervisor FW860, FW940, and FW950 could allow an attacker that gains service access to the FSP can read and write arbitrary host system … Powervm Hypervisor Mitigation only Fix from $2,3002021-12-10 HIGH 8.7 CVE-2021-29678 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a user with DBADM authority to access o… Db2 Mitigation only Fix from $1,9502021-12-09 HIGH 7.5 CVE-2021-20373 IBM Db2 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an Information Disclosure when using the LOAD utility as under certain circumstances the… Db2 Patch available Fix from $1,9502021-12-09 HIGH 7.5 CVE-2021-38951 IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote… Websphere Application Server Mitigation only Fix from $1,9502021-12-09 HIGH 7.5 CVE-2021-39002 IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 uses weaker than expected cryptographic algorithms … Db2 Mitigation only Fix from $1,9502021-12-09 MEDIUM 6.5 CVE-2021-38931 IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1, and 11.5 is vulnerable to an information disclosure as a result of a connecte… Db2 Mitigation only Fix from $1,6002021-12-09 MEDIUM 5.5 CVE-2021-38926 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to gain privileges due to … Db2 Mitigation only Fix from $1,6002021-12-09 MEDIUM 5.4 CVE-2021-38909 IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t… Cognos Analytics 11.1.7+ Fix from $1,6002021-12-03 MEDIUM 5.4 CVE-2021-29867 IBM Cognos Analytics 11.1.7 and 11.2.0 could allow an authenticated to view or edit a Jupyter notebook that they should not have access to. IBM X-For… Cognos Analytics 11.1.7+ Fix from $1,6002021-12-03 HIGH 8.8 CVE-2021-29756 IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site request forgery (CSRF) in the My Inbox page which could allow an attacker to execu… Cognos Analytics 11.1.7+ Fix from $1,9502021-12-03 MEDIUM 5.3 CVE-2021-29719 IBM Cognos Analytics 11.1.7 and 11.2.0 could be vulnerable to client side vulnerabilties due to a web response specifying an incorrect content type. … Cognos Analytics 11.1.7+ Fix from $1,6002021-12-03 MEDIUM 6.5 CVE-2021-29716 IBM Cognos Analytics 11.1.7 and 11.2.0 could allow a low level user to reas of the application that privileged user should only be allowed to view. I… Cognos Analytics 11.1.7+ Fix from $1,6002021-12-03 MEDIUM 6.1 CVE-2021-20493 IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t… Cognos Analytics 11.1.7+ Fix from $1,6002021-12-03 HIGH 7.5 CVE-2021-20470 IBM Cognos Analytics 11.1.7 and 11.2.0 does not require that users should have strong passwords by default, which makes it easier for attackers to co… Cognos Analytics 11.1.7+ Fix from $1,9502021-12-03 HIGH 7.5 CVE-2021-20400 IBM QRadar SIEM 7.3 and 7.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. … Qradar Security Information And Event Manager 7.3.3 / 7.4.3+ Fix from $1,9502021-12-01 MEDIUM 6.1 CVE-2021-29849 IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI t… Qradar Security Information And Event Manager 7.3.3 / 7.4.3+ Fix from $1,6002021-12-01 MEDIUM 5.9 CVE-2021-29779 IBM QRadar SIEM 7.3 and 7.4 could allow an attacker to obtain sensitive information due to the server performing key exchange without entity authenti… Qradar Security Information And Event Manager after 7.4.3 Fix from $1,6002021-12-01 MEDIUM 6.7 CVE-2021-38967 IBM MQ Appliance 9.2 CD and 9.2 LTS could allow a local privileged user to inject and execute malicious code. IBM X-Force ID: 212441. Mq Appliance Patch available Fix from $1,6002021-11-30 MEDIUM 5.5 CVE-2021-38958 IBM MQ Appliance 9.2 CD and 9.2 LTS is affected by a denial of service attack caused by a concurrency issue. IBM X-Force ID: 212042 Mq Appliance Patch available Fix from $1,6002021-11-30 MEDIUM 5.5 CVE-2021-38999 IBM MQ Appliance could allow a local attacker to obtain sensitive information by inclusion of sensitive data within trace. Mq Appliance Patch available Fix from $1,6002021-11-30 MEDIUM 5.5 CVE-2021-39000 IBM MQ Appliance 9.2 CD and 9.2 LTS could allow a local attacker to obtain sensitive information by inclusion of sensitive data within diagnostics. I… Mq Appliance Patch available Fix from $1,6002021-11-30 HIGH 7.8 CVE-2021-38873 IBM Planning Analytics 2.0 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by im… Planning Analytics Patch available Fix from $1,9502021-11-24 HIGH 7.5 CVE-2021-38890 IBM Sterling Connect:Direct Web Services 1.0 and 6.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force acc… Sterling Connect\ 6.2.0.1+ Fix from $1,9502021-11-23 HIGH 7.5 CVE-2021-38891 IBM Sterling Connect:Direct Web Services 1.0 and 6.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highl… Sterling Connect\ 6.2.0.1+ Fix from $1,9502021-11-23 MEDIUM 6.5 CVE-2021-38875 IBM MQ 8.0, 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.1 CD, and 9.2 CD is vulnerable to a denial of service attack caused by an error processing messages. IBM X-F… Mq Patch available Fix from $1,6002021-11-23 MEDIUM 5.3 CVE-2021-38980 IBM Tivoli Key Lifecycle Manager (IBM Security Guardium Key Lifecycle Manager) 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensi… Security Guardium Key Lifecycle Manager after 4.1.0.1 Fix from $1,6002021-11-23 MEDIUM 6.2 CVE-2021-29861 IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in EFS to expose sensitive information. IBM X-Force… Vios Mitigation only Fix from $1,6002021-11-17 MEDIUM 5.5 CVE-2021-38959 IBM SPSS Statistics for Windows 24.0, 25.0, 26.0, 27.0, 27.0.1, and 28.0 could allow a local user to cause a denial of service by writing arbitrary f… Spss Statistics Mitigation only Fix from $1,6002021-11-17 MEDIUM 6.2 CVE-2021-29860 IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the libc.a library to expose sensitive informati… Vios Mitigation only Fix from $1,6002021-11-17 MEDIUM 5.5 CVE-2021-38949 IBM MQ 7.5, 8.0, 9.0 LTS, 9.1 CD, and 9.1 LTS stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 211403. Mq 8.0.0.14 / 9.0.0.9+ Fix from $1,6002021-11-16