Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2021-38983
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt …
Security Guardium Key Lifecycle Manager
after 4.0.0.3
HIGH 7.5
CVE-2021-38984
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt …
Security Guardium Key Lifecycle Manager
after 4.1.0.1
MEDIUM 5.4
CVE-2021-38982
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary J…
Security Guardium Key Lifecycle Manager
after 4.0.0.3
MEDIUM 5.3
CVE-2021-38981
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensitive information when a detailed technical err…
Security Guardium Key Lifecycle Manager
after 4.0.0.3
HIGH 7.5
CVE-2021-38979
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses a one-way cryptographic hash against an input that should not be reversible, such as a…
Security Guardium Key Lifecycle Manager
after 4.0.0.3
MEDIUM 6.5
CVE-2021-38974
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow an authenticated user to cause a denial of service using specially crafted HTTP…
Security Guardium Key Lifecycle Manager
after 4.0.0.3
MEDIUM 6.5
CVE-2021-38975
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow an authenticated user to to obtain sensitive information from a specially craft…
Security Guardium Key Lifecycle Manager
after 4.0.0.3
MEDIUM 5.9
CVE-2021-38978
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensitive information, caused by the failure to pro…
Security Guardium Key Lifecycle Manager
after 4.0.0.3
MEDIUM 5.5
CVE-2021-38976
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 stores user credentials in plain clear text which can be read by a local user. X-Force ID: …
Security Guardium Key Lifecycle Manager
after 4.0.0.3
HIGH 8.8
CVE-2021-3723
A command injection vulnerability was reported in the Integrated Management Module (IMM) of legacy IBM System x 3550 M3 and IBM System x 3650 M3 serv…
System X3550 M3 Firmware
Mitigation only
MEDIUM 5.4
CVE-2020-4140
IBM Security SiteProtector System 3.1.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in …
Security Siteprotector System
Patch available
MEDIUM 5.3
CVE-2020-4146
IBM Security SiteProtector System 3.1.1 could allow a remote attacker to obtain sensitive information, caused by missing 'HttpOnly' flag. A remote at…
Security Siteprotector System
Mitigation only
MEDIUM 6.5
CVE-2021-38887
IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information from application response requests that coul…
Infosphere Information Server
Patch available
MEDIUM 6.5
CVE-2021-29843
IBM MQ 9.1 LTS, 9.1 CD, 9.2 LTS, and 9.2CD is vulnerable to a denial of service attack caused by an issue processing message properties. IBM X-Force …
Mq Appliance
9.1.0.9 / 9.2.0.3+
MEDIUM 5.9
CVE-2020-4152
IBM QRadar Network Security 5.4.0 and 5.5.0 transmits sensitive or security-critical data in cleartext in a communication channel that can be obtaine…
Qradar Network Security
5.4.0.14 / 5.5.0.9+
MEDIUM 5.9
CVE-2020-4160
IBM QRadar Network Security 5.4.0 and 5.5.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable H…
Qradar Network Security
5.4.0.14 / 5.5.0.9+
MEDIUM 5.4
CVE-2020-4153
IBM QRadar Network Security 5.4.0 and 5.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code…
Qradar Network Security
5.4.0.14 / 5.5.0.9+
MEDIUM 5.4
CVE-2021-29735
IBM Security Guardium 10.5, 10.6, 11.0, 11.1, 11.2, and 11.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar…
Security Guardium
Mitigation only
MEDIUM 5.9
CVE-2021-29753
IBM Business Automation Workflow 18. 19, 20, 21, and IBM Business Process Manager 8.5 and d8.6 transmits or stores authentication credentials, but it…
Business Automation Workflow
Mitigation only
CRITICAL 9.1
CVE-2021-38948
IBM InfoSphere Information Server 11.7 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker cou…
Infosphere Information Server
Patch available
HIGH 8.8
CVE-2021-29888
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorize…
Infosphere Information Server
Patch available
HIGH 7.5
CVE-2021-29737
IBM InfoSphere Data Flow Designer Engine (IBM InfoSphere Information Server 11.7 ) component has improper validation of the REST API server certifica…
Infosphere Information Server
Patch available
HIGH 7.5
CVE-2021-29875
IBM InfoSphere Information Server 11.7 could allow an attacker to obtain sensitive information due to a insecure third party domain access vulnerabil…
Infosphere Information Server
Patch available
MEDIUM 5.4
CVE-2021-29738
IBM InfoSphere Data Flow Designer (IBM InfoSphere Information Server 11.7 ) is vulnerable to server-side request forgery (SSRF). This may allow an au…
Infosphere Information Server
Patch available
MEDIUM 5.4
CVE-2021-29771
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…
Infosphere Information Server
Patch available
HIGH 8.8
CVE-2021-29844
IBM Jazz Team Server products is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requ…
Engineering Lifecycle Optimization
Patch available
HIGH 7.5
CVE-2021-29774
IBM Jazz Team Server products could allow an authenticated user to obtain elevated privileges under certain configurations. IBM X-Force ID: 203025.
Engineering Lifecycle Optimization
Patch available
MEDIUM 6.5
CVE-2021-29786
IBM Jazz Team Server products stores user credentials in clear text which can be read by an authenticated user. IBM X-Force ID: 203172.
Engineering Lifecycle Optimization
Patch available
MEDIUM 5.5
CVE-2021-29868
IBM i2 iBase 8.9.13 and 9.0.0 could allow a local attacker to obtain sensitive information due to insufficient session expiration. IBM X-Force ID: 20…
I2 Ibase
Patch available
MEDIUM 5.4
CVE-2021-29673
IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web U…
Engineering Lifecycle Optimization
Patch available