Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2021-29713 IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web U… Engineering Lifecycle Optimization Patch available Fix from $1,6002021-10-27 MEDIUM 5.3 CVE-2021-20526 IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote at… Planning Analytics Patch available Fix from $1,6002021-10-27 MEDIUM 6.1 CVE-2021-29835 IBM Business Automation Workflow 18.0, 19.0, 20.0, and 21.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary… Business Automation Workflow Patch available Fix from $1,6002021-10-22 HIGH 8.1 CVE-2021-29873 IBM Flash System 900 could allow an authenticated attacker to obtain sensitive information and cause a denial of service due to a restricted shell es… Spectrum Virtualize 8.4.0.0+ Fix from $1,9502021-10-21 MEDIUM 6.1 CVE-2021-38896 IBM QRadar Advisor 2.5 through 2.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the… Qradar Advisor after 2.6.1 Fix from $1,6002021-10-20 MEDIUM 5.4 CVE-2021-29912 IBM Security Risk Manager on CP4S 1.7.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code i… Security Risk Manager On Cp4s Patch available Fix from $1,6002021-10-19 MEDIUM 5.4 CVE-2021-29878 IBM Business Automation Workflow 18.0, 19.0, 20.0, and 21.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary… Business Automation Workflow Patch available Fix from $1,6002021-10-18 HIGH 8.8 CVE-2021-29679 IBM Cognos Analytics 11.1.7 and 11.2.0 could allow an authenticated user to execute code remotely due to incorrectly neutralizaing user-contrlled inp… Cognos Analytics Patch available Fix from $1,9502021-10-15 HIGH 8.8 CVE-2021-29745 IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to priviledge escalation where a lower evel user could have access to the 'New Job' page to whic… Cognos Analytics Patch available Fix from $1,9502021-10-15 HIGH 7.5 CVE-2021-38862 IBM Data Risk Manager (iDNA) 2.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive inform… Data Risk Manager Mitigation only Fix from $1,9502021-10-12 MEDIUM 6.5 CVE-2021-38915 IBM Data Risk Manager 2.0.6 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 209947. Data Risk Manager Mitigation only Fix from $1,6002021-10-12 MEDIUM 6.5 CVE-2020-4654 IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated user to obtain sensitive information due to improper permission contro… Sterling File Gateway 5.2.6.5_4 / 6.0.3.5+ Fix from $1,6002021-10-08 MEDIUM 5.5 CVE-2021-29906 IBM App Connect Enterprise Certified Container 1.0, 1.1, 1.2, 1.3, 1.4 and 1.5 could disclose sensitive information to a local user when it is config… App Connect Enterprise Certified Container Mitigation only Fix from $1,6002021-10-08 HIGH 8.8 CVE-2021-20489 IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and … Sterling File Gateway after 6.1.0.3 Fix from $1,9502021-10-07 HIGH 7.5 CVE-2021-20584 IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow a remote attacker to upload arbitrary files, caused by improper access controls. IBM X-… Sterling B2b Integrator after 6.1.0.2 Fix from $1,9502021-10-07 MEDIUM 6.1 CVE-2021-20481 IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScrip… Sterling File Gateway after 6.1.0.1 Fix from $1,6002021-10-07 MEDIUM 6.1 CVE-2021-20561 IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScrip… Sterling B2b Integrator after 6.1.0.2 Fix from $1,6002021-10-07 MEDIUM 5.4 CVE-2021-20571 IBM Sterling B2B Integrator 5.2.0.0 through 6.1.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary … Sterling B2b Integrator after 6.1.0.3 Fix from $1,6002021-10-07 MEDIUM 6.5 CVE-2021-20375 IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated user to intercept and replace a message sent by another user due to im… Sterling B2b Integrator after 6.1.0.1 Fix from $1,6002021-10-07 MEDIUM 6.5 CVE-2021-20473 IBM Sterling File Gateway User Interface 2.2.0.0 through 6.1.1.0 does not invalidate session after logout which could allow an authenticated user to … Sterling File Gateway after 6.1.0.1 Fix from $1,6002021-10-07 CRITICAL 9.8 CVE-2021-29908 The IBM TS7700 Management Interface is vulnerable to unauthenticated access. By accessing a specially-crafted URL, an attacker may gain administrativ… Ts7700 Firmware Mitigation only Fix from $2,3002021-10-06 CRITICAL 9.1 CVE-2021-38923 IBM PowerVM Hypervisor FW1010 could allow a privileged user to gain access to another VM due to assigning duplicate WWPNs. IBM X-Force ID: 210162. Powervm Hypervisor Firmware Mitigation only Fix from $2,3002021-10-06 CRITICAL 9.8 CVE-2021-29798 IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted S… Sterling B2b Integrator after 6.1.0.3 Fix from $2,3002021-10-06 CRITICAL 9.8 CVE-2021-29903 IBM Sterling B2B Integrator Standard Edition 5.2.6.0 through 6.1.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted S… Sterling B2b Integrator after 6.1.0.3 Fix from $2,3002021-10-06 HIGH 8.8 CVE-2021-29837 IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 is vulnerable to cross-site request forgery which could allow an attacker to exe… Sterling B2b Integrator after 6.1.0.3 Fix from $1,9502021-10-06 HIGH 7.5 CVE-2021-38925 IBM Sterling B2B Integrator Standard Edition 5.2.0. 0 through 6.1.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker… Sterling B2b Integrator after 6.1.0.3 Fix from $1,9502021-10-06 MEDIUM 5.4 CVE-2021-29764 IBM Sterling B2B Integrator 5.2.0.0 through 6.1.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary … Sterling B2b Integrator after 6.1.0.3 Fix from $1,6002021-10-06 MEDIUM 5.4 CVE-2021-29836 IBM Sterling B2B Integrator Standard Edition 5.2.0.0. through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed… Sterling B2b Integrator after 6.1.0.3 Fix from $1,6002021-10-06 MEDIUM 5.4 CVE-2021-29855 IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed … Sterling B2b Integrator after 6.1.0.3 Fix from $1,6002021-10-06 CRITICAL 9.8 CVE-2021-20578 IBM Cloud Pak for Security (CP4S) 1.7.0.0, 1.7.1.0, 1.7.2.0, and 1.8.0.0 could allow an attacker to perform unauthorized actions due to improper or m… Cloud Pak For Security Patch available Fix from $2,3002021-09-30