Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2021-20427
IBM Security Guardium 11.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Fo…
Security Guardium
Mitigation only
MEDIUM 6.5
CVE-2021-29714
IBM Content Navigator 3.0.CD could allow a malicious user to cause a denial of service due to improper input validation. IBM X-Force ID: 200968.
Content Navigator
Mitigation only
MEDIUM 5.3
CVE-2021-20349
IBM Tivoli Workload Scheduler 9.4 and 9.5 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local attacker could …
Tivoli Workload Scheduler
Mitigation only
HIGH 7.5
CVE-2021-29765
IBM PowerVM Hypervisor FW940 and FW950 could allow an attacker to obtain sensitive information if they gain service access to the FSP. IBM X-Force ID…
Powervm
Mitigation only
MEDIUM 5.4
CVE-2020-4707
IBM API Connect 5.0.0.0 through 5.0.8.11 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in…
Api Connect
after 5.0.8.11
HIGH 7.2
CVE-2021-29696
IBM Cloud Pak for Security (CP4S) 1.5.0.0, 1.5.1.0, 1.6.0.0, 1.6.1.0, 1.7.0.0, and 1.7.1.0 could allow a remote authenticated attacker to execute arb…
Cloud Pak For Security
Mitigation only
MEDIUM 5.3
CVE-2021-20539
IBM Cloud Pak for Security (CP4S) 1.5.0.0, 1.5.1.0, 1.6.0.0, 1.6.1.0, 1.7.0.0, and 1.7.1.0 could disclose sensitive information to an unauthorized us…
Cloud Pak For Security
Patch available
MEDIUM 5.3
CVE-2021-20540
IBM Cloud Pak for Security (CP4S) 1.5.0.0, 1.5.1.0, 1.6.0.0, 1.6.1.0, 1.7.0.0, and 1.7.1.0 could disclose sensitive information to an unauthorized us…
Cloud Pak For Security
Patch available
MEDIUM 5.3
CVE-2021-20541
IBM Cloud Pak for Security (CP4S) 1.5.0.0, 1.5.1.0, 1.6.0.0, 1.6.1.0, 1.7.0.0, and 1.7.1.0 could disclose sensitive information to an unauthorized us…
Cloud Pak For Security
Patch available
HIGH 8.8
CVE-2021-29757
IBM QRadar User Behavior Analytics 4.1.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthori…
Qradar User Behavior Analytics
Patch available
HIGH 7.8
CVE-2021-29741
IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user to exploit a vulnerability in Korn Shell (ksh) to gain root privileges. IBM X-Force ID: 20147…
Vios
Patch available
CRITICAL 9.8
CVE-2021-29781
IBM Partner Engagement Manager 2.0 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization flaw. B…
Partner Engagement Manager
Patch available
HIGH 8.8
CVE-2021-29736
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote user to gain elevated privileges on the system. IBM X-Force ID: 201300.
Websphere Application Server
after 9.0.5.8
MEDIUM 6.3
CVE-2020-4974
IBM Jazz Foundation products are vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requ…
Engineering Lifecycle Optimization Engineering Insights
No fix yet
MEDIUM 5.4
CVE-2020-5004
IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI…
Engineering Lifecycle Optimization Engineering Insights
Mitigation only
CRITICAL 9.1
CVE-2021-20399
IBM Qradar SIEM 7.3.0 to 7.3.3 Patch 8 and 7.4.0 to 7.4.3 GA is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data.…
Qradar Security Information And Event Manager
7.3.3 / 7.4.3+
MEDIUM 5.4
CVE-2021-20562
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_3 and 6.1.0.0 through 6.1.0.2 vulnerable to cross-site scripting. This vulnerabi…
Sterling B2b Integrator
after 6.1.0.2
HIGH 7.5
CVE-2021-20337
IBM QRadar SIEM 7.3.0 to 7.3.3 Patch 8 and 7.4.0 to 7.4.3 GA uses weaker than expected cryptographic algorithms that could allow an attacker to decry…
Qradar Security Information And Event Manager
7.3.3 / 7.4.3+
MEDIUM 6.5
CVE-2020-4623
IBM i2 iBase 8.9.13 could allow a local authenticated attacker to execute arbitrary code on the system, caused by a DLL search order hijacking flaw. …
I2 Ibase
Patch available
MEDIUM 6.5
CVE-2021-20431
IBM i2 Analyst's Notebook Premium 9.2.0, 9.2.1, and 9.2.2 does not invalidate session after logout which could allow an an attacker to obtain sensiti…
I2 Analysts Notebook
Patch available
MEDIUM 6.5
CVE-2021-29770
IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) could allow an authenticated user to perform unauthorized actions due to h…
I2 Analyze
Patch available
MEDIUM 5.4
CVE-2021-20560
IBM Sterling Connect:Direct Browser User Interface 1.4.1.1 and 1.5.0.2 could allow a remote attacker to hijack the clicking action of the victim. By …
Sterling Connect Direct User Interface
Patch available
MEDIUM 5.3
CVE-2021-20430
IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) could allow a remote attacker to obtain sensitive information when a detai…
I2 Analyze
Patch available
MEDIUM 5.3
CVE-2021-29766
IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) could allow a remote attacker to obtain sensitive information when a detai…
I2 Analyze
Patch available
MEDIUM 5.3
CVE-2021-29767
IBM i2 Analyst's Notebook Premium 9.2.0, 9.2.1, and 9.2.2 could allow a remote attacker to obtain sensitive information when a detailed technical err…
I2 Analysts Notebook
Patch available
HIGH 7.8
CVE-2021-29707
IBM HMC (Hardware Management Console) V9.1.910.0 and V9.2.950.0 could allow a local user to escalate their privileges to root access on a restricted …
Hardware Management Console
Mitigation only
MEDIUM 5.4
CVE-2020-5031
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScrip…
Engineering Lifecycle Optimization
Mitigation only
MEDIUM 5.4
CVE-2021-20507
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScrip…
Engineering Lifecycle Optimization
Mitigation only
MEDIUM 6.5
CVE-2020-4980
IBM QRadar SIEM 7.3 and 7.4 uses less secure methods for protecting data in transit between hosts when encrypt host connections is not enabled as wel…
Qradar Security Information And Event Manager
7.3.3 / 7.4.3+
CRITICAL 9.8
CVE-2020-4821
IBM InfoSphere Data Replication 11.4 and IBM InfoSphere Change Data Capture for z/OS 10.2.1, under certain configurations, could allow a user to bypa…
Infosphere Data Replication
Patch available