Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2021-20378 IBM Guardium Data Encryption (GDE) 3.0.0.2 and 4.0.0.4 does not invalidate session after logout which could allow an authenticated user to impersonat… Guardium Data Encryption Patch available Fix from $1,9502021-07-07 HIGH 7.5 CVE-2021-20379 IBM Guardium Data Encryption (GDE) 3.0.0.3 and 4.0.0.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt hig… Guardium Data Encryption Patch available Fix from $1,9502021-07-07 HIGH 7.5 CVE-2021-20415 IBM Guardium Data Encryption (GDE) 4.0.0.4 uses an inadequate account lockout setting that could allow a remote attacker to brute force account crede… Guardium Data Encryption Patch available Fix from $1,9502021-07-07 HIGH 7.5 CVE-2021-20474 IBM Guardium Data Encryption (GDE) 3.0.0.2 and 4.0.0.4 does not perform any authentication for functionality that requires a provable user identity o… Guardium Data Encryption Patch available Fix from $1,9502021-07-07 MEDIUM 5.3 CVE-2021-20416 IBM Guardium Data Encryption (GDE) 3.0.0.3 and 4.0.0.4 could allow a remote attacker to obtain sensitive information, caused by the failure to set th… Guardium Data Encryption Patch available Fix from $1,6002021-07-07 HIGH 8.8 CVE-2020-4902 IBM Datacap Taskmaster Capture (IBM Datacap Navigator 9.1.7) is vulnerable to SQL injection. A remote attacker could send specially crafted SQL state… Datacap Navigator Patch available Fix from $1,9502021-07-01 MEDIUM 5.4 CVE-2020-4935 IBM Datacap Fastdoc Capture (IBM Datacap Navigator 9.1.7 ) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary … Datacap Navigator Patch available Fix from $1,6002021-07-01 MEDIUM 6.5 CVE-2021-20461 IBM Cognos Analytics 10.0 and 11.1 is susceptible to a weakness in the implementation of the System Appearance configuration setting. An attacker cou… Cognos Analytics 11.0.13 / 11.1.7+ Fix from $1,6002021-06-30 MEDIUM 5.5 CVE-2021-20490 IBM Spectrum Protect Plus 10.1.0 through 10.1.8 could allow a local user to cause a denial of service due to insecure file permission settings. IBM X… Spectrum Protect Plus after 10.1.8 Fix from $1,6002021-06-29 MEDIUM 5.4 CVE-2021-20477 IBM Planning Analytics 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI th… Planning Analytics Mitigation only Fix from $1,6002021-06-29 HIGH 8.8 CVE-2021-20574 IBM Security Identity Manager Adapters 6.0 and 7.0 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially cra… Security Identity Manager Adapter Patch available Fix from $1,9502021-06-28 MEDIUM 6.5 CVE-2021-20494 IBM Security Identity Manager Adapters 6.0 and 7.0 are vulnerable to a heap based buffer overflow, caused by improper bounds. An authenticared user c… Security Identity Manager Adapter Patch available Fix from $1,6002021-06-28 MEDIUM 6.5 CVE-2021-20572 IBM Security Identity Manager Adapters 6.0 and 7.0 are vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A remote auth… Security Identity Manager Adapter Patch available Fix from $1,6002021-06-28 MEDIUM 6.5 CVE-2021-20573 IBM Security Identity Manager Adapters 6.0 and 7.0 are vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote authe… Security Identity Manager Adapter Patch available Fix from $1,6002021-06-28 MEDIUM 5.4 CVE-2021-29775 IBM Business Automation Workflow 19.0.03 and 20.0 and IBM Cloud Pak for Automation 20.0.3-IF002 and 21.0.1 are vulnerable to cross-site scripting. Th… Business Automation Workflow Patch available Fix from $1,6002021-06-28 HIGH 7.8 CVE-2020-4609 IBM Security Sevret Server (IBM Security Verify Privilege Manager 10.8.2) is vulnerable to a buffer overflow, caused by improper bounds checking. A l… Security Verify Privilege Manager 11.0+ Fix from $1,9502021-06-25 HIGH 7.8 CVE-2020-4610 IBM Security Secret Server (IBM Security Verify Privilege Manager 10.8.2 ) could allow a local user to execute code due to improper integrity checks.… Security Verify Privilege Manager 11.0+ Fix from $1,9502021-06-25 MEDIUM 5.4 CVE-2021-29676 IBM Security Verify (IBM Security Verify Privilege Vault 10.9.66) is vulnerable to link injection. By persuading a victim to click on a specially-cra… Security Verify 10.9.66+ Fix from $1,6002021-06-25 MEDIUM 5.4 CVE-2021-29677 IBM Security Verify (IBM Security Verify Privilege Vault 10.9.66) is vulnerable to cross-site scripting. This vulnerability allows users to embed arb… Security Verify 10.9.66+ Fix from $1,6002021-06-25 HIGH 8.1 CVE-2020-4945 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated user to overwrite arbirary files due to improper … Db2 Patch available Fix from $1,9502021-06-24 HIGH 7.5 CVE-2021-29703 Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of service as the server terminates abnormally when executing… Db2 Patch available Fix from $1,9502021-06-24 MEDIUM 6.5 CVE-2021-20579 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a user who can create a view or inline … Db2 Patch available Fix from $1,6002021-06-24 MEDIUM 6.5 CVE-2021-29777 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5, under specific circumstance of a table being dropp… Db2 Patch available Fix from $1,6002021-06-24 HIGH 7.1 CVE-2021-29706 IBM AIX 7.1 could allow a non-privileged local user to exploit a vulnerability in the trace facility to expose sensitive information or cause a denia… Aix Patch available Fix from $1,9502021-06-17 HIGH 7.5 CVE-2021-20566 IBM Resilient SOAR V38.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM… Resilient Security Orchestration Automation And Response Patch available Fix from $1,9502021-06-16 HIGH 7.5 CVE-2021-29702 Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1.4 and 11.5.5 is vulnerable to a denial of service as the server terminates abnorma… Db2 after 11.5.5.0 Fix from $1,9502021-06-16 MEDIUM 6.5 CVE-2021-20483 IBM Security Identity Manager 6.0.2 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, a remote authenticat… Security Identity Manager Patch available Fix from $1,6002021-06-16 MEDIUM 6.5 CVE-2021-20488 IBM Security Identity Manager 6.0.2 could allow an authenticated malicious user to change the passwords of other users in the Windows AD environment … Security Identity Manager Patch available Fix from $1,6002021-06-16 MEDIUM 5.4 CVE-2020-5000 IBM Financial Transaction Manager 3.2.0 through 3.2.8 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaS… Financial Transaction Manager Patch available Fix from $1,6002021-06-15 HIGH 8.8 CVE-2021-29754 IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a privilege escalation vulnerability when using the SAML Web Inbound Trust A… Websphere Application Server 7.0.0.45 / 8.0.0.15+ Fix from $1,9502021-06-11