Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.5 CVE-2020-4891 IBM Spectrum Scale 5.0.0 through 5.0.5.5 and 5.1.0 through 5.1.0.2 uses an inadequate account lockout setting that could allow a local user er to bru… Spectrum Scale after 5.1.0.2 Fix from $1,6002021-03-16 HIGH 7.3 CVE-2020-4184 IBM Security Guardium 11.2 performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or… Security Guardium No fix yet Fix from $1,9502021-03-15 HIGH 7.5 CVE-2020-4831 IBM DataPower Gateway 10.0.0.0 through 10.0.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sen… Datapower Gateway after 10.0.1.0 Fix from $1,9502021-03-12 MEDIUM 5.4 CVE-2021-20336 IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code… Tivoli Netcool\/omnibus Webgui Mitigation only Fix from $1,6002021-03-11 HIGH 7.8 CVE-2020-5025 IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 db2fm is vulnerable to a buffer overflow, caused by… Db2 11.1.4.6 / 11.5.5.0+ Fix from $1,9502021-03-11 HIGH 7.5 CVE-2020-5024 IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow an unauthenticated attacker to cause a … Db2 11.1.4.6 / 11.5.5.0+ Fix from $1,9502021-03-11 MEDIUM 6.5 CVE-2020-5016 IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the system. When application securit… Websphere Application Server after 9.0.5.6 Fix from $1,6002021-03-10 MEDIUM 5.5 CVE-2020-4717 A vulnerability exists in IBM SPSS Modeler Subscription Installer that allows a user with create symbolic link permission to write arbitrary file in … Spss Modeler Mitigation only Fix from $1,6002021-03-10 MEDIUM 5.3 CVE-2021-20341 IBM Cloud Pak for Multicloud Management Monitoring 2.2 returns potentially sensitive information in headers which could lead to further attacks again… Cloud Pak For Multicloud Management Monitoring 2.2.6+ Fix from $1,6002021-03-09 HIGH 7.5 CVE-2020-4695 IBM API Connect V10 is impacted by insecure communications during database replication. As the data replication happens over insecure communication c… Api Connect after 10.0.1.0 Fix from $1,9502021-03-08 MEDIUM 6.7 CVE-2020-5014 IBM DataPower Gateway V10 and V2018 could allow a local attacker with administrative privileges to execute arbitrary code on the system using a serve… Datapower Gateway after 2018.4.1.14 Fix from $1,6002021-03-08 MEDIUM 6.5 CVE-2020-4903 IBM API Connect V10 and V2018 could allow an attacker who has intercepted a registration invitation link to impersonate the registered user or obtain… Api Connect 10.0.1.1 / 2018.4.1.13+ Fix from $1,6002021-03-08 MEDIUM 5.4 CVE-2020-4856 IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web… Doors Next Patch available Fix from $1,6002021-03-04 MEDIUM 5.4 CVE-2020-4857 IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web… Doors Next Patch available Fix from $1,6002021-03-04 MEDIUM 5.4 CVE-2020-4863 IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web… Doors Next Patch available Fix from $1,6002021-03-04 MEDIUM 5.4 CVE-2020-4866 IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thu… Doors Next Patch available Fix from $1,6002021-03-04 MEDIUM 5.4 CVE-2020-4975 IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thu… Doors Next Patch available Fix from $1,6002021-03-04 MEDIUM 5.4 CVE-2021-20340 IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thu… Doors Next Patch available Fix from $1,6002021-03-04 MEDIUM 5.4 CVE-2021-20350 IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thu… Doors Next Patch available Fix from $1,6002021-03-04 MEDIUM 5.4 CVE-2021-20351 IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thu… Doors Next Patch available Fix from $1,6002021-03-04 HIGH 7.5 CVE-2021-20442 IBM Security Verify Bridge contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication… Security Verify Bridge Patch available Fix from $1,9502021-03-03 MEDIUM 5.9 CVE-2021-20441 IBM Security Verify Bridge uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. I… Security Verify Bridge Patch available Fix from $1,6002021-03-03 MEDIUM 6.5 CVE-2020-4931 IBM MQ 9.1 LTS, 9.2 LTS, and 9.1 CD AMQP Channels could allow an authenticated user to cause a denial of service due to an issue processing messages.… Mq Patch available Fix from $1,6002021-02-24 HIGH 8.8 CVE-2021-20443 IBM Maximo for Civil Infrastructure 7.6.2 includes executable functionality (such as a library) from a source that is outside of the intended control… Maximo For Civil Infrastructure Patch available Fix from $1,9502021-02-18 HIGH 7.5 CVE-2021-20354 IBM WebSphere Application Server 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories. An attacker could send a specially-crafted … Websphere Application Server after 9.0.5.6 Fix from $1,9502021-02-18 MEDIUM 6.5 CVE-2021-20445 IBM Maximo for Civil Infrastructure 7.6.2 could allow a user to obtain sensitive information due to insecure storeage of authentication credentials. … Maximo For Civil Infrastructure Patch available Fix from $1,6002021-02-18 MEDIUM 6.1 CVE-2021-20444 IBM Maximo for Civil Infrastructure 7.6.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code i… Maximo For Civil Infrastructure Patch available Fix from $1,6002021-02-18 MEDIUM 5.4 CVE-2021-20446 IBM Maximo for Civil Infrastructure 7.6.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code i… Maximo For Civil Infrastructure Patch available Fix from $1,6002021-02-18 MEDIUM 5.4 CVE-2020-4933 IBM Jazz Reporting Service 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary J… Jazz Reporting Service Patch available Fix from $1,6002021-02-18 HIGH 8.0 CVE-2020-4955 IBM Spectrum Protect Operations Center 7.1 and 8.1could allow a remote attacker to execute arbitrary code on the system, caused by improper parameter… Spectrum Protect Operations Center 7.1.13.000 / 8.1.10.200+ Fix from $1,9502021-02-15