Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2020-4697 IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI… Collaborative Lifecycle Management Mitigation only Fix from $1,6002021-01-08 MEDIUM 5.4 CVE-2020-4733 IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI… Collaborative Lifecycle Management Mitigation only Fix from $1,6002021-01-08 HIGH 7.5 CVE-2020-5018 IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may include sensitive information in its URLs increasing the risk of such information being caputured… Spectrum Protect Plus 10.1.7+ Fix from $1,9502021-01-08 MEDIUM 6.5 CVE-2020-5019 IBM Spectrum Protect Plus 10.1.0 through 10.1.6 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. B… Spectrum Protect Plus 10.1.7+ Fix from $1,6002021-01-08 MEDIUM 6.1 CVE-2020-5020 IBM Spectrum Protect Plus 10.1.0 through 10.1.6 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to … Spectrum Protect Plus 10.1.7+ Fix from $1,6002021-01-08 MEDIUM 5.5 CVE-2020-5017 IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may allow a local user to obtain access to information beyond their intended role and permissions. IB… Spectrum Protect 10.1.7+ Fix from $1,6002021-01-08 MEDIUM 5.3 CVE-2020-5022 IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may allow unauthenticated and unauthorized access to VDAP proxy which can result in an attacker obtai… Spectrum Protect Plus 10.1.7+ Fix from $1,6002021-01-08 MEDIUM 5.4 CVE-2020-4663 IBM Engineering Requirements Quality Assistant On-Premises is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary … Engineering Requirements Quality Assistant On Premises Patch available Fix from $1,6002021-01-08 MEDIUM 5.4 CVE-2020-4664 IBM Engineering Requirements Quality Assistant On-Premises is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary … Engineering Requirements Quality Assistant On Premises Patch available Fix from $1,6002021-01-08 MEDIUM 5.4 CVE-2020-4666 IBM Engineering Requirements Quality Assistant On-Premises is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary … Engineering Requirements Quality Assistant On Premises Patch available Fix from $1,6002021-01-08 HIGH 7.5 CVE-2020-4898 IBM Emptoris Strategic Supply Management 10.1.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sen… Emptoris Strategic Supply Management 10.1.3.30+ Fix from $1,9502021-01-07 MEDIUM 6.5 CVE-2020-4896 IBM Emptoris Sourcing 10.1.0, 10.1.1, and 10.1.3 is vulnerable to web cache poisoning, caused by improper input validation by modifying HTTP request … Emptoris Sourcing 10.1.0.38 / 10.1.1.35+ Fix from $1,6002021-01-07 MEDIUM 5.9 CVE-2020-4893 IBM Emptoris Strategic Supply Management 10.1.0, 10.1.1, and 10.1.3 transmits sensitive information in HTTP GET request parameters. This may lead to … Emptoris Strategic Supply Management 10.1.0.38 / 10.1.1.35+ Fix from $1,6002021-01-07 MEDIUM 5.4 CVE-2020-4892 IBM Emptoris Contract Management 10.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in … Emptoris Contract Management 10.1.3.30+ Fix from $1,6002021-01-07 MEDIUM 5.4 CVE-2020-4895 IBM Emptoris Strategic Supply Management 10.1.0, 10.1.1, and 10.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to … Emptoris Strategic Supply Management 10.1.0.38 / 10.1.1.35+ Fix from $1,6002021-01-07 MEDIUM 5.3 CVE-2020-4897 IBM Emptoris Contract Management and IBM Emptoris Spend Analysis 10.1.0, 10.1.1, and 10.1.3 could allow a remote attacker to obtain sensitive informa… Emptoris Contract Management 10.1.0.38 / 10.1.1.35+ Fix from $1,6002021-01-07 MEDIUM 5.3 CVE-2020-4336 IBM WebSphere eXtreme Scale 8.6.1 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties hav… Websphere Extreme Scale 8.6.1.4+ Fix from $1,6002021-01-06 CRITICAL 9.1 CVE-2020-4899 IBM API Connect 5.0.0.0 through 5.0.8.10 could potentially leak sensitive information or allow for data corruption due to plain text transmission of … Api Connect after 5.0.8.10 Fix from $2,3002021-01-05 HIGH 8.8 CVE-2019-4728 IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_2, 6.0.0.0 through 6.0.3.2, and 6.1.0.0 could allow a remote attacker to execute… Sterling B2b Integrator after 6.0.3.2 Fix from $1,9502021-01-05 HIGH 8.8 CVE-2020-4762 IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_2, 6.0.0.0 through 6.0.3.2, and 6.1.0.0 could allow an authenticated user to cre… Sterling B2b Integrator after 6.0.3.2 Fix from $1,9502021-01-05 MEDIUM 5.3 CVE-2020-4761 IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_2, 6.0.0.0 through 6.0.3.2, and 6.1.0.0 could allow a remote attacker to obtain … Sterling B2b Integrator after 6.0.3.2 Fix from $1,6002021-01-05 HIGH 8.8 CVE-2020-4942 IBM Curam Social Program Management 7.0.9 and 7.0.11 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious a… Curam Social Program Management Mitigation only Fix from $1,9502021-01-04 MEDIUM 6.7 CVE-2020-4928 IBM Cloud Pak System 2.3 could allow a local privileged attacker to upload arbitrary files. By intercepting the request and modifying the file extent… Cloud Pak System 2.3.3.3+ Fix from $1,6002021-01-04 HIGH 8.8 CVE-2020-4917 IBM Cloud Pak System 2.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions tran… Cloud Pak System 2.3.3.3+ Fix from $1,9502021-01-04 HIGH 7.2 CVE-2020-4912 IBM Cloud Pak System 2.3 Self Service Console could allow a privilege escalation by capturing the user request URL when logged in as a privileged use… Cloud Pak System 2.3.3.3+ Fix from $1,9502021-01-04 MEDIUM 5.5 CVE-2020-4642 IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow local attacker to cause a denial of ser… Db2 Mitigation only Fix from $1,6002020-12-23 CRITICAL 9.8 CVE-2020-4988 Loopback 8.0.0 contains a vulnerability that could allow an attacker to manipulate or pollute Javascript values and cause a denial of service or poss… Loopback Mitigation only Fix from $2,3002020-12-21 HIGH 7.5 CVE-2020-4870 IBM MQ 9.2 CD and LTS are vulnerable to a denial of service attack caused by an error processing connecting applications. IBM X-Force ID: 190833. Mq Patch available Fix from $1,9502020-12-21 MEDIUM 6.1 CVE-2020-4840 IBM Security Secret Server 10.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to v… Security Secret Server Patch available Fix from $1,6002020-12-21 MEDIUM 5.9 CVE-2020-4841 IBM Security Secret Server 10.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict T… Security Secret Server Patch available Fix from $1,6002020-12-21