Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2020-4576 IBM WebSphere Application Server 7.5, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to obtain sensitive information with a specially-cr… Websphere Application Server 7.0.0.45 / 8.0.0.15+ Fix from $1,9502020-10-01 HIGH 7.8 CVE-2020-4607 IBM Security Secret Server (IBM Security Verify Privilege Vault Remote 1.2 ) could allow a local user to bypass security restrictions due to improper… Security Verify Privilege Vault Remote On Premises Patch available Fix from $1,9502020-09-29 MEDIUM 6.1 CVE-2020-4727 IBM InfoSphere Information Server 11.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a m… Infosphere Information Server Mitigation only Fix from $1,6002020-09-25 MEDIUM 5.3 CVE-2020-4531 IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.0, 8.5, and 8.6 could allow a remote attacker to obtain sens… Business Automation Workflow Mitigation only Fix from $1,6002020-09-25 HIGH 8.8 CVE-2020-4620EPSS 5% IBM Data Risk Manager (iDNA) 2.0.6 could allow a remote authenticated attacker to upload arbitrary files, caused by the improper validation of file e… Data Risk Manager 2.0.6.4+ Fix from $1,9502020-09-22 HIGH 8.8 CVE-2020-4621 IBM Data Risk Manager (iDNA) 2.0.6 could allow an authenticated user to escalate their privileges to administrator due to insufficient authorization … Data Risk Manager 2.0.6.4+ Fix from $1,9502020-09-22 HIGH 7.5 CVE-2020-4622 IBM Data Risk Manager (iDNA) 2.0.6 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authen… Data Risk Manager 2.0.6.4+ Fix from $1,9502020-09-22 MEDIUM 6.5 CVE-2020-4619 IBM Data Risk Manager (iDNA) 2.0.6 stores user credentials in plain in clear text which can be read by an authenticated user. IBM X-Force ID: 184976. Data Risk Manager 2.0.6.4+ Fix from $1,6002020-09-22 HIGH 8.8 CVE-2020-4611 IBM Data Risk Manager (iDNA) 2.0.6 could allow an authenticated user to bypass security and execute actions reserved for admins. IBM X-Force ID: 1849… Data Risk Manager 2.0.6.4+ Fix from $1,9502020-09-22 HIGH 8.1 CVE-2020-4617 IBM Data Risk Manager (iDNA) 2.0.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized ac… Data Risk Manager 2.0.6.4+ Fix from $1,9502020-09-22 HIGH 7.5 CVE-2020-4613 IBM Data Risk Manager (iDNA) 2.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive inform… Data Risk Manager 2.0.6.4+ Fix from $1,9502020-09-22 HIGH 7.5 CVE-2020-4614 IBM Data Risk Manager (iDNA) 2.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive information. … Data Risk Manager 2.0.6.4+ Fix from $1,9502020-09-22 MEDIUM 6.5 CVE-2020-4612 IBM Data Risk Manager (iDNA) 2.0.6 could allow an authenticated user to obtain sensitive information using a specially crafted HTTP request. IBM X-Fo… Data Risk Manager 2.0.6.4+ Fix from $1,6002020-09-22 MEDIUM 5.4 CVE-2020-4615 IBM Data Risk Manager (iDNA) 2.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the W… Data Risk Manager 2.0.6.4+ Fix from $1,6002020-09-22 MEDIUM 5.3 CVE-2020-4616 IBM Data Risk Manager (iDNA) 2.0.6 could disclose sensitive username information to an attacker using a specially crafted HTTP request. IBM X-Force I… Data Risk Manager 2.0.6.4+ Fix from $1,6002020-09-22 HIGH 7.5 CVE-2020-4643 IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A re… Websphere Application Server after 9.0.5.5 Fix from $1,9502020-09-21 MEDIUM 6.5 CVE-2020-4590 IBM WebSphere Application Server Liberty 17.0.0.3 through 20.0.0.9 running oauth-2.0 or openidConnectServer-1.0 server features is vulnerable to a de… Websphere Application Server after 20.0.0.9 Fix from $1,6002020-09-21 MEDIUM 6.1 CVE-2020-4731 IBM Aspera Web Application 1.9.14 PL1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in th… Aspera Shares after 1.9.14 Fix from $1,6002020-09-21 HIGH 7.5 CVE-2020-4579 IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.12 could allow a remote attacker to cause a denial of service by sending a specially crafted HTTP/2… Datapower Gateway after 2018.4.1.12 Fix from $1,9502020-09-21 HIGH 7.5 CVE-2020-4580 IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.12 could allow a remote attacker to cause a denial of service by sending a specially crafted a JSON… Datapower Gateway after 2018.4.1.12 Fix from $1,9502020-09-21 HIGH 7.5 CVE-2020-4581 IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.12 could allow a remote attacker to cause a denial of service by sending a chunked transfer-encodin… Datapower Gateway after 2018.4.1.12 Fix from $1,9502020-09-21 HIGH 8.2 CVE-2020-4409 IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote attacker to conduct phishing attacks, using a tabnabbing attack. By persuading a vic… Control Desk 7.6.1.2+ Fix from $1,9502020-09-16 MEDIUM 5.3 CVE-2020-4708 IBM Security Trusteer Pinpoint Detect 11.6.5 could disclose some information due to using a wildcard in the Access-Control-Allow-Origin header. IBM X… Security Trusteer Pinpoint Detect 11.6.5.2+ Fix from $1,6002020-09-16 MEDIUM 6.1 CVE-2020-8339 A cross-site scripting inclusion (XSSI) vulnerability was reported in the legacy IBM BladeCenter Advanced Management Module (AMM) web interface prior… Bladecenter Advanced Management Module Firmware 3.68n+ Fix from $1,6002020-09-15 HIGH 8.8 CVE-2020-4521EPSS 6% IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unsafe … Maximo Asset Management 7.6.0.10 / 7.6.1.2+ Fix from $1,9502020-09-15 HIGH 8.0 CVE-2020-4703 IBM Spectrum Protect Plus 10.1.0 through 10.1.6 Administrative Console could allow an authenticated attacker to upload arbitrary files which could be… Spectrum Protect Plus after 10.1.6 Fix from $1,9502020-09-15 MEDIUM 6.5 CVE-2020-4711 IBM Spectrum Protect Plus 10.1.0 through 10.1.6 could allow a remote attacker to traverse directories on the system. An attacker could send a special… Spectrum Protect Plus after 10.1.6 Fix from $1,6002020-09-15 MEDIUM 5.4 CVE-2020-4530 IBM Business Automation Workflow C.D.0 and IBM Business Process Manager 8.0, 8.5, and 8.6 are vulnerable to cross-site scripting. This vulnerability … Business Automation Workflow 8.0.1.0 / 8.5.7.0+ Fix from $1,6002020-09-15 MEDIUM 6.3 CVE-2019-4671 IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which coul… Maximo Asset Management 7.6.0.10 / 7.6.1.2+ Fix from $1,6002020-09-15 MEDIUM 5.4 CVE-2020-4578 IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav… Websphere Application Server after 9.0.5.5 Fix from $1,6002020-09-10