Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2019-4692
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 discloses sensitive information to unauthorized users. The information can be used to mount furth…
Guardium Data Encryption
1.6.2+
MEDIUM 5.3
CVE-2019-4701
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 is deployed with active debugging code that can create unintended entry points. IBM X-Force ID: 1…
Guardium Data Encryption
1.7.0+
HIGH 7.5
CVE-2018-1501
IBM Security Guardium 10.5, 10.6, and 11.0 could allow an unauthorized user to obtain sensitive information due to missing security controls. IBM X-F…
Security Guardium
Patch available
HIGH 7.5
CVE-2019-4689
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly …
Guardium Data Encryption
1.7.0 / 4.0.0.3+
MEDIUM 5.3
CVE-2019-4686
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be ab…
Guardium Data Encryption
1.7.0 / 4.0.0.3+
HIGH 7.8
CVE-2020-4587
IBM Sterling Connect:Direct for UNIX 4.2.0, 4.3.0, 6.0.0, and 6.1.0 is vulnerable to a stack based buffer ovreflow, caused by improper bounds checkin…
Connect\
Mitigation only
MEDIUM 6.5
CVE-2020-4383
IBM Spectrum Scale for IBM Elastic Storage Server 5.3.0 through 5.3.5 could allow an authenticated user to cause a denial of service during deploymen…
Elastic Storage Server
after 5.3.5
MEDIUM 6.1
CVE-2020-4598
IBM Security Guardium Insights 2.0.1 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim…
Security Guardium Insights
Mitigation only
MEDIUM 5.5
CVE-2020-4382
IBM Spectrum Scale for IBM Elastic Storage Server 5.3.0 through 5.3.5 could allow an authenticated user to cause a denial of service during deploymen…
Elastic Storage Server
after 5.3.5
MEDIUM 5.4
CVE-2020-4165
IBM Security Guardium Insights 2.0.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a mal…
Security Guardium Insights
Mitigation only
MEDIUM 6.5
CVE-2020-4381
IBM Spectrum Scale for IBM Elastic Storage Server 5.3.0 through 5.3.6 could allow an authenticated user to cause a denial of service during deploymen…
Elastic Storage Server
after 5.3.6
MEDIUM 6.5
CVE-2020-4648
A vulnerability exsists in IBM Planning Analytics 2.0 whereby avatars in Planning Analytics Workspace could be modified by other users without author…
Planning Analytics
Patch available
MEDIUM 6.1
CVE-2020-4653
IBM Planning Analytics 2.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit …
Planning Analytics
Patch available
HIGH 8.1
CVE-2020-4686
IBM Spectrum Virtualize 8.3.1 could allow a remote user authenticated via LDAP to escalate their privileges and perform actions they should not have …
Spectrum Virtualize
Patch available
HIGH 8.8
CVE-2020-4662
IBM Event Streams 10.0.0 could allow an authenticated user to perform tasks to a schema due to improper authentication validation. IBM X-Force ID: 18…
Event Streams
Patch available
CRITICAL 9.8
CVE-2020-4589EPSS 8%
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafte…
Websphere Application Server
after 9.0.5.4
HIGH 8.1
CVE-2020-4486
IBM QRadar 7.2.0 thorugh 7.2.9 could allow an authenticated user to overwrite or delete arbitrary files due to a flaw after WinCollect installation. …
Qradar Security Information And Event Manager
after 7.2.9
MEDIUM 6.5
CVE-2020-4485
IBM QRadar 7.2.0 through 7.2.9 could allow an authenticated user to disable the Wincollect service which could aid an attacker in bypassing security …
Qradar Security Information And Event Manager
after 7.2.9
MEDIUM 6.1
CVE-2020-4533
IBM Jazz Reporting Service 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScri…
Jazz Reporting Service
Patch available
MEDIUM 6.1
CVE-2020-4539
IBM Jazz Reporting Service 6.0.2, 6.0.6, 6.0.6.1, 7.0, and 7.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbi…
Jazz Reporting Service
Patch available
MEDIUM 6.1
CVE-2020-4541
IBM Jazz Reporting Service 7.0 and 7.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in…
Jazz Reporting Service
Patch available
HIGH 8.2
CVE-2020-4481
IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML …
Urbancode Deploy
Mitigation only
CRITICAL 9.8
CVE-2020-4459
IBM Security Verify Access 10.7 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentic…
Security Secret Server
10.8+
MEDIUM 5.5
CVE-2020-4631
IBM Spectrum Protect Plus 10.1.0 through 10.1.6 agent files, in non-default configurations, on Windows are assigned access to everyone with full cont…
Spectrum Protect Plus
after 10.1.6
MEDIUM 5.4
CVE-2020-4396
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScrip…
Engineering Test Management
Patch available
MEDIUM 5.4
CVE-2020-4525
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScrip…
Engineering Workflow Management
Patch available
MEDIUM 5.4
CVE-2020-4542
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScrip…
Engineering Requirements Management Doors Next
Patch available
MEDIUM 6.1
CVE-2020-4560
IBM Financial Transaction Manager 3.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in …
Financial Transaction Manager
Mitigation only
CRITICAL 9.1
CVE-2020-4377
IBM Cognos Anaytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could ex…
Cognos Analytics
Mitigation only
HIGH 8.8
CVE-2020-4534
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local authenticated attacker to gain elevated privileges on the system, caused …
Websphere Application Server
Mitigation only