VYPR

Vendor CVEs

IBM

All CVEs

8,825 total · sorted by risk
  • CVE-2021-20378HigJul 7, 2021
    risk 0.57cvss 8.8epss 0.00

    IBM Guardium Data Encryption (GDE) 3.0.0.2 and 4.0.0.4 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 195709.

  • CVE-2020-4902HigJul 1, 2021
    risk 0.57cvss 8.8epss 0.01

    IBM Datacap Taskmaster Capture (IBM Datacap Navigator 9.1.7) is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 191045.

  • CVE-2021-20574HigJun 28, 2021
    risk 0.57cvss 8.8epss 0.02

    IBM Security Identity Manager Adapters 6.0 and 7.0 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this vulnerability and takeover other accounts. IBM X-Force ID: 199252.

  • CVE-2021-29754HigJun 11, 2021
    risk 0.57cvss 8.8epss 0.01

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a privilege escalation vulnerability when using the SAML Web Inbound Trust Association Interceptor (TAI). IBM X-Force ID: 202006.

  • CVE-2021-20517HigJun 7, 2021
    risk 0.57cvss 8.8epss 0.02

    IBM WebSphere Application Server Network Deployment 8.5 and 9.0 could allow a remote authenticated attacker to traverse directories. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to read and delete arbitrary files on the system. IBM…

  • CVE-2020-4495HigJun 2, 2021
    risk 0.57cvss 8.8epss 0.03

    IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to bypass security restrictions, caused by improper access control. By sending a specially-crafted request to the REST API, an attacker could exploit this vulnerability to bypass access restrictions,…

  • CVE-2020-4520HigJun 1, 2021
    risk 0.57cvss 8.8epss 0.03

    IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to inject malicious HTML code that when viewed by the authenticated victim would execute the code. IBM X-Force ID: 182395.

  • CVE-2020-4990HigMay 24, 2021
    risk 0.57cvss 8.8epss 0.01

    IBM Security Guardium 11.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 192710.

  • CVE-2021-29686HigMay 20, 2021
    risk 0.57cvss 8.8epss 0.01

    IBM Security Identity Manager 7.0.2 could allow an authenticated user to bypass security and perform actions that they should not have access to. IBM X-Force ID: 200015

  • CVE-2021-20443HigFeb 18, 2021
    risk 0.57cvss 8.8epss 0.01

    IBM Maximo for Civil Infrastructure 7.6.2 includes executable functionality (such as a library) from a source that is outside of the intended control sphere. IBM X-Force ID: 196619.

  • CVE-2021-20403HigFeb 11, 2021
    risk 0.57cvss 8.8epss 0.00

    IBM Security Verify Information Queue 1.0.6 and 1.0.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

  • CVE-2020-4952HigJan 27, 2021
    risk 0.57cvss 8.8epss 0.02

    IBM Security Guardium 11.2 could allow an authenticated user to gain root access due to improper access control. IBM X-Force ID: 192028.

  • CVE-2020-4921HigJan 20, 2021
    risk 0.57cvss 8.8epss 0.01

    IBM Security Guardium 10.6 and 11.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 191398.

  • CVE-2020-4762HigJan 5, 2021
    risk 0.57cvss 8.8epss 0.01

    IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_2, 6.0.0.0 through 6.0.3.2, and 6.1.0.0 could allow an authenticated user to create a privileged account due to improper access controls. IBM X-Force ID: 188896.

  • CVE-2020-4942HigJan 4, 2021
    risk 0.57cvss 8.8epss 0.01

    IBM Curam Social Program Management 7.0.9 and 7.0.11 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 191942.

  • CVE-2020-4917HigJan 4, 2021
    risk 0.57cvss 8.8epss 0.00

    IBM Cloud Pak System 2.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 191391.

  • CVE-2020-4633HigDec 11, 2020
    risk 0.57cvss 8.8epss 0.03

    IBM Resilient SOAR V38.0 could allow a remote attacker to execute arbitrary code on the system, caused by formula injection due to improper input validation.

  • CVE-2020-4700HigNov 16, 2020
    risk 0.57cvss 8.8epss 0.01

    IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 could allow an authenticated user belonging to a specific user group to create a user or group with administrative privileges. IBM X-Force ID: 187077.

  • CVE-2020-4655HigNov 16, 2020
    risk 0.57cvss 8.8epss 0.01

    IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the…

  • CVE-2020-4647HigNov 16, 2020
    risk 0.57cvss 8.8epss 0.01

    IBM Sterling File Gateway 2.2.0.0 through 2.2.6.5 and 6.0.0.0 through 6.0.3.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.

  • CVE-2019-4680HigOct 20, 2020
    risk 0.57cvss 8.8epss 0.01

    IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.2.2 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID:…

  • CVE-2020-4621HigSep 22, 2020
    risk 0.57cvss 8.8epss 0.01

    IBM Data Risk Manager (iDNA) 2.0.6 could allow an authenticated user to escalate their privileges to administrator due to insufficient authorization checks. IBM X-Force ID: 184981.

  • CVE-2020-4611HigSep 22, 2020
    risk 0.57cvss 8.8epss 0.02

    IBM Data Risk Manager (iDNA) 2.0.6 could allow an authenticated user to bypass security and execute actions reserved for admins. IBM X-Force ID: 184922.

  • CVE-2012-3336HigSep 1, 2020
    risk 0.57cvss 8.8epss 0.01

    IBM InfoSphere Guardium 8.0, 8.01, and 8.2 is vulnerable to SQL injection. A remote authenticated attacker could send specially-crafted SQL statements to multiple scripts, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM…

  • CVE-2019-4713HigAug 26, 2020
    risk 0.57cvss 8.8epss 0.03

    IBM Security Guardium Data Encryption (GDE) 3.0.0.2 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM…

  • CVE-2020-4662HigAug 14, 2020
    risk 0.57cvss 8.8epss 0.01

    IBM Event Streams 10.0.0 could allow an authenticated user to perform tasks to a schema due to improper authentication validation. IBM X-Force ID: 186233.

  • CVE-2020-4534HigAug 3, 2020
    risk 0.57cvss 8.8epss 0.00

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local authenticated attacker to gain elevated privileges on the system, caused by improper handling of UNC paths. By scheduling a task with a specially-crafted UNC path, an attacker could exploit this…

  • CVE-2020-4180HigJun 3, 2020
    risk 0.57cvss 8.8epss 0.03

    IBM Security Guardium 11.1 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 174735.

  • CVE-2019-4750HigApr 24, 2020
    risk 0.57cvss 8.8epss 0.01

    IBM Cloud App Management 2019.3.0 and 2019.4.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 173310.

  • CVE-2020-4202HigApr 23, 2020
    risk 0.57cvss 8.8epss 0.01

    IBM UrbanCode Deploy (UCD) 7.0.3.0 and 7.0.4.0 could allow an authenticated user to impersonate another user if the server is configured to enable Distributed Front End (DFE). IBM X-Force ID: 174955.

  • CVE-2020-4272HigApr 15, 2020
    risk 0.57cvss 8.8epss 0.03

    IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-crafted request specify a malicious file from a remote system, which could allow the attacker to execute arbitrary code on the vulnerable server.…

  • CVE-2020-4362HigApr 10, 2020
    risk 0.57cvss 8.8epss 0.02

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional is vulnerable to a privilege escalation vulnerability when using token-based authentication in an admin request over the SOAP connector. IBM X-Force ID: 178929.

  • CVE-2020-4238HigMar 31, 2020
    risk 0.57cvss 8.8epss 0.01

    IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 175411.

  • CVE-2020-4237HigMar 31, 2020
    risk 0.57cvss 8.8epss 0.01

    IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 175410.

  • CVE-2020-4253HigMar 24, 2020
    risk 0.57cvss 8.8epss 0.01

    IBM Content Navigator 3.0CD does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 175559.

  • CVE-2019-4752HigFeb 20, 2020
    risk 0.57cvss 8.8epss 0.01

    IBM Emptoris Spend Analysis and IBM Emptoris Strategic Supply Management Platform 10.1.0.x, 10.1.1.x, and 10.1.3.x is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete…

  • CVE-2019-4613HigFeb 5, 2020
    risk 0.57cvss 8.8epss 0.01

    IBM Planning Analytics 2.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 168524.

  • CVE-2018-1934HigDec 20, 2019
    risk 0.57cvss 8.8epss 0.00

    IBM Cognos Business Intelligence 10.2.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 153179.

  • CVE-2019-4612HigDec 9, 2019
    risk 0.57cvss 8.8epss 0.01

    IBM Planning Analytics 2.0 is vulnerable to malicious file upload in the My Account Portal. Attackers can make use of this weakness and upload malicious executable files into the system and it can be sent to victim for performing further attacks. IBM X-Force ID: 168523.

  • CVE-2019-4130HigDec 3, 2019
    risk 0.57cvss 8.8epss 0.02

    IBM Cloud Pak System 2.3 and 2.3.0.1 could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server. IBM X-Force ID: 158280.

  • CVE-2019-4387HigNov 26, 2019
    risk 0.57cvss 8.8epss 0.01

    IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.2.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID:…

  • CVE-2019-4561HigNov 20, 2019
    risk 0.57cvss 8.8epss 0.04

    IBM Security Identity Manager 6.0.0 could allow a remote attacker to execute arbitrary code on the system, caused by the deserialization of untrusted data. By persuading a victim to visit a specially crafted Web site, an attacker could exploit this vulnerability to execute…

  • CVE-2018-1721HigNov 9, 2019
    risk 0.57cvss 8.8epss 0.02

    IBM Cognos Analytics 11.0 and 11.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or cause the web server to make HTTP requests to arbitrary domains. IBM…

  • CVE-2019-4546HigOct 29, 2019
    risk 0.57cvss 8.8epss 0.01

    After installing the IBM Maximo Health- Safety and Environment Manager 7.6.1, a user is granted additional privileges that they are not normally allowed to access. IBM X-Force ID: 165948.

  • CVE-2019-4422HigOct 3, 2019
    risk 0.57cvss 8.8epss 0.02

    IBM Security Guardium 9.0, 9.5, and 10.6 are vulnerable to a privilege escalation which could allow an authenticated user to change the accessmgr password. IBM X-Force ID: 162768.

  • CVE-2019-4117HigAug 20, 2019
    risk 0.57cvss 8.8epss 0.01

    IBM Cloud Private 3.1.1 and 3.1.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 158116.

  • CVE-2019-4212HigJul 25, 2019
    risk 0.57cvss 8.8epss 0.01

    IBM QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 159132.

  • CVE-2019-4292HigJul 2, 2019
    risk 0.57cvss 8.8epss 0.04

    IBM Security Guardium 10.5 could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable web server. IBM X-Force ID: 160698.

  • CVE-2019-4224HigJun 26, 2019
    risk 0.57cvss 8.8epss 0.01

    IBM PureApplication System 2.2.3.0 through 2.2.5.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 159240.

  • CVE-2019-4135HigJun 25, 2019
    risk 0.57cvss 8.8epss 0.02

    IBM Security Access Manager 9.0.1 through 9.0.6 is affected by a security vulnerability that could allow authenticated users to impersonate other users. IBM X-Force ID: 158331.

Page 10 of 177