VYPR

Vendor CVEs

IBM

All CVEs

8,825 total · sorted by risk
  • CVE-2022-22490MedAug 10, 2022
    risk 0.32cvss 4.9epss 0.01

    IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a privileged user to obtain sensitive Azure bot credential information. IBM X-Force ID: 226342.

  • CVE-2021-38936MedJul 20, 2022
    risk 0.32cvss 4.9epss 0.01

    IBM QRadar SIEM 7.3, 7.4, and 7.5 could disclose highly sensitive information to a privileged user. IBM X-Force ID: 210893.

  • CVE-2022-31770MedJul 5, 2022
    risk 0.32cvss 4.9epss 0.01

    IBM App Connect Enterprise Certified Container 4.2 could allow a user from the administration console to cause a denial of service by creating a specially crafted request. IBM X-Force ID: 228221.

  • CVE-2021-39046MedMar 18, 2022
    risk 0.32cvss 4.9epss 0.01

    IBM Business Automation Workflow 18.0, 19.0, 20.0, and 21.0 and IBM Business Process Manager 8.5 and 8.6 stores user credentials in plain clear text which can be read by a lprivileged user. IBM X-Force ID: 214346.

  • CVE-2021-38971MedMar 14, 2022
    risk 0.32cvss 4.9epss 0.01

    IBM Data Virtualization on Cloud Pak for Data 1.3.0, 1.4.1, 1.5.0, 1.7.1 and 1.7.3 could allow an authorized user to bypass data masking rules and obtain sensitve information. IBM X-Force ID: 212620.

  • CVE-2021-38911MedOct 19, 2021
    risk 0.32cvss 4.9epss 0.01

    IBM Security Risk Manager on CP4S 1.7.0.0 stores user credentials in plain clear text which can be read by a an authenticatedl privileged user. IBM X-Force ID: 209940.

  • CVE-2021-29811MedSep 20, 2021
    risk 0.32cvss 4.9epss 0.01

    IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 stores user credentials in plain clear text which can be read by an authenticated admin user. IBM X-Force ID: 204329.

  • CVE-2021-29728MedAug 30, 2021
    risk 0.32cvss 4.9epss 0.01

    IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID:…

  • CVE-2021-29739MedAug 10, 2021
    risk 0.32cvss 4.9epss 0.01

    IBM Planning Analytics Local 2.0 could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser. X-Force ID: 198846.

  • CVE-2021-29697MedAug 2, 2021
    risk 0.32cvss 4.9epss 0.01

    IBM Cloud Pak for Security (CP4S) 1.5.0.0, 1.5.1.0, 1.6.0.0, 1.6.1.0, 1.7.0.0, and 1.7.1.0 could allow a remote authenticated attacker to obtain sensitive information through HTTP requests that could be used in further attacks against the system.

  • CVE-2021-20511MedJul 15, 2021
    risk 0.32cvss 4.9epss 0.02

    IBM Security Verify Access Docker 10.0.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 198300.

  • CVE-2021-20496MedJul 15, 2021
    risk 0.32cvss 4.9epss 0.01

    IBM Security Verify Access Docker 10.0.0 could allow an authenticated user to bypass input due to improper input validation. IBM X-Force ID: 197966.

  • CVE-2021-20414MedJul 12, 2021
    risk 0.32cvss 4.9epss 0.01

    IBM Guardium Data Encryption (GDE) 3.0.0.2 could allow a user to bruce force sensitive information due to not properly limiting the number of interactions. IBM X-Force ID: 196216.

  • CVE-2021-20583MedJun 25, 2021
    risk 0.32cvss 4.9epss 0.01

    IBM Security Verify (IBM Security Verify Privilege Vault 10.9.66) could disclose sensitive information through an HTTP GET request by a privileged user due to improper input validation.. IBM X-Force ID: 199396.

  • CVE-2020-4839MedMay 25, 2021
    risk 0.32cvss 4.9epss 0.02

    IBM Host firmware for LC-class Systems is vulnerable to a stack based buffer overflow, caused by improper bounds checking. A remote privileged attacker could exploit this vulnerability and cause a denial of service. IBM X-Force ID: 190037.

  • CVE-2020-4993MedMay 5, 2021
    risk 0.32cvss 4.9epss 0.01

    IBM QRadar SIEM 7.3 and 7.4 when decompressing or verifying signature of zip files processes data in a way that may be vulnerable to path traversal attacks. IBM X-Force ID: 192905.

  • CVE-2020-4719MedMar 2, 2021
    risk 0.32cvss 4.9epss 0.01

    The IBM Cloud APM 8.1.4 server will issue a DNS request to resolve any hostname specified in the Cloud Event Management Webhook URL configuration definition. This could enable an authenticated user with admin authorization to create DNS query strings that are not hostnames. IBM…

  • CVE-2020-4842MedDec 21, 2020
    risk 0.32cvss 4.9epss 0.01

    IBM Security Secret Server 10.6 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 190046.

  • CVE-2020-4678MedOct 12, 2020
    risk 0.32cvss 4.9epss 0.01

    IBM Security Guardium 11.2 could allow an attacker with admin access to obtain and read files that they normally would not have access to. IBM X-Force ID: 186423.

  • CVE-2020-4618MedSep 22, 2020
    risk 0.32cvss 4.9epss 0.01

    IBM Data Risk Manager (iDNA) 2.0.6 could allow a privileged user to cause a denial of service due to improper input validation. IBM X-Force ID: 184937.

  • CVE-2020-4378MedMay 27, 2020
    risk 0.32cvss 4.9epss 0.01

    IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 could allow a privileged authenticated user to perform unauthorized actions using a specially crated HTTP POST command. IBM X-Force ID: 179157.

  • CVE-2020-4203MedMar 19, 2020
    risk 0.32cvss 4.9epss 0.01

    IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.8 could potentially disclose highly sensitive information to a privileged user due to improper access controls. IBM X-Force ID: 174956.

  • CVE-2019-4674MedFeb 4, 2020
    risk 0.32cvss 4.9epss 0.02

    IBM Security Identity Manager 7.0.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 171510.

  • CVE-2019-4295MedJul 1, 2019
    risk 0.32cvss 4.9epss 0.01

    IBM Robotic Process Automation with Automation Anywhere 11 could allow an attacker with specialized access to obtain highly sensitive from the credential vault. IBM X-Force ID: 160758.

  • CVE-2018-2006MedFeb 21, 2019
    risk 0.32cvss 4.9epss 0.02

    IBM Robotic Process Automation with Automation Anywhere 11 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to upload arbitrary files to the system. IBM X-Force ID:…

  • CVE-2018-1976MedJan 29, 2019
    risk 0.32cvss 4.9epss 0.02

    IBM API Connect 5.0.0.0 through 5.0.8.4 is impacted by sensitive information disclosure via a REST API that could allow a user with administrative privileges to obtain highly sensitive information. IBM X-Force ID: 154031.

  • CVE-2018-1932MedJan 8, 2019
    risk 0.32cvss 4.9epss 0.03

    IBM API Connect 5.0.0.0 through 5.0.8.4 is affected by a vulnerability in the role-based access control in the management server that could allow an authenticated user to obtain highly sensitive information. IBM X-Force ID: 153175.

  • CVE-2018-9085MedNov 16, 2018
    risk 0.32cvss 4.9epss 0.01

    A write protection lock bit was left unset after boot on an older generation of Lenovo and IBM System x servers, potentially allowing an attacker with administrator access to modify the subset of flash memory containing Intel Server Platform Services (SPS) and the system Flash…

  • CVE-2018-1791MedSep 14, 2018
    risk 0.32cvss 4.9epss 0.01

    IBM Connections 5.0, 5.5, and 6.0 is vulnerable to an External Service Interaction attack, caused by improper validation of a request property. By submitting suitable payloads, an attacker could exploit this vulnerability to induce the Connections server to attack other systems.…

  • CVE-2017-1752MedMay 25, 2018
    risk 0.32cvss 4.9epss 0.02

    IBM UrbanCode Deploy 6.1 and 6.2 could allow an authenticated privileged user to obtain highly sensitive information. IBM X-Force ID: 135547.

  • CVE-2017-1495MedAug 2, 2017
    risk 0.32cvss 4.9epss 0.01

    IBM InfoSphere Information Server 9.1, 11.3, and 11.5 could allow a privileged user to cause a memory dump that could contain highly sensitive information including access credentials. IBM X-Force ID: 128693.

  • CVE-2017-1370MedJul 31, 2017
    risk 0.32cvss 4.9epss 0.01

    IBM Jazz Reporting Service (JRS) 5.0 and 6.0 could disclose sensitive information, including user credentials, through an error message from the Report Builder administrator configuration page. IBM X-Force ID: 126863.

  • CVE-2016-5976MedSep 26, 2016
    risk 0.32cvss 4.9epss 0.01

    The web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108_9.0.1A FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A before 9.0.2.5224_9.0.2A FP3 allows remote authenticated users…

  • CVE-2016-5440MedJul 21, 2016
    risk 0.32cvss 4.9epss 0.04

    Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and earlier and MariaDB before 5.5.50, 10.0.x before 10.0.26, and 10.1.x before 10.1.15 allows remote administrators to affect availability via vectors related to Server: RBR.

  • CVE-2016-0225MedFeb 29, 2016
    risk 0.32cvss 4.9epss 0.01

    IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.9 allows remote authenticated Commerce Accelerator administrators to obtain sensitive information via unspecified vectors.

  • CVE-2026-17424MedAug 20, 2026
    risk 0.31cvss 4.8epss 0.00

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to bypass security restrictions due to improper limitation of a pathname to a restricted directory.

  • CVE-2026-17009MedAug 20, 2026
    risk 0.31cvss 4.7epss 0.00

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to a NULL pointer dereference.

  • CVE-2026-16866MedAug 19, 2026
    risk 0.31cvss 4.8epss 0.00

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an out-of-bounds read.

  • CVE-2026-17476MedAug 13, 2026
    risk 0.31cvss 4.8epss 0.00

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an improper buffer write.

  • CVE-2026-13477MedAug 5, 2026
    risk 0.31cvss 4.7epss 0.00

    IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privileged user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input.

  • CVE-2026-4410MedMay 27, 2026
    risk 0.31cvss 4.8epss 0.01

    IBM WebSphere Application Server - Liberty 19.0.0.7 through 26.0.0.5 and IBM WebSphere Application Server 9.0, and 8.5 and WebSphere Application Server Liberty are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit…

  • CVE-2026-4919MedApr 23, 2026
    risk 0.31cvss 4.8epss 0.00

    IBM Guardium Data Protection 12.1 is vulnerable to cross-site scripting. This vulnerability allows an administrative user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted…

  • CVE-2026-1726MedApr 23, 2026
    risk 0.31cvss 4.8epss 0.00

    IBM Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2, 4.2.1, 5.0, and 5.1 enables privilege escalation, allowing unauthorized users to perform administrative operations after being demoted. Attackers could access sensitive data, modify system configurations, or change…

  • CVE-2025-66486MedApr 1, 2026
    risk 0.31cvss 4.8epss 0.00

    IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.

  • CVE-2026-2485MedMar 25, 2026
    risk 0.31cvss 4.8epss 0.00

    IBM Infosphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials…

  • CVE-2025-14923MedMar 3, 2026
    risk 0.31cvss 4.7epss 0.00

    IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.2 IBM WebSphere Application Server Liberty could provide weaker than expected security when using the Security Utility when administering security settings.

  • CVE-2025-36059MedJan 20, 2026
    risk 0.31cvss 4.7epss 0.00

    IBM Business Automation Workflow containers 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 Interim Fix 006. IBM Cloud Pak for Business Automation could allow a local user with access to the container to execute OS system…

  • CVE-2025-36093MedNov 3, 2025
    risk 0.31cvss 4.8epss 0.00

    IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an attacker to access unauthorized content or perform unauthorized actions using man in the middle techniques due to improper access controls.

  • CVE-2025-36143MedSep 18, 2025
    risk 0.31cvss 4.7epss 0.00

    IBM Lakehouse (watsonx.data 2.2) could allow an authenticated privileged user to execute arbitrary commands on the system due to improper validation of user supplied input.

  • CVE-2025-2694MedSep 4, 2025
    risk 0.31cvss 4.8epss 0.00

    IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 through 6.2.0.4 and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 through 6.2.0.4 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript…

Page 100 of 177