VYPR

Vendor CVEs

IBM

All CVEs

8,825 total · sorted by risk
  • CVE-2016-3004MedNov 30, 2016
    risk 0.30cvss 4.6epss 0.01

    Cross-site request forgery (CSRF) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to hijack the authentication of arbitrary users for requests that modify the set of available applications.

  • CVE-2015-2808LowApr 1, 2015
    risk 0.30cvss 3.7epss 0.74

    The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial bytes of a stream by sniffing…

  • CVE-2026-18822MedAug 20, 2026
    risk 0.29cvss 4.4epss 0.00

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to uncontrolled resource consumption when parsing directory records.

  • CVE-2026-16897MedAug 19, 2026
    risk 0.29cvss 4.4epss 0.00

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to an out-of-bounds write.

  • CVE-2026-16724MedAug 19, 2026
    risk 0.29cvss 4.5epss 0.00

    IBM Virtualization Management Interface FW1110.00 through FW1110.30, FW1120.00 through FW1120.00, and FW1060.00 through FW1060.80 is affected by a vulnerability in the Virtualization Management Interface (VMI). An attacker with authenticated administrator-level access can cause…

  • CVE-2026-18086MedAug 13, 2026
    risk 0.29cvss 4.5epss 0.00

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary code or cause a denial of service due to improper bounds checking.

  • CVE-2026-17438MedAug 13, 2026
    risk 0.29cvss 4.4epss 0.00

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to obtain sensitive information or modify data due to improper privilege management.

  • CVE-2026-5516MedMay 27, 2026
    risk 0.29cvss 4.4epss 0.00

    IBM WebSphere Application Server - Liberty 22.0.0.11 through 26.0.0.5 IBM WebSphere Application Server Liberty could allow a remote attacker to bypass security under limited conditions by exploiting a specific timing window.

  • CVE-2025-36187MedMar 25, 2026
    risk 0.29cvss 4.4epss 0.00

    IBM Knowledge Catalog Standard Cartridge 5.0.0, 5.0.1, 5.0.2, 5.0.3, 5.1, 5.1.1, 5,1.2, 5.1.3, 5.2.0, 5.2.1 stores potentially sensitive information in log files that could be read by a local privileged user.

  • CVE-2025-36105MedMar 10, 2026
    risk 0.29cvss 4.4epss 0.00

    IBM Planning Analytics Advanced Certified Containers 3.1.0 through 3.1.4 could allow a local privileged user to obtain sensitive information from environment variables.

  • CVE-2025-13333MedFeb 17, 2026
    risk 0.29cvss 4.4epss 0.00

    IBM WebSphere Application Server 9.0, and 8.5 could provide weaker than expected security during system administration of security settings.

  • CVE-2025-33116MedSep 25, 2025
    risk 0.29cvss 4.4epss 0.00

    IBM Watson Studio 4.0 through 5.2.0 on Cloud Pak for Data is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials…

  • CVE-2025-36000MedAug 12, 2025
    risk 0.29cvss 4.4epss 0.00

    IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.8 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to…

  • CVE-2024-38335MedJul 22, 2025
    risk 0.29cvss 4.5epss 0.00

    IBM Security QRadar Network Threat Analytics 1.0.0 through 1.3.1 could allow a privileged user to cause a denial of service due to improper allocation of resources.

  • CVE-2025-33104MedMay 14, 2025
    risk 0.29cvss 4.4epss 0.00

    IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

  • CVE-2024-7577MedMar 29, 2025
    risk 0.29cvss 4.4epss 0.00

    IBM InfoSphere Information Server 11.7 could disclose sensitive user credentials from log files during new installation of the product.

  • CVE-2025-0986MedMar 28, 2025
    risk 0.29cvss 4.5epss 0.00

    IBM PowerVM Hypervisor FW1050.00 through FW1050.30 and FW1060.00 through FW1060.20 could allow a local user, under certain Linux processor combability mode configurations, to cause undetected data loss or errors when performing gzip compression using HW acceleration.

  • CVE-2023-37412MedJan 29, 2025
    risk 0.29cvss 4.4epss 0.00

    IBM Aspera Faspex 5.0.0 through 5.0.10 could allow a privileged user to make system changes without proper access controls.

  • CVE-2023-33838MedJan 29, 2025
    risk 0.29cvss 4.4epss 0.00

    IBM Security Verify Governance 10.0.2 Identity Manager uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the product does not also use a salt as part of the input.

  • CVE-2024-51457MedJan 22, 2025
    risk 0.29cvss 4.4epss 0.00

    IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.19 and 23.0.0 through 23.0.19 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality…

  • CVE-2024-49338MedJan 18, 2025
    risk 0.29cvss 4.4epss 0.00

    IBM App Connect Enterprise 12.0.1.0 through 12.0.7.0and 13.0.1.0 under certain configurations could allow a privileged user to obtain JMS credentials.

  • CVE-2023-50956MedDec 18, 2024
    risk 0.29cvss 4.4epss 0.00

    IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9 could allow a privileged user to obtain highly sensitive user credentials from secret keys that are stored in clear text.

  • CVE-2024-49817MedDec 17, 2024
    risk 0.29cvss 4.4epss 0.00

    IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 stores user credentials in configuration files which can be read by a local privileged user.

  • CVE-2024-35117MedDec 11, 2024
    risk 0.29cvss 4.4epss 0.00

    IBM OpenPages with Watson 9.0 may write sensitive information, under specific configurations, in clear text to the system tracing log files that could be obtained by a privileged user.

  • CVE-2023-46175MedSep 26, 2024
    risk 0.29cvss 4.4epss 0.00

    IBM Cloud Pak for Multicloud Management 2.3 through 2.3 FP8 stores user credentials in a log file plain clear text which can be read by a privileged user.

  • CVE-2024-25052MedJun 13, 2024
    risk 0.29cvss 4.4epss 0.00

    IBM Jazz Reporting Service 7.0.3 stores user credentials in plain clear text which can be read by an admin user. IBM X-Force ID: 283363.

  • CVE-2023-47717MedMay 16, 2024
    risk 0.29cvss 4.4epss 0.00

    IBM Security Guardium 12.0 could allow a privileged user to perform unauthorized actions that could lead to a denial of service. IBM X-Force ID: 271690.

  • CVE-2024-28775MedMay 1, 2024
    risk 0.29cvss 4.4epss 0.00

    IBM WebSphere Automation 1.7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force…

  • CVE-2024-22334MedApr 12, 2024
    risk 0.29cvss 4.4epss 0.00

    IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4 and IBM DevOps Deploy 8.0 through 8.0.0.1 could be vulnerable to incomplete revocation of permissions when deleting a custom security resource type. When deleting a…

  • CVE-2022-32753MedMar 22, 2024
    risk 0.29cvss 4.5epss 0.00

    IBM Security Verify Directory 10.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 228444.

  • CVE-2024-27265MedMar 14, 2024
    risk 0.29cvss 4.5epss 0.00

    IBM Integration Bus for z/OS 10.1 through 10.1.0.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 284564.

  • CVE-2023-27291MedMar 3, 2024
    risk 0.29cvss 4.5epss 0.00

    IBM Watson CP4D Data Stores 4.6.0, 4.6.1, 4.6.2, and 4.6.3 does not encrypt sensitive or critical information before storage or transmission which could allow an attacker to obtain sensitive information. IBM X-Force ID: 248740.

  • CVE-2022-43880MedMar 3, 2024
    risk 0.29cvss 4.4epss 0.00

    IBM QRadar WinCollect Agent 10.0 through 10.1.2 could allow a privileged user to cause a denial of service. IBM X-Force ID: 240151.

  • CVE-2024-22312MedFeb 10, 2024
    risk 0.29cvss 4.4epss 0.00

    IBM Storage Defender - Resiliency Service 2.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 278748.

  • CVE-2024-0935MedFeb 1, 2024
    risk 0.29cvss 4.4epss 0.00

    Insertion of Sensitive Information into Log File vulnerabilities are affecting DELMIA Apriso Release 2019 through Release 2024

  • CVE-2023-40682MedOct 13, 2023
    risk 0.29cvss 4.4epss 0.00

    IBM App Connect Enterprise 12.0.1.0 through 12.0.8.0 contains an unspecified vulnerability that could allow a local privileged user to obtain sensitive information from API logs. IBM X-Force ID: 263833.

  • CVE-2023-40368MedSep 20, 2023
    risk 0.29cvss 4.4epss 0.00

    IBM Storage Protect 8.1.0.0 through 8.1.19.0 could allow a privileged user to obtain sensitive information from the administrative command line client. IBM X-Force ID: 263456.

  • CVE-2022-22307MedJun 15, 2023
    risk 0.29cvss 4.4epss 0.00

    IBM Security Guardium 11.3, 11.4, and 11.5 could allow a local user to obtain elevated privileges due to incorrect authorization checks. IBM X-Force ID: 216753.

  • CVE-2023-27863MedMay 12, 2023
    risk 0.29cvss 4.4epss 0.01

    IBM Spectrum Protect Plus Server 10.1.13, under specific configurations, could allow an elevated user to obtain SMB credentials that may be used to access vSnap data stores. IBM X-Force ID: 249325.

  • CVE-2022-22313MedMay 6, 2023
    risk 0.29cvss 4.4epss 0.00

    IBM QRadar Data Synchronization App 1.0 through 3.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 217370.

  • CVE-2023-26268MedMay 2, 2023
    risk 0.29cvss 4.4epss 0.01

    Design documents with matching document IDs, from databases on the same cluster, may share a mutable Javascript environment when using these design document functions: * validate_doc_update * list * filter * filter views (using view functions as filters) * …

  • CVE-2022-39166MedDec 20, 2022
    risk 0.29cvss 4.4epss 0.01

    IBM Security Guardium 11.4 could allow a privileged user to obtain sensitive information inside of an HTTP response. IBM X-Force ID: 235405.

  • CVE-2022-41299MedDec 9, 2022
    risk 0.29cvss 4.4epss 0.00

    IBM Cloud Transformation Advisor 2.0.1 through 3.3.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted…

  • CVE-2021-39077MedNov 3, 2022
    risk 0.29cvss 4.4epss 0.00

    IBM Security Guardium 10.5, 10.6, 11.0, 11.1, 11.2, 11.3, and 11.4 stores user credentials in plain clear text which can be read by a local privileged user. IBM X-Force ID: 215587.

  • CVE-2022-22366MedJul 1, 2022
    risk 0.29cvss 4.4epss 0.00

    IBM UrbanCode Deploy (UCD) 6.2.7.15, 7.0.5.10, 7.1.2.6, and 7.2.2.1 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 22106.

  • CVE-2022-30610MedJun 10, 2022
    risk 0.29cvss 4.5epss 0.01

    IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.15.0 is vulnerable to reverse tabnabbing where it could allow a page linked to from within IBM Spectrum Copy Data Management to rewrite it. An administrator could enter a link to a malicious URL that another administrator…

  • CVE-2021-39078MedApr 19, 2022
    risk 0.29cvss 4.4epss 0.00

    IBM Security Guardium 10.5 stores user credentials in plain clear text which can be read by a local privileged user. IBM X-Force ID: 215589.

  • CVE-2021-38955MedMar 1, 2022
    risk 0.29cvss 4.4epss 0.00

    IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a local user with elevated privileges to cause a denial of service due to a file creation vulnerability in the audit commands. IBM X-Force ID: 211825.

  • CVE-2021-38882MedNov 16, 2021
    risk 0.29cvss 4.4epss 0.00

    IBM Spectrum Scale 5.1.0 through 5.1.1.1 could allow a privileged admin to destroy filesystem audit logging records before expiration time. IBM X-Force ID: 209164.

  • CVE-2021-20434MedSep 23, 2021
    risk 0.29cvss 4.4epss 0.00

    IBM Security Verify Bridge 1.0.5.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 196346.

Page 103 of 177