VYPR

Vendor CVEs

IBM

All CVEs

8,825 total · sorted by risk
  • CVE-2025-66487LowApr 1, 2026
    risk 0.18cvss 2.7epss 0.00

    IBM Aspera Shares 1.9.9 through 1.11.0 does not properly rate limit the frequency that an authenticated user can send emails, which could result in email flooding or a denial of service.

  • CVE-2025-13459LowMar 16, 2026
    risk 0.18cvss 2.7epss 0.00

    IBM Aspera Console 3.3.0 through 3.4.8 could allow a privileged user to cause a denial of service due to improper enforcement of behavioral workflow.

  • CVE-2025-36194LowFeb 2, 2026
    risk 0.18cvss 2.8epss 0.00

    IBM PowerVM Hypervisor FW1110.00 through FW1110.03, FW1060.00 through FW1060.51, and FW950.00 through FW950.F0 may expose a limited amount of data to a peer partition in specific shared processor configurations during certain operations.

  • CVE-2024-56464LowDec 9, 2025
    risk 0.18cvss 2.7epss 0.00

    IBM QRadar SIEM 7.5 - 7.5.0 UP14 IF01 is affected by an information disclosure vulnerability involving exposure of directory information. IBM has addressed this vulnerability in the latest update.

  • CVE-2025-36102LowDec 8, 2025
    risk 0.18cvss 2.7epss 0.00

    IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 could allow a privileged user to bypass validation, passing user input into the application as trusted data, due to client-side enforcement of server-side security.

  • CVE-2025-2667LowSep 4, 2025
    risk 0.18cvss 2.7epss 0.00

    IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 through 6.2.0.4 and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 through 6.2.0.4 could disclose sensitive system information about the server to a privileged user that could aid in further…

  • CVE-2025-2988LowAug 19, 2025
    risk 0.18cvss 2.7epss 0.00

    IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7, 6.2.0.0 through 6.2.0.4, and 6.2.1.0 could disclose sensitive server information to an unauthorized user that could aid in further attacks against the system.

  • CVE-2024-55895LowMar 29, 2025
    risk 0.18cvss 2.7epss 0.00

    IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.

  • CVE-2024-52905LowMar 10, 2025
    risk 0.18cvss 2.7epss 0.00

    IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 could disclose sensitive database information to a privileged user.

  • CVE-2024-45658LowFeb 4, 2025
    risk 0.18cvss 2.7epss 0.00

    IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.

  • CVE-2024-35122LowJan 24, 2025
    risk 0.18cvss 2.8epss 0.00

    IBM i 7.2, 7.3, 7.4, and 7.5 is vulnerable to a file level local denial of service caused by an insufficient authority requirement. A local non-privileged user can configure a referential constraint with the privileges of a user socially engineered to access the target file.

  • CVE-2023-47711LowMay 14, 2024
    risk 0.18cvss 2.7epss 0.01

    IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow an authenticated user to upload files that would cause a denial of service. IBM X-Force ID: 271526.

  • CVE-2022-32756LowMar 22, 2024
    risk 0.18cvss 2.7epss 0.01

    IBM Security Verify Directory 10.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 228507.

  • CVE-2021-39008LowNov 23, 2023
    risk 0.18cvss 2.7epss 0.01

    IBM QRadar WinCollect Agent 10.0 through 10.1.7 could allow a privileged user to obtain sensitive information due to missing best practices. IBM X-Force ID: 213551.

  • CVE-2022-43891LowOct 17, 2023
    risk 0.18cvss 2.7epss 0.01

    IBM Security Verify Privilege On-Premises 11.5 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 240454.

  • CVE-2022-43893LowOct 17, 2023
    risk 0.18cvss 2.7epss 0.00

    IBM Security Verify Privilege On-Premises 11.5 could allow a privileged user to cause by using a malicious payload. IBM X-Force ID: 240634.

  • CVE-2023-35901LowJul 17, 2023
    risk 0.18cvss 2.7epss 0.00

    IBM Robotic Process Automation 21.0.0 through 21.0.7.6 and 23.0.0 through 23.0.6 is vulnerable to client side validation bypass which could allow invalid changes or values in some fields. IBM X-Force ID: 259380.

  • CVE-2023-25923LowMar 21, 2023
    risk 0.18cvss 2.7epss 0.01

    IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an attacker to upload files that could be used in a denial of service attack due to incorrect authorization. IBM X-Force ID: 247629.

  • CVE-2023-25689LowMar 21, 2023
    risk 0.18cvss 2.7epss 0.01

    IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1 , and 4.1.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. …

  • CVE-2021-29846LowJan 26, 2022
    risk 0.18cvss 2.7epss 0.01

    IBM Security Guardium Insights 3.0 could allow an authenticated user to obtain sensitive information due to insufficient session expiration. IBM X-Force ID: 205256.

  • CVE-2021-38894LowJan 10, 2022
    risk 0.18cvss 2.7epss 0.01

    IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 209515.

  • CVE-2021-38973LowNov 12, 2021
    risk 0.18cvss 2.7epss 0.01

    IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

  • CVE-2021-20377LowSep 23, 2021
    risk 0.18cvss 2.7epss 0.01

    IBM Security Guardium 11.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 195569.

  • CVE-2021-20523LowJul 15, 2021
    risk 0.18cvss 2.7epss 0.01

    IBM Security Verify Access Docker 10.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 198660

  • CVE-2021-20499LowJul 15, 2021
    risk 0.18cvss 2.7epss 0.01

    IBM Security Verify Access Docker 10.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 197973

  • CVE-2021-20402LowFeb 11, 2021
    risk 0.18cvss 2.7epss 0.01

    IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 196076.

  • CVE-2020-4846LowDec 17, 2020
    risk 0.18cvss 2.7epss 0.01

    IBM Security Key Lifecycle Manager 3.0.1 and 4.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 190290.

  • CVE-2019-4699LowAug 26, 2020
    risk 0.18cvss 2.7epss 0.01

    IBM Security Guardium Data Encryption (GDE) 3.0.0.2 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 171931.

  • CVE-2020-4548LowAug 20, 2020
    risk 0.18cvss 2.7epss 0.01

    IBM Content Navigator 3.0.7 and 3.0.8 is vulnerable to improper input validation. A malicious administrator could bypass the user interface and send requests to the IBM Content Navigator server with illegal characters that could be stored in the IBM Content Navigator database.…

  • CVE-2019-4706LowJul 1, 2020
    risk 0.18cvss 2.7epss 0.01

    IBM Security Identity Manager Virtual Appliance 7.0.2 writes information to log files which can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information. IBM X-Force ID: 172016.

  • CVE-2019-4705LowJul 1, 2020
    risk 0.18cvss 2.7epss 0.01

    IBM Security Identity Manager Virtual Appliance 7.0.2 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 172015.

  • CVE-2020-4248LowMay 28, 2020
    risk 0.18cvss 2.7epss 0.01

    IBM Security Identity Governance and Intelligence 5.2.6 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 175484.

  • CVE-2020-4164LowApr 8, 2020
    risk 0.18cvss 2.7epss 0.01

    IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, and 1.0.5 could expose sensitive information from applicatino errors which could be used in further attacks against the system. IBM X-Force ID: 174400.

  • CVE-2019-4636LowJan 28, 2020
    risk 0.18cvss 2.7epss 0.01

    IBM Security Secret Server 10.7 could disclose sensitive information to an authenticated user from generated error messages. IBM X-Force ID: 170013.

  • CVE-2019-4635LowJan 28, 2020
    risk 0.18cvss 2.7epss 0.01

    IBM Security Secret Server 10.7 could allow a privileged user to perform unauthorized command injection due to imporoper input neutralization of special elements. IBM X-Force ID: 170011.

  • CVE-2018-1991LowMay 22, 2019
    risk 0.18cvss 2.7epss 0.01

    IBM API Connect 5.0.0.0, and 5.0.8.6 could could return sensitive information that could provide critical information as to the underlying software stack in CMC UI headers. IBM X-Force ID: 154284.

  • CVE-2018-1380LowOct 29, 2018
    risk 0.18cvss 2.7epss 0.01

    IBM InfoSphere Master Data Management Collaboration Server 11.4, 11.5, and 11.6 could allow an authenticated user with CA level access to change change their ca-id to another users and read sensitive information. IBM X-Force ID: 138077.

  • CVE-2016-0369LowFeb 21, 2018
    risk 0.18cvss 2.7epss 0.01

    XML external entity (XXE) vulnerability in IBM Forms Experience Builder 8.5, 8.5.1, and 8.6 allows remote authenticated users to obtain sensitive information via crafted XML data. IBM X-Force ID: 112088.

  • CVE-2016-5979LowMay 15, 2017
    risk 0.18cvss 2.7epss 0.01

    IBM Distributed Marketing 8.6, 9.0, and 10.0 could allow a privileged authenticated user to create an instance that gets created with security profile not valid for the templates, that results in the new instance not accessible for the intended user. IBM X-Force ID: 116379.

  • CVE-2015-7494LowFeb 8, 2017
    risk 0.18cvss 2.8epss 0.00

    A vulnerability has been identified in IBM Cloud Orchestrator services/[action]/launch API. An authenticated domain admin user might modify cross domain resources via a /services/[action]/launch API call, provided it would have been possible for the domain admin user to gain…

  • CVE-2016-3046LowFeb 1, 2017
    risk 0.18cvss 2.7epss 0.01

    IBM Security Access Manager for Web is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements which could allow the attacker to view information in the back-end database.

  • CVE-2016-3021LowFeb 1, 2017
    risk 0.18cvss 2.7epss 0.01

    IBM Security Access Manager for Web could allow an authenticated attacker to obtain sensitive information from error message using a specially crafted HTTP request.

  • CVE-2016-2947LowNov 25, 2016
    risk 0.18cvss 2.7epss 0.01

    IBM Rational Collaborative Lifecycle Management 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Team Concert 4.0 before 4.0.7 iFix11, 5.0…

  • CVE-2016-0370LowSep 1, 2016
    risk 0.18cvss 2.7epss 0.01

    Cross-site scripting (XSS) vulnerability in IBM Forms Experience Builder 8.5.x and 8.6.x before 8.6.3 allows remote authenticated users to inject arbitrary web script or HTML via crafted input to an application that was built with this product.

  • CVE-2016-2870LowJul 2, 2016
    risk 0.18cvss 2.7epss 0.02

    Buffer overflow in the CLI on IBM WebSphere DataPower XC10 appliances 2.1 and 2.5 allows remote authenticated users to cause a denial of service via unspecified vectors.

  • CVE-2016-2868LowJul 2, 2016
    risk 0.18cvss 2.7epss 0.01

    IBM Security QRadar SIEM 7.2.x before 7.2.7 allows remote authenticated administrators to read arbitrary files via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

  • CVE-2023-46159LowFeb 2, 2024
    risk 0.17cvss 2.6epss 0.01

    IBM Storage Ceph 5.3z1, 5.3z5, and 6.1z1 could allow an authenticated user on the network to cause a denial of service from RGW. IBM X-Force ID: 268906.

  • CVE-2015-4961LowNov 24, 2016
    risk 0.17cvss 2.6epss 0.00

    IBM Tealeaf Customer Experience 8.x before 8.7.1.8847 FP10, 8.8.x before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108 FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A before 9.0.2.5224 FP3 does not encrypt connections between internal servers,…

  • CVE-2025-0895LowMar 2, 2025
    risk 0.16cvss 2.4epss 0.00

    IBM Cognos Analytics Mobile 1.1 for Android could allow a user with physical access to the device, to obtain sensitive information from debugging code log messages.

  • CVE-2024-28766LowJan 27, 2025
    risk 0.16cvss 2.4epss 0.00

    IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 could disclose sensitive information about directory contents that could aid in further attacks against the system.

Page 121 of 177