VYPR

Vendor CVEs

IBM

All CVEs

8,825 total · sorted by risk
  • CVE-2024-40702HigJan 7, 2025
    risk 0.53cvss 8.2epss 0.00

    IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow an unauthorized user to obtain valid tokens to gain access to protected resources due to improper certificate validation.

  • CVE-2024-39726HigNov 15, 2024
    risk 0.53cvss 8.2epss 0.01

    IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.

  • CVE-2024-39747HigAug 31, 2024
    risk 0.53cvss 8.1epss 0.01

    IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 uses default credentials for potentially critical functionality.

  • CVE-2024-39742HigJul 8, 2024
    risk 0.53cvss 8.1epss 0.01

    IBM MQ Operator 3.2.2 and IBM MQ Operator 2.0.24 could allow a user to bypass authentication under certain configurations due to a partial string comparison vulnerability. IBM X-Force ID: 297169.

  • CVE-2023-45192HigJun 6, 2024
    risk 0.53cvss 8.2epss 0.01

    IBM Engineering Requirements Management DOORS Next 7.0.2 and 7.0.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM…

  • CVE-2024-27273HigMay 7, 2024
    risk 0.53cvss 8.1epss 0.00

    IBM AIX's Unix domain (AIX 7.2, 7.3, VIOS 3.1, and VIOS 4.1) datagram socket implementation could potentially expose applications using Unix domain datagram sockets with SO_PEERID operation and may lead to privilege escalation. IBM X-Force ID: 284903.

  • CVE-2024-27266HigMar 14, 2024
    risk 0.53cvss 8.2epss 0.01

    IBM Maximo Application Suite 7.6.1.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 284566.

  • CVE-2023-43017HigFeb 7, 2024
    risk 0.53cvss 8.2epss 0.01

    IBM Security Verify Access 10.0.0.0 through 10.0.6.1 could allow a privileged user to install a configuration file that could allow remote access. IBM X-Force ID: 266155.

  • CVE-2023-38019HigFeb 2, 2024
    risk 0.53cvss 8.1epss 0.01

    IBM SOAR QRadar Plugin App 1.0 through 5.0.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 260575.

  • CVE-2023-40363HigNov 18, 2023
    risk 0.53cvss 8.1epss 0.01

    IBM InfoSphere Information Server 11.7 could allow an authenticated user to change installation files due to incorrect file permission settings. IBM X-Force ID: 263332.

  • CVE-2022-40609HigAug 2, 2023
    risk 0.53cvss 8.1epss 0.02

    IBM SDK, Java Technology Edition 7.1.5.18 and 8.0.8.0 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization flaw. By sending specially-crafted data, an attacker could exploit this vulnerability to execute arbitrary code on the…

  • CVE-2023-26278HigMay 31, 2023
    risk 0.53cvss 8.2epss 0.00

    IBM QRadar WinCollect Agent 10.0 through 10.1.3 could allow a local authenticated attacker to gain elevated privileges on the system. IBM X-Force ID: 248158.

  • CVE-2023-23477HigFeb 3, 2023
    risk 0.53cvss 8.1epss 0.02

    IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially crafted sequence of serialized objects. IBM X-Force ID: 245513.

  • CVE-2022-40616HigSep 21, 2022
    risk 0.53cvss 8.1epss 0.01

    IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, and 7.6.1.3 could allow a user to bypass authentication and obtain sensitive information or perform tasks they should not have access to. IBM X-Force ID: 236311.

  • CVE-2022-36773HigSep 1, 2022
    risk 0.53cvss 8.1epss 0.02

    IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 233571.

  • CVE-2021-38941HigJun 30, 2022
    risk 0.53cvss 8.1epss 0.01

    IBM CloudPak for Multicloud Monitoring 2.0 and 2.3 has a few containers running in privileged mode which is vulnerable to host information leakage or destruction if unauthorized access to these containers could execute arbitrary commands. IBM X-Force ID: 211048.

  • CVE-2020-4876HigJan 21, 2022
    risk 0.53cvss 8.2epss 0.02

    IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 190839.

  • CVE-2020-4875HigJan 21, 2022
    risk 0.53cvss 8.2epss 0.02

    IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 190838.

  • CVE-2021-39057HigDec 13, 2021
    risk 0.53cvss 8.1epss 0.00

    IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force…

  • CVE-2021-29873HigOct 21, 2021
    risk 0.53cvss 8.1epss 0.02

    IBM Flash System 900 could allow an authenticated attacker to obtain sensitive information and cause a denial of service due to a restricted shell escape vulnerability. IBM X-Force ID: 206229.

  • CVE-2021-29831HigSep 21, 2021
    risk 0.53cvss 8.1epss 0.01

    IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.…

  • CVE-2020-4945HigJun 24, 2021
    risk 0.53cvss 8.1epss 0.01

    IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated user to overwrite arbirary files due to improper group permissions. IBM X-Force ID: 191945.

  • CVE-2021-20492HigMay 26, 2021
    risk 0.53cvss 8.2epss 0.02

    IBM WebSphere Application Server 8.0, 8.5, 9.0, and Liberty Java Batch is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM…

  • CVE-2020-5013HigMay 5, 2021
    risk 0.53cvss 8.1epss 0.01

    IBM QRadar SIEM 7.3 and 7.4 may vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 193245.

  • CVE-2021-20501HigApr 21, 2021
    risk 0.53cvss 8.2epss 0.01

    IBM i 7.1, 7.2, 7.3, and 7.4 SMTP allows a network attacker to send emails to non-existent local-domain recipients to the SMTP server, caused by using a non-default configuration. An attacker could exploit this vulnerability to consume unnecessary network bandwidth and disk…

  • CVE-2021-20411HigFeb 12, 2021
    risk 0.53cvss 8.1epss 0.00

    IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a user to impersonate another user on the system due to incorrectly updating the session identifier. IBM X-Force ID: 198191.

  • CVE-2020-4795HigFeb 9, 2021
    risk 0.53cvss 8.2epss 0.02

    IBM Security Identity Governance and Intelligence 5.2.6 could disclose sensitive information to an unauthorized user using a specially crafted HTTP request. IBM X-Force ID: 189446.

  • CVE-2019-4702HigJan 13, 2021
    risk 0.53cvss 8.1epss 0.00

    IBM Security Guardium Data Encryption (GDE) 3.0.0.2 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

  • CVE-2020-4388HigOct 12, 2020
    risk 0.53cvss 8.2epss 0.01

    IBM Cognos Analytics 11.0 and 11.1 could be vulnerable to a denial of service attack by failing to catch exceptions in a servlet also exposing debug information could also be used in future attacks. IBM X-Force ID: 179270.

  • CVE-2020-4779HigOct 12, 2020
    risk 0.53cvss 8.1epss 0.01

    A HTTP Verb Tampering vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10. By sending a specially-crafted request, an attacker could exploit this vulnerability to bypass security access controls. IBM X-Force ID: 189156.

  • CVE-2020-4772HigOct 12, 2020
    risk 0.53cvss 8.1epss 0.01

    An XML External Entity Injection (XXE) vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10. A remote attacker could exploit this vulnerability to expose sensitive information, denial of service, server side request forgery or consume memory resources.…

  • CVE-2020-4617HigSep 22, 2020
    risk 0.53cvss 8.1epss 0.01

    IBM Data Risk Manager (iDNA) 2.0.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 184930.

  • CVE-2020-4409HigSep 16, 2020
    risk 0.53cvss 8.2epss 0.01

    IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote attacker to conduct phishing attacks, using a tabnabbing attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to redirect a user to a malicious…

  • CVE-2020-4686HigAug 17, 2020
    risk 0.53cvss 8.1epss 0.02

    IBM Spectrum Virtualize 8.3.1 could allow a remote user authenticated via LDAP to escalate their privileges and perform actions they should not have access to. IBM X-Force ID: 186678.

  • CVE-2020-4486HigAug 11, 2020
    risk 0.53cvss 8.1epss 0.02

    IBM QRadar 7.2.0 thorugh 7.2.9 could allow an authenticated user to overwrite or delete arbitrary files due to a flaw after WinCollect installation. IBM X-Force ID: 181861.

  • CVE-2020-4481HigAug 5, 2020
    risk 0.53cvss 8.2epss 0.02

    IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force…

  • CVE-2020-4125HigJul 20, 2020
    risk 0.53cvss 8.1epss 0.00

    Using HCL Marketing Operations 9.1.2.4, 10.1.x, 11.1.0.x, a malicious attacker could download files from the RHEL environment by doing some modification in the link, giving the attacker access to confidential information.

  • CVE-2015-0102HigFeb 5, 2020
    risk 0.53cvss 8.1epss 0.02

    IBM Workflow for Bluemix does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

  • CVE-2013-0507HigFeb 5, 2020
    risk 0.53cvss 8.1epss 0.01

    IBM InfoSphere Information Server 8.1, 8.5, 8.7, 9.1 has a Session Fixation Vulnerability

  • CVE-2019-4538HigOct 2, 2019
    risk 0.53cvss 8.2epss 0.01

    IBM Security Directory Server 6.4.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a…

  • CVE-2019-4424HigAug 20, 2019
    risk 0.53cvss 8.2epss 0.02

    IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, and 19.0.0.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory…

  • CVE-2019-4340HigAug 20, 2019
    risk 0.53cvss 8.2epss 0.02

    IBM Security Guardium Big Data Intelligence 4.0 (SonarG) is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID:…

  • CVE-2019-4419HigAug 20, 2019
    risk 0.53cvss 8.2epss 0.02

    IBM Intelligent Operations Center V5.1.0 through V5.2.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 162737.

  • CVE-2018-2024HigJul 22, 2019
    risk 0.53cvss 8.1epss 0.01

    IBM QRadar SIEM 7.2 and 7.3 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. IBM X-Force ID: 155350.

  • CVE-2019-4210HigApr 8, 2019
    risk 0.53cvss 8.1epss 0.02

    IBM QRadar SIEM 7.3.2 could allow a user to bypass authentication exposing certain functionality which could lead to information disclosure or modification of application configuration. IBM X-Force ID: 158986.

  • CVE-2018-1904HigDec 11, 2018
    risk 0.53cvss 8.1epss 0.04

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbitrary Java code through an administrative client class with a serialized object from untrusted sources. IBM X-Force ID: 152533.

  • CVE-2018-1756HigSep 7, 2018
    risk 0.53cvss 7.5epss 0.11

    IBM Security Identity Governance and Intelligence 5.2.3.2 and 5.2.4 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, information in the back-end database. IBM X-Force ID: 148599.

  • CVE-2013-3023HigMay 24, 2018
    risk 0.53cvss 8.1epss 0.02

    IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.1.2 and 7.2.0 through 7.2.1.4 might allow remote attackers to obtain sensitive information about Tomcat credentials by sniffing the network for a session in which HTTP is used. IBM X-Force ID: 84361.

  • CVE-2014-0927HigApr 20, 2018
    risk 0.53cvss 8.1epss 0.02

    The ActiveMQ admin user interface in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allows remote attackers to bypass authentication by leveraging knowledge of the port number and webapp path. IBM X-Force ID: 92259.

  • CVE-2016-0235HigMar 12, 2018
    risk 0.53cvss 8.2epss 0.00

    IBM Security Guardium Database Activity Monitor 10 allows local users to have unspecified impact by leveraging administrator access to a hardcoded password, related to use on GRUB systems. IBM X-Force ID: 110326.

Page 17 of 177