VYPR

Vendor CVEs

IBM

All CVEs

8,825 total · sorted by risk
  • CVE-2024-35141HigDec 19, 2024
    risk 0.51cvss 7.8epss 0.00

    IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to execution of unnecessary privileges.

  • CVE-2024-31891HigDec 14, 2024
    risk 0.51cvss 7.8epss 0.00

    IBM Storage Scale GUI 5.1.9.0 through 5.1.9.6 and 5.2.0.0 through 5.2.1.1 contains a local privilege escalation vulnerability. A malicious actor with command line access to the 'scalemgmt' user can elevate privileges to gain root access to the host operating system.

  • CVE-2024-47115HigDec 7, 2024
    risk 0.51cvss 7.8epss 0.00

    IBM AIX 7.2, 7.3 and VIOS 3.1 and 4.1 could allow a local user to execute arbitrary commands on the system due to improper neutralization of input.

  • CVE-2024-49804HigNov 29, 2024
    risk 0.51cvss 7.8epss 0.00

    IBM Security Verify Access Appliance 10.0.0 through 10.0.8 could allow a locally authenticated non-administrative user to escalate their privileges due to unnecessary permissions used to perform certain tasks.

  • CVE-2023-30998HigJun 27, 2024
    risk 0.51cvss 7.8epss 0.00

    IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain root access due to improper access controls. IBM X-Force ID: 254649.

  • CVE-2023-30997HigJun 27, 2024
    risk 0.51cvss 7.8epss 0.00

    IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain root access due to improper access controls. IBM X-Force ID: 254638.

  • CVE-2024-31890HigJun 21, 2024
    risk 0.51cvss 7.8epss 0.00

    IBM i 7.3, 7.4, and 7.5 product IBM TCP/IP Connectivity Utilities for i contains a local privilege escalation vulnerability. A malicious actor with command line access to the host operating system can elevate privileges to gain root access to the host operating system. IBM…

  • CVE-2023-47712HigMay 14, 2024
    risk 0.51cvss 7.8epss 0.00

    IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a local user to gain elevated privileges on the system due to improper permissions control. IBM X-Force ID: 271527.

  • CVE-2023-37400HigApr 19, 2024
    risk 0.51cvss 7.8epss 0.00

    IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to escalate their privileges due to insecure credential storage. IBM X-Force ID: 259677.

  • CVE-2023-26277HigMay 31, 2023
    risk 0.51cvss 7.8epss 0.00

    IBM QRadar WinCollect Agent 10.0 though 10.1.3 could allow a local user to execute commands on the system due to execution with unnecessary privileges. IBM X-Force ID: 248156.

  • CVE-2022-41739HigApr 26, 2023
    risk 0.51cvss 7.9epss 0.00

    IBM Spectrum Scale (IBM Spectrum Scale Container Native Storage Access 5.1.2.1 through 5.1.6.0) could allow programs running inside the container to overcome isolation mechanism and gain additional capabilities or access sensitive information on the host. IBM X-Force ID:…

  • CVE-2022-43867HigDec 6, 2022
    risk 0.51cvss 7.8epss 0.00

    IBM Spectrum Scale 5.1.0.1 through 5.1.4.1 could allow a local attacker to execute arbitrary commands in the container. IBM X-Force ID: 239437.

  • CVE-2022-35717HigNov 3, 2022
    risk 0.51cvss 7.8epss 0.01

    "IBM InfoSphere Information Server 11.7 could allow a locally authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-"Force ID: 231361.

  • CVE-2022-36768HigSep 13, 2022
    risk 0.51cvss 7.8epss 0.00

    IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the invscout command to obtain root privileges. IBM X-Force ID: 232014.

  • CVE-2022-34356HigSep 13, 2022
    risk 0.51cvss 7.8epss 0.00

    IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to obtain root privileges. IBM X-Force ID: 230502.

  • CVE-2021-39088HigJul 28, 2022
    risk 0.51cvss 7.8epss 0.00

    IBM QRadar SIEM 7.3, 7.4, and 7.5 is vulnerable to local privilege escalation if this could be combined with other unknown vulnerabilities then privilege escalation could be performed. IBM X-Force ID: 216111.

  • CVE-2022-22465HigJul 8, 2022
    risk 0.51cvss 7.8epss 0.00

    IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 could allow a local user to obtain elevated privileges due to improper access permissions. IBM X-Force ID: 225082.

  • CVE-2022-22454HigMay 10, 2022
    risk 0.51cvss 7.8epss 0.00

    IBM InfoSphere Information Server 11.7 could allow a locally authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.

  • CVE-2022-22392HigApr 25, 2022
    risk 0.51cvss 7.8epss 0.02

    IBM Planning Analytics Local 2.0 could allow an attacker to upload arbitrary executable files which, when executed by an unsuspecting victim could result in code execution. IBM X-Force ID: 222066.

  • CVE-2022-22308HigFeb 21, 2022
    risk 0.51cvss 7.8epss 0.01

    IBM Planning Analytics 2.0 is vulnerable to a Remote File Include (RFI) attack. User input could be passed into file include commands and the web application could be tricked into including remote files with malicious code. IBM X-Force ID: 216891.

  • CVE-2021-38991HigJan 11, 2022
    risk 0.51cvss 7.8epss 0.00

    IBM AIX 7.0, 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the lscore command which could lead to code execution. IBM X-Force ID: 212953.

  • CVE-2021-38990HigJan 10, 2022
    risk 0.51cvss 7.8epss 0.00

    IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the mount command which could lead to code execution. IBM X-Force ID: 212952.

  • CVE-2021-38950HigDec 14, 2021
    risk 0.51cvss 7.8epss 0.00

    IBM MQ on HPE NonStop 8.0.4 and 8.1.0 is vulnerable to a privilege escalation attack when SharedBindingsUserId is set to effective. IBM X-ForceID: 211404.

  • CVE-2021-39050HigDec 13, 2021
    risk 0.51cvss 7.8epss 0.00

    IBM i2 Analyst's Notebook 9.2.0, 9.2.1, and 9.2.2 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local attacker could overflow a buffer and gain lower level privileges. IBM X-Force ID: 214440.

  • CVE-2021-39049HigDec 13, 2021
    risk 0.51cvss 7.8epss 0.00

    IBM i2 Analyst's Notebook 9.2.0, 9.2.1, and 9.2.2 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local attacker could overflow a buffer and gain lower level privileges. IBM X-Force ID: 214439.

  • CVE-2021-38873HigNov 24, 2021
    risk 0.51cvss 7.8epss 0.02

    IBM Planning Analytics 2.0 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 208396.

  • CVE-2021-29801HigAug 26, 2021
    risk 0.51cvss 7.8epss 0.00

    IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the kernel to gain root privileges. IBM X-Force ID: 203977.

  • CVE-2021-29741HigAug 2, 2021
    risk 0.51cvss 7.8epss 0.00

    IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user to exploit a vulnerability in Korn Shell (ksh) to gain root privileges. IBM X-Force ID: 201478.

  • CVE-2021-29707HigJul 19, 2021
    risk 0.51cvss 7.8epss 0.00

    IBM HMC (Hardware Management Console) V9.1.910.0 and V9.2.950.0 could allow a local user to escalate their privileges to root access on a restricted shell. IBM X-Force ID: 200879.

  • CVE-2020-4610HigJun 25, 2021
    risk 0.51cvss 7.8epss 0.00

    IBM Security Secret Server (IBM Security Verify Privilege Manager 10.8.2 ) could allow a local user to execute code due to improper integrity checks. IBM X-Force ID: 184919.

  • CVE-2020-4609HigJun 25, 2021
    risk 0.51cvss 7.8epss 0.00

    IBM Security Sevret Server (IBM Security Verify Privilege Manager 10.8.2) is vulnerable to a buffer overflow, caused by improper bounds checking. A local attacker could overflow a buffer and execute arbitrary code on the system or cause the system to crash. IBM X-Force ID:…

  • CVE-2021-29740HigJun 1, 2021
    risk 0.51cvss 7.8epss 0.00

    IBM Spectrum Scale 5.0.0 through 5.0.5.6 and 5.1.0 through 5.1.0.3 system core component is affected by a format string security vulnerability. An attacker could execute arbitrary code in the context of process memory, potentially escalating their system privileges and taking…

  • CVE-2021-29665HigJun 1, 2021
    risk 0.51cvss 7.8epss 0.01

    IBM Security Verify Access 20.07 is vulnerable to a stack based buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code on the system with elevated privileges.

  • CVE-2019-4588HigMay 26, 2021
    risk 0.51cvss 7.8epss 0.00

    IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to execute arbitrary code and conduct DLL hijacking attacks.

  • CVE-2021-20389HigMay 24, 2021
    risk 0.51cvss 7.8epss 0.00

    IBM Security Guardium 11.2 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 195770.

  • CVE-2021-20401HigMay 5, 2021
    risk 0.51cvss 7.8epss 0.00

    IBM QRadar SIEM 7.3 and 7.4 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 196075.

  • CVE-2020-4932HigMay 5, 2021
    risk 0.51cvss 7.8epss 0.00

    IBM QRadar SIEM 7.3 and 7.4 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 191748.

  • CVE-2021-29667HigApr 27, 2021
    risk 0.51cvss 7.8epss 0.01

    IBM Spectrum Scale 5.0.0 through 5.0.5.6 and 5.1.0 through 5.1.0.2 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 199403.

  • CVE-2021-29672HigApr 26, 2021
    risk 0.51cvss 7.8epss 0.00

    IBM Spectrum Protect Client 8.1.0.0-8 through 1.11.0 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking when processing the current locale settings. A local attacker could overflow a buffer and execute arbitrary code on the system with elevated…

  • CVE-2021-20532HigApr 26, 2021
    risk 0.51cvss 7.8epss 0.00

    IBM Spectrum Protect Client 8.1.0.0 through 8.1.11.0 could allow a local user to escalate their privileges to take full control of the system due to insecure directory permissions. IBM X-Force ID: 198811.

  • CVE-2020-5025HigMar 11, 2021
    risk 0.51cvss 7.8epss 0.01

    IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 db2fm is vulnerable to a buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code on the system with root privileges. IBM…

  • CVE-2020-4983HigJan 20, 2021
    risk 0.51cvss 7.8epss 0.00

    IBM Spectrum LSF 10.1 and IBM Spectrum LSF Suite 10.2 could allow a user on the local network who has privileges to submit LSF jobs to execute arbitrary commands. IBM X-Force ID: 192586.

  • CVE-2020-4688HigJan 20, 2021
    risk 0.51cvss 7.8epss 0.01

    IBM Security Guardium 10.6 and 11.2 could allow a local attacker to execute arbitrary commands on the system as an unprivileged user, caused by command injection vulnerability. IBM X-Force ID: 186700.

  • CVE-2020-4829HigDec 10, 2020
    risk 0.51cvss 7.8epss 0.00

    IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user to exploit a vulnerability in the ksu user command to gain root privileges. IBM X-Force ID: 189960.

  • CVE-2020-4739HigNov 20, 2020
    risk 0.51cvss 7.8epss 0.00

    IBM DB2 Accessories Suite for Linux, UNIX, and Windows, DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local authenticated attacker to execute arbitrary code on the system, caused by DLL search order hijacking…

  • CVE-2020-4701HigNov 19, 2020
    risk 0.51cvss 7.8epss 0.00

    IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code on the system with root privileges.

  • CVE-2020-4759HigNov 9, 2020
    risk 0.51cvss 7.8epss 0.02

    IBM FileNet Content Manager 5.5.4 and 5.5.5 is potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 188736.

  • CVE-2020-4588HigOct 30, 2020
    risk 0.51cvss 7.8epss 0.01

    IBM i2 iBase 8.9.13 could allow an attacker to upload arbitrary executable files which, when executed by an unsuspecting victim could result in code execution. IBM X-Force ID: 184579.

  • CVE-2020-4724HigOct 29, 2020
    risk 0.51cvss 7.8epss 0.02

    IBM i2 Analyst Notebook 9.2.0 and 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the…

  • CVE-2020-4723HigOct 29, 2020
    risk 0.51cvss 7.8epss 0.02

    IBM i2 Analyst Notebook 9.2.0 and 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the…

Page 20 of 177