VYPR

Vendor CVEs

IBM

All CVEs

8,825 total · sorted by risk
  • CVE-2022-43581HigDec 7, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM Content Navigator 3.0.0, 3.0.1, 3.0.2, 3.0.3, 3.0.4, 3.0.5, 3.0.6, 3.0.7, 3.0.8, 3.0.9, 3.0.10, 3.0.11, and 3.0.12 is vulnerable to missing authorization and could allow an authenticated user to load external plugins and execute code. IBM X-Force ID: 238805.

  • CVE-2022-43574HigNov 3, 2022
    risk 0.49cvss 7.5epss 0.00

    "IBM Robotic Process Automation 21.0.1, 21.0.2, 21.0.3, 21.0.4, and 21.0.5 is vulnerable to incorrect permission assignment which could allow access to application configurations. IBM X-Force ID: 238679."

  • CVE-2022-22480HigOct 7, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM QRadar SIEM 7.4 and 7.5 data node rebalancing does not function correctly when using encrypted hosts which could result in information disclosure. IBM X-Force ID: 225889.

  • CVE-2022-39168HigSep 29, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM Robotic Process Automation Clients are vulnerable to proxy credentials being exposed in upgrade logs. IBM X-Force ID: 235422.

  • CVE-2012-2201HigSep 29, 2022
    risk 0.49cvss 7.5epss 0.02

    IBM WebSphere MQ 7.1 is vulnerable to a denial of service, caused by an error when handling user ids. A remote attacker could exploit this vulnerability to bypass the security configuration setup on a SVRCONN channel and flood the queue manager.

  • CVE-2022-40608HigSep 19, 2022
    risk 0.49cvss 7.5epss 0.02

    IBM Spectrum Protect Plus 10.1.6 through 10.1.11 Microsoft File Systems restore operation can download any file on the target machine by manipulating the URL with a directory traversal attack. This results in the restore operation gaining access to files which the operator…

  • CVE-2021-38924HigSep 14, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 210163.

  • CVE-2022-30614HigSep 1, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to a denial of service via email flooding caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume all available CPU resources. IBM X-Force ID:…

  • CVE-2022-35715HigAug 10, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in a stack trace. This information could be used in further attacks against the system. IBM X-Force ID: 231202.

  • CVE-2022-22505HigAug 1, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 contains a vulnerability that could allow IBM tenant credentials to be exposed. IBM X-Force ID: 227288.

  • CVE-2022-35639HigJul 26, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM Sterling Partner Engagement Manager 6.1, 6.2, and Cloud 22.2 do not limit the length of a connection which could cause the server to become unresponsive. IBM X-Force ID: 230932.

  • CVE-2022-35287HigJul 25, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM Security Verify Information Queue 10.0.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 230817.

  • CVE-2022-35284HigJul 25, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM Security Verify Information Queue 10.0.2 could disclose sensitive information due to a missing or insecure SameSite attribute for a sensitive cookie. IBM X-Force ID: 230811.

  • CVE-2021-29755HigJul 20, 2022
    risk 0.49cvss 7.5epss 0.00

    IBM QRadar SIEM 7.3, 7.4, and 7.5 does not preform proper certificate validation for some inter-host communications. IBM X-Force ID: 202015.

  • CVE-2022-22460HigJul 14, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM Security Verify Identity Manager 10.0 contains sensitive information in the source code repository that could be used in further attacks against the system. IBM X-Force ID: 225013.

  • CVE-2022-22453HigJul 14, 2022
    risk 0.49cvss 7.5epss 0.00

    IBM Security Verify Identity Manager 10.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 224919.

  • CVE-2022-22452HigJul 14, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM Security Verify Identity Manager 10.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 224918.

  • CVE-2020-4159HigJul 12, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM QRadar Network Security 5.4.0 and 5.5.0 discloses sensitive information to unauthorized users which could be used to mount further attacks against the system. IBM X-Force ID: 174339.

  • CVE-2020-4157HigJul 12, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM QRadar Network Security 5.4.0 and 5.5.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 174337.

  • CVE-2022-22464HigJul 8, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 225081.

  • CVE-2022-22474HigJun 30, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM Spectrum Protect 8.1.0.0 through 8.1.14.0 dsmcad, dsmc, and dsmcsvc processes incorrectly handle certain read operations on TCP/IP sockets. This can result in a denial of service for IBM Spectrum Protect client operations. IBM X-Force ID: 225348.

  • CVE-2022-22390HigJun 24, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an information disclosure caused by improper privilege management when table function is used. IBM X-Force ID: 221973.

  • CVE-2022-22396HigJun 6, 2022
    risk 0.49cvss 7.5epss 0.01

    Credentials are printed in clear text in the IBM Spectrum Protect Plus 10.1.0.0 through 10.1.9.3 virgo log file in certain cases. Credentials could be the remote vSnap, offload targets, or VADP credentials depending on the operation performed. Credentials that are using API key…

  • CVE-2022-22497HigMay 24, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM Aspera Faspex 4.4.1 and 5.0.0 could allow unauthorized access due to an incorrectly computed security token. IBM X-Force ID: 226951.

  • CVE-2021-38872HigMay 17, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM DataPower Gateway 10.0.2.0, 10.0.3.0, 10.0.1.0 through 10.0.1.4, and 2018.4.1.0 through 2018.4.1.17 could allow a remote user to cause a denial of service by consuming resources with multiple requests. IBM X-Force ID: 208348.

  • CVE-2020-4994HigMay 17, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM DataPower Gateway 10.0.1.0 through 10.0.1.4 and 2018.4.1.0 through 2018.4.1.17 could allow a remote user to cause a temporary denial of service by sending invalid HTTP requests. IBM X-Force ID: 192906.

  • CVE-2021-20479HigMay 9, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM Cloud Pak System 2.3.0 through 2.3.3.3 Interim Fix 1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 197498.

  • CVE-2021-39023HigMay 6, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM Guardium Data Encryption (GDE) 4.0.0 and 5.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 213860.

  • CVE-2022-22433HigMay 5, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM Robotic Process Automation 21.0.1 and 21.0.2 is vulnerable to External Service Interaction attack, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to induce the application to perform server-side DNS lookups or HTTP…

  • CVE-2022-22368HigMay 3, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM Spectrum Scale 5.1.0 through 5.1.3.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 221012.

  • CVE-2021-39082HigApr 29, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM UrbanCode Deploy (UCD) 7.1.1.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

  • CVE-2021-38919HigApr 27, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM QRadar SIEM 7.3, 7.4, and 7.5 in some senarios may reveal authorized service tokens to other QRadar users. IBM X-Force ID: 210021

  • CVE-2021-38878HigApr 27, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM QRadar 7.3, 7.4, and 7.5 could allow a malicious actor to impersonate an actor due to key exchange without entity authentication. IBM X-Force ID: 208756.

  • CVE-2021-39076HigApr 19, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM Security Guardium 10.5 and 11.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive information. IBM X-Force ID: 215585.

  • CVE-2021-38930HigApr 11, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM System Storage DS8000 Management Console (HMC) R8.5 88.5x.x.x, R9.1 89.1x.0.0, and R9.2 89.2x.0.0 could allow a remote attacker to obtain sensitive information through unpublished URLs. IBM X-Force ID: 210331.

  • CVE-2021-38929HigApr 11, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM System Storage DS8000 Management Console (HMC) R8.5 88.5x.x.x, R9.1 89.1x.0.0, and R9.2 89.2x.0.0 could allow a remote attacker to obtain sensitive information through unpublished URLs. IBM X-Force ID: 210330.

  • CVE-2022-22332HigApr 1, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM Sterling Partner Engagement Manager 6.2.0 could allow an attacker to impersonate another user due to missing revocation mechanism for the JWT token. IBM X-Force ID: 219131.

  • CVE-2022-22327HigApr 1, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM UrbanCode Deploy (UCD) 7.0.5, 7.1.0, 7.1.1, and 7.1.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 218859.

  • CVE-2022-22354HigMar 14, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM Spectrum Protect Plus 10.1.0.0 through 10.1.9.2 and IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 do not limit the length of a connection which could allow for a Slowloris HTTP denial of service attack to take place. This can cause the Admin Console to become…

  • CVE-2022-22336HigFeb 23, 2022
    risk 0.49cvss 7.5epss 0.02

    IBM Sterling External Authentication Server and IBM Sterling Secure Proxy 6.0.3.0, 6.0.2.0, and 3.4.3.2 could allow a remote user to consume resources causing a denial of service due to a resource leak. IBM X-Force ID: 219395.

  • CVE-2021-38935HigFeb 18, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM Maximo Asset Management 7.6.1.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 210892.

  • CVE-2021-39034HigFeb 17, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM MQ 9.1 LTS is vulnerable to a denial of service attack caused by an issue within the channel process. IBM X-Force ID: 213964.

  • CVE-2021-38960HigFeb 4, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM OPENBMC OP920, OP930, and OP940 could allow an unauthenticated user to obtain sensitive information. IBM X-Force ID: 212047.

  • CVE-2021-38957HigJan 10, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 could disclose sensitive information due to hazardous input validation during QR code generation. IBM X-Force ID: 212040.

  • CVE-2021-38921HigJan 10, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 210067.

  • CVE-2021-38918HigJan 5, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM PowerVM Hypervisor FW860, FW940, FW950, and FW1010, through a specific sequence of VM management operations could lead to a violation of the isolation between peer VMs. IBM X-Force ID: 210019.

  • CVE-2021-39064HigDec 13, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Spectrum Copy Data Management 2.2.13 and earlier has weak authentication and password rules and incorrectly handles default credentials for the Spectrum Copy Data Management Admin console. IBM X-Force ID: 214957.

  • CVE-2021-39058HigDec 13, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Spectrum Copy Data Management 2.2.13 and earlier uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 214617.

  • CVE-2021-39053HigDec 13, 2021
    risk 0.49cvss 7.5epss 0.02

    IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to obtain sensitive information, caused by the improper handling of requests for Spectrum Copy Data Management Admin Console. By sending a specially-crafted request, a remote attacker could…

  • CVE-2021-38947HigDec 13, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Spectrum Copy Data Management 2.2.13 and earlier uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 211242.

Page 27 of 177