VYPR

Vendor CVEs

IBM

All CVEs

8,825 total · sorted by risk
  • CVE-2021-39002HigDec 9, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

  • CVE-2021-38951HigDec 9, 2021
    risk 0.49cvss 7.5epss 0.02

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume all available CPU resources. IBM X-Force ID: 211405.

  • CVE-2021-20373HigDec 9, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Db2 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an Information Disclosure when using the LOAD utility as under certain circumstances the LOAD utility does not enforce directory restrictions. IBM X-Force ID: 199521.

  • CVE-2021-20470HigDec 3, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Cognos Analytics 11.1.7 and 11.2.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 196339.

  • CVE-2021-20400HigDec 1, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM QRadar SIEM 7.3 and 7.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 196074.

  • CVE-2021-38891HigNov 23, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Sterling Connect:Direct Web Services 1.0 and 6.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 209508.

  • CVE-2021-38890HigNov 23, 2021
    risk 0.49cvss 7.5epss 0.02

    IBM Sterling Connect:Direct Web Services 1.0 and 6.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 209507.

  • CVE-2021-38984HigNov 15, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 212793.

  • CVE-2021-38983HigNov 15, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 212792.

  • CVE-2021-38979HigNov 15, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the software does not also use a salt as part of the input. IBM X-Force ID: 212785.

  • CVE-2021-29875HigNov 2, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM InfoSphere Information Server 11.7 could allow an attacker to obtain sensitive information due to a insecure third party domain access vulnerability. IBM X-Force ID: 206572.

  • CVE-2021-29737HigNov 2, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM InfoSphere Data Flow Designer Engine (IBM InfoSphere Information Server 11.7 ) component has improper validation of the REST API server certificate. IBM X-Force ID: 201301.

  • CVE-2021-29774HigOct 27, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Jazz Team Server products could allow an authenticated user to obtain elevated privileges under certain configurations. IBM X-Force ID: 203025.

  • CVE-2021-38862HigOct 12, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Data Risk Manager (iDNA) 2.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 207980.

  • CVE-2021-20584HigOct 7, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow a remote attacker to upload arbitrary files, caused by improper access controls. IBM X-Force ID: 199397.

  • CVE-2021-38925HigOct 6, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Sterling B2B Integrator Standard Edition 5.2.0. 0 through 6.1.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 210171.

  • CVE-2021-29894HigSep 30, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Cloud Pak for Security (CP4S) 1.7.0.0, 1.7.1.0, 1.7.2.0, and 1.8.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 207320.

  • CVE-2021-38864HigSep 23, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Security Verify Bridge 1.0.5.0 could allow a user to obtain sensitive information due to improper certificate validation. IBM X-Force ID: 208155.

  • CVE-2021-29825HigSep 16, 2021
    risk 0.49cvss 7.5epss 0.02

    IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could disclose sensitive information when using ADMIN_CMD with LOAD or BACKUP. IBM X-Force ID: 204470.

  • CVE-2021-29750HigSep 15, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM QRadar SIEM 7.3 and 7.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 201778.

  • CVE-2021-29723HigAug 30, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-ForceID: 201100.

  • CVE-2021-29722HigAug 30, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 201095.

  • CVE-2021-29802HigAug 23, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Security SOAR performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.

  • CVE-2021-29704HigAug 23, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Security SOAR uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

  • CVE-2021-20427HigAug 11, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Security Guardium 11.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 196314.

  • CVE-2021-29765HigAug 4, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM PowerVM Hypervisor FW940 and FW950 could allow an attacker to obtain sensitive information if they gain service access to the FSP. IBM X-Force ID: 202476.

  • CVE-2021-20337HigJul 26, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM QRadar SIEM 7.3.0 to 7.3.3 Patch 8 and 7.4.0 to 7.4.3 GA uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 194448.

  • CVE-2021-20497HigJul 15, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Security Verify Access Docker 10.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 197969

  • CVE-2021-29725HigJul 15, 2021
    risk 0.49cvss 7.5epss 0.03

    IBM Secure External Authentication Server 2.4.3.2, 6.0.1, 6.0.2 and IBM Secure Proxy 3.4.3.2, 6.0.1, 6.0.2 could allow a remote user to consume resources causing a denial of service due to a resource leak.

  • CVE-2021-20439HigJul 15, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Security Access Manager 9.0 and IBM Security Verify Access Docker 10.0.0 stores user credentials in plain clear text which can be read by an unauthorized user.

  • CVE-2021-20422HigJul 13, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Cloud Pak for Applications 4.3 could disclose sensitive information to a malicious attacker by accessing data stored in memory. IBM X-Force ID: 196304.

  • CVE-2021-20360HigJul 13, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Cloud Pak for Applications 4.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 195031.

  • CVE-2021-29794HigJul 12, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Tivoli Netcool/Impact 7.1.0.20 and 7.1.0.21 uses an insecure SSH server configuration which enables weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 203556.

  • CVE-2021-20474HigJul 7, 2021
    risk 0.49cvss 7.5epss 0.00

    IBM Guardium Data Encryption (GDE) 3.0.0.2 and 4.0.0.4 does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

  • CVE-2021-20415HigJul 7, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Guardium Data Encryption (GDE) 4.0.0.4 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 196217.

  • CVE-2021-20379HigJul 7, 2021
    risk 0.49cvss 7.5epss 0.00

    IBM Guardium Data Encryption (GDE) 3.0.0.3 and 4.0.0.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 195711.

  • CVE-2021-29703HigJun 24, 2021
    risk 0.49cvss 7.5epss 0.02

    Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of service as the server terminates abnormally when executing a specially crafted SELECT statement. IBM X-Force ID: 200659.

  • CVE-2021-29702HigJun 16, 2021
    risk 0.49cvss 7.5epss 0.02

    Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1.4 and 11.5.5 is vulnerable to a denial of service as the server terminates abnormally when executing a specially crafted SELECT statement. IBM X-Force ID: 200658.

  • CVE-2021-20566HigJun 16, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Resilient SOAR V38.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 199238.

  • CVE-2021-20380HigJun 3, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM QRadar Advisor With Watson App 1.1 through 2.5 as used on IBM QRadar SIEM 7.4 could allow a remote user to obtain sensitive information from HTTP requests that could aid in further attacks against the system. IBM X-Force ID: 195712.

  • CVE-2021-20576HigJun 1, 2021
    risk 0.49cvss 7.5epss 0.02

    IBM Security Verify Access 20.07 could allow a remote attacker to send a specially crafted HTTP GET request that could cause the application to crash.

  • CVE-2019-4724HigJun 1, 2021
    risk 0.49cvss 7.5epss 0.02

    IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain credentials from a user's browser via incorrect autocomplete settings in New Content Backup page. IBM X-Force ID: 172130.

  • CVE-2019-4723HigJun 1, 2021
    risk 0.49cvss 7.5epss 0.02

    IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain credentials from a user's browser via incorrect autocomplete settings in New Data Server Connection page. IBM X-Force ID: 172129.

  • CVE-2021-20419HigMay 24, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Security Guardium 11.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 196280.

  • CVE-2021-29691HigMay 20, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Security Identity Manager 7.0.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 200252.

  • CVE-2021-29688HigMay 20, 2021
    risk 0.49cvss 7.5epss 0.02

    IBM Security Identity Manager 7.0.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 200102.

  • CVE-2020-4850HigMay 20, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Spectrum Scale 1.1.1.0 through 1.1.8.4 Transparent Cloud Tiering could allow a remote attacker to obtain sensitive information, caused by the leftover files after configuration. IBM X-Force ID: 190298.

  • CVE-2021-29747HigMay 17, 2021
    risk 0.49cvss 7.5epss 0.02

    IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain highly sensitive information due to a vulnerability in the authentication mechanism. IBM X-Force ID: 201775.

  • CVE-2021-20393HigMay 14, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM QRadar User Behavior Analytics 1.0.0 through 4.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 196001.

  • CVE-2020-4985HigMay 14, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Planning Analytics Local 2.0 could allow an attacker to obtain sensitive information due to accepting body parameters in a query. IBM X-Force ID: 192642.

Page 28 of 177