VYPR

Vendor CVEs

IBM

All CVEs

8,825 total · sorted by risk
  • CVE-2023-27874CriMar 21, 2023
    risk 0.64cvss 9.9epss 0.01

    IBM Aspera Faspex 4.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to execute arbitrary commands. IBM X-Force ID: 249845.

  • CVE-2022-40752CriNov 16, 2022
    risk 0.64cvss 9.8epss 0.02

    IBM InfoSphere DataStage 11.7 is vulnerable to a command injection vulnerability due to improper neutralization of special elements. IBM X-Force ID:  236687.

  • CVE-2022-22425CriNov 3, 2022
    risk 0.64cvss 9.8epss 0.01

    "IBM InfoSphere Information Server 11.7 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 223598."

  • CVE-2022-22455CriAug 17, 2022
    risk 0.64cvss 9.8epss 0.00

    IBM Security Verify Governance Identity Manager 10.0 virtual appliance component performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses. IBM X-Force ID: 224989.

  • CVE-2021-39085CriAug 16, 2022
    risk 0.64cvss 9.8epss 0.01

    IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete…

  • CVE-2022-35280CriAug 10, 2022
    risk 0.64cvss 9.8epss 0.01

    IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 230634.

  • CVE-2020-4150CriJul 11, 2022
    risk 0.64cvss 9.8epss 0.01

    IBM SiteProtector Appliance 3.1.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 174142.

  • CVE-2022-22487CriJun 30, 2022
    risk 0.64cvss 9.8epss 0.01

    An IBM Spectrum Protect storage agent could allow a remote attacker to perform a brute force attack by allowing unlimited attempts to login to the storage agent without locking the administrative ID. A remote attacker could exploit this vulnerability using brute force techniques…

  • CVE-2022-31767CriJun 24, 2022
    risk 0.64cvss 9.8epss 0.05

    IBM CICS TX Standard and Advanced 11.1 could allow a remote attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 227980.

  • CVE-2021-38945CriJun 24, 2022
    risk 0.64cvss 9.8epss 0.02

    IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 could allow a remote attacker to upload arbitrary files, caused by improper content validation. IBM X-Force ID: 211238.

  • CVE-2022-22318CriJun 20, 2022
    risk 0.64cvss 9.8epss 0.00

    IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.

  • CVE-2022-22317CriJun 20, 2022
    risk 0.64cvss 9.8epss 0.01

    IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 218281.

  • CVE-2022-22485CriJun 17, 2022
    risk 0.64cvss 9.8epss 0.01

    In some cases, an unsuccessful attempt to log into IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14.000 does not cause the administrator's invalid sign-on count to be incremented on the IBM Spectrum Protect Server. An attacker could exploit this vulnerability…

  • CVE-2019-4575CriJun 15, 2022
    risk 0.64cvss 9.8epss 0.01

    IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.2.0 through 3.2.9 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end…

  • CVE-2022-31768CriJun 6, 2022
    risk 0.64cvss 9.8epss 0.01

    IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.

  • CVE-2022-22413CriMay 12, 2022
    risk 0.64cvss 9.8epss 0.01

    IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 223022.

  • CVE-2021-38969CriMay 11, 2022
    risk 0.64cvss 9.8epss 0.01

    IBM Spectrum Virtualize 8.2, 8.3, and 8.4 could allow an attacker to allow unauthorized access due to the reuse of support generated credentials. IBM X-Force ID: 212609.

  • CVE-2021-38869CriApr 27, 2022
    risk 0.64cvss 9.8epss 0.01

    IBM QRadar SIEM 7.3, 7.4, and 7.5 in some situations may not automatically log users out after they exceede their idle timeout. IBM X-Force ID: 208341.

  • CVE-2021-3897CriApr 22, 2022
    risk 0.64cvss 9.8epss 0.01

    An authentication bypass vulnerability was discovered in an internal service of the Lenovo Fan Power Controller2 (FPC2) and Lenovo System Management Module (SMM) firmware during an that could allow an unauthenticated attacker to execute commands on the SMM and FPC2. SMM2 is not…

  • CVE-2021-3849CriApr 22, 2022
    risk 0.64cvss 9.8epss 0.01

    An authentication bypass vulnerability was discovered in the web interface of the Lenovo Fan Power Controller2 (FPC2) and Lenovo System Management Module (SMM) firmware that could allow an unauthenticated attacker to execute commands on the SMM and FPC2. SMM2 is not affected.

  • CVE-2021-39070CriFeb 2, 2022
    risk 0.64cvss 9.8epss 0.02

    IBM Security Verify Access 10.0.0.0, 10.0.1.0 and 10.0.2.0 with the advanced access control authentication service enabled could allow an attacker to authenticate as any user on the system. IBM X-Force ID: 215353.

  • CVE-2020-4879CriJan 21, 2022
    risk 0.64cvss 9.8epss 0.01

    IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could allow a remote attacker to bypass security restrictions, caused by improper validation of authentication cookies. IBM X-Force ID: 190847.

  • CVE-2020-4877CriJan 21, 2022
    risk 0.64cvss 9.8epss 0.01

    IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could be vulnerable to unauthorized modifications by using public fields in public classes. IBM X-Force ID: 190843.

  • CVE-2021-39065CriDec 13, 2021
    risk 0.64cvss 9.8epss 0.02

    IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to execute arbitrary commands on the system, caused by improper validation of user-supplied input by the Spectrum Copy Data Management Admin Console login and uploadcertificate function . A remote…

  • CVE-2021-39052CriDec 13, 2021
    risk 0.64cvss 9.8epss 0.01

    IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to access the Spring Boot console without authorization. IBM X-Force ID: 214523.

  • CVE-2021-29908CriOct 6, 2021
    risk 0.64cvss 9.8epss 0.02

    The IBM TS7700 Management Interface is vulnerable to unauthenticated access. By accessing a specially-crafted URL, an attacker may gain administrative access to the Management Interface without authentication. IBM X-Force ID: 207747.

  • CVE-2021-29903CriOct 6, 2021
    risk 0.64cvss 9.8epss 0.01

    IBM Sterling B2B Integrator Standard Edition 5.2.6.0 through 6.1.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID:…

  • CVE-2021-29798CriOct 6, 2021
    risk 0.64cvss 9.8epss 0.01

    IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID:…

  • CVE-2021-20578CriSep 30, 2021
    risk 0.64cvss 9.8epss 0.01

    IBM Cloud Pak for Security (CP4S) 1.7.0.0, 1.7.1.0, 1.7.2.0, and 1.8.0.0 could allow an attacker to perform unauthorized actions due to improper or missing authentication controls. IBM X-Force ID: 199282.

  • CVE-2020-4690CriSep 23, 2021
    risk 0.64cvss 9.8epss 0.01

    IBM Security Guardium 11.3 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 186697.

  • CVE-2021-29772CriAug 26, 2021
    risk 0.64cvss 9.8epss 0.01

    IBM API Connect 5.0.0.0 through 5.0.8.11 could allow a user to potentially inject code due to unsanitized user input. IBM X-Force ID: 202774.

  • CVE-2021-20509CriAug 12, 2021
    risk 0.64cvss 9.8epss 0.02

    IBM Maximo Asset Management 7.6.0 and 7.6.1 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 198243.

  • CVE-2021-20418CriAug 11, 2021
    risk 0.64cvss 9.8epss 0.01

    IBM Security Guardium 11.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 196279.

  • CVE-2021-29781CriJul 30, 2021
    risk 0.64cvss 9.8epss 0.03

    IBM Partner Engagement Manager 2.0 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization flaw. By sending specially-crafted data, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM…

  • CVE-2020-4821CriJul 16, 2021
    risk 0.64cvss 9.8epss 0.02

    IBM InfoSphere Data Replication 11.4 and IBM InfoSphere Change Data Capture for z/OS 10.2.1, under certain configurations, could allow a user to bypass authentication mechanisms using an empty password string. IBM X-Force ID: 189834

  • CVE-2021-20426CriMay 24, 2021
    risk 0.64cvss 9.8epss 0.01

    IBM Security Guardium 11.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 196313.

  • CVE-2020-4979CriMay 5, 2021
    risk 0.64cvss 9.8epss 0.02

    IBM QRadar SIEM 7.3 and 7.4 is vulnerable to insecure inter-deployment communication. An attacker that is able to comprimise or spoof traffic between hosts may be able to execute arbitrary commands. IBM X-Force D: 192538.

  • CVE-2020-4682CriJan 28, 2021
    risk 0.64cvss 9.8epss 0.08

    IBM MQ 7.5, 8.0, 9.0, 9.1, 9.2 LTS, and 9.2 CD could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization of trusted data. An attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 186509.

  • CVE-2020-27583CriJan 26, 2021
    risk 0.64cvss 9.8epss 0.04

    IBM InfoSphere Information Server 8.5.0.0 is affected by deserialization of untrusted data which could allow remote unauthenticated attackers to execute arbitrary code. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

  • CVE-2020-4958CriJan 21, 2021
    risk 0.64cvss 9.8epss 0.02

    IBM Security Identity Governance and Intelligence 5.2.6 does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. IBM X-Force ID: 192209.

  • CVE-2020-4988CriDec 21, 2020
    risk 0.64cvss 9.8epss 0.01

    Loopback 8.0.0 contains a vulnerability that could allow an attacker to manipulate or pollute Javascript values and cause a denial of service or possibly execute code. IBM X-Force ID: 192706.

  • CVE-2020-4747CriDec 15, 2020
    risk 0.64cvss 9.8epss 0.02

    IBM Connect:Direct for UNIX 6.1.0, 6.0.0, 4.3.0, and 4.2.0 can allow a local or remote user to obtain an authenticated CLI session due to improper authentication methods. IBM X-Force ID: 188516.

  • CVE-2020-4854CriNov 23, 2020
    risk 0.64cvss 9.8epss 0.02

    IBM Spectrum Protect Plus 10.1.0 thorugh 10.1.6 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 190454.

  • CVE-2020-4499CriOct 15, 2020
    risk 0.64cvss 9.8epss 0.01

    IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an unauthorized public Oauth client to bypass some or all of the authentication checks and gain access to applications. IBM X-Force ID: 182216.

  • CVE-2020-4493CriOct 5, 2020
    risk 0.64cvss 9.8epss 0.03

    IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow an attacker to bypass authentication and issue commands using a specially crafted HTTP command. IBM X-Force ID: 181995.

  • CVE-2020-4693CriSep 2, 2020
    risk 0.64cvss 9.8epss 0.03

    IBM Spectrum Protect Operations Center 7.1.0.000 through 7.1.10 and 8.1.0.000 through 8.1.9 may allow an attacker to execute arbitrary code on the system, caused by improper validation of data prior to export. IBM X-Force ID: 186782.

  • CVE-2019-4694CriAug 26, 2020
    risk 0.64cvss 9.8epss 0.01

    IBM Security Guardium Data Encryption (GDE) 3.0.0.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 171832.

  • CVE-2020-4589CriAug 13, 2020
    risk 0.64cvss 9.8epss 0.08

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects from untrusted sources. IBM X-Force ID: 184585.

  • CVE-2020-4459CriAug 4, 2020
    risk 0.64cvss 9.8epss 0.01

    IBM Security Verify Access 10.7 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 181395.

  • CVE-2020-4567CriJul 29, 2020
    risk 0.64cvss 9.8epss 0.02

    IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 184156.

Page 3 of 177