VYPR

Vendor CVEs

IBM

All CVEs

8,825 total · sorted by risk
  • CVE-2021-38975MedNov 15, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow an authenticated user to to obtain sensitive information from a specially crafted HTTP request. IBM X-Force ID: 212780.

  • CVE-2021-38974MedNov 15, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow an authenticated user to cause a denial of service using specially crafted HTTP requests. IBM X-Force ID: 212779.

  • CVE-2021-38887MedNov 10, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information from application response requests that could be used in further attacks against the system. IBM X-Force ID: 209401.

  • CVE-2021-29843MedNov 8, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM MQ 9.1 LTS, 9.1 CD, 9.2 LTS, and 9.2CD is vulnerable to a denial of service attack caused by an issue processing message properties. IBM X-Force ID: 205203.

  • CVE-2021-29786MedOct 27, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM Jazz Team Server products stores user credentials in clear text which can be read by an authenticated user. IBM X-Force ID: 203172.

  • CVE-2021-38915MedOct 12, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM Data Risk Manager 2.0.6 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 209947.

  • CVE-2020-4654MedOct 8, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated user to obtain sensitive information due to improper permission control. IBM X-Force ID: 186090.

  • CVE-2021-20473MedOct 7, 2021
    risk 0.42cvss 6.5epss 0.00

    IBM Sterling File Gateway User Interface 2.2.0.0 through 6.1.1.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 196944.

  • CVE-2021-20375MedOct 7, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated user to intercept and replace a message sent by another user due to improper access controls. IBM X-Force ID: 195567.

  • CVE-2021-29816MedSep 23, 2021
    risk 0.42cvss 6.5epss 0.00

    IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 204341.

  • CVE-2021-29856MedSep 20, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 could allow an authenticated usre to cause a denial of service through the WebGUI Map Creation page. IBM X-Force ID: 205685.

  • CVE-2021-20433MedSep 15, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM Security Guardium 11.3 could allow a an authenticated user to obtain sensitive information that could be used in further attacks against the system. IBM X-Force ID: 196345.

  • CVE-2020-4992MedAug 17, 2021
    risk 0.42cvss 6.5epss 0.00

    IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.16 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 192737.

  • CVE-2021-29880MedAug 13, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM QRadar SIEM 7.4.3 GA - 7.4.3 Fix Pack 1 when using domains or multi-tenancy could be vulnerable to information disclosure between tenants by routing SIEM data to the incorrect domain. IBM X-Force ID: 206979.

  • CVE-2021-29714MedAug 9, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM Content Navigator 3.0.CD could allow a malicious user to cause a denial of service due to improper input validation. IBM X-Force ID: 200968.

  • CVE-2021-29770MedJul 26, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) could allow an authenticated user to perform unauthorized actions due to hazardous input validation. IBM X-Force ID: 202771.

  • CVE-2021-20431MedJul 26, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM i2 Analyst's Notebook Premium 9.2.0, 9.2.1, and 9.2.2 does not invalidate session after logout which could allow an an attacker to obtain sensitive information from the system. IBM X-Force ID: 196342.

  • CVE-2020-4623MedJul 26, 2021
    risk 0.42cvss 6.5epss 0.00

    IBM i2 iBase 8.9.13 could allow a local authenticated attacker to execute arbitrary code on the system, caused by a DLL search order hijacking flaw. By using a specially-crafted .DLL file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM…

  • CVE-2020-4980MedJul 16, 2021
    risk 0.42cvss 6.5epss 0.00

    IBM QRadar SIEM 7.3 and 7.4 uses less secure methods for protecting data in transit between hosts when encrypt host connections is not enabled as well as data at rest. IBM X-Force ID: 192539.

  • CVE-2020-4675MedJul 16, 2021
    risk 0.42cvss 6.5epss 0.00

    IBM InfoSphere Master Data Management Server 11.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 186324.

  • CVE-2021-20537MedJul 15, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM Security Verify Access Docker 10.0.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID:198918

  • CVE-2021-20461MedJun 30, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM Cognos Analytics 10.0 and 11.1 is susceptible to a weakness in the implementation of the System Appearance configuration setting. An attacker could potentially bypass business logic to modify the appearance and behavior of the application. IBM X-Force ID: 196770.

  • CVE-2021-20573MedJun 28, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM Security Identity Manager Adapters 6.0 and 7.0 are vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote authenticated attacker could overflow the and cause the server to crash. IBM X-Force ID: 199249.

  • CVE-2021-20572MedJun 28, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM Security Identity Manager Adapters 6.0 and 7.0 are vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A remote authenticated attacker could overflow the and cause the server to crash. IBM X-Force ID: 199247.

  • CVE-2021-20494MedJun 28, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM Security Identity Manager Adapters 6.0 and 7.0 are vulnerable to a heap based buffer overflow, caused by improper bounds. An authenticared user could overflow the buffer and cause the service to crash. IBM X-Force ID: 197882.

  • CVE-2021-29777MedJun 24, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5, under specific circumstance of a table being dropped while being accessed in another session, could allow an authenticated user to cause a denial of srevice IBM X-Force ID: 203031.

  • CVE-2021-20579MedJun 24, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a user who can create a view or inline SQL function to obtain sensitive information when AUTO_REVAL is set to DEFFERED_FORCE. IBM X-Force ID: 199283.

  • CVE-2021-20488MedJun 16, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM Security Identity Manager 6.0.2 could allow an authenticated malicious user to change the passwords of other users in the Windows AD environment when IBM Security Identity Manager Windows Password Synch Plug-in is deployed and configured. IBM X-Force ID: 197789.

  • CVE-2021-20483MedJun 16, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM Security Identity Manager 6.0.2 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, a remote authenticated attacker could exploit this vulnerability to obtain sensitive data. IBM X-Force ID: 197591.

  • CVE-2021-20371MedJun 2, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to obtain sensitive information when an error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 195516.

  • CVE-2020-4732MedJun 2, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM Jazz Foundation and IBM Engineering products could allow an authenticated user to obtain sensitive information due to lack of security restrictions. IBM X-Force ID: 188126.

  • CVE-2019-4471MedJun 1, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain sensitive information, caused by the failure to set the secure flag for a sensitive cookie in an HTTPS session. A remote attacker could exploit this vulnerability to obtain sensitive information. IBM…

  • CVE-2021-20486MedMay 26, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM Cloud Pak for Data 3.0 could allow an authenticated user to obtain sensitive information when installed with additional plugins. IBM X-Force ID: 197668.

  • CVE-2021-29695MedMay 25, 2021
    risk 0.42cvss 6.5epss 0.02

    IBM Host firmware for LC-class Systems could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request that would allow them to delete arbitrary files on the system. IBM X-Force ID: 200558.

  • CVE-2021-29683MedMay 20, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM Security Identity Manager 7.0.2 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 199998.

  • CVE-2020-4901MedMay 7, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM Robotic Process Automation with Automation Anywhere 11.0 could allow an attacker on the network to obtain sensitive information or cause a denial of service through username enumeration. IBM X-Force ID: 190992.

  • CVE-2020-4883MedMay 5, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM QRadar SIEM 7.3 and 7.4 could disclose sensitive information about other domains which could be used in further attacks against the system. IBM X-Force ID: 190907.

  • CVE-2021-20432MedApr 26, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM Spectrum Protect Plus 10.1.0 through 10.1.7 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains. IBM X-Force ID: 196344.

  • CVE-2021-20480MedApr 8, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM WebSphere Application Server 7.0, 8.0, and 8.5 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, a remote authenticated attacker could exploit this vulnerability to obtain sensitive data. IBM X-Force ID: 197502.

  • CVE-2020-5016MedMar 10, 2021
    risk 0.42cvss 6.5epss 0.02

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the system. When application security is disabled and JAX-RPC applications are present, an attacker could send a specially-crafted URL request containing "dot dot"…

  • CVE-2020-4903MedMar 8, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM API Connect V10 and V2018 could allow an attacker who has intercepted a registration invitation link to impersonate the registered user or obtain sensitive information. IBM X-Force ID: 191105.

  • CVE-2020-4931MedFeb 24, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM MQ 9.1 LTS, 9.2 LTS, and 9.1 CD AMQP Channels could allow an authenticated user to cause a denial of service due to an issue processing messages. IBM X-Force ID: 191747.

  • CVE-2021-20445MedFeb 18, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM Maximo for Civil Infrastructure 7.6.2 could allow a user to obtain sensitive information due to insecure storeage of authentication credentials. IBM X-Force ID: 196621.

  • CVE-2020-4790MedFeb 9, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM Security Identity Governance and Intelligence 5.2.6 could allow a user to cause a denial of service due to improperly validating a supplied URL, rendering the application unusuable. IBM X-Force ID: 189375.

  • CVE-2021-20359MedFeb 8, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM Cloud Pak for Automation 20.0.3, 20.0.2-IF002 - Business Automation Application Designer Component stores potentially sensitive information in log files that could be obtained by an unauthorized user. IBM X-Force ID: 194966.

  • CVE-2021-20358MedFeb 8, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM Cloud Pak for Automation 20.0.3, 20.0.2-IF002 stores potentially sensitive information in clear text in API connection log files. This information could be obtained by a user with permissions to read log files. IBM X-Force ID: 194965.

  • CVE-2020-4828MedFeb 4, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 is vulnerable to web cache poisoning, caused by improper input validation by modifying HTTP request headers. IBM X-Force ID: 189842.

  • CVE-2020-4789MedJan 27, 2021
    risk 0.42cvss 6.5epss 0.03

    IBM QRadar SIEM 7.4.2 GA to 7.4.2 Patch 1, 7.4.0 to 7.4.1 Patch 1, and 7.3.0 to 7.3.3 Patch 5 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files…

  • CVE-2020-4968MedJan 21, 2021
    risk 0.42cvss 6.5epss 0.00

    IBM Security Identity Governance and Intelligence 5.2.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 192427.

  • CVE-2020-4869MedJan 11, 2021
    risk 0.42cvss 6.5epss 0.02

    IBM MQ Appliance 9.2 CD and 9.2 LTS is vulnerable to a denial of service, caused by a buffer overflow. A remote attacker could send a specially crafted SNMP query to cause the appliance to reload. IBM X-Force ID: 190831.

Page 46 of 177