VYPR

Vendor CVEs

IBM

All CVEs

8,825 total · sorted by risk
  • CVE-2025-0158MedFeb 6, 2025
    risk 0.36cvss 5.5epss 0.00

    IBM EntireX 11.1 could allow a local user to cause a denial of service due to an unhandled error and fault isolation.

  • CVE-2024-45647MedJan 20, 2025
    risk 0.36cvss 5.6epss 0.00

    IBM Security Verify Access 10.0.0 through 10.0.8 and IBM Security Verify Access Docker 10.0.0 through 10.0.8 could allow could an unverified user to change the password of an expired user without prior knowledge of that password.

  • CVE-2022-22491MedJan 9, 2025
    risk 0.36cvss 5.5epss 0.00

    IBM App Connect Enterprise Certified Container 7.1, 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, 12.3, and 12.4 operands running in Red Hat OpenShift do not restrict writing to the local filesystem, which may result…

  • CVE-2024-40679MedJan 8, 2025
    risk 0.36cvss 5.5epss 0.00

    IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to an information disclosure vulnerability as sensitive information may be included in a log file under specific conditions.

  • CVE-2024-31913MedJan 6, 2025
    risk 0.36cvss 5.5epss 0.00

    IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially…

  • CVE-2024-52906MedDec 25, 2024
    risk 0.36cvss 5.5epss 0.00

    IBM AIX 7.2, 7.3, VIOS 3.1, and 4.1 could allow a non-privileged local user to exploit a vulnerability in the TCP/IP kernel extension to cause a denial of service.

  • CVE-2024-47102MedDec 25, 2024
    risk 0.36cvss 5.5epss 0.00

    IBM AIX 7.2, 7.3, VIOS 3.1, and 4.1 could allow a non-privileged local user to exploit a vulnerability in the AIX perfstat kernel extension to cause a denial of service.

  • CVE-2024-25020MedDec 3, 2024
    risk 0.36cvss 5.5epss 0.00

    IBM Cognos Controller 11.0.0 and 11.0.1 is vulnerable to malicious file upload by allowing unrestricted filetype attachments in the Journal entry page. Attackers can make use of this weakness and upload malicious executable files into the system and can be sent to…

  • CVE-2024-25019MedDec 3, 2024
    risk 0.36cvss 5.5epss 0.00

    IBM Cognos Controller 11.0.0 and 11.0.1 could be vulnerable to malicious file upload by not validating the type of file uploaded to Journal entry attachments. Attackers can make use of this weakness and upload malicious executable files into the system that can be sent to…

  • CVE-2024-49351MedNov 26, 2024
    risk 0.36cvss 5.5epss 0.00

    IBM Workload Scheduler 9.5, 10.1, and 10.2 stores user credentials in plain text which can be read by a local user.

  • CVE-2024-45670MedNov 14, 2024
    risk 0.36cvss 5.6epss 0.00

    IBM Security SOAR 51.0.1.0 and earlier contains a mechanism for users to recover or change their passwords without knowing the original password, but the user account must be compromised prior to the weak recovery mechanism.

  • CVE-2024-45086MedNov 4, 2024
    risk 0.36cvss 5.5epss 0.00

    IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to expose sensitive information or consume memory resources.

  • CVE-2024-45072MedOct 16, 2024
    risk 0.36cvss 5.5epss 0.00

    IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to expose sensitive information or consume memory resources.

  • CVE-2024-45071MedOct 16, 2024
    risk 0.36cvss 5.5epss 0.00

    IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a…

  • CVE-2024-40703MedSep 22, 2024
    risk 0.36cvss 5.5epss 0.00

    IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and IBM Cognos Analytics Reports for iOS 11.0.0.7 could allow a local attacker to obtain sensitive information in the form of an API key. An attacker could use this information to…

  • CVE-2024-40680MedSep 7, 2024
    risk 0.36cvss 5.5epss 0.00

    IBM MQ 9.3 CD and 9.4 LTS/CD could allow a local user to cause a denial of service due to improper memory allocation causing a segmentation fault.

  • CVE-2024-25024MedAug 15, 2024
    risk 0.36cvss 5.5epss 0.00

    IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 281430.

  • CVE-2024-28799MedAug 14, 2024
    risk 0.36cvss 5.6epss 0.00

    IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 displays sensitive data improperly to a local privileged user, in non default configurations, during back-end commands which may result in the unexpected disclosure of…

  • CVE-2023-26288MedJul 30, 2024
    risk 0.36cvss 5.5epss 0.00

    IBM Aspera Orchestrator 4.0.1 does not invalidate session after a password change which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 248477.

  • CVE-2024-39733MedJul 14, 2024
    risk 0.36cvss 5.5epss 0.00

    IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 295972.

  • CVE-2024-25023MedJul 10, 2024
    risk 0.36cvss 5.5epss 0.00

    IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.22.0 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 281429.

  • CVE-2023-38368MedJun 27, 2024
    risk 0.36cvss 5.5epss 0.00

    IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could disclose sensitive information to a local user to do improper permission controls. IBM X-Force ID: 261195.

  • CVE-2023-30430MedJun 27, 2024
    risk 0.36cvss 5.5epss 0.00

    IBM Security Verify Access 10.0.0 through 10.0.7.1 could allow a local user to obtain sensitive information from trace logs. IBM X-Force ID: 252183.

  • CVE-2022-40745MedApr 19, 2024
    risk 0.36cvss 5.5epss 0.00

    IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain sensitive information due to weaker than expected security. IBM X-Force ID: 236452.

  • CVE-2023-22869MedApr 19, 2024
    risk 0.36cvss 5.5epss 0.00

    IBM Aspera Faspex 5.0.0 through 5.0.7 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 244119.

  • CVE-2023-46172MedMar 7, 2024
    risk 0.36cvss 5.6epss 0.01

    IBM DS8900F HMC 89.21.19.0, 89.21.31.0, 89.30.68.0, 89.32.40.0, and 89.33.48.0 could allow a remote attacker to bypass authentication restrictions for authorized user. IBM X-Force ID: 269409.

  • CVE-2023-25926MedFeb 29, 2024
    risk 0.36cvss 5.5epss 0.01

    IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. …

  • CVE-2024-22318MedFeb 9, 2024
    risk 0.36cvss 5.1epss 0.01

    IBM i Access Client Solutions (ACS) 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.4 is vulnerable to NT LAN Manager (NTLM) hash disclosure by an attacker modifying UNC capable paths within ACS configuration files to point to a hostile server. If NTLM is enabled, the Windows…

  • CVE-2022-32755MedOct 14, 2023
    risk 0.36cvss 5.5epss 0.01

    IBM Security Directory Server 6.4.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 228505.

  • CVE-2023-30436MedAug 27, 2023
    risk 0.36cvss 5.5epss 0.00

    IBM Security Guardium 11.3, 11.4, and 11.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. …

  • CVE-2023-28529MedMay 19, 2023
    risk 0.36cvss 5.5epss 0.00

    IBM InfoSphere Information Server 11.7 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. …

  • CVE-2023-22874MedMay 5, 2023
    risk 0.36cvss 5.5epss 0.00

    IBM MQ Clients 9.2 CD, 9.3 CD, and 9.3 LTS are vulnerable to a denial of service attack when processing configuration files. IBM X-Force ID: 244216.

  • CVE-2022-35281MedJan 9, 2023
    risk 0.36cvss 5.5epss 0.01

    IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, 7.6.1.3 and the IBM Maximo Manage 8.3, 8.4 application in IBM Maximo Application Suite are vulnerable to CSV injection. IBM X-Force ID: 2306335.

  • CVE-2022-22371MedJan 5, 2023
    risk 0.36cvss 5.5epss 0.00

    IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 does not invalidate session after a password change which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 221195.

  • CVE-2022-34331MedNov 11, 2022
    risk 0.36cvss 5.5epss 0.00

    After performing a sequence of Power FW950, FW1010 maintenance operations a SRIOV network adapter can be improperly configured leading to desired VEPA configuration being disabled. IBM X-Force ID: 229695.

  • CVE-2022-38388MedOct 11, 2022
    risk 0.36cvss 5.5epss 0.00

    IBM Navigator Mobile Android 3.4.1.1 and 3.4.1.2 app could allow a local user to obtain sensitive information due to improper access control. IBM X-Force ID: 233968.

  • CVE-2022-34308MedOct 7, 2022
    risk 0.36cvss 5.5epss 0.00

    IBM CICS TX 11.1 could allow a local user to cause a denial of service due to improper load handling. IBM X-Force ID: 229437.

  • CVE-2022-30613MedOct 7, 2022
    risk 0.36cvss 5.5epss 0.00

    IBM QRadar SIEM 7.4 and 7.5 could disclose sensitive information via a local service to a privileged user. IBM X-Force ID: 227366.

  • CVE-2015-1931MedSep 29, 2022
    risk 0.36cvss 5.5epss 0.00

    IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR1 FP10, 7 R1 before SR3 FP10, 7 before SR9 FP10, 6 R1 before SR8 FP7, 6 before SR16 FP7, and 5.0 before SR16 FP13 stores plaintext information in memory dumps, which allows local users to obtain…

  • CVE-2022-22423MedSep 23, 2022
    risk 0.36cvss 5.5epss 0.00

    IBM Common Cryptographic Architecture (CCA 5.x MTM for 4767 and CCA 7.x MTM for 4769) could allow a local user to cause a denial of service due to improper input validation. IBM X-Force ID: 223596.

  • CVE-2021-39045MedSep 1, 2022
    risk 0.36cvss 5.5epss 0.00

    IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a local attacker to obtain information due to the autocomplete feature on password input fields. IBM X-Force ID: 214345.

  • CVE-2021-39009MedSep 1, 2022
    risk 0.36cvss 5.5epss 0.00

    IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 stores user credentials in plain clear text which can be read by a local privileged user. IBM X-Force ID: 213554.

  • CVE-2021-3669MedAug 26, 2022
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segment counts which could lead to resource exhaustion and DoS.

  • CVE-2022-34164MedAug 1, 2022
    risk 0.36cvss 5.5epss 0.00

    IBM CICS TX 11.1 could allow a local user to impersonate another legitimate user due to improper input validation. IBM X-Force ID: 229338.

  • CVE-2022-22424MedJul 20, 2022
    risk 0.36cvss 5.5epss 0.00

    IBM QRadar SIEM 7.3, 7.4, and 7.5 could allow a local user to obtain sensitive information from the TLS key file due to incorrect file permissions. IBM X-Force ID: 223597.

  • CVE-2020-4138MedJul 11, 2022
    risk 0.36cvss 5.5epss 0.00

    IBM SiteProtector Appliance 3.1.1 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 174049.

  • CVE-2022-22367MedJul 1, 2022
    risk 0.36cvss 5.5epss 0.00

    IBM UrbanCode Deploy (UCD) 6.2.7.15, 7.0.5.10, 7.1.2.6, and 7.2.2.1 could disclose sensitive database information to a local user in plain text. IBM X-Force ID: 221008.

  • CVE-2022-22478MedJun 30, 2022
    risk 0.36cvss 5.5epss 0.00

    IBM Spectrum Protect Client 8.1.0.0 through 8.1.14.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 225886.

  • CVE-2022-22414MedJun 20, 2022
    risk 0.36cvss 5.5epss 0.00

    IBM Robotic Process Automation 21.0.2 could allow a local user to obtain sensitive web service configuration credentials from system memory. IBM X-Force ID: 223026.

  • CVE-2022-22444MedJun 15, 2022
    risk 0.36cvss 5.5epss 0.00

    IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a local user to exploit a vulnerability in the lpd daemon to cause a denial of service. IBM X-Force ID: 224444.

Page 66 of 177