ibm

8,320 tracked vulnerabilities.

CVE-2020-4252 MEDIUM
IBM DOORS Next Generation 6.0.2, 6.0.6, 6.0.61 - Cross-Site Scripting
Apr 08, 2020
CVSS 5.4
EPSS 0.01
CVE-2020-4164 LOW
IBM Security Information Queue 1.0.0-1.0.5 - Sensitive Information Exposure via Error Messages
Apr 08, 2020
CVSS 2.7
EPSS 0.01
CVE-2020-4273 HIGH
IBM Spectrum Scale <5.1 - Command Injection
Apr 03, 2020
CVSS 7.8
EPSS 0.00
CVE-2020-7621 CRITICAL
IBM StrongLoop Nginx Controller < 1.0.2 - OS Command Injection via _nginxCmd Function
Apr 02, 2020
CVSS 9.8
EPSS 0.03
CVE-2020-4325 MEDIUM
IBM Process Federation Server 18.0.0.1-19.0.0.3 - Denial of Service via Global Teams REST API Thread Pool Leak
Apr 02, 2020
CVSS 6.5
EPSS 0.01
CVE-2020-4304 MEDIUM
IBM WebSphere Application Server Liberty 17.0.0.3-20.0.0.3 - Cross-Site Scripting
Apr 02, 2020
CVSS 6.1
EPSS 0.01
CVE-2020-4303 MEDIUM
IBM WebSphere Application Server Liberty 17.0.0.3-20.0.0.3 - Cross-Site Scripting
Apr 02, 2020
CVSS 6.1
EPSS 0.01
CVE-2020-4242 HIGH
IBM Spectrum Scale and Spectrum Protect Plus 10.1.0-10.1.5 - Authenticated Remote Code Execution
Mar 31, 2020
CVSS 8.8
EPSS 0.05
CVE-2020-4241 HIGH
IBM Spectrum Scale and Spectrum Protect Plus 10.1.0-10.1.5 - Authenticated Remote Code Execution
Mar 31, 2020
CVSS 8.8
EPSS 0.66
CVE-2020-4240 MEDIUM
IBM Spectrum Protect Plus 10.1.0-10.1.5 - Path Traversal and Arbitrary File Write
Mar 31, 2020
CVSS 6.5
EPSS 0.02
CVE-2020-4239 MEDIUM
IBM Tivoli Netcool Impact 7.1.0.0-7.1.0.17 - Sensitive Information Exposure via Error Message
Mar 31, 2020
CVSS 5.3
EPSS 0.02
CVE-2020-4238 HIGH
IBM Tivoli Netcool Impact 7.1.0.0-7.1.0.17 - Cross-Site Request Forgery
Mar 31, 2020
CVSS 8.8
EPSS 0.01
CVE-2020-4237 HIGH
IBM Tivoli Netcool Impact 7.1.0.0-7.1.0.17 - Cross-Site Request Forgery
Mar 31, 2020
CVSS 8.8
EPSS 0.01
CVE-2020-4236 MEDIUM
IBM Tivoli Netcool Impact 7.1.0.0-7.1.0.17 - Authenticated Denial of Service in Project Management Module
Mar 31, 2020
CVSS 6.5
EPSS 0.01
CVE-2020-4235 MEDIUM
IBM Tivoli Netcool Impact 7.1.0.0-7.1.0.17 - Stored Cross-Site Scripting in Web UI
Mar 31, 2020
CVSS 5.4
EPSS 0.01
CVE-2020-4214 HIGH
IBM Spectrum Protect Plus 10.1.0-10.1.5 - Unauthenticated Arbitrary Directory Deletion via Improper Input Validation
Mar 31, 2020
CVSS 7.5
EPSS 0.02
CVE-2020-4208 CRITICAL
IBM Spectrum Protect Plus 10.1.0-10.1.5 - Use of Hard-coded Credentials
Mar 31, 2020
CVSS 9.8
EPSS 0.02
CVE-2020-4206 HIGH
IBM Spectrum Protect Plus 10.1.0-10.1.5 - Remote Code Execution via Improper Input Validation
Mar 31, 2020
CVSS 8.8
EPSS 0.05
CVE-2020-4276 HIGH
IBM WebSphere Application Server 7.0.0.0-7.0.0.45 - Privilege Escalation via SOAP Connector Token-Based Authentication
Mar 26, 2020
CVSS 7.5
EPSS 0.03
CVE-2020-4309 MEDIUM
IBM Content Navigator 3.0CD - Unauthenticated Exposure of Sensitive Information
Mar 24, 2020
CVSS 5.3
EPSS 0.01
CVE-2020-4253 HIGH
IBM Content Navigator 3.0CD - Insufficient Session Expiration
Mar 24, 2020
CVSS 8.8
EPSS 0.01
CVE-2020-4205 MEDIUM
IBM DataPower Gateway 2018.4.1.0-2018.4.1.8 - Authenticated Security Restriction Bypass via Revoked Certificate
Mar 19, 2020
CVSS 6.3
EPSS 0.01
CVE-2020-4203 MEDIUM
IBM DataPower Gateway <2018.4.1.9 - Info Disclosure
Mar 19, 2020
CVSS 4.9
EPSS 0.01
CVE-2020-4199 MEDIUM
IBM Tivoli Netcool/OMNIbus 8.1.0 - Cross-Site Request Forgery
Mar 18, 2020
CVSS 4.3
EPSS 0.00
CVE-2020-4162 MEDIUM
IBM InfoSphere Information Server 11.5 and 11.7 - Stored Cross-Site Scripting
Mar 10, 2020
CVSS 5.4
EPSS 0.01