ibm

8,153 tracked vulnerabilities.

CVE-2024-49344 MEDIUM
IBM OpenPages with Watson <9.0 - Info Disclosure
Feb 20, 2025
CVSS 4.3
EPSS 0.00
CVE-2024-49337 MEDIUM
IBM OpenPages with Watson 8.3-8.3.0.2 - Authenticated HTML Injection in Workflow Email Notifications
Feb 20, 2025
CVSS 5.4
EPSS 0.00
CVE-2024-49782 MEDIUM
IBM OpenPages with Watson <9.0 - SSRF
Feb 20, 2025
CVSS 6.8
EPSS 0.00
CVE-2024-49780 MEDIUM
IBM OpenPages <9.0 - Path Traversal
Feb 20, 2025
CVSS 5.3
EPSS 0.00
CVE-2024-49355 MEDIUM
IBM OpenPages with Watson <9.0 - Info Disclosure
Feb 20, 2025
CVSS 5.3
EPSS 0.00
CVE-2024-43196 MEDIUM
IBM OpenPages with Watson <9.0 - Privilege Escalation
Feb 20, 2025
CVSS 4.3
EPSS 0.00
CVE-2024-45084 HIGH
IBM Cognos Controller <11.0.2 - Command Injection
Feb 19, 2025
CVSS 8.0
EPSS 0.00
CVE-2024-45081 MEDIUM
IBM Cognos Controller 11.0.0-11.0.1 FP3 & 11.1.0 - Privilege Escala...
Feb 19, 2025
CVSS 6.5
EPSS 0.00
CVE-2024-28780 MEDIUM
IBM Cognos Controller 11.0.0-11.0.1 FP3 and IBM Controller 11.1.0 - Use of a Broken or Risky Cryptographic Algorithm
Feb 19, 2025
CVSS 5.9
EPSS 0.00
CVE-2024-28777 HIGH
IBM Cognos Controller 11.0.0-11.0.1 FP3 and IBM Controller 11.1.0 - Deserialization of Untrusted Data
Feb 19, 2025
CVSS 8.8
EPSS 0.00
CVE-2024-28776 MEDIUM
IBM Cognos Controller 11.0.0-11.0.1 FP3 and IBM Controller 11.1.0 - Cross-Site Scripting
Feb 19, 2025
CVSS 5.4
EPSS 0.00
CVE-2024-52902 HIGH
IBM Cognos Controller 11.0.0-11.0.1 FP3 and IBM Controller 11.1.0 - Use of Hard-coded Credentials
Feb 19, 2025
CVSS 8.8
EPSS 0.00
CVE-2024-56463 MEDIUM
IBM QRadar SIEM 7.5 - Stored Cross-Site Scripting via Web UI
Feb 14, 2025
CVSS 4.8
EPSS 0.00
CVE-2024-56477 MEDIUM
IBM Power Hardware Management Console V10.3.1050.0 - Path Traversal
Feb 14, 2025
CVSS 6.5
EPSS 0.01
CVE-2024-52895 MEDIUM
IBM i 7.4-7.5 - Database Access Denial of Service via Capabilities Restriction Bypass
Feb 14, 2025
CVSS 6.5
EPSS 0.00
CVE-2024-55904 HIGH
IBM DevOps Deploy 8.0.0.0-8.0.1.4 and UrbanCode Deploy 7.0.0.0-7.0.5.25 - Authenticated OS Command Injection
Feb 14, 2025
CVSS 7.2
EPSS 0.01
CVE-2024-54176 MEDIUM
IBM DevOps Deploy <8.0.1.4, UCD <7.3.2 - Info Disclosure
Feb 08, 2025
CVSS 4.3
EPSS 0.00
CVE-2024-56467 LOW
IBM EntireX 11.1 - Sensitive Information Exposure via Detailed Technical Error Message
Feb 06, 2025
CVSS 3.3
EPSS 0.00
CVE-2024-54171 HIGH
IBM EntireX 11.1 - Authenticated XML External Entity Injection
Feb 06, 2025
CVSS 7.1
EPSS 0.00
CVE-2024-52892 MEDIUM
IBM Jazz for Service Management 1.1.3-1.1.3.23 - Unauthenticated Stored Cross-Site Scripting
Feb 06, 2025
CVSS 6.1
EPSS 0.01
CVE-2024-51450 CRITICAL
IBM Security Verify Directory 10.0.0-10.0.3 - Authenticated OS Command Injection
Feb 06, 2025
CVSS 9.1
EPSS 0.01
CVE-2024-49814 HIGH
IBM Security Verify Access Appliance <10.0.4 - Privilege Escalation
Feb 06, 2025
CVSS 7.8
EPSS 0.00
CVE-2024-49800 MEDIUM
IBM ApplinX 11.1 - Authenticated Cleartext Storage of Sensitive Information in Memory
Feb 06, 2025
CVSS 4.3
EPSS 0.00
CVE-2024-49798 MEDIUM
IBM ApplinX 11.1 - Sensitive Information Exposure via Detailed Error Messages
Feb 06, 2025
CVSS 4.3
EPSS 0.00
CVE-2024-49797 MEDIUM
IBM ApplinX 11.1 - Sensitive Information Exposure via Missing HTTP Strict Transport Security
Feb 06, 2025
CVSS 5.9
EPSS 0.00