ibm

8,173 tracked vulnerabilities.

CVE-2023-25684 MEDIUM
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, 4.1.1 - SQL Injection
Mar 21, 2023
CVSS 6.5
EPSS 0.00
CVE-2023-25923 LOW
IBM Security Guardium Key Lifecycle Manager 3.0-4.1.1 - Unauthenticated File Upload and DoS
Mar 21, 2023
CVSS 2.7
EPSS 0.00
CVE-2023-25686 MEDIUM
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 - Insufficiently Protected Credentials
Mar 21, 2023
CVSS 6.2
EPSS 0.00
CVE-2023-27874 CRITICAL
IBM Aspera Faspex 4.4.2 - Authenticated XML External Entity Injection
Mar 21, 2023
CVSS 9.9
EPSS 0.01
CVE-2023-27873 MEDIUM
IBM Aspera Faspex <4.4.2 - Info Disclosure
Mar 21, 2023
CVSS 6.5
EPSS 0.00
CVE-2023-27871 HIGH
IBM Aspera Faspex < 4.4.2 - SQL Injection
Mar 21, 2023
CVSS 7.5
EPSS 0.00
CVE-2023-25689 LOW
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, 4.1.1 - Path Traversal via URL Request
Mar 21, 2023
CVSS 2.7
EPSS 0.00
CVE-2023-25687 MEDIUM
IBM Security Guardium Key Lifecycle Manager 3.0-4.1.1 Sensitive Info Exposure via Log Files
Mar 21, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-27875 HIGH
IBM Aspera Faspex 5.0.4 - Improper Access Control
Mar 16, 2023
CVSS 7.5
EPSS 0.00
CVE-2023-22591 LOW
IBM Robotic Process Automation 21.0.1-21.0.7 and 23.0.0-23.0.1 - Insufficient Session Expiration
Mar 15, 2023
CVSS 3.9
EPSS 0.00
CVE-2023-25680 MEDIUM
IBM Robotic Process Automation 21.0.1-21.0.5 - Exposure of Sensitive Information in Queue Provider Credentials
Mar 15, 2023
CVSS 4.2
EPSS 0.00
CVE-2023-22876 MEDIUM
IBM Sterling B2B Integrator 6.0.0.0-6.0.3.7 and 6.1.0.0-6.1.2.1 - Authenticated Exposure of Sensitive Information
Mar 15, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-26284 HIGH
IBM MQ Certified Container <9.3.0.4 - Privilege Escalation
Mar 15, 2023
CVSS 7.5
EPSS 0.01
CVE-2023-24975 MEDIUM
IBM Spectrum Symphony 7.3 - HTTP Header Injection via HOST Header
Mar 10, 2023
CVSS 5.4
EPSS 0.00
CVE-2023-27290 CRITICAL
IBM Observability with Instana 239-0-239-2, 241-0-241-2, 243-0 - Unauthenticated Data Store Access
Mar 03, 2023
CVSS 9.1
EPSS 0.09
CVE-2023-26281 MEDIUM
IBM HTTP Server 8.5 - Denial of Service via Crafted URL
Mar 01, 2023
CVSS 5.9
EPSS 0.00
CVE-2023-22860 MEDIUM
IBM Cloud Pak for Business Automation 18.0.0-22.0.2 - Stored Cross-Site Scripting
Feb 27, 2023
CVSS 5.4
EPSS 0.00
CVE-2023-25928 MEDIUM
IBM InfoSphere Information Server 11.7 - Cross-Site Scripting
Feb 21, 2023
CVSS 4.6
EPSS 0.00
CVE-2023-24960 HIGH
IBM InfoSphere Information Server 11.7 - Path Traversal via Dot Dot Sequences
Feb 17, 2023
CVSS 7.5
EPSS 0.00
CVE-2023-24964 MEDIUM
IBM InfoSphere Information Server 11.7 - Sensitive Information Exposure via Log Files
Feb 17, 2023
CVSS 6.2
EPSS 0.00
CVE-2023-22868 MEDIUM
IBM Aspera Faspex 4.4.1 - Stored Cross-Site Scripting
Feb 17, 2023
CVSS 5.4
EPSS 0.01
CVE-2023-23475 MEDIUM
IBM Infosphere Information Server 11.7 - Stored Cross-Site Scripting
Feb 08, 2023
CVSS 4.6
EPSS 0.00
CVE-2023-23477 HIGH
IBM WebSphere Application Server 8.5 and 9.0 - Remote Code Execution via Serialized Objects
Feb 03, 2023
CVSS 8.1
EPSS 0.00
CVE-2023-23469 MEDIUM
IBM ICP4A - Automation Decision Services <22.0.2 - Info Disclosure
Feb 01, 2023
CVSS 4.0
EPSS 0.00
CVE-2023-22863 MEDIUM
IBM Robotic Process Automation 20.12.0-21.0.2 - Cleartext Transmission of Sensitive Information via Default HTTP
Jan 18, 2023
CVSS 5.9
EPSS 0.00