ibm
8,202 tracked vulnerabilities.
CVE-2021-38960
HIGH
IBM Power System AC922 and HMC Firmware - Unauthenticated Exposure of Sensitive Information
Feb 04, 2022
CVSS 7.5
EPSS 0.00
CVE-2021-39021
MEDIUM
IBM Guardium Data Encryption 5.0.0.2 - Username Enumeration via Observable Discrepancy
Feb 02, 2022
CVSS 5.3
EPSS 0.00
CVE-2021-39070
CRITICAL
IBM Security Verify Access <10.0.2.0 - Privilege Escalation
Feb 02, 2022
CVSS 9.8
EPSS 0.01
CVE-2021-39066
HIGH
IBM Financial Transaction Manager 3.2.4 - Info Disclosure
Feb 02, 2022
CVSS 8.8
EPSS 0.00
CVE-2021-39044
HIGH
IBM Financial Transaction Manager 3.2.4 - Cross-Site Request Forgery
Feb 02, 2022
CVSS 8.8
EPSS 0.00
CVE-2021-29846
LOW
IBM Security Guardium Insights 3.0 - Authenticated Sensitive Information Exposure via Insufficient Session Expiration
Jan 26, 2022
CVSS 2.7
EPSS 0.00
CVE-2021-29845
HIGH
IBM Security Guardium Insights 3.0 - Authenticated Unauthorized Action via Improper Input Validation
Jan 26, 2022
CVSS 8.8
EPSS 0.00
CVE-2021-29838
MEDIUM
IBM Security Guardium Insights 3.0 - Exposure of Sensitive Information via Missing HSTS
Jan 26, 2022
CVSS 5.9
EPSS 0.00
CVE-2021-39031
HIGH
IBM WebSphere Application Server Liberty 17.0.0.3-22.0.0.1 - Authenticated LDAP Injection
Jan 25, 2022
CVSS 8.8
EPSS 0.00
CVE-2021-29785
MEDIUM
IBM Security SOAR <V44 - Info Disclosure
Jan 20, 2022
CVSS 5.9
EPSS 0.00
CVE-2021-29872
MEDIUM
IBM Cloud Pak for Automation 21.0.1-21.0.2 - HTTP Header Injection via HOST Header
Jan 18, 2022
CVSS 5.4
EPSS 0.00
CVE-2021-38965
HIGH
IBM FileNet Content Manager <5.5.8 - Command Injection
Jan 17, 2022
CVSS 8.8
EPSS 0.02
CVE-2021-39032
MEDIUM
IBM Sterling Gentran:Server for Microsoft Windows 5.3 - Sensitive Information Exposure in Log Files
Jan 14, 2022
CVSS 5.5
EPSS 0.00
CVE-2021-39056
MEDIUM
IBM i 7.1-7.4 - Authenticated Denial of Service in Extended Dynamic Remote SQL Server
Jan 13, 2022
CVSS 6.5
EPSS 0.00
CVE-2021-38991
HIGH
IBM AIX 7.0-7.2 and VIOS 3.1 - Local Code Execution via lscore Command
Jan 11, 2022
CVSS 7.8
EPSS 0.00
CVE-2021-29701
MEDIUM
IBM Engineering Workflow Management <7.0.2 - Info Disclosure
Jan 11, 2022
CVSS 4.3
EPSS 0.00
CVE-2021-38990
HIGH
IBM AIX 7.1, 7.2 and VIOS 3.1 - Local Code Execution via Mount Command
Jan 10, 2022
CVSS 7.8
EPSS 0.00
CVE-2021-38957
HIGH
IBM Security Verify <10.0.2.0 - Info Disclosure
Jan 10, 2022
CVSS 7.5
EPSS 0.00
CVE-2021-38956
MEDIUM
IBM Security Verify <10.0.2.0 - Info Disclosure
Jan 10, 2022
CVSS 5.3
EPSS 0.00
CVE-2021-38921
HIGH
IBM Security Verify <10.0.3 - Info Disclosure
Jan 10, 2022
CVSS 7.5
EPSS 0.00
CVE-2021-38895
MEDIUM
IBM Security Verify <10.0.2.0 - XSS
Jan 10, 2022
CVSS 5.4
EPSS 0.00
CVE-2021-38894
LOW
IBM Security Verify <10.0.3 - Info Disclosure
Jan 10, 2022
CVSS 2.7
EPSS 0.00
CVE-2021-38918
HIGH
IBM PowerVM Hypervisor - Privilege Escalation
Jan 05, 2022
CVSS 7.5
EPSS 0.00
CVE-2021-38876
MEDIUM
IBM i 7.2-7.4 - Cross-Site Scripting in Web UI
Dec 30, 2021
CVSS 6.1
EPSS 0.00
CVE-2021-38961
MEDIUM
IBM Power System AC922 Firmware - Stored Cross-Site Scripting in Web UI
Dec 27, 2021
CVSS 6.1
EPSS 0.00
Products
websphere_application_server 445
aix 393
db2 328
rational_quality_manager 202
sterling_b2b_integrator 195
infosphere_information_server 188
qradar_security_information_and_event_manager 187
maximo_asset_management 182
rational_doors_next_generation 153
rational_team_concert 142
rational_collaborative_lifecycle_management 141
rational_engineering_lifecycle_manager 141
websphere_portal 126
security_guardium 112
cognos_analytics 102
sterling_file_gateway 93
rational_rhapsody_design_manager 90
security_verify_access 90
websphere_mq 89
business_process_manager 88
lotus_domino 86
vios 85
rational_software_architect_design_manager 81
api_connect 79
lotus_notes 71
security_key_lifecycle_manager 70
db2_universal_database 66
concert 65
smartcloud_control_desk 65
urbancode_deploy 63
Quick Filters