Ibm
ibm
8,250 CVEs • 1,572 products
Products (1,572)
Click to collapseToggle
Products (1,572)
Click to collapse
CVEs (8,250)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
IBM Security Verify Governance 10.0, Identity Manager could allow a local privileged user to obtain sensitive information from source code. IBM X-Force ID: 257769. |
IBM Directory Server for IBM i contains a local privilege escalation vulnerability. A malicious actor with command line access to the host operating system can elevate privileges to gain component access to the host ope...Show more |
1Ibm 1Qradar Security Information And Event Manager Jun 17, 2026 Oct 14, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 IBM QRadar SIEM 7.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials di...Show more |
1Ibm 1Qradar Security Information And Event Manager Jun 17, 2026 Oct 14, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 IBM QRadar SIEM 7.5.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 254138 |
1Ibm 2App Connect Enterprise Integration BusJun 17, 2026 Oct 14, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 IBM App Connect Enterprise 11.0.0.1 through 11.0.0.23, 12.0.1.0 through 12.0.10.0 and IBM Integration Bus 10.1 through 10.1.0.1 are vulnerable to a denial of service for integration nodes on Windows. IBM X-Force ID: 24...Show more |
1Ibm 1Cloud Pak For Business Automation Jun 17, 2026 Oct 14, 2023 N/A· v4 7.6 HIGH· v3 N/A· v2 IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 is vulnerable to cross-site scripting. This vulnerability allows us...Show more |
1Ibm 1Security Verify Access Oidc Provider Jun 17, 2026 Oct 14, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 IBM Security Verify Access OIDC Provider could disclose directory information that could aid attackers in further attacks against the system. IBM X-Force ID: 239445. |
1Ibm 1Security Verify Access Oidc Provider Jun 17, 2026 Oct 14, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 IBM Security Verify Access OIDC Provider could allow a remote user to cause a denial of service due to uncontrolled resource consumption. IBM X-Force ID: 238921. |
IBM Security Directory Server 6.4.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary file...Show more |
1Ibm 4Security Directory Integrator Security Directory ServerSecurity Directory Suite+1 moreJun 17, 2026 Oct 14, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 IBM Security Directory Server 6.4.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to...Show more |
1Ibm 3Security Directory Server Security Directory SuiteSecurity Verify DirectoryJun 17, 2026 Oct 14, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2 IBM Security Directory Server 6.4.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume m...Show more |
IBM App Connect Enterprise 12.0.1.0 through 12.0.8.0 contains an unspecified vulnerability that could allow a local privileged user to obtain sensitive information from API logs. IBM X-Force ID: 263833. |
IBM Security Directory Suite 8.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 228568. |
1Ibm 2Collaborative Lifecycle Management Engineering Lifecycle ManagementJun 17, 2026 Oct 6, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 IBM Jazz Foundation (IBM Engineering Lifecycle Management 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2) could disclose sensitive version information to a user that could be used in further attacks against the system. IBM X-For...Show more |
1Ibm 2Robotic Process Automation Robotic Process Automation For Cloud PakJun 17, 2026 Oct 6, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 IBM Robotic Process Automation 23.0.9 is vulnerable to privilege escalation that affects ownership of projects. IBM X-Force ID: 247527. |
1Ibm 2Storage Protect Storage Protect ClientJun 17, 2026 Oct 6, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 IBM Spectrum Protect Client and IBM Storage Protect for Virtual Environments 8.1.0.0 through 8.1.19.0 could allow a local user to execute arbitrary code on the system using a specially crafted file, caused by a DLL hijac...Show more |
IBM Content Navigator 3.0.11, 3.0.13, and 3.0.14 with IBM Daeja ViewOne Virtual is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the in...Show more |
IBM UrbanCode Deploy (UCD) 7.1 - 7.1.2.12, 7.2 through 7.2.3.5, and 7.3 through 7.3.2.0 under certain configurations could allow an authenticated user to make changes to environment variables due to improper authenticati...Show more |
IBM Security Guardium 11.5 could disclose sensitive information due to a missing or insecure SameSite attribute for a sensitive cookie. IBM X-Force ID: 240897. |
IBM Observability with Instana 1.0.243 through 1.0.254 could allow an attacker on the network to execute arbitrary code on the host after a successful DNS poisoning attack. IBM X-Force ID: 259789. |