Ibm
ibm
8,250 CVEs • 1,572 products
Products (1,572)
Click to collapseToggle
Products (1,572)
Click to collapse
CVEs (8,250)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to an information disclosure in some scenarios due to unauthorized access caused by improper privilege management when CREATE OR REPLACE c...Show more |
IBM Control Desk 7.6.1 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information fro...Show more |
IBM Control Desk 7.6.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site t...Show more |
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.9 are vulnerable to HTTP header injection, caused by improper validation. This could allow an a...Show more |
IBM Planning Analytics Local 2.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 217371. |
2Ibm Netapp2Cognos Analytics Oncommand InsightJun 17, 2026 Sep 1, 2022 N/A· v4 8.1 HIGH· v3 N/A· v2 IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information...Show more |
2Ibm Netapp2Cognos Analytics Oncommand InsightJun 17, 2026 Sep 1, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to a denial of service via email flooding caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the serve...Show more |
2Ibm Netapp2Cognos Analytics Oncommand InsightJun 17, 2026 Sep 1, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a local attacker to obtain information due to the autocomplete feature on password input fields. IBM X-Force ID: 214345. |
2Ibm Netapp2Cognos Analytics Oncommand InsightJun 17, 2026 Sep 1, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 stores user credentials in plain clear text which can be read by a local privileged user. IBM X-Force ID: 213554. |
2Ibm Netapp2Cognos Analytics Oncommand InsightJun 17, 2026 Sep 1, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM...Show more |
2Ibm Netapp2Cognos Analytics Oncommand InsightJun 17, 2026 Sep 1, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM...Show more |
2Ibm Netapp2Cognos Analytics Oncommand InsightJun 17, 2026 Sep 1, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM...Show more |
IBM Security Identity Manager 6.0 and 6.0.2 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could...Show more |
1Ibm 2Engineering Test Management Rational Quality ManagerJun 17, 2026 Aug 29, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 IBM Engineering Test Management 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality poten...Show more |
IBM Maximo Asset Management 7.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cr...Show more |
IBM DataPower Gateway V10CD, 10.0.1, and 2018.4.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. I...Show more |
5Debian FedoraprojectIbm+2 more23Build Of Quarkus Codeready Linux BuilderDebian Linux+20 moreJun 17, 2026 Aug 26, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segment counts which could lead to resource exhaustion and DoS. |
1Ibm 4Hardware Management Console 7063 Cr2 Firmware Power System Ac922 (8335 Gtg) FirmwarePower System Ac922 (8335 Gth) Firmware+1 moreJun 17, 2026 Aug 22, 2022 N/A· v4 4.9 MEDIUM· v3 N/A· v2 IBM OPENBMC OP910 and OP940 could allow a privileged user to upload an improper site identity certificate that may cause it to lose network services. IBM X-Force ID: 207221. |
IBM MQ 8.0, (9.0, 9.1, 9.2 LTS), and (9.1 and 9.2 CD) are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive infor...Show more |
IBM Security Verify Governance Identity Manager 10.0 virtual appliance component performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the co...Show more |