Ibm
ibm
8,250 CVEs • 1,572 products
Products (1,572)
Click to collapseToggle
Products (1,572)
Click to collapse
CVEs (8,250)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
IBM CICS TX Standard and Advanced 11.1 could allow a remote attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 227980. |
1Ibm 3Robotic Process Automation Robotic Process Automation As A ServiceRobotic Process Automation For Cloud PakJun 17, 2026 Jun 24, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Robotic Process Automation 21.0.1 and 21.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentiall...Show more |
2Ibm Netapp3Cognos Analytics Oncommand InsightPlanning AnalyticsJun 17, 2026 Jun 24, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 IBM Planning Analytics 2.0 and IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the in...Show more |
2Ibm Netapp2Cognos Analytics Oncommand InsightJun 17, 2026 Jun 24, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 could allow a remote attacker to upload arbitrary files, caused by improper content validation. IBM X-Force ID: 211238. |
2Ibm Netapp2Cognos Analytics Oncommand InsightJun 17, 2026 Jun 24, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a low level user to obtain sensitive information from the details of the 'Cloud Storage' page for which they should not have access. IBM X-Force ID: 202682. |
IBM QRadar WinCollect Agent 10.0 and 10.0.1 could allow an attacker to obtain sensitive information due to missing best practices. IBM X-Force ID: 213549. |
1Ibm 1Robotic Process Automation Jun 17, 2026 Jun 20, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 IBM Robotic Process Automation 21.0.2 could allow a local user to obtain sensitive web service configuration credentials from system memory. IBM X-Force ID: 223026. |
1Ibm 1Curam Social Program Management Jun 17, 2026 Jun 20, 2022 N/A· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. |
1Ibm 1Curam Social Program Management Jun 17, 2026 Jun 20, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 218281. |
1Ibm 1Robotic Process Automation Jun 17, 2026 Jun 17, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 IBM Robotic Process Automation 20.10.0, 20.12.5, 21.0.0, 21.0.1, and 21.0.2 contains a vulnerability that could allow a user to obtain sensitive information due to information properly masked in the control center UI. IB...Show more |
1Ibm 1Spectrum Protect Operations Center Jun 17, 2026 Jun 17, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In some cases, an unsuccessful attempt to log into IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14.000 does not cause the administrator's invalid sign-on count to be incremented on the IBM Spectrum Protec...Show more |
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a local user to exploit a vulnerability in the lpd daemon to cause a denial of service. IBM X-Force ID: 224444. |
1Ibm 1Financial Transaction Manager Jun 17, 2026 Jun 15, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.2.0 through 3.2.9 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker...Show more |
1Ibm 1Spectrum Copy Data Management Jun 17, 2026 Jun 10, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.15.0 could allow a remote attacker to view product configuration information stored in PostgreSQL, which could be used in further attacks against the system. IBM X-Fo...Show more |
1Ibm 1Spectrum Copy Data Management Jun 17, 2026 Jun 10, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.15.0 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using some fields...Show more |
1Ibm 1Spectrum Copy Data Management Jun 17, 2026 Jun 10, 2022 N/A· v4 4.5 MEDIUM· v3 3.5 LOW· v2 IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.15.0 is vulnerable to reverse tabnabbing where it could allow a page linked to from within IBM Spectrum Copy Data Management to rewrite it. An administrator could ent...Show more |
1Ibm 1Spectrum Copy Data Management Jun 17, 2026 Jun 10, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 IBM Spectrum Copy Data Management 2.2.0.0through 2.2.15.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website t...Show more |
1Ibm 1Spectrum Copy Data Management Jun 17, 2026 Jun 10, 2022 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 IBM Spectrum Copy Data Management Admin 2.2.0.0 through 2.2.15.0 could allow a local attacker to bypass authentication restrictions, caused by the lack of proper session management. An attacker could exploit this vulnera...Show more |
1Ibm 1Sevone Network Performance Management Jun 17, 2026 Jun 7, 2022 N/A· v4 8.8 HIGH· v3 6.0 MEDIUM· v2 A vulnerability, which was classified as critical, has been found in SevOne Network Management System up to 5.7.2.22. This issue affects the Device Manager Page. An injection leads to privilege escalation. The attack may...Show more |
1Ibm 1Sevone Network Performance Management Jun 17, 2026 Jun 7, 2022 N/A· v4 8.8 HIGH· v3 6.0 MEDIUM· v2 A vulnerability classified as critical was found in SevOne Network Management System up to 5.7.2.22. This vulnerability affects the Alert Summary. The manipulation leads to sql injection. The attack can be initiated remo...Show more |