Ibm
ibm
8,252 CVEs • 1,572 products
Products (1,572)
Click to collapseToggle
Products (1,572)
Click to collapse
CVEs (8,252)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ibm 9Doors Next Engineering Lifecycle ManagementEngineering Requirements Quality Assistant On Premises+6 moreJun 17, 2026 Mar 4, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cre...Show more |
1Ibm 9Doors Next Engineering Lifecycle ManagementEngineering Requirements Quality Assistant On Premises+6 moreJun 17, 2026 Mar 4, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cre...Show more |
1Ibm 9Doors Next Engineering Lifecycle ManagementEngineering Requirements Quality Assistant On Premises+6 moreJun 17, 2026 Mar 4, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cre...Show more |
IBM Security Verify Bridge contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of inter...Show more |
IBM Security Verify Bridge uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 196617. |
1Ibm 1Cloud Application Performance Management Jun 17, 2026 Mar 2, 2021 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 The IBM Application Performance Monitoring UI (IBM Cloud APM 8.1.4) allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 187975. |
1Ibm 1Cloud Application Performance Management Jun 17, 2026 Mar 2, 2021 N/A· v4 3.5 LOW· v3 3.5 LOW· v2 IBM Monitoring (IBM Cloud APM 8.1.4 ) could allow an authenticated user to modify HTML content by sending a specially crafted HTTP request to the APM UI, which could mislead another user. IBM X-Force ID: 187974. |
1Ibm 1Cloud Application Performance Management Jun 17, 2026 Mar 2, 2021 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 The IBM Cloud APM 8.1.4 server will issue a DNS request to resolve any hostname specified in the Cloud Event Management Webhook URL configuration definition. This could enable an authenticated user with admin authorizati...Show more |
IBM MQ 9.1 LTS, 9.2 LTS, and 9.1 CD AMQP Channels could allow an authenticated user to cause a denial of service due to an issue processing messages. IBM X-Force ID: 191747. |
IBM Planning Analytics 2.0 could allow a remote authenticated attacker to obtain information about an organization's internal structure by exposing sensitive information in HTTP repsonses. IBM X-Force ID: 192029. |
1Ibm 1Maximo For Civil Infrastructure Jun 17, 2026 Feb 18, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Maximo for Civil Infrastructure 7.6.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leadi...Show more |
1Ibm 1Maximo For Civil Infrastructure Jun 17, 2026 Feb 18, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 IBM Maximo for Civil Infrastructure 7.6.2 could allow a user to obtain sensitive information due to insecure storeage of authentication credentials. IBM X-Force ID: 196621. |
1Ibm 1Maximo For Civil Infrastructure Jun 17, 2026 Feb 18, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 IBM Maximo for Civil Infrastructure 7.6.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leadi...Show more |
1Ibm 1Maximo For Civil Infrastructure Jun 17, 2026 Feb 18, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 IBM Maximo for Civil Infrastructure 7.6.2 includes executable functionality (such as a library) from a source that is outside of the intended control sphere. IBM X-Force ID: 196619. |
1Ibm 1Websphere Application Server Jun 17, 2026 Feb 18, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 IBM WebSphere Application Server 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary fil...Show more |
IBM Jazz Reporting Service 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality p...Show more |
1Ibm 1Spectrum Protect Operations Center Jun 17, 2026 Feb 15, 2021 N/A· v4 4.8 MEDIUM· v3 2.3 LOW· v2 IBM Spectrum Protect Operations Center 7.1 and 8.1 is vulnerable to a denial of service, caused by a RPC that allows certain cache values to be set and dumped to a file. By setting a grossly large cache value and dumping...Show more |
1Ibm 1Spectrum Protect Operations Center Jun 17, 2026 Feb 15, 2021 N/A· v4 8.0 HIGH· v3 5.2 MEDIUM· v2 IBM Spectrum Protect Operations Center 7.1 and 8.1could allow a remote attacker to execute arbitrary code on the system, caused by improper parameter validation. By creating an unspecified servlet request with specially...Show more |
1Ibm 1Spectrum Protect Operations Center Jun 17, 2026 Feb 15, 2021 N/A· v4 5.4 MEDIUM· v3 4.8 MEDIUM· v2 IBM Spectrum Protect Operations Center 7.1 and 8.1 could allow a remote attacker to bypass authentication restrictions, caused by improper session validation . By using the configuration panel to obtain a valid session u...Show more |
1Ibm 1Security Verify Information Queue Jun 17, 2026 Feb 12, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IBM Security Verify Information Queue 1.0.6 and 1.0.7 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external compone...Show more |