Ibm
ibm
8,252 CVEs • 1,572 products
Products (1,572)
Click to collapseToggle
Products (1,572)
Click to collapse
CVEs (8,252)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
IBM WebSphere Commerce Enterprise V7, V8, and V9 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentiall...Show more |
IBM Security Access Manager Appliance 9.0.3.1, 9.0.4.0 and 9.0.5.0 could allow unauthorized administration operations when Advanced Access Control services are running. IBM X-Force ID: 150998. |
1Ibm 2Flashsystem 840 Firmware Flashsystem 900 FirmwareNov 21, 2024 Oct 18, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 IBM FlashSystem 900 product GUI allows a specially crafted attack to bypass the authentication requirements of the system, resulting in the ability to remotely change the superuser password. This can be used by an attack...Show more |
1Ibm 2Infosphere Information Server Infosphere Information Server On CloudNov 21, 2024 Oct 18, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 IBM InfoSphere Information Server 11.7 is affected by a weak password encryption vulnerability that could allow a local user to obtain highly sensitive information. IBM X-Force ID: 141682. |
1Ibm 1Websphere Application Server Nov 21, 2024 Oct 16, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality pot...Show more |
1Ibm 1Security Key Lifecycle Manager Nov 21, 2024 Oct 15, 2018 N/A· v4 7.1 HIGH· v3 5.5 MEDIUM· v2 IBM Security Key Lifecycle Manager 2.5, 2.6, 2.7, and 3.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive inf...Show more |
1Ibm 1Security Key Lifecycle Manager Nov 21, 2024 Oct 15, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 IBM Security Key Lifecycle Manager 2.5, 2.6, 2.7, and 3.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../)...Show more |
IBM FileNet Content Manager 5.2.1 and 5.5.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or co...Show more |
1Ibm 1Websphere Application Server Nov 21, 2024 Oct 12, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to...Show more |
1Ibm 1Engineering Lifecycle Optimization Publishing Mar 25, 2025 Oct 12, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Rational Publishing Engine 6.0.5 and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially...Show more |
1Ibm 1Engineering Lifecycle Optimization Publishing Mar 25, 2025 Oct 12, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Rational Publishing Engine 6.0.5 and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially...Show more |
1Ibm 1Websphere Application Server Nov 21, 2024 Oct 12, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 IBM WebSphere Application Server 8.5 and 9.0 in IBM Cloud could allow a remote attacker to obtain sensitive information caused by improper handling of passwords. IBM X-Force ID: 150811. |
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially lea...Show more |
IBM BigFix Platform 9.5 - 9.5.9 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 123910. |
1Ibm 1Security Key Lifecycle Manager Nov 21, 2024 Oct 11, 2018 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 IBM Security Key Lifecycle Manager 2.7 and 3.0 could allow an unauthenticated user to restart the SKLM server due to missing authentication. IBM X-Force ID: 148424. |
1Ibm 1Security Key Lifecycle Manager Nov 21, 2024 Oct 11, 2018 N/A· v4 7.1 HIGH· v3 5.5 MEDIUM· v2 IBM Security Key Lifecycle Manager 2.6, 2.7, 3.0 could allow an authenticated user to obtain highly sensitive information or jeopardize system integrity due to improper authentication mechanisms. IBM X-Force ID: 147907. |
IBM Spectrum LSF 9.1.1 9.1.2, 9.1.3, and 10.1 could allow a local user to change their job user at job submission time due to improper file permission settings. IBM X-Force ID: 147439. |
1Ibm 2Platform Symphony Specturm SymphonyNov 21, 2024 Oct 11, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 IBM Spectrum Symphony 7.1.2 and 7.2.0.2 could allow an authenticated user to obtain sensitive user information such as passwords through the WebUI. IBM X-Force ID: 146343. |
IBM Spectrum Symphony 7.2.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to creden...Show more |
1Ibm 2Qlogic 20 Port 4/8 Gb San Switch Module Firmware Qlogic 4 Gb Fibre Channel Expansion Card FirmwareNov 21, 2024 Oct 10, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 The QLogic 4Gb Fibre Channel 5.5.2.6.0 and 4/8Gb SAN 7.10.1.20.0 modules for IBM BladeCenter have an undocumented support account with a support password, an undocumented diags account with a diags password, and an undoc...Show more |