Ibm
ibm
8,250 CVEs • 1,572 products
Products (1,572)
Click to collapseToggle
Products (1,572)
Click to collapse
CVEs (8,250)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web sit...Show more |
IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser w...Show more |
IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 is potentially vulnerable to Cross Site Scripting (XSS). A remote attacker could execute malicious commands due to improper validation of column he...Show more |
1Ibm 1Storage Defender Resiliency Service Jun 17, 2026 Dec 18, 2024 N/A· v4 5.7 MEDIUM· v3 N/A· v2 IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9
stores user credentials in plain text which can be read by an authenticated user with access to the pod. |
1Ibm 1Storage Defender Resiliency Service Jun 17, 2026 Dec 18, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9 does not properly validate a certificate which could allow an attacker to spoof a trusted entity by interfering in the communication path between the host and...Show more |
1Ibm 1Storage Defender Resiliency Service Jun 17, 2026 Dec 18, 2024 N/A· v4 4.9 MEDIUM· v3 N/A· v2 IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9
could allow a privileged user to obtain highly sensitive user credentials from secret keys that are stored in clear text. |
IBM i 7.4 and 7.5 is vulnerable to an authenticated user gaining elevated privilege to a physical file. A user with authority to a view can alter the based-on physical file security attributes without having object manag...Show more |
1Ibm 1Security Guardium Key Lifecycle Manager Jun 17, 2026 Dec 17, 2024 N/A· v4 3.7 LOW· v3 N/A· v2 IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker...Show more |
1Ibm 1Security Guardium Key Lifecycle Manager Jun 17, 2026 Dec 17, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information in cleartext in a communication channel that can be sniffed by unauthorized actors. |
1Ibm 1Security Guardium Key Lifecycle Manager Jun 17, 2026 Dec 17, 2024 N/A· v4 4.3 MEDIUM· v3 N/A· v2 IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This informatio...Show more |
1Ibm 1Security Guardium Key Lifecycle Manager Jun 17, 2026 Dec 17, 2024 N/A· v4 4.4 MEDIUM· v3 N/A· v2 IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 stores user credentials in configuration files which can be read by a local privileged user. |
1Ibm 1Security Guardium Key Lifecycle Manager Jun 17, 2026 Dec 17, 2024 N/A· v4 4.4 MEDIUM· v3 N/A· v2 IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 stores potentially sensitive information in log files that could be read by a local privileged user. |
IBM Storage Scale GUI 5.1.9.0 through 5.1.9.6 and 5.2.0.0 through 5.2.1.1 could allow a user to perform unauthorized actions after intercepting and modifying a csv file due to improper neutralization of formula elements. |
IBM Storage Scale GUI 5.1.9.0 through 5.1.9.6 and 5.2.0.0 through 5.2.1.1 contains a local privilege escalation vulnerability. A malicious actor with command line access to the 'scalemgmt' user can elevate privileges t...Show more |
1Ibm 1Infosphere Information Server Jun 17, 2026 Dec 12, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 IBM InfoSphere Information Server 11.7 could allow an authenticated user to GUI to not load or stop working due to improper input validation. |
1Ibm 1Infosphere Information Server Jun 17, 2026 Dec 11, 2024 N/A· v4 4.3 MEDIUM· v3 N/A· v2 IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information when a detailed technical error message is returned in a stack trace. This information could be used in further att...Show more |
1Ibm 1Infosphere Information Server Jun 17, 2026 Dec 11, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 IBM InfoSphere DataStage Flow Designer (InfoSphere Information Server 11.7) could allow an authenticated user to obtain sensitive information that could aid in further attacks against the system. |
IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain sensitive information due to improper encryption of certain data. |
IBM OpenPages with Watson 9.0 may write sensitive information, under specific configurations, in clear text to the system tracing log files that could be obtained by a privileged user. |
IBM Carbon Design System (Carbon Charts 0.4.0 through 1.13.16) is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the int...Show more |