Vulnerabilities > IBM

DATE CVE VULNERABILITY TITLE RISK
2024-04-10 CVE-2024-31872 Unspecified vulnerability in IBM Security Verify Access
IBM Security Verify Access Appliance 10.0.0 through 10.0.7 could allow a malicious actor to conduct a man in the middle attack when deploying Open Source scripts due to missing certificate validation.
network
high complexity
ibm
8.1
2024-04-10 CVE-2024-31873 Unspecified vulnerability in IBM Security Verify Access
IBM Security Verify Access Appliance 10.0.0 through 10.0.7 contains hard-coded credentials which it uses for its own inbound authentication that could be obtained by a malicious actor.
network
low complexity
ibm
7.5
2024-04-10 CVE-2024-31874 Use of Uninitialized Resource vulnerability in IBM Security Verify Access
IBM Security Verify Access Appliance 10.0.0 through 10.0.7 uses uninitialized variables when deploying that could allow a local user to cause a denial of service.
local
low complexity
ibm CWE-908
5.5
2024-04-06 CVE-2024-22328 Unspecified vulnerability in IBM Maximo Application Suite 8.10/8.11
IBM Maximo Application Suite 8.10 and 8.11 could allow a remote attacker to traverse directories on the system.
network
low complexity
ibm
7.5
2024-04-04 CVE-2024-27268 Unspecified vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server Liberty 18.0.0.2 through 24.0.0.4 is vulnerable to a denial of service, caused by sending a specially crafted request.
network
low complexity
ibm
7.5
2024-04-03 CVE-2023-38729 Unspecified vulnerability in IBM DB2 10.5/11.1/11.5
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to sensitive information disclosure when using ADMIN_CMD with IMPORT or EXPORT.
network
low complexity
ibm
6.5
2024-04-03 CVE-2023-52296 Unspecified vulnerability in IBM DB2 11.5
IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to denial of service when querying a specific UDF built-in function concurrently.
network
high complexity
ibm
5.3
2024-04-03 CVE-2024-22360 Unspecified vulnerability in IBM DB2 11.5
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to a denial of service with a specially crafted query on certain columnar tables.
network
low complexity
ibm
6.5
2024-04-03 CVE-2024-25030 Unspecified vulnerability in IBM DB2 11.1
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 stores potentially sensitive information in log files that could be read by a local user.
local
low complexity
ibm
5.5
2024-04-03 CVE-2024-25046 Unspecified vulnerability in IBM DB2 11.1/11.5
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to a denial of service by an authenticated user using a specially crafted query.
network
low complexity
ibm
6.5