Vulnerabilities > IBM

DATE CVE VULNERABILITY TITLE RISK
2023-04-29 CVE-2023-30441 Unspecified vulnerability in IBM products
IBM Runtime Environment, Java Technology Edition IBMJCEPlus and JSSE 8.0.7.0 through 8.0.7.11 components could expose sensitive information using a combination of flaws and configurations.
network
low complexity
ibm
7.5
2023-04-29 CVE-2022-41736 Unspecified vulnerability in IBM Spectrum Scale Container Native Storage Access 5.1.2.1/5.1.4.1/5.1.6.0
IBM Spectrum Scale Container Native Storage Access 5.1.2.1 through 5.1.6.0 contains an unspecified vulnerability that could allow a local user to obtain root privileges.
local
low complexity
ibm
7.8
2023-04-29 CVE-2022-43871 Unspecified vulnerability in IBM Financial Transaction Manager for Multiplatform 3.2.4
IBM Financial Transaction Manager for SWIFT Services 3.2.4 is vulnerable to cross-site scripting.
network
low complexity
ibm
5.4
2023-04-28 CVE-2023-26021 Unspecified vulnerability in IBM DB2
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to a denial of service as the server may crash when compiling a specially crafted SQL query using a LIMIT clause.
network
low complexity
ibm
7.5
2023-04-28 CVE-2023-26022 Unspecified vulnerability in IBM DB2
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of service as the server may crash when an Out of Memory occurs using the DBMS_OUTPUT module.
network
low complexity
ibm
7.5
2023-04-28 CVE-2023-25930 Unspecified vulnerability in IBM DB2
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.1, 11.1, and 11.5 is vulnerable to a denial of service.
network
high complexity
ibm
5.9
2023-04-28 CVE-2023-27555 Unspecified vulnerability in IBM DB2
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5 is vulnerable to a denial of service when attempting to use ACR client affinity for unfenced DRDA federation wrappers.
network
low complexity
ibm
7.5
2023-04-28 CVE-2023-27864 Cross-site Scripting vulnerability in IBM Maximo Asset Management 7.6.1.2/7.6.1.3
IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 is vulnerable to HTML injection.
network
low complexity
ibm CWE-79
5.4
2023-04-28 CVE-2023-28528 Unspecified vulnerability in IBM AIX and Vios
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the invscout command to execute arbitrary commands.
local
low complexity
ibm
7.8
2023-04-28 CVE-2020-4729 Unspecified vulnerability in IBM Safer Payments
IBM Counter Fraud Management for Safer Payments 5.7.0.00 through 5.7.0.10, 6.0.0.00 through 6.0.0.07, 6.1.0.00 through 6.1.0.05, and 6.2.0.00 through 6.2.1.00 could allow an authenticated attacker under special circumstances to send multiple specially crafted API requests that could cause the application to crash.
network
high complexity
ibm
5.3