Vulnerabilities > IBM > Critical

DATE CVE VULNERABILITY TITLE RISK
2019-04-08 CVE-2019-4155 Unspecified vulnerability in IBM API Connect
IBM API Connect's Developer Portal 2018.1 and 2018.4.1.3 is impacted by a privilege escalation vulnerability when integrated with an OpenID Connect (OIDC) user registry.
network
low complexity
ibm
critical
9.8
2019-03-05 CVE-2019-4032 SQL Injection vulnerability in IBM Financial Transaction Manager
IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.1.0 is vulnerable to SQL injection.
network
low complexity
ibm CWE-89
critical
9.8
2019-02-21 CVE-2018-1944 Use of Hard-coded Credentials vulnerability in IBM Security Identity Governance and Intelligence
IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
network
low complexity
ibm CWE-798
critical
9.8
2019-02-15 CVE-2019-4059 Insufficiently Protected Credentials vulnerability in IBM Rational Clearcase
IBM Rational ClearCase 1.0.0.0 GIT connector does not sufficiently protect the document database password.
network
low complexity
ibm CWE-522
critical
9.8
2019-02-15 CVE-2018-1727 XXE vulnerability in IBM Infosphere Information Server
IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data.
network
low complexity
ibm CWE-611
critical
9.1
2019-02-07 CVE-2019-4008 Information Exposure Through Log Files vulnerability in IBM API Connect
API Connect V2018.1 through 2018.4.1.1 is impacted by access token leak.
network
low complexity
ibm CWE-532
critical
9.8
2019-01-14 CVE-2018-1969 Unrestricted Upload of File with Dangerous Type vulnerability in IBM Security Identity Manager
IBM Security Identity Manager 6.0.0 allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment.
network
low complexity
ibm CWE-434
critical
9.9
2018-12-20 CVE-2018-1784 Unspecified vulnerability in IBM API Connect
IBM API Connect 5.0.0.0 and 5.0.8.4 is affected by a NoSQL Injection in MongoDB connector for the LoopBack framework.
network
low complexity
ibm
critical
9.8
2018-12-13 CVE-2018-1821 XXE vulnerability in IBM Operational Decision Manager
IBM Operational Decision Management 8.5, 8.6, 8.7, 8.8, and 8.9 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data.
network
low complexity
ibm CWE-611
critical
9.1
2018-12-13 CVE-2018-1818 Use of Hard-coded Credentials vulnerability in IBM Security Guardium
IBM Security Guardium 10 and 10.5 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
network
low complexity
ibm CWE-798
critical
9.8