Vulnerabilities > IBM > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-04-02 CVE-2023-27286 Unspecified vulnerability in IBM Aspera Cargo and Aspera Connect
IBM Aspera Cargo 4.2.5 and IBM Aspera Connect 4.2.5 are vulnerable to a buffer overflow, caused by improper bounds checking.
network
low complexity
ibm
critical
9.8
2023-03-21 CVE-2023-25684 Unspecified vulnerability in IBM Security KEY Lifecycle Manager
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 is vulnerable to SQL injection.
network
low complexity
ibm
critical
9.8
2023-03-03 CVE-2023-27290 Unspecified vulnerability in IBM Observability With Instana
Docker based datastores for IBM Instana (IBM Observability with Instana 239-0 through 239-2, 241-0 through 241-2, and 243-0) do not currently require authentication.
network
low complexity
ibm
critical
9.1
2023-02-17 CVE-2022-47986 Unspecified vulnerability in IBM Aspera Faspex 4.4.1/4.4.2
IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserialization flaw.
network
low complexity
ibm
critical
9.8
2023-02-12 CVE-2022-41731 Unspecified vulnerability in IBM Watson Knowledge Catalog on Cloud PAK for Data 4.5.0
IBM Watson Knowledge Catalog on Cloud Pak for Data 4.5.0 is vulnerable to SQL injection.
network
low complexity
ibm
critical
9.8
2023-02-03 CVE-2023-23477 Unspecified vulnerability in IBM Websphere Application Server 8.5/9.0
IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially crafted sequence of serialized objects.
network
low complexity
ibm
critical
9.8
2023-02-03 CVE-2022-22486 XXE vulnerability in IBM Tivoli Workload Scheduler 10.1/9.4/9.5
IBM Tivoli Workload Scheduler 9.4, 9.5, and 10.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data.
network
low complexity
ibm CWE-611
critical
9.1
2023-02-03 CVE-2022-38389 Unspecified vulnerability in IBM Tivoli Workload Scheduler 10.1/9.4/9.5
IBM Tivoli Workload Scheduler 9.4, 9.5, and 10.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data.
network
low complexity
ibm
critical
9.1
2023-01-11 CVE-2022-40615 Unspecified vulnerability in IBM Sterling Partner Engagement Manager 6.1.2/6.2.0/6.2.1
IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 is vulnerable to SQL injection.
network
low complexity
ibm
critical
9.8
2023-01-04 CVE-2022-22338 SQL Injection vulnerability in IBM Sterling B2B Integrator
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 is vulnerable to SQL injection.
network
low complexity
ibm CWE-89
critical
9.8