Vulnerabilities > IBM > Critical

DATE CVE VULNERABILITY TITLE RISK
2022-06-06 CVE-2022-31768 SQL Injection vulnerability in IBM Infosphere Information Server 11.7
IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection.
network
low complexity
ibm CWE-89
critical
9.8
2022-05-24 CVE-2020-4926 Missing Authorization vulnerability in IBM Elastic Storage System and Spectrum Scale
A vulnerability in the Spectrum Scale 5.1 core component and IBM Elastic Storage System 6.1 could allow unauthorized access to user data or injection of arbitrary data in the communication protocol.
network
low complexity
ibm CWE-862
critical
9.1
2022-05-12 CVE-2022-22413 SQL Injection vulnerability in IBM Robotic Process Automation 21.0.0/21.0.1/21.0.2
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to SQL injection.
network
low complexity
ibm CWE-89
critical
9.8
2022-05-11 CVE-2021-38969 Use of Hard-coded Credentials vulnerability in IBM Spectrum Virtualize 8.2.0.0/8.3.0.0/8.4.0.0
IBM Spectrum Virtualize 8.2, 8.3, and 8.4 could allow an attacker to allow unauthorized access due to the reuse of support generated credentials.
network
low complexity
ibm CWE-798
critical
9.8
2022-04-27 CVE-2021-38869 Session Fixation vulnerability in IBM Qradar Security Information and Event Manager
IBM QRadar SIEM 7.3, 7.4, and 7.5 in some situations may not automatically log users out after they exceede their idle timeout.
network
low complexity
ibm CWE-384
critical
9.8
2022-04-22 CVE-2021-3849 An authentication bypass vulnerability was discovered in the web interface of the Lenovo Fan Power Controller2 (FPC2) and Lenovo System Management Module (SMM) firmware that could allow an unauthenticated attacker to execute commands on the SMM and FPC2.
network
low complexity
lenovo ibm
critical
9.8
2022-04-22 CVE-2021-3897 An authentication bypass vulnerability was discovered in an internal service of the Lenovo Fan Power Controller2 (FPC2) and Lenovo System Management Module (SMM) firmware during an that could allow an unauthenticated attacker to execute commands on the SMM and FPC2.
network
low complexity
lenovo ibm
critical
9.8
2022-03-28 CVE-2003-5001 Unspecified vulnerability in IBM ISS Blackice PC Protection
A vulnerability was found in ISS BlackICE PC Protection and classified as critical.
network
low complexity
ibm
critical
9.8
2022-03-24 CVE-2022-22374 Unspecified vulnerability in IBM Power 9 Ac922 Firmware
The BMC (IBM Power 9 AC922 OP910, OP920, OP930, and OP940) may be subject to a firmware downgrade attack which may affect its ability to operate its host.
network
low complexity
ibm
critical
9.1
2022-02-02 CVE-2021-39070 Unspecified vulnerability in IBM products
IBM Security Verify Access 10.0.0.0, 10.0.1.0 and 10.0.2.0 with the advanced access control authentication service enabled could allow an attacker to authenticate as any user on the system.
network
low complexity
ibm
critical
9.8