VendorsIBMcloud_pak_for_securityall versions
Vulnerabilities

IBM Cloud Pak

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

53CVEs
CVE-2021-20578
IBM Cloud Pak for Security (CP4S) 1.7.0.0, 1.7.1.0, 1.7.2.0, and 1.8.0.0 could allow an attacker to perform unauthorized actions due to improper or missing authentication controls. IBM X-Force ID: 199282.
Published 2021-09-30 · Modified
9.8EPSS 0.010
CVE-2025-25022
IBM QRadar Suite Software and IBM Cloud Pak for Security information disclosure
Published 2025-06-03 · Analyzed
9.6EPSS 0.003
CVE-2021-20538
IBM Cloud Pak for Security (CP4S) 1.5.0.0 and 1.5.0.1 could allow a user to obtain sensitive information or perform actions they should not have access to due to incorrect authorization mechanisms. IBM X-Force ID: 198919.
Published 2021-05-10 · Modified
9.1EPSS 0.007
CVE-2021-29696
IBM Cloud Pak for Security (CP4S) 1.5.0.0, 1.5.1.0, 1.6.0.0, 1.6.1.0, 1.7.0.0, and 1.7.1.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.
Published 2021-08-02 · Modified
9.0EPSS 0.025
CVE-2020-4627
IBM Cloud Pak for Security 1.3.0.1(CP4S) potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 185367.
Published 2020-11-30 · Modified
9.0EPSS 0.016
CVE-2022-38387
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.2.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 233786.
Published 2022-11-11 · Modified
8.8EPSS 0.009
CVE-2023-47726
IBM QRadar Suite improper input validation
Published 2024-06-18 · Analyzed
8.8EPSS 0.004
CVE-2022-38385
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.2.0 could allow an authenticated user to obtain highly sensitive information or perform unauthorized actions due to improper input validation. IBM X-Force ID: 233777.
Published 2022-11-11 · Modified
8.1EPSS 0.005
CVE-2021-29894
IBM Cloud Pak for Security (CP4S) 1.7.0.0, 1.7.1.0, 1.7.2.0, and 1.8.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 207320.
Published 2021-09-30 · Modified
7.5EPSS 0.007
CVE-2023-30993
IBM Cloud Pak for Security information disclosure
Published 2023-06-27 · Modified
7.5EPSS 0.006
CVE-2023-47728
IBM QRadar Suite Software information disclosure
Published 2024-08-16 · Modified
7.5EPSS 0.005
CVE-2024-28799
IBM QRadar Suite Software information disclosure
Published 2024-08-14 · Modified
7.5EPSS 0.003
CVE-2025-25021
IBM QRadar Suite Software and IBM Cloud Pak for Security code injection
Published 2025-06-03 · Analyzed
7.2EPSS 0.006
CVE-2021-39013
IBM Cloud Pak for Security (CP4S) 1.7.2.0, 1.7.1.0, and 1.7.0.0 could allow an authenticated user to obtain sensitive information in HTTP responses that could be used in further attacks against the system. IBM X-Force ID: 213651.
Published 2021-12-22 · Modified
6.5EPSS 0.008
CVE-2021-39089
IBM Cloud Pak for Security information disclosure
Published 2023-01-20 · Modified
6.5EPSS 0.007
CVE-2022-36777
IBM Cloud Pak for Security information disclosure
Published 2023-11-22 · Modified
6.5EPSS 0.006
CVE-2025-25020
IBM QRadar Suite Software and IBM Cloud Pak for Security improper input validation
Published 2025-06-03 · Analyzed
6.5EPSS 0.004
CVE-2024-28782
IBM QRadar Suite Software information disclosure
Published 2024-04-03 · Analyzed
6.5EPSS 0.004
CVE-2025-25019
IBM QRadar Suite Software and IBM Cloud Pak for Security session fixation
Published 2025-06-03 · Analyzed
6.5EPSS 0.003
CVE-2020-4820
IBM Cloud Pak for Security (CP4S) 1.4.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Published 2021-01-27 · Modified
6.1EPSS 0.007
CVE-2021-20577
IBM Cloud Pak for Security (CP4S) 1.5.0.0 and 1.5.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199281.
Published 2021-05-10 · Modified
6.1EPSS 0.006
CVE-2020-4816
IBM Cloud Pak for Security (CP4S) 1.4.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 189703.
Published 2021-01-27 · Modified
5.9EPSS 0.012
CVE-2021-20564
IBM Cloud Pak for Security (CP4S) 1.4.0.0, 1.5.0.0, 1.5.0.1, 1.6.0.0, and 1.6.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 199235.
Published 2021-05-14 · Modified
5.9EPSS 0.009
CVE-2022-38386
IBM Cloud Pak for Security information disclosure
Published 2024-05-01 · Analyzed
5.9EPSS 0.005
CVE-2021-39090
IBM Cloud Pak for Security information disclosure
Published 2024-02-29 · Analyzed
5.9EPSS 0.004
CVE-2024-22355
IBM QRadar Suite information dislosure
Published 2024-03-03 · Analyzed
5.9EPSS 0.004
CVE-2023-47742
IBM QRadar Suite information dislosure
Published 2024-03-03 · Analyzed
5.9EPSS 0.002
CVE-2024-22336
IBM QRadar Suite information disclosure
Published 2024-02-17 · Analyzed
5.5EPSS 0.002
CVE-2024-22335
IBM QRadar Suite information disclosure
Published 2024-02-17 · Analyzed
5.5EPSS 0.002
CVE-2024-22337
IBM QRadar Suite information disclosure
Published 2024-02-17 · Analyzed
5.5EPSS 0.002
CVE-2024-25024
IBM QRadar Suite Software information disclosure
Published 2024-08-15 · Modified
5.5EPSS 0.001
CVE-2024-25023
IBM QRadar Suite Software information disclosure
Published 2024-07-09 · Modified
5.5EPSS 0.001
CVE-2022-36776
IBM Cloud Pak for Security (CP4S) 1.10.0.0 79and 1.10.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 233663.
Published 2022-11-11 · Modified
5.4EPSS 0.004
CVE-2023-47731
IBM QRadar Suite Software cross-site scripting
Published 2024-04-23 · Analyzed
5.4EPSS 0.003
CVE-2020-4625
IBM Cloud Pak for Security 1.3.0.1(CP4S) could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from the cookie.
Published 2020-11-30 · Modified
5.3EPSS 0.015
CVE-2020-4628
IBM Cloud Pak for Security (CP4S) 1.3.0.1 and 1.4.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 185369.
Published 2021-01-27 · Modified
5.3EPSS 0.013
CVE-2020-4815
IBM Cloud Pak for Security (CP4S) 1.4.0.0 could allow a remote user to obtain sensitive information from HTTP response headers that could be used in further attacks against the system.
Published 2021-01-27 · Modified
5.3EPSS 0.013
CVE-2021-20539
IBM Cloud Pak for Security (CP4S) 1.5.0.0, 1.5.1.0, 1.6.0.0, 1.6.1.0, 1.7.0.0, and 1.7.1.0 could disclose sensitive information to an unauthorized user through HTTP GET requests. This information could be used in further attacks against the system. IBM X-Force ID: 198920.
Published 2021-08-02 · Modified
5.3EPSS 0.009
CVE-2021-20540
IBM Cloud Pak for Security (CP4S) 1.5.0.0, 1.5.1.0, 1.6.0.0, 1.6.1.0, 1.7.0.0, and 1.7.1.0 could disclose sensitive information to an unauthorized user through HTTP GET requests. This information could be used in further attacks against the system. IBM X-Force ID: 198923.
Published 2021-08-02 · Modified
5.3EPSS 0.009
CVE-2021-20541
IBM Cloud Pak for Security (CP4S) 1.5.0.0, 1.5.1.0, 1.6.0.0, 1.6.1.0, 1.7.0.0, and 1.7.1.0 could disclose sensitive information to an unauthorized user through HTTP GET requests. This information could be used in further attacks against the system. IBM X-Force ID: 198927.
Published 2021-08-02 · Modified
5.3EPSS 0.009
1 / 2Next →