CISA Catalog
Data sourced from the official CISA Known Exploited Vulnerabilities Catalog. Federal agencies are required to remediate these vulnerabilities by the due date per BOD 22-01.
KEV Entries
1,660
Ransomware Use
335
Overdue
1,655
Vendors
276
Products
671
8 results · Page 1/1
IBM Langflow Code Injection Vulnerability
IBM · Langflow
Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.
Required Action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
IBM Aspera Faspex Code Execution Vulnerability
IBM · Aspera Faspex
IBM Aspera Faspex could allow a remote attacker to execute code on the system, caused by a YAML deserialization flaw.
Required Action
Apply updates per vendor instructions.
IBM InfoSphere BigInsights Invalid Input Vulnerability
IBM · InfoSphere BigInsights
Certain APIs within BigInsights can take invalid input that might allow attackers unauthorized access to read, write, modify, or delete data.
Required Action
The impacted product is end-of-life and should be disconnected if still in use.
IBM WebSphere Application Server and Server Hypervisor Edition Code Injection.
IBM · WebSphere Application Server and Server Hypervisor Edition
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands
Required Action
Apply updates per vendor instructions.
IBM Data Risk Manager Directory Traversal Vulnerability
IBM · Data Risk Manager
IBM Data Risk Manager contains a directory traversal vulnerability that could allow a remote authenticated attacker to traverse directories and send a specially crafted URL request to download arbitrary files from the system.
Required Action
Apply updates per vendor instructions.
IBM Data Risk Manager Security Bypass Vulnerability
IBM · Data Risk Manager
IBM Data Risk Manager contains a security bypass vulnerability that could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to bypass the authentication process and gain full administrative access to the system.
Required Action
Apply updates per vendor instructions.
IBM Data Risk Manager Remote Code Execution Vulnerability
IBM · Data Risk Manager
IBM Data Risk Manager contains an unspecified vulnerability which could allow a remote, authenticated attacker to execute commands on the system.�
Required Action
Apply updates per vendor instructions.
IBM Planning Analytics Remote Code Execution Vulnerability
IBM · Planning Analytics
IBM Planning Analytics is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting.
Required Action
Apply updates per vendor instructions.