Known vulnerabilities in IBM Cloud Application Performance Management (APM) - page 15

Software CPE: cpe:2.3:a:ibm_corporation:apm:*:*:*:*:*:*:*:*
Total vulnerabilities: 504
Public exploits: 30
Known exploited (KEV): 5
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting IBM Cloud Application Performance Management (APM) IBM Cloud Application Performance Management (APM) is affected by 504 known vulnerabilities: 2 critical, 125 high, 240 medium, 137 low Critical High Medium Low

Vulnerabilities (504)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU81098 - Improper input validation
CVE-2013-2186
CWE-20 High
No
No
8.1.4.0.14 25.09.2023 SB2013102803
SB2023092623
SB2023101310
and 3 more
#VU67586 - Server-Side Request Forgery (SSRF)
CVE-2022-38648
CWE-918 Medium
No
No
8.1.4.0.14 22.09.2022 SB2022092232
SB2023030742
SB2023040503
and 14 more
#VU67584 - Server-Side Request Forgery (SSRF)
CVE-2022-38398
CWE-918 Medium
No
No
8.1.4.0.14 22.09.2022 SB2022092232
SB2023030742
SB2023040503
and 14 more
#VU59098 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-44832
CWE-94 Medium
No
No
8.1.4.0.14 28.12.2021 SB2021122816
SB2021123002
SB2022010601
and 197 more
#VU59051 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2021-45105
CWE-835 Medium
Available
No
8.1.4.0.14 18.12.2021 SB2021121802
SB2021121903
SB2021122011
and 169 more
#VU58976 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-45046
CWE-94 High
Available
Exploited
8.1.4.0.14 15.12.2021 SB2021121504
SB2021121511
SB2021121512
and 178 more
#VU58816 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-44228
CWE-94 Critical
Available
Exploited
8.1.4.0.14 10.12.2021 SB2021121003
SB2021121101
SB2021121201
and 338 more
#VU54943 - UNIX Symbolic Link (Symlink) Following
CVE-2013-0248
CWE-61 Low
No
No
8.1.4.0.14 19.07.2021 SB2013031514
SB2021071906
SB2021120215
and 4 more
#VU52252 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-29425
CWE-22 Low
No
No
8.1.4.0.14 15.04.2021 SB2021041510
SB2021081922
SB2021093016
and 121 more
#VU27487 - Improper Certificate Validation
CVE-2020-9488
CWE-295 Low
No
No
8.1.4.0.14 04.05.2020 SB2020050406
SB2020071606
SB2020071620
and 67 more
#VU26493 - Deserialization of Untrusted Data
CVE-2020-10672
CWE-502 High
No
No
8.1.4.0.14 01.04.2020 SB2020030909
SB2020073033
SB2022060909
and 16 more
#VU26490 - Deserialization of Untrusted Data
CVE-2020-11113
CWE-502 High
Available
No
8.1.4.0.14 01.04.2020 SB2020030909
SB2020042318
SB2020073033
and 16 more
#VU22565 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2019-0205
CWE-835 Medium
No
No
8.1.4.0.14 06.11.2019 SB2019102916
SB2020031305
SB2021071503
and 12 more
#VU17780 - Improper input validation
CVE-2018-19360
CWE-20 High
No
No
8.1.4.0.14 19.02.2019 SB2018121501
SB2019052407
SB2019091718
and 22 more
#VU16954 - Exposure of sensitive information to an unauthorized actor
CVE-2018-1320
CWE-200 Low
No
No
8.1.4.0.14 13.01.2019 SB2019011106
SB2019080913
SB2022041520
and 4 more
#VU12842 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2017-12626
CWE-835 Low
No
No
8.1.4.0.14 18.05.2018 SB2018050312
SB2020011463
SB2020011481
and 24 more
#VU12312 - Deserialization of Untrusted Data
CVE-2016-1000031
CWE-502 High
No
No
8.1.4.0.14 01.05.2018 SB2017111432
SB2018110601
SB2019051512
and 39 more
#VU12127 - Deserialization of Untrusted Data
CVE-2017-5645
CWE-502 High
No
No
8.1.4.0.14 24.04.2018 SB2017040201
SB2019011707
SB2017090512
and 40 more
#VU5233 - Resource exhaustion
CVE-2014-0050
CWE-400 Medium
Available
No
8.1.4.0.14 23.01.2017 SB2014020601
SB2015092620
SB2014041701
and 12 more
#VU197 - Resource exhaustion
CVE-2016-3092
CWE-400 Medium
No
No
8.1.4.0.14 22.07.2016 SB2016070602
SB2016070203
SB2016063002
and 20 more


Showing elements 281 - 300 out of 504