Known vulnerabilities in IBM API Connect 10.0.8.2 ifix2 - page 3

Version: 10.0.8.2 ifix2
Software CPE: cpe:2.3:a:ibm_corporation:ibm_api_connect:*:*:*:*:*:*:*:*
Total vulnerabilities: 160
Public exploits: 11
Known exploited (KEV): 5
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting IBM API Connect version 10.0.8.2 ifix2 IBM API Connect 10.0.8.2 ifix2 is affected by 160 vulnerabilities: 3 critical, 19 high, 40 medium, 98 low Critical High Medium Low

Vulnerabilities (160)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU103502 - Use After Free
CVE-2022-49043
CWE-416 Medium
No
No
10.0.8.5 03.02.2025 SB2025020327
SB2025020330
SB2025020353
and 60 more
#VU101868 - Resource exhaustion
CVE-2024-45338
CWE-400 Medium
No
No
10.0.8.5 19.12.2024 SB2024121932
SB2024123101
SB2025010619
and 137 more
#VU99965 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2024-50345
CWE-601 Low
No
No
10.0.8.5 06.11.2024 SB2024110649
SB2024111157
SB2025021846
and 4 more
#VU97826 - Resource Management Errors
CVE-2024-46820
CWE-399 Low
No
No
10.0.8.5 30.09.2024 SB2024093077
SB2025020313
SB2025112543
and 1 more
#VU97801 - NULL Pointer Dereference
CVE-2024-46857
CWE-476 Low
No
No
10.0.8.5 30.09.2024 SB2024093053
SB2024100401
SB2024101070
and 19 more
#VU95073 - Resource Management Errors
CVE-2024-41082
CWE-399 Low
No
No
10.0.8.5 31.07.2024 SB20240731156
SB2024090668
SB2024090669
and 32 more
#VU94280 - Improper Locking
CVE-2024-40918
CWE-667 Low
No
No
10.0.8.5 13.07.2024 SB2024071380
SB2024072670
SB2024091144
and 7 more
#VU92341 - NULL Pointer Dereference
CVE-2024-38608
CWE-476 Low
No
No
10.0.8.5 20.06.2024 SB2024062061
SB2024070973
SB2024071103
and 36 more
#VU92331 - Out-of-bounds read
CVE-2024-38540
CWE-125 Low
No
No
10.0.8.5 20.06.2024 SB2024062051
SB2024070973
SB2024071103
and 39 more
#VU92262 - Exposure of sensitive information to an unauthorized actor
CVE-2024-37891
CWE-200 Low
No
No
10.0.8.5 19.06.2024 SB2024061955
SB20240625146
SB2024062605
and 194 more
#VU90791 - Improper Locking
CVE-2024-26726
CWE-667 Low
No
No
10.0.8.5 03.06.2024 SB2024060391
SB2024070850
SB2024070851
and 24 more
#VU90565 - NULL Pointer Dereference
CVE-2022-48646
CWE-476 Low
No
No
10.0.8.5 31.05.2024 SB20240531467
SB20240711188
SB20240711224
and 2 more
#VU87734 - Resource exhaustion
CVE-2024-28863
CWE-400 Medium
No
No
10.0.8.5 22.03.2024 SB2024032234
SB2024052306
SB2024061114
and 30 more
#VU87551 - Exposure of sensitive information to an unauthorized actor
CVE-2024-28849
CWE-200 Low
No
No
10.0.8.5 15.03.2024 SB2024031508
SB2024031517
SB2024040365
and 59 more
#VU85369 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2023-26159
CWE-601 Low
No
No
10.0.8.5 15.01.2024 SB2024011510
SB2024011517
SB2024011864
and 53 more
#VU83992 - Use of Insufficiently Random Values
CVE-2020-36732
CWE-330 Medium
No
No
10.0.8.5 08.12.2023 SB2023120804
SB2024030742
SB2025091116
and 26 more
#VU81322 - Exposure of sensitive information to an unauthorized actor
CVE-2023-43804
CWE-200 Low
Public exploit available
No
10.0.8.5 02.10.2023 SB2023100251
SB2023100259
SB2023100260
and 112 more
#VU77526 - Permissions, Privileges, and Access Controls
CVE-2023-2728
CWE-264 Medium
Public exploit available
No
10.0.8.5 19.06.2023 SB2023061947
SB2023061950
SB2023061951
and 15 more
#VU77525 - Permissions, Privileges, and Access Controls
CVE-2023-2727
CWE-264 Medium
No
No
10.0.8.5 19.06.2023 SB2023061947
SB2023061950
SB2023061951
and 15 more
#VU64275 - Deserialization of Untrusted Data
CVE-2022-28948
CWE-502 Medium
No
No
10.0.8.5 14.06.2022 SB2022061420
SB2022061421
SB2022080821
and 15 more


Showing elements 41 - 60 out of 160