Vulnerability index

Browse CVEs

228 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Tririga Application Platform MEDIUM 5.4
CVE-2016-0300

IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 might allow remote attackers to access arbitrary JSP …

Mitigation only
Fix from $1,600 2018-02-02
Tealeaf Customer Experience HIGH 8.1
CVE-2016-2983

IBM Tealeaf Customer Experience 8.7, 8.8, and 9.0.2 could allow a remote attacker under unusual circumstances to read operational data or TLS session…

Patch available
Fix from $1,950 2018-01-26
Engineering Requirements Management Doors MEDIUM 5.4
CVE-2017-1516

IBM Doors Web Access 9.5 and 9.6 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicio…

Fix: after 9.6.1.9
Fix from $1,600 2018-01-26
Db2 MEDIUM 6.5
CVE-2016-0215

IBM DB2 9.7, 10.1 before FP6, and 10.5 before FP8 on AIX, Linux, HP, Solaris and Windows allow remote authenticated users to cause a denial of servic…

Patch available
Fix from $1,600 2018-01-16
Algo Risk Application MEDIUM 5.4
CVE-2016-0207

IBM Algorithmics One-Algo Risk Application (ARA) 4.9.1 through 5.1.0 allows remote authenticated users to conduct clickjacking attacks via unspecifie…

Fix: after 5.1.0
Fix from $1,600 2018-01-16
Qradar Security Information And Event Manager HIGH 8.8
CVE-2017-1696

IBM QRadar 7.2 and 7.3 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted reques…

Patch available
Fix from $1,950 2017-12-20
Daeja Viewone HIGH 7.5
CVE-2017-1210

IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0.2 could allow an unauthenticated attacker to inject data into log files made to lo…

Mitigation only
Fix from $1,950 2017-10-24
Aix HIGH 7.3
CVE-2017-1541

A flaw in the AIX 5.3, 6.1, 7.1, and 7.2 JRE/SDK installp and updatep packages prevented the java.security, java.policy and javaws.policy files from …

Mitigation only
Fix from $1,950 2017-10-04
Api Connect MEDIUM 6.1
CVE-2017-1551

IBM API Connect 5.0.0.0 through 5.0.7.2 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a …

Patch available
Fix from $1,600 2017-09-25
Api Connect MEDIUM 6.5
CVE-2017-1556

IBM API Connect 5.0.7.0 through 5.0.7.2 is vulnerable to a regular expression attack that could allow an authenticated attacker to use a regex and ca…

Mitigation only
Fix from $1,600 2017-09-13
Db2 MEDIUM 5.9
CVE-2017-1519

IBM DB2 10.5 and 11.1 contains a denial of service vulnerability. A remote user can cause disruption of service for DB2 Connect Server setup with a p…

Patch available
Fix from $1,600 2017-09-12
Cognos Analytics MEDIUM 6.1
CVE-2017-1428

IBM Cognos Analytics 11.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web …

Patch available
Fix from $1,600 2017-08-29
1g L2 7 Slb HIGH 8.2
CVE-2017-3752

An industry-wide vulnerability has been identified in the implementation of the Open Shortest Path First (OSPF) routing protocol used on some Lenovo …

Fix: after 21.0.24.0
Fix from $1,950 2017-08-09
I HIGH 7.5
CVE-2017-1460

IBM i OSPF 6.1, 7.1, 7.2, and 7.3 is vulnerable when a rogue router spoofs its origin. Routing tables are affected by a missing LSA, which may lead t…

Mitigation only
Fix from $1,950 2017-07-31
Infosphere Master Data Management Server MEDIUM 6.5
CVE-2016-9717

HTTP Parameter Override is identified in the IBM Infosphere Master Data Management (MDM) 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 product. It enables a…

Patch available
Fix from $1,600 2017-07-31
Infosphere Master Data Management Server MEDIUM 5.7
CVE-2016-9719

IBM InfoSphere Master Data Management Server 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 could allow a remote attacker to hijack the clicking action of th…

Patch available
Fix from $1,600 2017-07-31
Security Guardium HIGH 7.5
CVE-2017-1267

IBM Security Guardium 10.0 and 10.1 processes patches, image backups and other updates without sufficiently verifying the origin and integrity of the…

Patch available
Fix from $1,950 2017-07-21
Websphere Mq MEDIUM 6.5
CVE-2017-1285

IBM WebSphere MQ 9.0.1 and 9.0.2 could allow an authenticated user with authority to send a specially crafted message that would cause a channel to r…

Patch available
Fix from $1,600 2017-07-12
Websphere Mq MEDIUM 6.5
CVE-2017-1236

IBM WebSphere MQ 9.0.2 could allow an authenticated user to potentially cause a denial of service by saving an incorrect channel status inquiry. IBM …

Mitigation only
Fix from $1,600 2017-07-06
Domino CRITICAL 9.8
CVE-2016-6087

IBM Domino 8.5 and 9.0 could allow an attacker to steal credentials using multiple sessions and large amounts of data using Domino TLS Key Exchange v…

Patch available
Fix from $2,300 2017-06-07
Maximo Asset Management HIGH 8.8
CVE-2016-9977

IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a remote attacker to hijack a user's session, caused by the failure to invalidate an existi…

Patch available
Fix from $1,950 2017-06-07
Websphere Cast Iron Solution HIGH 8.6
CVE-2016-9692

IBM WebSphere Cast Iron Solution 7.0.0 and 7.5.0.0 is vulnerable to External Service Interaction attack, caused by improper validation of user-suppli…

Patch available
Fix from $1,950 2017-05-05
Api Connect HIGH 7.3
CVE-2017-1161

IBM API Connect 5.0.6.0 could allow a remote attacker to execute arbitrary commands on the system, caused by improper validation of URLs for the Deve…

Mitigation only
Fix from $1,950 2017-04-17
Qradar Incident Forensics HIGH 8.8
CVE-2016-9726

IBM QRadar Incident Forensics 7.2 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-cra…

Patch available
Fix from $1,950 2017-03-07
Qradar Incident Forensics HIGH 8.5
CVE-2016-9727

IBM QRadar 7.2 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an at…

Patch available
Fix from $1,950 2017-03-07
Business Process Manager MEDIUM 6.1
CVE-2016-9693

IBM Business Process Manager 7.5, 8.0, and 8.5 has a file download capability that is vulnerable to a set of attacks. Ultimately, an attacker can cau…

Patch available
Fix from $1,600 2017-03-07
Aix MEDIUM 5.5
CVE-2016-8944

IBM AIX 7.1 and 7.2 allows a local user to open a file with a specially crafted argument that would crash the system. IBM APARs: IV91488, IV91487, IV…

Patch available
Fix from $1,600 2017-02-15
Bigfix Platform MEDIUM 6.5
CVE-2016-6084

IBM BigFix Platform could allow an attacker on the local network to crash the BES server using a specially crafted XMLSchema request.

Patch available
Fix from $1,600 2017-02-01
Powerkvm MEDIUM 6.5
CVE-2016-3044

The Linux kernel component in IBM PowerKVM 2.1 before 2.1.1.3-65.10 and 3.1 before 3.1.0.2 allows guest OS users to cause a denial of service (host O…

Mitigation only
Fix from $1,600 2016-12-01
Maximo Asset Management MEDIUM 5.3
CVE-2016-5987

IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5 before 7.5.0.10 IF4, and 7.6 before 7.6.0.5 IF3 allows remote attackers to obtain sensitive inf…

Patch available
Fix from $1,600 2016-11-30