Vulnerability index

Browse CVEs

228 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Bigfix Remote Control MEDIUM 6.5
CVE-2016-2937

IBM BigFix Remote Control before 9.1.3 allows remote attackers to obtain sensitive information or spoof e-mail transmission via a crafted POST reques…

Fix: after 9.1.2
Fix from $1,600 2016-11-30
Bigfix Remote Control MEDIUM 5.3
CVE-2016-2935

The broker application in IBM BigFix Remote Control before 9.1.3 allows remote attackers to cause a denial of service via an invalid HTTP request.

Fix: after 9.1.2
Fix from $1,600 2016-11-30
Security Privileged Identity Manager MEDIUM 6.5
CVE-2016-2996

IBM Security Privileged Identity Manager 2.0 before 2.0.2 FP8, when Virtual Appliance is used, allows remote authenticated users to append to arbitra…

Mitigation only
Fix from $1,600 2016-11-24
Tivoli Storage Productivity Center MEDIUM 5.7
CVE-2016-5947

IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to conduct clickjacking atta…

Patch available
Fix from $1,600 2016-09-26
Mq Appliance Firmware HIGH 8.8
CVE-2016-5879

MQCLI on IBM MQ Appliance M2000 and M2001 devices allows local users to execute arbitrary shell commands via a crafted (1) Disaster Recovery or (2) H…

Mitigation only
Fix from $1,950 2016-09-02
Emptoris Contract Management HIGH 7.5
CVE-2015-5042

IBM Emptoris Contract Management 9.5.0.x before 9.5.0.6 iFix15, 10.0.0.x and 10.0.1.x before 10.0.1.5 iFix5, 10.0.2.x before 10.0.2.7 iFix4, and 10.0…

Mitigation only
Fix from $1,950 2016-02-15
Tivoli Storage Manager MEDIUM 5.3
CVE-2015-4951

Client Acceptor Daemon (CAD) in the client in IBM Spectrum Protect (formerly Tivoli Storage Manager) 5.5 and 6.x before 6.3.2.5, 6.4 before 6.4.3.1, …

Patch available
Fix from $1,600 2016-01-20
Rational Quality Manager MEDIUM 6.8
CVE-2015-1928

Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.x and 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF11, and…

Mitigation only
Fix from $1,600 2016-01-02
Cognos Disclosure Management HIGH 9.3
CVE-2015-5014

IBM Cognos Disclosure Management (CDM) 10.1.x and 10.2.x before 10.2.4 IF10 allows man-in-the-middle attackers to obtain access by spoofing an execut…

Patch available
Fix from $1,950 2015-10-26
Db2 MEDIUM 6.8
CVE-2015-0157

IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and Windows allows remote authenticated users to cau…

Patch available
Fix from $1,600 2015-07-20
Tivoli Storage Manager Fastback HIGH 9.3
CVE-2015-1942EPSS 7%

The server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to write to arbitrary files, and subsequently execute the…

Mitigation only
Fix from $1,950 2015-06-30
Tririga Application Platform HIGH 7.5
CVE-2014-4840

IBM TRIRIGA Application Platform 3.2 and 3.3 before 3.3.0.2, 3.3.1 before 3.3.1.3, 3.3.2 before 3.3.2.2, and 3.4 before 3.4.0.1 allows remote attacke…

Mitigation only
Fix from $1,950 2014-10-19
Qradar Security Information And Event Manager MEDIUM 6.5
CVE-2014-4833

IBM Security QRadar SIEM QRM 7.1 MR1 and QRM/QVM 7.2 MR2 allows remote authenticated users to gain privileges via invalid input.

No fix yet
Fix from $1,600 2014-10-19
Websphere Application Server MEDIUM 5.0
CVE-2014-3021

IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.35, 8.0 before 8.0.0.10, and 8.5 before 8.5.5.4 does not properly handle HTTP headers, which …

Mitigation only
Fix from $1,600 2014-10-19
Sametime MEDIUM 5.0
CVE-2013-3980

The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to cause a denial of service (room unusability…

Mitigation only
Fix from $1,600 2014-05-26
Websphere Commerce HIGH 7.1
CVE-2014-0943

IBM WebSphere Commerce 6.0 Feature Pack 2 through Feature Pack 5, 7.0.0.0 through 7.0.0.8, and 7.0 Feature Pack 1 through Feature Pack 7 allows remot…

Mitigation only
Fix from $1,950 2014-05-25
Websphere Portal MEDIUM 6.8
CVE-2014-0954

IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, and 8.0 before 8.0.0.1 CF12 does not validate …

Patch available
Fix from $1,600 2014-05-22
Security Appscan HIGH 7.6
CVE-2014-0904

The update process in IBM Security AppScan Standard 7.9 through 8.8 does not require integrity checks of downloaded files, which allows remote attack…

Mitigation only
Fix from $1,950 2014-03-26
Sametime HIGH 7.5
CVE-2013-3983

The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 does not validate URLs in Cookie headers before using them in redire…

Mitigation only
Fix from $1,950 2014-02-14
Sametime MEDIUM 6.8
CVE-2013-3988

The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to conduct clickjacking attacks via unspecif…

Mitigation only
Fix from $1,600 2014-02-14
Global Security Kit HIGH 7.1
CVE-2013-6747

IBM GSKit 7.x before 7.0.4.48 and 8.x before 8.0.50.16, as used in IBM Security Directory Server (ISDS) and Tivoli Directory Server (TDS), allows rem…

Mitigation only
Fix from $1,950 2014-01-27
Atlas Ediscovery Process Management MEDIUM 6.4
CVE-2013-6334

IBM Atlas eDiscovery Process Management 6.0.1.5 and earlier and 6.0.2, Disposal and Governance Management for IT 6.0.1.5 and earlier and 6.0.2, and G…

Fix: after 6.0.1.5
Fix from $1,600 2014-01-10
I HIGH 8.5
CVE-2013-5385

The OSPF implementation in IBM i 6.1 and 7.1, in z/OS on zSeries servers, and in Networking Operating System (aka NOS, formerly BLADE Operating Syste…

Mitigation only
Fix from $1,950 2014-01-02
Spss Collaboration And Deployment Services MEDIUM 5.8
CVE-2013-4046

Open redirect vulnerability in IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote attackers to …

Mitigation only
Fix from $1,600 2013-12-21
Cognos Business Intelligence MEDIUM 5.0
CVE-2013-3030

The servlet gateway in IBM Cognos Business Intelligence 8.4.1 before IF3, 10.1.0 before IF4, 10.1.1 before IF4, 10.2.0 before IF4, 10.2.1 before IF2,…

Mitigation only
Fix from $1,600 2013-11-18
Tivoli Federated Identity Manager MEDIUM 5.8
CVE-2013-5431

Open redirect vulnerability in IBM Tivoli Federated Identity Manager (TFIM) 6.1.1 before IF 15, 6.2.0 before IF 14, 6.2.1, and 6.2.2 before IF 8 and …

Mitigation only
Fix from $1,600 2013-11-01
Storwize V7000 Unified Software MEDIUM 5.4
CVE-2013-0500

IBM Storwize V7000 Unified 1.3.x and 1.4.x before 1.4.2.0 does not properly handle device files that are created with the NFS protocol but accessed w…

Mitigation only
Fix from $1,600 2013-10-17
Db2 MEDIUM 5.0
CVE-2013-4032

The Fast Communications Manager (FCM) in IBM DB2 Enterprise Server Edition and Advanced Enterprise Server Edition 10.1 before FP3 and 10.5, when a mu…

Mitigation only
Fix from $1,600 2013-10-02
Websphere Application Server MEDIUM 6.8
CVE-2013-4053

The WS-Security implementation in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.31, 8.0 before 8.0.0.8, and 8.5 before…

Mitigation only
Fix from $1,600 2013-09-20
Global Console Manager 16 Firmware HIGH 8.5
CVE-2013-0526EPSS 6%

ping.php in Global Console Manager 16 (GCM16) and Global Console Manager 32 (GCM32) before 1.20.0.22575 on the IBM Avocent 1754 KVM switch allows rem…

Fix: after 1.18.0.22011
Fix from $1,950 2013-08-21