Vulnerability index

Browse CVEs

228 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Websphere Commerce MEDIUM 6.4
CVE-2013-2994

IBM WebSphere Commerce 7.0 Feature Pack 4 and Feature Pack 5 incorrectly maintains a valid session after unspecified interaction with REST services, …

Mitigation only
Fix from $1,600 2013-08-01
Tivoli Monitoring MEDIUM 5.0
CVE-2013-0551

The Basic Services component in IBM Tivoli Monitoring (ITM) 6.2.0 through FP3, 6.2.1 through FP4, 6.2.2 through FP9, and 6.2.3 before FP3, as used in…

Mitigation only
Fix from $1,600 2013-06-21
Aix HIGH 7.1
CVE-2013-3035

The IPv6 implementation in the inet subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, allows remote attackers to cause a denial of serv…

Mitigation only
Fix from $1,950 2013-06-21
Sterling Multi Channel Fulfillment Solution MEDIUM 5.5
CVE-2013-0505

IBM Sterling Order Management 8.0 before HF127, 8.5 before HF89, 9.0 before HF69, 9.1.0 before FP41, and 9.2.0 before FP13 allows remote authenticate…

Mitigation only
Fix from $1,600 2013-03-19
Cognos Business Intelligence HIGH 9.3
CVE-2012-4858

IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 does not properly validate Java seria…

Mitigation only
Fix from $1,950 2013-03-05
Infosphere Information Server HIGH 7.1
CVE-2012-0705

InfoSphere Import Export Manager in InfoSphere Information Server MetaBrokers & Bridges (MBB) in IBM InfoSphere Information Server 8.1, 8.5 before FP…

Mitigation only
Fix from $1,950 2013-01-31
Infosphere Information Server MEDIUM 5.8
CVE-2012-0703

Open redirect vulnerability in Information Services Framework (ISF) in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 allows remote a…

Mitigation only
Fix from $1,600 2013-01-31
Security Appscan MEDIUM 5.8
CVE-2012-0738

IBM Security AppScan Enterprise before 8.6.0.2 and Rational Policy Tester before 8.5.0.3 do not validate X.509 certificates during scanning, which al…

Fix: after 8.6.0.1
Fix from $1,600 2012-12-28
Security Appscan MEDIUM 5.8
CVE-2012-0741

IBM Security AppScan Enterprise before 8.6.0.2 and Rational Policy Tester before 8.5.0.3 do not validate X.509 certificates during use of the Manual …

Fix: after 8.6.0.1
Fix from $1,600 2012-12-28
Websphere Application Server HIGH 7.5
CVE-2012-4850

IBM WebSphere Application Server 8.5 Liberty Profile before 8.5.0.1, when JAX-RS is used, does not properly validate requests, which allows remote at…

Mitigation only
Fix from $1,950 2012-11-14
Lotus Notes Traveler MEDIUM 5.8
CVE-2012-4824

Open redirect vulnerability in servlet/traveler in IBM Lotus Notes Traveler 8.5.3 before 8.5.3.3 Interim Fix 1 allows remote attackers to redirect us…

No fix yet
Fix from $1,600 2012-10-08
Tivoli Federated Identity Manager MEDIUM 5.8
CVE-2012-3314

IBM Tivoli Federated Identity Manager (TFIM) and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.1.1, 6.2.0, 6.2.1, and 6.2.2 allow rem…

Patch available
Fix from $1,600 2012-10-02
Websphere Application Server MEDIUM 6.0
CVE-2012-3325

IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.45, 7.0.x before 7.0.0.25, 8.0.x before 8.0.0.5, and 8.5.x Full Profile before 8.5.0.1, whe…

Mitigation only
Fix from $1,600 2012-08-30
Global Security Kit MEDIUM 5.0
CVE-2012-2191

IBM Global Security Kit (aka GSKit) before 8.0.14.22, as used in IBM Rational Directory Server, IBM Tivoli Directory Server, and other products, does…

Fix: after 8.0.13
Fix from $1,600 2012-08-08
Security Appscan Source MEDIUM 5.8
CVE-2012-2159

Open redirect vulnerability in IBM Eclipse Help System (IEHS), as used in IBM Security AppScan Source 7.x and 8.x before 8.6 and IBM SPSS Data Collec…

Mitigation only
Fix from $1,600 2012-06-20
Rational Appscan HIGH 9.3
CVE-2012-0736

IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 does not properly create scan jobs, which allows remote attackers to execute arbitrary cod…

Mitigation only
Fix from $1,950 2012-05-03
Rational Appscan HIGH 7.6
CVE-2012-0735

IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 does not properly scan file: URLs, which allows man-in-the-middle attackers to obtain sens…

Mitigation only
Fix from $1,950 2012-05-03
Db2 MEDIUM 5.0
CVE-2012-0710

IBM DB2 9.1 before FP11, 9.5 before FP9, 9.7 before FP5, and 9.8 before FP4 allows remote attackers to cause a denial of service (daemon crash) via a…

Mitigation only
Fix from $1,600 2012-03-20
Websphere Application Server MEDIUM 5.0
CVE-2012-0193

IBM WebSphere Application Server (WAS) 6.0 through 6.0.2.43, 6.1 before 6.1.0.43, 7.0 before 7.0.0.23, and 8.0 before 8.0.0.3 computes hash values fo…

Patch available
Fix from $1,600 2012-01-20
Tivoli Federated Identity Manager MEDIUM 5.0
CVE-2008-7299

IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.2 uses an incomplete SAML 1.x browser-artifact, which allows remote OpenID providers …

Mitigation only
Fix from $1,600 2011-08-12
Websphere Application Server MEDIUM 5.8
CVE-2011-1355

Open redirect vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.39 and 7.0 before 7.0.0.19 allows remote attackers to redirect…

Mitigation only
Fix from $1,600 2011-07-19
Rational Doors Web Access HIGH 10.0
CVE-2011-2681

IBM Rational DOORS Web Access 1.4.x before 1.4.0.4 does not properly handle exceptions, which has unspecified impact and remote attack vectors.

Mitigation only
Fix from $1,950 2011-07-07
Websphere Application Server MEDIUM 6.8
CVE-2011-1320

The Security component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.35 and 7.x before 7.0.0.15, when the Tivoli Integrated Portal /…

Mitigation only
Fix from $1,600 2011-03-08
Websphere Application Server HIGH 7.5
CVE-2011-1309

The Plug-in component in IBM WebSphere Application Server (WAS) before 7.0.0.15 does not properly handle trace requests, which has unspecified impact…

Fix: after 7.0.0.13
Fix from $1,950 2011-03-08
Lotus Notes HIGH 9.3
CVE-2011-0912

Argument injection vulnerability in IBM Lotus Notes 8.0.x before 8.0.2 FP6 and 8.5.x before 8.5.1 FP5 allows remote attackers to execute arbitrary co…

Mitigation only
Fix from $1,950 2011-02-08
Lotus Notes Traveler MEDIUM 5.0
CVE-2010-4553

An unspecified Domino API in IBM Lotus Notes Traveler before 8.5.1.1 does not properly handle MIME types, which allows remote attackers to cause a de…

Fix: after 8.5.0.2
Fix from $1,600 2010-12-16
Lotus Notes Traveler MEDIUM 5.0
CVE-2010-4550

IBM Lotus Notes Traveler before 8.5.1.3 allows remote attackers to cause a denial of service (sync failure) via a malformed document.

Fix: after 8.5.1.2
Fix from $1,600 2010-12-16
Websphere Application Server MEDIUM 5.0
CVE-2010-0786

The Web Services Security component in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.13 does not properly implement the Java API for XML We…

Mitigation only
Fix from $1,600 2010-11-09
Tivoli Storage Manager Fastback MEDIUM 5.0
CVE-2010-3756

The _CalcHashValueWithLength function in FastBackServer.exe in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.…

Mitigation only
Fix from $1,600 2010-10-05
Filenet P8 Application Engine MEDIUM 5.8
CVE-2010-3473

Open redirect vulnerability in the Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 3.5.1 before 3.5.1-021 allows remote atta…

Mitigation only
Fix from $1,600 2010-09-20