Vulnerability index

Browse CVEs

228 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Filenet Content Manager MEDIUM 6.8
CVE-2010-3320

Open redirect vulnerability in IBM Records Manager (RM) 4.5.x before 4.5.1.1-IER-FP001 allows remote attackers to redirect users to arbitrary web sit…

Mitigation only
Fix from $1,600 2010-09-13
Websphere Application Server HIGH 10.0
CVE-2010-3186

IBM WebSphere Application Server (WAS) 7.x before 7.0.0.13, and WebSphere Application Server Feature Pack for Web Services 6.1.0.9 through 6.1.0.32, …

Mitigation only
Fix from $1,950 2010-08-30
Communications Server MEDIUM 5.0
CVE-2010-2090

The npb_protocol_error function in sna V5router64 in IBM Communications Server for Windows 6.1.3 and Communications Server for AIX (aka CSAIX or CS/A…

Mitigation only
Fix from $1,600 2010-05-27
Websphere Application Server MEDIUM 5.0
CVE-2010-0776

The Web Container in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.43, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.11 does not properly handl…

Mitigation only
Fix from $1,600 2010-05-17
Tivoli Directory Server MEDIUM 5.0
CVE-2010-0312

The do_extendedOp function in ibmslapd in IBM Tivoli Directory Server (TDS) 6.2 on Linux allows remote attackers to cause a denial of service (NULL p…

No fix yet
Fix from $1,600 2010-01-14
Db2 MEDIUM 6.4
CVE-2009-4325

The Client Interfaces component in IBM DB2 8.2 before FP18, 9.1 before FP8, 9.5 before FP5, and 9.7 before FP1 does not validate an unspecified point…

Patch available
Fix from $1,600 2009-12-16
Db2 MEDIUM 5.0
CVE-2009-4327

The Common Code Infrastructure component in IBM DB2 9.5 before FP5 and 9.7 before FP1 does not properly validate the size of a memory pool during a c…

Patch available
Fix from $1,600 2009-12-16
Tivoli Identity Manager MEDIUM 6.8
CVE-2009-2583

Multiple session fixation vulnerabilities in IBM Tivoli Identity Manager (ITIM) 5.0.0.6 allow remote attackers to hijack web sessions via unspecified…

Patch available
Fix from $1,600 2009-07-23
Websphere Application Server HIGH 10.0
CVE-2009-1172

The JAX-RPC WS-Security runtime in the Web Services Security component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 and 7.0 before 7…

Patch available
Fix from $1,950 2009-03-31
Director MEDIUM 5.0
CVE-2009-0879EPSS 8%

The CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows remote attackers to cause a denial of service (daemon crash) via a lo…

Fix: after 5.20.3
Fix from $1,600 2009-03-12
Websphere Application Server HIGH 10.0
CVE-2008-4283

CRLF injection vulnerability in the WebContainer component in IBM WebSphere Application Server (WAS) 5.1.1.19 and earlier 5.1.x versions allows remot…

Fix: after 5.1.1.19
Fix from $1,950 2009-02-10
Db2 Universal Database MEDIUM 5.0
CVE-2009-0172EPSS 8%

Unspecified vulnerability in IBM DB2 8 before FP17a, 9.1 before FP6a, and 9.5 before FP3a allows remote attackers to cause a denial of service (infin…

Patch available
Fix from $1,600 2009-01-16
Db2 Universal Database MEDIUM 5.0
CVE-2009-0173

Unspecified vulnerability in the server in IBM DB2 8 before FP17a, 9.1 before FP6a, and 9.5 before FP3a allows remote authenticated users to cause a …

Patch available
Fix from $1,600 2009-01-16
Websphere Datapower Xml Security Gateway Xs40 HIGH 7.8
CVE-2009-0120

The IBM WebSphere DataPower XML Security Gateway XS40 with firmware 3.6.1.5 allows remote attackers to cause a denial of service (device reboot) by s…

No fix yet
Fix from $1,950 2009-01-15
Lotus Quickr HIGH 7.8
CVE-2008-4505

Unspecified vulnerability in IBM Lotus Quickr 8.1 before Fix pack 1 (8.1.0.1) might allow attackers to cause a denial of service (system crash) via a…

Mitigation only
Fix from $1,950 2008-10-09
Zseries HIGH 10.0
CVE-2008-4404

The IPv6 Neighbor Discovery Protocol (NDP) implementation on IBM zSeries servers does not validate the origin of Neighbor Discovery messages, which a…

Mitigation only
Fix from $1,950 2008-10-03
Db2 Universal Database MEDIUM 5.0
CVE-2008-3960

Unspecified vulnerability in the JDBC Applet Server Service (aka db2jds) in IBM DB2 UDB 8 before Fixpak 17 allows remote attackers to cause a denial …

Fix: after 8.2
Fix from $1,600 2008-09-11
Lotus Quickr Server MEDIUM 6.8
CVE-2008-1216

IBM Lotus Quickr 8.0 server, and possibly QuickPlace 7.x, does not properly identify URIs containing cross-site scripting (XSS) attack strings, which…

Mitigation only
Fix from $1,600 2008-03-09