Vulnerability index

Browse CVEs

379 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Maximo Asset Management MEDIUM 5.3
CVE-2016-0393

IBM Maximo Asset Management 7.5 before 7.5.0.10-TIV-MBS-IFIX002 and 7.6 before 7.6.0.5-TIV-MAMMT-FP001 allows remote attackers to obtain sensitive UR…

Mitigation only
Fix from $1,600 2016-07-17
Personal Communications MEDIUM 6.2
CVE-2016-0321

IBM Personal Communications (aka PCOMM) 6.x before 6.0.17 and 12.x before 12.0.0.1 does not properly restrict credential extraction, which allows loc…

Mitigation only
Fix from $1,600 2016-07-17
Rational Team Concert MEDIUM 6.5
CVE-2016-2865

The GIT Integration component in IBM Rational Team Concert (RTC) 5.x before 5.0.2 iFix14 and 6.x before 6.0.1 iFix5 and Rational Collaborative Lifecy…

Patch available
Fix from $1,600 2016-07-15
Security Identity Manager Adapter MEDIUM 6.2
CVE-2016-0338

IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 allows local users to discover cleartext p…

Mitigation only
Fix from $1,600 2016-07-15
Tivoli Directory Server HIGH 7.5
CVE-2015-1977

Directory traversal vulnerability in the Web Administration tool in IBM Tivoli Directory Server (ITDS) before 6.1.0.74-ISS-ISDS-IF0074, 6.2.x before …

Mitigation only
Fix from $1,950 2016-07-15
I Access HIGH 7.8
CVE-2016-0287

IBM i Access 7.1 on Windows allows local users to discover registry passwords via unspecified vectors.

Mitigation only
Fix from $1,950 2016-07-08
Control Center MEDIUM 5.1
CVE-2016-0252

IBM Control Center 6.x before 6.0.0.1 iFix06 and Sterling Control Center 5.4.x before 5.4.2.1 iFix09 allow local users to decrypt the master key via …

Mitigation only
Fix from $1,600 2016-07-08
Websphere Application Server HIGH 7.5
CVE-2016-2923

IBM WebSphere Application Server (WAS) 8.5 through 8.5.5.9 Liberty before Liberty Fix Pack 16.0.0.2 does not include the HTTPOnly flag in a Set-Cooki…

Mitigation only
Fix from $1,950 2016-07-07
Websphere Application Server MEDIUM 5.3
CVE-2016-0389

Admin Center in IBM WebSphere Application Server (WAS) 8.5.5.2 through 8.5.5.9 Liberty before Liberty Fix Pack 16.0.0.2 allows remote attackers to ob…

Mitigation only
Fix from $1,600 2016-07-07
Integration Bus MEDIUM 5.3
CVE-2016-2961

The integration server in IBM Integration Bus 9 before 9.0.0.6 and 10 before 10.0.0.5 and WebSphere Message Broker 8 before 8.0.0.8 allows remote att…

Mitigation only
Fix from $1,600 2016-07-02
Urbancode Deploy MEDIUM 5.9
CVE-2016-0365

IBM UrbanCode Deploy 6.0.x before 6.0.1.13, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1, when agent-relay Codestation artifact caching is enabled,…

Mitigation only
Fix from $1,600 2016-07-01
Security Guardium MEDIUM 6.5
CVE-2016-0298

Directory traversal vulnerability in IBM Security Guardium Database Activity Monitor 10 before 10.0p100 allows remote authenticated users to read arb…

Fix: after 10.0
Fix from $1,600 2016-06-29
Urbancode Deploy HIGH 7.7
CVE-2016-0267

IBM UrbanCode Deploy 6.0.x before 6.0.1.13, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1 allows remote authenticated users to obtain sensitive clea…

Mitigation only
Fix from $1,950 2016-06-29
Websphere Application Server MEDIUM 5.9
CVE-2016-0306

IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.41, 8.0 before 8.0.0.13, and 8.5 before 8.5.5.10, when FIPS 140-2 is enabled, misconfigures T…

Mitigation only
Fix from $1,600 2016-05-17
B2b Advanced Communications HIGH 7.5
CVE-2016-0341

IBM Multi-Enterprise Integration Gateway 1.0 through 1.0.0.1 and B2B Advanced Communications 1.0.0.2 through 1.0.0.4 do not require HTTPS, which migh…

Mitigation only
Fix from $1,950 2016-05-15
Websphere Commerce MEDIUM 5.3
CVE-2015-7444

The Update Installer in IBM WebSphere Commerce Enterprise 7.0.0.8 and 7.0.0.9 does not properly replicate the search index, which allows attackers to…

Patch available
Fix from $1,600 2016-02-15
Qradar Security Information And Event Manager MEDIUM 5.3
CVE-2015-2005

IBM Security QRadar SIEM 7.1.x before 7.1 MR2 Patch 12 and 7.2.x before 7.2.5 Patch 6 does not properly expire sessions, which allows remote attacker…

Mitigation only
Fix from $1,600 2016-02-15
Spectrum Scale MEDIUM 5.9
CVE-2015-7488

IBM Spectrum Scale 4.1.1.x before 4.1.1.4 and 4.2.x before 4.2.0.1, in certain LDAP File protocol configurations, allows remote attackers to discover…

Mitigation only
Fix from $1,600 2016-01-27
Security Network Protection Firmware MEDIUM 5.9
CVE-2016-0201

GSKit in IBM Security Network Protection 5.3.1 before 5.3.1.7 and 5.3.2 allows remote attackers to discover credentials by triggering an MD5 collisio…

Patch available
Fix from $1,600 2016-01-18
Jazz Reporting Service HIGH 7.5
CVE-2015-7470

Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows man-in-the-…

Patch available
Fix from $1,950 2016-01-17
Integration Bus MEDIUM 5.3
CVE-2015-7399

IBM WebSphere Message Broker 7 before 7.0.0.8 and 8 before 8.0.0.6 and IBM Integration Bus 9 before 9.0.0.3 and 10 before 10.0.0.0 allow remote attac…

Mitigation only
Fix from $1,600 2016-01-11
Sterling B2b Integrator MEDIUM 5.5
CVE-2015-7437

Queue Watcher in IBM Sterling B2B Integrator 5.2 allows local users to obtain sensitive information via unspecified vectors.

No fix yet
Fix from $1,600 2016-01-02
Spectrum Protect For Virtual Environments HIGH 8.5
CVE-2015-7429

The Data Protection extension in the VMware GUI in IBM Tivoli Storage Manager for Virtual Environments: Data Protection for VMware (aka Spectrum Prot…

Mitigation only
Fix from $1,950 2016-01-02
Rational Clearquest MEDIUM 5.1
CVE-2015-4996

IBM Rational ClearQuest 7.1.x and 8.0.0.x before 8.0.0.17 and 8.0.1.x before 8.0.1.10 allows local users to spoof database servers and discover crede…

Mitigation only
Fix from $1,600 2016-01-02
Spectrum Scale MEDIUM 6.5
CVE-2015-7456

IBM Spectrum Scale 4.1.1 before 4.1.1.4, and 4.2.0.0, allows remote authenticated users to discover object-storage admin passwords via unspecified ve…

Mitigation only
Fix from $1,600 2016-01-01
Websphere Portal MEDIUM 5.3
CVE-2015-7447

IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF20, and 8.5.0 before …

Mitigation only
Fix from $1,600 2015-12-31
Datapower Gateway MEDIUM 5.0
CVE-2015-7427

IBM DataPower Gateway appliances with firmware 6.x before 6.0.0.17, 6.0.1.x before 6.0.1.17, 7.x before 7.0.0.10, 7.1.0.x before 7.1.0.7, and 7.2.x b…

Fix: after 6.0.0.16
Fix from $1,600 2015-11-14
Websphere Commerce Enterprise MEDIUM 5.0
CVE-2015-5015

IBM WebSphere Commerce Enterprise 7.0.0.9 and 8.x before Feature Pack 8 allows remote attackers to obtain sensitive information via a crafted REST UR…

Fix: after 7.0.0.9
Fix from $1,600 2015-11-08
Security Qradar Incident Forensics MEDIUM 5.0
CVE-2015-1999

IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 places session IDs in https URLs, which allows remote attackers to obtain sensitive…

Mitigation only
Fix from $1,600 2015-11-08
Security Qradar Incident Forensics MEDIUM 5.0
CVE-2015-1994

IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, w…

Mitigation only
Fix from $1,600 2015-11-08