Vulnerability index

Browse CVEs

379 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Websphere Portal MEDIUM 5.0
CVE-2014-3056

The Unified Task List (UTL) Portlet for IBM WebSphere Portal 7.x and 8.x through 8.0.0.1 CF12 allows remote attackers to obtain potentially sensitive…

Mitigation only
Fix from $1,600 2014-07-29
Infosphere Master Data Management Collaboration Server MEDIUM 6.3
CVE-2014-3064

The GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0 FP4 and InfoSphere Master Data Managemen…

Mitigation only
Fix from $1,600 2014-07-19
Flex System Manager MEDIUM 5.0
CVE-2013-5423

IBM Flex System Manager (FSM) 1.1 through 1.3 before 1.3.2.0 allows remote attackers to enumerate user accounts via unspecified vectors.

Mitigation only
Fix from $1,600 2014-07-07
Tivoli Endpoint Manager MEDIUM 5.0
CVE-2014-3066

IBM Tivoli Endpoint Manager 9.1 before 9.1.1088.0 allows remote attackers to read arbitrary files via XML data containing an external entity declarat…

Mitigation only
Fix from $1,600 2014-07-02
Websphere Application Server MEDIUM 5.0
CVE-2014-0891

IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.33, 8.0.x before 8.0.0.9, and 8.5.x before 8.5.5.2 allows remote attackers to obtain sensit…

Patch available
Fix from $1,600 2014-06-28
Sametime MEDIUM 5.0
CVE-2014-3867

The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 does not include the HTTPOnly flag in a Set-Cookie header for an unspe…

Mitigation only
Fix from $1,600 2014-05-26
Sametime MEDIUM 5.0
CVE-2013-3982EPSS 13%

The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to obtain unspecified installation information…

Mitigation only
Fix from $1,600 2014-05-26
Lotus Domino MEDIUM 5.0
CVE-2014-0892

IBM Notes and Domino 8.5.x before 8.5.3 FP6 IF3 and 9.x before 9.0.1 FP1 on 32-bit Linux platforms use incorrect gcc options, which makes it easier f…

Mitigation only
Fix from $1,600 2014-04-23
Spss Collaboration And Deployment Services MEDIUM 5.0
CVE-2013-4043

The server in IBM SPSS Collaboration and Deployment Services 4.x before 4.2.1.3 IF3, 5.x before 5.0 FP3, and 6.x before 6.0 IF1 allows remote attacke…

Mitigation only
Fix from $1,600 2014-02-01
Spss Collaboration And Deployment Services MEDIUM 5.0
CVE-2013-4069

The Portal application in IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote attackers to read …

Mitigation only
Fix from $1,600 2013-12-21
Spss Collaboration And Deployment Services MEDIUM 5.0
CVE-2013-4070

The Portal application in IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote attackers to disco…

Mitigation only
Fix from $1,600 2013-12-21
Infosphere Information Server MEDIUM 5.0
CVE-2013-3040

IBM InfoSphere Information Server through 8.5 FP3, 8.7 through FP2, and 9.1 produces login-failure messages indicating whether the username or passwo…

Patch available
Fix from $1,600 2013-08-16
Sterling B2b Integrator MEDIUM 5.0
CVE-2013-0481

The console in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allows remote attackers to read stack traces by triggeri…

Mitigation only
Fix from $1,600 2013-07-03
Sterling B2b Integrator MEDIUM 5.0
CVE-2013-0558

IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote attackers to obtain sensitive information about applicatio…

No fix yet
Fix from $1,600 2013-07-03
Rational Directory Server MEDIUM 5.0
CVE-2013-0599

IBM Eclipse Help System (IEHS), as used in IBM Rational Directory Server 5.1.1 through 5.1.1.2 and 5.2 through 5.2.1 and other products, allows remot…

Fix: after 5.2.1
Fix from $1,600 2013-05-28
Sterling Secure Proxy MEDIUM 5.0
CVE-2013-0519

IBM Sterling Secure Proxy 3.2.0 and 3.3.01 before 3.3.01.23 Interim Fix 1, 3.4.0 before 3.4.0.6 Interim Fix 1, and 3.4.1 before 3.4.1.7 provides web-…

Mitigation only
Fix from $1,600 2013-05-10
Infosphere Replication Server MEDIUM 5.0
CVE-2013-0584

The Data Replication Dashboard component in IBM InfoSphere Replication Server 9.7 and 10.x before 10.2.0.0-b113 allows remote attackers to obtain a l…

Mitigation only
Fix from $1,600 2013-04-23
Sterling Multi Channel Fulfillment Solution MEDIUM 5.5
CVE-2013-0505

IBM Sterling Order Management 8.0 before HF127, 8.5 before HF89, 9.0 before HF69, 9.1.0 before FP41, and 9.2.0 before FP13 allows remote authenticate…

Mitigation only
Fix from $1,600 2013-03-19
Rational Clearquest MEDIUM 5.0
CVE-2012-5765

The Web Client (aka CQ Web) in IBM Rational ClearQuest 7.1.2.x before 7.1.2.9 and 8.0.0.x before 8.0.0.5 allows remote attackers to obtain sensitive …

Mitigation only
Fix from $1,600 2012-12-20
Rational Business Developer MEDIUM 5.0
CVE-2012-3319

IBM Rational Business Developer 8.x before 8.0.1.4 allows remote attackers to obtain potentially sensitive information via a connection to a web serv…

Fix: after 8.0.1.3
Fix from $1,600 2012-10-01
Rational Clearquest MEDIUM 5.0
CVE-2012-0744EPSS 8%

IBM Rational ClearQuest 7.1.x through 7.1.2.7 and 8.x through 8.0.0.3 allows remote attackers to obtain potentially sensitive information via a reque…

Mitigation only
Fix from $1,600 2012-08-17
Db2 MEDIUM 5.0
CVE-2012-2196

IBM DB2 9.1 before FP12, 9.5 through FP9, 9.7 through FP6, 9.8 through FP5, and 10.1 allows remote attackers to read arbitrary XML files via the (1) …

Mitigation only
Fix from $1,600 2012-07-25
Rational Appscan MEDIUM 6.8
CVE-2012-0731

IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 does not prevent service-account impersonation, which allows remote authenticated users to…

Mitigation only
Fix from $1,600 2012-05-03
Tivoli Endpoint Manager MEDIUM 5.0
CVE-2012-1837

The (1) webreports, (2) post/create-role, and (3) post/update-role programs in IBM Tivoli Endpoint Manager (TEM) before 8.2 do not include the HTTPOn…

Fix: after 8.1
Fix from $1,600 2012-03-22
Websphere Application Server MEDIUM 5.0
CVE-2011-1368

The JavaServer Faces (JSF) application functionality in IBM WebSphere Application Server 8.x before 8.0.0.1 does not properly handle requests, which …

Mitigation only
Fix from $1,600 2011-10-29
Tivoli Directory Server MEDIUM 5.0
CVE-2011-2759

The login page of IDSWebApp in the Web Administration Tool in IBM Tivoli Directory Server (TDS) 6.2 before 6.2.0.3-TIV-ITDS-IF0004 does not have an o…

Mitigation only
Fix from $1,600 2011-07-17
Rational Build Forge MEDIUM 5.0
CVE-2011-1839

IBM Rational Build Forge 7.1.0 uses the HTTP GET method during redirection from the authentication servlet to a PHP script, which makes it easier for…

Mitigation only
Fix from $1,600 2011-04-28
Websphere Portal MEDIUM 5.0
CVE-2011-0679

IBM WebSphere Portal 6.0.1.1 through 7.0.0.0, as used in IBM Lotus Web Content Management (WCM) and IBM Lotus Quickr for WebSphere Portal, allows rem…

No fix yet
Fix from $1,600 2011-01-28
Websphere Commerce MEDIUM 5.0
CVE-2010-2639

IBM WebSphere Commerce Enterprise 7.0 before 7.0.0.2 allows remote attackers to read messages intended for other recipients via vectors involving acc…

Mitigation only
Fix from $1,600 2010-12-06
Websphere Application Server MEDIUM 5.0
CVE-2010-2323

IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11 on z/OS might allow attackers to obtain sensitive information by reading the default_creat…

Fix: after 7.0.0.10
Fix from $1,600 2010-06-18