Vulnerability index

Browse CVEs

379 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Websphere Application Server MEDIUM 5.0
CVE-2010-0563

The Single Sign-on (SSO) functionality in IBM WebSphere Application Server (WAS) 7.0.0.0 through 7.0.0.8 does not recognize the Requires SSL configur…

Patch available
Fix from $1,600 2010-02-08
Rational Clearcase MEDIUM 5.0
CVE-2009-4357

CQWeb (aka the web interface) in IBM Rational ClearQuest before 7.1.1 does not properly handle use of legacy URLs for automatic login, which might al…

Fix: after 7.1
Fix from $1,600 2009-12-18
Db2 HIGH 7.5
CVE-2009-4333

The Relational Data Services component in IBM DB2 9.5 before FP5 allows attackers to obtain the password argument from the SET ENCRYPTION PASSWORD st…

Patch available
Fix from $1,950 2009-12-16
Websphere Commerce Suite MEDIUM 5.0
CVE-2009-2956

The (1) Net.Commerce and (2) Net.Data components in IBM WebSphere Commerce Suite store sensitive information under the web root with insufficient acc…

Mitigation only
Fix from $1,600 2009-08-24
Websphere Application Server MEDIUM 5.0
CVE-2009-1898

The secure login page in the Administrative Console component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 does not redirect to an…

Fix: after 6.0.2.33
Fix from $1,600 2009-06-03
Websphere Application Server MEDIUM 5.0
CVE-2009-1900

The Configservice APIs in the Administrative Console component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35, 6.1 before 6.1.0.25, …

Fix: after 6.0.2.33
Fix from $1,600 2009-06-03
Db2 MEDIUM 5.0
CVE-2009-1239

IBM DB2 9.1 before FP7 returns incorrect query results in certain situations related to the order of application of an INNER JOIN predicate and an OU…

Fix: after 9.1
Fix from $1,600 2009-04-03
Websphere Application Server HIGH 7.5
CVE-2009-0508

The Servlet Engine/Web Container and JSP components in IBM WebSphere Application Server (WAS) 5.1.0, 5.1.1.19, 6.0.2 before 6.0.2.35, 6.1 before 6.1.…

Patch available
Fix from $1,950 2009-03-16
Websphere Application Server HIGH 7.8
CVE-2009-0391

Unspecified vulnerability in IBM WebSphere Application Server (WAS) 6.0.1 on z/OS allows attackers to read arbitrary files via unknown vectors.

No fix yet
Fix from $1,950 2009-02-02
Websphere Application Server MEDIUM 5.0
CVE-2008-5413

PerfServlet in the PMI/Performance Tools component in IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 allows attackers to obtain sensitive in…

Fix: after 7.0
Fix from $1,600 2008-12-10
Lotus Connections MEDIUM 5.0
CVE-2008-4808

IBM Lotus Connections 2.x before 2.0.1 allows attackers to discover passwords via unspecified vectors. NOTE: the provenance of this information is u…

Fix: after 2.0
Fix from $1,600 2008-10-31
Db2 MEDIUM 5.0
CVE-2008-4693

The SORT/LIST SERVICES component in IBM DB2 9.1 before FP6 and 9.5 before FP2 writes sensitive information to the trace output, which allows attacker…

Fix: after 9.5
Fix from $1,600 2008-10-22
Rational Clearquest MEDIUM 5.0
CVE-2008-3550

The CQWeb login page in IBM Rational ClearQuest 7.0.1 allows remote attackers to obtain potentially sensitive information (page source code) via a co…

Mitigation only
Fix from $1,600 2008-08-08
Rational Clearquest MEDIUM 5.0
CVE-2008-1288

IBM Rational ClearQuest 7.0.1.1 and 7.0.0.2 might allow local or remote attackers to obtain sensitive information about users by reading user cookies.

Patch available
Fix from $1,600 2008-03-11
Tivoli Provisioning Manager Express MEDIUM 5.0
CVE-2007-6408

IBM Tivoli Provisioning Manager Express provides unspecified information in error messages when (1) attempted duplication of a username occurs when c…

Mitigation only
Fix from $1,600 2007-12-17
Tivoli Storage Manager Client MEDIUM 5.0
CVE-2007-5022

Unspecified vulnerability in certain IBM Tivoli Storage Manager (TSM) clients 5.1 before 5.1.8.1, 5.2 before 5.2.5.2, 5.3 before 5.3.5.3, and 5.4 bef…

Fix: 5.1.8.1 / 5.2.5.2+
Fix from $1,600 2007-09-21
Websphere Application Server MEDIUM 5.0
CVE-2006-6637

The Servlet Engine and Web Container in IBM WebSphere Application Server (WAS) before 6.0.2.17, when ibm-web-ext.xmi sets fileServingEnabled to true …

Patch available
Fix from $1,600 2006-12-19
Websphere Application Server MEDIUM 5.0
CVE-2006-4223

IBM WebSphere Application Server (WAS) before 6.0.2.13 allows context-dependent attackers to obtain sensitive information via unspecified vectors rel…

Fix: after 6.0.2.11
Fix from $1,600 2006-08-18
Websphere Application Server HIGH 7.5
CVE-2006-4136

Multiple unspecified vulnerabilities in IBM WebSphere Application Server before 6.1.0.1 have unspecified impact and attack vectors involving (1) "SOA…

Fix: after 6.1.0.0
Fix from $1,950 2006-08-14