Vulnerability index

Browse CVEs

379 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Integrated Management Module Firmware MEDIUM 6.5
CVE-2014-0882

Integrated Management Module II (IMM2) on IBM Flex System, NeXtScale, System x3xxx, and System x iDataPlex systems might allow remote authenticated u…

Mitigation only
Fix from $1,600 2018-04-25
Sterling B2b Integrator MEDIUM 5.3
CVE-2014-0912

IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote attackers to obtain sensitive product information via vect…

Patch available
Fix from $1,600 2018-04-20
Infosphere Biginsights MEDIUM 6.5
CVE-2014-4782

IBM InfoSphere BigInsights 2.1.2 allows remote authenticated users to discover SMTP server credentials via vectors related to the Alert management se…

Patch available
Fix from $1,600 2018-04-20
Security Identity Manager MEDIUM 5.9
CVE-2014-6108

IBM Tivoli Identity Manager 5.1.x before 5.1.0.15-ISS-TIM-IF0057 and Security Identity Manager 6.0.x before 6.0.0.4-ISS-SIM-IF0001 and 7.0.x before 7…

Patch available
Fix from $1,600 2018-04-20
Security Identity Manager MEDIUM 5.9
CVE-2014-6112

IBM Tivoli Identity Manager 5.1.x before 5.1.0.15-ISS-TIM-IF0057 and Security Identity Manager 6.0.x before 6.0.0.4-ISS-SIM-IF0001 and 7.0.x before 7…

Patch available
Fix from $1,600 2018-04-20
Security Identity Manager MEDIUM 5.3
CVE-2014-6109

IBM Tivoli Identity Manager 5.1.x before 5.1.0.15-ISS-TIM-IF0057 and Security Identity Manager 6.0.x before 6.0.0.4-ISS-SIM-IF0001 and 7.0.x before 7…

Patch available
Fix from $1,600 2018-04-20
Websphere Mq MEDIUM 5.3
CVE-2015-1957

IBM WebSphere MQ 7.5.x before 7.5.0.6 and 8.0.x before 8.0.0.3 allows remote authenticated users to obtain sensitive information via a man-in-the-mid…

Fix: 7.5.0.6 / 8.0.0.3+
Fix from $1,600 2018-04-10
Security Siteprotector System HIGH 7.5
CVE-2015-0172

IBM Security SiteProtector System 3.0, 3.1.0 and 3.1.1 allows remote attackers to bypass intended security restrictions and consequently execute unsp…

No fix yet
Fix from $1,950 2018-04-10
Capacity Management Analytics HIGH 7.8
CVE-2015-7432

IBM Capacity Management Analytics 2.1.0.0 allows local users to decrypt usernames and passwords by leveraging access to setenv.sh and parameter.txt. …

Patch available
Fix from $1,950 2018-03-26
Capacity Management Analytics HIGH 7.8
CVE-2015-7433

IBM Capacity Management Analytics 2.1.0.0 allows local users to discover cleartext usernames and passwords by leveraging access to the CMA install ma…

Patch available
Fix from $1,950 2018-03-26
Capacity Management Analytics HIGH 7.8
CVE-2015-7434

IBM Capacity Management Analytics 2.1.0.0 allows local users to discover encrypted usernames and passwords by leveraging access to the CMA install ma…

Patch available
Fix from $1,950 2018-03-26
Cognos Analytics MEDIUM 5.3
CVE-2016-9711

IBM Predictive Solutions Foundation (IBM Cognos Analytics 11.0) reveals sensitive information in detailed error messages that could aid an attacker i…

Mitigation only
Fix from $1,600 2018-03-22
Security Guardium Database Activity Monitor MEDIUM 5.5
CVE-2016-0237

IBM Security Guardium Database Activity Monitor 10 allows local users to obtain sensitive information by reading cached browser data. IBM X-Force ID:…

Mitigation only
Fix from $1,600 2018-03-12
Tivoli Business Service Manager HIGH 8.8
CVE-2016-0286

IBM Tivoli Business Service Manager 6.1.0 before 6.1.0-TIV-BSM-FP0004 and 6.1.1 before 6.1.1-TIV-BSM-FP0004 allows remote authenticated users to obta…

Patch available
Fix from $1,950 2018-03-09
Qradar Pulse MEDIUM 5.3
CVE-2017-1625

IBM Pulse for QRadar 1.0.0 - 1.0.3 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the…

Patch available
Fix from $1,600 2018-03-08
Application Performance Management MEDIUM 5.3
CVE-2018-1387

IBM Application Performance Management for Monitoring & Diagnostics (IBM Monitoring 8.1.3 and 8.1.4) may release sensitive personal data to the staff…

Patch available
Fix from $1,600 2018-03-08
Tririga Application Platform MEDIUM 5.3
CVE-2016-0299

IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote attackers to obtain sensitive informati…

Fix: 3.3.2.6 / 3.4.2.3+
Fix from $1,600 2018-02-28
Security Guardium Big Data Intelligence MEDIUM 5.3
CVE-2017-1774

IBM Security Guardium Big Data Intelligence (SonarG) 3.1 discloses sensitive information to unauthorized users. The information can be used to mount …

Mitigation only
Fix from $1,600 2018-02-26
Sametime MEDIUM 5.3
CVE-2012-3331

IBM Sametime allows remote attackers to obtain sensitive information from the Sametime Log database via a direct request to STLOG.NSF. IBM X-Force ID…

Mitigation only
Fix from $1,600 2018-02-08
Websphere Mq HIGH 7.5
CVE-2018-1388

GSKit V7 may disclose side channel information via discrepancies between valid and invalid PKCS#1 padding. IBM X-Force ID: 138212.

Mitigation only
Fix from $1,950 2018-02-07
Tririga Application Platform HIGH 7.5
CVE-2016-0312

IBM TRIRIGA Application Platform before 3.3.2 allows remote attackers to obtain sensitive information via vectors related to granting unauthenticated…

Fix: after 3.3.1
Fix from $1,950 2018-02-02
Cognos Analytics MEDIUM 5.5
CVE-2017-1784

IBM Cognos Analytics 11.0 could produce results in temporary files that contain highly sensitive information that can be read by a local user. IBM X-…

Patch available
Fix from $1,600 2018-01-29
Websphere Portal MEDIUM 5.3
CVE-2017-1698

IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 could reveal sensitive information from an error message that could lead to further attacks against the s…

Mitigation only
Fix from $1,600 2017-12-27
Security Guardium MEDIUM 5.5
CVE-2017-1596

IBM Security Guardium 10.0 Database Activity Monitor could allow a local attacker to obtain highly sensitive information via unspecified vectors. IBM…

Mitigation only
Fix from $1,600 2017-12-20
Security Guardium MEDIUM 5.5
CVE-2017-1595

IBM Security Guardium 10.0 Database Activity Monitor could allow a local attacker to obtain highly sensitive information via unspecified vectors. IBM…

Mitigation only
Fix from $1,600 2017-12-20
Websphere Portal MEDIUM 5.3
CVE-2017-1423

IBM WebSphere Portal 8.5 and 9.0 exposes backend server URLs that are configured for usage by the Web Application Bridge component. IBM X-Force ID: 1…

Mitigation only
Fix from $1,600 2017-12-20
Connections MEDIUM 5.3
CVE-2017-1613

IBM Connections 6.0 could allow an unauthenticated remote attacker to gain unauthenticated or unauthorized access to non-sensitive Engagement Center …

Mitigation only
Fix from $1,600 2017-12-11
Sterling File Gateway MEDIUM 6.5
CVE-2017-1487

IBM Sterling File Gateway 2.2 could allow an authenticated attacker to obtain sensitive information such as login ids on the system. IBM X-Force ID: …

Mitigation only
Fix from $1,600 2017-12-07
Bigfix Platform MEDIUM 5.9
CVE-2017-1229

IBM Tivoli Endpoint Manager (IBM BigFix 9.2 and 9.5) could allow a remote attacker to obtain sensitive information, caused by the failure to properly…

Mitigation only
Fix from $1,600 2017-11-13
Openpages Grc Platform MEDIUM 5.3
CVE-2017-1148

IBM OpenPages GRC Platform 7.2 and 7.3 with OpenPages Loss Event Entry (LEE) application could allow a user to obtain sensitive information including…

Patch available
Fix from $1,600 2017-11-01