Vulnerability index

Browse CVEs

379 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Openpages Grc Platform MEDIUM 5.3
CVE-2017-1333

IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 could allow an unauthenticated user to obtain sensitive information about the server that could be used …

Patch available
Fix from $1,600 2017-11-01
Jazz Reporting Service MEDIUM 5.0
CVE-2017-1340

IBM Jazz Reporting Service (JRS) 6.0.4 could allow an authenticated user to obtain information on another server that the current report builder inte…

Patch available
Fix from $1,600 2017-11-01
Bigfix Platform MEDIUM 5.3
CVE-2017-1220

IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) discloses sensitive information to unauthorized users. The information can be used to m…

Patch available
Fix from $1,600 2017-10-26
Bigfix Platform MEDIUM 5.3
CVE-2017-1225

IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) stores sensitive information in URL parameters. This may lead to information disclosure…

Patch available
Fix from $1,600 2017-10-26
Bigfix Platform MEDIUM 5.3
CVE-2017-1230

IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) uses insufficiently random numbers or values in a security context that depends on unpr…

Patch available
Fix from $1,600 2017-10-26
Liberty HIGH 7.5
CVE-2017-1583

IBM WebSphere Application Server (IBM Liberty for Java for Bluemix 3.13)could allow a remote attacker to obtain sensitive information caused by impro…

Mitigation only
Fix from $1,950 2017-10-24
Financial Transaction Manager MEDIUM 6.5
CVE-2017-1538

IBM Financial Transaction Manager for ACH Services for Multi-Platform 3.0.2 could allow an authenticated user to obtain sensitive information from an…

No fix yet
Fix from $1,600 2017-10-10
Integration Bus MEDIUM 5.3
CVE-2017-1126

IBM WebSphere Message Broker (IBM Integration Bus 9.0 and 10.0) could allow an unauthorized user to obtain sensitive information about software versi…

Patch available
Fix from $1,600 2017-10-04
Jazz Reporting Service MEDIUM 5.3
CVE-2017-1490

An unspecified vulnerability in the Lifecycle Query Engine of Jazz Reporting Service 6.0 through 6.0.4 could disclose highly sensitive information.

Patch available
Fix from $1,600 2017-09-14
Qradar Security Information And Event Manager HIGH 7.5
CVE-2017-1162

IBM QRadar 7.2 and 7.3 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM…

Patch available
Fix from $1,950 2017-09-12
Sametime MEDIUM 5.3
CVE-2016-2964

IBM Sametime 8.5.2 and 9.0 under certain conditions provides an error message to a user that is too detailed and may reveal details about the applica…

Patch available
Fix from $1,600 2017-08-29
Sametime MEDIUM 5.3
CVE-2016-2971

IBM Sametime Media Services 8.5.2 and 9.0 can disclose sensitive information in stack trace error logs that could aid an attacker in future attacks. …

Mitigation only
Fix from $1,600 2017-08-29
Curam Social Program Management MEDIUM 6.5
CVE-2017-1110

IBM Curam Social Program Management 6.0, 6.1, 6.2, and 7.0 contains an unspecified vulnerability that could allow an authenticated user to view the i…

Patch available
Fix from $1,600 2017-08-29
Websphere Application Server MEDIUM 5.9
CVE-2017-1501

IBM WebSphere Application Server 8.0, 8.5, and 9.0 could provide weaker than expected security after using the Admin Console to update the web servic…

Patch available
Fix from $1,600 2017-08-18
Emptoris Strategic Supply Management MEDIUM 5.9
CVE-2016-6029

IBM Emptoris Strategic Supply Management Platform 10.0 and 10.1 could allow a remote attacker to obtain sensitive information, caused by the failure …

Patch available
Fix from $1,600 2017-08-14
Tririga Application Platform MEDIUM 6.5
CVE-2017-1374

Sensitive data can be exposed in the IBM TRIRIGA Application Platform 3.3, 3.4, and 3.5 that can lead to an attacker gaining unauthorized access to t…

Patch available
Fix from $1,600 2017-07-21
Bigfix Inventory CRITICAL 9.8
CVE-2016-8964

IBM BigFix Inventory v9 9.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-F…

Fix: 9.2.8+
Fix from $2,300 2017-07-13
Tivoli Monitoring MEDIUM 5.3
CVE-2016-6083

IBM Tivoli Monitoring V6 could allow an unauthenticated user to access SOAP queries that could contain sensitive information. IBM X-Force ID: 117696.

Patch available
Fix from $1,600 2017-06-27
Sterling B2b Integrator MEDIUM 6.5
CVE-2017-1131

IBM Sterling B2B Integrator Standard Edition 5.2 could allow an authenticated user to obtain sensitive information by using unsupported, specially cr…

Patch available
Fix from $1,600 2017-06-23
Sterling B2b Integrator MEDIUM 6.5
CVE-2017-1193

IBM Sterling B2B Integrator Standard Edition 5.2 could allow user to obtain sensitive information using an HTTP GET request. IBM X-Force ID: 123667.

Patch available
Fix from $1,600 2017-06-23
Sterling B2b Integrator MEDIUM 5.5
CVE-2016-5893

IBM Sterling B2B Integrator Standard Edition 5.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force I…

Patch available
Fix from $1,600 2017-06-23
Sterling B2b Integrator MEDIUM 5.5
CVE-2017-1302

IBM Sterling B2B Integrator Standard Edition 5.2 could allow a local user view sensitive information due to improper access controls. IBM X-Force ID:…

Patch available
Fix from $1,600 2017-06-23
Sterling B2b Integrator MEDIUM 5.5
CVE-2017-1349

IBM Sterling B2B Integrator Standard Edition 5.2 stores potentially sensitive information from HTTP sessions that could be read by a local user. IBM …

Patch available
Fix from $1,600 2017-06-23
Sterling B2b Integrator MEDIUM 6.5
CVE-2016-9982

IBM Sterling B2B Integrator Standard Edition 5.2 could allow an authenticated user to obtain sensitive information such as account lists due to impro…

Patch available
Fix from $1,600 2017-06-22
Sterling B2b Integrator MEDIUM 5.3
CVE-2016-9983

IBM Sterling B2B Integrator Standard Edition 5.2 could allow an authenticated user with special privileges to view files that they should not have ac…

Patch available
Fix from $1,600 2017-06-22
Api Connect HIGH 7.5
CVE-2017-1379

IBM API Connect 5.0.0.0 could allow a remote attacker to obtain sensitive information, caused by improper handling of requests to the Developer Porta…

Patch available
Fix from $1,950 2017-06-15
Inotes MEDIUM 5.7
CVE-2017-1214

IBM iNotes 8.5 and 9.0 could allow a remote attacker to send a malformed email to a victim, that when opened could cause an information disclosure. I…

Patch available
Fix from $1,600 2017-06-12
Websphere Application Server MEDIUM 5.3
CVE-2016-9736

IBM WebSphere Application Server using malformed SOAP requests could allow a remote attacker to obtain sensitive information.

Patch available
Fix from $1,600 2017-06-08
Security Privileged Identity Manager MEDIUM 5.5
CVE-2016-5960

IBM Security Privileged Identity Manager 2.0.2 and 2.1.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Forc…

Mitigation only
Fix from $1,600 2017-06-07
Tivoli Storage Manager MEDIUM 5.5
CVE-2016-8939

IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) clients/agents store password information in the Windows Registry in a manner which can…

Mitigation only
Fix from $1,600 2017-06-07