Vulnerability index

Browse CVEs

379 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Security Privileged Identity Manager MEDIUM 5.3
CVE-2016-5959

IBM Security Privileged Identity Manager 2.0.2 and 2.1.0 stores sensitive information in URL parameters. This may lead to information disclosure if u…

Patch available
Fix from $1,600 2017-06-07
Cognos Business Intelligence Server MEDIUM 5.3
CVE-2016-9710

IBM Predictive Solutions Foundation (formerly PMQ) could allow a remote attacker to include arbitrary files. A remote attacker could send a specially…

Patch available
Fix from $1,600 2017-06-07
Maximo Asset Management MEDIUM 5.3
CVE-2017-1292

IBM Maximo Asset Management 7.5 and 7.6 generates error messages that could reveal sensitive information that could be used in further attacks agains…

Patch available
Fix from $1,600 2017-05-26
Tivoli Storage Manager MEDIUM 5.5
CVE-2016-8916

IBM Tivoli Storage Manager 5.5, 6.1-6.4, and 7.1 stores password information in a log file that could be read by a local user when a set password com…

Fix: after 6.3
Fix from $1,600 2017-05-05
Cognos Business Intelligence MEDIUM 5.7
CVE-2016-3037

IBM Cognos TM1 10.1 and 10.2 provides a service to return the victim's password with a valid session key. An authenticated attacker with user interac…

Patch available
Fix from $1,600 2017-04-17
Tivoli Application Dependency Discovery Manager MEDIUM 6.5
CVE-2016-8925

IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 could allow a remote attacker to include arbitrary files which could allow the atta…

Patch available
Fix from $1,600 2017-04-14
Algo One MEDIUM 6.5
CVE-2017-1154

IBM Algorithmics One-Algo Risk Application 4.9.1, 5.0, and 5.1.0 could allow a user to gain access to files in the local environment which should not…

Patch available
Fix from $1,600 2017-03-31
Kenexa Lcms Premier MEDIUM 6.5
CVE-2017-1142

IBM Kenexa LCMS Premier on Cloud 9.x and 10.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set the secure …

Mitigation only
Fix from $1,600 2017-03-27
Kenexa Lcms Premier MEDIUM 5.3
CVE-2017-1143

IBM Kenexa LCMS Premier on Cloud 9.x and 10.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable…

Mitigation only
Fix from $1,600 2017-03-27
Rational Collaborative Lifecycle Management MEDIUM 6.8
CVE-2016-2981

An undisclosed vulnerability in the CLM applications in IBM Jazz Team Server may allow unauthorized access to user credentials. IBM Reference #: 1999…

Patch available
Fix from $1,600 2017-03-20
Websphere Commerce MEDIUM 5.1
CVE-2016-5894

IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 7.0 and 8.0 is vulnerable to information disclosure vulnerability. A local us…

Patch available
Fix from $1,600 2017-03-08
Tivoli Storage Manager HIGH 8.8
CVE-2016-8940

IBM Tivoli Storage Manager (IBM Spectrum Protect) 6.1, 6.2, 6.3, and 7.1 does not perform sufficient authority checking on SQL queries. As a result, …

Patch available
Fix from $1,950 2017-03-07
Qradar Incident Forensics MEDIUM 5.3
CVE-2016-9720

IBM QRadar 7.2 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM Referen…

Patch available
Fix from $1,600 2017-03-07
Qradar Security Information And Event Manager MEDIUM 5.3
CVE-2016-9725

IBM QRadar Incident Forensics 7.2 allows for Cross-Origin Resource Sharing (CORS), which is a mechanism that allows web sites to request resources fr…

Patch available
Fix from $1,600 2017-03-07
Websphere Mq MEDIUM 5.9
CVE-2016-3052

Under non-standard configurations, IBM WebSphere MQ might send password data in clear text over the network. This data could be intercepted using man…

Fix: after 8.0.0.5
Fix from $1,600 2017-02-22
Tealeaf Customer Experience On Cloud Network Capture Add On MEDIUM 5.9
CVE-2016-5900

IBM Tealeaf Customer Experience on Cloud Network Capture Add-On could allow a remote attacker to obtain sensitive information, caused by the failure …

Patch available
Fix from $1,600 2017-02-08
Cloud Orchestrator MEDIUM 5.5
CVE-2016-0203

A vulnerability has been identified in the IBM Cloud Orchestrator task API. The task API might allow an authenticated user to view background informa…

Patch available
Fix from $1,600 2017-02-08
Sterling B2b Integrator MEDIUM 5.3
CVE-2016-0210

IBM Sterling B2B Integrator Standard Edition could allow a remote attacker to obtain sensitive information. By allowing HTTP OPTIONS method, a remote…

Patch available
Fix from $1,600 2017-02-08
Client Application Access MEDIUM 5.9
CVE-2016-0270

IBM Domino 9.0.1 Fix Pack 3 Interim Fix 2 through 9.0.1 Fix Pack 5 Interim Fix 1, when using TLS and AES GCM, uses random nonce generation, which mak…

Patch available
Fix from $1,600 2017-02-08
Security Key Lifecycle Manager MEDIUM 6.2
CVE-2016-6092

IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 stores user credentials in plain in clear text which can be read by a local user.

Patch available
Fix from $1,600 2017-02-07
Dashboard Application Services Hub MEDIUM 5.9
CVE-2016-5935

IBM Jazz for Service Management could allow a remote attacker to obtain sensitive information, caused by the failure to properly validate the SSL cer…

Mitigation only
Fix from $1,600 2017-02-02
Security Key Lifecycle Manager MEDIUM 5.9
CVE-2016-6116

IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable …

Patch available
Fix from $1,600 2017-02-02
Security Key Lifecycle Manager MEDIUM 5.3
CVE-2016-6099

IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 discloses sensitive information to unauthorized users. The information can be used to mount further atta…

Patch available
Fix from $1,600 2017-02-02
License Metric Tool MEDIUM 5.3
CVE-2016-8977

IBM BigFix Inventory v9 could disclose sensitive information to an unauthorized user using HTTP GET requests. This information could be used to mount…

Mitigation only
Fix from $1,600 2017-02-01
Infosphere Datastage MEDIUM 5.3
CVE-2016-8982

IBM InfoSphere Information Server stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties hav…

Patch available
Fix from $1,600 2017-02-01
Urbancode Deploy HIGH 7.5
CVE-2016-6068

IBM UrbanCode Deploy could allow an authenticated user with access to the REST endpoints to access API and CLI getResource secured role properties.

Patch available
Fix from $1,950 2017-02-01
Urbancode Deploy MEDIUM 5.5
CVE-2016-2941

IBM UrbanCode Deploy creates temporary files during step execution that could contain sensitive information including passwords that could be read by…

Mitigation only
Fix from $1,600 2017-02-01
License Metric Tool MEDIUM 5.5
CVE-2016-8963

IBM BigFix Inventory v9 stores potentially sensitive information in log files that could be read by a local user.

Fix: after 9.2
Fix from $1,600 2017-02-01
Security Key Lifecycle Manager MEDIUM 5.3
CVE-2016-6117

IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 can be deployed with active debugging code that can disclose sensitive information.

Patch available
Fix from $1,600 2017-02-01
License Metric Tool MEDIUM 5.9
CVE-2016-8966

IBM BigFix Inventory v9 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport…

Mitigation only
Fix from $1,600 2017-02-01