Vulnerability index

Browse CVEs

379 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
License Metric Tool MEDIUM 5.5
CVE-2016-8981

IBM BigFix Inventory v9 allows web pages to be stored locally which can be read by another user on the system.

Mitigation only
Fix from $1,600 2017-02-01
Websphere Message Broker MEDIUM 5.3
CVE-2016-6080

The WebAdmin context for WebSphere Message Broker allows directory listings which could disclose sensitive information to the attacker.

Patch available
Fix from $1,600 2017-02-01
Security Privileged Identity Manager HIGH 7.5
CVE-2016-5958

IBM Security Privileged Identity Manager could allow a remote attacker to obtain sensitive information, caused by the failure to set the secure flag …

Patch available
Fix from $1,950 2017-02-01
Tivoli Storage Manager For Virtual Environments Data Protection For Vmware MEDIUM 6.8
CVE-2016-6034

IBM Tivoli Storage Manager for Virtual Environments (VMware) could disclose the Windows domain credentials to a user with a high level of privileges.

Patch available
Fix from $1,600 2017-02-01
Security Privileged Identity Manager MEDIUM 6.5
CVE-2016-5988

IBM Security Privileged Identity Manager Virtual Appliance could disclose sensitive information in generated error messages that would be available t…

Patch available
Fix from $1,600 2017-02-01
Infosphere Information Server MEDIUM 6.5
CVE-2016-5994

IBM InfoSphere Information Server contains a vulnerability that would allow an authenticated user to browse any file on the engine tier, and examine …

Patch available
Fix from $1,600 2017-02-01
Security Privileged Identity Manager MEDIUM 5.9
CVE-2016-5966

IBM Security Privileged Identity Manager Virtual Appliance could allow a remote attacker to obtain sensitive information, caused by the failure to pr…

Patch available
Fix from $1,600 2017-02-01
Security Access Manager For Web 7.0 Firmware MEDIUM 5.9
CVE-2016-3043

IBM Security Access Manager for Web could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Stri…

Patch available
Fix from $1,600 2017-02-01
Security Access Manager 9.0 Firmware MEDIUM 5.3
CVE-2016-3023

IBM Security Access Manager for Web could allow an unauthenticated user to gain access to sensitive information by entering invalid file names.

Patch available
Fix from $1,600 2017-02-01
Security Appscan Source MEDIUM 5.3
CVE-2016-3035

IBM AppScan Source could reveal some sensitive information through the browsing of testlinks on the server.

Patch available
Fix from $1,600 2017-02-01
Maximo Asset Management MEDIUM 5.3
CVE-2016-5896

IBM Maximo Asset Management could disclose sensitive information from a stack trace after submitting incorrect login onto Cognos browser.

Patch available
Fix from $1,600 2017-02-01
Powerkvm CRITICAL 9.1
CVE-2015-5073EPSS 8%

Heap-based buffer overflow in the find_fixedlength function in pcre_compile.c in PCRE before 8.38 allows remote attackers to cause a denial of servic…

Fix: after 8.37
Fix from $2,300 2016-12-13
Api Connect HIGH 7.5
CVE-2016-3012

IBM API Connect (aka APIConnect) before 5.0.3.0 with NPM before 2.2.8 includes certain internal server credentials in the software package, which mig…

Fix: after 5.0.2.0
Fix from $1,950 2016-12-01
Ims Enterprise Suite HIGH 8.1
CVE-2016-2887

IBM IMS Enterprise Suite Data Provider before 3.2.0.1 for Microsoft .NET allows remote authenticated users to obtain sensitive information or modify …

Fix: after 3.2.0.0
Fix from $1,950 2016-11-30
Bigfix Remote Control MEDIUM 5.3
CVE-2016-2940

Multiple unspecified vulnerabilities in IBM BigFix Remote Control before 9.1.3 allow remote attackers to obtain sensitive information via unknown vec…

Fix: after 9.1.2
Fix from $1,600 2016-11-30
Bigfix Remote Control MEDIUM 6.5
CVE-2016-2937

IBM BigFix Remote Control before 9.1.3 allows remote attackers to obtain sensitive information or spoof e-mail transmission via a crafted POST reques…

Fix: after 9.1.2
Fix from $1,600 2016-11-30
Bigfix Remote Control MEDIUM 5.3
CVE-2016-2931

IBM BigFix Remote Control before 9.1.3 allows remote attackers to obtain sensitive cleartext information by sniffing the network.

Fix: after 9.1.2
Fix from $1,600 2016-11-30
Bigfix Remote Control MEDIUM 5.9
CVE-2016-2927

IBM BigFix Remote Control before 9.1.3 does not properly restrict the set of available encryption algorithms, which makes it easier for remote attack…

Fix: after 9.1.2
Fix from $1,600 2016-11-25
Security Guardium HIGH 7.8
CVE-2016-0247

IBM Security Guardium 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows local users to obtain sensitive cleartex…

Patch available
Fix from $1,950 2016-10-22
Sterling Secure Proxy MEDIUM 5.3
CVE-2016-6026

The Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.0 iFix 1 allows man-in-the-middle att…

Mitigation only
Fix from $1,600 2016-10-06
Websphere Application Server HIGH 7.5
CVE-2016-5986

IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.x before 8.0.0.13, 8.5.x before 8.5.5.11, 9.0.x before 9.0.0.2, and Liberty before 16…

Patch available
Fix from $1,950 2016-10-01
Security Privileged Identity Manager Virtual Appliance MEDIUM 6.8
CVE-2016-5972

IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 uses weak permissions for unspecified resources, which allows…

Fix: after 2.0.2
Fix from $1,600 2016-09-26
Security Privileged Identity Manager Virtual Appliance HIGH 7.1
CVE-2016-5971

IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 allows remote authenticated users to read arbitrary files or …

Fix: after 2.0.2
Fix from $1,950 2016-09-26
Security Privileged Identity Manager Virtual Appliance MEDIUM 6.5
CVE-2016-5970

Directory traversal vulnerability in IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 allows remote authentica…

Fix: after 2.0.2
Fix from $1,600 2016-09-26
Spectrum Control MEDIUM 6.5
CVE-2016-5946

Directory traversal vulnerability in IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticat…

Patch available
Fix from $1,600 2016-09-26
Connections MEDIUM 6.5
CVE-2016-2999

IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to obtain sensitive information via an unsp…

Fix: after 5.5.0.0
Fix from $1,600 2016-09-26
Tivoli Storage Manager For Space Management MEDIUM 5.5
CVE-2016-5927

IBM Tivoli Storage Manager for Space Management (aka Spectrum Protect for Space Management) 6.3.x before 6.3.2.6, 6.4.x before 6.4.3.3, and 7.1.x bef…

Patch available
Fix from $1,600 2016-09-12
Bigfix Webreports MEDIUM 5.9
CVE-2016-0397

WebReports in IBM BigFix Platform (formerly Tivoli Endpoint Manager) 9.x before 9.5.2 allows remote attackers to obtain sensitive information by snif…

Mitigation only
Fix from $1,600 2016-08-30
Bigfix MEDIUM 5.5
CVE-2016-0292

WebReports in IBM BigFix Platform (formerly Tivoli Endpoint Manager) 9.x before 9.5.2 allows local users to discover the cleartext system password by…

Mitigation only
Fix from $1,600 2016-08-30
Tivoli Storage Flashcopy Manager For Sql Server MEDIUM 6.2
CVE-2016-3059

IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server (aka IBM Spectrum Protect for Databases) 6.3 before 6.3.1.7 and 6.…

Fix: after 6.4.1.8
Fix from $1,600 2016-08-08