Vulnerability index

Browse CVEs

201 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Db2 HIGH 8.8
CVE-2023-42005

IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data 3.5, 4.0, 4.5, 4.6, 4.7, and 4.8 could allow a user with access to the Kubernet…

Mitigation only
Fix from $1,950 2024-05-29
Websphere Application Server HIGH 7.8
CVE-2013-3024

IBM WebSphere Application Server (WAS) 8.5 through 8.5.0.2 on UNIX allows local users to gain privileges by leveraging improper process initializatio…

Fix: after 8.5.0.2
Fix from $1,950 2018-05-24
Rational Collaborative Lifecycle Management HIGH 7.8
CVE-2015-7440

IBM Rational Collaborative Lifecycle Management (CLM) 3.0.1 before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15,…

Fix: after 6.0.1
Fix from $1,950 2018-03-15
Security Identity Manager Virtual Appliance HIGH 7.8
CVE-2016-0327

IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows local users to gain administrator p…

Patch available
Fix from $1,950 2018-01-12
Security Siteprotector System HIGH 7.0
CVE-2015-0162

IBM Security SiteProtector System 3.0, 3.1, and 3.1.1 allows local users to gain privileges.

No fix yet
Fix from $1,950 2017-09-20
Qradar Security Information And Event Manager MEDIUM 5.9
CVE-2016-9972

IBM QRadar 7.2 and 7.3 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport …

Patch available
Fix from $1,600 2017-06-27
Maximo Asset Management HIGH 8.8
CVE-2016-9984

IBM Maximo Asset Management 7.5 and 7.6 could allow a remote authenticated attacker to execute arbitrary commands on the system as administrator. IBM…

Mitigation only
Fix from $1,950 2017-06-13
Marketing Platform HIGH 8.8
CVE-2016-6112

IBM Distributed Marketing and Marketing Platform 8.6, 9.0, 9.1, and 10.0 could allow an authenticated user to escalate their privileges and gain admi…

Mitigation only
Fix from $1,950 2017-05-22
Cognos Business Intelligence HIGH 8.8
CVE-2016-8960

IBM Cognos Business Intelligence 10.2 could allow a user with lower privilege Capabilities to adopt the Capabilities of a higher-privilege user by in…

Patch available
Fix from $1,950 2017-03-27
Aix HIGH 7.8
CVE-2016-8972

IBM AIX 6.1, 7.1, and 7.2 could allow a local user to gain root privileges using a specially crafted command within the bellmail client. IBM APARs: I…

Patch available
Fix from $1,950 2017-02-15
Aix HIGH 7.8
CVE-2016-6079

IBM AIX 5.3, 6.1, 7.1, and 7.2 contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges. I…

Patch available
Fix from $1,950 2017-02-15
Tivoli Storage Manager Fastback HIGH 7.3
CVE-2016-5934

IBM Tivoli Storage Manager FastBack installer could allow a remote attacker to execute arbitrary code on the system. By placing a specially-crafted D…

Mitigation only
Fix from $1,950 2017-02-08
Aix HIGH 7.8
CVE-2016-3053

IBM AIX contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges.

No fix yet
Fix from $1,950 2017-02-01
Tririga Application Platform HIGH 8.8
CVE-2016-2917

The notifications component in IBM TRIRIGA Applications 10.4 and 10.5 before 10.5.1 allows remote authenticated users to obtain sensitive password in…

Mitigation only
Fix from $1,950 2016-11-30
Qradar Security Information And Event Manager HIGH 7.5
CVE-2016-2876

IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 executes unspecified processes at an incorrect privilege level, which makes it easier fo…

Fix: after 7.1.0
Fix from $1,950 2016-11-30
Tivoli Storage Manager For Virtual Environments HIGH 8.5
CVE-2016-2988

IBM Tivoli Storage Manger for Virtual Environments: Data Protection for VMware (aka Spectrum Protect for Virtual Environments) 6.4.x before 6.4.3.4 a…

Mitigation only
Fix from $1,950 2016-11-25
Spectrum Scale HIGH 7.0
CVE-2016-2985

IBM Spectrum Scale 4.1.1.x before 4.1.1.8 and 4.2.x before 4.2.0.4 and General Parallel File System (GPFS) 3.5.x before 3.5.0.32 and 4.1.x before 4.1…

Mitigation only
Fix from $1,950 2016-11-25
Spectrum Scale HIGH 7.0
CVE-2016-2984

IBM Spectrum Scale 4.1.1.x before 4.1.1.8 and 4.2.x before 4.2.0.4 and General Parallel File System (GPFS) 3.5.x before 3.5.0.32 and 4.1.x before 4.1…

Mitigation only
Fix from $1,950 2016-11-25
Security Guardium Database Activity Monitor HIGH 8.8
CVE-2016-0239

IBM Security Guardium Database Activity Monitor 9.x through 9.5 before p700 and 10.x through 10.0.1 before p100 allows remote authenticated users to …

Patch available
Fix from $1,950 2016-10-22
Sterling Secure Proxy MEDIUM 5.9
CVE-2016-6025

The Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.0 iFix 1 allows remote attackers to o…

Mitigation only
Fix from $1,600 2016-10-06
Db2 HIGH 7.3
CVE-2016-5995

Untrusted search path vulnerability in IBM DB2 9.7 through FP11, 10.1 through FP5, 10.5 before FP8, and 11.1 GA on Linux, AIX, and HP-UX allows local…

Patch available
Fix from $1,950 2016-10-01
Websphere Application Server HIGH 7.5
CVE-2016-2945

The API Discovery implementation in IBM WebSphere Application Server (WAS) 8.5.5.8 through 8.5.5.9 Liberty before Liberty Fix Pack 16.0.0.2 allows re…

Mitigation only
Fix from $1,950 2016-07-08
Urbancode Deploy HIGH 8.2
CVE-2016-0271

The agents in IBM UrbanCode Deploy 6.x before 6.0.1.14, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1 do not verify a server's identity in a JMS ses…

Mitigation only
Fix from $1,950 2016-07-08
Hardware Management Console MEDIUM 6.8
CVE-2016-0230

IBM Power Hardware Management Console (HMC) 7.3 through 7.3.0 SP7, 7.9 through 7.9.0 SP3, 8.1 through 8.1.0 SP3, 8.2 through 8.2.0 SP2, 8.3 through 8…

Patch available
Fix from $1,600 2016-07-07
Security Qradar Incident Forensics MEDIUM 6.5
CVE-2016-2968

IBM Security QRadar Incident Forensics 7.2.x before 7.2.7 allows remote attackers to bypass authentication, and obtain sensitive information or modif…

Mitigation only
Fix from $1,600 2016-07-02
Messagesight HIGH 8.8
CVE-2016-0375

JMS Client in IBM MessageSight 1.1.x through 1.1.0.1, 1.2.x through 1.2.0.3, and 2.0.x through 2.0.0.0 allows remote authenticated users to obtain ad…

Mitigation only
Fix from $1,950 2016-07-01
Tririga Application Platform HIGH 8.8
CVE-2016-0374

The builder tools in IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.4, and 3.5 before 3.5.0.2 allow remote authenticated users…

Mitigation only
Fix from $1,950 2016-07-01
General Parallel File System Storage Server HIGH 7.0
CVE-2016-0263

IBM Spectrum Scale 4.1 before 4.1.1.5 and 4.2 before 4.2.0.2 and General Parallel File System 3.5 before 3.5.0.30 allow local users to gain privilege…

Mitigation only
Fix from $1,950 2016-06-29
Tivoli Netview Access Services HIGH 8.8
CVE-2014-9768

IBM Tivoli NetView Access Services (NVAS) allows remote authenticated users to gain privileges by entering the ADM command and modifying a "page ID" …

Mitigation only
Fix from $1,950 2016-03-18
Tivoli Monitoring CRITICAL 9.9
CVE-2015-7411

The portal client in IBM Tivoli Monitoring (ITM) 6.2.2 through FP9, 6.2.3 through FP5, and 6.3.0 through FP6 allows remote authenticated users to gai…

Mitigation only
Fix from $2,300 2016-03-12