Vulnerability index

Browse CVEs

201 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Tivoli Storage Flashcopy Manager For Vmware CRITICAL 10.0
CVE-2015-7425

The Data Protection component in the VMware vSphere GUI in IBM Tivoli Storage Manager for Virtual Environments: Data Protection for VMware (aka Spect…

Mitigation only
Fix from $2,300 2016-02-21
Maximo Asset Management MEDIUM 5.4
CVE-2015-7396

The Scheduler in IBM Maximo Asset Management 7.5 before 7.5.0.8 IF6 and 7.6 before 7.6.0.1 FP1 and Maximo Asset Management 7.5 before 7.5.0.8 IF6, 7.…

Mitigation only
Fix from $1,600 2016-01-02
Installation Manager HIGH 7.0
CVE-2015-7442

consoleinst.sh in IBM Installation Manager before 1.7.4.4 and 1.8.x before 1.8.4 and Packaging Utility before 1.7.4.4 and 1.8.x before 1.8.4 allows l…

Fix: after 1.7.4.3
Fix from $1,950 2016-01-02
Spss Statistics HIGH 7.8
CVE-2015-7489

IBM SPSS Statistics 22.0.0.2 before IF10 and 23.0.0.2 before IF7 uses weak permissions (Everyone: Write) for Python scripts, which allows local users…

Mitigation only
Fix from $1,950 2016-01-01
System Networking Switch Center HIGH 7.2
CVE-2015-7818

The administration-panel web service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows loca…

Fix: after 8.1.1.0
Fix from $1,950 2015-11-12
Security Guardium HIGH 7.2
CVE-2015-5043

diag in IBM Security Guardium 8.2 before p6015, 9.0 before p6015, 9.1, 9.5, and 10.0 before p6015 allows local users to obtain root access via unspec…

Mitigation only
Fix from $1,950 2015-11-08
Sterling B2b Integrator MEDIUM 5.5
CVE-2015-5019

IBM Sterling Integrator 5.1 before 5010004_8 and Sterling B2B Integrator 5.2 before 5020500_9 allow remote authenticated users to read or upload file…

Mitigation only
Fix from $1,600 2015-11-08
Powerha System Mirror HIGH 8.5
CVE-2015-5005

CSPOC in IBM PowerHA SystemMirror on AIX 6.1 and 7.1 allows remote authenticated users to perform an "su root" action by leveraging presence on the c…

Mitigation only
Fix from $1,950 2015-11-08
Infosphere Information Server MEDIUM 5.5
CVE-2015-5021

IBM InfoSphere Information Server 11.3 and 11.5 allows remote authenticated DataStage users to bypass intended job-execution restrictions or obtain s…

Patch available
Fix from $1,600 2015-11-04
Tivoli Storage Manager HIGH 7.2
CVE-2015-4927

The Reporting and Monitoring component in Tivoli Monitoring in IBM Tivoli Storage Manager 6.3 before 6.3.6 and 7.1 before 7.1.3 on Linux and AIX uses…

Mitigation only
Fix from $1,950 2015-11-04
Websphere Portal MEDIUM 6.8
CVE-2015-4997

IBM WebSphere Portal 8.5.0 before CF08 allows remote attackers to bypass intended access restrictions via a crafted request.

Patch available
Fix from $1,600 2015-10-29
Vios MEDIUM 6.9
CVE-2015-4948

netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows local users to gain privileges via unspecified vect…

Mitigation only
Fix from $1,600 2015-10-16
Urbancode Deploy MEDIUM 6.0
CVE-2015-4964

IBM UrbanCode Deploy 6.0 and 6.0.1.x before 6.0.1.10, 6.1.1.x before 6.1.1.8, and 6.1.2 writes admin AUTH_TOKEN values to execution logs, which allow…

Patch available
Fix from $1,600 2015-10-06
Infosphere Datastage HIGH 7.2
CVE-2015-1900

IBM InfoSphere DataStage 8.1, 8.5, 8.7, 9.1, and 11.3 through 11.3.1.2 on UNIX allows local users to write to executable files, and consequently obta…

Patch available
Fix from $1,950 2015-06-29
Tivoli Directory Server MEDIUM 6.5
CVE-2015-1974

The web administration tool in IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, 6.3 before iFix 37, 6…

Patch available
Fix from $1,600 2015-06-28
Security Siteprotector System HIGH 9.0
CVE-2015-0160

IBM Security SiteProtector System 3.0 before 3.0.0.7, 3.1 before 3.1.0.4, and 3.1.1 before 3.1.1.2 allows remote authenticated users to execute arbit…

Mitigation only
Fix from $1,950 2015-05-25
Optim Workload Replay MEDIUM 5.0
CVE-2015-1895

IBM InfoSphere Optim Workload Replay 2.x before 2.1.0.3 relies on client-side code to verify authorization, which allows remote attackers to bypass i…

Patch available
Fix from $1,600 2015-05-25
Websphere Application Server HIGH 9.3
CVE-2015-1885

WebSphereOauth20SP.ear in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.39, 8.0 before 8.0.0.11, 8.5 Liberty Profile before 8.5.5.5, and 8.…

Patch available
Fix from $1,950 2015-04-27
Websphere Application Server MEDIUM 5.5
CVE-2015-0175

IBM WebSphere Application Server (WAS) 8.5 Liberty Profile before 8.5.5.5 does not properly implement authData elements, which allows remote authenti…

Patch available
Fix from $1,600 2015-04-27
Websphere Datapower Xc10 Appliance Firmware MEDIUM 6.8
CVE-2015-1893

The IBM WebSphere DataPower XC10 appliance 2.1 before 2.1.0.3 allows remote attackers to hijack the sessions of arbitrary users, and consequently obt…

Patch available
Fix from $1,600 2015-04-06
Domino HIGH 7.2
CVE-2015-0179

Notes System Diagnostic (NSD) in IBM Domino 8.5.x before 8.5.3 FP6 IF6 and 9.x before 9.0.1 FP3 IF1 allows local users to obtain the System privilege…

Patch available
Fix from $1,950 2015-04-06
General Parallel File System HIGH 7.2
CVE-2015-0197

IBM General Parallel File System (GPFS) 3.4 before 3.4.0.32, 3.5 before 3.5.0.24, and 4.1 before 4.1.0.7 allows local users to obtain root privileges…

Patch available
Fix from $1,950 2015-03-24
Api Management MEDIUM 5.5
CVE-2015-0149

The developer portal in IBM API Management 3.0 before 3.0.4.1 does not properly restrict access to the public and private APIs, which allows remote a…

Patch available
Fix from $1,600 2015-03-18
Rational Quality Manager MEDIUM 5.5
CVE-2014-6129

IBM Rational Jazz Team Server (JTS), as used in Rational Collaborative Lifecycle Management 3.x and 4.x before 4.0.7 iFix4 and 5.x before 5.0.2 iFix2…

Patch available
Fix from $1,600 2015-03-18
Tivoli Storage Manager HIGH 7.2
CVE-2014-6185

dsmtca in the client in IBM Tivoli Storage Manager (TSM) 6.3 before 6.3.2.3, 6.4 before 6.4.2.2, and 7.1 before 7.1.1.3 does not properly restrict sh…

Patch available
Fix from $1,950 2015-02-13
Tivoli Monitoring HIGH 8.5
CVE-2014-6141

IBM Tivoli Monitoring (ITM) 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP09, 6.2.3 through FP05, and 6.3.0 before FP04 allows remote authe…

Mitigation only
Fix from $1,950 2015-02-02
Sas Raid Module Firmware MEDIUM 5.0
CVE-2014-3019

IBM BladeCenter SAS Connectivity Module (aka NSSM) and SAS RAID Module (aka RSSM) before 1.3.3.006 allow remote attackers to obtain blade and storage…

Fix: after 1.3.3.004
Fix from $1,600 2015-01-17
Vios HIGH 7.2
CVE-2014-8904

lquerylv in cmdlvm in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x allows local users to gain privileges via a crafted DBGCMD_LQUERYLV environment-variab…

No fix yet
Fix from $1,950 2015-01-15
Security Appscan MEDIUM 5.5
CVE-2014-6122

IBM Security AppScan Enterprise 8.5 before 8.5 IFix 002, 8.6 before 8.6 IFix 004, 8.7 before 8.7 IFix 004, 8.8 before 8.8 iFix 003, 9.0 before 9.0.0.…

Mitigation only
Fix from $1,600 2014-12-23
Websphere Application Server MEDIUM 5.1
CVE-2014-8890

IBM WebSphere Application Server Liberty Profile 8.5.x before 8.5.5.4 allows remote attackers to gain privileges by leveraging the combination of a s…

Mitigation only
Fix from $1,600 2014-12-18