Vulnerability index

Browse CVEs

201 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Business Process Manager MEDIUM 6.5
CVE-2014-4844

The import/export functionality in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, and 8.5.x through 8.5.5 allows re…

Mitigation only
Fix from $1,600 2014-12-17
Websphere Mq MEDIUM 6.5
CVE-2014-4793

IBM WebSphere MQ 8.x before 8.0.0.1 does not properly enforce CHLAUTH rules for blocking client connections in certain circumstances related to the C…

Patch available
Fix from $1,600 2014-10-02
Cognos Tm1 MEDIUM 5.0
CVE-2014-0877

IBM Cognos TM1 10.2.0.2 before IF1 and 10.2.2.0 before IF1 allows remote attackers to bypass intended access restrictions by visiting the Rights page…

Patch available
Fix from $1,600 2014-09-05
Monitoring Agent For Unix Logs HIGH 7.2
CVE-2013-5467

Monitoring Agent for UNIX Logs 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP09, and 6.2.3 through FP04 and Monitoring Server (ms) and Shar…

Mitigation only
Fix from $1,950 2014-08-29
Websphere Application Server MEDIUM 5.0
CVE-2014-3070

The addFileRegistryAccount Virtual Member Manager (VMM) SPI Admin Task in IBM WebSphere Application Server (WAS) 8.0.x before 8.0.0.10 and 8.5.x befo…

Mitigation only
Fix from $1,600 2014-08-22
Websphere Application Server MEDIUM 5.0
CVE-2014-3083

IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.35, 8.0.x before 8.0.0.10, and 8.5.x before 8.5.5.3 does not properly restrict resource acc…

Mitigation only
Fix from $1,600 2014-08-22
Infosphere Master Data Management HIGH 7.5
CVE-2014-3063

IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1-FP11 and 11.x before 11.0-FP5 and InfoSphere Master Data Management Se…

Patch available
Fix from $1,950 2014-08-17
Embedded Websphere Application Server MEDIUM 6.9
CVE-2014-3020

install.sh in the Embedded WebSphere Application Server (eWAS) 7.0 before FP33 in IBM Tivoli Integrated Portal (TIP) 2.1 and 2.2 sets world-writable …

Mitigation only
Fix from $1,600 2014-07-29
Storwize Unified V7000 Software MEDIUM 6.5
CVE-2014-3043

IBM Storwize V7000 Unified 1.3.x and 1.4.x before 1.4.3.3 allows remote authenticated users to gain privileges by leveraging access to the service ac…

Mitigation only
Fix from $1,600 2014-07-19
Vios HIGH 7.2
CVE-2014-3074

The runtime linker in IBM AIX 6.1 and 7.1 and VIOS 2.2.x allows local users to create a mode-666 root-owned file, and consequently gain privileges, b…

No fix yet
Fix from $1,950 2014-07-02
Sametime Meeting Server MEDIUM 5.5
CVE-2014-3088

stconf.nsf in IBM Sametime Meeting Server 8.5.1 relies on the client to validate the file format used in wAttach?OpenForm multipart/form-data POST re…

No fix yet
Fix from $1,600 2014-07-01
Openpages Grc Platform MEDIUM 6.4
CVE-2011-1381

Unspecified vulnerability in IBM OpenPages GRC Platform 6.1.0.1 before IF4 allows remote attackers to bypass intended access restrictions via unknown…

Mitigation only
Fix from $1,600 2014-06-27
Pureapplication System MEDIUM 6.6
CVE-2014-0960

IBM PureApplication System 1.0 before 1.0.0.4 cfix8 and 1.1 before 1.1.0.4 IF1 allows remote authenticated users to bypass intended access restrictio…

Mitigation only
Fix from $1,600 2014-06-14
Db2 HIGH 8.5
CVE-2013-6744

The Stored Procedure infrastructure in IBM DB2 9.5, 9.7 before FP9a, 10.1 before FP3a, and 10.5 before FP3a on Windows allows remote authenticated us…

Mitigation only
Fix from $1,950 2014-05-30
Maximo Asset Management MEDIUM 6.0
CVE-2014-0849

IBM Maximo Asset Management 7.x before 7.5.0.3 IFIX027 and SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2 allow remote authent…

Mitigation only
Fix from $1,600 2014-05-26
Maximo Asset Management MEDIUM 6.5
CVE-2013-5465

IBM Maximo Asset Management 7.x before 7.1.1.7 LAFIX.20140319-0837, 7.1.1.11 before IFIX.20140323-0749, 7.1.1.12 before IFIX.20140321-1336, 7.5.x bef…

Mitigation only
Fix from $1,600 2014-05-26
Maximo Asset Management MEDIUM 6.0
CVE-2013-5464

IBM Maximo Asset Management 7.5.x before 7.5.0.3 IFIX027, 7.5.0.4 before IFIX011, and 7.5.0.5 before IFIX006 and SmartCloud Control Desk 7.x before 7…

Mitigation only
Fix from $1,600 2014-05-26
Sametime MEDIUM 5.0
CVE-2013-3981

The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to download avatar photos of arbitrary users v…

Mitigation only
Fix from $1,600 2014-05-26
Business Process Manager MEDIUM 6.0
CVE-2014-0908

The User Attribute implementation in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.2, and 8.5.x through 8.5.0.1 does …

Mitigation only
Fix from $1,600 2014-04-10
Aix MEDIUM 6.5
CVE-2014-0899

ftpd in IBM AIX 7.1.1 before SP10 and 7.1.2 before SP5, when a Workload Partition (aka WPAR) for AIX 5.2 or 5.3 is used, allows remote authenticated …

Mitigation only
Fix from $1,600 2014-03-11
Cognos Business Intelligence MEDIUM 5.0
CVE-2014-0854

The server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1 before IF6, 10.1.1 before IF5, 10.2 before IF7, 10.2.1 before IF4, and 10.2.1.1 befor…

Mitigation only
Fix from $1,600 2014-02-22
Sametime HIGH 7.5
CVE-2013-6742

The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 do not have an off autocomplete attribute for a password field, whic…

Mitigation only
Fix from $1,950 2014-02-14
Sametime MEDIUM 5.0
CVE-2013-3978

The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 does not send the appropriate HTTP response headers to prevent unwan…

Mitigation only
Fix from $1,600 2014-02-14
Websphere Dashboard Framework MEDIUM 5.8
CVE-2013-6728

The charting component in IBM WebSphere Dashboard Framework (WDF) 6.1.5 and 7.0.1 allows remote attackers to view or delete image files by leveraging…

Mitigation only
Fix from $1,600 2014-02-14
Financial Transaction Manager MEDIUM 5.5
CVE-2014-0833

The OAC component in IBM Financial Transaction Manager (FTM) 2.0 before 2.0.0.3 does not properly enforce operator-intervention requirements, which a…

Mitigation only
Fix from $1,600 2014-02-01
Sametime MEDIUM 5.0
CVE-2013-6727

The Connect client in IBM Sametime 8.5.2 through 8.5.2.1 and 9.0 before HF1 does not properly restrict unsigned Java plugins, which allows remote att…

Mitigation only
Fix from $1,600 2014-01-31
Tivoli Application Dependency Discovery Manager HIGH 7.5
CVE-2013-2974

The BIRT viewer in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.1.x before 7.2.1.5 allows remote authenticated users to bypass aut…

Mitigation only
Fix from $1,950 2014-01-29
Websphere Portal MEDIUM 5.0
CVE-2013-6723

IBM WebSphere Portal 8.0.0.1 before CF09 does not properly handle references in compute="always" Web Content Manager (WCM) navigator components, whic…

Patch available
Fix from $1,600 2013-12-22
Websphere Portal MEDIUM 5.0
CVE-2013-6735

IBM WebSphere Portal 6.0.0.x through 6.0.0.1, 6.0.1.x through 6.0.1.7, 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x through 7.…

Patch available
Fix from $1,600 2013-12-22
Flex System Manager MEDIUM 6.8
CVE-2013-5424

IBM Flex System Manager (FSM) 1.3.0 allows remote attackers to bypass intended access restrictions, and create new user accounts or execute tasks, by…

Mitigation only
Fix from $1,600 2013-10-25