Vulnerability index

Browse CVEs

201 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Websphere Datapower Xc10 Appliance HIGH 7.1
CVE-2013-5428

IBM WebSphere DataPower XC10 appliances 2.5.0 do not require authentication for all administrative actions, which allows remote attackers to cause a …

Mitigation only
Fix from $1,950 2013-10-22
Infosphere Optim Data Growth For Oracle E Business Suite MEDIUM 5.2
CVE-2013-0577

The Optim E-Business Console in IBM Data Growth Solution for Oracle E-business Suite 6.0 through 9.1 allows remote authenticated users to bypass inte…

Mitigation only
Fix from $1,600 2013-10-10
Infosphere Information Server MEDIUM 5.8
CVE-2013-4067

IBM InfoSphere Information Server 8.0, 8.1, 8.5 through FP3, 8.7, and 9.1 allows remote attackers to hijack sessions and read cookie values, or condu…

Mitigation only
Fix from $1,600 2013-10-02
Maximo Asset Management MEDIUM 6.5
CVE-2013-4027

IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.12, and 7.5 before 7.5.0.5 allows remote authenticated users to bypass intended acce…

Mitigation only
Fix from $1,600 2013-10-01
Maximo Asset Management MEDIUM 6.8
CVE-2012-3323

IBM Maximo Asset Management 6.2 before 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.3 allows remote attackers to gain privileges via unspecified …

No fix yet
Fix from $1,600 2013-10-01
Rational Clearcase MEDIUM 6.9
CVE-2013-5373

The RemoteClient component in IBM Rational ClearCase 8.0.0.03 through 8.0.0.07, and 8.0.1, uses world-writable permissions for the rcleartool script,…

Mitigation only
Fix from $1,600 2013-09-25
Websphere Portal MEDIUM 5.0
CVE-2013-3016

IBM WebSphere Portal 6.1, 7.0, and 8.0 allows remote attackers to access the user directory via a crafted request for a servlet, related to the serve…

Mitigation only
Fix from $1,600 2013-08-21
Aix HIGH 8.5
CVE-2013-3005

The TFTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, when RBAC is enabled, allows remote authenticated users to bypass intended file…

Mitigation only
Fix from $1,950 2013-07-06
Lotus Inotes HIGH 7.2
CVE-2013-0536

ntmulti.exe in the Multi User Profile Cleanup service in IBM Notes 8.0, 8.0.1, 8.0.2, 8.5, 8.5.1, 8.5.2, 8.5.3 before FP5, and 9.0 before IF2 allows …

Mitigation only
Fix from $1,950 2013-06-21
Sterling Connect Direct User Interface MEDIUM 5.0
CVE-2013-0529

The Browser in IBM Sterling Connect:Direct 1.4 before 1.4.0.11 and 1.5 through 1.5.0.1 does not set the secure flag for the session cookie in an http…

Mitigation only
Fix from $1,600 2013-06-21
Sterling Connect MEDIUM 6.8
CVE-2013-2989

The file-copying functionality in IBM Sterling Connect:Direct 3.8.00, 4.0.00, and 4.1.0 for UNIX on AIX 6.1 through 7.1 uses incorrect privileges, wh…

Mitigation only
Fix from $1,600 2013-05-28
Lotus Notes MEDIUM 5.8
CVE-2013-0127

IBM Lotus Notes 8.x before 8.5.3 FP4 Interim Fix 1 and 9.0 before Interim Fix 1 does not block APPLET elements in HTML e-mail, which allows remote at…

Mitigation only
Fix from $1,600 2013-05-01
Cognos Disclosure Management HIGH 9.3
CVE-2013-0501

The EdrawSoft EDOFFICE.EDOfficeCtrl.1 ActiveX control, as used in Edraw Office Viewer Component, the client in IBM Cognos Disclosure Management (CDM)…

Mitigation only
Fix from $1,950 2013-04-12
Infosphere Information Server HIGH 7.2
CVE-2012-5938

The installation process in IBM InfoSphere Information Server 8.1, 8.5, 8.7, and 9.1 on UNIX and Linux sets incorrect permissions and ownerships for …

No fix yet
Fix from $1,950 2013-03-20
Maximo Asset Management MEDIUM 6.5
CVE-2012-6355

IBM Maximo Asset Management 6.2 through 7.5, Maximo Asset Management Essentials 6.2 through 7.5, Tivoli Asset Management for IT 6.2 through 7.2, Tivo…

Mitigation only
Fix from $1,600 2013-02-20
Maximo Asset Management MEDIUM 6.5
CVE-2012-6356

IBM Maximo Asset Management 7.5, Maximo Asset Management Essentials 7.5, and SmartCloud Control Desk 7.5 allow remote authenticated users to gain pri…

Mitigation only
Fix from $1,600 2013-02-20
Maximo Asset Management MEDIUM 6.5
CVE-2012-6357

IBM Maximo Asset Management 7.5, Maximo Asset Management Essentials 7.5, and SmartCloud Control Desk 7.5 allow remote authenticated users to gain pri…

Mitigation only
Fix from $1,600 2013-02-20
Smartcloud Control Desk MEDIUM 6.5
CVE-2012-3321

IBM SmartCloud Control Desk 7.5 allows remote authenticated users to bypass intended access restrictions via vectors involving an expired password.

Mitigation only
Fix from $1,600 2013-02-20
Infosphere Information Server MEDIUM 6.5
CVE-2012-0205

InfoSphere Metadata Workbench (MWB) 8.1 through 8.7 in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 does not properly restrict use …

Mitigation only
Fix from $1,600 2013-01-31
Infosphere Datastage MEDIUM 6.5
CVE-2012-0701

The client applications in the DataStage Administrator client in InfoSphere DataStage in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8…

Mitigation only
Fix from $1,600 2013-01-31
Rational Automation Framework HIGH 7.5
CVE-2012-4816

IBM Rational Automation Framework (RAF) 3.x through 3.0.0.5 allows remote attackers to bypass intended Env Gen Wizard (aka Environment Generation Wiz…

Mitigation only
Fix from $1,950 2012-12-26
Tivoli Netview HIGH 7.2
CVE-2012-5951

Unspecified vulnerability in IBM Tivoli NetView 1.4, 5.1 through 5.4, and 6.1 on z/OS allows local users to gain privileges by leveraging access to t…

Mitigation only
Fix from $1,950 2012-12-26
Websphere Message Broker MEDIUM 6.9
CVE-2012-3317

IBM WebSphere Message Broker 6.1 before 6.1.0.11, 7.0 before 7.0.0.5, and 8.0 before 8.0.0.2 has incorrect ownership of certain uninstaller Java Runt…

Mitigation only
Fix from $1,600 2012-12-05
Websphere Datapower Xc10 Appliance HIGH 9.0
CVE-2012-5759

The IBM WebSphere DataPower XC10 Appliance 2.0.0.0 through 2.0.0.3 and 2.1.0.0 through 2.1.0.2 allows remote authenticated users to bypass intended a…

Mitigation only
Fix from $1,950 2012-11-23
Vios MEDIUM 6.8
CVE-2012-4845

The FTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly manage privileges in an RBAC environment, which allows attacke…

Mitigation only
Fix from $1,600 2012-10-20
Rational Clearquest MEDIUM 5.5
CVE-2012-2164

The Web client in IBM Rational ClearQuest 7.1.x before 7.1.2.7 and 8.x before 8.0.0.3 allows remote authenticated users to bypass intended access res…

Mitigation only
Fix from $1,600 2012-08-17
Global Security Kit HIGH 7.5
CVE-2012-2203

IBM Global Security Kit (aka GSKit) before 8.0.14.22, as used in IBM Rational Directory Server, IBM Tivoli Directory Server, and other products, uses…

Fix: after 8.0.13
Fix from $1,950 2012-08-08
Power Hardware Management Console Firmware HIGH 7.2
CVE-2012-2188

IBM Power Hardware Management Console (HMC) 7R3.5.0 before SP4, 7R7.1.0 and 7R7.2.0 before 7R7.2.0 SP3, and 7R7.3.0 before SP2, and Systems Director …

Mitigation only
Fix from $1,950 2012-08-06
Scale Out Network Attached Storage HIGH 9.0
CVE-2012-2163

IBM Scale Out Network Attached Storage (SONAS) 1.1 through 1.3.1 allows remote authenticated administrators to execute arbitrary Linux commands via t…

Mitigation only
Fix from $1,950 2012-07-30
Vios HIGH 7.2
CVE-2012-2200

The default configuration of sendmail in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, allows local users to gain privileges by entering a comma…

Mitigation only
Fix from $1,950 2012-06-27