Vulnerability index

Browse CVEs

201 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Aix MEDIUM 6.9
CVE-2012-2179

libodm.a in IBM AIX 5.3, 6.1, and 7.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary file.

Patch available
Fix from $1,600 2012-06-22
Lotus Expeditor MEDIUM 5.0
CVE-2012-0191

The web container in IBM Lotus Expeditor 6.1.x and 6.2.x before 6.2 FP5+Security Pack does not properly perform access control for requests, which al…

Mitigation only
Fix from $1,600 2012-06-22
Aix HIGH 7.2
CVE-2012-0745

The getpwnam function in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.1.0.10 through 2.2.1.3 does not properly interact with customer-extended LDAP user filt…

Mitigation only
Fix from $1,950 2012-05-04
Rational Appscan MEDIUM 6.0
CVE-2012-0733

IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1, when Integrated Windows authentication is used, allows remote authenticated users to obta…

Mitigation only
Fix from $1,600 2012-05-03
Db2 HIGH 10.0
CVE-2012-1797

IBM DB2 9.5 uses world-writable permissions for nodes.reg, which has unspecified impact and attack vectors.

Mitigation only
Fix from $1,950 2012-03-20
Db2 Tools For Z\/os MEDIUM 5.0
CVE-2011-4435

The web-server component in the Consolidation and Analysis Engine (CAE) Server in DB2 Query Monitor in IBM DB2 Tools 2.3.0 for z/OS does not prevent …

Mitigation only
Fix from $1,600 2011-11-11
Websphere Application Server MEDIUM 5.0
CVE-2009-2747

The Java Naming and Directory Interface (JNDI) implementation in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.39, 6.1 before 6.1.0.29, and…

Mitigation only
Fix from $1,600 2011-10-30
Web Application Firewall MEDIUM 5.0
CVE-2011-3140

IBM Web Application Firewall, as used on the G400 IPS-G400-IB-1 and GX4004 IPS-GX4004-IB-2 appliances with update 31.030, does not properly handle qu…

No fix yet
Fix from $1,600 2011-08-15
Infosphere Datastage HIGH 7.2
CVE-2011-3123

IBM InfoSphere Information Server 8.5 and 8.5.0.1 on Unix and Linux, as used in IBM InfoSphere DataStage 8.5 and 8.5.0.1 and other products, uses wea…

Mitigation only
Fix from $1,950 2011-08-10
Infosphere Datastage HIGH 7.2
CVE-2011-3124

IBM InfoSphere Information Server 8.5 and 8.5.0.1 on Unix and Linux, as used in IBM InfoSphere DataStage 8.5 and 8.5.0.1 and other products, assigns …

Mitigation only
Fix from $1,950 2011-08-10
Tivoli Management Framework HIGH 9.0
CVE-2011-2330

Tivoli Endpoint in IBM Tivoli Management Framework 3.7.1, 4.1, 4.1.1, and 4.3.1 has an unspecified "built-in account" that is "trivially" accessed, w…

No fix yet
Fix from $1,950 2011-06-02
Datacap Taskmaster Capture MEDIUM 6.8
CVE-2011-2143

IBM Datacap Taskmaster Capture 8.0.1 before FP1, when Windows Authentication is enabled, allows remote attackers to obtain login access by using an i…

Mitigation only
Fix from $1,600 2011-05-16
Db2 MEDIUM 6.5
CVE-2011-1846

IBM DB2 9.5 before FP7 and 9.7 before FP4 on Linux, UNIX, and Windows does not properly revoke role membership from groups, which allows remote authe…

Fix: after 9.7
Fix from $1,600 2011-05-03
Websphere Application Server MEDIUM 6.8
CVE-2011-1683

IBM WebSphere Application Server (WAS) 6.0.x through 6.0.2.43, 6.1.x before 6.1.0.37, and 7.0.x before 7.0.0.17 on z/OS, when a Local OS user registr…

Mitigation only
Fix from $1,600 2011-04-13
Websphere Application Server MEDIUM 6.5
CVE-2011-1321

The AuthCache purge implementation in the Security component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.37 and 7.x before 7.0.0.1…

Mitigation only
Fix from $1,600 2011-03-08
Websphere Application Server MEDIUM 6.0
CVE-2011-1311

The Security component in IBM WebSphere Application Server (WAS) before 7.0.0.15, when a J2EE 1.4 application is used, determines the security role m…

Fix: after 7.0.0.13
Fix from $1,600 2011-03-08
Filenet P8 Content Engine MEDIUM 5.0
CVE-2011-1046

IBM FileNet P8 Content Engine (aka P8CE) 4.0.1 through 5.0.0, as used in FileNet P8 Content Manager (CM) and FileNet P8 Business Process Manager (BPM…

Mitigation only
Fix from $1,600 2011-02-21
Lotus Connections MEDIUM 6.8
CVE-2011-1032

IBM Lotus Connections 3.0, when IBM WebSphere Application Server 7.0.0.11 is used, does not properly restrict access to the internal login module, wh…

Mitigation only
Fix from $1,600 2011-02-15
Db2 MEDIUM 6.5
CVE-2011-0757

IBM DB2 9.1 before FP10, 9.5 before FP6a, and 9.7 before FP2 on Linux, UNIX, and Windows does not properly revoke the DBADM authority, which allows r…

Fix: after 9.7
Fix from $1,600 2011-02-02
Websphere Application Server MEDIUM 5.0
CVE-2011-0316

The Administrative Console component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.35 and 7.0 before 7.0.0.15 does not properly restrict…

Mitigation only
Fix from $1,600 2011-01-12
Lotus Mobile Connect MEDIUM 5.0
CVE-2010-4595

The Connection Manager in IBM Lotus Mobile Connect before 6.1.4 disables the http.device.stanza blacklisting functionality for HTTP Access Services (…

Fix: after 6.1.3
Fix from $1,600 2010-12-22
Websphere Service Registry And Repository MEDIUM 5.0
CVE-2010-2644

IBM WebSphere Service Registry and Repository (WSRR) 7.0.0 before FP1 does not properly implement access control, which allows remote attackers to pe…

Mitigation only
Fix from $1,600 2010-12-22
Omnifind HIGH 7.5
CVE-2010-3893

The administrator interface in IBM OmniFind Enterprise Edition 8.x and 9.x does not restrict use of a session ID (aka SID) value to a single IP addre…

No fix yet
Fix from $1,950 2010-11-12
Omnifind HIGH 7.2
CVE-2010-3895

esRunCommand in IBM OmniFind Enterprise Edition before 9.1 allows local users to gain privileges by specifying an arbitrary command name as the first…

Fix: after 9.0
Fix from $1,950 2010-11-12
Omnifind MEDIUM 5.0
CVE-2010-3898

IBM OmniFind Enterprise Edition 8.x and 9.x does not properly restrict the cookie path of administrator (aka ESAdmin) cookies, which might allow remo…

Mitigation only
Fix from $1,600 2010-11-12
Db2 HIGH 7.2
CVE-2010-3733

The Engine Utilities component in IBM DB2 UDB 9.5 before FP6a uses world-writable permissions for the sqllib/cfg/db2sprf file, which might allow loca…

Mitigation only
Fix from $1,950 2010-10-05
Db2 MEDIUM 5.0
CVE-2010-3734

The Install component in IBM DB2 UDB 9.5 before FP6a on Linux, UNIX, and Windows enforces an unintended limit on password length, which makes it easi…

Mitigation only
Fix from $1,600 2010-10-05
Db2 MEDIUM 5.0
CVE-2010-3738

The Security component in IBM DB2 UDB 9.5 before FP6a logs AUDIT events by using a USERID and an AUTHID value corresponding to the instance owner, in…

Mitigation only
Fix from $1,600 2010-10-05
Db2 MEDIUM 5.0
CVE-2010-3474

IBM DB2 9.7 before FP3 does not perform the expected drops or invalidations of dependent functions upon a loss of privileges by the functions' owners…

Mitigation only
Fix from $1,600 2010-09-20
Filenet P8 Application Engine MEDIUM 6.4
CVE-2009-5002

The Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 4.0.2.x before 4.0.2.1-P8AE-FP001 does not record Get Content Failure Au…

Mitigation only
Fix from $1,600 2010-09-20