Vulnerability index

Browse CVEs

201 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Db2 HIGH 7.5
CVE-2010-3194

The DB2DART program in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 allows attackers to bypass intended file access restrictions via un…

Mitigation only
Fix from $1,950 2010-08-31
Db2 MEDIUM 5.0
CVE-2010-3197

IBM DB2 9.7 before FP2 does not perform the expected access control on the monitor administrative views in the SYSIBMADM schema, which allows remote …

Mitigation only
Fix from $1,600 2010-08-31
Advanced Management Module MEDIUM 5.0
CVE-2010-2656

The IBM BladeCenter with Advanced Management Module (AMM) firmware build ID BPET48L, and possibly other versions before 4.7 and 5.0, stores sensitive…

Fix: after 2.48
Fix from $1,600 2010-07-08
P8 Content Engine HIGH 7.5
CVE-2010-2518

Unspecified vulnerability in the P8 Content Engine (P8CE) 4.5.1 before FP3 and the P8 Content Search Engine (P8CSE) before 4.5.0 FP3 and 4.5.1 before…

No fix yet
Fix from $1,950 2010-06-30
Director Agent HIGH 7.2
CVE-2010-1347

Director Agent 6.1 before 6.1.2.3 in IBM Systems Director on AIX and Linux uses incorrect permissions for the (1) diruninstall and (2) opt/ibm/direct…

Mitigation only
Fix from $1,950 2010-04-12
Db2 MEDIUM 6.5
CVE-2009-4438

The Query Compiler, Rewrite, and Optimizer component in IBM DB2 9.1 before FP8, 9.5 before FP5, and 9.7 before FP1 does not enforce privilege require…

Patch available
Fix from $1,600 2009-12-28
Db2 HIGH 7.2
CVE-2009-4331

The Install component in IBM DB2 9.5 before FP5 and 9.7 before FP1 configures the High Availability (HA) scripts with incorrect file-permission and a…

Patch available
Fix from $1,950 2009-12-16
Db2 MEDIUM 6.5
CVE-2009-3472

IBM DB2 8 before FP18, 9.1 before FP8, and 9.5 before FP4 allows remote authenticated users to bypass intended access restrictions, and update, inser…

Mitigation only
Fix from $1,600 2009-09-29
Websphere Application Server MEDIUM 5.0
CVE-2009-3106

The Servlet Engine/Web Container component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.37 does not properly implement security const…

Patch available
Fix from $1,600 2009-09-08
Websphere Application Server MEDIUM 5.0
CVE-2009-2091

The System Management/Repository component in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.5 on z/OS uses weak file permissions for new ap…

Patch available
Fix from $1,600 2009-08-13
Aix HIGH 7.2
CVE-2009-2669

A certain debugging component in IBM AIX 5.3 and 6.1 does not properly handle the (1) _LIB_INIT_DBG and (2) _LIB_INIT_DBG_FILE environment variables,…

Patch available
Fix from $1,950 2009-08-05
Websphere Application Server MEDIUM 6.4
CVE-2009-0904

The IBM Stax XMLStreamWriter in the Web Services component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 does not properly process XM…

Mitigation only
Fix from $1,600 2009-07-05
Websphere Mq HIGH 7.2
CVE-2009-0439

Unspecified vulnerability in the queue manager in IBM WebSphere MQ (WMQ) 5.3, 6.0 before 6.0.2.6, and 7.0 before 7.0.0.2 allows local users to gain p…

Patch available
Fix from $1,950 2009-02-24
Websphere Application Server HIGH 7.2
CVE-2009-0436

The (1) mod_ibm_ssl and (2) mod_cgid modules in IBM HTTP Server 6.0.x before 6.0.2.31 and 6.1.x before 6.1.0.19, as used in WebSphere Application Ser…

Patch available
Fix from $1,950 2009-02-10
Websphere Application Server MEDIUM 5.0
CVE-2009-0438

IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 on Windows allows remote attackers to bypass "Authorization checking" and obtain sensitive in…

Patch available
Fix from $1,600 2009-02-10
Websphere Portal HIGH 10.0
CVE-2008-5675

Unspecified vulnerability in IBM WebSphere Portal 6.0 before 6.0.1.5 has unknown impact and attack vectors related to "Access problems with BasicAuth…

Fix: after 6.0.1.4
Fix from $1,950 2008-12-19
Aix MEDIUM 6.9
CVE-2008-5384

crontab in bos.rte.cron in IBM AIX 6.1.0 through 6.1.2 allows local users with aix.system.config.cron authorization to gain privileges by launching a…

Patch available
Fix from $1,600 2008-12-09
Aix MEDIUM 6.9
CVE-2008-5385

enq in bos.rte.printers in IBM AIX 6.1.0 through 6.1.2, when a print queue is defined in /etc/qconfig, allows local users to delete arbitrary files v…

Patch available
Fix from $1,600 2008-12-09
Lotus Quickr HIGH 7.5
CVE-2008-4507

Unspecified vulnerability in IBM Lotus Quickr 8.1 before Fix pack 1 (8.1.0.1) allows editors to delete pages that were created by a different author …

Mitigation only
Fix from $1,950 2008-10-09
Lotus Quickr HIGH 7.5
CVE-2008-4506

Unspecified vulnerability in IBM Lotus Quickr 8.1 before Fix pack 1 (8.1.0.1) allows a place manager to "demote or delete a place superuser group" vi…

Mitigation only
Fix from $1,950 2008-10-09
Tivoli Netcool Webtop HIGH 7.2
CVE-2008-4294

IBM Tivoli Netcool/Webtop 2.1 before 2.1.0.5 preserves cached user privileges after logout, which allows physically proximate attackers to hijack a s…

Patch available
Fix from $1,950 2008-09-27
Aix HIGH 7.2
CVE-2008-4018

swcons in bos.rte.console in IBM AIX 5.2.0 through 6.1.1 allows local users in the system group to create or overwrite an arbitrary file, and establi…

Mitigation only
Fix from $1,950 2008-09-11
Db2 Universal Database HIGH 7.5
CVE-2008-3856

The routine infrastructure component in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP1 on Unix and Linux does not change the ownership of …

Fix: after 9.1
Fix from $1,950 2008-08-28
Db2 Universal Database MEDIUM 6.5
CVE-2008-3852

Unspecified vulnerability in the CLR stored procedure deployment from IBM Database Add-Ins for Visual Studio in the Visual Studio Net component in IB…

Fix: after 9.5
Fix from $1,600 2008-08-28
Websphere Portal HIGH 7.5
CVE-2008-3423

IBM WebSphere Portal 5.1 through 6.1.0.0 allows remote attackers to bypass authentication and obtain administrative access via unspecified vectors.

Patch available
Fix from $1,950 2008-08-04
Aix HIGH 7.2
CVE-2008-2515

Unspecified vulnerability in iostat in IBM AIX 5.2, 5.3, and 6.1 allows local users to gain privileges via unknown vectors related to an "environment…

Patch available
Fix from $1,950 2008-06-02
Db2 HIGH 8.5
CVE-2008-1998

The NNSTAT (aka SYSPROC.NNSTAT) procedure in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before FP1 on Windows allows remote authenticated users …

Mitigation only
Fix from $1,950 2008-04-28
Aix HIGH 7.2
CVE-2008-1710

Untrusted search path vulnerability in chnfsmnt in IBM AIX 6.1 allows local users to gain privileges via a modified PATH environment variable.

Mitigation only
Fix from $1,950 2008-04-09
Db2 Content Manager HIGH 10.0
CVE-2008-1681

Unspecified vulnerability in IBM DB2 Content Manager before 8.3 FP8 has unknown impact and attack vectors related to the AllowedTrustedLogin privileg…

Fix: after 8.3
Fix from $1,950 2008-04-04
Aix HIGH 7.2
CVE-2008-1593

The checkpoint and restart feature in the kernel in IBM AIX 5.2, 5.3, and 6.1 does not properly protect kernel memory, which allows local users to re…

Patch available
Fix from $1,950 2008-03-31