Vulnerability index

Browse CVEs

201 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
HIGH 7.1 CVE-2013-5428 IBM WebSphere DataPower XC10 appliances 2.5.0 do not require authentication for all administrative actions, which allows remote attackers to cause a … Websphere Datapower Xc10 Appliance Mitigation only Fix from $1,9502013-10-22 MEDIUM 5.2 CVE-2013-0577 The Optim E-Business Console in IBM Data Growth Solution for Oracle E-business Suite 6.0 through 9.1 allows remote authenticated users to bypass inte… Infosphere Optim Data Growth For Oracle E Business Suite Mitigation only Fix from $1,6002013-10-10 MEDIUM 5.8 CVE-2013-4067 IBM InfoSphere Information Server 8.0, 8.1, 8.5 through FP3, 8.7, and 9.1 allows remote attackers to hijack sessions and read cookie values, or condu… Infosphere Information Server Mitigation only Fix from $1,6002013-10-02 MEDIUM 6.5 CVE-2013-4027 IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.12, and 7.5 before 7.5.0.5 allows remote authenticated users to bypass intended acce… Maximo Asset Management Mitigation only Fix from $1,6002013-10-01 MEDIUM 6.8 CVE-2012-3323 IBM Maximo Asset Management 6.2 before 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.3 allows remote attackers to gain privileges via unspecified … Maximo Asset Management No fix yet Fix from $1,6002013-10-01 MEDIUM 6.9 CVE-2013-5373 The RemoteClient component in IBM Rational ClearCase 8.0.0.03 through 8.0.0.07, and 8.0.1, uses world-writable permissions for the rcleartool script,… Rational Clearcase Mitigation only Fix from $1,6002013-09-25 MEDIUM 5.0 CVE-2013-3016 IBM WebSphere Portal 6.1, 7.0, and 8.0 allows remote attackers to access the user directory via a crafted request for a servlet, related to the serve… Websphere Portal Mitigation only Fix from $1,6002013-08-21 HIGH 8.5 CVE-2013-3005 The TFTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, when RBAC is enabled, allows remote authenticated users to bypass intended file… Aix Mitigation only Fix from $1,9502013-07-06 HIGH 7.2 CVE-2013-0536 ntmulti.exe in the Multi User Profile Cleanup service in IBM Notes 8.0, 8.0.1, 8.0.2, 8.5, 8.5.1, 8.5.2, 8.5.3 before FP5, and 9.0 before IF2 allows … Lotus Inotes Mitigation only Fix from $1,9502013-06-21 MEDIUM 5.0 CVE-2013-0529 The Browser in IBM Sterling Connect:Direct 1.4 before 1.4.0.11 and 1.5 through 1.5.0.1 does not set the secure flag for the session cookie in an http… Sterling Connect Direct User Interface Mitigation only Fix from $1,6002013-06-21 MEDIUM 6.8 CVE-2013-2989 The file-copying functionality in IBM Sterling Connect:Direct 3.8.00, 4.0.00, and 4.1.0 for UNIX on AIX 6.1 through 7.1 uses incorrect privileges, wh… Sterling Connect Mitigation only Fix from $1,6002013-05-28 MEDIUM 5.8 CVE-2013-0127 IBM Lotus Notes 8.x before 8.5.3 FP4 Interim Fix 1 and 9.0 before Interim Fix 1 does not block APPLET elements in HTML e-mail, which allows remote at… Lotus Notes Mitigation only Fix from $1,6002013-05-01 HIGH 9.3 CVE-2013-0501 The EdrawSoft EDOFFICE.EDOfficeCtrl.1 ActiveX control, as used in Edraw Office Viewer Component, the client in IBM Cognos Disclosure Management (CDM)… Cognos Disclosure Management Mitigation only Fix from $1,9502013-04-12 HIGH 7.2 CVE-2012-5938 The installation process in IBM InfoSphere Information Server 8.1, 8.5, 8.7, and 9.1 on UNIX and Linux sets incorrect permissions and ownerships for … Infosphere Information Server No fix yet Fix from $1,9502013-03-20 MEDIUM 6.5 CVE-2012-6355 IBM Maximo Asset Management 6.2 through 7.5, Maximo Asset Management Essentials 6.2 through 7.5, Tivoli Asset Management for IT 6.2 through 7.2, Tivo… Maximo Asset Management Mitigation only Fix from $1,6002013-02-20 MEDIUM 6.5 CVE-2012-6356 IBM Maximo Asset Management 7.5, Maximo Asset Management Essentials 7.5, and SmartCloud Control Desk 7.5 allow remote authenticated users to gain pri… Maximo Asset Management Mitigation only Fix from $1,6002013-02-20 MEDIUM 6.5 CVE-2012-6357 IBM Maximo Asset Management 7.5, Maximo Asset Management Essentials 7.5, and SmartCloud Control Desk 7.5 allow remote authenticated users to gain pri… Maximo Asset Management Mitigation only Fix from $1,6002013-02-20 MEDIUM 6.5 CVE-2012-3321 IBM SmartCloud Control Desk 7.5 allows remote authenticated users to bypass intended access restrictions via vectors involving an expired password. Smartcloud Control Desk Mitigation only Fix from $1,6002013-02-20 MEDIUM 6.5 CVE-2012-0205 InfoSphere Metadata Workbench (MWB) 8.1 through 8.7 in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 does not properly restrict use … Infosphere Information Server Mitigation only Fix from $1,6002013-01-31 MEDIUM 6.5 CVE-2012-0701 The client applications in the DataStage Administrator client in InfoSphere DataStage in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8… Infosphere Datastage Mitigation only Fix from $1,6002013-01-31 HIGH 7.5 CVE-2012-4816 IBM Rational Automation Framework (RAF) 3.x through 3.0.0.5 allows remote attackers to bypass intended Env Gen Wizard (aka Environment Generation Wiz… Rational Automation Framework Mitigation only Fix from $1,9502012-12-26 HIGH 7.2 CVE-2012-5951 Unspecified vulnerability in IBM Tivoli NetView 1.4, 5.1 through 5.4, and 6.1 on z/OS allows local users to gain privileges by leveraging access to t… Tivoli Netview Mitigation only Fix from $1,9502012-12-26 MEDIUM 6.9 CVE-2012-3317 IBM WebSphere Message Broker 6.1 before 6.1.0.11, 7.0 before 7.0.0.5, and 8.0 before 8.0.0.2 has incorrect ownership of certain uninstaller Java Runt… Websphere Message Broker Mitigation only Fix from $1,6002012-12-05 HIGH 9.0 CVE-2012-5759 The IBM WebSphere DataPower XC10 Appliance 2.0.0.0 through 2.0.0.3 and 2.1.0.0 through 2.1.0.2 allows remote authenticated users to bypass intended a… Websphere Datapower Xc10 Appliance Mitigation only Fix from $1,9502012-11-23 MEDIUM 6.8 CVE-2012-4845 The FTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly manage privileges in an RBAC environment, which allows attacke… Vios Mitigation only Fix from $1,6002012-10-20 MEDIUM 5.5 CVE-2012-2164 The Web client in IBM Rational ClearQuest 7.1.x before 7.1.2.7 and 8.x before 8.0.0.3 allows remote authenticated users to bypass intended access res… Rational Clearquest Mitigation only Fix from $1,6002012-08-17 HIGH 7.5 CVE-2012-2203 IBM Global Security Kit (aka GSKit) before 8.0.14.22, as used in IBM Rational Directory Server, IBM Tivoli Directory Server, and other products, uses… Global Security Kit after 8.0.13 Fix from $1,9502012-08-08 HIGH 7.2 CVE-2012-2188 IBM Power Hardware Management Console (HMC) 7R3.5.0 before SP4, 7R7.1.0 and 7R7.2.0 before 7R7.2.0 SP3, and 7R7.3.0 before SP2, and Systems Director … Power Hardware Management Console Firmware Mitigation only Fix from $1,9502012-08-06 HIGH 9.0 CVE-2012-2163 IBM Scale Out Network Attached Storage (SONAS) 1.1 through 1.3.1 allows remote authenticated administrators to execute arbitrary Linux commands via t… Scale Out Network Attached Storage Mitigation only Fix from $1,9502012-07-30 HIGH 7.2 CVE-2012-2200 The default configuration of sendmail in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, allows local users to gain privileges by entering a comma… Vios Mitigation only Fix from $1,9502012-06-27