Vulnerability index

Browse CVEs

201 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
MEDIUM 6.9 CVE-2012-2179 libodm.a in IBM AIX 5.3, 6.1, and 7.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary file. Aix Patch available Fix from $1,6002012-06-22 MEDIUM 5.0 CVE-2012-0191 The web container in IBM Lotus Expeditor 6.1.x and 6.2.x before 6.2 FP5+Security Pack does not properly perform access control for requests, which al… Lotus Expeditor Mitigation only Fix from $1,6002012-06-22 HIGH 7.2 CVE-2012-0745 The getpwnam function in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.1.0.10 through 2.2.1.3 does not properly interact with customer-extended LDAP user filt… Aix Mitigation only Fix from $1,9502012-05-04 MEDIUM 6.0 CVE-2012-0733 IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1, when Integrated Windows authentication is used, allows remote authenticated users to obta… Rational Appscan Mitigation only Fix from $1,6002012-05-03 HIGH 10.0 CVE-2012-1797 IBM DB2 9.5 uses world-writable permissions for nodes.reg, which has unspecified impact and attack vectors. Db2 Mitigation only Fix from $1,9502012-03-20 MEDIUM 5.0 CVE-2011-4435 The web-server component in the Consolidation and Analysis Engine (CAE) Server in DB2 Query Monitor in IBM DB2 Tools 2.3.0 for z/OS does not prevent … Db2 Tools For Z\/os Mitigation only Fix from $1,6002011-11-11 MEDIUM 5.0 CVE-2009-2747 The Java Naming and Directory Interface (JNDI) implementation in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.39, 6.1 before 6.1.0.29, and… Websphere Application Server Mitigation only Fix from $1,6002011-10-30 MEDIUM 5.0 CVE-2011-3140 IBM Web Application Firewall, as used on the G400 IPS-G400-IB-1 and GX4004 IPS-GX4004-IB-2 appliances with update 31.030, does not properly handle qu… Web Application Firewall No fix yet Fix from $1,6002011-08-15 HIGH 7.2 CVE-2011-3123 IBM InfoSphere Information Server 8.5 and 8.5.0.1 on Unix and Linux, as used in IBM InfoSphere DataStage 8.5 and 8.5.0.1 and other products, uses wea… Infosphere Datastage Mitigation only Fix from $1,9502011-08-10 HIGH 7.2 CVE-2011-3124 IBM InfoSphere Information Server 8.5 and 8.5.0.1 on Unix and Linux, as used in IBM InfoSphere DataStage 8.5 and 8.5.0.1 and other products, assigns … Infosphere Datastage Mitigation only Fix from $1,9502011-08-10 HIGH 9.0 CVE-2011-2330 Tivoli Endpoint in IBM Tivoli Management Framework 3.7.1, 4.1, 4.1.1, and 4.3.1 has an unspecified "built-in account" that is "trivially" accessed, w… Tivoli Management Framework No fix yet Fix from $1,9502011-06-02 MEDIUM 6.8 CVE-2011-2143 IBM Datacap Taskmaster Capture 8.0.1 before FP1, when Windows Authentication is enabled, allows remote attackers to obtain login access by using an i… Datacap Taskmaster Capture Mitigation only Fix from $1,6002011-05-16 MEDIUM 6.5 CVE-2011-1846 IBM DB2 9.5 before FP7 and 9.7 before FP4 on Linux, UNIX, and Windows does not properly revoke role membership from groups, which allows remote authe… Db2 after 9.7 Fix from $1,6002011-05-03 MEDIUM 6.8 CVE-2011-1683 IBM WebSphere Application Server (WAS) 6.0.x through 6.0.2.43, 6.1.x before 6.1.0.37, and 7.0.x before 7.0.0.17 on z/OS, when a Local OS user registr… Websphere Application Server Mitigation only Fix from $1,6002011-04-13 MEDIUM 6.5 CVE-2011-1321 The AuthCache purge implementation in the Security component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.37 and 7.x before 7.0.0.1… Websphere Application Server Mitigation only Fix from $1,6002011-03-08 MEDIUM 6.0 CVE-2011-1311 The Security component in IBM WebSphere Application Server (WAS) before 7.0.0.15, when a J2EE 1.4 application is used, determines the security role m… Websphere Application Server after 7.0.0.13 Fix from $1,6002011-03-08 MEDIUM 5.0 CVE-2011-1046 IBM FileNet P8 Content Engine (aka P8CE) 4.0.1 through 5.0.0, as used in FileNet P8 Content Manager (CM) and FileNet P8 Business Process Manager (BPM… Filenet P8 Content Engine Mitigation only Fix from $1,6002011-02-21 MEDIUM 6.8 CVE-2011-1032 IBM Lotus Connections 3.0, when IBM WebSphere Application Server 7.0.0.11 is used, does not properly restrict access to the internal login module, wh… Lotus Connections Mitigation only Fix from $1,6002011-02-15 MEDIUM 6.5 CVE-2011-0757 IBM DB2 9.1 before FP10, 9.5 before FP6a, and 9.7 before FP2 on Linux, UNIX, and Windows does not properly revoke the DBADM authority, which allows r… Db2 after 9.7 Fix from $1,6002011-02-02 MEDIUM 5.0 CVE-2011-0316 The Administrative Console component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.35 and 7.0 before 7.0.0.15 does not properly restrict… Websphere Application Server Mitigation only Fix from $1,6002011-01-12 MEDIUM 5.0 CVE-2010-4595 The Connection Manager in IBM Lotus Mobile Connect before 6.1.4 disables the http.device.stanza blacklisting functionality for HTTP Access Services (… Lotus Mobile Connect after 6.1.3 Fix from $1,6002010-12-22 MEDIUM 5.0 CVE-2010-2644 IBM WebSphere Service Registry and Repository (WSRR) 7.0.0 before FP1 does not properly implement access control, which allows remote attackers to pe… Websphere Service Registry And Repository Mitigation only Fix from $1,6002010-12-22 HIGH 7.5 CVE-2010-3893 The administrator interface in IBM OmniFind Enterprise Edition 8.x and 9.x does not restrict use of a session ID (aka SID) value to a single IP addre… Omnifind No fix yet Fix from $1,9502010-11-12 HIGH 7.2 CVE-2010-3895 esRunCommand in IBM OmniFind Enterprise Edition before 9.1 allows local users to gain privileges by specifying an arbitrary command name as the first… Omnifind after 9.0 Fix from $1,9502010-11-12 MEDIUM 5.0 CVE-2010-3898 IBM OmniFind Enterprise Edition 8.x and 9.x does not properly restrict the cookie path of administrator (aka ESAdmin) cookies, which might allow remo… Omnifind Mitigation only Fix from $1,6002010-11-12 HIGH 7.2 CVE-2010-3733 The Engine Utilities component in IBM DB2 UDB 9.5 before FP6a uses world-writable permissions for the sqllib/cfg/db2sprf file, which might allow loca… Db2 Mitigation only Fix from $1,9502010-10-05 MEDIUM 5.0 CVE-2010-3734 The Install component in IBM DB2 UDB 9.5 before FP6a on Linux, UNIX, and Windows enforces an unintended limit on password length, which makes it easi… Db2 Mitigation only Fix from $1,6002010-10-05 MEDIUM 5.0 CVE-2010-3738 The Security component in IBM DB2 UDB 9.5 before FP6a logs AUDIT events by using a USERID and an AUTHID value corresponding to the instance owner, in… Db2 Mitigation only Fix from $1,6002010-10-05 MEDIUM 5.0 CVE-2010-3474 IBM DB2 9.7 before FP3 does not perform the expected drops or invalidations of dependent functions upon a loss of privileges by the functions' owners… Db2 Mitigation only Fix from $1,6002010-09-20 MEDIUM 6.4 CVE-2009-5002 The Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 4.0.2.x before 4.0.2.1-P8AE-FP001 does not record Get Content Failure Au… Filenet P8 Application Engine Mitigation only Fix from $1,6002010-09-20