Vulnerability index

Browse CVEs

79 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Security Key Lifecycle Manager CRITICAL 9.8
CVE-2016-6095

IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 uses an inadequate account lockout setting that could allow a remote attacker to brute force account cre…

Patch available
Fix from $2,300 2017-02-02
Urbancode Deploy HIGH 7.5
CVE-2016-9008

IBM UrbanCode Deploy could allow a malicious user to access the Agent Relay ActiveMQ Broker JMX interface and run plugins on the agent.

Patch available
Fix from $1,950 2017-02-01
Urbancode Deploy CRITICAL 10.0
CVE-2016-8938

IBM UrbanCode Deploy could allow a user to execute code using a specially crafted file upload that would replace code on the server. This code could …

Patch available
Fix from $2,300 2017-02-01
Kenexa Lms HIGH 8.8
CVE-2016-8931

IBM Kenexa LMS on Cloud could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vuln…

Patch available
Fix from $1,950 2017-02-01
Kenexa Lms HIGH 8.8
CVE-2016-8932

IBM Kenexa LMS on Cloud could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vuln…

Patch available
Fix from $1,950 2017-02-01
Urbancode Deploy HIGH 7.5
CVE-2016-2942

IBM UrbanCode Deploy could allow an authenticated attacker with special permissions to craft a script on the server in a way that will cause processe…

Patch available
Fix from $1,950 2017-02-01
Security Key Lifecycle Manager HIGH 8.2
CVE-2016-6105

IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 do not perform an authentication check for a critical resource or functionality allowing anonymous users…

Patch available
Fix from $1,950 2017-02-01
Bigfix Platform MEDIUM 6.5
CVE-2016-6085

IBM BigFix Platform could allow an attacker on the local network to crash the BES and relay servers.

Patch available
Fix from $1,600 2017-02-01
Security Privileged Identity Manager CRITICAL 9.8
CVE-2016-5964

IBM Security Privileged Identity Manager Virtual Appliance version 2.0.2 uses an inadequate account lockout setting that could allow a remote attacke…

Patch available
Fix from $2,300 2017-02-01
Security Privileged Identity Manager MEDIUM 6.3
CVE-2016-5990

IBM Security Privileged Identity Manager Virtual Appliance allows an authenticated user to upload malicious files that would be automatically execute…

Patch available
Fix from $1,600 2017-02-01
Powerkvm MEDIUM 6.5
CVE-2016-3044

The Linux kernel component in IBM PowerKVM 2.1 before 2.1.1.3-65.10 and 3.1 before 3.1.0.2 allows guest OS users to cause a denial of service (host O…

Mitigation only
Fix from $1,600 2016-12-01
Ims Enterprise Suite HIGH 8.1
CVE-2016-2887

IBM IMS Enterprise Suite Data Provider before 3.2.0.1 for Microsoft .NET allows remote authenticated users to obtain sensitive information or modify …

Fix: after 3.2.0.0
Fix from $1,950 2016-11-30
Bigfix Remote Control HIGH 8.1
CVE-2016-2929

IBM BigFix Remote Control before 9.1.3 does not properly restrict password choices, which makes it easier for remote attackers to obtain access via a…

Fix: after 9.1.2
Fix from $1,950 2016-11-25
Jazz Reporting Service HIGH 7.5
CVE-2016-0319

The XML parser in Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 allows remote authenticated administr…

Patch available
Fix from $1,950 2016-11-25
Jazz Reporting Service MEDIUM 5.0
CVE-2016-0318

Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 does not destroy a Session ID upon a logout action, whi…

Patch available
Fix from $1,600 2016-11-25
Jazz Reporting Service MEDIUM 6.5
CVE-2016-0317

Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 allows remote attackers to conduct clickjacking attacks…

Patch available
Fix from $1,600 2016-11-25
Financial Transaction Manager MEDIUM 5.7
CVE-2016-3060

Payments Director in IBM Financial Transaction Manager (FTM) for ACH Services, Check Services, and Corporate Payment Services (CPS) 3.0.0.x before fp…

Patch available
Fix from $1,600 2016-10-29
Security Guardium Database Activity Monitor HIGH 8.8
CVE-2016-0241

IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote authent…

Patch available
Fix from $1,950 2016-10-22
Websphere Application Server HIGH 7.5
CVE-2016-5983

IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.43, 8.0 before 8.0.0.13, 8.5 before 8.5.5.11, 9.0 before 9.0.0.2, and Liberty before 16.0.0.4…

Patch available
Fix from $1,950 2016-10-05
Security Privileged Identity Manager Virtual Appliance MEDIUM 6.8
CVE-2016-5972

IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 uses weak permissions for unspecified resources, which allows…

Fix: after 2.0.2
Fix from $1,600 2016-09-26
Security Privileged Identity Manager Virtual Appliance HIGH 8.8
CVE-2016-5963

IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 does not properly validate updates, which allows remote authe…

Patch available
Fix from $1,950 2016-09-26
Spectrum Control MEDIUM 5.4
CVE-2016-5943

IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to bypass intended access re…

Patch available
Fix from $1,600 2016-09-26
Websphere Portal MEDIUM 6.5
CVE-2016-5954

IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF30, 8.0.0 through 8.0.0.1 CF21, and 8.5.0 before…

Patch available
Fix from $1,600 2016-09-12
Connections Portlets MEDIUM 6.5
CVE-2016-2989

Open redirect vulnerability in the Connections Portlets component 5.x before 5.0.2 for IBM WebSphere Portal allows remote attackers to redirect users…

Patch available
Fix from $1,600 2016-08-08
Security Identity Manager Adapter HIGH 7.4
CVE-2016-0340

IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 mishandles session expiration, which allow…

Mitigation only
Fix from $1,950 2016-07-15
Security Identity Manager Adapter MEDIUM 5.6
CVE-2016-0339

IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 mishandles session identifiers after logou…

Mitigation only
Fix from $1,600 2016-07-15
Jazz Reporting Service HIGH 8.8
CVE-2016-0315

The Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 main…

Mitigation only
Fix from $1,950 2016-07-08
Watson Developer Cloud CRITICAL 9.8
CVE-2016-0391

The IBM Watson Developer Cloud services on Bluemix platforms do not properly generate random numbers for service-instance credentials, which makes it…

Mitigation only
Fix from $2,300 2016-07-02
Business Process Manager MEDIUM 6.5
CVE-2016-0349

IBM Business Process Manager 8.5.6 through 8.5.6.2 and 8.5.7 before 8.5.7.CF201606 allows remote authenticated users to bypass intended access restri…

Mitigation only
Fix from $1,600 2016-06-30
Domino HIGH 8.1
CVE-2016-0304

The Java Console in IBM Domino 8.5.x before 8.5.3 FP6 IF13 and 9.x before 9.0.1 FP6, when a certain unsupported configuration involving UNC share pat…

Mitigation only
Fix from $1,950 2016-06-29