Vulnerability index

Browse CVEs

93 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Rational Clearcase MEDIUM 5.0
CVE-2014-3106

IBM Rational ClearQuest 7.1 before 7.1.2.15, 8.0.0 before 8.0.0.12, and 8.0.1 before 8.0.1.5 does not properly implement the Local Access Only protec…

Patch available
Fix from $1,600 2014-09-23
Rational Clearcase MEDIUM 5.0
CVE-2014-3101

The login form in the Web component in IBM Rational ClearQuest 7.1 before 7.1.2.15, 8.0.0 before 8.0.0.12, and 8.0.1 before 8.0.1.5 does not insert a…

Patch available
Fix from $1,600 2014-09-23
Security Access Manager For Web 8.0 Firmware HIGH 8.0
CVE-2014-3053

The Local Management Interface (LMI) in IBM Security Access Manager (ISAM) for Mobile 8.0 with firmware 8.0.0.0 through 8.0.0.3 and IBM Security Acce…

Mitigation only
Fix from $1,950 2014-06-21
Rational Requirements Composer MEDIUM 5.4
CVE-2013-3039

IBM Rational Requirements Composer before 4.0.4 does not properly perform authentication, which has unspecified impact and remote attack vectors.

Fix: after 4.0.3
Fix from $1,600 2013-09-12
Websphere Commerce MEDIUM 5.8
CVE-2013-2993

IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.7 does not properly perform authentication for unspecified web services, which allo…

Mitigation only
Fix from $1,600 2013-08-01
Infosphere Optim Data Growth For Oracle E Business Suite MEDIUM 5.0
CVE-2013-2954

The login page in the Console in IBM InfoSphere Optim Data Growth for Oracle E-Business Suite 6.x, 7.x, and 9.x before 9.1.0.3 does not limit the num…

Mitigation only
Fix from $1,600 2013-05-27
Lotus Domino HIGH 8.5
CVE-2013-0487

The Java Console in IBM Domino 8.5.x allows remote authenticated users to hijack temporary credentials by leveraging knowledge of configuration detai…

Mitigation only
Fix from $1,950 2013-03-27
Websphere Message Broker MEDIUM 5.0
CVE-2012-5952

IBM WebSphere Message Broker 6.1 before 6.1.0.12, 7.0 before 7.0.0.6, and 8.0 before 8.0.0.2 does not validate Basic Authentication credentials befor…

Mitigation only
Fix from $1,600 2013-02-20
San Volume Controller Software HIGH 7.5
CVE-2012-6354

The management GUI on the IBM SAN Volume Controller and Storwize V7000 6.x before 6.4.1.3 allows remote attackers to bypass authentication and obtain…

Mitigation only
Fix from $1,950 2013-02-19
Websphere Datapower Xc10 Appliance HIGH 7.8
CVE-2012-5758

The IBM WebSphere DataPower XC10 Appliance 2.0.0.0 through 2.0.0.3 and 2.1.0.0 through 2.1.0.2 does not require authentication for an unspecified int…

Mitigation only
Fix from $1,950 2012-11-23
Tivoli Federated Identity Manager MEDIUM 5.0
CVE-2012-3315

The Java servlets in the management console in IBM Tivoli Federated Identity Manager (TFIM) through 6.2.2 and Tivoli Federated Identity Manager Busin…

Fix: after 6.2.2
Fix from $1,600 2012-11-08
Lotus Notes Traveler MEDIUM 6.8
CVE-2012-5309

servlet/traveler in IBM Lotus Notes Traveler through 8.5.3.3 Interim Fix 1 does not properly restrict invalid authentication attempts, which makes it…

No fix yet
Fix from $1,600 2012-10-08
Ts3100 Tape Library Firmware MEDIUM 6.8
CVE-2011-1372

The Web User Interface on the IBM TS3100 and TS3200 tape libraries with firmware before A.60 allows remote attackers to bypass authentication and obt…

Mitigation only
Fix from $1,600 2011-11-28
Websphere Commerce HIGH 10.0
CVE-2011-3577

IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.3 does not properly implement Activity Token authentication for Web Services, which…

Mitigation only
Fix from $1,950 2011-09-20
Tivoli Federated Identity Manager MEDIUM 6.8
CVE-2009-5083

IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.2, when configured as an OpenID relying party, does not perform the expected login re…

No fix yet
Fix from $1,600 2011-08-12
Tivoli Directory Server MEDIUM 5.0
CVE-2011-2758

IDSWebApp in the Web Administration Tool in IBM Tivoli Directory Server (TDS) 6.2 before 6.2.0.3-TIV-ITDS-IF0004 does not require authentication for …

Mitigation only
Fix from $1,600 2011-07-17
Aix MEDIUM 6.8
CVE-2011-1561

The LDAP login feature in bos.rte.security 6.1.6.4 in IBM AIX 6.1, when ldap_auth is enabled in ldap.cfg, allows remote attackers to bypass authentic…

Mitigation only
Fix from $1,600 2011-04-05
Lotus Domino HIGH 7.2
CVE-2011-1520

The default configuration of the server console in IBM Lotus Domino does not require a password (aka Server_Console_Password), which allows physicall…

Mitigation only
Fix from $1,950 2011-03-25
Lotus Domino HIGH 10.0
CVE-2011-1519EPSS 9%

The remote console in the Server Controller in IBM Lotus Domino 7.x and 8.x verifies credentials against a file located at a UNC share pathname speci…

Mitigation only
Fix from $1,950 2011-03-25
Lotus Domino HIGH 9.3
CVE-2011-0920EPSS 10%

The Remote Console in IBM Lotus Domino, when a certain unsupported configuration involving UNC share pathnames is used, allows remote attackers to by…

Mitigation only
Fix from $1,950 2011-02-08
Omnifind HIGH 7.5
CVE-2010-3896

The ESSearchApplication directory tree in IBM OmniFind Enterprise Edition 8.x and 9.x does not require authentication, which allows remote attackers …

No fix yet
Fix from $1,950 2010-11-12
Tivoli Provisioning Manager Os Deployment HIGH 7.5
CVE-2010-4121

The TCP-to-ODBC gateway in IBM Tivoli Provisioning Manager for OS Deployment 7.1.1.3 does not require authentication for SQL statements, which allows…

Mitigation only
Fix from $1,950 2010-10-28
Db2 Universal Database MEDIUM 6.4
CVE-2010-3739

The audit facility in the Security component in IBM DB2 UDB 9.5 before FP6a uses instance-level audit settings to capture connection (aka CONNECT and…

Fix: after 9.5
Fix from $1,600 2010-10-05
Tivoli Directory Server MEDIUM 5.0
CVE-2010-2927

The slapi_printmessage function in IBM Tivoli Directory Server (ITDS) before 6.0.0.8-TIV-ITDS-IF0006 allows remote attackers to cause a denial of ser…

Fix: after 6.0.0.8
Fix from $1,600 2010-08-02
Websphere Application Server HIGH 7.5
CVE-2009-2085

The Security component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5 does not properly handle use of Identity …

Patch available
Fix from $1,950 2009-08-13
Websphere Application Server HIGH 7.5
CVE-2009-2088

The Servlet Engine/Web Container component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5, when SPNEGO Single S…

Patch available
Fix from $1,950 2009-08-13
Websphere Application Server MEDIUM 6.5
CVE-2009-0906

The Service Component Architecture (SCA) feature pack for IBM WebSphere Application Server (WAS) SCA 1.0 before 1.0.0.3 allows remote authenticated u…

Patch available
Fix from $1,600 2009-08-13
Websphere Application Server MEDIUM 5.5
CVE-2009-0892

The administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 and 7.0 before 7.0.0.3 allows attackers to hijack user sessi…

Patch available
Fix from $1,600 2009-03-31
Websphere Application Server MEDIUM 5.5
CVE-2009-0891

The Web Services Security component in IBM WebSphere Application Server 7.0 before Fix Pack 1 (7.0.0.1), 6.1 before Fix Pack 23 (6.1.0.23),and 6.0.2 …

Patch available
Fix from $1,600 2009-03-25
Websphere Partner Gateway MEDIUM 6.5
CVE-2009-0440

IBM WebSphere Partner Gateway (WPG) 6.0.0 through 6.0.0.7 does not properly handle failures of signature verification, which might allow remote authe…

Patch available
Fix from $1,600 2009-02-22