Vulnerability index

Browse CVEs

40 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cryptographic IssuesCWE-310 × clear
Security Verify Access CRITICAL 9.8
CVE-2026-17616

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 thr…

No fix yet
Fix from $5,750 2026-08-12
Security Guardium HIGH 7.5
CVE-2017-1268

IBM Security Guardium 10 and 10.5 uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the softw…

Fix: after 10.5
Fix from $1,950 2018-12-13
Tivoli Application Dependency Discovery Manager HIGH 7.5
CVE-2013-3017

IBM Tivoli Application Dependency Discovery Manager (TADDM) before 7.2.1.5 and 7.2.x before 7.2.2 make it easier for remote attackers to defeat crypt…

Fix: 7.2.1.5+
Fix from $1,950 2018-07-09
Ibm Db HIGH 8.1
CVE-2016-10577

ibm_db is an asynchronous/synchronous interface for node.js to IBM DB2 and IBM Informix. ibm_db before 1.0.2 downloads binary resources over HTTP, wh…

Fix: 1.0.2+
Fix from $1,950 2018-05-29
Sterling Connect HIGH 7.3
CVE-2013-4035

IBM Sterling Connect:Direct for OpenVMS 3.4.00, 3.4.01, 3.5.00, 3.6.0, and 3.6.0.1 allow remote attackers to have unspecified impact by leveraging fa…

No fix yet
Fix from $1,950 2018-05-01
Worklight MEDIUM 5.3
CVE-2013-5391

IBM Worklight Consumer and Enterprise Editions 5.0.x before 5.0.6 Fix Pack 2 and 6.0.x before 6.0.0 Fix Pack 2, and Mobile Foundation Consumer and En…

Mitigation only
Fix from $1,600 2018-04-27
Rational Clearcase HIGH 7.4
CVE-2015-5039

The Remote Client and change management integrations in IBM Rational ClearCase 7.1.x, 8.0.0.x before 8.0.0.18, and 8.0.1.x before 8.0.1.11 do not pro…

Fix: after 8.0.1.10
Fix from $1,950 2018-03-26
Security Privileged Identity Manager Virtual Appliance HIGH 7.5
CVE-2016-5957

IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 allows remote attackers to defeat cryptographic protection me…

Fix: after 2.0.2
Fix from $1,950 2016-09-26
Security Access Manager 9.0 Firmware HIGH 7.5
CVE-2015-5012

The SSH implementation on IBM Security Access Manager for Web appliances 7.0 before 7.0.0 FP19, 8.0 before 8.0.1.3 IF3, and 9.0 before 9.0.0.0 IF1 do…

Patch available
Fix from $1,950 2016-02-15
Change And Configuration Management Database MEDIUM 5.0
CVE-2015-1934

IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX002, and 7.6.0 before 7.6.0.1 IFIX001; Maximo Asset Management 7.5.x befor…

Patch available
Fix from $1,600 2015-10-04
Rational Test Virtualization Server MEDIUM 5.0
CVE-2015-1913

Rational Test Control Panel in IBM Rational Test Workbench and Rational Test Virtualization Server 8.0.0.x before 8.0.0.5, 8.0.1.x before 8.0.1.6, 8.…

Patch available
Fix from $1,600 2015-06-30
Rational Clearcase HIGH 9.4
CVE-2014-6221

The MSCAPI/MSCNG interface implementation in GSKit in IBM Rational ClearCase 7.1.2.x before 7.1.2.17, 8.0.0.x before 8.0.0.14, and 8.0.1.x before 8.0…

Patch available
Fix from $1,950 2015-04-06
Security Appscan MEDIUM 5.8
CVE-2014-8918

IBM Security AppScan Standard 8.x and 9.x before 9.0.1.1 FP1 does not properly verify X.509 certificates from SSL servers, which allows man-in-the-mi…

Mitigation only
Fix from $1,600 2015-02-02
Security Appscan MEDIUM 5.0
CVE-2014-6136

IBM Security AppScan Standard 8.x and 9.x before 9.0.1.1 FP1 supports unencrypted sessions, which allows remote attackers to obtain sensitive informa…

Mitigation only
Fix from $1,600 2015-02-02
Security Access Manager For Web MEDIUM 5.0
CVE-2014-6087

IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 make it easier…

Mitigation only
Fix from $1,600 2014-12-18
Security Access Manager For Mobile MEDIUM 5.0
CVE-2014-6084

IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 make it easier…

Mitigation only
Fix from $1,600 2014-12-18
Tivoli Endpoint Manager Mobile Device Management HIGH 9.3
CVE-2014-6140EPSS 6%

IBM Tivoli Endpoint Manager Mobile Device Management (MDM) before 9.0.60100 uses the same secret HMAC token across different customers' installations…

Fix: after 9.0
Fix from $1,950 2014-12-06
Integrated Management Module Firmware MEDIUM 5.0
CVE-2014-0860

The firmware before 3.66E in IBM BladeCenter Advanced Management Module (AMM), the firmware before 1.43 in IBM Integrated Management Module (IMM), an…

Fix: after 3.65
Fix from $1,600 2014-07-07
Java Sdk MEDIUM 5.8
CVE-2014-0878

The IBMSecureRandom component in the IBMJCE and IBMSecureRandom cryptographic providers in IBM SDK Java Technology Edition 5.0 before Service Refresh…

Mitigation only
Fix from $1,600 2014-05-26
Cognos Express MEDIUM 5.0
CVE-2013-5444

The server in IBM Cognos Express 9.0 before IFIX 2, 9.5 before IFIX 2, 10.1 before IFIX 2, and 10.2.1 before FP1 allows remote attackers to read encr…

Mitigation only
Fix from $1,600 2014-03-25
Cognos Express MEDIUM 5.0
CVE-2013-5445

IBM Cognos Express 9.0 before IFIX 2, 9.5 before IFIX 2, 10.1 before IFIX 2, and 10.2.1 before FP1 allows local users to obtain sensitive cleartext i…

Mitigation only
Fix from $1,600 2014-03-25
Algo One MEDIUM 5.0
CVE-2013-5468

IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Security Access Control Management 4.7.0 through 4.9.0,…

Mitigation only
Fix from $1,600 2014-03-05
Content Manager Ondemand For Multiplatforms HIGH 7.8
CVE-2013-6329

IBM Global Security Kit (aka GSKit), as used in Content Manager OnDemand 8.5 and 9.0 and other products, allows remote attackers to cause a denial of…

Patch available
Fix from $1,950 2013-12-17
Advanced Management Module Firmware MEDIUM 6.4
CVE-2013-6718

The Advanced Management Module (AMM) with firmware 3.64B, 3.64C, and 3.64G for IBM BladeCenter systems allows remote attackers to discover account na…

Mitigation only
Fix from $1,600 2013-12-01
Rational Policy Tester MEDIUM 6.8
CVE-2013-4062

IBM Rational Policy Tester 8.5 before 8.5.0.5 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof …

Mitigation only
Fix from $1,600 2013-09-09
Security Appscan MEDIUM 5.0
CVE-2013-0531

The SSL implementation in IBM Security AppScan Enterprise before 8.7.0.1 enables cipher suites with weak encryption algorithms, which makes it easier…

Fix: after 8.7.0.0
Fix from $1,600 2013-09-08
Sterling B2b Integrator MEDIUM 5.0
CVE-2012-5936

IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 do not set the secure flag for the session cookie in an https session, …

Mitigation only
Fix from $1,600 2013-07-03
Ims Enterprise Suite MEDIUM 5.0
CVE-2013-0483

The login component in SOAP Gateway in IBM IMS Enterprise Suite 1.1, 2.1, and 2.2 uses cleartext credentials, which allows remote attackers to obtain…

Mitigation only
Fix from $1,600 2013-04-05
Remote Supervisor Adapter Ii Firmware MEDIUM 5.0
CVE-2012-2187

IBM Remote Supervisor Adapter II firmware for System x3650, x3850 M2, and x3950 M2 1.13 and earlier generates weak RSA keys, which makes it easier fo…

Fix: after 1.13
Fix from $1,600 2012-09-25
Infosphere Guardium MEDIUM 5.0
CVE-2012-3312

The datasource definition editor in IBM InfoSphere Guardium 8.2 and earlier, when the save-password setting is enabled, transmits cleartext database …

Fix: after 8.2
Fix from $1,600 2012-08-29