Vulnerability index

Browse CVEs

40 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cryptographic IssuesCWE-310 × clear
Websphere Application Server MEDIUM 5.0
CVE-2012-2190

IBM Global Security Kit (aka GSKit), as used in IBM HTTP Server in IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.45, 7.0.x before 7.0.0.2…

Mitigation only
Fix from $1,600 2012-08-21
Rational Appscan MEDIUM 5.8
CVE-2012-0732

The Enterprise Console client in IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 does not verify X.509 certificates from SSL servers, whic…

Mitigation only
Fix from $1,600 2012-05-03
Websphere Application Server MEDIUM 6.8
CVE-2012-2162

The Web Server Plug-in in IBM WebSphere Application Server (WAS) 8.0 and earlier uses unencrypted HTTP communication after expiration of the plugin-k…

Fix: after 8.0.0.0
Fix from $1,600 2012-05-01
Tivoli Directory Server MEDIUM 6.4
CVE-2012-0726

The default configuration of TLS in IBM Tivoli Directory Server (TDS) 6.3 and earlier supports the (1) NULL-MD5 and (2) NULL-SHA ciphers, which allow…

Fix: after 6.3.0
Fix from $1,600 2012-04-22
Datacap Taskmaster Capture MEDIUM 5.0
CVE-2011-2142

The Web Client Service in IBM Datacap Taskmaster Capture 8.0.1 before FP1 requires a cleartext password, which has unspecified impact and attack vect…

No fix yet
Fix from $1,600 2011-05-16
Lotus Notes Traveler MEDIUM 5.8
CVE-2009-5032

The encrypted e-mail feature in IBM Lotus Notes Traveler before 8.5.0.2 sends unencrypted messages when the feature is used without uploading a Notes…

Fix: after 8.5.0.1
Fix from $1,600 2010-12-16
Websphere Application Server MEDIUM 6.4
CVE-2009-2749

Feature Pack for Communications Enabled Applications (CEA) before 1.0.0.1 for IBM WebSphere Application Server 7.0.0.7 uses predictable session value…

Fix: after 1.0
Fix from $1,600 2009-12-08
Websphere Application Server HIGH 10.0
CVE-2009-1174

The Web Services Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 and 7.0 before 7.0.0.3 has an unspecified "securi…

Patch available
Fix from $1,950 2009-03-31
Websphere Application Server MEDIUM 5.0
CVE-2008-5411

IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 sends SSL traffic over "unsecured TCP," which makes it easier for remote attackers to obtain …

Fix: after 7.0
Fix from $1,600 2008-12-10
Websphere Application Server MEDIUM 5.0
CVE-2008-3236

Unspecified vulnerability in Wsadmin in the System Management/Repository component in IBM WebSphere Application Server (WAS) 5.1 before 5.1.1.19 allo…

Mitigation only
Fix from $1,600 2008-07-21