Vulnerability index

Browse CVEs

199 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Security Identity Manager HIGH 8.8
CVE-2016-0335

Cross-site request forgery (CSRF) vulnerability in IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SI…

Patch available
Fix from $1,950 2018-01-12
Security Key Lifecycle Manager HIGH 8.8
CVE-2017-1672

IBM Tivoli Key Lifecycle Manager 2.6 and 2.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unaut…

Mitigation only
Fix from $1,950 2018-01-04
Jazz For Service Management HIGH 8.8
CVE-2017-1631

IBM Jazz for Service Management (IBM Tivoli Components 1.1.3) is vulnerable to cross-site request forgery which could allow an attacker to execute ma…

Patch available
Fix from $1,950 2017-12-20
Jazz For Service Management HIGH 8.8
CVE-2017-1746

IBM Jazz for Service Management (IBM Tivoli Components 1.1.3) is vulnerable to cross-site request forgery which could allow an attacker to execute ma…

Patch available
Fix from $1,950 2017-12-20
Openpages Grc Platform HIGH 8.8
CVE-2017-1300

IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unaut…

Patch available
Fix from $1,950 2017-11-01
Security Identity Manager HIGH 8.8
CVE-2014-6106

Cross-site request forgery (CSRF) vulnerability in IBM Security Identity Manager 5.1, 6.0, and 7.0 allows remote attackers to hijack the authenticati…

Patch available
Fix from $1,950 2017-09-18
Ib6131 Firmware HIGH 8.8
CVE-2014-9565

Cross-site request forgery (CSRF) vulnerability in IBM Flex System EN6131 40Gb Ethernet and IB6131 40Gb Infiniband Switch firmware 3.4.0000 and earli…

Fix: after 3.4.0.0.0.0
Fix from $1,950 2017-09-07
Emptoris Strategic Supply Management HIGH 8.8
CVE-2017-1097

IBM Emptoris Strategic Supply Management Platform 10.0.0.x through 10.1.1.x is vulnerable to cross-site request forgery which could allow an attacker…

Mitigation only
Fix from $1,950 2017-09-05
Emptoris Services Procurement HIGH 8.8
CVE-2017-1442

IBM Emptoris Services Procurement 10.0.0.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unautho…

Patch available
Fix from $1,950 2017-08-30
Sametime MEDIUM 6.5
CVE-2016-0355

IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user that has been invited to a Sametime meeting room, to cause the…

Patch available
Fix from $1,600 2017-08-29
Sametime MEDIUM 6.5
CVE-2016-0356

IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user that has been invited to a Sametime meeting room, to cause the…

Patch available
Fix from $1,600 2017-08-29
Sametime MEDIUM 6.5
CVE-2016-2965

IBM Sametime Meeting Server 8.5.2 and 9.0 is vulnerable to cross-site request forgery, caused by improper validation of user-supplied input. By persu…

Patch available
Fix from $1,600 2017-08-29
Urbancode Deploy HIGH 8.8
CVE-2014-8900

Cross-site request forgery (CSRF) vulnerability in IBM UrbanCode Release 6.0.1.6 and earlier, 6.1.0.7 and earlier, and 6.1.1.1 and earlier.

Fix: after 6.1.1.1
Fix from $1,950 2017-08-28
Infosphere Master Data Management Server HIGH 8.8
CVE-2016-9714

IBM InfoSphere Master Data Management Server 10.1, 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site request forgery which could allow an …

Patch available
Fix from $1,950 2017-07-31
Infosphere Master Data Management Server HIGH 8.8
CVE-2016-9716

IBM InfoSphere Master Data Management Server 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site request forgery which could allow an attack…

Patch available
Fix from $1,950 2017-07-31
Bigfix Platform HIGH 8.8
CVE-2017-1218

IBM Tivoli Endpoint Manager is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions t…

Mitigation only
Fix from $1,950 2017-07-19
Sterling Selling And Fulfillment Foundation HIGH 8.0
CVE-2016-9991

IBM Sterling Order Management 9.2 through 9.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unau…

Patch available
Fix from $1,950 2017-06-08
Interact HIGH 8.8
CVE-2016-5889

IBM Interact 8.6, 9.0, 9.1, and 10.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized …

Patch available
Fix from $1,950 2017-05-10
Websphere Application Server HIGH 8.8
CVE-2017-1194

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site request forgery which could allow an attacker to execute maliciou…

Patch available
Fix from $1,950 2017-04-28
Disposal And Governance Management For It HIGH 8.8
CVE-2016-6100

IBM Disposal and Governance Management for IT and IBM Global Retention Policy and Schedule Management, components of IBM Atlas Policy Suite 6.0.3 is …

Mitigation only
Fix from $1,950 2017-04-05
Sterling Selling And Fulfillment Foundation HIGH 8.8
CVE-2016-8917

IBM Sterling Order Management 9.2 - 9.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthoriz…

Patch available
Fix from $1,950 2017-03-31
Dashboard Application Services Hub HIGH 8.8
CVE-2016-9975

IBM Jazz for Service Management 1.1.2.1 and 1.1.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and …

Patch available
Fix from $1,950 2017-02-24
Tivoli Storage Manager For Virtual Environments Data Protection For Vmware HIGH 8.8
CVE-2016-6033

IBM Tivoli Storage Manager for Virtual Environments 7.1 (VMware) is vulnerable to cross-site request forgery which could allow an attacker to execute…

Patch available
Fix from $1,950 2017-02-15
Security Key Lifecycle Manager HIGH 8.8
CVE-2016-6103

IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unaut…

Patch available
Fix from $1,950 2017-02-02
Spectrum Control HIGH 8.8
CVE-2016-8941

IBM Tivoli Storage Productivity Center is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorize…

Patch available
Fix from $1,950 2017-02-01
Kenexa Lcms Premier HIGH 8.8
CVE-2016-5937

IBM Kenexa LCMS Premier on Cloud is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized acti…

Patch available
Fix from $1,950 2017-02-01
Tivoli Storage Manager HIGH 8.8
CVE-2016-6045

IBM Tivoli Storage Manager Operations Center is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unaut…

Patch available
Fix from $1,950 2017-02-01
Security Access Manager 9.0 Firmware HIGH 8.8
CVE-2016-3029

IBM Security Access Manager for Web is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized a…

Patch available
Fix from $1,950 2017-02-01
Forms Experience Builder HIGH 8.0
CVE-2016-2884

Cross-site request forgery (CSRF) vulnerability in IBM Forms Experience Builder 8.5.x and 8.6.x before 8.6.3.1, in an unspecified non-default configu…

Patch available
Fix from $1,950 2016-11-30
Qradar Security Information And Event Manager HIGH 8.0
CVE-2016-2878

Multiple cross-site request forgery (CSRF) vulnerabilities in IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 allow remote attackers to …

Mitigation only
Fix from $1,950 2016-11-30