Vulnerability index

Browse CVEs

16 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
Security Verify Access HIGH 7.8
CVE-2023-31003

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.6.1)…

Fix: 10.0.0.7+
Fix from $1,950 2024-01-11
Spss Modeler MEDIUM 5.5
CVE-2020-4717

A vulnerability exists in IBM SPSS Modeler Subscription Installer that allows a user with create symbolic link permission to write arbitrary file in …

Mitigation only
Fix from $1,600 2021-03-10
Informix Dynamic Server MEDIUM 6.7
CVE-2018-1632

IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges throu…

Mitigation only
Fix from $1,600 2019-08-20
Informix Dynamic Server MEDIUM 6.7
CVE-2018-1633

IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges throu…

Mitigation only
Fix from $1,600 2019-08-20
Informix Dynamic Server MEDIUM 6.7
CVE-2018-1634

IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges throu…

Mitigation only
Fix from $1,600 2019-08-20
Informix Dynamic Server MEDIUM 6.7
CVE-2018-1630

IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges throu…

Mitigation only
Fix from $1,600 2019-08-20
Informix Dynamic Server MEDIUM 6.7
CVE-2018-1631

IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges throu…

Mitigation only
Fix from $1,600 2019-08-20
Db2 HIGH 7.8
CVE-2018-1780

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local db2 instance owner to obtain root acc…

Mitigation only
Fix from $1,950 2018-11-09
Db2 HIGH 7.8
CVE-2018-1781

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to obtain root access by exploit…

Mitigation only
Fix from $1,950 2018-11-09
Db2 HIGH 7.8
CVE-2018-1834

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability that could allow a local user to…

Mitigation only
Fix from $1,950 2018-11-09
Tivoli Storage Manager MEDIUM 5.5
CVE-2017-1301

IBM Spectrum Protect 7.1 and 8.1 could allow a local attacker to launch a symlink attack. IBM Spectrum Protect Backup-archive Client creates temporar…

Patch available
Fix from $1,600 2017-10-05
Vios MEDIUM 6.9
CVE-2014-3977

libodm.a in IBM AIX 6.1 and 7.1, and VIOS 2.2.x, allows local users to overwrite arbitrary files via a symlink attack on a temporary file. NOTE: this…

No fix yet
Fix from $1,600 2014-06-08
Websphere Application Server MEDIUM 5.8
CVE-2008-4284

Open redirect vulnerability in the ibm_security_logout servlet in IBM WebSphere Application Server (WAS) 5.1.1.19 and earlier 5.x versions, 6.0.x bef…

Patch available
Fix from $1,600 2009-02-10
Db2 Universal Database MEDIUM 6.9
CVE-2007-5664

db2dasrrm in the DB2 Administration Server (DAS) in IBM DB2 Universal Database 9.5 before Fix Pack 1, 9.1 before Fix Pack 4a, and 8 before FixPak 16 …

Patch available
Fix from $1,600 2008-04-16
Aix MEDIUM 6.9
CVE-2007-5805

cfgcon in IBM AIX 5.2 and 5.3 does not properly validate the argument to the "-p" option to swcons, which allows local users in the system group to c…

Patch available
Fix from $1,600 2007-11-05
U2 Universe HIGH 7.8
CVE-2003-0578

cci_dir in IBM U2 UniVerse 10.0.0.9 and earlier creates hard links and unlinks files as root, which allows local users to gain privileges by deleting…

Fix: after 10.0.0.9
Fix from $1,950 2003-08-18