Vulnerability index

Browse CVEs

47 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
Security Information Queue MEDIUM 5.3
CVE-2020-4289

IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, and 1.0.5 could allow a remote attacker to obtain sensitive information, cau…

Patch available
Fix from $1,600 2020-04-08
Platform Lsf HIGH 7.8
CVE-2020-4278

IBM Platform LSF 9.1 and 10.1, IBM Spectrum LSF Suite 10.2, and IBM Spectrum Suite for HPA 10.2 could allow a local user to escalate their privileges…

Patch available
Fix from $1,950 2020-03-05
Qradar Security Information And Event Manager HIGH 8.1
CVE-2018-2024

IBM QRadar SIEM 7.2 and 7.3 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unint…

Patch available
Fix from $1,950 2019-07-22
Websphere Mq HIGH 7.8
CVE-2019-4078

IBM WebSphere MQ 8.0.0.0 through 8.0.0.9 and 9.0.0.0 through 9.1.1 could allow a local non privileged user to execute code as an administrator due to…

Fix: after 9.1.0.1
Fix from $1,950 2019-05-23
Spectrum Protect For Virtual Environments MEDIUM 5.5
CVE-2018-1787

IBM Spectrum Protect 7.1 and 8.1 is affected by a password exposure vulnerability caused by insecure file permissions. IBM X-Force ID: 148872.

Fix: after 8.1.6.1
Fix from $1,600 2019-04-08
Spectrum Lsf MEDIUM 5.3
CVE-2018-1724

IBM Spectrum LSF 9.1.1 9.1.2, 9.1.3, and 10.1 could allow a local user to change their job user at job submission time due to improper file permissio…

Patch available
Fix from $1,600 2018-10-11
Security Key Lifecycle Manager HIGH 8.1
CVE-2018-1750

IBM Security Key Lifecycle Manager 3.0 specifies permissions for a security-critical resource in a way that allows that resource to be read or modifi…

Fix: after 2.7.0.4
Fix from $1,950 2018-10-08
Websphere Portal MEDIUM 6.5
CVE-2018-1420

IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 resets access control settings to the out of the box configuration during Combined Cumulative Fix (CF) in…

Patch available
Fix from $1,600 2018-10-01
Db2 HIGH 7.8
CVE-2018-1711

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to to gain privileges due to all…

Mitigation only
Fix from $1,950 2018-09-21
Websphere Mq HIGH 7.5
CVE-2018-1551

IBM WebSphere MQ 8.0.0.2 through 8.0.0.8 and 9.0.0.0 through 9.0.0.3 could allow users to have more authority than they should have if an MQ administ…

Fix: after 9.0.0.3
Fix from $1,950 2018-08-06
Security Guardium Big Data Intelligence MEDIUM 5.4
CVE-2018-1370

IBM Security Guardium Big Data Intelligence (SonarG) 3.1 specifies permissions for a security-critical resource in a way that allows that resource to…

Patch available
Fix from $1,600 2018-05-29
Qradar Security Information And Event Manager MEDIUM 5.4
CVE-2017-1624

IBM QRadar 7.3 and 7.3.1 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintend…

Patch available
Fix from $1,600 2018-04-04
Tivoli Workload Scheduler HIGH 7.8
CVE-2018-1386

IBM Tivoli Workload Automation for AIX (IBM Workload Scheduler 8.6, 9.1, 9.2, 9.3, and 9.4) contains directories with improper permissions that could…

Mitigation only
Fix from $1,950 2018-03-14
Java Sdk HIGH 8.1
CVE-2018-1417

Under certain circumstances, a flaw in the J9 JVM (IBM SDK, Java Technology Edition 7.1 and 8.0) allows untrusted code running under a security manag…

Mitigation only
Fix from $1,950 2018-02-22
Security Guardium MEDIUM 5.4
CVE-2017-1266

IBM Security Guardium 10.0 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by uninte…

Mitigation only
Fix from $1,600 2017-12-20
Lotus Domino HIGH 7.8
CVE-2007-5544

IBM Lotus Notes before 6.5.6, and 7.x before 7.0.3; and Domino before 6.5.5 FP3, and 7.x before 7.0.2 FP1; uses weak permissions (Everyone:Full Contr…

Fix: 6.5.5 / 7.0.2+
Fix from $1,950 2007-10-29
Db2 Universal Database HIGH 7.1
CVE-2005-4868

Shared memory sections and events in IBM DB2 8.1 have default permissions of read and write for the Everyone group, which allows local users to gain …

Patch available
Fix from $1,950 2005-12-31