Vulnerability index

Browse CVEs

138 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Kenexa Lcms Premier HIGH 8.8
CVE-2016-5952

IBM Kenexa LCMS Premier on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the…

Patch available
Fix from $1,950 2017-02-01
Kenexa Lms On Cloud MEDIUM 6.3
CVE-2016-5939

IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker…

Patch available
Fix from $1,600 2017-02-01
Qradar Security Information And Event Manager HIGH 8.8
CVE-2016-2873

SQL injection vulnerability in IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 allows remote authenticated users to execute arbitrary SQ…

Fix: after 7.1.0
Fix from $1,950 2016-11-30
Bigfix Remote Control MEDIUM 6.5
CVE-2016-2950

SQL injection vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote authenticated users to execute arbitrary SQL commands via unspeci…

Fix: after 9.1.2
Fix from $1,600 2016-11-30
Security Guardium HIGH 8.6
CVE-2016-0249

SQL injection vulnerability in IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 be…

Fix: after 8.2
Fix from $1,950 2016-10-16
Marketing Platform HIGH 8.8
CVE-2016-0233

SQL injection vulnerability in IBM Marketing Platform 8.5.x, 8.6.x, and 9.x before 9.1.2.2 allows remote authenticated users to execute arbitrary SQL…

Mitigation only
Fix from $1,950 2016-06-28
Marketing Platform CRITICAL 9.8
CVE-2016-0224

SQL injection vulnerability in IBM Marketing Platform 8.5.x, 8.6.x, and 9.x before 9.1.2.2 allows remote attackers to execute arbitrary SQL commands …

Mitigation only
Fix from $2,300 2016-06-28
Change And Configuration Management Database MEDIUM 5.4
CVE-2015-7448

SQL injection vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.9 IFIX003, and 7.6.0 before 7.6.0.3 IFIX001; Maxi…

Mitigation only
Fix from $1,600 2016-03-12
Curam Social Program Management MEDIUM 5.4
CVE-2015-5023

SQL injection vulnerability in IBM Curam Social Program Management 6.1 before 6.1.1 allows remote authenticated users to execute arbitrary SQL comman…

Mitigation only
Fix from $1,600 2016-01-03
Openpages Grc Platform MEDIUM 5.4
CVE-2015-5049

SQL injection vulnerability in the API in IBM OpenPages GRC Platform 7.0 before 7.0.0.4 IF3 and 7.1 before 7.1.0.1 IF6 allows remote authenticated us…

Mitigation only
Fix from $1,600 2016-01-01
Security Qradar Incident Forensics MEDIUM 6.5
CVE-2015-1989

SQL injection vulnerability in IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 allows remote authenticated users to execute arbitra…

Mitigation only
Fix from $1,600 2015-11-08
Change And Configuration Management Database MEDIUM 6.5
CVE-2015-4967

SQL injection vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX004, and 7.6.0 before 7.6.0.1 IFIX002; Maxi…

Patch available
Fix from $1,600 2015-10-06
Security Siteprotector System MEDIUM 6.5
CVE-2015-0161

SQL injection vulnerability in IBM Security SiteProtector System 3.0 before 3.0.0.7, 3.1 before 3.1.0.4, and 3.1.1 before 3.1.1.2 allows remote authe…

Mitigation only
Fix from $1,600 2015-05-25
Infosphere Biginsights MEDIUM 6.5
CVE-2015-1889

The Big SQL component in IBM InfoSphere BigInsights 3.0 through 3.0.0.2 allows remote authenticated users to bypass intended HDFS data-access restric…

Mitigation only
Fix from $1,600 2015-04-22
Security Access Manager For Mobile MEDIUM 6.5
CVE-2014-6080

SQL injection vulnerability in IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and …

Mitigation only
Fix from $1,600 2014-12-18
Qradar Security Information And Event Manager MEDIUM 6.5
CVE-2014-4824

SQL injection vulnerability in IBM Security QRadar SIEM 7.2 before 7.2.3 Patch 1 allows remote authenticated users to execute arbitrary SQL commands …

Patch available
Fix from $1,600 2014-09-18
Emptoris Contract Management MEDIUM 6.5
CVE-2014-3041

SQL injection vulnerability in IBM Emptoris Contract Management 9.5.x before 9.5.0.6 iFix 10, 10.0.0.x before 10.0.0.1 iFix 10, 10.0.1.x before 10.0.…

Mitigation only
Fix from $1,600 2014-08-26
Infosphere Master Data Management MEDIUM 6.5
CVE-2014-0966

SQL injection vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0-FP5 and I…

Mitigation only
Fix from $1,600 2014-08-17
Websphere Portal HIGH 7.5
CVE-2014-3055

SQL injection vulnerability in the Unified Task List (UTL) Portlet for IBM WebSphere Portal 7.x and 8.x through 8.0.0.1 CF12 allows remote attackers …

Mitigation only
Fix from $1,950 2014-07-29
Marketing Platform MEDIUM 6.5
CVE-2013-6311

SQL injection vulnerability in IBM Marketing Platform 9.1 before FP2 allows remote authenticated users to execute arbitrary SQL commands via unspecif…

Mitigation only
Fix from $1,600 2014-06-28
Change And Configuration Management Database MEDIUM 6.5
CVE-2013-4016

SQL injection vulnerability in IBM Maximo Asset Management 7.x before 7.1.1.7 LAFIX.20140319-0837, 7.1.1.11 before IFIX.20140323-0749, 7.1.1.12 befor…

Mitigation only
Fix from $1,600 2014-05-26
Infosphere Information Server MEDIUM 6.5
CVE-2013-4058

Multiple SQL injection vulnerabilities in IBM InfoSphere Information Server 8.x through 8.5 FP3, 8.7.x through 8.7 FP2, and 9.1.x through 9.1.2.0 all…

Mitigation only
Fix from $1,600 2014-03-16
Algo One MEDIUM 6.5
CVE-2013-6302

SQL injection vulnerability in IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Security Access Control …

Mitigation only
Fix from $1,600 2014-03-05
Algo One MEDIUM 6.5
CVE-2013-6331

SQL injection vulnerability in IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Security Access Control …

Mitigation only
Fix from $1,600 2014-03-05
Atlas Ediscovery Process Management HIGH 7.5
CVE-2013-6321

SQL injection vulnerability in IBM Atlas eDiscovery Process Management 6.0.1.5 and earlier and 6.0.2, Disposal and Governance Management for IT 6.0.1…

Fix: after 6.0.1.5
Fix from $1,950 2014-01-10
Sterling B2b Integrator MEDIUM 6.5
CVE-2013-5409

Multiple SQL injection vulnerabilities in IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 allow remote authenticated users to execute a…

Mitigation only
Fix from $1,600 2013-12-21
Maximo Asset Management MEDIUM 6.5
CVE-2013-0451

SQL injection vulnerability in IBM Maximo Asset Management 6.2 through 6.2.8 and 7.1 through 7.1.1.12 allows remote authenticated users to execute ar…

Mitigation only
Fix from $1,600 2013-10-01
Maximo Asset Management MEDIUM 6.5
CVE-2013-3973

SQL injection vulnerability in IBM Maximo Asset Management 7.1 before 7.1.1.12 and 7.5 before 7.5.0.5 allows remote authenticated users to execute ar…

Mitigation only
Fix from $1,600 2013-10-01
Maximo Asset Management MEDIUM 6.5
CVE-2013-4017

SQL injection vulnerability in IBM Maximo Asset Management 7.1 before 7.1.1.12 allows remote attackers to execute arbitrary SQL commands via unspecif…

Mitigation only
Fix from $1,600 2013-10-01
Tivoli Remote Control MEDIUM 6.5
CVE-2013-3033

SQL injection vulnerability in the server component in IBM Tivoli Remote Control 5.1.2 before 5.1.2-TIV-TRC512-IF0015 allows remote authenticated use…

Mitigation only
Fix from $1,600 2013-07-29