Vulnerability index

Browse CVEs

55 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Rational Quality Manager MEDIUM 5.4
CVE-2017-1242

IBM Quality Manager (RQM) 5.0.x and 6.0 through 6.0.5 are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which whe…

Fix: after 6.0.5
Fix from $1,600 2018-07-06
Rational Quality Manager MEDIUM 5.4
CVE-2017-1329

IBM Quality Manager (RQM) 5.0.x and 6.0 through 6.0.5 are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which whe…

Fix: after 6.0.5
Fix from $1,600 2018-07-06
Qradar Security Information And Event Manager MEDIUM 5.6
CVE-2017-1721

IBM Security QRadar SIEM 7.2 and 7.3 could allow an unauthenticated user to execute code remotely with lower level privileges under unusual circumsta…

Fix: 7.2.8+
Fix from $1,600 2018-04-26
Tivoli Monitoring CRITICAL 9.8
CVE-2017-1789

IBM Tivoli Monitoring V6 6.2.3 and 6.3.0 could allow an unauthenticated user to remotely execute code through unspecified methods. IBM X-Force ID: 13…

Mitigation only
Fix from $2,300 2018-03-22
Emptoris Services Procurement HIGH 8.8
CVE-2017-1440

IBM Emptoris Services Procurement 10.0.0.5 could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-crafted…

Patch available
Fix from $1,950 2017-08-30
Infosphere Information Server HIGH 7.8
CVE-2017-1469

IBM InfoSphere Information Server 9.1, 11.3, and 11.5 could allow a local user to gain elevated privileges by placing arbitrary files in installation…

Mitigation only
Fix from $1,950 2017-08-14
Security Appscan HIGH 9.3
CVE-2014-6119

IBM Security AppScan Enterprise 8.5 before 8.5 IFix 002, 8.6 before 8.6 IFix 004, 8.7 before 8.7 IFix 004, 8.8 before 8.8 iFix 003, 9.0 before 9.0.0.…

Mitigation only
Fix from $1,950 2014-12-23
Java MEDIUM 6.9
CVE-2014-3065

Unspecified vulnerability in IBM Java Runtime Environment (JRE) 7 R1 before SR2 (7.1.2.0), 7 before SR8 (7.0.8.0), 6 R1 before SR8 FP2 (6.1.8.2), 6 b…

Mitigation only
Fix from $1,600 2014-12-02
Websphere Application Server MEDIUM 6.5
CVE-2014-4767

IBM WebSphere Application Server (WAS) Liberty Profile 8.5.x before 8.5.5.3 does not properly use the Liberty Repository for feature installation, wh…

Mitigation only
Fix from $1,600 2014-08-22
Marketing Platform MEDIUM 6.0
CVE-2013-6309

IBM Marketing Platform 9.1 before FP2 allows remote authenticated users to hijack sessions, and consequently read records, modify records, or conduct…

Mitigation only
Fix from $1,600 2014-06-28
Openpages Grc Platform MEDIUM 5.0
CVE-2014-3011

IBM OpenPages GRC Platform 6.1.0.1 before IF4 allows remote attackers to conduct link injection attacks via unspecified vectors.

No fix yet
Fix from $1,600 2014-06-27
Spss Analytical Decision Management HIGH 9.3
CVE-2013-5369

IBM SPSS Analytical Decision Management 6.1 before IF1, 6.2 before IF1, and 7.0 before FP1 IF6 might allow remote attackers to execute arbitrary code…

Mitigation only
Fix from $1,950 2013-09-16
Cognos Business Intelligence MEDIUM 5.0
CVE-2012-4840

IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 allows remote attackers to conduct XP…

Mitigation only
Fix from $1,600 2013-03-05
Lotus Notes HIGH 9.3
CVE-2012-2174EPSS 38%

The URL handler in IBM Lotus Notes 8.x before 8.5.3 FP2 allows remote attackers to execute arbitrary code via a crafted notes:// URL.

Mitigation only
Fix from $1,950 2012-06-20
Tivoli Netcool\/reporter HIGH 7.5
CVE-2011-4668

IBM Tivoli Netcool/Reporter 2.2 before 2.2.0.8 allows remote attackers to execute arbitrary code via vectors related to an unspecified CGI program us…

Mitigation only
Fix from $1,950 2011-12-02
Tivoli Storage Manager Fastback HIGH 10.0
CVE-2010-3758EPSS 7%

Multiple stack-based buffer overflows in FastBackServer.exe in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.…

Mitigation only
Fix from $1,950 2010-10-05
Tivoli Storage Manager Fastback HIGH 10.0
CVE-2010-3759

FastBackMount.exe in the Mount service in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 writes a cert…

Mitigation only
Fix from $1,950 2010-10-05
Tivoli Storage Manager Fastback HIGH 10.0
CVE-2010-3761

Unspecified vulnerability in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 allows remote attackers to…

Mitigation only
Fix from $1,950 2010-10-05
Soliddb HIGH 10.0
CVE-2010-2771EPSS 5%

solid.exe in IBM solidDB before 6.5 FP2 allows remote attackers to execute arbitrary code via a long username field in the first handshake packet.

Fix: after 6.5.0.1
Fix from $1,950 2010-07-22
Installation Manager HIGH 9.3
CVE-2009-3518EPSS 5%

Argument injection vulnerability in the iim: URI handler in IBMIM.exe in IBM Installation Manager 1.3.2 and earlier, as used in IBM Rational Robot an…

Fix: after 1.3.2
Fix from $1,950 2009-10-01
Lotus Notes HIGH 7.5
CVE-2009-3114

The RSS reader widget in IBM Lotus Notes 8.0 and 8.5 saves items from an RSS feed as local HTML documents, which allows remote attackers to execute a…

Mitigation only
Fix from $1,950 2009-09-09
Db2 HIGH 9.0
CVE-2008-1997

Unspecified vulnerability in the ADMIN_SP_C2 procedure in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before FP1 allows remote authenticated user…

Mitigation only
Fix from $1,950 2008-04-28
Lotus Expeditor Client HIGH 9.3
CVE-2008-1965EPSS 11%

Argument injection vulnerability in the cai: URI handler in rcplauncher in IBM Lotus Expeditor Client for Desktop 6.1.1 and 6.1.2, as used by Lotus S…

No fix yet
Fix from $1,950 2008-04-25
Lotus Notes HIGH 9.3
CVE-2007-6706

Unspecified vulnerability in nlnotes.dll in the client in IBM Lotus Notes 6.5, 7.0.x before 7.0.2 CCH or 7.0.3, and possibly 8.0 allows remote attack…

Fix: after 7.0.2
Fix from $1,950 2008-03-09
Lotus Notes HIGH 9.3
CVE-2008-1217

Unspecified vulnerability in nlnotes.dll in the client in IBM Lotus Notes 6.5, 7.0.x before 7.0.2 CCH, and 8.0.x before 8.0.1 allows remote attackers…

Mitigation only
Fix from $1,950 2008-03-09