Vulnerability index

Browse CVEs

2,216 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Case Manager HIGH 7.8
CVE-2018-1884

IBM Case Manager 5.2.0.0, 5.2.0.4, 5.2.1.0, 5.2.1.7, 5.3.0.0, and 5.3.3.0 is vulnerable to a "zip slip" vulnerability which could allow a remote atta…

Mitigation only
Fix from $1,950 2018-11-12
Db2 HIGH 7.8
CVE-2018-1780

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local db2 instance owner to obtain root acc…

Mitigation only
Fix from $1,950 2018-11-09
Db2 HIGH 7.8
CVE-2018-1781

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to obtain root access by exploit…

Mitigation only
Fix from $1,950 2018-11-09
Db2 HIGH 7.8
CVE-2018-1802

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 binaries load shared libraries from an untrusted path pot…

Mitigation only
Fix from $1,950 2018-11-09
Db2 HIGH 7.8
CVE-2018-1834

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability that could allow a local user to…

Mitigation only
Fix from $1,950 2018-11-09
Db2 MEDIUM 6.5
CVE-2018-1857

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1 could allow a user to bypass FGAC control and gain access to data they shouldn…

Mitigation only
Fix from $1,600 2018-11-09
Db2 MEDIUM 5.5
CVE-2018-1799

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local unprivileged user to overwrite files …

Mitigation only
Fix from $1,600 2018-11-09
Daeja Viewone HIGH 7.1
CVE-2018-1835

IBM Daeja ViewONE Professional, Standard & Virtual 5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote…

Mitigation only
Fix from $1,950 2018-11-02
Security Access Manager HIGH 7.5
CVE-2018-1850

IBM Security Access Manager Appliance 9.0.3.1, 9.0.4.0 and 9.0.5.0 could allow unauthorized administration operations when Advanced Access Control se…

Mitigation only
Fix from $1,950 2018-10-22
Websphere Application Server MEDIUM 6.5
CVE-2018-1838

IBM WebSphere Application Server 8.5 and 9.0 in IBM Cloud could allow a remote attacker to obtain sensitive information caused by improper handling o…

Mitigation only
Fix from $1,600 2018-10-12
Qlogic 4 Gb Fibre Channel Expansion Card Firmware CRITICAL 9.8
CVE-2018-18202

The QLogic 4Gb Fibre Channel 5.5.2.6.0 and 4/8Gb SAN 7.10.1.20.0 modules for IBM BladeCenter have an undocumented support account with a support pass…

No fix yet
Fix from $2,300 2018-10-10
Security Guardium HIGH 7.8
CVE-2018-1498

IBM Security Guardium EcoSystem 10.5 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 141223.

Mitigation only
Fix from $1,950 2018-10-02
Security Guardium HIGH 7.4
CVE-2018-1509

IBM Security Guardium EcoSystem 10.5 does not validate, or incorrectly validates, a certificate.This weakness might allow an attacker to spoof a trus…

Mitigation only
Fix from $1,950 2018-10-02
Platform Symphony HIGH 7.1
CVE-2018-1702

IBM Platform Symphony 7.1 Fix Pack 1 and 7.1.1 and IBM Spectrum Symphony 7.1.2 and 7.2.0.2 are vulnerable to a XML External Entity Injection (XXE) at…

Mitigation only
Fix from $1,950 2018-09-28
Platform Symphony MEDIUM 5.4
CVE-2018-1704

IBM Platform Symphony 7.1 Fix Pack 1 and 7.1.1 and IBM Spectrum Symphony 7.1.2 and 7.2.0.2 could allow a remote attacker to conduct phishing attacks,…

Mitigation only
Fix from $1,600 2018-09-28
Db2 HIGH 7.8
CVE-2018-1710

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.1, 10.5, and 11.1 tool db2licm is affected by buffer overflow vulnerability that…

Mitigation only
Fix from $1,950 2018-09-21
Db2 HIGH 7.8
CVE-2018-1711

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to to gain privileges due to all…

Mitigation only
Fix from $1,950 2018-09-21
Db2 MEDIUM 5.5
CVE-2018-1685

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability in db2cacpy that could allow a l…

Mitigation only
Fix from $1,600 2018-09-21
Spectrum Scale MEDIUM 6.5
CVE-2018-1782

IBM GPFS (IBM Spectrum Scale 5.0.1.0 and 5.0.1.1) allows a local, unprivileged user to cause a kernel panic on a node running GPFS by accessing a fil…

Mitigation only
Fix from $1,600 2018-09-19
Campaign MEDIUM 5.4
CVE-2017-1114

IBM Campaign 9.1, 9.1.2, and 10 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web …

Mitigation only
Fix from $1,600 2018-09-07
Platform Symphony MEDIUM 6.5
CVE-2018-1705

IBM Platform Symphony 7.1 Fix Pack 1 and 7.1.1 and IBM Spectrum Symphony 7.1.2 and 7.2.0.2 contain an information disclosure vulnerability that could…

Mitigation only
Fix from $1,600 2018-08-28
Security Access Manager CRITICAL 10.0
CVE-2018-1722EPSS 9%

IBM Security Access Manager Appliance 9.0.4.0 and 9.0.5.0 could allow remote code execution when Advanced Access Control or Federation services are r…

Mitigation only
Fix from $2,300 2018-08-24
Tivoli Application Dependency Discovery Manager HIGH 8.8
CVE-2018-1455

IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 is vulnerable to cross-site request forgery which could allow an attacker to execut…

Mitigation only
Fix from $1,950 2018-08-15
Platform Symphony HIGH 8.8
CVE-2018-1595

IBM Spectrum Symphony and Platform Symphony 7.1.2 and 7.2.0.2 could allow an authenticated user to execute arbitrary commands due to improper handlin…

Mitigation only
Fix from $1,950 2018-08-01
Lotus Notes HIGH 7.0
CVE-2013-0522

The Notes Client Single Logon feature in IBM Notes 8.0, 8.0.1, 8.0.2, 8.5, 8.5.1, 8.5.2, 8.5.3, and 9.0 on Windows allows local users to discover pas…

Mitigation only
Fix from $1,950 2018-07-16
Network Operating System MEDIUM 5.3
CVE-2013-0570

The Fibre Channel over Ethernet (FCoE) feature in IBM System Networking and Blade Network Technology (BNT) switches running IBM Networking Operating …

Mitigation only
Fix from $1,600 2018-07-13
Db2 HIGH 7.8
CVE-2018-1458

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10,1, 10.5 and 11.1 could allow a local user to execute arbitrary code and con…

Mitigation only
Fix from $1,950 2018-07-10
Db2 HIGH 7.8
CVE-2018-1487

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5 and 11.1 binaries load shared libraries from an untrusted path pote…

Mitigation only
Fix from $1,950 2018-07-10
Db2 HIGH 7.8
CVE-2018-1566

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to execute arbitrary code due to…

Mitigation only
Fix from $1,950 2018-07-10
Infosphere Data Replication Dashboard CRITICAL 9.8
CVE-2013-3000

SQL injection vulnerability in IBM InfoSphere Data Replication Dashboard 9.7 and 10.1 allows remote attackers to execute arbitrary SQL commands via u…

Mitigation only
Fix from $2,300 2018-07-09