Vulnerability index

Browse CVEs

2,226 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Websphere Portal MEDIUM 5.3
CVE-2017-1698

IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 could reveal sensitive information from an error message that could lead to further attacks against the s…

Mitigation only
Fix from $1,600 2017-12-27
Security Guardium HIGH 8.8
CVE-2017-1757

IBM Security Guardium 10.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attac…

Mitigation only
Fix from $1,950 2017-12-20
Integration Bus HIGH 8.1
CVE-2017-1694

IBM Integration Bus 9.0 and 10.0 transmits user credentials in plain in clear text which can be read by an attacker using man in the middle technique…

Mitigation only
Fix from $1,950 2017-12-20
Security Guardium HIGH 7.5
CVE-2017-1598

IBM Security Guardium 10.0 Database Activity Monitor uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highl…

Mitigation only
Fix from $1,950 2017-12-20
Security Guardium MEDIUM 5.5
CVE-2017-1596

IBM Security Guardium 10.0 Database Activity Monitor could allow a local attacker to obtain highly sensitive information via unspecified vectors. IBM…

Mitigation only
Fix from $1,600 2017-12-20
Security Guardium MEDIUM 5.4
CVE-2017-1600

IBM Security Guardium 10.0 Database Activity Monitor is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaSc…

Mitigation only
Fix from $1,600 2017-12-20
Robotic Process Automation With Automation Anywhere MEDIUM 5.4
CVE-2017-1751

IBM Robotic Process Automation with Automation Anywhere 10.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitr…

Mitigation only
Fix from $1,600 2017-12-20
Security Guardium MEDIUM 6.1
CVE-2017-1262

IBM Security Guardium 10.0 is vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-craft…

Mitigation only
Fix from $1,600 2017-12-20
Security Guardium MEDIUM 5.5
CVE-2017-1595

IBM Security Guardium 10.0 Database Activity Monitor could allow a local attacker to obtain highly sensitive information via unspecified vectors. IBM…

Mitigation only
Fix from $1,600 2017-12-20
Security Guardium MEDIUM 5.4
CVE-2017-1266

IBM Security Guardium 10.0 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by uninte…

Mitigation only
Fix from $1,600 2017-12-20
Business Process Manager MEDIUM 5.4
CVE-2017-1494

IBM Business Process Manager 8.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web…

Mitigation only
Fix from $1,600 2017-12-20
Websphere Portal MEDIUM 5.3
CVE-2017-1423

IBM WebSphere Portal 8.5 and 9.0 exposes backend server URLs that are configured for usage by the Web Application Bridge component. IBM X-Force ID: 1…

Mitigation only
Fix from $1,600 2017-12-20
Tivoli Monitoring HIGH 8.0
CVE-2017-1635

IBM Tivoli Monitoring V6 6.2.2.x could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free error. A remote at…

Mitigation only
Fix from $1,950 2017-12-13
Inotes MEDIUM 6.1
CVE-2017-1421

IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the …

Mitigation only
Fix from $1,600 2017-12-13
Maximo Asset Management MEDIUM 6.1
CVE-2017-1558

IBM Maximo Asset Management 7.5 and 7.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a vic…

Mitigation only
Fix from $1,600 2017-12-13
Rational Doors Next Generation MEDIUM 5.4
CVE-2017-1546

IBM DOORS Next Generation (DNG/RRC) 4.07, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Java…

Mitigation only
Fix from $1,600 2017-12-13
Financial Transaction Manager HIGH 8.8
CVE-2017-1606

IBM Financial Transaction Manager (FTM) for Multi-Platform (MP) 3.0.0.0 through 3.0.0.7 is vulnerable to SQL injection. A remote attacker could send …

Mitigation only
Fix from $1,950 2017-12-11
Websphere Mq HIGH 7.1
CVE-2017-1760

IBM WebSphere MQ 7.5, 8.0, and 9.0 could allow a local user to crash the queue manager agent thread and expose some sensitive information. IBM X-Forc…

Mitigation only
Fix from $1,950 2017-12-11
Sterling File Gateway MEDIUM 6.5
CVE-2017-1550

IBM Sterling File Gateway 2.2 could allow an authenticated user to change other user's passwords. IBM X-Force ID: 131290.

Mitigation only
Fix from $1,600 2017-12-11
Websphere Portal MEDIUM 5.4
CVE-2017-1536

IBM Support Tools for Lotus WCM (IBM WebSphere Portal 7.0, 8.0, 8.5 and 9.0) is vulnerable to cross-site scripting. This vulnerability allows users t…

Mitigation only
Fix from $1,600 2017-12-11
Sterling File Gateway MEDIUM 5.4
CVE-2017-1549

IBM Sterling File Gateway 2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI…

Mitigation only
Fix from $1,600 2017-12-11
Sterling File Gateway MEDIUM 5.4
CVE-2017-1632

IBM Sterling File Gateway 2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI…

Mitigation only
Fix from $1,600 2017-12-11
Connections Engagement Center MEDIUM 5.4
CVE-2017-1683

IBM Connections Engagement Center 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in th…

Mitigation only
Fix from $1,600 2017-12-11
Sterling File Gateway MEDIUM 5.3
CVE-2017-1548

IBM Sterling File Gateway 2.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL req…

Mitigation only
Fix from $1,600 2017-12-11
Connections MEDIUM 5.3
CVE-2017-1613

IBM Connections 6.0 could allow an unauthenticated remote attacker to gain unauthenticated or unauthorized access to non-sensitive Engagement Center …

Mitigation only
Fix from $1,600 2017-12-11
Sterling File Gateway MEDIUM 6.5
CVE-2017-1487

IBM Sterling File Gateway 2.2 could allow an authenticated attacker to obtain sensitive information such as login ids on the system. IBM X-Force ID: …

Mitigation only
Fix from $1,600 2017-12-07
Sterling B2b Integrator MEDIUM 5.4
CVE-2017-1482

IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript…

Mitigation only
Fix from $1,600 2017-12-07
Connections MEDIUM 5.4
CVE-2017-1498

IBM Connections 5.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alte…

Mitigation only
Fix from $1,600 2017-12-07
Atlas Ediscovery Process Management HIGH 8.8
CVE-2017-1356

IBM Atlas eDiscovery Process Management 6.0.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which co…

Mitigation only
Fix from $1,950 2017-12-07
Security Guardium HIGH 7.5
CVE-2017-1271

IBM Security Guardium 9.0, 9.1, and 9.5 supports interaction between multiple actors and allows those actors to negotiate which algorithm should be u…

Mitigation only
Fix from $1,950 2017-12-07