Vulnerability index

Browse CVEs

2,226 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Security Guardium CRITICAL 9.9
CVE-2017-1253

IBM Security Guardium 10.0 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted re…

Mitigation only
Fix from $2,300 2017-07-05
Security Guardium HIGH 7.5
CVE-2017-1264

IBM Security Guardium 10.0 does not prove or insufficiently proves that the actors identity is correct which can lead to exposure of resources or fun…

Mitigation only
Fix from $1,950 2017-07-05
Security Guardium HIGH 7.1
CVE-2017-1254

IBM Security Guardium 10.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit th…

Mitigation only
Fix from $1,950 2017-07-05
Jazz Reporting Service MEDIUM 5.4
CVE-2016-9986

IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav…

Mitigation only
Fix from $1,600 2017-07-05
Jazz Reporting Service MEDIUM 5.4
CVE-2016-9987

IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav…

Mitigation only
Fix from $1,600 2017-07-05
Jazz Reporting Service MEDIUM 5.4
CVE-2016-9988

IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav…

Mitigation only
Fix from $1,600 2017-07-05
Jazz Reporting Service MEDIUM 5.4
CVE-2016-9989

IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav…

Mitigation only
Fix from $1,600 2017-07-05
Jazz Reporting Service MEDIUM 5.4
CVE-2017-1096

IBM Jazz Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript cod…

Mitigation only
Fix from $1,600 2017-07-05
Maximo Asset Management CRITICAL 9.8
CVE-2017-1175

IBM Maximo Asset Management 7.1, 7.5, and 7.6 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which co…

Mitigation only
Fix from $2,300 2017-07-05
Websphere Message Broker MEDIUM 5.5
CVE-2017-1207

IBM WebSphere Message Broker stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 123777.

Mitigation only
Fix from $1,600 2017-07-05
Rational Team Concert MEDIUM 5.4
CVE-2016-9701

IBM Team Concert 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the We…

Mitigation only
Fix from $1,600 2017-07-05
Rational Team Concert MEDIUM 5.4
CVE-2016-9733

IBM Team Concert (RTC) 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in …

Mitigation only
Fix from $1,600 2017-07-05
Rational Team Concert MEDIUM 5.4
CVE-2016-9746

IBM Team Concert (RTC) 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in …

Mitigation only
Fix from $1,600 2017-07-05
Rational Team Concert MEDIUM 5.4
CVE-2017-1113

IBM Rational Team Concert (RTC) 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript…

Mitigation only
Fix from $1,600 2017-07-05
Maximo Asset Management MEDIUM 5.4
CVE-2017-1208

IBM Maximo Asset Management 7.1, 7.5, and 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript co…

Mitigation only
Fix from $1,600 2017-07-05
Security Guardium CRITICAL 9.8
CVE-2017-1269

IBM Security Guardium 10.0 and 10.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow …

Mitigation only
Fix from $2,300 2017-07-05
Security Guardium MEDIUM 6.5
CVE-2017-1258

IBM Security Guardium 10.0 and 10.1 does not perform an authentication check for a critical resource or functionality allowing anonymous users access…

Mitigation only
Fix from $1,600 2017-07-05
Websphere Portal MEDIUM 6.1
CVE-2017-1217

IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web…

Mitigation only
Fix from $1,600 2017-07-05
Security Guardium MEDIUM 6.1
CVE-2017-1256

IBM Security Guardium 10.0, 10.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web…

Mitigation only
Fix from $1,600 2017-07-05
Curam Social Program Management MEDIUM 5.4
CVE-2017-1106

IBM Curam Social Program Management 5.2, 6.0, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaS…

Mitigation only
Fix from $1,600 2017-06-28
Elastic Storage Server MEDIUM 6.2
CVE-2017-1304

IBM has identified a vulnerability with IBM Spectrum Scale/GPFS utilized on the Elastic Storage Server (ESS)/GPFS Storage Server (GSS) during testing…

Mitigation only
Fix from $1,600 2017-06-21
Bigfix Security Compliance Analytics CRITICAL 9.8
CVE-2017-1197

IBM BigFix Compliance (TEMA SUAv1 SCA SCM) uses an inadequate account lockout setting that could allow a remote attacker to brute force account crede…

Mitigation only
Fix from $2,300 2017-06-15
Maximo Asset Management HIGH 8.8
CVE-2016-9984

IBM Maximo Asset Management 7.5 and 7.6 could allow a remote authenticated attacker to execute arbitrary commands on the system as administrator. IBM…

Mitigation only
Fix from $1,950 2017-06-13
Rational Collaborative Lifecycle Management MEDIUM 5.4
CVE-2016-9973

IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alte…

Mitigation only
Fix from $1,600 2017-06-13
Curam Social Program Management MEDIUM 5.3
CVE-2014-4843

Curam Universal Access in IBM Curam Social Program Management (SPM) 6.0 SP2 before EP26, 6.0.4 before 6.0.4.6, and 6.0.5 before 6.0.5.5 iFix5 allows …

Mitigation only
Fix from $1,600 2017-06-08
Bigfix Security Compliance Analytics CRITICAL 9.8
CVE-2017-1196

IBM BigFix Compliance (TEMA SUAv1 SCA SCM) 1.9.70 does not require that users should have strong passwords by default, which makes it easier for atta…

Mitigation only
Fix from $2,300 2017-06-07
Bigfix Security Compliance Analytics MEDIUM 6.1
CVE-2017-1178

IBM Endpoint Manager for Security and Compliance 1.9.70 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav…

Mitigation only
Fix from $1,600 2017-06-07
Security Privileged Identity Manager MEDIUM 5.5
CVE-2016-5960

IBM Security Privileged Identity Manager 2.0.2 and 2.1.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Forc…

Mitigation only
Fix from $1,600 2017-06-07
Tivoli Storage Manager MEDIUM 5.5
CVE-2016-8939

IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) clients/agents store password information in the Windows Registry in a manner which can…

Mitigation only
Fix from $1,600 2017-06-07
Marketing Platform HIGH 8.8
CVE-2016-6112

IBM Distributed Marketing and Marketing Platform 8.6, 9.0, 9.1, and 10.0 could allow an authenticated user to escalate their privileges and gain admi…

Mitigation only
Fix from $1,950 2017-05-22