Vulnerability index

Browse CVEs

2,226 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Qradar Security Information And Event Manager MEDIUM 6.5
CVE-2016-9750

IBM QRadar 7.2 and 7.3 stores user credentials in plain in clear text which can be read by an authenticated user. IBM X-Force ID: 120207.

Mitigation only
Fix from $1,600 2017-05-15
Cognos Analytics MEDIUM 5.4
CVE-2016-3032

IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thu…

Mitigation only
Fix from $1,600 2017-05-10
Maximo Asset Management MEDIUM 5.6
CVE-2016-8924

IBM Maximo Asset Management 7.1, 7.5 and 7.6 could allow a remote attacker to hijack a user's session, caused by the failure to invalidate an existin…

Mitigation only
Fix from $1,600 2017-04-26
Domino HIGH 8.8
CVE-2017-1274EPSS 7%

IBM Domino 8.5.3, and 9.0 is vulnerable to a stack based overflow in the IMAP service that could allow an authenticated attacker to execute arbitrary…

No fix yet
Fix from $1,950 2017-04-25
Urbancode Deploy HIGH 8.1
CVE-2017-1149

IBM UrbanCode Deploy (UCD) 6.0, 6.1, and 6.2 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when proces…

Mitigation only
Fix from $1,950 2017-04-25
Change And Configuration Management Database MEDIUM 6.5
CVE-2015-0107EPSS 6%

IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration Management Database 7.1 through 7.1.1.8 and 7.2 a…

Mitigation only
Fix from $1,600 2017-04-24
Security Guardium HIGH 7.4
CVE-2017-1122

IBM Security Guardium 8.2, 9.0, and 10.0 contains a vulnerability that could allow a local attacker with CLI access to inject arbitrary commands whic…

Mitigation only
Fix from $1,950 2017-04-20
Api Connect HIGH 7.3
CVE-2017-1161

IBM API Connect 5.0.6.0 could allow a remote attacker to execute arbitrary commands on the system, caused by improper validation of URLs for the Deve…

Mitigation only
Fix from $1,950 2017-04-17
Disposal And Governance Management For It HIGH 8.8
CVE-2016-6100

IBM Disposal and Governance Management for IT and IBM Global Retention Policy and Schedule Management, components of IBM Atlas Policy Suite 6.0.3 is …

Mitigation only
Fix from $1,950 2017-04-05
Tririga Application Platform MEDIUM 5.3
CVE-2017-1180

The IBM TRIRIGA Document Manager contains a vulnerability that could allow an authenticated user to execute actions they did not have access to. IBM …

Mitigation only
Fix from $1,600 2017-04-05
Kenexa Lcms Premier MEDIUM 6.5
CVE-2017-1142

IBM Kenexa LCMS Premier on Cloud 9.x and 10.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set the secure …

Mitigation only
Fix from $1,600 2017-03-27
Kenexa Lcms Premier MEDIUM 5.3
CVE-2017-1143

IBM Kenexa LCMS Premier on Cloud 9.x and 10.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable…

Mitigation only
Fix from $1,600 2017-03-27
Content Navigator MEDIUM 5.4
CVE-2017-1146

IBM Content Navigator 2.0.3 and 3.0.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…

Mitigation only
Fix from $1,600 2017-03-20
Urbancode Deploy MEDIUM 5.4
CVE-2016-9006

IBM UrbanCode Deploy 6.1 and 6.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web…

Mitigation only
Fix from $1,600 2017-03-08
Advanced Management Module Firmware MEDIUM 6.1
CVE-2016-8232

Document Object Model-(DOM) based cross-site scripting vulnerability in the Advanced Management Module (AMM) versions earlier than 66Z of Lenovo IBM …

Mitigation only
Fix from $1,600 2017-03-01
Connections MEDIUM 5.4
CVE-2016-5932

IBM Connections 4.0, 4.5, 5.0, and 5.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…

Mitigation only
Fix from $1,600 2017-03-01
Resilient MEDIUM 6.1
CVE-2016-6062

IBM Resilient v26.0, v26.1, and v26.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in th…

Mitigation only
Fix from $1,600 2017-02-16
Websphere Mq Jms CRITICAL 9.8
CVE-2016-0360

IBM Websphere MQ JMS 7.0.1, 7.1, 7.5, 8.0, and 9.0 client provides classes that deserialize objects from untrusted sources which could allow a malici…

Mitigation only
Fix from $2,300 2017-02-15
System Storage Ts3100 Ts3200 Tape Library CRITICAL 9.8
CVE-2016-9005

IBM System Storage TS3100-TS3200 Tape Library could allow an unauthenticated user with access to the company network, to change a user's password and…

Mitigation only
Fix from $2,300 2017-02-08
Tivoli Storage Manager Fastback HIGH 7.3
CVE-2016-5934

IBM Tivoli Storage Manager FastBack installer could allow a remote attacker to execute arbitrary code on the system. By placing a specially-crafted D…

Mitigation only
Fix from $1,950 2017-02-08
Aix HIGH 7.8
CVE-2017-1093

IBM AIX 6.1, 7.1, and 7.2 could allow a local user to exploit a vulnerability in the bellmail binary to gain root privileges.

Mitigation only
Fix from $1,950 2017-02-02
Dashboard Application Services Hub MEDIUM 5.9
CVE-2016-5935

IBM Jazz for Service Management could allow a remote attacker to obtain sensitive information, caused by the failure to properly validate the SSL cer…

Mitigation only
Fix from $1,600 2017-02-02
License Metric Tool MEDIUM 5.3
CVE-2016-8977

IBM BigFix Inventory v9 could disclose sensitive information to an unauthorized user using HTTP GET requests. This information could be used to mount…

Mitigation only
Fix from $1,600 2017-02-01
Inotes MEDIUM 6.1
CVE-2016-5881

IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the …

Mitigation only
Fix from $1,600 2017-02-01
Urbancode Deploy MEDIUM 5.5
CVE-2016-2941

IBM UrbanCode Deploy creates temporary files during step execution that could contain sensitive information including passwords that could be read by…

Mitigation only
Fix from $1,600 2017-02-01
License Metric Tool MEDIUM 5.5
CVE-2016-8967

IBM BigFix Inventory v9 9.2 stores user credentials in plain in clear text which can be read by a local user.

Mitigation only
Fix from $1,600 2017-02-01
License Metric Tool HIGH 8.1
CVE-2016-8980

IBM BigFix Inventory v9 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remo…

Mitigation only
Fix from $1,950 2017-02-01
License Metric Tool MEDIUM 5.9
CVE-2016-8966

IBM BigFix Inventory v9 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport…

Mitigation only
Fix from $1,600 2017-02-01
License Metric Tool MEDIUM 5.5
CVE-2016-8981

IBM BigFix Inventory v9 allows web pages to be stored locally which can be read by another user on the system.

Mitigation only
Fix from $1,600 2017-02-01
Kenexa Lms On Cloud HIGH 8.8
CVE-2016-6124

IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arb…

Mitigation only
Fix from $1,950 2017-02-01