Vulnerability index

Browse CVEs

2,226 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filenet Workplace Xt HIGH 8.8
CVE-2016-8921

IBM FileNet WorkPlace XT could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vul…

Mitigation only
Fix from $1,950 2017-02-01
Kenexa Lms On Cloud MEDIUM 6.5
CVE-2016-6126

IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to traverse directories on the system. An attacker could send a speciall…

Mitigation only
Fix from $1,600 2017-02-01
Kenexa Lms On Cloud MEDIUM 6.5
CVE-2016-8913

IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to traverse directories on the system. An attacker could send a speciall…

Mitigation only
Fix from $1,600 2017-02-01
Domino MEDIUM 6.1
CVE-2016-6113

IBM Verse is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the i…

Mitigation only
Fix from $1,600 2017-02-01
Web Content Manager Production Analytics MEDIUM 6.1
CVE-2016-8922

Exphox WebRadar is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering…

Mitigation only
Fix from $1,600 2017-02-01
Kenexa Lms On Cloud MEDIUM 5.4
CVE-2016-6123

IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript c…

Mitigation only
Fix from $1,600 2017-02-01
Kenexa Lms On Cloud MEDIUM 5.4
CVE-2016-6125

IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript c…

Mitigation only
Fix from $1,600 2017-02-01
Kenexa Lms On Cloud MEDIUM 5.4
CVE-2016-8911

IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to v…

Mitigation only
Fix from $1,600 2017-02-01
Kenexa Lms On Cloud MEDIUM 5.4
CVE-2016-8920

IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript c…

Mitigation only
Fix from $1,600 2017-02-01
Aix HIGH 7.8
CVE-2016-3053

IBM AIX contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges.

No fix yet
Fix from $1,950 2017-02-01
Security Access Manager MEDIUM 6.1
CVE-2016-3018

IBM Security Access Manager for Web is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the …

Mitigation only
Fix from $1,600 2017-02-01
Filenet Workplace MEDIUM 6.8
CVE-2016-3047

Open redirect vulnerability in IBM FileNet Workplace 4.0.2 through 4.0.2.14 IF001 allows remote authenticated users to redirect users to arbitrary we…

Mitigation only
Fix from $1,600 2016-12-01
Powerkvm MEDIUM 6.5
CVE-2016-3044

The Linux kernel component in IBM PowerKVM 2.1 before 2.1.1.3-65.10 and 3.1 before 3.1.0.2 allows guest OS users to cause a denial of service (host O…

Mitigation only
Fix from $1,600 2016-12-01
Appscan Source HIGH 8.1
CVE-2016-3033

IBM AppScan Source 8.7 through 9.0.3.3 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) vi…

Mitigation only
Fix from $1,950 2016-12-01
Urbancode Deploy MEDIUM 5.4
CVE-2016-2994

Cross-site scripting (XSS) vulnerability in IBM UrbanCode Deploy 6.2.x before 6.2.1.2 allows remote authenticated users to inject arbitrary web scrip…

Mitigation only
Fix from $1,600 2016-12-01
Lotus Protector For Mail Security MEDIUM 5.4
CVE-2016-2991

Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Protector for Mail Security 2.8.0.0 through 2.8.1.0 before 2.8.1.0-22115 allow remot…

Mitigation only
Fix from $1,600 2016-12-01
Tririga Application Platform HIGH 8.8
CVE-2016-2917

The notifications component in IBM TRIRIGA Applications 10.4 and 10.5 before 10.5.1 allows remote authenticated users to obtain sensitive password in…

Mitigation only
Fix from $1,950 2016-11-30
Qradar Security Information And Event Manager HIGH 8.0
CVE-2016-2878

Multiple cross-site request forgery (CSRF) vulnerabilities in IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 allow remote attackers to …

Mitigation only
Fix from $1,950 2016-11-30
Rational Engineering Lifecycle Manager MEDIUM 5.4
CVE-2016-3014

Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 4.0 before 4.0.7 iFix11 and 5.0 before 5.0.2 iFix17, Rati…

Mitigation only
Fix from $1,600 2016-11-30
Bigfix Remote Control HIGH 7.8
CVE-2016-2948

IBM BigFix Remote Control before 9.1.3 allows local users to discover hardcoded credentials via unspecified vectors.

Mitigation only
Fix from $1,950 2016-11-30
Rational Asset Analyzer MEDIUM 5.5
CVE-2016-5967

The installation component in IBM Rational Asset Analyzer (RAA) 6.1.0 before FP10 allows local users to discover the WAS Admin password by reading IM…

Mitigation only
Fix from $1,600 2016-11-25
Rational Doors Next Generation MEDIUM 5.4
CVE-2016-5955

Cross-site scripting (XSS) vulnerability in IBM Rational DOORS Next Generation 6.0.2 before iFix004 allows remote authenticated users to inject arbit…

Mitigation only
Fix from $1,600 2016-11-25
Security Access Manager CRITICAL 9.1
CVE-2016-3028

IBM Security Access Manager for Web 7.0 before IF2 and 8.0 before 8.0.1.4 IF3 and Security Access Manager 9.0 before 9.0.1.0 IF5 allow remote authent…

Mitigation only
Fix from $2,300 2016-11-25
Security Access Manager HIGH 8.1
CVE-2016-3025

IBM Security Access Manager for Mobile 8.x before 8.0.1.4 IF3 and Security Access Manager 9.x before 9.0.1.0 IF5 do not properly restrict failed logi…

Mitigation only
Fix from $1,950 2016-11-25
Tivoli Storage Manager For Virtual Environments HIGH 8.5
CVE-2016-2988

IBM Tivoli Storage Manger for Virtual Environments: Data Protection for VMware (aka Spectrum Protect for Virtual Environments) 6.4.x before 6.4.3.4 a…

Mitigation only
Fix from $1,950 2016-11-25
Rational Engineering Lifecycle Manager MEDIUM 5.4
CVE-2016-2986

Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 6.x before 6.0.1 iFix6, Rational Quality Manager 6.x befo…

Mitigation only
Fix from $1,600 2016-11-25
Spectrum Scale HIGH 7.0
CVE-2016-2985

IBM Spectrum Scale 4.1.1.x before 4.1.1.8 and 4.2.x before 4.2.0.4 and General Parallel File System (GPFS) 3.5.x before 3.5.0.32 and 4.1.x before 4.1…

Mitigation only
Fix from $1,950 2016-11-25
Spectrum Scale HIGH 7.0
CVE-2016-2984

IBM Spectrum Scale 4.1.1.x before 4.1.1.8 and 4.2.x before 4.2.0.4 and General Parallel File System (GPFS) 3.5.x before 3.5.0.32 and 4.1.x before 4.1…

Mitigation only
Fix from $1,950 2016-11-25
Security Privileged Identity Manager MEDIUM 6.5
CVE-2016-2996

IBM Security Privileged Identity Manager 2.0 before 2.0.2 FP8, when Virtual Appliance is used, allows remote authenticated users to append to arbitra…

Mitigation only
Fix from $1,600 2016-11-24
Rational Quality Manager MEDIUM 5.4
CVE-2016-2864

Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before…

Mitigation only
Fix from $1,600 2016-11-24