Vulnerability index

Browse CVEs

2,226 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Rational Team Concert MEDIUM 6.3
CVE-2016-0325

IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; R…

Mitigation only
Fix from $1,600 2016-11-24
Rational Team Concert MEDIUM 5.4
CVE-2016-0285

Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before…

Mitigation only
Fix from $1,600 2016-11-24
Rational Software Architect Design Manager MEDIUM 5.4
CVE-2016-0284

The XML parser in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 bef…

Mitigation only
Fix from $1,600 2016-11-24
Lotus Inotes MEDIUM 5.4
CVE-2016-0282

Cross-site scripting (XSS) vulnerability in IBM iNotes before 8.5.3 FP6 IF2 allows remote authenticated users to inject arbitrary web script or HTML …

Mitigation only
Fix from $1,600 2016-11-24
Rational Doors Next Generation MEDIUM 5.4
CVE-2016-0273

Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before…

Mitigation only
Fix from $1,600 2016-11-24
Sterling Secure Proxy MEDIUM 6.1
CVE-2016-6027

The Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.0 iFix 1 does not enable the HSTS pro…

Mitigation only
Fix from $1,600 2016-10-06
Sterling Secure Proxy MEDIUM 5.3
CVE-2016-6026

The Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.0 iFix 1 allows man-in-the-middle att…

Mitigation only
Fix from $1,600 2016-10-06
Sterling Secure Proxy MEDIUM 5.9
CVE-2016-6025

The Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.0 iFix 1 allows remote attackers to o…

Mitigation only
Fix from $1,600 2016-10-06
Sterling Secure Proxy HIGH 7.5
CVE-2016-6023

Directory traversal vulnerability in the Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.…

Mitigation only
Fix from $1,950 2016-10-06
Websphere Application Server MEDIUM 5.4
CVE-2016-3042

Cross-site scripting (XSS) vulnerability in the Web UI in IBM WebSphere Application Server (WAS) Liberty before 16.0.0.3 allows remote authenticated …

Mitigation only
Fix from $1,600 2016-10-01
Aix MEDIUM 6.5
CVE-2016-6038

Directory traversal vulnerability in Eclipse Help in IBM Tivoli Lightweight Infrastructure (aka LWI), as used in AIX 5.3, 6.1, and 7.1, allows remote…

Mitigation only
Fix from $1,600 2016-09-26
Tealeaf Customer Experience MEDIUM 5.4
CVE-2016-5978

Cross-site scripting (XSS) vulnerability in the Web UI in the web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.…

Mitigation only
Fix from $1,600 2016-09-26
Mq Appliance Firmware HIGH 8.8
CVE-2016-5879

MQCLI on IBM MQ Appliance M2000 and M2001 devices allows local users to execute arbitrary shell commands via a crafted (1) Disaster Recovery or (2) H…

Mitigation only
Fix from $1,950 2016-09-02
Bigfix Platform MEDIUM 6.1
CVE-2016-0293

Cross-site scripting (XSS) vulnerability in IBM BigFix Platform (formerly Tivoli Endpoint Manager) 9.x before 9.1.8 and 9.2.x before 9.2.8 allows rem…

Mitigation only
Fix from $1,600 2016-09-01
Bigfix Webreports MEDIUM 5.9
CVE-2016-0397

WebReports in IBM BigFix Platform (formerly Tivoli Endpoint Manager) 9.x before 9.5.2 allows remote attackers to obtain sensitive information by snif…

Mitigation only
Fix from $1,600 2016-08-30
Bigfix MEDIUM 5.5
CVE-2016-0292

WebReports in IBM BigFix Platform (formerly Tivoli Endpoint Manager) 9.x before 9.5.2 allows local users to discover the cleartext system password by…

Mitigation only
Fix from $1,600 2016-08-30
Websphere Portal MEDIUM 5.4
CVE-2016-2925

Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.x through 7.0.0.2 CF30…

Mitigation only
Fix from $1,600 2016-08-08
Engineering Lifecycle Optimization Publishing MEDIUM 5.4
CVE-2016-2912

Cross-site scripting (XSS) vulnerability in the Document Builder in IBM Rational Publishing Engine (aka RPENG) 2.0.1 before ifix002 allows remote aut…

Mitigation only
Fix from $1,600 2016-08-08
Traveler HIGH 8.1
CVE-2016-3039

IBM Traveler 8.x and 9.x before 9.0.1.12 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) …

Mitigation only
Fix from $1,950 2016-07-17
Maximo Asset Management MEDIUM 5.3
CVE-2016-0393

IBM Maximo Asset Management 7.5 before 7.5.0.10-TIV-MBS-IFIX002 and 7.6 before 7.6.0.5-TIV-MAMMT-FP001 allows remote attackers to obtain sensitive UR…

Mitigation only
Fix from $1,600 2016-07-17
Personal Communications MEDIUM 6.2
CVE-2016-0321

IBM Personal Communications (aka PCOMM) 6.x before 6.0.17 and 12.x before 12.0.0.1 does not properly restrict credential extraction, which allows loc…

Mitigation only
Fix from $1,600 2016-07-17
Security Identity Manager Adapter HIGH 7.4
CVE-2016-0340

IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 mishandles session expiration, which allow…

Mitigation only
Fix from $1,950 2016-07-15
Security Identity Manager Adapter MEDIUM 5.6
CVE-2016-0339

IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 mishandles session identifiers after logou…

Mitigation only
Fix from $1,600 2016-07-15
Security Identity Manager Adapter MEDIUM 6.2
CVE-2016-0338

IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 allows local users to discover cleartext p…

Mitigation only
Fix from $1,600 2016-07-15
Security Identity Manager Adapter HIGH 7.3
CVE-2016-0330

IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 mishandles password creation, which makes …

No fix yet
Fix from $1,950 2016-07-15
Bigfix Platform MEDIUM 5.4
CVE-2016-0269

Cross-site scripting (XSS) vulnerability in IBM BigFix Platform 9.x before 9.1.8 and 9.2.x before 9.2.7 allows remote authenticated users to inject a…

Mitigation only
Fix from $1,600 2016-07-15
Tivoli Directory Server HIGH 7.5
CVE-2015-1977

Directory traversal vulnerability in the Web Administration tool in IBM Tivoli Directory Server (ITDS) before 6.1.0.74-ISS-ISDS-IF0074, 6.2.x before …

Mitigation only
Fix from $1,950 2016-07-15
Websphere Application Server HIGH 7.5
CVE-2016-2945

The API Discovery implementation in IBM WebSphere Application Server (WAS) 8.5.5.8 through 8.5.5.9 Liberty before Liberty Fix Pack 16.0.0.2 allows re…

Mitigation only
Fix from $1,950 2016-07-08
Jazz Reporting Service HIGH 8.8
CVE-2016-2889

Cross-site request forgery (CSRF) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x bef…

Mitigation only
Fix from $1,950 2016-07-08
Jazz Reporting Service MEDIUM 5.4
CVE-2016-2888

Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0…

Mitigation only
Fix from $1,600 2016-07-08