Vulnerability index

Browse CVEs

2,232 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Integration Bus MEDIUM 5.3
CVE-2015-7399

IBM WebSphere Message Broker 7 before 7.0.0.8 and 8 before 8.0.0.6 and IBM Integration Bus 9 before 9.0.0.3 and 10 before 10.0.0.0 allow remote attac…

Mitigation only
Fix from $1,600 2016-01-11
Jazz Reporting Service HIGH 8.8
CVE-2015-7465

Cross-site request forgery (CSRF) vulnerability in Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service (JRS) 6.0 before 6.0.0-Rational-CLM-ifi…

Mitigation only
Fix from $1,950 2016-01-10
Websphere Commerce HIGH 7.4
CVE-2015-7397

Multiple open redirect vulnerabilities in the Aurora starter store in IBM WebSphere Commerce 7.0 through Feature Pack 8 allow remote attackers to red…

Mitigation only
Fix from $1,950 2016-01-10
Curam Social Program Management MEDIUM 5.4
CVE-2015-5023

SQL injection vulnerability in IBM Curam Social Program Management 6.1 before 6.1.1 allows remote authenticated users to execute arbitrary SQL comman…

Mitigation only
Fix from $1,600 2016-01-03
Change And Configuration Management Database MEDIUM 5.4
CVE-2015-5017

IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX005, and 7.6.0 before 7.6.0.2 IFIX002; Maximo Asset Management 7.5.0 befor…

Mitigation only
Fix from $1,600 2016-01-03
Tivoli Monitoring HIGH 8.5
CVE-2015-5003

The portal in IBM Tivoli Monitoring (ITM) 6.2.2 through FP9, 6.2.3 through FP5, and 6.3.0 before FP7 allows remote authenticated users to execute arb…

Mitigation only
Fix from $1,950 2016-01-03
Qradar Security Information And Event Manager MEDIUM 5.0
CVE-2015-2007

Directory traversal vulnerability in IBM Security QRadar SIEM 7.2.x before 7.2.5 Patch 6 allows remote authenticated users to read arbitrary files vi…

Mitigation only
Fix from $1,600 2016-01-03
Sterling B2b Integrator MEDIUM 5.5
CVE-2015-7437

Queue Watcher in IBM Sterling B2B Integrator 5.2 allows local users to obtain sensitive information via unspecified vectors.

No fix yet
Fix from $1,600 2016-01-02
Sterling B2b Integrator MEDIUM 6.1
CVE-2015-7431

Cross-site scripting (XSS) vulnerability in Queue Watcher in IBM Sterling B2B Integrator 5.2 allows remote attackers to inject arbitrary web script o…

Mitigation only
Fix from $1,600 2016-01-02
Spectrum Protect For Virtual Environments CRITICAL 10.0
CVE-2015-7426

The Data Protection extension in the VMware GUI in IBM Tivoli Storage Manager for Virtual Environments: Data Protection for VMware (aka Spectrum Prot…

Mitigation only
Fix from $2,300 2016-01-02
I Access MEDIUM 5.5
CVE-2015-7422

Buffer overflow in IBM i Access 7.1 on Windows allows local users to cause a denial of service (application crash) via unspecified vectors.

Mitigation only
Fix from $1,600 2016-01-02
Mashups Center HIGH 8.8
CVE-2015-7407

Cross-site request forgery (CSRF) vulnerability in Lotus Mashups in IBM Mashup Center 3.0.0.1 allows remote attackers to hijack the authentication of…

Mitigation only
Fix from $1,950 2016-01-02
Mashups Center HIGH 7.7
CVE-2015-7400

The Lotus Mashups component in IBM Mashup Center 3.0.0.1 allows remote authenticated users to cause a denial of service (CPU consumption) via an XML …

Mitigation only
Fix from $1,950 2016-01-02
Maximo Asset Management MEDIUM 5.4
CVE-2015-7396

The Scheduler in IBM Maximo Asset Management 7.5 before 7.5.0.8 IF6 and 7.6 before 7.6.0.1 FP1 and Maximo Asset Management 7.5 before 7.5.0.8 IF6, 7.…

Mitigation only
Fix from $1,600 2016-01-02
I Access HIGH 8.8
CVE-2015-2023

Buffer overflow in IBM i Access 7.1 on Windows allows local users to gain privileges via unspecified vectors.

No fix yet
Fix from $1,950 2016-01-02
Rational Quality Manager MEDIUM 6.8
CVE-2015-1928

Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.x and 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF11, and…

Mitigation only
Fix from $1,600 2016-01-02
Maximo Asset Management MEDIUM 5.4
CVE-2015-7451

Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5 before 7.5.0.9 IF2 and 7.6 before 7.6.0.3 FP3 and Maximo Asset Management…

Mitigation only
Fix from $1,600 2016-01-02
Spectrum Protect For Virtual Environments HIGH 8.5
CVE-2015-7429

The Data Protection extension in the VMware GUI in IBM Tivoli Storage Manager for Virtual Environments: Data Protection for VMware (aka Spectrum Prot…

Mitigation only
Fix from $1,950 2016-01-02
Curam Social Program Management MEDIUM 5.4
CVE-2015-7402

Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management 6.1 before 6.1.1.1 allows remote authenticated users to inject arbitr…

Mitigation only
Fix from $1,600 2016-01-02
Security Access Manager 9.0 Firmware HIGH 8.0
CVE-2015-5018

IBM Security Access Manager for Web 7.0.0 before FP19 and 8.0 before 8.0.1.3 IF3, and Security Access Manager 9.0 before 9.0.0.0 IF1, allows remote a…

Mitigation only
Fix from $1,950 2016-01-02
Rational Clearquest MEDIUM 5.1
CVE-2015-4996

IBM Rational ClearQuest 7.1.x and 8.0.0.x before 8.0.0.17 and 8.0.1.x before 8.0.1.10 allows local users to spoof database servers and discover crede…

Mitigation only
Fix from $1,600 2016-01-02
Spectrum Scale MEDIUM 6.5
CVE-2015-7456

IBM Spectrum Scale 4.1.1 before 4.1.1.4, and 4.2.0.0, allows remote authenticated users to discover object-storage admin passwords via unspecified ve…

Mitigation only
Fix from $1,600 2016-01-01
Qradar Security Information And Event Manager MEDIUM 5.4
CVE-2015-7409

Cross-site scripting (XSS) vulnerability in IBM Security QRadar SIEM 7.2.x before 7.2.6 allows remote authenticated users to inject arbitrary web scr…

Mitigation only
Fix from $1,600 2016-01-01
Urbancode Deploy MEDIUM 5.4
CVE-2015-7415

Multiple cross-site scripting (XSS) vulnerabilities in IBM UrbanCode Deploy 6.0 before 6.0.1.12, 6.1 before 6.1.3.2, and 6.2 before 6.2.0.2 allow rem…

Mitigation only
Fix from $1,600 2016-01-01
Sterling B2b Integrator HIGH 7.4
CVE-2015-7410

The Health Check tool in IBM Sterling B2B Integrator 5.2 does not properly use cookies in conjunction with HTTPS sessions, which allows man-in-the-mi…

Mitigation only
Fix from $1,950 2016-01-01
Openpages Grc Platform MEDIUM 5.4
CVE-2015-5049

SQL injection vulnerability in the API in IBM OpenPages GRC Platform 7.0 before 7.0.0.4 IF3 and 7.1 before 7.1.0.1 IF6 allows remote authenticated us…

Mitigation only
Fix from $1,600 2016-01-01
Websphere Mq Light MEDIUM 5.3
CVE-2015-4943

IBM WebSphere MQ Light 1.x before 1.0.2 allows remote attackers to cause a denial of service (MQXR service crash) via a series of connect and disconn…

Mitigation only
Fix from $1,600 2016-01-01
Websphere Mq Light MEDIUM 5.3
CVE-2015-4941

IBM WebSphere MQ Light 1.x before 1.0.2 mishandles abbreviated TLS handshakes, which allows remote attackers to cause a denial of service (MQXR servi…

Mitigation only
Fix from $1,600 2016-01-01
Spss Statistics HIGH 7.8
CVE-2015-7489

IBM SPSS Statistics 22.0.0.2 before IF10 and 23.0.0.2 before IF7 uses weak permissions (Everyone: Write) for Python scripts, which allows local users…

Mitigation only
Fix from $1,950 2016-01-01
Business Process Manager MEDIUM 6.8
CVE-2015-7441

Remote Artifact Loader (RAL) in IBM WebSphere Process Server 7 and Business Process Manager Advanced 7.5 through 7.5.1.2, 8.0 through 8.0.1.3, 8.5.0 …

Mitigation only
Fix from $1,600 2016-01-01