Vulnerability index

Browse CVEs

2,232 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Websphere Mq Internet Pass Thru MEDIUM 5.0
CVE-2013-5401

The command-port listener in IBM WebSphere MQ Internet Pass-Thru (MQIPT) 2.x before 2.1.0.1 allows remote attackers to cause a denial of service (rem…

Mitigation only
Fix from $1,600 2014-03-21
Spss Samplepower HIGH 7.5
CVE-2014-0895

Buffer overflow in the vsflex8l ActiveX control in IBM SPSS SamplePower 3.0.1 before FP1 3.0.1-IM-S3SAMPC-WIN32-FP001-IF02 allows remote attackers to…

Mitigation only
Fix from $1,950 2014-03-16
Infosphere Master Data Management Server MEDIUM 6.8
CVE-2014-0873

Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) Data Stewardship, (2) Business Admin, and (3) Product interfaces in IBM InfoSph…

Mitigation only
Fix from $1,600 2014-03-16
Infosphere Information Server MEDIUM 6.8
CVE-2013-4057

Cross-site request forgery (CSRF) vulnerability in the XML Pack in IBM InfoSphere Information Server 8.5.x through 8.5 FP3, 8.7.x through 8.7 FP2, an…

Mitigation only
Fix from $1,600 2014-03-16
Infosphere Information Server MEDIUM 6.5
CVE-2013-4058

Multiple SQL injection vulnerabilities in IBM InfoSphere Information Server 8.x through 8.5 FP3, 8.7.x through 8.7 FP2, and 9.1.x through 9.1.2.0 all…

Mitigation only
Fix from $1,600 2014-03-16
Aix MEDIUM 6.5
CVE-2014-0899

ftpd in IBM AIX 7.1.1 before SP10 and 7.1.2 before SP5, when a Workload Partition (aka WPAR) for AIX 5.2 or 5.3 is used, allows remote authenticated …

Mitigation only
Fix from $1,600 2014-03-11
Tealeaf Cx MEDIUM 6.0
CVE-2013-6719EPSS 27%

delivery.php in the Passive Capture Application (PCA) web console in IBM Tealeaf CX 7.x, 8.x through 8.6, 8.7 before FP2, and 8.8 before FP2 allows r…

No fix yet
Fix from $1,600 2014-03-06
Tealeaf Cx MEDIUM 5.5
CVE-2013-6720EPSS 29%

Directory traversal vulnerability in download.php in the Passive Capture Application (PCA) web console in IBM Tealeaf CX 7.x, 8.x through 8.6, 8.7 be…

No fix yet
Fix from $1,600 2014-03-06
Algo One MEDIUM 6.5
CVE-2013-6302

SQL injection vulnerability in IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Security Access Control …

Mitigation only
Fix from $1,600 2014-03-05
Algo One MEDIUM 6.5
CVE-2013-6331

SQL injection vulnerability in IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Security Access Control …

Mitigation only
Fix from $1,600 2014-03-05
Algo One MEDIUM 5.0
CVE-2013-5468

IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Security Access Control Management 4.7.0 through 4.9.0,…

Mitigation only
Fix from $1,600 2014-03-05
Rational Collaborative Lifecycle Management HIGH 10.0
CVE-2014-0862

Unspecified vulnerability in Jazz Team Server in IBM Rational Collaborative Lifecycle Management (CLM) 3.x before 3.0.1.6 iFix 2 and 4.x before 4.0.6…

Mitigation only
Fix from $1,950 2014-03-02
Cognos Business Intelligence MEDIUM 5.0
CVE-2014-0854

The server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1 before IF6, 10.1.1 before IF5, 10.2 before IF7, 10.2.1 before IF4, and 10.2.1.1 befor…

Mitigation only
Fix from $1,600 2014-02-22
Sametime HIGH 7.5
CVE-2013-3983

The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 does not validate URLs in Cookie headers before using them in redire…

Mitigation only
Fix from $1,950 2014-02-14
Sametime HIGH 7.5
CVE-2013-6742

The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 do not have an off autocomplete attribute for a password field, whic…

Mitigation only
Fix from $1,950 2014-02-14
Sametime MEDIUM 6.8
CVE-2013-3988

The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to conduct clickjacking attacks via unspecif…

Mitigation only
Fix from $1,600 2014-02-14
Sametime MEDIUM 5.0
CVE-2013-3978

The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 does not send the appropriate HTTP response headers to prevent unwan…

Mitigation only
Fix from $1,600 2014-02-14
Platform Symphony HIGH 10.0
CVE-2013-5400

An unspecified servlet in IBM Platform Symphony Developer Edition (DE) 5.2 and 6.1.x through 6.1.1 has hardcoded credentials, which allows remote att…

Mitigation only
Fix from $1,950 2014-02-14
Websphere Portal MEDIUM 5.8
CVE-2013-6722

Unrestricted file upload vulnerability in the Registration/Edit My Profile portlet in IBM WebSphere Portal 7.x before 7.0.0.2 CF27 and 8.x through 8.…

Mitigation only
Fix from $1,600 2014-02-14
Websphere Dashboard Framework MEDIUM 5.8
CVE-2013-6728

The charting component in IBM WebSphere Dashboard Framework (WDF) 6.1.5 and 7.0.1 allows remote attackers to view or delete image files by leveraging…

Mitigation only
Fix from $1,600 2014-02-14
Lotus Domino HIGH 7.8
CVE-2014-0822

The IMAP server in IBM Domino 8.5.x before 8.5.3 FP6 IF1 and 9.0.x before 9.0.1 FP1 allows remote attackers to cause a denial of service (daemon cras…

Mitigation only
Fix from $1,950 2014-02-06
Algo One HIGH 8.5
CVE-2013-6332

Unrestricted file upload vulnerability in IBM Algo One UDS 4.7.0 through 5.0.0 allows remote authenticated users to execute arbitrary code by uploadi…

Mitigation only
Fix from $1,950 2014-02-06
Infosphere Master Data Management Collaboration Server MEDIUM 6.8
CVE-2013-5427

Cross-site request forgery (CSRF) vulnerability in IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1 FP8 through 11.0 an…

Mitigation only
Fix from $1,600 2014-02-04
Spss Samplepower HIGH 9.3
CVE-2013-6724

Unspecified vulnerability in the vsflex8l ActiveX control in IBM SPSS SamplePower 3.0.1 before FP1 IF1 allows remote attackers to execute arbitrary c…

Mitigation only
Fix from $1,950 2014-02-01
Financial Transaction Manager MEDIUM 6.8
CVE-2014-0831

Cross-site request forgery (CSRF) vulnerability in the OAC component in IBM Financial Transaction Manager (FTM) 2.0 before 2.0.0.3 allows remote atta…

Mitigation only
Fix from $1,600 2014-02-01
Financial Transaction Manager MEDIUM 5.5
CVE-2014-0833

The OAC component in IBM Financial Transaction Manager (FTM) 2.0 before 2.0.0.3 does not properly enforce operator-intervention requirements, which a…

Mitigation only
Fix from $1,600 2014-02-01
Spss Collaboration And Deployment Services MEDIUM 5.0
CVE-2013-4043

The server in IBM SPSS Collaboration and Deployment Services 4.x before 4.2.1.3 IF3, 5.x before 5.0 FP3, and 6.x before 6.0 IF1 allows remote attacke…

Mitigation only
Fix from $1,600 2014-02-01
Sametime MEDIUM 5.0
CVE-2013-6727

The Connect client in IBM Sametime 8.5.2 through 8.5.2.1 and 9.0 before HF1 does not properly restrict unsigned Java plugins, which allows remote att…

Mitigation only
Fix from $1,600 2014-01-31
Tivoli Application Dependency Discovery Manager HIGH 7.5
CVE-2013-2974

The BIRT viewer in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.1.x before 7.2.1.5 allows remote authenticated users to bypass aut…

Mitigation only
Fix from $1,950 2014-01-29
Lotus Quickr For Domino HIGH 7.5
CVE-2013-6748

Buffer overflow in the ActiveX control in qp2.cab in IBM Lotus Quickr for Domino 8.5.1 before 8.5.1.42-001b allows remote attackers to execute arbitr…

Mitigation only
Fix from $1,950 2014-01-29