Vulnerability index

Browse CVEs

2,232 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Sterling Multi Channel Fulfillment Solution MEDIUM 5.5
CVE-2013-0505

IBM Sterling Order Management 8.0 before HF127, 8.5 before HF89, 9.0 before HF69, 9.1.0 before FP41, and 9.2.0 before FP13 allows remote authenticate…

Mitigation only
Fix from $1,600 2013-03-19
Cognos Business Intelligence HIGH 9.3
CVE-2012-4858

IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 does not properly validate Java seria…

Mitigation only
Fix from $1,950 2013-03-05
Cognos Business Intelligence MEDIUM 5.0
CVE-2012-4840

IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 allows remote attackers to conduct XP…

Mitigation only
Fix from $1,600 2013-03-05
Infosphere Guardium HIGH 7.2
CVE-2013-0490

Unspecified vulnerability in IBM InfoSphere Guardium S-TAP 8.1 for DB2 on z/OS allows local users to gain privileges via unknown vectors.

No fix yet
Fix from $1,950 2013-02-27
Lotus Domino MEDIUM 5.8
CVE-2012-4842

Open redirect vulnerability in the web server in IBM Lotus Domino 8.5.x through 8.5.3 allows remote attackers to redirect users to arbitrary web site…

Mitigation only
Fix from $1,600 2013-02-27
Ts3500 Tape Library Firmware MEDIUM 6.5
CVE-2012-5767

Unspecified vulnerability in the web interface on the IBM TS3500 Tape Library with firmware before C260 allows remote authenticated users to gain pri…

Mitigation only
Fix from $1,600 2013-02-27
Infosphere Master Data Management Collaboration Server MEDIUM 6.0
CVE-2013-0477

Multiple cross-site scripting (XSS) vulnerabilities in IBM InfoSphere Master Data Management - Collaborative Edition 10.0 and 10.1 before FP1 and Inf…

Mitigation only
Fix from $1,600 2013-02-21
Netezza MEDIUM 6.8
CVE-2012-5763

Cross-site request forgery (CSRF) vulnerability in the WebAdmin application 6.0.5, 6.0.8, and 7.0 before P2 in IBM Netezza allows remote attackers to…

Mitigation only
Fix from $1,600 2013-02-20
Netezza MEDIUM 6.5
CVE-2012-5760

SQL injection vulnerability in the WebAdmin application 6.0.5, 6.0.8, and 7.0 before P2 in IBM Netezza allows remote authenticated users to execute a…

Mitigation only
Fix from $1,600 2013-02-20
Maximo Asset Management MEDIUM 6.5
CVE-2012-6355

IBM Maximo Asset Management 6.2 through 7.5, Maximo Asset Management Essentials 6.2 through 7.5, Tivoli Asset Management for IT 6.2 through 7.2, Tivo…

Mitigation only
Fix from $1,600 2013-02-20
Maximo Asset Management MEDIUM 6.5
CVE-2012-6356

IBM Maximo Asset Management 7.5, Maximo Asset Management Essentials 7.5, and SmartCloud Control Desk 7.5 allow remote authenticated users to gain pri…

Mitigation only
Fix from $1,600 2013-02-20
Maximo Asset Management MEDIUM 6.5
CVE-2012-6357

IBM Maximo Asset Management 7.5, Maximo Asset Management Essentials 7.5, and SmartCloud Control Desk 7.5 allow remote authenticated users to gain pri…

Mitigation only
Fix from $1,600 2013-02-20
Websphere Message Broker MEDIUM 5.0
CVE-2012-5952

IBM WebSphere Message Broker 6.1 before 6.1.0.12, 7.0 before 7.0.0.6, and 8.0 before 8.0.0.2 does not validate Basic Authentication credentials befor…

Mitigation only
Fix from $1,600 2013-02-20
Smartcloud Control Desk MEDIUM 6.5
CVE-2012-3321

IBM SmartCloud Control Desk 7.5 allows remote authenticated users to bypass intended access restrictions via vectors involving an expired password.

Mitigation only
Fix from $1,600 2013-02-20
San Volume Controller Software HIGH 7.5
CVE-2012-6354

The management GUI on the IBM SAN Volume Controller and Storwize V7000 6.x before 6.4.1.3 allows remote attackers to bypass authentication and obtain…

Mitigation only
Fix from $1,950 2013-02-19
Sterling Connect MEDIUM 5.0
CVE-2012-6352

The Session Manager in IBM Sterling Connect:Direct through 4.1.0.3 on UNIX allows remote attackers to cause a denial of service (daemon crash and dis…

Mitigation only
Fix from $1,600 2013-02-02
Infosphere Import Export Manager HIGH 9.3
CVE-2012-0204

Untrusted search path vulnerability in InfoSphere Import Export Manager 8.1 through 9.1 in InfoSphere Information Server MetaBrokers & Bridges (MBB) …

Mitigation only
Fix from $1,950 2013-01-31
Infosphere Information Server HIGH 7.1
CVE-2012-0705

InfoSphere Import Export Manager in InfoSphere Information Server MetaBrokers & Bridges (MBB) in IBM InfoSphere Information Server 8.1, 8.5 before FP…

Mitigation only
Fix from $1,950 2013-01-31
Infosphere Information Server MEDIUM 6.5
CVE-2012-0205

InfoSphere Metadata Workbench (MWB) 8.1 through 8.7 in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 does not properly restrict use …

Mitigation only
Fix from $1,600 2013-01-31
Infosphere Datastage MEDIUM 6.5
CVE-2012-0701

The client applications in the DataStage Administrator client in InfoSphere DataStage in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8…

Mitigation only
Fix from $1,600 2013-01-31
Infosphere Information Server MEDIUM 5.8
CVE-2012-0703

Open redirect vulnerability in Information Services Framework (ISF) in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 allows remote a…

Mitigation only
Fix from $1,600 2013-01-31
Websphere Application Server HIGH 10.0
CVE-2013-0462

Unspecified vulnerability in IBM WebSphere Application Server (WAS) 6.1, 7.0 before 7.0.0.27, 8.0, and 8.5 has unknown impact and attack vectors.

Mitigation only
Fix from $1,950 2013-01-27
Websphere Application Server MEDIUM 6.8
CVE-2013-0460

Cross-site request forgery (CSRF) vulnerability in the portlet subsystem in the administrative console in IBM WebSphere Application Server (WAS) 6.1 …

Mitigation only
Fix from $1,600 2013-01-27
Spss Modeler MEDIUM 5.8
CVE-2012-5769

IBM SPSS Modeler 14.0, 14.1, 14.2 through FP3, and 15.0 before FP2 allows remote attackers to read arbitrary files, and possibly send HTTP requests t…

Mitigation only
Fix from $1,600 2013-01-01
Rational Automation Framework HIGH 7.5
CVE-2012-4816

IBM Rational Automation Framework (RAF) 3.x through 3.0.0.5 allows remote attackers to bypass intended Env Gen Wizard (aka Environment Generation Wiz…

Mitigation only
Fix from $1,950 2012-12-26
Tivoli Netview HIGH 7.2
CVE-2012-5951

Unspecified vulnerability in IBM Tivoli NetView 1.4, 5.1 through 5.4, and 6.1 on z/OS allows local users to gain privileges by leveraging access to t…

Mitigation only
Fix from $1,950 2012-12-26
HTTP Server HIGH 10.0
CVE-2012-5955

Unspecified vulnerability in the IBM HTTP Server component 5.3 in IBM WebSphere Application Server (WAS) for z/OS allows remote attackers to execute …

Mitigation only
Fix from $1,950 2012-12-20
Rational Clearquest MEDIUM 5.0
CVE-2012-5765

The Web Client (aka CQ Web) in IBM Rational ClearQuest 7.1.2.x before 7.1.2.9 and 8.0.0.x before 8.0.0.5 allows remote attackers to obtain sensitive …

Mitigation only
Fix from $1,600 2012-12-20
Power 5 System Firmware HIGH 7.9
CVE-2012-4856

The Service Processor in the IBM Power 5 91##-### and 940#-### before SF240_418_382 does not ensure that firewall code is executed, which allows remo…

Mitigation only
Fix from $1,950 2012-12-20
Informix Dynamic Server HIGH 9.0
CVE-2012-4857

Buffer overflow in IBM Informix 11.50 through 11.50.xC9W2 and 11.70 before 11.70.xC7 allows remote authenticated users to execute arbitrary code via …

Mitigation only
Fix from $1,950 2012-12-08