Vulnerability index

Browse CVEs

2,232 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Websphere Message Broker MEDIUM 6.9
CVE-2012-3317

IBM WebSphere Message Broker 6.1 before 6.1.0.11, 7.0 before 7.0.0.5, and 8.0 before 8.0.0.2 has incorrect ownership of certain uninstaller Java Runt…

Mitigation only
Fix from $1,600 2012-12-05
Websphere Datapower Xc10 Appliance HIGH 9.0
CVE-2012-5759

The IBM WebSphere DataPower XC10 Appliance 2.0.0.0 through 2.0.0.3 and 2.1.0.0 through 2.1.0.2 allows remote authenticated users to bypass intended a…

Mitigation only
Fix from $1,950 2012-11-23
Websphere Datapower Xc10 Appliance HIGH 7.8
CVE-2012-5758

The IBM WebSphere DataPower XC10 Appliance 2.0.0.0 through 2.0.0.3 and 2.1.0.0 through 2.1.0.2 does not require authentication for an unspecified int…

Mitigation only
Fix from $1,950 2012-11-23
Websphere Application Server HIGH 7.5
CVE-2012-4850

IBM WebSphere Application Server 8.5 Liberty Profile before 8.5.0.1, when JAX-RS is used, does not properly validate requests, which allows remote at…

Mitigation only
Fix from $1,950 2012-11-14
Websphere Application Server MEDIUM 6.8
CVE-2012-4853

Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Application Server 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and…

Mitigation only
Fix from $1,600 2012-11-14
Websphere Application Server MEDIUM 5.0
CVE-2012-3330

The proxy server in IBM WebSphere Application Server 7.0 before 7.0.0.27, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1, and WebSphere Virtual Enterpris…

Mitigation only
Fix from $1,600 2012-11-14
Db2 HIGH 8.5
CVE-2012-4826

Stack-based buffer overflow in the SQL/PSM (aka SQL Persistent Stored Module) Stored Procedure (SP) infrastructure in IBM DB2 9.1, 9.5, 9.7 before FP…

Mitigation only
Fix from $1,950 2012-10-20
Vios MEDIUM 6.8
CVE-2012-4845

The FTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly manage privileges in an RBAC environment, which allows attacke…

Mitigation only
Fix from $1,600 2012-10-20
Lotus Notes Traveler MEDIUM 6.8
CVE-2012-5308

Cross-site request forgery (CSRF) vulnerability in servlet/traveler in IBM Lotus Notes Traveler through 8.5.3.3 Interim Fix 1 allows remote attackers…

No fix yet
Fix from $1,600 2012-10-08
Lotus Notes Traveler MEDIUM 6.8
CVE-2012-5309

servlet/traveler in IBM Lotus Notes Traveler through 8.5.3.3 Interim Fix 1 does not properly restrict invalid authentication attempts, which makes it…

No fix yet
Fix from $1,600 2012-10-08
Lotus Notes Traveler MEDIUM 5.8
CVE-2012-4824

Open redirect vulnerability in servlet/traveler in IBM Lotus Notes Traveler 8.5.3 before 8.5.3.3 Interim Fix 1 allows remote attackers to redirect us…

No fix yet
Fix from $1,600 2012-10-08
Websphere Commerce MEDIUM 5.0
CVE-2012-4830

Unspecified vulnerability in IBM WebSphere Commerce 6.0 through 6.0.0.11 and 7.0 through 7.0.0.6 allows remote attackers to obtain users' personal da…

No fix yet
Fix from $1,600 2012-10-01
Rational Team Concert MEDIUM 6.8
CVE-2012-0748

Multiple cross-site request forgery (CSRF) vulnerabilities in unspecified services in IBM Rational Team Concert (RTC) 4.x before 4.0.0.1 allow remote…

Mitigation only
Fix from $1,600 2012-10-01
Db2 HIGH 9.0
CVE-2012-3324

Directory traversal vulnerability in the UTL_FILE module in IBM DB2 and DB2 Connect 10.1 before FP1 on Windows allows remote authenticated users to m…

Mitigation only
Fix from $1,950 2012-09-25
Informix Dynamic Server HIGH 9.0
CVE-2012-3334

Stack-based buffer overflow in IBM Informix Dynamic Server (IDS) 11.50 before 11.50.xC9W2 and 11.70 before 11.70.xC5 allows remote authenticated user…

Mitigation only
Fix from $1,950 2012-09-25
Websphere Application Server MEDIUM 6.8
CVE-2012-3304

The Administrative Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5…

Mitigation only
Fix from $1,600 2012-09-25
Websphere Application Server MEDIUM 6.8
CVE-2012-3306

IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1, when multi-domain suppor…

Mitigation only
Fix from $1,600 2012-09-25
Websphere Application Server MEDIUM 6.4
CVE-2012-3305

Directory traversal vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 bef…

Mitigation only
Fix from $1,600 2012-09-25
Websphere Commerce HIGH 10.0
CVE-2012-3298

Unspecified vulnerability in the REST services framework in IBM WebSphere Commerce 7.0 Feature Pack 4 allows remote attackers to obtain sensitive inf…

Mitigation only
Fix from $1,950 2012-09-25
Websphere Mq MEDIUM 5.0
CVE-2012-2199

The server message channel agent in the queue manager in the server in IBM WebSphere MQ 7.0.1 before 7.0.1.9, 7.1, and 7.5 on Solaris allows remote a…

Mitigation only
Fix from $1,600 2012-09-25
Vios MEDIUM 5.0
CVE-2012-4817EPSS 8%

The NFSv4 client implementation in IBM AIX 5.3, 6.1, and 7.1, and VIOS before 2.2.1.4-FP-25 SP-02, does not properly handle GID values, which allows …

Mitigation only
Fix from $1,600 2012-09-14
Change And Configuration Management Database MEDIUM 6.8
CVE-2012-2183

Session fixation vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Ti…

Mitigation only
Fix from $1,600 2012-09-10
Change And Configuration Management Database MEDIUM 6.8
CVE-2012-2184

Session fixation vulnerability in IBM Maximo Asset Management 7.1 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Ti…

Mitigation only
Fix from $1,600 2012-09-10
Change And Configuration Management Database MEDIUM 6.5
CVE-2012-0727

SQL injection vulnerability in IBM Maximo Asset Management 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Re…

Mitigation only
Fix from $1,600 2012-09-10
Change And Configuration Management Database MEDIUM 6.5
CVE-2012-0728

SQL injection vulnerability in IBM Maximo Asset Management 7.1 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivol…

Mitigation only
Fix from $1,600 2012-09-10
Change And Configuration Management Database MEDIUM 6.5
CVE-2012-0747

SQL injection vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivol…

Mitigation only
Fix from $1,600 2012-09-10
Change And Configuration Management Database MEDIUM 6.8
CVE-2012-0714

Cross-site request forgery (CSRF) vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Mana…

Mitigation only
Fix from $1,600 2012-09-10
Lotus Notes MEDIUM 6.9
CVE-2010-5251

Multiple untrusted search path vulnerabilities in IBM Lotus Notes 8.5 allow local users to gain privileges via a Trojan horse (1) nnoteswc.dll or (2)…

Mitigation only
Fix from $1,600 2012-09-07
Lotus Symphony MEDIUM 6.9
CVE-2010-5204

Multiple untrusted search path vulnerabilities in IBM Lotus Symphony 1.3.0 20090908.0900 allow local users to gain privileges via a Trojan horse (1) …

Mitigation only
Fix from $1,600 2012-09-06
Websphere Application Server MEDIUM 6.0
CVE-2012-3325

IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.45, 7.0.x before 7.0.0.25, 8.0.x before 8.0.0.5, and 8.5.x Full Profile before 8.5.0.1, whe…

Mitigation only
Fix from $1,600 2012-08-30