Vulnerability index

Browse CVEs

2,232 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Websphere Application Server MEDIUM 5.0
CVE-2012-2190

IBM Global Security Kit (aka GSKit), as used in IBM HTTP Server in IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.45, 7.0.x before 7.0.0.2…

Mitigation only
Fix from $1,600 2012-08-21
Rational Clearquest MEDIUM 5.5
CVE-2012-2164

The Web client in IBM Rational ClearQuest 7.1.x before 7.1.2.7 and 8.x before 8.0.0.3 allows remote authenticated users to bypass intended access res…

Mitigation only
Fix from $1,600 2012-08-17
Rational Clearquest MEDIUM 5.0
CVE-2012-0744EPSS 8%

IBM Rational ClearQuest 7.1.x through 7.1.2.7 and 8.x through 8.0.0.3 allows remote attackers to obtain potentially sensitive information via a reque…

Mitigation only
Fix from $1,600 2012-08-17
Power Hardware Management Console Firmware HIGH 7.2
CVE-2012-2188

IBM Power Hardware Management Console (HMC) 7R3.5.0 before SP4, 7R7.1.0 and 7R7.2.0 before 7R7.2.0 SP3, and 7R7.3.0 before SP2, and Systems Director …

Mitigation only
Fix from $1,950 2012-08-06
Scale Out Network Attached Storage HIGH 9.0
CVE-2012-2163

IBM Scale Out Network Attached Storage (SONAS) 1.1 through 1.3.1 allows remote authenticated administrators to execute arbitrary Linux commands via t…

Mitigation only
Fix from $1,950 2012-07-30
Db2 HIGH 7.1
CVE-2012-2197

Stack-based buffer overflow in the Java Stored Procedure infrastructure in IBM DB2 9.1 before FP12, 9.5 through FP9, 9.7 through FP6, 9.8 through FP5…

Mitigation only
Fix from $1,950 2012-07-25
Db2 MEDIUM 5.0
CVE-2012-2194

Directory traversal vulnerability in the SQLJ.DB2_INSTALL_JAR stored procedure in IBM DB2 9.1 before FP12, 9.5 through FP9, 9.7 through FP6, 9.8 thro…

Mitigation only
Fix from $1,600 2012-07-25
Db2 MEDIUM 5.0
CVE-2012-2196

IBM DB2 9.1 before FP12, 9.5 through FP9, 9.7 through FP6, 9.8 through FP5, and 10.1 allows remote attackers to read arbitrary XML files via the (1) …

Mitigation only
Fix from $1,600 2012-07-25
Websphere Portal MEDIUM 5.0
CVE-2012-2181

Directory traversal vulnerability in the Dojo module in IBM WebSphere Portal 7.0.0.1 and 7.0.0.2 before CF14, and 8.0, allows remote attackers to rea…

Mitigation only
Fix from $1,600 2012-07-03
Vios HIGH 7.2
CVE-2012-2200

The default configuration of sendmail in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, allows local users to gain privileges by entering a comma…

Mitigation only
Fix from $1,950 2012-06-27
Lotus Expeditor HIGH 9.3
CVE-2012-0187

Untrusted search path vulnerability in IBM Lotus Expeditor 6.1.x and 6.2.x before 6.2 FP5+Security Pack allows local users to gain privileges via a T…

Mitigation only
Fix from $1,950 2012-06-22
Lotus Expeditor MEDIUM 5.0
CVE-2012-0191

The web container in IBM Lotus Expeditor 6.1.x and 6.2.x before 6.2 FP5+Security Pack does not properly perform access control for requests, which al…

Mitigation only
Fix from $1,600 2012-06-22
Lotus Notes HIGH 9.3
CVE-2012-2174EPSS 38%

The URL handler in IBM Lotus Notes 8.x before 8.5.3 FP2 allows remote attackers to execute arbitrary code via a crafted notes:// URL.

Mitigation only
Fix from $1,950 2012-06-20
Lotus Inotes HIGH 9.3
CVE-2012-2175EPSS 29%

Buffer overflow in the Attachment_Times method in a certain ActiveX control in dwa85W.dll in IBM Lotus iNotes 8.5.x before 8.5.3 FP2 allows remote at…

Mitigation only
Fix from $1,950 2012-06-20
Security Appscan Source MEDIUM 5.8
CVE-2012-2159

Open redirect vulnerability in IBM Eclipse Help System (IEHS), as used in IBM Security AppScan Source 7.x and 8.x before 8.6 and IBM SPSS Data Collec…

Mitigation only
Fix from $1,600 2012-06-20
Security Appscan Source MEDIUM 5.0
CVE-2012-2173

The ODBC driver in IBM Security AppScan Source 7.x and 8.x before 8.6 sends an SHA-1 hash of the connection password during connections to a solidDB …

Mitigation only
Fix from $1,600 2012-06-20
Lotus Quickr HIGH 9.3
CVE-2012-2176EPSS 31%

Multiple stack-based buffer overflows in a certain ActiveX control in qp2.cab in IBM Lotus Quickr 8.2 before 8.2.0.27-002a for Domino allow remote at…

Mitigation only
Fix from $1,950 2012-05-25
Rational Clearquest HIGH 7.5
CVE-2011-1390

SQL injection vulnerability in the Maintenance tool in IBM Rational ClearQuest 7.1.1.x before 7.1.1.9, 7.1.2.x before 7.1.2.6, and 8.x before 8.0.0.2…

Mitigation only
Fix from $1,950 2012-05-14
Cognos Tm1 HIGH 10.0
CVE-2012-0202EPSS 55%

Multiple stack-based buffer overflows in tm1admsd.exe in the Admin Server in IBM Cognos TM1 9.4.x and 9.5.x before 9.5.2 FP2 allow remote attackers t…

Mitigation only
Fix from $1,950 2012-05-04
Aix HIGH 7.2
CVE-2012-0745

The getpwnam function in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.1.0.10 through 2.2.1.3 does not properly interact with customer-extended LDAP user filt…

Mitigation only
Fix from $1,950 2012-05-04
Rational Appscan HIGH 9.3
CVE-2012-0736

IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 does not properly create scan jobs, which allows remote attackers to execute arbitrary cod…

Mitigation only
Fix from $1,950 2012-05-03
Rational Appscan HIGH 7.6
CVE-2012-0735

IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 does not properly scan file: URLs, which allows man-in-the-middle attackers to obtain sens…

Mitigation only
Fix from $1,950 2012-05-03
Rational Appscan HIGH 7.6
CVE-2012-0734

IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 does not properly import jobs, which allows man-in-the-middle attackers to obtain sensitiv…

Mitigation only
Fix from $1,950 2012-05-03
Rational Appscan MEDIUM 6.8
CVE-2012-0731

IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 does not prevent service-account impersonation, which allows remote authenticated users to…

Mitigation only
Fix from $1,600 2012-05-03
Rational Appscan MEDIUM 6.0
CVE-2012-0729

Unrestricted file upload vulnerability in IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 allows remote authenticated users to execute arb…

Mitigation only
Fix from $1,600 2012-05-03
Rational Appscan MEDIUM 6.0
CVE-2012-0730

Multiple cross-site request forgery (CSRF) vulnerabilities in IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 allow remote attackers to hi…

Mitigation only
Fix from $1,600 2012-05-03
Rational Appscan MEDIUM 6.0
CVE-2012-0733

IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1, when Integrated Windows authentication is used, allows remote authenticated users to obta…

Mitigation only
Fix from $1,600 2012-05-03
Rational Appscan MEDIUM 5.8
CVE-2012-0732

The Enterprise Console client in IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 does not verify X.509 certificates from SSL servers, whic…

Mitigation only
Fix from $1,600 2012-05-03
Rational Clearquest HIGH 9.3
CVE-2012-0708EPSS 31%

Heap-based buffer overflow in the Ole API in the CQOle ActiveX control in cqole.dll in IBM Rational ClearQuest 7.1.1 before 7.1.1.9, 7.1.2 before 7.1…

Mitigation only
Fix from $1,950 2012-04-22
Db2 HIGH 10.0
CVE-2012-1797

IBM DB2 9.5 uses world-writable permissions for nodes.reg, which has unspecified impact and attack vectors.

Mitigation only
Fix from $1,950 2012-03-20