Vulnerability index

Browse CVEs

2,232 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Db2 HIGH 10.0
CVE-2009-3473

IBM DB2 9.1 before FP8 does not require the SETSESSIONUSER privilege for the SET SESSION AUTHORIZATION statement, which has unspecified impact and re…

Mitigation only
Fix from $1,950 2009-09-29
Db2 HIGH 7.5
CVE-2009-3471

IBM DB2 8 before FP18, 9.1 before FP8, 9.5 before FP4, and 9.7 before FP2 does not perform the expected drops of certain table functions upon a loss …

Mitigation only
Fix from $1,950 2009-09-29
Db2 MEDIUM 6.5
CVE-2009-3472

IBM DB2 8 before FP18, 9.1 before FP8, and 9.5 before FP4 allows remote authenticated users to bypass intended access restrictions, and update, inser…

Mitigation only
Fix from $1,600 2009-09-29
Informix Dynamic Server MEDIUM 5.0
CVE-2009-3470

IBM Informix Dynamic Server (IDS) 10.00 before 10.00.xC11, 11.10 before 11.10.xC4, and 11.50 before 11.50.xC5 allows remote attackers to cause a deni…

Mitigation only
Fix from $1,600 2009-09-29
Websphere Business Events HIGH 10.0
CVE-2009-2741

Unspecified vulnerability in the wberuntimeear application in the test servlet in IBM WebSphere Business Events 6.1 and 6.2 allows remote attackers t…

Mitigation only
Fix from $1,950 2009-09-18
Lotus Notes HIGH 7.5
CVE-2009-3114

The RSS reader widget in IBM Lotus Notes 8.0 and 8.5 saves items from an RSS feed as local HTML documents, which allows remote attackers to execute a…

Mitigation only
Fix from $1,950 2009-09-09
Tivoli Directory Server HIGH 7.8
CVE-2009-3089

IBM Tivoli Directory Server (TDS) 6.0 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via unspecifie…

No fix yet
Fix from $1,950 2009-09-08
Tivoli Directory Server HIGH 7.5
CVE-2009-3088

Heap-based buffer overflow in ibmdiradm in IBM Tivoli Directory Server (TDS) 6.0 on Linux allows remote attackers to have an unspecified impact via u…

No fix yet
Fix from $1,950 2009-09-08
Lotus Domino MEDIUM 5.0
CVE-2009-3087

Unspecified vulnerability in nserver.exe in the server in IBM Lotus Domino 8.0 on Windows Server 2003 allows remote attackers to cause a denial of se…

No fix yet
Fix from $1,600 2009-09-08
Tivoli Directory Server MEDIUM 5.0
CVE-2009-3090

Unspecified vulnerability in IBM Tivoli Directory Server (TDS) 6.0 on Linux allows remote attackers to cause a denial of service via unknown vectors,…

No fix yet
Fix from $1,600 2009-09-08
Websphere Commerce Suite MEDIUM 5.0
CVE-2009-2956

The (1) Net.Commerce and (2) Net.Data components in IBM WebSphere Commerce Suite store sensitive information under the web root with insufficient acc…

Mitigation only
Fix from $1,600 2009-08-24
Tklm HIGH 10.0
CVE-2009-2667

Unspecified vulnerability in IBM Tivoli Key Lifecycle Manager (TKLM) 1.0 has unknown impact and attack vectors, related to a "password security vulne…

Mitigation only
Fix from $1,950 2009-08-05
Proventia Desktop Endpoint Security HIGH 10.0
CVE-2009-2543

Multiple unspecified vulnerabilities in the IBM Proventia engine 4.9.0.0.44 20081231, as used in IBM Proventia Network Mail Security System, Network …

Mitigation only
Fix from $1,950 2009-07-20
Lotus Instant Messaging And Web Conferencing MEDIUM 5.0
CVE-2009-2435

The Sametime server in IBM Lotus Instant Messaging and Web Conferencing 6.5.1 generates error messages for a failed logon attempt with different time…

Mitigation only
Fix from $1,600 2009-07-13
Websphere Application Server MEDIUM 6.4
CVE-2009-0904

The IBM Stax XMLStreamWriter in the Web Services component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 does not properly process XM…

Mitigation only
Fix from $1,600 2009-07-05
Tivoli Storage Manager Client HIGH 10.0
CVE-2009-1520

Buffer overflow in the Web GUI in the IBM Tivoli Storage Manager (TSM) client 5.1.0.0 through 5.1.8.2, 5.2.0.0 through 5.2.5.3, 5.3.0.0 through 5.3.6…

Mitigation only
Fix from $1,950 2009-05-05
Advanced Management Module MEDIUM 6.8
CVE-2009-1290

Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration interface in the Advanced Management Module (AMM) on the IBM Bla…

No fix yet
Fix from $1,600 2009-04-13
Proventia Desktop Endpoint Security HIGH 10.0
CVE-2009-1240

Unspecified vulnerability in the IBM Proventia engine 4.9.0.0.44 20081231, as used in IBM Proventia Network Mail Security System, Network Mail Securi…

Mitigation only
Fix from $1,950 2009-04-03
Access Support Activex Control HIGH 9.3
CVE-2009-0215EPSS 36%

Stack-based buffer overflow in the GetXMLValue method in the IBM Access Support ActiveX control in IbmEgath.dll, as distributed on IBM and Lenovo com…

Mitigation only
Fix from $1,950 2009-03-25
Workplace For Business Controls And Reporting MEDIUM 6.8
CVE-2008-6106

Cross-site request forgery (CSRF) vulnerability in IBM Workplace for Business Controls and Reporting 2.x and IBM Workplace Web Content Management 6.x…

No fix yet
Fix from $1,600 2009-02-10
Websphere Application Server HIGH 7.8
CVE-2009-0391

Unspecified vulnerability in IBM WebSphere Application Server (WAS) 6.0.1 on z/OS allows attackers to read arbitrary files via unknown vectors.

No fix yet
Fix from $1,950 2009-02-02
Hardware Management Console HIGH 10.0
CVE-2009-0178

Unspecified vulnerability in IBM Hardware Management Console (HMC) 7 release 3.2.0 SP1 has unknown impact and attack vectors.

No fix yet
Fix from $1,950 2009-01-20
Websphere Datapower Xml Security Gateway Xs40 HIGH 7.8
CVE-2009-0120

The IBM WebSphere DataPower XML Security Gateway XS40 with firmware 3.6.1.5 allows remote attackers to cause a denial of service (device reboot) by s…

No fix yet
Fix from $1,950 2009-01-15
Rational Clearquest MEDIUM 6.5
CVE-2008-5327

The ClearQuest Maintenance Tool in IBM Rational ClearQuest 7 before 7.1 stores the database password in cleartext in an object in a ClearQuest connec…

Mitigation only
Fix from $1,600 2008-12-05
Hardware Management Console MEDIUM 5.0
CVE-2008-5035

The Resource Monitoring and Control (RMC) daemon in IBM Hardware Management Console (HMC) 7 release 3.2.0 SP1 and 3.3.0 SP2 allows remote attackers t…

Mitigation only
Fix from $1,600 2008-11-10
Lotus Connections HIGH 10.0
CVE-2008-4809

Multiple unspecified vulnerabilities in the Profiles search pages in IBM Lotus Connections 2.x before 2.0.1 have unknown impact and attack vectors re…

Mitigation only
Fix from $1,950 2008-10-31
Websphere Application Server HIGH 7.8
CVE-2008-4678

The HTTP_Request_Parser method in the HTTP Transport component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.31 allows remote attacker…

Mitigation only
Fix from $1,950 2008-10-22
Lotus Quickr HIGH 7.5
CVE-2008-4507

Unspecified vulnerability in IBM Lotus Quickr 8.1 before Fix pack 1 (8.1.0.1) allows editors to delete pages that were created by a different author …

Mitigation only
Fix from $1,950 2008-10-09
Lotus Quickr HIGH 7.8
CVE-2008-4505

Unspecified vulnerability in IBM Lotus Quickr 8.1 before Fix pack 1 (8.1.0.1) might allow attackers to cause a denial of service (system crash) via a…

Mitigation only
Fix from $1,950 2008-10-09
Lotus Quickr HIGH 7.5
CVE-2008-4506

Unspecified vulnerability in IBM Lotus Quickr 8.1 before Fix pack 1 (8.1.0.1) allows a place manager to "demote or delete a place superuser group" vi…

Mitigation only
Fix from $1,950 2008-10-09