Vulnerability index

Browse CVEs

2,226 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.3 CVE-2016-0325 IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; R… Rational Team Concert Mitigation only Fix from $1,6002016-11-24 MEDIUM 5.4 CVE-2016-0285 Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before… Rational Team Concert Mitigation only Fix from $1,6002016-11-24 MEDIUM 5.4 CVE-2016-0284 The XML parser in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 bef… Rational Software Architect Design Manager Mitigation only Fix from $1,6002016-11-24 MEDIUM 5.4 CVE-2016-0282 Cross-site scripting (XSS) vulnerability in IBM iNotes before 8.5.3 FP6 IF2 allows remote authenticated users to inject arbitrary web script or HTML … Lotus Inotes Mitigation only Fix from $1,6002016-11-24 MEDIUM 5.4 CVE-2016-0273 Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before… Rational Doors Next Generation Mitigation only Fix from $1,6002016-11-24 MEDIUM 6.1 CVE-2016-6027 The Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.0 iFix 1 does not enable the HSTS pro… Sterling Secure Proxy Mitigation only Fix from $1,6002016-10-06 MEDIUM 5.3 CVE-2016-6026 The Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.0 iFix 1 allows man-in-the-middle att… Sterling Secure Proxy Mitigation only Fix from $1,6002016-10-06 MEDIUM 5.9 CVE-2016-6025 The Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.0 iFix 1 allows remote attackers to o… Sterling Secure Proxy Mitigation only Fix from $1,6002016-10-06 HIGH 7.5 CVE-2016-6023 Directory traversal vulnerability in the Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.… Sterling Secure Proxy Mitigation only Fix from $1,9502016-10-06 MEDIUM 5.4 CVE-2016-3042 Cross-site scripting (XSS) vulnerability in the Web UI in IBM WebSphere Application Server (WAS) Liberty before 16.0.0.3 allows remote authenticated … Websphere Application Server Mitigation only Fix from $1,6002016-10-01 MEDIUM 6.5 CVE-2016-6038 Directory traversal vulnerability in Eclipse Help in IBM Tivoli Lightweight Infrastructure (aka LWI), as used in AIX 5.3, 6.1, and 7.1, allows remote… Aix Mitigation only Fix from $1,6002016-09-26 MEDIUM 5.4 CVE-2016-5978 Cross-site scripting (XSS) vulnerability in the Web UI in the web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.… Tealeaf Customer Experience Mitigation only Fix from $1,6002016-09-26 HIGH 8.8 CVE-2016-5879 MQCLI on IBM MQ Appliance M2000 and M2001 devices allows local users to execute arbitrary shell commands via a crafted (1) Disaster Recovery or (2) H… Mq Appliance Firmware Mitigation only Fix from $1,9502016-09-02 MEDIUM 6.1 CVE-2016-0293 Cross-site scripting (XSS) vulnerability in IBM BigFix Platform (formerly Tivoli Endpoint Manager) 9.x before 9.1.8 and 9.2.x before 9.2.8 allows rem… Bigfix Platform Mitigation only Fix from $1,6002016-09-01 MEDIUM 5.9 CVE-2016-0397 WebReports in IBM BigFix Platform (formerly Tivoli Endpoint Manager) 9.x before 9.5.2 allows remote attackers to obtain sensitive information by snif… Bigfix Webreports Mitigation only Fix from $1,6002016-08-30 MEDIUM 5.5 CVE-2016-0292 WebReports in IBM BigFix Platform (formerly Tivoli Endpoint Manager) 9.x before 9.5.2 allows local users to discover the cleartext system password by… Bigfix Mitigation only Fix from $1,6002016-08-30 MEDIUM 5.4 CVE-2016-2925 Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.x through 7.0.0.2 CF30… Websphere Portal Mitigation only Fix from $1,6002016-08-08 MEDIUM 5.4 CVE-2016-2912 Cross-site scripting (XSS) vulnerability in the Document Builder in IBM Rational Publishing Engine (aka RPENG) 2.0.1 before ifix002 allows remote aut… Engineering Lifecycle Optimization Publishing Mitigation only Fix from $1,6002016-08-08 HIGH 8.1 CVE-2016-3039 IBM Traveler 8.x and 9.x before 9.0.1.12 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) … Traveler Mitigation only Fix from $1,9502016-07-17 MEDIUM 5.3 CVE-2016-0393 IBM Maximo Asset Management 7.5 before 7.5.0.10-TIV-MBS-IFIX002 and 7.6 before 7.6.0.5-TIV-MAMMT-FP001 allows remote attackers to obtain sensitive UR… Maximo Asset Management Mitigation only Fix from $1,6002016-07-17 MEDIUM 6.2 CVE-2016-0321 IBM Personal Communications (aka PCOMM) 6.x before 6.0.17 and 12.x before 12.0.0.1 does not properly restrict credential extraction, which allows loc… Personal Communications Mitigation only Fix from $1,6002016-07-17 HIGH 7.4 CVE-2016-0340 IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 mishandles session expiration, which allow… Security Identity Manager Adapter Mitigation only Fix from $1,9502016-07-15 MEDIUM 5.6 CVE-2016-0339 IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 mishandles session identifiers after logou… Security Identity Manager Adapter Mitigation only Fix from $1,6002016-07-15 MEDIUM 6.2 CVE-2016-0338 IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 allows local users to discover cleartext p… Security Identity Manager Adapter Mitigation only Fix from $1,6002016-07-15 HIGH 7.3 CVE-2016-0330 IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 mishandles password creation, which makes … Security Identity Manager Adapter No fix yet Fix from $1,9502016-07-15 MEDIUM 5.4 CVE-2016-0269 Cross-site scripting (XSS) vulnerability in IBM BigFix Platform 9.x before 9.1.8 and 9.2.x before 9.2.7 allows remote authenticated users to inject a… Bigfix Platform Mitigation only Fix from $1,6002016-07-15 HIGH 7.5 CVE-2015-1977 Directory traversal vulnerability in the Web Administration tool in IBM Tivoli Directory Server (ITDS) before 6.1.0.74-ISS-ISDS-IF0074, 6.2.x before … Tivoli Directory Server Mitigation only Fix from $1,9502016-07-15 HIGH 7.5 CVE-2016-2945 The API Discovery implementation in IBM WebSphere Application Server (WAS) 8.5.5.8 through 8.5.5.9 Liberty before Liberty Fix Pack 16.0.0.2 allows re… Websphere Application Server Mitigation only Fix from $1,9502016-07-08 HIGH 8.8 CVE-2016-2889 Cross-site request forgery (CSRF) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x bef… Jazz Reporting Service Mitigation only Fix from $1,9502016-07-08 MEDIUM 5.4 CVE-2016-2888 Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0… Jazz Reporting Service Mitigation only Fix from $1,6002016-07-08