Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Domino HIGH 7.8
CVE-2018-1771

IBM Domino 9.0 and 9.0.1 could allow an attacker to execute commands on the system by triggering a buffer overflow in the parsing of command line arg…

Fix: after 9.0.1.10
Fix from $1,950 2018-12-20
Api Connect HIGH 7.2
CVE-2018-1973

IBM API Connect 5.0.0.0 through 5.0.8.4 allows a user with limited 'API Administrator level access to give themselves full 'Administrator' level acce…

Fix: after 5.0.8.4
Fix from $1,950 2018-12-20
Datapower Gateway MEDIUM 5.5
CVE-2018-1677

IBM DataPower Gateways 7.1, 7.2, 7.5, 7.5.1, 7.5.2, 7.6, and 7.7 and IBM MQ Appliance are vulnerable to a denial of service, caused by the improper h…

Fix: after 7.7.1.0
Fix from $1,600 2018-12-20
Event Streams MEDIUM 5.3
CVE-2018-1833

IBM Event Streams 2018.3.0 could allow a remote attacker to submit an API request with a fake Host request header. An attacker, who has already gaine…

Mitigation only
Fix from $1,600 2018-12-18
Security Guardium HIGH 7.5
CVE-2017-1597

IBM Security Guardium 10.0, 10.0.1, 10.1, 10.1.2, 10.1.3, 10.1.4, and 10.5 Database Activity Monitor does not require that users should have strong p…

Fix: after 10.5
Fix from $1,950 2018-12-17
Security Guardium MEDIUM 5.9
CVE-2017-1265

IBM Security Guardium 10.0, 10.0.1, 10.1, 10.1.2, 10.1.3, 10.1.4, and 10.5 does not validate, or incorrectly validates, a certificate. This weakness …

Fix: after 10.5
Fix from $1,600 2018-12-17
Security Guardium MEDIUM 5.4
CVE-2018-1889

IBM Security Guardium 10.0 and 10.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the …

Fix: after 10.5
Fix from $1,600 2018-12-17
Security Guardium MEDIUM 5.4
CVE-2018-1891

IBM Security Guardium 10 and 10.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the We…

Fix: after 10.5
Fix from $1,600 2018-12-17
Security Guardium MEDIUM 5.3
CVE-2017-1272

IBM Security Guardium 10.0 and 10.5 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties h…

Fix: after 10.5
Fix from $1,600 2018-12-17
Db2 MEDIUM 6.5
CVE-2018-1977

IBM DB2 for Linux, UNIX and Windows 11.1 (includes DB2 Connect Server) contains a denial of service vulnerability. A remote, authenticated DB2 user c…

Patch available
Fix from $1,600 2018-12-14
Business Automation Workflow MEDIUM 6.1
CVE-2018-1848

IBM Business Automation Workflow 18.0.0.0 and 18.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Java…

Fix: after 8.5.0.2
Fix from $1,600 2018-12-14
Security Guardium CRITICAL 9.8
CVE-2018-1818

IBM Security Guardium 10 and 10.5 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authent…

Fix: after 10.5
Fix from $2,300 2018-12-13
Operational Decision Manager CRITICAL 9.1
CVE-2018-1821EPSS 16%

IBM Operational Decision Management 8.5, 8.6, 8.7, 8.8, and 8.9 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML dat…

Fix: 8.6.0.3 / 8.7.1.2+
Fix from $2,300 2018-12-13
Security Access Manager HIGH 7.8
CVE-2018-1887

IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 contains hard-coded credentials, such as a password or cryptogr…

Fix: after 9.0.5.0
Fix from $1,950 2018-12-13
Security Guardium MEDIUM 6.1
CVE-2018-1817

IBM Security Guardium 10 and 10.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the We…

Fix: after 10.5
Fix from $1,600 2018-12-13
Security Access Manager MEDIUM 5.3
CVE-2018-1886

IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 discloses sensitive information to unauthorized users. The info…

Fix: after 9.0.5.0
Fix from $1,600 2018-12-13
Security Guardium HIGH 7.5
CVE-2017-1268

IBM Security Guardium 10 and 10.5 uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the softw…

Fix: after 10.5
Fix from $1,950 2018-12-13
Datapower Gateway HIGH 7.5
CVE-2018-1665

IBM DataPower Gateway 7.6.0.0 through 7.6.0.10, 7.5.2.0 through 7.5.2.17, 7.5.1.0 through 7.5.1.17, 7.5.0.0 through 7.5.0.18, and 7.7.0.0 through 7.7…

Fix: after 7.7.1.3
Fix from $1,950 2018-12-13
Security Access Manager HIGH 7.5
CVE-2018-1814

IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 uses weaker than expected cryptographic algorithms that could a…

Fix: after 9.0.5.0
Fix from $1,950 2018-12-13
Security Access Manager MEDIUM 6.5
CVE-2018-1813

IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 uses incomplete blacklisting for input validation which allows …

Fix: after 9.0.5.0
Fix from $1,600 2018-12-13
Security Access Manager MEDIUM 6.1
CVE-2018-1803

IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 could allow a remote attacker to hijack the clicking action of …

Fix: after 9.0.5.0
Fix from $1,600 2018-12-13
Security Access Manager MEDIUM 6.1
CVE-2018-1815

IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 for Enterprise Single-Sign On is vulnerable to cross-site scrip…

Fix: after 9.0.5.0
Fix from $1,600 2018-12-13
Security Access Manager MEDIUM 5.4
CVE-2018-1653

IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 is vulnerable to cross-site scripting. This vulnerability allow…

Fix: after 9.0.5.0
Fix from $1,600 2018-12-13
Datapower Gateway MEDIUM 5.4
CVE-2018-1667

IBM DataPower Gateway 7.6.0.0 through 7.6.0.10, 7.5.2.0 through 7.5.2.17, 7.5.1.0 through 7.5.1.17, 7.5.0.0 through 7.5.0.18, and 7.7.0.0 through 7.7…

Fix: after 7.7.1.3
Fix from $1,600 2018-12-13
Security Access Manager MEDIUM 5.4
CVE-2018-1740

IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 is vulnerable to cross-site scripting. This vulnerability allow…

Fix: after 9.0.5.0
Fix from $1,600 2018-12-13
Websphere Application Server HIGH 8.8
CVE-2018-1901

IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to temporarily gain elevated privileges on the system, caused by incorrect…

Fix: after 9.0.0.9
Fix from $1,950 2018-12-12
Websphere Application Server HIGH 8.8
CVE-2018-1926

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Admin Console is vulnerable to cross-site request forgery, caused by improper validation of u…

Fix: after 9.0.0.9
Fix from $1,950 2018-12-12
Bigfix Platform MEDIUM 5.3
CVE-2018-1480

IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 does not set the 'HttpOnly' attribute on authorization tokens or session cookies. If a…

Fix: after 9.5.9
Fix from $1,600 2018-12-12
Bigfix Platform MEDIUM 5.3
CVE-2018-1481

IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 stores sensitive information in URL parameters. This may lead to information disclosur…

Fix: after 9.5.9
Fix from $1,600 2018-12-12
Bigfix Platform HIGH 7.5
CVE-2018-1476

IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 discloses sensitive information to unauthorized users. The information can be used to …

Fix: after 9.5.9
Fix from $1,950 2018-12-12