Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Bigfix Platform MEDIUM 6.1
CVE-2018-1478

IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 could allow a remote attacker to hijack the clicking action of the victim. By persuadi…

Fix: after 9.5.9
Fix from $1,600 2018-12-12
Websphere Application Server CRITICAL 9.8
CVE-2018-1904

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbitrary Java code through an administrative client …

Fix: after 9.0.0.9
Fix from $2,300 2018-12-11
Curam Social Program Management MEDIUM 5.4
CVE-2018-1900

IBM Curam Social Program Management 6.0.5, 6.1.1, 6.2.0, 7.0.1, and 7.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to e…

Fix: after 7.0.4.0
Fix from $1,600 2018-12-11
Curam Social Program Management MEDIUM 6.1
CVE-2018-1654

IBM Curam Social Program Management 6.0.5, 6.1.1, 6.2.0, 7.0.1, and 7.0.3 could allow a remote attacker to conduct phishing attacks, using an open re…

Fix: after 7.0.3.0
Fix from $1,600 2018-12-11
Datapower Gateway MEDIUM 5.5
CVE-2018-1652

IBM DataPower Gateway 7.1.0.0 through 7.1.0.19, 7.2.0.0 through 7.2.0.16, 7.5.0.0 through 7.5.0.10, 7.5.1.0 through 7.5.1.9, 7.5.2.0 through 7.5.2.9,…

Fix: after 9.0.5
Fix from $1,600 2018-12-11
Curam Social Program Management MEDIUM 6.1
CVE-2018-1671

IBM Curam Social Program Management 7.0.3 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, wou…

Patch available
Fix from $1,600 2018-12-10
Websphere Application Server MEDIUM 5.5
CVE-2018-1957

IBM WebSphere Application Server 9 could allow sensitive information to be available caused by mishandling of data by the application based on an inc…

Fix: after 9.0.0.9
Fix from $1,600 2018-12-10
Mq HIGH 7.5
CVE-2018-1883

A problem within the IBM MQ 9.0.2, 9.0.3, 9.0.4, 9.0.5, and 9.1.0.0 Console REST API Could allow attackers to execute a denial of service attack prev…

Fix: after 9.0.5
Fix from $1,950 2018-12-07
Marketing Platform HIGH 7.1
CVE-2018-1424

IBM Marketing Platform 9.1.0, 9.1.2, and 10.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attack…

Mitigation only
Fix from $1,950 2018-12-07
Marketing Platform HIGH 7.1
CVE-2018-1920

IBM Marketing Platform 9.1.0, 9.1.2 and 10.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacke…

Mitigation only
Fix from $1,950 2018-12-07
Datapower Gateway MEDIUM 5.9
CVE-2018-1663

IBM DataPower Gateways 7.5, 7.5.1, 7.5.2, 7.6, and 2018.4 could allow a remote attacker to obtain sensitive information, caused by the failure to pro…

Fix: after 7.7.1.3
Fix from $1,600 2018-12-07
Connections MEDIUM 5.4
CVE-2018-1896

IBM Connections 5.0, 5.5, and 6.0 is vulnerable to possible host header injection attack that could cause navigation to the attacker's domain. IBM X-…

Patch available
Fix from $1,600 2018-12-07
I2 Enterprise Insight Analysis MEDIUM 6.1
CVE-2018-1504

IBM i2 Enterprise Insight Analysis 2.1.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a…

Mitigation only
Fix from $1,600 2018-12-06
I2 Enterprise Insight Analysis MEDIUM 5.9
CVE-2018-1525

IBM i2 Enterprise Insight Analysis 2.1.7 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP…

Mitigation only
Fix from $1,600 2018-12-06
Financial Transaction Manager MEDIUM 5.4
CVE-2018-1871

IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.0.0, 3.0.2, and 3.0.5 is vulnerable to cross-site scripting. This vulnera…

Patch available
Fix from $1,600 2018-12-06
Campaign HIGH 7.8
CVE-2018-1941

IBM Campaign 9.1.0 and 9.1.2 could allow a local user to obtain admini privileges due to the application not validating access permissions. IBM X-For…

Fix: 9.1.0.13 / 9.1.2.7+
Fix from $1,950 2018-12-05
Qradar Incident Forensics HIGH 7.5
CVE-2018-1648

IBM QRadar SIEM 7.2 and 7.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. …

Fix: 7.2.8 / 7.3.1+
Fix from $1,950 2018-12-05
Qradar Advisor With Watson HIGH 7.5
CVE-2018-1732

IBM QRadar Advisor with Watson 1.14.0 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on …

Fix: after 1.14.0
Fix from $1,950 2018-12-05
Qradar Incident Forensics HIGH 7.4
CVE-2017-1622

IBM QRadar SIEM 7.2.8 and 7.3 does not validate, or incorrectly validates, a certificate. This weakness might allow an attacker to spoof a trusted en…

Fix: 7.2.8 / 7.3.1+
Fix from $1,950 2018-12-05
Qradar Security Information And Event Manager HIGH 7.1
CVE-2018-1730

IBM QRadar SIEM 7.2 and 7.3 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit t…

Fix: after 7.3.1
Fix from $1,950 2018-12-05
Qradar Incident Forensics MEDIUM 5.5
CVE-2018-1650

IBM QRadar SIEM 7.2 and 7.3 uses hard-coded credentials which could allow an attacker to bypass the authentication configured by the administrator. I…

Fix: 7.2.8 / 7.3.1+
Fix from $1,600 2018-12-05
Qradar Incident Forensics MEDIUM 5.4
CVE-2018-1728

IBM QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI t…

Fix: 7.2.8 / 7.3.1+
Fix from $1,600 2018-12-05
Websphere Application Server HIGH 8.1
CVE-2018-1840

IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to gain elevated privileges on the system, caused when a security domain i…

Fix: after 9.0.0.9
Fix from $1,950 2018-12-03
Storediq HIGH 8.8
CVE-2018-1927

IBM StoredIQ 7.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted …

Fix: 7.6.0.17+
Fix from $1,950 2018-11-30
Db2 HIGH 7.8
CVE-2018-1897

IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5., and 11.1 db2pdcfg is vulnerable to a stack based buffer overflow, caused by improper bounds che…

Patch available
Fix from $1,950 2018-11-30
Storediq MEDIUM 5.5
CVE-2018-1928

IBM StoredIQ 7.6.0 does not implement proper authorization of user roles due to which it was possible for a low privileged user to access the applica…

Fix: 7.6.0.17+
Fix from $1,600 2018-11-30
Rational Collaborative Lifecycle Management MEDIUM 5.4
CVE-2018-1762

IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability al…

Fix: after 6.0.6
Fix from $1,600 2018-11-29
Maximo Asset Management MEDIUM 5.4
CVE-2018-1584

IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web …

Patch available
Fix from $1,600 2018-11-28
Websphere Application Server HIGH 7.1
CVE-2018-1905

IBM WebSphere Application Server 9.0.0.0 through 9.0.0.9 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A re…

Fix: after 9.0.0.9
Fix from $1,950 2018-11-26
Integration Bus MEDIUM 5.5
CVE-2017-1418

IBM Integration Bus 9.0.0.0, 9.0.0.11, 10.0.0.0, and 10.0.0.14 (including IBM WebSphere Message Broker 8.0.0.0 and 8.0.0.9) has insecure permissions …

Fix: after 10.0.0.14
Fix from $1,600 2018-11-26