Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Db2 MEDIUM 5.5
CVE-2018-1450

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability that could allow a local user to…

Mitigation only
Fix from $1,600 2018-05-25
Db2 MEDIUM 5.5
CVE-2018-1451

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability that could allow a local user to…

Mitigation only
Fix from $1,600 2018-05-25
Db2 MEDIUM 5.5
CVE-2018-1452

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability that could allow a local user to…

Mitigation only
Fix from $1,600 2018-05-25
Tivoli Application Dependency Discovery Manager HIGH 8.1
CVE-2013-3023

IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.1.2 and 7.2.0 through 7.2.1.4 might allow remote attackers to obtain sensitive informat…

Fix: after 7.2.1.4
Fix from $1,950 2018-05-24
Websphere Application Server HIGH 7.8
CVE-2013-3024

IBM WebSphere Application Server (WAS) 8.5 through 8.5.0.2 on UNIX allows local users to gain privileges by leveraging improper process initializatio…

Fix: after 8.5.0.2
Fix from $1,950 2018-05-24
Tivoli Application Dependency Discovery Manager MEDIUM 5.3
CVE-2013-3018

The AXIS webapp in deploy-tomcat/axis in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.1.2 and 7.2.0 through 7.2.1.4 allows remote at…

Fix: after 7.2.1.4
Fix from $1,600 2018-05-24
Storediq MEDIUM 5.4
CVE-2018-1583

IBM StoredIQ 7.6 could allow an authenticated attacker to bypass certain security restrictions. By sending a specially-crafted request, an authentica…

Mitigation only
Fix from $1,600 2018-05-22
Storwize V7000 Firmware HIGH 8.8
CVE-2018-1434

IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6…

Fix: 7.5.0.14 / 7.7.1.9+
Fix from $1,950 2018-05-17
Storwize V7000 Firmware HIGH 7.6
CVE-2018-1462

IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6…

Fix: 7.5.0.14 / 7.7.1.9+
Fix from $1,950 2018-05-17
Storwize V7000 Firmware HIGH 7.5
CVE-2018-1433

IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6…

Fix: 7.5.0.14 / 7.7.1.9+
Fix from $1,950 2018-05-17
Storwize V7000 Firmware HIGH 7.5
CVE-2018-1438

IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6…

Fix: 7.5.0.14 / 7.7.1.9+
Fix from $1,950 2018-05-17
Storwize V7000 Firmware MEDIUM 6.5
CVE-2018-1463

IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6…

Fix: 7.5.0.14 / 7.7.1.9+
Fix from $1,600 2018-05-17
Storwize V7000 Firmware MEDIUM 6.5
CVE-2018-1464

IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6…

Fix: 7.5.0.14 / 7.7.1.9+
Fix from $1,600 2018-05-17
Storwize V7000 Firmware MEDIUM 5.4
CVE-2018-1461

IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6…

Fix: 7.5.0.14 / 7.7.1.9+
Fix from $1,600 2018-05-17
Storwize V7000 Firmware MEDIUM 5.3
CVE-2018-1465

IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6…

Fix: 7.5.0.14 / 7.7.1.9+
Fix from $1,600 2018-05-17
Storwize V7000 Firmware MEDIUM 5.3
CVE-2018-1466

IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products (6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.…

Fix: 7.5.0.14 / 7.7.1.9+
Fix from $1,600 2018-05-17
Cognos Analytics MEDIUM 5.4
CVE-2018-1413

IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thu…

Fix: after 11.0.10.0
Fix from $1,600 2018-05-07
Security Guardium Database Activity Monitor CRITICAL 9.8
CVE-2017-1601

IBM Security Guardium 10.0, 10.0.1, and 10.1 through 10.1.4 Database Activity Monitor does not require that users should have strong passwords by def…

Patch available
Fix from $2,300 2018-05-02
Security Guardium HIGH 7.5
CVE-2017-1255

IBM Security Guardium 10.0, 10.0.1, and 10.1 through 10.1.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decryp…

Patch available
Fix from $1,950 2018-05-02
Sterling Connect HIGH 7.3
CVE-2013-4035

IBM Sterling Connect:Direct for OpenVMS 3.4.00, 3.4.01, 3.5.00, 3.6.0, and 3.6.0.1 allow remote attackers to have unspecified impact by leveraging fa…

No fix yet
Fix from $1,950 2018-05-01
Tivoli Application Dependency Discovery Manager MEDIUM 5.5
CVE-2013-4040

IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.1.2.x before 7.2.1.5 and 7.2.x before 7.2.2.0 on Unix use weak permissions (755) for un…

Fix: after 7.2.1.4
Fix from $1,600 2018-05-01
Content Manager MEDIUM 5.4
CVE-2018-1502

IBM Content Manager Enterprise Edition Resource Manager 8.4.3 and 9.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed…

Patch available
Fix from $1,600 2018-05-01
Api Connect MEDIUM 6.5
CVE-2018-1389

IBM API Connect 5.0.0.0 through 5.0.8.2 is impacted by generated LoopBack APIs for a Model using the BelongsTo/HasMany relationship allowing unauthor…

Fix: after 5.0.8.2
Fix from $1,600 2018-04-30
Api Connect MEDIUM 5.4
CVE-2018-1430

IBM API Connect 5.0.0.0 through 5.0.8.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in …

Fix: after 5.0.8.2
Fix from $1,600 2018-04-30
Endpoint Manager For Remote Control HIGH 8.8
CVE-2013-5461

IBM Endpoint Manager for Remote Control 9.0.0 and 9.0.1 and Tivoli Remote Control 5.1.2 store multiple hashes of partial passwords, which makes it ea…

Mitigation only
Fix from $1,950 2018-04-27
Spss Modeler MEDIUM 5.4
CVE-2013-6739

IBM SPSS Modeler before 16 on UNIX allows remote authenticated users to bypass intended access restrictions via an SSO token. IBM X-Force ID: 89855.

Fix: 16.0.0.0+
Fix from $1,600 2018-04-27
Worklight MEDIUM 5.3
CVE-2013-5391

IBM Worklight Consumer and Enterprise Editions 5.0.x before 5.0.6 Fix Pack 2 and 6.0.x before 6.0.0 Fix Pack 2, and Mobile Foundation Consumer and En…

Mitigation only
Fix from $1,600 2018-04-27
Rational Focal Point MEDIUM 5.3
CVE-2014-0841

IBM Rational Focal Point 6.4.0, 6.4.1, 6.5.1, 6.5.2, and 6.6.0 use a weak algorithm to hash passwords, which makes it easier for context-dependent at…

Patch available
Fix from $1,600 2018-04-27
Bigfix Platform HIGH 8.8
CVE-2018-1479

IBM BigFix Platform 9.2 and 9.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actio…

Fix: after 9.5.8
Fix from $1,950 2018-04-27
Bigfix Platform CRITICAL 9.8
CVE-2018-1475

IBM BigFix Platform 9.2 and 9.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM…

Fix: after 9.5.8
Fix from $2,300 2018-04-27