Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Notes MEDIUM 5.3
CVE-2017-1720

IBM Notes 8.5 and 9.0 could allow a local attacker to execute arbitrary commands by carefully crafting a command line sent via the shared memory IPC.…

Patch available
Fix from $1,600 2018-02-13
Websphere Portal MEDIUM 6.1
CVE-2017-1761

IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code…

Patch available
Fix from $1,600 2018-02-09
Websphere Portal MEDIUM 6.1
CVE-2018-1401

IBM WebSphere Portal 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…

Patch available
Fix from $1,600 2018-02-09
Websphere Application Server CRITICAL 9.8
CVE-2011-4889

The javax.naming.directory.AttributeInUseException class in the Virtual Member Manager in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.43,…

Fix: 6.1.0.43 / 7.0.0.21+
Fix from $2,300 2018-02-08
Xiv Storage System 2810 A14 Firmware CRITICAL 9.8
CVE-2012-2166

IBM XIV Storage System 2810-A14 and 2812-A14 devices before level 10.2.4.e-2 and 2810-114 and 2812-114 devices before level 11.1.1 have hardcoded pas…

Fix: 10.2.4.e-2 / 11.1.1+
Fix from $2,300 2018-02-08
Sametime MEDIUM 5.3
CVE-2012-3331

IBM Sametime allows remote attackers to obtain sensitive information from the Sametime Log database via a direct request to STLOG.NSF. IBM X-Force ID…

Mitigation only
Fix from $1,600 2018-02-08
Aix HIGH 7.8
CVE-2017-1692

IBM AIX 5.3, 6.1, 7.1, and 7.2 contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges. I…

Mitigation only
Fix from $1,950 2018-02-07
Content Navigator HIGH 7.8
CVE-2018-1366

IBM Content Navigator 2.0 and 3.0 is vulnerable to Comma Separated Value (CSV) Injection. An attacker could exploit this vulnerability to exploit oth…

Patch available
Fix from $1,950 2018-02-07
Websphere Mq HIGH 7.5
CVE-2018-1388

GSKit V7 may disclose side channel information via discrepancies between valid and invalid PKCS#1 padding. IBM X-Force ID: 138212.

Mitigation only
Fix from $1,950 2018-02-07
Api Connect MEDIUM 5.4
CVE-2018-1382

IBM API Connect 5.0.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus …

Fix: after 5.0.6.4
Fix from $1,600 2018-02-07
Tririga Application Platform HIGH 7.5
CVE-2016-0312

IBM TRIRIGA Application Platform before 3.3.2 allows remote attackers to obtain sensitive information via vectors related to granting unauthenticated…

Fix: after 3.3.1
Fix from $1,950 2018-02-02
Tririga Application Platform MEDIUM 5.4
CVE-2016-0300

IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 might allow remote attackers to access arbitrary JSP …

Mitigation only
Fix from $1,600 2018-02-02
Tivoli Integrated Portal MEDIUM 5.4
CVE-2016-0303

Cross-site scripting (XSS) vulnerability in IBM Tivoli Integrated Portal 2.2.0.0 through 2.2.0.15 allows remote attackers to inject arbitrary web scr…

Fix: after 2.2.0.15
Fix from $1,600 2018-02-02
Tivoli Business Service Manager MEDIUM 5.4
CVE-2016-0311

Cross-site scripting (XSS) vulnerability in IBM Tivoli Business Service Manager 6.1.0 before 6.1.0-TIV-BSM-FP0004 and 6.1.1 before 6.1.1-TIV-BSM-FP00…

Mitigation only
Fix from $1,600 2018-02-02
Emptoris Sourcing MEDIUM 5.4
CVE-2016-0329

Open redirect vulnerability in IBM Emptoris Sourcing 10.0.0.x before 10.0.0.1_iFix3, 10.0.1.x before 10.0.1.3_iFix3, 10.0.2.x before 10.0.2.8_iFix1, …

Fix: after 10.1.0.0
Fix from $1,600 2018-02-02
Tririga Application Platform MEDIUM 5.4
CVE-2016-0342

IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote authenticated users to read or modify a…

Fix: 3.3.2.6 / 3.4.2.3+
Fix from $1,600 2018-02-02
Bigfix Remote Control MEDIUM 6.7
CVE-2017-1233

IBM Remote Control v9 could allow a local user to use the component to replace files to which he does not have write access and which he can cause to…

Patch available
Fix from $1,600 2018-01-31
Websphere Application Server HIGH 8.8
CVE-2017-1731

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could provide weaker than expected security when using the Administrative Console. An authent…

Fix: after 9.0.0.6
Fix from $1,950 2018-01-30
Content Navigator HIGH 8.2
CVE-2018-1364

IBM Content Navigator 2.0 and 3.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exp…

Mitigation only
Fix from $1,950 2018-01-29
Cognos Analytics HIGH 7.8
CVE-2017-1779

IBM Cognos Analytics 11.0 could store cached credentials locally that could be obtained by a local user. IBM X-Force ID: 136824.

Patch available
Fix from $1,950 2018-01-29
Cognos Analytics MEDIUM 5.5
CVE-2017-1784

IBM Cognos Analytics 11.0 could produce results in temporary files that contain highly sensitive information that can be read by a local user. IBM X-…

Patch available
Fix from $1,600 2018-01-29
Tealeaf Customer Experience CRITICAL 9.8
CVE-2017-1204

IBM Tealeaf Customer Experience 8.7, 8.8, and 9.0.2 contains hard-coded credentials. A remote attacker could exploit this vulnerability to gain acces…

Patch available
Fix from $2,300 2018-01-26
Tealeaf Customer Experience HIGH 8.1
CVE-2016-2983

IBM Tealeaf Customer Experience 8.7, 8.8, and 9.0.2 could allow a remote attacker under unusual circumstances to read operational data or TLS session…

Patch available
Fix from $1,950 2018-01-26
Engineering Requirements Management Doors MEDIUM 6.8
CVE-2017-1545

IBM Doors Web Access 9.5 and 9.6 could allow an attacker with physical access to the system to log into the application using previously stored crede…

Fix: after 9.6.1.9
Fix from $1,600 2018-01-26
Tealeaf Customer Experience MEDIUM 6.5
CVE-2017-1279

IBM Tealeaf Customer Experience 8.7, 8.8, and 9.0.2 could allow a remote attacker to traverse directories on the system. An attacker could send a spe…

Patch available
Fix from $1,600 2018-01-26
Cognos Tm1 MEDIUM 6.1
CVE-2017-1506

IBM Cognos TM1 10.2 and 10.2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web U…

Patch available
Fix from $1,600 2018-01-26
Engineering Requirements Management Doors MEDIUM 5.4
CVE-2017-1516

IBM Doors Web Access 9.5 and 9.6 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicio…

Fix: after 9.6.1.9
Fix from $1,600 2018-01-26
Engineering Requirements Management Doors MEDIUM 5.4
CVE-2017-1532

IBM DOORS 9.5 and 9.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus al…

Fix: after 9.6.1.9
Fix from $1,600 2018-01-26
Engineering Requirements Management Doors MEDIUM 5.4
CVE-2017-1540

IBM Doors Web Access 9.5 and 9.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web…

Fix: after 9.6.1.9
Fix from $1,600 2018-01-26
Engineering Requirements Management Doors MEDIUM 5.4
CVE-2017-1563

IBM Doors Web Access 9.5 and 9.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web…

Fix: after 9.6.1.9
Fix from $1,600 2018-01-26