Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Rational Engineering Lifecycle Manager MEDIUM 5.4
CVE-2017-1334

IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI th…

Mitigation only
Fix from $1,600 2017-10-03
Rational Engineering Lifecycle Manager MEDIUM 5.4
CVE-2017-1335

IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI th…

Mitigation only
Fix from $1,600 2017-10-03
Insights Foundation For Energy MEDIUM 5.4
CVE-2017-1345

IBM Insights Foundation for Energy 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…

Mitigation only
Fix from $1,600 2017-10-03
Rational Engineering Lifecycle Manager MEDIUM 5.4
CVE-2017-1359

IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI th…

Mitigation only
Fix from $1,600 2017-10-03
Rational Engineering Lifecycle Manager MEDIUM 5.4
CVE-2017-1364

IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI th…

Mitigation only
Fix from $1,600 2017-10-03
Rational Engineering Lifecycle Manager MEDIUM 5.4
CVE-2017-1369

IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI th…

Mitigation only
Fix from $1,600 2017-10-03
Rational Engineering Lifecycle Manager MEDIUM 5.4
CVE-2017-1429

IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI th…

Mitigation only
Fix from $1,600 2017-10-03
Security Identity Governance And Intelligence HIGH 8.6
CVE-2017-1483

IBM Security Identity Manager Adapters 6.0 and 7.0 does not perform an authentication check for a critical resource or functionality allowing anonymo…

Patch available
Fix from $1,950 2017-09-28
Websphere Portal HIGH 7.5
CVE-2017-1577

IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-c…

Patch available
Fix from $1,950 2017-09-28
Datapower Gateway MEDIUM 6.1
CVE-2017-1591

IBM WebSphere DataPower Appliances 7.0.0 through 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaSc…

Patch available
Fix from $1,600 2017-09-28
Security Identity Governance And Intelligence HIGH 8.8
CVE-2017-1407

IBM Security Identity Manager Virtual Appliance 6.0 and 7.0 could allow a remote authenticated attacker to execute arbitrary commands on the system. …

Patch available
Fix from $1,950 2017-09-28
Business Process Manager HIGH 8.8
CVE-2017-1539

IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to privilege escalation by not properly distinguishing internal group memberships from u…

Patch available
Fix from $1,950 2017-09-26
Business Process Manager HIGH 8.1
CVE-2017-1527

IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attac…

Patch available
Fix from $1,950 2017-09-26
Business Process Manager MEDIUM 5.4
CVE-2017-1425

IBM Business Process Manager 8.0.1.1 and 8.5.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript c…

Mitigation only
Fix from $1,600 2017-09-26
Business Process Manager MEDIUM 5.4
CVE-2017-1530

IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript c…

Patch available
Fix from $1,600 2017-09-26
Business Process Manager MEDIUM 5.4
CVE-2017-1531

IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript c…

Patch available
Fix from $1,600 2017-09-26
Security Identity Manager HIGH 7.8
CVE-2017-1362

IBM Security Identity Manager Adapters 6.0 and 7.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: …

Patch available
Fix from $1,950 2017-09-25
Websphere Mq MEDIUM 6.5
CVE-2017-1235

IBM WebSphere MQ 8.0 could allow an authenticated user to cause a premature termination of a client application thread which could potentially cause …

Patch available
Fix from $1,600 2017-09-25
Api Connect MEDIUM 6.1
CVE-2017-1551

IBM API Connect 5.0.0.0 through 5.0.7.2 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a …

Patch available
Fix from $1,600 2017-09-25
Business Process Manager MEDIUM 5.4
CVE-2017-1424

IBM Business Process Manager 8.5.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the W…

Mitigation only
Fix from $1,600 2017-09-25
Security Siteprotector System HIGH 7.0
CVE-2015-0162

IBM Security SiteProtector System 3.0, 3.1, and 3.1.1 allows local users to gain privileges.

No fix yet
Fix from $1,950 2017-09-20
Curam Social Program Management MEDIUM 5.4
CVE-2014-6191

Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management 6.0 SP2, 6.0.4, and 6.0.5 allows remote attackers to inject arbitrary…

Patch available
Fix from $1,600 2017-09-19
Security Identity Manager HIGH 8.8
CVE-2014-6106

Cross-site request forgery (CSRF) vulnerability in IBM Security Identity Manager 5.1, 6.0, and 7.0 allows remote attackers to hijack the authenticati…

Patch available
Fix from $1,950 2017-09-18
Business Process Manager MEDIUM 6.5
CVE-2015-0110

IBM Business Process Manager (aka BPM) 7.5.x, 8.0.x, and 8.5.x and WebSphere Lombardi Edition (aka WLE) 7.2.x allow remote authenticated users to byp…

Mitigation only
Fix from $1,600 2017-09-15
Jazz Reporting Service MEDIUM 5.3
CVE-2017-1490

An unspecified vulnerability in the Lifecycle Query Engine of Jazz Reporting Service 6.0 through 6.0.4 could disclose highly sensitive information.

Patch available
Fix from $1,600 2017-09-14
Informix Dynamic Server MEDIUM 6.7
CVE-2017-1508

IBM Informix Dynamic Server 12.1 could allow a local user logged in with database administrator user to gain root privileges. IBM X-Force ID: 129620.

Mitigation only
Fix from $1,600 2017-09-13
Api Connect MEDIUM 6.5
CVE-2017-1556

IBM API Connect 5.0.7.0 through 5.0.7.2 is vulnerable to a regular expression attack that could allow an authenticated attacker to use a regex and ca…

Mitigation only
Fix from $1,600 2017-09-13
Db2 HIGH 7.8
CVE-2017-1451

IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user with DB2 instance owner privileg…

Patch available
Fix from $1,950 2017-09-12
Db2 HIGH 7.8
CVE-2017-1452

IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user to obtain elevated privilege and…

Patch available
Fix from $1,950 2017-09-12
Qradar Security Information And Event Manager HIGH 7.5
CVE-2017-1162

IBM QRadar 7.2 and 7.3 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM…

Patch available
Fix from $1,950 2017-09-12