Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Db2 MEDIUM 6.7
CVE-2017-1438

IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user with DB2 instance owner privileg…

Patch available
Fix from $1,600 2017-09-12
Db2 MEDIUM 6.7
CVE-2017-1439

IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user with DB2 instance owner privileg…

Patch available
Fix from $1,600 2017-09-12
Db2 MEDIUM 5.9
CVE-2017-1519

IBM DB2 10.5 and 11.1 contains a denial of service vulnerability. A remote user can cause disruption of service for DB2 Connect Server setup with a p…

Patch available
Fix from $1,600 2017-09-12
Maximo Asset Management MEDIUM 5.5
CVE-2017-1352

IBM Maximo Asset Management 7.5 and 7.6 could allow an authenticated user to inject commands into work orders that could be executed by another user …

Mitigation only
Fix from $1,600 2017-09-12
Ib6131 Firmware HIGH 8.8
CVE-2014-9565

Cross-site request forgery (CSRF) vulnerability in IBM Flex System EN6131 40Gb Ethernet and IB6131 40Gb Infiniband Switch firmware 3.4.0000 and earli…

Fix: after 3.4.0.0.0.0
Fix from $1,950 2017-09-07
Websphere Portal MEDIUM 6.1
CVE-2017-1189

IBM WebSphere Portal and Web Content Manager 6.1, 7.0, and 8.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitr…

Mitigation only
Fix from $1,600 2017-09-07
Emptoris Supplier Lifecycle Management MEDIUM 5.4
CVE-2017-1098

IBM Emptoris Supplier Lifecycle Management 10.1.0.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScr…

Mitigation only
Fix from $1,600 2017-09-07
Content Navigator MEDIUM 5.4
CVE-2017-1502

IBM Content Navigator & CMIS 2.0.3, 3.0.0, and 3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaSc…

Mitigation only
Fix from $1,600 2017-09-07
Emptoris Strategic Supply Management HIGH 8.8
CVE-2017-1097

IBM Emptoris Strategic Supply Management Platform 10.0.0.x through 10.1.1.x is vulnerable to cross-site request forgery which could allow an attacker…

Mitigation only
Fix from $1,950 2017-09-05
Qradar Network Security HIGH 8.1
CVE-2017-1458

IBM QRadar Network Security 5.4 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could explo…

Mitigation only
Fix from $1,950 2017-09-05
Qradar Network Security HIGH 7.5
CVE-2017-1491

IBM QRadar Network Security 5.4 supports interaction between multiple actors and allows those actors to negotiate which algorithm should be used as a…

Mitigation only
Fix from $1,950 2017-09-05
Inotes MEDIUM 6.5
CVE-2017-1129EPSS 30%

IBM Notes 8.5 and 9.0 is vulnerable to a denial of service. If a user is persuaded to click on a malicious link, it could cause the Notes client to h…

Patch available
Fix from $1,600 2017-09-05
Inotes MEDIUM 6.5
CVE-2017-1130EPSS 29%

IBM Notes 8.5 and 9.0 is vulnerable to a denial of service. If a user is persuaded to click on a malicious link, it would open up many file select di…

Patch available
Fix from $1,600 2017-09-05
Qradar Network Security MEDIUM 6.1
CVE-2017-1457

IBM QRadar Network Security 5.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web …

Mitigation only
Fix from $1,600 2017-09-05
Emptoris Sourcing MEDIUM 6.1
CVE-2017-1450

IBM Emptoris Sourcing 9.5 - 10.1.3 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim t…

Mitigation only
Fix from $1,600 2017-08-31
Emptoris Sourcing MEDIUM 5.4
CVE-2017-1444

IBM Emptoris Sourcing 9.5 - 10.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the W…

Mitigation only
Fix from $1,600 2017-08-31
Emptoris Sourcing MEDIUM 5.4
CVE-2017-1447

IBM Emptoris Sourcing 9.5 - 10.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the W…

Mitigation only
Fix from $1,600 2017-08-31
Emptoris Sourcing MEDIUM 5.4
CVE-2017-1449

IBM Emptoris Sourcing 9.5 - 10.1.3 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim t…

Mitigation only
Fix from $1,600 2017-08-31
Emptoris Services Procurement HIGH 8.8
CVE-2017-1440

IBM Emptoris Services Procurement 10.0.0.5 could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-crafted…

Patch available
Fix from $1,950 2017-08-30
Emptoris Services Procurement HIGH 8.8
CVE-2017-1442

IBM Emptoris Services Procurement 10.0.0.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unautho…

Patch available
Fix from $1,950 2017-08-30
Emptoris Services Procurement MEDIUM 6.1
CVE-2017-1443

IBM Emptoris Services Procurement 10.0.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code …

Patch available
Fix from $1,600 2017-08-30
Emptoris Services Procurement MEDIUM 5.5
CVE-2017-1441

IBM Emptoris Services Procurement 10.0.0.5 could allow a local user to view sensitive information stored locally due to improper access control. IBM …

Patch available
Fix from $1,600 2017-08-30
Emptoris Spend Analysis MEDIUM 5.4
CVE-2017-1445

IBM Emptoris Spend Analysis 9.5.0.0 through 10.1.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScri…

Mitigation only
Fix from $1,600 2017-08-30
Emptoris Spend Analysis MEDIUM 5.4
CVE-2017-1446

IBM Emptoris Spend Analysis 9.5.0.0 through 10.1.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScri…

Mitigation only
Fix from $1,600 2017-08-30
Sametime MEDIUM 6.3
CVE-2016-2980

The Sametime WebPlayer 8.5.2 and 9.0 is vulnerable to a script injection where a malicious site can inject their own script by exploiting a vulnerabi…

Patch available
Fix from $1,600 2017-08-29
Curam Social Program Management MEDIUM 6.1
CVE-2017-1195

IBM Curam Social Program Management 6.0, 6.1, 6.2, and 7.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. …

Patch available
Fix from $1,600 2017-08-29
Cognos Analytics MEDIUM 6.1
CVE-2017-1427

IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thu…

Patch available
Fix from $1,600 2017-08-29
Cognos Analytics MEDIUM 6.1
CVE-2017-1428

IBM Cognos Analytics 11.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web …

Patch available
Fix from $1,600 2017-08-29
Sametime MEDIUM 5.4
CVE-2016-2967

IBM Sametime 8.5.2 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Sametime …

Patch available
Fix from $1,600 2017-08-29
Sametime MEDIUM 5.4
CVE-2016-2975

IBM Sametime 8.5.2 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI th…

Patch available
Fix from $1,600 2017-08-29