Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cognos Analytics MEDIUM 5.4
CVE-2017-1485

IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thu…

Patch available
Fix from $1,600 2017-08-29
Cognos Analytics MEDIUM 5.4
CVE-2017-1535

IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thu…

Patch available
Fix from $1,600 2017-08-29
Sametime MEDIUM 5.3
CVE-2016-2964

IBM Sametime 8.5.2 and 9.0 under certain conditions provides an error message to a user that is too detailed and may reveal details about the applica…

Patch available
Fix from $1,600 2017-08-29
Sametime HIGH 7.8
CVE-2016-2972

IBM Sametime Meeting Server 8.5.2 and 9.0 could store credentials of the Sametime Meetings user in the local cache of their browser which could be ac…

Patch available
Fix from $1,950 2017-08-29
Sametime MEDIUM 6.5
CVE-2016-0355

IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user that has been invited to a Sametime meeting room, to cause the…

Patch available
Fix from $1,600 2017-08-29
Sametime MEDIUM 6.5
CVE-2016-0356

IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user that has been invited to a Sametime meeting room, to cause the…

Patch available
Fix from $1,600 2017-08-29
Sametime MEDIUM 6.5
CVE-2016-2965

IBM Sametime Meeting Server 8.5.2 and 9.0 is vulnerable to cross-site request forgery, caused by improper validation of user-supplied input. By persu…

Patch available
Fix from $1,600 2017-08-29
Sametime MEDIUM 5.5
CVE-2016-0354

IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user to upload a malicious file to a Sametime meeting room, that co…

Patch available
Fix from $1,600 2017-08-29
Sametime MEDIUM 5.4
CVE-2016-2973

IBM Sametime Media Services 8.5.2 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code i…

Patch available
Fix from $1,600 2017-08-29
Sametime MEDIUM 5.4
CVE-2016-2979

IBM Sametime Meeting Server 8.5.2 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code i…

Patch available
Fix from $1,600 2017-08-29
Sametime MEDIUM 5.3
CVE-2016-2971

IBM Sametime Media Services 8.5.2 and 9.0 can disclose sensitive information in stack trace error logs that could aid an attacker in future attacks. …

Mitigation only
Fix from $1,600 2017-08-29
Operations Analytics Predictive Insights CRITICAL 9.8
CVE-2017-1376

A flaw in the IBM J9 VM class verifier allows untrusted code to disable the security manager and elevate its privileges. IBM X-Force ID: 126873.

Mitigation only
Fix from $2,300 2017-08-29
Curam Social Program Management MEDIUM 6.5
CVE-2017-1110

IBM Curam Social Program Management 6.0, 6.1, 6.2, and 7.0 contains an unspecified vulnerability that could allow an authenticated user to view the i…

Patch available
Fix from $1,600 2017-08-29
Tivoli Access Manager For E Business MEDIUM 6.1
CVE-2017-1489

IBM Security Access Manager 6.1, 7.0, 8.0, and 9.0 e-community configurations may be affected by a redirect vulnerability. ECSSO Master Authenticatio…

Mitigation only
Fix from $1,600 2017-08-29
Curam Social Program Management MEDIUM 5.4
CVE-2016-9732

IBM Curam Social Program Management 6.0, 6.1, 6.2 and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary J…

Patch available
Fix from $1,600 2017-08-29
Urbancode Deploy HIGH 8.8
CVE-2014-8900

Cross-site request forgery (CSRF) vulnerability in IBM UrbanCode Release 6.0.1.6 and earlier, 6.1.0.7 and earlier, and 6.1.1.1 and earlier.

Fix: after 6.1.1.1
Fix from $1,950 2017-08-28
I Access For Windows HIGH 7.8
CVE-2015-0114

Stack-based buffer overflow in IBM V5R4, and IBM i Access for Windows 6.1 and 7.1.

Patch available
Fix from $1,950 2017-08-28
Business Process Manager MEDIUM 6.1
CVE-2015-0101

Cross-site scripting (XSS) vulnerability in IBM Business Process Manager Standard 7.5.x before 7.5, 8.0.x before 8.0.1, 8.5.x before 8.5.5; IBM Busin…

Mitigation only
Fix from $1,600 2017-08-28
Ib6131 Firmware MEDIUM 6.1
CVE-2014-9564

CRLF injection vulnerability in IBM Flex System EN6131 40Gb Ethernet and IB6131 40Gb Infiniband Switch firmware before 3.4.1110 allows remote attacke…

Mitigation only
Fix from $1,600 2017-08-25
Security Network Protection 4100 Firmware MEDIUM 6.1
CVE-2014-6189

Cross-site scripting (XSS) vulnerability in IBM Security Network Protection 3100, 4100, 5100, and 7100 devices with firmware 5.2 before 5.2.0.0-ISS-X…

Mitigation only
Fix from $1,600 2017-08-22
Websphere Application Server MEDIUM 5.9
CVE-2017-1501

IBM WebSphere Application Server 8.0, 8.5, and 9.0 could provide weaker than expected security after using the Admin Console to update the web servic…

Patch available
Fix from $1,600 2017-08-18
Rational Doors Next Generation MEDIUM 5.4
CVE-2017-1338

IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaS…

Patch available
Fix from $1,600 2017-08-18
Infosphere Information Server HIGH 7.8
CVE-2017-1469

IBM InfoSphere Information Server 9.1, 11.3, and 11.5 could allow a local user to gain elevated privileges by placing arbitrary files in installation…

Mitigation only
Fix from $1,950 2017-08-14
Emptoris Strategic Supply Management MEDIUM 6.4
CVE-2017-1190

IBM Emptoris Strategic Supply Management Platform 10.x and 10.1 could allow a local user with special access roles to execute arbitrary code on the s…

Patch available
Fix from $1,600 2017-08-14
Emptoris Strategic Supply Management MEDIUM 5.9
CVE-2016-6029

IBM Emptoris Strategic Supply Management Platform 10.0 and 10.1 could allow a remote attacker to obtain sensitive information, caused by the failure …

Patch available
Fix from $1,600 2017-08-14
Emptoris Strategic Supply Management MEDIUM 5.4
CVE-2016-6021

IBM Emptoris Strategic Supply Management Platform 10.0 and 10.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbit…

Patch available
Fix from $1,600 2017-08-14
Sterling B2b Integrator HIGH 8.8
CVE-2017-1174

IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which…

Mitigation only
Fix from $1,950 2017-08-10
Sterling B2b Integrator HIGH 8.2
CVE-2017-1192

IBM Sterling B2B Integrator 5.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could expl…

Mitigation only
Fix from $1,950 2017-08-10
Rational Engineering Lifecycle Manager MEDIUM 5.4
CVE-2017-1168

IBM Rational Engineering Lifecycle Manager 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar…

Patch available
Fix from $1,600 2017-08-10
Infosphere Streams MEDIUM 5.4
CVE-2017-1431

IBM InfoSphere Streams 4.0, 4.1, and 4.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in…

Patch available
Fix from $1,600 2017-08-10