Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

1g L2 7 Slb HIGH 8.2
CVE-2017-3752

An industry-wide vulnerability has been identified in the implementation of the Open Shortest Path First (OSPF) routing protocol used on some Lenovo …

Fix: after 21.0.24.0
Fix from $1,950 2017-08-09
Emptoris Strategic Supply Management MEDIUM 5.4
CVE-2016-6121

IBM Emptoris Supplier Lifecycle Management 10.0.x and 10.1.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar…

Mitigation only
Fix from $1,600 2017-08-09
Emptoris Strategic Supply Management MEDIUM 5.4
CVE-2016-8949

IBM Emptoris Supplier Lifecycle Management 10.0.x and 10.1.x could allow a remote attacker to conduct phishing attacks, using an open redirect attack…

Mitigation only
Fix from $1,600 2017-08-09
Emptoris Strategic Supply Management MEDIUM 5.4
CVE-2017-1448

IBM Emptoris Supplier Lifecycle Management 10.0.x and 10.1.x could allow a remote attacker to conduct phishing attacks, using an open redirect attack…

Mitigation only
Fix from $1,600 2017-08-09
Content Navigator MEDIUM 5.4
CVE-2017-1331

IBM Content Navigator 2.0.3 and 3.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in th…

Patch available
Fix from $1,600 2017-08-04
Websphere Application Server MEDIUM 6.5
CVE-2017-1504

IBM WebSphere Application Server version 9.0.0.4 could provide weaker than expected security after using the PasswordUtil command to enable AES passw…

Mitigation only
Fix from $1,600 2017-08-03
Inotes MEDIUM 6.1
CVE-2017-1327

IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus a…

Patch available
Fix from $1,600 2017-08-03
Infosphere Master Data Management Server MEDIUM 5.4
CVE-2017-1199

IBM InfoSphere Master Data Management Server 10.0, 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site scripting. This vulnerability allows …

Patch available
Fix from $1,600 2017-08-03
Curam Social Program Management HIGH 8.8
CVE-2014-8903

IBM Curam Social Program Management 6.0 SP2 before EP26, 6.0.4 before 6.0.4.5iFix10 and 6.0.5 before 6.0.5.6 allows remote authenticated users to loa…

Mitigation only
Fix from $1,950 2017-08-02
Sterling B2b Integrator MEDIUM 6.5
CVE-2015-0194

XML External Entity (XXE) vulnerability in IBM Sterling B2B Integrator 5.1 and 5.2 and IBM Sterling File Gateway 2.1 and 2.2 allows remote attackers …

Patch available
Fix from $1,600 2017-08-02
Infosphere Information Server CRITICAL 9.1
CVE-2017-1383

IBM InfoSphere Information Server 9.1, 11.3, and 11.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remot…

Mitigation only
Fix from $2,300 2017-08-02
Security Appscan HIGH 8.1
CVE-2016-9981

IBM AppScan Enterprise Edition 9.0 contains an unspecified vulnerability that could allow an attacker to hijack a valid user's session. IBM X-Force I…

Patch available
Fix from $1,950 2017-08-02
Infosphere Information Server HIGH 8.1
CVE-2017-1467

A network layer security vulnerability in InfoSphere Information Server 9.1, 11.3, and 11.5 can lead to privilege escalation or unauthorized access. …

Mitigation only
Fix from $1,950 2017-08-02
Infosphere Information Server HIGH 7.8
CVE-2017-1468

IBM InfoSphere Information Server 9.1, 11.3, and 11.5 could allow a local user to gain elevated privileges by placing arbitrary files in installation…

Mitigation only
Fix from $1,950 2017-08-02
Websphere Mq Internet Pass Thru HIGH 7.5
CVE-2017-1118

IBM WebSphere MQ Internet Pass-Thru 2.0 and 2.1 could allow n attacker to cause the MQIPT to stop responding due to an incorrectly configured securit…

Patch available
Fix from $1,950 2017-08-02
Mobilefirst Platform Foundation MEDIUM 6.1
CVE-2017-1500

A Reflected Cross Site Scripting (XSS) vulnerability exists in the authorization function exposed by RESTful Web Api of IBM Worklight Framework 6.1, …

Mitigation only
Fix from $1,600 2017-08-01
Infosphere Master Data Management Server HIGH 8.8
CVE-2016-9714

IBM InfoSphere Master Data Management Server 10.1, 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site request forgery which could allow an …

Patch available
Fix from $1,950 2017-07-31
Infosphere Master Data Management Server HIGH 8.8
CVE-2016-9716

IBM InfoSphere Master Data Management Server 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site request forgery which could allow an attack…

Patch available
Fix from $1,950 2017-07-31
Bigfix Platform HIGH 7.5
CVE-2017-1227

IBM Tivoli Endpoint Manager could allow a unauthorized user to consume all resources and crash the system. IBM X-Force ID: 123906.

Patch available
Fix from $1,950 2017-07-31
I HIGH 7.5
CVE-2017-1460

IBM i OSPF 6.1, 7.1, 7.2, and 7.3 is vulnerable when a rogue router spoofs its origin. Routing tables are affected by a missing LSA, which may lead t…

Mitigation only
Fix from $1,950 2017-07-31
Infosphere Master Data Management Server MEDIUM 6.5
CVE-2016-9717

HTTP Parameter Override is identified in the IBM Infosphere Master Data Management (MDM) 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 product. It enables a…

Patch available
Fix from $1,600 2017-07-31
Websphere Portal MEDIUM 6.1
CVE-2017-1303

IBM WebSphere Portal and Web Content Manager 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed a…

Patch available
Fix from $1,600 2017-07-31
Inotes MEDIUM 6.1
CVE-2017-1332

IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus a…

Mitigation only
Fix from $1,600 2017-07-31
Api Connect MEDIUM 5.9
CVE-2017-1386

IBM API Connect 5.0.0.0 could allow a user to bypass policy restrictions and create non-compliant passwords which could be intercepted and decrypted …

Mitigation only
Fix from $1,600 2017-07-31
Infosphere Master Data Management Server MEDIUM 5.7
CVE-2016-9719

IBM InfoSphere Master Data Management Server 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 could allow a remote attacker to hijack the clicking action of th…

Patch available
Fix from $1,600 2017-07-31
Infosphere Master Data Management Server MEDIUM 5.4
CVE-2016-9715

IBM InfoSphere Master Data Management Server 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site scripting. This vulnerability allows users …

Patch available
Fix from $1,600 2017-07-31
Infosphere Master Data Management Server MEDIUM 5.4
CVE-2016-9718

IBM InfoSphere Master Data Management Server 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site scripting. This vulnerability allows …

Patch available
Fix from $1,600 2017-07-31
Sterling B2b Integrator MEDIUM 5.4
CVE-2017-1496

IBM Sterling B2B Integrator Standard Edition 5.2.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScri…

Mitigation only
Fix from $1,600 2017-07-31
Websphere Application Server HIGH 7.1
CVE-2017-1382

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 might create files using the default permissions instead of the customized permissions when c…

Fix: after 9.0.0.4
Fix from $1,950 2017-07-24
Emptoris Strategic Supply Management MEDIUM 5.4
CVE-2016-6118

IBM Emptoris Supplier Lifecycle Management 10.1.0.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScr…

Patch available
Fix from $1,600 2017-07-24