Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Security Key Lifecycle Manager CRITICAL 9.8
CVE-2016-6093

IBM Tivoli Key Lifecycle Manager does not require that users should have strong passwords by default, which makes it easier for attackers to compromi…

Patch available
Fix from $2,300 2017-06-08
Security Key Lifecycle Manager HIGH 8.1
CVE-2016-6098

IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 specifies permissions for a security-critical resource in a way that allows that resource to be …

Patch available
Fix from $1,950 2017-06-08
Rational Rhapsody Design Manager HIGH 8.1
CVE-2016-9698

IBM Rhapsody DM 4.0, 5.0, and 6.0 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML da…

Patch available
Fix from $1,950 2017-06-08
Sterling Selling And Fulfillment Foundation HIGH 8.0
CVE-2016-9991

IBM Sterling Order Management 9.2 through 9.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unau…

Patch available
Fix from $1,950 2017-06-08
Tivoli Federated Identity Manager HIGH 7.5
CVE-2017-1319

IBM Tivoli Federated Identity Manager 6.2 is affected by a vulnerability due to a missing secure attribute in encrypted session (SSL) cookie. IBM X-F…

Patch available
Fix from $1,950 2017-06-08
Bigfix Security Compliance Analytics MEDIUM 5.9
CVE-2017-1179

IBM BigFix Compliance Analytics 1.9.79 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive in…

Patch available
Fix from $1,600 2017-06-08
Business Process Manager MEDIUM 5.4
CVE-2017-1140

IBM Business Process Manager 8.0 and 8.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code i…

Patch available
Fix from $1,600 2017-06-08
Websphere Application Server MEDIUM 5.3
CVE-2016-9736

IBM WebSphere Application Server using malformed SOAP requests could allow a remote attacker to obtain sensitive information.

Patch available
Fix from $1,600 2017-06-08
Curam Social Program Management MEDIUM 5.3
CVE-2014-4843

Curam Universal Access in IBM Curam Social Program Management (SPM) 6.0 SP2 before EP26, 6.0.4 before 6.0.4.6, and 6.0.5 before 6.0.5.5 iFix5 allows …

Mitigation only
Fix from $1,600 2017-06-08
Domino CRITICAL 9.8
CVE-2016-6087

IBM Domino 8.5 and 9.0 could allow an attacker to steal credentials using multiple sessions and large amounts of data using Domino TLS Key Exchange v…

Patch available
Fix from $2,300 2017-06-07
Bigfix Security Compliance Analytics CRITICAL 9.8
CVE-2017-1196

IBM BigFix Compliance (TEMA SUAv1 SCA SCM) 1.9.70 does not require that users should have strong passwords by default, which makes it easier for atta…

Mitigation only
Fix from $2,300 2017-06-07
Maximo Asset Management HIGH 8.8
CVE-2016-9977

IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a remote attacker to hijack a user's session, caused by the failure to invalidate an existi…

Patch available
Fix from $1,950 2017-06-07
Cognos Business Intelligence MEDIUM 6.5
CVE-2016-0254

IBM Cognos Business Intelligence 10.1 and 10.2 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when proc…

Patch available
Fix from $1,600 2017-06-07
Security Access Manager 9.0 Firmware MEDIUM 6.5
CVE-2016-3019

IBM Security Access Manager for Web 9.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive…

Patch available
Fix from $1,600 2017-06-07
Bigfix Security Compliance Analytics MEDIUM 6.1
CVE-2017-1178

IBM Endpoint Manager for Security and Compliance 1.9.70 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav…

Mitigation only
Fix from $1,600 2017-06-07
Security Privileged Identity Manager MEDIUM 5.5
CVE-2016-5960

IBM Security Privileged Identity Manager 2.0.2 and 2.1.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Forc…

Mitigation only
Fix from $1,600 2017-06-07
Websphere Mq MEDIUM 5.5
CVE-2016-6089

IBM WebSphere MQ 9.0.0.1 and 9.0.2 could allow a local user to write to a file or delete files in a directory they should not have access to due to i…

Patch available
Fix from $1,600 2017-06-07
Tivoli Storage Manager MEDIUM 5.5
CVE-2016-8939

IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) clients/agents store password information in the Windows Registry in a manner which can…

Mitigation only
Fix from $1,600 2017-06-07
Rational Doors Next Generation MEDIUM 5.4
CVE-2017-1305

IBM DOORS Next Generation (DNG/RRC) 6.0.2 and 6.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScr…

Patch available
Fix from $1,600 2017-06-07
Security Privileged Identity Manager MEDIUM 5.3
CVE-2016-5959

IBM Security Privileged Identity Manager 2.0.2 and 2.1.0 stores sensitive information in URL parameters. This may lead to information disclosure if u…

Patch available
Fix from $1,600 2017-06-07
Cognos Business Intelligence Server MEDIUM 5.3
CVE-2016-9710

IBM Predictive Solutions Foundation (formerly PMQ) could allow a remote attacker to include arbitrary files. A remote attacker could send a specially…

Patch available
Fix from $1,600 2017-06-07
Inotes MEDIUM 6.1
CVE-2017-1325

IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus a…

Patch available
Fix from $1,600 2017-05-26
Maximo Asset Management MEDIUM 5.4
CVE-2017-1291

IBM Maximo Asset Management 7.5 and 7.6 is vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using sp…

Patch available
Fix from $1,600 2017-05-26
Maximo Asset Management MEDIUM 5.3
CVE-2017-1292

IBM Maximo Asset Management 7.5 and 7.6 generates error messages that could reveal sensitive information that could be used in further attacks agains…

Patch available
Fix from $1,600 2017-05-26
Informix Open Admin Tool CRITICAL 9.8
CVE-2017-1092EPSS 76%

IBM Informix Open Admin Tool 11.5, 11.7, and 12.1 could allow an unauthorized user to execute arbitrary code as system admin on Windows servers. IBM …

Patch available
Fix from $2,300 2017-05-22
Marketing Platform HIGH 8.8
CVE-2016-6112

IBM Distributed Marketing and Marketing Platform 8.6, 9.0, 9.1, and 10.0 could allow an authenticated user to escalate their privileges and gain admi…

Mitigation only
Fix from $1,950 2017-05-22
Sdk HIGH 8.2
CVE-2017-1289

IBM SDK, Java Technology Edition is vulnerable XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit th…

Fix: after 8
Fix from $1,950 2017-05-22
Business Process Manager MEDIUM 5.4
CVE-2017-1159

IBM Business Process Manager 8.0 and 8.5 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a vi…

Patch available
Fix from $1,600 2017-05-22
Content Navigator MEDIUM 5.4
CVE-2017-1282

IBM Content Navigator & CMIS 2.0 and 3.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in…

Patch available
Fix from $1,600 2017-05-22
Tivoli Federated Identity Manager MEDIUM 5.4
CVE-2017-1320

IBM Tivoli Federated Identity Manager 6.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code i…

Patch available
Fix from $1,600 2017-05-22