Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Qradar Security Information And Event Manager MEDIUM 6.5
CVE-2016-9750

IBM QRadar 7.2 and 7.3 stores user credentials in plain in clear text which can be read by an authenticated user. IBM X-Force ID: 120207.

Mitigation only
Fix from $1,600 2017-05-15
Interact HIGH 8.8
CVE-2016-5889

IBM Interact 8.6, 9.0, 9.1, and 10.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized …

Patch available
Fix from $1,950 2017-05-10
Rational Team Concert HIGH 8.1
CVE-2017-1103

IBM Team Concert (RTC) is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remot…

Patch available
Fix from $1,950 2017-05-10
Websphere Application Server HIGH 8.1
CVE-2017-1137

IBM WebSphere Application Server 8.0 and 8.5.5 could provide weaker than expected security. A remote attacker could exploit this weakness to obtain s…

Patch available
Fix from $1,950 2017-05-10
Cognos Analytics MEDIUM 5.4
CVE-2016-3032

IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thu…

Mitigation only
Fix from $1,600 2017-05-10
Interact MEDIUM 5.4
CVE-2016-5888

IBM Interact 8.6, 9.0, 9.1, and 10.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the…

Patch available
Fix from $1,600 2017-05-10
Rational Team Concert MEDIUM 5.4
CVE-2016-6035

IBM Rational Quality Manager is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI …

Patch available
Fix from $1,600 2017-05-10
Websphere Portal HIGH 8.8
CVE-2017-1156

IBM WebSphere Portal 8.5 and 9.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to …

Patch available
Fix from $1,950 2017-05-05
Websphere Cast Iron Solution HIGH 8.6
CVE-2016-9691

IBM WebSphere Cast Iron Solution 7.0.0 and 7.5.0.0 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when …

Patch available
Fix from $1,950 2017-05-05
Websphere Cast Iron Solution HIGH 8.6
CVE-2016-9692

IBM WebSphere Cast Iron Solution 7.0.0 and 7.5.0.0 is vulnerable to External Service Interaction attack, caused by improper validation of user-suppli…

Patch available
Fix from $1,950 2017-05-05
Marketing Platform MEDIUM 6.1
CVE-2016-0255

IBM Marketing Platform 9.1 and 10.0 is vulnerable to stored cross-site scripting, caused by improper validation of user-supplied input. A remote atta…

Patch available
Fix from $1,600 2017-05-05
Tivoli Storage Manager MEDIUM 5.5
CVE-2016-8916

IBM Tivoli Storage Manager 5.5, 6.1-6.4, and 7.1 stores password information in a log file that could be read by a local user when a set password com…

Fix: after 6.3
Fix from $1,600 2017-05-05
Maximo Asset Management HIGH 8.4
CVE-2016-9976

IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-craf…

Patch available
Fix from $1,950 2017-05-03
Bigfix Remote Control HIGH 7.5
CVE-2016-2930

IBM BigFix Remote Control 9.1.3 could allow a remote attacker to perform actions reserved for an administrator without authentication. IBM X-Force ID…

Patch available
Fix from $1,950 2017-05-03
Websphere Application Server HIGH 8.8
CVE-2017-1194

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site request forgery which could allow an attacker to execute maliciou…

Patch available
Fix from $1,950 2017-04-28
Bigfix Inventory MEDIUM 5.9
CVE-2016-8962

IBM BigFix Inventory 9.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user …

Fix: after 9.2
Fix from $1,600 2017-04-26
Maximo Asset Management MEDIUM 5.6
CVE-2016-8924

IBM Maximo Asset Management 7.1, 7.5 and 7.6 could allow a remote attacker to hijack a user's session, caused by the failure to invalidate an existin…

Mitigation only
Fix from $1,600 2017-04-26
Websphere Commerce MEDIUM 5.3
CVE-2017-1170

IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 8.0 could allow a local user to hijack a user's session. IBM X-Force ID: 1232…

Patch available
Fix from $1,600 2017-04-26
Domino HIGH 8.8
CVE-2017-1274EPSS 7%

IBM Domino 8.5.3, and 9.0 is vulnerable to a stack based overflow in the IMAP service that could allow an authenticated attacker to execute arbitrary…

No fix yet
Fix from $1,950 2017-04-25
Urbancode Deploy HIGH 8.1
CVE-2017-1149

IBM UrbanCode Deploy (UCD) 6.0, 6.1, and 6.2 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when proces…

Mitigation only
Fix from $1,950 2017-04-25
Change And Configuration Management Database HIGH 8.8
CVE-2015-0104EPSS 7%

IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration Management Database 7.1 through 7.1.1.8 and 7.2 a…

Patch available
Fix from $1,950 2017-04-24
Change And Configuration Management Database MEDIUM 6.5
CVE-2015-0107EPSS 6%

IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration Management Database 7.1 through 7.1.1.8 and 7.2 a…

Mitigation only
Fix from $1,600 2017-04-24
Security Guardium HIGH 7.4
CVE-2017-1122

IBM Security Guardium 8.2, 9.0, and 10.0 contains a vulnerability that could allow a local attacker with CLI access to inject arbitrary commands whic…

Mitigation only
Fix from $1,950 2017-04-20
Curam Social Program Management MEDIUM 5.4
CVE-2016-9979

IBM Curam Social Program Management 5.2, 6.0, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaS…

Patch available
Fix from $1,600 2017-04-20
Curam Social Program Management MEDIUM 5.4
CVE-2016-9980

IBM Curam Social Program Management 5.2, 6.0, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaS…

Patch available
Fix from $1,600 2017-04-20
Cognos Business Intelligence HIGH 7.5
CVE-2016-3036

IBM Cognos TM1 10.1 and 10.2 is vulnerable to a denial of service, caused by a stack-based buffer overflow when parsing packets. A remote attacker co…

Patch available
Fix from $1,950 2017-04-17
Api Connect HIGH 7.3
CVE-2017-1161

IBM API Connect 5.0.6.0 could allow a remote attacker to execute arbitrary commands on the system, caused by improper validation of URLs for the Deve…

Mitigation only
Fix from $1,950 2017-04-17
Cognos Business Intelligence MEDIUM 5.7
CVE-2016-3037

IBM Cognos TM1 10.1 and 10.2 provides a service to return the victim's password with a valid session key. An authenticated attacker with user interac…

Patch available
Fix from $1,600 2017-04-17
Marketing Platform MEDIUM 5.4
CVE-2016-0228

IBM Marketing Platform 10.0 could allow a remote attacker to conduct phishing attacks, caused by an open redirect vulnerability in various scripts. A…

Patch available
Fix from $1,600 2017-04-17
Cognos Business Intelligence MEDIUM 5.4
CVE-2016-3038

IBM Cognos TM1 10.1 and 10.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI …

Patch available
Fix from $1,600 2017-04-17