Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Financial Transaction Manager MEDIUM 5.4
CVE-2017-1160

IBM Financial Transaction Manager for ACH Services for Multi-Platform 3.0.0.x is vulnerable to cross-site scripting. This vulnerability allows users …

Patch available
Fix from $1,600 2017-04-17
Spectrum Lsf HIGH 8.8
CVE-2017-1205

IBM Platform LSF 10.1 contains an unspecified vulnerability that could allow a local user to escalate their privileges and obtain root access. IBM X-…

Patch available
Fix from $1,950 2017-04-14
Tivoli Application Dependency Discovery Manager MEDIUM 6.5
CVE-2016-8925

IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 could allow a remote attacker to include arbitrary files which could allow the atta…

Patch available
Fix from $1,600 2017-04-14
Tivoli Application Dependency Discovery Manager MEDIUM 5.4
CVE-2016-8927

IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arb…

Patch available
Fix from $1,600 2017-04-14
Disposal And Governance Management For It HIGH 8.8
CVE-2016-6100

IBM Disposal and Governance Management for IT and IBM Global Retention Policy and Schedule Management, components of IBM Atlas Policy Suite 6.0.3 is …

Mitigation only
Fix from $1,950 2017-04-05
Cognos Analytics MEDIUM 5.4
CVE-2016-3015

IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thu…

Patch available
Fix from $1,600 2017-04-05
Cognos Analytics MEDIUM 5.4
CVE-2016-3031

IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thu…

Patch available
Fix from $1,600 2017-04-05
Tririga Application Platform MEDIUM 5.3
CVE-2017-1180

The IBM TRIRIGA Document Manager contains a vulnerability that could allow an authenticated user to execute actions they did not have access to. IBM …

Mitigation only
Fix from $1,600 2017-04-05
Curam Social Program Management CRITICAL 9.1
CVE-2016-6111

IBM Curam Social Program Management 6.0 and 7.0 are vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when pr…

Patch available
Fix from $2,300 2017-03-31
Sterling Selling And Fulfillment Foundation HIGH 8.8
CVE-2016-8917

IBM Sterling Order Management 9.2 - 9.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthoriz…

Patch available
Fix from $1,950 2017-03-31
Rational Rhapsody Design Manager HIGH 8.1
CVE-2016-9707

IBM Jazz Foundation is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote a…

Patch available
Fix from $1,950 2017-03-31
Algo One MEDIUM 6.5
CVE-2017-1154

IBM Algorithmics One-Algo Risk Application 4.9.1, 5.0, and 5.1.0 could allow a user to gain access to files in the local environment which should not…

Patch available
Fix from $1,600 2017-03-31
Inotes MEDIUM 6.1
CVE-2016-9990

IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus a…

Patch available
Fix from $1,600 2017-03-31
Rational Quality Manager MEDIUM 5.4
CVE-2016-6022

IBM Quality Manager (RQM) 4.0, 5.0, and 6.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript cod…

Patch available
Fix from $1,600 2017-03-31
Rational Quality Manager MEDIUM 5.4
CVE-2016-6031

IBM Rational Quality Manager 4.0, 5.0, and 6.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript …

Patch available
Fix from $1,600 2017-03-31
Rational Quality Manager MEDIUM 5.4
CVE-2016-6036

IBM Rational Quality Manager (RQM) 4.0, 5.0, and 6.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaS…

Patch available
Fix from $1,600 2017-03-31
Kenexa Lms MEDIUM 5.4
CVE-2016-8935

IBM Kenexa LMS on Cloud 13.1, 13.2, 13.2.2, 13.2.3, 13.2.4 and 14.0.0 are vulnerable to cross-site scripting. This vulnerability allows users to embe…

Patch available
Fix from $1,600 2017-03-31
Cognos Business Intelligence HIGH 8.8
CVE-2016-8960

IBM Cognos Business Intelligence 10.2 could allow a user with lower privilege Capabilities to adopt the Capabilities of a higher-privilege user by in…

Patch available
Fix from $1,950 2017-03-27
Tririga Application Platform HIGH 8.8
CVE-2017-1153

IBM TRIRIGA Report Manager 3.2 through 3.5 contains a vulnerability that could allow an authenticated user to execute actions that they do not have a…

Patch available
Fix from $1,950 2017-03-27
Kenexa Lcms Premier MEDIUM 6.5
CVE-2017-1142

IBM Kenexa LCMS Premier on Cloud 9.x and 10.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set the secure …

Mitigation only
Fix from $1,600 2017-03-27
Websphere Portal MEDIUM 6.1
CVE-2017-1120

IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web…

Patch available
Fix from $1,600 2017-03-27
Call Center For Commerce MEDIUM 5.4
CVE-2016-6056

IBM Call Center for Commerce 9.3 and 9.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in…

Patch available
Fix from $1,600 2017-03-27
Tririga Application Platform MEDIUM 5.4
CVE-2016-9737

IBM TRIRIGA 3.3, 3.4, and 3.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI…

Patch available
Fix from $1,600 2017-03-27
Kenexa Lcms Premier MEDIUM 5.3
CVE-2017-1143

IBM Kenexa LCMS Premier on Cloud 9.x and 10.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable…

Mitigation only
Fix from $1,600 2017-03-27
Websphere Application Server HIGH 8.1
CVE-2017-1151

IBM WebSphere Application Server 8.0, 8.5, 8.5.5, and 9.0 using OpenID Connect (OIDC) configured with a Trust Association Interceptor (TAI) could all…

Patch available
Fix from $1,950 2017-03-20
Websphere Mq HIGH 8.6
CVE-2017-1145

IBM WebSphere MQ 8.0.0.6 does not properly terminate channel agents when they are no longer needed, which could allow a user to cause a denial of ser…

Patch available
Fix from $1,950 2017-03-20
Power Hardware Management Console HIGH 7.8
CVE-2017-1134

IBM Reliable Scalable Cluster Technology could allow a local user to escalate their privileges to gain root access. IBM Reference #: 1998459.

Patch available
Fix from $1,950 2017-03-20
Rational Collaborative Lifecycle Management MEDIUM 6.8
CVE-2016-2981

An undisclosed vulnerability in the CLM applications in IBM Jazz Team Server may allow unauthorized access to user credentials. IBM Reference #: 1999…

Patch available
Fix from $1,600 2017-03-20
Rational Rhapsody Design Manager MEDIUM 5.4
CVE-2016-9694

IBM Rhapsody DM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the We…

Patch available
Fix from $1,600 2017-03-20
Rational Rhapsody Design Manager MEDIUM 5.4
CVE-2016-9696

IBM Rhapsody DM 4.0, 5.0, and 6.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be ex…

Patch available
Fix from $1,600 2017-03-20