Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Websphere Mq MEDIUM 6.5
CVE-2016-8915

IBM WebSphere MQ 8.0 could allow an authenticated user with access to the queue manager and queue, to deny service to other channels running under th…

Patch available
Fix from $1,600 2017-02-22
Websphere Mq MEDIUM 6.5
CVE-2016-8986

IBM WebSphere MQ 8.0 could allow an authenticated user with access to the queue manager to bring down MQ channels using specially crafted HTTP reques…

Patch available
Fix from $1,600 2017-02-22
Websphere Mq MEDIUM 5.9
CVE-2016-3052

Under non-standard configurations, IBM WebSphere MQ might send password data in clear text over the network. This data could be intercepted using man…

Fix: after 8.0.0.5
Fix from $1,600 2017-02-22
Security Access Manager For Web 7.0 Firmware HIGH 7.5
CVE-2016-5919

IBM Security Access Manager for Web 7.0.0, 8.0.0, and 9.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decryp…

Patch available
Fix from $1,950 2017-02-16
Resilient MEDIUM 6.1
CVE-2016-6062

IBM Resilient v26.0, v26.1, and v26.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in th…

Mitigation only
Fix from $1,600 2017-02-16
Integration Bus CRITICAL 9.1
CVE-2016-9706

IBM Integration Bus 9.0 and 10.0 and WebSphere Message Broker SOAP FLOWS is vulnerable to a denial of service, caused by an XML External Entity Injec…

Patch available
Fix from $2,300 2017-02-15
Aix HIGH 7.8
CVE-2016-8972

IBM AIX 6.1, 7.1, and 7.2 could allow a local user to gain root privileges using a specially crafted command within the bellmail client. IBM APARs: I…

Patch available
Fix from $1,950 2017-02-15
Integration Bus MEDIUM 6.1
CVE-2016-9010

IBM WebSphere Message Broker 9.0 and 10.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit …

Patch available
Fix from $1,600 2017-02-15
Aix MEDIUM 5.5
CVE-2016-8944

IBM AIX 7.1 and 7.2 allows a local user to open a file with a specially crafted argument that would crash the system. IBM APARs: IV91488, IV91487, IV…

Patch available
Fix from $1,600 2017-02-15
Rational Collaborative Lifecycle Management MEDIUM 5.4
CVE-2016-8968

IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alte…

Patch available
Fix from $1,600 2017-02-15
Websphere Mq Jms CRITICAL 9.8
CVE-2016-0360

IBM Websphere MQ JMS 7.0.1, 7.1, 7.5, 8.0, and 9.0 client provides classes that deserialize objects from untrusted sources which could allow a malici…

Mitigation only
Fix from $2,300 2017-02-15
Tivoli Storage Manager For Virtual Environments Data Protection For Vmware HIGH 8.8
CVE-2016-6033

IBM Tivoli Storage Manager for Virtual Environments 7.1 (VMware) is vulnerable to cross-site request forgery which could allow an attacker to execute…

Patch available
Fix from $1,950 2017-02-15
Aix HIGH 7.8
CVE-2016-6079

IBM AIX 5.3, 6.1, 7.1, and 7.2 contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges. I…

Patch available
Fix from $1,950 2017-02-15
Cognos Disclosure Management MEDIUM 5.3
CVE-2016-6077

IBM Cognos Disclosure Management 10.2 could allow a malicious attacker to execute commands as a lower privileged user that opens a malicious document…

Patch available
Fix from $1,600 2017-02-15
Websphere Application Server MEDIUM 5.4
CVE-2017-1121

IBM WebSphere Application Server 7.0, 8.0, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScri…

Patch available
Fix from $1,600 2017-02-13
Dashdb Local CRITICAL 9.8
CVE-2016-8954

IBM dashDB Local uses hard-coded credentials that could allow a remote attacker to gain access to the Docker container or database.

Patch available
Fix from $2,300 2017-02-08
System Storage Ts3100 Ts3200 Tape Library CRITICAL 9.8
CVE-2016-9005

IBM System Storage TS3100-TS3200 Tape Library could allow an unauthenticated user with access to the company network, to change a user's password and…

Mitigation only
Fix from $2,300 2017-02-08
Bigfix Platform HIGH 7.8
CVE-2016-0214

IBM Tivoli Endpoint Manager could allow a remote attacker to upload arbitrary files. A remote attacker could exploit this vulnerability to upload a m…

Patch available
Fix from $1,950 2017-02-08
Tivoli Storage Manager Fastback HIGH 7.3
CVE-2016-5934

IBM Tivoli Storage Manager FastBack installer could allow a remote attacker to execute arbitrary code on the system. By placing a specially-crafted D…

Mitigation only
Fix from $1,950 2017-02-08
Maximo Asset Management MEDIUM 6.1
CVE-2016-5902

IBM Maximo Asset Management is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI t…

Patch available
Fix from $1,600 2017-02-08
Tealeaf Customer Experience On Cloud Network Capture Add On MEDIUM 5.9
CVE-2016-5900

IBM Tealeaf Customer Experience on Cloud Network Capture Add-On could allow a remote attacker to obtain sensitive information, caused by the failure …

Patch available
Fix from $1,600 2017-02-08
Security Directory Server MEDIUM 5.5
CVE-2015-1976

IBM Security Directory Server could allow an authenticated user to execute commands into the web administration tool that would cause the tool to cra…

Fix: after 6.4.0.6
Fix from $1,600 2017-02-08
Cloud Orchestrator MEDIUM 5.5
CVE-2016-0203

A vulnerability has been identified in the IBM Cloud Orchestrator task API. The task API might allow an authenticated user to view background informa…

Patch available
Fix from $1,600 2017-02-08
Connections MEDIUM 5.4
CVE-2016-0305

IBM Connections is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vul…

Patch available
Fix from $1,600 2017-02-08
Connections MEDIUM 5.4
CVE-2016-0310

IBM Connections 5.5 and earlier is vulnerable to possible host header injection attack that could cause navigation to the attacker's domain.

Patch available
Fix from $1,600 2017-02-08
Sterling B2b Integrator MEDIUM 5.3
CVE-2016-0210

IBM Sterling B2B Integrator Standard Edition could allow a remote attacker to obtain sensitive information. By allowing HTTP OPTIONS method, a remote…

Patch available
Fix from $1,600 2017-02-08
Security Access Manager For Web 8.0 Firmware MEDIUM 5.5
CVE-2015-5013

The IBM Security Access Manager appliance includes configuration files that contain obfuscated plaintext-passwords which authenticated users can acce…

Patch available
Fix from $1,600 2017-02-08
Rational Collaborative Lifecycle Management MEDIUM 5.4
CVE-2016-6032

IBM Rational Team Concert 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code …

Patch available
Fix from $1,600 2017-02-08
Rational Doors Next Generation MEDIUM 5.4
CVE-2017-1127

IBM Rational DOORS Next Generation 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScr…

Patch available
Fix from $1,600 2017-02-08
Rational Doors Next Generation MEDIUM 5.4
CVE-2017-1128

IBM Rational DOORS Next Generation 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaSc…

Patch available
Fix from $1,600 2017-02-08