Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Client Application Access MEDIUM 5.9
CVE-2016-0270

IBM Domino 9.0.1 Fix Pack 3 Interim Fix 2 through 9.0.1 Fix Pack 5 Interim Fix 1, when using TLS and AES GCM, uses random nonce generation, which mak…

Patch available
Fix from $1,600 2017-02-08
Security Key Lifecycle Manager HIGH 7.2
CVE-2016-6104

IBM Tivoli Key Lifecycle Manager 2.5, and 2.6 could allow a remote attacker to upload arbitrary files, caused by the improper validation of file exte…

Patch available
Fix from $1,950 2017-02-07
Security Key Lifecycle Manager MEDIUM 6.2
CVE-2016-6092

IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 stores user credentials in plain in clear text which can be read by a local user.

Patch available
Fix from $1,600 2017-02-07
Security Key Lifecycle Manager MEDIUM 6.1
CVE-2016-6096

IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaSc…

Patch available
Fix from $1,600 2017-02-07
Security Access Manager For Web 7.0 Firmware MEDIUM 5.5
CVE-2016-3020

IBM Security Access Manager for Web 7.0.0, 8.0.0, and 9.0.0 could allow a remote attacker to bypass security restrictions, caused by improper content…

Patch available
Fix from $1,600 2017-02-07
Security Key Lifecycle Manager CRITICAL 9.8
CVE-2016-6095

IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 uses an inadequate account lockout setting that could allow a remote attacker to brute force account cre…

Patch available
Fix from $2,300 2017-02-02
Security Key Lifecycle Manager HIGH 8.8
CVE-2016-6103

IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unaut…

Patch available
Fix from $1,950 2017-02-02
Aix HIGH 7.8
CVE-2017-1093

IBM AIX 6.1, 7.1, and 7.2 could allow a local user to exploit a vulnerability in the bellmail binary to gain root privileges.

Mitigation only
Fix from $1,950 2017-02-02
Dashboard Application Services Hub MEDIUM 5.9
CVE-2016-5935

IBM Jazz for Service Management could allow a remote attacker to obtain sensitive information, caused by the failure to properly validate the SSL cer…

Mitigation only
Fix from $1,600 2017-02-02
Security Key Lifecycle Manager MEDIUM 5.9
CVE-2016-6116

IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable …

Patch available
Fix from $1,600 2017-02-02
Security Key Lifecycle Manager MEDIUM 5.3
CVE-2016-6099

IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 discloses sensitive information to unauthorized users. The information can be used to mount further atta…

Patch available
Fix from $1,600 2017-02-02
Security Identity Manager HIGH 7.8
CVE-2016-9739

IBM Security Identity Manager Virtual Appliance stores user credentials in plain in clear text which can be read by a local user.

Patch available
Fix from $1,950 2017-02-01
Urbancode Deploy HIGH 7.5
CVE-2016-9008

IBM UrbanCode Deploy could allow a malicious user to access the Agent Relay ActiveMQ Broker JMX interface and run plugins on the agent.

Patch available
Fix from $1,950 2017-02-01
Infosphere Datastage MEDIUM 6.1
CVE-2016-9000

IBM InfoSphere DataStage is vulnerable to cross-frame scripting, caused by insufficient HTML iframe protection. A remote attacker could exploit this …

Patch available
Fix from $1,600 2017-02-01
Security Identity Manager Virtual Appliance MEDIUM 6.1
CVE-2016-9704

IBM Security Identity Manager Virtual Appliance is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript …

Patch available
Fix from $1,600 2017-02-01
Infosphere Datastage MEDIUM 5.4
CVE-2016-8999

IBM InfoSphere Information Server contains a Path-relative stylesheet import vulnerability that allows attackers to render a page in quirks mode ther…

Patch available
Fix from $1,600 2017-02-01
License Metric Tool MEDIUM 5.3
CVE-2016-8977

IBM BigFix Inventory v9 could disclose sensitive information to an unauthorized user using HTTP GET requests. This information could be used to mount…

Mitigation only
Fix from $1,600 2017-02-01
Infosphere Datastage MEDIUM 5.3
CVE-2016-8982

IBM InfoSphere Information Server stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties hav…

Patch available
Fix from $1,600 2017-02-01
Urbancode Deploy CRITICAL 10.0
CVE-2016-8938

IBM UrbanCode Deploy could allow a user to execute code using a specially crafted file upload that would replace code on the server. This code could …

Patch available
Fix from $2,300 2017-02-01
Kenexa Lms HIGH 8.8
CVE-2016-8931

IBM Kenexa LMS on Cloud could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vuln…

Patch available
Fix from $1,950 2017-02-01
Kenexa Lms HIGH 8.8
CVE-2016-8932

IBM Kenexa LMS on Cloud could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vuln…

Patch available
Fix from $1,950 2017-02-01
Kenexa Lms HIGH 7.6
CVE-2016-8928

IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker…

Patch available
Fix from $1,950 2017-02-01
Kenexa Lms HIGH 7.6
CVE-2016-8930

IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker…

Patch available
Fix from $1,950 2017-02-01
Urbancode Deploy HIGH 7.5
CVE-2016-2942

IBM UrbanCode Deploy could allow an authenticated attacker with special permissions to craft a script on the server in a way that will cause processe…

Patch available
Fix from $1,950 2017-02-01
Urbancode Deploy HIGH 7.5
CVE-2016-6068

IBM UrbanCode Deploy could allow an authenticated user with access to the REST endpoints to access API and CLI getResource secured role properties.

Patch available
Fix from $1,950 2017-02-01
Websphere Application Server HIGH 7.5
CVE-2016-8919

IBM WebSphere Application Server may be vulnerable to a denial of service, caused by allowing serialized objects from untrusted sources to run and ca…

Patch available
Fix from $1,950 2017-02-01
General Parallel File System HIGH 7.2
CVE-2016-6115

IBM General Parallel File System is vulnerable to a buffer overflow. A remote authenticated attacker could overflow a buffer and execute arbitrary co…

Patch available
Fix from $1,950 2017-02-01
Tivoli Storage Manager For Virtual Environments Data Protection For Vmware MEDIUM 6.5
CVE-2016-6110

IBM Tivoli Storage Manager discloses unencrypted login credentials to Vmware vCenter that could be obtained by a local user.

Fix: after 7.1.6.3
Fix from $1,600 2017-02-01
Kenexa Lms MEDIUM 6.5
CVE-2016-8933

IBM Kenexa LMS on Cloud could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request c…

Patch available
Fix from $1,600 2017-02-01
Inotes MEDIUM 6.1
CVE-2016-5881

IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the …

Mitigation only
Fix from $1,600 2017-02-01