Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Kenexa Lms MEDIUM 5.7
CVE-2016-5941

IBM Kenexa LMS on Cloud could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request c…

Patch available
Fix from $1,600 2017-02-01
Urbancode Deploy MEDIUM 5.5
CVE-2016-2941

IBM UrbanCode Deploy creates temporary files during step execution that could contain sensitive information including passwords that could be read by…

Mitigation only
Fix from $1,600 2017-02-01
License Metric Tool MEDIUM 5.5
CVE-2016-8963

IBM BigFix Inventory v9 stores potentially sensitive information in log files that could be read by a local user.

Fix: after 9.2
Fix from $1,600 2017-02-01
Cognos Analytics MEDIUM 5.4
CVE-2016-0217

IBM Cognos Business Intelligence and IBM Cognos Analytics are vulnerable to stored cross-site scripting, caused by improper validation of user-suppli…

Patch available
Fix from $1,600 2017-02-01
Cognos Business Intelligence MEDIUM 5.4
CVE-2016-0218

IBM Cognos Business Intelligence and IBM Cognos Analytics are vulnerable to cross-site scripting, caused by improper validation of user-supplied inpu…

Patch available
Fix from $1,600 2017-02-01
Biginsights MEDIUM 5.4
CVE-2016-2924

IBM Infosphere BigInsights is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could explo…

Patch available
Fix from $1,600 2017-02-01
Biginsights MEDIUM 5.4
CVE-2016-2992

IBM Infosphere BigInsights is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI th…

Patch available
Fix from $1,600 2017-02-01
Kenexa Lms MEDIUM 5.4
CVE-2016-5940

IBM Kenexa LMS on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus …

Patch available
Fix from $1,600 2017-02-01
Kenexa Lms MEDIUM 5.4
CVE-2016-5942

IBM Kenexa LMS on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus …

Patch available
Fix from $1,600 2017-02-01
Kenexa Lms MEDIUM 5.4
CVE-2016-8929

IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker…

Patch available
Fix from $1,600 2017-02-01
Security Key Lifecycle Manager HIGH 8.2
CVE-2016-6105

IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 do not perform an authentication check for a critical resource or functionality allowing anonymous users…

Patch available
Fix from $1,950 2017-02-01
Tivoli Storage Manager MEDIUM 5.5
CVE-2016-0371

The Tivoli Storage Manager (TSM) password may be displayed in plain text via application trace output while application tracing is enabled.

Fix: after 7.1.6.2
Fix from $1,600 2017-02-01
License Metric Tool MEDIUM 5.5
CVE-2016-8967

IBM BigFix Inventory v9 9.2 stores user credentials in plain in clear text which can be read by a local user.

Mitigation only
Fix from $1,600 2017-02-01
Security Key Lifecycle Manager MEDIUM 5.3
CVE-2016-6117

IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 can be deployed with active debugging code that can disclose sensitive information.

Patch available
Fix from $1,600 2017-02-01
License Metric Tool HIGH 8.1
CVE-2016-8980

IBM BigFix Inventory v9 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remo…

Mitigation only
Fix from $1,950 2017-02-01
License Metric Tool MEDIUM 6.1
CVE-2016-8961

IBM BigFix Inventory v9 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a s…

Fix: after 9.2
Fix from $1,600 2017-02-01
License Metric Tool MEDIUM 5.9
CVE-2016-8966

IBM BigFix Inventory v9 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport…

Mitigation only
Fix from $1,600 2017-02-01
License Metric Tool MEDIUM 5.5
CVE-2016-8981

IBM BigFix Inventory v9 allows web pages to be stored locally which can be read by another user on the system.

Mitigation only
Fix from $1,600 2017-02-01
Spectrum Control MEDIUM 5.4
CVE-2016-8943

IBM Tivoli Storage Productivity Center is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…

Patch available
Fix from $1,600 2017-02-01
Business Process Manager MEDIUM 5.4
CVE-2016-9731

IBM Business Process Manager is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI …

Patch available
Fix from $1,600 2017-02-01
Bigfix Platform CRITICAL 10.0
CVE-2016-6082

IBM BigFix Platform could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free race condition. An attacker cou…

Patch available
Fix from $2,300 2017-02-01
Websphere Commerce CRITICAL 9.8
CVE-2016-6090

IBM WebSphere Commerce contains an unspecified vulnerability that could allow disclosure of user personal data, performing of unauthorized administra…

Fix: after 8.0.1.8
Fix from $2,300 2017-02-01
Kenexa Lms On Cloud HIGH 8.8
CVE-2016-6124

IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arb…

Mitigation only
Fix from $1,950 2017-02-01
Filenet Workplace Xt HIGH 8.8
CVE-2016-8921

IBM FileNet WorkPlace XT could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vul…

Mitigation only
Fix from $1,950 2017-02-01
Spectrum Control HIGH 8.8
CVE-2016-8941

IBM Tivoli Storage Productivity Center is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorize…

Patch available
Fix from $1,950 2017-02-01
Infosphere Datastage HIGH 8.1
CVE-2016-6059

IBM InfoSphere Information Server is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML da…

Patch available
Fix from $1,950 2017-02-01
Security Guardium HIGH 7.8
CVE-2016-6065

IBM Security Guardium Database Activity Monitor appliance could allow a local user to inject commands that would be executed as root.

Patch available
Fix from $1,950 2017-02-01
Bigfix Platform MEDIUM 6.5
CVE-2016-6084

IBM BigFix Platform could allow an attacker on the local network to crash the BES server using a specially crafted XMLSchema request.

Patch available
Fix from $1,600 2017-02-01
Bigfix Platform MEDIUM 6.5
CVE-2016-6085

IBM BigFix Platform could allow an attacker on the local network to crash the BES and relay servers.

Patch available
Fix from $1,600 2017-02-01
Kenexa Lms On Cloud MEDIUM 6.5
CVE-2016-6126

IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to traverse directories on the system. An attacker could send a speciall…

Mitigation only
Fix from $1,600 2017-02-01