Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Kenexa Lms On Cloud MEDIUM 6.5
CVE-2016-8913

IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to traverse directories on the system. An attacker could send a speciall…

Mitigation only
Fix from $1,600 2017-02-01
Domino MEDIUM 6.1
CVE-2016-6113

IBM Verse is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the i…

Mitigation only
Fix from $1,600 2017-02-01
Web Content Manager Production Analytics MEDIUM 6.1
CVE-2016-8922

Exphox WebRadar is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering…

Mitigation only
Fix from $1,600 2017-02-01
Social Rendering Templates For Digital Data Connector MEDIUM 6.1
CVE-2016-8936

IBM Social Rendering Templates for Digital Data Connector is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary J…

Patch available
Fix from $1,600 2017-02-01
Integration Bus MEDIUM 5.9
CVE-2016-8918

IBM Integration Bus, under non default configurations, could allow a remote user to authenticate without providing valid credentials.

Patch available
Fix from $1,600 2017-02-01
Jazz Reporting Service MEDIUM 5.4
CVE-2016-6047

IBM Jazz Reporting Service (JRS) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web…

Patch available
Fix from $1,600 2017-02-01
Jazz Reporting Service MEDIUM 5.4
CVE-2016-6054

IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alte…

Patch available
Fix from $1,600 2017-02-01
Rational Collaborative Lifecycle Management MEDIUM 5.4
CVE-2016-6061

IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alte…

Patch available
Fix from $1,600 2017-02-01
Maximo Asset Management MEDIUM 5.4
CVE-2016-6072

IBM Maximo Asset Management is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI t…

Patch available
Fix from $1,600 2017-02-01
Kenexa Lms On Cloud MEDIUM 5.4
CVE-2016-6123

IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript c…

Mitigation only
Fix from $1,600 2017-02-01
Kenexa Lms On Cloud MEDIUM 5.4
CVE-2016-6125

IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript c…

Mitigation only
Fix from $1,600 2017-02-01
Kenexa Lms On Cloud MEDIUM 5.4
CVE-2016-8911

IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to v…

Mitigation only
Fix from $1,600 2017-02-01
Kenexa Lms On Cloud MEDIUM 5.4
CVE-2016-8920

IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript c…

Mitigation only
Fix from $1,600 2017-02-01
Websphere Application Server MEDIUM 5.4
CVE-2016-8934

IBM WebSphere Application Server is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web…

Patch available
Fix from $1,600 2017-02-01
Websphere Message Broker MEDIUM 5.3
CVE-2016-6080

The WebAdmin context for WebSphere Message Broker allows directory listings which could disclose sensitive information to the attacker.

Patch available
Fix from $1,600 2017-02-01
Security Privileged Identity Manager CRITICAL 9.8
CVE-2016-5964

IBM Security Privileged Identity Manager Virtual Appliance version 2.0.2 uses an inadequate account lockout setting that could allow a remote attacke…

Patch available
Fix from $2,300 2017-02-01
Kenexa Lcms Premier HIGH 8.8
CVE-2016-5937

IBM Kenexa LCMS Premier on Cloud is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized acti…

Patch available
Fix from $1,950 2017-02-01
Kenexa Lcms Premier HIGH 8.8
CVE-2016-5952

IBM Kenexa LCMS Premier on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the…

Patch available
Fix from $1,950 2017-02-01
Tivoli Storage Manager HIGH 8.8
CVE-2016-6045

IBM Tivoli Storage Manager Operations Center is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unaut…

Patch available
Fix from $1,950 2017-02-01
Tivoli Storage Manager HIGH 7.8
CVE-2016-5985

The IBM Tivoli Storage Manager (IBM Spectrum Protect) AIX client is vulnerable to a buffer overflow when Journal-Based Backup is enabled. A local att…

Fix: after 7.1.6.2
Fix from $1,950 2017-02-01
Security Privileged Identity Manager HIGH 7.5
CVE-2016-5958

IBM Security Privileged Identity Manager could allow a remote attacker to obtain sensitive information, caused by the failure to set the secure flag …

Patch available
Fix from $1,950 2017-02-01
Security Appscan HIGH 7.3
CVE-2016-6042

IBM AppScan Enterprise Edition could allow a remote attacker to execute arbitrary code on the system, caused by improper handling of objects in memor…

Patch available
Fix from $1,950 2017-02-01
Tivoli Storage Manager HIGH 7.0
CVE-2016-6043

Tivoli Storage Manager Operations Center could allow a local user to take over a previously logged in user due to session expiration not being enforc…

Patch available
Fix from $1,950 2017-02-01
Tivoli Storage Manager For Virtual Environments Data Protection For Vmware MEDIUM 6.8
CVE-2016-6034

IBM Tivoli Storage Manager for Virtual Environments (VMware) could disclose the Windows domain credentials to a user with a high level of privileges.

Patch available
Fix from $1,600 2017-02-01
Kenexa Lcms Premier MEDIUM 6.5
CVE-2016-5950

IBM Kenexa LCMS Premier on Cloud stores user credentials in plain in clear text which can be read by an authenticated user.

Patch available
Fix from $1,600 2017-02-01
Security Privileged Identity Manager MEDIUM 6.5
CVE-2016-5988

IBM Security Privileged Identity Manager Virtual Appliance could disclose sensitive information in generated error messages that would be available t…

Patch available
Fix from $1,600 2017-02-01
Infosphere Information Server MEDIUM 6.5
CVE-2016-5994

IBM InfoSphere Information Server contains a vulnerability that would allow an authenticated user to browse any file on the engine tier, and examine …

Patch available
Fix from $1,600 2017-02-01
Kenexa Lms On Cloud MEDIUM 6.3
CVE-2016-5939

IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker…

Patch available
Fix from $1,600 2017-02-01
Security Privileged Identity Manager MEDIUM 6.3
CVE-2016-5990

IBM Security Privileged Identity Manager Virtual Appliance allows an authenticated user to upload malicious files that would be automatically execute…

Patch available
Fix from $1,600 2017-02-01
Infosphere Information Server MEDIUM 6.1
CVE-2016-5984

IBM InfoSphere Information Server is vulnerable to cross-frame scripting, caused by insufficient HTML iframe protection. A remote attacker could expl…

Patch available
Fix from $1,600 2017-02-01