Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Tririga Application Platform MEDIUM 6.1
CVE-2016-6000

IBM TRIRIGA Application Platform is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web…

Patch available
Fix from $1,600 2017-02-01
Sterling B2b Integrator MEDIUM 6.1
CVE-2016-6020

IBM Sterling B2B Integrator Standard Edition could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading …

Patch available
Fix from $1,600 2017-02-01
Security Privileged Identity Manager MEDIUM 5.9
CVE-2016-5966

IBM Security Privileged Identity Manager Virtual Appliance could allow a remote attacker to obtain sensitive information, caused by the failure to pr…

Patch available
Fix from $1,600 2017-02-01
Jazz Reporting Service MEDIUM 5.4
CVE-2016-5897

IBM Jazz Reporting Service (JRS) is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be exe…

Patch available
Fix from $1,600 2017-02-01
Jazz Reporting Service MEDIUM 5.4
CVE-2016-5899

IBM Jazz Reporting Service (JRS) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web…

Patch available
Fix from $1,600 2017-02-01
Kenexa Lcms Premier MEDIUM 5.4
CVE-2016-5948

IBM Kenexa LCMS Premier on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web…

Patch available
Fix from $1,600 2017-02-01
Kenexa Lcms Premier MEDIUM 5.4
CVE-2016-5951

IBM Kenexa LCMS Premier on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web…

Patch available
Fix from $1,600 2017-02-01
Tririga Application Platform MEDIUM 5.4
CVE-2016-5980

IBM TRIRIGA Application Platform is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web…

Patch available
Fix from $1,600 2017-02-01
Rational Collaborative Lifecycle Management MEDIUM 5.4
CVE-2016-6030

IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alte…

Patch available
Fix from $1,600 2017-02-01
Jazz Reporting Service MEDIUM 5.4
CVE-2016-6039

IBM Jazz Reporting Service (JRS) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web…

Patch available
Fix from $1,600 2017-02-01
Tivoli Storage Manager MEDIUM 5.4
CVE-2016-6046

IBM Tivoli Storage Manager Operations Center is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript cod…

Patch available
Fix from $1,600 2017-02-01
Rational Collaborative Lifecycle Management MEDIUM 5.0
CVE-2016-6040

IBM Jazz Foundation could allow an authenticated user to take over a previously logged in user due to session expiration not being enforced.

Patch available
Fix from $1,600 2017-02-01
Security Access Manager 9.0 Firmware CRITICAL 9.1
CVE-2016-2908

IBM Single Sign On for Bluemix could allow a remote attacker to obtain sensitive information, caused by a XML external entity (XXE) error when proces…

Patch available
Fix from $2,300 2017-02-01
Security Access Manager 9.0 Firmware HIGH 8.8
CVE-2016-3029

IBM Security Access Manager for Web is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized a…

Patch available
Fix from $1,950 2017-02-01
Bigfix Platform HIGH 8.1
CVE-2016-0396

IBM Tivoli Endpoint Manager could allow a user under special circumstances to inject commands that would be executed with unnecessary higher privileg…

Patch available
Fix from $1,950 2017-02-01
Aix HIGH 7.8
CVE-2016-3053

IBM AIX contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges.

No fix yet
Fix from $1,950 2017-02-01
Security Access Manager 9.0 Firmware HIGH 7.5
CVE-2016-3017

IBM Security Access Manager for Web could allow a remote attacker to obtain sensitive information due to security misconfigurations.

Patch available
Fix from $1,950 2017-02-01
Security Access Manager 9.0 Firmware MEDIUM 6.5
CVE-2016-3022

IBM Security Access Manager for Web could allow an authenticated user to gain access to highly sensitive information due to incorrect file permission…

Patch available
Fix from $1,600 2017-02-01
Security Access Manager 9.0 Firmware MEDIUM 6.5
CVE-2016-3027

IBM Security Access Manager for Web is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML …

Patch available
Fix from $1,600 2017-02-01
Domino MEDIUM 6.1
CVE-2016-2938

IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the …

Patch available
Fix from $1,600 2017-02-01
Domino MEDIUM 6.1
CVE-2016-2939

IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the …

Patch available
Fix from $1,600 2017-02-01
Security Access Manager MEDIUM 6.1
CVE-2016-3018

IBM Security Access Manager for Web is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the …

Mitigation only
Fix from $1,600 2017-02-01
Domino MEDIUM 6.1
CVE-2016-5882

IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the …

Patch available
Fix from $1,600 2017-02-01
Domino MEDIUM 6.1
CVE-2016-5884

IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the …

Patch available
Fix from $1,600 2017-02-01
Security Access Manager For Web 7.0 Firmware MEDIUM 5.9
CVE-2016-3043

IBM Security Access Manager for Web could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Stri…

Patch available
Fix from $1,600 2017-02-01
Campaign MEDIUM 5.4
CVE-2016-0265

IBM Campaign is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulner…

Patch available
Fix from $1,600 2017-02-01
Domino MEDIUM 5.4
CVE-2016-5880

IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the …

Patch available
Fix from $1,600 2017-02-01
Security Access Manager 9.0 Firmware MEDIUM 5.3
CVE-2016-3023

IBM Security Access Manager for Web could allow an unauthenticated user to gain access to sensitive information by entering invalid file names.

Patch available
Fix from $1,600 2017-02-01
Security Appscan Source MEDIUM 5.3
CVE-2016-3035

IBM AppScan Source could reveal some sensitive information through the browsing of testlinks on the server.

Patch available
Fix from $1,600 2017-02-01
Maximo Asset Management MEDIUM 5.3
CVE-2016-5896

IBM Maximo Asset Management could disclose sensitive information from a stack trace after submitting incorrect login onto Cognos browser.

Patch available
Fix from $1,600 2017-02-01