Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Powerkvm CRITICAL 9.1
CVE-2015-5073EPSS 8%

Heap-based buffer overflow in the find_fixedlength function in pcre_compile.c in PCRE before 8.38 allows remote attackers to cause a denial of servic…

Fix: after 8.37
Fix from $2,300 2016-12-13
Filenet Workplace HIGH 8.1
CVE-2016-3055

IBM FileNet Workplace 4.0.2 before 4.0.2.14 LA012 allows remote authenticated users to read arbitrary files or cause a denial of service (memory cons…

Patch available
Fix from $1,950 2016-12-01
Filenet Workplace MEDIUM 6.8
CVE-2016-3047

Open redirect vulnerability in IBM FileNet Workplace 4.0.2 through 4.0.2.14 IF001 allows remote authenticated users to redirect users to arbitrary we…

Mitigation only
Fix from $1,600 2016-12-01
Powerkvm MEDIUM 6.5
CVE-2016-3044

The Linux kernel component in IBM PowerKVM 2.1 before 2.1.1.3-65.10 and 3.1 before 3.1.0.2 allows guest OS users to cause a denial of service (host O…

Mitigation only
Fix from $1,600 2016-12-01
Appscan Source HIGH 8.1
CVE-2016-3033

IBM AppScan Source 8.7 through 9.0.3.3 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) vi…

Mitigation only
Fix from $1,950 2016-12-01
Api Connect HIGH 7.5
CVE-2016-3012

IBM API Connect (aka APIConnect) before 5.0.3.0 with NPM before 2.2.8 includes certain internal server credentials in the software package, which mig…

Fix: after 5.0.2.0
Fix from $1,950 2016-12-01
Urbancode Deploy MEDIUM 5.4
CVE-2016-2994

Cross-site scripting (XSS) vulnerability in IBM UrbanCode Deploy 6.2.x before 6.2.1.2 allows remote authenticated users to inject arbitrary web scrip…

Mitigation only
Fix from $1,600 2016-12-01
Lotus Protector For Mail Security MEDIUM 5.4
CVE-2016-2991

Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Protector for Mail Security 2.8.0.0 through 2.8.1.0 before 2.8.1.0-22115 allow remot…

Mitigation only
Fix from $1,600 2016-12-01
Connections MEDIUM 5.4
CVE-2016-2955

Cross-site scripting (XSS) vulnerability in IBM Connections 5.0 before CR4 and 5.5 before CR1 allows remote authenticated users to inject arbitrary w…

Patch available
Fix from $1,600 2016-12-01
Tivoli Monitoring HIGH 7.8
CVE-2016-2946

Stack-based buffer overflow in the ax Shared Libraries in the Agent in IBM Tivoli Monitoring (ITM) 6.2.2 before FP9, 6.2.3 before FP5, and 6.3.0 befo…

Patch available
Fix from $1,950 2016-12-01
Tririga Application Platform HIGH 8.8
CVE-2016-2917

The notifications component in IBM TRIRIGA Applications 10.4 and 10.5 before 10.5.1 allows remote authenticated users to obtain sensitive password in…

Mitigation only
Fix from $1,950 2016-11-30
Ims Enterprise Suite HIGH 8.1
CVE-2016-2887

IBM IMS Enterprise Suite Data Provider before 3.2.0.1 for Microsoft .NET allows remote authenticated users to obtain sensitive information or modify …

Fix: after 3.2.0.0
Fix from $1,950 2016-11-30
Forms Experience Builder HIGH 8.0
CVE-2016-2884

Cross-site request forgery (CSRF) vulnerability in IBM Forms Experience Builder 8.5.x and 8.6.x before 8.6.3.1, in an unspecified non-default configu…

Patch available
Fix from $1,950 2016-11-30
Qradar Security Information And Event Manager MEDIUM 6.5
CVE-2016-2881

IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 and QRadar Incident Forensics 7.2 before 7.2.7 allow remote attackers to bypass intended…

Fix: after 7.1.0
Fix from $1,600 2016-11-30
Qradar Security Information And Event Manager HIGH 8.0
CVE-2016-2878

Multiple cross-site request forgery (CSRF) vulnerabilities in IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 allow remote attackers to …

Mitigation only
Fix from $1,950 2016-11-30
Qradar Security Information And Event Manager HIGH 7.5
CVE-2016-2876

IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 executes unspecified processes at an incorrect privilege level, which makes it easier fo…

Fix: after 7.1.0
Fix from $1,950 2016-11-30
Qradar Security Information And Event Manager HIGH 8.8
CVE-2016-2873

SQL injection vulnerability in IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 allows remote authenticated users to execute arbitrary SQ…

Fix: after 7.1.0
Fix from $1,950 2016-11-30
Qradar Security Information And Event Manager HIGH 7.8
CVE-2016-2871

IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 uses cleartext storage for unspecified passwords, which allows local users to obtain sen…

Fix: after 7.1.0
Fix from $1,950 2016-11-30
Qradar Security Information And Event Manager MEDIUM 5.4
CVE-2016-2869

Multiple cross-site scripting (XSS) vulnerabilities in the UI in IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 allow remote authentica…

Fix: after 7.1.0
Fix from $1,600 2016-11-30
Maximo Asset Management MEDIUM 5.3
CVE-2016-5987

IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5 before 7.5.0.10 IF4, and 7.6 before 7.6.0.5 IF3 allows remote attackers to obtain sensitive inf…

Patch available
Fix from $1,600 2016-11-30
Maximo Asset Management MEDIUM 5.4
CVE-2016-5905

Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5 before 7.5.0.10 IF3 and 7.6 before 7.6.0.5 IF2 allows remote authenticate…

Patch available
Fix from $1,600 2016-11-30
Sterling B2b Integrator MEDIUM 5.3
CVE-2016-5890

IBM Sterling B2B Integrator 5.2 before 5020500_14 and 5.2 06 before 5020602_1 allows remote authenticated users to change arbitrary passwords via uns…

Patch available
Fix from $1,600 2016-11-30
Sterling B2b Integrator MEDIUM 6.1
CVE-2016-3057

Cross-site scripting (XSS) vulnerability in IBM Sterling B2B Integrator 5.2 before 5020500_14 and 5.2 06 before 5020602_1 allows remote attackers to …

Patch available
Fix from $1,600 2016-11-30
Rational Engineering Lifecycle Manager MEDIUM 5.4
CVE-2016-3014

Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 4.0 before 4.0.7 iFix11 and 5.0 before 5.0.2 iFix17, Rati…

Mitigation only
Fix from $1,600 2016-11-30
Bigfix Remote Control HIGH 8.8
CVE-2016-2963

Cross-site request forgery (CSRF) vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote attackers to hijack the authentication of arb…

Fix: after 9.1.2
Fix from $1,950 2016-11-30
Bigfix Remote Control MEDIUM 6.5
CVE-2016-2950

SQL injection vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote authenticated users to execute arbitrary SQL commands via unspeci…

Fix: after 9.1.2
Fix from $1,600 2016-11-30
Bigfix Remote Control HIGH 7.8
CVE-2016-2948

IBM BigFix Remote Control before 9.1.3 allows local users to discover hardcoded credentials via unspecified vectors.

Mitigation only
Fix from $1,950 2016-11-30
Bigfix Remote Control CRITICAL 9.8
CVE-2016-2944

IBM BigFix Remote Control before 9.1.3 does not properly restrict failed login attempts, which makes it easier for remote attackers to obtain access …

Fix: after 9.1.2
Fix from $2,300 2016-11-30
Bigfix Remote Control MEDIUM 5.3
CVE-2016-2940

Multiple unspecified vulnerabilities in IBM BigFix Remote Control before 9.1.3 allow remote attackers to obtain sensitive information via unknown vec…

Fix: after 9.1.2
Fix from $1,600 2016-11-30
Bigfix Remote Control MEDIUM 6.5
CVE-2016-2937

IBM BigFix Remote Control before 9.1.3 allows remote attackers to obtain sensitive information or spoof e-mail transmission via a crafted POST reques…

Fix: after 9.1.2
Fix from $1,600 2016-11-30