Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Bigfix Remote Control HIGH 7.3
CVE-2016-2936

IBM BigFix Remote Control before 9.1.3 uses cleartext storage for unspecified passwords, which allows local users to obtain sensitive information via…

Fix: after 9.1.2
Fix from $1,950 2016-11-30
Bigfix Remote Control MEDIUM 5.3
CVE-2016-2935

The broker application in IBM BigFix Remote Control before 9.1.3 allows remote attackers to cause a denial of service via an invalid HTTP request.

Fix: after 9.1.2
Fix from $1,600 2016-11-30
Bigfix Remote Control MEDIUM 6.1
CVE-2016-2934

Cross-site scripting (XSS) vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote attackers to inject arbitrary web script or HTML via…

Fix: after 9.1.2
Fix from $1,600 2016-11-30
Bigfix Remote Control MEDIUM 6.8
CVE-2016-2933

Directory traversal vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote authenticated administrators to read arbitrary files via a …

Fix: after 9.1.2
Fix from $1,600 2016-11-30
Bigfix Remote Control MEDIUM 5.3
CVE-2016-2932

IBM BigFix Remote Control before 9.1.3 allows remote attackers to conduct XML injection attacks via unspecified vectors.

Fix: after 9.1.2
Fix from $1,600 2016-11-30
Bigfix Remote Control MEDIUM 5.3
CVE-2016-2931

IBM BigFix Remote Control before 9.1.3 allows remote attackers to obtain sensitive cleartext information by sniffing the network.

Fix: after 9.1.2
Fix from $1,600 2016-11-30
Bigfix Remote Control HIGH 8.1
CVE-2016-2929

IBM BigFix Remote Control before 9.1.3 does not properly restrict password choices, which makes it easier for remote attackers to obtain access via a…

Fix: after 9.1.2
Fix from $1,950 2016-11-25
Bigfix Remote Control MEDIUM 5.9
CVE-2016-2927

IBM BigFix Remote Control before 9.1.3 does not properly restrict the set of available encryption algorithms, which makes it easier for remote attack…

Fix: after 9.1.2
Fix from $1,600 2016-11-25
Rational Team Concert MEDIUM 5.4
CVE-2016-2926

Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix19, and 6.0…

Patch available
Fix from $1,600 2016-11-25
Jazz Reporting Service HIGH 7.5
CVE-2016-0319

The XML parser in Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 allows remote authenticated administr…

Patch available
Fix from $1,950 2016-11-25
Jazz Reporting Service MEDIUM 5.0
CVE-2016-0318

Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 does not destroy a Session ID upon a logout action, whi…

Patch available
Fix from $1,600 2016-11-25
Jazz Reporting Service MEDIUM 6.5
CVE-2016-0317

Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 allows remote attackers to conduct clickjacking attacks…

Patch available
Fix from $1,600 2016-11-25
Jazz Reporting Service MEDIUM 5.4
CVE-2016-0316

Cross-site scripting (XSS) vulnerability in Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 and 6.0.2 b…

Patch available
Fix from $1,600 2016-11-25
Filenet Workplace MEDIUM 5.4
CVE-2016-5981

Cross-site scripting (XSS) vulnerability in IBM FileNet Workplace XT through 1.1.5.2-WPXT-LA011 and FileNet Workplace (Application Engine) through 4.…

Fix: after 4.0.2.14-p8ae-if001
Fix from $1,600 2016-11-25
Tealeaf Customer Experience MEDIUM 5.3
CVE-2016-5968

The Replay Server in IBM Tealeaf Customer Experience 8.x before 8.7.1.8847 FP10, 8.8.x before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, …

Fix: after 8.6
Fix from $1,600 2016-11-25
Rational Asset Analyzer MEDIUM 5.5
CVE-2016-5967

The installation component in IBM Rational Asset Analyzer (RAA) 6.1.0 before FP10 allows local users to discover the WAS Admin password by reading IM…

Mitigation only
Fix from $1,600 2016-11-25
Rational Doors Next Generation MEDIUM 5.4
CVE-2016-5955

Cross-site scripting (XSS) vulnerability in IBM Rational DOORS Next Generation 6.0.2 before iFix004 allows remote authenticated users to inject arbit…

Mitigation only
Fix from $1,600 2016-11-25
Security Access Manager CRITICAL 9.1
CVE-2016-3028

IBM Security Access Manager for Web 7.0 before IF2 and 8.0 before 8.0.1.4 IF3 and Security Access Manager 9.0 before 9.0.1.0 IF5 allow remote authent…

Mitigation only
Fix from $2,300 2016-11-25
Security Access Manager HIGH 8.1
CVE-2016-3025

IBM Security Access Manager for Mobile 8.x before 8.0.1.4 IF3 and Security Access Manager 9.x before 9.0.1.0 IF5 do not properly restrict failed logi…

Mitigation only
Fix from $1,950 2016-11-25
Tivoli Storage Manager For Virtual Environments HIGH 8.5
CVE-2016-2988

IBM Tivoli Storage Manger for Virtual Environments: Data Protection for VMware (aka Spectrum Protect for Virtual Environments) 6.4.x before 6.4.3.4 a…

Mitigation only
Fix from $1,950 2016-11-25
Rational Engineering Lifecycle Manager MEDIUM 5.4
CVE-2016-2986

Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 6.x before 6.0.1 iFix6, Rational Quality Manager 6.x befo…

Mitigation only
Fix from $1,600 2016-11-25
Spectrum Scale HIGH 7.0
CVE-2016-2985

IBM Spectrum Scale 4.1.1.x before 4.1.1.8 and 4.2.x before 4.2.0.4 and General Parallel File System (GPFS) 3.5.x before 3.5.0.32 and 4.1.x before 4.1…

Mitigation only
Fix from $1,950 2016-11-25
Spectrum Scale HIGH 7.0
CVE-2016-2984

IBM Spectrum Scale 4.1.1.x before 4.1.1.8 and 4.2.x before 4.2.0.4 and General Parallel File System (GPFS) 3.5.x before 3.5.0.32 and 4.1.x before 4.1…

Mitigation only
Fix from $1,950 2016-11-25
Security Privileged Identity Manager MEDIUM 6.5
CVE-2016-2996

IBM Security Privileged Identity Manager 2.0 before 2.0.2 FP8, when Virtual Appliance is used, allows remote authenticated users to append to arbitra…

Mitigation only
Fix from $1,600 2016-11-24
Rational Quality Manager MEDIUM 5.4
CVE-2016-2864

Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before…

Mitigation only
Fix from $1,600 2016-11-24
Rational Team Concert MEDIUM 6.3
CVE-2016-0325

IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; R…

Mitigation only
Fix from $1,600 2016-11-24
Rational Team Concert MEDIUM 5.4
CVE-2016-0285

Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before…

Mitigation only
Fix from $1,600 2016-11-24
Rational Software Architect Design Manager MEDIUM 5.4
CVE-2016-0284

The XML parser in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 bef…

Mitigation only
Fix from $1,600 2016-11-24
Lotus Inotes MEDIUM 5.4
CVE-2016-0282

Cross-site scripting (XSS) vulnerability in IBM iNotes before 8.5.3 FP6 IF2 allows remote authenticated users to inject arbitrary web script or HTML …

Mitigation only
Fix from $1,600 2016-11-24
Rational Doors Next Generation MEDIUM 5.4
CVE-2016-0273

Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before…

Mitigation only
Fix from $1,600 2016-11-24