Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Financial Transaction Manager MEDIUM 5.4
CVE-2016-5920

Cross-site scripting (XSS) vulnerability in the Web UI in IBM Financial Transaction Manager (FTM) for ACH Services 3.0.0.x before fp0015 and 3.0.1.0 …

Patch available
Fix from $1,600 2016-10-29
Financial Transaction Manager MEDIUM 5.7
CVE-2016-3060

Payments Director in IBM Financial Transaction Manager (FTM) for ACH Services, Check Services, and Corporate Payment Services (CPS) 3.0.0.x before fp…

Patch available
Fix from $1,600 2016-10-29
Security Guardium Database Activity Monitor HIGH 7.8
CVE-2016-0328

IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows local users to…

Patch available
Fix from $1,950 2016-10-22
Rational Collaborative Lifecycle Management HIGH 8.8
CVE-2016-0326

IBM Rational Quality Manager (RQM) and Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.x before 4.0.7 iFix11, 5.x before 5.0.2 iF…

Patch available
Fix from $1,950 2016-10-22
Security Guardium HIGH 7.8
CVE-2016-0247

IBM Security Guardium 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows local users to obtain sensitive cleartex…

Patch available
Fix from $1,950 2016-10-22
Security Guardium MEDIUM 6.1
CVE-2016-0246

Cross-site scripting (XSS) vulnerability in IBM Security Guardium 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 all…

Patch available
Fix from $1,600 2016-10-22
Security Guardium Database Activity Monitor HIGH 8.8
CVE-2016-0241

IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote authent…

Patch available
Fix from $1,950 2016-10-22
Security Guardium Database Activity Monitor HIGH 8.8
CVE-2016-0239

IBM Security Guardium Database Activity Monitor 9.x through 9.5 before p700 and 10.x through 10.0.1 before p100 allows remote authenticated users to …

Patch available
Fix from $1,950 2016-10-22
Security Guardium Database Activity Monitor HIGH 8.8
CVE-2016-0236

IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote authent…

Patch available
Fix from $1,950 2016-10-21
Security Guardium HIGH 8.6
CVE-2016-0249

SQL injection vulnerability in IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 be…

Fix: after 8.2
Fix from $1,950 2016-10-16
Cloud Orchestrator MEDIUM 6.8
CVE-2016-0204

Open redirect vulnerability in IBM Cloud Orchestrator 2.4.x before 2.4.0 FP3 allows remote authenticated users to redirect users to arbitrary web sit…

Patch available
Fix from $1,600 2016-10-16
Business Process Manager MEDIUM 5.4
CVE-2016-3056

Cross-site scripting (XSS) vulnerability in Business Space in IBM Business Process Manager 7.5 through 7.5.1.2, 8.0 through 8.0.1.3, and 8.5 before 8…

Patch available
Fix from $1,600 2016-10-14
Sterling Secure Proxy MEDIUM 6.1
CVE-2016-6027

The Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.0 iFix 1 does not enable the HSTS pro…

Mitigation only
Fix from $1,600 2016-10-06
Sterling Secure Proxy MEDIUM 5.3
CVE-2016-6026

The Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.0 iFix 1 allows man-in-the-middle att…

Mitigation only
Fix from $1,600 2016-10-06
Sterling Secure Proxy MEDIUM 5.9
CVE-2016-6025

The Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.0 iFix 1 allows remote attackers to o…

Mitigation only
Fix from $1,600 2016-10-06
Sterling Secure Proxy HIGH 7.5
CVE-2016-6023

Directory traversal vulnerability in the Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.…

Mitigation only
Fix from $1,950 2016-10-06
Websphere Application Server HIGH 7.5
CVE-2016-5983

IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.43, 8.0 before 8.0.0.13, 8.5 before 8.5.5.11, 9.0 before 9.0.0.2, and Liberty before 16.0.0.4…

Patch available
Fix from $1,950 2016-10-05
Business Process Manager MEDIUM 5.4
CVE-2016-5901

Cross-site scripting (XSS) vulnerability in a test page in IBM Business Process Manager Advanced 8.5.6.0 through 8.5.7.0 before cumulative fix 2016.0…

Patch available
Fix from $1,600 2016-10-05
Multi Enterprise Integration Gateway MEDIUM 5.4
CVE-2016-5892

Cross-site scripting (XSS) vulnerability in IBM 10x, as used in Multi-Enterprise Integration Gateway 1.x through 1.0.0.1 and B2B Advanced Communicati…

Fix: after 1.0.0.5_1
Fix from $1,600 2016-10-05
Db2 HIGH 7.3
CVE-2016-5995

Untrusted search path vulnerability in IBM DB2 9.7 through FP11, 10.1 through FP5, 10.5 before FP8, and 11.1 GA on Linux, AIX, and HP-UX allows local…

Patch available
Fix from $1,950 2016-10-01
Websphere Application Server HIGH 7.5
CVE-2016-5986

IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.x before 8.0.0.13, 8.5.x before 8.5.5.11, 9.0.x before 9.0.0.2, and Liberty before 16…

Patch available
Fix from $1,950 2016-10-01
Websphere Application Server MEDIUM 5.4
CVE-2016-3042

Cross-site scripting (XSS) vulnerability in the Web UI in IBM WebSphere Application Server (WAS) Liberty before 16.0.0.3 allows remote authenticated …

Mitigation only
Fix from $1,600 2016-10-01
Aix MEDIUM 6.5
CVE-2016-6038

Directory traversal vulnerability in Eclipse Help in IBM Tivoli Lightweight Infrastructure (aka LWI), as used in AIX 5.3, 6.1, and 7.1, allows remote…

Mitigation only
Fix from $1,600 2016-09-26
Tealeaf Customer Experience MEDIUM 6.5
CVE-2016-5997

The web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A be…

Fix: after 8.7
Fix from $1,600 2016-09-26
Tealeaf Customer Experience HIGH 7.5
CVE-2016-5996

The web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A be…

Fix: after 8.7
Fix from $1,950 2016-09-26
Tealeaf Customer Experience MEDIUM 5.4
CVE-2016-5978

Cross-site scripting (XSS) vulnerability in the Web UI in the web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.…

Mitigation only
Fix from $1,600 2016-09-26
Tealeaf Customer Experience MEDIUM 6.8
CVE-2016-5977

Open redirect vulnerability in the web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 b…

Fix: after 8.7
Fix from $1,600 2016-09-26
Tealeaf Customer Experience MEDIUM 5.4
CVE-2016-5975

Cross-site scripting (XSS) vulnerability in the Web UI in the web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.…

Fix: after 8.7
Fix from $1,600 2016-09-26
Security Privileged Identity Manager Virtual Appliance MEDIUM 5.4
CVE-2016-5974

Cross-site scripting (XSS) vulnerability in the Web UI in IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 all…

Fix: after 2.0.2
Fix from $1,600 2016-09-26
Security Privileged Identity Manager Virtual Appliance MEDIUM 6.8
CVE-2016-5972

IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 uses weak permissions for unspecified resources, which allows…

Fix: after 2.0.2
Fix from $1,600 2016-09-26