Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Security Privileged Identity Manager Virtual Appliance HIGH 7.1
CVE-2016-5971

IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 allows remote authenticated users to read arbitrary files or …

Fix: after 2.0.2
Fix from $1,950 2016-09-26
Security Privileged Identity Manager Virtual Appliance MEDIUM 6.5
CVE-2016-5970

Directory traversal vulnerability in IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 allows remote authentica…

Fix: after 2.0.2
Fix from $1,600 2016-09-26
Security Privileged Identity Manager Virtual Appliance HIGH 8.8
CVE-2016-5963

IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 does not properly validate updates, which allows remote authe…

Patch available
Fix from $1,950 2016-09-26
Security Privileged Identity Manager Virtual Appliance HIGH 7.5
CVE-2016-5957

IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 allows remote attackers to defeat cryptographic protection me…

Fix: after 2.0.2
Fix from $1,950 2016-09-26
Tivoli Storage Productivity Center MEDIUM 5.7
CVE-2016-5947

IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to conduct clickjacking atta…

Patch available
Fix from $1,600 2016-09-26
Spectrum Control MEDIUM 6.5
CVE-2016-5946

Directory traversal vulnerability in IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticat…

Patch available
Fix from $1,600 2016-09-26
Spectrum Control MEDIUM 5.4
CVE-2016-5944

Cross-site scripting (XSS) vulnerability in the Web UI in IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allo…

Patch available
Fix from $1,600 2016-09-26
Spectrum Control MEDIUM 5.4
CVE-2016-5943

IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to bypass intended access re…

Patch available
Fix from $1,600 2016-09-26
Security Privileged Identity Manager Virtual Appliance MEDIUM 6.8
CVE-2016-3040

IBM WebSphere Application Server (WAS) Liberty, as used in IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8, a…

Patch available
Fix from $1,600 2016-09-26
Connections HIGH 8.8
CVE-2016-3007

Cross-site request forgery (CSRF) vulnerability in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticate…

Patch available
Fix from $1,950 2016-09-26
Connections MEDIUM 5.4
CVE-2016-3006

Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authe…

Patch available
Fix from $1,600 2016-09-26
Connections MEDIUM 5.4
CVE-2016-3003

Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authe…

Patch available
Fix from $1,600 2016-09-26
Connections MEDIUM 5.4
CVE-2016-3001

Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authe…

Patch available
Fix from $1,600 2016-09-26
Connections MEDIUM 6.5
CVE-2016-2999

IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to obtain sensitive information via an unsp…

Fix: after 5.5.0.0
Fix from $1,600 2016-09-26
Websphere Portal MEDIUM 6.5
CVE-2016-5954

IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF30, 8.0.0 through 8.0.0.1 CF21, and 8.5.0 before…

Patch available
Fix from $1,600 2016-09-12
Tivoli Storage Manager For Space Management MEDIUM 5.5
CVE-2016-5927

IBM Tivoli Storage Manager for Space Management (aka Spectrum Protect for Space Management) 6.3.x before 6.3.2.6, 6.4.x before 6.4.3.3, and 7.1.x bef…

Patch available
Fix from $1,600 2016-09-12
Rational Collaborative Lifecycle Management MEDIUM 5.4
CVE-2016-0331

Cross-site scripting (XSS) vulnerability in IBM Rational Team Concert 6.0.1 and 6.0.2 before 6.0.2 iFix2 and Rational Collaborative Lifecycle Managem…

Patch available
Fix from $1,600 2016-09-12
Mq Appliance Firmware HIGH 8.8
CVE-2016-5879

MQCLI on IBM MQ Appliance M2000 and M2001 devices allows local users to execute arbitrary shell commands via a crafted (1) Disaster Recovery or (2) H…

Mitigation only
Fix from $1,950 2016-09-02
Connections MEDIUM 5.4
CVE-2016-3010

Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 before CR4, and 5.5 before CR1 allows…

Patch available
Fix from $1,600 2016-09-01
Connections MEDIUM 5.4
CVE-2016-3008

Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 5.0 before CR4 and 5.5 before CR1 allows remote authenticated users to inje…

Patch available
Fix from $1,600 2016-09-01
Connections MEDIUM 5.4
CVE-2016-3005

Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 before CR4, and 5.5 before CR1 allows…

Patch available
Fix from $1,600 2016-09-01
Connections MEDIUM 5.4
CVE-2016-2997

Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 before CR4, and 5.5 before CR1 allows…

Patch available
Fix from $1,600 2016-09-01
Connections MEDIUM 5.4
CVE-2016-2995

Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 before CR4, and 5.5 before CR1 allows…

Patch available
Fix from $1,600 2016-09-01
Connections MEDIUM 5.4
CVE-2016-2956

Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 5.0 before CR4 and 5.5 before CR1 allows remote authenticated users to inje…

Patch available
Fix from $1,600 2016-09-01
Connections MEDIUM 5.4
CVE-2016-2954

Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 5.0 before CR4 and 5.5 before CR1 allows remote authenticated users to inje…

Patch available
Fix from $1,600 2016-09-01
Bigfix Platform MEDIUM 6.1
CVE-2016-0293

Cross-site scripting (XSS) vulnerability in IBM BigFix Platform (formerly Tivoli Endpoint Manager) 9.x before 9.1.8 and 9.2.x before 9.2.8 allows rem…

Mitigation only
Fix from $1,600 2016-09-01
Bigfix Webreports MEDIUM 5.9
CVE-2016-0397

WebReports in IBM BigFix Platform (formerly Tivoli Endpoint Manager) 9.x before 9.5.2 allows remote attackers to obtain sensitive information by snif…

Mitigation only
Fix from $1,600 2016-08-30
Bigfix MEDIUM 5.5
CVE-2016-0292

WebReports in IBM BigFix Platform (formerly Tivoli Endpoint Manager) 9.x before 9.5.2 allows local users to discover the cleartext system password by…

Mitigation only
Fix from $1,600 2016-08-30
Filenet Workplace MEDIUM 6.8
CVE-2016-5878

Open redirect vulnerability in IBM FileNet Workplace 4.0.2 before 4.0.2.14 allows remote authenticated users to redirect users to arbitrary web sites…

Patch available
Fix from $1,600 2016-08-08
Tivoli Storage Flashcopy Manager For Sql Server MEDIUM 6.2
CVE-2016-3059

IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server (aka IBM Spectrum Protect for Databases) 6.3 before 6.3.1.7 and 6.…

Fix: after 6.4.1.8
Fix from $1,600 2016-08-08