Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filenet Workplace MEDIUM 5.4
CVE-2016-3054

Cross-site scripting (XSS) vulnerability in IBM FileNet Workplace 4.0.2 allows remote authenticated users to inject arbitrary web script or HTML by u…

Patch available
Fix from $1,600 2016-08-08
Connections Portlets MEDIUM 6.5
CVE-2016-2989

Open redirect vulnerability in the Connections Portlets component 5.x before 5.0.2 for IBM WebSphere Portal allows remote attackers to redirect users…

Patch available
Fix from $1,600 2016-08-08
Websphere Portal MEDIUM 5.4
CVE-2016-2925

Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.x through 7.0.0.2 CF30…

Mitigation only
Fix from $1,600 2016-08-08
Engineering Lifecycle Optimization Publishing MEDIUM 5.4
CVE-2016-2914

Unrestricted file upload vulnerability in the Document Builder in IBM Rational Publishing Engine (aka RPENG) 2.0.1 before ifix002 allows remote authe…

Patch available
Fix from $1,600 2016-08-08
Engineering Lifecycle Optimization Publishing MEDIUM 5.4
CVE-2016-2912

Cross-site scripting (XSS) vulnerability in the Document Builder in IBM Rational Publishing Engine (aka RPENG) 2.0.1 before ifix002 allows remote aut…

Mitigation only
Fix from $1,600 2016-08-08
Qradar Security Information And Event Manager HIGH 8.8
CVE-2016-2875

IBM Security QRadar SIEM 7.1.x and 7.2.x before 7.2.7 allows remote authenticated users to execute arbitrary OS commands as root via unspecified vect…

Patch available
Fix from $1,950 2016-08-08
General Parallel File System MEDIUM 6.5
CVE-2016-0361

IBM General Parallel File System (GPFS) 3.5 before 3.5.0.29 efix 6 and 4.1.1 before 4.1.1.4 efix 9, when the Spectrum Scale GUI is used with DB2 on L…

Patch available
Fix from $1,600 2016-08-08
Information Server Framework MEDIUM 5.4
CVE-2016-0280

Cross-site scripting (XSS) vulnerability in IBM Information Server Framework 8.5, Information Server Framework and InfoSphere Information Server Busi…

Patch available
Fix from $1,600 2016-08-08
Traveler HIGH 8.1
CVE-2016-3039

IBM Traveler 8.x and 9.x before 9.0.1.12 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) …

Mitigation only
Fix from $1,950 2016-07-17
Maximo Asset Management MEDIUM 5.3
CVE-2016-0393

IBM Maximo Asset Management 7.5 before 7.5.0.10-TIV-MBS-IFIX002 and 7.6 before 7.6.0.5-TIV-MAMMT-FP001 allows remote attackers to obtain sensitive UR…

Mitigation only
Fix from $1,600 2016-07-17
Personal Communications MEDIUM 6.2
CVE-2016-0321

IBM Personal Communications (aka PCOMM) 6.x before 6.0.17 and 12.x before 12.0.0.1 does not properly restrict credential extraction, which allows loc…

Mitigation only
Fix from $1,600 2016-07-17
Rational Team Concert MEDIUM 6.5
CVE-2016-2865

The GIT Integration component in IBM Rational Team Concert (RTC) 5.x before 5.0.2 iFix14 and 6.x before 6.0.1 iFix5 and Rational Collaborative Lifecy…

Patch available
Fix from $1,600 2016-07-15
Security Identity Manager Adapter HIGH 7.4
CVE-2016-0340

IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 mishandles session expiration, which allow…

Mitigation only
Fix from $1,950 2016-07-15
Security Identity Manager Adapter MEDIUM 5.6
CVE-2016-0339

IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 mishandles session identifiers after logou…

Mitigation only
Fix from $1,600 2016-07-15
Security Identity Manager Adapter MEDIUM 6.2
CVE-2016-0338

IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 allows local users to discover cleartext p…

Mitigation only
Fix from $1,600 2016-07-15
Security Identity Manager Adapter HIGH 7.3
CVE-2016-0330

IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 mishandles password creation, which makes …

No fix yet
Fix from $1,950 2016-07-15
Bigfix Platform MEDIUM 5.4
CVE-2016-0269

Cross-site scripting (XSS) vulnerability in IBM BigFix Platform 9.x before 9.1.8 and 9.2.x before 9.2.7 allows remote authenticated users to inject a…

Mitigation only
Fix from $1,600 2016-07-15
Tivoli Directory Server HIGH 7.5
CVE-2015-1977

Directory traversal vulnerability in the Web Administration tool in IBM Tivoli Directory Server (ITDS) before 6.1.0.74-ISS-ISDS-IF0074, 6.2.x before …

Mitigation only
Fix from $1,950 2016-07-15
Websphere Application Server HIGH 7.5
CVE-2016-2945

The API Discovery implementation in IBM WebSphere Application Server (WAS) 8.5.5.8 through 8.5.5.9 Liberty before Liberty Fix Pack 16.0.0.2 allows re…

Mitigation only
Fix from $1,950 2016-07-08
Jazz Reporting Service HIGH 8.8
CVE-2016-2889

Cross-site request forgery (CSRF) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x bef…

Mitigation only
Fix from $1,950 2016-07-08
Jazz Reporting Service MEDIUM 5.4
CVE-2016-2888

Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0…

Mitigation only
Fix from $1,600 2016-07-08
Jazz Reporting Service MEDIUM 5.4
CVE-2016-0350

Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0…

Mitigation only
Fix from $1,600 2016-07-08
Jazz Reporting Service HIGH 8.8
CVE-2016-0315

The Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 main…

Mitigation only
Fix from $1,950 2016-07-08
Jazz Reporting Service MEDIUM 6.5
CVE-2016-0314

The Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 allo…

Mitigation only
Fix from $1,600 2016-07-08
Jazz Reporting Service MEDIUM 5.4
CVE-2016-0313

Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0…

Mitigation only
Fix from $1,600 2016-07-08
I Access HIGH 7.8
CVE-2016-0287

IBM i Access 7.1 on Windows allows local users to discover registry passwords via unspecified vectors.

Mitigation only
Fix from $1,950 2016-07-08
Urbancode Deploy HIGH 8.2
CVE-2016-0271

The agents in IBM UrbanCode Deploy 6.x before 6.0.1.14, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1 do not verify a server's identity in a JMS ses…

Mitigation only
Fix from $1,950 2016-07-08
Control Center MEDIUM 5.1
CVE-2016-0252

IBM Control Center 6.x before 6.0.0.1 iFix06 and Sterling Control Center 5.4.x before 5.4.2.1 iFix09 allow local users to decrypt the master key via …

Mitigation only
Fix from $1,600 2016-07-08
Websphere Application Server HIGH 7.5
CVE-2016-2923

IBM WebSphere Application Server (WAS) 8.5 through 8.5.5.9 Liberty before Liberty Fix Pack 16.0.0.2 does not include the HTTPOnly flag in a Set-Cooki…

Mitigation only
Fix from $1,950 2016-07-07
Websphere Application Server MEDIUM 5.3
CVE-2016-0389

Admin Center in IBM WebSphere Application Server (WAS) 8.5.5.2 through 8.5.5.9 Liberty before Liberty Fix Pack 16.0.0.2 allows remote attackers to ob…

Mitigation only
Fix from $1,600 2016-07-07