Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Websphere Application Server HIGH 10.0
CVE-2015-1920EPSS 7%

IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.47, 7.0 before 7.0.0.39, 8.0 before 8.0.0.11, and 8.5 before 8.5.5.6 allows remote attackers…

Patch available
Fix from $1,950 2015-05-20
Websphere Application Server HIGH 9.3
CVE-2015-1885

WebSphereOauth20SP.ear in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.39, 8.0 before 8.0.0.11, 8.5 Liberty Profile before 8.5.5.5, and 8.…

Patch available
Fix from $1,950 2015-04-27
Websphere Application Server HIGH 8.5
CVE-2015-1882

Multiple race conditions in IBM WebSphere Application Server (WAS) 8.5 Liberty Profile before 8.5.5.5 allow remote authenticated users to gain privil…

Patch available
Fix from $1,950 2015-04-27
Websphere Application Server MEDIUM 5.5
CVE-2015-0175

IBM WebSphere Application Server (WAS) 8.5 Liberty Profile before 8.5.5.5 does not properly implement authData elements, which allows remote authenti…

Patch available
Fix from $1,600 2015-04-27
Websphere Portal HIGH 7.8
CVE-2015-1886

The Remote Document Conversion Service (DCS) in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF…

Patch available
Fix from $1,950 2015-04-27
Rational Software Architect Design Manager MEDIUM 5.0
CVE-2015-0113

The Jazz help system in IBM Rational Collaborative Lifecycle Management 4.0 through 5.0.2, Rational Quality Manager 4.0 through 4.0.7 and 5.0 through…

Patch available
Fix from $1,600 2015-04-27
Curam Social Program Management MEDIUM 5.0
CVE-2014-6092

IBM Curam Social Program Management (SPM) 5.2 before SP6 EP6, 6.0 SP2 before EP26, 6.0.4 before 6.0.4.6, and 6.0.5 before 6.0.5.6 requires failed-log…

Fix: after 5.2
Fix from $1,600 2015-04-27
Curam Social Program Management MEDIUM 6.8
CVE-2014-6090

Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) DataMappingEditorCommands, (2) DatastoreEditorCommands, and (3) IEGEditorComman…

Patch available
Fix from $1,600 2015-04-27
Infosphere Biginsights MEDIUM 6.5
CVE-2015-1889

The Big SQL component in IBM InfoSphere BigInsights 3.0 through 3.0.0.2 allows remote authenticated users to bypass intended HDFS data-access restric…

Mitigation only
Fix from $1,600 2015-04-22
Domino HIGH 10.0
CVE-2015-0135EPSS 42%

IBM Domino 8.5 before 8.5.3 FP6 IF4 and 9.0 before 9.0.1 FP3 IF2 allows remote attackers to execute arbitrary code or cause a denial of service (inte…

Patch available
Fix from $1,950 2015-04-21
Tivoli Storage Manager Fastback HIGH 7.2
CVE-2015-1898

Stack-based buffer overflow in the FastBackMount process in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.11.1 allows local users to gain privil…

Patch available
Fix from $1,950 2015-04-15
Tivoli Storage Manager Fastback HIGH 7.2
CVE-2015-1897

Stack-based buffer overflow in the FastBackMount process in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.11.1 allows local users to gain privil…

Patch available
Fix from $1,950 2015-04-15
Websphere Datapower Xc10 Appliance Firmware MEDIUM 6.8
CVE-2015-1893

The IBM WebSphere DataPower XC10 appliance 2.1 before 2.1.0.3 allows remote attackers to hijack the sessions of arbitrary users, and consequently obt…

Patch available
Fix from $1,600 2015-04-06
Domino HIGH 7.2
CVE-2015-0179

Notes System Diagnostic (NSD) in IBM Domino 8.5.x before 8.5.3 FP6 IF6 and 9.x before 9.0.1 FP3 IF1 allows local users to obtain the System privilege…

Patch available
Fix from $1,950 2015-04-06
Domino HIGH 10.0
CVE-2015-0134

Buffer overflow in the SSLv2 implementation in IBM Domino 8.5.x before 8.5.1 FP5 IF3, 8.5.2 before FP4 IF3, 8.5.3 before FP6 IF6, 9.0 before IF7, and…

Patch available
Fix from $1,950 2015-04-06
Tivoli Storage Manager Fastback HIGH 7.5
CVE-2015-0119

FastBack Mount in IBM Tivoli Storage Manager FastBack 6.1.x before 6.1.11.1 allows remote attackers to execute arbitrary code by connecting to the Mo…

Fix: after 6.1.11.0
Fix from $1,950 2015-04-06
Domino HIGH 10.0
CVE-2015-0117

The LDAP Server in IBM Domino 8.5.x before 8.5.3 FP6 IF6 and 9.x before 9.0.1 FP3 IF1 allows remote attackers to execute arbitrary code or cause a de…

Patch available
Fix from $1,950 2015-04-06
Rational Clearcase HIGH 9.4
CVE-2014-6221

The MSCAPI/MSCNG interface implementation in GSKit in IBM Rational ClearCase 7.1.2.x before 7.1.2.17, 8.0.0.x before 8.0.0.14, and 8.0.1.x before 8.0…

Patch available
Fix from $1,950 2015-04-06
Security Access Manager For Web 7.0 Firmware MEDIUM 5.0
CVE-2015-1892

The Multicast DNS (mDNS) responder in IBM Security Access Manager for Web 7.x before 7.0.0 FP12 and 8.x before 8.0.1 FP1 inadvertently responds to un…

Fix: after 7.0.0.11
Fix from $1,600 2015-04-01
Rational Clearquest MEDIUM 6.8
CVE-2014-8925

Cross-site request forgery (CSRF) vulnerability in ClearQuest Web in IBM Rational ClearQuest 7.1.x before 7.1.2.17, 8.0.0.x before 8.0.0.14, and 8.0.…

Patch available
Fix from $1,600 2015-03-25
General Parallel File System HIGH 10.0
CVE-2015-0198

IBM General Parallel File System (GPFS) 3.4 before 3.4.0.32, 3.5 before 3.5.0.24, and 4.1 before 4.1.0.7 in certain cipherList configurations allows …

Patch available
Fix from $1,950 2015-03-24
General Parallel File System HIGH 7.2
CVE-2015-0197

IBM General Parallel File System (GPFS) 3.4 before 3.4.0.32, 3.5 before 3.5.0.24, and 4.1 before 4.1.0.7 allows local users to obtain root privileges…

Patch available
Fix from $1,950 2015-03-24
Api Management MEDIUM 5.5
CVE-2015-0149

The developer portal in IBM API Management 3.0 before 3.0.4.1 does not properly restrict access to the public and private APIs, which allows remote a…

Patch available
Fix from $1,600 2015-03-18
Rational Requirements Composer HIGH 7.8
CVE-2015-0132

The XML parser in IBM Rational DOORS Next Generation 4.x before 4.0.7 iFix3 and 5.x before 5.0.2 and Rational Requirements Composer 2.x and 3.x befor…

Patch available
Fix from $1,950 2015-03-18
Rational Quality Manager MEDIUM 5.5
CVE-2014-6129

IBM Rational Jazz Team Server (JTS), as used in Rational Collaborative Lifecycle Management 3.x and 4.x before 4.0.7 iFix4 and 5.x before 5.0.2 iFix2…

Patch available
Fix from $1,600 2015-03-18
Websphere Commerce MEDIUM 5.0
CVE-2015-0133

IBM WebSphere Commerce 7.0 Feature Pack 4 through 8 allows remote attackers to read arbitrary files and possibly obtain administrative privileges via…

Patch available
Fix from $1,600 2015-03-13
Websphere Portal MEDIUM 6.8
CVE-2014-6214

Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Portal 8.0.0 through 8.0.0.1 CF15 and 8.5.0 before CF05 allows remote attackers to h…

Patch available
Fix from $1,600 2015-03-13
Java Sdk HIGH 7.8
CVE-2014-8892

Unspecified vulnerability in the Java Virtual Machine (JVM) in IBM SDK, Java Technology Edition 5.0 before SR16-FP9, 6 before SR16-FP3, 6R1 before SR…

Fix: 6.0.16.3 / 7.0.8.10+
Fix from $1,950 2015-03-06
Java Sdk HIGH 10.0
CVE-2014-8891EPSS 7%

Unspecified vulnerability in the Java Virtual Machine (JVM) in IBM SDK, Java Technology Edition 5.0 before SR16-FP9, 6 before SR16-FP3, 6R1 before SR…

Fix: 6.0.16.3 / 7.0.8.10+
Fix from $1,950 2015-03-06
Rational Insight MEDIUM 5.0
CVE-2014-6115

IBM Rational Insight 1.1.1.5 allows remote attackers to bypass authentication and obtain sensitive information via a crafted request to a Jazz Report…

Patch available
Fix from $1,600 2015-02-24