Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Infosphere Master Data Management HIGH 7.5
CVE-2014-3063

IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1-FP11 and 11.x before 11.0-FP5 and InfoSphere Master Data Management Se…

Patch available
Fix from $1,950 2014-08-17
Global Console Manager 16 Firmware HIGH 7.1
CVE-2014-3085EPSS 8%

systest.php on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allows remote authenticated users to execute ar…

Fix: after 1.20.0.22575
Fix from $1,950 2014-08-17
Infosphere Master Data Management MEDIUM 6.8
CVE-2014-0969

Cross-site request forgery (CSRF) vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x b…

Patch available
Fix from $1,600 2014-08-17
Infosphere Master Data Management MEDIUM 6.5
CVE-2014-0966

SQL injection vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0-FP5 and I…

Mitigation only
Fix from $1,600 2014-08-17
Global Console Manager 16 Firmware MEDIUM 6.3
CVE-2014-3081

prodtest.php on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allows remote authenticated users to read arbi…

Fix: after 1.20.0.22575
Fix from $1,600 2014-08-17
Security Appscan Source HIGH 7.2
CVE-2014-3072

Unspecified vulnerability in the Automation Server in IBM Security AppScan Source 8 through 8.0.0.2, 8.5 through 8.5.0.1, 8.6 through 8.6.0.2, 8.7 th…

Patch available
Fix from $1,950 2014-08-12
Websphere Portal MEDIUM 5.8
CVE-2014-4760

Open redirect vulnerability in IBM WebSphere Portal 6.1.0.0 through 6.1.0.6 CF27, 6.1.5.0 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF28, 8.0.0 bef…

Patch available
Fix from $1,600 2014-08-12
Websphere Portal MEDIUM 5.0
CVE-2014-4746

IBM WebSphere Portal 8.0.0 before 8.0.0.1 CF13 and 8.5.0 through CF01 provides different error codes for firewall-traversal requests depending on whe…

Patch available
Fix from $1,600 2014-08-12
Lotus Notes HIGH 7.5
CVE-2014-3086EPSS 5%

Unspecified vulnerability in the IBM Java Virtual Machine, as used in IBM WebSphere Real Time 3 before Service Refresh 7 FP1 and other products, allo…

Mitigation only
Fix from $1,950 2014-08-12
Business Process Manager MEDIUM 5.0
CVE-2014-3076

IBM Business Process Manager (BPM) 8.5 through 8.5.5 allows remote attackers to obtain potentially sensitive information by visiting an unspecified J…

Patch available
Fix from $1,600 2014-08-11
Rational Software Architect Design Manager MEDIUM 6.0
CVE-2014-0947

Unspecified vulnerability in the server in IBM Rational Software Architect Design Manager 4.0.6 allows remote authenticated users to execute arbitrar…

Mitigation only
Fix from $1,600 2014-07-30
Rhapsody Design Manager MEDIUM 6.0
CVE-2014-0948

Unspecified vulnerability in IBM Rational Software Architect Design Manager and Rational Rhapsody Design Manager 3.x and 4.x before 4.0.7 allows remo…

Mitigation only
Fix from $1,600 2014-07-30
Websphere Portal HIGH 7.5
CVE-2014-3055

SQL injection vulnerability in the Unified Task List (UTL) Portlet for IBM WebSphere Portal 7.x and 8.x through 8.0.0.1 CF12 allows remote attackers …

Mitigation only
Fix from $1,950 2014-07-29
Embedded Websphere Application Server MEDIUM 6.9
CVE-2014-3020

install.sh in the Embedded WebSphere Application Server (eWAS) 7.0 before FP33 in IBM Tivoli Integrated Portal (TIP) 2.1 and 2.2 sets world-writable …

Mitigation only
Fix from $1,600 2014-07-29
Websphere Portal MEDIUM 5.8
CVE-2014-3054

Multiple open redirect vulnerabilities in the Unified Task List (UTL) Portlet for IBM WebSphere Portal 7.x and 8.x through 8.0.0.1 CF12 allow remote …

Mitigation only
Fix from $1,600 2014-07-29
Websphere Portal MEDIUM 5.0
CVE-2014-3056

The Unified Task List (UTL) Portlet for IBM WebSphere Portal 7.x and 8.x through 8.0.0.1 CF12 allows remote attackers to obtain potentially sensitive…

Mitigation only
Fix from $1,600 2014-07-29
Storwize Unified V7000 Software MEDIUM 6.5
CVE-2014-3043

IBM Storwize V7000 Unified 1.3.x and 1.4.x before 1.4.3.3 allows remote authenticated users to gain privileges by leveraging access to the service ac…

Mitigation only
Fix from $1,600 2014-07-19
Infosphere Master Data Management Collaboration Server MEDIUM 6.3
CVE-2014-3064

The GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0 FP4 and InfoSphere Master Data Managemen…

Mitigation only
Fix from $1,600 2014-07-19
Algo Credit Limits MEDIUM 6.8
CVE-2014-0864

Multiple cross-site request forgery (CSRF) vulnerabilities in Executer in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0…

No fix yet
Fix from $1,600 2014-07-07
Infosphere Biginsights MEDIUM 6.5
CVE-2013-3993 KEVEPSS 5%

IBM InfoSphere BigInsights before 2.1.0.3 allows remote authenticated users to bypass intended file and directory restrictions, or access untrusted d…

Fix: 2.1.0.3+
Fix from $1,600 2014-07-07
Algo Credit Limits MEDIUM 5.8
CVE-2014-0867EPSS 5%

rcore6/main/addcookie.jsp in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allows remote att…

No fix yet
Fix from $1,600 2014-07-07
Flex System Manager MEDIUM 5.0
CVE-2013-5423

IBM Flex System Manager (FSM) 1.1 through 1.3 before 1.3.2.0 allows remote attackers to enumerate user accounts via unspecified vectors.

Mitigation only
Fix from $1,600 2014-07-07
Integrated Management Module Firmware MEDIUM 5.0
CVE-2014-0860

The firmware before 3.66E in IBM BladeCenter Advanced Management Module (AMM), the firmware before 1.43 in IBM Integrated Management Module (IMM), an…

Fix: after 3.65
Fix from $1,600 2014-07-07
Vios HIGH 7.2
CVE-2014-3074

The runtime linker in IBM AIX 6.1 and 7.1 and VIOS 2.2.x allows local users to create a mode-666 root-owned file, and consequently gain privileges, b…

No fix yet
Fix from $1,950 2014-07-02
Tivoli Endpoint Manager MEDIUM 5.0
CVE-2014-3066

IBM Tivoli Endpoint Manager 9.1 before 9.1.1088.0 allows remote attackers to read arbitrary files via XML data containing an external entity declarat…

Mitigation only
Fix from $1,600 2014-07-02
Sametime Meeting Server MEDIUM 5.5
CVE-2014-3088

stconf.nsf in IBM Sametime Meeting Server 8.5.1 relies on the client to validate the file format used in wAttach?OpenForm multipart/form-data POST re…

No fix yet
Fix from $1,600 2014-07-01
Marketing Platform MEDIUM 6.5
CVE-2013-6311

SQL injection vulnerability in IBM Marketing Platform 9.1 before FP2 allows remote authenticated users to execute arbitrary SQL commands via unspecif…

Mitigation only
Fix from $1,600 2014-06-28
Marketing Platform MEDIUM 6.0
CVE-2013-6309

IBM Marketing Platform 9.1 before FP2 allows remote authenticated users to hijack sessions, and consequently read records, modify records, or conduct…

Mitigation only
Fix from $1,600 2014-06-28
Websphere Application Server MEDIUM 5.0
CVE-2014-0891

IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.33, 8.0.x before 8.0.0.9, and 8.5.x before 8.5.5.2 allows remote attackers to obtain sensit…

Patch available
Fix from $1,600 2014-06-28
Openpages Grc Platform MEDIUM 6.4
CVE-2011-1381

Unspecified vulnerability in IBM OpenPages GRC Platform 6.1.0.1 before IF4 allows remote attackers to bypass intended access restrictions via unknown…

Mitigation only
Fix from $1,600 2014-06-27