Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Websphere Application Server MEDIUM 5.0
CVE-2014-0859

The web-server plugin in IBM WebSphere Application Server (WAS) 7.x before 7.0.0.33, 8.x before 8.0.0.9, and 8.5.x before 8.5.5.2, when POST retries …

Mitigation only
Fix from $1,600 2014-05-01
Lotus Domino MEDIUM 5.0
CVE-2014-0892

IBM Notes and Domino 8.5.x before 8.5.3 FP6 IF3 and 9.x before 9.0.1 FP1 on 32-bit Linux platforms use incorrect gcc options, which makes it easier f…

Mitigation only
Fix from $1,600 2014-04-23
Rhapsody Design Manager MEDIUM 5.5
CVE-2013-5459

Unspecified vulnerability in IBM Rational Software Architect (RSA) Design Manager and Rational Rhapsody Design Manager 3.x through 3.0.1 and 4.x befo…

Mitigation only
Fix from $1,600 2014-04-21
Business Process Manager MEDIUM 6.0
CVE-2014-0908

The User Attribute implementation in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.2, and 8.5.x through 8.5.0.1 does …

Mitigation only
Fix from $1,600 2014-04-10
Storwize V7000 Software HIGH 7.5
CVE-2014-0880

IBM SAN Volume Controller; Storwize V3500, V3700, V5000, and V7000; and Flex System V7000 with software 6.3 and 6.4 before 6.4.1.8, and 7.1 and 7.2 b…

Mitigation only
Fix from $1,950 2014-03-29
Security Appscan HIGH 7.6
CVE-2014-0904

The update process in IBM Security AppScan Standard 7.9 through 8.8 does not require integrity checks of downloaded files, which allows remote attack…

Mitigation only
Fix from $1,950 2014-03-26
Lotus Protector For Mail Security HIGH 7.1
CVE-2014-0886

The Admin Web UI in IBM Lotus Protector for Mail Security 2.8.x before 2.8.1-22905 allows remote authenticated users to bypass intended access restri…

Mitigation only
Fix from $1,950 2014-03-25
Lotus Protector For Mail Security HIGH 7.1
CVE-2014-0887

The Admin Web UI in IBM Lotus Protector for Mail Security 2.8.x before 2.8.1-22905 allows remote authenticated users to execute arbitrary commands wi…

Mitigation only
Fix from $1,950 2014-03-25
Lotus Protector For Mail Security MEDIUM 6.8
CVE-2014-0885

Cross-site request forgery (CSRF) vulnerability in the Admin Web UI in IBM Lotus Protector for Mail Security 2.8.x before 2.8.1-22905 allows remote a…

Mitigation only
Fix from $1,600 2014-03-25
Cognos Express MEDIUM 6.8
CVE-2013-5443

Cross-site request forgery (CSRF) vulnerability in IBM Cognos Express 9.0 before IFIX 2, 9.5 before IFIX 2, 10.1 before IFIX 2, and 10.2.1 before FP1…

Mitigation only
Fix from $1,600 2014-03-25
Cognos Express MEDIUM 5.0
CVE-2013-5444

The server in IBM Cognos Express 9.0 before IFIX 2, 9.5 before IFIX 2, 10.1 before IFIX 2, and 10.2.1 before FP1 allows remote attackers to read encr…

Mitigation only
Fix from $1,600 2014-03-25
Cognos Express MEDIUM 5.0
CVE-2013-5445

IBM Cognos Express 9.0 before IFIX 2, 9.5 before IFIX 2, 10.1 before IFIX 2, and 10.2.1 before FP1 allows local users to obtain sensitive cleartext i…

Mitigation only
Fix from $1,600 2014-03-25
Datacap Taskmaster Capture HIGH 9.3
CVE-2014-0879

Stack-based buffer overflow in the Taskmaster Capture ActiveX control in IBM Datacap Taskmaster Capture 8.0.1, and 8.1 before FP2, allows remote atta…

Patch available
Fix from $1,950 2014-03-21
Rational Clearcase MEDIUM 6.5
CVE-2014-0829

Multiple buffer overflows in IBM Rational ClearCase 7.x before 7.1.2.13, 8.0.0.x before 8.0.0.10, and 8.0.1.x before 8.0.1.3 allow remote authenticat…

Patch available
Fix from $1,600 2014-03-21
Websphere Mq Internet Pass Thru MEDIUM 5.0
CVE-2013-5401

The command-port listener in IBM WebSphere MQ Internet Pass-Thru (MQIPT) 2.x before 2.1.0.1 allows remote attackers to cause a denial of service (rem…

Mitigation only
Fix from $1,600 2014-03-21
Spss Samplepower HIGH 7.5
CVE-2014-0895

Buffer overflow in the vsflex8l ActiveX control in IBM SPSS SamplePower 3.0.1 before FP1 3.0.1-IM-S3SAMPC-WIN32-FP001-IF02 allows remote attackers to…

Mitigation only
Fix from $1,950 2014-03-16
Infosphere Master Data Management Server MEDIUM 6.8
CVE-2014-0873

Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) Data Stewardship, (2) Business Admin, and (3) Product interfaces in IBM InfoSph…

Mitigation only
Fix from $1,600 2014-03-16
Infosphere Information Server MEDIUM 6.8
CVE-2013-4057

Cross-site request forgery (CSRF) vulnerability in the XML Pack in IBM InfoSphere Information Server 8.5.x through 8.5 FP3, 8.7.x through 8.7 FP2, an…

Mitigation only
Fix from $1,600 2014-03-16
Infosphere Information Server MEDIUM 6.5
CVE-2013-4058

Multiple SQL injection vulnerabilities in IBM InfoSphere Information Server 8.x through 8.5 FP3, 8.7.x through 8.7 FP2, and 9.1.x through 9.1.2.0 all…

Mitigation only
Fix from $1,600 2014-03-16
Aix MEDIUM 6.5
CVE-2014-0899

ftpd in IBM AIX 7.1.1 before SP10 and 7.1.2 before SP5, when a Workload Partition (aka WPAR) for AIX 5.2 or 5.3 is used, allows remote authenticated …

Mitigation only
Fix from $1,600 2014-03-11
Tealeaf Cx MEDIUM 6.0
CVE-2013-6719EPSS 27%

delivery.php in the Passive Capture Application (PCA) web console in IBM Tealeaf CX 7.x, 8.x through 8.6, 8.7 before FP2, and 8.8 before FP2 allows r…

No fix yet
Fix from $1,600 2014-03-06
Tealeaf Cx MEDIUM 5.5
CVE-2013-6720EPSS 29%

Directory traversal vulnerability in download.php in the Passive Capture Application (PCA) web console in IBM Tealeaf CX 7.x, 8.x through 8.6, 8.7 be…

No fix yet
Fix from $1,600 2014-03-06
Algo One MEDIUM 6.5
CVE-2013-6302

SQL injection vulnerability in IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Security Access Control …

Mitigation only
Fix from $1,600 2014-03-05
Algo One MEDIUM 6.5
CVE-2013-6331

SQL injection vulnerability in IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Security Access Control …

Mitigation only
Fix from $1,600 2014-03-05
Algo One MEDIUM 5.0
CVE-2013-5468

IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Security Access Control Management 4.7.0 through 4.9.0,…

Mitigation only
Fix from $1,600 2014-03-05
Rational Collaborative Lifecycle Management HIGH 10.0
CVE-2014-0862

Unspecified vulnerability in Jazz Team Server in IBM Rational Collaborative Lifecycle Management (CLM) 3.x before 3.0.1.6 iFix 2 and 4.x before 4.0.6…

Mitigation only
Fix from $1,950 2014-03-02
Rational Focal Point MEDIUM 5.0
CVE-2014-0842

The account-creation functionality in IBM Rational Focal Point 6.4.x and 6.5.x before 6.5.2.3 and 6.6.x before 6.6.1 places the new user's default pa…

Patch available
Fix from $1,600 2014-02-26
Cognos Business Intelligence MEDIUM 5.0
CVE-2014-0854

The server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1 before IF6, 10.1.1 before IF5, 10.2 before IF7, 10.2.1 before IF4, and 10.2.1.1 befor…

Mitigation only
Fix from $1,600 2014-02-22
Sametime HIGH 7.5
CVE-2013-3983

The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 does not validate URLs in Cookie headers before using them in redire…

Mitigation only
Fix from $1,950 2014-02-14
Sametime HIGH 7.5
CVE-2013-6742

The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 do not have an off autocomplete attribute for a password field, whic…

Mitigation only
Fix from $1,950 2014-02-14