Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Sametime MEDIUM 6.8
CVE-2013-3988

The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to conduct clickjacking attacks via unspecif…

Mitigation only
Fix from $1,600 2014-02-14
Sametime MEDIUM 5.0
CVE-2013-3978

The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 does not send the appropriate HTTP response headers to prevent unwan…

Mitigation only
Fix from $1,600 2014-02-14
Platform Symphony HIGH 10.0
CVE-2013-5400

An unspecified servlet in IBM Platform Symphony Developer Edition (DE) 5.2 and 6.1.x through 6.1.1 has hardcoded credentials, which allows remote att…

Mitigation only
Fix from $1,950 2014-02-14
Websphere Portal MEDIUM 5.8
CVE-2013-6722

Unrestricted file upload vulnerability in the Registration/Edit My Profile portlet in IBM WebSphere Portal 7.x before 7.0.0.2 CF27 and 8.x through 8.…

Mitigation only
Fix from $1,600 2014-02-14
Websphere Dashboard Framework MEDIUM 5.8
CVE-2013-6728

The charting component in IBM WebSphere Dashboard Framework (WDF) 6.1.5 and 7.0.1 allows remote attackers to view or delete image files by leveraging…

Mitigation only
Fix from $1,600 2014-02-14
Lotus Domino HIGH 7.8
CVE-2014-0822

The IMAP server in IBM Domino 8.5.x before 8.5.3 FP6 IF1 and 9.0.x before 9.0.1 FP1 allows remote attackers to cause a denial of service (daemon cras…

Mitigation only
Fix from $1,950 2014-02-06
Algo One HIGH 8.5
CVE-2013-6332

Unrestricted file upload vulnerability in IBM Algo One UDS 4.7.0 through 5.0.0 allows remote authenticated users to execute arbitrary code by uploadi…

Mitigation only
Fix from $1,950 2014-02-06
Infosphere Master Data Management Collaboration Server MEDIUM 6.8
CVE-2013-5427

Cross-site request forgery (CSRF) vulnerability in IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1 FP8 through 11.0 an…

Mitigation only
Fix from $1,600 2014-02-04
Spss Samplepower HIGH 9.3
CVE-2013-6724

Unspecified vulnerability in the vsflex8l ActiveX control in IBM SPSS SamplePower 3.0.1 before FP1 IF1 allows remote attackers to execute arbitrary c…

Mitigation only
Fix from $1,950 2014-02-01
Financial Transaction Manager MEDIUM 6.8
CVE-2014-0831

Cross-site request forgery (CSRF) vulnerability in the OAC component in IBM Financial Transaction Manager (FTM) 2.0 before 2.0.0.3 allows remote atta…

Mitigation only
Fix from $1,600 2014-02-01
Financial Transaction Manager MEDIUM 5.5
CVE-2014-0833

The OAC component in IBM Financial Transaction Manager (FTM) 2.0 before 2.0.0.3 does not properly enforce operator-intervention requirements, which a…

Mitigation only
Fix from $1,600 2014-02-01
Spss Collaboration And Deployment Services MEDIUM 5.0
CVE-2013-4043

The server in IBM SPSS Collaboration and Deployment Services 4.x before 4.2.1.3 IF3, 5.x before 5.0 FP3, and 6.x before 6.0 IF1 allows remote attacke…

Mitigation only
Fix from $1,600 2014-02-01
Sametime MEDIUM 5.0
CVE-2013-6727

The Connect client in IBM Sametime 8.5.2 through 8.5.2.1 and 9.0 before HF1 does not properly restrict unsigned Java plugins, which allows remote att…

Mitigation only
Fix from $1,600 2014-01-31
Qradar Security Information And Event Manager HIGH 7.5
CVE-2014-0838

The AutoUpdate package before 6.4 for IBM Security QRadar SIEM 7.2 MR1 and earlier allows remote attackers to execute arbitrary console commands by l…

Fix: after 7.2.0
Fix from $1,950 2014-01-30
Qradar Security Information And Event Manager MEDIUM 6.8
CVE-2014-0835

Cross-site request forgery (CSRF) vulnerability in IBM Security QRadar SIEM 7.2 MR1 and earlier allows remote attackers to hijack the authentication …

Fix: after 7.2.0
Fix from $1,600 2014-01-30
Tivoli Application Dependency Discovery Manager HIGH 7.5
CVE-2013-2974

The BIRT viewer in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.1.x before 7.2.1.5 allows remote authenticated users to bypass aut…

Mitigation only
Fix from $1,950 2014-01-29
Lotus Quickr For Domino HIGH 7.5
CVE-2013-6748

Buffer overflow in the ActiveX control in qp2.cab in IBM Lotus Quickr for Domino 8.5.1 before 8.5.1.42-001b allows remote attackers to execute arbitr…

Mitigation only
Fix from $1,950 2014-01-29
Lotus Quickr For Domino HIGH 7.5
CVE-2013-6749

Buffer overflow in the ActiveX control in qp2.cab in IBM Lotus Quickr for Domino 8.5.1 before 8.5.1.42-001b allows remote attackers to execute arbitr…

Mitigation only
Fix from $1,950 2014-01-29
Global Security Kit HIGH 7.1
CVE-2013-6747

IBM GSKit 7.x before 7.0.4.48 and 8.x before 8.0.50.16, as used in IBM Security Directory Server (ISDS) and Tivoli Directory Server (TDS), allows rem…

Mitigation only
Fix from $1,950 2014-01-27
Java HIGH 10.0
CVE-2013-0485

Unspecified vulnerability in IBM Java SDK 7 before SR4-FP1, 6 before SR13-FP1, 5.0 before SR16-FP1, and 1.4.2 before SR13-FP16 has unknown impact and…

Mitigation only
Fix from $1,950 2014-01-21
Atlas Ediscovery Process Management HIGH 7.5
CVE-2013-6321

SQL injection vulnerability in IBM Atlas eDiscovery Process Management 6.0.1.5 and earlier and 6.0.2, Disposal and Governance Management for IT 6.0.1…

Fix: after 6.0.1.5
Fix from $1,950 2014-01-10
Atlas Ediscovery Process Management MEDIUM 6.4
CVE-2013-6334

IBM Atlas eDiscovery Process Management 6.0.1.5 and earlier and 6.0.2, Disposal and Governance Management for IT 6.0.1.5 and earlier and 6.0.2, and G…

Fix: after 6.0.1.5
Fix from $1,600 2014-01-10
I HIGH 8.5
CVE-2013-5385

The OSPF implementation in IBM i 6.1 and 7.1, in z/OS on zSeries servers, and in Networking Operating System (aka NOS, formerly BLADE Operating Syste…

Mitigation only
Fix from $1,950 2014-01-02
Websphere Portal MEDIUM 5.0
CVE-2013-6723

IBM WebSphere Portal 8.0.0.1 before CF09 does not properly handle references in compute="always" Web Content Manager (WCM) navigator components, whic…

Patch available
Fix from $1,600 2013-12-22
Websphere Portal MEDIUM 5.0
CVE-2013-6735

IBM WebSphere Portal 6.0.0.x through 6.0.0.1, 6.0.1.x through 6.0.1.7, 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x through 7.…

Patch available
Fix from $1,600 2013-12-22
Sterling B2b Integrator MEDIUM 6.5
CVE-2013-5409

Multiple SQL injection vulnerabilities in IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 allow remote authenticated users to execute a…

Mitigation only
Fix from $1,600 2013-12-21
Spss Collaboration And Deployment Services MEDIUM 5.8
CVE-2013-4046

Open redirect vulnerability in IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote attackers to …

Mitigation only
Fix from $1,600 2013-12-21
Spss Collaboration And Deployment Services MEDIUM 5.0
CVE-2013-4069

The Portal application in IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote attackers to read …

Mitigation only
Fix from $1,600 2013-12-21
Spss Collaboration And Deployment Services MEDIUM 5.0
CVE-2013-4070

The Portal application in IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote attackers to disco…

Mitigation only
Fix from $1,600 2013-12-21
Rational Clearcase HIGH 7.2
CVE-2013-5415

Buffer overflow in IBM Rational ClearCase through 7.1.2.12, 8.0.0.x before 8.0.0.9, and 8.0.1.x before 8.0.1.2 allows local users to gain privileges …

Mitigation only
Fix from $1,950 2013-12-18