Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Rational Clearcase HIGH 7.2
CVE-2013-5416

Unspecified vulnerability in IBM Rational ClearCase through 7.1.2.12, 8.0.0.x before 8.0.0.9, and 8.0.1.x before 8.0.1.2 allows local users to gain p…

Mitigation only
Fix from $1,950 2013-12-18
Content Manager Ondemand For Multiplatforms HIGH 7.8
CVE-2013-6329

IBM Global Security Kit (aka GSKit), as used in Content Manager OnDemand 8.5 and 9.0 and other products, allows remote attackers to cause a denial of…

Patch available
Fix from $1,950 2013-12-17
Cognos Command Center MEDIUM 6.8
CVE-2013-4000

Multiple cross-site request forgery (CSRF) vulnerabilities in IBM Cognos Command Center before 10.2 allow remote attackers to hijack the authenticati…

Fix: after 10.1
Fix from $1,600 2013-12-14
Forms Viewer MEDIUM 6.8
CVE-2013-5447EPSS 34%

Stack-based buffer overflow in IBM Forms Viewer 4.x before 4.0.0.3 and 8.x before 8.0.1.1 allows remote attackers to execute arbitrary code via an XF…

No fix yet
Fix from $1,600 2013-12-10
Advanced Management Module Firmware MEDIUM 6.4
CVE-2013-6718

The Advanced Management Module (AMM) with firmware 3.64B, 3.64C, and 3.64G for IBM BladeCenter systems allows remote attackers to discover account na…

Mitigation only
Fix from $1,600 2013-12-01
Java HIGH 9.3
CVE-2013-5456EPSS 6%

The com.ibm.rmi.io.SunSerializableFactory class in IBM Java SDK 7.0.0 before SR6 allows remote attackers to bypass a sandbox protection mechanism and…

Mitigation only
Fix from $1,950 2013-11-24
Java HIGH 9.3
CVE-2013-5457EPSS 6%

Unspecified vulnerability in IBM Java SDK 7.0.0 before SR6, 6.0.1 before SR7, and 6.0.0 before SR15 allows remote attackers to execute arbitrary code…

Mitigation only
Fix from $1,950 2013-11-24
Java HIGH 9.3
CVE-2013-5458EPSS 5%

Unspecified vulnerability in IBM Java SDK 7.0.0 before SR6 allows remote attackers to execute arbitrary code via unspecified vectors.

Mitigation only
Fix from $1,950 2013-11-24
Java MEDIUM 6.8
CVE-2013-4041

Unspecified vulnerability in IBM Java SDK 5.0.0 before SR16 FP4, 7.0.0 before SR6, 6.0.1 before SR7, and 6.0.0 before SR15 allows remote attackers to…

No fix yet
Fix from $1,600 2013-11-24
Java MEDIUM 6.8
CVE-2013-5375

Unspecified vulnerability in IBM Java SDK 7.0.0 before SR6, 6.0.1 before SR7, 6.0.0 before SR15, and 5.0.0 before SR16 FP4 allows remote attackers to…

Mitigation only
Fix from $1,600 2013-11-24
Rational Performance Tester MEDIUM 5.0
CVE-2013-6312

Unspecified vulnerability in IBM Rational Service Tester 8.3.x and 8.5.x before 8.5.1 and Rational Performance Tester 8.3.x and 8.5.x before 8.5.1 al…

Mitigation only
Fix from $1,600 2013-11-22
Cognos Business Intelligence MEDIUM 5.0
CVE-2013-3030

The servlet gateway in IBM Cognos Business Intelligence 8.4.1 before IF3, 10.1.0 before IF4, 10.1.1 before IF4, 10.2.0 before IF4, 10.2.1 before IF2,…

Mitigation only
Fix from $1,600 2013-11-18
Lotus Domino MEDIUM 6.0
CVE-2013-4050

Cross-site request forgery (CSRF) vulnerability in webadmin.nsf in Domino Web Administrator in IBM Domino 8.5 and 9.0 allows remote authenticated use…

Mitigation only
Fix from $1,600 2013-11-08
Tivoli Federated Identity Manager MEDIUM 5.8
CVE-2013-5431

Open redirect vulnerability in IBM Tivoli Federated Identity Manager (TFIM) 6.1.1 before IF 15, 6.2.0 before IF 14, 6.2.1, and 6.2.2 before IF 8 and …

Mitigation only
Fix from $1,600 2013-11-01
Security Appscan MEDIUM 5.5
CVE-2013-5430

The Jazz Team Server component in IBM Security AppScan Enterprise 8.x before 8.8 has a default username and password, which makes it easier for remot…

Mitigation only
Fix from $1,600 2013-10-28
Flex System Manager MEDIUM 6.8
CVE-2013-5424

IBM Flex System Manager (FSM) 1.3.0 allows remote attackers to bypass intended access restrictions, and create new user accounts or execute tasks, by…

Mitigation only
Fix from $1,600 2013-10-25
Websphere Datapower Xc10 Appliance HIGH 10.0
CVE-2013-5446

The console on IBM WebSphere DataPower XC10 appliances 2.1.0 and 2.5.0 does not properly process logoff actions, which has unspecified impact and rem…

Mitigation only
Fix from $1,950 2013-10-22
Websphere Datapower Xc10 Appliance HIGH 7.1
CVE-2013-5428

IBM WebSphere DataPower XC10 appliances 2.5.0 do not require authentication for all administrative actions, which allows remote attackers to cause a …

Mitigation only
Fix from $1,950 2013-10-22
Storwize V7000 Unified Software MEDIUM 5.4
CVE-2013-0500

IBM Storwize V7000 Unified 1.3.x and 1.4.x before 1.4.2.0 does not properly handle device files that are created with the NFS protocol but accessed w…

Mitigation only
Fix from $1,600 2013-10-17
Websphere Extreme Scale HIGH 7.5
CVE-2013-5393

The monitoring console in IBM WebSphere eXtreme Scale 7.1.0, 7.1.1, 8.5.0, and 8.6.0 does not properly process logoff actions, which has unspecified …

No fix yet
Fix from $1,950 2013-10-16
Business Process Monitor HIGH 10.0
CVE-2013-4804

Unspecified vulnerability in HP Business Process Monitor 9.13.1 patch 1 and 9.22 patch 1 allows remote attackers to execute arbitrary code and obtain…

Mitigation only
Fix from $1,950 2013-10-13
Business Process Monitor HIGH 10.0
CVE-2013-2366

Unspecified vulnerability in HP Business Process Monitor 9.13.1 patch 1 and 9.22 patch 1 allows remote attackers to execute arbitrary code and obtain…

Mitigation only
Fix from $1,950 2013-10-13
Infosphere Information Server MEDIUM 6.8
CVE-2013-4056

Cross-site request forgery (CSRF) vulnerability in the Data Quality Console and Information Analyzer components in IBM InfoSphere Information Server …

Mitigation only
Fix from $1,600 2013-10-13
Infosphere Optim Data Growth For Oracle E Business Suite MEDIUM 5.2
CVE-2013-0577

The Optim E-Business Console in IBM Data Growth Solution for Oracle E-business Suite 6.0 through 9.1 allows remote authenticated users to bypass inte…

Mitigation only
Fix from $1,600 2013-10-10
Aix MEDIUM 6.9
CVE-2013-5419

Multiple buffer overflows in (1) mkque and (2) mkquedev in bos.rte.printers in IBM AIX 6.1 and 7.1 allow local users to gain privileges by leveraging…

Mitigation only
Fix from $1,600 2013-10-04
Tivoli Storage Manager HIGH 7.2
CVE-2013-2964

Buffer overflow in dsmtca in IBM Tivoli Storage Manager (TSM) through 5.5.4.0, 6.1.0 through 6.1.5.4, 6.2.0 through 6.2.4.7, and 6.3.0 through 6.3.0.…

Fix: after 5.5.4
Fix from $1,950 2013-10-04
Infosphere Information Server MEDIUM 5.8
CVE-2013-4067

IBM InfoSphere Information Server 8.0, 8.1, 8.5 through FP3, 8.7, and 9.1 allows remote attackers to hijack sessions and read cookie values, or condu…

Mitigation only
Fix from $1,600 2013-10-02
Db2 MEDIUM 5.0
CVE-2013-4032

The Fast Communications Manager (FCM) in IBM DB2 Enterprise Server Edition and Advanced Enterprise Server Edition 10.1 before FP3 and 10.5, when a mu…

Mitigation only
Fix from $1,600 2013-10-02
Maximo Asset Management HIGH 7.5
CVE-2013-5395

IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows remote attackers to bypass intended access restrict…

Mitigation only
Fix from $1,950 2013-10-01
Maximo Asset Management MEDIUM 6.5
CVE-2013-4021

IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows remote authenticated users to conduct unspecified f…

Mitigation only
Fix from $1,600 2013-10-01