Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Maximo Asset Management MEDIUM 6.5
CVE-2013-4027

IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.12, and 7.5 before 7.5.0.5 allows remote authenticated users to bypass intended acce…

Mitigation only
Fix from $1,600 2013-10-01
Maximo Asset Management MEDIUM 6.5
CVE-2013-5381

IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.12, and 7.5 before 7.5.0.3 allows remote authenticated users to gain privileges via …

Mitigation only
Fix from $1,600 2013-10-01
Maximo Asset Management MEDIUM 6.8
CVE-2012-3323

IBM Maximo Asset Management 6.2 before 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.3 allows remote attackers to gain privileges via unspecified …

No fix yet
Fix from $1,600 2013-10-01
Maximo Asset Management MEDIUM 6.5
CVE-2013-0451

SQL injection vulnerability in IBM Maximo Asset Management 6.2 through 6.2.8 and 7.1 through 7.1.1.12 allows remote authenticated users to execute ar…

Mitigation only
Fix from $1,600 2013-10-01
Maximo Asset Management MEDIUM 6.5
CVE-2013-3047

IBM Maximo Asset Management 7.1 before 7.1.1.12 and 7.5 before 7.5.0.5 allows remote authenticated users to gain privileges via unspecified vectors.

No fix yet
Fix from $1,600 2013-10-01
Maximo Asset Management MEDIUM 6.5
CVE-2013-3973

SQL injection vulnerability in IBM Maximo Asset Management 7.1 before 7.1.1.12 and 7.5 before 7.5.0.5 allows remote authenticated users to execute ar…

Mitigation only
Fix from $1,600 2013-10-01
Maximo Asset Management MEDIUM 6.5
CVE-2013-4017

SQL injection vulnerability in IBM Maximo Asset Management 7.1 before 7.1.1.12 allows remote attackers to execute arbitrary SQL commands via unspecif…

Mitigation only
Fix from $1,600 2013-10-01
Maximo Asset Management MEDIUM 6.0
CVE-2013-4018

IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows remote authenticated users to obtain sensitive info…

Mitigation only
Fix from $1,600 2013-10-01
Maximo Asset Management MEDIUM 5.0
CVE-2013-4013

IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.12, and 7.5 before 7.5.0.2 allows remote attackers to obtain sensitive information v…

Mitigation only
Fix from $1,600 2013-10-01
Spss Collaboration And Deployment Services HIGH 10.0
CVE-2013-4042

Unspecified vulnerability in IBM SPSS Collaboration and Deployment Services 4.2.1 and 5.0 through FP2 allows remote attackers to execute arbitrary co…

Mitigation only
Fix from $1,950 2013-10-01
Spss Collaboration And Deployment Services HIGH 10.0
CVE-2013-5370

Unspecified vulnerability in IBM SPSS Collaboration and Deployment Services 4.2.1 and 5.0 through FP2 allows remote attackers to execute arbitrary co…

Mitigation only
Fix from $1,950 2013-10-01
Rational Clearquest MEDIUM 6.8
CVE-2013-0598

Cross-site request forgery (CSRF) vulnerability in the Web Client in IBM Rational ClearQuest 7.1 before 7.1.2.12, 8.0 before 8.0.0.8, and 8.0.1 befor…

Mitigation only
Fix from $1,600 2013-09-28
Websphere Datapower Xc10 Appliance Firmware HIGH 10.0
CVE-2013-5403

Unspecified vulnerability on the IBM WebSphere DataPower XC10 appliance 2.0 through 2.5.0.1 allows remote attackers to obtain administrative access v…

Mitigation only
Fix from $1,950 2013-09-27
Rational Clearcase MEDIUM 6.9
CVE-2013-5373

The RemoteClient component in IBM Rational ClearCase 8.0.0.03 through 8.0.0.07, and 8.0.1, uses world-writable permissions for the rcleartool script,…

Mitigation only
Fix from $1,600 2013-09-25
Websphere Application Server MEDIUM 6.8
CVE-2013-4053

The WS-Security implementation in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.31, 8.0 before 8.0.0.8, and 8.5 before…

Mitigation only
Fix from $1,600 2013-09-20
Lotus Domino HIGH 7.1
CVE-2013-4068

Buffer overflow in iNotes in IBM Domino 8.5.3 before FP5 IF1 and 9.0 before IF4 allows remote authenticated users to execute arbitrary code via unspe…

Patch available
Fix from $1,950 2013-09-20
Spss Analytical Decision Management HIGH 9.3
CVE-2013-5369

IBM SPSS Analytical Decision Management 6.1 before IF1, 6.2 before IF1, and 7.0 before FP1 IF6 might allow remote attackers to execute arbitrary code…

Mitigation only
Fix from $1,950 2013-09-16
Spss Analytical Decision Management HIGH 8.5
CVE-2013-4049

Unrestricted file upload vulnerability in IBM SPSS Analytical Decision Management 6.1 before IF1, 6.2 before IF1, and 7.0 before FP1 IF6 allows remot…

Mitigation only
Fix from $1,950 2013-09-16
Rational Requirements Composer MEDIUM 5.4
CVE-2013-3039

IBM Rational Requirements Composer before 4.0.4 does not properly perform authentication, which has unspecified impact and remote attack vectors.

Fix: after 4.0.3
Fix from $1,600 2013-09-12
Rational Requirements Composer MEDIUM 5.4
CVE-2013-3038

Unspecified vulnerability in IBM Rational Requirements Composer before 4.0.4 makes it easier for remote attackers to discover credentials via unknown…

Fix: after 4.0.3
Fix from $1,600 2013-09-12
Rational Policy Tester MEDIUM 6.8
CVE-2013-4062

IBM Rational Policy Tester 8.5 before 8.5.0.5 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof …

Mitigation only
Fix from $1,600 2013-09-09
Security Appscan MEDIUM 5.0
CVE-2013-0531

The SSL implementation in IBM Security AppScan Enterprise before 8.7.0.1 enables cipher suites with weak encryption algorithms, which makes it easier…

Fix: after 8.7.0.0
Fix from $1,600 2013-09-08
Websphere Application Server MEDIUM 6.8
CVE-2013-3029

Cross-site request forgery (CSRF) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 befo…

Mitigation only
Fix from $1,600 2013-08-21
Websphere Portal MEDIUM 5.0
CVE-2013-3016

IBM WebSphere Portal 6.1, 7.0, and 8.0 allows remote attackers to access the user directory via a crafted request for a servlet, related to the serve…

Mitigation only
Fix from $1,600 2013-08-21
Global Console Manager 16 Firmware HIGH 8.5
CVE-2013-0526EPSS 6%

ping.php in Global Console Manager 16 (GCM16) and Global Console Manager 32 (GCM32) before 1.20.0.22575 on the IBM Avocent 1754 KVM switch allows rem…

Fix: after 1.18.0.22011
Fix from $1,950 2013-08-21
Infosphere Information Server MEDIUM 5.0
CVE-2013-3040

IBM InfoSphere Information Server through 8.5 FP3, 8.7 through FP2, and 9.1 produces login-failure messages indicating whether the username or passwo…

Patch available
Fix from $1,600 2013-08-16
Bladecenter HIGH 10.0
CVE-2013-4031

The Intelligent Platform Management Interface (IPMI) implementation in Integrated Management Module (IMM) and Integrated Management Module II (IMM2) …

Mitigation only
Fix from $1,950 2013-08-09
Sterling B2b Integrator MEDIUM 5.0
CVE-2013-0494

IBM Sterling B2B Integrator 5.0 and 5.1 allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted HTTP (1) Rang…

Mitigation only
Fix from $1,600 2013-08-09
Lotus Domino HIGH 9.3
CVE-2013-3027

Integer overflow in the DWA9W ActiveX control in iNotes in IBM Domino 9.0 before IF3 allows remote attackers to execute arbitrary code via a crafted …

Mitigation only
Fix from $1,950 2013-08-09
Infosphere Biginsights MEDIUM 6.0
CVE-2013-3992

Cross-site request forgery (CSRF) vulnerability in IBM InfoSphere BigInsights 2.0 through 2.1 allows remote authenticated users to hijack the authent…

Mitigation only
Fix from $1,600 2013-08-06