Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Websphere Commerce MEDIUM 6.4
CVE-2013-2994

IBM WebSphere Commerce 7.0 Feature Pack 4 and Feature Pack 5 incorrectly maintains a valid session after unspecified interaction with REST services, …

Mitigation only
Fix from $1,600 2013-08-01
Websphere Commerce MEDIUM 5.8
CVE-2013-2993

IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.7 does not properly perform authentication for unspecified web services, which allo…

Mitigation only
Fix from $1,600 2013-08-01
Tivoli Remote Control MEDIUM 6.5
CVE-2013-3033

SQL injection vulnerability in the server component in IBM Tivoli Remote Control 5.1.2 before 5.1.2-TIV-TRC512-IF0015 allows remote authenticated use…

Mitigation only
Fix from $1,600 2013-07-29
Java HIGH 9.3
CVE-2013-3006

Unspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 7 before 7 SR5 allows remote attackers to affect confidentiality, availab…

Mitigation only
Fix from $1,950 2013-07-23
Java HIGH 9.3
CVE-2013-3007

Unspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 6.0.1 before 6.0.1 SR6 and 7 before 7 SR5 allows remote attackers to affe…

No fix yet
Fix from $1,950 2013-07-23
Java HIGH 9.3
CVE-2013-3008

Unspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 7 before 7 SR5 allows remote attackers to affect confidentiality, availab…

No fix yet
Fix from $1,950 2013-07-23
Java HIGH 9.3
CVE-2013-3009

The com.ibm.CORBA.iiop.ClientDelegate class in IBM Java 1.4.2 before 1.4.2 SR13-FP18, 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR…

Mitigation only
Fix from $1,950 2013-07-23
Java HIGH 9.3
CVE-2013-3010

Unspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 6.0.1 before 6.0.1 SR6 and 7 before 7 SR5 allows remote attackers to affe…

Mitigation only
Fix from $1,950 2013-07-23
Java HIGH 9.3
CVE-2013-3011

Unspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 1.4.2 before 1.4.2 SR13-FP18, 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6…

Mitigation only
Fix from $1,950 2013-07-23
Java HIGH 9.3
CVE-2013-3012

Unspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 1.4.2 before 1.4.2 SR13-FP18, 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6…

Mitigation only
Fix from $1,950 2013-07-23
Api Management MEDIUM 6.4
CVE-2013-0559

Unspecified vulnerability in IBM API Management 2.0 before 2.0.0.1 allows remote attackers to access tenant APIs, and consequently obtain sensitive i…

No fix yet
Fix from $1,600 2013-07-19
Aix HIGH 7.2
CVE-2013-4011

Multiple unspecified vulnerabilities in the InfiniBand subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, allow local users to gain priv…

Mitigation only
Fix from $1,950 2013-07-18
Aix HIGH 8.5
CVE-2013-3005

The TFTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, when RBAC is enabled, allows remote authenticated users to bypass intended file…

Mitigation only
Fix from $1,950 2013-07-06
Sterling B2b Integrator MEDIUM 6.5
CVE-2013-0560

Multiple SQL injection vulnerabilities in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated us…

Mitigation only
Fix from $1,600 2013-07-03
Sterling B2b Integrator MEDIUM 6.5
CVE-2013-2982

IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to upload arbitrary files via unspecif…

Mitigation only
Fix from $1,600 2013-07-03
Sterling B2b Integrator MEDIUM 6.5
CVE-2013-2984

Directory traversal vulnerability in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allows remote authenticated users …

Mitigation only
Fix from $1,600 2013-07-03
Sterling B2b Integrator MEDIUM 5.0
CVE-2013-0481

The console in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allows remote attackers to read stack traces by triggeri…

Mitigation only
Fix from $1,600 2013-07-03
Sterling B2b Integrator MEDIUM 5.0
CVE-2013-0539

An unspecified third-party component in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 uses short session ID values, w…

Mitigation only
Fix from $1,600 2013-07-03
Sterling B2b Integrator MEDIUM 5.0
CVE-2013-0558

IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote attackers to obtain sensitive information about applicatio…

No fix yet
Fix from $1,600 2013-07-03
Sterling B2b Integrator MEDIUM 6.5
CVE-2012-5766

Multiple SQL injection vulnerabilities in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated us…

Mitigation only
Fix from $1,600 2013-07-03
Sterling B2b Integrator MEDIUM 6.4
CVE-2013-0476

IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote attackers to inject arbitrary FTP commands via unspecified…

Mitigation only
Fix from $1,600 2013-07-03
Sterling B2b Integrator MEDIUM 5.0
CVE-2012-5936

IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 do not set the secure flag for the session cookie in an https session, …

Mitigation only
Fix from $1,600 2013-07-03
Ims Enterprise Suite HIGH 9.0
CVE-2013-3003

Unspecified vulnerability in SOAP Gateway in IBM IMS Enterprise Suite 1.1, 2.1, and 2.2 allows remote authenticated users to execute arbitrary comman…

Mitigation only
Fix from $1,950 2013-07-02
Lotus Inotes HIGH 7.2
CVE-2013-0536

ntmulti.exe in the Multi User Profile Cleanup service in IBM Notes 8.0, 8.0.1, 8.0.2, 8.5, 8.5.1, 8.5.2, 8.5.3 before FP5, and 9.0 before IF2 allows …

Mitigation only
Fix from $1,950 2013-06-21
Tivoli Monitoring MEDIUM 5.0
CVE-2013-0551

The Basic Services component in IBM Tivoli Monitoring (ITM) 6.2.0 through FP3, 6.2.1 through FP4, 6.2.2 through FP9, and 6.2.3 before FP3, as used in…

Mitigation only
Fix from $1,600 2013-06-21
Tivoli Monitoring MEDIUM 5.0
CVE-2013-2960

Buffer overflow in KDSMAIN in the Basic Services component in IBM Tivoli Monitoring (ITM) 6.2.0 through FP3, 6.2.1 through FP4, 6.2.2 through FP9, an…

Mitigation only
Fix from $1,600 2013-06-21
Aix HIGH 7.1
CVE-2013-3035

The IPv6 implementation in the inet subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, allows remote attackers to cause a denial of serv…

Mitigation only
Fix from $1,950 2013-06-21
Sterling Connect Direct User Interface MEDIUM 5.0
CVE-2013-0529

The Browser in IBM Sterling Connect:Direct 1.4 before 1.4.0.11 and 1.5 through 1.5.0.1 does not set the secure flag for the session cookie in an http…

Mitigation only
Fix from $1,600 2013-06-21
Sterling Control Center MEDIUM 6.3
CVE-2013-2968

An unspecified buffer-read method in IBM Sterling Control Center (SCC) 5.2 before 5.2.0.9, 5.3 before 5.3.0.4, and 5.4 through 5.4.0.1 allows remote …

Mitigation only
Fix from $1,600 2013-06-19
Data Studio MEDIUM 6.8
CVE-2013-2980

Cross-site request forgery (CSRF) vulnerability in the Web Console in IBM Data Studio 3.1.0 and 3.1.1 allows remote attackers to hijack the authentic…

Mitigation only
Fix from $1,600 2013-06-17