Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Data Studio MEDIUM 5.0
CVE-2013-2981

Directory traversal vulnerability in the Web Console in IBM Data Studio 3.1.0 and 3.1.1 allows remote attackers to read arbitrary files via unspecifi…

Mitigation only
Fix from $1,600 2013-06-17
Lotus Quickr For Domino HIGH 9.3
CVE-2013-3026

Buffer overflow in the Lotus Quickr for Domino ActiveX control in qp2.cab in IBM Lotus Quickr 8.1 before FP 8.1.0.32-001a, 8.2 before FP 8.2.0.28-001…

Mitigation only
Fix from $1,950 2013-06-17
Tivoli Netcool Application Service Monitors HIGH 7.6
CVE-2013-0509EPSS 7%

Buffer overflow in the Transaction MIB agent in IBM Tivoli Netcool System Service Monitors (SSM) and Application Service Monitors (ASM) 4.0.0 before …

Mitigation only
Fix from $1,950 2013-06-05
Db2 HIGH 7.2
CVE-2013-3475

Stack-based buffer overflow in db2aud in the Audit Facility in IBM DB2 and DB2 Connect 9.1, 9.5, 9.7, 9.8, and 10.1, as used in Smart Analytics Syste…

Mitigation only
Fix from $1,950 2013-06-05
Tivoli Netcool Application Service Monitors HIGH 7.6
CVE-2013-0508

Multiple buffer overflows in IBM Tivoli Netcool System Service Monitors (SSM) and Application Service Monitors (ASM) 4.0.0 before FP14 and 4.0.1 befo…

Mitigation only
Fix from $1,950 2013-06-05
Qradar Security Information And Event Manager MEDIUM 6.5
CVE-2013-2970

Unspecified vulnerability in IBM QRadar Security Information and Event Manager (SIEM) 7.x before 7.1 MR2 Patch 1 allows remote authenticated users to…

Mitigation only
Fix from $1,600 2013-06-03
Sterling Connect MEDIUM 6.8
CVE-2013-2989

The file-copying functionality in IBM Sterling Connect:Direct 3.8.00, 4.0.00, and 4.1.0 for UNIX on AIX 6.1 through 7.1 uses incorrect privileges, wh…

Mitigation only
Fix from $1,600 2013-05-28
Rational Directory Server MEDIUM 5.0
CVE-2013-0599

IBM Eclipse Help System (IEHS), as used in IBM Rational Directory Server 5.1.1 through 5.1.1.2 and 5.2 through 5.2.1 and other products, allows remot…

Fix: after 5.2.1
Fix from $1,600 2013-05-28
Infosphere Optim Data Growth For Oracle E Business Suite HIGH 7.5
CVE-2013-2956

SQL injection vulnerability in the Console in IBM InfoSphere Optim Data Growth for Oracle E-Business Suite 6.x, 7.x, and 9.x before 9.1.0.3 allows re…

Mitigation only
Fix from $1,950 2013-05-27
Infosphere Optim Data Growth For Oracle E Business Suite MEDIUM 5.0
CVE-2013-2954

The login page in the Console in IBM InfoSphere Optim Data Growth for Oracle E-Business Suite 6.x, 7.x, and 9.x before 9.1.0.3 does not limit the num…

Mitigation only
Fix from $1,600 2013-05-27
Infosphere Optim Data Growth For Oracle E Business Suite MEDIUM 5.0
CVE-2013-2959

The Console in IBM InfoSphere Optim Data Growth for Oracle E-Business Suite 6.x, 7.x, and 9.x before 9.1.0.3 does not provide an encrypted session fo…

Mitigation only
Fix from $1,600 2013-05-27
Lotus Notes MEDIUM 6.8
CVE-2013-2977

Integer overflow in IBM Notes 8.5.x before 8.5.3 FP4 Interim Fix 1 and 9.x before 9.0 Interim Fix 1 on Windows, and 8.5.x before 8.5.3 FP5 and 9.x be…

Mitigation only
Fix from $1,600 2013-05-10
Sterling Secure Proxy MEDIUM 5.0
CVE-2013-0519

IBM Sterling Secure Proxy 3.2.0 and 3.3.01 before 3.3.01.23 Interim Fix 1, 3.4.0 before 3.4.0.6 Interim Fix 1, and 3.4.1 before 3.4.1.7 provides web-…

Mitigation only
Fix from $1,600 2013-05-10
Websphere Datapower Xc10 Appliance Firmware HIGH 9.3
CVE-2013-0600

Unspecified vulnerability on IBM WebSphere DataPower XC10 Appliance devices 2.0 and 2.1 through 2.1 FP3 allows remote attackers to bypass authenticat…

Mitigation only
Fix from $1,950 2013-05-09
Lotus Notes MEDIUM 5.8
CVE-2013-0127

IBM Lotus Notes 8.x before 8.5.3 FP4 Interim Fix 1 and 9.0 before Interim Fix 1 does not block APPLET elements in HTML e-mail, which allows remote at…

Mitigation only
Fix from $1,600 2013-05-01
Spss Samplepower HIGH 9.3
CVE-2012-5947

Buffer overflow in the vsflex7l ActiveX control in IBM SPSS SamplePower 3.0 before FP1 allows remote attackers to execute arbitrary code via unspecif…

Mitigation only
Fix from $1,950 2013-04-30
Spss Samplepower HIGH 9.3
CVE-2012-5946EPSS 34%

Buffer overflow in the c1sizer ActiveX control in C1sizer.ocx in IBM SPSS SamplePower 3.0 before FP1 allows remote attackers to execute arbitrary cod…

Mitigation only
Fix from $1,950 2013-04-30
Spss Samplepower HIGH 9.3
CVE-2012-5945

Multiple buffer overflows in the Vsflex8l ActiveX control in IBM SPSS SamplePower 3.0 before FP1 allow remote attackers to execute arbitrary code via…

Mitigation only
Fix from $1,950 2013-04-30
Spss Samplepower HIGH 9.3
CVE-2013-0593

Unspecified vulnerability in the olch2x32 ActiveX control in IBM SPSS SamplePower 3.0 before 3.0-IM-S3SAMPC-WIN32-FP001 allows remote attackers to ex…

Mitigation only
Fix from $1,950 2013-04-27
Websphere Application Server MEDIUM 6.8
CVE-2013-0543

IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2 on Linux, Solaris, and HP…

Mitigation only
Fix from $1,600 2013-04-24
Tririga Application Platform MEDIUM 6.8
CVE-2012-5950

Multiple cross-site request forgery (CSRF) vulnerabilities in IBM TRIRIGA Application Platform 2.x and 3.x before 3.3, and 8, allow remote attackers …

Mitigation only
Fix from $1,600 2013-04-23
Infosphere Replication Server MEDIUM 5.0
CVE-2013-0584

The Data Replication Dashboard component in IBM InfoSphere Replication Server 9.7 and 10.x before 10.2.0.0-b113 allows remote attackers to obtain a l…

Mitigation only
Fix from $1,600 2013-04-23
Gentran Integration Suite HIGH 9.3
CVE-2012-5937

Unspecified vulnerability in the CLA2 server in IBM Gentran Integration Suite 4.3, Sterling Integrator 5.0 and 5.1, and Sterling B2B Integrator 5.2, …

Mitigation only
Fix from $1,950 2013-04-12
Cognos Disclosure Management HIGH 9.3
CVE-2013-0501

The EdrawSoft EDOFFICE.EDOfficeCtrl.1 ActiveX control, as used in Edraw Office Viewer Component, the client in IBM Cognos Disclosure Management (CDM)…

Mitigation only
Fix from $1,950 2013-04-12
Ims Enterprise Suite MEDIUM 5.0
CVE-2013-0483

The login component in SOAP Gateway in IBM IMS Enterprise Suite 1.1, 2.1, and 2.2 uses cleartext credentials, which allows remote attackers to obtain…

Mitigation only
Fix from $1,600 2013-04-05
Security Appscan HIGH 7.2
CVE-2013-0513

IBM Security AppScan Enterprise 5.6 and 8.x before 8.7 and IBM Rational Policy Tester 5.6 and 8.x before 8.5.0.4 create a service that lacks " (doubl…

Mitigation only
Fix from $1,950 2013-03-29
Security Appscan MEDIUM 6.8
CVE-2013-0532

Cross-site request forgery (CSRF) vulnerability in IBM Security AppScan Enterprise 5.6 and 8.x before 8.7 and IBM Rational Policy Tester 5.6 and 8.x …

Mitigation only
Fix from $1,600 2013-03-29
Security Appscan MEDIUM 6.5
CVE-2013-0511

Multiple SQL injection vulnerabilities in IBM Security AppScan Enterprise 5.6 and 8.x before 8.7 allow remote authenticated users to execute arbitrar…

Mitigation only
Fix from $1,600 2013-03-29
Software Use Analysis MEDIUM 6.8
CVE-2013-0452

Cross-site request forgery (CSRF) vulnerability in the Software Use Analysis (SUA) application before 1.3.3 in IBM Tivoli Endpoint Manager 8.2 allows…

Fix: after 1.3.2
Fix from $1,600 2013-03-29
Lotus Domino HIGH 8.5
CVE-2013-0487

The Java Console in IBM Domino 8.5.x allows remote authenticated users to hijack temporary credentials by leveraging knowledge of configuration detai…

Mitigation only
Fix from $1,950 2013-03-27