Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Lotus Domino MEDIUM 6.0
CVE-2013-0489

Cross-site request forgery (CSRF) vulnerability in webadmin.nsf (aka the Web Administrator client) in IBM Domino 8.5.x allows remote authenticated us…

Mitigation only
Fix from $1,600 2013-03-27
Infosphere Information Server HIGH 7.2
CVE-2012-5938

The installation process in IBM InfoSphere Information Server 8.1, 8.5, 8.7, and 9.1 on UNIX and Linux sets incorrect permissions and ownerships for …

No fix yet
Fix from $1,950 2013-03-20
Sterling Multi Channel Fulfillment Solution MEDIUM 5.5
CVE-2013-0505

IBM Sterling Order Management 8.0 before HF127, 8.5 before HF89, 9.0 before HF69, 9.1.0 before FP41, and 9.2.0 before FP13 allows remote authenticate…

Mitigation only
Fix from $1,600 2013-03-19
Tivoli Application Dependency Discovery Manager MEDIUM 5.8
CVE-2012-5770

The SSL configuration in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.x before 7.2.1.4 supports the MD5 hash algorithm, which make…

Patch available
Fix from $1,600 2013-03-06
Cognos Business Intelligence HIGH 9.3
CVE-2012-4858

IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 does not properly validate Java seria…

Mitigation only
Fix from $1,950 2013-03-05
Cognos Business Intelligence MEDIUM 5.0
CVE-2012-4840

IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 allows remote attackers to conduct XP…

Mitigation only
Fix from $1,600 2013-03-05
Infosphere Guardium HIGH 7.2
CVE-2013-0490

Unspecified vulnerability in IBM InfoSphere Guardium S-TAP 8.1 for DB2 on z/OS allows local users to gain privileges via unknown vectors.

No fix yet
Fix from $1,950 2013-02-27
Lotus Domino MEDIUM 5.8
CVE-2012-4842

Open redirect vulnerability in the web server in IBM Lotus Domino 8.5.x through 8.5.3 allows remote attackers to redirect users to arbitrary web site…

Mitigation only
Fix from $1,600 2013-02-27
Ts3500 Tape Library Firmware MEDIUM 6.5
CVE-2012-5767

Unspecified vulnerability in the web interface on the IBM TS3500 Tape Library with firmware before C260 allows remote authenticated users to gain pri…

Mitigation only
Fix from $1,600 2013-02-27
Webshere Cast Iron Cloud Integration MEDIUM 5.4
CVE-2013-0465

Unspecified vulnerability in the IBM WebSphere Cast Iron physical and virtual appliance 6.0 and 6.1 before 6.1.0.15 and 6.3 before 6.3.0.1, when LDAP…

Patch available
Fix from $1,600 2013-02-22
Tivoli Storage Manager MEDIUM 5.1
CVE-2013-0472

The Web GUI in the client in IBM Tivoli Storage Manager (TSM) 6.3 before 6.3.1.0 and 6.4 before 6.4.0.1 allows man-in-the-middle attackers to obtain …

Fix: after 6.2.4.4
Fix from $1,600 2013-02-21
Infosphere Master Data Management Collaboration Server MEDIUM 6.0
CVE-2013-0477

Multiple cross-site scripting (XSS) vulnerabilities in IBM InfoSphere Master Data Management - Collaborative Edition 10.0 and 10.1 before FP1 and Inf…

Mitigation only
Fix from $1,600 2013-02-21
Netezza MEDIUM 6.8
CVE-2012-5763

Cross-site request forgery (CSRF) vulnerability in the WebAdmin application 6.0.5, 6.0.8, and 7.0 before P2 in IBM Netezza allows remote attackers to…

Mitigation only
Fix from $1,600 2013-02-20
Netezza MEDIUM 6.5
CVE-2012-5760

SQL injection vulnerability in the WebAdmin application 6.0.5, 6.0.8, and 7.0 before P2 in IBM Netezza allows remote authenticated users to execute a…

Mitigation only
Fix from $1,600 2013-02-20
Maximo Asset Management MEDIUM 6.5
CVE-2012-6355

IBM Maximo Asset Management 6.2 through 7.5, Maximo Asset Management Essentials 6.2 through 7.5, Tivoli Asset Management for IT 6.2 through 7.2, Tivo…

Mitigation only
Fix from $1,600 2013-02-20
Maximo Asset Management MEDIUM 6.5
CVE-2012-6356

IBM Maximo Asset Management 7.5, Maximo Asset Management Essentials 7.5, and SmartCloud Control Desk 7.5 allow remote authenticated users to gain pri…

Mitigation only
Fix from $1,600 2013-02-20
Maximo Asset Management MEDIUM 6.5
CVE-2012-6357

IBM Maximo Asset Management 7.5, Maximo Asset Management Essentials 7.5, and SmartCloud Control Desk 7.5 allow remote authenticated users to gain pri…

Mitigation only
Fix from $1,600 2013-02-20
Websphere Message Broker MEDIUM 5.0
CVE-2012-5952

IBM WebSphere Message Broker 6.1 before 6.1.0.12, 7.0 before 7.0.0.6, and 8.0 before 8.0.0.2 does not validate Basic Authentication credentials befor…

Mitigation only
Fix from $1,600 2013-02-20
Smartcloud Control Desk MEDIUM 6.5
CVE-2012-3321

IBM SmartCloud Control Desk 7.5 allows remote authenticated users to bypass intended access restrictions via vectors involving an expired password.

Mitigation only
Fix from $1,600 2013-02-20
San Volume Controller Software HIGH 7.5
CVE-2012-6354

The management GUI on the IBM SAN Volume Controller and Storwize V7000 6.x before 6.4.1.3 allows remote attackers to bypass authentication and obtain…

Mitigation only
Fix from $1,950 2013-02-19
Sterling Connect MEDIUM 5.0
CVE-2012-6352

The Session Manager in IBM Sterling Connect:Direct through 4.1.0.3 on UNIX allows remote attackers to cause a denial of service (daemon crash and dis…

Mitigation only
Fix from $1,600 2013-02-02
Infosphere Import Export Manager HIGH 9.3
CVE-2012-0204

Untrusted search path vulnerability in InfoSphere Import Export Manager 8.1 through 9.1 in InfoSphere Information Server MetaBrokers & Bridges (MBB) …

Mitigation only
Fix from $1,950 2013-01-31
Infosphere Information Server HIGH 7.1
CVE-2012-0705

InfoSphere Import Export Manager in InfoSphere Information Server MetaBrokers & Bridges (MBB) in IBM InfoSphere Information Server 8.1, 8.5 before FP…

Mitigation only
Fix from $1,950 2013-01-31
Infosphere Information Server MEDIUM 6.5
CVE-2012-0205

InfoSphere Metadata Workbench (MWB) 8.1 through 8.7 in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 does not properly restrict use …

Mitigation only
Fix from $1,600 2013-01-31
Infosphere Datastage MEDIUM 6.5
CVE-2012-0701

The client applications in the DataStage Administrator client in InfoSphere DataStage in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8…

Mitigation only
Fix from $1,600 2013-01-31
Infosphere Information Server MEDIUM 5.8
CVE-2012-0703

Open redirect vulnerability in Information Services Framework (ISF) in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 allows remote a…

Mitigation only
Fix from $1,600 2013-01-31
Websphere Application Server HIGH 10.0
CVE-2013-0462

Unspecified vulnerability in IBM WebSphere Application Server (WAS) 6.1, 7.0 before 7.0.0.27, 8.0, and 8.5 has unknown impact and attack vectors.

Mitigation only
Fix from $1,950 2013-01-27
Websphere Application Server MEDIUM 6.8
CVE-2013-0460

Cross-site request forgery (CSRF) vulnerability in the portlet subsystem in the administrative console in IBM WebSphere Application Server (WAS) 6.1 …

Mitigation only
Fix from $1,600 2013-01-27
Java HIGH 9.3
CVE-2012-4821EPSS 7%

Multiple unspecified vulnerabilities in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 …

Fix: after 7.0.2.0
Fix from $1,950 2013-01-11
Java HIGH 9.3
CVE-2012-4822EPSS 7%

Multiple unspecified vulnerabilities in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 …

Fix: after 7.0.2.0
Fix from $1,950 2013-01-11