Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Java HIGH 9.3
CVE-2012-4823EPSS 7%

Unspecified vulnerability in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and ea…

Fix: after 7.0.2.0
Fix from $1,950 2013-01-11
Java HIGH 9.3
CVE-2012-4820EPSS 5%

Unspecified vulnerability in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and ea…

Fix: after 7.0.2.0
Fix from $1,950 2013-01-11
Spss Modeler MEDIUM 5.8
CVE-2012-5769

IBM SPSS Modeler 14.0, 14.1, 14.2 through FP3, and 15.0 before FP2 allows remote attackers to read arbitrary files, and possibly send HTTP requests t…

Mitigation only
Fix from $1,600 2013-01-01
Security Appscan MEDIUM 5.8
CVE-2012-0738

IBM Security AppScan Enterprise before 8.6.0.2 and Rational Policy Tester before 8.5.0.3 do not validate X.509 certificates during scanning, which al…

Fix: after 8.6.0.1
Fix from $1,600 2012-12-28
Security Appscan MEDIUM 5.8
CVE-2012-0741

IBM Security AppScan Enterprise before 8.6.0.2 and Rational Policy Tester before 8.5.0.3 do not validate X.509 certificates during use of the Manual …

Fix: after 8.6.0.1
Fix from $1,600 2012-12-28
Rational Automation Framework HIGH 7.5
CVE-2012-4816

IBM Rational Automation Framework (RAF) 3.x through 3.0.0.5 allows remote attackers to bypass intended Env Gen Wizard (aka Environment Generation Wiz…

Mitigation only
Fix from $1,950 2012-12-26
Tivoli Netview HIGH 7.2
CVE-2012-5951

Unspecified vulnerability in IBM Tivoli NetView 1.4, 5.1 through 5.4, and 6.1 on z/OS allows local users to gain privileges by leveraging access to t…

Mitigation only
Fix from $1,950 2012-12-26
Tivoli Storage Manager For Space Management HIGH 7.2
CVE-2012-4859

Unspecified vulnerability in IBM Tivoli Storage Manager for Space Management (aka TSM HSM) before 6.2.5.0 and 6.3.x before 6.3.1.0 allows local users…

Fix: after 6.2.0
Fix from $1,950 2012-12-21
Tivoli Storage Manager For Space Management MEDIUM 6.4
CVE-2012-5954

Unspecified vulnerability in IBM Tivoli Storage Manager for Space Management (aka TSM HSM) before 6.2.5.0 and 6.3.x before 6.3.1.0 allows remote atta…

Fix: after 6.2.4.4
Fix from $1,600 2012-12-21
HTTP Server HIGH 10.0
CVE-2012-5955

Unspecified vulnerability in the IBM HTTP Server component 5.3 in IBM WebSphere Application Server (WAS) for z/OS allows remote attackers to execute …

Mitigation only
Fix from $1,950 2012-12-20
Rational Clearquest MEDIUM 5.0
CVE-2012-5765

The Web Client (aka CQ Web) in IBM Rational ClearQuest 7.1.2.x before 7.1.2.9 and 8.0.0.x before 8.0.0.5 allows remote attackers to obtain sensitive …

Mitigation only
Fix from $1,600 2012-12-20
Power 5 System Firmware HIGH 7.9
CVE-2012-4856

The Service Processor in the IBM Power 5 91##-### and 940#-### before SF240_418_382 does not ensure that firewall code is executed, which allows remo…

Mitigation only
Fix from $1,950 2012-12-20
Informix Dynamic Server HIGH 9.0
CVE-2012-4857

Buffer overflow in IBM Informix 11.50 through 11.50.xC9W2 and 11.70 before 11.70.xC7 allows remote authenticated users to execute arbitrary code via …

Mitigation only
Fix from $1,950 2012-12-08
Websphere Message Broker MEDIUM 6.9
CVE-2012-3317

IBM WebSphere Message Broker 6.1 before 6.1.0.11, 7.0 before 7.0.0.5, and 8.0 before 8.0.0.2 has incorrect ownership of certain uninstaller Java Runt…

Mitigation only
Fix from $1,600 2012-12-05
Websphere Portal MEDIUM 5.0
CVE-2012-4834

Directory traversal vulnerability in LayerLoader.jsp in the theme component in IBM WebSphere Portal 7.0.0.1 and 7.0.0.2 before CF19 and 8.0 before CF…

Patch available
Fix from $1,600 2012-11-30
Tivoli Endpoint Manager MEDIUM 5.0
CVE-2012-4841

Unspecified vulnerability in Tivoli Endpoint Manager for Remote Control Broker 8.2 before 8.2.1-TIV-TEMRC821-IF0002 allows remote attackers to cause …

Patch available
Fix from $1,600 2012-11-29
Websphere Datapower Xc10 Appliance HIGH 9.0
CVE-2012-5759

The IBM WebSphere DataPower XC10 Appliance 2.0.0.0 through 2.0.0.3 and 2.1.0.0 through 2.1.0.2 allows remote authenticated users to bypass intended a…

Mitigation only
Fix from $1,950 2012-11-23
Websphere Datapower Xc10 Appliance HIGH 7.8
CVE-2012-5758

The IBM WebSphere DataPower XC10 Appliance 2.0.0.0 through 2.0.0.3 and 2.1.0.0 through 2.1.0.2 does not require authentication for an unspecified int…

Mitigation only
Fix from $1,950 2012-11-23
Websphere Application Server HIGH 7.5
CVE-2012-4850

IBM WebSphere Application Server 8.5 Liberty Profile before 8.5.0.1, when JAX-RS is used, does not properly validate requests, which allows remote at…

Mitigation only
Fix from $1,950 2012-11-14
Websphere Application Server MEDIUM 6.8
CVE-2012-4853

Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Application Server 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and…

Mitigation only
Fix from $1,600 2012-11-14
Websphere Application Server MEDIUM 5.0
CVE-2012-3330

The proxy server in IBM WebSphere Application Server 7.0 before 7.0.0.27, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1, and WebSphere Virtual Enterpris…

Mitigation only
Fix from $1,600 2012-11-14
Tivoli Federated Identity Manager MEDIUM 5.0
CVE-2012-3315

The Java servlets in the management console in IBM Tivoli Federated Identity Manager (TFIM) through 6.2.2 and Tivoli Federated Identity Manager Busin…

Fix: after 6.2.2
Fix from $1,600 2012-11-08
Xiv Storage System Gen3 Firmware HIGH 7.8
CVE-2012-2167

The IBM XIV Storage System Gen3 before 11.1.0.a allows remote attackers to cause a denial of service (device outage) via TCP packets to unspecified p…

Fix: after 11.1.0
Fix from $1,950 2012-10-20
Db2 HIGH 8.5
CVE-2012-4826

Stack-based buffer overflow in the SQL/PSM (aka SQL Persistent Stored Module) Stored Procedure (SP) infrastructure in IBM DB2 9.1, 9.5, 9.7 before FP…

Mitigation only
Fix from $1,950 2012-10-20
Vios MEDIUM 6.8
CVE-2012-4845

The FTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly manage privileges in an RBAC environment, which allows attacke…

Mitigation only
Fix from $1,600 2012-10-20
Lotus Notes Traveler MEDIUM 6.8
CVE-2012-5308

Cross-site request forgery (CSRF) vulnerability in servlet/traveler in IBM Lotus Notes Traveler through 8.5.3.3 Interim Fix 1 allows remote attackers…

No fix yet
Fix from $1,600 2012-10-08
Lotus Notes Traveler MEDIUM 6.8
CVE-2012-5309

servlet/traveler in IBM Lotus Notes Traveler through 8.5.3.3 Interim Fix 1 does not properly restrict invalid authentication attempts, which makes it…

No fix yet
Fix from $1,600 2012-10-08
Lotus Notes Traveler MEDIUM 5.8
CVE-2012-4824

Open redirect vulnerability in servlet/traveler in IBM Lotus Notes Traveler 8.5.3 before 8.5.3.3 Interim Fix 1 allows remote attackers to redirect us…

No fix yet
Fix from $1,600 2012-10-08
Tivoli Federated Identity Manager MEDIUM 5.8
CVE-2012-3314

IBM Tivoli Federated Identity Manager (TFIM) and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.1.1, 6.2.0, 6.2.1, and 6.2.2 allow rem…

Patch available
Fix from $1,600 2012-10-02
Websphere Commerce MEDIUM 5.0
CVE-2012-4830

Unspecified vulnerability in IBM WebSphere Commerce 6.0 through 6.0.0.11 and 7.0 through 7.0.0.6 allows remote attackers to obtain users' personal da…

No fix yet
Fix from $1,600 2012-10-01