Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Rational Team Concert MEDIUM 6.8
CVE-2012-0748

Multiple cross-site request forgery (CSRF) vulnerabilities in unspecified services in IBM Rational Team Concert (RTC) 4.x before 4.0.0.1 allow remote…

Mitigation only
Fix from $1,600 2012-10-01
Rational Business Developer MEDIUM 5.0
CVE-2012-3319

IBM Rational Business Developer 8.x before 8.0.1.4 allows remote attackers to obtain potentially sensitive information via a connection to a web serv…

Fix: after 8.0.1.3
Fix from $1,600 2012-10-01
Db2 HIGH 9.0
CVE-2012-3324

Directory traversal vulnerability in the UTL_FILE module in IBM DB2 and DB2 Connect 10.1 before FP1 on Windows allows remote authenticated users to m…

Mitigation only
Fix from $1,950 2012-09-25
Informix Dynamic Server HIGH 9.0
CVE-2012-3334

Stack-based buffer overflow in IBM Informix Dynamic Server (IDS) 11.50 before 11.50.xC9W2 and 11.70 before 11.70.xC5 allows remote authenticated user…

Mitigation only
Fix from $1,950 2012-09-25
Websphere Application Server MEDIUM 6.8
CVE-2012-3304

The Administrative Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5…

Mitigation only
Fix from $1,600 2012-09-25
Websphere Application Server MEDIUM 6.8
CVE-2012-3306

IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1, when multi-domain suppor…

Mitigation only
Fix from $1,600 2012-09-25
Websphere Application Server MEDIUM 6.4
CVE-2012-3305

Directory traversal vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 bef…

Mitigation only
Fix from $1,600 2012-09-25
Websphere Commerce HIGH 10.0
CVE-2012-3298

Unspecified vulnerability in the REST services framework in IBM WebSphere Commerce 7.0 Feature Pack 4 allows remote attackers to obtain sensitive inf…

Mitigation only
Fix from $1,950 2012-09-25
Remote Supervisor Adapter Ii Firmware MEDIUM 5.0
CVE-2012-2187

IBM Remote Supervisor Adapter II firmware for System x3650, x3850 M2, and x3950 M2 1.13 and earlier generates weak RSA keys, which makes it easier fo…

Fix: after 1.13
Fix from $1,600 2012-09-25
Websphere Mq MEDIUM 5.0
CVE-2012-2199

The server message channel agent in the queue manager in the server in IBM WebSphere MQ 7.0.1 before 7.0.1.9, 7.1, and 7.5 on Solaris allows remote a…

Mitigation only
Fix from $1,600 2012-09-25
Vios MEDIUM 5.0
CVE-2012-4817EPSS 8%

The NFSv4 client implementation in IBM AIX 5.3, 6.1, and 7.1, and VIOS before 2.2.1.4-FP-25 SP-02, does not properly handle GID values, which allows …

Mitigation only
Fix from $1,600 2012-09-14
Change And Configuration Management Database MEDIUM 6.8
CVE-2012-2183

Session fixation vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Ti…

Mitigation only
Fix from $1,600 2012-09-10
Change And Configuration Management Database MEDIUM 6.8
CVE-2012-2184

Session fixation vulnerability in IBM Maximo Asset Management 7.1 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Ti…

Mitigation only
Fix from $1,600 2012-09-10
Change And Configuration Management Database MEDIUM 6.5
CVE-2012-0727

SQL injection vulnerability in IBM Maximo Asset Management 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Re…

Mitigation only
Fix from $1,600 2012-09-10
Change And Configuration Management Database MEDIUM 6.5
CVE-2012-0728

SQL injection vulnerability in IBM Maximo Asset Management 7.1 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivol…

Mitigation only
Fix from $1,600 2012-09-10
Change And Configuration Management Database MEDIUM 6.5
CVE-2012-0747

SQL injection vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivol…

Mitigation only
Fix from $1,600 2012-09-10
Change And Configuration Management Database MEDIUM 6.8
CVE-2012-0714

Cross-site request forgery (CSRF) vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Mana…

Mitigation only
Fix from $1,600 2012-09-10
Lotus Notes MEDIUM 6.9
CVE-2010-5251

Multiple untrusted search path vulnerabilities in IBM Lotus Notes 8.5 allow local users to gain privileges via a Trojan horse (1) nnoteswc.dll or (2)…

Mitigation only
Fix from $1,600 2012-09-07
Lotus Symphony MEDIUM 6.9
CVE-2010-5204

Multiple untrusted search path vulnerabilities in IBM Lotus Symphony 1.3.0 20090908.0900 allow local users to gain privileges via a Trojan horse (1) …

Mitigation only
Fix from $1,600 2012-09-06
Websphere Application Server MEDIUM 6.0
CVE-2012-3325

IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.45, 7.0.x before 7.0.0.25, 8.0.x before 8.0.0.5, and 8.5.x Full Profile before 8.5.0.1, whe…

Mitigation only
Fix from $1,600 2012-08-30
Infosphere Guardium MEDIUM 6.8
CVE-2012-3309

Cross-site request forgery (CSRF) vulnerability in the account-creation panel in IBM InfoSphere Guardium 8.2 and earlier, when the CSRF filtering (ak…

Fix: after 8.2
Fix from $1,600 2012-08-29
Infosphere Guardium MEDIUM 5.0
CVE-2012-3312

The datasource definition editor in IBM InfoSphere Guardium 8.2 and earlier, when the save-password setting is enabled, transmits cleartext database …

Fix: after 8.2
Fix from $1,600 2012-08-29
Websphere Application Server MEDIUM 5.0
CVE-2012-2190

IBM Global Security Kit (aka GSKit), as used in IBM HTTP Server in IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.45, 7.0.x before 7.0.0.2…

Mitigation only
Fix from $1,600 2012-08-21
Rational Clearquest MEDIUM 5.5
CVE-2012-2164

The Web client in IBM Rational ClearQuest 7.1.x before 7.1.2.7 and 8.x before 8.0.0.3 allows remote authenticated users to bypass intended access res…

Mitigation only
Fix from $1,600 2012-08-17
Rational Clearquest MEDIUM 5.0
CVE-2012-0744EPSS 8%

IBM Rational ClearQuest 7.1.x through 7.1.2.7 and 8.x through 8.0.0.3 allows remote attackers to obtain potentially sensitive information via a reque…

Mitigation only
Fix from $1,600 2012-08-17
Websphere Mq MEDIUM 6.8
CVE-2012-3294

Multiple cross-site request forgery (CSRF) vulnerabilities in the Web Gateway component in IBM WebSphere MQ File Transfer Edition 7.0.4 and earlier, …

Fix: after 7.0.4
Fix from $1,600 2012-08-17
Global Security Kit HIGH 7.5
CVE-2012-2203

IBM Global Security Kit (aka GSKit) before 8.0.14.22, as used in IBM Rational Directory Server, IBM Tivoli Directory Server, and other products, uses…

Fix: after 8.0.13
Fix from $1,950 2012-08-08
Global Security Kit MEDIUM 5.0
CVE-2012-2191

IBM Global Security Kit (aka GSKit) before 8.0.14.22, as used in IBM Rational Directory Server, IBM Tivoli Directory Server, and other products, does…

Fix: after 8.0.13
Fix from $1,600 2012-08-08
Power Hardware Management Console Firmware HIGH 7.2
CVE-2012-2188

IBM Power Hardware Management Console (HMC) 7R3.5.0 before SP4, 7R7.1.0 and 7R7.2.0 before 7R7.2.0 SP3, and 7R7.3.0 before SP2, and Systems Director …

Mitigation only
Fix from $1,950 2012-08-06
Scale Out Network Attached Storage HIGH 9.0
CVE-2012-2163

IBM Scale Out Network Attached Storage (SONAS) 1.1 through 1.3.1 allows remote authenticated administrators to execute arbitrary Linux commands via t…

Mitigation only
Fix from $1,950 2012-07-30