Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Db2 HIGH 10.0
CVE-2012-1797

IBM DB2 9.5 uses world-writable permissions for nodes.reg, which has unspecified impact and attack vectors.

Mitigation only
Fix from $1,950 2012-03-20
Db2 HIGH 7.5
CVE-2012-0711

Integer signedness error in the db2dasrrm process in the DB2 Administration Server (DAS) in IBM DB2 9.1 through FP11, 9.5 before FP9, and 9.7 through…

Mitigation only
Fix from $1,950 2012-03-20
Db2 HIGH 7.2
CVE-2012-1796

Unspecified vulnerability in IBM Tivoli Monitoring Agent (ITMA), as used in IBM DB2 9.5 before FP9 on UNIX, allows local users to gain privileges via…

Mitigation only
Fix from $1,950 2012-03-20
Db2 MEDIUM 5.0
CVE-2012-0710

IBM DB2 9.1 before FP11, 9.5 before FP9, 9.7 before FP5, and 9.8 before FP4 allows remote attackers to cause a denial of service (daemon crash) via a…

Mitigation only
Fix from $1,600 2012-03-20
Maximo Asset Management MEDIUM 6.5
CVE-2011-4816

SQL injection vulnerability in the KPI component in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset M…

Mitigation only
Fix from $1,600 2012-03-13
Maximo Asset Management MEDIUM 6.8
CVE-2011-1397

Cross-site request forgery (CSRF) vulnerability in the Labor Reporting page in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, …

Mitigation only
Fix from $1,600 2012-03-13
Maximo Asset Management MEDIUM 5.0
CVE-2011-1394

IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Management for IT 6.2, 7.1, and 7.2; IBM Tivoli Servi…

Mitigation only
Fix from $1,600 2012-03-13
Tivoli Provisioning Manager Express For Software Distribution HIGH 9.3
CVE-2012-0198EPSS 37%

Stack-based buffer overflow in the RunAndUploadFile method in the Isig.isigCtl.1 ActiveX control in IBM Tivoli Provisioning Manager Express for Softw…

Mitigation only
Fix from $1,950 2012-03-06
Tivoli Provisioning Manager Express For Software Distribution HIGH 7.5
CVE-2012-0199

Multiple SQL injection vulnerabilities in IBM Tivoli Provisioning Manager Express for Software Distribution 4.1.1 allow remote attackers to execute a…

Mitigation only
Fix from $1,950 2012-03-06
Vios HIGH 7.8
CVE-2011-1385

IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.1.x and 2.2.x, allows remote attackers to cause a denial of service (system crash) via an ICMP Echo Reply packe…

Patch available
Fix from $1,950 2012-03-02
Personal Communications HIGH 9.3
CVE-2012-0201EPSS 37%

Stack-based buffer overflow in pcspref.dll in pcsws.exe in IBM Personal Communications 5.9.x before 5.9.8 and 6.0.x before 6.0.4 might allow remote a…

No fix yet
Fix from $1,950 2012-03-02
Aix HIGH 7.1
CVE-2012-0194

The TCP implementation in IBM AIX 5.3, 6.1, and 7.1, when the Large Send Offload option is enabled, allows remote attackers to cause a denial of serv…

Patch available
Fix from $1,950 2012-02-06
Lotus Symphony HIGH 9.3
CVE-2012-0192EPSS 5%

Multiple integer overflows in vclmi.dll in the visual class library module in IBM Lotus Symphony before 3.0.1 might allow remote attackers to execute…

Fix: after 3.0.0.3
Fix from $1,950 2012-01-23
Websphere Application Server MEDIUM 5.0
CVE-2012-0193

IBM WebSphere Application Server (WAS) 6.0 through 6.0.2.43, 6.1 before 6.1.0.43, 7.0 before 7.0.0.23, and 8.0 before 8.0.0.3 computes hash values fo…

Patch available
Fix from $1,600 2012-01-20
Rational License Key Server HIGH 10.0
CVE-2011-1389EPSS 7%

Multiple directory traversal vulnerabilities in the vendor daemon in Rational Common Licensing in Telelogic License Server 2.0, Rational License Serv…

Patch available
Fix from $1,950 2012-01-19
Spss Samplepower HIGH 9.3
CVE-2012-0189

Multiple unspecified vulnerabilities in the (1) PrintFile and (2) SaveDoc methods in the VsVIEW6 ActiveX control in VsVIEW6.ocx in IBM SPSS SamplePow…

Mitigation only
Fix from $1,950 2012-01-18
Spss Data Collection HIGH 9.3
CVE-2012-0190

Unspecified vulnerability in the Render method in the ExportHTML.ocx ActiveX control in ExportHTML.dll in IBM SPSS Dimensions 5.5 and SPSS Data Colle…

Mitigation only
Fix from $1,950 2012-01-18
Spss Data Collection HIGH 9.3
CVE-2012-0188

Unspecified vulnerability in the SetLicenseInfoEx method in an ActiveX control in mraboutb.dll in IBM SPSS Dimensions 5.5 and SPSS Data Collection 5.…

Mitigation only
Fix from $1,950 2012-01-18
Websphere Application Server HIGH 10.0
CVE-2011-1377

The Web Services Security component in the Web Services Feature Pack before 6.1.0.41 for IBM WebSphere Application Server (WAS) 6.1 does not properly…

Mitigation only
Fix from $1,950 2012-01-15
Lotus Domino HIGH 7.8
CVE-2011-1393

Unspecified vulnerability in the authentication functionality in the server in IBM Lotus Domino 8.x before 8.5.2 FP4 allows remote attackers to cause…

Fix: after 8.5.2
Fix from $1,950 2011-12-27
Tivoli Netcool\/reporter HIGH 7.5
CVE-2011-4668

IBM Tivoli Netcool/Reporter 2.2 before 2.2.0.8 allows remote attackers to execute arbitrary code via vectors related to an unspecified CGI program us…

Mitigation only
Fix from $1,950 2011-12-02
Ts3100 Tape Library Firmware MEDIUM 6.8
CVE-2011-1372

The Web User Interface on the IBM TS3100 and TS3200 tape libraries with firmware before A.60 allows remote attackers to bypass authentication and obt…

Mitigation only
Fix from $1,600 2011-11-28
Db2 Tools For Z\/os MEDIUM 5.0
CVE-2011-4435

The web-server component in the Consolidation and Analysis Engine (CAE) Server in DB2 Query Monitor in IBM DB2 Tools 2.3.0 for z/OS does not prevent …

Mitigation only
Fix from $1,600 2011-11-11
Rational Appscan HIGH 9.3
CVE-2011-1367

Unspecified vulnerability in the File Load feature in IBM Rational AppScan Standard and Express 7.8.x, 7.9.x, and 8.0.x before 8.0.0.3 allows remote …

Mitigation only
Fix from $1,950 2011-10-30
Rational Appscan HIGH 8.8
CVE-2011-1366

Unspecified vulnerability in the Import feature in IBM Rational AppScan Enterprise and AppScan Reporting Console 5.2 through 7.9.x and 8.x before 8.0…

Mitigation only
Fix from $1,950 2011-10-30
Websphere Application Server MEDIUM 5.0
CVE-2009-2747

The Java Naming and Directory Interface (JNDI) implementation in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.39, 6.1 before 6.1.0.29, and…

Mitigation only
Fix from $1,600 2011-10-30
Websphere Application Server MEDIUM 5.0
CVE-2011-1368

The JavaServer Faces (JSF) application functionality in IBM WebSphere Application Server 8.x before 8.0.0.1 does not properly handle requests, which …

Mitigation only
Fix from $1,600 2011-10-29
Lotus Sametime MEDIUM 5.0
CVE-2011-1370

The default configuration of the Sametime configuration servlet (SCS) in the server in IBM Lotus Sametime 7.0 through 8.5.2 does not enable an authen…

Mitigation only
Fix from $1,600 2011-10-29
Db2 MEDIUM 6.9
CVE-2011-4061

Multiple untrusted search path vulnerabilities in (1) db2rspgn and (2) kbbacf1 in IBM DB2 Express Edition 9.7, as used in the IBM Tivoli Monitoring f…

No fix yet
Fix from $1,600 2011-10-18
Websphere Commerce HIGH 10.0
CVE-2011-3577

IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.3 does not properly implement Activity Token authentication for Web Services, which…

Mitigation only
Fix from $1,950 2011-09-20