Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Lotus Domino HIGH 9.0
CVE-2011-3575EPSS 11%

Stack-based buffer overflow in the NSFComputeEvaluateExt function in Nnotes.dll in IBM Lotus Domino 8.5.2 allows remote authenticated users to execut…

No fix yet
Fix from $1,950 2011-09-19
Websphere Application Server MEDIUM 5.0
CVE-2011-1359

Directory traversal vulnerability in the administration console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.41, 7.0 before 7.0.0.19, a…

Mitigation only
Fix from $1,600 2011-09-06
Web Application Firewall MEDIUM 5.0
CVE-2011-3140

IBM Web Application Firewall, as used on the G400 IPS-G400-IB-1 and GX4004 IPS-GX4004-IB-2 appliances with update 31.030, does not properly handle qu…

No fix yet
Fix from $1,600 2011-08-15
Tivoli Federated Identity Manager HIGH 10.0
CVE-2011-3135

Unspecified vulnerability in the Runtime in IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.9 and Tivoli Federated Identity Manager B…

Mitigation only
Fix from $1,950 2011-08-12
Tivoli Federated Identity Manager HIGH 10.0
CVE-2011-3136

Unspecified vulnerability in the Management Console in IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.9 and Tivoli Federated Identit…

Mitigation only
Fix from $1,950 2011-08-12
Tivoli Federated Identity Manager HIGH 10.0
CVE-2011-3137

Unspecified vulnerability in the Management Console in IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.9 and Tivoli Federated Identit…

Mitigation only
Fix from $1,950 2011-08-12
Tivoli Federated Identity Manager MEDIUM 5.0
CVE-2011-3138

The LTPA STS module support implementation in IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.9 and Tivoli Federated Identity Manager…

Mitigation only
Fix from $1,600 2011-08-12
Tivoli Federated Identity Manager MEDIUM 6.8
CVE-2009-5083

IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.2, when configured as an OpenID relying party, does not perform the expected login re…

No fix yet
Fix from $1,600 2011-08-12
Tivoli Federated Identity Manager MEDIUM 5.0
CVE-2008-7299

IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.2 uses an incomplete SAML 1.x browser-artifact, which allows remote OpenID providers …

Mitigation only
Fix from $1,600 2011-08-12
Infosphere Datastage HIGH 7.2
CVE-2011-3123

IBM InfoSphere Information Server 8.5 and 8.5.0.1 on Unix and Linux, as used in IBM InfoSphere DataStage 8.5 and 8.5.0.1 and other products, uses wea…

Mitigation only
Fix from $1,950 2011-08-10
Infosphere Datastage HIGH 7.2
CVE-2011-3124

IBM InfoSphere Information Server 8.5 and 8.5.0.1 on Unix and Linux, as used in IBM InfoSphere DataStage 8.5 and 8.5.0.1 and other products, assigns …

Mitigation only
Fix from $1,950 2011-08-10
Lotus Symphony HIGH 10.0
CVE-2011-2884

Multiple unspecified vulnerabilities in IBM Lotus Symphony 3 before FP3 have unknown impact and attack vectors, related to "critical security vulnera…

No fix yet
Fix from $1,950 2011-07-27
Websphere Application Server MEDIUM 5.8
CVE-2011-1355

Open redirect vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.39 and 7.0 before 7.0.0.19 allows remote attackers to redirect…

Mitigation only
Fix from $1,600 2011-07-19
Websphere Application Server MEDIUM 6.8
CVE-2010-3271

Multiple cross-site request forgery (CSRF) vulnerabilities in the Integrated Solutions Console (aka administrative console) in IBM WebSphere Applicat…

Fix: after 7.0.0.13
Fix from $1,600 2011-07-18
Tivoli Directory Server MEDIUM 5.0
CVE-2011-2758

IDSWebApp in the Web Administration Tool in IBM Tivoli Directory Server (TDS) 6.2 before 6.2.0.3-TIV-ITDS-IF0004 does not require authentication for …

Mitigation only
Fix from $1,600 2011-07-17
Tivoli Directory Server MEDIUM 5.0
CVE-2011-2759

The login page of IDSWebApp in the Web Administration Tool in IBM Tivoli Directory Server (TDS) 6.2 before 6.2.0.3-TIV-ITDS-IF0004 does not have an o…

Mitigation only
Fix from $1,600 2011-07-17
Tivoli Storage Manager HIGH 7.2
CVE-2011-1222

Buffer overflow in the Journal Based Backup (JBB) feature in the backup-archive client in IBM Tivoli Storage Manager (TSM) before 5.4.3.4, 5.5.x befo…

Fix: after 5.4.3.3
Fix from $1,950 2011-07-17
Tivoli Storage Manager HIGH 7.2
CVE-2011-1223

Buffer overflow in the Alternate Data Stream (aka ADS or named stream) functionality in the backup-archive client in IBM Tivoli Storage Manager (TSM)…

Fix: after 5.4.3.3
Fix from $1,950 2011-07-17
Rational Doors Web Access HIGH 10.0
CVE-2011-2680

Unspecified vulnerability in IBM Rational DOORS Web Access 1.4.x before 1.4.0.4 has unknown impact and remote attack vectors related to the "server e…

Mitigation only
Fix from $1,950 2011-07-07
Rational Doors Web Access HIGH 10.0
CVE-2011-2681

IBM Rational DOORS Web Access 1.4.x before 1.4.0.4 does not properly handle exceptions, which has unspecified impact and remote attack vectors.

Mitigation only
Fix from $1,950 2011-07-07
Tivoli Management Framework HIGH 9.0
CVE-2011-2330

Tivoli Endpoint in IBM Tivoli Management Framework 3.7.1, 4.1, 4.1.1, and 4.3.1 has an unspecified "built-in account" that is "trivially" accessed, w…

No fix yet
Fix from $1,950 2011-06-02
Tivoli Management Framework HIGH 9.0
CVE-2011-1220EPSS 63%

Stack-based buffer overflow in lcfd.exe in Tivoli Endpoint in IBM Tivoli Management Framework 3.7.1, 4.1, 4.1.1, and 4.3.1 allows remote authenticate…

Mitigation only
Fix from $1,950 2011-06-02
Lotus Notes HIGH 9.3
CVE-2011-1215EPSS 6%

Stack-based buffer overflow in mw8sr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitra…

Fix: after 8.5.2.2
Fix from $1,950 2011-05-31
Lotus Notes HIGH 9.3
CVE-2011-1216EPSS 6%

Stack-based buffer overflow in assr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrar…

Fix: after 8.5.2.2
Fix from $1,950 2011-05-31
Lotus Notes HIGH 9.3
CVE-2011-1217EPSS 5%

Buffer overflow in kpprzrdr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code v…

Fix: after 8.5.2.2
Fix from $1,950 2011-05-31
Lotus Notes HIGH 9.3
CVE-2011-1213EPSS 33%

Integer underflow in lzhsr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code vi…

Fix: after 8.5.2.2
Fix from $1,950 2011-05-31
Lotus Notes HIGH 9.3
CVE-2011-1214EPSS 6%

Stack-based buffer overflow in rtfsr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitra…

Fix: after 8.5.2.2
Fix from $1,950 2011-05-31
Systems Director HIGH 9.3
CVE-2011-2163

Unspecified vulnerability in Virtualization Manager 1.2.2 in IBM Systems Director 1.2.2 has unknown impact and attack vectors.

No fix yet
Fix from $1,950 2011-05-20
Datacap Taskmaster Capture HIGH 7.5
CVE-2011-2141

SQL injection vulnerability in TMWeb in IBM Datacap Taskmaster Capture 8.0.1 before FP1 allows remote attackers to execute arbitrary SQL commands via…

Mitigation only
Fix from $1,950 2011-05-16
Datacap Taskmaster Capture MEDIUM 6.8
CVE-2011-2143

IBM Datacap Taskmaster Capture 8.0.1 before FP1, when Windows Authentication is enabled, allows remote attackers to obtain login access by using an i…

Mitigation only
Fix from $1,600 2011-05-16