Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Datacap Taskmaster Capture MEDIUM 5.0
CVE-2011-2142

The Web Client Service in IBM Datacap Taskmaster Capture 8.0.1 before FP1 requires a cleartext password, which has unspecified impact and attack vect…

No fix yet
Fix from $1,600 2011-05-16
Datacap Taskmaster Capture MEDIUM 5.0
CVE-2011-2144

The eDocument Conversion Actions implementation in IBM Datacap Taskmaster Capture 8.0.1 FP1 and earlier allows remote attackers to cause a denial of …

Fix: after 8.0.1
Fix from $1,600 2011-05-16
Rational System Architect HIGH 9.3
CVE-2011-1207EPSS 5%

The ActiveBar1 ActiveX control in the Data Dynamics ActiveBar ActiveX controls, as distributed in ActBar.ocx 1.0.6.5 in IBM Rational System Architect…

Fix: after 11.4.0.2
Fix from $1,950 2011-05-05
Soliddb HIGH 7.8
CVE-2011-1208

IBM solidDB 4.5.x before 4.5.182, 6.0.x before 6.0.1069, 6.1.x and 6.3.x before 6.3 FP8 (aka 6.3.49), and 6.5.x before 6.5 FP4 (aka 6.5.0.4) does not…

Mitigation only
Fix from $1,950 2011-05-05
Db2 MEDIUM 6.5
CVE-2011-1846

IBM DB2 9.5 before FP7 and 9.7 before FP4 on Linux, UNIX, and Windows does not properly revoke role membership from groups, which allows remote authe…

Fix: after 9.7
Fix from $1,600 2011-05-03
Rational Build Forge MEDIUM 5.0
CVE-2011-1839

IBM Rational Build Forge 7.1.0 uses the HTTP GET method during redirection from the authentication servlet to a PHP script, which makes it easier for…

Mitigation only
Fix from $1,600 2011-04-28
Tivoli Directory Server HIGH 10.0
CVE-2011-1206EPSS 16%

Stack-based buffer overflow in the server process in ibmslapd.exe in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0010, 6.0 before…

Patch available
Fix from $1,950 2011-04-21
Tivoli Directory Server MEDIUM 6.8
CVE-2007-6742

The get_filter_list function in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0006 does not properly perform certain sub filter par…

Patch available
Fix from $1,600 2011-04-21
Tivoli Directory Server MEDIUM 5.0
CVE-2008-7288

IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0007 on AIX allows remote attackers to cause a denial of service (server destabilizat…

Mitigation only
Fix from $1,600 2011-04-21
Websphere Application Server MEDIUM 6.8
CVE-2011-1683

IBM WebSphere Application Server (WAS) 6.0.x through 6.0.2.43, 6.1.x before 6.1.0.37, and 7.0.x before 7.0.0.17 on z/OS, when a Local OS user registr…

Mitigation only
Fix from $1,600 2011-04-13
Aix MEDIUM 6.8
CVE-2011-1561

The LDAP login feature in bos.rte.security 6.1.6.4 in IBM AIX 6.1, when ldap_auth is enabled in ldap.cfg, allows remote attackers to bypass authentic…

Mitigation only
Fix from $1,600 2011-04-05
Webi HIGH 10.0
CVE-2011-1559

Unspecified vulnerability in the IBM Web Interface for Content Management (aka WEBi) 1.0.4 before FP3 has unknown impact and attack vectors.

No fix yet
Fix from $1,950 2011-04-05
Soliddb HIGH 9.3
CVE-2011-1560

solid.exe in IBM solidDB before 4.5.181, 6.0.x before 6.0.1067, 6.1.x and 6.3.x before 6.3.47, and 6.5.x before 6.5.0.3 uses a password-hash length s…

Fix: after 4.5.180
Fix from $1,950 2011-04-05
Rational Clearcase MEDIUM 6.9
CVE-2011-1205

Multiple buffer overflows in unspecified COM objects in Rational Common Licensing 7.0 through 7.1.1.4 in IBM Rational ClearCase 7.0.0.4 through 7.1.1…

Mitigation only
Fix from $1,600 2011-03-29
Lotus Domino HIGH 7.2
CVE-2011-1520

The default configuration of the server console in IBM Lotus Domino does not require a password (aka Server_Console_Password), which allows physicall…

Mitigation only
Fix from $1,950 2011-03-25
Lotus Domino HIGH 10.0
CVE-2011-1519EPSS 9%

The remote console in the Server Controller in IBM Lotus Domino 7.x and 8.x verifies credentials against a file located at a UNC share pathname speci…

Mitigation only
Fix from $1,950 2011-03-25
Lotus Quickr HIGH 10.0
CVE-2011-1505

Unspecified vulnerability in IBM Lotus Quickr 8.1 before 8.1.0.27 services for Lotus Domino has unknown impact and attack vectors, aka SPR ESEO8DQME2.

No fix yet
Fix from $1,950 2011-03-22
Lotus Quickr MEDIUM 5.0
CVE-2008-7285

Unspecified vulnerability in the docnote string handling implementation in IBM Lotus Quickr 8.1 before 8.1.0.2 services for Lotus Domino allows remot…

Mitigation only
Fix from $1,600 2011-03-22
Tivoli Netcool\/omnibus HIGH 7.5
CVE-2011-1343

SQL injection vulnerability in the Web GUI in IBM Tivoli Netcool/OMNIbus before 7.3.0.4 allows remote attackers to execute arbitrary SQL commands via…

Fix: after 7.2.1.10
Fix from $1,950 2011-03-09
Websphere Application Server MEDIUM 6.8
CVE-2011-1320

The Security component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.35 and 7.x before 7.0.0.15, when the Tivoli Integrated Portal /…

Mitigation only
Fix from $1,600 2011-03-08
Websphere Application Server MEDIUM 6.5
CVE-2011-1321

The AuthCache purge implementation in the Security component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.37 and 7.x before 7.0.0.1…

Mitigation only
Fix from $1,600 2011-03-08
Websphere Application Server MEDIUM 5.0
CVE-2011-1317

Memory leak in com.ibm.ws.jsp.runtime.WASJSPStrBufferImpl in the JavaServer Pages (JSP) component in IBM WebSphere Application Server (WAS) 6.1.0.x b…

Patch available
Fix from $1,600 2011-03-08
Websphere Application Server MEDIUM 5.0
CVE-2011-1318

Memory leak in org.apache.jasper.runtime.JspWriterImpl.response in the JavaServer Pages (JSP) component in IBM WebSphere Application Server (WAS) bef…

Fix: after 7.0.0.13
Fix from $1,600 2011-03-08
Websphere Application Server MEDIUM 5.0
CVE-2011-1322

The SOAP with Attachments API for Java (SAAJ) implementation in the Web Services component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6…

Mitigation only
Fix from $1,600 2011-03-08
Websphere Application Server HIGH 7.5
CVE-2011-1309

The Plug-in component in IBM WebSphere Application Server (WAS) before 7.0.0.15 does not properly handle trace requests, which has unspecified impact…

Fix: after 7.0.0.13
Fix from $1,950 2011-03-08
Websphere Application Server MEDIUM 6.0
CVE-2011-1311

The Security component in IBM WebSphere Application Server (WAS) before 7.0.0.15, when a J2EE 1.4 application is used, determines the security role m…

Fix: after 7.0.0.13
Fix from $1,600 2011-03-08
Websphere Application Server MEDIUM 5.0
CVE-2011-1313

Double free vulnerability in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.35 and 7.x before 7.0.0.15 allows remote backend IIOP server…

Patch available
Fix from $1,600 2011-03-08
Websphere Application Server MEDIUM 5.0
CVE-2011-1314

The Service Integration Bus (SIB) messaging engine in IBM WebSphere Application Server (WAS) before 7.0.0.15 allows remote attackers to cause a denia…

Fix: after 7.0.0.13
Fix from $1,600 2011-03-08
Websphere Application Server MEDIUM 5.0
CVE-2011-1315

Memory leak in the messaging engine in IBM WebSphere Application Server (WAS) before 7.0.0.15 allows remote attackers to cause a denial of service (m…

Fix: after 7.0.0.13
Fix from $1,600 2011-03-08
Websphere Application Server MEDIUM 5.0
CVE-2011-1316

The Session Initiation Protocol (SIP) Proxy in the HTTP Transport component in IBM WebSphere Application Server (WAS) before 7.0.0.15 allows remote a…

Fix: after 7.0.0.13
Fix from $1,600 2011-03-08