Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Tivoli Storage Manager Fastback MEDIUM 5.0
CVE-2010-3061

Unspecified vulnerability in the message-protocol implementation in the Mount service in IBM Tivoli Storage Manager (TSM) FastBack 5.x.x before 5.5.7…

Mitigation only
Fix from $1,600 2010-08-20
Tivoli Directory Server MEDIUM 5.0
CVE-2010-2927

The slapi_printmessage function in IBM Tivoli Directory Server (ITDS) before 6.0.0.8-TIV-ITDS-IF0006 allows remote attackers to cause a denial of ser…

Fix: after 6.0.0.8
Fix from $1,600 2010-08-02
Soliddb HIGH 10.0
CVE-2010-2771EPSS 5%

solid.exe in IBM solidDB before 6.5 FP2 allows remote attackers to execute arbitrary code via a long username field in the first handshake packet.

Fix: after 6.5.0.1
Fix from $1,950 2010-07-22
Advanced Management Module MEDIUM 5.0
CVE-2010-2656

The IBM BladeCenter with Advanced Management Module (AMM) firmware build ID BPET48L, and possibly other versions before 4.7 and 5.0, stores sensitive…

Fix: after 2.48
Fix from $1,600 2010-07-08
Rational Clearquest HIGH 7.5
CVE-2010-2517

Multiple unspecified vulnerabilities in IBM Rational ClearQuest before 7.1.1.02 have unknown impact and attack vectors, as demonstrated by an AppScan…

Fix: after 7.1.1.1
Fix from $1,950 2010-06-30
P8 Content Engine HIGH 7.5
CVE-2010-2518

Unspecified vulnerability in the P8 Content Engine (P8CE) 4.5.1 before FP3 and the P8 Content Search Engine (P8CSE) before 4.5.0 FP3 and 4.5.1 before…

No fix yet
Fix from $1,950 2010-06-30
Websphere Application Server HIGH 7.5
CVE-2010-2324

IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11 on z/OS allows attackers to perform unspecified "link injection" actions via unknown vecto…

Fix: after 7.0.0.10
Fix from $1,950 2010-06-18
Websphere Application Server MEDIUM 5.0
CVE-2010-2323

IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11 on z/OS might allow attackers to obtain sensitive information by reading the default_creat…

Fix: after 7.0.0.10
Fix from $1,600 2010-06-18
Websphere Application Server MEDIUM 5.0
CVE-2010-2328

The HTTP Channel in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11 allows remote attackers to cause a denial of service (NullPointerExcep…

Patch available
Fix from $1,600 2010-06-18
Lotus Connections HIGH 7.6
CVE-2010-2279

The Top Updates implementation in the Homepage component in IBM Lotus Connections 2.5.x before 2.5.0.2, when "forced SSL" is enabled, uses http for l…

Patch available
Fix from $1,950 2010-06-15
Communications Server MEDIUM 5.0
CVE-2010-2090

The npb_protocol_error function in sna V5router64 in IBM Communications Server for Windows 6.1.3 and Communications Server for AIX (aka CSAIX or CS/A…

Mitigation only
Fix from $1,600 2010-05-27
Websphere Application Server MEDIUM 5.0
CVE-2010-0775

Unspecified vulnerability in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.11 allows remote a…

Mitigation only
Fix from $1,600 2010-05-17
Websphere Application Server MEDIUM 5.0
CVE-2010-0776

The Web Container in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.43, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.11 does not properly handl…

Mitigation only
Fix from $1,600 2010-05-17
Websphere Datapower Xml Accelerator Xa35 MEDIUM 5.0
CVE-2010-1612

The IBM WebSphere DataPower XML Accelerator XA35, Low Latency Appliance XM70, Integration Appliance XI50, B2B Appliance XB60, and XML Security Gatewa…

Fix: after 3.7.3.10
Fix from $1,600 2010-04-29
Lotus Notes HIGH 10.0
CVE-2010-1608EPSS 6%

Stack-based buffer overflow in IBM Lotus Notes 8.5 and 8.5fp1, and possibly other versions, allows remote attackers to execute arbitrary code via unk…

Mitigation only
Fix from $1,950 2010-04-29
Cognos 8 Business Intelligence HIGH 10.0
CVE-2010-1490

Unspecified vulnerability in IBM Cognos 8 Business Intelligence before 8.4.1 FP1 has unknown impact and attack vectors.

Fix: after 8.4.1
Fix from $1,950 2010-04-21
Advanced Management Module MEDIUM 5.0
CVE-2010-1460

The IBM BladeCenter with Advanced Management Module (AMM) firmware before bpet50g does not properly perform interrupt sharing for USB and iSCSI, whic…

Fix: after 2.50
Fix from $1,600 2010-04-16
Websphere Portal HIGH 7.5
CVE-2010-1348

Unspecified vulnerability in the login process in IBM WebSphere Portal 6.0.1.1, and 6.1.0.x before 6.1.0.3 Cumulative Fix 03, has unknown impact and …

Patch available
Fix from $1,950 2010-04-12
Director Agent HIGH 7.2
CVE-2010-1347

Director Agent 6.1 before 6.1.2.3 in IBM Systems Director on AIX and Linux uses incorrect permissions for the (1) diruninstall and (2) opt/ibm/direct…

Mitigation only
Fix from $1,950 2010-04-12
Webi HIGH 7.5
CVE-2010-1243

The IBM Web Interface for Content Management (aka WEBi) before 1.0.4 creates persistent cookies on client workstations, which has unspecified impact …

Fix: after 1.0.3
Fix from $1,950 2010-04-05
Websphere Application Server HIGH 7.5
CVE-2010-1182

Multiple unspecified vulnerabilities in the administrative console in IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.9 on z/OS have unknow…

No fix yet
Fix from $1,950 2010-03-29
Aix HIGH 7.8
CVE-2010-1124

bos.rte.libc 5.3.9.4 on IBM AIX 5.3 does not properly support reading a certain address field after a successful getaddrinfo function call, which all…

Mitigation only
Fix from $1,950 2010-03-26
Db2 Content Manager HIGH 10.0
CVE-2010-1041

Unspecified vulnerability in the single sign-on functionality in the Web Services implementation in IBM DB2 Content Manager (CM) Toolkit 8.3 before F…

Fix: after 8.3
Fix from $1,950 2010-03-23
Vios HIGH 7.2
CVE-2010-0960

Buffer overflow in qosmod in bos.net.tcp.server in IBM AIX 6.1 and VIOS 2.1 allows local users to gain privileges via unspecified vectors.

Mitigation only
Fix from $1,950 2010-03-10
Vios HIGH 7.2
CVE-2010-0961

Buffer overflow in qoslist in bos.net.tcp.server in IBM AIX 6.1 and VIOS 2.1 allows local users to gain privileges via unspecified vectors.

Mitigation only
Fix from $1,950 2010-03-10
Lotus Notes HIGH 10.0
CVE-2009-3032

Integer overflow in kvolefio.dll 8.5.0.8339 and 10.5.0.0 in the Autonomy KeyView Filter SDK, as used in IBM Lotus Notes 8.5, Symantec Mail Security f…

No fix yet
Fix from $1,950 2010-03-05
Informix Dynamic Server HIGH 10.0
CVE-2009-2753EPSS 11%

Multiple buffer overflows in the authentication functionality in librpc.dll in the Informix Storage Manager (ISM) Portmapper service (aka portmap.exe…

Patch available
Fix from $1,950 2010-03-05
Informix Dynamic Server HIGH 10.0
CVE-2009-2754EPSS 40%

Integer signedness error in the authentication functionality in librpc.dll in the Informix Storage Manager (ISM) Portmapper service (aka portmap.exe)…

Patch available
Fix from $1,950 2010-03-05
Lotus Inotes HIGH 10.0
CVE-2010-0918

Multiple unspecified vulnerabilities in the UltraLite functionality in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.281 for Domino 8.0.…

Fix: after 229.271
Fix from $1,950 2010-03-03
Aix HIGH 7.8
CVE-2010-0922

Unspecified vulnerability in secldapclntd in IBM AIX 5.3 with SP 5300-11-02 allows attackers to cause a denial of service (LDAP login failure) via un…

Mitigation only
Fix from $1,950 2010-03-03