Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Websphere Application Server HIGH 7.5
CVE-2009-2085

The Security component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5 does not properly handle use of Identity …

Patch available
Fix from $1,950 2009-08-13
Websphere Application Server HIGH 7.5
CVE-2009-2088

The Servlet Engine/Web Container component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5, when SPNEGO Single S…

Patch available
Fix from $1,950 2009-08-13
Websphere Application Server HIGH 7.5
CVE-2009-2092

IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.5 does not properly read the portletServingEnabled parameter in ibm-portlet-ext.xmi, which al…

Patch available
Fix from $1,950 2009-08-13
Websphere Application Server MEDIUM 6.5
CVE-2009-0906

The Service Component Architecture (SCA) feature pack for IBM WebSphere Application Server (WAS) SCA 1.0 before 1.0.0.3 allows remote authenticated u…

Patch available
Fix from $1,600 2009-08-13
Websphere Partner Gateway MEDIUM 6.5
CVE-2009-2093

SQL injection vulnerability in the console in IBM WebSphere Partner Gateway (WPG) Enterprise 6.0 before FP8, 6.1 before FP3, 6.1.1 before FP2, and 6.…

Patch available
Fix from $1,600 2009-08-13
Websphere Application Server MEDIUM 5.0
CVE-2009-2090

Unspecified vulnerability in wsadmin in the System Management/Repository component in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.5 allow…

Patch available
Fix from $1,600 2009-08-13
Websphere Application Server MEDIUM 5.0
CVE-2009-2091

The System Management/Repository component in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.5 on z/OS uses weak file permissions for new ap…

Patch available
Fix from $1,600 2009-08-13
Aix HIGH 9.3
CVE-2009-2727EPSS 27%

Stack-based buffer overflow in the _tt_internal_realpath function in the ToolTalk library (libtt.a) in IBM AIX 5.2.0, 5.3.0, 5.3.7 through 5.3.10, an…

Patch available
Fix from $1,950 2009-08-10
Tklm HIGH 10.0
CVE-2009-2667

Unspecified vulnerability in IBM Tivoli Key Lifecycle Manager (TKLM) 1.0 has unknown impact and attack vectors, related to a "password security vulne…

Mitigation only
Fix from $1,950 2009-08-05
Aix HIGH 7.2
CVE-2009-2669

A certain debugging component in IBM AIX 5.3 and 6.1 does not properly handle the (1) _LIB_INIT_DBG and (2) _LIB_INIT_DBG_FILE environment variables,…

Patch available
Fix from $1,950 2009-08-05
Tivoli Identity Manager MEDIUM 6.8
CVE-2009-2583

Multiple session fixation vulnerabilities in IBM Tivoli Identity Manager (ITIM) 5.0.0.6 allow remote attackers to hijack web sessions via unspecified…

Patch available
Fix from $1,600 2009-07-23
Proventia Desktop Endpoint Security HIGH 10.0
CVE-2009-2543

Multiple unspecified vulnerabilities in the IBM Proventia engine 4.9.0.0.44 20081231, as used in IBM Proventia Network Mail Security System, Network …

Mitigation only
Fix from $1,950 2009-07-20
Websphere Application Server MEDIUM 5.0
CVE-2009-0217EPSS 6%

The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in products including (1) the Oracle Security Deve…

Patch available
Fix from $1,600 2009-07-14
Aix HIGH 7.2
CVE-2009-2434

Buffer overflow in the syscall implementation in IBM AIX 5.3 allows local users to gain privileges via unspecified vectors.

Patch available
Fix from $1,950 2009-07-13
Lotus Instant Messaging And Web Conferencing MEDIUM 5.0
CVE-2009-2435

The Sametime server in IBM Lotus Instant Messaging and Web Conferencing 6.5.1 generates error messages for a failed logon attempt with different time…

Mitigation only
Fix from $1,600 2009-07-13
Websphere Application Server MEDIUM 6.4
CVE-2009-0904

The IBM Stax XMLStreamWriter in the Web Services component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 does not properly process XM…

Mitigation only
Fix from $1,600 2009-07-05
Rational Clearquest MEDIUM 5.0
CVE-2009-2212

The CQWeb server in IBM Rational ClearQuest 7.0.0 before 7.0.0.6 and 7.0.1 before 7.0.1.5 allows attackers to discover a (1) username or (2) password…

Patch available
Fix from $1,600 2009-06-25
Websphere Application Server HIGH 7.5
CVE-2009-0903

IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.3, and the Feature Pack for Web Services for WAS 6.1 before 6.1.0.25, when a WS-Security poli…

Patch available
Fix from $1,950 2009-06-25
Aix HIGH 7.8
CVE-2009-1954

Unspecified vulnerability in portmapper (aka portmap) in IBM AIX 5.3 allows attackers to cause a denial of service (daemon hang) via unknown vectors,…

Patch available
Fix from $1,950 2009-06-08
Db2 HIGH 10.0
CVE-2008-6820

The db2fmp process in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 on Windows runs with "OS privilege," which has unknown impact and att…

Patch available
Fix from $1,950 2009-06-03
Db2 HIGH 10.0
CVE-2008-6821

Buffer overflow in the DAS server in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 might allow attackers to execute arbitrary code or cau…

Patch available
Fix from $1,950 2009-06-03
Db2 MEDIUM 6.0
CVE-2008-2154

IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 provides an INSTALL_JAR (aka sqlj.install_jar) procedure, which allows remote authenticated…

Patch available
Fix from $1,600 2009-06-03
Websphere Mq HIGH 10.0
CVE-2009-0896EPSS 7%

Buffer overflow in the queue manager in IBM WebSphere MQ 6.x before 6.0.2.7 and 7.x before 7.0.1.0 allows remote attackers to execute arbitrary code …

Patch available
Fix from $1,950 2009-06-03
Websphere Application Server HIGH 10.0
CVE-2009-1899

Unspecified vulnerability in the Administrative Configservice API in the System Management/Repository component in IBM WebSphere Application Server (…

Fix: after 6.0.2.33
Fix from $1,950 2009-06-03
Websphere Application Server HIGH 10.0
CVE-2009-1901

The Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 permits "non-standard http methods," which has unknown impact …

Fix: after 6.0.2.33
Fix from $1,950 2009-06-03
Websphere Application Server MEDIUM 5.0
CVE-2009-1898

The secure login page in the Administrative Console component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 does not redirect to an…

Fix: after 6.0.2.33
Fix from $1,600 2009-06-03
Websphere Application Server MEDIUM 5.0
CVE-2009-1900

The Configservice APIs in the Administrative Console component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35, 6.1 before 6.1.0.25, …

Fix: after 6.0.2.33
Fix from $1,600 2009-06-03
Hardware Management Console HIGH 9.3
CVE-2009-1806

Unspecified vulnerability in IBM Hardware Management Console (HMC) 7 release 3.4.0 SP2, when Active Memory Sharing is used, has unknown impact and at…

Patch available
Fix from $1,950 2009-05-28
Aix MEDIUM 6.9
CVE-2009-1786

The malloc subsystem in libc in IBM AIX 5.3 and 6.1 allows local users to create or overwrite arbitrary files via a symlink attack on the log file as…

Patch available
Fix from $1,600 2009-05-26
Tivoli Storage Manager Client HIGH 10.0
CVE-2008-4828EPSS 71%

Multiple stack-based buffer overflows in dsmagent.exe in the Remote Agent Service in the IBM Tivoli Storage Manager (TSM) client 5.1.0.0 through 5.1.…

Patch available
Fix from $1,950 2009-05-05