Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Tivoli Storage Manager Client HIGH 10.0
CVE-2009-1520

Buffer overflow in the Web GUI in the IBM Tivoli Storage Manager (TSM) client 5.1.0.0 through 5.1.8.2, 5.2.0.0 through 5.2.5.3, 5.3.0.0 through 5.3.6…

Mitigation only
Fix from $1,950 2009-05-05
Tivoli Storage Manager Client HIGH 7.5
CVE-2009-1521

Unspecified vulnerability in the Java GUI in the IBM Tivoli Storage Manager (TSM) client 5.2.0.0 through 5.2.5.3, 5.3.0.0 through 5.3.6.5, 5.4.0.0 th…

Patch available
Fix from $1,950 2009-05-05
Tivoli Storage Manager Client HIGH 7.1
CVE-2009-1522

The IBM Tivoli Storage Manager (TSM) client 5.5.0.0 through 5.5.1.17 on AIX and Windows, when SSL is used, allows remote attackers to conduct unspeci…

Patch available
Fix from $1,950 2009-05-05
Aix HIGH 7.2
CVE-2009-1355

Stack-based buffer overflow in muxatmd in IBM AIX 5.2, 5.3, and 6.1 allows local users to gain privileges via a long filename.

Patch available
Fix from $1,950 2009-04-21
Advanced Management Module MEDIUM 6.8
CVE-2009-1290

Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration interface in the Advanced Management Module (AMM) on the IBM Bla…

No fix yet
Fix from $1,600 2009-04-13
Lotus Domino MEDIUM 5.0
CVE-2009-1286

The IMAP task in the server in IBM Lotus Domino 8.0.2 before FP1 IF1 and 8.5 before IF3 allows remote attackers to cause a denial of service (daemon …

Patch available
Fix from $1,600 2009-04-13
Afs HIGH 7.8
CVE-2009-1250

The cache manager in the client in OpenAFS 1.0 through 1.4.8 and 1.5.0 through 1.5.58, and IBM AFS 3.6 before Patch 19, on Linux allows remote attack…

Fix: after 3.6
Fix from $1,950 2009-04-09
Proventia Desktop Endpoint Security HIGH 10.0
CVE-2009-1240

Unspecified vulnerability in the IBM Proventia engine 4.9.0.0.44 20081231, as used in IBM Proventia Network Mail Security System, Network Mail Securi…

Mitigation only
Fix from $1,950 2009-04-03
Db2 MEDIUM 5.0
CVE-2009-1239

IBM DB2 9.1 before FP7 returns incorrect query results in certain situations related to the order of application of an INNER JOIN predicate and an OU…

Fix: after 9.1
Fix from $1,600 2009-04-03
Db2 Content Manager HIGH 10.0
CVE-2009-1231

Unspecified vulnerability in the eClient in IBM DB2 Content Manager 8.4.1 before 8.4.1.1 has unknown impact and attack vectors.

Patch available
Fix from $1,950 2009-04-02
Tivoli Storage Manager HIGH 10.0
CVE-2009-1178

Unspecified vulnerability in the server in IBM Tivoli Storage Manager (TSM) 5.3.x before 5.3.2 and 6.x before 6.1 has unknown impact and attack vecto…

Patch available
Fix from $1,950 2009-03-31
Websphere Application Server HIGH 10.0
CVE-2009-1172

The JAX-RPC WS-Security runtime in the Web Services Security component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 and 7.0 before 7…

Patch available
Fix from $1,950 2009-03-31
Websphere Application Server HIGH 10.0
CVE-2009-1174

The Web Services Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 and 7.0 before 7.0.0.3 has an unspecified "securi…

Patch available
Fix from $1,950 2009-03-31
Websphere Application Server MEDIUM 5.5
CVE-2009-0892

The administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 and 7.0 before 7.0.0.3 allows attackers to hijack user sessi…

Patch available
Fix from $1,600 2009-03-31
Access Support Activex Control HIGH 9.3
CVE-2009-0215EPSS 36%

Stack-based buffer overflow in the GetXMLValue method in the IBM Access Support ActiveX control in IbmEgath.dll, as distributed on IBM and Lenovo com…

Mitigation only
Fix from $1,950 2009-03-25
Websphere Application Server MEDIUM 5.5
CVE-2009-0891

The Web Services Security component in IBM WebSphere Application Server 7.0 before Fix Pack 1 (7.0.0.1), 6.1 before Fix Pack 23 (6.1.0.23),and 6.0.2 …

Patch available
Fix from $1,600 2009-03-25
Rational Appscan MEDIUM 5.0
CVE-2009-1056

IBM Rational AppScan Enterprise before 5.5 FP1 allows remote attackers to read arbitrary exported reports by "forcefully browsing."

Fix: after 5.5
Fix from $1,600 2009-03-24
Websphere Application Server HIGH 7.5
CVE-2009-0508

The Servlet Engine/Web Container and JSP components in IBM WebSphere Application Server (WAS) 5.1.0, 5.1.1.19, 6.0.2 before 6.0.2.35, 6.1 before 6.1.…

Patch available
Fix from $1,950 2009-03-16
Director MEDIUM 6.8
CVE-2009-0880EPSS 32%

Directory traversal vulnerability in the CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows remote attackers to load and exe…

Fix: after 5.20.3
Fix from $1,600 2009-03-12
Director MEDIUM 5.0
CVE-2009-0879EPSS 8%

The CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows remote attackers to cause a denial of service (daemon crash) via a lo…

Fix: after 5.20.3
Fix from $1,600 2009-03-12
Tivoli Storage Manager HIGH 10.0
CVE-2008-4563EPSS 29%

Heap-based buffer overflow in adsmdll.dll 5.3.7.7296, as used by the daemon (dsmsvc.exe) in the backup server in IBM Tivoli Storage Manager (TSM) Exp…

Patch available
Fix from $1,950 2009-03-11
Tivoli Storage Manager Hsm HIGH 10.0
CVE-2009-0869EPSS 6%

Buffer overflow in the client in IBM Tivoli Storage Manager (TSM) HSM 5.3.2.0 through 5.3.5.0, 5.4.0.0 through 5.4.2.5, and 5.5.0.0 through 5.5.1.4 o…

Patch available
Fix from $1,950 2009-03-10
Aix HIGH 7.2
CVE-2009-0779

Buffer overflow in pppdial in IBM AIX 5.3 and 6.1 allows local users to gain privileges via a long "input string."

Patch available
Fix from $1,950 2009-03-04
Txseries HIGH 9.0
CVE-2009-0505

The CICS listener in IBM TXSeries for Multiplatforms 6.2 GA waits for a forcepurge acknowledgement from the CICS Application Server (CICSAS) after an…

Patch available
Fix from $1,950 2009-02-25
Websphere Application Server MEDIUM 6.2
CVE-2009-0506

Unspecified vulnerability in IBM WebSphere Application Server (WAS) 5.1 and 6.0.2 before 6.0.2.33 on z/OS, when CSIv2 Identity Assertion is enabled a…

Patch available
Fix from $1,600 2009-02-25
Websphere Mq HIGH 7.2
CVE-2009-0439

Unspecified vulnerability in the queue manager in IBM WebSphere MQ (WMQ) 5.3, 6.0 before 6.0.2.6, and 7.0 before 7.0.0.2 allows local users to gain p…

Patch available
Fix from $1,950 2009-02-24
Websphere Partner Gateway MEDIUM 6.5
CVE-2009-0440

IBM WebSphere Partner Gateway (WPG) 6.0.0 through 6.0.0.7 does not properly handle failures of signature verification, which might allow remote authe…

Patch available
Fix from $1,600 2009-02-22
Websphere Application Server MEDIUM 5.0
CVE-2008-4285

Unspecified vulnerability in the Performance Monitoring Infrastructure (PMI) feature in the Servlet Engine/Web Container component in IBM WebSphere A…

Patch available
Fix from $1,600 2009-02-17
Websphere Application Server HIGH 10.0
CVE-2008-4283

CRLF injection vulnerability in the WebContainer component in IBM WebSphere Application Server (WAS) 5.1.1.19 and earlier 5.1.x versions allows remot…

Fix: after 5.1.1.19
Fix from $1,950 2009-02-10
Websphere Application Server HIGH 7.2
CVE-2009-0436

The (1) mod_ibm_ssl and (2) mod_cgid modules in IBM HTTP Server 6.0.x before 6.0.2.31 and 6.1.x before 6.1.0.19, as used in WebSphere Application Ser…

Patch available
Fix from $1,950 2009-02-10