Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Websphere Application Server MEDIUM 5.8
CVE-2008-4284

Open redirect vulnerability in the ibm_security_logout servlet in IBM WebSphere Application Server (WAS) 5.1.1.19 and earlier 5.x versions, 6.0.x bef…

Patch available
Fix from $1,600 2009-02-10
Websphere Application Server MEDIUM 5.0
CVE-2009-0432

The installation process for the File Transfer servlet in the System Management/Repository component in IBM WebSphere Application Server (WAS) 6.1.x …

Patch available
Fix from $1,600 2009-02-10
Websphere Application Server MEDIUM 5.0
CVE-2009-0435

Unspecified vulnerability in the IBM Asynchronous I/O (aka AIO or libibmaio) library in the Java Message Service (JMS) component in IBM WebSphere App…

Patch available
Fix from $1,600 2009-02-10
Websphere Application Server MEDIUM 5.0
CVE-2009-0438

IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 on Windows allows remote attackers to bypass "Authorization checking" and obtain sensitive in…

Patch available
Fix from $1,600 2009-02-10
Workplace For Business Controls And Reporting MEDIUM 6.8
CVE-2008-6106

Cross-site request forgery (CSRF) vulnerability in IBM Workplace for Business Controls and Reporting 2.x and IBM Workplace Web Content Management 6.x…

No fix yet
Fix from $1,600 2009-02-10
Websphere Application Server HIGH 7.8
CVE-2009-0391

Unspecified vulnerability in IBM WebSphere Application Server (WAS) 6.0.1 on z/OS allows attackers to read arbitrary files via unknown vectors.

No fix yet
Fix from $1,950 2009-02-02
Aix HIGH 7.2
CVE-2009-0370

Multiple unspecified vulnerabilities in IBM AIX 5.2.0 through 6.1.2 allow local users to append data to arbitrary files, related to (1) rmsock and (2…

Patch available
Fix from $1,950 2009-01-30
Hardware Management Console HIGH 10.0
CVE-2009-0178

Unspecified vulnerability in IBM Hardware Management Console (HMC) 7 release 3.2.0 SP1 has unknown impact and attack vectors.

No fix yet
Fix from $1,950 2009-01-20
Db2 Universal Database MEDIUM 5.0
CVE-2009-0172EPSS 8%

Unspecified vulnerability in IBM DB2 8 before FP17a, 9.1 before FP6a, and 9.5 before FP3a allows remote attackers to cause a denial of service (infin…

Patch available
Fix from $1,600 2009-01-16
Db2 Universal Database MEDIUM 5.0
CVE-2009-0173

Unspecified vulnerability in the server in IBM DB2 8 before FP17a, 9.1 before FP6a, and 9.5 before FP3a allows remote authenticated users to cause a …

Patch available
Fix from $1,600 2009-01-16
Websphere Datapower Xml Security Gateway Xs40 HIGH 7.8
CVE-2009-0120

The IBM WebSphere DataPower XML Security Gateway XS40 with firmware 3.6.1.5 allows remote attackers to cause a denial of service (device reboot) by s…

No fix yet
Fix from $1,950 2009-01-15
Tivoli Provisioning Manager HIGH 8.5
CVE-2008-5686

IBM Tivoli Provisioning Manager (TPM) before 5.1.1.1 IF0006, when its LDAP service is shared with other applications, does not require that an LDAP u…

Patch available
Fix from $1,950 2008-12-19
Websphere Portal HIGH 10.0
CVE-2008-5675

Unspecified vulnerability in IBM WebSphere Portal 6.0 before 6.0.1.5 has unknown impact and attack vectors related to "Access problems with BasicAuth…

Fix: after 6.0.1.4
Fix from $1,950 2008-12-19
Websphere Application Server HIGH 10.0
CVE-2008-5412

Unspecified vulnerability in IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 on Windows has unknown impact and attack vectors related to JSPs…

Fix: after 7.0
Fix from $1,950 2008-12-10
Websphere Application Server HIGH 10.0
CVE-2008-5414

Unspecified vulnerability in the Feature Pack for Web Services in the Web Services Security component in IBM WebSphere Application Server (WAS) 7 bef…

Patch available
Fix from $1,950 2008-12-10
Websphere Application Server MEDIUM 5.0
CVE-2008-5411

IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 sends SSL traffic over "unsecured TCP," which makes it easier for remote attackers to obtain …

Fix: after 7.0
Fix from $1,600 2008-12-10
Websphere Application Server MEDIUM 5.0
CVE-2008-5413

PerfServlet in the PMI/Performance Tools component in IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 allows attackers to obtain sensitive in…

Fix: after 7.0
Fix from $1,600 2008-12-10
Aix MEDIUM 6.9
CVE-2008-5384

crontab in bos.rte.cron in IBM AIX 6.1.0 through 6.1.2 allows local users with aix.system.config.cron authorization to gain privileges by launching a…

Patch available
Fix from $1,600 2008-12-09
Aix MEDIUM 6.9
CVE-2008-5385

enq in bos.rte.printers in IBM AIX 6.1.0 through 6.1.2, when a print queue is defined in /etc/qconfig, allows local users to delete arbitrary files v…

Patch available
Fix from $1,600 2008-12-09
Aix MEDIUM 6.9
CVE-2008-5386

Buffer overflow in ndp in IBM AIX 6.1.0 through 6.1.2, when the netcd daemon is running, allows local users to gain privileges via unspecified vector…

Patch available
Fix from $1,600 2008-12-09
Aix MEDIUM 6.2
CVE-2008-5387

Buffer overflow in autoconf6 in IBM AIX 6.1.0 through 6.1.2, when Role-Based Access Control is enabled, allows local users with aix.network.config.tc…

Patch available
Fix from $1,600 2008-12-09
Rational Clearquest HIGH 7.5
CVE-2008-5329

ClearQuest Web in IBM Rational ClearQuest MultiSite before 7.1 allows remote servers to direct a client's submissions and changes to an arbitrary dat…

Fix: after 7.0.0.3
Fix from $1,950 2008-12-05
Rational Clearquest MEDIUM 6.5
CVE-2008-5327

The ClearQuest Maintenance Tool in IBM Rational ClearQuest 7 before 7.1 stores the database password in cleartext in an object in a ClearQuest connec…

Mitigation only
Fix from $1,600 2008-12-05
Hardware Management Console MEDIUM 5.0
CVE-2008-5035

The Resource Monitoring and Control (RMC) daemon in IBM Hardware Management Console (HMC) 7 release 3.2.0 SP1 and 3.3.0 SP2 allows remote attackers t…

Mitigation only
Fix from $1,600 2008-11-10
Lotus Connections HIGH 10.0
CVE-2008-4809

Multiple unspecified vulnerabilities in the Profiles search pages in IBM Lotus Connections 2.x before 2.0.1 have unknown impact and attack vectors re…

Mitigation only
Fix from $1,950 2008-10-31
Lotus Connections HIGH 7.5
CVE-2008-4806

Multiple SQL injection vulnerabilities in IBM Lotus Connections 2.x before 2.0.1 allow remote attackers to execute arbitrary SQL commands via the sor…

Fix: after 2.0
Fix from $1,950 2008-10-31
Lotus Connections MEDIUM 5.0
CVE-2008-4808

IBM Lotus Connections 2.x before 2.0.1 allows attackers to discover passwords via unspecified vectors. NOTE: the provenance of this information is u…

Fix: after 2.0
Fix from $1,600 2008-10-31
Tivoli Storage Manager Client HIGH 10.0
CVE-2008-4801EPSS 11%

Heap-based buffer overflow in the Data Protection for SQL CAD service (aka dsmcat.exe) in the Client Acceptor Daemon (CAD) and the scheduler in the B…

Fix: after 5.5.0.91
Fix from $1,950 2008-10-31
Db2 HIGH 10.0
CVE-2008-4692

The Native Managed Provider for .NET component in IBM DB2 8 before FP17, 9.1 before FP6, and 9.5 before FP2, when a definer cannot maintain objects, …

Fix: after 9.5
Fix from $1,950 2008-10-22
Db2 MEDIUM 5.0
CVE-2008-4691

Unspecified vulnerability in the SQLNLS_UNPADDEDCHARLEN function in the New Compiler (aka Starburst derived compiler) component in the server in IBM …

Fix: after 9.1
Fix from $1,600 2008-10-22