Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2017-1720
IBM Notes 8.5 and 9.0 could allow a local attacker to execute arbitrary commands by carefully crafting a command line sent via the shared memory IPC.…
Notes
Patch available
MEDIUM 6.1
CVE-2017-1761
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code…
Websphere Portal
Patch available
MEDIUM 6.1
CVE-2018-1401
IBM WebSphere Portal 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…
Websphere Portal
Patch available
CRITICAL 9.8
CVE-2011-4889
The javax.naming.directory.AttributeInUseException class in the Virtual Member Manager in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.43,…
Websphere Application Server
6.1.0.43 / 7.0.0.21+
CRITICAL 9.8
CVE-2012-2166
IBM XIV Storage System 2810-A14 and 2812-A14 devices before level 10.2.4.e-2 and 2810-114 and 2812-114 devices before level 11.1.1 have hardcoded pas…
Xiv Storage System 2810 A14 Firmware
10.2.4.e-2 / 11.1.1+
MEDIUM 5.3
CVE-2012-3331
IBM Sametime allows remote attackers to obtain sensitive information from the Sametime Log database via a direct request to STLOG.NSF. IBM X-Force ID…
Sametime
Mitigation only
HIGH 7.8
CVE-2017-1692
IBM AIX 5.3, 6.1, 7.1, and 7.2 contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges. I…
Aix
Mitigation only
HIGH 7.8
CVE-2018-1366
IBM Content Navigator 2.0 and 3.0 is vulnerable to Comma Separated Value (CSV) Injection. An attacker could exploit this vulnerability to exploit oth…
Content Navigator
Patch available
HIGH 7.5
CVE-2018-1388
GSKit V7 may disclose side channel information via discrepancies between valid and invalid PKCS#1 padding. IBM X-Force ID: 138212.
Websphere Mq
Mitigation only
MEDIUM 5.4
CVE-2018-1382
IBM API Connect 5.0.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus …
Api Connect
after 5.0.6.4
HIGH 7.5
CVE-2016-0312
IBM TRIRIGA Application Platform before 3.3.2 allows remote attackers to obtain sensitive information via vectors related to granting unauthenticated…
Tririga Application Platform
after 3.3.1
MEDIUM 5.4
CVE-2016-0300
IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 might allow remote attackers to access arbitrary JSP …
Tririga Application Platform
Mitigation only
MEDIUM 5.4
CVE-2016-0303
Cross-site scripting (XSS) vulnerability in IBM Tivoli Integrated Portal 2.2.0.0 through 2.2.0.15 allows remote attackers to inject arbitrary web scr…
Tivoli Integrated Portal
after 2.2.0.15
MEDIUM 5.4
CVE-2016-0311
Cross-site scripting (XSS) vulnerability in IBM Tivoli Business Service Manager 6.1.0 before 6.1.0-TIV-BSM-FP0004 and 6.1.1 before 6.1.1-TIV-BSM-FP00…
Tivoli Business Service Manager
Mitigation only
MEDIUM 5.4
CVE-2016-0329
Open redirect vulnerability in IBM Emptoris Sourcing 10.0.0.x before 10.0.0.1_iFix3, 10.0.1.x before 10.0.1.3_iFix3, 10.0.2.x before 10.0.2.8_iFix1, …
Emptoris Sourcing
after 10.1.0.0
MEDIUM 5.4
CVE-2016-0342
IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote authenticated users to read or modify a…
Tririga Application Platform
3.3.2.6 / 3.4.2.3+
MEDIUM 6.7
CVE-2017-1233
IBM Remote Control v9 could allow a local user to use the component to replace files to which he does not have write access and which he can cause to…
Bigfix Remote Control
Patch available
HIGH 8.8
CVE-2017-1731
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could provide weaker than expected security when using the Administrative Console. An authent…
Websphere Application Server
after 9.0.0.6
HIGH 8.2
CVE-2018-1364
IBM Content Navigator 2.0 and 3.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exp…
Content Navigator
Mitigation only
HIGH 7.8
CVE-2017-1779
IBM Cognos Analytics 11.0 could store cached credentials locally that could be obtained by a local user. IBM X-Force ID: 136824.
Cognos Analytics
Patch available
MEDIUM 5.5
CVE-2017-1784
IBM Cognos Analytics 11.0 could produce results in temporary files that contain highly sensitive information that can be read by a local user. IBM X-…
Cognos Analytics
Patch available
CRITICAL 9.8
CVE-2017-1204
IBM Tealeaf Customer Experience 8.7, 8.8, and 9.0.2 contains hard-coded credentials. A remote attacker could exploit this vulnerability to gain acces…
Tealeaf Customer Experience
Patch available
HIGH 8.1
CVE-2016-2983
IBM Tealeaf Customer Experience 8.7, 8.8, and 9.0.2 could allow a remote attacker under unusual circumstances to read operational data or TLS session…
Tealeaf Customer Experience
Patch available
MEDIUM 6.8
CVE-2017-1545
IBM Doors Web Access 9.5 and 9.6 could allow an attacker with physical access to the system to log into the application using previously stored crede…
Engineering Requirements Management Doors
after 9.6.1.9
MEDIUM 6.5
CVE-2017-1279
IBM Tealeaf Customer Experience 8.7, 8.8, and 9.0.2 could allow a remote attacker to traverse directories on the system. An attacker could send a spe…
Tealeaf Customer Experience
Patch available
MEDIUM 6.1
CVE-2017-1506
IBM Cognos TM1 10.2 and 10.2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web U…
Cognos Tm1
Patch available
MEDIUM 5.4
CVE-2017-1516
IBM Doors Web Access 9.5 and 9.6 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicio…
Engineering Requirements Management Doors
after 9.6.1.9
MEDIUM 5.4
CVE-2017-1532
IBM DOORS 9.5 and 9.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus al…
Engineering Requirements Management Doors
after 9.6.1.9
MEDIUM 5.4
CVE-2017-1540
IBM Doors Web Access 9.5 and 9.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web…
Engineering Requirements Management Doors
after 9.6.1.9
MEDIUM 5.4
CVE-2017-1563
IBM Doors Web Access 9.5 and 9.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web…
Engineering Requirements Management Doors
after 9.6.1.9