Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.1 CVE-2016-5971 IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 allows remote authenticated users to read arbitrary files or … Security Privileged Identity Manager Virtual Appliance after 2.0.2 Fix from $1,9502016-09-26 MEDIUM 6.5 CVE-2016-5970 Directory traversal vulnerability in IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 allows remote authentica… Security Privileged Identity Manager Virtual Appliance after 2.0.2 Fix from $1,6002016-09-26 HIGH 8.8 CVE-2016-5963 IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 does not properly validate updates, which allows remote authe… Security Privileged Identity Manager Virtual Appliance Patch available Fix from $1,9502016-09-26 HIGH 7.5 CVE-2016-5957 IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 allows remote attackers to defeat cryptographic protection me… Security Privileged Identity Manager Virtual Appliance after 2.0.2 Fix from $1,9502016-09-26 MEDIUM 5.7 CVE-2016-5947 IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to conduct clickjacking atta… Tivoli Storage Productivity Center Patch available Fix from $1,6002016-09-26 MEDIUM 6.5 CVE-2016-5946 Directory traversal vulnerability in IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticat… Spectrum Control Patch available Fix from $1,6002016-09-26 MEDIUM 5.4 CVE-2016-5944 Cross-site scripting (XSS) vulnerability in the Web UI in IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allo… Spectrum Control Patch available Fix from $1,6002016-09-26 MEDIUM 5.4 CVE-2016-5943 IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to bypass intended access re… Spectrum Control Patch available Fix from $1,6002016-09-26 MEDIUM 6.8 CVE-2016-3040 IBM WebSphere Application Server (WAS) Liberty, as used in IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8, a… Security Privileged Identity Manager Virtual Appliance Patch available Fix from $1,6002016-09-26 HIGH 8.8 CVE-2016-3007 Cross-site request forgery (CSRF) vulnerability in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticate… Connections Patch available Fix from $1,9502016-09-26 MEDIUM 5.4 CVE-2016-3006 Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authe… Connections Patch available Fix from $1,6002016-09-26 MEDIUM 5.4 CVE-2016-3003 Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authe… Connections Patch available Fix from $1,6002016-09-26 MEDIUM 5.4 CVE-2016-3001 Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authe… Connections Patch available Fix from $1,6002016-09-26 MEDIUM 6.5 CVE-2016-2999 IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to obtain sensitive information via an unsp… Connections after 5.5.0.0 Fix from $1,6002016-09-26 MEDIUM 6.5 CVE-2016-5954 IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF30, 8.0.0 through 8.0.0.1 CF21, and 8.5.0 before… Websphere Portal Patch available Fix from $1,6002016-09-12 MEDIUM 5.5 CVE-2016-5927 IBM Tivoli Storage Manager for Space Management (aka Spectrum Protect for Space Management) 6.3.x before 6.3.2.6, 6.4.x before 6.4.3.3, and 7.1.x bef… Tivoli Storage Manager For Space Management Patch available Fix from $1,6002016-09-12 MEDIUM 5.4 CVE-2016-0331 Cross-site scripting (XSS) vulnerability in IBM Rational Team Concert 6.0.1 and 6.0.2 before 6.0.2 iFix2 and Rational Collaborative Lifecycle Managem… Rational Collaborative Lifecycle Management Patch available Fix from $1,6002016-09-12 HIGH 8.8 CVE-2016-5879 MQCLI on IBM MQ Appliance M2000 and M2001 devices allows local users to execute arbitrary shell commands via a crafted (1) Disaster Recovery or (2) H… Mq Appliance Firmware Mitigation only Fix from $1,9502016-09-02 MEDIUM 5.4 CVE-2016-3010 Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 before CR4, and 5.5 before CR1 allows… Connections Patch available Fix from $1,6002016-09-01 MEDIUM 5.4 CVE-2016-3008 Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 5.0 before CR4 and 5.5 before CR1 allows remote authenticated users to inje… Connections Patch available Fix from $1,6002016-09-01 MEDIUM 5.4 CVE-2016-3005 Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 before CR4, and 5.5 before CR1 allows… Connections Patch available Fix from $1,6002016-09-01 MEDIUM 5.4 CVE-2016-2997 Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 before CR4, and 5.5 before CR1 allows… Connections Patch available Fix from $1,6002016-09-01 MEDIUM 5.4 CVE-2016-2995 Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 before CR4, and 5.5 before CR1 allows… Connections Patch available Fix from $1,6002016-09-01 MEDIUM 5.4 CVE-2016-2956 Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 5.0 before CR4 and 5.5 before CR1 allows remote authenticated users to inje… Connections Patch available Fix from $1,6002016-09-01 MEDIUM 5.4 CVE-2016-2954 Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 5.0 before CR4 and 5.5 before CR1 allows remote authenticated users to inje… Connections Patch available Fix from $1,6002016-09-01 MEDIUM 6.1 CVE-2016-0293 Cross-site scripting (XSS) vulnerability in IBM BigFix Platform (formerly Tivoli Endpoint Manager) 9.x before 9.1.8 and 9.2.x before 9.2.8 allows rem… Bigfix Platform Mitigation only Fix from $1,6002016-09-01 MEDIUM 5.9 CVE-2016-0397 WebReports in IBM BigFix Platform (formerly Tivoli Endpoint Manager) 9.x before 9.5.2 allows remote attackers to obtain sensitive information by snif… Bigfix Webreports Mitigation only Fix from $1,6002016-08-30 MEDIUM 5.5 CVE-2016-0292 WebReports in IBM BigFix Platform (formerly Tivoli Endpoint Manager) 9.x before 9.5.2 allows local users to discover the cleartext system password by… Bigfix Mitigation only Fix from $1,6002016-08-30 MEDIUM 6.8 CVE-2016-5878 Open redirect vulnerability in IBM FileNet Workplace 4.0.2 before 4.0.2.14 allows remote authenticated users to redirect users to arbitrary web sites… Filenet Workplace Patch available Fix from $1,6002016-08-08 MEDIUM 6.2 CVE-2016-3059 IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server (aka IBM Spectrum Protect for Databases) 6.3 before 6.3.1.7 and 6.… Tivoli Storage Flashcopy Manager For Sql Server after 6.4.1.8 Fix from $1,6002016-08-08