MidnightBSD

Advisories for ibm

CVE-1999-0003 HIGH

Execute commands as root via buffer overflow in Tooltalk database server (rpc.ttdbserverd).

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
sgi irix 6.4
ibm aix 4.1.5
sgi irix 6.0
ibm aix 4.1
sun sunos -
sun sunos 4.1.3
hp hp-ux 10.03
tritreal ted_cde 4.3
sgi irix 6.3
ibm aix 4.1.4
sun sunos 5.5.1
ibm aix 4.1.1
sgi irix 5.2
sun sunos 5.0
sun sunos 5.2
hp hp-ux 10.01
sun sunos 5.3
ibm aix 4.2.1
sun sunos 5.5
hp hp-ux 11.00
sun solaris 2.6
ibm aix 4.1.3
ibm aix 4.3
sgi irix 6.2
sgi irix 6.1
ibm aix 4.1.2
hp hp-ux 10.02
sgi irix 5.3
ibm aix 4.2
sun sunos 5.1
sun sunos 5.4
CVE-1999-0009 HIGH

Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
sgi irix 6.0
sgi irix 3.3.2
sgi irix 3.2
sco open_desktop 5.0
sco open_desktop 3.0
caldera openlinux 1.0
sco unixware 7.0
sgi irix 4.0.1t
sgi irix 3.3.3
sgi irix 4.0.5a
data_general dg_ux 5.4_3.1
sgi irix 4.0.5h
sgi irix 4.0.5_ipr
sgi irix 5.0.1
sgi irix 4.0.2
sgi irix 4.0.5e
netbsd netbsd 1.3
netbsd netbsd 1.2.1
sgi irix 5.2
sgi irix 4.0.4t
netbsd netbsd 1.1
bsdi bsd_os 2.0
sgi irix 4.0.5
ibm aix 4.2.1
sun sunos 5.5
redhat linux 4.1
sgi irix 4.0
netbsd netbsd 1.2
data_general dg_ux 5.4_4.1
sun solaris 2.5.1
data_general dg_ux 5.4_3.0
ibm aix 4.1.3
sgi irix 4.0.5g
sgi irix 3.3
ibm aix 4.1.2
sgi irix 5.3
bsdi bsd_os 2.0.1
ibm aix 4.2
sgi irix 4.0.4b
sun sunos 5.4
ibm aix 4.1.5
nec asl_ux_4800 64
ibm aix 4.1
sun sunos -
isc bind 8.1.1
sgi irix 4.0.5f
sgi irix 5.1.1
redhat linux 4.0
netbsd netbsd 1.3.1
sun solaris 2.5
sgi irix 3.3.1
sgi irix 4.0.5d
isc bind 8.1
sgi irix 6.3
ibm aix 4.1.4
sgi irix 5.0
sun sunos 5.5.1
ibm aix 4.1.1
sgi irix 4.0.4
redhat linux 4.2
redhat linux 5.0
sun sunos 5.3
sgi irix 4.0.1
sgi irix 4.0.5_iop
sco unixware 2.1
sun solaris 2.6
netbsd netbsd 1.0
data_general dg_ux 5.4_4.11
bsdi bsd_os 2.1
ibm aix 4.3
sgi irix 6.2
sgi irix 6.1
sgi irix 5.1
sgi irix 4.0.3
isc bind 4.9.6
CVE-1999-0010 MEDIUM

Denial of Service vulnerability in BIND 8 Releases via maliciously formatted DNS messages.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
data_general dg_ux y2k_patchr4.11mu05
data_general dg_ux y2k_patchr4.20mu01
ibm aix 4.1
sco open_desktop 3.0
sco unixware 7.0
netbsd netbsd 1.3.1
data_general dg_ux y2k_patchr4.20mu02
nec asl_ux_4800 11
sco unix 3.2v4
nec asl_ux_4800 13
sun sunos 5.5.1
netbsd netbsd 1.3
sco openserver 5.0
redhat linux 4.2
redhat linux 5.0
sun sunos 5.3
isc bind 4.9
sun sunos 5.5
sco unixware 2.1
data_general dg_ux y2k_patchr4.20mu03
ibm aix 4.3
sun sunos 5.6
isc bind 8
ibm aix 4.2
data_general dg_ux y2k_patchr4.12mu03
sun sunos 5.4
CVE-1999-0011 HIGH

Denial of Service vulnerabilities in BIND 4.9 and BIND 8 Releases via CNAME record and zone transfer.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
134c704f-9b21-4f2e-91b3-4a467353bcc0 5.4 MEDIUM CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L 2.8 2.5

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,CWE-1067,

Products Affected

Vendor Product Version
data_general dg_ux y2k_patchr4.11mu05
data_general dg_ux y2k_patchr4.20mu01
ibm aix 4.1
sco open_desktop 3.0
sco unixware 7.0
netbsd netbsd 1.3.1
data_general dg_ux y2k_patchr4.20mu02
nec asl_ux_4800 11
sco unix 3.2v4
nec asl_ux_4800 13
sun sunos 5.5.1
netbsd netbsd 1.3
sco openserver 5.0
redhat linux 4.2
redhat linux 5.0
sun sunos 5.3
isc bind 4.9
sun sunos 5.5
sco unixware 2.1
data_general dg_ux y2k_patchr4.20mu03
ibm aix 4.3
sun sunos 5.6
isc bind 8
ibm aix 4.2
data_general dg_ux y2k_patchr4.12mu03
sun sunos 5.4
CVE-1999-0014 HIGH

Unauthorized privileged access or denial of service via dtappgather program in CDE.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
hp vvos 10.24
hp hp-ux 10.10
cde cde 1.2
cde cde 1.01_x86
ibm aix 4.1
hp hp-ux 11.00
cde cde 1.2_x86
cde cde 1.02_x86
hp hp-ux 10.20
ibm aix 4.3
cde cde 1.01
ibm aix 4.2
cde cde 1.02
CVE-1999-0017 HIGH

FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP client, aka FTP bounce.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
freebsd freebsd 1.1
ibm aix 4.1
sco open_desktop 3.0
freebsd freebsd 1.0
sco openserver 5.0.4
freebsd freebsd 2.1.0
siemens reliant_unix *
freebsd freebsd 2.1.7
sun sunos 5.5.1
netbsd netbsd 1.2.1
netbsd netbsd 1.1
freebsd freebsd 2.0
gnu inet 5.01
sun sunos 5.3
sun sunos 5.5
sco unixware 2.1
sun sunos 4.1.3u1
sun sunos 4.1.4
netbsd netbsd 1.0
netbsd netbsd 1.2
freebsd freebsd 1.2
gnu inet 6.01
ibm aix 4.3
washington_university wu-ftpd 2.4
gnu inet 6.02
ibm aix 3.2
ibm aix 4.2
caldera openlinux 1.2
sun sunos 5.4
CVE-1999-0018 HIGH

Buffer overflow in statd allows root privileges.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
sgi irix 5.2
ibm aix 4.1
sun sunos 5.5
sgi irix 5.1.1
sun solaris 2.5
sun solaris 2.5.1
sun solaris 2.4
sgi irix 5.0.1
sgi irix 5.3
ibm aix 3.2
sgi irix 5.1
sgi irix 5.0
sun sunos 5.5.1
sun sunos 5.4
CVE-1999-0019 MEDIUM

Delete or create a file via rpc.statd, due to invalid information.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
sco openserver 5.0
ncr mp-ras 3.0
sco unixware 2
sco open_desktop 3
sun sunos 5.3
ibm aix 4.1
sun sunos 5.5
data_general dg_ux 4.11
sun sunos 4.1.3
sco openserver 3.0
sun sunos 4.1.4
nighthawk cx_ux *
sco open_desktop 2
ncr mp-ras 2.03
sgi irix 6.1
ibm aix 3.2
nighthawk powerux *
sun sunos 5.4
CVE-1999-0022 HIGH

Local user gains root privileges via buffer overflow in rdist, via expstr() function.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
134c704f-9b21-4f2e-91b3-4a467353bcc0 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 1.8 5.9

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,CWE-125,

Products Affected

Vendor Product Version
sgi irix 6.4
ibm aix 4.1.5
sgi irix 6.0
ibm aix 4.1
ibm aix 3.2.5
sgi irix 5.1.1
freebsd freebsd 2.1.0
hp hp-ux 10.00
sgi irix 5.0.1
freebsd freebsd 2.0.5
sgi irix 6.3
ibm aix 4.1.4
sun solaris 4.1.3
sgi irix 5.0
ibm aix 4.1.1
ibm aix 3.2.4
sgi irix 5.2
sun sunos 5.0
sgi irix 6.0.1
ibm aix 3.1
freebsd freebsd 2.0
sun sunos 5.2
sun sunos 5.3
sun sunos 4.1.3u1
bsdi bsd_os 1.1
sun sunos 4.1.2
ibm aix 4.1.3
sgi irix 6.2
sgi irix 6.1
ibm aix 4.1.2
sgi irix 5.3
ibm aix 3.2
ibm aix 4.2
sun sunos 5.1
sgi irix 5.1
sun sunos 4.1.1
sun sunos 5.4
CVE-1999-0023 HIGH

Local user gains root privileges via buffer overflow in rdist, via lookup() function.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.1
sco open_desktop 3.0
sun sunos -
sco tcp_ip 1.2.0
sun sunos 4.1.3
sco internet_faststart 1.0
freebsd freebsd 2.1.0
freebsd freebsd 2.2
freebsd freebsd 2.0.5
sun sunos 5.5.1
sco open_desktop 2.0
sco openserver 5.0
freebsd freebsd 2.0
sun sunos 5.3
inet inet 6.01
sun sunos 5.5
sco unixware 2.1
sun sunos 4.1.3u1
sun sunos 4.1.4
sco openserver 2.0
inet inet 5.01
sco openserver 5.0.2
sco tcp_ip 1.2.1
ibm aix 3.2
ibm aix 4.2
sco unixware 2.0
bsdi bsd_os *
sun sunos 5.4
CVE-1999-0024 MEDIUM

DNS cache poisoning via BIND, by predictable query IDs.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
sco openserver 5.0
nec asl_ux_4800 64
sun sunos 5.3
ibm aix 4.1
sco open_desktop 3.0
sun sunos -
nec ews-ux_v 4.2mp
sun sunos 5.5
isc bind 4.9.5
sco unixware 2.1
sun solaris 2.6
bsdi bsd_os 3.0
sun solaris 2.5
sun solaris 2.5.1
nec ews-ux_v 4.2
nec up-ux_v 4.2mp
bsdi bsd_os 2.1
sun solaris 2.4
sco unix 3.2v4
isc bind 8.1
ibm aix 4.2
sun sunos 5.5.1
sun sunos 5.4
CVE-1999-0033 HIGH

Command execution in Sun systems via buffer overflow in the at program.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
sgi irix *
sco openserver 5.0
ibm aix *
ncr mp-ras 3.0
sun sunos 5.3
sco open_desktop 3.0
sun sunos 5.5
sco unixware 2.1
sco openserver 3.0
sco unixware 3.2v4
sun sunos 5.5.1
sun sunos 5.4
CVE-1999-0038 HIGH

Buffer overflow in xlock program allows local users to execute commands as root.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
134c704f-9b21-4f2e-91b3-4a467353bcc0 8.4 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 2.5 5.9

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,CWE-120,

Products Affected

Vendor Product Version
sgi irix 6.4
sgi irix 6.0
hp hp-ux 10.10
debian debian_linux 0.93
ibm aix 4.1
data_general dg_ux 7.0
debian debian_linux 1.3
sgi irix 5.1.1
hp hp-ux 10.34
data_general dg_ux 1.0
debian debian_linux 1.2
sun solaris 2.5
hp hp-ux 10.30
hp hp-ux 10.00
sgi irix 5.0.1
sgi irix 6.3
data_general dg_ux 4.0
sgi irix 5.0
sun sunos 5.5.1
sgi irix 5.2
sgi irix 6.0.1
hp hp-ux 10.16
hp hp-ux 10.01
sun sunos 5.3
hp hp-ux 10.24
data_general dg_ux 3.0
sun sunos 5.5
data_general dg_ux 6.0
debian debian_linux 1.1
sun solaris 2.5.1
bsdi bsd_os 2.1
sun solaris 2.4
data_general dg_ux 2.0
hp hp-ux 10.20
sgi irix 6.1
sgi irix 5.3
ibm aix 3.2
ibm aix 4.2
hp hp-ux 10.08
sgi irix 5.1
sun sunos 5.4
data_general dg_ux 5.0
CVE-1999-0040 HIGH

Buffer overflow in Xt library of X Windowing System allows local users to execute commands with root privileges.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
sgi irix 6.4
sgi irix 6.0
hp hp-ux 10.10
hp hp-ux 9.00
nec asl_ux_4800 64
ibm aix 4.1
nec ews-ux_v 4.2mp
sun sunos 4.1.3
hp hp-ux 10.34
sun solaris 2.5
hp hp-ux 10.30
hp hp-ux 10.00
sgi irix 6.3
sgi irix 5.0
sun sunos 5.5.1
bsdi bsd_os 2.0
hp hp-ux 10.16
freebsd freebsd 2.0
hp hp-ux 10.01
sun sunos 5.3
hp hp-ux 10.24
hp hp-ux 9.10
sun sunos 5.5
sgi irix 4.0
sun sunos 4.1.3u1
sun sunos 4.1.4
sun solaris 2.5.1
nec ews-ux_v 4.2
hp hp-ux 9.01
freebsd freebsd 1.1.5.1
nec up-ux_v 4.2mp
bsdi bsd_os 2.1
sun solaris 2.4
hp hp-ux 10.20
hp hp-ux 10.09
sgi irix 6.2
sgi irix 6.1
sgi irix 5.3
ibm aix 3.2
bsdi bsd_os 2.0.1
ibm aix 4.2
hp hp-ux 10.08
sun sunos 5.4
CVE-1999-0041 HIGH

Buffer overflow in NLS (Natural Language Service).

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.1
ibm aix 3.2.5
redhat linux 4.0
gnu libc 5.0.9
slackware slackware_linux 3.1
cray unicos 9.2
cray unicos 1.5
ibm aix 4.2
gnu libc 5.2.18
gnu libc 5.3.12
cray unicos 9.0
cray unicos_max 1.3
CVE-1999-0042 HIGH

Buffer overflow in University of Washington's implementation of IMAP and POP servers.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
bsdi bsd_os 2.1
redhat linux 2.0
ibm aix 4.2.1
university_of_washington pop 3
caldera openlinux 1.0
university_of_washington imap 4
redhat linux 4.0
bsdi bsd_os 3.0
CVE-1999-0046 HIGH

Buffer overflow of rlogin program using TERM environmental variable.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-120,

Products Affected

Vendor Product Version
ibm aix 4.1.5
oracle solaris 8
hp hp-ux 10.10
debian debian_linux 0.93
ibm aix 4.1
hp hp-ux 10.34
hp hp-ux 10.30
freebsd freebsd 2.1.0
hp hp-ux 10.00
oracle solaris 2.6
freebsd freebsd 2.0.5
ibm aix 4.1.4
sun sunos 5.5.1
ibm aix 4.1.1
digital ultrix -
oracle solaris -
netbsd netbsd 1.1
bsdi bsd_os 2.0
hp hp-ux 10.16
freebsd freebsd 2.0
hp hp-ux 10.01
sun sunos 5.3
hp hp-ux 10.24
sun sunos 5.5
sun sunos 4.1.3u1
sun sunos 4.1.4
netbsd netbsd 1.0
bsdi bsd_os 1.1
oracle solaris 7.0
freebsd freebsd 1.1.5.1
bsdi bsd_os 2.1
next nextstep -
ibm aix 4.1.3
hp hp-ux 10.20
hp hp-ux 10.09
ibm aix 4.1.2
ibm aix 3.2
bsdi bsd_os 2.0.1
hp hp-ux 10.08
freebsd freebsd 2.1.5
oracle solaris 2.5.1
sun sunos 5.4
CVE-1999-0048 HIGH

Talkd, when given corrupt DNS information, can be used to execute arbitrary commands with root privileges.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 3.1
ibm aix 4.1
nec up-ux_v *
ibm aix 4.2
nec ews-ux_v *
debian netkit 0.07
nec asl_ux_4800 *
CVE-1999-0055 HIGH

Buffer overflows in Sun libnsl allow root access.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
sun sunos 5.2
sun sunos 5.3
ibm aix 4.2.1
sun sunos -
sun sunos 5.5
sun solaris 2.6
sun solaris 2.5
sun solaris 2.5.1
ibm aix 4.3.1
ibm aix 4.3.2
sun solaris 2.4
ibm aix 4.3
ibm aix 4.2
sun sunos 5.5.1
sun sunos 5.4
CVE-1999-0057 HIGH

Vacation program allows command execution by remote users through a sendmail command.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
freebsd freebsd 6.2
hp hp-ux 9
sun sunos *
ibm aix *
sun solaris *
hp hp-ux 10.00
eric_allman vacation *
hp hp-ux 10.09
hp vvos *
hp hp-ux 10.24
CVE-1999-0064 HIGH

Buffer overflow in AIX lquerylv program gives root access to local users.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 3.2.4
ibm aix 4.1.5
ibm aix 4.1.3
ibm aix 4.1
ibm aix 4.1.2
ibm aix 3.2
ibm aix 4.2
ibm aix 4.1.4
ibm aix 3.2.5
ibm aix 4.1.1
CVE-1999-0072 HIGH

Buffer overflow in AIX xdat gives root access to local users.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.1.5
ibm aix 4.1.3
ibm aix 4.2.1
ibm aix 4.1
ibm aix 4.1.2
ibm aix 4.2
ibm aix 4.1.4
ibm aix 4.1.1
CVE-1999-0078 LOW

pcnfsd (aka rpc.pcnfsd) allows local users to change file permissions, or execute arbitrary commands through arguments in the RPC call.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
freebsd freebsd 6.2
ncr mp-ras 3.0
sun sunos 4.1
ibm aix 4.1
ncr mp-ras 3.01
sun sunos 5.5
next nextstep *
sco unixware 2.1
ncr mp-ras 2.03
sgi irix 5.3
nec up-ux_v *
sco openserver 5
ibm aix 3.2
ibm aix 4.2
hp hp-ux *
bsdi bsd_os *
sun sunos 5.4
CVE-1999-0085 HIGH

Buffer overflow in rwhod on AIX and other operating systems allows remote attackers to execute arbitrary code via a UDP packet with a long hostname.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
freebsd freebsd 6.2
ibm aix 4.2
netbsd netbsd 2.0.4
CVE-1999-0086 MEDIUM

AIX routed allows remote users to modify sensitive files.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.3
ibm aix 4.1
ibm aix 3.2
ibm aix 4.2
CVE-1999-0087 MEDIUM

Denial of service in AIX telnet can freeze a system and prevent users from accessing the server.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.3
ibm aix 4.1
ibm aix 4.2
CVE-1999-0088 HIGH

IRIX and AIX automountd services (autofsd) allow remote users to execute root commands.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.3
CVE-1999-0089 HIGH

Buffer overflow in AIX libDtSvc library can allow local users to gain root access.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.3
CVE-1999-0090 HIGH

Buffer overflow in AIX rcp command allows local users to obtain root access.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.1.5
ibm aix 4.1.3
ibm aix 4.1
ibm aix 4.2
ibm aix 4.1.4
ibm aix 4.1.1
CVE-1999-0091 HIGH

Buffer overflow in AIX writesrv command allows local users to obtain root access.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.1.5
ibm aix 4.1.3
ibm aix 4.2.1
ibm aix 4.1
ibm aix 4.1.2
ibm aix 4.2
ibm aix 4.1.4
ibm aix 4.1.1
CVE-1999-0092 HIGH

Various vulnerabilities in the AIX portmir command allows local users to obtain root access.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.2.1
CVE-1999-0093 HIGH

AIX nslookup command allows local users to obtain root access by not dropping privileges correctly.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.1.5
ibm aix 4.1.3
ibm aix 4.1
ibm aix 4.1.2
ibm aix 4.2
ibm aix 4.1.4
ibm aix 4.1.1
CVE-1999-0094 MEDIUM

AIX piodmgrsu command allows local users to gain additional group privileges.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.1.5
ibm aix 4.1.3
ibm aix 4.1
ibm aix 4.1.2
ibm aix 4.2
ibm aix 4.1.4
ibm aix 4.1.1
CVE-1999-0097 HIGH

The AIX FTP client can be forced to execute commands from a malicious server through shell metacharacters (e.g. a pipe character).

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.1.5
hp hp-ux 10.10
hp hp-ux 9.08
hp hp-ux 9.00
hp hp-ux 9.09
ibm aix 4.1
sun sunos -
ibm aix 3.2.5
sun solaris 2.5
hp hp-ux 9.07
hp hp-ux 10.00
hp hp-ux 9.04
ibm aix 4.1.4
sun sunos 5.5.1
ibm aix 4.1.1
ibm aix 3.2.4
hp hp-ux 10.16
sun sunos 5.3
hp hp-ux 9.05
hp hp-ux 10.24
ibm aix 4.2.1
hp hp-ux 9.10
sun sunos 5.5
hp hp-ux 9.06
hp hp-ux 11.00
sun solaris 2.6
sun sunos 4.1.3u1
sun sunos 4.1.4
sun solaris 2.5.1
hp hp-ux 9.01
sun solaris 2.4
ibm aix 4.1.3
hp hp-ux 9.03
hp hp-ux 10.20
ibm aix 4.1.2
sun sunos 4.1.3c
ibm aix 3.2
ibm aix 4.2
sun sunos 5.4
CVE-1999-0099 HIGH

Buffer overflow in syslog utility allows local or remote attackers to gain root privileges.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
bsdi bsd_os 2.0
convex convexos 10.1
cray unicos 8.3
sun sunos 5.3
ibm aix 4.1
convex convexos 10.2
convex convexos 11.1
sun sunos 4.1.3
sun sunos 4.1.3u1
sun sunos 4.1.4
cray unicos 8.0
convex spp-ux 3
sun solaris 2.4
ibm aix 3.2
bsdi bsd_os 2.0.1
convex convexos 11.0
cray unicos 9.0
sun sunos 5.4
CVE-1999-0101 HIGH

Buffer overflow in AIX and Solaris "gethostbyname" library call allows root access through corrupt DNS host names.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.1
ibm aix 3.2
ibm aix 4.2
CVE-1999-0111 MEDIUM

RIP v1 is susceptible to spoofing.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.3
ibm aix 4.1
ibm aix 3.2
ibm aix 4.2
CVE-1999-0112 HIGH

Buffer overflow in AIX dtterm program for the CDE.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
cde cde *
ibm aix 4.1
ibm aix 4.2
CVE-1999-0113 HIGH

Some implementations of rlogin allow root access if given a -froot parameter.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-88,

Products Affected

Vendor Product Version
ibm aix 3.2.4
ibm aix 3.1
ibm aix 3.2
ibm aix 3.2.5
CVE-1999-0115 HIGH

AIX bugfiler program allows local users to gain root access.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 3.2.4
ibm aix 3.1
ibm aix 3.2
ibm aix 3.2.5
CVE-1999-0116 MEDIUM

Denial of service when an attacker sends many SYN packets to create multiple connections without ever sending an ACK to complete the connection, aka SYN flood.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm sng 2.2
ibm sng 2.1
ibm aix 4.1
ibm aix 4.2
ibm aix 3.2.5
CVE-1999-0117 HIGH

AIX passwd allows local users to gain root access.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 3.1
ibm aix 3.2
CVE-1999-0118 HIGH

AIX infod allows local users to gain root access through an X display.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.3
ibm aix 4.1
ibm aix 3.2
ibm aix 4.2
CVE-1999-0122 HIGH

Buffer overflow in AIX lchangelv gives root access.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.1.5
ibm aix 4.1.3
ibm aix 4.1
ibm aix 4.1.2
ibm aix 4.2
ibm aix 4.1.4
ibm aix 4.1.1
CVE-1999-0128 MEDIUM

Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
sco openserver 5.0
ibm sng 2.2
digital osf_1 1.3.3
ibm aix 4.1
sco open_desktop 3.0
sun sunos 5.5
ibm sng *
sco internet_faststart 1.0
linux linux_kernel 1.3.0
sco openserver 5.0.2
sco tcp_ip 1.2.1
sco internet_faststart 1.1
ibm sng 2.1
ibm aix 3.2
ibm aix 4.2
sun sunos 5.5.1
linux linux_kernel 2.0
sun sunos 5.4
CVE-1999-0129 MEDIUM

Sendmail allows local users to write to a file and gain group permissions via a .forward or :include: file.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
hp hp-ux 10.10
eric_allman sendmail 8.8.1
eric_allman sendmail 8.8.2
ibm aix 4.1
sun solaris 2.5
sco internet_faststart 1.0
eric_allman sendmail 8.8
hp hp-ux 10.00
freebsd freebsd 2.1.6.1
sun sunos 5.5.1
sco openserver 5.0
hp hp-ux 10.16
hp hp-ux 10.01
sun sunos 5.3
sun sunos 5.5
sun sunos 4.1.3u1
sun sunos 4.1.4
sun solaris 2.5.1
bsdi bsd_os 2.1
eric_allman sendmail 8.8.3
sun solaris 2.4
hp hp-ux 10.20
sco openserver 5.0.2
freebsd freebsd 2.1.6
sco internet_faststart 1.1
ibm aix 3.2
ibm aix 4.2
freebsd freebsd 2.1.5
sun sunos 5.4
CVE-1999-0130 HIGH

Local users can start Sendmail in daemon mode and gain root privileges.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
eric_allman sendmail 8.7
hp hp-ux 10.10
eric_allman sendmail 8.8.1
eric_allman sendmail 8.8.2
hp hp-ux 10.01
caldera network_desktop 1.0
redhat linux 4.0
bsdi bsd_os 2.1
eric_allman sendmail 8.8
hp hp-ux 10.00
hp hp-ux 10.20
freebsd freebsd 2.1.6
ibm aix 4.2
freebsd freebsd 2.1.5
CVE-1999-0131 HIGH

Buffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root access to local users.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
sco openserver 5.0
hp hp-ux 10.10
eric_allman sendmail 8.7.1
hp hp-ux 10.01
ibm aix 4.1
eric_allman sendmail 8.7.4
eric_allman sendmail 8.7.5
eric_allman sendmail 8.7.3
bsdi bsd_os 2.1
sco internet_faststart 1.0
hp hp-ux 10.20
digital osf_1 1.3.2
sco openserver 5.0.2
eric_allman sendmail 8.6
ibm aix 3.2
ibm aix 4.2
eric_allman sendmail 8.7.2
freebsd freebsd 2.1.5
redhat linux 3.0.3
CVE-1999-0138 HIGH

The suidperl and sperl program do not give up root privileges when changing UIDs back to the original users, allowing root access.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
hp hp-ux 9
freebsd freebsd 2.0
ibm aix 4
linux linux_kernel 1.2.0
nec ews-ux_v 4.2mp
nec asl_ux_4800 *
ibm aix 3.2.5
hp hp-ux 10
nec ews-ux_v 4.2
nec up-ux_v 4.2mp
digital osf_1 1.3
freebsd freebsd 2.1.0
apple a_ux 3.1.1
hp hp-ux 8
freebsd freebsd 2.0.5
linux linux_kernel 2.0
CVE-1999-0208 HIGH

rpc.ypupdated (NIS) allows remote users to execute arbitrary commands.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
sgi irix 5.2
sgi irix 4
sgi irix 3
ibm aix 4.1
nec up-ux_v *
ibm aix 3.2
sgi irix 5.1
nec ews-ux_v *
sgi irix 5.0
nec asl_ux_4800 *
CVE-1999-0284 HIGH

Denial of service to NT mail servers including Ipswitch, Mdaemon, and Exchange through a buffer overflow in the SMTP HELO command.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-120,

Products Affected

Vendor Product Version
microsoft exchange_server 4.0
ibm lotus_domino_mail_server *
microsoft exchange_server 5.0
CVE-1999-0318 HIGH

Buffer overflow in xmcd 2.0p12 allows local users to gain access through an environmental variable.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
sun sunos 5.7
sun sunos 5.8
redhat linux 6.0
ibm aix 4
hp hp-ux 11
sun sunos 5.5.1
sun solaris 2.6
CVE-1999-0337 HIGH

AIX batch queue (bsh) allows local and remote users to gain additional privileges when network printing is enabled.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 1.3
ibm aix 3.1
ibm aix 3.2
ibm aix 2.2.1
ibm aix 1.2.1
CVE-1999-0338 HIGH

AIX Licensed Program Product performance tools allow local users to gain root access.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 3.2.4
ibm aix 3.2.5
CVE-1999-0345 MEDIUM

Jolt ICMP attack causes a denial of service in Windows 95 and Windows NT systems.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm sng 2.2
freebsd freebsd 2.0
sco open_desktop 3
freebsd freebsd 1.1
ibm aix 4.1
freebsd freebsd 1.0
freebsd freebsd 1.2
sun sunos *
freebsd freebsd 1.1.5.1
sco internet_faststart 1.0
sco internet_faststart 1.1
ibm sng 2.1
freebsd freebsd 2.0.5
sco openserver 5
ibm aix 3.2
ibm aix 4.2
CVE-1999-0429 HIGH

The Lotus Notes 4.5 client may send a copy of encrypted mail in the clear across the network if the user does not set the "Encrypt Saved Mail" preference.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_notes 4.5
CVE-1999-0513 MEDIUM

ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denial of service.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
freebsd freebsd 2.2.4
digital unix 4.0d
sun sunos -
ibm aix 3.2.5
linux linux_kernel 2.1
sun solaris 2.5
digital unix 4.0a
freebsd freebsd 2.2.2
digital unix 4.0c
freebsd freebsd 2.1.0
digital unix 4.0b
freebsd freebsd 2.0.5
sun sunos 5.5.1
linux linux_kernel 2.0
ibm aix 3.2.4
ibm aix 3.1
digital unix 4.0
sun sunos 5.5
hp hp-ux 11.00
digital unix 3.2g
freebsd freebsd 2.1.7.1
sun solaris 2.6
netbsd netbsd 1.2
sun solaris 2.5.1
freebsd freebsd 1.1.5.1
sun solaris 2.4
hp hp-ux 10.20
freebsd freebsd 2.2.3
freebsd freebsd 2.1.6
ibm aix 3.2
freebsd freebsd 2.1.5
sun sunos 5.4
CVE-1999-0524 LOW

ICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
134c704f-9b21-4f2e-91b3-4a467353bcc0 4.0 MEDIUM CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N 2.5 1.4

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,NVD-CWE-noinfo,CWE-200,

Products Affected

Vendor Product Version
ibm os2 -
apple mac_os_x -
linux linux_kernel -
novell netware -
ibm aix -
cisco ios -
windriver bsdos -
sgi irix -
apple macos -
sco sco_unix -
hp tru64 -
microsoft windows -
hp hp-ux -
oracle solaris -
CVE-1999-0566 MEDIUM

An attacker can write to syslog files from any location, causing a denial of service by filling up the logs, and hiding activities.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix *
CVE-1999-0627 LOW

The rexd service is running, which uses weak authentication that can allow an attacker to execute commands.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 3.1
ibm aix 3.2
CVE-1999-0628 MEDIUM

The rwho/rwhod service is running, which exposes machine status and user information.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
freebsd freebsd 6.2
ibm aix 4.2
linux linux_kernel 2.6.20.1
netbsd netbsd 2.0.4
CVE-1999-0687 HIGH

The ToolTalk ttsession daemon uses weak RPC authentication, which allows a remote attacker to execute commands.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
sun solaris 7.0
ibm aix 4.1.5
cde cde 1.2
cde cde 2.0
digital unix 4.0d
ibm aix 4.1
sun sunos -
cde cde 1.0.1
cde cde 1.1
sun solaris 2.5
sun sunos 5.7
ibm aix 4.1.4
sun sunos 5.5.1
cde cde 1.0.2
ibm aix 4.1.1
cde cde 2.1
sun sunos 5.3
ibm aix 4.2.1
sun sunos 5.5
sun solaris 2.6
sun sunos 4.1.3u1
sun sunos 4.1.4
sun solaris 2.5.1
ibm aix 4.3.1
ibm aix 4.3.2
sun solaris 2.4
ibm aix 4.1.3
digital unix 4.0f
ibm aix 4.3
ibm aix 4.1.2
cde cde 2.120
ibm aix 4.2
sun sunos 5.4
CVE-1999-0691 HIGH

Buffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root privileges via a long user name.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
sun solaris 7.0
ibm aix 4.1.5
cde cde 1.2
cde cde 2.0
digital unix 4.0d
ibm aix 4.1
cde cde 1.0.1
cde cde 1.1
sun sunos 5.7
ibm aix 4.1.4
sun sunos 5.5.1
cde cde 1.0.2
ibm aix 4.1.1
digital unix 4.0e
cde cde 2.1
ibm aix 4.2.1
sun sunos 5.5
sun solaris 2.6
sun solaris 2.5.1
ibm aix 4.3.1
ibm aix 4.3.2
sun solaris 2.4
ibm aix 4.1.3
digital unix 4.0f
ibm aix 4.3
ibm aix 4.1.2
ibm aix 4.2
sun sunos 5.4
CVE-1999-0693 HIGH

Buffer overflow in TT_SESSION environment variable in ToolTalk shared library allows local users to gain root privileges.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
hp hp-ux 10
ibm aix 4
hp hp-ux 11
sco unixware 7
CVE-1999-0694 LOW

Denial of service in AIX ptrace system call allows local users to crash the system.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.3
ibm aix 4.2
CVE-1999-0718 MEDIUM

IBM GINA, when used for OS/2 domain authentication of Windows NT users, allows local users to gain administrator privileges by changing the GroupMapping registry key.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm gina 1.0
CVE-1999-0729 MEDIUM

Buffer overflow in Lotus Notes LDAP (NLDAP) allows an attacker to conduct a denial of service through the ldap_search request.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_domino_server 4.6
CVE-1999-0745 HIGH

Buffer overflow in Source Code Browser Program Database Name Server Daemon (pdnsd) for the IBM AIX C Set ++ compiler.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 3.2.4
ibm aix 3.1
ibm aix 3.2
ibm aix 2.2.1
ibm aix 3.2.5
CVE-1999-0789 HIGH

Buffer overflow in AIX ftpd in the libc library.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.3.1
ibm aix 4.3.2
ibm aix 4.3
CVE-1999-0803 LOW

The fwluser script in AIX eNetwork Firewall allows local users to write to arbitrary files via a symlink attack.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix_enetwork_firewall 3.2
ibm aix_enetwork_firewall 3.3
CVE-1999-0835 HIGH

Denial of service in BIND named via malformed SIG records.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
sun sunos 5.7
sco unixware 2
ibm aix 4.3
sco unixware 7
sco openserver 5
CVE-1999-0851 LOW

Denial of service in BIND named via naptr.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
sun sunos 5.7
sco unixware 2
ibm aix 4.3
sco unixware 7
sco openserver 5
CVE-1999-0852 HIGH

IBM WebSphere sets permissions that allow a local user to modify a deinstallation script or its data files stored in /usr/bin.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_application_server 3.0
CVE-1999-0903 HIGH

genfilt in the AIX Packet Filtering Module does not properly filter traffic to destination ports greater than 32767.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.3.2
CVE-1999-1013 HIGH

named-xfer in AIX 4.1.5 and 4.2.1 allows members of the system group to overwrite system files to gain root access via the -f parameter and a malformed zone file.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.1.5
ibm aix 4.2.1
CVE-1999-1075 MEDIUM

inetd in AIX 4.1.5 dynamically assigns a port N when starting ttdbserver (ToolTalk server), but also inadvertently listens on port N-1 without passing control to ttdbserver, which allows remote attackers to cause a denial of service via a large number of connections to port N-1, which are not properly closed by inetd.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.1.5
CVE-1999-1079 MEDIUM

Vulnerability in ptrace in AIX 4.3 allows local users to gain privileges by attaching to a setgid program.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.1.5
ibm aix 4.3.2
ibm aix 4.1.3
ibm aix 4.3
ibm aix 4.2.1
ibm aix 4.1
ibm aix 4.1.2
ibm aix 4.2
ibm aix 4.1.4
ibm aix 3.2.5
ibm aix 4.1.1
CVE-1999-1117 LOW

lquerypv in AIX 4.1 and 4.2 allows local users to read arbitrary files by specifying the file in the -h command line parameter.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.1
ibm aix 4.2
CVE-1999-1119 HIGH

FTP installation script anon.ftp in AIX insecurely configures anonymous FTP, which allows remote attackers to execute arbitrary commands.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix *
CVE-1999-1121 HIGH

The default configuration for UUCP in AIX before 3.2 allows local users to gain root privileges.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix *
CVE-1999-1208 HIGH

Buffer overflow in ping in AIX 4.2 and earlier allows local users to gain root privileges via a long command line argument.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.1
ibm aix 4.2
ibm aix 3.2.5
CVE-1999-1275 MEDIUM

Lotus cc:Mail release 8 stores the postoffice password in plaintext in a hidden file which has insecure permissions, which allows local users to gain privileges.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_cc_mail 8.0
CVE-1999-1403 HIGH

IBM/Tivoli OPC Tracker Agent version 2 release 1 creates files, directories, and IPC message queues with insecure permissions (world-readable and world-writable), which could allow local users to disrupt operations and possibly gain privileges by modifying or deleting files.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm tivoli_opc_tracker_agent 3.0x
ibm tivoli_opc_tracker_agent 2.0x
ibm tivoli_opc_tracker_agent 1.0x
CVE-1999-1404 MEDIUM

IBM/Tivoli OPC Tracker Agent version 2 release 1 allows remote attackers to cause a denial of service (resource exhaustion) via malformed data to the localtracker client port (5011), which prevents the connection from being closed properly.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm tivoli_opc_tracker_agent 3.0x
ibm tivoli_opc_tracker_agent 2.0x
ibm tivoli_opc_tracker_agent 1.0x
CVE-1999-1405 HIGH

snap command in AIX before 4.3.2 creates the /tmp/ibmsupt directory with world-readable permissions and does not remove or clear the directory when snap -a is executed, which could allow local users to access the shadowed password file by creating /tmp/ibmsupt/general/passwd before root runs snap -a.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.1.5
ibm aix 4.1.3
ibm aix 4.2.1
ibm aix 4.1
ibm aix 4.1.2
ibm aix 4.2
ibm aix 4.1.4
ibm aix 3.2.5
CVE-1999-1408 LOW

Vulnerability in AIX 4.1.4 and HP-UX 10.01 and 9.05 allows local users to cause a denial of service (crash) by using a socket to connect to a port on the localhost, calling shutdown to clear the socket, then using the same socket to connect to a different port on localhost.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.1.5
ibm aix 4.1.3
hp hp-ux 10.01
hp hp-ux 10.20
hp hp-ux 9.05
ibm aix 4.1
ibm aix 4.1.2
ibm aix 4.1.4
ibm aix 4.1.1
CVE-1999-1414 HIGH

IBM Netfinity Remote Control allows local users to gain administrator privileges by starting programs from the process manager, which runs with system level privileges.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm netfinity_remote_control *
CVE-1999-1480 LOW

(1) acledit and (2) aclput in AIX 4.3 allow local users to create or modify files via a symlink attack.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.3
CVE-1999-1486 LOW

sadc in IBM AIX 4.1 through 4.3, when called from programs such as timex that are setgid adm, allows local users to overwrite arbitrary files via a symlink attack.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.1.5
ibm aix 4.1.3
ibm aix 4.3
ibm aix 4.2.1
ibm aix 4.1
ibm aix 4.1.2
ibm aix 4.2
ibm aix 4.1.4
ibm aix 4.1.1
CVE-1999-1487 HIGH

Vulnerability in digest in AIX 4.3 allows printq users to gain root privileges by creating and/or modifing any file on the system.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.1.5
ibm aix 4.1.3
ibm aix 4.3
ibm aix 4.2.1
ibm aix 4.1
ibm aix 4.1.2
ibm aix 4.2
ibm aix 4.1.4
ibm aix 4.1.1
CVE-1999-1488 MEDIUM

sdrd daemon in IBM SP2 System Data Repository (SDR) allows remote attackers to read files without authentication.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm system_data_repository sp_2.0
CVE-1999-1531 HIGH

Buffer overflow in IBM HomePagePrint 1.0.7 for Windows98J allows a malicious Web site to execute arbitrary code on a viewer's system via a long IMG_SRC HTML tag.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm homepageprint 1.0.7
CVE-1999-1546 MEDIUM

netstation.navio-com.rte 1.1.0.1 configuration script for Navio NC on IBM AIX exports /tmp over NFS as world-readable and world-writable.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm navio_nc_browser 1.1.0.1
CVE-1999-1552 HIGH

dpsexec (DPS Server) when running under XDM in IBM AIX 3.2.5 and earlier does not properly check privileges, which allows local users to overwrite arbitrary files and gain privileges.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 3.2.4
ibm aix *
ibm aix 3.1
ibm aix 3.2
CVE-1999-1574 HIGH

Buffer overflow in the lex routines of nslookup for AIX 4.3 may allow attackers to cause a core dump and possibly execute arbitrary code via "long input strings."

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.3.0
CVE-1999-1583 HIGH

Buffer overflow in nslookup for AIX 4.3 allows local users to execute arbitrary code via a long hostname command line argument.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.3
CVE-1999-1589 HIGH

Unspecified vulnerability in crontab in IBM AIX 3.2 allows local users to gain root privileges via unknown attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm aix 1.3
ibm aix 3.1
ibm aix 3.2
ibm aix 2.2.1
ibm aix 1.2.1
CVE-2000-0027 MEDIUM

IBM Network Station Manager NetStation allows local users to gain privileges via a symlink attack.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm network_station_manager 2.0r1
CVE-2000-0080 LOW

AIX techlibss allows local users to overwrite files via a symlink attack.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.3.2
CVE-2000-0249 HIGH

The AIX Fast Response Cache Accelerator (FRCA) allows local users to modify arbitrary files via the configuration capability in the frcactrl program.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.3.1
ibm aix 4.3.2
ibm aix 4.3
CVE-2000-0441 MEDIUM

Vulnerability in AIX 3.2.x and 4.x allows local users to gain write access to files on locally or remotely mounted AIX filesystems.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 3.2.4
ibm aix 4.1.5
ibm aix 4.2.1
ibm aix 4.1
ibm aix 3.2.5
ibm aix 4.3.1
ibm aix 4.3.2
ibm aix 4.1.3
ibm aix 4.3
ibm aix 4.1.2
ibm aix 3.2
ibm aix 4.2
ibm aix 4.1.4
ibm aix 4.1.1
CVE-2000-0466 HIGH

AIX cdmount allows local users to gain root privileges via shell metacharacters.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.3.1
ibm aix 4.3.2
ibm aix 4.3
CVE-2000-0497 MEDIUM

IBM WebSphere server 3.0.2 allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 3.9 3.6

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-178,

Products Affected

Vendor Product Version
ibm websphere_application_server 3.0.2
CVE-2000-0505 MEDIUM

The Apache 1.3.x HTTP server for Windows platforms allows remote attackers to list directory contents by requesting a URL containing a large number of / characters.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm http_server 1.3.3
apache http_server 1.3.9
ibm http_server 1.3.6.2
apache http_server 1.3.12
apache http_server 1.3.6
apache http_server 1.3.11
CVE-2000-0652 MEDIUM

IBM WebSphere allows remote attackers to read source code for executable web files by directly calling the default InvokerServlet using a URL which contains the "/servlet/file" string.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_application_server 3.0
ibm websphere_application_server 2.0
ibm websphere_application_server 3.0.21
CVE-2000-0677 HIGH

Buffer overflow in IBM Net.Data db2www CGI program allows remote attackers to execute arbitrary commands via a long PATH_INFO environmental variable.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm net.data *
CVE-2000-0761 MEDIUM

OS2/Warp 4.5 FTP server allows remote attackers to cause a denial of service via a long username.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm os2_ftp_server 4.2
ibm os2_ftp_server 4.3
ibm os2_ftp_server 4.0
CVE-2000-0844 HIGH

Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
debian debian_linux 2.2
redhat linux 5.1
sgi irix 6.5.3f
trustix secure_linux 1.1
turbolinux turbolinux 6.0.4
mandrakesoft mandrake_linux 7.0
suse suse_linux 6.3
ibm aix 3.2.5
suse suse_linux 7.0
sun sunos 5.7
debian debian_linux 2.3
turbolinux turbolinux 6.0.2
caldera openlinux_ebuilder 3.0
caldera openlinux_eserver 2.3
sgi irix 6.5.6
trustix secure_linux 1.0
turbolinux turbolinux 6.0.1
ibm aix 3.2.4
sgi irix 6.5
sgi irix 6.5.3
mandrakesoft mandrake_linux 7.1
turbolinux turbolinux 6.0
redhat linux 5.2
ibm aix 4.2.1
redhat linux 6.1
conectiva linux 4.2
sun sunos 5.5
sgi irix 6.5.7
debian debian_linux 2.0
sgi irix 6.5.8
conectiva linux 5.1
sun sunos 5.8
ibm aix 4.1.3
ibm aix 4.1.2
ibm aix 3.2
ibm aix 4.2
sun sunos 5.1
immunix immunix 6.2
sgi irix 6.5.2m
sun sunos 5.4
caldera openlinux *
sgi irix 6.4
ibm aix 4.1.5
suse suse_linux 6.2
slackware slackware_linux 7.0
redhat linux 6.0
conectiva linux 4.0es
slackware slackware_linux 7.1
ibm aix 4.1
sgi irix 6.5.1
suse suse_linux 6.4
turbolinux turbolinux 6.0.3
conectiva linux 4.1
sgi irix 6.5.4
conectiva linux 4.0
sgi irix 6.5.3m
sgi irix 6.3
ibm aix 4.1.4
sun sunos 5.5.1
ibm aix 4.1.1
sun sunos 5.0
redhat linux 5.0
sun sunos 5.2
redhat linux 6.2
sun sunos 5.3
suse suse_linux 6.1
sun solaris 2.6
debian debian_linux 2.1
ibm aix 4.3.1
ibm aix 4.3.2
conectiva linux 5.0
ibm aix 4.0
ibm aix 4.3
sgi irix 6.2
CVE-2000-0848 HIGH

Buffer overflow in IBM WebSphere web application server (WAS) allows remote attackers to execute arbitrary commands via a long Host: request header.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_application_server 3.0.2
CVE-2000-0873 LOW

netstat in AIX 4.x.x does not properly restrict access to the -Zi option, which allows local users to clear network interface statistics and possibly hide evidence of unusual network activities.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.3.1
ibm aix 4.3.2
ibm aix 4.3
ibm aix 4.2.1
ibm aix 4.2
CVE-2000-0891 HIGH

A default ECL in Lotus Notes before 5.02 allows remote attackers to execute arbitrary commands by attaching a malicious program in an email message that is automatically executed when the user opens the email.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_notes *
CVE-2000-1038 MEDIUM

The web administration interface for IBM AS/400 Firewall allows remote attackers to cause a denial of service via an empty GET request.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm as400_firewall r440
CVE-2000-1110 MEDIUM

document.d2w CGI program in the IBM Net.Data db2www package allows remote attackers to determine the physical path of the web server by sending a nonexistent command to the program.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm net.data 7.0
CVE-2000-1117 MEDIUM

The Extended Control List (ECL) feature of the Java Virtual Machine (JVM) in Lotus Notes Client R5 allows malicious web site operators to determine the existence of files on the client by measuring delays in the execution of the getSystemResource method.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-203,

Products Affected

Vendor Product Version
ibm lotus_notes r5
CVE-2000-1119 MEDIUM

Buffer overflow in setsenv command in IBM AIX 4.3.x and earlier allows local users to execute arbitrary commands via a long "x=" argument.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.3.1
ibm aix 4.3.2
ibm aix 4.3.3
ibm aix 4.3
ibm aix 4.2.1
ibm aix 4.2
CVE-2000-1120 HIGH

Buffer overflow in digest command in IBM AIX 4.3.x and earlier allows local users to execute arbitrary commands.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.3.1
ibm aix 4.3.2
ibm aix 4.3.3
ibm aix 4.3
ibm aix 4.2.1
ibm aix 4.2
CVE-2000-1121 HIGH

Buffer overflow in enq command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands via a long -M argument.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.3.1
ibm aix 4.3.2
ibm aix 4.3.3
ibm aix 4.3
ibm aix 4.2.1
ibm aix 4.2
CVE-2000-1122 HIGH

Buffer overflow in setclock command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands via a long argument.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.3.1
ibm aix 4.3.2
ibm aix 4.3.3
ibm aix 4.3
ibm aix 4.2.1
ibm aix 4.2
CVE-2000-1123 HIGH

Buffer overflow in pioout command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.3.1
ibm aix 4.3.2
ibm aix 4.3.3
ibm aix 4.3
CVE-2000-1124 HIGH

Buffer overflow in piobe command in IBM AIX 4.3.x allows local users to gain privileges via long environmental variables.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.3.1
ibm aix 4.3.2
ibm aix 4.3.3
ibm aix 4.3
CVE-2000-1138 HIGH

Lotus Notes R5 client R5.0.5 and earlier does not properly warn users when an S/MIME email message has been modified, which could allow an attacker to modify the email in transit without being detected.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_notes *
ibm lotus_notes 5.0
ibm lotus_notes 5.0.4
ibm lotus_notes 5.0.3
ibm lotus_notes 5.0.1
ibm lotus_notes 5.0.2
CVE-2000-1168 HIGH

IBM HTTP Server 1.3.6 (based on Apache) allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long GET request.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm http_server 1.3.6.3
CVE-2000-1202 HIGH

ikeyman in IBM IBMHSSSB 1.0 sets the CLASSPATH environmental variable to include the user's own CLASSPATH directories before the system's directories, which allows a malicious local user to execute arbitrary code as root via a Trojan horse Ikeyman class.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm http_server_ssl_module_common 1.0
CVE-2000-1215 MEDIUM

The default configuration of Lotus Domino server 5.0.8 includes system information (version, operating system, and build date) in the HTTP headers of replies, which allows remote attackers to obtain sensitive information.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_domino 5.0.8
CVE-2000-1216 HIGH

Buffer overflow in portmir for AIX 4.3.0 allows local users to corrupt lock files and gain root privileges via the echo_error routine.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-120,

Products Affected

Vendor Product Version
ibm aix 4.3.0
CVE-2000-1222 HIGH

AIX sysback before 4.2.1.13 uses a relative path to find and execute the hostname program, which allows local users to gain privileges by modifying the path to point to a malicious hostname program.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix *
CVE-2000-1239 HIGH

The HTTP interface of Tivoli Lightweight Client Framework (LCF) in IBM Tivoli Management Framework 3.7.1 sets http_disable to zero at install time, which allows remote authenticated users to bypass file permissions on Tivoli Endpoint Configuration data files via an unspecified manipulation of log files.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm tivoli_management_framework 3.7.1
CVE-2001-0051 HIGH

IBM DB2 Universal Database version 6.1 creates an account with a default user name and password, which allows remote attackers to gain access to the database.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm db2_universal_database 6.1
CVE-2001-0052 LOW

IBM DB2 Universal Database version 6.1 allows users to cause a denial of service via a malformed query.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm db2_universal_database 6.1
ibm db2_universal_database 7.1
CVE-2001-0122 MEDIUM

Kernel leak in AfpaCache module of the Fast Response Cache Accelerator (FRCA) component of IBM HTTP Server 1.3.x and Websphere 3.52 allows remote attackers to cause a denial of service via a series of malformed HTTP requests that generate a "bad request" error.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_application_server 3.52
ibm http_server 1.3.12.2
CVE-2001-0312 MEDIUM

IBM WebSphere plugin for Netscape Enterprise server allows remote attackers to read source code for JSP files via an HTTP request that contains a host header that references a host that is not in WebSphere's host aliases list, which will bypass WebSphere processing.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_plugin *
CVE-2001-0319 HIGH

orderdspc.d2w macro in IBM Net.Commerce 3.x allows remote attackers to execute arbitrary SQL queries by inserting them into the order_rn option of the report capability.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm net.commerce 3.2
ibm websphere_commerce_suite 3.2
ibm net.commerce 3.1
ibm net.commerce 3.1.2
ibm net.commerce 3.1.1
ibm net.commerce_hosting_server 3.2
ibm net.commerce_hosting_server 3.1.2
ibm websphere_commerce_suite 3.1.2
ibm net.commerce 3.0
ibm net.commerce 2.0
ibm websphere_commerce_suite 4.1
ibm net.commerce_hosting_server 3.1.1
ibm websphere_commerce_suite 4.1.1
CVE-2001-0389 MEDIUM

IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to determine the real path of the server by directly calling the macro.d2w macro with a NOEXISTINGHTMLBLOCK argument.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm net.commerce 3.1.2
ibm websphere_application_server 5.1.0.3
CVE-2001-0390 MEDIUM

IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to cause a denial of service by directly calling the macro.d2w macro with a long string of %0a characters.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm net.commerce 3.1
ibm net.commerce 3.1.2
ibm net.commerce 3.1.1
ibm net.commerce 3.0
ibm net.commerce 2.0
ibm websphere_application_server 5.1.0.3
ibm net.commerce_hosting_server 3.1.1
ibm net.commerce_hosting_server 3.1.2
CVE-2001-0446 MEDIUM

IBM WCS (WebSphere Commerce Suite) 4.0.1 with Application Server 3.0.2 allows remote attackers to read source code for .jsp files by appending a / to the requested URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_commerce_suite 4.0.1
CVE-2001-0472 MEDIUM

Hursley Software Laboratories Consumer Transaction Framework (HSLCTF) HTTP object allows remote attackers to cause a denial of service (crash) via an extremely long HTTP request.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm high_availability_cluster_multiprocessing 1.0
CVE-2001-0487 MEDIUM

AIX SNMP server snmpd allows remote attackers to cause a denial of service via a RST during the TCP connection.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix_snmp *
CVE-2001-0533 HIGH

Buffer overflow in libi18n library in IBM AIX 5.1 and 4.3.x allows local users to gain root privileges via a long LANG environmental variable.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.1
ibm aix 4.3
CVE-2001-0552 HIGH

ovactiond in HP OpenView Network Node Manager (NNM) 6.1 and Tivoli Netview 5.x and 6.x allows remote attackers to execute arbitrary commands via shell metacharacters in a certain SNMP trap message.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
hp openview_network_node_manager 5.01
hp openview_network_node_manager 6.1
ibm tivoli_netview 6.0
ibm tivoli_netview 5.0
CVE-2001-0554 HIGH

Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by the telrcv function.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-120,

Products Affected

Vendor Product Version
debian debian_linux 2.2
netbsd netbsd 1.4.1
netbsd netbsd 1.4.3
ibm aix 4.3.3
freebsd freebsd 2.2.4
mit kerberos_5 1.2.1
freebsd freebsd 4.3
openbsd openbsd 2.3
sun sunos 5.7
freebsd freebsd 2.2.2
openbsd openbsd 2.5
netkit linux_netkit 0.11
freebsd freebsd 2.1.6.1
freebsd freebsd 2.0.5
mit kerberos 1.0
openbsd openbsd 2.0
netbsd netbsd 1.3
freebsd freebsd 4.2
netbsd netbsd 1.2.1
sgi irix 6.5
netbsd netbsd 1.1
mit kerberos_5 1.1.1
ibm aix 5.1
freebsd freebsd 2.2.1
netbsd netbsd 1.5.1
openbsd openbsd 2.1
freebsd freebsd 4.0
sun sunos 5.5
openbsd openbsd 2.6
netbsd netbsd 1.5
freebsd freebsd 2.2.5
netbsd netbsd 1.2
sun sunos 5.8
openbsd openbsd 2.8
openbsd openbsd 2.2
freebsd freebsd 2.2.3
openbsd openbsd 2.7
freebsd freebsd 2.1.6
freebsd freebsd 4.1
freebsd freebsd 4.1.1
freebsd freebsd 3.1
freebsd freebsd 2.0.1
sun sunos 5.1
freebsd freebsd 3.5.1
sun sunos 5.4
mit kerberos_5 1.2.2
netbsd netbsd 1.3.2
mit kerberos_5 1.2
freebsd freebsd 3.2
netkit linux_netkit 0.12
freebsd freebsd 2.2.6
netbsd netbsd 1.3.1
netkit linux_netkit 0.10
freebsd freebsd 2.2.8
freebsd freebsd 2.1.0
freebsd freebsd 3.5
freebsd freebsd 2.2
freebsd freebsd 2.1.7
freebsd freebsd 3.0
freebsd freebsd 3.4
sun sunos 5.5.1
freebsd freebsd 2.2.7
sun sunos 5.0
freebsd freebsd 2.0
netbsd netbsd 1.3.3
sun sunos 5.2
sun sunos 5.3
freebsd freebsd 3.3
netbsd netbsd 1.4.2
freebsd freebsd 2.1.7.1
sun solaris 2.6
netbsd netbsd 1.0
openbsd openbsd 2.4
ibm aix 4.3.1
freebsd freebsd 2.1
ibm aix 4.3.2
netbsd netbsd 1.4
mit kerberos_5 1.1
ibm aix 4.3
freebsd freebsd 2.1.5
CVE-2001-0573 MEDIUM

lsfs in AIX 4.x allows a local user to gain additional privileges by creating Trojan horse programs named (1) grep or (2) lslv in a certain directory that is under the user's control, which cause lsfs to access the programs in that directory.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4
CVE-2001-0671 HIGH

Buffer overflows in (1) send_status, (2) kill_print, and (3) chk_fhost in lpd in AIX 4.3 and 5.1 allow remote attackers to gain root privileges.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.1
ibm aix 4.3
CVE-2001-0797 HIGH

Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large number of arguments through services such as telnet and rlogin.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
sun solaris 7.0
hp hp-ux 10.10
sgi irix 3.3.2
ibm aix 4.3.3
hp hp-ux 11.11
sgi irix 3.2
sun sunos -
sco openserver 5.0.6
sgi irix 3.3.3
sco openserver 5.0.5
sun solaris 2.5
sun sunos 5.7
sco openserver 5.0.4
hp hp-ux 11.0.4
hp hp-ux 10.00
sgi irix 3.3.1
sco openserver 5.0.3
sun sunos 5.5.1
sun sunos 5.0
sco openserver 5.0
ibm aix 5.1
sun sunos 5.2
hp hp-ux 10.01
sun sunos 5.3
sco openserver 5.0.1
hp hp-ux 10.24
sco openserver 5.0.6a
sun sunos 5.5
hp hp-ux 11.00
sun solaris 2.6
sun solaris 8.0
sun solaris 2.5.1
ibm aix 4.3.1
ibm aix 4.3.2
sun sunos 5.8
sun solaris 2.4
hp hp-ux 10.20
ibm aix 4.3
sco openserver 5.0.2
sgi irix 3.3
sun sunos 5.1
sun sunos 5.4
CVE-2001-0824 HIGH

Cross-site scripting vulnerability in IBM WebSphere 3.02 and 3.5 FP2 allows remote attackers to execute Javascript by inserting the Javascript into (1) a request for a .JSP file, or (2) a request to the webapp/examples/ directory, which inserts the Javascript into an error page.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_application_server 3.0.2
ibm websphere_application_server 3.5
CVE-2001-0856 MEDIUM

Common Cryptographic Architecture (CCA) in IBM 4758 allows an attacker with physical access to the system and Combine_Key_Parts permissions, to steal DES and 3DES keys by using a brute force attack to create a 3DES exporter key.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm 4758 *
CVE-2001-0924 MEDIUM

Directory traversal vulnerability in ifx CGI program in Informix Web DataBlade allows remote attackers to read arbitrary files via a .. (dot dot) in the LO parameter.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm informix_web_datablade 3.7
ibm informix_web_datablade 3.6
ibm informix_web_datablade 4.12
ibm informix_web_datablade 4.10
ibm informix_web_datablade 4.11
ibm informix_web_datablade 3.3
ibm informix_web_datablade 3.4
ibm informix_web_datablade 3.5
CVE-2001-0962 HIGH

IBM WebSphere Application Server 3.02 through 3.53 uses predictable session IDs for cookies, which allows remote attackers to gain privileges of WebSphere users via brute force guessing.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_commerce_suite 3.1.2
ibm websphere_commerce_suite 3.2
ibm websphere_application_server *
CVE-2001-0982 MEDIUM

Directory traversal vulnerability in IBM Tivoli WebSEAL Policy Director 3.01 through 3.7.1 allows remote attackers to read arbitrary files or directories via encoded .. (dot dot) sequences containing "%2e" strings.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm tivoli_secureway_policy_director 3.7
ibm tivoli_secureway_policy_director 3.7.1
ibm tivoli_secureway_policy_director 3.0.1
ibm tivoli_secureway_policy_director 3.6
CVE-2001-0998 MEDIUM

IBM HACMP 4.4 allows remote attackers to cause a denial of service via a completed TCP connection to HACMP ports (e.g., using a port scan) that does not send additional data, which causes a failure in snmpd.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.1
ibm aix 4.3.3
ibm aix 4.3
ibm hacmp 4.4
CVE-2001-1061 HIGH

Vulnerability in lsmcode in unknown versions of AIX, possibly related to a usage error.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix *
CVE-2001-1079 LOW

create_keyfiles in PSSP 3.2 with DCE 3.1 authentication on AIX creates keyfile directories with world-writable permissions, which could allow a local user to delete key files and cause a denial of service.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 3.2.0
CVE-2001-1080 HIGH

diagrpt in AIX 4.3.x and 5.1 uses the DIAGDATADIR environment variable to find and execute certain programs, which allows local users to gain privileges by modifying the variable to point to a Trojan horse program.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.1
ibm aix 4.3
CVE-2001-1095 MEDIUM

Buffer overflow in uuq in AIX 4 could allow local users to execute arbitrary code via a long -r parameter.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.0
CVE-2001-1096 MEDIUM

Buffer overflows in muxatmd in AIX 4 allows an attacker to cause a core dump and possibly execute code.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.0
CVE-2001-1143 MEDIUM

IBM DB2 7.0 allows a remote attacker to cause a denial of service (crash) via a single byte to (1) db2ccs.exe on port 6790, or (2) db2jds.exe on port 6789.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm db2_universal_database 7.0
CVE-2001-1189 MEDIUM

IBM Websphere Application Server 3.5.3 and earlier stores a password in cleartext in the sas.server.props file, which allows local users to obtain the passwords via a JSP script.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_application_server 3.0.2.4
ibm websphere_application_server 3.5.2
ibm websphere_application_server 3.0.2
ibm websphere_application_server 3.0
ibm websphere_application_server 3.5
ibm websphere_application_server 3.5.3
ibm websphere_application_server 3.5.1
ibm websphere_application_server 3.0.2.2
ibm websphere_application_server 3.0.2.3
ibm websphere_application_server 3.0.2.1
CVE-2001-1191 MEDIUM

WebSeal in IBM Tivoli SecureWay Policy Director 3.8 allows remote attackers to cause a denial of service (crash) via a URL that ends in %2e.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm tivoli_secureway_policy_director 3.8
CVE-2001-1265 HIGH

Directory traversal vulnerability in IBM alphaWorks Java TFTP server 1.21 allows remote attackers to conduct unauthorized operations on arbitrary files via a .. (dot dot) attack.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm alphaworks_tftp_server 1.21
CVE-2001-1309 HIGH

Buffer overflows in IBM SecureWay 3.2.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm secureway_directory 3.2.1
CVE-2001-1310 HIGH

IBM SecureWay 3.2.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, via invalid encodings for the L field of a BER encoding, as demonstrated by the PROTOS LDAPv3 test suite.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm secureway_directory 3.2.1
CVE-2001-1311 HIGH

Buffer overflows in Lotus Domino R5 before R5.0.7a allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_domino_r5 *
CVE-2001-1312 HIGH

Format string vulnerabilities in Lotus Domino R5 before R5.0.7a allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_domino_r5 *
CVE-2001-1313 HIGH

Lotus Domino R5 before R5.0.7a allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via miscellaneous packets with semi-valid BER encodings, as demonstrated by the PROTOS LDAPv3 test suite.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_domino_r5 *
CVE-2001-1329 HIGH

Buffer overflow in rsh on AIX 4.2.0.0 may allow local users to gain root privileges via a long command line argument.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.2.0
CVE-2001-1330 HIGH

Buffer overflow in rsh on AIX 4.2.0.0 may allow local users to gain root privileges via a long command line argument.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.2.0
CVE-2001-1440 HIGH

Unknown vulnerability in login for AIX 5.1L, when using loadable authentication modules, allows remote attackers to gain access to the system.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.1l
CVE-2001-1441 MEDIUM

Cross-site scripting (XSS) vulnerability in VisualAge for Java 3.5 Professional allows remote attackers to execute JavaScript on other clients via the URL, which injects the script in the resulting error message.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm visualage_for_java 3.5
CVE-2001-1504 HIGH

Lotus Notes R5 Client 4.6 allows remote attackers to execute arbitrary commands via a Lotus Notes object with code in an event, which is automatically executed when the user processes the e-mail message.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_notes 4.6
ibm lotus_notes 5.0
CVE-2001-1529 HIGH

Buffer overflow in rpc.yppasswdd (yppasswd server) in AIX allows attackers to gain unauthorized access via a long string. NOTE: due to lack of details in the vendor advisory, it is not clear if this is the same issue as CVE-2001-0779.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix *
CVE-2001-1554 MEDIUM

IBM AIX 430 does not properly unlock IPPMTU_LOCK, which allows remote attackers to cause a denial of service (hang) via Path Maximum Transmit Unit (PMTU) IP packets.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 430
CVE-2001-1557 HIGH

Buffer overflow in ftpd in IBM AIX 4.3 and 5.1 allows attackers to gain privileges.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.1
ibm aix 4.3
CVE-2001-1567 MEDIUM

Lotus Domino server 5.0.9a and earlier allows remote attackers to bypass security restrictions and view Notes database files and possibly sensitive Notes template files (.ntf) via an HTTP request with a large number of "+" characters before the .nsf file extension, which are converted to spaces by Domino.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_domino 5.0.2
ibm lotus_domino 5.0.7
ibm lotus_domino 5.0.7a
ibm lotus_domino 5.0.5
ibm lotus_domino 5.0.8
ibm lotus_domino 5.0.1
ibm lotus_domino 5.0.9
ibm lotus_domino 5.0.4
ibm lotus_domino 5.0
ibm lotus_domino 5.0.3
ibm lotus_domino 5.0.6
ibm lotus_domino_server *
CVE-2002-0037 HIGH

Lotus Domino Servers 5.x, 4.6x, and 4.5x allows attackers to bypass the intended Reader and Author access list for a document's object via a Notes API call (NSFDbReadObject) that directly accesses the object.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_domino_server 4.6
ibm lotus_domino_server 5
ibm lotus_domino_server 4.5
CVE-2002-0086 HIGH

Buffer overflow in bindsock in Lotus Domino 5.0.4 and 5.0.7 on Linux allows local users to gain root privileges via a long (1) Notes_ExecDirectory or (2) PATH environment variable.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_domino 5.0.7
ibm lotus_domino 5.0.4
CVE-2002-0370 HIGH

Buffer overflow in the ZIP capability for multiple products allows remote attackers to cause a denial of service or execute arbitrary code via ZIP files containing entries with long filenames, including (1) Microsoft Windows 98 with Plus! Pack, (2) Windows XP, (3) Windows ME, (4) Lotus Notes R4 through R6 (pre-gold), (5) Verity KeyView, and (6) Stuffit Expander before 7.0.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_notes 5.0.9a
microsoft windows_98_plus_pack *
winzip winzip 7.0
ibm lotus_notes 5.0.1
ibm lotus_notes r5
microsoft windows_xp *
ibm lotus_notes r6
ibm lotus_notes *
ibm lotus_notes 5.0
allume_systems_division stuffit_expander 6.5.2
ibm lotus_notes 5.0.11
ibm lotus_notes 5.0.4
verity keyview_viewing_sdk gold
ibm lotus_notes 5.0.3
ibm lotus_notes 5.0.5
ibm lotus_notes 5.0.10
microsoft windows_me *
ibm lotus_notes 5.0.2
CVE-2002-0541 HIGH

Buffer overflow in Tivoli Storage Manager TSM (1) Server or Storage Agents 3.1 through 5.1, and (2) the TSM Client Acceptor Service 4.2 and 5.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request to port 1580 or port 1581.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager 4.2.1
ibm tivoli_storage_manager 4.2
CVE-2002-0554 HIGH

webdriver in IBM Informix Web DataBlade 4.12 allows remote attackers to bypass user access levels or read arbitrary files via a SQL injection attack in an HTTP request.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm informix_web_datablade 4.12
ibm informix_web_datablade 4.10
ibm informix_web_datablade 4.11
CVE-2002-0555 HIGH

IBM Informix Web DataBlade 4.12 unescapes user input even if an application has escaped it, which could allow remote attackers to execute SQL code in a web form even when the developer has attempted to escape it.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm informix_web_datablade 4.12
ibm informix_web_datablade 4.10
ibm informix_web_datablade 4.11
ibm informix_web_datablade 4.13
CVE-2002-0677 HIGH

CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
sgi irix 6.4
sgi irix 6.0
hp hp-ux 10.10
sgi irix 6.5.15
ibm aix 4.3.3
hp hp-ux 11.11
caldera unixware 7.1_.0
sgi irix 6.5.2
xi_graphics dextop 2.1
sgi irix 6.5.1
caldera unixware 7
sun sunos 5.7
caldera openunix 8.0
caldera unixware 7.1.1
sgi irix 6.5.4
sgi irix 6.3
sgi irix 6.5.12
sgi irix 6.5.6
compaq tru64 4.0g
compaq tru64 5.1a
sun sunos 5.5.1
sgi irix 5.2
sgi irix 6.5
sgi irix 6.5.3
sgi irix 6.5.10
sgi irix 6.0.1
sgi irix 6.5.5
sgi irix 6.5.14
ibm aix 5.1
sgi irix 6.5.16
hp hp-ux 10.24
hp hp-ux 11.00
sgi irix 6.5.7
compaq tru64 5.1
compaq tru64 5.0a
sun solaris 2.6
compaq tru64 4.0f
sgi irix 6.5.8
sun sunos 5.8
sgi irix 6.5.11
sgi irix 6.5.13
hp hp-ux 10.20
sgi irix 6.2
sgi irix 6.1
sgi irix 5.3
sgi irix 6.5.9
CVE-2002-0678 HIGH

CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
sgi irix 6.4
caldera unixware 7.1.0
sgi irix 6.0
hp hp-ux 10.10
sgi irix 6.5.15
ibm aix 4.3.3
hp hp-ux 11.11
sgi irix 6.5.2
xi_graphics dextop 2.1
sgi irix 6.5.1
sun sunos 5.7
caldera openunix 8.0
caldera unixware 7.1.1
sgi irix 6.5.4
sgi irix 6.3
sgi irix 6.5.12
sgi irix 6.5.6
compaq tru64 4.0g
compaq tru64 5.1a
sun sunos 5.5.1
sgi irix 5.2
sgi irix 6.5
sgi irix 6.5.3
sgi irix 6.5.10
sgi irix 6.0.1
sgi irix 6.5.5
sgi irix 6.5.14
ibm aix 5.1
caldera unixware 7.0
sgi irix 6.5.16
hp hp-ux 10.24
hp hp-ux 11.00
sgi irix 6.5.7
compaq tru64 5.1
compaq tru64 5.0a
sun solaris 2.6
compaq tru64 4.0f
sgi irix 6.5.8
sun sunos 5.8
sgi irix 6.5.11
sgi irix 6.5.13
hp hp-ux 10.20
sgi irix 6.2
sgi irix 6.1
sgi irix 5.3
sgi irix 6.5.9
sun solaris 9.0
CVE-2002-0679 HIGH

Buffer overflow in Common Desktop Environment (CDE) ToolTalk RPC database server (rpc.ttdbserverd) allows remote attackers to execute arbitrary code via an argument to the _TT_CREATE_FILE procedure.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
caldera unixware 7.1.0
hp hp-ux 10.10
ibm aix 5.1
caldera unixware 7.0
ibm aix 4.3.3
hp hp-ux 11.11
hp hp-ux 10.24
xi_graphics dextop 2.1
hp hp-ux 11.00
compaq tru64 5.1
compaq tru64 5.0a
sun solaris 2.6
compaq tru64 4.0f
sun sunos 5.7
caldera openunix 8.0
sun sunos 5.8
caldera unixware 7.1.1
hp hp-ux 10.20
compaq tru64 4.0g
compaq tru64 5.1a
sun sunos 5.5.1
sun solaris 9.0
CVE-2002-0742 HIGH

Buffer overflow in pioout on AIX 4.3.3.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.3.3
CVE-2002-0743 HIGH

mail and mailx in AIX 4.3.3 core dump when called with a very long argument, an indication of a buffer overflow.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.3.3
CVE-2002-0744 HIGH

namerslv in AIX 4.3.3 core dumps when called with a very long argument, possibly as a result of a buffer overflow.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.3.3
CVE-2002-0745 HIGH

Buffer overflow in uucp in AIX 4.3.3.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.3.3
CVE-2002-0746 HIGH

Vulnerability in template.dhcpo in AIX 4.3.3 related to an insecure linker argument.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.3.3
CVE-2002-0747 HIGH

Buffer overflow in lsmcode in AIX 4.3.3.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.3.3
CVE-2002-0790 LOW

clchkspuser and clpasswdremote in AIX expose an encrypted password in the cspoc.log file, which could allow local users to gain privileges.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix *
CVE-2002-0905 HIGH

Buffer overflow in sqlexec for Informix SE-7.25 allows local users to gain root privileges via a long INFORMIXDIR environment variable.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm informix 7.25_.uc3_se
ibm informix 7.25_.uc2_se
ibm informix 7.25_.uc1_se
CVE-2002-1011 HIGH

Buffer overflow in web server for Tivoli Management Framework (TMF) Endpoint 3.6.x through 3.7.1, before Fixpack 2, allows remote attackers to cause a denial of service or execute arbitrary code via a long HTTP GET request.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm tivoli_management_framework 3.6
ibm tivoli_management_framework 3.7.1
ibm tivoli_management_framework 3.6.1
ibm tivoli_management_framework 3.7
CVE-2002-1012 HIGH

Buffer overflow in web server for Tivoli Management Framework (TMF) ManagedNode 3.6.x through 3.7.1 allows remote attackers to cause a denial of service or execute arbitrary code via a long HTTP GET request.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm tivoli_management_framework 3.6
ibm tivoli_management_framework 3.7.1
ibm tivoli_management_framework 3.6.1
ibm tivoli_management_framework 3.7
CVE-2002-1040 MEDIUM

Unknown vulnerability in the WebSecure (DFSWeb) configuration utilities in AIX 4.x, possibly related to relative pathnames.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix *
CVE-2002-1041 MEDIUM

Unknown vulnerability in DCE (1) SMIT panels and (2) configuration commands, possibly related to relative pathnames.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix *
CVE-2002-1153 MEDIUM

IBM Websphere 4.0.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP request with long HTTP headers, such as "Host".

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_application_server 4.0.3
CVE-2002-1167 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to execute script as other users via an HTTP GET request.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_caching_proxy_server 4.0
ibm websphere_caching_proxy_server 3.6
CVE-2002-1168 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to execute script as other users via an HTTP request that contains an Location: header with a "%0a%0d" (CRLF) sequence, which echoes the Location as an HTTP header in the server response.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_caching_proxy_server 4.0
ibm websphere_caching_proxy_server 3.6
CVE-2002-1169 MEDIUM

IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to cause a denial of service (crash) via an HTTP request to helpout.exe with a missing HTTP version number, which causes ibmproxy.exe to crash.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_caching_proxy_server 4.0
ibm websphere_caching_proxy_server 3.6
CVE-2002-1201 MEDIUM

IBM AIX 4.3.3 and AIX 5 allows remote attackers to cause a denial of service (CPU consumption or crash) via a flood of malformed TCP packets without any flags set, which prevents AIX from releasing the associated memory buffers.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5
ibm aix 4.3.3
CVE-2002-1203 MEDIUM

IBM SecureWay Firewall before 4.2.2 performs extra processing before determining that a packet is invalid and dropping it, which allows remote attackers to cause a denial of service (resource exhaustion) via a flood of malformed TCP packets without any flags set.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm secureway_firewall 4.2
ibm secureway_firewall 4.2.1
CVE-2002-1450 MEDIUM

IBM UniVerse with UV/ODBC allows attackers to cause a denial of service (client crash or server CPU consumption) via a query with an invalid link between tables, possibly via a buffer overflow.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm u2_universe *
CVE-2002-1468 HIGH

Buffer overflow in errpt in AIX 4.3.3 allows local users to execute arbitrary code as root.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.3.3
CVE-2002-1548 HIGH

Unknown vulnerability in autofs on AIX 4.3.0, when using executable maps, allows attackers to execute arbitrary commands as root, possibly related to "string handling around how the executable map is called."

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.3.0
CVE-2002-1550 MEDIUM

dump_smutil.sh in IBM AIX allows local users to overwrite arbitrary files via a symlink attack on temporary files.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix *
CVE-2002-1551 MEDIUM

Buffer overflow in nslookup in IBM AIX may allow attackers to cause a denial of service or execute arbitrary code.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix *
CVE-2002-1583 HIGH

Buffer overflow in sqllib/security/db2ckpw for IBM DB2 Universal Database 6.0 and 7.0 allows local users to execute arbitrary code via a long username that is read from a file descriptor argument.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm db2_universal_database 7.2
ibm db2_universal_database 8.2
ibm db2_universal_database 7.1
ibm db2_universal_database 6.0
ibm db2_universal_database 7.0
CVE-2002-1619 MEDIUM

Buffer overflow in the FC client for IBM AIX 4.3.x allows remote attackers to cause a denial of service (crash and core dump).

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.3.1
ibm aix 4.3.2
ibm aix 4.3.3
ibm aix 4.3
CVE-2002-1620 MEDIUM

Unknown vulnerability in IBM AIX Parallel Systems Support Programs (PSSP) 3.1.1, 3.2, and 3.4 allows remote attackers to read arbitrary files from a file collection.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix_parallel_systems_support_programs 3.4
ibm aix_parallel_systems_support_programs 3.2
ibm aix_parallel_systems_support_programs 3.1.1
CVE-2002-1621 HIGH

Buffer overflow in the file_comp function in rcp for IBM AIX 4.3.x and 5.1 allows remote attackers to execute arbitrary code.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.3.1
ibm aix 4.3.2
ibm aix 5.1
ibm aix 4.3.3
ibm aix 4.3
CVE-2002-1622 HIGH

Buffer overflow in certain RPC routines in IBM AIX 4.3 may allow attackers to execute arbitrary code, related to a "variable data type."

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.3
CVE-2002-1624 MEDIUM

Buffer overflow in Lotus Domino web server before R5.0.10, when logging to DOMLOG.NSF, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP Authenticate header containing certain non-ASCII characters.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_domino 5.0.2
ibm lotus_domino 5.0.7
ibm lotus_domino 5.0.7a
ibm lotus_domino 5.0.5
ibm lotus_domino 5.0.9a
ibm lotus_domino 5.0.8
ibm lotus_domino 5.0.4a
ibm lotus_domino 5.0.1
ibm lotus_domino 5.0.6a
ibm lotus_domino 5.0.9
ibm lotus_domino 5.0.4
ibm lotus_domino 5.0
ibm lotus_domino 5.0.3
ibm lotus_domino 5.0.6
CVE-2002-1686 HIGH

Buffer overflow in lscfg of unknown versions of AIX has unknown impact.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix *
CVE-2002-1687 LOW

Buffer overflow in the diagnostics library in AIX allows local users to "cause data and instructions to be overwritten" via a long DIAGNOSTICS environment variable.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix *
CVE-2002-1689 HIGH

Unknown vulnerability in the login program on AIX before 4.0 could allow remote users to specify 100 or more environment variables when logging on, which exceeds the length of a certain string, possibly triggering a buffer overflow.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 3.2.5
CVE-2002-1690 HIGH

Unknown vulnerability in AIX before 4.0 with unknown attack vectors and unknown impact, aka "security issue," as fixed by APAR IY28225.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 3.2.5
CVE-2002-1731 LOW

The System Request menu in IBM AS/400 allows local users to list valid user accounts by viewing the object names that are type USRPRF.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm os_400 v4r2
ibm os_400 v4r3
ibm os_400 v4r5
ibm os_400 v5r1
ibm os_400 v4r4
CVE-2002-1822 MEDIUM

IBM HTTP Server 1.0 on AS/400 allows remote attackers to obtain the path to the web root directory and other sensitive information, which is leaked in an error mesage when a request is made for a non-existent Java Server Page (JSP).

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm http_server 1.0
CVE-2002-2014 MEDIUM

Lotus Domino 5.0.8 web server returns different error messages when a valid or invalid user is provided in HTTP requests, which allows remote attackers to determine valid user names and makes it easier to conduct brute force attacks.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_domino 5.0.8
CVE-2002-2025 MEDIUM

Lotus Domino server 5.0.9a and earlier allows remote attackers to cause a denial of service by exhausting the number of working threads via a large number of HTTP requests for (1) an MS-DOS device name and (2) an MS-DOS device name with a large number of characters appended to the device name.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_domino_server 5.0.2
ibm lotus_domino_server 4.6.1
ibm lotus_domino_server 5.0.8
ibm lotus_domino_server 5.0.1
ibm lotus_domino_server 5.0.4
ibm lotus_domino_server 5.0.5
ibm lotus_domino_server 5.0.9
ibm lotus_domino_server 4.6.3
ibm lotus_domino_server 5.0
ibm lotus_domino_server 4.6.4
ibm lotus_domino_server 5.0.7a
ibm lotus_domino_server 5.0.6
ibm lotus_domino_server 5.0.3
ibm lotus_domino_server 5.0.7
CVE-2002-2372 MEDIUM

The telnet server in Infoprint 21 running controller software before 1.056007 allows remote attackers to cause a denial of service (crash) via a long username, possibly due to a buffer overflow.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm infoprint_21 1.047012
CVE-2003-0028 HIGH

Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
openbsd openbsd 3.2
openafs openafs 1.0.3
mit kerberos_5 1.2.1
freebsd freebsd 4.3
openafs openafs 1.2.4
openafs openafs 1.2.3
openbsd openbsd 2.5
sgi irix 6.5.16m
sgi irix 6.5.15f
cray unicos 6.1
openbsd openbsd 2.0
sgi irix 6.5.13f
freebsd freebsd 4.2
sgi irix 6.5.11f
sgi irix 6.5
openafs openafs 1.2.2a
ibm aix 5.1
openbsd openbsd 2.1
freebsd freebsd 4.0
freebsd freebsd 4.5
sgi irix 6.5.7
sgi irix 6.5.7f
sgi irix 6.5.8
openafs openafs 1.1.1a
gnu glibc 2.1
hp hp-ux_series_800 10.20
sun sunos 5.8
openafs openafs 1.0.4
hp hp-ux 10.20
openbsd openbsd 2.7
cray unicos 9.0.2.5
freebsd freebsd 4.1
freebsd freebsd 4.1.1
sgi irix 6.5.4m
cray unicos 6.0e
sun solaris 7.0
mit kerberos_5 1.2.2
sgi irix 6.5.5m
sgi irix 6.5.15
gnu glibc 2.2.1
sgi irix 6.5.19
openafs openafs 1.2
sgi irix 6.5.2
sgi irix 6.5.1
sgi irix 6.5.12m
openafs openafs 1.2.2
mit kerberos_5 1.2.3
cray unicos 7.0
gnu glibc 2.2.4
mit kerberos_5 1.2.5
cray unicos 9.2
sgi irix 6.5.17
gnu glibc 2.3.1
sun sunos 5.5.1
sgi irix 6.5.15m
mit kerberos_5 1.2.7
sgi irix 6.5.16
openafs openafs 1.0.4a
hp hp-ux 10.24
sgi irix 6.5.17f
sun solaris 2.6
openafs openafs 1.2.6
hp hp-ux_series_700 10.20
openafs openafs 1.0.2
freebsd freebsd 4.6.2
gnu glibc 2.3
openafs openafs 1.2.2b
cray unicos 6.0
mit kerberos_5 1.2.6
sgi irix 6.5.3f
ibm aix 4.3.3
hp hp-ux 11.11
sgi irix 6.5.20
freebsd freebsd 4.4
openbsd openbsd 3.0
cray unicos 8.3
gnu glibc 2.3.2
gnu glibc 2.1.2
sgi irix 6.5.9m
sgi irix 6.5.14m
gnu glibc 2.2
openbsd openbsd 2.3
sun sunos 5.7
sgi irix 6.5.16f
gnu glibc 2.2.5
cray unicos 9.2.4
openafs openafs 1.2.1
sgi irix 6.5.6
sgi irix 6.5.3
openbsd openbsd 2.9
openafs openafs 1.2.5
gnu glibc 2.1.3
ibm aix 5.2
hp hp-ux 11.00
openbsd openbsd 2.6
sgi irix 6.5.6f
sun solaris 8.0
sgi irix 6.5.9f
sun solaris 2.5.1
sgi irix 6.5.2f
sgi irix 6.5.13
openbsd openbsd 2.8
mit kerberos_5 1.2.4
openbsd openbsd 2.2
openafs openafs 1.0.1
openafs openafs 1.1
sgi irix 6.5.9
gnu glibc 2.2.3
sgi irix 6.5.2m
hp hp-ux 11.04
openafs openafs 1.3
sun solaris 9.0
sgi irix 6.5.18
sgi irix 6.5.4f
hp hp-ux 11.22
openafs openafs 1.3.1
mit kerberos_5 1.2
hp hp-ux 11.20
gnu glibc 2.2.2
sgi irix 6.5.18f
sun sunos -
sgi irix 6.5.10m
freebsd freebsd 4.7
cray unicos 8.0
openafs openafs 1.3.2
sgi irix 6.5.4
sgi irix 6.5.3m
freebsd freebsd 5.0
sgi irix 6.5.8f
sgi irix 6.5.12
openafs openafs 1.1.1
openafs openafs 1.0
sgi irix 6.5.7m
sgi irix 6.5.10
sgi irix 6.5.5
sgi irix 6.5.11m
sgi irix 6.5.6m
sgi irix 6.5.14
openbsd openbsd 3.1
sgi irix 6.5.14f
sgi irix 6.5.12f
sgi irix 6.5.13m
openbsd openbsd 2.4
sgi irix 6.5.11
sgi irix 6.5.8m
sgi irix 6.5.10f
sgi irix 6.5.17m
cray unicos 9.0
sgi irix 6.5.5f
freebsd freebsd 4.6
sgi irix 6.5.18m
gnu glibc 2.1.1
CVE-2003-0064 HIGH

The dtterm terminal emulator allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
sgi irix 6.5.3f
sgi irix 6.0
ibm aix 4.3.3
hp hp-ux 11.11
sgi irix 6.5.9m
hp hp-ux 10.34
sgi irix 6.5.14m
sun sunos 5.7
sgi irix 6.5.16f
sgi irix 5.0.1
sgi irix 6.5.16m
sgi irix 6.5.15f
sgi irix 6.5.6
sgi irix 6.5.13f
sgi irix 6.5.11f
sgi irix 5.2
sgi irix 6.5
sgi irix 6.5.3
ibm aix 5.1
ibm aix 5.2
hp hp-ux 11.00
sgi irix 6.5.7
sgi irix 6.5.7f
sgi irix 6.5.6f
sun solaris 8.0
sgi irix 6.5.9f
sun solaris 2.5.1
sgi irix 6.5.8
sgi irix 6.5.2f
sun sunos 5.8
sgi irix 6.5.13
hp hp-ux 10.20
sgi irix 5.3
sgi irix 6.5.4m
sgi irix 6.5.9
sgi irix 6.5.2m
hp hp-ux 11.04
sun solaris 9.0
sgi irix 6.5.18
sun solaris 7.0
sgi irix 6.4
sgi irix 6.5.4f
sgi irix 6.5.5m
sgi irix 6.5.15
hp hp-ux 11.22
hp hp-ux 11.20
sgi irix 6.5.18f
sgi irix 6.5.2
sgi irix 6.5.1
sun sunos -
sgi irix 6.5.12m
sgi irix 6.5.10m
sgi irix 5.1.1
hp hp-ux 10.30
hp hp-ux 10.26
sgi irix 6.5.4
sgi irix 6.5.3m
sgi irix 6.5.8f
sgi irix 6.3
sgi irix 6.5.12
sgi irix 6.5.17
sgi irix 5.0
sun sunos 5.5.1
sgi irix 6.5.7m
sgi irix 6.5.15m
sgi irix 6.5.10
sgi irix 6.0.1
sgi irix 6.5.5
sgi irix 6.5.11m
sgi irix 6.5.6m
sgi irix 6.5.14
sgi irix 6.5.16
hp hp-ux 10.24
sgi irix 6.5.17f
sgi irix 6.5.14f
sgi irix 6.5.12f
sgi irix 6.5.13m
sun solaris 2.6
ibm aix 4.3.1
ibm aix 4.3.2
sgi irix 6.5.11
sgi irix 6.5.8m
ibm aix 4.3
sgi irix 6.5.10f
sgi irix 6.2
sgi irix 6.5.17m
sgi irix 6.1
sgi irix 5.1
sgi irix 6.5.5f
sgi irix 6.5.18m
CVE-2003-0119 HIGH

The secldapclntd daemon in AIX 4.3, 5.1 and 5.2 uses an Internet socket when communicating with the loadmodule, which allows remote attackers to directly connect to the daemon and conduct unauthorized activities.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.1
ibm aix 4.3.3
ibm aix 5.2
CVE-2003-0122 MEDIUM

Buffer overflow in Notes server before Lotus Notes R4, R5 before 5.0.11, and early R6 allows remote attackers to execute arbitrary code via a long distinguished name (DN) during NotesRPC authentication and an outer field length that is less than that of the DN field.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_domino 5.0.9a
ibm lotus_notes_client r5
ibm lotus_notes_client 5.0.1
ibm lotus_domino 5.0.10
ibm lotus_domino 5.0.9
ibm lotus_domino 5.0.8a
ibm lotus_notes_client 5.0.9a
ibm lotus_domino 5.0.3
ibm lotus_notes_client 5.0.2
ibm lotus_domino 5.0.2
ibm lotus_domino 5.0.7a
ibm lotus_notes_client 5.0.10
ibm lotus_domino 4.6.4
ibm lotus_domino 5.0.5
ibm lotus_domino 5.0.8
ibm lotus_domino 5.0.4a
ibm lotus_domino 5.0.1
ibm lotus_domino 5.0.11
ibm lotus_notes_client 5.0.11
ibm lotus_domino 5.0.6a
ibm lotus_domino 4.6.3
ibm lotus_notes_client 5.0.3
ibm lotus_domino 4.6.1
ibm lotus_domino 5.0.4
ibm lotus_domino 5.0
ibm lotus_notes_client 5.0.5
ibm lotus_notes_client 5.0
ibm lotus_domino 5.0.6
ibm lotus_notes_client 5.0.4
CVE-2003-0123 MEDIUM

Buffer overflow in Web Retriever client for Lotus Notes/Domino R4.5 through R6 allows remote malicious web servers to cause a denial of service (crash) via a long HTTP status line.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_domino 5.0.7
ibm lotus_domino 5.0.9a
ibm lotus_notes_client r5
ibm lotus_notes_client 5.0.1
ibm lotus_domino 5.0.10
ibm lotus_domino 5.0.9
ibm lotus_domino 5.0.8a
ibm lotus_notes_client 5.0.9a
ibm lotus_domino 5.0.3
ibm lotus_notes_client 5.0.2
ibm lotus_domino 5.0.2
ibm lotus_domino 5.0.7a
ibm lotus_notes_client 5.0.10
ibm lotus_domino 4.6.4
ibm lotus_domino 5.0.5
ibm lotus_domino 5.0.8
ibm lotus_domino 5.0.4a
ibm lotus_domino 5.0.1
ibm lotus_domino 5.0.11
ibm lotus_notes_client 5.0.11
ibm lotus_domino 5.0.6a
ibm lotus_domino 4.6.3
ibm lotus_notes_client 5.0.3
ibm lotus_domino 4.6.1
ibm lotus_domino 5.0.4
ibm lotus_domino 5.0
ibm lotus_notes_client 5.0.5
ibm lotus_notes_client 5.0
ibm lotus_domino 5.0.6
ibm lotus_notes_client 5.0.4
CVE-2003-0170 HIGH

Unknown vulnerability in ftpd in IBM AIX 5.2, when configured to use Kerberos 5 for authentication, allows remote attackers to gain privileges via unknown attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.2
CVE-2003-0178 HIGH

Multiple buffer overflows in Lotus Domino Web Server before 6.0.1 allow remote attackers to cause a denial of service or execute arbitrary code via (1) the s_ViewName option in the PresetFields parameter for iNotes, (2) the Foldername option in the PresetFields parameter for iNotes, or (3) a long Host header, which is inserted into a long Location header and used during a redirect operation.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_domino_web_server 6.0
CVE-2003-0179 HIGH

Buffer overflow in the COM Object Control Handler for Lotus Domino 6.0.1 and earlier allows remote attackers to execute arbitrary code via multiple attack vectors, as demonstrated using the InitializeUsingNotesUserName method in the iNotes ActiveX control.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_notes_client 6.0
ibm lotus_domino_web_server 6.0
CVE-2003-0180 MEDIUM

Lotus Domino Web Server (nhttp.exe) before 6.0.1 allows remote attackers to cause a denial of service via an incomplete POST request, as demonstrated using the h_PageUI form.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_domino_web_server 6.0
CVE-2003-0181 MEDIUM

Lotus Domino Web Server (nhttp.exe) before 6.0.1 allows remote attackers to cause a denial of service via a "Fictionary Value Field POST request" as demonstrated using the s_Validation form with a long, unknown parameter name.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_domino_web_server 6.0
CVE-2003-0257 HIGH

Format string vulnerability in the printer capability for IBM AIX .3, 5.1, and 5.2 allows local users to gain printq or root privileges.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.3.1
ibm aix 4.3.2
ibm aix 5.1
ibm aix 4.3.3
ibm aix 4.3
ibm aix 5.2
CVE-2003-0285 MEDIUM

IBM AIX 5.2 and earlier distributes Sendmail with a configuration file (sendmail.cf) with the (1) promiscuous_relay, (2) accept_unresolvable_domains, and (3) accept_unqualified_senders features enabled, which allows Sendmail to be used as an open mail relay for sending spam e-mail.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix *
CVE-2003-0578 MEDIUM

cci_dir in IBM U2 UniVerse 10.0.0.9 and earlier creates hard links and unlinks files as root, which allows local users to gain privileges by deleting and overwriting arbitrary files.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 1.8 5.9

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-59,

Products Affected

Vendor Product Version
ibm u2_universe *
CVE-2003-0579 MEDIUM

uvadmsh in IBM U2 UniVerse 10.0.0.9 and earlier trusts the user-supplied -uv.install command line option to find and execute the uv.install program, which allows local users to gain privileges by providing a pathname that is under control of the user.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm u2_universe *
CVE-2003-0580 HIGH

Buffer overflow in uvadmsh in IBM U2 UniVerse 10.0.0.9 and earlier allows the uvadm user to execute arbitrary code via a long -uv.install command line argument.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm u2_universe *
CVE-2003-0681 HIGH

A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has unknown consequences.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
openbsd openbsd 3.2
sendmail sendmail 2.6.1
netbsd netbsd 1.4.3
sendmail sendmail 8.10
netbsd netbsd 1.5.3
sendmail sendmail 8.11.6
gentoo linux 1.2
sendmail sendmail 8.11.3
sendmail sendmail 8.9.2
sendmail sendmail_switch 2.2.1
apple mac_os_x 10.2.2
sendmail sendmail_switch 2.2.4
ibm aix 5.1
sendmail sendmail 8.12.1
sendmail sendmail 8.11.5
gentoo linux 0.7
sendmail sendmail_pro 8.9.2
apple mac_os_x 10.2.3
sendmail advanced_message_server 1.2
apple mac_os_x_server 10.2
sendmail sendmail_switch 3.0
openbsd openbsd 3.3
sendmail sendmail 8.12.4
sendmail sendmail 3.0
sendmail sendmail_switch 2.2.3
sendmail sendmail_switch 3.0.2
sendmail sendmail 8.12.0
sendmail sendmail 8.9.1
gentoo linux 0.5
apple mac_os_x_server 10.2.2
netbsd netbsd 1.5.2
sendmail sendmail_switch 2.1.4
sendmail advanced_message_server 1.3
sendmail sendmail 8.12.8
sendmail sendmail_switch 2.1
sendmail sendmail 8.10.2
sendmail sendmail 8.12
sendmail sendmail 8.12.6
netbsd netbsd 1.6
sendmail sendmail_switch 3.0.3
apple mac_os_x_server 10.2.3
apple mac_os_x_server 10.2.4
sendmail sendmail_switch 2.2.2
gentoo linux 1.4
sendmail sendmail 8.8.8
ibm aix 4.3.3
hp hp-ux 11.11
gentoo linux 1.1a
turbolinux turbolinux_workstation 8.0
sendmail sendmail 3.0.1
sendmail sendmail 2.6.2
hp hp-ux 11.0.4
sendmail sendmail 8.12.2
sendmail sendmail_switch 2.1.1
apple mac_os_x_server 10.2.6
sendmail sendmail 3.0.2
netbsd netbsd 1.6.1
turbolinux turbolinux_server 6.5
turbolinux turbolinux_server 8.0
apple mac_os_x 10.2.1
sendmail sendmail 8.11.1
sendmail sendmail 8.11.2
sendmail sendmail_switch 2.2.5
turbolinux turbolinux_workstation 6.0
netbsd netbsd 1.5.1
ibm aix 5.2
turbolinux turbolinux_workstation 7.0
sendmail sendmail 8.12.9
hp hp-ux 11.00
sendmail sendmail_switch 2.1.3
netbsd netbsd 1.5
sendmail sendmail 8.12.3
sendmail sendmail 8.12.7
sendmail sendmail 2.6
sendmail sendmail_pro 8.9.3
sendmail sendmail 8.12.5
apple mac_os_x_server 10.2.5
turbolinux turbolinux_advanced_server 6.0
sendmail sendmail_switch 2.2
apple mac_os_x 10.2.5
sendmail sendmail_switch 3.0.1
sendmail sendmail 8.10.1
hp hp-ux 11.22
sendmail sendmail 8.9.0
sendmail sendmail 8.9.3
sendmail sendmail_switch 2.1.5
turbolinux turbolinux_server 6.1
apple mac_os_x 10.2.6
turbolinux turbolinux_server 7.0
apple mac_os_x_server 10.2.1
sendmail sendmail 8.11.0
sendmail sendmail_switch 2.1.2
sendmail sendmail 8.11.4
apple mac_os_x 10.2.4
sendmail sendmail 3.0.3
apple mac_os_x 10.2
CVE-2003-0694 HIGH

The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
sendmail sendmail 2.6.1
netbsd netbsd 1.4.3
sendmail sendmail 8.10
compaq tru64 4.0f_pk8_bl22
freebsd freebsd 4.3
netbsd netbsd 1.5.3
sendmail sendmail 8.11.6
gentoo linux 1.2
sendmail sendmail 8.11.3
sendmail sendmail 8.9.2
compaq tru64 5.1a_pk2_bl2
sendmail sendmail_switch 2.2.1
apple mac_os_x 10.2.2
sendmail sendmail_switch 2.2.4
compaq tru64 5.1_pk3_bl17
ibm aix 5.1
compaq tru64 4.0g_pk3_bl17
freebsd freebsd 4.0
freebsd freebsd 4.5
sendmail sendmail 8.12.1
sendmail sendmail 8.11.5
gentoo linux 0.7
freebsd freebsd 4.8
sun sunos 5.8
sendmail sendmail_pro 8.9.2
compaq tru64 5.1_pk4_bl18
apple mac_os_x 10.2.3
sendmail advanced_message_server 1.2
apple mac_os_x_server 10.2
sendmail sendmail_switch 3.0
sun solaris 7.0
sendmail sendmail 8.12.4
compaq tru64 5.1_pk5_bl19
sendmail sendmail 3.0
sendmail sendmail_switch 2.2.3
sendmail sendmail_switch 3.0.2
sgi irix 6.5.15
sendmail sendmail 8.12.0
sendmail sendmail 8.9.1
gentoo linux 0.5
apple mac_os_x_server 10.2.2
netbsd netbsd 1.5.2
sendmail sendmail_switch 2.1.4
sendmail advanced_message_server 1.3
sendmail sendmail 8.12.8
sendmail sendmail_switch 2.1
sendmail sendmail 8.10.2
compaq tru64 4.0g
compaq tru64 5.1a
sendmail sendmail 8.12
sgi irix 6.5.16
sgi irix 6.5.20m
sgi irix 6.5.17f
sun solaris 2.6
compaq tru64 4.0f
sendmail sendmail 8.12.6
netbsd netbsd 1.6
sendmail sendmail_switch 3.0.3
sgi irix 6.5.21f
apple mac_os_x_server 10.2.3
compaq tru64 5.1b_pk1_bl1
apple mac_os_x_server 10.2.4
sendmail sendmail_switch 2.2.2
gentoo linux 1.4
sendmail sendmail 8.8.8
ibm aix 4.3.3
hp hp-ux 11.11
freebsd freebsd 4.4
gentoo linux 1.1a
turbolinux turbolinux_workstation 8.0
sgi irix 6.5.19f
sendmail sendmail 3.0.1
compaq tru64 4.0g_pk4_bl22
sendmail sendmail 2.6.2
sun sunos 5.7
hp hp-ux 11.0.4
sendmail sendmail 8.12.2
sendmail sendmail_switch 2.1.1
apple mac_os_x_server 10.2.6
sendmail sendmail 3.0.2
netbsd netbsd 1.6.1
turbolinux turbolinux_server 6.5
turbolinux turbolinux_server 8.0
apple mac_os_x 10.2.1
sendmail sendmail 8.11.1
sendmail sendmail 8.11.2
sgi irix 6.5.21m
sendmail sendmail_switch 2.2.5
turbolinux turbolinux_workstation 6.0
netbsd netbsd 1.5.1
ibm aix 5.2
turbolinux turbolinux_workstation 7.0
sendmail sendmail 8.12.9
hp hp-ux 11.00
sgi irix 6.5.19m
sendmail sendmail_switch 2.1.3
netbsd netbsd 1.5
sendmail sendmail 8.12.3
sun solaris 8.0
sendmail sendmail 8.12.7
sendmail sendmail 2.6
compaq tru64 4.0f_pk7_bl18
sendmail sendmail_pro 8.9.3
sendmail sendmail 8.12.5
compaq tru64 5.1b
apple mac_os_x_server 10.2.5
compaq tru64 5.1a_pk1_bl1
turbolinux turbolinux_advanced_server 6.0
sendmail sendmail_switch 2.2
apple mac_os_x 10.2.5
sendmail sendmail_switch 3.0.1
sun solaris 9.0
compaq tru64 4.0f_pk6_bl17
sendmail sendmail 8.10.1
sgi irix 6.5.20f
hp hp-ux 11.22
sendmail sendmail 8.9.0
sendmail sendmail 8.9.3
sendmail sendmail_switch 2.1.5
sgi irix 6.5.18f
turbolinux turbolinux_server 6.1
sun sunos -
compaq tru64 5.1b_pk2_bl22
freebsd freebsd 5.1
freebsd freebsd 4.7
apple mac_os_x 10.2.6
freebsd freebsd 3.0
freebsd freebsd 5.0
turbolinux turbolinux_server 7.0
apple mac_os_x_server 10.2.1
compaq tru64 5.1a_pk4_bl21
compaq tru64 5.1_pk6_bl20
compaq tru64 5.1
freebsd freebsd 4.9
sendmail sendmail 8.11.0
compaq tru64 5.1a_pk5_bl23
sgi irix 6.5.17m
sendmail sendmail_switch 2.1.2
sendmail sendmail 8.11.4
compaq tru64 5.1a_pk3_bl3
apple mac_os_x 10.2.4
freebsd freebsd 4.6
sendmail sendmail 3.0.3
sgi irix 6.5.18m
apple mac_os_x 10.2
CVE-2003-0696 MEDIUM

The getipnodebyname() API in AIX 5.1 and 5.2 does not properly close sockets, which allows attackers to cause a denial of service (resource exhaustion).

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.1
ibm aix 5.2
CVE-2003-0697 HIGH

Format string vulnerability in lpd in the bos.rte.printers fileset for AIX 4.3 through 5.2, with debug enabled, allows local users to cause a denial of service (crash) or gain root privileges.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.1
ibm aix 4.3
ibm aix 5.2
CVE-2003-0758 HIGH

Buffer overflow in db2dart in IBM DB2 Universal Data Base 7.2 before Fixpak 10 allows local users to gain root privileges via a long command line argument.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm db2_universal_database 7.2
CVE-2003-0759 HIGH

Buffer overflow in db2licm in IBM DB2 Universal Data Base 7.2 before Fixpak 10a allows local users to gain root privileges via a long command line argument.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm db2_universal_database 7.2
CVE-2003-0784 HIGH

Format string vulnerability in tsm for the bos.rte.security fileset on AIX 5.2 allows remote attackers to gain root privileges via login, and local users to gain privileges via login, su, or passwd, with a username that contains format string specifiers.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.1
ibm aix 4.3.3
ibm aix 5.2
CVE-2003-0827 MEDIUM

The DB2 Discovery Service for IBM DB2 before FixPak 10a allows remote attackers to cause a denial of service (crash) via a long packet to UDP port 523.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm db2_universal_database 7.2
ibm db2_universal_database 7.1
CVE-2003-0836 HIGH

Stack-based buffer overflow in IBM DB2 Universal Data Base 7.2 before Fixpak 10 and 10a, and 8.1 before Fixpak 2, allows attackers with "Connect" privileges to execute arbitrary code via a LOAD command.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm db2_universal_database 7.2
ibm db2_universal_database 8.1
CVE-2003-0837 HIGH

Stack-based buffer overflow in IBM DB2 Universal Data Base 7.2 for Windows, before Fixpak 10a, allows attackers with "Connect" privileges to execute arbitrary code via the INVOKE command.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm db2_universal_database 7.2
CVE-2003-0898 MEDIUM

IBM DB2 7.2 before FixPak 10a, and earlier versions including 7.1, allows local users to overwrite arbitrary files and gain privileges via a symlink attack on (1) db2job and (2) db2job2.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm db2_universal_database *
ibm db2_universal_database 7.1
CVE-2003-0914 MEDIUM

ISC BIND 8.3.x before 8.3.7, and 8.4.x before 8.4.3, allows remote attackers to poison the cache via a malicious name server that returns negative responses with a large TTL (time-to-live) value.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
hp hp-ux 11.11
isc bind 8.2.6
freebsd freebsd 4.4
compaq tru64 4.0f_pk8_bl22
compaq tru64 4.0g_pk4_bl22
nixu namesurfer standard_3.0.1
sun sunos 5.7
compaq tru64 5.1a_pk2_bl2
isc bind 8.2.3
isc bind 8.2.4
netbsd netbsd 1.6.1
ibm aix 5.1l
compaq tru64 5.1_pk3_bl17
isc bind 8.3.0
compaq tru64 4.0g_pk3_bl17
freebsd freebsd 4.5
hp hp-ux 11.00
sun solaris 8.0
isc bind 8.3.3
freebsd freebsd 4.8
nixu namesurfer suite_3.0.1
sun sunos 5.8
compaq tru64 4.0f_pk7_bl18
compaq tru64 5.1_pk4_bl18
compaq tru64 5.1b
compaq tru64 5.1a_pk1_bl1
sco unixware 7.1.1
sun solaris 9.0
isc bind 8.3.1
netbsd netbsd current
sun solaris 7.0
compaq tru64 4.0f_pk6_bl17
compaq tru64 5.1_pk5_bl19
isc bind 8.2.7
isc bind 8.3.4
compaq tru64 5.1b_pk2_bl22
freebsd freebsd 4.7
isc bind 8.4.1
isc bind 8.3.2
freebsd freebsd 5.0
compaq tru64 4.0g
compaq tru64 5.1a
isc bind 8.4
isc bind 8.3.6
compaq tru64 5.1a_pk4_bl21
compaq tru64 5.1_pk6_bl20
compaq tru64 5.1
isc bind 8.2.5
freebsd freebsd 4.9
compaq tru64 4.0f
netbsd netbsd 1.6
freebsd freebsd 4.6.2
isc bind 8.3.5
compaq tru64 5.1b_pk1_bl1
compaq tru64 5.1a_pk5_bl23
compaq tru64 5.1a_pk3_bl3
freebsd freebsd 4.6
CVE-2003-0954 HIGH

Buffer overflow in rcp for AIX 4.3.3, 5.1 and 5.2 allows local users to gain privileges.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.1
ibm aix 4.3.3
ibm aix 5.2
CVE-2003-1018 HIGH

Format string vulnerability in enq command in AIX 4.3, 5.1, and 5.2 allows local users with rintq group privileges to gain privileges via unknown attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.1
ibm aix 4.3.3
ibm aix 5.2
CVE-2003-1049 MEDIUM

IBM DB2 Universal Database 7 before FixPak 12 creates certain DMS directories with insecure permissions (777), which allows local users to modify or delete certain DB2 files.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm db2_universal_database 8.0
ibm db2_universal_database 7.0
CVE-2003-1051 HIGH

Multiple format string vulnerabilities in IBM DB2 Universal Database 8.1 may allow local users to execute arbitrary code via certain command line arguments to (1) db2start, (2) db2stop, or (3) db2govd.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm db2 9.0
CVE-2003-1052 HIGH

IBM DB2 7.1 and 8.1 allow the bin user to gain root privileges by modifying the shared libraries that are used in setuid root programs.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm db2_universal_database 7.2
ibm db2 9.0
ibm db2_universal_database 8.0
ibm db2_universal_database 8.2
ibm db2_universal_database 7.1
ibm db2_universal_database 6.0
ibm db2_universal_database 7.0
ibm db2_universal_database 8.1
CVE-2003-1104 HIGH

Buffer overflow in IBM Tivoli Firewall Toolbox (TFST) 1.2 allows remote attackers to execute arbitrary code via unknown vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm tivoli_firewall_toolbox 1.2
CVE-2003-1447 LOW

IBM WebSphere Advanced Server Edition 4.0.4 uses a weak encryption algorithm (XOR and base64 encoding), which allows local users to decrypt passwords when the configuration file is exported to XML.

CVSS 2.0

Severity: LOW

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm websphere_application_server 4.0.4
CVE-2003-1527 MEDIUM

BlackICE Defender 2.9.cap and Server Protection 3.5.cdf, when configured to automatically block attacks, allows remote attackers to block IP addresses and cause a denial of service via spoofed packets.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
iss blackice_server_protection 3.5.cdf
ibm internet_security_systems_blackice_defender 2.9cap
CVE-2003-1570 LOW

The server in IBM Tivoli Storage Manager (TSM) 5.1.x, 5.2.x before 5.2.1.2, and 6.x before 6.1 does not require credentials to observe the server console in some circumstances, which allows remote authenticated administrators to monitor server operations by establishing a console mode session, related to "session exposure."

CVSS 2.0

Severity: LOW

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager 5.1.6
ibm tivoli_storage_manager 5.1.7
ibm tivoli_storage_manager 5.1.8
ibm tivoli_storage_manager 5.1.5
ibm tivoli_storage_manager 5.1.0
ibm tivoli_storage_manager 5.1.1
ibm tivoli_storage_manager 6.0
ibm tivoli_storage_manager 5.1.9
ibm tivoli_storage_manager 5.2.1
ibm tivoli_storage_manager 5.1.10
ibm tivoli_storage_manager 5.2.0
CVE-2004-0029 MEDIUM

Lotus Notes Domino 6.0.2 on Linux installs the notes.ini configuration file with world-writable permissions, which allows local users to modify the Notes configuration and gain privileges.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_domino 6.0.2
CVE-2004-0243 MEDIUM

AIX 4.3.3 through AIX 5.1, when direct remote login is disabled, displays a different message if the password is correct, which allows remote attackers to guess the password via brute force methods.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-203,

Products Affected

Vendor Product Version
ibm aix *
CVE-2004-0253 HIGH

IBM Cloudscape 5.1 running jdk 1.4.2_03 allows remote attackers to execute arbitrary programs or cause a denial of service via certain SQL code, possibly due to a SQL injection vulnerability.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm cloudscape 5.1
CVE-2004-0263 MEDIUM

PHP 4.3.4 and earlier in Apache 1.x and 2.x (mod_php) can leak global variables between virtual hosts that are handled by the same Apache child process but have different settings, which could allow remote attackers to obtain sensitive information.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
apache http_server 2.0.46
apache http_server 2.0.36
apache http_server 1.3.6
apache http_server 1.3.11
apache http_server 2.0.32
apache http_server 1.0.3
apache http_server 2.0.47
ibm http_server 1.3.19
apache http_server 1.3.3
apache http_server 1.0.2
apache http_server 2.0.9
apache http_server 1.3.18
apache http_server 1.3.28
apache http_server 2.0.39
apache http_server 2.0.28
apache http_server 1.3.20
apache http_server 2.0.35
apache http_server 1.3.17
apache http_server 1.3.9
apache http_server 2.0
apache http_server 2.0.48
apache http_server 1.3.7
apache http_server 1.0.5
apache http_server 1.3.22
apache http_server 2.0.38
apache http_server 1.3.27
apache http_server 1.3.23
apache http_server 1.1
apache http_server 1.3.26
apache http_server 2.0.45
apache http_server 2.0.41
apache http_server 1.3.4
apache http_server 1.3.24
apache http_server 1.1.1
apache http_server 1.3.14
apache http_server 2.0.37
apache http_server 1.3.25
apache http_server 1.3.1
apache http_server 1.2
apache http_server 1.0
apache http_server 1.3.12
apache http_server 1.3
apache http_server 1.3.29
apache http_server 2.0.43
apache http_server 2.0.44
apache http_server 2.0.40
apache http_server 2.0.42
apache http_server 1.2.5
apache http_server 1.3.19
CVE-2004-0368 HIGH

Double free vulnerability in dtlogin in CDE on Solaris, HP-UX, and other operating systems allows remote attackers to execute arbitrary code via a crafted XDMCP packet.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
open_group cde_common_desktop_environment 1.2
ibm aix 5.1
ibm aix 4.3.3
open_group cde_common_desktop_environment 2.1
xi_graphics dextop 2.1
ibm aix 5.2
open_group cde_common_desktop_environment 2.0
open_group cde_common_desktop_environment 1.1
open_group cde_common_desktop_environment 2.1.20
xi_graphics dextop 3.0
open_group cde_common_desktop_environment 1.0.2
open_group cde_common_desktop_environment 1.0.1
CVE-2004-0480 HIGH

Argument injection vulnerability in IBM Lotus Notes 6.0.3 and 6.5 allows remote attackers to execute arbitrary code via a notes: URI that uses a UNC network share pathname to provide an alternate notes.ini configuration file to notes.exe.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-88,

Products Affected

Vendor Product Version
ibm lotus_notes 6.0.3
ibm lotus_notes 6.5
CVE-2004-0492 HIGH

Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a negative Content-Length HTTP header field, which causes a large amount of data to be copied.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
apache http_server 1.3.27
apache http_server 1.3.28
ibm http_server 1.3.26.1
ibm http_server 1.3.26.2
apache http_server 1.3.26
apache http_server 1.3.31
apache http_server 1.3.29
openbsd openbsd 3.5
ibm http_server 1.3.28
openbsd openbsd *
ibm http_server 1.3.26
hp webproxy 2.0
sgi propack 2.4
hp webproxy 2.1
hp virtualvault 11.0.4
hp vvos 11.04
openbsd openbsd 3.4
CVE-2004-0493 MEDIUM

The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a denial of service (memory exhaustion), and possibly an integer signedness error leading to a heap-based buffer overflow on 64 bit systems, via long header lines with large numbers of space or tab characters.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
avaya s8700 r2.0.0
trustix secure_linux 1.5
ibm http_server 2.0.42.1
ibm http_server 2.0.42.2
avaya converged_communications_server 2.0
trustix secure_linux 2.1
ibm http_server 2.0.42
apache http_server 2.0.47
ibm http_server 2.0.47
apache http_server 2.0.48
trustix secure_linux 2.0
apache http_server 2.0.49
ibm http_server 2.0.47.1
avaya s8500 r2.0.0
avaya s8300 r2.0.0
gentoo linux 1.4
CVE-2004-0544 HIGH

Multiple buffer overflows in LVM for AIX 5.1 and 5.2 allow local users to gain privileges via the (1) putlvcb or (2) getlvcb commands.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.1
ibm aix 4.3.3
ibm aix 5.2
CVE-2004-0545 HIGH

LVM for AIX 5.1 and 5.2 allows local users to overwrite arbitrary files via a symlink attack.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.1
ibm aix 5.2
CVE-2004-0586 HIGH

acpRunner ActiveX 1.2.5.0 allows remote attackers to execute arbitrary code via the (1) DownLoadURL, (2) SaveFilePath, and (3) Download ActiveX methods.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm acprunner 1.2.5.0
CVE-2004-0669 HIGH

Lotus Domino 6.5.0 and 6.5.1, with IMAP enabled, allows remote authenticated users to change their quota by using the IMAP setquota command.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_domino 6.5.1
ibm lotus_domino 6.5.0
CVE-2004-0684 MEDIUM

WebSphere Edge Component Caching Proxy in WebSphere Edge Server 5.02, with the JunctionRewrite directive enabled, allows remote attackers to cause a denial of service via an HTTP GET request without any parameters.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_edge_server_caching_proxy 5.0.2
ibm websphere_caching_proxy_server 5.0.2
CVE-2004-0795 HIGH

DB2 8.1 remote command server (DB2RCMD.EXE) executes the db2rcmdc.exe program as the db2admin administrator, which allows local users to gain privileges via the DB2REMOTECMD named pipe.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm db2_universal_database 8.1
CVE-2004-0828 LOW

The ctstrtcasd program in RSCT 2.3.0.0 and earlier on IBM AIX 5.2 and 5.3 does not properly drop privileges before executing the -f option, which allows local users to modify or create arbitrary files.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 5.2
CVE-2004-1028 HIGH

Untrusted execution path vulnerability in chcod on AIX IBM 5.1.0, 5.2.0, and 5.3.0 allows local users to execute arbitrary programs by modifying the PATH environment variable to point to a malicious "grep" program, which is executed from chcod.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.3_l
ibm aix 5.1l
ibm aix 5.1
ibm aix 5.3
ibm aix 5.2_l
ibm aix 5.2
ibm aix 5.2.2
CVE-2004-1054 HIGH

Untrusted execution path vulnerability in invscout in IBM AIX 5.1.0, 5.2.0, and 5.3.0 allows local users to gain privileges by modifying the PATH environment variable to point to a malicious "uname" program, which is executed from lsvpd after lsvpd has been invoked by invscout.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.3_l
ibm aix 5.1l
ibm aix 5.1
ibm aix 5.3
ibm aix 5.2_l
ibm aix 5.2
ibm aix 5.2.2
CVE-2004-1082 HIGH

mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attackers to replay credentials.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
apache http_server 1.3.22
apache http_server 1.3.27
apache http_server 1.3.23
hp virtualvault 4.7
apache http_server 1.3.6
apache http_server 1.3.26
avaya intuity_audix_lx *
hp webproxy a.02.10
openbsd openbsd 3.5
apache http_server 1.3.4
sco openserver 5.0.6
apache http_server 1.3.24
openbsd openbsd current
apache http_server 1.3.11
avaya communication_manager 2.0.1
apache http_server 1.3.14
ibm http_server 1.3.19
avaya mn100 *
apache http_server 1.3.3
apache http_server 1.3.25
avaya modular_messaging_message_storage_server 1.1
apache http_server 1.3.1
openbsd openbsd 3.4
hp webproxy a.02.00
apache http_server 1.3.12
apache http_server 1.3.18
apache http_server 1.3.28
avaya communication_manager 1.1
apache http_server 1.3
hp virtualvault 4.5
apache http_server 1.3.29
hp virtualvault 4.6
avaya network_routing *
avaya communication_manager 2.0
sun solaris 8.0
apache http_server 1.3.20
apache http_server 1.3.17
apache http_server 1.3.9
sun sunos 5.8
apache http_server 1.3.19
avaya modular_messaging_message_storage_server 2.0
apache http_server 1.3.7
apple apache_mod_digest_apple *
avaya communication_manager 1.3.1
sun solaris 9.0
sco openserver 5.0.7
CVE-2004-1329 HIGH

Untrusted execution path vulnerability in the diag commands (1) lsmcode, (2) diag_exec, (3) invscout, and (4) invscoutd in AIX 5.1 through 5.3 allows local users to execute arbitrary programs by modifying the DIAGNOSTICS environment variable to point to a malicious Dctrl program.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.3_l
ibm aix 5.1l
ibm aix 5.1
ibm aix 5.3
ibm aix 5.2_l
ibm aix 5.2
ibm aix 5.2.2
CVE-2004-1330 HIGH

Buffer overflow in paginit in AIX 5.1 through 5.3 allows local users to execute arbitrary code via a long username.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.3_l
ibm aix 5.3
ibm aix 5.2_l
ibm aix 5.2
ibm aix 5.2.2
CVE-2004-1372 HIGH

Multiple stack-based buffer overflows in IBM DB2 7.x and 8.1 allow local users to execute arbitrary code via (1) a long third argument to the rec2xml function or (2) a long filename argument to the generate_distfile procedure.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm db2_universal_database 7.2
ibm db2_universal_database 7.1
ibm db2_universal_database 7.0
ibm db2_universal_database 8.1
CVE-2004-1442 MEDIUM

Cross-site scripting (XSS) vulnerability in db2www CGI interpreter in IBM Net.Data 7 and 7.2 allows remote attackers to inject arbitrary web script or HTML via a macro filename, which is not properly handled by error messages such as "DTWP001E."

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm net.data 7.0
ibm net.data 7.2
CVE-2004-1621 MEDIUM

NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in IBM Lotus Notes R6 and Domino R6, and possibly earlier versions, allows remote attackers to execute arbitrary web script or HTML via square brackets at the beginning and end of (1) computed for display, (2) computed when composed, or (3) computed text element fields. NOTE: the vendor has disputed this issue, saying that it is not a problem with Notes/Domino itself, but with the applications that do not properly handle this feature

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_domino 6.0.2
ibm lotus_domino 6.5.1
ibm lotus_domino 6.0.3
ibm lotus_domino 6.0
ibm lotus_domino 6.0.2_cf2
ibm lotus_domino 6.5.0
ibm lotus_domino 6.0.1
ibm lotus_domino 6.5.2
CVE-2004-1663 MEDIUM

Engenio/LSI Logic storage controllers, as used in products such as Storagetek D280, and IBM DS4100 (formerly FastT 100) and Brocade SilkWorm Switches, allow remote attackers to cause a denial of service (freeze and possible data corruption) via crafted TCP packets.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
engenio storage_controller 4884
brocade silkworm_fiber_channel_switch 2050
brocade silkworm 3850
ibm ds4100 *
brocade silkworm 3250
brocade silkworm 3900
broadcom fabric_operating_system 2.1.2
engenio storage_controller 2822
storagetek d280 *
brocade silkworm 3800
brocade silkworm_fiber_channel_switch 2040
brocade silkworm 3200
engenio storage_controller 2882
broadcom fabric_operating_system 3.1
brocade silkworm_fiber_channel_switch 2010
broadcom fabric_operating_system 2.2
engenio storage_controller 5884
CVE-2004-1759 MEDIUM

Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, allows remote attackers to cause a denial of service (CPU consumption) via arbitrary packets to TCP port 14247, as demonstrated using port scanning.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
cisco ip_call_center_express_standard 3.0
ibm mcs-7835i-3.0 *
cisco call_manager 3.1(3a)
ibm x330 8674
ibm director_agent 3.11
ibm x330 8654
cisco internet_service_node *
ibm mcs-7815-1000 *
cisco personal_assistant 1.3(4)
cisco ip_interactive_voice_response 3.0
cisco conference_connection 1.1(1)
cisco ip_call_center_express_enhanced 3.0
cisco call_manager 4.0
ibm x345 *
cisco emergency_responder 1.1
cisco personal_assistant 1.3(3)
cisco call_manager 1.0
ibm mcs-7835i-2.4 *
ibm x342 *
cisco call_manager 3.0
cisco personal_assistant 1.4(2)
cisco call_manager 3.3(3)
cisco call_manager 2.0
ibm mcs-7815i-2.0 *
cisco personal_assistant 1.3(2)
cisco personal_assistant 1.3(1)
ibm director_agent 2.2
ibm x340 *
cisco call_manager 3.1
cisco call_manager 3.3
cisco conference_connection 1.2
cisco call_manager 3.2
cisco personal_assistant 1.4(1)
cisco call_manager 3.1(2)
CVE-2004-1760 HIGH

The default installation of Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, does not require authentication, which allows remote attackers to gain administrator privileges by connecting to TCP port 14247.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-287,

Products Affected

Vendor Product Version
cisco ip_call_center_express_standard 3.0
ibm mcs-7835i-3.0 *
cisco call_manager 3.1(3a)
ibm x330 8674
ibm director_agent 3.11
ibm x330 8654
cisco internet_service_node *
ibm mcs-7815-1000 *
cisco personal_assistant 1.3(4)
cisco ip_interactive_voice_response 3.0
cisco conference_connection 1.1(1)
cisco ip_call_center_express_enhanced 3.0
cisco call_manager 4.0
ibm x345 *
cisco emergency_responder 1.1
cisco personal_assistant 1.3(3)
cisco call_manager 1.0
ibm mcs-7835i-2.4 *
ibm x342 *
cisco call_manager 3.0
cisco personal_assistant 1.4(2)
cisco call_manager 3.3(3)
cisco call_manager 2.0
ibm mcs-7815i-2.0 *
cisco personal_assistant 1.3(2)
cisco personal_assistant 1.3(1)
ibm director_agent 2.2
ibm x340 *
cisco call_manager 3.1
cisco call_manager 3.3
cisco conference_connection 1.2
cisco call_manager 3.2
cisco personal_assistant 1.4(1)
cisco call_manager 3.1(2)
CVE-2004-2131 HIGH

Stack-based buffer overflow in ontape for IBM Informix Dynamic Server (IDS) 9.40.xC3 and earlier allows local users, with DSA privileges, to execute arbitrary code via a long ONCONFIG environment variable.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm informix_dynamic_server 9.40.uc2
ibm informix_dynamic_server 9.40.uc1
ibm informix_extended_parallel_server 8.40_uc1
CVE-2004-2270 HIGH

Unknown vulnerability in IBM Parallel Environment (PE) 3.2 and 4.1 allows attackers to execute arbitrary commands as root via unknown vectors in the sample code.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm parallel_environment 3.2
ibm parallel_environment 4.1
CVE-2004-2280 MEDIUM

Buffer overflow in IBM Lotus Notes 6.5.x before 6.5.3 and 6.0.x before 6.0.5 allows remote attackers to cause a denial of service (crash) via unknown vectors related to Java applets, as identified by KSPR62F4KN.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_notes 6.0.1
ibm lotus_notes 6.0.3
ibm lotus_notes 6.0.2
ibm lotus_notes 6.0.5
ibm lotus_notes 6.5
ibm lotus_notes 6.5.1
ibm lotus_notes 6.5.3
ibm lotus_notes 6.0
ibm lotus_notes 6.0.4
ibm lotus_notes 6.5.2
CVE-2004-2281 HIGH

Multiple unknown vulnerabilities in IBM Lotus Notes 6.5.x before 6.5.4 and 6.0.x before 6.0.5 have unknown impact and attack vectors, related to Java applets, as identified by (1) KSPR5YS6GR and (2) KSPR62F4D3.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_notes 6.0.1
ibm lotus_notes 6.0.3
ibm lotus_notes 6.0.2
ibm lotus_notes 6.5
ibm lotus_notes 6.5.1
ibm lotus_notes 6.5.3
ibm lotus_notes 6.0
ibm lotus_notes 6.0.4
ibm lotus_notes 6.5.2
CVE-2004-2310 MEDIUM

Cross-site scripting (XSS) vulnerability in webadmin.nsf in Lotus Domino R6 6.5.1 allows remote attackers to inject arbitrary web script or HTML via a Domino command in the Quick Console.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_domino 6.5.1
CVE-2004-2311 LOW

Directory traversal vulnerability in webadmin.nsf in Lotus Domino R6 6.5.1 allows local users to create folders or determine the existence of files via a .. (dot dot) in the new folder dialog.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_domino 6.5.1
CVE-2004-2312 HIGH

Buffer overflow in GNU make for IBM AIX 4.3.3, when installed setgid, allows local users to gain privileges via a long CC argument.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.3.3
CVE-2004-2319 LOW

IBM Informix Dynamic Server (IDS) before 9.40.xC3 allows local users to (1) create or overwrite files via the /001 log file to onedcu or (2) read arbitrary files via a symlink attack on a file in /tmp to onshowaudit.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm informix_dynamic_server 9.40.uc2
ibm informix_extended_parallel_server 8.40_uc2
ibm informix_dynamic_server 9.40.uc1
ibm informix_extended_parallel_server 8.40_uc1
CVE-2004-2369 MEDIUM

Directory traversal vulnerability in webadmin.nsf for Lotus Domino R6 6.5.1 allows attackers to create and detect directories via a .. (dot dot) in the directory creation command.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_domino 6.5.1
CVE-2004-2388 HIGH

rexecd for AIX 4.3.3 does not properly use a local copy of the pwd structure when calling getpwnam, which may cause the structure to be overwritten by the authenticate function and assign privileges to the wrong user.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.3.3
CVE-2004-2478 HIGH

Unspecified vulnerability in Jetty HTTP Server, as used in (1) IBM Trading Partner Interchange before 4.2.4, (2) CA Unicenter Web Services Distributed Management (WSDM) before 3.11, and possibly other products, allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm trading_partner_interchange *
jetty jetty_http_server 4.2.11
ca unicenter_web_services_distributed_management *
jetty jetty_http_server 4.2.7
jetty jetty_http_server 4.2.18
jetty jetty_http_server 4.2.6
jetty jetty_http_server 4.2.4
jetty jetty_http_server 3.1.7
jetty jetty_http_server 4.1.0
jetty jetty_http_server 4.2.12
jetty jetty_http_server 4.2.14
jetty jetty_http_server 4.2.5
jetty jetty_http_server 4.2.16
jetty jetty_http_server 4.2.9
jetty jetty_http_server 3.1.6
jetty jetty_http_server 4.1.0_rc4
jetty jetty_http_server 4.2.15
ibm trading_partner_interchange 4.2.1
jetty jetty_http_server 4.1.1
jetty jetty_http_server 4.2.17
jetty jetty_http_server 4.2.19
CVE-2004-2489 MEDIUM

Format string vulnerability in IBM Informix Dynamic Server (IDS) before 9.40.xC3 allows local users to execute arbitrary code via a modified INFORMIXDIR environment variable that points to a file with format string specifiers in the filename.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm informix_dynamic_server 9.40.uc2
ibm informix_dynamic_server 9.40.uc1
CVE-2004-2490 MEDIUM

Buffer overflow in IBM Informix Dynamic Server (IDS) 9.40.xC1 and 9.40.xC2 allows local users to execute arbitrary code via a long GL_PATH environment variable.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm informix_dynamic_server 9.40.uc2
ibm informix_extended_parallel_server 8.40_uc2
ibm informix_dynamic_server 9.40.uc1
ibm informix_extended_parallel_server 8.40_uc1
CVE-2004-2526 MEDIUM

Directory traversal vulnerability in ldacgi.exe in IBM Tivoli Directory Server 4.1 and earlier allows remote attackers to view arbitrary files via a .. (dot dot) in the Template parameter.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm tivoli_directory_server 3.2.2
ibm tivoli_directory_server *
CVE-2004-2558 HIGH

Unspecified vulnerability in IBM Tivoli SecureWay Policy Director 3.8, Access Manager for e-business 3.9 to 5.1, Access Manager Identity Manager Solution 5.1, Configuration Manager 4.2, Configuration Manager for Automated Teller Machines 2.1.0, and IBM WebSphere Everyplace Server, Service Provider Offering for Multi-platforms 2.1.3 to 2.15 allow remote attackers to hijack sessions of authenticated users via unknown attack vectors involving certain cookies, aka "Potential Credential Impersonation Attack."

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm tivoli_access_manager_identity_manager_solution 5.1
ibm tivoli_configuration_manager_for_atm 2.1
ibm tivoli_access_manager_for_e-business 3.9
ibm tivoli_access_manager_for_e-business 5.1
ibm tivoli_secureway_policy_director 3.8
ibm websphere_everyplace_server 2.1.3
ibm tivoli_configuration_manager 4.2
ibm websphere_everyplace_server 2.1.4
ibm websphere_everyplace_server 2.1.5
ibm tivoli_access_manager_for_e-business 4.1
CVE-2004-2663 HIGH

The (1) SetDebugging and (2) RunEgatherer methods in IBM Access Support eGatherer ActiveX control 2.0.0.16 allow remote attackers to create files with arbitrary content, as demonstrated by creating a .hta file in a Startup folder.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm egatherer 2.0.0.16
CVE-2004-2697 MEDIUM

The Inventory Scout daemon (invscoutd) 1.3.0.0 and 2.0.2 for AIX 4.3.3 and 5.1 allows local users to gain privileges via a symlink attack on a command line argument (log file). NOTE: this might be related to CVE-2006-5002.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-362,

Products Affected

Vendor Product Version
ibm aix 5.1l
ibm aix 5.1
ibm aix 4.3.3
CVE-2004-2762 MEDIUM

The server in IBM Tivoli Storage Manager (TSM) 4.2.x on MVS, 5.1.9.x before 5.1.9.1, 5.1.x before 5.1.10, 5.2.2.x before 5.2.2.3, 5.2.x before 5.2.3, 5.3.x before 5.3.0, and 6.x before 6.1, when the HTTP communication method is enabled, allows remote attackers to cause a denial of service (daemon crash or hang) via unspecified HTTP traffic, as demonstrated by the IBM port scanner 1.3.1.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager 5.1.6
ibm tivoli_storage_manager 5.1.8
ibm tivoli_storage_manager 5.3
ibm tivoli_storage_manager 5.1.5
ibm tivoli_storage_manager 6.0
ibm tivoli_storage_manager 4.2.3
ibm tivoli_storage_manager 4.2.4
ibm tivoli_storage_manager 5.2.1
ibm tivoli_storage_manager 5.2.0
ibm tivoli_storage_manager 4.2.1
ibm tivoli_storage_manager 5.1.7
ibm tivoli_storage_manager 4.2
ibm tivoli_storage_manager 5.1.0
ibm tivoli_storage_manager 5.1.1
ibm tivoli_storage_manager 5.2.2
ibm tivoli_storage_manager 5.1.9
ibm tivoli_storage_manager 4.2.2
CVE-2005-0156 LOW

Buffer overflow in the PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to execute arbitrary code by setting the PERLIO_DEBUG variable and executing a Perl script whose full pathname contains a long directory tree.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
sgi propack 3.0
redhat fedora_core core_3.0
trustix secure_linux 2.1
suse suse_linux 8.1
redhat enterprise_linux 3.0
larry_wall perl 5.8.4.2.3
trustix secure_linux 2.0
ibm aix 5.3
larry_wall perl 5.8.4
larry_wall perl 5.8.4.1
suse suse_linux 8.0
larry_wall perl 5.8.4.5
trustix secure_linux 1.5
ibm aix 5.2
larry_wall perl 5.8.4.2
ubuntu ubuntu_linux 4.1
suse suse_linux 9.2
larry_wall perl 5.8.4.4
larry_wall perl 5.8.4.3
larry_wall perl 5.8.3
redhat enterprise_linux_desktop 3.0
larry_wall perl 5.8.1
suse suse_linux 9.1
larry_wall perl 5.8.0
trustix secure_linux 2.2
suse suse_linux 8.2
suse suse_linux 9.0
CVE-2005-0240 HIGH

Format string vulnerability in chdev on IBM AIX 5.2 allows local users to execute arbitrary code via format string specifiers in a command line argument, which is not properly handled when printing an error message.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.2
CVE-2005-0250 HIGH

Format string vulnerability in auditselect on IBM AIX 5.1, 5.2, and 5.3 allows local users to execute arbitrary code via format string specifiers in a command line argument.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.1
ibm aix 5.3
ibm aix 5.2
CVE-2005-0261 LOW

lspath in AIX 5.2, 5.3, and possibly earlier versions, does not drop privileges before processing the -f option, which allows local users to read one line of arbitrary files.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 5.2
CVE-2005-0262 HIGH

Buffer overflow in ipl_varyon on AIX 5.1, 5.2, and 5.3 allows local users to execute arbitrary code via a long -d argument.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.1
ibm aix 5.3
ibm aix 5.2
CVE-2005-0263 HIGH

Buffer overflow in netpmon on AIX 5.1, 5.2, and 5.3 allows local users to execute arbitrary code via a long -O argument.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.1
ibm aix 5.3
ibm aix 5.2
CVE-2005-0417 HIGH

Unknown "high risk" vulnerability in DB2 Universal Database 8.1 and earlier has unknown impact and attack vectors. NOTE: due to the delayed disclosure of details for this issue, this candidate may be SPLIT in the future. In addition, this may be a duplicate of other issues as reported by the vendor.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm db2_universal_database 7.2
ibm db2_universal_database 8.0
ibm db2_universal_database 8.2
ibm db2_universal_database 7.1
ibm db2_universal_database 6.0
ibm db2_universal_database 7.0
ibm db2_universal_database 8.1
CVE-2005-0425 MEDIUM

Unknown vulnerability in IBM Websphere Application Server 5.0, 5.1, and 6.0 when running on Windows, allows remote attackers to obtain the source code for Java Server Pages (.jsp) via a crafted URL that causes the page to be processed by the file serving servlet instead of the JSP engine.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_application_server 5.1.0
ibm websphere_application_server 6.0
ibm websphere_application_server 5.0
CVE-2005-0539 MEDIUM

Unknown vulnerability in IBM Hardware Management Console (HMC) before 4.4 for POWER5 servers allows local users to gain privileges, related to the Guided Setup Wizard.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm hardware_management_console 4.2
ibm hardware_management_console 4.1
CVE-2005-0868 HIGH

AS/400 Telnet 5250 terminal emulation clients, as implemented by (1) IBM client access, (2) Bosanova, (3) PowerTerm, (4) Mochasoft, and possibly other emulations, allows malicious AS/400 servers to execute arbitrary commands via a STRPCO (Start PC Organizer) command followed by STRPCCMD (Start PC command), as demonstrated by creating a backdoor account using REXEC.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
powerterm interconnect *
mochasoft tn5250 *
bosanova launcher400 *
ibm client_access *
CVE-2005-0899 LOW

AS/400 running OS400 5.2 installs and enables LDAP by default, which allows remote authenticated users to obtain OS/400 user profiles by performing a search.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm os_400 5.2
CVE-2005-0986 MEDIUM

NLSCCSTR.DLL in the web service in IBM Lotus Domino Server 6.5.1, 6.0.3, and possibly other versions allows remote attackers to cause a denial of service (deep recursion and nHTTP.exe process crash) via a long GET request containing UNICODE decimal value 430 characters, which causes the stack to be exhausted. NOTE: IBM has reported that it is unable to replicate this issue.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_domino_server 6.5.1
ibm lotus_domino_server 6.0.3
CVE-2005-1025 MEDIUM

The FTP server in AS/400 4.3, when running in IFS mode, allows remote attackers to obtain sensitive information via a symlink attack using RCMD and the ADDLNK utility, as demonstrated using the QSYS.LIB library.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm iseries_as_400 4.3
CVE-2005-1037 HIGH

Unknown vulnerability in AIX 5.3.0, when configured as an NIS client, allows remote attackers to gain root privileges.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.3.0
CVE-2005-1101 HIGH

Multiple buffer overflows in Lotus Domino Server 6.0.5 and 6.5.4 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via large amounts of data in certain (1) time or (2) date fields.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_domino_server 6.5.4
ibm lotus_domino_server 6.0.5
CVE-2005-1112 MEDIUM

IBM WebSphere Application Server 6.0 and earlier, when sharing the document root of the web server, allows remote attackers to obtain the source code for Java Server Pages (.jsp) via an HTTP request with an invalid Host header, which causes the page to be processed by the web server instead of the JSP engine.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_application_server 5.1.1
ibm websphere_application_server 5.1.1.1
ibm websphere_application_server 5.1.1.3
ibm websphere_application_server 5.0.2.4
ibm websphere_application_server 5.0.2.3
ibm websphere_application_server 5.1.1.2
ibm websphere_application_server 5.0
ibm websphere_application_server 5.0.1
ibm websphere_application_server 5.0.2.6
ibm websphere_application_server 5.1.0
ibm websphere_application_server 6.0
ibm websphere_application_server 5.0.2.8
ibm websphere_application_server 5.0.2
ibm websphere_application_server 5.0.2.1
ibm websphere_application_server 5.1.0.2
ibm websphere_application_server 5.1.0.5
ibm websphere_application_server 5.0.2.7
ibm websphere_application_server 5.0.2.9
ibm websphere_application_server 5.0.2.5
ibm websphere_application_server 5.1.0.4
CVE-2005-1133 MEDIUM

The POP3 server in IBM iSeries AS/400 returns different error messages when the user exists or not, which allows remote attackers to determine valid user IDs on the server.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm iseries_as_400 *
CVE-2005-1176 LOW

Race condition in JFS2 on AIX 5.2 and 5.3, when deleting a file while I/O is still occurring for that file, may write data to a different file, which could leak sensitive information.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.3.0.10
ibm aix 5.2.0.54
ibm aix 5.2.0.50
ibm aix 5.3.0.20
CVE-2005-1182 MEDIUM

Unknown vulnerability in Incoming Remote Command (iSeries Access for Windows Remote Command service) in IBM OS/400 R510, R520, and R530 allows attackers to cause a denial of service (IRC shutdown) via certain inputs.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm os_400 r510
ibm os_400 r520
ibm os_400 r530
CVE-2005-1238 HIGH

By design, the built-in FTP server for iSeries AS/400 systems does not support a restricted document root, which allows attackers to read or write arbitrary files, including sensitive QSYS databases, via a full pathname in a GET or PUT request.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm iseries_as_400 *
CVE-2005-1405 LOW

HTTP response splitting vulnerability in the @SetHTTPHeader function in Lotus Domino 6.5.x before 6.5.4 and 6.0.x before 6.0.5 allows attackers to poison the web cache via malicious applications.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_notes 6.0.1
ibm lotus_notes 6.0.3
ibm lotus_notes 6.0.2
ibm lotus_notes 6.5
ibm lotus_notes 6.5.1
ibm lotus_notes 6.5.3
ibm lotus_notes 6.0
ibm lotus_notes 6.0.4
ibm lotus_notes 6.5.2
CVE-2005-1441 MEDIUM

Format string vulnerability in Lotus Domino 6.0.x before 6.0.5 and 6.5.x before 6.5.4 allows remote attackers to cause a denial of service via the Notes protocol (NRPC).

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_domino 6.0.2
ibm lotus_domino 6.5.1
ibm lotus_domino 6.0.3
ibm lotus_domino 6.0
ibm lotus_domino 6.0.2_cf2
ibm lotus_domino 6.5.3
ibm lotus_domino 6.5.0
ibm lotus_domino 6.0.1
ibm lotus_domino 6.5.2
CVE-2005-1442 MEDIUM

Buffer overflow in the Lotus Notes client for Domino 6.5 before 6.5.4 and 6.0 before 6.0.5 allows local users to cause a denial of service (client crash) and possibly execute arbitrary code via the NOTES.INI file.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_notes 6.0.1
ibm lotus_notes 6.0.3
ibm lotus_notes 6.0.2
ibm lotus_notes 6.5
ibm lotus_notes 6.5.1
ibm lotus_notes 6.5.3
ibm lotus_notes 6.0
ibm lotus_notes 6.0.4
ibm lotus_notes 6.5.2
CVE-2005-1872 HIGH

Buffer overflow in the administrative console in IBM WebSphere Application Server 5.x, when the global security option is enabled, allows remote attackers to execute arbitrary code.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_application_server 5.0
CVE-2005-2073 LOW

Unknown vulnerability in IBM DB2 8.1.4 through 8.1.9 and 8.2.0 through 8.2.2 allows local users with SELECT privileges to conduct unauthorized activities and insert, update or delete table contents.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm db2 8.1.8a
ibm db2 8.2.2
ibm db2 8.1.6
ibm db2 8.1.5
ibm db2 8.2.0
ibm db2 8.2.1
ibm db2 8.1.7
ibm db2 8.1.9
ibm db2 8.1.4
CVE-2005-2091 MEDIUM

IBM WebSphere 5.1 and WebSphere 5.0 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes WebSphere to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_application_server 5.1.0
ibm websphere_application_server 5.0
CVE-2005-2170 MEDIUM

The LCF component (lcfd) in IBM Tivoli Management Framework Endpoint allows remote attackers to cause a denial of service (process exit and connection loss) by connecting to LCF and ending the connection without sending any data.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm tivoli_management_framework 4.1.1
CVE-2005-2175 MEDIUM

The web interface for Lotus Notes mail automatically processes HTML in an attachment without prompting the user to save or open it, which makes it easier for remote attackers to conduct web-based attacks and steal cookies.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_notes *
CVE-2005-2232 MEDIUM

Buffer overflow in invscout in IBM AIX 5.1.0 through 5.3.0 might allow local users to execute arbitrary code via a long command line argument.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.1
ibm aix 5.3
ibm aix 5.2
CVE-2005-2233 HIGH

Buffer overflow in multiple "p" commands in IBM AIX 5.1, 5.2 and 5.3 might allow local users to execute arbitrary code via long command line arguments to (1) penable or other hard-linked files including (2) pdisable, (3) pstart, (4) phold, (5) pdelay, or (6) pshare.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.3_l
ibm aix 5.1l
ibm aix 5.1
ibm aix 5.3
ibm aix 5.2_l
ibm aix 5.2
ibm aix 5.2.2
CVE-2005-2235 HIGH

Buffer overflow in the diagTasksWebSM command in IBM AIX 5.1, 5.2 and 5.3, might allow local users to execute arbitrary code via long command line arguments.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.3_l
ibm aix 5.1l
ibm aix 5.1
ibm aix 5.3
ibm aix 5.2_l
ibm aix 5.2
ibm aix 5.2.2
CVE-2005-2236 HIGH

Format string vulnerability in the paginit command in IBM AIX 5.3, and possibly other versions, might allow local users to execute arbitrary code via format strings in command line arguments.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.3
CVE-2005-2238 LOW

ftpd in IBM AIX 5.1, 5.2 and 5.3 allows remote authenticated users to cause a denial of service (port exhaustion and memory consumption) by using all ephemeral ports.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.1
ibm aix 5.3
ibm aix 5.2
CVE-2005-2428 MEDIUM

Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores sensitive data from names.nsf in hidden form fields, which allows remote attackers to read the HTML source to obtain sensitive information such as (1) the password hash in the HTTPPassword field, (2) the password change date in the HTTPPasswordChangeDate field, (3) the client platform in the ClntPltfrm field, (4) the client machine name in the ClntMachine field, and (5) the client Lotus Domino release in the ClntBld field, a different vulnerability than CVE-2005-2696.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_domino 6.5
ibm lotus_domino 6.0
ibm lotus_domino 5.0
CVE-2005-2454 MEDIUM

IBM Lotus Notes 6.5.4 and 6.5.5, and 7.0.0 and 7.0.1, uses insecure default permissions (Everyone/Full Control) for the "Notes" folder and all children, which allows local users to gain privileges and modify, add, or delete files in that folder.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm lotus_notes 6.5.5
ibm lotus_notes 7.0.1
ibm lotus_notes 6.5.4
ibm lotus_notes 7.0.0
CVE-2005-2618 HIGH

Multiple stack-based buffer overflows in Autonomy (formerly Verity) KeyView SDK before 9.2.0, as used in Lotus Notes 6.5.4 and 7.0, allow remote attackers to execute arbitrary code via (1) a UUE file containing an encoded file with a long filename handled by uudrdr.dll, (2) a compressed ZIP file with a long filename handled by kvarcve.dll, (3) a TAR archive with a long filename that is extracted to a directory with a long path handled by the TAR reader (tarrdr.dll), (4) an email that contains a long HTTP, FTP, or // link handled by the HTML speed reader (htmsr.dll) or (5) an email containing a crafted long link handled by the HTML speed reader (htmsr.dll).

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
autonomy keyview_filter_sdk *
ibm lotus_notes 6.0.3
ibm lotus_notes 6.0.2
ibm lotus_notes 6.0.5
ibm lotus_notes 7.0
ibm lotus_notes 6.5.2
ibm lotus_notes 6.0.1
ibm lotus_notes 6.5
autonomy keyview_export_sdk *
ibm lotus_notes 6.5.1
ibm lotus_notes 6.5.3
ibm lotus_notes 6.5.4
autonomy keyview_viewer_sdk *
ibm lotus_notes 6.0.4
CVE-2005-2619 HIGH

Directory traversal vulnerability in kvarcve.dll in Autonomy (formerly Verity) KeyView SDK before 9.2.0, as used in Lotus Notes 6.5.4 and 7.0, allows remote attackers to delete arbitrary files via a (1) ZIP, (2) UUE or (3) TAR archive that contains a .. (dot dot) in the filename, which is not properly handled when generating a preview.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-22,

Products Affected

Vendor Product Version
autonomy keyview_filter_sdk *
ibm lotus_notes 6.0.3
ibm lotus_notes 6.0.2
ibm lotus_notes 6.0.5
ibm lotus_notes 7.0
ibm lotus_notes 6.5.2
ibm lotus_notes 6.0.1
ibm lotus_notes 6.5
autonomy keyview_export_sdk *
ibm lotus_notes 6.5.1
ibm lotus_notes 6.5.3
ibm lotus_notes 6.5.4
autonomy keyview_viewer_sdk *
ibm lotus_notes 6.0.4
CVE-2005-2696 MEDIUM

IBM Lotus Notes does not properly restrict access to password hashes in the Notes Address Book (NAB), which allows remote attackers to obtain sensitive information via the (1) password digest field in the Administration tab of a Lotus Notes client, (2) "PasswordDigest" and "HTTPPassword" fields in the document properties in the NAB, or (3) a direct query to the Domino LDAP server, a different vulnerability than CVE-2005-2428.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_notes *
CVE-2005-2712 HIGH

The LDAP server (nldap.exe) in IBM Lotus Domino before 7.0.1, 6.5.5, and 6.5.4 FP2 allows remote attackers to cause a denial of service (crash) via a long bind request, which triggers a null dereference.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_domino 6.0.2.1
ibm lotus_domino 6.5.4
ibm lotus_domino 6.5.1
ibm lotus_domino 6.0.1.3
ibm lotus_domino 6.0.5
ibm lotus_domino 7.0
ibm lotus_domino 6.5
ibm lotus_domino 6.0
ibm lotus_domino 6.0.1.2
ibm lotus_domino 6.5.2
ibm lotus_domino 6.0.4
ibm lotus_domino 6.0.1.1
ibm lotus_domino 6.5.3.1
ibm lotus_domino 6.0.3
ibm lotus_domino 6.5.3
ibm lotus_domino 6.5.2.1
ibm lotus_domino 6.0.2.2
ibm lotus_domino 6.0.1
CVE-2005-2994 MEDIUM

Unspecified vulnerability in the web client for IBM Rational ClearQuest 2002.05.00 and 2002.05.20, and 2003.06.00 through 2003.06.15 before SR5, allows remote attackers to execute XML Style Sheets (XSS).

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm rational_clearquest 6.12
ibm rational_clearquest 5.20
ibm rational_clearquest 6.10
ibm rational_clearquest 5.00
ibm rational_clearquest 6.00
ibm rational_clearquest 6.13
ibm rational_clearquest 6.14
ibm rational_clearquest 6.15
CVE-2005-3015 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Lotus Domino 6.5.2 allows remote attackers to inject arbitrary web script or HTML via the (1) BaseTarget or (2) Src parameters.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_domino_enterprise_server 6.5.2
ibm lotus_domino 6.5.2
CVE-2005-3060 HIGH

Buffer overflow in getconf in IBM AIX 5.2 to 5.3 allows local users to execute arbitrary code via unknown vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 5.2
CVE-2005-3289 LOW

LSCFG in IBM AIX 5.2 and 5.3 does not create temporary files securely, which allows local users to corrupt /etc/passwd and possibly other system files via the trace file.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 5.2
CVE-2005-3396 HIGH

Buffer overflow in the chcons (chcon) command in IBM AIX 5.2 and 5.3, when DEBUG MALLOC is enabled, might allow attackers to execute arbitrary code via a long command line argument.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.3_l
ibm aix 5.1l
ibm aix 5.1
ibm aix 5.3
ibm aix 5.2_l
ibm aix 5.2
ibm aix 5.2.2
CVE-2005-3498 MEDIUM

IBM WebSphere Application Server 5.0.x before 5.02.15, 5.1.x before 5.1.1.8, and 6.x before fixpack V6.0.2.5, when session trace is enabled, records a full URL including the queryString in the trace logs when an application encodes a URL, which could allow attackers to obtain sensitive information.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_application_server *
CVE-2005-3504 HIGH

Buffer overflow in swcons in IBM AIX 5.2, when debug malloc is enabled, allows remote attackers to cause a core dump and possibly execute arbitrary code.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.2_l
ibm aix 5.2
ibm aix 5.2.2
CVE-2005-3567 MEDIUM

slapd daemon in IBM Tivoli Directory Server (ITDS) 5.2.0 and 6.0.0 binds using SASL EXTERNAL, which allows attackers to bypass authentication and modify and delete directory data via unknown attack vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm tivoli_directory_server 5.2.0
ibm tivoli_directory_server 6.0
CVE-2005-3568 LOW

db2fmp process in IBM DB2 Content Manager before 8.2 Fix Pack 10 allows local users to cause a denial of service (CPU consumption) by importing a corrupted Microsoft Excel file, aka "CORRUPTED EXEL FILE WILL CAUSE TEXT SEARCH PROCESS LOOPING."

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm db2_content_manager 8.2
CVE-2005-3569 MEDIUM

INSO service in IBM DB2 Content Manager before 8.2 Fix Pack 10 on AIX allows attackers to cause a denial of service (application crash) via unknown attack vectors involving LZH files.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm db2_content_manager 8.2
CVE-2005-3642 HIGH

IBM Informix Dynamic Database server running on Windows XP with Simple File Sharing enabled, allows remote attackers to bypass authentication and log on to the guest account by supplying an invalid username.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm informix_dynamic_database_server 9.40.uc1
ibm informix_dynamic_database_server 9.40.uc3
ibm informix_dynamic_database_server 9.40.uc2
ibm informix_dynamic_database_server 9.3
CVE-2005-3643 HIGH

IBM DB2 Database server running on Windows XP with Simple File Sharing enabled, allows remote attackers to bypass authentication and log on to the guest account without supplying a password.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm db2_universal_database 8.1.4
ibm db2_universal_database 8.1.9a
ibm db2_universal_database 8.0
ibm db2_universal_database 8.1.6
ibm db2_universal_database 8.1.7
ibm db2_universal_database 8.1.5
ibm db2_universal_database 8.1.8a
ibm db2_universal_database 8.1.6c
ibm db2_universal_database 8.1.9
ibm db2_universal_database 7.2
ibm db2_universal_database 8.1.7b
ibm db2_universal_database 7.1
ibm db2_universal_database 8.1
ibm db2_universal_database 8.1.8
CVE-2005-3749 HIGH

Unspecified "absolute path vulnerabilities" in the diagela command (diagela.sh) in IBM AIX 5.2 and 5.3 have unknown impact and attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 5.2
CVE-2005-3760 HIGH

Double free vulnerability in the BBOORB module in IBM WebSphere Application Server for z/OS 5.0 allows attackers to cause a denial of service (ABEND).

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm websphere_application_server 5.0
CVE-2005-4068 HIGH

Unspecified "absolute path vulnerability" in umountall in IBM AIX 5.1 through 5.3 allows local users to cause unknown impact via unknown vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.1
ibm aix 5.3
ibm aix 5.2
CVE-2005-4271 HIGH

Buffer overflow in the malloc debug system in IBM AIX 5.3 allows local users to execute arbitrary code.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.3_l
ibm aix 5.3
CVE-2005-4272 HIGH

Multiple buffer overflows in IBM AIX 5.1, 5.2, and 5.3 allow remote attackers to execute arbitrary code via (1) muxatmd and (2) slocal.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.3_l
ibm aix 5.1l
ibm aix 5.1
ibm aix 5.3
ibm aix 5.2_l
ibm aix 5.2
ibm aix 5.2.2
CVE-2005-4273 LOW

Multiple unspecified vulnerabilities in (1) getShell and (2) getCommand in IBM AIX 5.3 allow local users to append to arbitrary files.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm aix 5.3_l
ibm aix 5.3
CVE-2005-4413 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in sample scripts in IBM WebSphere Application Server 6 allow remote attackers to inject arbitrary web script or HTML via the (1) E-mail address field to (a) PlantsByWebSphere/login.jsp, (2) message field to (b) TechnologySample/BulletinBoard Script, (3) Email address field to (c) TechnologySamples/Subscription, and the (4) Movie Name, (5) Movie Reviewer, and (6) Movie Review fields to (d) TechnologySamples/MovieReview2_1.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.0
CVE-2005-4735 MEDIUM

IBM DB2 Universal Database (UDB) 810 before 8.1 FP10 allows remote authenticated users to cause a denial of service (application crash) via (1) certain equality predicates that trigger self-removal, aka IY70808; and (2) a query with more than 32000 elements in the IN-list, aka LI70817.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm db2_universal_database 8.1.4
ibm db2_universal_database 8.1.9a
ibm db2_universal_database 8.0
ibm db2_universal_database 8.1.6
ibm db2_universal_database 8.1.7
ibm db2_universal_database 8.1.5
ibm db2_universal_database 8.1.8a
ibm db2_universal_database 8.1.6c
ibm db2_universal_database 8.1.9
ibm db2_universal_database 8.1.7b
ibm db2_universal_database 8.1
ibm db2_universal_database 8.1.8
CVE-2005-4736 MEDIUM

IBM DB2 Universal Database (UDB) 820 before 8.2 FP10 allows remote authenticated users to cause a denial of service (disk consumption) via a hash join (hsjn) that triggers an infinite loop in sqlri_hsjnFlushBlocks.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm db2_universal_database 8.1.4
ibm db2_universal_database 8.1.9a
ibm db2_universal_database 8.0
ibm db2_universal_database 8.1.6
ibm db2_universal_database 8.1.7
ibm db2_universal_database 8.1.5
ibm db2_universal_database 8.1.8a
ibm db2_universal_database 8.1.6c
ibm db2_universal_database 8.1.9
ibm db2_universal_database 8.1.7b
ibm db2_universal_database 8.1
ibm db2_universal_database 8.1.8
CVE-2005-4737 HIGH

IBM DB2 Universal Database (UDB) 820 before ESE AIX 5765F4100 allows remote authenticated users to cause a denial of service (CPU consumption) by "abnormally" terminating a connection, which prevents db2agents from being properly cleared.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm db2_universal_database 8.1.4
ibm db2_universal_database 8.1.9a
ibm db2_universal_database 8.0
ibm db2_universal_database 8.1.6
ibm db2_universal_database 8.1.7
ibm db2_universal_database 8.1.5
ibm db2_universal_database 8.1.8a
ibm db2_universal_database 8.1.6c
ibm db2_universal_database 8.1.9
ibm db2_universal_database 8.1.7b
ibm db2_universal_database 8.1
ibm db2_universal_database 8.1.8
CVE-2005-4738 MEDIUM

IBM DB2 Universal Database (UDB) 810 before ESE AIX 5765F4100 does not ensure that a user has execute privileges before permitting object creation based on routines, which allows remote authenticated users to gain privileges.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm db2_universal_database 8.1.4
ibm db2_universal_database 8.1.9a
ibm db2_universal_database 8.0
ibm db2_universal_database 8.1.6
ibm db2_universal_database 8.1.7
ibm db2_universal_database 8.1.5
ibm db2_universal_database 8.1.8a
ibm db2_universal_database 8.1.6c
ibm db2_universal_database 8.1.9
ibm db2_universal_database 8.1.7b
ibm db2_universal_database 8.1
ibm db2_universal_database 8.1.8
CVE-2005-4739 MEDIUM

IBM DB2 Universal Database (UDB) 820 before version 8 FixPak 10 (s050811) allows remote authenticated users to cause a denial of service (application crash) by using a table function for an instance of snapshot_tbreorg, which triggers a trap in sqlnr_EStoE_action.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm db2_universal_database 8.1.4
ibm db2_universal_database 8.1.9a
ibm db2_universal_database 8.0
ibm db2_universal_database 8.1.6
ibm db2_universal_database 8.1.7
ibm db2_universal_database 8.1.5
ibm db2_universal_database 8.1.8a
ibm db2_universal_database 8.1.6c
ibm db2_universal_database 8.1.9
ibm db2_universal_database 8.1.7b
ibm db2_universal_database 8.1
ibm db2_universal_database 8.1.8
CVE-2005-4819 MEDIUM

Cross-site scripting (XSS) vulnerability in Lotus Domino versions before 6.5.4 fix pack 1 (FP1) and versions before 7.0 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_domino 6.5.4
ibm lotus_domino 6.0.5
ibm lotus_domino 6.5.4.3
ibm lotus_domino 6.5.4.1
ibm lotus_domino 6.5.4.2
CVE-2005-4833 MEDIUM

IBM WebSphere Application Server (WAS) 6.0 before 20050201, when serving pages in an Application WAR or an Extended Document Root, allows remote attackers to obtain the JSP source code and other sensitive information via "a specific JSP URL," related to lack of normalization of the URL format.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.0
CVE-2005-4834 MEDIUM

IBM WebSphere Application Server (WAS) 5.0.2.5 through 5.1.1.3 allows remote attackers to obtain JSP source code and other sensitive information, related to incorrect request processing by the web container.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_application_server 5.1.1
ibm websphere_application_server 5.1.1.3
ibm websphere_application_server 5.1.0.3
ibm websphere_application_server 5.1.1.2
ibm websphere_application_server 5.0.2.6
ibm websphere_application_server 5.1.0
ibm websphere_application_server 5.0.2.8
ibm websphere_application_server 5.1.0.2
ibm websphere_application_server 5.1.0.5
ibm websphere_application_server 5.0.2.7
ibm websphere_application_server 5.0.2.9
ibm websphere_application_server 5.0.2.5
ibm websphere_application_server 5.1.0.4
CVE-2005-4863 HIGH

Stack-based buffer overflow in db2fmp in IBM DB2 7.x and 8.1 allows local users to execute arbitrary code via a long parameter.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm db2_universal_database 7.2
ibm db2_universal_database 7.1
ibm db2_universal_database 7.0
ibm db2_universal_database 8.1
CVE-2005-4864 HIGH

Stack-based buffer overflow in libdb2.so in IBM DB2 7.x and 8.1 allows local users to execute arbitrary code via a long DB2LPORT environment variable.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm db2_universal_database 7.2
ibm db2_universal_database 8.0
ibm db2_universal_database 7.1
ibm db2_universal_database 7.0
ibm db2_universal_database 8.1
CVE-2005-4865 HIGH

Stack-based buffer overflow in call in IBM DB2 7.x and 8.1 allows remote attackers to execute arbitrary code via a long libname.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm db2_universal_database 7.2
ibm db2_universal_database 8.0
ibm db2_universal_database 7.1
ibm db2_universal_database 7.0
ibm db2_universal_database 8.1
CVE-2005-4866 MEDIUM

Stack-based buffer overflow in JDBC Applet Server in IBM DB2 8.1 allows remote attackers to execute arbitrary by connecting and sending a long username, then disconnecting gracefully and reconnecting and sending a short username and an unexpected db2java.zip version, which causes a null terminator to be removed and leads to the overflow.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm db2_universal_database 7.2
ibm db2_universal_database 8.0
ibm db2_universal_database 7.1
ibm db2_universal_database 7.0
ibm db2_universal_database 8.1
CVE-2005-4867 HIGH

Stack-based buffer overflow in the SATENCRYPT function in IBM DB2 8.1, when Satellite Administration (SATADMIN) is enabled, allows remote attackers to execute arbitrary code via a long parameter.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm db2_universal_database 7.2
ibm db2_universal_database 8.0
ibm db2_universal_database 7.1
ibm db2_universal_database 7.0
ibm db2_universal_database 8.1
CVE-2005-4868 LOW

Shared memory sections and events in IBM DB2 8.1 have default permissions of read and write for the Everyone group, which allows local users to gain unauthorized access, gain sensitive information, such as cleartext passwords, and cause a denial of service.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.1 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H 1.8 5.2

CVSS 2.0

Severity: LOW

Problem Type: CWE-732,

Products Affected

Vendor Product Version
ibm db2_universal_database 7.2
ibm db2_universal_database 8.0
ibm db2_universal_database 7.1
ibm db2_universal_database 8.1
CVE-2005-4869 LOW

The (1) to_char and (2) to_date function in IBM DB2 8.1 allows local users to cause a denial of service (application crash) via an empty string in the second parameter, which causes a null pointer dereference.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm db2 8.1
CVE-2005-4870 MEDIUM

Stack-based buffer overflows in the (1) xmlvarcharfromfile, (2) xmlclobfromfile, (3) xmlfilefromvarchar, and (4) xmlfilefromclob function calls in IBM DB2 8.1 allow remote attackers to execute arbitrary code via a 94-byte second argument, which causes the return address to be overwritten with a pointer to the argument.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm db2 8.1
CVE-2005-4871 MEDIUM

Certain XML functions in IBM DB2 8.1 run with the privileges of DB2 instead of the logged-in user, which allows remote attackers to create or overwrite files via (1) XMLFileFromVarchar or (2) XMLFileFromClob, or read files via (3) XMLVarcharFromFile or (4) XMLClobFromFile.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm db2 8.1
CVE-2006-0117 MEDIUM

Buffer overflow in IBM Lotus Notes and Domino Server before 6.5.5 allows attackers to cause a denial of service (router crash or hang) via unspecified vectors involving "CD to MIME Conversion".

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_domino 6.5.4
ibm lotus_domino 6.5.1
ibm lotus_domino_enterprise_server 6.5.2
ibm lotus_domino 6.5.0
ibm lotus_domino 6.5.2
ibm lotus_notes 6.5.2
ibm lotus_notes 6.5
ibm lotus_notes 6.5.1
ibm lotus_notes 6.5.3
ibm lotus_domino 6.5.3
ibm lotus_notes 6.5.4
ibm lotus_domino_enterprise_server 6.5.4
CVE-2006-0118 MEDIUM

Unspecified vulnerability in IBM Lotus Notes and Domino Server before 6.5.5, when running on AIX, allows attackers to cause a denial of service (deep recursion leading to stack overflow and crash) via long formulas.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_domino 6.5.4
ibm lotus_domino 6.5.1
ibm lotus_domino_enterprise_server 6.5.2
ibm lotus_domino 6.5.0
ibm lotus_domino 6.5.2
ibm lotus_notes 6.5.2
ibm lotus_notes 6.5
ibm lotus_notes 6.5.1
ibm lotus_notes 6.5.3
ibm lotus_domino 6.5.3
ibm lotus_notes 6.5.4
ibm lotus_domino_enterprise_server 6.5.4
CVE-2006-0119 HIGH

Multiple unspecified vulnerabilities in IBM Lotus Notes and Domino Server before 6.5.5 have unknown impact and attack vectors, due to "potential security issues" as identified by SPR numbers (1) GPKS6C9J67 in Agents, (2) JGAN6B6TZ3 and (3) KSPR699NBP in the Router, (4) GPKS5YQGPT in Security, or (5) HSAO6BNL6Y in the Web Server. NOTE: vector 3 is related to an issue in NROUTER in IBM Lotus Notes and Domino Server before 6.5.4 FP1, 6.5.5, and 7.0, which allows remote attackers to cause a denial of service (CPU consumption) via a crafted vCal meeting request sent via SMTP (aka SPR# KSPR699NBP).

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm lotus_domino 6.5.4
ibm lotus_domino 6.5.1
ibm lotus_domino_enterprise_server 6.5.2
ibm lotus_domino 6.5.0
ibm lotus_domino 6.5.2
ibm lotus_notes 6.5.2
ibm lotus_notes 6.5
ibm lotus_notes 6.5.1
ibm lotus_notes 6.5.3
ibm lotus_domino 6.5.3
ibm lotus_notes 6.5.4
ibm lotus_domino_enterprise_server 6.5.4
CVE-2006-0120 MEDIUM

Multiple unspecified vulnerabilities in IBM Lotus Notes and Domino Server before 6.5.5 allow attackers to cause a denial of service (application crash) via multiple vectors, involving (1) a malformed message sent to an "Out Of Office" agent (SPR LPEE6DMQWJ), (2) the compact command (RTIN5U2SAJ), (3) malformed bitmap images (MYAA6FH5HW), (4) the "Delete Attachment" action (YPHG6844LD), (5) parsing certificates from a remote Certificate Table (AELE6DZFJW), and (6) creating a SSL key ring with the Domino Administration client (NSUA4FQPTN).

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_domino 6.5.4
ibm lotus_domino 6.5.1
ibm lotus_domino_enterprise_server 6.5.2
ibm lotus_domino 6.5.0
ibm lotus_domino 6.5.2
ibm lotus_notes 6.5.2
ibm lotus_notes 6.5
ibm lotus_notes 6.5.1
ibm lotus_notes 6.5.3
ibm lotus_domino 6.5.3
ibm lotus_notes 6.5.4
ibm lotus_domino_enterprise_server 6.5.4
CVE-2006-0121 HIGH

Multiple memory leaks in IBM Lotus Notes and Domino Server before 6.5.5 allow attackers to cause a denial of service (memory consumption and crash) via unknown vectors related to (1) unspecified vectors during the SSL handshake (SPR# MKIN67MQVW), (2) the stash file during the SSL handshake (SPR# MKIN693QUT), and possibly other vectors. NOTE: due to insufficient information in the original vendor advisory, it is not clear whether there is an attacker role in other memory leaks that are specified in the advisory.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_domino 6.5.4
ibm lotus_domino 6.5.1
ibm lotus_domino_enterprise_server 6.5.2
ibm lotus_domino 6.5.0
ibm lotus_domino 6.5.2
ibm lotus_notes 6.5.2
ibm lotus_notes 6.5
ibm lotus_notes 6.5.1
ibm lotus_notes 6.5.3
ibm lotus_domino 6.5.3
ibm lotus_notes 6.5.4
ibm lotus_domino_enterprise_server 6.5.4
CVE-2006-0133 LOW

Multiple directory traversal vulnerabilities in AIX 5.3 ML03 allow local users to determine the existence of files and read partial contents of certain files via a .. (dot dot) in the argument to (1) getCommand.new (aka getCommand) and (2) getShell, a different vulnerability than CVE-2005-4273.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.3_ml03
CVE-2006-0513 MEDIUM

Directory traversal vulnerability in pkmslogout in Tivoli Web Server Plug-in 5.1.0.10 in Tivoli Access Manager (TAM) 5.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm tivoli_access_manager_for_e-business 6.0.0
ibm tivoli_access_manager_for_e-business 5.1.0.10
CVE-2006-0580 MEDIUM

IBM Lotus Domino Server 7.0 allows remote attackers to cause a denial of service (segmentation fault) via a crafted packet to the LDAP port (389/TCP).

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_domino_server 7.0
CVE-2006-0662 MEDIUM

Cross-site scripting (XSS) vulnerability in Lotus Domino iNotes Client 6.5.4 allows remote attackers to inject arbitrary web script or HTML via email with attached html files, which are directly rendered in the browser.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_domino_inotes_client 6.5.4
CVE-2006-0663 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in Lotus Domino iNotes Client 6.5.4 and 7.0 allow remote attackers to inject arbitrary web script or HTML via (1) an email subject; (2) an encoded javascript URI, as demonstrated using "java
script:"; or (3) when the Domino Web Access ActiveX control is not installed, via an email attachment filename.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm lotus_domino_inotes_client 7.0
ibm lotus_domino_inotes_client 6.5.4
CVE-2006-0666 MEDIUM

Unspecified vulnerability in the (1) unix_mp and (2) unix_64 kernels in IBM AIX 5.3 VRMF 5.3.0.30 through 5.3.0.33 allows local users to cause a denial of service (system crash) via unknown vectors related to EMULATE_VMX.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.3_l
ibm aix 5.3
CVE-2006-0667 MEDIUM

lscfg in IBM AIX 5.2 and 5.3 allows local users to modify arbitrary files via a symlink attack.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 5.2
CVE-2006-0674 MEDIUM

Buffer overflow in the arp command of IBM AIX 5.3 L, 5.3, 5.2.2, 5.2 L, and 5.2 allows local users to cause a denial of service (crash) via a long iftype argument.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.3_l
ibm aix 5.3
ibm aix 5.2_l
ibm aix 5.2
ibm aix 5.2.2
CVE-2006-0717 MEDIUM

IBM Tivoli Directory Server 6.0 allows remote attackers to cause a denial of service (crash) via a crafted LDAP request, as demonstrated by test 2532 in the ProtoVer Sample LDAP test suite.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm tivoli_directory_server 6.0
CVE-2006-1093 MEDIUM

Unspecified vulnerability in IBM WebSphere 5.0.2.10 through 5.0.2.15 and 5.1.1.4 through 5.1.1.9 allows remote attackers to obtain sensitive information via unknown attack vectors, which causes JSP source code to be revealed.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_application_server 5.1.1
ibm websphere_application_server 5.0.2.4
ibm websphere_application_server 5.1.1.2
ibm websphere_application_server 5.0.2.6
ibm websphere_application_server 5.0.2.10
ibm websphere_application_server 5.1.1.6
ibm websphere_application_server 5.0.2.11
ibm websphere_application_server 5.0.2.1
ibm websphere_application_server 5.0.2.7
ibm websphere_application_server 5.0.2.9
ibm websphere_application_server 5.0.2.5
ibm websphere_application_server 5.0.2.14
ibm websphere_application_server 5.1.1.7
ibm websphere_application_server 5.1.1.1
ibm websphere_application_server 5.1.1.3
ibm websphere_application_server 5.0.2.3
ibm websphere_application_server 5.0.2.12
ibm websphere_application_server 5.1.1.5
ibm websphere_application_server 5.1.1.9
ibm websphere_application_server 5.0.2.2
ibm websphere_application_server 5.0.2.13
ibm websphere_application_server 5.0.2.8
ibm websphere_application_server 5.0.2
ibm websphere_application_server 5.1.1.8
ibm websphere_application_server 5.1.1.4
CVE-2006-1246 HIGH

Unspecified vulnerability in mklvcopy in BOS.RTE.LVM in IBM AIX 5.3 allows local users to execute arbitrary commands when mklvcopy calls external commands, possibly due to an untrusted search path vulnerability.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm aix 5.3
CVE-2006-1247 LOW

rm_mlcache_file in bos.rte.install in AIX 5.1.0 through 5.3.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files.

CVSS 2.0

Severity: LOW

Problem Type: CWE-59,

Products Affected

Vendor Product Version
ibm aix 5.3_l
ibm aix 5.1l
ibm aix 5.1
ibm aix 5.3.0.10
ibm aix 5.2
ibm aix 5.3.0.20
ibm aix 5.3_ml03
ibm aix 5.3.0
ibm aix 5.3
ibm aix 5.2_l
ibm aix 5.2.0.54
ibm aix 5.2.2
ibm aix 5.2.0.50
CVE-2006-1384 MEDIUM

Cross-site scripting (XSS) vulnerability in apwc_win_main.jsp in the web console in IBM Tivoli Business Systems Manager (TBSM) before 3.1.0.1 allows remote attackers to inject arbitrary web script or HTML via the skin parameter.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm tivoli_business_systems_manager 3.1
CVE-2006-1619 MEDIUM

IBM WebSphere Application Server 4.0.1 through 4.0.3 allows remote attackers to cause a denial of service (application crash) via an HTTP request with a large header.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_application_server 4.0.2
ibm websphere_application_server 4.0.1
ibm websphere_application_server 4.0.3
CVE-2006-1948 MEDIUM

The "Add Sender to Address Book" operation (AddSenderToAddressBook.lss) and NameHelper.lss in IBM Lotus Notes 6.0 and 6.5 before 20060331 do not properly store information in the Personal Address Book when multiple messages are checked and a message uses AltFrom, which might allow user-assisted remote attackers to trick a user into sending e-mail to an unauthorized recipient.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_notes 6.5
ibm lotus_notes 6.0
CVE-2006-2342 HIGH

IBM WebSphere Application Server 6.0.2 before FixPack 3 allows remote attackers to bypass authentication for the Welcome Page via a request to the default context root.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.0.2
CVE-2006-2429 HIGH

Unspecified vulnerability in IBM WebSphere Application Server 6.0.2, 6.0.2.1, 6.0.2.3, 6.0.2.5, and 6.0.2.7 has unknown impact and remote attack vectors related to "HTTP request handlers".

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.0.2.3
ibm websphere_application_server 6.0.2
ibm websphere_application_server 6.0.2.7
ibm websphere_application_server 6.0.2.1
ibm websphere_application_server 6.0.2.5
CVE-2006-2430 HIGH

IBM WebSphere Application Server 5.0.2 and earlier, 5.1.1 and earlier, and 6.0.2 up to 6.0.2.7 records user credentials in plaintext in addNode.log, which allows attackers to gain privileges.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_application_server 5.1.1
ibm websphere_application_server 6.0.2.2
ibm websphere_application_server 6.0.2.6
ibm websphere_application_server 6.0.2.7
ibm websphere_application_server 5.0.1
ibm websphere_application_server 6.0.2.5
ibm websphere_application_server 6.0.2.4
ibm websphere_application_server 5.1.0
ibm websphere_application_server 6.0.2.3
ibm websphere_application_server 5.0.0
ibm websphere_application_server 6.0.2
ibm websphere_application_server 5.0.2
ibm websphere_application_server 6.0.2.1
CVE-2006-2431 MEDIUM

Cross-site scripting (XSS) vulnerability in the 500 Internal Server Error page on the SOAP port (8880/tcp) in IBM WebSphere Application Server 5.0.2 and earlier, 5.1.x before 5.1.1.12, and 6.0.2 up to 6.0.2.7, allows remote attackers to inject arbitrary web script or HTML via the URI, which is contained in a FAULTACTOR element on this page. NOTE: some sources have reported the element as "faultfactor," but this is likely erroneous.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_application_server 5.1.1
ibm websphere_application_server 6.0.2.2
ibm websphere_application_server 5.1.1.1
ibm websphere_application_server 5.1.0.3
ibm websphere_application_server 6.0.2.6
ibm websphere_application_server 6.0.2.7
ibm websphere_application_server 5.0.1
ibm websphere_application_server 6.0.2.5
ibm websphere_application_server 6.0.2.4
ibm websphere_application_server 5.1.0
ibm websphere_application_server 6.0.2.3
ibm websphere_application_server 5.0.0
ibm websphere_application_server 5.1.1.11
ibm websphere_application_server 6.0.2
ibm websphere_application_server 5.0.2
ibm websphere_application_server 5.1.0.2
ibm websphere_application_server 5.1.0.5
ibm websphere_application_server 5.1.1.10
ibm websphere_application_server 6.0.2.1
ibm websphere_application_server 5.1.0.4
CVE-2006-2432 HIGH

IBM WebSphere Application Server 5.0.2 (or any earlier cumulative fix) and 5.1.1 (or any earlier cumulative fix) allows EJB access on Solaris systems via a crafted LTPA token.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_application_server 5.1.1
ibm websphere_application_server 5.1.0
ibm websphere_application_server 5.0.0
ibm websphere_application_server 5.0.2
ibm websphere_application_server 5.0.1
CVE-2006-2433 HIGH

Unspecified vulnerability in IBM WebSphere Application Server 6.0.2, 6.0.2.1, 6.0.2.3, 6.0.2.5, and 6.0.2.7 has unknown impact and attack vectors related to the "administrative console".

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.0.2.3
ibm websphere_application_server 6.0.2
ibm websphere_application_server 6.0.2.7
ibm websphere_application_server 6.0.2.1
ibm websphere_application_server 6.0.2.5
CVE-2006-2434 MEDIUM

Unspecified vulnerability in WebSphere 5.1.1 (or any earlier cumulative fix) Common Configuration Mode + CommonArchive and J2EE Models might allow attackers to obtain sensitive information via the trace.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_application_server 5.1.1
CVE-2006-2435 MEDIUM

Unspecified vulnerability in IBM WebSphere Application Server 5.0.2 and earlier, and 5.1.1 and earlier, has unknown impact and attack vectors related to "Inserting certain script tags in urls [that] may allow unintended execution of scripts."

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_application_server 5.1.1
ibm websphere_application_server 5.1.0
ibm websphere_application_server 5.0.0
ibm websphere_application_server 5.0.2
ibm websphere_application_server 5.0.1
CVE-2006-2436 HIGH

WebSphere Application Server 5.0.2 (or any earlier cumulative fix) stores admin and LDAP passwords in plaintext in the FFDC logs when a login to WebSphere fails, which allows attackers to gain privileges.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_application_server 5.0.0
ibm websphere_application_server 5.0.2
ibm websphere_application_server 5.0.1
CVE-2006-2647 HIGH

Untrusted search path vulnerability in update_flash for IBM AIX 5.1, 5.2 and 5.3 allows local users to execute arbitrary commands via unknown vectors involving lsmcode and possibly other commands.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.1
ibm aix 5.3
ibm aix 5.2
CVE-2006-3066 MEDIUM

Buffer overflow in the TCP/IP listener in IBM DB2 Universal Database (UDB) before 8.1 FixPak 12 allows remote attackers to cause a denial of service (application crash) via a long MGRLVLLS message inside of an EXCSAT message when establishing a connection.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm db2_universal_database 8.1.4
ibm db2_universal_database 8.1.9a
ibm db2_universal_database 8.0
ibm db2_universal_database 8.1.6
ibm db2_universal_database 8.1.7
ibm db2_universal_database 8.1.5
ibm db2_universal_database 8.1.8a
ibm db2_universal_database 8.1.6c
ibm db2_universal_database 8.1.9
ibm db2_universal_database *
ibm db2_universal_database 8.1.7b
ibm db2_universal_database 8.1
ibm db2_universal_database 8.1.8
CVE-2006-3067 MEDIUM

Multiple unspecified vulnerabilities in IBM DB2 Universal Database (UDB) before 8.1 FixPak 12 allow remote attackers to cause a denial of service (application crash) via a (1) "long column list" in the (a) REPLACE INTO and (b) INSERT INTO portions of the LOAD command or a (2) large number of values in an IN clause, possibly related to a buffer overflow.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm db2_universal_database *
ibm db2_universal_database 8.0
ibm db2_universal_database 8.1
CVE-2006-3068 MEDIUM

IBM DB2 Universal Database (UDB) before 8.2 FixPak 12 allows remote attackers to cause a denial of service (application crash) by sending "incorrect information ... regarding the package name/creator," which leads to a "memory overwrite."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm db2_universal_database 8.1
CVE-2006-3231 MEDIUM

Unspecified vulnerability in IBM WebSphere Application Server (WAS) before 6.0.2.11, when fileServingEnabled is true, allows remote attackers to obtain JSP source code and other sensitive information via "URIs with special characters."

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_application_server 3.5.2
ibm websphere_application_server 3.5.1
ibm websphere_application_server 5.0.2.6
ibm websphere_application_server 3.0.2.2
ibm websphere_application_server 3.0.2.1
ibm websphere_application_server 5.1.0.2
ibm websphere_application_server 5.1.1.10
ibm websphere_application_server 5.0.2.14
ibm websphere_application_server 3.0
ibm websphere_application_server 5.0.2.16
ibm websphere_application_server 5.0
ibm websphere_application_server 6.0.2.9
ibm websphere_application_server 5.0.2.12
ibm websphere_application_server 5.1.1.5
ibm websphere_application_server 5.1.1.9
ibm websphere_application_server 5.0.2.2
ibm websphere_application_server 6.0
ibm websphere_application_server 5.0.2.8
ibm websphere_application_server 5.0.2
ibm websphere_application_server 5.1.1.8
ibm websphere_application_server 5.1.0.4
ibm websphere_application_server 5.1.1
ibm websphere_application_server 3.0.2
ibm websphere_application_server 3.5
ibm websphere_application_server 5.0.2.4
ibm websphere_application_server 5.1.1.2
ibm websphere_application_server 4.0.4
ibm websphere_application_server 5.0.1
ibm websphere_application_server 5.0.2.15
ibm websphere_application_server 3.0.2.3
ibm websphere_application_server 5.0.2.10
ibm websphere_application_server 5.1.1.6
ibm websphere_application_server 2.0
ibm websphere_application_server 5.0.2.11
ibm websphere_application_server 5.0.2.1
ibm websphere_application_server 5.0.2.7
ibm websphere_application_server 4.0.3
ibm websphere_application_server 5.0.2.9
ibm websphere_application_server 5.0.2.5
ibm websphere_application_server 5.1.1.7
ibm websphere_application_server 5.1.1.1
ibm websphere_application_server 5.1.1.3
ibm websphere_application_server 5.0.2.3
ibm websphere_application_server 3.0.2.4
ibm websphere_application_server 5.1.0
ibm websphere_application_server 5.0.2.13
ibm websphere_application_server 3.5.3
ibm websphere_application_server 6.0.2
ibm websphere_application_server 5.1.0.5
ibm websphere_application_server 5.1.1.4
CVE-2006-3232 HIGH

Unspecified vulnerability in IBM WebSphere Application Server before 6.0.2.11 has unknown impact and attack vectors because the "UserNameToken cache was improperly used."

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_application_server 3.5.2
ibm websphere_application_server 3.5.1
ibm websphere_application_server 5.0.2.6
ibm websphere_application_server 3.0.2.2
ibm websphere_application_server 3.0.2.1
ibm websphere_application_server 5.1.0.2
ibm websphere_application_server 5.1.1.10
ibm websphere_application_server 5.0.2.14
ibm websphere_application_server 3.0
ibm websphere_application_server 5.0.2.16
ibm websphere_application_server 5.0
ibm websphere_application_server 6.0.2.9
ibm websphere_application_server 5.0.2.12
ibm websphere_application_server 5.1.1.5
ibm websphere_application_server 5.1.1.9
ibm websphere_application_server 5.0.2.2
ibm websphere_application_server 6.0
ibm websphere_application_server 5.0.2.8
ibm websphere_application_server 5.0.2
ibm websphere_application_server 5.1.1.8
ibm websphere_application_server 5.1.0.4
ibm websphere_application_server 5.1.1
ibm websphere_application_server 3.0.2
ibm websphere_application_server 3.5
ibm websphere_application_server 5.0.2.4
ibm websphere_application_server 5.1.1.2
ibm websphere_application_server 4.0.4
ibm websphere_application_server 5.0.1
ibm websphere_application_server 5.0.2.15
ibm websphere_application_server 3.0.2.3
ibm websphere_application_server 5.0.2.10
ibm websphere_application_server 5.1.1.6
ibm websphere_application_server 2.0
ibm websphere_application_server 5.0.2.11
ibm websphere_application_server 5.0.2.1
ibm websphere_application_server 5.0.2.7
ibm websphere_application_server 4.0.3
ibm websphere_application_server 5.0.2.9
ibm websphere_application_server 5.0.2.5
ibm websphere_application_server 5.1.1.7
ibm websphere_application_server 5.1.1.1
ibm websphere_application_server 5.1.1.3
ibm websphere_application_server 5.0.2.3
ibm websphere_application_server 3.0.2.4
ibm websphere_application_server 5.1.0
ibm websphere_application_server 5.0.2.13
ibm websphere_application_server 3.5.3
ibm websphere_application_server 6.0.2
ibm websphere_application_server 5.1.0.5
ibm websphere_application_server 5.1.1.4
CVE-2006-3569 MEDIUM

Unspecified vulnerability in NetApp Data ONTAP 7.0x through 7.0.4P8D9, 7.1x, 7.1.0.1x, and 7.2RC1, RC2, and RC3, as used in IBM N series Filers and other products, allows unauthorized users to gain access to privileged commands via unknown vectors, probably related to incorrect capabilities with the audit role.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm network_appliance_data_ontap 7.0
ibm network_appliance_data_ontap 7.0.4p8d9
ibm network_appliance_data_ontap 7.1
ibm network_appliance_data_ontap 7.2
ibm network_appliance_data_ontap 7.1.0.1
CVE-2006-3778 MEDIUM

IBM Lotus Notes 6.0, 6.5, and 7.0 does not properly handle replies to e-mail messages with alternate name users when the (1) "Save As Draft" option is used or (2) a "," (comma) is inside the "phrase" portion of an address, which can cause the e-mail to be sent to users that were deleted from the To, CC, and BCC fields, which allows remote attackers to obtain the list of original recipients.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_notes 6.5
ibm lotus_notes 7.0
ibm lotus_notes 6.0
CVE-2006-3853 MEDIUM

Buffer overflow in IBM Informix Dynamic Server (IDS) before 9.40.TC7 and 10.00 before 10.00.TC3, when running on Windows, allows remote attackers to execute arbitrary code via a long username.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm informix_dynamic_server 9.40.uc2
ibm informix_dynamic_server 9.40.xc7
ibm informix_dynamic_server 9.40.uc5
ibm informix_dynamic_server 9.40.uc3
ibm informix_dynamic_server 10.0.xc3
ibm informix_dynamic_server 9.40.tc5
ibm informix_dynamic_server 10.0
ibm informix_dynamic_server 9.40.uc1
ibm informix_dynamic_server 9.4
CVE-2006-3854 HIGH

Buffer overflow in IBM Informix Dynamic Server (IDS) 9.40.TC7, 9.40.TC8, 10.00.TC4, and 10.00.TC5, when running on Windows, allows remote attackers to execute arbitrary code via a long username, which causes an overflow in vsprintf when displaying in the resulting error message. NOTE: this issue is due to an incomplete fix for CVE-2006-3853.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm informix_dynamic_database_server 9.40.tc7
ibm informix_dynamic_database_server 10.00.tc5
ibm informix_dynamic_database_server 10.00.tc4
ibm informix_dynamic_database_server 9.40.tc8
CVE-2006-3855 MEDIUM

The ifx_load_internal function in IBM Informix Dynamic Server (IDS) allows remote authenticated users to execute arbitrary C code via the DllMain or _init function in a library, aka "C code UDR."

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm informix_dynamic_server 9.40.uc2
ibm informix_dynamic_server 9.40.uc5
ibm informix_dynamic_server 9.40.uc3
ibm informix_dynamic_server 10.0.xc3
ibm informix_dynamic_server 9.40.tc5
ibm informix_dynamic_server 10.0
ibm informix_dynamic_server 9.40.uc1
ibm informix_dynamic_server 9.4
CVE-2006-3856 LOW

IBM Informix Dynamic Server (IDS) before 9.40.xC7 and 10.00 before 10.00.xC3 allows local users to cause a denial of service (crash) via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm informix_dynamic_server 9.40.xc5
ibm informix_dynamic_server 9.40.uc2
ibm informix_dynamic_server 10.0.xc1
ibm informix_dynamic_server 9.40.uc5
ibm informix_dynamic_server 9.40.uc3
ibm informix_dynamic_server 9.40.tc5
ibm informix_dynamic_server 10.0
ibm informix_dynamic_server 9.40.uc1
ibm informix_dynamic_server 9.4
CVE-2006-3857 MEDIUM

Multiple buffer overflows in IBM Informix Dynamic Server (IDS) before 9.40.TC6 and 10.00 before 10.00.TC3 allow remote authenticated users to execute arbitrary code via (1) the getname function, as used by (a) _sq_remview, (b) _sq_remproc, (c) _sq_remperms, (d) _sq_distfetch, and (e) _sq_dcatalog; and the (2) SET DEBUG FILE, (3) IFX_FILE_TO_FILE, (4) FILETOCLOB, (5) LOTOFILE, and (6) DBINFO functions (product defect IDs 171649, 171367, 171387, 171391, 171906, 172179).

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm informix_dynamic_database_server 9.40.tc1
ibm informix_dynamic_database_server 10.00.tc2
ibm informix_dynamic_database_server 9.40.uc1
ibm informix_dynamic_database_server 9.40.tc2
ibm informix_dynamic_database_server 9.40.tc4
ibm informix_dynamic_database_server 9.40.tc5
ibm informix_dynamic_database_server 9.40.uc3
ibm informix_dynamic_database_server 9.40.uc2
ibm informix_dynamic_database_server 10.00.tc1
ibm informix_dynamic_database_server 9.3
ibm informix_dynamic_database_server 9.40.tc3
CVE-2006-3858 LOW

IBM Informix Dynamic Server (IDS) before 9.40.xC8 and 10.00 before 10.00.xC4 stores passwords in plaintext in shared memory, which allows local users to obtain passwords by reading the memory (product defects 171893, 171894, 173772).

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm informix_dynamic_server 9.40.xc5
ibm informix_dynamic_server 9.40.uc2
ibm informix_dynamic_server 9.40.xc7
ibm informix_dynamic_server 10.0.xc1
ibm informix_dynamic_server 9.40.uc5
ibm informix_dynamic_server 9.40.uc3
ibm informix_dynamic_server 10.0.xc3
ibm informix_dynamic_server 9.40.tc5
ibm informix_dynamic_server 10.0
ibm informix_dynamic_server 9.40.uc1
ibm informix_dynamic_server 9.4
CVE-2006-3859 MEDIUM

IBM Informix Dynamic Server (IDS) allows remote authenticated users to create and overwrite arbitrary files via the (1) LOTOFILE and (2) trl_tracefile_set functions, and the (3) "SET DEBUG FILE" commands.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm informix_dynamic_database_server 9.40.tc7
ibm informix_dynamic_database_server 10.00.tc5
ibm informix_dynamic_database_server 10.00.tc4
ibm informix_dynamic_database_server 9.40.tc8
CVE-2006-3860 HIGH

IBM Informix Dynamic Server (IDS) before 9.40.xC7 and 10.00 before 10.00.xC3 allows allows remote authenticated users to execute arbitrary commands via the (1) "SET DEBUG FILE" SQL command, and the (2) start_onpload and (3) dbexp functions.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm informix_dynamic_database_server 9.4
ibm informix_dynamic_database_server 9.40.uc1
ibm informix_dynamic_database_server 9.40.xc7
ibm informix_dynamic_database_server 9.40.tc5
ibm informix_dynamic_database_server 9.40.uc5
ibm informix_dynamic_database_server 10.0
ibm informix_dynamic_database_server 9.40.uc3
ibm informix_dynamic_database_server 10.0_xc3
ibm informix_dynamic_database_server 9.40.uc2
ibm informix_dynamic_database_server 7.31_.xd8
ibm informix_dynamic_database_server 7.3
CVE-2006-3861 MEDIUM

IBM Informix Dynamic Server (IDS) before 9.40.xC7 and 10.00 before 10.00.xC3 does not use database creation permissions, which allows remote authenticated users to create arbitrary databases.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm informix_dynamic_server 9.40.xc5
ibm informix_dynamic_server 9.40.uc2
ibm informix_dynamic_server 10.0.xc1
ibm informix_dynamic_server 9.40.uc5
ibm informix_dynamic_server 9.40.uc3
ibm informix_dynamic_server 9.40.tc5
ibm informix_dynamic_server 10.0
ibm informix_dynamic_server 9.40.uc1
ibm informix_dynamic_server 9.4
ibm informix_dynamic_server 7.31
CVE-2006-3862 HIGH

Buffer overflow in IBM Informix Dynamic Server (IDS) 9.40.TC5 through 9.40.xC7 and 10.00.TC1 through 10.00.xC3 allows attackers to execute arbitrary code via the SQLIDEBUG environment variable (envariable).

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm informix_dynamic_server 9.40.xc5
ibm informix_dynamic_server 10.0.xc1
ibm informix_dynamic_server 9.40.uc5
ibm informix_dynamic_server 10.0.tc1
ibm informix_dynamic_server 9.40.tc5
CVE-2006-4136 HIGH

Multiple unspecified vulnerabilities in IBM WebSphere Application Server before 6.1.0.1 have unspecified impact and attack vectors involving (1) "SOAP requests and responses", (2) mbean, (3) ThreadIdentitySupport, and possibly others.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-200,CWE-264,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.0.2.2
ibm websphere_application_server 6.0.0.1
ibm websphere_application_server 6.0.2.6
ibm websphere_application_server 6.0.1
ibm websphere_application_server 6.0.2.7
ibm websphere_application_server 6.0.0.2
ibm websphere_application_server 6.0.2.5
ibm websphere_application_server 6.0.2.9
ibm websphere_application_server 6.0.2.4
ibm websphere_application_server 6.0.2.3
ibm websphere_application_server *
ibm websphere_application_server 6.0
ibm websphere_application_server 6.0.2
ibm websphere_application_server 6.0.0.3
ibm websphere_application_server 6.0.1.2
ibm websphere_application_server 6.0.2.1
CVE-2006-4137 MEDIUM

IBM WebSphere Application Server before 6.1.0.1 allows attackers to obtain sensitive information via unspecified vectors related to (1) the log file, (2) "script generated syntax on wsadmin command line," and (3) traces.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.0.2.2
ibm websphere_application_server 6.0.0.1
ibm websphere_application_server 6.0.2.6
ibm websphere_application_server 6.0.1
ibm websphere_application_server 6.0.2.7
ibm websphere_application_server 6.0.0.2
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.0.2.5
ibm websphere_application_server 6.0.2.9
ibm websphere_application_server 6.0.2.4
ibm websphere_application_server 6.0.2.3
ibm websphere_application_server 6.0
ibm websphere_application_server 6.0.2
ibm websphere_application_server 6.0.0.3
ibm websphere_application_server 6.0.1.2
ibm websphere_application_server 6.0.2.1
CVE-2006-4221 HIGH

Stack-based buffer overflow in the IBM Access Support eGatherer ActiveX control before 3.20.0284.0 allows remote attackers to execute arbitrary code via a long filename parameter to the RunEgatherer method.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm egatherer 2.0.16
ibm egatherer 2.42.243
CVE-2006-4222 MEDIUM

Multiple unspecified vulnerabilities in IBM WebSphere Application Server before 6.0.2.13 have unspecified vectors and impact, including (1) an "authority problem" in ThreadIdentitySupport as identified by PK25199, and "Potential security exposure" issues as identified by (2) PK22747, (3) PK24334, (4) PK25740, and (5) PK26123.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.0.2.3
ibm websphere_application_server *
ibm websphere_application_server 6.0.2
ibm websphere_application_server 6.0.2.7
ibm websphere_application_server 6.0.2.1
ibm websphere_application_server 6.0.2.5
ibm websphere_application_server 6.0.2.9
CVE-2006-4223 MEDIUM

IBM WebSphere Application Server (WAS) before 6.0.2.13 allows context-dependent attackers to obtain sensitive information via unspecified vectors related to "JSP source code exposure" (PK23475), which occurs when ibm-web-ext.xmi sets fileServingEnabled to true or ExtendedDocumentRoot is used to place a JSP outside a WAR.file; (3) the First Failure Data Capture (ffdc) log file (PK24834); and (4) traces (PK25568), a different issue than CVE-2006-4137.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.0.2.3
ibm websphere_application_server *
ibm websphere_application_server 6.0.2
ibm websphere_application_server 6.0.2.7
ibm websphere_application_server 6.0.2.1
ibm websphere_application_server 6.0.2.5
ibm websphere_application_server 6.0.2.9
CVE-2006-4254 HIGH

Unspecified vulnerability in setlocale in IBM AIX 5.1.0 through 5.3.0 allows local users to gain privileges via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.1
ibm aix 5.3
ibm aix 5.2
CVE-2006-4257 MEDIUM

IBM DB2 Universal Database (UDB) before 8.1 FixPak 13 allows remote authenticated users to cause a denial of service (crash) by (1) sending the first ACCSEC command without an RDBNAM parameter during the CONNECT process, or (2) sending crafted SQLJRA packet, which results in a null dereference.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm db2 8.1.8a
ibm db2 8.1.7b
ibm db2 8.1
ibm db2 8.10
ibm db2 8.2
ibm db2 8.0
ibm db2 8.1.8
ibm db2 8.1.7
ibm db2 8.1.6c
ibm db2 8.1.4
ibm db2 8.1.9a
ibm db2 8.1.6
ibm db2 8.12
ibm db2 8.1.5
ibm db2 8.1.9
CVE-2006-4416 HIGH

Untrusted search path vulnerability in the mkvg command in IBM AIX 5.2 and 5.3 allows local users to gain privileges by modifying the path to point to a malicious (1) chdev, (2) mkboot, (3) varyonvg, or (4) varyoffvg program.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.1
ibm aix 5.3
ibm aix 5.2
CVE-2006-4522 HIGH

Unspecified vulnerability in dtterm in IBM AIX 5.2 and 5.3 allows local users to execute arbitrary code with root privileges via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 5.2
CVE-2006-4681 MEDIUM

Directory traversal vulnerability in Redirect.bat in IBM Director before 5.10 allows remote attackers to read arbitrary files via a .. (dot dot) sequence in the file parameter.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm director *
CVE-2006-4682 MEDIUM

Multiple unspecified vulnerabilities in IBM Director before 5.10 allow remote attackers to cause a denial of service (crash) via unspecified vectors involving (1) malformed WMI CIM server requests and (2) malformed packets.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm director *
CVE-2006-4683 MEDIUM

IBM Director before 5.10 allows remote attackers to obtain sensitive information from HTTP headers via HTTP TRACE.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm director *
CVE-2006-4763 HIGH

IBM Lotus Domino Web Access (DWA) 7.0.1 does not expire a client's Lightweight Third-Party Authentication token (LtpaToken) upon logout, which allows remote attackers to obtain a user's privileges by intercepting the LtpaToken cookie.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_domino_web_access 7.0.1
CVE-2006-4843 MEDIUM

Cross-site scripting (XSS) vulnerability in the Active Content Filter feature in IBM Lotus Domino before 6.5.6 and 7.x before 7.0.2 FP1 allows remote attackers to inject arbitrary web script or HTML via unspecified "code sequences" that bypass the protection scheme.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_domino 6.5.4
ibm lotus_domino 6.5.1
ibm lotus_domino 7.0.2
ibm lotus_domino 7.0
ibm lotus_domino 6.5.5
ibm lotus_domino 6.5.3
ibm lotus_domino 6.5.0
ibm lotus_domino 6.5.2
ibm lotus_domino 7.0.1
CVE-2006-5002 MEDIUM

Unspecified vulnerability in IBM Inventory Scout for AIX 2.2.0.0 through 2.2.0.9 (invscoutClient_VPD_Survey) allows attackers to overwrite arbitrary files via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm inventory_scout 2.2.0.3
ibm inventory_scout 2.2.0.2
ibm inventory_scout 2.2.0.5
ibm inventory_scout 2.2.0.7
ibm inventory_scout 2.2.0.8
ibm inventory_scout 2.2.0.9
ibm inventory_scout 2.2.0.0
ibm inventory_scout 2.2.0.4
ibm inventory_scout 2.2.0.6
ibm inventory_scout 2.2.0.1
CVE-2006-5003 HIGH

Unspecified vulnerability in the named8 command in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary commands via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.3.0
ibm aix 5.2.0
CVE-2006-5004 LOW

Unspecified vulnerability in the rdist command in IBM AIX 5.2.0 and 5.3.0 allows local users to overwrite arbitrary files via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.3.0
ibm aix 5.2.0
CVE-2006-5005 HIGH

Unspecified vulnerability in bos.net.tcp.client in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary commands via unspecified vectors involving /etc/slip.login.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.3.0
ibm aix 5.2.0
CVE-2006-5006 HIGH

Buffer overflow in cfgmgr in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary code via a long directory path argument.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.3.0
ibm aix 5.2.0
CVE-2006-5007 MEDIUM

Untrusted search path vulnerability in uucp in IBM AIX 5.2.0 and 5.3.0 allows local users to local users to gain privileges via a Trojan horse program involving uux.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.3.0
ibm aix 5.2.0
CVE-2006-5008 HIGH

Unspecified vulnerability in utape in IBM AIX 5.2.0 and 5.3.0 allows attackers to execute arbitrary commands and overwrite arbitrary files via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.3.0
ibm aix 5.2.0
CVE-2006-5009 HIGH

Unspecified vulnerability in xlock in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary commands and overwrite arbitrary files via unspecified vectors, possibly involving a buffer overflow.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.3.0
ibm aix 5.2.0
CVE-2006-5010 HIGH

Untrusted search path vulnerability in acctctl in IBM AIX 5.3.0 allows local users to execute arbitrary commands by modifying the path to point to a malicious mkdir program.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.3.0
CVE-2006-5011 HIGH

Untrusted search path vulnerability in snappd in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary commands via a Trojan horse program, involving the "system subroutine".

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.3.0
ibm aix 5.2.0
CVE-2006-5161 MEDIUM

IBM Client Security Password Manager stores and distributes saved passwords based upon the title of a website, which allows remote attackers to obtain username and password credentials by changing the title of an HTML page.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm client_security_password_manager *
CVE-2006-5163 LOW

IBM Informix Dynamic Server 10.UC3RC1 Trial for Linux and possibly other versions creates /tmp/installserver.txt with insecure permissions, which allows local users to append data to arbitrary files via a symlink attack.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm informix_dynamic_server 10.uc_rc1
CVE-2006-5323 HIGH

Unspecified vulnerability in IBM WebSphere Application Server before 6.1.0.2 has unspecified impact and attack vectors, related to a "possible security exposure," aka PK29360.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_application_server *
CVE-2006-5324 HIGH

The Web Services Notification (WSN) security component of IBM WebSphere Application Server before 6.1.0.2 allows attackers to obtain unspecified access without supplying a username and password, aka PK28374.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_application_server *
CVE-2006-5663 MEDIUM

IBM Informix Dynamic Server 10.00, Informix Client Software Development Kit (CSDK) 2.90, and Informix I-Connect 2.90 use insecure permissions for installation scripts, which allows local users to gain privileges by modifying the scripts.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm informix_dynamic_server 10.00
ibm informix_client_sdk 2.90
ibm informix_i-connect 2.90
CVE-2006-5664 MEDIUM

The installation script in IBM Informix Dynamic Server 10.00, Informix Client Software Development Kit (CSDK) 2.90, and Informix I-Connect 2.90 allows local users to "compromise security" via a symlink attack on temporary files.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm informix_dynamic_server 10.00
ibm informix_client_sdk 2.90
ibm informix_i-connect 2.90
CVE-2006-5818 HIGH

Multiple buffer overflows in tunekrnl in IBM Lotus Domino 6.x before 6.5.5 FP2 and 7.x before 7.0.2 allow local users to gain privileges and execute arbitrary code via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_domino 6.5.4
ibm lotus_domino 6.5.1
ibm lotus_domino 6.0.5
ibm lotus_domino 7.0
ibm lotus_domino 6.5
ibm lotus_domino 6.0
ibm lotus_domino 6.0.2_cf2
ibm lotus_domino *
ibm lotus_domino 6.5.2
ibm lotus_domino 6.0.4
ibm lotus_domino 6.0.2
ibm lotus_domino 6.5.5
ibm lotus_domino 6.0.3
ibm lotus_domino 6.5.3
ibm lotus_domino 6.0.1
CVE-2006-5835 MEDIUM

The Notes Remote Procedure Call (NRPC) protocol in IBM Lotus Notes Domino before 6.5.5 FP2 and 7.x before 7.0.2 does not require authentication to perform user lookups, which allows remote attackers to obtain the user ID file.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_notes 5.0.12
ibm lotus_notes 6.0.3
ibm lotus_notes 6.0.2
ibm lotus_notes 6.0.5
ibm lotus_notes 7.0
ibm lotus_notes 6.5.2
ibm lotus_notes 6.0.1
ibm lotus_notes 6.5
ibm lotus_notes 6.5.1
ibm lotus_notes 6.5.5
ibm lotus_notes 6.5.3
ibm lotus_notes 7.0.1
ibm lotus_notes 5.0.3
ibm lotus_notes 6.5.4
ibm lotus_notes 6.0
ibm lotus_notes 6.0.4
CVE-2006-5855 HIGH

Multiple buffer overflows in IBM Tivoli Storage Manager (TSM) before 5.2.9 and 5.3.x before 5.3.4 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in (1) the language field at logon that begins with a 0x18 byte, (2) two unspecified parameters to the SmExecuteWdsfSession function, and (3) the contact field in an open registration message.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager 5.3.1
ibm tivoli_storage_manager 5.2.8
ibm tivoli_storage_manager 5.3.2
ibm tivoli_storage_manager 5.2.7
ibm tivoli_storage_manager 5.3.0
ibm tivoli_storage_manager 5.3.3
CVE-2006-6135 HIGH

Multiple unspecified vulnerabilities in IBM WebSphere Application Server 6.1.0 before Fix Pack 3 (6.1.0.3) have unknown impact and attack vectors, related to (1) a "Potential security vulnerability" (PK29725) and (2) "Potential security exposure" (PK30831).

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0
CVE-2006-6136 HIGH

IBM WebSphere Application Server 6.1.0 before Fix Pack 3 (6.1.0.3) does not perform EAL4 authentication checks at the proper time during "registering of response operation," which has unknown impact and attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0
CVE-2006-6309 HIGH

Multiple array index errors in IBM Tivoli Storage Manager (TSM) before 5.2.9 and 5.3.x before 5.3.4 allow remote attackers to read arbitrary memory locations and cause a denial of service (crash) via a large index value in unspecified messages, a different issue than CVE-2006-5855.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager 5.3.1
ibm tivoli_storage_manager *
ibm tivoli_storage_manager 5.3.2
ibm tivoli_storage_manager 5.3.0
ibm tivoli_storage_manager 5.3.3
CVE-2006-6537 HIGH

IBM WebSphere Host On-Demand 6.0, 7.0, 8.0, 9.0, and possibly 10, allows remote attackers to bypass authentication via a modified pnl parameter, related to hod/HODAdmin.html and hod/frameset.html.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_host_on-demand 7.0
ibm websphere_host_on-demand 8.0
ibm websphere_host_on-demand 9.0
ibm websphere_host_on-demand 6.0
CVE-2006-6607 LOW

The Java Key Store (JKS) for WebSphere Application Server (WAS) for IBM Tivoli Identity Manager (ITIM) 4.6 places the JKS password in a -Djavax.net.ssl.trustStorePassword command line argument, which allows local users to obtain the password by listing the process or using other methods.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm tivoli_identity_manager 4.6
CVE-2006-6636 HIGH

Unspecified vulnerability in the Utility Classes for IBM WebSphere Application Server (WAS) before 5.1.1.13 and 6.x before 6.0.2.17 has unknown impact and attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_application_server 5.1.1
ibm websphere_application_server 5.1.1.7
ibm websphere_application_server 6.0.2.13
ibm websphere_application_server 5.1.1.1
ibm websphere_application_server 6.0.2.11
ibm websphere_application_server 5.1.1.3
ibm websphere_application_server 6.0.2.7
ibm websphere_application_server 5.1.1.2
ibm websphere_application_server 6.0.2.5
ibm websphere_application_server 6.0.2.9
ibm websphere_application_server 5.1.1.12
ibm websphere_application_server 6.0.2.15
ibm websphere_application_server 5.1.1.5
ibm websphere_application_server 5.1.1.6
ibm websphere_application_server 6.0.2.3
ibm websphere_application_server 5.1.1.9
ibm websphere_application_server 5.1.1.8
ibm websphere_application_server 5.1.1.10
ibm websphere_application_server 6.0.2.1
ibm websphere_application_server 5.1.1.4
CVE-2006-6637 MEDIUM

The Servlet Engine and Web Container in IBM WebSphere Application Server (WAS) before 6.0.2.17, when ibm-web-ext.xmi sets fileServingEnabled to true and servlet caching is enabled, allows remote attackers to obtain JSP source code and other sensitive information via "specific requests."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.0.2.13
ibm websphere_application_server 6.0.2.3
ibm websphere_application_server 6.0.2.11
ibm websphere_application_server 6.0.2.7
ibm websphere_application_server 6.0.2.1
ibm websphere_application_server 6.0.2.5
ibm websphere_application_server 6.0.2.9
ibm websphere_application_server 6.0.2.15
CVE-2006-6638 MEDIUM

IBM DB2 8.1 before FixPak 14 allows remote attackers to cause a denial of service via a crafted SQLJRA packet, which causes a NULL pointer dereference in the sqle_db2ra_as_recvrequest function in DB2ENGN.DLL, a different issue than CVE-2006-4257.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm db2_universal_database 8.1.4
ibm db2_universal_database 8.1.9a
ibm db2_universal_database 8.12
ibm db2_universal_database 8.10
ibm db2_universal_database 8.1.6
ibm db2_universal_database 8.1.7
ibm db2_universal_database 8.1.5
ibm db2_universal_database 8.1.8a
ibm db2_universal_database 8.1.6c
ibm db2_universal_database 8.1.9
ibm db2_universal_database 8.1.7b
ibm db2_universal_database 8.1
ibm db2_universal_database 8.1.8
CVE-2006-6836 HIGH

Multiple unspecified vulnerabilities in osp-cert in IBM OS/400 V5R3M0 have unspecified impact and attack vectors, related to ASN.1 parsing.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm os_400 v5r3m0
CVE-2006-6914 MEDIUM

Unspecified vulnerability in ftpd in IBM AIX 5.2.0 and 5.3.0 allows remote attackers to obtain sensitive information, including passwords, via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.3.0
ibm aix 5.2.0
CVE-2006-6915 MEDIUM

ftpd in IBM AIX 5.2.0 and 5.3.0 allows remote authenticated users to cause a denial of service (port exhaustion) via unspecified vectors. NOTE: some details were obtained from third party sources.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.3.0
ibm aix 5.2.0
CVE-2006-7164 MEDIUM

SimpleFileServlet in IBM WebSphere Application Server 5.0.1 through 5.0.2.7 on Linux and UNIX does not block certain invalid URIs and does not issue a security challenge, which allows remote attackers to read secure files and obtain sensitive information via certain requests.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_application_server 5.0.2.14
ibm websphere_application_server 5.0.2.16
ibm websphere_application_server 5.0.2.4
ibm websphere_application_server 5.0.2.3
ibm websphere_application_server 5.0.1
ibm websphere_application_server 5.0.2.6
ibm websphere_application_server 5.0.2.15
ibm websphere_application_server 5.0.2.10
ibm websphere_application_server 5.0.2.12
ibm websphere_application_server 5.0.2.2
ibm websphere_application_server 5.0.2.13
ibm websphere_application_server 5.0.2.8
ibm websphere_application_server 5.0.2.11
ibm websphere_application_server 5.0.2
ibm websphere_application_server 5.0.2.1
ibm websphere_application_server 5.0.2.7
ibm websphere_application_server 5.0.2.9
ibm websphere_application_server 5.0.2.5
CVE-2006-7165 MEDIUM

IBM WebSphere Application Server (WAS) 5.0 through 5.1.1.0 allows remote attackers to obtain JSP source code and other sensitive information via certain "special URIs."

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_application_server 5.1.1
ibm websphere_application_server 5.1.0
ibm websphere_application_server 5.1.0.3
ibm websphere_application_server 5.1.0.2
ibm websphere_application_server 5.1.0.5
ibm websphere_application_server 5.1.0.4
CVE-2006-7166 MEDIUM

IBM WebSphere Application Server (WAS) 5.1.1.9 and earlier allows remote attackers to obtain JSP source code and other sensitive information via "a specific JSP URL."

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_application_server 5.1.1
ibm websphere_application_server 5.0.2.4
ibm websphere_application_server 5.1.1.2
ibm websphere_application_server 5.0.1
ibm websphere_application_server 5.0.2.6
ibm websphere_application_server 5.0.2.15
ibm websphere_application_server 5.0.2.10
ibm websphere_application_server 5.1.1.6
ibm websphere_application_server 5.0.2.11
ibm websphere_application_server 5.0.2.1
ibm websphere_application_server 5.1.0.2
ibm websphere_application_server 5.0.2.7
ibm websphere_application_server 5.0.2.9
ibm websphere_application_server 5.0.2.5
ibm websphere_application_server 5.0.2.14
ibm websphere_application_server 5.1.1.7
ibm websphere_application_server 5.1.1.1
ibm websphere_application_server 5.1.1.3
ibm websphere_application_server 5.1.0.3
ibm websphere_application_server 5.0.2.16
ibm websphere_application_server 5.0.2.3
ibm websphere_application_server 5.0
ibm websphere_application_server 5.0.2.12
ibm websphere_application_server 5.1.0
ibm websphere_application_server 5.1.1.5
ibm websphere_application_server 5.1.1.9
ibm websphere_application_server 5.0.2.2
ibm websphere_application_server 5.0.2.13
ibm websphere_application_server 5.0.2.8
ibm websphere_application_server 5.0.2
ibm websphere_application_server 5.1.0.5
ibm websphere_application_server 5.1.1.8
ibm websphere_application_server 5.1.0.4
ibm websphere_application_server 5.1.1.4
CVE-2006-7198 HIGH

Unspecified vulnerability in IBM WebSphere Application Server (WAS) before 5.1.1.14, and WAS for z/OS 601 before 6.0.2.13, has unknown impact and attack vectors, related to a "Potential security exposure," aka PK26123.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_application_server 5.1.1.14
ibm websphere_application_server *
CVE-2006-7241 MEDIUM

The Image Viewer component in IBM FileNet P8 Application Engine (P8AE) 3.5.1 before 3.5.1-002 removes a user from an ACL when the user is denied all permissions for an annotation, which might allow remote authenticated users to bypass intended access restrictions in opportunistic circumstances.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm filenet_p8_application_engine 3.5.1
CVE-2006-7242 MEDIUM

The Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 3.5.1 before 3.5.1-001 does not ensure that the AE Administrator role is present for Site Preferences modifications, which allows remote authenticated users to bypass intended access restrictions via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm filenet_p8_application_engine 3.5.1
CVE-2007-0067 HIGH

Unspecified vulnerability in the Lotus Domino Web Server 6.0, 6.5.x before 6.5.6, and 7.0.x before 7.0.3 allows remote attackers to cause a denial of service (daemon crash) via requests for URLs that reference certain files.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm lotus_domino_web_server 6.5.1
ibm lotus_domino_web_server 6.5.4
ibm lotus_domino_web_server 6.0.2_cf2
ibm lotus_domino_web_server 6.5.3
ibm lotus_domino_web_server 6.0.2
ibm lotus_domino_web_server 6.0.3
ibm lotus_domino_web_server 6.5.5
ibm lotus_domino_web_server 7.0.1
ibm lotus_domino_web_server 6.5.0
ibm lotus_domino_web_server 6.0.5
ibm lotus_domino_web_server 6.5.2
ibm lotus_domino_web_server 6.0.1
ibm lotus_domino_web_server 6.0
ibm lotus_domino_web_server 6.0.4
ibm lotus_domino_web_server 7.0
ibm lotus_domino_web_server 7.0.2
CVE-2007-0068 HIGH

IBM Lotus Domino 7.0.x before 7.0.3 does not revalidate the signature on a signed scheduled agent after the agent is modified, which allows remote authenticated users to gain privileges via a modified agent in a server database.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_domino 7.0.2
ibm lotus_domino 7.0
ibm lotus_domino 7.0.1
CVE-2007-0392 MEDIUM

IBM AIX 5.3 does not properly verify the status of file descriptors before setuid execution, which allows local users to gain privileges by closing file descriptor 0, 1, or 2 and then invoking a setuid program, a variant of CVE-2002-0572.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.3
CVE-2007-0442 MEDIUM

Unspecified vulnerability in IBM OS/400 R530 and R535 has unknown impact and remote attack vectors, related to an "Integrity Problem" involving LIC-TCPIP and TCP reset. NOTE: it is possible that this issue is related to CVE-2004-0230, but this is not certain.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm os_400 r530
ibm os_400 r535
CVE-2007-0618 HIGH

Unspecified vulnerability in (1) pop3d, (2) pop3ds, (3) imapd, and (4) imapds in IBM AIX 5.3.0 has unspecified impact and attack vectors, involving an "authentication vulnerability."

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.3.0
CVE-2007-0670 MEDIUM

Buffer overflow in bos.rte.libc in IBM AIX 5.2 and 5.3 allows local users to execute arbitrary code via the "r-commands", possibly including (1) rdist, (2) rsh, (3) rcp, (4) rsync, and (5) rlogin.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 5.2
CVE-2007-0977 HIGH

IBM Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores HTTPPassword hashes from names.nsf in a manner accessible through Readviewentries and OpenDocument requests to the defaultview view, a different vector than CVE-2005-2428.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_domino 6.0
ibm lotus_domino 5.0
CVE-2007-0978 HIGH

Buffer overflow in swcons in IBM AIX 5.3 allows local users to gain privileges via long input data.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.3
CVE-2007-1027 MEDIUM

Certain setuid DB2 binaries in IBM DB2 before 9 Fix Pack 2 for Linux and Unix allow local users to overwrite arbitrary files via a symlink attack on the DB2DIAG.LOG temporary file.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-59,

Products Affected

Vendor Product Version
ibm db2 9.0
CVE-2007-1086 HIGH

Unspecified binaries in IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 allow local users to create or modify arbitrary files via unspecified environment variables related to "unsafe file access."

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm db2_universal_database 8.1.4
ibm db2_universal_database 8.1.9a
ibm db2_universal_database 8.12
ibm db2_universal_database 8.0
ibm db2_universal_database 8.10
ibm db2_universal_database 8.1.6
ibm db2_universal_database 8.1.7
ibm db2_universal_database 8.1.5
ibm db2_universal_database 8.1.8a
ibm db2_universal_database 8.1.6c
ibm db2_universal_database 8.1.9
ibm db2_universal_database 9.1
ibm db2_universal_database 8.1.7b
ibm db2_universal_database 8.1
ibm db2_universal_database 8.1.8
CVE-2007-1087 HIGH

IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 does not properly terminate certain input strings, which allows local users to execute arbitrary code via unspecified environment variables that trigger a heap-based buffer overflow.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm db2 8.1.8a
ibm db2 8.1.7b
ibm db2 8.1
ibm db2 8.0
ibm db2 8.1.8
ibm db2 8.1.7
ibm db2 8.1.6c
ibm db2 8.1.4
ibm db2 8.1.9a
ibm db2 9.1
ibm db2 8.1.6
ibm db2 8.1.5
ibm db2 8.1.9
CVE-2007-1088 HIGH

Stack-based buffer overflow in IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 allows local users to execute arbitrary code via a long string in unspecified environment variables.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm db2 8.1.8a
ibm db2 8.1.7b
ibm db2 8.1
ibm db2 8.0
ibm db2 8.1.8
ibm db2 8.1.7
ibm db2 8.1.6c
ibm db2 8.1.4
ibm db2 8.1.9a
ibm db2 9.1
ibm db2 8.1.6
ibm db2 8.1.5
ibm db2 8.1.9
CVE-2007-1089 HIGH

IBM DB2 Universal Database (UDB) 9.1 GA through 9.1 FP1 allows local users with table SELECT privileges to perform unauthorized UPDATE and DELETE SQL commands via unknown vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm db2_universal_database *
ibm db2_universal_database 9.1
CVE-2007-1228 MEDIUM

IBM DB2 UDB 8.2 before Fixpak 7 (aka fixpack 14), and DB2 9 before Fix Pack 2, on UNIX allows the "fenced" user to access certain unauthorized directories.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm db2 9.0
ibm db2 8.2
CVE-2007-1468 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Rational ClearQuest (CQ) Web 7.0.0.0 allows remote attackers to inject arbitrary web script or HTML via an attachment to a defect log entry.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_clearquest 7.0.0.0
CVE-2007-1608 HIGH

CRLF injection vulnerability in IBM WebSphere Application Server (WAS) before 6.0.2.19 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a single CRLF sequence in a context that is not a valid multi-line header.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_application_server *
CVE-2007-1675 HIGH

Buffer overflow in the CRAM-MD5 authentication mechanism in the IMAP server (nimap.exe) in IBM Lotus Domino before 6.5.6 and 7.x before 7.0.2 FP1 allows remote attackers to cause a denial of service via a long username.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_domino 6.5.4
ibm lotus_domino 6.5.1
ibm lotus_domino 7.0.2
ibm lotus_domino 7.0
ibm lotus_domino 6.5.5
ibm lotus_domino 6.5.3
ibm lotus_domino 6.5.0
ibm lotus_domino 6.5.2
ibm lotus_domino 7.0.1
CVE-2007-1739 HIGH

Heap-based buffer overflow in the LDAP server in IBM Lotus Domino before 6.5.6 and 7.x before 7.0.2 FP1 allows remote attackers to cause a denial of service (crash) via a long, malformed DN request, which causes only the lower 16 bits of the string length to be used in memory allocation.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_domino 7.0.2
ibm lotus_domino 7.0
ibm lotus_domino 7.0.1
CVE-2007-1784 HIGH

The JNILoader ActiveX control (STJNILoader.ocx) 3.1.0.26 in IBM Lotus Notes Sametime before 7.5 allows remote attackers to load arbitrary DLL libraries and execute arbitrary code via arbitrary arguments to the loadLibrary function.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_sametime *
ibm lotus_sametime 7.5
CVE-2007-1798 HIGH

Buffer overflow in the drmgr command in IBM AIX 5.2 and 5.3 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long path name.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 5.2
CVE-2007-1868 HIGH

The management service in IBM Tivoli Provisioning Manager for OS Deployment before 5.1 Fix Pack 2 does not properly handle multipart/form-data in HTTP POST requests, which allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via crafted POST requests to port 8080/tcp or 443/tcp.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm tivoli_provisioning_manager_os_deployment 5.1.0.116
CVE-2007-1940 MEDIUM

IBM Tivoli Business Service Manager (TBSM) 4.1 before Interim Fix 1 logs passwords in plaintext, which allows local users to obtain sensitive information by reading (1) ncisetup.db or (2) msi.log.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm tivoli_business_service_manager 4.1
CVE-2007-1941 MEDIUM

Cross-site scripting (XSS) vulnerability in the Active Content Filter feature in Domino Web Access (DWA) in IBM Lotus Notes before 6.5.6 and 7.x before 7.0.2 FP1 allows remote attackers to inject arbitrary web script or HTML via a multipart/related e-mail message, a different issue than CVE-2006-4843.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_notes 6.5.5
ibm lotus_notes 7.0.1
ibm lotus_notes 7.0
CVE-2007-1944 MEDIUM

The Java Message Service (JMS) in IBM WebSphere Application Server (WAS) before 6.1.0.7 allows attackers to cause a denial of service via unknown vectors involving the "double release [of] a bytebuffer input stream," possibly a double free vulnerability.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm websphere_application_server *
CVE-2007-1945 HIGH

Unspecified vulnerability in the Servlet Engine/Web Container in IBM WebSphere Application Server (WAS) before 6.1.0.7 has unknown impact and attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_application_server *
CVE-2007-2137 HIGH

Heap-based buffer overflow in kde.dll in IBM Tivoli Monitoring Express 6.1.0 before Fix Pack 2, as used in Tivoli Universal Agent, Windows OS Monitoring agent, and Enterprise Portal Server, allows remote attackers to execute arbitrary code by sending a long string to a certain TCP port.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm tivoli_monitoring_express 6.1.0
CVE-2007-2582 HIGH

Multiple buffer overflows in the DB2 JDBC Applet Server (DB2JDS) service in IBM DB2 9.x and earlier allow remote attackers to (1) execute arbitrary code via a crafted packet to the DB2JDS service on tcp/6789; and cause a denial of service via (2) an invalid LANG parameter or (2) a long packet that generates a "MemTree overflow."

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm db2 *
CVE-2007-2995 MEDIUM

Unspecified vulnerability in sysmgt.websm.rte in IBM AIX 5.2.0 and 5.3.0 has unknown impact and attack vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 5.2.0
CVE-2007-2996 MEDIUM

Unspecified vulnerability in perl.rte 5.8.0.10 through 5.8.0.95 on IBM AIX 5.2, and 5.8.2.10 through 5.8.2.50 on AIX 5.3, allows local users to gain privileges via unspecified vectors related to the installation and "waiting for a legitimate user to execute a binary that ships with Perl."

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 5.2
CVE-2007-3127 MEDIUM

content.php in WSPortal 1.0, when magic_quotes_gpc is disabled, allows remote attackers to obtain sensitive information via a "';" (quote semicolon) sequence in the page parameter, which reveals the installation path in the resulting forced SQL error message.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_portal 1.0
CVE-2007-3128 MEDIUM

SQL injection vulnerability in content.php in WSPortal 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the page parameter.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_portal 1.0
CVE-2007-3232 HIGH

The IBM TotalStorage DS400 with firmware 4.15 uses a blank password for the (1) root, (2) user, (3) manager, (4) administrator, and (5) operator accounts, which allows remote attackers to gain login access via certain Linux daemons, including a telnet daemon on a nonstandard port, tcp/6000.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm totalstorage_ds400 4.15
CVE-2007-3262 HIGH

Unspecified vulnerability in the Default Messaging Component in IBM WebSphere Application Server (WAS) 6.1.0.7 and earlier allows remote attackers to cause a denial of service related to a thread hang, and possibly related to a "TCP issue," or to MPAlarmThread and a resultant memory leak.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_application_server *
CVE-2007-3263 HIGH

Unspecified vulnerability in the Default Messaging Component in IBM WebSphere Application Server (WAS) 6.1.0.7 and earlier has unknown impact and attack vectors, related to "incorrect authorization on a remote interface to the SDO repository."

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_application_server *
CVE-2007-3264 HIGH

Unspecified vulnerability in the PD tools component in IBM WebSphere Application Server (WAS) 6.1.0.7 and earlier has unknown impact and attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_application_server *
CVE-2007-3265 MEDIUM

Cross-site scripting (XSS) vulnerability in the Samples component in IBM WebSphere Application Server (WAS) 6.1.0.7 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_application_server *
CVE-2007-3268 MEDIUM

The TFTP implementation in IBM Tivoli Provisioning Manager for OS Deployment 5.1 before Fix Pack 3 allows remote attackers to cause a denial of service (rembo.exe crash and multiple service outage) via a read (RRQ) request with an invalid blksize (blocksize), which triggers a divide-by-zero error.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 3.9 3.6

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-369,

Products Affected

Vendor Product Version
ibm tivoli_provisioning_manager_os_deployment 5.1.0.2
CVE-2007-3333 MEDIUM

Stack-based buffer overflow in capture in IBM AIX 5.3 SP6 and 5.2.0 allows remote attackers to execute arbitrary code via a large number of terminal control sequences.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 5.2.0
CVE-2007-3397 MEDIUM

The web container in IBM WebSphere Application Server (WAS) before 6.0.2.21, and 6.1.x before 6.1.0.9, sends response data intended for a different request in certain circumstances after a closed connection error, which might allow remote attackers to obtain sensitive information.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.0.2.2
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 6.0.2.13
ibm websphere_application_server 6.0.2.11
ibm websphere_application_server 6.0.2.19
ibm websphere_application_server 6.0.2.6
ibm websphere_application_server 6.0.2.7
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.0.2.17
ibm websphere_application_server 6.0.2.5
ibm websphere_application_server 6.0.2.9
ibm websphere_application_server 6.0.2.15
ibm websphere_application_server 6.0.2.4
ibm websphere_application_server 6.1.0
ibm websphere_application_server 6.0.2.3
ibm websphere_application_server 6.0.2
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.0.2.1
CVE-2007-3510 HIGH

Buffer overflow in the IMAP service in IBM Lotus Domino before 6.5.6 FP2, and 7.x before 7.0.3, allows remote authenticated users to execute arbitrary code via a long mailbox name.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm lotus_domino 7.0.2
ibm lotus_domino 7.0
ibm lotus_domino 6.5.5
ibm lotus_domino 6.5.6
CVE-2007-3537 HIGH

IBM OS/400 (aka i5/OS) V4R2M0 through V5R3M0 on iSeries machines sends responses to TCP SYN-FIN packets, which allows remote attackers to obtain system information and possibly bypass firewall rules.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm os_400 v4r3
ibm os_400 r520
ibm os_400 v4r2m0
ibm os_400 v4r5
ibm os_400 v5r1
ibm os_400 v4r4
ibm os_400 v5r3m0
ibm os_400 v5r2m0
CVE-2007-3676 HIGH

IBM DB2 Universal Database (UDB) Administration Server (DAS) 8 before Fix Pack 16 and 9 before Fix Pack 4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via modified pointer values in unspecified remote administration requests, which triggers memory corruption or other invalid memory access. NOTE: this might be the same issue as CVE-2008-0698.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm db2 *
CVE-2007-3680 HIGH

Stack-based buffer overflow in the odm_searchpath function in libodm in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary code via a long ODMPATH environment variable.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm aix 5.3.0
ibm aix 5.2.0
CVE-2007-3830 LOW

Cross-site scripting (XSS) vulnerability in alert.php in ISS Proventia Network IPS GX5108 1.3 and GX5008 1.5 allows remote attackers to inject arbitrary web script or HTML via the reminder parameter.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm proventia_network_ips_gx5008 1.5
ibm proventia_network_ips_gx5108 1.3
CVE-2007-3831 HIGH

PHP remote file inclusion in main.php in ISS Proventia Network IPS GX5108 1.3 and GX5008 1.5 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm proventia_network_ips_gx5008 1.5
ibm proventia_network_ips_gx5108 1.3
CVE-2007-3960 HIGH

Multiple unspecified vulnerabilities in IBM WebSphere Application Server (WAS) before Fix Pack 21 (6.0.2.21) have unknown impact and attack vectors, aka (1) PK33799, or (2) a "Potential security exposure" in the Samples component (PK40213).

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_application_server *
CVE-2007-4003 MEDIUM

pioout in IBM AIX 5.3 SP6 allows local users to execute arbitrary code by specifying a malicious library with the -R (ParseRoutine) command line argument.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.3
CVE-2007-4004 MEDIUM

Buffer overflow in the ftp client in IBM AIX 5.3 SP6 and 5.2.0 allows local users to execute arbitrary code via unspecified vectors that trigger the overflow in a gets function call. NOTE: the client is setuid root on AIX, so this issue crosses privilege boundaries.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 5.2.0
CVE-2007-4142 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Lotus Sametime Server 7.5.1 before 20070731 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving a crafted Sametime meeting.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_sametime *
CVE-2007-4217 HIGH

Stack-based buffer overflow in the domacro function in ftp in IBM AIX 5.2 and 5.3 allows local users to gain privileges via a long parameter to a macro, as demonstrated by executing a macro via the '$' command.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 5.2
CVE-2007-4222 HIGH

Buffer overflow in the TagAttributeListCopy function in nnotes.dll in IBM Lotus Notes before 7.0.3 allows user-assisted remote attackers to execute arbitrary code via a crafted HTML email, related to duplicate RTF conversion when the recipient operates on this email.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm lotus_notes *
CVE-2007-4228 MEDIUM

rmpvc on IBM AIX 4.3 allows local users to cause a denial of service (system crash) via long port logical name (-l) argument.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 4.3
CVE-2007-4236 MEDIUM

Buffer overflow in lpd in bos.rte.printers in AIX 5.2 and 5.3 allows local users with printq group privileges to gain root privileges.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 5.2
CVE-2007-4237 MEDIUM

Buffer overflow in the atm subset in arp in devices.common.IBM.atm.rte in AIX 5.2 and 5.3 allows local users to gain root privileges.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 5.2
CVE-2007-4238 MEDIUM

AIX 5.2 and 5.3 install pioinit with user and group ownership of bin, which allows local users with bin or possibly printq privileges to gain root privileges by modifying pioinit.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 5.2
CVE-2007-4270 MEDIUM

Multiple race conditions in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allow local users to gain root privileges via a symlink attack on certain files.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm db2_universal_database *
CVE-2007-4271 LOW

Directory traversal vulnerability in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allows local users to create arbitrary files via a .. (dot dot) in an unspecified environment variable, which is appended to "/tmp/" and used as a log file. NOTE: this issue might be related to symlink following.

CVSS 2.0

Severity: LOW

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm db2_universal_database *
CVE-2007-4272 LOW

Multiple vulnerabilities in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allow local users to create arbitrary files via (1) unspecified vectors where an attacker's umask is honored, (2) /etc/ld.so.preload, (3) certain "cron data file locations", and other unspecified vectors possibly involving the (4) OSSEMEMDBG or (5) TRC_LOG_FILE environment variable in db2licd (db2licm).

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm db2_universal_database *
CVE-2007-4273 MEDIUM

IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allows local users to create arbitrary directories and execute arbitrary code via a "crafted localized message file" that enables a format string attack, possibly involving the (1) OSSEMEMDBG or (2) TRC_LOG_FILE environment variable in db2licd (db2licm).

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-134,

Products Affected

Vendor Product Version
ibm db2_universal_database *
CVE-2007-4275 MEDIUM

Multiple untrusted search path vulnerabilities in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allow local users to gain privileges via certain vectors related to (1) DB2 instance or FMP startup on Linux and Solaris; (2) exec of executables while running as root on non-Windows systems, as demonstrated by AIX; and unspecified vectors involving (3) db2licm and (4) db2pd.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm db2_universal_database *
CVE-2007-4276 MEDIUM

Stack-based buffer overflow in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allows attackers to execute arbitrary code via a long DASPROF and possibly other environment variables, which are copied into the buildDasPaths buffer.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm db2_universal_database *
CVE-2007-4309 LOW

IBM Lotus Notes 5.x through 7.0.2 allows user-assisted remote authenticated administrators to obtain a cleartext notes.id password by setting the notes.ini (1) KFM_ShowEntropy and (2) Debug_Outfile debug variables, a different vulnerability than CVE-2005-2696.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_notes 5.0
ibm lotus_notes 7.0.1
ibm lotus_notes 7.0
ibm lotus_notes 7.0.2
ibm lotus_notes 6.0
CVE-2007-4348 MEDIUM

Cross-site scripting (XSS) vulnerability in the CAD service in IBM Tivoli Storage Manager (TSM) Client 5.3.5.3 and 5.4.1.2 for Windows allows remote attackers to inject arbitrary web script or HTML via HTTP requests to port 1581, which generate log entries in a dsmerror.log file that is accessible through a certain web interface.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_client *
CVE-2007-4353 MEDIUM

Multiple buffer overflows in IBM AIX 5.2 and 5.3 allow local users in the system group to gain root privileges via unspecified vectors involving the (1) chpath, (2) rmpath, and (3) devinstall programs in bos.rte.methods.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 5.2
CVE-2007-4354 HIGH

Buffer overflow in fileplace in bos.perf.tools in IBM AIX 5.2 and 5.3 allows local users to gain privileges via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 5.2
CVE-2007-4355 HIGH

Buffer overflow in the at program on IBM AIX 5.3 allows local users to gain privileges via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.3
CVE-2007-4368 HIGH

SQL injection vulnerability in /main in IBM Rational ClearQuest (CQ) Web 7.0.0.0-IFIX02 and 7.0.0.1 allows remote attackers to execute arbitrary SQL commands via the username parameter in a GenerateMainFrame command.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm rational_clearquest 7.0.0.0
ibm rational_clearquest 7.0.0.1
CVE-2007-4417 MEDIUM

IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 does not properly revoke privileges on methods, which allows remote authenticated users to execute a method after revocation until the routine auth cache is flushed.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm db2_universal_database *
CVE-2007-4418 MEDIUM

IBM DB2 UDB 8 before Fixpak 15 does not properly check authorization, which allows remote authenticated users with a certain SELECT privilege to have an unknown impact via unspecified vectors. NOTE: this issue is probably related to CVE-2007-1089, but this is uncertain due to lack of details.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm db2_universal_database *
CVE-2007-4423 MEDIUM

Stack-based buffer overflow in the AUTH_LIST_GROUPS_FOR_AUTHID function in IBM DB2 UDB 9.1 before Fixpak 3 allows attackers to cause a denial of service and possibly execute arbitrary code via a long argument.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm db2_universal_database 9.0
ibm db2_universal_database 8.0
ibm db2_universal_database 9.1
CVE-2007-4474 HIGH

Multiple stack-based buffer overflows in the IBM Lotus Domino Web Access ActiveX control, as provided by inotes6.dll, inotes6w.dll, dwa7.dll, and dwa7w.dll, in Domino 6.x and 7.x allow remote attackers to execute arbitrary code, as demonstrated by an overflow from a long General_ServerName property value when calling the InstallBrowserHelperDll function in the Upload Module in the dwa7.dwa7.1 control in dwa7w.dll 7.0.34.1.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm domino_web_access 6.5.1
ibm domino_web_access 6.5.4
ibm domino_web_access 6.5.5
ibm domino_web_access 6.0.1
ibm domino_web_access 6.0.1.1
ibm domino_web_access 7.0
ibm domino_web_access 6.5.3
ibm domino_web_access 6.0.2
ibm domino_web_access 7.0.1
ibm domino_web_access 6.0.3
ibm domino_web_access 6.0.5
ibm domino_web_access 6.0.4
ibm domino_web_access 6.0
ibm domino_web_access 6.5.2
ibm lotus_domino_web_access 7.0.1
ibm domino_web_access 6.5
ibm lotus_domino_web_access 7.0.34.1
CVE-2007-4513 HIGH

Multiple stack-based buffer overflows in IBM AIX 5.2 and 5.3 allow local users to gain privileges via a long argument to the (1) "-p" option to lqueryvg or (2) the "-V" option to lquerypv.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 5.2
CVE-2007-4592 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in the web interface for IBM Rational ClearQuest before 2003.06.16 Patch 2008A, 7.0.0.2_iFix01, and 7.0.1.1_iFix01 allow remote attackers to inject arbitrary web script or HTML via the (1) contextid, (2) username, (3) userNameVal, and (4) schema parameters to the login component.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_clearquest 7.0.1.1
ibm rational_clearquest *
ibm rational_clearquest 7.0.1
ibm rational_clearquest 7.0.2
CVE-2007-4598 MEDIUM

IBM SurePOS 500 has (1) a default password of "12345" for the manager and (2) blank default passwords for operator accounts.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm surepos_500 *
CVE-2007-4621 HIGH

Buffer overflow in crontab in IBM AIX 5.2 allows local users to gain privileges via long command line arguments.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm aix 5.2
CVE-2007-4622 HIGH

Integer underflow in the dns_name_fromtext function in (1) libdns_nonsecure.a and (2) libdns_secure.a in IBM AIX 5.2 allows local users to gain privileges via a crafted "-y" (TSIG key) command line argument to dig.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-189,

Products Affected

Vendor Product Version
ibm aix 5.2
CVE-2007-4623 HIGH

Stack-based buffer overflow in the sendrmt function in bellmail in IBM AIX 5.2 and 5.3 allows local users to execute arbitrary code via a long parameter to the m command.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 5.2
CVE-2007-4791 HIGH

Buffer overflow in the swcons command in bos.rte.console in IBM AIX 5.2 and 5.3 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2005-3504 and CVE-2007-0978.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 5.2
CVE-2007-4792 HIGH

Buffer overflow in ibstat in devices.common.IBM.ib.rte in IBM AIX 5.3 allows local users to gain privileges via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm aix 5.3
CVE-2007-4793 HIGH

Buffer overflow in xlplm in plm.server.rte in IBM AIX 5.2 and 5.3 allows local users to gain privileges via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 5.2
CVE-2007-4794 HIGH

Buffer overflow in fcstat in devices.common.IBM.fc.rte in IBM AIX 5.2 and 5.3 allows local users to gain privileges via a long input parameter.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 5.2
CVE-2007-4795 HIGH

Buffer overflow in mkpath in bos.rte.methods in IBM AIX 5.2 and 5.3 allows local users to gain privileges via a long ODM name.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 5.2
CVE-2007-4796 HIGH

Buffer overflow in uucp in bos.net.uucp in IBM AIX 5.2 and 5.3 allows local users to gain privileges via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 5.2
CVE-2007-4797 HIGH

Multiple buffer overflows in unspecified svprint (System V print) commands in bos.svprint.rte in IBM AIX 5.2 and 5.3 allow local users to gain privileges via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 5.2
CVE-2007-4798 MEDIUM

Unspecified vulnerability in invscout in Inventory Scout in invscout.rte in IBM AIX 5.2 and 5.3 allows local users to delete system files that have names matching the final substring of a hostname alias, as demonstrated by hostnames ending in "unix".

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 5.2
CVE-2007-4799 MEDIUM

The perfstat kernel extension in bos.perf.perfstat in AIX 5.3 does not verify privileges when processing a SET call, which allows local users to cause a denial of service (system hang or crash) via unspecified SET operations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm aix 5.3
CVE-2007-4833 MEDIUM

Unspecified vulnerability in the Edge Component in IBM WebSphere Application Server (WAS) 6.1 before Fix Pack 11 (6.1.0.11) has unknown impact and attack vectors, aka PK44789.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_application_server *
CVE-2007-4839 HIGH

Unspecified vulnerability in the PD tools component in IBM WebSphere Application Server (WAS) 6.1 before Fix Pack 11 (6.1.0.11) has unknown impact and attack vectors, aka PK33803.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.9
CVE-2007-4880 HIGH

Buffer overflow in the Client Acceptor Daemon (CAD), dsmcad.exe, in certain IBM Tivoli Storage Manager (TSM) clients 5.1 before 5.1.8.1, 5.2 before 5.2.5.2, 5.3 before 5.3.5.3, and 5.4 before 5.4.1.2 allows remote attackers to execute arbitrary code via crafted HTTP headers, aka IC52905.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_client 5.4.1.1
ibm tivoli_storage_manager_client 5.1.8.0
ibm tivoli_storage_manager_client 5.3
ibm tivoli_storage_manager_client 5.1
ibm tivoli_storage_manager_client 5.4
ibm tivoli_storage_manager_client 5.2
ibm tivoli_storage_manager_client 5.2.5.1
ibm tivoli_storage_manager_client 5.3.5.2
CVE-2007-5022 MEDIUM

Unspecified vulnerability in certain IBM Tivoli Storage Manager (TSM) clients 5.1 before 5.1.8.1, 5.2 before 5.2.5.2, 5.3 before 5.3.5.3, and 5.4 before 5.4.1.2, when using "server-initiated prompted scheduling," allows remote attackers to read a client's data, aka IC53616.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_client *
CVE-2007-5090 HIGH

Unspecified vulnerability in IBM Rational ClearQuest (CQ), when a Microsoft SQL Server or an IBM DB2 database is used, allows attackers to corrupt data via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm rational_clearquest 6.12
ibm rational_clearquest 5.20
ibm rational_clearquest 5.00
ibm rational_clearquest 7.0.1
ibm rational_clearquest 6.00
ibm rational_clearquest 6.16
ibm rational_clearquest 7.0
ibm rational_clearquest 6.13
ibm rational_clearquest 6.14
ibm rational_clearquest 6.15
ibm rational_clearquest 7.0.0.1
CVE-2007-5399 HIGH

Multiple heap-based buffer overflows in emlsr.dll in the EML reader in Autonomy (formerly Verity) KeyView 10.3.0.0, as used by IBM Lotus Notes, allow remote attackers to execute arbitrary code via a long (1) To, (2) Cc, (3) Bcc, (4) From, (5) Date, (6) Subject, (7) Priority, (8) Importance, or (9) X-MSMail-Priority header; (10) a long string at the beginning of an RFC2047 encoded-word in a header; (11) a long text string in an RFC2047 encoded-word in a header; or (12) a long Subject header, related to creation of an associated filename.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm lotus_notes 6.5
autonomy keyview 10.3.0.0
ibm lotus_notes 7.0.3
ibm lotus_notes 7.0
ibm lotus_notes 7.0.2
ibm lotus_notes 6.0
CVE-2007-5405 HIGH

Multiple buffer overflows in kpagrdr.dll 2.0.0.2 and 10.3.0.0 in the Applix Presents reader in Autonomy (formerly Verity) KeyView, as used by IBM Lotus Notes, Symantec Mail Security, and activePDF DocConverter, allow remote attackers to execute arbitrary code via a .ag file with (1) a long ENCODING attribute in a *BEGIN tag, (2) a long token, or (3) the initial *BEGIN tag.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
symantec mail_security 5.0.1
autonomy keyview 10.3.0.0
ibm lotus_notes 7.0.3
ibm lotus_notes 7.0
ibm lotus_notes 7.0.2
symantec mail_security 5.0.0
activepdf docconverter 3.8.2_.5
ibm lotus_notes 6.5
activepdf docconverter 3.8.4.0
symantec mail_security_appliance 5.0
ibm lotus_notes 6.0
symantec mail_security 5.0
symantec mail_security 7.5
autonomy keyview 2.0.0.2
CVE-2007-5406 HIGH

kpagrdr.dll 2.0.0.2 and 10.3.0.0 in the Applix Presents reader in Autonomy (formerly Verity) KeyView, as used by IBM Lotus Notes, Symantec Mail Security, and activePDF DocConverter, does not properly parse long tokens, which allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted .ag file.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_notes 6.5
symantec mail_security 5.0.1
ibm lotus_notes 8.0
autonomy keyview *
ibm lotus_notes 7.0
ibm lotus_notes 6.0
symantec mail_security 5.0
symantec mail_security 5.0.0
ibm lotus_notes 8.0.1
symantec mail_security *
CVE-2007-5483 HIGH

Unspecified vulnerability in the Administrative Scripting Tools (such as wsadmin or ANT) in IBM WebSphere Application Server 5.x and 6.0.x has unknown impact and attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_application_server 5.1.1
ibm websphere_application_server 6.0.2.2
ibm websphere_application_server 6.0.2.13
ibm websphere_application_server 6.0.0.1
ibm websphere_application_server 6.0.2.11
ibm websphere_application_server 5.1.1.14
ibm websphere_application_server 6.0.2.19
ibm websphere_application_server 6.0.2.7
ibm websphere_application_server 5.1.1.2
ibm websphere_application_server 6.0.0.2
ibm websphere_application_server 5.1.1.12
ibm websphere_application_server 6.0.2.15
ibm websphere_application_server 6.0.2.4
ibm websphere_application_server 5.1.1.6
ibm websphere_application_server 5.1.1.10
ibm websphere_application_server 6.0.1.2
ibm websphere_application_server 5.1.1.7
ibm websphere_application_server 5.1.1.1
ibm websphere_application_server 5.1.1.3
ibm websphere_application_server 6.0.2.6
ibm websphere_application_server 6.0.1
ibm websphere_application_server 6.0.2.17
ibm websphere_application_server 6.0.2.5
ibm websphere_application_server 6.0.2.9
ibm websphere_application_server 5.1.1.5
ibm websphere_application_server 6.0.2.3
ibm websphere_application_server 5.1.1.9
ibm websphere_application_server 6.0
ibm websphere_application_server 6.0.2
ibm websphere_application_server 6.0.0.3
ibm websphere_application_server 5.1.1.8
ibm websphere_application_server 6.0.2.1
ibm websphere_application_server 5.1.1.4
CVE-2007-5544 MEDIUM

IBM Lotus Notes before 6.5.6, and 7.x before 7.0.3; and Domino before 6.5.5 FP3, and 7.x before 7.0.2 FP1; uses weak permissions (Everyone:Full Control) for memory mapped files (shared memory) in IPC, which allows local users to obtain sensitive information, or inject Lotus Script or other character sequences into a session.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 1.8 5.9

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-732,

Products Affected

Vendor Product Version
ibm lotus_notes *
ibm lotus_domino 7.0.2
ibm lotus_domino 6.5.5
ibm lotus_domino *
CVE-2007-5559 HIGH

Heap-based buffer overflow in the IBM ThinkVantage TPM Service allows remote attackers to execute arbitrary code via a crafted HTTP packet. NOTE: as of 20071016, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm thinkvantage_tpm *
CVE-2007-5612 HIGH

CIM Server in IBM Director 5.20.1 and earlier allows remote attackers to cause a denial of service (CPU consumption, connection slot exhaustion, and daemon crash) via a large number of idle connections.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm director *
ibm director 3.1
ibm director 5.10.3
ibm director 5.10
CVE-2007-5652 HIGH

IBM DB2 UDB 9.1 before Fixpak 4 does not properly manage storage of a list containing authentication information, which might allow attackers to cause a denial of service (instance crash) or trigger memory corruption. NOTE: the vendor description of this issue is too vague to be certain that it is security-related.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm db2 9.1
ibm db2 *
CVE-2007-5664 MEDIUM

db2dasrrm in the DB2 Administration Server (DAS) in IBM DB2 Universal Database 9.5 before Fix Pack 1, 9.1 before Fix Pack 4a, and 8 before FixPak 16 allows local users to overwrite arbitrary files via a symlink attack on files used for initialization.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-59,

Products Affected

Vendor Product Version
ibm db2_universal_database 9.5
ibm db2_universal_database 8
ibm db2_universal_database 9.1
CVE-2007-5700 MEDIUM

The Evaluate LotusScript method in IBM Lotus Domino before 7.0.3 uses an incorrect security context for @ formula commands in some circumstances, which might allow remote authenticated users to gain privileges and obtain sensitive information.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm lotus_domino 7.0.2
ibm lotus_domino 7.0
ibm lotus_domino 6.5.5
ibm lotus_domino 6.5.6
CVE-2007-5701 LOW

Incomplete blacklist vulnerability in the Certificate Authority (CA) in IBM Lotus Domino before 7.0.3 allows local users, or attackers with physical access, to obtain sensitive information (passwords) when an administrator enters a "ca activate" or "ca unlock" command with any uppercase character, which bypasses a blacklist designed to suppress password logging, resulting in cleartext password disclosure in the console log and Admin panel.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,CWE-310,

Products Affected

Vendor Product Version
ibm lotus_domino 7.0.2
ibm lotus_domino 7.0
ibm lotus_domino 6.5.5
ibm lotus_domino 6.5.6
CVE-2007-5757 MEDIUM

Untrusted search path vulnerability in db2pd in IBM DB2 Universal Database (UDB) 8 before FixPak 16 and 9 before Fix Pack 4 allows local users to gain root privileges via a modified DB2INSTANCE environment variable that points to a malicious library. NOTE: this might be the same issue as CVE-2008-0697.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm db2_universal_database *
ibm db2_universal_database 9.0
CVE-2007-5758 MEDIUM

Stack-based buffer overflow in db2dasrrm in the DB2 Administration Server (DAS) in IBM DB2 Universal Database 9.5 before Fix Pack 1, 9.1 before Fix Pack 4a, and 8 before FixPak 16 allows local users to execute arbitrary code via a long DASPROF environment variable.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm db2_universal_database 9.5
ibm db2_universal_database 8
ibm db2_universal_database 9.1
CVE-2007-5764 HIGH

Buffer overflow in the pioout program in printers.rte in IBM AIX 5.2, 5.3, and 6.1 allows local users to gain privileges via a long command line option.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 6.1
ibm aix 5.2
CVE-2007-5798 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in uddigui/navigateTree.do in the UDDI user console in IBM WebSphere Application Server (WAS) before 6.1.0 Fix Pack 13 (6.1.0.13) allow remote attackers to inject arbitrary web script or HTML via the (1) keyField, (2) nameField, (3) valueField, and (4) frameReturn parameters.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_application_server *
CVE-2007-5799 MEDIUM

Multiple cross-site request forgery (CSRF) vulnerabilities in uddigui/navigateTree.do in the UDDI user console in IBM WebSphere Application Server (WAS) before 6.1.0 Fix Pack 13 (6.1.0.13) allow remote attackers to perform some actions as WAS UDDI users via the (1) keyField, (2) nameField, (3) valueField, and (4) frameReturn parameters.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm websphere_application_server *
CVE-2007-5804 MEDIUM

cfgcon in IBM AIX 5.2 and 5.3 does not properly validate the argument to the "-p" option to swcons, which allows local users in the system group to create or overwrite an arbitrary file, and enable world writability of this file, by using the file's name as the argument.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 5.2
CVE-2007-5805 MEDIUM

cfgcon in IBM AIX 5.2 and 5.3 does not properly validate the argument to the "-p" option to swcons, which allows local users in the system group to create an arbitrary file, and enable world writability of this file, via a symlink attack involving use of the file's name as the argument. NOTE: this issue is due to an incomplete fix for CVE-2007-5804.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-59,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 5.2
CVE-2007-5819 LOW

IBM Tivoli Continuous Data Protection for Files (CDP) 3.1.0 uses weak permissions (unrestricted write) for the Central Admin Global download directory, which allows local users to place arbitrary files into a location used for updating CDP clients.

CVSS 2.0

Severity: LOW

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm tivoli_continuous_data_protection_for_files 3.1.0
CVE-2007-5909 HIGH

Multiple stack-based buffer overflows in Autonomy (formerly Verity) KeyView Viewer, Filter, and Export SDK before 9.2.0.12, as used by ActivePDF DocConverter, IBM Lotus Notes before 7.0.3, Symantec Mail Security, and other products, allow remote attackers to execute arbitrary code via a crafted (1) AG file to kpagrdr.dll, (2) AW file to awsr.dll, (3) DLL or (4) EXE file to exesr.dll, (5) DOC file to mwsr.dll, (6) MIF file to mifsr.dll, (7) SAM file to lasr.dll, or (8) RTF file to rtfsr.dll. NOTE: the WPD (wp6sr.dll) vector is covered by CVE-2007-5910.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
autonomy keyview_filter_sdk *
symantec mail_security 5.0.1
ibm lotus_notes *
autonomy keyview_export_sdk *
symantec mail_security 5.0.0.24
symantec mail_security 5.0
symantec mail_security 5.0.0
activepdf docconverter 3.8.2_.5
autonomy keyview_viewer_sdk *
symantec mail_security 7.5
CVE-2007-5910 HIGH

Stack-based buffer overflow in Autonomy (formerly Verity) KeyView Viewer, Filter, and Export SDK before 9.2.0.12, as used by ActivePDF DocConverter, wp6sr.dll in IBM Lotus Notes 8.0 and before 7.0.3, Symantec Mail Security, and other products, allows remote attackers to execute arbitrary code via a crafted WordPerfect (WPD) file.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
autonomy keyview_filter_sdk *
symantec mail_security 5.0.1
ibm lotus_notes *
autonomy keyview_export_sdk *
symantec mail_security 5.0.0.24
symantec mail_security 5.0
symantec mail_security 5.0.0
activepdf docconverter 3.8.2_.5
autonomy keyview_viewer_sdk *
symantec mail_security 7.5
CVE-2007-5924 MEDIUM

Cross-site scripting (XSS) vulnerability in the Web Server (HTTP) task in IBM Lotus Domino before 6.5.6 FP2, and 7.x before 7.0.2 FP2, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm lotus_domino 7.0.2
ibm lotus_domino 7.0
ibm lotus_domino *
CVE-2007-5944 MEDIUM

Cross-site scripting (XSS) vulnerability in Servlet Engine / Web Container in IBM WebSphere Application Server (WAS) 5.1.1.4 through 5.1.1.16 allows remote attackers to inject arbitrary web script or HTML via the Expect HTTP header. NOTE: this might be the same issue as CVE-2006-3918, but there are insufficient details to be sure.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_application_server 5.1.1.7
ibm websphere_application_server 5.1.1.16
ibm websphere_application_server 5.1.1.13
ibm websphere_application_server 5.1.1.14
ibm websphere_application_server 5.1.1.12
ibm websphere_application_server 5.1.1.15
ibm websphere_application_server 5.1.1.5
ibm websphere_application_server 5.1.1.6
ibm websphere_application_server 5.1.1.9
ibm websphere_application_server 5.1.1.11
ibm websphere_application_server 5.1.1.8
ibm websphere_application_server 5.1.1.10
ibm websphere_application_server 5.1.1.4
CVE-2007-5949 LOW

Cross-site scripting (XSS) vulnerability in IBM Tivoli Service Desk 6.2 allows remote authenticated users to inject arbitrary web script or HTML via the Description parameter in a Maximo change action.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_service_desk 6.2
CVE-2007-5956 HIGH

Directory traversal vulnerability in IBM Informix Dynamic Server (IDS) before 10.00.xC7W1 allows local users to gain privileges by referencing modified NLS message files through directory traversal sequences in the DBLANG environment variable.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm informix_dynamic_server *
CVE-2007-5957 MEDIUM

Unspecified vulnerability in IBM Informix Dynamic Server (IDS) 10.00.TC3TL and 11.10.TB4TL on Windows allows attackers to cause a denial of service (application crash) via unspecified SQ_ONASSIST requests.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm informix_dynamic_server 10.00.tc3tl
ibm informix_dynamic_server 11.10.tb4tl
CVE-2007-6020 HIGH

Multiple stack-based buffer overflows in foliosr.dll in the Folio Flat File speed reader in Autonomy (formerly Verity) KeyView 10.3.0.0, as used by IBM Lotus Notes, Symantec Mail Security, and activePDF DocConverter, allow remote attackers to execute arbitrary code via a long attribute value in a (1) DI, (2) FD, (3) FT, (4) JD, (5) JL, (6) LE, (7) OB, (8) OD, (9) OL, (10) PN, (11) PS, (12) PW, (13) RD, (14) QL, or (15) TS tag in a .fff file.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
symantec mail_security 5.0.1
autonomy keyview 10.3.0.0
ibm lotus_notes 7.0.3
ibm lotus_notes 7.0
ibm lotus_notes 7.0.2
symantec mail_security 5.0.0
ibm lotus_notes 6.5
activepdf docconverter 3.8.4.0
symantec mail_security_appliance 5.0
ibm lotus_notes 6.0
symantec mail_security 5.0
symantec mail_security 7.5
autonomy keyview 2.0.0.2
CVE-2007-6044 HIGH

Multiple unspecified vulnerabilities in IBM WebSphere MQ 6.0 have unknown impact and remote attack vectors involving "memory corruption." NOTE: as of 20071116, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm websphere_mq 6.0
CVE-2007-6045 HIGH

Unspecified vulnerability in (1) DB2WATCH and (2) DB2FREEZE in IBM DB2 UDB 9.1 before Fixpak 4 has unknown impact and attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm db2_universal_database *
CVE-2007-6046 HIGH

Unspecified vulnerability in unspecified setuid programs in IBM DB2 UDB 9.1 before Fixpak 4 allows local users to have an unknown impact.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm db2_universal_database *
CVE-2007-6047 HIGH

Unspecified vulnerability in the DB2DART tool in IBM DB2 UDB 9.1 before Fixpak 4 allows attackers to execute arbitrary commands as the DB2 instance owner, related to invocation of TPUT by DB2DART.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm db2_universal_database *
CVE-2007-6048 HIGH

IBM DB2 UDB 9.1 before Fixpak 4 uses incorrect permissions on ACLs for DB2NODES.CFG, which has unknown impact and attack vectors. NOTE: the vendor description of this issue is too vague to be certain that it is security-related.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm db2_universal_database *
CVE-2007-6049 HIGH

Unspecified vulnerability in the SSL LOAD GSKIT action in IBM DB2 UDB 9.1 before Fixpak 4 has unknown impact and attack vectors, involving a call to dlopen when the effective uid is root.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm db2_universal_database *
CVE-2007-6050 HIGH

Unspecified vulnerability in DB2LICD in IBM DB2 UDB 9.1 before Fixpak 4 has unknown impact and attack vectors, related to creation of an "insecure directory."

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm db2_universal_database *
CVE-2007-6051 HIGH

IBM DB2 UDB 9.1 before Fixpak 4 assigns incorrect privileges to the (1) DB2ADMNS and (2) DB2USERS alternative groups, which has unknown impact. NOTE: the vendor description of this issue is too vague to be certain that it is security-related.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm db2_universal_database *
CVE-2007-6052 HIGH

IBM DB2 UDB 9.1 before Fixpak 4 does not properly perform vector aggregation, which might allow attackers to cause a denial of service (divide-by-zero error and DBMS crash), related to an "overflow." NOTE: the vendor description of this issue is too vague to be certain that it is security-related.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm db2_universal_database *
CVE-2007-6053 HIGH

IBM DB2 UDB 9.1 before Fixpak 4 does not properly handle use of large numbers of file descriptors, which might allow attackers to have an unknown impact involving "memory corruption." NOTE: the vendor description of this issue is too vague to be certain that it is security-related.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm db2_universal_database *
CVE-2007-6219 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Tivoli Netcool Security Manager 1.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_netcool_security_manager 1.3.0
CVE-2007-6293 HIGH

Multiple unspecified vulnerabilities in IBM Hardware Management Console (HMC) 6 R1.3 allow attackers to gain privileges via "some HMC commands."

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm hardware_management_console 6.1.3
CVE-2007-6294 MEDIUM

Multiple unspecified vulnerabilities in IBM Hardware Management Console (HMC) 3 R3.7 allow attackers to gain privileges via "some HMC commands."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm hardware_management_console 3.3.7
CVE-2007-6295 MEDIUM

Cross-site scripting (XSS) vulnerability in the WebRunMenuFrame page in the online meeting center template in IBM Lotus Sametime before 8.0 allows remote attackers to inject arbitrary web script or HTML via the URI.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm lotus_sametime *
CVE-2007-6305 MEDIUM

Multiple unspecified vulnerabilities in IBM Hardware Management Console (HMC) 7 R3.2.0 allow attackers to gain privileges via "some HMC commands."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,CWE-264,

Products Affected

Vendor Product Version
ibm hardware_management_console 7.3.2.0
CVE-2007-6363 LOW

IBM Tivoli Netcool Security Manager 1.3.0 before Interim Fix 1, when using Active Directory (AD) LDAP authentication, allows remote attackers to obtain login access via unspecified vectors without entering a password.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_netcool_security_manager 1.3.0
CVE-2007-6407 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in IBM Tivoli Provisioning Manager Express allow remote attackers to inject arbitrary web script or HTML via the (1) "assess modification," (2) user-id, and other unspecified fields to the /tpmx URI; or (3) involving unspecified vectors related to "error processing."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_provisioning_manager_express *
CVE-2007-6408 MEDIUM

IBM Tivoli Provisioning Manager Express provides unspecified information in error messages when (1) attempted duplication of a username occurs when creating an account or (2) when trying to login using a valid username, which makes it easier for remote attackers to enumerate usernames.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm tivoli_provisioning_manager_express *
CVE-2007-6525 HIGH

Unspecified vulnerability in eClient in IBM DB2 Content Manager (CM) Toolkit 8.3 before fix pack 7 for z/OS has unknown impact and attack vectors, related to "scripting."

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm db2_content_manager_toolkit 8.3
CVE-2007-6593 HIGH

Multiple stack-based buffer overflows in l123sr.dll in Autonomy (formerly Verity) KeyView SDK, as used by IBM Lotus Notes 5.x through 8.x, allow user-assisted remote attackers to execute arbitrary code via the (1) Length and (2) Value fields for certain Types in a Lotus 1-2-3 (.123) file in the Worksheet File (WKS) format, as demonstrated by a file with a crafted SRANGE record, a different vulnerability than CVE-2007-5909.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm lotus_notes 6.5
ibm lotus_notes 5.0
ibm lotus_notes 8.0
ibm lotus_notes 7.0
ibm lotus_notes 6.0
CVE-2007-6594 MEDIUM

IBM Lotus Notes 8 for Linux before 8.0.1 uses (1) unspecified weak permissions for the installation kit obtained through a Notes 8 download and (2) 0777 permissions for the installdata file that is created by setup.sh, which allows local users to gain privileges via a Trojan horse file.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm lotus_notes *
CVE-2007-6679 HIGH

Unspecified vulnerability in the Administrative Console in IBM WebSphere Application Server 6.1 before Fix Pack 13 has unknown impact and attack vectors, related to "security concerns with monitor role users." NOTE: it was later reported that 6.0.2 before Fix Pack 25 is also affected.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.1
ibm websphere_application_server *
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.11
CVE-2007-6680 LOW

Trusted Execution in IBM AIX 6.1 uses an incorrect pathname argument in a call to the trustchk_block_write function, which might allow local users to modify trusted files, related to an error in the support for links in the TSD_FILES_LOCK policy.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 6.1
CVE-2007-6705 LOW

The WebSphere MQ XA 5.3 before FP13 and 6.0.x before 6.0.2.1 client for Windows, when running in an MTS or a COM+ environment, grants the PROCESS_DUP_HANDLE privilege to the Everyone group upon connection to a queue manager, which allows local users to duplicate an arbitrary handle and possibly hijack an arbitrary process.

CVSS 2.0

Severity: LOW

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_mq *
CVE-2007-6706 HIGH

Unspecified vulnerability in nlnotes.dll in the client in IBM Lotus Notes 6.5, 7.0.x before 7.0.2 CCH or 7.0.3, and possibly 8.0 allows remote attackers to execute arbitrary code via crafted text in an e-mail message sent over SMTP.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-94,

Products Affected

Vendor Product Version
ibm lotus_notes 6.5
ibm lotus_notes *
ibm lotus_notes 8.0
CVE-2007-6717 HIGH

Buffer overflow in tftp in bos.net.tcp.client in IBM AIX 5.2.0 and 5.3.0 allows local users to gain privileges via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm aix 5.3.0
ibm aix 5.2.0
CVE-2007-6742 MEDIUM

The get_filter_list function in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0006 does not properly perform certain sub filter parsing, which allows remote authenticated users to cause a denial of service (infinite loop) via a malformed search filter.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm tivoli_directory_server 5.2.0
ibm tivoli_directory_server 5.2.0.4
CVE-2007-6743 MEDIUM

Double free vulnerability in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0005 allows remote authenticated users to cause a denial of service (ABEND) via search operations that trigger recursive filter_free calls.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm tivoli_directory_server 5.2.0
ibm tivoli_directory_server 5.2.0.4
CVE-2008-0066 HIGH

Multiple buffer overflows in htmsr.dll in the HTML speed reader in Autonomy (formerly Verity) KeyView, as used by IBM Lotus Notes 7.0.2 and 7.0.3, allow remote attackers to execute arbitrary code via an HTML document with (1) "large chunks of data," or a long URL in the (2) BACKGROUND attribute of a BODY element or (3) SRC attribute of an IMG element.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm lotus_notes 7.0.3
autonomy keyview *
ibm lotus_notes 7.0.2
CVE-2008-0243 HIGH

Unspecified vulnerability in Lotus Domino 7.0.2 before Fix Pack 3 allows attackers to cause a denial of service via unknown vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm lotus_domino 7.0.2
ibm lotus_domino 7.0
ibm lotus_domino 7.0.1
CVE-2008-0247 HIGH

Heap-based buffer overflow in the Express Backup Server service (dsmsvc.exe) in IBM Tivoli Storage Manager (TSM) Express 5.3 before 5.3.7.3 allows remote attackers to execute arbitrary code via a packet with a large length value.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_express *
CVE-2008-0354 MEDIUM

Cross-site scripting (XSS) vulnerability in the chat client in IBM Lotus Sametime 7.5 and 7.5.1 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted message, which triggers code execution after a mouseover event initiated by the victim.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm lotus_sametime 7.5
ibm lotus_sametime 7.5.1
CVE-2008-0368 HIGH

onedcu in IBM Informix Dynamic Server (IDS) 10.x before 10.00.xC8 allows local users to create arbitrary files via the Trace file argument.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm informix_dynamic_server 10.0
CVE-2008-0369 MEDIUM

Multiple unspecified programs in IBM Informix Dynamic Server (IDS) 10.x before 10.00.xC8 allow local users to create arbitrary files by specifying the target file in the SQLIDEBUG environment variable, whose ownership is changed to the user invoking the programs.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm informix_dynamic_server 10.00
CVE-2008-0389 HIGH

Unspecified vulnerability in the serveServletsByClassnameEnabled feature in IBM WebSphere Application Server (WAS) 6.0 through 6.0.2.25, 6.1 through 6.1.0.14, and 5.1.1.x before 5.1.1.18 has unknown impact and attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_application_server 5.1.1
ibm websphere_application_server 6.0.2.13
ibm websphere_application_server 6.0.2.11
ibm websphere_application_server 5.1.1.14
ibm websphere_application_server 6.0.2.19
ibm websphere_application_server 6.0.2.7
ibm websphere_application_server 5.1.1.2
ibm websphere_application_server 5.1.1.12
ibm websphere_application_server 5.1.1.15
ibm websphere_application_server 5.1.1.6
ibm websphere_application_server 6.1
ibm websphere_application_server 6.1.6
ibm websphere_application_server *
ibm websphere_application_server 5.1.1.10
ibm websphere_application_server 5.1.1.7
ibm websphere_application_server 5.1.1.16
ibm websphere_application_server 6.1.3
ibm websphere_application_server 5.1.1.1
ibm websphere_application_server 6.0.2.25
ibm websphere_application_server 5.1.1.3
ibm websphere_application_server 6.0.2.23
ibm websphere_application_server 6.0.1
ibm websphere_application_server 6.1.5
ibm websphere_application_server 6.1.14
ibm websphere_application_server 6.0.2.24
ibm websphere_application_server 6.0.2.5
ibm websphere_application_server 6.0.2.9
ibm websphere_application_server 6.1.7
ibm websphere_application_server 5.1.1.5
ibm websphere_application_server 6.0.2.3
ibm websphere_application_server 5.1.1.9
ibm websphere_application_server 6.0.2.22
ibm websphere_application_server 6.0
ibm websphere_application_server 6.0.2
ibm websphere_application_server 6.1.1
ibm websphere_application_server 5.1.1.8
ibm websphere_application_server 6.0.2.1
ibm websphere_application_server 6.1.13
ibm websphere_application_server 5.1.1.4
CVE-2008-0401 HIGH

Buffer overflow in the logging functionality of the HTTP server in IBM Tivoli Provisioning Manager for OS Deployment (TPMfOSD) before 5.1.0.3 Interim Fix 3 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via an HTTP request with a long method string to port 443/tcp.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm tivoli_provisioning_manager_os_deployment *
CVE-2008-0402 MEDIUM

Unspecified vulnerability in IBM WebSphere Business Modeler Basic and Advanced 6.0.2.1 before Interim Fix 11 allows remote authenticated users to bypass intended access restrictions and delete unspecified repository resources via unknown vectors, even when they are not administrators or members of the repository's owning group.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_business_modeler 6.0.2_1
CVE-2008-0441 LOW

IBM Tivoli Business Service Manager (TBSM) 4.1.1 stores passwords in cleartext (1) after external authentication, which triggers writing the password to SM_server.log; and (2) after a reconfig action; which allows local users to obtain sensitive information.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm tivoli_business_service_manager 4.1.1
CVE-2008-0495 HIGH

Unspecified vulnerability in the Pegasus CIM Server in IBM Hardware Management Console (HMC) 7 R3.2.0 allows remote attackers to cause a denial of service via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm hardware_management_console 7.3.2.0
CVE-2008-0509 MEDIUM

Multiple buffer overflows in IBM AIX 4.3 allow remote attackers to cause a denial of service (crash) or possibly gain privileges via a long argument to (1) piox25, related to piox25.c; or (2) piox25remote, related to piox25remote.sh.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm aix 4.3
CVE-2008-0584 HIGH

Multiple buffer overflows in bos.rte.control in IBM AIX 5.2 and 5.3 allow local users to gain privileges via unspecified vectors related to the (1) swap, (2) swapoff, and (3) swapon programs.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 5.2
CVE-2008-0585 MEDIUM

sysmgt.websm.webaccess in IBM AIX 5.2 and 5.3 has world writable permissions for unspecified WebSM Remote Client files, which allows local users to "alter the behavior of" this client by overwriting these files.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 5.2
CVE-2008-0586 HIGH

Multiple buffer overflows in IBM AIX 5.2 and 5.3 allow local users to gain privileges via unspecified vectors related to the (1) lchangevg, (2) ldeletepv, (3) putlvodm, (4) lvaryoffvg, and (5) lvgenminor programs in bos.rte.lvm; and the (6) tellclvmd program in bos.clvm.enh.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 5.2
CVE-2008-0587 HIGH

Buffer overflow in the uspchrp program in devices.chrp.base.diag in IBM AIX 5.2 and 5.3 allows local users to gain privileges via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 5.2
CVE-2008-0588 HIGH

Buffer overflow in the utape program in devices.scsi.tape.diag in IBM AIX 5.2 and 5.3 allows local users to gain privileges via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 5.2
CVE-2008-0589 MEDIUM

The ps program in bos.rte.control in IBM AIX 5.2, 5.3, and 6.1 allows local users to obtain sensitive information via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 6.1
ibm aix 5.2
CVE-2008-0694 MEDIUM

Cross-site scripting (XSS) vulnerability in the HTTP Server in IBM OS/400 V5R3M0 and V5R4M0 allows remote attackers to inject arbitrary web script or HTML via the Expect HTTP header.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm os_400 v5r3m0
ibm os_400 v5r4m0
CVE-2008-0696 HIGH

IBM DB2 UDB before 8.2 Fixpak 16 does not properly check authorization for the ALTER TABLE statement, which has unknown impact and attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm db2 8.2_fixpack15
CVE-2008-0697 HIGH

Unspecified vulnerability in DB2PD in IBM DB2 UDB before 8.2 Fixpak 16 allows local users to gain root privileges via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm db2 8.2_fixpack15
CVE-2008-0698 HIGH

Buffer overflow in the DAS server in IBM DB2 UDB before 8.2 Fixpak 16 has unknown attack vectors, and an impact probably involving "invalid memory access."

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm db2 8.2_fixpack15
CVE-2008-0699 HIGH

Unspecified vulnerability in the ADMIN_SP_C procedure (SYSPROC.ADMIN_SP_C) in IBM DB2 UDB before 8.2 Fixpak 16, 9.1 before FP4a, and 9.5 before FP1 allows remote authenticated users to execute arbitrary code via unspecified attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm db2 9.1
ibm db2 8.2
ibm db2 9.5
CVE-2008-0717 MEDIUM

Cross-site scripting (XSS) vulnerability in Caching Proxy (CP) 5.1 through 6.1 in IBM WebSphere Edge Server, when CGI mapping rules are enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors that trigger injection into an error response.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_edge_server 6.1
ibm websphere_edge_server 6.0.1
ibm websphere_edge_server 5.1
ibm websphere_edge_server 6.0.2
ibm websphere_edge_server 5.1.1
ibm websphere_edge_server 6.0
CVE-2008-0727 HIGH

Multiple buffer overflows in oninit.exe in IBM Informix Dynamic Server (IDS) 7.x through 11.x allow (1) remote attackers to execute arbitrary code via a long password and (2) remote authenticated users to execute arbitrary code via a long DBPATH value.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm informix_dynamic_server 7.31.xd9
ibm informix_dynamic_server 9.40.uc2
ibm informix_dynamic_server 9.40.xd8
ibm informix_dynamic_server 11.10.xc2
ibm informix_dynamic_server 10.0.xc4
ibm informix_dynamic_server 10.0.xc3
ibm informix_dynamic_server 9.40.tc5
ibm informix_dynamic_server 9.40.uc1
ibm informix_dynamic_server 9.4
ibm informix_dynamic_server 9.3
ibm informix_dynamic_server 10.00.xc7w1
ibm informix_dynamic_server 9.40.uc5
ibm informix_dynamic_server 9.40.uc3
ibm informix_dynamic_server 7.3
ibm informix_dynamic_server 10.0
ibm informix_dynamic_server 7.31.xd8
ibm informix_dynamic_server 9.40_xc7
CVE-2008-0740 LOW

IBM WebSphere Application Server (WAS) before 6.0.2 Fix Pack 25 (6.0.2.25) and 6.1 before Fix Pack 15 (6.1.0.15) writes unspecified cleartext information to http_plugin.log, which might allow local users to obtain sensitive information by reading this file.

CVSS 2.0

Severity: LOW

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_application_server *
CVE-2008-0741 HIGH

Unspecified vulnerability in the PropFilePasswordEncoder utility in IBM WebSphere Application Server (WAS) before 6.0.2 Fix Pack 25 (6.0.2.25) has unknown impact and attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_application_server *
CVE-2008-0768 HIGH

Multiple stack-based and heap-based buffer overflows in the Windows RPC components for IBM Informix Storage Manager (ISM), as used in Informix Dynamic Server (IDS) 10.00.xC8 and earlier and 11.10.xC2 and earlier, allow attackers to execute arbitrary code via crafted XDR requests.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm informix_dynamic_server *
ibm informix_storage_manager -
CVE-2008-0834 MEDIUM

Cross-site scripting (XSS) vulnerability in Lotus Quickr for i5/OS before 8.0.0.2 Hotfix 11, when anonymous access is disabled on HTTP ports, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm lotus_quickr 8.0.2
ibm lotus_quickr 8.0
CVE-2008-0861 MEDIUM

Cross-site scripting (XSS) vulnerability in leg/Main.nsf in IBM Lotus Quickplace 7.0 allows remote attackers to inject arbitrary web script or HTML via an h_SearchString sub-parameter in the PreSetFields parameter of an EditDocument action.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm lotus_quickplace 7.0
CVE-2008-0862 MEDIUM

IBM Lotus Notes 6.0, 6.5, 7.0, and 8.0 signs an unsigned applet when a user forwards an email message to another user, which allows user-assisted remote attackers to bypass Execution Control List (ECL) protection.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm lotus_notes 6.5
ibm lotus_notes 8.0
ibm lotus_notes 7.0
ibm lotus_notes 6.0
CVE-2008-0949 HIGH

Unspecified vulnerability in IBM Informix Dynamic Server (IDS) 7.x through 11.x allows remote attackers to gain privileges via a malformed connection request packet.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm informix_dynamic_server 7.31.xd9
ibm informix_dynamic_server 9.40.uc2
ibm informix_dynamic_server 9.40.xd8
ibm informix_dynamic_server 11.10.xc2
ibm informix_dynamic_server 10.0.xc4
ibm informix_dynamic_server 10.0.xc3
ibm informix_dynamic_server 9.40.tc5
ibm informix_dynamic_server 9.40.uc1
ibm informix_dynamic_server 9.4
ibm informix_dynamic_server 9.3
ibm informix_dynamic_server 10.00.xc7w1
ibm informix_dynamic_server 9.40.uc5
ibm informix_dynamic_server 9.40.uc3
ibm informix_dynamic_server 7.3
ibm informix_dynamic_server 10.0
ibm informix_dynamic_server 7.31.xd8
ibm informix_dynamic_server 9.40_xc7
CVE-2008-1101 HIGH

Buffer overflow in kvdocve.dll in the KeyView document viewing engine in Autonomy (formerly Verity) KeyView, as used by IBM Lotus Notes 7.0.2 and 7.0.3, allows remote attackers to execute arbitrary code via a long pathname, as demonstrated by a long SRC attribute of an IMG element in an HTML document.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm lotus_notes 6.5
autonomy keyview 10.3.0.0
ibm lotus_notes 7.0.3
ibm lotus_notes 7.0
ibm lotus_notes 7.0.2
ibm lotus_notes 6.0
autonomy keyview 2.0.0.2
CVE-2008-1130 MEDIUM

Unspecified vulnerability in IBM WebSphere MQ 6.0.x before 6.0.2.2 and 5.3 before Fix Pack 14 allows attackers to bypass access restrictions for a queue manager via a SVRCONN (MQ client) channel.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm websphere_mq 5.3
ibm websphere_mq 6
CVE-2008-1216 MEDIUM

IBM Lotus Quickr 8.0 server, and possibly QuickPlace 7.x, does not properly identify URIs containing cross-site scripting (XSS) attack strings, which allows remote attackers to inject arbitrary web script or HTML via a Calendar OpenDocument action to main.nsf with a Count parameter containing a JavaScript event in a malformed element, as demonstrated by an onload event in an IFRAME element.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm lotus_quickr_server 8.0
CVE-2008-1217 HIGH

Unspecified vulnerability in nlnotes.dll in the client in IBM Lotus Notes 6.5, 7.0.x before 7.0.2 CCH, and 8.0.x before 8.0.1 allows remote attackers to execute arbitrary code via a crafted attachment in an e-mail message sent over SMTP, a variant of CVE-2007-6706.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-94,

Products Affected

Vendor Product Version
ibm lotus_notes 6.5
ibm lotus_notes 8.0.0
ibm lotus_notes 7.0.2
CVE-2008-1274 MEDIUM

Untrusted search path vulnerability in man in IBM AIX 6.1.0 allows local users to execute arbitrary code via a malicious program in the man directory.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 6.1.0
CVE-2008-1287 MEDIUM

IBM Rational ClearQuest 7.0.1.1 and 7.0.0.2 generates different error messages depending on whether the username is valid or invalid, which allows remote attackers to enumerate usernames.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-16,

Products Affected

Vendor Product Version
ibm rational_clearquest 7.0.1.1
ibm rational_clearquest 7.0.0.2
CVE-2008-1288 MEDIUM

IBM Rational ClearQuest 7.0.1.1 and 7.0.0.2 might allow local or remote attackers to obtain sensitive information about users by reading user cookies.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_clearquest 7.0.1.1
ibm rational_clearquest 7.0.0.2
CVE-2008-1592 MEDIUM

MQSeries 5.1 in IBM WebSphere MQ 5.1 through 5.3.1 on the HP NonStop and Tandem NSK platforms does not require mqm group membership for execution of administrative tasks, which allows local users to bypass intended access restrictions via the runmqsc program, related to "Pathway panels."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_mq 5.1
ibm websphere_mq 5.3
ibm websphere_mq 5.3.1
CVE-2008-1593 HIGH

The checkpoint and restart feature in the kernel in IBM AIX 5.2, 5.3, and 6.1 does not properly protect kernel memory, which allows local users to read and modify portions of memory and gain privileges via unspecified vectors involving a restart of a 64-bit process, probably related to the as_getadsp64 function.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 6.1
ibm aix 5.2
CVE-2008-1594 MEDIUM

The kernel in IBM AIX 5.2 and 5.3 does not properly handle resizing JFS2 filesystems on concurrent volume groups spread across multiple nodes, which allows local users of one node to cause a denial of service (remote node crash) by using chfs or lreducelv to reduce a filesystem's size.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 6.1
ibm aix 5.2
CVE-2008-1595 MEDIUM

The proc filesystem in the kernel in IBM AIX 5.2 and 5.3 does not properly enforce directory permissions when a file executing from a directory has weaker permissions than the directory itself, which allows local users to obtain sensitive information.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 6.1
ibm aix 5.2
CVE-2008-1596 HIGH

Trusted Execution in IBM AIX 6.1 uses an incorrect pathname argument in a call to the trustchk_block_write function, which might allow local users to modify trusted files, related to missing checks in the TSD_FILES_LOCK policy for modifications performed via hard links, a different vulnerability than CVE-2007-6680.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 6.1
ibm aix 5.2
CVE-2008-1597 MEDIUM

The WPAR system call implementation in the kernel in IBM AIX 6.1 allows local users to cause a denial of service via unknown calls that trigger "undefined behavior."

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm aix 6.1
CVE-2008-1598 MEDIUM

The kernel in IBM AIX 6.1 allows local users with ProbeVue privileges to read arbitrary kernel memory and obtain sensitive information via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm aix 6.1
CVE-2008-1599 HIGH

The nddstat programs on IBM AIX 5.2, 5.3, and 6.1 do not properly handle environment variables, which allows local users to gain privileges by invoking (1) atmstat, (2) entstat, (3) fddistat, (4) hdlcstat, or (5) tokstat.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 6.1
ibm aix 5.2
CVE-2008-1600 HIGH

The lsmcode program on IBM AIX 5.2, 5.3, and 6.1 does not properly handle environment variables, which allows local users to gain privileges, a different vulnerability than CVE-2004-1329.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 6.1
ibm aix 5.2
CVE-2008-1601 HIGH

Stack-based buffer overflow in the reboot program on IBM AIX 5.2 and 5.3 allows local users in the shutdown group to gain privileges.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 5.2
CVE-2008-1681 HIGH

Unspecified vulnerability in IBM DB2 Content Manager before 8.3 FP8 has unknown impact and attack vectors related to the AllowedTrustedLogin privilege.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm db2_content_manager *
CVE-2008-1705 MEDIUM

Format string vulnerability in the logging function in IBM solidDB 06.00.1018 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the (1) user name, (2) peer name, and possibly unspecified other fields.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-134,

Products Affected

Vendor Product Version
ibm soliddb 06.00.1018
CVE-2008-1706 MEDIUM

Uncontrolled array index in IBM solidDB 06.00.1018 and earlier allows remote attackers to cause a denial of service (daemon crash) via a large value in a certain 32-bit field.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-189,

Products Affected

Vendor Product Version
ibm soliddb 06.00.1018
CVE-2008-1707 MEDIUM

IBM solidDB 06.00.1018 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a packet with an 0x11 value in a certain "type" field.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm soliddb *
CVE-2008-1708 MEDIUM

IBM solidDB 06.00.1018 and earlier does not validate a certain field that specifies an amount of memory to allocate, which allows remote attackers to cause a denial of service (daemon exit) via a packet with a large value in this field.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm soliddb *
CVE-2008-1710 HIGH

Untrusted search path vulnerability in chnfsmnt in IBM AIX 6.1 allows local users to gain privileges via a modified PATH environment variable.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm aix 6.1
CVE-2008-1718 HIGH

Buffer overflow in mimesr.dll in Autonomy (formerly Verity) KeyView, as used in IBM Lotus Notes before 8.0, might allow user-assisted remote attackers to execute arbitrary code via an e-mail message with a crafted Text mail (MIME) attachment.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm lotus_notes 6.5
ibm lotus_notes 8.0
autonomy keyview *
ibm lotus_notes 7.0
ibm lotus_notes 6.0
ibm lotus_notes 8.0.1
CVE-2008-1965 HIGH

Argument injection vulnerability in the cai: URI handler in rcplauncher in IBM Lotus Expeditor Client for Desktop 6.1.1 and 6.1.2, as used by Lotus Symphony and possibly other products, allows remote attackers to execute arbitrary code by injecting a -launcher option via a cai: URI, as demonstrated by a reference to a UNC share pathname.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-94,

Products Affected

Vendor Product Version
ibm lotus_expeditor_client 6.1.2
ibm lotus_symphany *
ibm lotus_expeditor_client 6.1.1
CVE-2008-1966 MEDIUM

Multiple buffer overflows in the JAR file administration routines in the BSU JAVA subcomponent in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before FP1 allow remote authenticated users to cause a denial of service (instance crash) via a call to the (1) RECOVERJAR or (2) REMOVE_JAR procedure with a crafted parameter, related to (a) sqlj.install_jar and (b) sqlj.replace_jar.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm db2 9.1
ibm db2 8.0
ibm db2 9.5
CVE-2008-1997 HIGH

Unspecified vulnerability in the ADMIN_SP_C2 procedure in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before FP1 allows remote authenticated users to execute arbitrary code via unknown vectors. NOTE: the ADMIN_SP_C issue is already covered by CVE-2008-0699.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-94,

Products Affected

Vendor Product Version
ibm db2 9.1
ibm db2 8.0
ibm db2 9.5
CVE-2008-1998 HIGH

The NNSTAT (aka SYSPROC.NNSTAT) procedure in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before FP1 on Windows allows remote authenticated users to overwrite arbitrary files via the log file parameter.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm db2 9.1
ibm db2 8.0
ibm db2 9.5
CVE-2008-2122 MEDIUM

IBM Rational Build Forge 7.0.2 allows remote attackers to cause a denial of service (CPU consumption) via a port scan, which spawns multiple bfagent server processes that attempt to read data from closed sockets.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 3.9 3.6

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-772,

Products Affected

Vendor Product Version
ibm rational_build_forge 7.0.2
CVE-2008-2154 MEDIUM

IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 provides an INSTALL_JAR (aka sqlj.install_jar) procedure, which allows remote authenticated users to create or overwrite arbitrary files via unspecified calls.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-16,

Products Affected

Vendor Product Version
ibm db2 9.1
ibm db2 8.0
ibm db2 9.5
CVE-2008-2163 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Lotus Quickr 8.1 before Hotfix 5 for Windows and AIX, and before Hotfix 3 for i5/OS, allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to "WYSIWYG editors."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm lotus_quickr 8.1
CVE-2008-2221 HIGH

Unspecified vulnerability in the Java plugin in IBM WebSphere Application Server 5.0.2 allows untrusted applets to gain privileges via unknown attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_application_server 5.0.2
CVE-2008-2240 HIGH

Stack-based buffer overflow in the Web Server service in IBM Lotus Domino before 7.0.3 FP1, and 8.x before 8.0.1, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long Accept-Language HTTP header.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm lotus_domino 7.0
ibm lotus_domino 6.5
ibm lotus_domino 6.0
ibm lotus_domino 8.0.1
ibm lotus_domino 8.0
CVE-2008-2410 MEDIUM

Cross-site scripting (XSS) vulnerability in the servlet engine and Web container in the Web Server service in IBM Lotus Domino before 7.0.3 FP1, and 8.x before 8.0.1, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm lotus_domino_web_server 7.0.1
ibm lotus_domino_web_server *
ibm lotus_domino_web_server 7.0
ibm lotus_domino_web_server 7.0.2
ibm lotus_domino_web_server 7.0.3
CVE-2008-2499 HIGH

Stack-based buffer overflow in the Community Services Multiplexer (aka MUX or StMux.exe) in IBM Lotus Sametime 7.5.1 CF1 and earlier, and 8.x before 8.0.1, allows remote attackers to execute arbitrary code via a crafted URL.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm lotus_sametime *
ibm lotus_sametime 7.5.1
CVE-2008-2513 HIGH

Buffer overflow in the kernel in IBM AIX 5.2, 5.3, and 6.1 allows local users to execute arbitrary code in kernel mode via unknown attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 6.1
ibm aix 5.2
CVE-2008-2514 MEDIUM

Buffer overflow in errpt in IBM AIX 5.2, 5.3, and 6.1 allows local users to gain privileges via unknown attack vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 6.1
ibm aix 5.2
CVE-2008-2515 HIGH

Unspecified vulnerability in iostat in IBM AIX 5.2, 5.3, and 6.1 allows local users to gain privileges via unknown vectors related to an "environment variable handling error."

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 6.1
ibm aix 5.2
CVE-2008-2550 MEDIUM

Unspecified vulnerability in the Web Services Security component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.17 has unknown impact and attack vectors related to an attribute in the SOAP security header.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.1.0.10
ibm websphere_application_server 6.1.0.14
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0
ibm websphere_application_server 6.1.0.4
ibm websphere_application_server 6.1
ibm websphere_application_server *
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.8
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.6
ibm websphere_application_server 6.1.0.11
CVE-2008-2709 MEDIUM

Buffer overflow in the BrSmRcvAndCheck function in the RCHMGR module on IBM OS/400 V5R4M0, V5R4M5, and V6R1M0 allows local users to cause a denial of service (task halt and main storage dump) via unspecified vectors involving the running of diagnostics on a modem port. NOTE: there might be limited attack scenarios.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm os_400 v6r1m0
ibm os_400 v5r4m5
ibm os_400 v5r4m0
CVE-2008-2880 HIGH

Heap-based buffer overflow in the IBM AFP Viewer Plug-in 2.0.7.1 and 3.2.1.1 allows remote attackers to execute arbitrary code via a long SRC property value. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm afp_viewer_plug-in 3.2.1.1
ibm afp_viewer_plug-in 2.0.7.1
CVE-2008-2943 MEDIUM

Double free vulnerability in IBM Tivoli Directory Server (TDS) 6.1.0.0 through 6.1.0.15 allows remote authenticated administrators to cause a denial of service (ABEND) and possibly execute arbitrary code by using ldapadd to attempt to create a duplicate ibm-globalAdminGroup LDAP database entry. NOTE: the vendor states "There is no real risk of a vulnerability," although there are likely scenarios in which a user is allowed to make administrative LDAP requests but does not have the privileges to stop the server.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm tivoli_directory_server 6.1.0.0
ibm tivoli_directory_server 6.1.0.12
ibm tivoli_directory_server 6.1.0.5
ibm tivoli_directory_server 6.1.0.6
ibm tivoli_directory_server 6.1.0.11
ibm tivoli_directory_server 6.1.0.4
ibm tivoli_directory_server 6.1.0.9
ibm tivoli_directory_server 6.1.0.10
ibm tivoli_directory_server 6.1.0.13
ibm tivoli_directory_server 6.1.0.3
ibm tivoli_directory_server 6.1.0.14
ibm tivoli_directory_server 6.1.0.7
ibm tivoli_directory_server 6.1.0.15
ibm tivoli_directory_server 6.1.0.2
ibm tivoli_directory_server 6.1.0.8
ibm tivoli_directory_server 6.1.0.1
CVE-2008-3160 HIGH

Multiple unspecified vulnerabilities in IBM Data ONTAP 7.1 before 7.1.3, as used by IBM System Storage N series Filer and IBM System Storage N series Gateway, have unknown impact and attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm data_ontap *
CVE-2008-3161 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in jsp/common/system/debug.jsp in IBM Maximo 4.1 and 5.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Accept, (2) Accept-Language, (3) UA-CPU, (4) Accept-Encoding, (5) User-Agent, or (6) Cookie HTTP header. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm maximo 4.1
ibm maximo 5.2
CVE-2008-3235 HIGH

Unspecified vulnerability in the PropFilePasswordEncoder utility in the Security component in IBM WebSphere Application Server (WAS) 5.1 before 5.1.1.19 has unknown impact and attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-255,NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_application_server 5.1.1
ibm websphere_application_server 5.1.1.7
ibm websphere_application_server 5.1.1.16
ibm websphere_application_server 5.1.1.1
ibm websphere_application_server 5.1.1.13
ibm websphere_application_server 5.1.1.14
ibm websphere_application_server 5.1.1.3
ibm websphere_application_server 5.1.1.2
ibm websphere_application_server 5.1.1.12
ibm websphere_application_server 5.1.1.15
ibm websphere_application_server 5.1.0
ibm websphere_application_server 5.1.1.5
ibm websphere_application_server 5.1.1.6
ibm websphere_application_server 5.1.1.9
ibm websphere_application_server 5.1.1.17
ibm websphere_application_server 5.1.1.11
ibm websphere_application_server 5.1.1.18
ibm websphere_application_server 5.1.1.8
ibm websphere_application_server 5.1.1.10
ibm websphere_application_server 5.1.1.4
CVE-2008-3236 MEDIUM

Unspecified vulnerability in Wsadmin in the System Management/Repository component in IBM WebSphere Application Server (WAS) 5.1 before 5.1.1.19 allows attackers to obtain sensitive information via vectors related to "previously encrypted properties" that are not encrypted.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_application_server 5.1.1
ibm websphere_application_server 5.1.1.7
ibm websphere_application_server 5.1.1.16
ibm websphere_application_server 5.1.1.1
ibm websphere_application_server 5.1.1.13
ibm websphere_application_server 5.1.1.14
ibm websphere_application_server 5.1.1.3
ibm websphere_application_server 5.1.1.2
ibm websphere_application_server 5.1.1.12
ibm websphere_application_server 5.1.1.15
ibm websphere_application_server 5.1.0
ibm websphere_application_server 5.1.1.5
ibm websphere_application_server 5.1.1.6
ibm websphere_application_server 5.1.1.9
ibm websphere_application_server 5.1.1.17
ibm websphere_application_server 5.1.1.11
ibm websphere_application_server 5.1.1.18
ibm websphere_application_server 5.1.1.8
ibm websphere_application_server 5.1.1.10
ibm websphere_application_server 5.1.1.4
CVE-2008-3423 HIGH

IBM WebSphere Portal 5.1 through 6.1.0.0 allows remote attackers to bypass authentication and obtain administrative access via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_portal 6.0.1.3
ibm websphere_portal 6.0.0.0
ibm websphere_portal 5.1.0.4
ibm websphere_portal 6.0.0.1
ibm websphere_portal 6.0.1.1
ibm websphere_portal 5.1.0.2
ibm websphere_portal 5.1.0.3
ibm websphere_portal 5.1.0.5
ibm websphere_portal 5.1.0.0
ibm websphere_portal 5.1.0.1
ibm websphere_portal 6.1.0.0
CVE-2008-3550 MEDIUM

The CQWeb login page in IBM Rational ClearQuest 7.0.1 allows remote attackers to obtain potentially sensitive information (page source code) via a combination of ?script? and ?/script? sequences in the id field, possibly related to a cross-site scripting (XSS) vulnerability.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_clearquest 7.0.1
CVE-2008-3852 MEDIUM

Unspecified vulnerability in the CLR stored procedure deployment from IBM Database Add-Ins for Visual Studio in the Visual Studio Net component in IBM DB2 9.1 before Fixpak 5 and 9.5 before Fixpak 2 allows remote authenticated users to execute arbitrary code via unknown vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm db2_universal_database 9.5
ibm db2_universal_database *
ibm db2_universal_database 9.1
CVE-2008-3853 HIGH

Buffer overflow in the DAS server program in the Core DAS function component in IBM DB2 9.1 before FP4a and 9.5 before FP1 allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via unspecified vectors. NOTE: this might be related to CVE-2007-3676.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm db2_universal_database 9.1
CVE-2008-3854 HIGH

Multiple stack-based buffer overflows in IBM DB2 9.1 before Fixpak 5 and 9.5 before Fixpak 1 allow remote attackers to cause a denial of service (system outage) via vectors related to (1) use of XQuery to issue statements; the (2) XMLQUERY, (3) XMLEXISTS, and (4) XMLTABLE statements; and the (5) sqlrlaka function.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm db2_universal_database 9.5
ibm db2_universal_database 9.1
CVE-2008-3855 MEDIUM

Unspecified vulnerability in the DB2 Administration Server (DAS) in the Core DAS function component in IBM DB2 9.1 before Fixpak 5 allows local users to gain privileges, aka a "FILE CREATION VULNERABILITY." NOTE: this may be the same as CVE-2007-5664.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm db2_universal_database 9.1
CVE-2008-3856 HIGH

The routine infrastructure component in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP1 on Unix and Linux does not change the ownership of the db2fmp process, which has unknown impact and attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm db2_universal_database *
ibm db2_universal_database 8
ibm db2_universal_database 8.0
ibm db2_universal_database 9.1
CVE-2008-3857 MEDIUM

The Base Service Utilities component in IBM DB2 9.1 before Fixpak 5 retains a cleartext password in memory after the database connection that sent the password is fully established, which might allow local users to obtain sensitive information by reading a memory dump.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm db2_universal_database 9.1
CVE-2008-3858 MEDIUM

The Downlevel DB2RA Support component in IBM DB2 9.1 before Fixpak 4a allows remote attackers to cause a denial of service (instance crash) via a crafted CONNECT data stream that simulates a V7 client connect request.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm db2_universal_database 9.1
CVE-2008-3860 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities (1) in the WYSIWYG editors, (2) during local group creation, (3) during HTML redirects, (4) in the HTML import, (5) in the Rich text editor, and (6) in link-page in IBM Lotus Quickr 8.1 services for Lotus Domino before Hotfix 15 allow remote attackers to inject arbitrary web script or HTML via unknown vectors, including (7) the Imported Page. NOTE: the vulnerability in the WYSIWYG editors may exist because of an incomplete fix for CVE-2008-2163.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm lotus_quickr 8.1
CVE-2008-3894 LOW

IBM Lenovo firmware 7CETB5WW 2.05 stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm lenovo_7cetb5ww 2.05
CVE-2008-3958 HIGH

IBM DB2 UDB 8 before Fixpak 17 allows remote attackers to cause a denial of service (instance crash) via a crafted CONNECT/ATTACH data stream that simulates a V7 client connect/attach request. NOTE: this may overlap CVE-2008-3858. NOTE: this issue exists because of an incomplete fix for CVE-2008-3959.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm db2 8.0
ibm db2 *
CVE-2008-3959 MEDIUM

IBM DB2 UDB 8.1 before FixPak 16, 8.2 before FixPak 9, and 9.1 before FixPak 4a allows remote attackers to cause a denial of service (instance crash) via a crafted SQLJRA packet within a CONNECT/ATTACH data stream that simulates a V7 client connect/attach request.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm db2 8.1
ibm db2 8.2
ibm db2 *
CVE-2008-3960 MEDIUM

Unspecified vulnerability in the JDBC Applet Server Service (aka db2jds) in IBM DB2 UDB 8 before Fixpak 17 allows remote attackers to cause a denial of service (service crash) via "malicious packets."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm db2_universal_database *
ibm db2_universal_database 8.2
CVE-2008-4018 HIGH

swcons in bos.rte.console in IBM AIX 5.2.0 through 6.1.1 allows local users in the system group to create or overwrite an arbitrary file, and establish weak permissions and root ownership for this file, via unspecified vectors. NOTE: this can be leveraged to gain privileges. NOTE: this issue exists because of an incomplete fix for CVE-2007-5805.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 6.1
ibm aix 5.2
CVE-2008-4111 HIGH

Unspecified vulnerability in Servlet Engine/Web Container in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.31 and 6.1 before 6.1.0.19, when the FileServing feature is enabled, has unknown impact and attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.1.0.10
ibm websphere_application_server 6.1.0.14
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0
ibm websphere_application_server 6.1.0.4
ibm websphere_application_server 6.1
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.16
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.8
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.18
ibm websphere_application_server 6.1.0.6
ibm websphere_application_server 6.1.0.11
CVE-2008-4283 HIGH

CRLF injection vulnerability in the WebContainer component in IBM WebSphere Application Server (WAS) 5.1.1.19 and earlier 5.1.x versions allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm websphere_application_server 5.1.1
ibm websphere_application_server 5.1.1.14
ibm websphere_application_server 5.0.2.4
ibm websphere_application_server 5.1.1.2
ibm websphere_application_server 5.0.1
ibm websphere_application_server 5.0.2.6
ibm websphere_application_server 5.0.2.15
ibm websphere_application_server 5.1.1.12
ibm websphere_application_server 5.1.1.15
ibm websphere_application_server 5.0.2.10
ibm websphere_application_server 5.1.1.6
ibm websphere_application_server *
ibm websphere_application_server 5.1.1.11
ibm websphere_application_server 5.0.2.11
ibm websphere_application_server 5.0.2.1
ibm websphere_application_server 5.1.0.2
ibm websphere_application_server 5.0.2.7
ibm websphere_application_server 5.1.1.10
ibm websphere_application_server 5.0.2.9
ibm websphere_application_server 5.0.2.5
ibm websphere_application_server 5.0.2.14
ibm websphere_application_server 5.1.1.7
ibm websphere_application_server 5.1.1.16
ibm websphere_application_server 5.1.1.1
ibm websphere_application_server 5.1.1.13
ibm websphere_application_server 5.1.1.3
ibm websphere_application_server 5.1.0.3
ibm websphere_application_server 5.0.2.16
ibm websphere_application_server 5.0.2.3
ibm websphere_application_server 5.0
ibm websphere_application_server 5.0.2.12
ibm websphere_application_server 5.1.0
ibm websphere_application_server 5.1.1.5
ibm websphere_application_server 5.1.1.9
ibm websphere_application_server 5.1.1.17
ibm websphere_application_server 5.0.2.2
ibm websphere_application_server 5.0.2.13
ibm websphere_application_server 5.0.0
ibm websphere_application_server 5.0.2.8
ibm websphere_application_server 5.1.1.18
ibm websphere_application_server 5.0.2
ibm websphere_application_server 5.1.0.5
ibm websphere_application_server 5.1.1.8
ibm websphere_application_server 5.1.0.4
ibm websphere_application_server 5.1.1.4
CVE-2008-4284 MEDIUM

Open redirect vulnerability in the ibm_security_logout servlet in IBM WebSphere Application Server (WAS) 5.1.1.19 and earlier 5.x versions, 6.0.x before 6.0.2.33, and 6.1.x before 6.1.0.23 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the logoutExitPage feature.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-59,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 6.0.2.19
ibm websphere_application_server 6.1.0.14
ibm websphere_application_server 6.0.2.7
ibm websphere_application_server 6.1.0.20
ibm websphere_application_server 5.0.2.6
ibm websphere_application_server 5.1.1.12
ibm websphere_application_server 5.1.0.2
ibm websphere_application_server 5.1.1.16
ibm websphere_application_server 6.1.0.10
ibm websphere_application_server 6.0.2.25
ibm websphere_application_server 6.0.2.9
ibm websphere_application_server 5.0.2.2
ibm websphere_application_server 5.1.1.18
ibm websphere_application_server 6.1.1
ibm websphere_application_server 6.1.0.18
ibm websphere_application_server 6.1.0.6
ibm websphere_application_server 5.1.1
ibm websphere_application_server 6.0.2.13
ibm websphere_application_server 6.0.1.11
ibm websphere_application_server 5.0.2.4
ibm websphere_application_server 5.0.2.15
ibm websphere_application_server 6.0.2.15
ibm websphere_application_server 5.0.2.10
ibm websphere_application_server 6.0.2.4
ibm websphere_application_server 6.1.0
ibm websphere_application_server 6.1.0.4
ibm websphere_application_server 6.1
ibm websphere_application_server 5.1.1.11
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 5.0.2.7
ibm websphere_application_server 5.0.2.9
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 5.1.0.3
ibm websphere_application_server 6.0.2.6
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 5.0.2.3
ibm websphere_application_server 6.0.2.24
ibm websphere_application_server 6.0.2.5
ibm websphere_application_server 5.1.0
ibm websphere_application_server 5.1.1.17
ibm websphere_application_server 5.0.2.13
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.8
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.0.1.1
ibm websphere_application_server 6.0.2.1
ibm websphere_application_server 6.1.13
ibm websphere_application_server 6.0.1.5
ibm websphere_application_server 6.0.0.1
ibm websphere_application_server 5.1.1.14
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.0.0.2
ibm websphere_application_server 5.1.1.15
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.6
ibm websphere_application_server 5.1.1.10
ibm websphere_application_server 6.0.1.2
ibm websphere_application_server 5.0.2.14
ibm websphere_application_server 6.1.3
ibm websphere_application_server 6.0.1.17
ibm websphere_application_server 6.0.1.13
ibm websphere_application_server 5.0.2.16
ibm websphere_application_server 5.0
ibm websphere_application_server 6.0.2.31
ibm websphere_application_server 5.0.2.12
ibm websphere_application_server 6.1.7
ibm websphere_application_server 6.0.2.22
ibm websphere_application_server 5.0.0
ibm websphere_application_server 6.0
ibm websphere_application_server 5.0.2.8
ibm websphere_application_server 6.0.1.3
ibm websphere_application_server 5.0.2
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 5.1.0.4
ibm websphere_application_server 6.0.2.2
ibm websphere_application_server 6.0.2.11
ibm websphere_application_server 5.1.1.19
ibm websphere_application_server 6.0.1.15
ibm websphere_application_server 5.0.1
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 6.1.0.22
ibm websphere_application_server 6.0.2.30
ibm websphere_application_server 6.0.2.32
ibm websphere_application_server 5.0.2.11
ibm websphere_application_server 5.0.2.1
ibm websphere_application_server 5.0.2.5
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 5.1.1.1
ibm websphere_application_server 5.1.1.13
ibm websphere_application_server 6.0.2.23
ibm websphere_application_server 6.0.1
ibm websphere_application_server 6.0.1.7
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.0.2.17
ibm websphere_application_server 6.1.5
ibm websphere_application_server 6.1.14
ibm websphere_application_server 6.0.2.3
ibm websphere_application_server 6.1.0.16
ibm websphere_application_server 6.0.2.29
ibm websphere_application_server 6.0.1.9
ibm websphere_application_server 6.0.2
ibm websphere_application_server 6.0.2.28
ibm websphere_application_server 6.0.2.27
ibm websphere_application_server 5.1.0.5
ibm websphere_application_server 6.0.0.3
CVE-2008-4285 MEDIUM

Unspecified vulnerability in the Performance Monitoring Infrastructure (PMI) feature in the Servlet Engine/Web Container component in IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.19, when a component statistic is enabled, allows attackers to cause a denial of service (daemon crash) via vectors related to "a gradual degradation in performance."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.1.0
ibm websphere_application_server 6.1
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 6.1.13
CVE-2008-4294 HIGH

IBM Tivoli Netcool/Webtop 2.1 before 2.1.0.5 preserves cached user privileges after logout, which allows physically proximate attackers to hijack a session by visiting an unattended workstation, as demonstrated by a root session that is still valid after a subsequent read-only session has begun.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm tivoli_netcool_webtop 2.1.0
CVE-2008-4404 HIGH

The IPv6 Neighbor Discovery Protocol (NDP) implementation on IBM zSeries servers does not validate the origin of Neighbor Discovery messages, which allows remote attackers to cause a denial of service (loss of connectivity) or read private network traffic via a spoofed message that modifies the Forward Information Base (FIB), a related issue to CVE-2008-2476.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm zseries *
CVE-2008-4505 HIGH

Unspecified vulnerability in IBM Lotus Quickr 8.1 before Fix pack 1 (8.1.0.1) might allow attackers to cause a denial of service (system crash) via a "nonstandard URL argument" to the OpenDocument command. NOTE: due to lack of details from the vendor, it is not clear whether this is a vulnerability.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm lotus_quickr 8.1
CVE-2008-4506 HIGH

Unspecified vulnerability in IBM Lotus Quickr 8.1 before Fix pack 1 (8.1.0.1) allows a place manager to "demote or delete a place superuser group" via unknown vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm lotus_quickr 8.1
CVE-2008-4507 HIGH

Unspecified vulnerability in IBM Lotus Quickr 8.1 before Fix pack 1 (8.1.0.1) allows editors to delete pages that were created by a different author via unknown vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm lotus_quickr 8.1
CVE-2008-4563 HIGH

Heap-based buffer overflow in adsmdll.dll 5.3.7.7296, as used by the daemon (dsmsvc.exe) in the backup server in IBM Tivoli Storage Manager (TSM) Express 5.3.7.3 and earlier and TSM 5.2, 5.3 before 5.3.6.0, and 5.4.0.0 through 5.4.4.0, allows remote attackers to execute arbitrary code via a crafted length value.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager 5.2
ibm tivoli_storage_manager 5.4.2
ibm tivoli_storage_manager 5.3.1
ibm tivoli_storage_manager 5.3
ibm tivoli_storage_manager 5.4.1
ibm tivoli_storage_manager 5.4.4.0
ibm tivoli_storage_manager 5.3.4
ibm tivoli_storage_manager 5.3.2
ibm tivoli_storage_manager_express 5.3.7.3
ibm tivoli_storage_manager 5.3.5.1
ibm tivoli_storage_manager 5.3.3
ibm tivoli_storage_manager_express 5.3.3.0
ibm tivoli_storage_manager 5.4.0
ibm tivoli_storage_manager 5.4.2.4
ibm tivoli_storage_manager 5.4.2.3
ibm tivoli_storage_manager 5.3.0
ibm tivoli_storage_manager 5.3.2.4
ibm tivoli_storage_manager_express 5.3
ibm tivoli_storage_manager 5.4.2.2
ibm tivoli_storage_manager_express 5.3.6.4
CVE-2008-4564 HIGH

Stack-based buffer overflow in wp6sr.dll in the Autonomy KeyView SDK 10.4 and earlier, as used in IBM Lotus Notes, Symantec Mail Security (SMS) products, Symantec BrightMail Appliance products, and Symantec Data Loss Prevention (DLP) products, allows remote attackers to execute arbitrary code via a crafted Word Perfect Document (WPD) file.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm lotus_notes 6.0.2
symantec mail_security 5.0.1
symantec mail_security 5.0.11
symantec mail_security 5.0.1.181
ibm lotus_notes 7.0.2
symantec mail_security 5.0.0
autonomy keyview_export_sdk 2.0
ibm lotus_notes 6.5.6
ibm lotus_notes 6.5.2
symantec data_loss_prevention_endpoint_agents 8.1
symantec data_loss_prevention_detection_servers 7.0
ibm lotus_notes 8.0
ibm lotus_notes 5.0.3
symantec altiris_deployment_solution *
autonomy keyview_filter_sdk 10
ibm lotus_notes 6.0.3
ibm lotus_notes 6.0.5
symantec data_loss_prevention_detection_servers 8.0
symantec enforce 8.0
ibm lotus_notes 6.0.1
symantec mail_security 6.0.7
ibm lotus_notes 6.5.1
ibm lotus_notes 6.5.5
ibm lotus_notes 7.0.1
symantec enforce 8.1
autonomy keyview_viewer_sdk 2.0
autonomy keyview_viewer_sdk *
symantec mail_security 5.0.1.189
ibm lotus_notes 6.0.4
autonomy keyview_filter_sdk *
ibm lotus_notes 5.0.12
symantec mail_security 7.5..4.29
autonomy keyview_viewer_sdk 9.2.0
symantec enforce 7.0
autonomy keyview_export_sdk 10
autonomy keyview_export_sdk 9.2.0
symantec brightmail 5.0
ibm lotus_notes 6.5
symantec mail_security 5.0.1.182
ibm lotus_notes 6.5.3
autonomy keyview_filter_sdk 2.0
symantec mail_security 5.0.0.24
autonomy keyview_viewer_sdk 10
symantec mail_security 5.0
symantec data_loss_prevention_endpoint_agents 8.0
symantec mail_security 5.0.10
autonomy keyview_filter_sdk 10.3
symantec mail_security 7.5.3.25
symantec mail_security 7.5.5.32
ibm lotus_notes 7.0.3
symantec mail_security 6.0.6
autonomy keyview_export_sdk 10.3
ibm lotus_notes 7.0
autonomy keyview_filter_sdk 9.2.0
autonomy keyview_export_sdk *
ibm lotus_notes 6.5.4
ibm lotus_notes 6.0
symantec data_loss_prevention_detection_servers 8.1
symantec mail_security 5.0.1.200
autonomy keyview_viewer_sdk 10.3
CVE-2008-4581 MEDIUM

The Editor in IBM ENOVIA SmarTeam 5 before release 18 SP5, and release 19 before SP01, allows remote authenticated users to bypass intended access restrictions and read Document objects via the Workflow Process (aka Flow Process) view.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm enovia_smarteam 5
CVE-2008-4678 HIGH

The HTTP_Request_Parser method in the HTTP Transport component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.31 allows remote attackers to cause a denial of service (controller 0C4 abend and application hang) via a long HTTP Host header, related to "storage overlay" on the stack and a "parse failure."

CVSS 2.0

Severity: HIGH

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.0.2.2
ibm websphere_application_server 6.0.2.13
ibm websphere_application_server 6.0.2.11
ibm websphere_application_server 6.0.2.25
ibm websphere_application_server 6.0.2.19
ibm websphere_application_server 6.0.2.23
ibm websphere_application_server 6.0.2.6
ibm websphere_application_server 6.0.2.17
ibm websphere_application_server 6.0.2.5
ibm websphere_application_server 6.0.2.9
ibm websphere_application_server 6.0.2.15
ibm websphere_application_server 6.0.2.4
ibm websphere_application_server 6.0.2.3
ibm websphere_application_server 6.0.2
ibm websphere_application_server 6.0.2.27
ibm websphere_application_server 6.0.2.1
CVE-2008-4679 MEDIUM

The Web Services Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.31 and 6.1 before 6.1.0.19, when Certificate Store Collections is configured to use Certificate Revocation Lists (CRL), does not call the setRevocationEnabled method on the PKIXBuilderParameters object, which prevents the "Java security method" from checking the revocation status of X.509 certificates and allows remote attackers to bypass intended access restrictions via a SOAP message with a revoked certificate.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.0.2.2
ibm websphere_application_server 6.0.1.5
ibm websphere_application_server 6.0.2.13
ibm websphere_application_server 6.0.1.11
ibm websphere_application_server 6.0.2.11
ibm websphere_application_server 6.0.2.19
ibm websphere_application_server 6.0.1.15
ibm websphere_application_server 6.0.2.15
ibm websphere_application_server 6.0.2.4
ibm websphere_application_server 6.0.1.2
ibm websphere_application_server 6.0.1.17
ibm websphere_application_server 6.0.2.25
ibm websphere_application_server 6.0.1.13
ibm websphere_application_server 6.0.2.23
ibm websphere_application_server 6.0.2.6
ibm websphere_application_server 6.0.1.7
ibm websphere_application_server 6.0.2.17
ibm websphere_application_server 6.0.2.5
ibm websphere_application_server 6.0.2.9
ibm websphere_application_server 6.0.2.3
ibm websphere_application_server 6.0.1.9
ibm websphere_application_server 6.0.2
ibm websphere_application_server 6.0.1.3
ibm websphere_application_server 6.0.2.27
ibm websphere_application_server 6.0.1.1
ibm websphere_application_server 6.0.2.1
CVE-2008-4691 MEDIUM

Unspecified vulnerability in the SQLNLS_UNPADDEDCHARLEN function in the New Compiler (aka Starburst derived compiler) component in the server in IBM DB2 9.1 before FP6 allows attackers to cause a denial of service (segmentation violation and trap) via unknown vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm db2 9.1
ibm db2 *
CVE-2008-4692 HIGH

The Native Managed Provider for .NET component in IBM DB2 8 before FP17, 9.1 before FP6, and 9.5 before FP2, when a definer cannot maintain objects, preserves views and triggers without marking them inoperative or dropping them, which has unknown impact and attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm db2 9.1
ibm db2 8.0
ibm db2 9.5
ibm db2 *
CVE-2008-4693 MEDIUM

The SORT/LIST SERVICES component in IBM DB2 9.1 before FP6 and 9.5 before FP2 writes sensitive information to the trace output, which allows attackers to obtain sensitive information by reading "PASSWORD-RELATED CONNECTION STRING KEYWORD VALUES."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm db2 9.1
ibm db2 9.5
ibm db2 *
CVE-2008-4801 HIGH

Heap-based buffer overflow in the Data Protection for SQL CAD service (aka dsmcat.exe) in the Client Acceptor Daemon (CAD) and the scheduler in the Backup-Archive client 5.1.0.0 through 5.1.8.1, 5.2.0.0 through 5.2.5.2, 5.3.0.0 through 5.3.6.1, 5.4.0.0 through 5.4.2.2, and 5.5.0.0 through 5.5.0.91 in IBM Tivoli Storage Manager (TSM); and the Backup-Archive client in TSM Express; allows remote attackers to execute arbitrary code by sending a large amount of crafted data to a TCP port.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_client *
ibm tivoli_storage_manager_express *
CVE-2008-4805 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Connections 2.x before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via (1) the community title, (2) API input, and vectors related to the (3) Homepage, (4) Blogs, (5) Profiles, (6) Dogear, (7) Activities, and (8) Global Search components. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm lotus_connections *
ibm lotus_connections 1.0.2
CVE-2008-4806 HIGH

Multiple SQL injection vulnerabilities in IBM Lotus Connections 2.x before 2.0.1 allow remote attackers to execute arbitrary SQL commands via the sortField parameter to unspecified components. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm lotus_connections *
ibm lotus_connections 1.0.2
CVE-2008-4807 LOW

IBM Lotus Connections 2.x before 2.0.1 stores the password for the administrative user in the trace.log file, which allows local users to obtain sensitive information by reading this file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVSS 2.0

Severity: LOW

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm lotus_connections *
ibm lotus_connections 1.0.2
CVE-2008-4808 MEDIUM

IBM Lotus Connections 2.x before 2.0.1 allows attackers to discover passwords via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm lotus_connections *
ibm lotus_connections 1.0.2
CVE-2008-4809 HIGH

Multiple unspecified vulnerabilities in the Profiles search pages in IBM Lotus Connections 2.x before 2.0.1 have unknown impact and attack vectors related to "Active" content. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm lotus_connections 2.0
CVE-2008-4828 HIGH

Multiple stack-based buffer overflows in dsmagent.exe in the Remote Agent Service in the IBM Tivoli Storage Manager (TSM) client 5.1.0.0 through 5.1.8.2, 5.2.0.0 through 5.2.5.3, 5.3.0.0 through 5.3.6.4, and 5.4.0.0 through 5.4.1.96, and the TSM Express client 5.3.3.0 through 5.3.6.4, allow remote attackers to execute arbitrary code via (1) a request packet that is not properly parsed by an unspecified "generic string handling function" or (2) a crafted NodeName in a dicuGetIdentifyRequest request packet, related to the (a) Web GUI and (b) Java GUI.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_client 5.4.1.1
ibm tivoli_storage_manager_client 5.3
ibm tivoli_storage_manager_client 5.1
ibm tivoli_storage_manager_client 5.4
ibm tivoli_storage_manager_client 5.1.8.2
ibm tivoli_storage_manager_client 5.4.1.2
ibm tivoli_storage_manager_client 5.2.5.2
ibm tivoli_storage_manager_client 5.3.6.4
ibm tivoli_storage_manager_express 5.3.3.0
ibm tivoli_storage_manager_client 5.1.8.0
ibm tivoli_storage_manager_client 5.3.5.3
ibm tivoli_storage_manager_client 5.2.5.3
ibm tivoli_storage_manager_client 5.4.1.96
ibm tivoli_storage_manager_client 5.2
ibm tivoli_storage_manager_client 5.2.5.1
ibm tivoli_storage_manager_express 5.3
ibm tivoli_storage_manager_client 5.3.6.3
ibm tivoli_storage_manager_client 5.3.5.2
ibm tivoli_storage_manager_express 5.3.6.4
CVE-2008-5011 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Quickr 8.1 before 8.1.0.2 services for Lotus Domino allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to qpconfig_sample.xml, aka SPR CWIR7KMPVP and THES7F9NVR, a different vulnerability than CVE-2008-2163 and CVE-2008-3860.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm lotus *
ibm lotus quickr
CVE-2008-5035 MEDIUM

The Resource Monitoring and Control (RMC) daemon in IBM Hardware Management Console (HMC) 7 release 3.2.0 SP1 and 3.3.0 SP2 allows remote attackers to cause a denial of service (daemon crash or hang) via a packet with an invalid length.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm hardware_management_console 3.2.0
ibm hardware_management_console 3.3.0
CVE-2008-5043 LOW

Multiple cross-site scripting (XSS) vulnerabilities in the web-based interface in IBM Metrica Service Assurance Framework allow remote authenticated users to inject arbitrary web script or HTML via (1) the elementid parameter in a generatedreportresults action to the ReportTree program, (2) the jnlpname parameter to the Launch program, or (3) the :tasklabel parameter to the ReportRequest program, related to the name of a report.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm metrica_service_assurance_framework *
CVE-2008-5228 LOW

Cross-site scripting (XSS) vulnerability in IBM Workplace Content Management (WCM) 6.0G and 6.1 before CF8, when a Page Navigation Component shows menu entries, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters in the URI, related to parameters "not being encoded."

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm workplace_content_management 6.1
ibm workplace_content_management 6.0
CVE-2008-5257 MEDIUM

webseald in WebSEAL 6.0.0.17 in IBM Tivoli Access Manager for e-business allows remote attackers to cause a denial of service (crash or hang) via HTTP requests, as demonstrated by a McAfee vulnerability scan.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm tivoli_access_manager_for_e-business 6.0.0.17
CVE-2008-5324 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in CQ Web in IBM Rational ClearQuest 2007 before 2007D and 2008 before 2008B allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_clearquest 2008
ibm rational_clearquest 2007
CVE-2008-5325 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in CQ Web in IBM Rational ClearQuest 7.0.0 before 7.0.0.4 and 7.0.1 before 7.0.1.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_clearquest *
CVE-2008-5326 MEDIUM

The ClearQuest Maintenance Tool in IBM Rational ClearQuest 7.0.0 before 7.0.0.4 and 7.0.1 before 7.0.1.3 on Windows allows local users to obtain (1) user and (2) database passwords by using a password revealer utility on a field containing a series of asterisks.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm rational_clearquest 7.0.1.1
ibm rational_clearquest 7.0.1.2
ibm rational_clearquest 7.0.0.3
ibm rational_clearquest 7.0.1
ibm rational_clearquest 7.0.0.0
ibm rational_clearquest 7.0.0.2
ibm rational_clearquest 7.0.0.1
CVE-2008-5327 MEDIUM

The ClearQuest Maintenance Tool in IBM Rational ClearQuest 7 before 7.1 stores the database password in cleartext in an object in a ClearQuest connection profile or export file, which allows remote authenticated users to obtain sensitive information by locating the password object within the object tree.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm rational_clearquest 7.0.1.1
ibm rational_clearquest 7.0.1.2
ibm rational_clearquest 7.0.0.3
ibm rational_clearquest 7.0.1
ibm rational_clearquest 7.0.2
ibm rational_clearquest 7.0.0.0
ibm rational_clearquest 7.0
ibm rational_clearquest 7.0.0.2
ibm rational_clearquest 7.0.0.1
CVE-2008-5328 MEDIUM

The ClearQuest Maintenance Tool in IBM Rational ClearQuest before 7 stores the database password in cleartext in an object in a ClearQuest connection profile or export file, which allows remote authenticated users to obtain sensitive information by locating the password object within the object tree during an import process.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm rational_clearquest 7.0.1.1
ibm rational_clearquest 7.0.1.2
ibm rational_clearquest *
ibm rational_clearquest 7.0.1
ibm rational_clearquest 7.0.0.0
ibm rational_clearquest 7.0.0.2
ibm rational_clearquest 7.0.0.1
CVE-2008-5329 HIGH

ClearQuest Web in IBM Rational ClearQuest MultiSite before 7.1 allows remote servers to direct a client's submissions and changes to an arbitrary database by specifying multiple comma-separated server identifiers on the JTLRMIREGISTRYSERVERS line in a jtl.properties file.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm rational_clearquest 7.0.1.1
ibm rational_clearquest 7.0.1.2
ibm rational_clearquest *
ibm rational_clearquest 7.0.1
ibm rational_clearquest 7.0.0.0
ibm rational_clearquest 7.0.0.2
ibm rational_clearquest 7.0.0.1
CVE-2008-5330 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in the web interface in ClearCase RWP server in IBM Rational ClearCase 7.0.0 before 7.0.0.4, and 7.0.1.1-RATL-RCC-IFIX02 and possibly other 7.0.1 versions before 7.0.1.3, allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO of a URI associated with a VOB page.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_clearquest 7.0.1.1
ibm rational_clearquest 7.0.1.2
ibm rational_clearquest 7.0.0.3
ibm rational_clearquest 7.0.1
ibm rational_clearquest 7.0.0.0
ibm rational_clearquest 7.0.0.2
ibm rational_clearquest 7.0.0.1
CVE-2008-5384 MEDIUM

crontab in bos.rte.cron in IBM AIX 6.1.0 through 6.1.2 allows local users with aix.system.config.cron authorization to gain privileges by launching an editor.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm aix 6.1.1
ibm aix 6.1
ibm aix 6.1.2
CVE-2008-5385 MEDIUM

enq in bos.rte.printers in IBM AIX 6.1.0 through 6.1.2, when a print queue is defined in /etc/qconfig, allows local users to delete arbitrary files via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm aix 6.1.1
ibm aix 6.1
ibm aix 6.1.2
CVE-2008-5386 MEDIUM

Buffer overflow in ndp in IBM AIX 6.1.0 through 6.1.2, when the netcd daemon is running, allows local users to gain privileges via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm aix 6.1.1
ibm aix 6.1
ibm aix 6.1.2
CVE-2008-5387 MEDIUM

Buffer overflow in autoconf6 in IBM AIX 6.1.0 through 6.1.2, when Role-Based Access Control is enabled, allows local users with aix.network.config.tcpip authorization to gain privileges via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm aix 6.1.1
ibm aix 6.1
ibm aix 6.1.2
CVE-2008-5411 MEDIUM

IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 sends SSL traffic over "unsecured TCP," which makes it easier for remote attackers to obtain sensitive information by sniffing the network.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm websphere_application_server *
CVE-2008-5412 HIGH

Unspecified vulnerability in IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 on Windows has unknown impact and attack vectors related to JSPs. NOTE: this is probably a duplicate of CVE-2009-0438.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_application_server *
CVE-2008-5413 MEDIUM

PerfServlet in the PMI/Performance Tools component in IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 allows attackers to obtain sensitive information by reading the (1) systemout.log and (2) ffdc files. NOTE: this is probably a duplicate of CVE-2009-0434.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_application_server *
CVE-2008-5414 HIGH

Unspecified vulnerability in the Feature Pack for Web Services in the Web Services Security component in IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 has unknown impact and attack vectors related to "userNameToken."

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0
CVE-2008-5675 HIGH

Unspecified vulnerability in IBM WebSphere Portal 6.0 before 6.0.1.5 has unknown impact and attack vectors related to "Access problems with BasicAuthTAI."

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_portal 6.0.1.2
ibm websphere_portal 6.0.1.3
ibm websphere_portal *
ibm websphere_portal 6.0.0.0
ibm websphere_portal 6.0.0.1
ibm websphere_portal 6.0.1.1
CVE-2008-5686 HIGH

IBM Tivoli Provisioning Manager (TPM) before 5.1.1.1 IF0006, when its LDAP service is shared with other applications, does not require that an LDAP user be listed in the TPM user records, which allows remote authenticated users to execute SOAP commands that access arbitrary TPM functionality, as demonstrated by running provisioning workflows.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm tivoli_provisioning_manager 5.1.0.2
ibm tivoli_provisioning_manager 5.1.1.1
ibm tivoli_provisioning_manager 5.1.1
ibm tivoli_provisioning_manager 5.1
CVE-2008-6105 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Workplace for Business Controls and Reporting 2.x and IBM Workplace Web Content Management 6.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: some of these details are obtained from third party information.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm workplace_for_business_controls_and_reporting 2.0
ibm workplace_web_content_management 6.0
CVE-2008-6106 MEDIUM

Cross-site request forgery (CSRF) vulnerability in IBM Workplace for Business Controls and Reporting 2.x and IBM Workplace Web Content Management 6.x has unknown impact and remote attack vectors. NOTE: some of these details are obtained from third party information.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm workplace_for_business_controls_and_reporting 2.0
ibm workplace_web_content_management 6.0
CVE-2008-6820 HIGH

The db2fmp process in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 on Windows runs with "OS privilege," which has unknown impact and attack vectors, a different vulnerability than CVE-2008-3856.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-16,

Products Affected

Vendor Product Version
ibm db2 9.1
ibm db2 8.0
ibm db2 9.5
CVE-2008-6821 HIGH

Buffer overflow in the DAS server in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 might allow attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors, a different vulnerability than CVE-2007-3676 and CVE-2008-3853.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm db2 9.1
ibm db2 8.0
ibm db2 9.5
CVE-2008-6973 HIGH

Multiple unspecified vulnerabilities in IBM WebSphere Commerce 6.0 before 6.0.0.7 have unknown impact and attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_commerce 6.0.0.6
ibm websphere_commerce 6.0.0.3
ibm websphere_commerce 6.0.0.1
ibm websphere_commerce 6.0.0.2
ibm websphere_commerce 6.0.0.4
ibm websphere_commerce 6.0.0.5
CVE-2008-7253 MEDIUM

The default configuration of the web server in IBM Lotus Domino Server, possibly 6.0 through 8.0, enables the HTTP TRACE method, which makes it easier for remote attackers to steal cookies and authentication credentials via a cross-site tracing (XST) attack, a related issue to CVE-2004-2763 and CVE-2005-3398.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-16,

Products Affected

Vendor Product Version
ibm lotus_domino_server 6.0
ibm lotus_domino_server 8.0
ibm lotus_domino_server 7.0
ibm lotus_domino_server 6.5
CVE-2008-7261 LOW

The Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 3.5.1 before 3.5.1-010 records DEBUG messages containing user credentials in the log4j.xml file, which might allow local users to obtain sensitive information by reading this file.

CVSS 2.0

Severity: LOW

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm filenet_p8_application_engine 3.5.1
CVE-2008-7274 MEDIUM

IBM WebSphere Application Server (WAS) 6.1.0.9, when the JAAS Login functionality is enabled, allows attackers to perform an internal application hashtable login by (1) not providing a password or (2) providing an empty password.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.9
CVE-2008-7284 LOW

IBM Lotus Quickr 8.1 before 8100.003 services for Lotus Domino allows remote authenticated users to cause a denial of service (daemon crash) by clicking a download link, aka SPR QCAO7E6AM8.

CVSS 2.0

Severity: LOW

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm lotus_quickr 8.1
CVE-2008-7285 MEDIUM

Unspecified vulnerability in the docnote string handling implementation in IBM Lotus Quickr 8.1 before 8.1.0.2 services for Lotus Domino allows remote attackers to cause a denial of service (daemon crash) via unknown vectors, aka SPR JFLD7GZT25.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm lotus_quickr 8.1
CVE-2008-7286 LOW

IBM Lotus Quickr 8.1 before 8.1.0.2 services for Lotus Domino does not properly handle URLs that request images, which allows remote authenticated users to cause a denial of service (daemon crash) via a request to resources.nsf, aka SPR XFXF7JDBCX.

CVSS 2.0

Severity: LOW

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm lotus_quickr 8.1
CVE-2008-7287 MEDIUM

Multiple memory leaks in the (1) ldap_init and (2) ldap_url_search_direct API functions in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0007 allow remote authenticated users to cause a denial of service (memory consumption) by making many function calls.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm tivoli_directory_server 5.2.0
ibm tivoli_directory_server 5.2.0.4
CVE-2008-7288 MEDIUM

IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0007 on AIX allows remote attackers to cause a denial of service (server destabilization) via an anonymous DIGEST-MD5 LDAP Bind operation.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm tivoli_directory_server 5.2.0
ibm tivoli_directory_server 5.2.0.4
CVE-2008-7289 MEDIUM

IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0007 does not properly handle the simultaneous changing of multiple passwords, which makes it easier for remote authenticated users to cause a denial of service (DB2 daemon deadlock) by making password changes that trigger updates to a DB2 password-history table.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm tivoli_directory_server 5.2.0
ibm tivoli_directory_server 5.2.0.4
CVE-2008-7290 MEDIUM

Memory leak in the ldap_explode_rdn API function in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0007 allows remote authenticated users to cause a denial of service (memory consumption) by making many function calls.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm tivoli_directory_server 5.2.0
ibm tivoli_directory_server 5.2.0.4
CVE-2008-7299 MEDIUM

IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.2 uses an incomplete SAML 1.x browser-artifact, which allows remote OpenID providers to spoof assertions via vectors related to the Issuer field.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm tivoli_federated_identity_manager 6.2.0
ibm tivoli_federated_identity_manager 6.2.0.1
CVE-2009-0120 HIGH

The IBM WebSphere DataPower XML Security Gateway XS40 with firmware 3.6.1.5 allows remote attackers to cause a denial of service (device reboot) by sending data over an established SSL connection, as demonstrated by the abc\r\n\r\n string data.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm websphere_datapower_xml_security_gateway_xs40 3.6.1.5
CVE-2009-0172 MEDIUM

Unspecified vulnerability in IBM DB2 8 before FP17a, 9.1 before FP6a, and 9.5 before FP3a allows remote attackers to cause a denial of service (infinite loop) via a crafted CONNECT data stream.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm db2_universal_database 9.5
ibm db2_universal_database 9.1
CVE-2009-0173 MEDIUM

Unspecified vulnerability in the server in IBM DB2 8 before FP17a, 9.1 before FP6a, and 9.5 before FP3a allows remote authenticated users to cause a denial of service (trap) via a crafted data stream.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm db2_universal_database 9.5
ibm db2_universal_database 9.1
CVE-2009-0178 HIGH

Unspecified vulnerability in IBM Hardware Management Console (HMC) 7 release 3.2.0 SP1 has unknown impact and attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm hardware_management_console 7.3.2.0
CVE-2009-0215 HIGH

Stack-based buffer overflow in the GetXMLValue method in the IBM Access Support ActiveX control in IbmEgath.dll, as distributed on IBM and Lenovo computers, allows remote attackers to execute arbitrary code via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm access_support_activex_control 3.20.284.0
CVE-2009-0217 MEDIUM

The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in products including (1) the Oracle Security Developer Tools component in Oracle Application Server 10.1.2.3, 10.1.3.4, and 10.1.4.3IM; (2) the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, and 8.1 SP6; (3) Mono before 2.4.2.2; (4) XML Security Library before 1.2.12; (5) IBM WebSphere Application Server Versions 6.0 through 6.0.2.33, 6.1 through 6.1.0.23, and 7.0 through 7.0.0.1; (6) Sun JDK and JRE Update 14 and earlier; (7) Microsoft .NET Framework 3.0 through 3.0 SP2, 3.5, and 4.0; and other products uses a parameter that defines an HMAC truncation length (HMACOutputLength) but does not require a minimum for this length, which allows attackers to spoof HMAC-based signatures and bypass authentication by specifying a truncation length with a small number of bits.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 6.0.1.5
ibm websphere_application_server 6.0.0.1
ibm websphere_application_server 7.0
ibm websphere_application_server 6.0.2.19
ibm websphere_application_server 6.1.0.14
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.0.0.2
ibm websphere_application_server 6.1.0.20
ibm websphere_application_server 6.1.0.12
oracle weblogic_server_component 10.3
oracle bea_product_suite 8.1
ibm websphere_application_server 6.0.2.33
ibm websphere_application_server 6.0.1.2
oracle bea_product_suite 10.3
ibm websphere_application_server 6.1.0.10
ibm websphere_application_server 6.0.1.17
ibm websphere_application_server 6.0.2.18
ibm websphere_application_server 6.0.2.25
ibm websphere_application_server 6.0.1.13
ibm websphere_application_server 6.0.2.12
ibm websphere_application_server 6.0.2.16
oracle weblogic_server_component 9.1
ibm websphere_application_server 6.0.2.31
oracle weblogic_server_component 8.1
ibm websphere_application_server 7.0.0.1
oracle weblogic_server_component 9.0
ibm websphere_application_server 6.0.2.22
oracle application_server 10.1.3.4
ibm websphere_application_server 6.0.2.10
ibm websphere_application_server 6.0
oracle bea_product_suite 9.2
ibm websphere_application_server 6.0.1.3
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.18
ibm websphere_application_server 6.0.2.21
ibm websphere_application_server 6.1.0.6
ibm websphere_application_server 6.0.2.2
ibm websphere_application_server 6.0.2.20
ibm websphere_application_server 6.0.2.13
ibm websphere_application_server 6.0.1.11
ibm websphere_application_server 6.0.2.11
mono_project mono 1.2.6
ibm websphere_application_server 6.0.1.15
oracle application_server 10.1.2.3
ibm websphere_application_server 6.0.2.14
oracle application_server 10.1.4.3im
mono_project mono 1.9
mono_project mono 1.2.1
mono_project mono 1.2.3
ibm websphere_application_server 6.0.2.15
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 6.1.0.22
ibm websphere_application_server 6.1.0
oracle bea_product_suite 9.1
ibm websphere_application_server 6.1.0.4
ibm websphere_application_server 6.0.2.30
ibm websphere_application_server 6.1
ibm websphere_application_server 6.0.2.32
ibm websphere_application_server 6.1.0.23
oracle bea_product_suite 10.0
ibm websphere_application_server 6.1.0.1
oracle weblogic_server_component 10.0
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 6.1.0.9
mono_project mono 1.2.5
ibm websphere_application_server 6.0.2.23
ibm websphere_application_server 6.0.1
mono_project mono 1.2.4
ibm websphere_application_server 6.0.1.7
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
oracle bea_product_suite 9.0
ibm websphere_application_server 6.0.2.17
ibm websphere_application_server 6.0.2.24
ibm websphere_application_server 6.0.2.3
mono_project mono 1.2.2
mono_project mono 2.0
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.16
ibm websphere_application_server 6.0.2.29
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.0.1.9
ibm websphere_application_server 6.0.2
ibm websphere_application_server 6.1.0.8
ibm websphere_application_server 6.0.2.28
oracle weblogic_server_component 9.2
ibm websphere_application_server 6.0.0.3
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.0.1.1
ibm websphere_application_server 6.0.2.1
CVE-2009-0306 HIGH

Buffer overflow in the IBM Lotus Notes Intellisync ActiveX control in lnresobject.dll in BlackBerry Desktop Manager in Research In Motion (RIM) BlackBerry Desktop Software before 5.0.1 allows remote attackers to execute arbitrary code via a crafted web page. NOTE: some of these details are obtained from third party information.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
rim blackberry_desktop_software *
ibm lotus_notes_intellisync *
CVE-2009-0370 HIGH

Multiple unspecified vulnerabilities in IBM AIX 5.2.0 through 6.1.2 allow local users to append data to arbitrary files, related to (1) rmsock and (2) rmsock64 not creating "secure log files."

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm aix 5.3_l
ibm aix 5.3
ibm aix 5.2_l
ibm aix 6.1.1
ibm aix 6.1
ibm aix 6.1.2
ibm aix 5.2
ibm aix 5.2.2
ibm aix 5.3.9
ibm aix 5.3.7
ibm aix 5.3.8
CVE-2009-0391 HIGH

Unspecified vulnerability in IBM WebSphere Application Server (WAS) 6.0.1 on z/OS allows attackers to read arbitrary files via unknown vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-200,NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.0.1
CVE-2009-0432 MEDIUM

The installation process for the File Transfer servlet in the System Management/Repository component in IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.19 does not enable the secure version, which allows remote attackers to obtain sensitive information via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-16,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 6.1.0.13
CVE-2009-0433 LOW

Unspecified vulnerability in IBM WebSphere Application Server (WAS) 5.1.x before 5.1.1.19, 6.0.x before 6.0.2.29, and 6.1.x before 6.1.0.19, when Web Server plug-in content buffering is enabled, allows attackers to cause a denial of service (daemon crash) via unknown vectors, related to a mishandling of client read failures in which clients receive many 500 HTTP error responses and backend servers are incorrectly labeled as down.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 6.0.1.5
ibm websphere_application_server 6.0.0.1
ibm websphere_application_server 5.1.1.14
ibm websphere_application_server 6.0.2.19
ibm websphere_application_server 6.1.0.14
ibm websphere_application_server 6.0.2.7
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.0.0.2
ibm websphere_application_server 5.1.1.12
ibm websphere_application_server 5.1.1.15
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 5.1.0.2
ibm websphere_application_server 5.1.1.10
ibm websphere_application_server 6.0.1.2
ibm websphere_application_server 5.1.1.16
ibm websphere_application_server 6.1.0.10
ibm websphere_application_server 6.0.1.17
ibm websphere_application_server 6.0.2.25
ibm websphere_application_server 6.0.1.13
ibm websphere_application_server 6.0.2.9
ibm websphere_application_server 6.0.2.22
ibm websphere_application_server 6.0
ibm websphere_application_server 5.1.1.18
ibm websphere_application_server 6.0.1.3
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.18
ibm websphere_application_server 6.1.0.6
ibm websphere_application_server 5.1.0.4
ibm websphere_application_server 5.1.1
ibm websphere_application_server 6.0.2.2
ibm websphere_application_server 6.0.2.13
ibm websphere_application_server 6.0.1.11
ibm websphere_application_server 6.0.2.11
ibm websphere_application_server 5.1.1.19
ibm websphere_application_server 6.0.1.15
ibm websphere_application_server 6.0.2.15
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 6.0.2.4
ibm websphere_application_server 6.1.0
ibm websphere_application_server 6.1.0.4
ibm websphere_application_server 6.1
ibm websphere_application_server 5.1.1.11
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 5.1.1.1
ibm websphere_application_server 5.1.1.13
ibm websphere_application_server 6.0.2.23
ibm websphere_application_server 5.1.0.3
ibm websphere_application_server 6.0.2.6
ibm websphere_application_server 6.0.1
ibm websphere_application_server 6.0.1.7
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.0.2.17
ibm websphere_application_server 6.0.2.24
ibm websphere_application_server 6.0.2.5
ibm websphere_application_server 5.1.0
ibm websphere_application_server 6.0.2.3
ibm websphere_application_server 5.1.1.17
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.16
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.0.1.9
ibm websphere_application_server 6.0.2
ibm websphere_application_server 6.1.0.8
ibm websphere_application_server 6.0.2.28
ibm websphere_application_server 6.0.2.27
ibm websphere_application_server 5.1.0.5
ibm websphere_application_server 6.0.0.3
ibm websphere_application_server 6.0.1.1
ibm websphere_application_server 6.0.2.1
CVE-2009-0434 LOW

PerfServlet in the PMI/Performance Tools component in IBM WebSphere Application Server (WAS) 6.0.x before 6.0.2.31, 6.1.x before 6.1.0.21, and 7.0.x before 7.0.0.1, when Performance Monitoring Infrastructure (PMI) is enabled, allows local users to obtain sensitive information by reading the (1) systemout.log and (2) ffdc files. NOTE: this is probably a duplicate of CVE-2008-5413.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 6.0.1.5
ibm websphere_application_server 6.0.0.1
ibm websphere_application_server 7.0
ibm websphere_application_server 6.0.2.19
ibm websphere_application_server 6.1.0.14
ibm websphere_application_server 6.0.2.7
ibm websphere_application_server 6.0.0.2
ibm websphere_application_server 6.1.0.20
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.0.1.2
ibm websphere_application_server 6.1.0.10
ibm websphere_application_server 6.0.1.17
ibm websphere_application_server 6.0.2.25
ibm websphere_application_server 6.0.1.13
ibm websphere_application_server 6.0.2.31
ibm websphere_application_server 6.0.2.9
ibm websphere_application_server 6.0.2.22
ibm websphere_application_server 6.0
ibm websphere_application_server 6.0.1.3
ibm websphere_application_server 6.1.0.18
ibm websphere_application_server 6.0.2.2
ibm websphere_application_server 6.0.2.13
ibm websphere_application_server 6.0.1.11
ibm websphere_application_server 6.0.2.11
ibm websphere_application_server 6.0.1.15
ibm websphere_application_server 6.0.2.15
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 6.0.2.4
ibm websphere_application_server 6.1.0
ibm websphere_application_server 6.0.2.30
ibm websphere_application_server 6.1
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 6.0.2.23
ibm websphere_application_server 6.0.2.6
ibm websphere_application_server 6.0.1
ibm websphere_application_server 6.0.1.7
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.0.2.17
ibm websphere_application_server 6.0.2.24
ibm websphere_application_server 6.0.2.5
ibm websphere_application_server 6.0.2.3
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.16
ibm websphere_application_server 6.0.2.29
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.0.1.9
ibm websphere_application_server 6.0.2
ibm websphere_application_server 6.0.2.28
ibm websphere_application_server 6.0.2.27
ibm websphere_application_server 6.0.0.3
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.0.1.1
ibm websphere_application_server 6.0.2.1
CVE-2009-0435 MEDIUM

Unspecified vulnerability in the IBM Asynchronous I/O (aka AIO or libibmaio) library in the Java Message Service (JMS) component in IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.17 on AIX 5.3 allows attackers to cause a denial of service (daemon crash) via vectors related to the aio_getioev2 and getEvent methods.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 6.1.0.14
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0
ibm websphere_application_server 6.1.0.4
ibm websphere_application_server 6.1.6
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.1.3
ibm websphere_application_server 6.1.0.10
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.1.5
ibm websphere_application_server 6.1.14
ibm websphere_application_server 6.1.7
ibm websphere_application_server 6.1.0.16
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.8
ibm websphere_application_server 6.1.1
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.6
ibm websphere_application_server 6.1.13
CVE-2009-0436 HIGH

The (1) mod_ibm_ssl and (2) mod_cgid modules in IBM HTTP Server 6.0.x before 6.0.2.31 and 6.1.x before 6.1.0.19, as used in WebSphere Application Server (WAS), set incorrect permissions for AF_UNIX sockets, which has unknown impact and local attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 6.0.1.5
ibm websphere_application_server 6.0.0.1
ibm websphere_application_server 6.0.2.19
ibm websphere_application_server 6.1.0.14
ibm websphere_application_server 6.0.2.7
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.0.0.2
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.0.1.2
ibm websphere_application_server 6.1.0.10
ibm websphere_application_server 6.0.1.17
ibm websphere_application_server 6.0.2.25
ibm websphere_application_server 6.0.1.13
ibm websphere_application_server 6.0.2.9
ibm websphere_application_server 6.0.2.22
ibm websphere_application_server 6.0
ibm websphere_application_server 6.0.1.3
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.18
ibm websphere_application_server 6.1.0.6
ibm websphere_application_server 6.0.2.2
ibm websphere_application_server 6.0.2.13
ibm websphere_application_server 6.0.1.11
ibm websphere_application_server 6.0.2.11
ibm websphere_application_server 6.0.1.15
ibm websphere_application_server 6.0.2.15
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 6.0.2.4
ibm websphere_application_server 6.1.0
ibm websphere_application_server 6.1.0.4
ibm websphere_application_server 6.0.2.30
ibm websphere_application_server 6.1
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.0.2.23
ibm websphere_application_server 6.0.2.6
ibm websphere_application_server 6.0.1
ibm websphere_application_server 6.0.1.7
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.0.2.17
ibm websphere_application_server 6.0.2.24
ibm websphere_application_server 6.0.2.5
ibm websphere_application_server 6.0.2.3
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.16
ibm websphere_application_server 6.0.2.29
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.0.1.9
ibm websphere_application_server 6.0.2
ibm websphere_application_server 6.1.0.8
ibm websphere_application_server 6.0.2.28
ibm websphere_application_server 6.0.2.27
ibm websphere_application_server 6.0.0.3
ibm websphere_application_server 6.0.1.1
ibm websphere_application_server 6.0.2.1
ibm websphere_application_server 6.1.13
CVE-2009-0437 LOW

The Installation Factory installation process for IBM WebSphere Application Server (WAS) 6.0.2 on Windows, when WAS is registered as a Windows service, allows local users to obtain sensitive information by reading the logs/instconfigifwas6.log log file.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.0.2
CVE-2009-0438 MEDIUM

IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 on Windows allows remote attackers to bypass "Authorization checking" and obtain sensitive information from JSP pages via a crafted request. NOTE: this is probably a duplicate of CVE-2008-5412.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0
CVE-2009-0439 HIGH

Unspecified vulnerability in the queue manager in IBM WebSphere MQ (WMQ) 5.3, 6.0 before 6.0.2.6, and 7.0 before 7.0.0.2 allows local users to gain privileges via vectors related to the (1) setmqaut, (2) dmpmqaut, and (3) dspmqaut authorization commands.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_mq 6.0.2.0
ibm websphere_mq 6.0.0.0
ibm websphere_mq 6.0.2.3
ibm websphere_mq 7.0
ibm websphere_mq 6.0.1.0
ibm websphere_mq 6.0.1.1
ibm websphere_mq 5.3
ibm websphere_mq 7.0.0.1
ibm websphere_mq 5.3.1
ibm websphere_mq 6.0.2.4
ibm websphere_mq 6.0.2.1
ibm websphere_mq 6.0.2.2
CVE-2009-0440 MEDIUM

IBM WebSphere Partner Gateway (WPG) 6.0.0 through 6.0.0.7 does not properly handle failures of signature verification, which might allow remote authenticated users to submit a crafted RosettaNet (aka RNIF) document to a backend application, related to (1) "altered service content" and (2) "digital signature foot-print."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm websphere_partner_gateway 6.0.0.1
ibm websphere_partner_gateway 6.0.0.3
ibm websphere_partner_gateway 6.0.0.6
ibm websphere_partner_gateway 6.0.0.2
ibm websphere_partner_gateway 6.0.0.4
ibm websphere_partner_gateway 6.0.0.5
ibm websphere_partner_gateway 6.0.0.7
ibm websphere_partner_gateway 6.0.0
CVE-2009-0503 LOW

IBM WebSphere Message Broker 6.1.x before 6.1.0.2 writes a database connection password to the Event Log and System Log during exception handling for a JDBC error, which allows local users to obtain sensitive information by reading these logs.

CVSS 2.0

Severity: LOW

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm websphere_message_broker 6.1
ibm websphere_message_broker *
CVE-2009-0504 LOW

WSPolicy in the Web Services component in IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.1 does not properly recognize the IDAssertion.isUsed binding property, which allows local users to discover a password by reading a SOAP message.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_application_server *
CVE-2009-0505 HIGH

The CICS listener in IBM TXSeries for Multiplatforms 6.2 GA waits for a forcepurge acknowledgement from the CICS Application Server (CICSAS) after an eci response timeout, which might allow remote authenticated users to cause a denial of service (forcepurge handling delay), or have unspecified other impact, via vectors involving slow or nonexistent acknowledgement.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm txseries 6.2
CVE-2009-0506 MEDIUM

Unspecified vulnerability in IBM WebSphere Application Server (WAS) 5.1 and 6.0.2 before 6.0.2.33 on z/OS, when CSIv2 Identity Assertion is enabled and Enterprise JavaBeans (EJB) interaction occurs between a WAS 6.1 instance and a WAS pre-6.1 instance, allows local users to have an unknown impact via vectors related to (1) use of the wrong subject and (2) multiple CBIND checks.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.0.2.20
ibm websphere_application_server 6.0.2.18
ibm websphere_application_server 6.0.2.12
ibm websphere_application_server 6.0.2.8
ibm websphere_application_server 6.0.2.16
ibm websphere_application_server 6.0.2.6
ibm websphere_application_server 6.0.2.14
ibm websphere_application_server 6.0.2.24
ibm websphere_application_server 6.0.2.4
ibm websphere_application_server 5.1.0
ibm websphere_application_server 6.0.2.22
ibm websphere_application_server 6.0.2.10
ibm websphere_application_server 6.0.2
CVE-2009-0507 MEDIUM

IBM WebSphere Process Server (WPS) 6.1.2 before 6.1.2.3 and 6.2 before 6.2.0.1 does not properly restrict configuration data during an export of the cluster configuration file from the administrative console, which allows remote authenticated users to obtain the (1) JMSAPI, (2) ESCALATION, and (3) MAILSESSION (aka mail session) cleartext passwords via vectors involving access to a cluster member.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-16,

Products Affected

Vendor Product Version
ibm websphere_process_server 6.1.2
ibm websphere_process_server *
ibm websphere_process_server 6.1.2.1
CVE-2009-0508 HIGH

The Servlet Engine/Web Container and JSP components in IBM WebSphere Application Server (WAS) 5.1.0, 5.1.1.19, 6.0.2 before 6.0.2.35, 6.1 before 6.1.0.23, and 7.0 before 7.0.0.3 allow remote attackers to read arbitrary files contained in war files in (1) web-inf, (2) meta-inf, and unspecified other directories via unknown vectors, related to (a) web-based applications and (b) the administrative console.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 6.0.2.11
ibm websphere_application_server 5.1.1.19
ibm websphere_application_server 7.0
ibm websphere_application_server 6.0.2.19
ibm websphere_application_server 6.0.2.7
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.0.2.15
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 6.1
ibm websphere_application_server 6.0.2.33
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.0.2.25
ibm websphere_application_server 6.0.2.23
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.0.2.17
ibm websphere_application_server 6.0.2.31
ibm websphere_application_server 6.0.2.5
ibm websphere_application_server 6.0.2.9
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 5.1.0
ibm websphere_application_server 6.0.2.3
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.0.2.29
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.0.2
ibm websphere_application_server 6.0.2.27
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.0.2.21
ibm websphere_application_server 6.0.2.1
CVE-2009-0536 MEDIUM

at in bos.rte.cron on IBM AIX 5.2.0, 5.3.0 through 5.3.9, and 6.1.0 through 6.1.2 allows local users to read arbitrary files via unspecified vectors, related to failure to drop root privileges.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm aix 5.3.0
ibm aix 6.1.1
ibm aix 6.1.0
ibm aix 6.1.2
ibm aix 5.3.9
ibm aix 5.3.7
ibm aix 5.3.8
ibm aix 5.2.0
CVE-2009-0779 HIGH

Buffer overflow in pppdial in IBM AIX 5.3 and 6.1 allows local users to gain privileges via a long "input string."

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 6.1
CVE-2009-0809 LOW

The Web Editor in Dassault Systemes ENOVIA SmarTeam V5 before Release 18 Service Pack 8, and possibly CATIA and other products, allows remote authenticated users to read the profile card of an object in the document class via a link that is sent from the owner of the document object.

CVSS 2.0

Severity: LOW

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm catia 5.16
ibm catia 5.17
3ds enovia_smarteam *
ibm catia *
CVE-2009-0855 MEDIUM

Cross-site scripting (XSS) vulnerability in the administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 on z/OS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 6.1.0.14
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.1.0.20
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 6.1.0.22
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0
ibm websphere_application_server 6.1.0.4
ibm websphere_application_server 6.1
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.1.0.10
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.16
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.8
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.1.0.18
ibm websphere_application_server 6.1.0.6
CVE-2009-0856 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in sample applications in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35, and 6.1 before 6.1.0.23 on z/OS, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 6.1.0.14
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.1.0.20
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 6.1.0.22
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0.4
ibm websphere_application_server 6.1
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.1.0.10
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.16
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.8
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.1.0.18
ibm websphere_application_server 6.1.0.6
CVE-2009-0869 HIGH

Buffer overflow in the client in IBM Tivoli Storage Manager (TSM) HSM 5.3.2.0 through 5.3.5.0, 5.4.0.0 through 5.4.2.5, and 5.5.0.0 through 5.5.1.4 on Windows allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_hsm 5.5.0.0
ibm tivoli_storage_manager_hsm 5.4.2.5
ibm tivoli_storage_manager_hsm 5.3.2.0
ibm tivoli_storage_manager_hsm 5.4.0.0
ibm tivoli_storage_manager_hsm 5.5.1.4
ibm tivoli_storage_manager_hsm 5.3.5.0
CVE-2009-0879 MEDIUM

The CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows remote attackers to cause a denial of service (daemon crash) via a long consumer name, as demonstrated by an M-POST request to a long /CIMListener/ URI.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm director 5.10.2
ibm director 5.20.0
ibm director 5.10.1
ibm director *
ibm director 4.10
ibm director 3.1.1
ibm director 4.11
ibm director 5.20.1
ibm director 4.21
ibm director 5.10.3
ibm director 4.22
ibm director 5.10.0
ibm director 4.20
ibm director 4.12
ibm director 5.20.2
CVE-2009-0880 MEDIUM

Directory traversal vulnerability in the CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows remote attackers to load and execute arbitrary local DLL code via a .. (dot dot) in a /CIMListener/ URI in an M-POST request.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm director 5.10.2
ibm director 5.20.0
ibm director 5.10.1
ibm director *
ibm director 4.10
ibm director 3.1.1
ibm director 4.11
ibm director 5.20.1
ibm director 4.21
ibm director 5.10.3
ibm director 4.22
ibm director 5.10.0
ibm director 4.20
ibm director 4.12
ibm director 5.20.2
CVE-2009-0891 MEDIUM

The Web Services Security component in IBM WebSphere Application Server 7.0 before Fix Pack 1 (7.0.0.1), 6.1 before Fix Pack 23 (6.1.0.23),and 6.0.2 before Fix Pack 33 (6.0.2.33) does not properly enforce (1) nonce and (2) timestamp expiration values in WS-Security bindings as stored in the com.ibm.wsspi.wssecurity.core custom property, which allows remote authenticated users to conduct session hijacking attacks.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0
ibm websphere_application_server 6.0.2.19
ibm websphere_application_server 6.1.0.14
ibm websphere_application_server 6.0.2.7
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.1.0.20
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0.10
ibm websphere_application_server 6.0.2.18
ibm websphere_application_server 6.0.2.25
ibm websphere_application_server 6.0.2.12
ibm websphere_application_server 6.0.2.16
ibm websphere_application_server 6.0.2.31
ibm websphere_application_server 6.0.2.9
ibm websphere_application_server 6.0.2.22
ibm websphere_application_server 6.0.2.10
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.18
ibm websphere_application_server 6.0.2.21
ibm websphere_application_server 6.1.0.6
ibm websphere_application_server 6.0.2.2
ibm websphere_application_server 6.0.2.20
ibm websphere_application_server 6.0.2.13
ibm websphere_application_server 6.0.2.11
ibm websphere_application_server 6.0.2.8
ibm websphere_application_server 6.0.2.14
ibm websphere_application_server 6.0.2.15
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 6.1.0.22
ibm websphere_application_server 6.0.2.4
ibm websphere_application_server 6.1.0
ibm websphere_application_server 6.1.0.4
ibm websphere_application_server 6.0.2.30
ibm websphere_application_server 6.1
ibm websphere_application_server 6.0.2.32
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.0.2.23
ibm websphere_application_server 6.0.2.6
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.0.2.17
ibm websphere_application_server 6.0.2.24
ibm websphere_application_server 6.0.2.5
ibm websphere_application_server 6.0.2.3
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.16
ibm websphere_application_server 6.0.2.29
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.0.2
ibm websphere_application_server 6.1.0.8
ibm websphere_application_server 6.0.2.28
ibm websphere_application_server 6.0.2.27
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.0.2.1
CVE-2009-0892 MEDIUM

The administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 and 7.0 before 7.0.0.3 allows attackers to hijack user sessions in "specific scenarios" related to a forced logout.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0
ibm websphere_application_server 6.1.0.14
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.1.0.20
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 6.1.0.22
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0
ibm websphere_application_server 6.1.0.4
ibm websphere_application_server 6.1
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.1.0.10
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.16
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.8
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.1.0.18
ibm websphere_application_server 6.1.0.6
CVE-2009-0896 HIGH

Buffer overflow in the queue manager in IBM WebSphere MQ 6.x before 6.0.2.7 and 7.x before 7.0.1.0 allows remote attackers to execute arbitrary code via a crafted request.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm websphere_mq 6.0.2.0
ibm websphere_mq 6.0.0.0
ibm websphere_mq 6.0.2.3
ibm websphere_mq 7.0.0.2
ibm websphere_mq 7.0
ibm websphere_mq 6.0
ibm websphere_mq 6.0.1.0
ibm websphere_mq 6.0.1.1
ibm websphere_mq 6.0.2.6
ibm websphere_mq 7.0.0.1
ibm websphere_mq 6.0.2.4
ibm websphere_mq 6.0.2.5
ibm websphere_mq 6.0.2.1
ibm websphere_mq 6.0.2.2
CVE-2009-0897 MEDIUM

IBM WebSphere Partner Gateway (WPG) 6.1.0 before 6.1.0.1 and 6.1.1 before 6.1.1.1 allows remote authenticated users to obtain sensitive information via vectors related to the "schema DB2 instance id" and the bcgarchive (aka the archiver script).

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_partner_gateway 6.1.0
ibm websphere_partner_gateway 6.1.1
CVE-2009-0899 MEDIUM

IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.24 and 7.0 through 7.0.0.4, IBM WebSphere Portal Server 5.1 through 6.0, and IBM Integrated Solutions Console (ISC) 6.0.1 do not properly set the IsSecurityEnabled security flag during migration of WebSphere Member Manager (WMM) to Virtual Member Manager (VMM) and a Federated Repository, which allows attackers to obtain sensitive information from repositories via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_portal *
ibm websphere_application_server *
ibm integrated_solutions_console 6.0.1
CVE-2009-0900 MEDIUM

Heap-based buffer overflow in the client in IBM WebSphere MQ 6.0 before 6.0.2.7 and 7.0 before 7.0.1.0 allows local users to gain privileges via crafted SSL information in a Client Channel Definition Table (CCDT) file.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm websphere_mq 6.0.2.0
ibm websphere_mq 6.0.2.3
ibm websphere_mq 7.0.0.2
ibm websphere_mq 7.0
ibm websphere_mq 6.0
ibm websphere_mq 6.0.1.0
ibm websphere_mq 6.0.1.1
ibm websphere_mq 6.0.2.6
ibm websphere_mq 6.0.2.10
ibm websphere_mq 7.0.0.1
ibm websphere_mq 6.0.2.4
ibm websphere_mq 6.0.2.5
ibm websphere_mq 6.0.2.1
ibm websphere_mq 6.0.2.2
CVE-2009-0903 HIGH

IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.3, and the Feature Pack for Web Services for WAS 6.1 before 6.1.0.25, when a WS-Security policy is established at the operation level, does not properly handle inbound requests that lack a SOAPAction or WS-Addressing Action, which allows remote attackers to bypass intended access restrictions via a crafted request to a JAX-WS application.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0
ibm websphere_application_server 6.1.0.14
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.1.0.20
ibm websphere_application_server 6.1.0.24
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 6.1.0.22
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0
ibm websphere_application_server 6.1.0.4
ibm websphere_application_server 6.1
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.1.0.10
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.16
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.8
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.1.0.18
ibm websphere_application_server 6.1.0.6
CVE-2009-0904 MEDIUM

The IBM Stax XMLStreamWriter in the Web Services component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 does not properly process XML encoding, which allows remote attackers to bypass intended access restrictions and possibly modify data via "XML fuzzing attacks" sent through SOAP requests.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 6.1.0.14
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.1.0.20
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 6.1.0.22
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0
ibm websphere_application_server 6.1.0.4
ibm websphere_application_server 6.1
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.1.0.10
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.1.14
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.16
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.8
ibm websphere_application_server 6.1.1
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.1.0.18
ibm websphere_application_server 6.1.0.6
ibm websphere_application_server 6.1.13
CVE-2009-0905 LOW

IBM WebSphere MQ 6.0 before 6.0.2.8 and 7.0 before 7.0.1.0 does not properly handle long group names, which might allow local users to gain privileges by leveraging combinations of group names with the same initial substring.

CVSS 2.0

Severity: LOW

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm websphere_mq 6.0.2.0
ibm websphere_mq 6.0.2.7
ibm websphere_mq 6.0.2.3
ibm websphere_mq 7.0.0.2
ibm websphere_mq 7.0
ibm websphere_mq 6.0
ibm websphere_mq 6.0.1.0
ibm websphere_mq 6.0.1.1
ibm websphere_mq 6.0.2.6
ibm websphere_mq 7.0.0.1
ibm websphere_mq 6.0.2.4
ibm websphere_mq 6.0.2.5
ibm websphere_mq 6.0.2.1
ibm websphere_mq 6.0.2.2
CVE-2009-0906 MEDIUM

The Service Component Architecture (SCA) feature pack for IBM WebSphere Application Server (WAS) SCA 1.0 before 1.0.0.3 allows remote authenticated users to bypass intended authentication.transport access restrictions and obtain unspecified access via unknown vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm websphere_application_server 1.0
ibm websphere_application_server 1.0.0.2
CVE-2009-1008 MEDIUM

Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.2.2 and 8.3.0 allows local users to affect confidentiality, integrity, and availability, related to HTML, a different vulnerability than CVE-2009-1010.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
oracle application_server 8.2.2
ibm websphere_portal 8.0.0.0
ibm websphere_portal 6.0.0.0
ibm websphere_portal 6.0.1.0
ibm websphere_portal 6.1.5.0
ibm websphere_portal 7.0.0.0
oracle application_server 8.3.0
ibm websphere_portal 6.1.0.0
CVE-2009-1009 MEDIUM

Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.1.9 allows local users to affect confidentiality, integrity, and availability, related to HTML.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.0
ibm websphere_portal 6.0.0.0
ibm websphere_portal 6.0.1.0
ibm websphere_portal 6.1.5.0
ibm websphere_portal 7.0.0.0
oracle application_server 8.1.9
ibm websphere_portal 6.1.0.0
CVE-2009-1010 MEDIUM

Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.2.2 and 8.3.0 allows local users to affect confidentiality, integrity, and availability, related to HTML, a different vulnerability than CVE-2009-1008.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
oracle application_server 8.2.2
ibm websphere_portal 8.0.0.0
ibm websphere_portal 6.0.0.0
ibm websphere_portal 6.0.1.0
ibm websphere_portal 6.1.5.0
ibm websphere_portal 7.0.0.0
oracle application_server 8.3.0
ibm websphere_portal 6.1.0.0
CVE-2009-1056 MEDIUM

IBM Rational AppScan Enterprise before 5.5 FP1 allows remote attackers to read arbitrary exported reports by "forcefully browsing."

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm rational_appscan *
CVE-2009-1172 HIGH

The JAX-RPC WS-Security runtime in the Web Services Security component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 and 7.0 before 7.0.0.3, when APAR PK41002 is installed, does not properly validate UsernameToken objects, which has unknown impact and attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0
ibm websphere_application_server 6.1.0.14
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.1.0.20
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 6.1.0.22
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0
ibm websphere_application_server 6.1.0.4
ibm websphere_application_server 6.1
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.1.0.10
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.16
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.8
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.1.0.18
ibm websphere_application_server 6.1.0.6
CVE-2009-1173 LOW

IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.3 uses weak permissions (777) for files associated with unspecified "interim fixes," which allows attackers to modify files that would not have been accessible if the intended 755 permissions were used.

CVSS 2.0

Severity: LOW

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0
ibm websphere_application_server 7.0.0.1
CVE-2009-1174 HIGH

The Web Services Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 and 7.0 before 7.0.0.3 has an unspecified "security problem" in the XML digital-signature specification, which has unknown impact and attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0
ibm websphere_application_server 7.0.0.1
CVE-2009-1178 HIGH

Unspecified vulnerability in the server in IBM Tivoli Storage Manager (TSM) 5.3.x before 5.3.2 and 6.x before 6.1 has unknown impact and attack vectors related to the "admin command line."

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager 5.3.1
ibm tivoli_storage_manager 6.0
ibm tivoli_storage_manager 5.3.0
CVE-2009-1231 HIGH

Unspecified vulnerability in the eClient in IBM DB2 Content Manager 8.4.1 before 8.4.1.1 has unknown impact and attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm db2_content_manager 8.4.1
CVE-2009-1239 MEDIUM

IBM DB2 9.1 before FP7 returns incorrect query results in certain situations related to the order of application of an INNER JOIN predicate and an OUTER JOIN predicate, which might allow attackers to obtain sensitive information via a crafted query.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm db2 9.1
ibm db2 *
CVE-2009-1240 HIGH

Unspecified vulnerability in the IBM Proventia engine 4.9.0.0.44 20081231, as used in IBM Proventia Network Mail Security System, Network Mail Security System Virtual Appliance, Desktop Endpoint Security, Network Multi-Function Security (MFS), and possibly other products, allows remote attackers to bypass detection of malware via a modified RAR archive.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm network_multi-function_security *
ibm proventia_network_mail_security_system *
ibm proventia_desktop_endpoint_security *
ibm proventia_network_mail_security_system_virtual_appliance *
CVE-2009-1250 HIGH

The cache manager in the client in OpenAFS 1.0 through 1.4.8 and 1.5.0 through 1.5.58, and IBM AFS 3.6 before Patch 19, on Linux allows remote attackers to cause a denial of service (system crash) via an RX response with a large error-code value that is interpreted as a pointer and dereferenced, related to use of the ERR_PTR macro.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-189,

Products Affected

Vendor Product Version
openafs openafs 1.2.11
openafs openafs 1.5.38
openafs openafs 1.0.3
openafs openafs 1.2.4
openafs openafs 1.4.0
openafs openafs 1.4.8_pre3
openafs openafs 1.2.3
openafs openafs 1.5.50
openafs openafs 1.5.58
openafs openafs 1.5.34
ibm afs *
openafs openafs 1.2.9
openafs openafs 1.4.7_pre5
openafs openafs 1.2.7
openafs openafs 1.2.10
openafs openafs 1.2.1
openafs openafs 1.4.7
openafs openafs 1.5.31
openafs openafs 1.2.13
openafs openafs 1.2.2a
openafs openafs 1.2.5
openafs openafs 1.3.77
openafs openafs 1.4.8
openafs openafs 1.4.3
openafs openafs 1.1.1a
openafs openafs 1.0.4
openafs openafs 1.5.35
openafs openafs 1.0.1
openafs openafs 1.5.16
openafs openafs 1.4.8_pre1
openafs openafs 1.3.74
openafs openafs 1.1
openafs openafs 1.3
openafs openafs 1.5.39
openafs openafs 1.3.5
openafs openafs 1.4.7_pre2
openafs openafs 1.3.81
openafs openafs 1.1.0
openafs openafs 1.3.1
openafs openafs 1.5.52
openafs openafs 1.2
openafs openafs 1.5.27
openafs openafs 1.5.36
openafs openafs 1.3.70
openafs openafs 1.2.2
openafs openafs 1.3.2
openafs openafs 1.4.8_pre2
openafs openafs 1.4.7_pre4
openafs openafs 1.5.17
openafs openafs 1.5.26
openafs openafs 1.4.5
openafs openafs 1.1.1
ibm afs 3.6
openafs openafs 1.0
openafs openafs 1.4.6
openafs openafs 1.5.33
openafs openafs 1.5.32
openafs openafs 1.5.57
openafs openafs 1.0.4a
openafs openafs 1.2.8
openafs openafs 1.5.54
openafs openafs 1.5.55
openafs openafs 1.4.7_pre3
openafs openafs 1.2.6
openafs openafs 1.5.56
openafs openafs 1.5.30
openafs openafs 1.0.2
openafs openafs 1.4.7_pre1
openafs openafs 1.4
openafs openafs 1.4.4
openafs openafs 1.5.53
openafs openafs 1.2.2b
openafs openafs 1.5
CVE-2009-1286 MEDIUM

The IMAP task in the server in IBM Lotus Domino 8.0.2 before FP1 IF1 and 8.5 before IF3 allows remote attackers to cause a denial of service (daemon crash) via a MIME e-mail message with RFC822 attachments (aka blobs) containing malformed root entities.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_domino 8.0.2.1
ibm lotus_domino 8.0.1
ibm lotus_domino 8.0
ibm lotus_domino 8.0.2
CVE-2009-1288 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in the Advanced Management Module (AMM) on the IBM BladeCenter, including the BladeCenter H with BPET36H 54, allow remote attackers to inject arbitrary web script or HTML via (1) the username in a login action or (2) the PATH parameter to private/file_management.ssi in the File manager.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm bladecenter hs12
ibm bladecenter js12
ibm bladecenter s
ibm bladecenter h
ibm bladecenter js22
ibm bladecenter ls20
ibm bladecenter hs21_xm
ibm bladecenter ls21
ibm bladecenter hc10
ibm bladecenter qs21
ibm bladecenter hs21
ibm bladecenter qs22
ibm advanced_management_module 1.36h
ibm bladecenter e
ibm bladecenter ht
ibm bladecenter t
ibm bladecenter ls41
ibm bladecenter hs20
ibm bladecenter js21
CVE-2009-1289 MEDIUM

private/login.ssi in the Advanced Management Module (AMM) on the IBM BladeCenter, including the BladeCenter H with BPET36H 54, allows remote attackers to discover the access roles and scopes of arbitrary user accounts via a modified WEBINDEX parameter.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm bladecenter hs12
ibm bladecenter js12
ibm bladecenter s
ibm bladecenter h
ibm bladecenter js22
ibm bladecenter ls20
ibm bladecenter hs21_xm
ibm bladecenter ls21
ibm bladecenter hc10
ibm bladecenter qs21
ibm bladecenter hs21
ibm bladecenter qs22
ibm advanced_management_module 1.36h
ibm bladecenter e
ibm bladecenter ht
ibm bladecenter t
ibm bladecenter ls41
ibm bladecenter hs20
ibm bladecenter js21
CVE-2009-1290 MEDIUM

Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration interface in the Advanced Management Module (AMM) on the IBM BladeCenter, including the BladeCenter H with BPET36H 54, allow remote attackers to hijack the authentication of administrators, as demonstrated by a power-off request to the private/blade_power_action script.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm advanced_management_module 1.36h
CVE-2009-1292 LOW

UCM-CQ in IBM Rational ClearCase 7.0.0.x before 7.0.0.5, 7.0.1.x before 7.0.1.4, and 7.1.x before 7.1.0.1 on Linux and AIX places a username and password on the command line, which allows local users to obtain credentials by listing the process.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_clearcase 7.0.0.2
ibm rational_clearcase 7.0.0.4
ibm rational_clearcase 7.0.1.2
ibm rational_clearcase 7.0.0.3
ibm rational_clearcase 7.0.0.1
ibm rational_clearcase 7.1
ibm rational_clearcase 7.0
ibm rational_clearcase 7.0.1.3
ibm rational_clearcase 7.0.1.1
ibm rational_clearcase 7.0.1
CVE-2009-1334 MEDIUM

Cross-site scripting (XSS) vulnerability in login/FilepathLogin.html in IBM Tivoli Continuous Data Protection (CDP) for Files 3.1.4.0 allows remote attackers to inject arbitrary web script or HTML via the reason parameter.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_continuous_data_protection_for_files 3.1.4.0
CVE-2009-1355 HIGH

Stack-based buffer overflow in muxatmd in IBM AIX 5.2, 5.3, and 6.1 allows local users to gain privileges via a long filename.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 6.1
ibm aix 5.2
CVE-2009-1520 HIGH

Buffer overflow in the Web GUI in the IBM Tivoli Storage Manager (TSM) client 5.1.0.0 through 5.1.8.2, 5.2.0.0 through 5.2.5.3, 5.3.0.0 through 5.3.6.4, 5.4.0.0 through 5.4.2.6, and 5.5.0.0 through 5.5.1.17 allows attackers to cause a denial of service (application crash) or execute arbitrary code via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_client 5.4.1.1
ibm tivoli_storage_manager_client 5.3
ibm tivoli_storage_manager_client 5.1
ibm tivoli_storage_manager_client 5.4
ibm tivoli_storage_manager_client 5.1.8.2
ibm tivoli_storage_manager_client 5.4.1.2
ibm tivoli_storage_manager_client 5.2.5.2
ibm tivoli_storage_manager_client 5.3.6.4
ibm tivoli_storage_manager_express 5.3.3.0
ibm tivoli_storage_manager_client 5.1.8.0
ibm tivoli_storage_manager_client 5.3.5.3
ibm tivoli_storage_manager_client 5.2.5.3
ibm tivoli_storage_manager_client 5.4.1.96
ibm tivoli_storage_manager_client 5.2
ibm tivoli_storage_manager_client 5.2.5.1
ibm tivoli_storage_manager_express 5.3
ibm tivoli_storage_manager_client 5.3.6.3
ibm tivoli_storage_manager_client 5.3.5.2
ibm tivoli_storage_manager_express 5.3.6.4
CVE-2009-1521 HIGH

Unspecified vulnerability in the Java GUI in the IBM Tivoli Storage Manager (TSM) client 5.2.0.0 through 5.2.5.3, 5.3.0.0 through 5.3.6.5, 5.4.0.0 through 5.4.2.6, and 5.5.0.0 through 5.5.1.17, and the TSM Express client 5.3.3.0 through 5.3.6.5, allows attackers to read or modify arbitrary files via unknown vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_client 5.2.3
ibm tivoli_storage_manager_client 5.3.3
ibm tivoli_storage_manager_client 5.4.2
ibm tivoli_storage_manager_client 5.5.0
ibm tivoli_storage_manager_client 5.2.2
ibm tivoli_storage_manager_client 5.3.0
ibm tivoli_storage_manager_client 5.3.5
ibm tivoli_storage_manager_client 5.2.4
ibm tivoli_storage_manager_client 5.4.0
ibm tivoli_storage_manager_client 5.3.4
ibm tivoli_storage_manager_client 5.2.5
ibm tivoli_storage_manager_client 5.3.2
ibm tivoli_storage_manager_client 5.5.1
ibm tivoli_storage_manager_client 5.2.0
ibm tivoli_storage_manager_client 5.3.6
ibm tivoli_storage_manager_express 5.3
ibm tivoli_storage_manager_client 5.4.1
CVE-2009-1522 HIGH

The IBM Tivoli Storage Manager (TSM) client 5.5.0.0 through 5.5.1.17 on AIX and Windows, when SSL is used, allows remote attackers to conduct unspecified man-in-the-middle attacks and read arbitrary files via unknown vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_client 5.5.0.91
ibm tivoli_storage_manager_client 5.5.1.17
ibm tivoli_storage_manager_client 5.5.1
ibm tivoli_storage_manager_client 5.5.0.0
CVE-2009-1786 MEDIUM

The malloc subsystem in libc in IBM AIX 5.3 and 6.1 allows local users to create or overwrite arbitrary files via a symlink attack on the log file associated with the MALLOCDEBUG environment variable.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-362,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 6.1
CVE-2009-1806 HIGH

Unspecified vulnerability in IBM Hardware Management Console (HMC) 7 release 3.4.0 SP2, when Active Memory Sharing is used, has unknown impact and attack vectors, related to a shared memory partition and a shared memory pool with redundant paging Virtual I/O Server (VIOS) partitions. NOTE: some of these details are obtained from third party information.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm hardware_management_console 7.3.4.0
CVE-2009-1898 MEDIUM

The secure login page in the Administrative Console component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 does not redirect to an https page upon receiving an http request, which makes it easier for remote attackers to read the contents of WAS sessions by sniffing the network.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.0.2.2
ibm websphere_application_server 6.0.2.20
ibm websphere_application_server 6.0.2.13
ibm websphere_application_server 6.0.2.11
ibm websphere_application_server 6.0.2.19
ibm websphere_application_server 6.0.2.8
ibm websphere_application_server 6.0.2.14
ibm websphere_application_server 6.0.2.7
ibm websphere_application_server 6.0.2.15
ibm websphere_application_server 6.0.2.4
ibm websphere_application_server 6.0.2.30
ibm websphere_application_server 6.0.2.32
ibm websphere_application_server *
ibm websphere_application_server 6.0.2.18
ibm websphere_application_server 6.0.2.25
ibm websphere_application_server 6.0.2.12
ibm websphere_application_server 6.0.2.23
ibm websphere_application_server 6.0.2.16
ibm websphere_application_server 6.0.2.6
ibm websphere_application_server 6.0.2.17
ibm websphere_application_server 6.0.2.24
ibm websphere_application_server 6.0.2.31
ibm websphere_application_server 6.0.2.5
ibm websphere_application_server 6.0.2.9
ibm websphere_application_server 6.0.2.3
ibm websphere_application_server 6.0.2.22
ibm websphere_application_server 6.0.2.29
ibm websphere_application_server 6.0.2.10
ibm websphere_application_server 6.0.2
ibm websphere_application_server 6.0.2.28
ibm websphere_application_server 6.0.2.27
ibm websphere_application_server 6.0.2.21
ibm websphere_application_server 6.0.2.1
CVE-2009-1899 HIGH

Unspecified vulnerability in the Administrative Configservice API in the System Management/Repository component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35, 6.1 before 6.1.0.25, and 7.0 before 7.0.0.5 on z/OS allows remote authenticated users to obtain sensitive information via unknown use of the wsadmin scripting tool, related to a "security exposure in wsadmin."

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.0.2.2
ibm websphere_application_server 6.0.2.20
ibm websphere_application_server 6.0.2.13
ibm websphere_application_server 6.0.2.11
ibm websphere_application_server 6.0.2.19
ibm websphere_application_server 6.0.2.8
ibm websphere_application_server 6.0.2.14
ibm websphere_application_server 6.0.2.7
ibm websphere_application_server 6.0.2.15
ibm websphere_application_server 6.0.2.4
ibm websphere_application_server 6.0.2.30
ibm websphere_application_server 6.0.2.32
ibm websphere_application_server *
ibm websphere_application_server 6.0.2.18
ibm websphere_application_server 6.0.2.25
ibm websphere_application_server 6.0.2.12
ibm websphere_application_server 6.0.2.23
ibm websphere_application_server 6.0.2.16
ibm websphere_application_server 6.0.2.6
ibm websphere_application_server 6.0.2.17
ibm websphere_application_server 6.0.2.24
ibm websphere_application_server 6.0.2.31
ibm websphere_application_server 6.0.2.5
ibm websphere_application_server 6.0.2.9
ibm websphere_application_server 6.0.2.3
ibm websphere_application_server 6.0.2.22
ibm websphere_application_server 6.0.2.29
ibm websphere_application_server 6.0.2.10
ibm websphere_application_server 6.0.2
ibm websphere_application_server 6.0.2.28
ibm websphere_application_server 6.0.2.27
ibm websphere_application_server 6.0.2.21
ibm websphere_application_server 6.0.2.1
CVE-2009-1900 MEDIUM

The Configservice APIs in the Administrative Console component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35, 6.1 before 6.1.0.25, and 7.0 before 7.0.0.5, when tracing is enabled, allow remote attackers to obtain sensitive information via unspecified use of the wsadmin scripting tool.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.0.2.2
ibm websphere_application_server 6.0.2.20
ibm websphere_application_server 6.0.2.13
ibm websphere_application_server 6.0.2.11
ibm websphere_application_server 6.0.2.19
ibm websphere_application_server 6.0.2.8
ibm websphere_application_server 6.0.2.14
ibm websphere_application_server 6.0.2.7
ibm websphere_application_server 6.0.2.15
ibm websphere_application_server 6.0.2.4
ibm websphere_application_server 6.0.2.30
ibm websphere_application_server 6.0.2.32
ibm websphere_application_server *
ibm websphere_application_server 6.0.2.18
ibm websphere_application_server 6.0.2.25
ibm websphere_application_server 6.0.2.12
ibm websphere_application_server 6.0.2.23
ibm websphere_application_server 6.0.2.16
ibm websphere_application_server 6.0.2.6
ibm websphere_application_server 6.0.2.17
ibm websphere_application_server 6.0.2.24
ibm websphere_application_server 6.0.2.31
ibm websphere_application_server 6.0.2.5
ibm websphere_application_server 6.0.2.9
ibm websphere_application_server 6.0.2.3
ibm websphere_application_server 6.0.2.22
ibm websphere_application_server 6.0.2.29
ibm websphere_application_server 6.0.2.10
ibm websphere_application_server 6.0.2
ibm websphere_application_server 6.0.2.28
ibm websphere_application_server 6.0.2.27
ibm websphere_application_server 6.0.2.21
ibm websphere_application_server 6.0.2.1
CVE-2009-1901 HIGH

The Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 permits "non-standard http methods," which has unknown impact and remote attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.0.2.2
ibm websphere_application_server 6.0.2.20
ibm websphere_application_server 6.0.2.13
ibm websphere_application_server 6.0.2.11
ibm websphere_application_server 6.0.2.19
ibm websphere_application_server 6.0.2.8
ibm websphere_application_server 6.0.2.14
ibm websphere_application_server 6.0.2.7
ibm websphere_application_server 6.0.2.15
ibm websphere_application_server 6.0.2.4
ibm websphere_application_server 6.0.2.30
ibm websphere_application_server 6.0.2.32
ibm websphere_application_server *
ibm websphere_application_server 6.0.2.18
ibm websphere_application_server 6.0.2.25
ibm websphere_application_server 6.0.2.12
ibm websphere_application_server 6.0.2.23
ibm websphere_application_server 6.0.2.16
ibm websphere_application_server 6.0.2.6
ibm websphere_application_server 6.0.2.17
ibm websphere_application_server 6.0.2.24
ibm websphere_application_server 6.0.2.31
ibm websphere_application_server 6.0.2.5
ibm websphere_application_server 6.0.2.9
ibm websphere_application_server 6.0.2.3
ibm websphere_application_server 6.0.2.22
ibm websphere_application_server 6.0.2.29
ibm websphere_application_server 6.0.2.10
ibm websphere_application_server 6.0.2
ibm websphere_application_server 6.0.2.28
ibm websphere_application_server 6.0.2.27
ibm websphere_application_server 6.0.2.21
ibm websphere_application_server 6.0.2.1
CVE-2009-1905 LOW

The Common Code Infrastructure component in IBM DB2 8 before FP17, 9.1 before FP7, and 9.5 before FP4, when LDAP security (aka IBMLDAPauthserver) and anonymous bind are enabled, allows remote attackers to bypass password authentication and establish a database connection via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm db2 9.1
ibm db2 8.0
ibm db2 *
CVE-2009-1906 MEDIUM

The DRDA Services component in IBM DB2 9.1 before FP7 and 9.5 before FP4 allows remote attackers to cause a denial of service (memory corruption and application crash) via an IPv6 address in the correlation token in the APPID string, as demonstrated by an APPID string sent by the third-party DataDirect JDBC driver 3.7.32.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm db2 9.1
ibm db2 9.5
CVE-2009-1953 MEDIUM

IBM FileNet Content Manager 4.0, 4.0.1, and 4.5, as used in IBM WebSphere Application Server (WAS) and Oracle BEA WebLogic Application Server, when the CE Web Services listener has a certain WSEAF configuration, does not properly restrict use of a cached Subject, which allows remote attackers to obtain access with the credentials of a recently authenticated user via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm filenet_content_manager 4.5
ibm filenet_content_manager 4.0
ibm filenet_content_manager 4.0.1
CVE-2009-1954 HIGH

Unspecified vulnerability in portmapper (aka portmap) in IBM AIX 5.3 allows attackers to cause a denial of service (daemon hang) via unknown vectors, related to libtli.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm aix 5.3
CVE-2009-2030 HIGH

Unspecified vulnerability in the XML Digital Signature verification functionality in JVA-RUN in JDK 6.0 in IBM OS/400 i5/OS V5R4M0 and V6R1M0 has unknown impact and attack vectors related to "XML SECURITY PATCH."

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
sun jdk 6
ibm os/400 v5r4m0
ibm os/400 v6r1m0
CVE-2009-2085 HIGH

The Security component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5 does not properly handle use of Identity Assertion with CSIv2 Security, which allows remote attackers to bypass intended CSIv2 access restrictions via vectors involving Enterprise JavaBeans (EJB).

CVSS 2.0

Severity: HIGH

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0
ibm websphere_application_server 6.1.0.14
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.1.0.20
ibm websphere_application_server 6.1.0.24
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 6.1.0.22
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0
ibm websphere_application_server 6.1.0.4
ibm websphere_application_server 6.1
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.1.0.10
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.16
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.8
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.1.0.18
ibm websphere_application_server 6.1.0.6
ibm websphere_application_server 7.0.0.4
CVE-2009-2087 LOW

The Web Services functionality in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5, in certain circumstances involving the ibm-webservicesclient-bind.xmi file and custom password encryption, uses weak password obfuscation, which allows local users to cause a denial of service (deployment failure) via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0
ibm websphere_application_server 6.1.0.14
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.1.0.20
ibm websphere_application_server 6.1.0.24
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 6.1.0.22
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0
ibm websphere_application_server 6.1.0.4
ibm websphere_application_server 6.1
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.1.0.10
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.16
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.8
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.1.0.18
ibm websphere_application_server 6.1.0.6
ibm websphere_application_server 7.0.0.4
CVE-2009-2088 HIGH

The Servlet Engine/Web Container component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5, when SPNEGO Single Sign-on (SSO) and disableSecurityPreInvokeOnFilters are configured, allows remote attackers to bypass authentication via a request for a "secure URL," related to a certain invokefilterscompatibility property.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0
ibm websphere_application_server 6.1.0.14
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.1.0.20
ibm websphere_application_server 6.1.0.24
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 6.1.0.22
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0
ibm websphere_application_server 6.1.0.4
ibm websphere_application_server 6.1
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.1.0.10
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.16
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.8
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.1.0.18
ibm websphere_application_server 6.1.0.6
ibm websphere_application_server 7.0.0.4
CVE-2009-2089 LOW

The Migration component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5, when tracing is enabled and a 6.1 to 7.0 migration has occurred, allows remote authenticated users to obtain sensitive information by reading a Migration Trace file.

CVSS 2.0

Severity: LOW

Problem Type: CWE-16,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0
ibm websphere_application_server 6.1.0.14
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.1.0.20
ibm websphere_application_server 6.1.0.24
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 6.1.0.22
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0
ibm websphere_application_server 6.1.0.4
ibm websphere_application_server 6.1
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.1.0.10
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.16
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.8
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.1.0.18
ibm websphere_application_server 6.1.0.6
ibm websphere_application_server 7.0.0.4
CVE-2009-2090 MEDIUM

Unspecified vulnerability in wsadmin in the System Management/Repository component in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.5 allows remote attackers to bypass intended Java Management Extensions (JMX) Management Beans (aka MBeans) access restrictions, and cause a denial of service (daemon stop), via unknown vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 7.0.0.4
CVE-2009-2091 MEDIUM

The System Management/Repository component in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.5 on z/OS uses weak file permissions for new applications, which allows remote attackers to obtain sensitive information via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 7.0.0.4
CVE-2009-2092 HIGH

IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.5 does not properly read the portletServingEnabled parameter in ibm-portlet-ext.xmi, which allows remote attackers to bypass intended access restrictions via unknown vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 7.0.0.4
CVE-2009-2093 MEDIUM

SQL injection vulnerability in the console in IBM WebSphere Partner Gateway (WPG) Enterprise 6.0 before FP8, 6.1 before FP3, 6.1.1 before FP2, and 6.2 before FP1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm websphere_partner_gateway 6.1.0
ibm websphere_partner_gateway 6.1.1
ibm websphere_partner_gateway 6.0.0
ibm websphere_partner_gateway 6.2
CVE-2009-2094 LOW

Unspecified vulnerability in IBM WebSphere Commerce 6.0 Enterprise before 6.0.0.8, when trace is enabled, allows local users to obtain sensitive information via unknown vectors.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_commerce 6.0.0.6
ibm websphere_commerce 6.0.0.3
ibm websphere_commerce 6.0.0.1
ibm websphere_commerce 6.0.0.2
ibm websphere_commerce 6.0.0.4
ibm websphere_commerce 6.0.0.5
CVE-2009-2211 MEDIUM

Cross-site scripting (XSS) vulnerability in the CQWeb server in IBM Rational ClearQuest 7.0.0 before 7.0.0.6 and 7.0.1 before 7.0.1.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_clearquest 7.0.0.4
ibm rational_clearquest 7.0.0.5
ibm rational_clearquest 7.0.0.0
ibm rational_clearquest 7.0
ibm rational_clearquest 7.0.1.4
ibm rational_clearquest 7.0.0.1
ibm rational_clearquest 7.0.1.1
ibm rational_clearquest 7.0.1.3
ibm rational_clearquest 7.0.1.2
ibm rational_clearquest 7.0.1.0
ibm rational_clearquest 7.0.0.3
ibm rational_clearquest 7.0.1
ibm rational_clearquest 7.0.2
ibm rational_clearquest 7.0.0.2
CVE-2009-2212 MEDIUM

The CQWeb server in IBM Rational ClearQuest 7.0.0 before 7.0.0.6 and 7.0.1 before 7.0.1.5 allows attackers to discover a (1) username or (2) password via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm rational_clearquest 7.0.1.1
ibm rational_clearquest 7.0.1.3
ibm rational_clearquest 7.0.1.2
ibm rational_clearquest 7.0.0.4
ibm rational_clearquest 7.0.0.5
ibm rational_clearquest 7.0.0.3
ibm rational_clearquest 7.0.1
ibm rational_clearquest 7.0.0.0
ibm rational_clearquest 7.0.1.4
ibm rational_clearquest 7.0.0.2
ibm rational_clearquest 7.0.0.1
CVE-2009-2316 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in IBM Tivoli Identity Manager (ITIM) 5.0 allow remote attackers to inject arbitrary web script or HTML by entering an unspecified URL in (1) the self-service UI interface or (2) the console interface. NOTE: it was later reported that 4.6.0 is also affected by the first vector.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_identity_manager 5.0
CVE-2009-2434 HIGH

Buffer overflow in the syscall implementation in IBM AIX 5.3 allows local users to gain privileges via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm aix 5.3
CVE-2009-2435 MEDIUM

The Sametime server in IBM Lotus Instant Messaging and Web Conferencing 6.5.1 generates error messages for a failed logon attempt with different time delays depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm lotus_instant_messaging_and_web_conferencing 6.5.1
CVE-2009-2543 HIGH

Multiple unspecified vulnerabilities in the IBM Proventia engine 4.9.0.0.44 20081231, as used in IBM Proventia Network Mail Security System, Network Mail Security System Virtual Appliance, Desktop Endpoint Security, Network Multi-Function Security (MFS), and possibly other products, allow remote attackers to bypass detection of malware via a modified (1) ZIP or (2) CAB archive, a related issue to CVE-2009-1240.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm proventia_network_mail_security_system *
ibm proventia_network_multi-function_security *
ibm proventia_desktop_endpoint_security *
ibm proventia_network_mail_security_system_vitual_appliance *
CVE-2009-2583 MEDIUM

Multiple session fixation vulnerabilities in IBM Tivoli Identity Manager (ITIM) 5.0.0.6 allow remote attackers to hijack web sessions via unspecified vectors involving the (1) console and (2) self service interfaces.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm tivoli_identity_manager 5.0.0.6
CVE-2009-2667 HIGH

Unspecified vulnerability in IBM Tivoli Key Lifecycle Manager (TKLM) 1.0 has unknown impact and attack vectors, related to a "password security vulnerability."

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm tklm 1.0
CVE-2009-2669 HIGH

A certain debugging component in IBM AIX 5.3 and 6.1 does not properly handle the (1) _LIB_INIT_DBG and (2) _LIB_INIT_DBG_FILE environment variables, which allows local users to gain privileges by leveraging a setuid-root program to create an arbitrary root-owned file with world-writable permissions, related to libC.a (aka the XL C++ runtime library) in AIX 5.3 and libc.a in AIX 6.1.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 6.1
CVE-2009-2727 HIGH

Stack-based buffer overflow in the _tt_internal_realpath function in the ToolTalk library (libtt.a) in IBM AIX 5.2.0, 5.3.0, 5.3.7 through 5.3.10, and 6.1.0 through 6.1.3, when the rpc.ttdbserver daemon is enabled in /etc/inetd.conf, allows remote attackers to execute arbitrary code via a long XDR-encoded ASCII string to remote procedure 15.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm aix 5.3.10
ibm aix 6.1
ibm aix 6.1.0
ibm aix 5.2
ibm aix 5.3.8
ibm aix 5.2.0
ibm aix 5.3.0
ibm aix 5.3
ibm aix 5.2_l
ibm aix 6.1.1
ibm aix 6.1.2
ibm aix 5.2.0.54
ibm aix 5.2.2
ibm aix 5.2.0.50
ibm aix 5.3.9
ibm aix 5.3.7
CVE-2009-2741 HIGH

Unspecified vulnerability in the wberuntimeear application in the test servlet in IBM WebSphere Business Events 6.1 and 6.2 allows remote attackers to execute arbitrary code via unknown vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_business_events 6.2
ibm websphere_business_events 6.1
CVE-2009-2742 MEDIUM

Cross-site scripting (XSS) vulnerability in Eclipse Help in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.27 allows remote attackers to inject arbitrary web script or HTML via unspecified input.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 6.1
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.1.0.11
CVE-2009-2743 LOW

IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.27, and 7.0 before 7.0.0.7, does not properly handle an exception occurring after use of wsadmin scripts and configuration of JAAS-J2C Authentication Data, which allows local users to obtain sensitive information by reading the First Failure Data Capture (FFDC) log file.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 7.0.0.4
CVE-2009-2744 HIGH

Unspecified vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.27 allows remote attackers to cause a denial of service via unknown vectors, related to "an error in fixpacks 6.1.0.23 and 6.1.0.25."

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 6.1.0.14
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.1.0.20
ibm websphere_application_server 6.1.0.24
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 6.1.0.22
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0
ibm websphere_application_server 6.1.0.4
ibm websphere_application_server 6.1
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.26
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.1.0.10
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.16
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.8
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.1.0.18
ibm websphere_application_server 6.1.0.6
CVE-2009-2746 MEDIUM

Cross-site request forgery (CSRF) vulnerability in the administrative console in the Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.39, 6.1 before 6.1.0.29, and 7.0 before 7.0.0.7 allows remote attackers to hijack the authentication of administrators via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0
ibm websphere_application_server 6.0.2.19
ibm websphere_application_server 6.0.2.7
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.0.2.33
ibm websphere_application_server 6.0.2.18
ibm websphere_application_server 6.0.2.25
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 6.0.2.12
ibm websphere_application_server 6.0.2.16
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 6.0.2.31
ibm websphere_application_server 6.0.2.9
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.0.2.35
ibm websphere_application_server 6.0.2.22
ibm websphere_application_server 6.0.2.10
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.0.2.21
ibm websphere_application_server 6.0.2.2
ibm websphere_application_server 6.0.2.20
ibm websphere_application_server 6.0.2.13
ibm websphere_application_server 6.0.2.11
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 6.0.2.8
ibm websphere_application_server 6.0.2.14
ibm websphere_application_server 6.0.2.15
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 6.0.2.4
ibm websphere_application_server 6.1.0
ibm websphere_application_server 6.0.2.30
ibm websphere_application_server 6.0.2.32
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.0.2.23
ibm websphere_application_server 6.0.2.6
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.0.2.17
ibm websphere_application_server 6.0.2.37
ibm websphere_application_server 6.0.2.24
ibm websphere_application_server 6.0.2.5
ibm websphere_application_server 6.0.2.3
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.0.2.29
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.0.2
ibm websphere_application_server 6.0.2.28
ibm websphere_application_server 6.0.2.27
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.0.2.1
CVE-2009-2747 MEDIUM

The Java Naming and Directory Interface (JNDI) implementation in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.39, 6.1 before 6.1.0.29, and 7.0 before 7.0.0.7 does not properly restrict access to UserRegistry object methods, which allows remote attackers to obtain sensitive information via a crafted method call.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 6.0.1.5
ibm websphere_application_server 6.0.0.1
ibm websphere_application_server 7.0
ibm websphere_application_server 6.0.2.19
ibm websphere_application_server 6.0.2.7
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.0.0.2
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.0.2.33
ibm websphere_application_server 6.0.1.2
ibm websphere_application_server 6.0.1.17
ibm websphere_application_server 6.0.2.25
ibm websphere_application_server 6.0.1.13
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 6.0.2.31
ibm websphere_application_server 6.0.2.9
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.0.2.35
ibm websphere_application_server 6.0.2.22
ibm websphere_application_server 6.0
ibm websphere_application_server 6.0.1.3
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.0.2.2
ibm websphere_application_server 6.0.2.13
ibm websphere_application_server 6.0.1.11
ibm websphere_application_server 6.0.2.11
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 6.0.1.15
ibm websphere_application_server 6.0.2.15
ibm websphere_application_server 6.0.2.4
ibm websphere_application_server 6.1.0
ibm websphere_application_server 6.0.2.30
ibm websphere_application_server 6.0.2.32
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.0.2.23
ibm websphere_application_server 6.0.2.6
ibm websphere_application_server 6.0.1
ibm websphere_application_server 6.0.1.7
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.0.2.17
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.0.2.37
ibm websphere_application_server 6.0.2.24
ibm websphere_application_server 6.0.2.5
ibm websphere_application_server 6.0.2.3
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.0.2.29
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.0.1.9
ibm websphere_application_server 6.0.2
ibm websphere_application_server 6.0.2.28
ibm websphere_application_server 6.0.2.27
ibm websphere_application_server 6.0.0.3
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.0.1.1
ibm websphere_application_server 6.0.2.1
ibm websphere_application_server 7.0.0.4
CVE-2009-2748 MEDIUM

Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.29 and 7.1 before 7.0.0.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 7.0.0.4
CVE-2009-2749 MEDIUM

Feature Pack for Communications Enabled Applications (CEA) before 1.0.0.1 for IBM WebSphere Application Server 7.0.0.7 uses predictable session values, which allows man-in-the-middle attackers to spoof a collaboration session by guessing the value.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0.0.7
ibm communications_enabled_applications *
CVE-2009-2750 MEDIUM

IBM WebSphere Service Registry and Repository (WSRR) 6.3.0 before FP2 does not have the intended configuration properties, which allows remote authenticated users to obtain unspecified data access via a property query.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-16,

Products Affected

Vendor Product Version
ibm websphere_service_registry_and_repository 6.3.0
ibm websphere_service_registry_and_repository 6.3.0.1
CVE-2009-2751 MEDIUM

IBM WebSphere Commerce 7.0 uses the same cryptographic key for session attributes and merchant data encryption, which has unspecified impact and remote attack vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm websphere_commerce 7.0
CVE-2009-2752 LOW

IBM WebSphere Commerce 7.0 does not properly encrypt data in a database, which makes it easier for local users to obtain sensitive information by defeating cryptographic protection mechanisms.

CVSS 2.0

Severity: LOW

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm websphere_commerce 7.0
CVE-2009-2753 HIGH

Multiple buffer overflows in the authentication functionality in librpc.dll in the Informix Storage Manager (ISM) Portmapper service (aka portmap.exe), as used in IBM Informix Dynamic Server (IDS) 10.x before 10.00.TC9 and 11.x before 11.10.TC3, allow remote attackers to execute arbitrary code via a crafted parameter size.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm informix_dynamic_server 11.10.xc1de
ibm informix_dynamic_server 10.0.xc1
ibm informix_dynamic_server 10.0.xc4
ibm informix_dynamic_server 10.0.tc1
ibm informix_dynamic_server 10.0.xc3e
ibm informix_dynamic_server 10.0.xc8e
ibm informix_dynamic_server 11.1
ibm informix_dynamic_server 10.0.xc6
ibm informix_dynamic_server 10.0.xc8
ibm informix_dynamic_server 10.0.xc7e
ibm informix_dynamic_server 10.0.xc5
ibm informix_dynamic_server 10.0.xc4e
ibm informix_dynamic_server 11.10.xc1
ibm informix_dynamic_server 10.0.xc6e
ibm informix_dynamic_server 10.0.xc7
ibm informix_dynamic_server 11.10.xc2
ibm informix_dynamic_server 10.0.xc3
ibm informix_dynamic_server 10.0.xc5e
ibm informix_dynamic_server 10.0.xc10
ibm informix_dynamic_server 10.0.xc10e
ibm informix_dynamic_server 10.0.xc2e
ibm informix_dynamic_server 11.10
ibm informix_dynamic_server 10.0.xc9
ibm informix_dynamic_server 10.0
ibm informix_dynamic_server 11.10.xc2e
ibm informix_dynamic_server 11.10.xc3
ibm informix_dynamic_server 10.0.xc9e
ibm informix_dynamic_server 11.10.xc3e
CVE-2009-2754 HIGH

Integer signedness error in the authentication functionality in librpc.dll in the Informix Storage Manager (ISM) Portmapper service (aka portmap.exe), as used in IBM Informix Dynamic Server (IDS) 10.x before 10.00.TC9 and 11.x before 11.10.TC3 and EMC Legato NetWorker, allows remote attackers to execute arbitrary code via a crafted parameter size that triggers a stack-based buffer overflow.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-189,

Products Affected

Vendor Product Version
ibm informix_dynamic_server 11.10.xc1de
ibm informix_dynamic_server 10.0.xc1
ibm informix_dynamic_server 10.0.xc4
ibm informix_dynamic_server 10.0.tc1
ibm informix_dynamic_server 10.0.xc3e
ibm informix_dynamic_server 10.0.xc8e
ibm informix_dynamic_server 11.1
ibm informix_dynamic_server 10.0.xc6
ibm informix_dynamic_server 10.0.xc8
ibm informix_dynamic_server 10.0.xc7e
ibm informix_dynamic_server 10.0.xc5
ibm informix_dynamic_server 10.0.xc4e
ibm informix_dynamic_server 11.10.xc1
ibm informix_dynamic_server 10.0.xc6e
ibm informix_dynamic_server 10.0.xc7
ibm informix_dynamic_server 11.10.xc2
emc legato_networker *
ibm informix_dynamic_server 10.0.xc3
ibm informix_dynamic_server 10.0.xc5e
ibm informix_dynamic_server 10.0.xc10
ibm informix_dynamic_server 10.0.xc10e
ibm informix_dynamic_server 10.0.xc2e
ibm informix_dynamic_server 11.10
ibm informix_dynamic_server 10.0.xc9
ibm informix_dynamic_server 10.0
ibm informix_dynamic_server 11.10.xc2e
ibm informix_dynamic_server 11.10.xc3
ibm informix_dynamic_server 10.0.xc9e
ibm informix_dynamic_server 11.10.xc3e
CVE-2009-2858 MEDIUM

Memory leak in the Security component in IBM DB2 8.1 before FP18 on Unix platforms allows attackers to cause a denial of service (memory consumption) via unspecified vectors, related to private memory within the DB2 memory structure.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm db2 8.1
ibm db2 *
CVE-2009-2859 MEDIUM

IBM DB2 8.1 before FP18 allows attackers to obtain unspecified access via a das command.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm db2 8.1
ibm db2 *
CVE-2009-2860 MEDIUM

Unspecified vulnerability in db2jds in IBM DB2 8.1 before FP18 allows remote attackers to cause a denial of service (service crash) via "malicious packets."

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm db2 8.1
ibm db2 *
CVE-2009-2956 MEDIUM

The (1) Net.Commerce and (2) Net.Data components in IBM WebSphere Commerce Suite store sensitive information under the web root with insufficient access control, which allows remote attackers to discover passwords, and database and filesystem details, via direct requests for configuration files.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_commerce_suite *
CVE-2009-3032 HIGH

Integer overflow in kvolefio.dll 8.5.0.8339 and 10.5.0.0 in the Autonomy KeyView Filter SDK, as used in IBM Lotus Notes 8.5, Symantec Mail Security for Microsoft Exchange 5.0.10 through 5.0.13, and other products, allows context-dependent attackers to execute arbitrary code via a crafted OLE document that triggers a heap-based buffer overflow.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-189,

Products Affected

Vendor Product Version
symantec mail_security 6.0.8
symantec mail_security 5.0.11
symantec mail_security 5.0.1.181
symantec data_loss_prevention_detection_servers 9.0.1
symantec mail_security 5.0.12
symantec brightmail_gateway 8.0
symantec mail_security 7.5.4.29
symantec mail_security 5.0.0
symantec data_loss_prevention_endpoint_agents 8.1.1
symantec mail_security 5.0.13
symantec data_loss_prevention_detection_servers 8.1.1
symantec mail_security 5.0.1.182
symantec mail_security 7.5.8
symantec data_loss_prevention_endpoint_agents 9.0.1
symantec data_loss_prevention_detection_servers 10.0
symantec mail_security 7.5.3.25
symantec mail_security 7.5.5.32
symantec mail_security 6.0.6
symantec data_loss_prevention_endpoint_agents 10.0
symantec im_manager_2007 *
symantec mail_security 6.0.7
symantec mail_security 8.0.2
symantec mail_security 7.5.7
symantec mail_security 8.0
symantec mail_security 8.0.1
symantec mail_security 5.0.1.189
ibm lotus_notes 8.5
symantec mail_security 7.5.6
CVE-2009-3037 HIGH

Buffer overflow in xlssr.dll in the Autonomy KeyView XLS viewer (aka File Viewer for Excel), as used in IBM Lotus Notes 5.x through 8.5.x, Symantec Mail Security, Symantec BrightMail Appliance, Symantec Data Loss Prevention (DLP), and other products, allows remote attackers to execute arbitrary code via a crafted .xls spreadsheet attachment.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm lotus_notes 6.0.2
symantec mail_security 6.0.8
symantec mail_security 5.0.1
symantec mail_security 5.0.11
symantec mail_security 5.0.1.181
symantec data_loss_prevention_detection_servers 9.0.1
ibm lotus_notes 8.0.0
symantec mail_security 5.0.12
autonomy keyview *
ibm lotus_notes 7.0.2
symantec mail_security 5.0.0
ibm lotus_notes 6.5.6
ibm lotus_notes 6.5.2
ibm lotus_notes 8.0.1
symantec data_loss_prevention_endpoint_agents 8.1.1
symantec data_loss_prevention_detection_servers 8.1.1
symantec mail_security_appliance 5.0
ibm lotus_notes 8.0
ibm lotus_notes 5.0.3
ibm lotus_notes 5.0.2
ibm lotus_notes 5.0.9a
ibm lotus_notes 6.0.3
ibm lotus_notes 6.0.5
ibm lotus_notes 5.0.6
ibm lotus_notes 6.0.1
symantec mail_security 6.0.7
ibm lotus_notes 5.0
ibm lotus_notes 5.0.11
ibm lotus_notes 6.5.1
ibm lotus_notes 6.5.5
ibm lotus_notes 7.0.1
symantec mail_security 8.0
ibm lotus_notes 5.0.5
symantec mail_security 5.0.1.189
symantec mail_security 7.5.6
ibm lotus_notes 6.0.4
ibm lotus_notes 5.0.12
ibm lotus_notes 5.02
symantec mail_security 7.5.4.29
ibm lotus_notes 5.0.1
ibm lotus_notes 7.0.0
symantec brightmail_appliance 8.0.1
ibm lotus_notes 6.5
ibm lotus_notes 5.0.4
symantec mail_security 5.0.1.182
ibm lotus_notes 6.5.3
ibm lotus_notes 5.0.10
symantec data_loss_prevention_endpoint_agents 9.0.1
symantec mail_security_appliance 5.0.0.24
symantec mail_security 5.0
symantec mail_security 5.0.10
symantec mail_security 7.5.3.25
symantec mail_security 7.5.5.32
ibm lotus_notes 7.0.3
symantec mail_security 6.0.6
ibm lotus_notes 7.0
symantec brightmail_appliance 5.0
symantec brightmail_appliance 8.0.0
ibm lotus_notes 6.5.4
symantec mail_security_appliance 5.0.0.36
ibm lotus_notes 6.0
symantec mail_security 5.0.1.200
symantec data_loss_prevention_detection_servers 7.2
ibm lotus_notes 8.5
CVE-2009-3038 MEDIUM

A certain ActiveX control in lnresobject.dll 7.1.1.119 in the Research In Motion (RIM) Lotus Notes connector for BlackBerry Desktop Manager 5.0.0.11 allows remote attackers to cause a denial of service (Internet Explorer crash) by referencing the control's CLSID in the classid attribute of an OBJECT element.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm lotus_notes_connector *
CVE-2009-3087 MEDIUM

Unspecified vulnerability in nserver.exe in the server in IBM Lotus Domino 8.0 on Windows Server 2003 allows remote attackers to cause a denial of service (daemon crash) via unknown vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.11. NOTE: as of 20090903, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm lotus_domino 8.0
CVE-2009-3088 HIGH

Heap-based buffer overflow in ibmdiradm in IBM Tivoli Directory Server (TDS) 6.0 on Linux allows remote attackers to have an unspecified impact via unknown vectors that trigger heap corruption, as demonstrated by a certain module in VulnDisco Pack Professional 8.11. NOTE: as of 20090903, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm tivoli_directory_server 6.0
CVE-2009-3089 HIGH

IBM Tivoli Directory Server (TDS) 6.0 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via unspecified vectors, related to (1) the ibmslapd.exe daemon on Windows and (2) the ibmdiradm daemon in the administration server on Linux, as demonstrated by certain modules in VulnDisco Pack Professional 8.11, a different vulnerability than CVE-2006-0717. NOTE: as of 20090903, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm tivoli_directory_server 6.0
CVE-2009-3090 MEDIUM

Unspecified vulnerability in IBM Tivoli Directory Server (TDS) 6.0 on Linux allows remote attackers to cause a denial of service via unknown vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.11. NOTE: as of 20090903, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm tivoli_directory_server 6.0
CVE-2009-3105 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Lotus iNotes (aka Domino Web Access or DWA) before 211.241 for Domino 8.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka SPR EZEL7UURYC.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm domino_web_access 8.0.1
CVE-2009-3106 MEDIUM

The Servlet Engine/Web Container component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.37 does not properly implement security constraints on the (1) doGet and (2) doTrace methods, which allows remote attackers to bypass intended access restrictions and obtain sensitive information via a crafted HTTP HEAD request to a Web Application.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.0.2.2
ibm websphere_application_server 6.0.2.20
ibm websphere_application_server 6.0.2.13
ibm websphere_application_server 6.0.2.11
ibm websphere_application_server 6.0.2.19
ibm websphere_application_server 6.0.2.8
ibm websphere_application_server 6.0.2.14
ibm websphere_application_server 6.0.2.7
ibm websphere_application_server 6.0.2.15
ibm websphere_application_server 6.0.2.4
ibm websphere_application_server 6.0.2.30
ibm websphere_application_server 6.0.2.32
ibm websphere_application_server 6.0.2.33
ibm websphere_application_server 6.0.2.18
ibm websphere_application_server 6.0.2.25
ibm websphere_application_server 6.0.2.12
ibm websphere_application_server 6.0.2.23
ibm websphere_application_server 6.0.2.16
ibm websphere_application_server 6.0.2.6
ibm websphere_application_server 6.0.2.17
ibm websphere_application_server 6.0.2.24
ibm websphere_application_server 6.0.2.31
ibm websphere_application_server 6.0.2.5
ibm websphere_application_server 6.0.2.9
ibm websphere_application_server 6.0.2.35
ibm websphere_application_server 6.0.2.3
ibm websphere_application_server 6.0.2.22
ibm websphere_application_server 6.0.2.29
ibm websphere_application_server 6.0.2.10
ibm websphere_application_server 6.0.2
ibm websphere_application_server 6.0.2.28
ibm websphere_application_server 6.0.2.27
ibm websphere_application_server 6.0.2.21
ibm websphere_application_server 6.0.2.1
CVE-2009-3114 HIGH

The RSS reader widget in IBM Lotus Notes 8.0 and 8.5 saves items from an RSS feed as local HTML documents, which allows remote attackers to execute arbitrary script in Internet Explorer's Local Machine Zone via a crafted feed, aka SPR RGAU7RDJ9K.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-94,

Products Affected

Vendor Product Version
ibm lotus_notes 8.5
CVE-2009-3159 HIGH

Unspecified vulnerability in the rriDecompress function in IBM WebSphere MQ 7.0.0.0, 7.0.0.1, and 7.0.0.2 allows remote attackers to cause a denial of service via unknown vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_mq 7.0.0.2
ibm websphere_mq 7.0.0.1
ibm websphere_mq 7.0.0.0
CVE-2009-3160 HIGH

IBM WebSphere MQ 6.x through 6.0.2.7, 7.0.0.0, 7.0.0.1, 7.0.0.2, and 7.0.1.0, when read ahead or asynchronous message consumption is enabled, allows attackers to have an unspecified impact via unknown vectors, related to a "memory overwrite" issue.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_mq 6.0.2.0
ibm websphere_mq 6.0.2.7
ibm websphere_mq 6.0.0.0
ibm websphere_mq 6.0.2.3
ibm websphere_mq 7.0.1.0
ibm websphere_mq 7.0.0.2
ibm websphere_mq 6
ibm websphere_mq 6.0
ibm websphere_mq 6.0.1.0
ibm websphere_mq 6.0.1.1
ibm websphere_mq 6.0.2.6
ibm websphere_mq 7.0.0.1
ibm websphere_mq 6.0.2.4
ibm websphere_mq 6.0.2.5
ibm websphere_mq 7.0.0.0
ibm websphere_mq 6.0.2.1
ibm websphere_mq 6.0.2.2
CVE-2009-3161 HIGH

The server in IBM WebSphere MQ 7.0.0.1, 7.0.0.2, and 7.0.1.0 allows attackers to cause a denial of service (trap) or possibly have unspecified other impact via malformed data.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_mq 7.0.1.0
ibm websphere_mq 7.0.0.2
ibm websphere_mq 7.0.0.1
CVE-2009-3262 LOW

Cross-site scripting (XSS) vulnerability in the Self Service UI (SSUI) in IBM Tivoli Identity Manager (ITIM) 5.0.0.5 allows remote authenticated users to inject arbitrary web script or HTML via the last name field in a profile.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_identity_manager 5.0.0.5
CVE-2009-3453 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Quickr 8.1.0 services for WebSphere Portal allow remote attackers to inject arbitrary web script or HTML via the filename of a .odt file in a Lotus Quickr place, related to the Library template.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm lotus_quickr 8.1.0
CVE-2009-3469 MEDIUM

Cross-site scripting (XSS) vulnerability in profiles/html/simpleSearch.do in IBM Lotus Connections 2.0.1 allows remote attackers to inject arbitrary web script or HTML via the name parameter.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm lotus_connections 2.0.1
CVE-2009-3470 MEDIUM

IBM Informix Dynamic Server (IDS) 10.00 before 10.00.xC11, 11.10 before 11.10.xC4, and 11.50 before 11.50.xC5 allows remote attackers to cause a denial of service (memory corruption, assertion failure, and daemon crash) by sending a long password over a JDBC connection.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm informix_dynamic_server 11.10.xc2
ibm informix_dynamic_server 10.00.xc8
ibm informix_dynamic_server 10.00.xc10
ibm informix_dynamic_server 10.00.xc4
ibm informix_dynamic_server 10.00.xc2
ibm informix_dynamic_server 10.00.xc6
ibm informix_dynamic_server 11.10
ibm informix_dynamic_server 11.50.xc2
ibm informix_dynamic_server 10.00.xc1
ibm informix_dynamic_server 10.00.xc5
ibm informix_dynamic_server 11.50
ibm informix_dynamic_server 10.0
ibm informix_dynamic_server 11.50.xc3
ibm informix_dynamic_server 11.50.xc4
ibm informix_dynamic_server 11.10.xc3
ibm informix_dynamic_server 10.00.xc9
ibm informix_dynamic_server 10.00.xc3
ibm informix_dynamic_server 11.10.xc1
ibm informix_dynamic_server 11.50.xc1
CVE-2009-3471 HIGH

IBM DB2 8 before FP18, 9.1 before FP8, 9.5 before FP4, and 9.7 before FP2 does not perform the expected drops of certain table functions upon a loss of privileges by the functions' definers, which has unspecified impact and remote attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm db2 9.1
ibm db2 8.0
ibm db2 9.5
CVE-2009-3472 MEDIUM

IBM DB2 8 before FP18, 9.1 before FP8, and 9.5 before FP4 allows remote authenticated users to bypass intended access restrictions, and update, insert, or delete table rows, via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm db2 9.1
ibm db2 8.0
ibm db2 9.5
CVE-2009-3473 HIGH

IBM DB2 9.1 before FP8 does not require the SETSESSIONUSER privilege for the SET SESSION AUTHORIZATION statement, which has unspecified impact and remote attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm db2 9.1
CVE-2009-3516 HIGH

gssd in IBM AIX 5.3.x through 5.3.9 and 6.1.0 through 6.1.2 does not properly handle the NFSv4 Kerberos credential cache, which allows local users to bypass intended access restrictions for Kerberized NFSv4 shares via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm aix 5.3.0
ibm aix 6.1.1
ibm aix 6.1
ibm aix 6.1.0
ibm aix 6.1.2
ibm aix 5.3.7
ibm aix 5.3.8
CVE-2009-3517 HIGH

nfs.ext in IBM AIX 5.3.x through 5.3.9 and 6.1.0 through 6.1.2 does not properly use the nfs_portmon setting, which allows remote attackers to bypass intended access restrictions for NFSv4 shares via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm aix 5.3.0
ibm aix 6.1.1
ibm aix 6.1
ibm aix 6.1.0
ibm aix 6.1.2
ibm aix 5.3.7
ibm aix 5.3.8
CVE-2009-3518 HIGH

Argument injection vulnerability in the iim: URI handler in IBMIM.exe in IBM Installation Manager 1.3.2 and earlier, as used in IBM Rational Robot and Rational Team Concert, allows remote attackers to load arbitrary DLL files via the -vm option, as demonstrated by a reference to a UNC share pathname.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-94,

Products Affected

Vendor Product Version
ibm installation_manager 1.0
ibm installation_manager 1.2.1
ibm installation_manager *
ibm installation_manager 1.3.0
ibm installation_manager 1.3.1
CVE-2009-3521 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in the Visualization Engine (VE) in IBM Tivoli Composite Application Manager for WebSphere (ITCAM) 6.1.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_composite_application_manager_for_wesbsphere 6.1.0
CVE-2009-3691 HIGH

Multiple integer overflows in setnet32.exe 3.50.0.13752 in IBM Informix Client SDK 3.0 and 3.50 and Informix Connect Runtime 3.x allow remote attackers to execute arbitrary code via a .nfx file with a crafted (1) HostSize, and possibly (2) ProtoSize and (3) ServerSize, field that triggers a stack-based buffer overflow involving a crafted HostList field. NOTE: some of these details are obtained from third party information.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-189,

Products Affected

Vendor Product Version
ibm informix_client_sdk 3.0
ibm informix_connect_runtime 3.0
ibm informix_client_sdk 3.50
CVE-2009-3699 HIGH

Stack-based buffer overflow in libcsa.a (aka the calendar daemon library) in IBM AIX 5.x through 5.3.10 and 6.x through 6.1.3, and VIOS 2.1 and earlier, allows remote attackers to execute arbitrary code via a long XDR string in the first argument to procedure 21 of rpc.cmsd.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm aix 5.3_l
ibm vios 1.5.1
ibm aix 5.3.10
ibm aix 6.1.0
ibm aix 5.3.0.20
ibm vios *
ibm aix 5
ibm vios 1.5.2
ibm aix 5.3.0
ibm aix 5.3
ibm aix 5.2_l
ibm aix 6.1.1
ibm aix 5.2.0.54
ibm aix 5.2.2
ibm aix 5.3.9
ibm aix 5.3.7
ibm aix 5.1l
ibm aix 6.1.3
ibm aix 5.1
ibm aix 5.1.0.10
ibm vios 1.5.0
ibm aix 6.1
ibm aix 5.2
ibm aix 5.3.8
ibm aix 5.3_ml03
ibm aix 5.2.0
ibm aix 5l
ibm vios 1.4
ibm aix 6.1.2
ibm aix 5.2.0.50
CVE-2009-3730 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in the ReqWeb Help feature (aka the Web Client Help system) in IBM Rational RequisitePro 7.1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the operation parameter to ReqWebHelp/advanced/workingSet.jsp, or the (2) searchWord, (3) maxHits, (4) scopedSearch, or (5) scope parameter to ReqWebHelp/basic/searchView.jsp.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_requisitepro 7.1.0
CVE-2009-3745 MEDIUM

Cross-site scripting (XSS) vulnerability in the help pages in IBM Rational AppScan Enterprise Edition 5.5.0.2 allows remote attackers to inject arbitrary web script or HTML via the query string.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_appscan 5.5.0.2
CVE-2009-3816 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in Activities pages in the Mobile subsystem in IBM Lotus Connections 2.5.0.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm lotus_connections 2.5.0.0
CVE-2009-3852 HIGH

Unspecified vulnerability in the XML component in IBM Runtimes for Java Technology 5.0.0 before SR10 has unknown impact and attack vectors, related to the "updated version of XML4J 4.4.17."

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm runtimes_for_java_technology *
CVE-2009-3853 HIGH

Stack-based buffer overflow in the client acceptor daemon (CAD) scheduler in the client in IBM Tivoli Storage Manager (TSM) 5.3 before 5.3.6.7, 5.4 before 5.4.3, 5.5 before 5.5.2.2, and 6.1 before 6.1.0.2, and TSM Express 5.3.3.0 through 5.3.6.6, allows remote attackers to execute arbitrary code via crafted data in a TCP packet.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager 5.3.6.4
ibm tivoli_storage_manager 6.1.0
ibm tivoli_storage_manager 5.4.2
ibm tivoli_storage_manager 5.3.6
ibm tivoli_storage_manager 5.3.1
ibm tivoli_storage_manager 5.3
ibm tivoli_storage_manager 5.4.1
ibm tivoli_storage_manager 5.3.5
ibm tivoli_storage_manager 5.3.4
ibm tivoli_storage_manager 5.3.6.6
ibm tivoli_storage_manager 5.2.5.3
ibm tivoli_storage_manager 5.3.6.3
ibm tivoli_storage_manager 5.3.0
ibm tivoli_storage_manager 5.3.6.1
ibm tivoli_storage_manager 5.3.6.2
ibm tivoli_storage_manager 5.3.2
ibm tivoli_storage_manager 5.5.1
ibm tivoli_storage_manager 5.3.5.1
ibm tivoli_storage_manager 5.3.3
ibm tivoli_storage_manager 5.4.0
ibm tivoli_storage_manager 5.5.0
ibm tivoli_storage_manager 5.3.6.5
ibm tivoli_storage_manager 5.5.2
ibm tivoli_storage_manager 5.3.2.4
CVE-2009-3854 HIGH

Buffer overflow in the traditional client scheduler in the client in IBM Tivoli Storage Manager (TSM) 5.3 before 5.3.6.7 and 5.4 before 5.4.2 allows remote attackers to execute arbitrary code via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager 5.3.6.4
ibm tivoli_storage_manager 5.3.6.1
ibm tivoli_storage_manager 5.3.1
ibm tivoli_storage_manager 5.3
ibm tivoli_storage_manager 5.4.1
ibm tivoli_storage_manager 5.3.6.2
ibm tivoli_storage_manager 5.3.4
ibm tivoli_storage_manager 5.3.6.6
ibm tivoli_storage_manager 5.3.2
ibm tivoli_storage_manager 5.3.5.1
ibm tivoli_storage_manager 5.3.3
ibm tivoli_storage_manager 5.4.0
ibm tivoli_storage_manager 5.2.5.3
ibm tivoli_storage_manager 5.3.6.3
ibm tivoli_storage_manager 5.5.0
ibm tivoli_storage_manager 5.3.6.5
ibm tivoli_storage_manager 5.3.0
ibm tivoli_storage_manager 5.3.2.4
CVE-2009-3855 HIGH

Multiple unspecified vulnerabilities in the (1) UNIX and (2) Linux backup-archive clients, and the (3) OS/400 API client, in IBM Tivoli Storage Manager (TSM) 5.3 before 5.3.6.6, 5.4 before 5.4.2, and 5.5 before 5.5.1, when the MAILPROG option is enabled, allow attackers to read, modify, or delete arbitrary files via unknown vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager 5.3.6.4
ibm tivoli_storage_manager 5.3.6.1
ibm tivoli_storage_manager 5.3.1
ibm tivoli_storage_manager 5.3
ibm tivoli_storage_manager 5.4.1
ibm tivoli_storage_manager 5.3.6.2
ibm tivoli_storage_manager 5.3.4
ibm tivoli_storage_manager 5.3.2
ibm tivoli_storage_manager 5.3.5.1
ibm tivoli_storage_manager 5.3.3
ibm tivoli_storage_manager 5.4.0
ibm tivoli_storage_manager 5.2.5.3
ibm tivoli_storage_manager 5.3.6.3
ibm tivoli_storage_manager 5.5.0
ibm tivoli_storage_manager 5.3.6.5
ibm tivoli_storage_manager 5.3.0
ibm tivoli_storage_manager 5.3.2.4
CVE-2009-3900 HIGH

Unspecified vulnerability in the Cluster Management component in IBM PowerHA 5.4, 5.4.1, 5.5, and 6.1 on AIX allows remote attackers to modify the operating-system configuration via packets to the godm port (6177/tcp).

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm powerha 6.1
ibm powerha 5.4
ibm powerha 5.4.1
ibm powerha 5.5
CVE-2009-3935 HIGH

Multiple unspecified vulnerabilities in the Advanced Management Module firmware before 2.50G for the IBM BladeCenter T 8720-2xx and 8730-2xx have unknown impact and attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm advanced_management_module_firmware 1.25
ibm advanced_management_module_firmware 1.26e
ibm advanced_management_module_firmware 1.25e
ibm advanced_management_module_firmware 1.01
ibm advanced_management_module_firmware 1.26k
ibm advanced_management_module_firmware 1.34e
ibm advanced_management_module_firmware 1.20f
ibm advanced_management_module_firmware 2.46c
ibm advanced_management_module_firmware 1.20
ibm advanced_management_module_firmware 1.42f
ibm advanced_management_module_firmware 1.36h
ibm advanced_management_module_firmware 1.26i
ibm advanced_management_module_firmware 1.34b
ibm advanced_management_module_firmware 1.36d
ibm advanced_management_module_firmware 1.42i
ibm advanced_management_module_firmware 1.00
ibm advanced_management_module_firmware 1.42n
ibm advanced_management_module_firmware 2.48d
ibm advanced_management_module_firmware *
ibm advanced_management_module_firmware 1.36k
ibm advanced_management_module_firmware 1.42t
ibm advanced_management_module_firmware 2.46j
ibm advanced_management_module_firmware 2.48n
ibm advanced_management_module_firmware 2.48g
ibm advanced_management_module_firmware 2.48c
ibm advanced_management_module_firmware 1.28g
ibm advanced_management_module_firmware 2.48l
ibm advanced_management_module_firmware 1.42d
ibm advanced_management_module_firmware 1.42o
ibm advanced_management_module_firmware 1.36g
ibm advanced_management_module_firmware 1.32d
ibm advanced_management_module_firmware 1.25i
ibm advanced_management_module_firmware 1.26b
ibm advanced_management_module_firmware 1.26h
CVE-2009-4052 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in the JSF Widget Library Runtime in IBM Rational Application Developer for WebSphere Software before 7.0.0.10 and Rational Software Architect before 7.0.0.10 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) the JSF Tree Control and (2) the JavaScript Resource Servlet.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_application_developer_for_websphere 7.0.0.7
ibm rational_application_developer_for_websphere 7.0
ibm rational_software_architect 7.0.0.1
ibm rational_software_architect 7.0.0.4
ibm rational_application_developer_for_websphere 7.0.0.3
ibm rational_software_architect 7.0.0.6
ibm rational_application_developer_for_websphere 7.0.0.9
ibm rational_application_developer_for_websphere 7.0.0.2
ibm rational_application_developer_for_websphere 7.0.0.5
ibm rational_software_architect 7.0.0.2
ibm rational_application_developer_for_websphere 7.0.0.4
ibm rational_software_architect 7.0.0.5
ibm rational_application_developer_for_websphere 7.0.0.8
ibm rational_software_architect 7.0.0.0
ibm rational_software_architect 7.0.0.7
ibm rational_software_architect 7.0.0.8
ibm rational_application_developer_for_websphere 7.0.0.1
ibm rational_software_architect 7.0.0.3
ibm rational_application_developer_for_websphere 7.0.0.6
ibm rational_software_architect 7.0.0.9
CVE-2009-4150 MEDIUM

dasauto in IBM DB2 8 before FP18, 9.1 before FP8, 9.5 before FP4, and 9.7 before FP1 permits execution by unprivileged user accounts, which has unspecified impact and local attack vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm db2 9.1
ibm db2_universal_database 8
ibm db2 9.5
ibm db2 9.7
CVE-2009-4152 MEDIUM

Cross-site scripting (XSS) vulnerability in the Collaboration component in IBM WebSphere Portal 6.1.x before 6.1.0.3 allows remote attackers to inject arbitrary web script or HTML via the people picker tag.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 6.1.0.2
ibm websphere_portal 6.1.0.1
ibm websphere_portal 6.1.0.0
CVE-2009-4153 HIGH

Unspecified vulnerability in the XMLAccess component in IBM WebSphere Portal 6.1.x before 6.1.0.3 has unknown impact and attack vectors, related to the work directory.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_portal 6.1.0.2
ibm websphere_portal 6.1.0.1
ibm websphere_portal 6.1.0.0
CVE-2009-4239 MEDIUM

Cross-site scripting (XSS) vulnerability in the Web console in IBM InfoSphere Information Server 8.1 before FP1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm infosphere_information_server 8.1
CVE-2009-4240 HIGH

Multiple buffer overflows in unspecified setuid executables in the DataStage subsystem in IBM InfoSphere Information Server 8.1 before FP1 have unknown impact and attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm infosphere_information_server 8.1
CVE-2009-4325 MEDIUM

The Client Interfaces component in IBM DB2 8.2 before FP18, 9.1 before FP8, 9.5 before FP5, and 9.7 before FP1 does not validate an unspecified pointer, which allows attackers to overwrite "external memory" via unknown vectors, related to a missing "check for null pointers."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm db2 9.1
ibm db2 8.2
ibm db2 9.5
ibm db2 9.7
CVE-2009-4326 MEDIUM

The RAND scalar function in the Common Code Infrastructure component in IBM DB2 9.5 before FP5 and 9.7 before FP1, when the Database Partitioning Feature (DPF) is used, produces "repeating" return values, which might allow attackers to defeat protection mechanisms based on randomization by predicting a value.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm db2 9.5
ibm db2 9.7
CVE-2009-4327 MEDIUM

The Common Code Infrastructure component in IBM DB2 9.5 before FP5 and 9.7 before FP1 does not properly validate the size of a memory pool during a creation attempt, which allows attackers to cause a denial of service (memory consumption) via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm db2 9.5
ibm db2 9.7
CVE-2009-4328 MEDIUM

Unspecified vulnerability in the DRDA Services component in IBM DB2 9.5 before FP5 allows remote authenticated users to cause a denial of service (server trap) by calling a SQL stored procedure in unknown circumstances.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm db2 9.5
CVE-2009-4329 MEDIUM

Unspecified vulnerability in the Engine Utilities component in IBM DB2 9.5 before FP5 allows remote authenticated users to cause a denial of service (segmentation fault) by modifying the db2ra data stream sent in a request from the Load Utility.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm db2 9.5
CVE-2009-4330 HIGH

Unspecified vulnerability in db2licm in the Engine Utilities component in IBM DB2 9.5 before FP5 has unknown impact and local attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm db2 9.5
CVE-2009-4331 HIGH

The Install component in IBM DB2 9.5 before FP5 and 9.7 before FP1 configures the High Availability (HA) scripts with incorrect file-permission and authorization settings, which has unknown impact and local attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm db2 9.5
ibm db2 9.7
CVE-2009-4332 MEDIUM

db2pd in the Problem Determination component in IBM DB2 9.1 before FP7 and 9.5 before FP5 allows attackers to cause a denial of service (NULL pointer dereference and application termination) via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm db2 9.1
ibm db2 9.5
ibm db2 9.7
CVE-2009-4333 HIGH

The Relational Data Services component in IBM DB2 9.5 before FP5 allows attackers to obtain the password argument from the SET ENCRYPTION PASSWORD statement via vectors involving the GET SNAPSHOT FOR DYNAMIC SQL command.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm db2 9.5
CVE-2009-4334 MEDIUM

The Self Tuning Memory Manager (STMM) component in IBM DB2 9.1 before FP8, 9.5 before FP5, and 9.7 before FP1 uses 0666 permissions for the STMM log file, which allows local users to cause a denial of service or have unspecified other impact by writing to this file.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm db2 9.1
ibm db2 9.5
ibm db2 9.7
CVE-2009-4335 HIGH

Multiple unspecified vulnerabilities in bundled stored procedures in the Spatial Extender component in IBM DB2 9.5 before FP5 have unknown impact and remote attack vectors, related to "remote exploits."

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm db2 9.5
CVE-2009-4357 MEDIUM

CQWeb (aka the web interface) in IBM Rational ClearQuest before 7.1.1 does not properly handle use of legacy URLs for automatic login, which might allow attackers to discover the passwords for user accounts via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_clearcase 7.0.0.2
ibm rational_clearquest 5.20
ibm rational_clearquest 6.10
ibm rational_clearquest 6.16
ibm rational_clearcase 7.0.1.3
ibm rational_clearcase 7.0.1.1
ibm rational_clearcase *
ibm rational_clearquest 6.12
ibm rational_clearquest 7.0.1.1
ibm rational_clearcase 7.0.0.4
ibm rational_clearquest 5.00
ibm rational_clearquest 7.0.1
ibm rational_clearquest 2007
ibm rational_clearquest 6.00
ibm rational_clearcase 7.0.0.1
ibm rational_clearquest 7.0
ibm rational_clearquest 6.14
ibm rational_clearquest 6.15
ibm rational_clearquest 7.0.0.1
ibm rational_clearquest 2008
ibm rational_clearquest 7.0.1.3
ibm rational_clearquest 7.0.1.0
ibm rational_clearquest 7.0.2
ibm rational_clearquest 6.13
CVE-2009-4361 HIGH

Multiple buffer overflows in qoslist in IBM AIX 6.1 allow local users to cause a denial of service (application crash) or possibly gain privileges via a long string argument. NOTE: some of these details are obtained from third party information.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm aix 6.1
CVE-2009-4362 HIGH

Multiple buffer overflows in qosmod in IBM AIX 6.1 allow local users to cause a denial of service (application crash) or possibly gain privileges via long string arguments. NOTE: some of these details are obtained from third party information.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm aix 6.1
CVE-2009-4438 MEDIUM

The Query Compiler, Rewrite, and Optimizer component in IBM DB2 9.1 before FP8, 9.5 before FP5, and 9.7 before FP1 does not enforce privilege requirements for access to a (1) sequence or (2) global-variable object, which allows remote authenticated users to make use of data via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm db2 9.1
ibm db2 9.5
ibm db2 9.7
CVE-2009-4439 MEDIUM

Unspecified vulnerability in the Query Compiler, Rewrite, and Optimizer component in IBM DB2 9.5 before FP5 allows remote authenticated users to cause a denial of service (instance crash) by compiling a SQL query.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm db2 9.5
CVE-2009-4594 HIGH

Unspecified vulnerability in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.131 for Domino 8.0.x has unknown impact and attack vectors, aka SPR SDOY7RHBNH.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm lotus_inotes 229.041
ibm lotus_inotes 229.031
ibm lotus_inotes 229.101
ibm lotus_inotes 229.061
ibm lotus_inotes *
ibm lotus_inotes 229.011
ibm lotus_inotes 229.021
ibm lotus_inotes 229.051
CVE-2009-4998 LOW

The Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 3.5.1 before 3.5.1-019 and 4.0.2.x before 4.0.2.7-P8AE-FP007, in certain FileTracker configurations, does not apply a security policy to the first document added during a session, which might allow remote attackers to bypass intended access restrictions via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm filenet_p8_application_engine 4.0.2
ibm filenet_p8_application_engine 3.5.1
CVE-2009-4999 MEDIUM

Cross-site scripting (XSS) vulnerability in the Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 3.5.1 before 3.5.1-016 allows remote attackers to inject arbitrary web script or HTML via the Name field.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm filenet_p8_application_engine 3.5.1
CVE-2009-5000 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in the Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 4.0.2.x before 4.0.2.3-P8AE-FP003 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to .jsp pages.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm filenet_p8_application_engine 4.0.2
CVE-2009-5001 MEDIUM

The Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 4.0.2.x before 4.0.2.2-P8AE-FP002 grants a document's Creator-Owner full control over an annotation object, even if the default instance security has changed, which might allow remote authenticated users to bypass intended access restrictions in opportunistic circumstances.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm filenet_p8_application_engine 4.0.2
CVE-2009-5002 MEDIUM

The Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 4.0.2.x before 4.0.2.1-P8AE-FP001 does not record Get Content Failure Audit events, which might allow remote attackers to attempt content access without detection.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm filenet_p8_application_engine 4.0.2
CVE-2009-5032 MEDIUM

The encrypted e-mail feature in IBM Lotus Notes Traveler before 8.5.0.2 sends unencrypted messages when the feature is used without uploading a Notes ID file, which makes it easier for remote attackers to obtain sensitive information by sniffing the network.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm lotus_notes_traveler 8.0
ibm lotus_notes_traveler 8.5.0.0
ibm lotus_notes_traveler 8.0.1
ibm lotus_notes_traveler 8.0.1.3
ibm lotus_notes_traveler *
ibm lotus_notes_traveler 8.0.1.2
CVE-2009-5033 MEDIUM

IBM Lotus Notes Traveler before 8.5.0.2 does not properly handle a "* *" argument sequence for a certain tell command, which allows remote authenticated users to obtain access to other users' data via a sync operation, related to storage of the data of multiple users within the same thread.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm lotus_notes_traveler 8.0
ibm lotus_notes_traveler 8.5.0.0
ibm lotus_notes_traveler 8.0.1
ibm lotus_notes_traveler 8.0.1.3
ibm lotus_notes_traveler *
ibm lotus_notes_traveler 8.0.1.2
CVE-2009-5034 MEDIUM

IBM Lotus Notes Traveler before 8.5.0.2 allows remote authenticated users to cause a denial of service (memory consumption and daemon crash) by syncing a large volume of data, related to the launch of a new process to handle the data while the previous process is still operating on the data.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm lotus_notes_traveler 8.0
ibm lotus_notes_traveler 8.5.0.0
ibm lotus_notes_traveler 8.0.1
ibm lotus_notes_traveler 8.0.1.3
ibm lotus_notes_traveler *
ibm lotus_notes_traveler 8.0.1.2
CVE-2009-5035 MEDIUM

The Nokia client in IBM Lotus Notes Traveler before 8.5.0.2 does not properly handle multiple outgoing e-mail messages between sync operations, which might allow remote attackers to read communications intended for other recipients by examining appended messages.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm lotus_notes_traveler 8.0
ibm lotus_notes_traveler 8.5.0.0
ibm lotus_notes_traveler 8.0.1
ibm lotus_notes_traveler 8.0.1.3
ibm lotus_notes_traveler *
ibm lotus_notes_traveler 8.0.1.2
CVE-2009-5036 MEDIUM

traveler.exe in IBM Lotus Notes Traveler before 8.0.1.3 CF1 allows remote authenticated users to cause a denial of service (daemon crash) via a malformed invitation document in a sync operation.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_notes_traveler 8.0
ibm lotus_notes_traveler 8.0.1
ibm lotus_notes_traveler *
ibm lotus_notes_traveler 8.0.1.2
CVE-2009-5058 LOW

Unspecified vulnerability in IBM Lotus Quickr 8.1 before 8.1.0.5 services for Lotus Domino allows remote authenticated users to cause a denial of service (daemon crash) by deleting an item that is accessed through a connector, aka SPR RELS7LARKR.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm lotus_quickr 8.1
CVE-2009-5059 LOW

Unspecified vulnerability in IBM Lotus Quickr 8.1 before 8.1.0.10 services for Lotus Domino might allow remote authenticated users to cause a denial of service (daemon crash) by checking out a document that is accessed through a connector, aka SPR MMOI7PSR8J.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm lotus_quickr 8.1
CVE-2009-5060 LOW

Unspecified vulnerability in IBM Lotus Quickr 8.1 before 8.1.0.11 services for Lotus Domino might allow remote authenticated users to cause a denial of service (daemon crash) by accessing an entry in a calendar, aka SPR MZHA7SEBJX.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm lotus_quickr 8.1
CVE-2009-5061 LOW

Unspecified vulnerability in IBM Lotus Quickr 8.1 before 8.1.0.14 services for Lotus Domino, when Domino Native Authentication is enabled, might allow remote authenticated users to cause a denial of service (daemon crash) by going offline, aka SPR MLZG7UPB9N.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm lotus_quickr 8.1
CVE-2009-5062 LOW

IBM Lotus Quickr 8.1 before 8.1.0.15 services for Lotus Domino on AIX allows remote authenticated users to cause a denial of service (daemon crash) by subscribing to an Atom feed, aka SPR JRIE7VKMP9.

CVSS 2.0

Severity: LOW

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm lotus_quickr 8.1
CVE-2009-5072 MEDIUM

Memory leak in the ldap_explode_dn function in IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.61 (aka 6.0.0.8-TIV-ITDS-IF0003) allows remote authenticated users to cause a denial of service (memory consumption) via an empty string argument.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm tivoli_directory_server 6.0.0.19
ibm tivoli_directory_server 6.0.0.41
ibm tivoli_directory_server 6.0.0.58
ibm tivoli_directory_server 6.0.0.60
ibm tivoli_directory_server 6.0.0.45
ibm tivoli_directory_server 6.0.0.57
ibm tivoli_directory_server 6.0.0.54
ibm tivoli_directory_server 6.0.0.1
ibm tivoli_directory_server 6.0.0.7
ibm tivoli_directory_server 6.0.0.0
ibm tivoli_directory_server 6.0.0.8
ibm tivoli_directory_server 6.0
ibm tivoli_directory_server 6.0.0.59
ibm tivoli_directory_server 6.0.0.52
ibm tivoli_directory_server 6.0.0.14
ibm tivoli_directory_server 6.0.0.56
ibm tivoli_directory_server 6.0.0.55
ibm tivoli_directory_server 6.0.0.33
ibm tivoli_directory_server 6.0.0.53
CVE-2009-5073 MEDIUM

IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.59 (aka 6.0.0.8-TIV-ITDS-IF0001) allows remote authenticated users to cause a denial of service (infinite loop and daemon hang) by adding a nested group that contains the Distinguished Name (DN) of its parent entry.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm tivoli_directory_server 6.0.0.19
ibm tivoli_directory_server 6.0.0.41
ibm tivoli_directory_server 6.0.0.58
ibm tivoli_directory_server 6.0.0.45
ibm tivoli_directory_server 6.0.0.57
ibm tivoli_directory_server 6.0.0.54
ibm tivoli_directory_server 6.0.0.1
ibm tivoli_directory_server 6.0.0.7
ibm tivoli_directory_server 6.0.0.0
ibm tivoli_directory_server 6.0.0.8
ibm tivoli_directory_server 6.0
ibm tivoli_directory_server 6.0.0.52
ibm tivoli_directory_server 6.0.0.14
ibm tivoli_directory_server 6.0.0.56
ibm tivoli_directory_server 6.0.0.55
ibm tivoli_directory_server 6.0.0.33
ibm tivoli_directory_server 6.0.0.53
CVE-2009-5083 MEDIUM

IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.2, when configured as an OpenID relying party, does not perform the expected login rejection upon receiving an OP-Identifier from an OpenID provider, which allows remote attackers to bypass authentication via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm tivoli_federated_identity_manager 6.2.0
ibm tivoli_federated_identity_manager 6.2.0.1
CVE-2009-5084 LOW

IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.2, when com.tivoli.am.fim.infocard.delegates.InfoCardSTSDelegate tracing is enabled, creates a cleartext log entry containing a password, which might allow local users to obtain sensitive information by reading the log data.

CVSS 2.0

Severity: LOW

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm tivoli_federated_identity_manager 6.2.0
ibm tivoli_federated_identity_manager 6.2.0.1
CVE-2009-5085 LOW

IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.2, when configured as an OpenID provider, does not delete the site information cookie in response to a user's deletion of a relying-party trust entry, which allows user-assisted remote attackers to bypass intended trust restrictions via vectors that trigger absence of the consent-to-authenticate page.

CVSS 2.0

Severity: LOW

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm tivoli_federated_identity_manager 6.2.0
ibm tivoli_federated_identity_manager 6.2.0.1
CVE-2010-0152 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in the Local Management Interface (LMI) on the IBM Proventia Network Mail Security System (PNMSS) appliance with firmware before 2.5.0.2 allow remote attackers to inject arbitrary web script or HTML via (1) the date1 parameter to pvm_messagestore.php, (2) the userfilter parameter to pvm_user_management.php, (3) the ping parameter to sys_tools.php in a sys_ping.php action, (4) the action parameter to pvm_cert_commaction.php, (5) the action parameter to pvm_cert_serveraction.php, (6) the action parameter to pvm_smtpstore.php, (7) the l parameter to sla/index.php, or (8) unspecified stored data; and allow remote authenticated users to inject arbitrary web script or HTML via (9) saved search filters.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm proventia_network_mail_security_system_virtual_appliance_firmware 2.5
ibm proventia_network_mail_security_system_virtual_appliance_firmware 1.6
ibm proventia_network_mail_security_system_virtual_appliance *
CVE-2010-0153 MEDIUM

Multiple cross-site request forgery (CSRF) vulnerabilities in the Local Management Interface (LMI) on the IBM Proventia Network Mail Security System (PNMSS) appliance with firmware before 2.5.0.2 allow remote attackers to hijack the authentication of administrators for requests that (1) change settings or (2) conduct denial of service attacks.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm proventia_network_mail_security_system_virtual_appliance_firmware 2.5
ibm proventia_network_mail_security_system_virtual_appliance_firmware 1.6
ibm proventia_network_mail_security_system_virtual_appliance *
CVE-2010-0154 MEDIUM

Directory traversal vulnerability in sla/index.php in the Local Management Interface (LMI) on the IBM Proventia Network Mail Security System (PNMSS) appliance with firmware before 2.5 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the l parameter, related to an "Insecure Direct Object Reference vulnerability."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm proventia_network_mail_security_system_virtual_appliance_firmware 1.6
ibm proventia_network_mail_security_system_virtual_appliance *
CVE-2010-0155 LOW

CRLF injection vulnerability in load.php in the Local Management Interface (LMI) on the IBM Proventia Network Mail Security System (PNMSS) appliance with firmware before 2.5 allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the javaVersion parameter.

CVSS 2.0

Severity: LOW

Problem Type: CWE-94,

Products Affected

Vendor Product Version
ibm proventia_network_mail_security_system_virtual_appliance_firmware 1.6
ibm proventia_network_mail_security_system_virtual_appliance *
CVE-2010-0274 HIGH

Unspecified vulnerability in the Edit Contact scene in Ultra-light Mode in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.241 for Domino 8.0.2 FP3 has unknown impact and attack vectors, aka SPR LSHR7TBLY5.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm lotus_inotes 229.031
ibm lotus_inotes 229.111
ibm lotus_inotes 229.101
ibm lotus_inotes 229.171
ibm lotus_inotes 229.201
ibm lotus_inotes 229.191
ibm lotus_inotes 229.221
ibm lotus_inotes 229.131
ibm lotus_inotes 229.141
ibm lotus_inotes *
ibm lotus_inotes 229.051
ibm lotus_inotes 229.041
ibm lotus_inotes 229.151
ibm lotus_inotes 229.061
ibm lotus_inotes 229.181
ibm lotus_inotes 229.211
ibm lotus_inotes 229.161
ibm lotus_inotes 229.011
ibm lotus_inotes 229.021
CVE-2010-0275 HIGH

Ultra-light Mode in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.241 for Domino 8.0.2 FP3 does not properly handle script commands in the status-alerts URL, which has unspecified impact and attack vectors, aka SPR LSHR7TBM58.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm lotus_inotes 229.031
ibm lotus_inotes 229.111
ibm lotus_inotes 229.101
ibm lotus_inotes 229.171
ibm lotus_inotes 229.201
ibm lotus_inotes 229.191
ibm lotus_inotes 229.221
ibm lotus_inotes 229.131
ibm lotus_inotes 229.141
ibm lotus_inotes *
ibm lotus_inotes 229.051
ibm lotus_inotes 229.041
ibm lotus_inotes 229.151
ibm lotus_inotes 229.061
ibm lotus_inotes 229.181
ibm lotus_inotes 229.211
ibm lotus_inotes 229.161
ibm lotus_inotes 229.011
ibm lotus_inotes 229.021
CVE-2010-0276 HIGH

IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.241 for Domino 8.0.2 FP3 does not properly handle navigation of the "Try Lotus iNotes anyway" link from the page that reports use of an unsupported browser, which has unspecified impact and attack vectors, aka SPR LSHR7TBMQU.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm domino_web_access *
ibm lotus_domino 8.0.2.3
ibm lotus_inotes *
CVE-2010-0312 MEDIUM

The do_extendedOp function in ibmslapd in IBM Tivoli Directory Server (TDS) 6.2 on Linux allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted SecureWay 3.2 Event Registration Request (aka a 1.3.18.0.2.12.1 request).

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm tivoli_directory_server 6.2
CVE-2010-0357 MEDIUM

Cross-site scripting (XSS) vulnerability in the Login page in IBM Lotus Web Content Management (WCM) 6.0.1.4, 6.0.1.5, and 6.0.1.6 before iFix 32; and 6.1.0.1 and 6.1.0.2 before iFix 24; for WebSphere Portal allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm lotus_web_content_management 6.1.0.1
ibm lotus_web_content_management 6.1.0.2
ibm lotus_web_content_management 6.0.1.6
ibm lotus_web_content_management 6.0.1.4
ibm lotus_web_content_management 6.0.1.5
CVE-2010-0358 HIGH

Heap-based buffer overflow in the server in IBM Lotus Domino 7 and 8.5 FP1 allows remote attackers to cause a denial of service (daemon exit) and possibly have unspecified other impact via a long string in a crafted LDAP message to a TCP port, a different vulnerability than CVE-2009-3087.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm lotus_domino 7.0
ibm lotus_domino 8.5.0.1
CVE-2010-0425 HIGH

modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure that request processing is complete before calling isapi_unload for an ISAPI .dll module, which allows remote attackers to execute arbitrary code via unspecified vectors related to a crafted request, a reset packet, and "orphaned callback pointers."

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm http_server 6.1.0.5
ibm http_server 6.1.0.21
ibm http_server 6.0.2.39
ibm http_server 6.1.0.9
ibm http_server 6.0.2.27
oracle http_server 10.1.3.5.0
ibm http_server 6.1.0.25
ibm http_server 6.0.2.9
broadcom vmware_ace_management_server *
ibm http_server 6.0.2.33
ibm http_server 6.1.0.3
apache http_server *
ibm http_server 6.0.2.29
ibm http_server 6.0.2.35
ibm http_server 6.1.0.2
ibm http_server 6.1.0.23
ibm http_server 6.0.2.1
ibm websphere_application_server *
ibm http_server 6.0.2.23
ibm http_server 6.0.2.31
ibm http_server 6.1.0.15
ibm http_server 6.0.2.7
ibm http_server 6.0.2.15
ibm http_server 6.1.0.27
ibm http_server 6.0.2.25
ibm http_server 6.1.0.7
ibm http_server 6.0.2.11
ibm http_server 6.1.0.11
ibm http_server 6.0.2.21
ibm http_server 6.1.0.13
ibm http_server 6.0.2
ibm http_server 6.1
ibm http_server 6.0.2.13
ibm http_server 6.1.0.29
ibm http_server 6.0.2.37
ibm http_server 6.1.0.19
ibm http_server 6.0.2.3
ibm http_server 6.0.2.19
ibm http_server 6.1.0.17
CVE-2010-0462 MEDIUM

Heap-based buffer overflow in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 allows remote authenticated users to have an unspecified impact via a SELECT statement that has a long column name generated with the REPEAT function.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm db2 9.1
ibm db2 9.5
ibm db2 9.7
CVE-2010-0472 MEDIUM

kuddb2 in Tivoli Monitoring for DB2, as distributed in IBM DB2 9.7 FP1 on Linux, allows remote attackers to cause a denial of service (daemon crash) via a certain byte sequence.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm db2 9.7.0.1
CVE-2010-0557 HIGH

IBM Cognos Express 9.0 allows attackers to obtain unspecified access to the Tomcat Manager component, and cause a denial of service, by leveraging hardcoded credentials.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm cognos_express 9.0
CVE-2010-0563 MEDIUM

The Single Sign-on (SSO) functionality in IBM WebSphere Application Server (WAS) 7.0.0.0 through 7.0.0.8 does not recognize the Requires SSL configuration option, which might allow remote attackers to obtain sensitive information by sniffing network sessions that were expected to be encrypted.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 7.0.0.1
CVE-2010-0704 MEDIUM

Cross-site scripting (XSS) vulnerability in the Portlet Palette in IBM WebSphere Portal 6.0.1.5 wp6015_008_01 allows remote attackers to inject arbitrary web script or HTML via the search field.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 6.0.1.5
CVE-2010-0714 MEDIUM

Cross-site scripting (XSS) vulnerability in login.jsp in IBM WebSphere Portal, IBM Lotus Web Content Management (WCM), and IBM Lotus Workplace Web Content Management 5.1.0.0 through 5.1.0.5, 6.0.0.0 through 6.0.0.4, 6.0.1.0 through 6.0.1.7, 6.1.0.0 through 6.1.0.3, and 6.1.5.0; and IBM Lotus Quickr services 8.0, 8.0.0.2, 8.1, 8.1.1, and 8.1.1.1 for WebSphere Portal; allows remote attackers to inject arbitrary web script or HTML via the query string.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 6.0.0.2
ibm lotus_web_content_management 6.1.5.0
ibm websphere_portal 6.1.0.3
ibm lotus_workplace_web_content_management 6.0.1.6
ibm websphere_portal 6.0.1.0
ibm lotus_workplace_web_content_management 6.0.1.7
ibm websphere_portal 6.0.1.1
ibm websphere_portal 5.1.0.3
ibm lotus_web_content_management 5.1.0.5
ibm lotus_quickr 8.0
ibm lotus_web_content_management 6.1.0.1
ibm lotus_workplace_web_content_management 6.0.1.0
ibm websphere_portal 6.0.1.3
ibm lotus_workplace_web_content_management 6.0.1.3
ibm lotus_workplace_web_content_management 6.1.0.2
ibm lotus_workplace_web_content_management 5.1.0.1
ibm lotus_workplace_web_content_management 6.0.1.2
ibm websphere_portal 6.0.0.1
ibm websphere_portal 6.1.5.0
ibm lotus_web_content_management 6.0.1.7
ibm lotus_workplace_web_content_management 5.1.0.3
ibm lotus_workplace_web_content_management 6.1.5.0
ibm websphere_portal 6.1.0.1
ibm lotus_web_content_management 6.0.1.5
ibm websphere_portal 6.0.1.4
ibm lotus_workplace_web_content_management 6.1.0.3
ibm lotus_web_content_management 5.1.0.0
ibm websphere_portal 6.0.0.0
ibm lotus_web_content_management 5.1.0.2
ibm websphere_portal 6.0.1.6
ibm lotus_web_content_management 6.0.0.2
ibm lotus_workplace_web_content_management 6.0.1.5
ibm lotus_web_content_management 6.0.1.2
ibm lotus_workplace_web_content_management 6.0.0.2
ibm websphere_portal 6.0.1.2
ibm lotus_web_content_management 6.0.0.4
ibm lotus_web_content_management 6.0.0.3
ibm websphere_portal 6.0.1.5
ibm websphere_portal 6.0.0.3
ibm lotus_web_content_management 6.0.0.1
ibm lotus_web_content_management 6.1.0.0
ibm lotus_web_content_management 5.1.0.1
ibm websphere_portal 5.1.0.1
ibm lotus_web_content_management 6.0.1.0
ibm lotus_workplace_web_content_management 6.0.0.4
ibm websphere_portal 5.1.0.4
ibm lotus_quickr 8.0.0.2
ibm lotus_quickr 8.1.1.1
ibm websphere_portal 6.0.0.4
ibm websphere_portal 5.1.0.2
ibm websphere_portal 5.1.0.0
ibm lotus_workplace_web_content_management 5.1.0.4
ibm lotus_workplace_web_content_management 6.1.0.1
ibm lotus_workplace_web_content_management 5.1.0.5
ibm lotus_workplace_web_content_management 6.0.1.4
ibm lotus_quickr 8.1.1
ibm lotus_web_content_management 6.0.1.6
ibm lotus_web_content_management 6.0.1.3
ibm lotus_workplace_web_content_management 6.0.0.3
ibm lotus_web_content_management 6.1.0.3
ibm websphere_portal 6.1.0.0
ibm lotus_web_content_management 6.1.0.2
ibm lotus_quickr 8.1
ibm lotus_web_content_management 6.0.1.1
ibm websphere_portal 6.1.0.2
ibm lotus_workplace_web_content_management 5.1.0.2
ibm lotus_workplace_web_content_management 6.1.0.0
ibm lotus_web_content_management 6.0.1.4
ibm lotus_workplace_web_content_management 5.1.0.0
ibm lotus_web_content_management 5.1.0.4
ibm lotus_web_content_management 6.0.0.0
ibm lotus_web_content_management 5.1.0.3
ibm websphere_portal 6.0.1.7
ibm lotus_workplace_web_content_management 6.0.0.1
ibm lotus_workplace_web_content_management 6.0.0.0
ibm websphere_portal 5.1.0.5
ibm lotus_workplace_web_content_management 6.0.1.1
CVE-2010-0715 MEDIUM

Open redirect vulnerability in login.jsp in IBM WebSphere Portal, IBM Lotus Web Content Management (WCM), and IBM Lotus Workplace Web Content Management 5.1.0.0 through 5.1.0.5, 6.0.0.0 through 6.0.0.4, 6.0.1.0 through 6.0.1.7, 6.1.0.0 through 6.1.0.3, and 6.1.5.0; and IBM Lotus Quickr services 8.0, 8.0.0.2, 8.1, 8.1.1, and 8.1.1.1 for WebSphere Portal; allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the query string.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_portal 6.0.0.2
ibm lotus_web_content_management 6.1.5.0
ibm websphere_portal 6.1.0.3
ibm lotus_workplace_web_content_management 6.0.1.6
ibm websphere_portal 6.0.1.0
ibm lotus_workplace_web_content_management 6.0.1.7
ibm websphere_portal 6.0.1.1
ibm websphere_portal 5.1.0.3
ibm lotus_web_content_management 5.1.0.5
ibm lotus_quickr 8.0
ibm lotus_web_content_management 6.1.0.1
ibm lotus_workplace_web_content_management 6.0.1.0
ibm websphere_portal 6.0.1.3
ibm lotus_workplace_web_content_management 6.0.1.3
ibm lotus_workplace_web_content_management 6.1.0.2
ibm lotus_workplace_web_content_management 5.1.0.1
ibm lotus_workplace_web_content_management 6.0.1.2
ibm websphere_portal 6.0.0.1
ibm websphere_portal 6.1.5.0
ibm lotus_web_content_management 6.0.1.7
ibm lotus_workplace_web_content_management 5.1.0.3
ibm lotus_workplace_web_content_management 6.1.5.0
ibm websphere_portal 6.1.0.1
ibm lotus_web_content_management 6.0.1.5
ibm websphere_portal 6.0.1.4
ibm lotus_workplace_web_content_management 6.1.0.3
ibm lotus_web_content_management 5.1.0.0
ibm websphere_portal 6.0.0.0
ibm lotus_web_content_management 5.1.0.2
ibm websphere_portal 6.0.1.6
ibm lotus_web_content_management 6.0.0.2
ibm lotus_workplace_web_content_management 6.0.1.5
ibm lotus_web_content_management 6.0.1.2
ibm lotus_workplace_web_content_management 6.0.0.2
ibm websphere_portal 6.0.1.2
ibm lotus_web_content_management 6.0.0.4
ibm lotus_web_content_management 6.0.0.3
ibm websphere_portal 6.0.1.5
ibm websphere_portal 6.0.0.3
ibm lotus_web_content_management 6.0.0.1
ibm lotus_web_content_management 6.1.0.0
ibm lotus_web_content_management 5.1.0.1
ibm websphere_portal 5.1.0.1
ibm lotus_web_content_management 6.0.1.0
ibm lotus_workplace_web_content_management 6.0.0.4
ibm websphere_portal 5.1.0.4
ibm lotus_quickr 8.0.0.2
ibm lotus_quickr 8.1.1.1
ibm websphere_portal 6.0.0.4
ibm websphere_portal 5.1.0.2
ibm websphere_portal 5.1.0.0
ibm lotus_workplace_web_content_management 5.1.0.4
ibm lotus_workplace_web_content_management 6.1.0.1
ibm lotus_workplace_web_content_management 5.1.0.5
ibm lotus_workplace_web_content_management 6.0.1.4
ibm lotus_quickr 8.1.1
ibm lotus_web_content_management 6.0.1.6
ibm lotus_web_content_management 6.0.1.3
ibm lotus_workplace_web_content_management 6.0.0.3
ibm lotus_web_content_management 6.1.0.3
ibm websphere_portal 6.1.0.0
ibm lotus_web_content_management 6.1.0.2
ibm lotus_quickr 8.1
ibm lotus_web_content_management 6.0.1.1
ibm websphere_portal 6.1.0.2
ibm lotus_workplace_web_content_management 5.1.0.2
ibm lotus_workplace_web_content_management 6.1.0.0
ibm lotus_web_content_management 6.0.1.4
ibm lotus_workplace_web_content_management 5.1.0.0
ibm lotus_web_content_management 5.1.0.4
ibm lotus_web_content_management 6.0.0.0
ibm lotus_web_content_management 5.1.0.3
ibm websphere_portal 6.0.1.7
ibm lotus_workplace_web_content_management 6.0.0.1
ibm lotus_workplace_web_content_management 6.0.0.0
ibm websphere_portal 5.1.0.5
ibm lotus_workplace_web_content_management 6.0.1.1
CVE-2010-0768 MEDIUM

Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.9 allows remote attackers to inject arbitrary web script or HTML via the URI.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 6.0.2.13
ibm websphere_application_server 6.0.2.11
ibm websphere_application_server 7.0
ibm websphere_application_server 6.0.2.19
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 6.0.2.7
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.0.2.15
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 6.1.0
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server *
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.0.2.33
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.0.2.25
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 6.0.2.23
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.0.2.17
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 6.0.2.37
ibm websphere_application_server 6.0.2.31
ibm websphere_application_server 6.0.2.5
ibm websphere_application_server 6.0.2.9
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.0.2.35
ibm websphere_application_server 6.0.2.3
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.0.2.29
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.0.2
ibm websphere_application_server 6.0.2.27
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.0.2.21
ibm websphere_application_server 6.0.2.1
CVE-2010-0769 LOW

IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.9 does not properly define wsadmin scripting J2CConnectionFactory objects, which allows local users to discover a KeyRingPassword password by reading a cleartext field in the resources.xml file.

CVSS 2.0

Severity: LOW

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 6.0.2.13
ibm websphere_application_server 6.0.2.11
ibm websphere_application_server 7.0
ibm websphere_application_server 6.0.2.19
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 6.0.2.7
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.0.0.2
ibm websphere_application_server 6.0.2.15
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 6.1.0
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server *
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.0.2.33
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.0.1.2
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.0.2.25
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 6.0.2.23
ibm websphere_application_server 6.0.1
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.0.2.17
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 6.0.2.37
ibm websphere_application_server 6.0.2.31
ibm websphere_application_server 6.0.2.5
ibm websphere_application_server 6.0.2.9
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.0.2.35
ibm websphere_application_server 6.0.2.3
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.0.2.29
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.0
ibm websphere_application_server 6.0.2
ibm websphere_application_server 6.0.2.27
ibm websphere_application_server 6.0.0.3
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.0.2.21
ibm websphere_application_server 6.0.2.1
CVE-2010-0770 MEDIUM

IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.9 allows remote authenticated users to cause a denial of service (ORB ListenerThread hang) by aborting an SSL handshake.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 6.0.2.13
ibm websphere_application_server 6.0.2.11
ibm websphere_application_server 7.0
ibm websphere_application_server 6.0.2.19
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 6.0.2.7
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.0.0.2
ibm websphere_application_server 6.0.2.15
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 6.1.0
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server *
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.0.2.33
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.0.1.2
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.0.2.25
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 6.0.2.23
ibm websphere_application_server 6.0.1
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.0.2.17
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 6.0.2.37
ibm websphere_application_server 6.0.2.31
ibm websphere_application_server 6.0.2.5
ibm websphere_application_server 6.0.2.9
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.0.2.35
ibm websphere_application_server 6.0.2.3
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.0.2.29
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.0
ibm websphere_application_server 6.0.2
ibm websphere_application_server 6.0.2.27
ibm websphere_application_server 6.0.0.3
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.0.2.21
ibm websphere_application_server 6.0.2.1
CVE-2010-0772 MEDIUM

Unspecified vulnerability in the channel process in IBM WebSphere MQ 7.0 before 7.0.1.2 allows remote authenticated users to cause a denial of service (daemon crash) via "incorrect channel control data."

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_mq 7.0.0
ibm websphere_mq 7.0.1.1
ibm websphere_mq 7.0.1
CVE-2010-0774 MEDIUM

The (1) JAX-RPC WS-Security 1.0 and (2) JAX-WS runtime implementations in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.11 do not properly handle WebServices PKCS#7 and PKIPath tokens, which allows remote attackers to bypass intended access restrictions via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 6.0.1.5
ibm websphere_application_server 6.0.0.1
ibm websphere_application_server 7.0
ibm websphere_application_server 6.0.2.19
ibm websphere_application_server 6.0.2.7
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.0.0.2
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 6.0.2.39
ibm websphere_application_server 6.0.2.33
ibm websphere_application_server 6.0.1.2
ibm websphere_application_server 6.0.1.17
ibm websphere_application_server 6.0.2.18
ibm websphere_application_server 6.0.2.25
ibm websphere_application_server 6.0.1.13
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 6.0.2.12
ibm websphere_application_server 6.0.2.16
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 6.0.2.31
ibm websphere_application_server 6.0.2.9
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.0.2.35
ibm websphere_application_server 6.0.2.22
ibm websphere_application_server 6.0.2.10
ibm websphere_application_server 6.0
ibm websphere_application_server 6.0.1.3
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.0.2.21
ibm websphere_application_server 6.0.2.2
ibm websphere_application_server 6.0.2.20
ibm websphere_application_server 6.0.2.13
ibm websphere_application_server 6.0.1.11
ibm websphere_application_server 6.0.2.11
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 6.0.2.8
ibm websphere_application_server 6.0.1.15
ibm websphere_application_server 6.0.2.14
ibm websphere_application_server 6.0.2.15
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 6.0.2.4
ibm websphere_application_server 6.1.0
ibm websphere_application_server 6.0.2.30
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 6.1
ibm websphere_application_server 6.0.2.32
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.0.2.23
ibm websphere_application_server 6.0.2.6
ibm websphere_application_server 6.0.1
ibm websphere_application_server 6.0.1.7
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.0.2.17
ibm websphere_application_server 6.0.2.37
ibm websphere_application_server 6.0.2.24
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 6.0.2.5
ibm websphere_application_server 6.0.2.3
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.0.2.29
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.0.1.9
ibm websphere_application_server 6.0.2
ibm websphere_application_server 6.0.2.28
ibm websphere_application_server 6.0.2.27
ibm websphere_application_server 6.0.0.3
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.0.1.1
ibm websphere_application_server 6.0.2.1
CVE-2010-0775 MEDIUM

Unspecified vulnerability in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.11 allows remote attackers to cause a denial of service (memory consumption and daemon crash) via a crafted request, related to the nodeagent and Deployment Manager components.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 6.0.1.5
ibm websphere_application_server 6.0.0.1
ibm websphere_application_server 7.0
ibm websphere_application_server 6.0.2.19
ibm websphere_application_server 6.0.2.7
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.0.0.2
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 6.0.2.39
ibm websphere_application_server 6.0.2.33
ibm websphere_application_server 6.0.1.2
ibm websphere_application_server 6.0.1.17
ibm websphere_application_server 6.0.2.18
ibm websphere_application_server 6.0.2.25
ibm websphere_application_server 6.0.1.13
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 6.0.2.12
ibm websphere_application_server 6.0.2.16
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 6.0.2.31
ibm websphere_application_server 6.0.2.9
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.0.2.35
ibm websphere_application_server 6.0.2.22
ibm websphere_application_server 6.0.2.10
ibm websphere_application_server 6.0
ibm websphere_application_server 6.0.1.3
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.0.2.21
ibm websphere_application_server 6.0.2.2
ibm websphere_application_server 6.0.2.20
ibm websphere_application_server 6.0.2.13
ibm websphere_application_server 6.0.1.11
ibm websphere_application_server 6.0.2.11
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 6.0.2.8
ibm websphere_application_server 6.0.1.15
ibm websphere_application_server 6.0.2.14
ibm websphere_application_server 6.0.2.15
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 6.0.2.4
ibm websphere_application_server 6.1.0
ibm websphere_application_server 6.0.2.30
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 6.1
ibm websphere_application_server 6.0.2.32
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.0.2.23
ibm websphere_application_server 6.0.2.6
ibm websphere_application_server 6.0.1
ibm websphere_application_server 6.0.1.7
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.0.2.17
ibm websphere_application_server 6.0.2.37
ibm websphere_application_server 6.0.2.24
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 6.0.2.5
ibm websphere_application_server 6.0.2.3
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.0.2.29
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.0.1.9
ibm websphere_application_server 6.0.2
ibm websphere_application_server 6.0.2.28
ibm websphere_application_server 6.0.2.27
ibm websphere_application_server 6.0.0.3
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.0.1.1
ibm websphere_application_server 6.0.2.1
CVE-2010-0776 MEDIUM

The Web Container in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.43, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.11 does not properly handle chunked transfer encoding during a call to response.sendRedirect, which allows remote attackers to cause a denial of service via a GET request.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 6.0.1.5
ibm websphere_application_server 6.0.0.1
ibm websphere_application_server 7.0
ibm websphere_application_server 6.0.2.19
ibm websphere_application_server 6.0.2.7
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.0.0.2
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 6.0.2.39
ibm websphere_application_server 6.0.2.33
ibm websphere_application_server 6.0.1.2
ibm websphere_application_server 6.0.1.17
ibm websphere_application_server 6.0.2.18
ibm websphere_application_server 6.0.2.25
ibm websphere_application_server 6.0.1.13
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 6.0.2.12
ibm websphere_application_server 6.0.2.16
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 6.0.2.31
ibm websphere_application_server 6.0.2.9
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.0.2.35
ibm websphere_application_server 6.0.2.22
ibm websphere_application_server 6.0.2.10
ibm websphere_application_server 6.0
ibm websphere_application_server 6.0.1.3
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.0.2.21
ibm websphere_application_server 6.0.2.2
ibm websphere_application_server 6.0.2.20
ibm websphere_application_server 6.0.2.13
ibm websphere_application_server 6.0.1.11
ibm websphere_application_server 6.0.2.11
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 6.0.2.8
ibm websphere_application_server 6.0.1.15
ibm websphere_application_server 6.0.2.14
ibm websphere_application_server 6.0.2.15
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 6.0.2.4
ibm websphere_application_server 6.1.0
ibm websphere_application_server 6.0.2.30
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 6.1
ibm websphere_application_server 6.0.2.32
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.0.2.23
ibm websphere_application_server 6.0.2.6
ibm websphere_application_server 6.0.1
ibm websphere_application_server 6.0.1.7
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.0.2.17
ibm websphere_application_server 6.0.2.37
ibm websphere_application_server 6.0.2.24
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 6.0.2.5
ibm websphere_application_server 6.0.2.3
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.0.2.29
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.0.1.9
ibm websphere_application_server 6.0.2
ibm websphere_application_server 6.0.2.28
ibm websphere_application_server 6.0.2.27
ibm websphere_application_server 6.0.0.3
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.0.1.1
ibm websphere_application_server 6.0.2.1
CVE-2010-0777 LOW

The Web Container in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.43, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.11 does not properly handle long filenames and consequently sends an incorrect file in some responses, which allows remote attackers to obtain sensitive information by reading the retrieved file.

CVSS 2.0

Severity: LOW

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 6.0.1.5
ibm websphere_application_server 6.0.0.1
ibm websphere_application_server 7.0
ibm websphere_application_server 6.0.2.19
ibm websphere_application_server 6.0.2.7
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.0.0.2
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 6.0.2.39
ibm websphere_application_server 6.0.2.33
ibm websphere_application_server 6.0.1.2
ibm websphere_application_server 6.0.1.17
ibm websphere_application_server 6.0.2.18
ibm websphere_application_server 6.0.2.25
ibm websphere_application_server 6.0.1.13
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 6.0.2.12
ibm websphere_application_server 6.0.2.16
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 6.0.2.31
ibm websphere_application_server 6.0.2.9
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.0.2.35
ibm websphere_application_server 6.0.2.22
ibm websphere_application_server 6.0.2.10
ibm websphere_application_server 6.0
ibm websphere_application_server 6.0.1.3
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.0.2.21
ibm websphere_application_server 6.0.2.2
ibm websphere_application_server 6.0.2.20
ibm websphere_application_server 6.0.2.13
ibm websphere_application_server 6.0.1.11
ibm websphere_application_server 6.0.2.11
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 6.0.2.8
ibm websphere_application_server 6.0.1.15
ibm websphere_application_server 6.0.2.14
ibm websphere_application_server 6.0.2.15
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 6.0.2.4
ibm websphere_application_server 6.1.0
ibm websphere_application_server 6.0.2.30
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 6.1
ibm websphere_application_server 6.0.2.32
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.0.2.23
ibm websphere_application_server 6.0.2.6
ibm websphere_application_server 6.0.1
ibm websphere_application_server 6.0.1.7
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.0.2.17
ibm websphere_application_server 6.0.2.37
ibm websphere_application_server 6.0.2.24
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 6.0.2.5
ibm websphere_application_server 6.0.2.3
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.0.2.29
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.0.1.9
ibm websphere_application_server 6.0.2
ibm websphere_application_server 6.0.2.28
ibm websphere_application_server 6.0.2.27
ibm websphere_application_server 6.0.0.3
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.0.1.1
ibm websphere_application_server 6.0.2.1
CVE-2010-0778 MEDIUM

Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.33 and 7.0 before 7.0.0.11 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 6.1.0
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 6.1
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.19
CVE-2010-0779 MEDIUM

Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.43, 6.1 before 6.1.0.33, and 7.0 before 7.0.0.11 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 6.0.0.1
ibm websphere_application_server 7.0
ibm websphere_application_server 6.0.2.19
ibm websphere_application_server 6.0.2.7
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.0.0.2
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 6.0.2.39
ibm websphere_application_server 6.0.2.33
ibm websphere_application_server 6.0.1.2
ibm websphere_application_server 6.0.2.25
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 6.0.2.31
ibm websphere_application_server 6.0.2.9
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.0.2.35
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 6.0.2.41
ibm websphere_application_server 6.0
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.0.2.21
ibm websphere_application_server 6.0.2.13
ibm websphere_application_server 6.0.2.11
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 6.0.2.15
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 6.1.0
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 6.1
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.0.2.23
ibm websphere_application_server 6.0.1
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.0.2.17
ibm websphere_application_server 6.0.2.37
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 6.0.2.5
ibm websphere_application_server 6.0.2.3
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.0.2.29
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.0.2
ibm websphere_application_server 6.0.2.27
ibm websphere_application_server 6.0.0.3
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.0.2.1
CVE-2010-0780 MEDIUM

IBM WebSphere MQ 7.x before 7.0.1.4 allows remote attackers to cause a denial of service (disk consumption) via multiple connection attempts to a stopped queue manager.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm websphere_mq 7.0.1.2
ibm websphere_mq 7.0.1.0
ibm websphere_mq 7.0.0.2
ibm websphere_mq 7.0.0.1
ibm websphere_mq 7.0.1.1
ibm websphere_mq 7.0
ibm websphere_mq 7.0.1.3
CVE-2010-0781 MEDIUM

Unspecified vulnerability in the administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.33 allows remote authenticated users to cause a denial of service (CPU consumption) via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 6.1.0
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.1.0.11
CVE-2010-0782 MEDIUM

IBM WebSphere MQ 6.x before 6.0.2.10 and 7.x before 7.0.1.3 allows remote attackers to spoof X.509 certificate authentication, and send or receive channel messages, via a crafted Subject Distinguished Name (DN) value in a certificate.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_mq 6.0.2.0
ibm websphere_mq 6.0.2.7
ibm websphere_mq 6.0.2.3
ibm websphere_mq 7.0.1.0
ibm websphere_mq 6.0.2.8
ibm websphere_mq 7.0.0.2
ibm websphere_mq 6.0.2.9
ibm websphere_mq 7.0.1.1
ibm websphere_mq 7.0
ibm websphere_mq 6.0
ibm websphere_mq 7.0.1.2
ibm websphere_mq 6.0.1.0
ibm websphere_mq 6.0.1.1
ibm websphere_mq 6.0.2.6
ibm websphere_mq 7.0.0.1
ibm websphere_mq 6.0.2.4
ibm websphere_mq 6.0.2.5
ibm websphere_mq 6.0.2.1
ibm websphere_mq 6.0.2.2
CVE-2010-0783 MEDIUM

Cross-site scripting (XSS) vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.35 and 7.0 before 7.0.0.13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 6.1.0.14
ibm websphere_application_server 7.0.0.12
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.1.0.20
ibm websphere_application_server 6.1.0.24
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 6.1.0.22
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0
ibm websphere_application_server 6.1.0.4
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 6.1
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.26
ibm websphere_application_server 7.0.0.10
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.1.0.32
ibm websphere_application_server 6.1.0.10
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.16
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.8
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.1.0.18
ibm websphere_application_server 6.1.0.6
ibm websphere_application_server 7.0.0.4
CVE-2010-0784 MEDIUM

Cross-site scripting (XSS) vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.12
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 7.0.0.10
ibm websphere_application_server 7.0.0.4
CVE-2010-0785 MEDIUM

Cross-site request forgery (CSRF) vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.35 and 7.0 before 7.0.0.13 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 6.1
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 7.0.0.4
CVE-2010-0786 MEDIUM

The Web Services Security component in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.13 does not properly implement the Java API for XML Web Services (aka JAX-WS), which allows remote attackers to cause a denial of service (data corruption) via a crafted JAX-WS request that leads to incorrectly encoded data.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.12
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 7.0.0.10
ibm websphere_application_server 7.0.0.4
CVE-2010-0918 HIGH

Multiple unspecified vulnerabilities in the UltraLite functionality in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.281 for Domino 8.0.2 FP4 have unknown impact and attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm lotus_inotes 229.031
ibm lotus_inotes 229.111
ibm lotus_inotes 229.261
ibm lotus_inotes 229.101
ibm lotus_inotes 229.171
ibm lotus_inotes 229.201
ibm lotus_inotes 229.191
ibm lotus_inotes 229.221
ibm lotus_inotes 229.131
ibm lotus_inotes 229.141
ibm lotus_inotes 229.241
ibm lotus_inotes *
ibm lotus_inotes 229.051
ibm lotus_inotes 229.041
ibm lotus_inotes 229.231
ibm lotus_inotes 229.151
ibm lotus_inotes 229.061
ibm lotus_inotes 229.181
ibm lotus_inotes 229.211
ibm lotus_inotes 229.161
ibm lotus_inotes 229.011
ibm lotus_inotes 229.021
ibm lotus_inotes 229.251
CVE-2010-0919 HIGH

Stack-based buffer overflow in the Lotus Domino Web Access ActiveX control in IBM Lotus iNotes (aka Domino Web Access or DWA) 6.5, 7.0 before 7.0.4, 8.0, 8.0.2, and before 229.281 for Domino 8.0.2 FP4 allows remote attackers to execute arbitrary code via a long URL argument to an unspecified method, aka PRAD7JTNHJ.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm lotus_inotes 229.101
ibm lotus_inotes 229.201
ibm domino_web_access 7.0
ibm lotus_inotes 229.191
ibm lotus_inotes 229.131
ibm domino_web_access 7.0.2
ibm domino_web_access 7.0.1
ibm lotus_inotes *
ibm lotus_inotes 229.051
ibm lotus_inotes 229.231
ibm lotus_inotes 229.151
ibm lotus_inotes 229.061
ibm domino_web_access 6.5
ibm lotus_inotes 229.211
ibm lotus_inotes 229.161
ibm domino_web_access 8.0
ibm lotus_inotes 229.011
ibm lotus_inotes 229.031
ibm lotus_inotes 229.111
ibm lotus_inotes 229.261
ibm lotus_inotes 229.171
ibm lotus_inotes 229.221
ibm lotus_inotes 229.141
ibm lotus_inotes 229.241
ibm lotus_inotes 229.041
ibm domino_web_access 8.0.2
ibm lotus_inotes 229.181
ibm lotus_inotes 229.021
ibm domino_web_access 7.0.3
ibm lotus_inotes 229.251
CVE-2010-0920 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.281 for Domino 8.0.2 FP4 allows remote attackers to inject arbitrary web script or HTML via vectors related to lack of "XSS/CSRF Get Filter and Referer Check fixes."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm lotus_inotes 229.031
ibm lotus_inotes 229.111
ibm lotus_inotes 229.261
ibm lotus_inotes 229.101
ibm lotus_inotes 229.171
ibm lotus_inotes 229.201
ibm lotus_inotes 229.191
ibm lotus_inotes 229.221
ibm lotus_inotes 229.131
ibm lotus_inotes 229.141
ibm lotus_inotes 229.241
ibm lotus_inotes *
ibm lotus_inotes 229.051
ibm lotus_inotes 229.041
ibm lotus_inotes 229.231
ibm lotus_inotes 229.151
ibm lotus_inotes 229.061
ibm lotus_inotes 229.181
ibm lotus_inotes 229.211
ibm lotus_inotes 229.161
ibm lotus_inotes 229.011
ibm lotus_inotes 229.021
ibm lotus_inotes 229.251
CVE-2010-0921 MEDIUM

Cross-site request forgery (CSRF) vulnerability in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.281 for Domino 8.0.2 FP4 allows remote attackers to hijack the authentication of unspecified victims via vectors related to lack of "XSS/CSRF Get Filter and Referer Check fixes."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm lotus_inotes 229.031
ibm lotus_inotes 229.111
ibm lotus_inotes 229.261
ibm lotus_inotes 229.101
ibm lotus_inotes 229.171
ibm lotus_inotes 229.201
ibm lotus_inotes 229.191
ibm lotus_inotes 229.221
ibm lotus_inotes 229.131
ibm lotus_inotes 229.141
ibm lotus_inotes 229.241
ibm lotus_inotes *
ibm lotus_inotes 229.051
ibm lotus_inotes 229.041
ibm lotus_inotes 229.231
ibm lotus_inotes 229.151
ibm lotus_inotes 229.061
ibm lotus_inotes 229.181
ibm lotus_inotes 229.211
ibm lotus_inotes 229.161
ibm lotus_inotes 229.011
ibm lotus_inotes 229.021
ibm lotus_inotes 229.251
CVE-2010-0922 HIGH

Unspecified vulnerability in secldapclntd in IBM AIX 5.3 with SP 5300-11-02 allows attackers to cause a denial of service (LDAP login failure) via unknown vectors. NOTE: some of these details are obtained from third party information. NOTE: there may be no attacker role, and the issue may be triggered entirely by an administrator's installation of an official service pack.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm aix 5.3
CVE-2010-0927 MEDIUM

Cross-site scripting (XSS) vulnerability in help/readme.nsf/Header in the Help component in IBM Lotus Domino 7.x before 7.0.4 and 8.x before 8.0.2 allows remote attackers to inject arbitrary web script or HTML via the BaseTarget parameter in an OpenPage action. NOTE: this may overlap CVE-2010-0920.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm lotus_domino 7.0.1.1
ibm lotus_domino 7.0.2
ibm lotus_domino 7.0.2.3
ibm lotus_domino 7.0
ibm lotus_domino 7.0.2.2
ibm lotus_domino 8.0.1
ibm lotus_domino 8.0
ibm lotus_domino 7.0.2.1
ibm lotus_domino 7.0.3.1
ibm lotus_domino 7.0.1
ibm lotus_domino 7.0.3
CVE-2010-0959 MEDIUM

Cross-site scripting (XSS) vulnerability in WebEditor/Authentication/LoginPage.aspx in IBM ENOVIA SmarTeam 5 allows remote attackers to inject arbitrary web script or HTML via the errMsg parameter.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm enovia_smarteam 5
CVE-2010-0960 HIGH

Buffer overflow in qosmod in bos.net.tcp.server in IBM AIX 6.1 and VIOS 2.1 allows local users to gain privileges via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm aix 6.1
ibm aix 6.1.0
ibm vios 2.1
CVE-2010-0961 HIGH

Buffer overflow in qoslist in bos.net.tcp.server in IBM AIX 6.1 and VIOS 2.1 allows local users to gain privileges via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm aix 6.1
ibm aix 6.1.0
ibm vios 2.1
CVE-2010-1039 HIGH

Format string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; IBM VIOS 2.1, 1.5, and earlier; NFS/ONCplus B.11.31_09 and earlier on HP HP-UX B.11.11, B.11.23, and B.11.31; and SGI IRIX 6.5 allows remote attackers to execute arbitrary code via an RPC request containing format string specifiers in an invalid directory name.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-134,

Products Affected

Vendor Product Version
ibm aix 4.1.5
ibm aix *
ibm aix 4.3.3
ibm aix 430
ibm aix 4.1
ibm aix 2.2.1
ibm vios *
ibm aix 3.2.5
ibm aix 5.2_l
hp nfs/oncplus *
ibm aix 3.2.0
ibm vios 2.1
ibm aix 5.2.0.54
ibm aix 5.2.2
ibm aix 4.1.4
ibm aix 4.3.0
ibm aix 4.1.1
ibm aix 3.2.4
sgi irix 6.5
ibm aix 4.2.0
ibm aix 5.1l
ibm aix 3.1
ibm aix 5.1
ibm aix 5.1.0.10
ibm aix 4
ibm aix 6.1
ibm aix 4.2.1.12
ibm aix 4.2.1
ibm aix 5.2
ibm aix 1.2.1
ibm aix 5.2.0
ibm aix 4.3.1
ibm aix 1.3
ibm aix 4.3.2
ibm aix 4.0
ibm aix 4.1.3
ibm vios 1.4
ibm aix 4.3
ibm aix 4.1.2
ibm aix 3.2
ibm aix 4.2
ibm aix 5.2.0.50
CVE-2010-1041 HIGH

Unspecified vulnerability in the single sign-on functionality in the Web Services implementation in IBM DB2 Content Manager (CM) Toolkit 8.3 before FP13 on z/OS and DB2 Information Integrator for Content 8.3 before FP13 has unknown impact and remote attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm db2_content_manager *
ibm db2_content_manager 8.3
CVE-2010-1124 HIGH

bos.rte.libc 5.3.9.4 on IBM AIX 5.3 does not properly support reading a certain address field after a successful getaddrinfo function call, which allows context-dependent attackers to cause a denial of service (application crash) via unspecified vectors, as demonstrated by IBM DB2 crashes on "systems with databases cataloged with alternate servers using IP addresses."

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm aix 5.3.0
ibm aix 5.3
CVE-2010-1182 HIGH

Multiple unspecified vulnerabilities in the administrative console in IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.9 on z/OS have unknown impact and attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 7.0.0.4
CVE-2010-1242 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in the IBM Web Interface for Content Management (aka WEBi) before 1.0.4 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm webi 1.0.2
ibm webi *
CVE-2010-1243 HIGH

The IBM Web Interface for Content Management (aka WEBi) before 1.0.4 creates persistent cookies on client workstations, which has unspecified impact and attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm webi 1.0.2
ibm webi *
CVE-2010-1347 HIGH

Director Agent 6.1 before 6.1.2.3 in IBM Systems Director on AIX and Linux uses incorrect permissions for the (1) diruninstall and (2) opt/ibm/director/bin/wcitinst scripts, which allows local users to gain privileges by executing these scripts.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm director_agent 6.1
ibm director_agent 6.1.2
CVE-2010-1348 HIGH

Unspecified vulnerability in the login process in IBM WebSphere Portal 6.0.1.1, and 6.1.0.x before 6.1.0.3 Cumulative Fix 03, has unknown impact and remote attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_portal 6.0.1.1
ibm websphere_portal 6.1.0.2
ibm websphere_portal 6.1.0.1
ibm websphere_portal 6.1.0.0
CVE-2010-1460 MEDIUM

The IBM BladeCenter with Advanced Management Module (AMM) firmware before bpet50g does not properly perform interrupt sharing for USB and iSCSI, which allows remote attackers to cause a denial of service (management module reboot) via TCP packets with malformed application data.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm advanced_management_module 1.01
ibm advanced_management_module 1.25
ibm advanced_management_module 1.32
ibm advanced_management_module 1.42
ibm advanced_management_module 1.00
ibm advanced_management_module 1.36
ibm advanced_management_module *
ibm advanced_management_module 2.48
ibm advanced_management_module 1.28
ibm advanced_management_module 1.34
ibm advanced_management_module 1.20
ibm advanced_management_module 1.26
ibm advanced_management_module 2.46
CVE-2010-1487 LOW

IBM Lotus Notes 7.0, 8.0, and 8.5 stores administrative credentials in cleartext in SURunAs.exe, which allows local users to obtain sensitive information by examining this file, aka SPR JSTN837SEG.

CVSS 2.0

Severity: LOW

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm lotus_notes 8.0
ibm lotus_notes 7.0
ibm lotus_notes 8.5
CVE-2010-1490 HIGH

Unspecified vulnerability in IBM Cognos 8 Business Intelligence before 8.4.1 FP1 has unknown impact and attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm cognos_8_business_intelligence *
CVE-2010-1560 MEDIUM

Buffer overflow in the REPEAT function in IBM DB2 9.1 before FP9 allows remote authenticated users to cause a denial of service (trap) via unspecified vectors. NOTE: this might overlap CVE-2010-0462.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm db2 9.1
ibm db2 *
CVE-2010-1608 HIGH

Stack-based buffer overflow in IBM Lotus Notes 8.5 and 8.5fp1, and possibly other versions, allows remote attackers to execute arbitrary code via unknown attack vectors, as demonstrated by the vd_ln module in VulnDisco 9.0. NOTE: as of 20100222, this disclosure has no actionable information. However, because the VulnDisco author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm lotus_notes 8.5.1.1
ibm lotus_notes 8.5.1
ibm lotus_notes 8.5
CVE-2010-1612 MEDIUM

The IBM WebSphere DataPower XML Accelerator XA35, Low Latency Appliance XM70, Integration Appliance XI50, B2B Appliance XB60, and XML Security Gateway XS40 SOA Appliances before 3.8.0.0, when a QLOGIC Ethernet interface is used, allow remote attackers to cause a denial of service (interface outage) via malformed ICMP packets to the 0.0.0.0 destination IP address.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_datapower_low_latency_appliance_xm70 3.7.3.3
ibm websphere_datapower_b2b_appliance_xb60 3.8.0.4
ibm websphere_datapower_xml_accelerator_xa35 3.7.3
ibm websphere_datapower_xml_security_gateway_xs40 3.7.2
ibm websphere_datapower_b2b_appliance_xb60 3.7.3.3
ibm websphere_datapower_b2b_appliance_xb60 3.7.3.7
ibm websphere_datapower_datapower_integration_appliance_xi50 3.8.03
ibm websphere_datapower_low_latency_appliance_xm70 3.7.3.7
ibm websphere_datapower_xml_accelerator_xa35 3.7.3.2
ibm websphere_datapower_xml_accelerator_xa35 3.7.2
ibm websphere_datapower_xml_security_gateway_xs40 3.8.0.2
ibm websphere_datapower_xml_accelerator_xa35 3.7.3.1
ibm websphere_datapower_datapower_integration_appliance_xi50 3.7.3.5
ibm websphere_datapower_low_latency_appliance_xm70 3.8.0.2
ibm websphere_datapower_b2b_appliance_xb60 3.7.3.4
ibm websphere_datapower_low_latency_appliance_xm70 *
ibm websphere_datapower_datapower_integration_appliance_xi50 3.7.3
ibm websphere_datapower_xml_accelerator_xa35 3.8.0.1
ibm websphere_datapower_xml_security_gateway_xs40 3.7.3.1
ibm websphere_datapower_low_latency_appliance_xm70 3.7.3.1
ibm websphere_datapower_xml_accelerator_xa35 3.7.3.6
ibm websphere_datapower_xml_security_gateway_xs40 3.8.0.1
ibm websphere_datapower_datapower_integration_appliance_xi50 3.8.0.2
ibm websphere_datapower_b2b_appliance_xb60 3.8.0.1
ibm websphere_datapower_datapower_integration_appliance_xi50 3.7.3.4
ibm websphere_datapower_datapower_integration_appliance_xi50 3.7.3.1
ibm websphere_datapower_xml_accelerator_xa35 3.7.3.7
ibm websphere_datapower_b2b_appliance_xb60 3.8.0.0
ibm websphere_datapower_xml_security_gateway_xs40 3.8.0.0
ibm websphere_datapower_xml_accelerator_xa35 3.8.0.0
ibm websphere_datapower_xml_accelerator_xa35 3.8.0.3
ibm websphere_datapower_b2b_appliance_xb60 3.7.3.9
ibm websphere_datapower_xml_security_gateway_xs40 3.7.3.5
ibm websphere_datapower_b2b_appliance_xb60 3.7.3.8
ibm websphere_datapower_low_latency_appliance_xm70 3.7.3.2
ibm websphere_datapower_xml_security_gateway_xs40 3.8.0.3
ibm websphere_datapower_datapower_integration_appliance_xi50 3.7.3.2
ibm websphere_datapower_b2b_appliance_xb60 *
ibm websphere_datapower_xml_security_gateway_xs40 3.7.3.4
ibm websphere_datapower_low_latency_appliance_xm70 3.7.3.4
ibm websphere_datapower_b2b_appliance_xb60 3.8.0.2
ibm websphere_datapower_xml_accelerator_xa35 3.7.3.4
ibm websphere_datapower_xml_accelerator_xa35 3.8.0.4
ibm websphere_datapower_datapower_integration_appliance_xi50 *
ibm websphere_datapower_xml_security_gateway_xs40 3.7.3.2
ibm websphere_datapower_datapower_integration_appliance_xi50 3.7.3.6
ibm websphere_datapower_low_latency_appliance_xm70 3.7.3.9
ibm websphere_datapower_xml_security_gateway_xs40 3.7.3.3
ibm websphere_datapower_low_latency_appliance_xm70 3.8.0.3
ibm websphere_datapower_datapower_integration_appliance_xi50 3.7.2
ibm websphere_datapower_xml_security_gateway_xs40 3.7.3
ibm websphere_datapower_xml_security_gateway_xs40 3.7.3.9
ibm websphere_datapower_xml_accelerator_xa35 3.7.3.8
ibm websphere_datapower_datapower_integration_appliance_xi50 3.7.3.3
ibm websphere_datapower_datapower_integration_appliance_xi50 3.8.0.1
ibm websphere_datapower_b2b_appliance_xb60 3.7.3.6
ibm websphere_datapower_low_latency_appliance_xm70 3.8.0.0
ibm websphere_datapower_b2b_appliance_xb60 3.7.3.1
ibm websphere_datapower_xml_accelerator_xa35 3.8.0.2
ibm websphere_datapower_xml_security_gateway_xs40 3.7.3.8
ibm websphere_datapower_b2b_appliance_xb60 3.7.3.5
ibm websphere_datapower_b2b_appliance_xb60 3.7.3.2
ibm websphere_datapower_datapower_integration_appliance_xi50 3.7.3.9
ibm websphere_datapower_datapower_integration_appliance_xi50 3.8.0.4
ibm websphere_datapower_low_latency_appliance_xm70 3.8.0.4
ibm websphere_datapower_xml_security_gateway_xs40 3.7.3.6
ibm websphere_datapower_xml_security_gateway_xs40 3.8.0.4
ibm websphere_datapower_datapower_integration_appliance_xi50 3.7.3.8
ibm websphere_datapower_xml_security_gateway_xs40 *
ibm websphere_datapower_xml_security_gateway_xs40 3.7.3.7
ibm websphere_datapower_low_latency_appliance_xm70 3.7.3.6
ibm websphere_datapower_xml_accelerator_xa35 3.7.3.5
ibm websphere_datapower_xml_accelerator_xa35 *
ibm websphere_datapower_b2b_appliance_xb60 3.8.0.3
ibm websphere_datapower_low_latency_appliance_xm70 3.7.3.8
ibm websphere_datapower_xml_accelerator_xa35 3.7.3.3
ibm websphere_datapower_xml_accelerator_xa35 3.7.3.9
ibm websphere_datapower_low_latency_appliance_xm70 3.7.3.5
ibm websphere_datapower_datapower_integration_appliance_xi50 3.8.0.0
ibm websphere_datapower_low_latency_appliance_xm70 3.8.0.1
ibm websphere_datapower_datapower_integration_appliance_xi50 3.7.3.7
CVE-2010-1650 LOW

IBM WebSphere Application Server (WAS) 6.0.x before 6.0.2.41, 6.1.x before 6.1.0.31, and 7.0.x before 7.0.0.11, when the -trace option (aka debugging mode) is enabled, executes debugging statements that print string representations of unspecified objects, which allows attackers to obtain sensitive information by reading the trace output.

CVSS 2.0

Severity: LOW

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 6.0.1.5
ibm websphere_application_server 6.0.0.1
ibm websphere_application_server 7.0
ibm websphere_application_server 6.0.2.19
ibm websphere_application_server 6.1.0.14
ibm websphere_application_server 6.0.2.7
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.0.0.2
ibm websphere_application_server 6.1.0.20
ibm websphere_application_server 6.1.0.24
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 6.1.6
ibm websphere_application_server 6.0.2.39
ibm websphere_application_server 6.0.2.33
ibm websphere_application_server 6.0.1.2
ibm websphere_application_server 6.1.3
ibm websphere_application_server 6.1.0.10
ibm websphere_application_server 6.0.1.17
ibm websphere_application_server 6.0.2.18
ibm websphere_application_server 6.0.2.25
ibm websphere_application_server 6.0.1.13
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 6.0.2.12
ibm websphere_application_server 6.0.2.16
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 6.0.2.31
ibm websphere_application_server 6.0.2.9
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.7
ibm websphere_application_server 6.0.2.35
ibm websphere_application_server 6.0.2.22
ibm websphere_application_server 6.0.2.10
ibm websphere_application_server 6.0
ibm websphere_application_server 6.0.1.3
ibm websphere_application_server 6.1.1
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.18
ibm websphere_application_server 6.0.2.21
ibm websphere_application_server 6.1.0.6
ibm websphere_application_server 6.0.2.2
ibm websphere_application_server 6.0.2.20
ibm websphere_application_server 6.0.2.13
ibm websphere_application_server 6.0.1.11
ibm websphere_application_server 6.0.2.11
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 6.0.2.8
ibm websphere_application_server 6.0.1.15
ibm websphere_application_server 6.0.2.14
ibm websphere_application_server 6.0.2.15
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 6.1.0.22
ibm websphere_application_server 6.0.2.4
ibm websphere_application_server 6.1.0
ibm websphere_application_server 6.1.0.4
ibm websphere_application_server 6.0.2.30
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 6.1
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.26
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.0.2.23
ibm websphere_application_server 6.0.2.6
ibm websphere_application_server 6.0.1
ibm websphere_application_server 6.0.1.7
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.0.2.17
ibm websphere_application_server 6.1.5
ibm websphere_application_server 6.1.14
ibm websphere_application_server 6.0.2.37
ibm websphere_application_server 6.0.2.24
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 6.0.2.5
ibm websphere_application_server 6.0.2.3
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.16
ibm websphere_application_server 6.0.2.29
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.0.1.9
ibm websphere_application_server 6.0.2
ibm websphere_application_server 6.1.0.8
ibm websphere_application_server 6.0.2.28
ibm websphere_application_server 6.0.2.27
ibm websphere_application_server 6.0.0.3
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.0.1.1
ibm websphere_application_server 6.0.2.1
ibm websphere_application_server 6.1.13
CVE-2010-1651 LOW

IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.31 and 7.0.x before 7.0.0.11, when Basic authentication and SIP tracing (aka full trace logging for SIP) are enabled, logs the entirety of all inbound and outbound SIP messages, which allows local users to obtain sensitive information by reading the trace log.

CVSS 2.0

Severity: LOW

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 6.1.0.14
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.1.0.20
ibm websphere_application_server 6.1.0.24
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 6.1.0.22
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0
ibm websphere_application_server 6.1.0.4
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 6.1
ibm websphere_application_server 6.1.6
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.26
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.1.3
ibm websphere_application_server 6.1.0.10
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.1.5
ibm websphere_application_server 6.1.14
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.7
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.16
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.8
ibm websphere_application_server 6.1.1
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.1.0.18
ibm websphere_application_server 6.1.0.6
ibm websphere_application_server 6.1.13
CVE-2010-2090 MEDIUM

The npb_protocol_error function in sna V5router64 in IBM Communications Server for Windows 6.1.3 and Communications Server for AIX (aka CSAIX or CS/AIX) in sna.rte before 6.3.1.2 allows remote attackers to cause a denial of service (daemon crash) via APPC data containing a GDSID variable with a GDS length that is too small.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm communications_server 6.1.3
ibm communications_server 6.3.1.0
CVE-2010-2277 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Connections 2.5.x before 2.5.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) create or (2) edit form in the Communities component, the (3) verbiage field in the Bookmarks component, or (4) unspecified vectors related to the Mobile Blogs component.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm lotus_connections 2.5.0
ibm lotus_connections 2.5.0.1
CVE-2010-2278 MEDIUM

The bookmarklet pop-up in the Bookmarks component in IBM Lotus Connections 2.5.x before 2.5.0.2 does not properly follow the "force SSL" setting, which might make it easier for remote attackers to obtain the cleartext of network communication by sniffing the network, or spoof arbitrary servers via a man-in-the-middle attack.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_connections 2.5.0
ibm lotus_connections 2.5.0.1
CVE-2010-2279 HIGH

The Top Updates implementation in the Homepage component in IBM Lotus Connections 2.5.x before 2.5.0.2, when "forced SSL" is enabled, uses http for links, which has unspecified impact and remote attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_connections 2.5.0
ibm lotus_connections 2.5.0.1
CVE-2010-2280 MEDIUM

Open redirect vulnerability in the Mobile component in IBM Lotus Connections 2.5.x before 2.5.0.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, related to "mobile edit actions," aka SPR ASRE83PPVH.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_connections 2.5.0
ibm lotus_connections 2.5.0.1
CVE-2010-2323 MEDIUM

IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11 on z/OS might allow attackers to obtain sensitive information by reading the default_create.log file that is associated with profile creation by the BBOWWPFx job and the zPMT.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 7.0
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server *
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 7.0.0.4
CVE-2010-2324 HIGH

IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11 on z/OS allows attackers to perform unspecified "link injection" actions via unknown vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 7.0
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server *
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 7.0.0.4
CVE-2010-2325 MEDIUM

Cross-site scripting (XSS) vulnerability in the administrative console in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11 on z/OS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related in part to "URL injection."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 7.0
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server *
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 7.0.0.4
CVE-2010-2326 MEDIUM

IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11, when addNode -trace is used during node federation, allows attackers to obtain sensitive information about CIMMetadataCollectorImpl trace actions by reading the addNode.log file.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 7.0
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 7.0.0.1
CVE-2010-2327 MEDIUM

mod_ibm_ssl in IBM HTTP Server 6.0 before 6.0.2.43, 6.1 before 6.1.0.33, and 7.0 before 7.0.0.11, as used in IBM WebSphere Application Server (WAS) on z/OS, does not properly handle a large HTTP request body in uploading over SSL, which might allow remote attackers to cause a denial of service (daemon fail) via an upload.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 6.0.0.1
ibm websphere_application_server 7.0
ibm websphere_application_server 6.0.2.19
ibm websphere_application_server 6.0.2.7
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.0.0.2
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 6.0.2.39
ibm websphere_application_server 6.0.2.33
ibm websphere_application_server 6.0.1.2
ibm websphere_application_server 6.0.2.25
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 6.0.2.31
ibm websphere_application_server 6.0.2.9
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.0.2.35
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 6.0.2.41
ibm websphere_application_server 6.0
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.0.2.21
ibm websphere_application_server 6.0.2.13
ibm websphere_application_server 6.0.2.11
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 6.0.2.15
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 6.1.0
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 6.1
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.0.2.23
ibm websphere_application_server 6.0.1
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.0.2.17
ibm websphere_application_server 6.0.2.37
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 6.0.2.5
ibm websphere_application_server 6.0.2.3
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.0.2.29
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.0.2
ibm websphere_application_server 6.0.2.27
ibm websphere_application_server 6.0.0.3
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.0.2.1
CVE-2010-2328 MEDIUM

The HTTP Channel in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11 allows remote attackers to cause a denial of service (NullPointerException) via a large amount of chunked data that uses gzip compression.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 7.0
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 7.0.0.1
CVE-2010-2433 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in content/internalError.jsp in IBM WebSphere ILOG JRules 6.7 allow remote attackers to inject arbitrary web script or HTML via an RTS URL to (1) explore/explore.jsp, (2) compose/compose.jsp, or (3) home.jsp in faces/.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_ilog_jrules 6.7
CVE-2010-2517 HIGH

Multiple unspecified vulnerabilities in IBM Rational ClearQuest before 7.1.1.02 have unknown impact and attack vectors, as demonstrated by an AppScan report.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm rational_clearquest 5.20
ibm rational_clearquest 6.10
ibm rational_clearquest 7.0.0.4
ibm rational_clearquest 7.0.0.5
ibm rational_clearquest 7.0.1.6
ibm rational_clearquest 7.0.0.0
ibm rational_clearquest 6.16
ibm rational_clearquest 7.0.1.4
ibm rational_clearquest 6.12
ibm rational_clearquest 7.0.1.1
ibm rational_clearquest 5.00
ibm rational_clearquest 7.0.1
ibm rational_clearquest 7.0.1.8
ibm rational_clearquest 7.0.0.2
ibm rational_clearquest 7.0.0.7
ibm rational_clearquest 2007
ibm rational_clearquest *
ibm rational_clearquest 7.0.1.7
ibm rational_clearquest 6.00
ibm rational_clearquest 7.0.1.9
ibm rational_clearquest 7.0
ibm rational_clearquest 6.14
ibm rational_clearquest 6.15
ibm rational_clearquest 7.0.0.6
ibm rational_clearquest 7.0.0.9
ibm rational_clearquest 7.0.0.1
ibm rational_clearquest 7.0.0.8
ibm rational_clearquest 2008
ibm rational_clearquest 7.0.1.3
ibm rational_clearquest 7.0.1.2
ibm rational_clearquest 7.0.1.0
ibm rational_clearquest 7.0.1.5
ibm rational_clearquest 7.0.0.3
ibm rational_clearquest 7.0.2
ibm rational_clearquest 6.13
CVE-2010-2518 HIGH

Unspecified vulnerability in the P8 Content Engine (P8CE) 4.5.1 before FP3 and the P8 Content Search Engine (P8CSE) before 4.5.0 FP3 and 4.5.1 before FP1, as used in IBM FileNet P8 Content Manager (CM) and FileNet P8 Business Process Manager (BPM), allows remote attackers to gain privileges via unknown vectors. NOTE: some of these details are obtained from third party information.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm p8_content_engine 4.5.1
ibm p8_content_search_engine 4.5.0
ibm p8_content_engine 4.5.1.1
ibm p8_content_search_engine 4.5.1
ibm p8_content_engine 4.5.1.2
ibm p8_content_search_engine 4.5.0.2
ibm p8_content_search_engine 4.5.0.1
CVE-2010-2635 MEDIUM

SQL injection vulnerability in IBM WebSphere Commerce 6.0 before 6.0.0.10 allows remote authenticated users to execute arbitrary SQL commands via unspecified parameters to "Commerce Organization Admin Console JavaServer pages."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm websphere_commerce 6.0.0.6
ibm websphere_commerce 6.0.0.3
ibm websphere_commerce 6.0.0.1
ibm websphere_commerce 6.0.0.2
ibm websphere_commerce 6.0.0.4
ibm websphere_commerce 6.0.0.9
ibm websphere_commerce 6.0.0.7
ibm websphere_commerce 6.0.0.8
ibm websphere_commerce 6.0.0.5
CVE-2010-2636 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in sample store pages in IBM WebSphere Commerce 7.0 before 7.0.0.1 allow remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_commerce 7.0
CVE-2010-2637 MEDIUM

IBM WebSphere MQ 6.0 before 6.0.2.9 and 7.0 before 7.0.1.1 does not encrypt the username and password in the security parameters field, which allows remote attackers to obtain sensitive information by sniffing the network traffic from a .NET client application.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm websphere_mq 6.0.2.0
ibm websphere_mq 6.0.2.7
ibm websphere_mq 6.0.0.0
ibm websphere_mq 6.0.2.3
ibm websphere_mq 7.0.1.0
ibm websphere_mq 6.0.2.8
ibm websphere_mq 7.0.0.2
ibm websphere_mq 7.0
ibm websphere_mq 6.0
ibm websphere_mq 6.0.1.0
ibm websphere_mq 6.0.1.1
ibm websphere_mq 6.0.2.6
ibm websphere_mq 6.0.2.10
ibm websphere_mq 7.0.0.1
ibm websphere_mq 6.0.2.4
ibm websphere_mq 6.0.2.5
ibm websphere_mq 6.0.2.1
ibm websphere_mq 6.0.2.2
CVE-2010-2638 MEDIUM

Unspecified vulnerability in IBM WebSphere MQ 7.0 before 7.0.1.5 allows remote authenticated users to cause a denial of service (disk consumption) via vectors that trigger an FDC with an RM680004 Probe Id value.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm websphere_mq 7.0.1.2
ibm websphere_mq 7.0.1.0
ibm websphere_mq 7.0.0.2
ibm websphere_mq 7.0.0.1
ibm websphere_mq 7.0.1.1
ibm websphere_mq 7.0
ibm websphere_mq 7.0.1.3
ibm websphere_mq 7.0.1.4
CVE-2010-2639 MEDIUM

IBM WebSphere Commerce Enterprise 7.0 before 7.0.0.2 allows remote attackers to read messages intended for other recipients via vectors involving access by the outbound messaging system to the RunTimeProfileCacheCmdImpl class, related to the caching of mutable objects and "concurrency issues."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_commerce 7.0
ibm websphere_commerce 7.0.0.1
CVE-2010-2644 MEDIUM

IBM WebSphere Service Registry and Repository (WSRR) 7.0.0 before FP1 does not properly implement access control, which allows remote attackers to perform governance actions via unspecified API requests to an EJB interface.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_service_registry_and_repository 7.0.0
CVE-2010-2654 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities on the IBM BladeCenter with Advanced Management Module (AMM) firmware build ID BPET48L, and possibly other versions before 4.7 and 5.0, allow remote attackers to inject arbitrary web script or HTML via the (1) INDEX or (2) IPADDR parameter to private/cindefn.php, (3) the domain parameter to private/power_management_policy_options.php, the slot parameter to (4) private/pm_temp.php or (5) private/power_module.php, (6) the WEBINDEX parameter to private/blade_leds.php, or (7) the SLOT parameter to private/ipmi_bladestatus.php.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm advanced_management_module 1.01
ibm advanced_management_module 1.25
ibm advanced_management_module 1.32
ibm advanced_management_module 1.42
ibm advanced_management_module 1.00
ibm advanced_management_module 1.36
ibm advanced_management_module *
ibm advanced_management_module 2.50
ibm advanced_management_module 2.48
ibm advanced_management_module 1.28
ibm advanced_management_module 3.54
ibm advanced_management_module 1.34
ibm advanced_management_module 1.20
ibm advanced_management_module 1.26
ibm advanced_management_module 2.46
CVE-2010-2655 MEDIUM

Directory traversal vulnerability in private/file_management.php on the IBM BladeCenter with Advanced Management Module (AMM) firmware build ID BPET48L, and possibly other versions before 4.7 and 5.0, allows remote authenticated users to list arbitrary directories and possibly have unspecified other impact via a .. (dot dot) in the DIR parameter.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm advanced_management_module 1.01
ibm advanced_management_module 1.25
ibm advanced_management_module 1.32
ibm advanced_management_module 1.42
ibm advanced_management_module 1.00
ibm advanced_management_module 1.36
ibm advanced_management_module *
ibm advanced_management_module 2.50
ibm advanced_management_module 2.48
ibm advanced_management_module 1.28
ibm advanced_management_module 1.34
ibm advanced_management_module 1.20
ibm advanced_management_module 1.26
ibm advanced_management_module 2.46
CVE-2010-2656 MEDIUM

The IBM BladeCenter with Advanced Management Module (AMM) firmware build ID BPET48L, and possibly other versions before 4.7 and 5.0, stores sensitive information under the web root with insufficient access control, which allows remote attackers to download (1) logs or (2) core files via direct requests, as demonstrated by a request for private/sdc.tgz.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm advanced_management_module 1.01
ibm advanced_management_module 1.25
ibm advanced_management_module 1.32
ibm advanced_management_module 1.42
ibm advanced_management_module 1.00
ibm advanced_management_module 1.36
ibm advanced_management_module *
ibm advanced_management_module 2.50
ibm advanced_management_module 2.48
ibm advanced_management_module 1.28
ibm advanced_management_module 1.34
ibm advanced_management_module 1.20
ibm advanced_management_module 1.26
ibm advanced_management_module 2.46
CVE-2010-2771 HIGH

solid.exe in IBM solidDB before 6.5 FP2 allows remote attackers to execute arbitrary code via a long username field in the first handshake packet.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-94,

Products Affected

Vendor Product Version
ibm soliddb 6.5.0.0
ibm soliddb 6.0.1061
ibm soliddb 4.5.167
ibm soliddb 6.3.37
ibm soliddb 4.5.168
ibm soliddb 6.30.0044
ibm soliddb 6.1.20
ibm soliddb 6.30.0039
ibm soliddb 4.5.176
ibm soliddb 6.0.1064
ibm soliddb 4.5.178
ibm soliddb 6.30.0040
ibm soliddb 4.5.169
ibm soliddb 4.5.173
ibm soliddb 6.1
ibm soliddb 6.3.33
ibm soliddb 6.0.1066
ibm soliddb *
ibm soliddb 06.00.1018
ibm soliddb 4.5.175
ibm soliddb 6.0.1065
ibm soliddb 6.0.1060
CVE-2010-2896 MEDIUM

IBM FileNet Content Manager (CM) 4.0.0, 4.0.1, 4.5.0, and 4.5.1 before FP4 does not properly manage the InheritParentPermissions setting during an upgrade from 3.x, which might allow attackers to bypass intended folder permissions via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm filenet_content_manager 4.5.1
ibm filenet_content_manager 4.0.1
ibm filenet_content_manager 4.0.0
ibm filenet_content_manager 4.5.0
CVE-2010-2927 MEDIUM

The slapi_printmessage function in IBM Tivoli Directory Server (ITDS) before 6.0.0.8-TIV-ITDS-IF0006 allows remote attackers to cause a denial of service (daemon crash) via multiple incomplete DIGEST-MD5 connection attempts.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm tivoli_directory_server 6.0.0.7
ibm tivoli_directory_server 6.0
ibm tivoli_directory_server *
CVE-2010-2985 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in IBM WebSphere Service Registry and Repository (WSRR) 6.3 allow remote attackers to inject arbitrary web script or HTML via (1) the searchTerm parameter to ServiceRegistry/HelpSearch.do or (2) the queryItems[0].value parameter to ServiceRegistry/QueryWizardProcessStep1.do.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_service_registry_and_repository 6.3.0
CVE-2010-3058 HIGH

The Mount service in IBM Tivoli Storage Manager (TSM) FastBack 5.x.x before 5.5.7, and 6.1.0.0, establishes an open UDP port, which might allow remote attackers to overwrite memory locations and execute arbitrary code, or cause a denial of service (application hang), via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_fastback 5.5.0
ibm tivoli_storage_manager_fastback 5.5.4.0
ibm tivoli_storage_manager_fastback 5.5.2.0
ibm tivoli_storage_manager_fastback 5.5.3.0
ibm tivoli_storage_manager_fastback 5.5.1
ibm tivoli_storage_manager_fastback 6.1.0.0
ibm tivoli_storage_manager_fastback 5.5.5.0
ibm tivoli_storage_manager_fastback 5.5.6.0
ibm tivoli_storage_manager_fastback 5.5.2
CVE-2010-3059 HIGH

Buffer overflow in the message-protocol implementation in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.x.x before 5.5.7, and 6.1.0.0, allows remote attackers to read and modify data, and possibly have other impact, via an unspecified command.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_fastback 5.5.0
ibm tivoli_storage_manager_fastback 5.5.4.0
ibm tivoli_storage_manager_fastback 5.5.2.0
ibm tivoli_storage_manager_fastback 5.5.3.0
ibm tivoli_storage_manager_fastback 5.5.1
ibm tivoli_storage_manager_fastback 6.1.0.0
ibm tivoli_storage_manager_fastback 5.5.5.0
ibm tivoli_storage_manager_fastback 5.5.6.0
ibm tivoli_storage_manager_fastback 5.5.2
CVE-2010-3060 MEDIUM

Unspecified vulnerability in the message-protocol implementation in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.x.x before 5.5.7, and 6.1.0.0, allows remote attackers to cause a denial of service (daemon outage) via unknown vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_fastback 5.5.0
ibm tivoli_storage_manager_fastback 5.5.4.0
ibm tivoli_storage_manager_fastback 5.5.2.0
ibm tivoli_storage_manager_fastback 5.5.3.0
ibm tivoli_storage_manager_fastback 5.5.1
ibm tivoli_storage_manager_fastback 6.1.0.0
ibm tivoli_storage_manager_fastback 5.5.5.0
ibm tivoli_storage_manager_fastback 5.5.6.0
ibm tivoli_storage_manager_fastback 5.5.2
CVE-2010-3061 MEDIUM

Unspecified vulnerability in the message-protocol implementation in the Mount service in IBM Tivoli Storage Manager (TSM) FastBack 5.x.x before 5.5.7, and 6.1.0.0, allows remote attackers to cause a denial of service (recovery failure), and possibly trigger loss of data, via unknown vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_fastback 5.5.0
ibm tivoli_storage_manager_fastback 5.5.4.0
ibm tivoli_storage_manager_fastback 5.5.2.0
ibm tivoli_storage_manager_fastback 5.5.3.0
ibm tivoli_storage_manager_fastback 5.5.1
ibm tivoli_storage_manager_fastback 6.1.0.0
ibm tivoli_storage_manager_fastback 5.5.5.0
ibm tivoli_storage_manager_fastback 5.5.6.0
ibm tivoli_storage_manager_fastback 5.5.2
CVE-2010-3186 HIGH

IBM WebSphere Application Server (WAS) 7.x before 7.0.0.13, and WebSphere Application Server Feature Pack for Web Services 6.1.0.9 through 6.1.0.32, when a JAX-WS application is used, does not properly handle an IncludeTimestamp setting in the WS-Security policy, which has unspecified impact and remote attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 6.1.0.14
ibm websphere_application_server 6.1.0.20
ibm websphere_application_server 6.1.0.24
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 6.1.0.22
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.26
ibm websphere_application_server 7.0.0.10
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.1.0.32
ibm websphere_application_server 6.1.0.10
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.16
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.1.0.18
ibm websphere_application_server 7.0.0.4
CVE-2010-3187 HIGH

Buffer overflow in ftpd in IBM AIX 5.3 and earlier allows remote attackers to execute arbitrary code via a long NLST command.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm aix *
CVE-2010-3193 HIGH

Unspecified vulnerability in the DB2STST program in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 has unknown impact and attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm db2 9.1
ibm db2 9.5
ibm db2 9.7
CVE-2010-3194 HIGH

The DB2DART program in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 allows attackers to bypass intended file access restrictions via unspecified vectors related to overwriting files owned by an instance owner.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm db2 9.1
ibm db2 9.5
ibm db2 9.7
CVE-2010-3195 MEDIUM

Unspecified vulnerability in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 on Windows Server 2008 allows attackers to cause a denial of service (trap) via vectors involving "special group and user enumeration."

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm db2 9.1
ibm db2 9.5
ibm db2 9.7
CVE-2010-3196 LOW

IBM DB2 9.7 before FP2, when AUTO_REVAL is IMMEDIATE, allows remote authenticated users to cause a denial of service (loss of privileges) to a view owner by defining a dependent view.

CVSS 2.0

Severity: LOW

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm db2 9.7
CVE-2010-3197 MEDIUM

IBM DB2 9.7 before FP2 does not perform the expected access control on the monitor administrative views in the SYSIBMADM schema, which allows remote attackers to obtain sensitive information via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm db2 9.7
CVE-2010-3271 MEDIUM

Multiple cross-site request forgery (CSRF) vulnerabilities in the Integrated Solutions Console (aka administrative console) in IBM WebSphere Application Server (WAS) 7.0.0.13 and earlier allow remote attackers to hijack the authentication of administrators for requests that disable certain security options via an Edit action to console/adminSecurityDetail.do followed by a save action to console/syncworkspace.do.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0
ibm websphere_application_server 6.0.2.19
ibm websphere_application_server 4.0.1
ibm websphere_application_server 6.0.2.7
ibm websphere_application_server 5.0.2.6
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 5.1.1.12
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server *
ibm websphere_application_server 5.1.0.2
ibm websphere_application_server 5.1.1.16
ibm websphere_application_server 6.0.2.25
ibm websphere_application_server 3.0
ibm websphere_application_server 6.0.2.9
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 5.1.1.9
ibm websphere_application_server 5.0.2.2
ibm websphere_application_server 4.0.2
ibm websphere_application_server 6.1.1
ibm websphere_application_server 5.1.1.8
ibm websphere_application_server 5.1.1
ibm websphere_application_server 6.0.2.13
ibm websphere_application_server 6.0.1.11
ibm websphere_application_server 3.0.2
ibm websphere_application_server 3.52
ibm websphere_application_server 5.0.2.4
ibm websphere_application_server 4.0.4
ibm websphere_application_server 5.0.2.15
ibm websphere_application_server 6.0.2.15
ibm websphere_application_server 5.0.2.10
ibm websphere_application_server 6.0.2.4
ibm websphere_application_server 6.1.0
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 6.1
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 5.1.1.11
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 5.0.2.7
ibm websphere_application_server 4.0.3
ibm websphere_application_server 5.0.2.9
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 5.1.1.3
ibm websphere_application_server 5.1.0.3
ibm websphere_application_server 6.0.2.6
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 5.0.2.3
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.0.2.24
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 6.0.2.5
ibm websphere_application_server 3.0.2.4
ibm websphere_application_server 5.1.0
ibm websphere_application_server 5.1.1.17
ibm websphere_application_server 5.0.2.13
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 3.5.3
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.0.1.1
ibm websphere_application_server 6.0.2.1
ibm websphere_application_server 6.1.13
ibm websphere_application_server 3.5.2
ibm websphere_application_server 6.0.1.5
ibm websphere_application_server 6.0.0.1
ibm websphere_application_server 5.1.1.14
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.0.0.2
ibm websphere_application_server 3.5.1
ibm websphere_application_server 3.0.2.2
ibm websphere_application_server 3.0.2.1
ibm websphere_application_server 5.1.1.15
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 6.1.6
ibm websphere_application_server 5.1.1.10
ibm websphere_application_server 6.0.1.2
ibm websphere_application_server 5.0.2.14
ibm websphere_application_server 6.1.3
ibm websphere_application_server 6.0.1.17
ibm websphere_application_server 6.0.1.13
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 5.0.2.16
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 5.0
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 6.0.2.31
ibm websphere_application_server 5.0.2.12
ibm websphere_application_server 6.1.7
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 5.1.1.5
ibm websphere_application_server 6.0.2.22
ibm websphere_application_server 5.0.0
ibm websphere_application_server 6.0
ibm websphere_application_server 5.0.2.8
ibm websphere_application_server 6.0.1.3
ibm websphere_application_server 5.0.2
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 5.1.0.4
ibm websphere_application_server 6.0.2.2
ibm websphere_application_server 6.0.2.11
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 3.5
ibm websphere_application_server 6.0.1.15
ibm websphere_application_server 5.1.1.2
ibm websphere_application_server 5.0.1
ibm websphere_application_server 3.0.2.3
ibm websphere_application_server 5.1.1.6
ibm websphere_application_server 6.0.2.30
ibm websphere_application_server 6.0.2.32
ibm websphere_application_server 2.0
ibm websphere_application_server 5.0.2.11
ibm websphere_application_server 5.0.2.1
ibm websphere_application_server 5.0.2.5
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 5.1.1.7
ibm websphere_application_server 5.1.1.1
ibm websphere_application_server 5.1.1.13
ibm websphere_application_server 6.0.2.23
ibm websphere_application_server 6.0.1
ibm websphere_application_server 6.0.1.7
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.0.2.17
ibm websphere_application_server 6.1.5
ibm websphere_application_server 6.1.14
ibm websphere_application_server 6.0.2.3
ibm websphere_application_server 6.0.2.29
ibm websphere_application_server 6.0.1.9
ibm websphere_application_server 6.0.2
ibm websphere_application_server 6.0.2.28
ibm websphere_application_server 6.0.2.27
ibm websphere_application_server 3.0.21
ibm websphere_application_server 5.1.0.5
ibm websphere_application_server 6.0.0.3
ibm websphere_application_server 5.1.1.4
ibm websphere_application_server 7.0.0.4
CVE-2010-3317 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Records Manager (RM) 4.5.x before 4.5.1.1-IER-FP001 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm filenet_content_manager 4.5.1
ibm filenet_content_manager 4.5.0
CVE-2010-3318 MEDIUM

IBM Records Manager (RM) 4.5.x before 4.5.1.1-IER-FP001 transmits passwords in cleartext, which allows remote attackers to obtain sensitive information by sniffing the network.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm filenet_content_manager 4.5.1
ibm filenet_content_manager 4.5.0
CVE-2010-3319 MEDIUM

IBM Records Manager (RM) 4.5.x before 4.5.1.1-IER-FP001 places a session token in the URI, which might allow remote attackers to obtain sensitive information by reading a Referer log file.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm filenet_content_manager 4.5.1
ibm filenet_content_manager 4.5.0
CVE-2010-3320 MEDIUM

Open redirect vulnerability in IBM Records Manager (RM) 4.5.x before 4.5.1.1-IER-FP001 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm filenet_content_manager 4.5.1
ibm filenet_content_manager 4.5.0
CVE-2010-3398 HIGH

Unspecified vulnerability in the webcontainer implementation in IBM Lotus Sametime Connect 8.5.1 before CF1 has unknown impact and attack vectors, aka SPRs LXUU87S57H and LXUU87S93W.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm lotus_sametime *
ibm lotus_sametime 2.5
ibm lotus_sametime 8.0
ibm lotus_sametime 8.5
ibm lotus_sametime 1.5
ibm lotus_sametime 8.0.1
ibm lotus_sametime 8.0.2
ibm lotus_sametime 7.5
ibm lotus_sametime 7.0
ibm lotus_sametime 7.5.1
CVE-2010-3405 MEDIUM

Buffer overflow in sa_snap in the bos.esagent fileset in IBM AIX 6.1, 5.3, and earlier and VIOS 2.1, 1.5, and earlier allows local users to leverage system group membership and gain privileges via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm vios 1.5
ibm aix 5.3
ibm aix 6.1
ibm vios 2.1
CVE-2010-3406 LOW

Unspecified vulnerability in sa_snap in the bos.esagent fileset in IBM AIX 5.3 allows local users to leverage system group membership and delete files via unknown vectors.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm aix 5.3
CVE-2010-3407 HIGH

Stack-based buffer overflow in the MailCheck821Address function in nnotes.dll in the nrouter.exe service in the server in IBM Lotus Domino 8.0.x before 8.0.2 FP5 and 8.5.x before 8.5.1 FP2 allows remote attackers to execute arbitrary code via a long e-mail address in an ORGANIZER:mailto header in an iCalendar calendar-invitation e-mail message, aka SPR NRBY7ZPJ9V.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm lotus_domino 8.0.2.1
ibm lotus_domino 8.5.0
ibm lotus_domino 8.5.1
ibm lotus_domino 8.5.1.1
ibm lotus_domino 8.0.1
ibm lotus_domino 8.0
ibm lotus_domino 8.0.2.3
ibm lotus_domino 8.0.2.4
ibm lotus_domino 8.0.2.2
ibm lotus_domino 8.0.2
ibm lotus_domino 8.5.0.1
CVE-2010-3470 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in the Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 3.5.1 before 3.5.1-021 and 4.0.2.x before 4.0.2.7-P8AE-FP007 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm filenet_p8_application_engine 4.0.2
ibm filenet_p8_application_engine 3.5.1
CVE-2010-3471 MEDIUM

Session fixation vulnerability in the Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 4.0.2.x before 4.0.2.7-P8AE-FP007 allows remote attackers to hijack web sessions via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm filenet_p8_application_engine 4.0.2
CVE-2010-3472 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in the Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 3.5.1 before 3.5.1-021 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm filenet_p8_application_engine 3.5.1
CVE-2010-3473 MEDIUM

Open redirect vulnerability in the Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 3.5.1 before 3.5.1-021 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm filenet_p8_application_engine 3.5.1
CVE-2010-3474 MEDIUM

IBM DB2 9.7 before FP3 does not perform the expected drops or invalidations of dependent functions upon a loss of privileges by the functions' owners, which allows remote authenticated users to bypass intended access restrictions via calls to these functions, a different vulnerability than CVE-2009-3471.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm db2 9.7.0.2
ibm db2 9.7.0.1
ibm db2 9.7
CVE-2010-3475 MEDIUM

IBM DB2 9.7 before FP3 does not properly enforce privilege requirements for execution of entries in the dynamic SQL cache, which allows remote authenticated users to bypass intended access restrictions by leveraging the cache to execute an UPDATE statement contained in a compiled compound SQL statement.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm db2 9.7.0.2
ibm db2 9.7.0.1
ibm db2 9.7
CVE-2010-3700 MEDIUM

VMware SpringSource Spring Security 2.x before 2.0.6 and 3.x before 3.0.4, and Acegi Security 1.0.0 through 1.0.7, as used in IBM WebSphere Application Server (WAS) 6.1 and 7.0, allows remote attackers to bypass security constraints via a path parameter.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
vmware springsource_spring_security 3.0.2
acegisecurity acegi-security 1.0.0
acegisecurity acegi-security 1.0.3
vmware springsource_spring_security 2.0.3
ibm websphere_application_server 7.0
vmware springsource_spring_security 3.0.3
acegisecurity acegi-security 1.0.5
vmware springsource_spring_security 3.0.1
acegisecurity acegi-security 1.0.7
acegisecurity acegi-security 1.0.6
vmware springsource_spring_security 2.0.2
vmware springsource_spring_security 2.0.1
vmware springsource_spring_security 3.0.0
acegisecurity acegi-security 1.0.1
acegisecurity acegi-security 1.0.4
vmware springsource_spring_security 2.0.4
ibm websphere_application_server 6.1
vmware springsource_spring_security 2.0.0
acegisecurity acegi-security 1.0.2
vmware springsource_spring_security 2.0.5
CVE-2010-3731 HIGH

Stack-based buffer overflow in the validateUser implementation in the com.ibm.db2.das.core.DasSysCmd function in db2dasrrm in the DB2 Administration Server (DAS) component in IBM DB2 9.1 before FP10, 9.5 before FP6a, and 9.7 before FP3 allows remote attackers to execute arbitrary code via a long username string.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm db2 9.5
CVE-2010-3732 LOW

The DRDA Services component in IBM DB2 UDB 9.5 before FP6a allows remote authenticated users to cause a denial of service (database server ABEND) by using the client CLI on Linux, UNIX, or Windows for executing a prepared statement with a large number of parameter markers.

CVSS 2.0

Severity: LOW

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm db2 9.5
CVE-2010-3733 HIGH

The Engine Utilities component in IBM DB2 UDB 9.5 before FP6a uses world-writable permissions for the sqllib/cfg/db2sprf file, which might allow local users to gain privileges by modifying this file.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm db2 9.5
CVE-2010-3734 MEDIUM

The Install component in IBM DB2 UDB 9.5 before FP6a on Linux, UNIX, and Windows enforces an unintended limit on password length, which makes it easier for attackers to obtain access via a brute-force attack.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm db2 9.5
CVE-2010-3735 LOW

The "Query Compiler, Rewrite, Optimizer" component in IBM DB2 UDB 9.5 before FP6a allows remote authenticated users to cause a denial of service (CPU consumption) via a crafted query involving certain UNION ALL views, leading to an indefinitely large amount of compilation time.

CVSS 2.0

Severity: LOW

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm db2 9.5
CVE-2010-3736 MEDIUM

Memory leak in the Relational Data Services component in IBM DB2 UDB 9.5 before FP6a, when the connection concentrator is enabled, allows remote authenticated users to cause a denial of service (heap memory consumption) by using a different code page than the database server.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm db2 9.5
CVE-2010-3737 LOW

Memory leak in the Relational Data Services component in IBM DB2 UDB 9.5 before FP6a allows remote authenticated users to cause a denial of service (heap memory consumption) by executing a (1) user-defined function (UDF) or (2) stored procedure while using a different code page than the database server.

CVSS 2.0

Severity: LOW

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm db2 9.5
CVE-2010-3738 MEDIUM

The Security component in IBM DB2 UDB 9.5 before FP6a logs AUDIT events by using a USERID and an AUTHID value corresponding to the instance owner, instead of a USERID and an AUTHID value corresponding to the logged-in user account, which makes it easier for remote authenticated users to execute Audit administration commands without discovery.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm db2 9.5
CVE-2010-3739 MEDIUM

The audit facility in the Security component in IBM DB2 UDB 9.5 before FP6a uses instance-level audit settings to capture connection (aka CONNECT and AUTHENTICATION) events in certain circumstances in which database-level audit settings were intended, which might make it easier for remote attackers to connect without discovery.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm db2_universal_database 9.5
ibm db2_universal_database *
CVE-2010-3740 MEDIUM

The Net Search Extender (NSE) implementation in the Text Search component in IBM DB2 UDB 9.5 before FP6a does not properly handle an alphanumeric Fuzzy search, which allows remote authenticated users to cause a denial of service (memory consumption and system hang) via the db2ext.textSearch function.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm db2 9.5
CVE-2010-3754 HIGH

The FXCLI_OraBR_Exec_Command function in FastBackServer.exe in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 uses values of packet fields to determine the content and length of data copied to memory, which allows remote attackers to execute arbitrary code via a crafted packet. NOTE: this might overlap CVE-2010-3059.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-78,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_fastback 6.1.0.1
ibm tivoli_storage_manager_fastback 5.5.0
ibm tivoli_storage_manager_fastback 5.5.4.0
ibm tivoli_storage_manager_fastback 5.5.2.0
ibm tivoli_storage_manager_fastback 5.5.3.0
ibm tivoli_storage_manager_fastback 5.5.1
ibm tivoli_storage_manager_fastback 6.1.0.0
ibm tivoli_storage_manager_fastback 5.5.5.0
ibm tivoli_storage_manager_fastback 5.5.6.0
ibm tivoli_storage_manager_fastback 5.5.2
CVE-2010-3755 MEDIUM

The _DAS_ReadBlockReply function in FastBackServer.exe in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via data in a TCP packet. NOTE: this might overlap CVE-2010-3060.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_fastback 6.1.0.1
ibm tivoli_storage_manager_fastback 5.5.0
ibm tivoli_storage_manager_fastback 5.5.4.0
ibm tivoli_storage_manager_fastback 5.5.2.0
ibm tivoli_storage_manager_fastback 5.5.3.0
ibm tivoli_storage_manager_fastback 5.5.1
ibm tivoli_storage_manager_fastback 6.1.0.0
ibm tivoli_storage_manager_fastback 5.5.5.0
ibm tivoli_storage_manager_fastback 5.5.6.0
ibm tivoli_storage_manager_fastback 5.5.2
CVE-2010-3756 MEDIUM

The _CalcHashValueWithLength function in FastBackServer.exe in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 does not properly validate an unspecified length value, which allows remote attackers to cause a denial of service (daemon crash) by sending data over TCP. NOTE: this might overlap CVE-2010-3060.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_fastback 6.1.0.1
ibm tivoli_storage_manager_fastback 5.5.0
ibm tivoli_storage_manager_fastback 5.5.4.0
ibm tivoli_storage_manager_fastback 5.5.2.0
ibm tivoli_storage_manager_fastback 5.5.3.0
ibm tivoli_storage_manager_fastback 5.5.1
ibm tivoli_storage_manager_fastback 6.1.0.0
ibm tivoli_storage_manager_fastback 5.5.5.0
ibm tivoli_storage_manager_fastback 5.5.6.0
ibm tivoli_storage_manager_fastback 5.5.2
CVE-2010-3757 HIGH

Format string vulnerability in the _Eventlog function in FastBackServer.exe in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 allows remote attackers to execute arbitrary code via format string specifiers located after a | (pipe) character in a string. NOTE: this might overlap CVE-2010-3059.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-78,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_fastback 6.1.0.1
ibm tivoli_storage_manager_fastback 5.5.0
ibm tivoli_storage_manager_fastback 5.5.4.0
ibm tivoli_storage_manager_fastback 5.5.2.0
ibm tivoli_storage_manager_fastback 5.5.3.0
ibm tivoli_storage_manager_fastback 5.5.1
ibm tivoli_storage_manager_fastback 6.1.0.0
ibm tivoli_storage_manager_fastback 5.5.5.0
ibm tivoli_storage_manager_fastback 5.5.6.0
ibm tivoli_storage_manager_fastback 5.5.2
CVE-2010-3758 HIGH

Multiple stack-based buffer overflows in FastBackServer.exe in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 allow remote attackers to execute arbitrary code via vectors involving the (1) AGI_SendToLog (aka _SendToLog) function; the (2) group, (3) workgroup, or (4) domain name field to the USER_S_AddADGroup function; the (5) user_path variable to the FXCLI_checkIndexDBLocation function; or (6) the _AGI_S_ActivateLTScriptReply (aka ActivateLTScriptReply) function. NOTE: this might overlap CVE-2010-3059.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-94,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_fastback 6.1.0.1
ibm tivoli_storage_manager_fastback 5.5.0
ibm tivoli_storage_manager_fastback 5.5.4.0
ibm tivoli_storage_manager_fastback 5.5.2.0
ibm tivoli_storage_manager_fastback 5.5.3.0
ibm tivoli_storage_manager_fastback 5.5.1
ibm tivoli_storage_manager_fastback 6.1.0.0
ibm tivoli_storage_manager_fastback 5.5.5.0
ibm tivoli_storage_manager_fastback 5.5.6.0
ibm tivoli_storage_manager_fastback 5.5.2
CVE-2010-3759 HIGH

FastBackMount.exe in the Mount service in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 writes a certain value to a memory location specified by a UDP packet field, which allows remote attackers to execute arbitrary code via multiple requests. NOTE: this might overlap CVE-2010-3058.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-94,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_fastback 6.1.0.1
ibm tivoli_storage_manager_fastback 5.5.0
ibm tivoli_storage_manager_fastback 5.5.4.0
ibm tivoli_storage_manager_fastback 5.5.2.0
ibm tivoli_storage_manager_fastback 5.5.3.0
ibm tivoli_storage_manager_fastback 5.5.1
ibm tivoli_storage_manager_fastback 6.1.0.0
ibm tivoli_storage_manager_fastback 5.5.5.0
ibm tivoli_storage_manager_fastback 5.5.6.0
ibm tivoli_storage_manager_fastback 5.5.2
CVE-2010-3760 HIGH

FastBackMount.exe in the Mount service in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 does not properly handle a certain failure to allocate memory, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash, and recovery failure) by specifying a large size value within TCP packet data. NOTE: this might overlap CVE-2010-3061.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_fastback 6.1.0.1
ibm tivoli_storage_manager_fastback 5.5.0
ibm tivoli_storage_manager_fastback 5.5.4.0
ibm tivoli_storage_manager_fastback 5.5.2.0
ibm tivoli_storage_manager_fastback 5.5.3.0
ibm tivoli_storage_manager_fastback 5.5.1
ibm tivoli_storage_manager_fastback 6.1.0.0
ibm tivoli_storage_manager_fastback 5.5.5.0
ibm tivoli_storage_manager_fastback 5.5.6.0
ibm tivoli_storage_manager_fastback 5.5.2
CVE-2010-3761 HIGH

Unspecified vulnerability in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-700. NOTE: this might overlap CVE-2010-3058 or CVE-2010-3059.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-94,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_fastback 6.1.0.1
ibm tivoli_storage_manager_fastback 5.5.0
ibm tivoli_storage_manager_fastback 5.5.4.0
ibm tivoli_storage_manager_fastback 5.5.2.0
ibm tivoli_storage_manager_fastback 5.5.3.0
ibm tivoli_storage_manager_fastback 5.5.1
ibm tivoli_storage_manager_fastback 6.1.0.0
ibm tivoli_storage_manager_fastback 5.5.5.0
ibm tivoli_storage_manager_fastback 5.5.6.0
ibm tivoli_storage_manager_fastback 5.5.2
CVE-2010-3890 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM OmniFind Enterprise Edition before 9.1 allows remote attackers to inject arbitrary web script or HTML via the command parameter to the administration interface, as demonstrated by the command parameter to ESAdmin/collection.do.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm omnifind *
ibm omnifind 8.0
ibm omnifind 8.4
ibm omnifind 8.5
CVE-2010-3891 MEDIUM

Cross-site request forgery (CSRF) vulnerability in ESAdmin/security.do in the administrator interface in IBM OmniFind Enterprise Edition before 9.1 allows remote attackers to hijack the authentication of administrators for requests that add an administrative user via a saveNewUser action.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm omnifind *
ibm omnifind 8.0
ibm omnifind 8.4
ibm omnifind 8.5
CVE-2010-3892 MEDIUM

Session fixation vulnerability in the login form in the administrator interface in IBM OmniFind Enterprise Edition 8.x and 9.x allows remote attackers to hijack web sessions by replaying a session ID (aka SID) value.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm omnifind 8.0
ibm omnifind 8.4
ibm omnifind 8.5
ibm omnifind 9.1
ibm omnifind 9.0
CVE-2010-3893 HIGH

The administrator interface in IBM OmniFind Enterprise Edition 8.x and 9.x does not restrict use of a session ID (aka SID) value to a single IP address, which allows remote attackers to perform arbitrary administrative actions by leveraging cookie theft, related to a "session impersonation" issue.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm omnifind 8.0
ibm omnifind 8.4
ibm omnifind 8.5
ibm omnifind 9.1
ibm omnifind 9.0
CVE-2010-3894 HIGH

Stack-based buffer overflow in the Java_com_ibm_es_oss_CryptionNative_ESEncrypt function in /opt/IBM/es/lib/libffq.cryptionjni.so in the login form in the administration interface in IBM OmniFind Enterprise Edition before 8.5 FP6 allows remote attackers to execute arbitrary code via a long password.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm omnifind *
ibm omnifind 8.0
ibm omnifind 6.1
ibm omnifind 8.4
CVE-2010-3895 HIGH

esRunCommand in IBM OmniFind Enterprise Edition before 9.1 allows local users to gain privileges by specifying an arbitrary command name as the first argument.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm omnifind *
ibm omnifind 8.0
ibm omnifind 8.4
ibm omnifind 8.5
CVE-2010-3896 HIGH

The ESSearchApplication directory tree in IBM OmniFind Enterprise Edition 8.x and 9.x does not require authentication, which allows remote attackers to modify the server configuration via a request to palette.do.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm omnifind 8.0
ibm omnifind 8.4
ibm omnifind 8.5
ibm omnifind 9.1
ibm omnifind 9.0
CVE-2010-3897 MEDIUM

ESSearchApplication/palette.do in IBM OmniFind Enterprise Edition 8.x and 9.x includes the administrator password in the HTML source code, which might allow remote attackers to obtain sensitive information by leveraging read access to this file.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm omnifind 8.0
ibm omnifind 8.4
ibm omnifind 8.5
ibm omnifind 9.1
ibm omnifind 9.0
CVE-2010-3898 MEDIUM

IBM OmniFind Enterprise Edition 8.x and 9.x does not properly restrict the cookie path of administrator (aka ESAdmin) cookies, which might allow remote attackers to bypass authentication by leveraging access to other pages on the web site.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm omnifind 8.0
ibm omnifind 8.4
ibm omnifind 8.5
ibm omnifind 9.1
ibm omnifind 9.0
CVE-2010-3899 MEDIUM

IBM OmniFind Enterprise Edition 8.x and 9.x performs web crawls with an unlimited recursion depth, which allows remote web servers to cause a denial of service (infinite loop) via a crafted series of documents.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm omnifind 8.0
ibm omnifind 9.0
CVE-2010-4053 HIGH

Stack-based buffer overflow in an unspecified logging function in oninit.exe in IBM Informix Dynamic Server (IDS) 11.10 before 11.10.xC2W2 and 11.50 before 11.50.xC1 allows remote authenticated users to execute arbitrary code via a crafted EXPLAIN directive, aka idsdb00154125 and idsdb00154243.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm informix_dynamic_server 11.10
ibm informix_dynamic_server 11.50
CVE-2010-4055 MEDIUM

Stack consumption vulnerability in solid.exe in IBM solidDB 6.5.0.3 and earlier allows remote attackers to cause a denial of service (memory consumption and daemon crash) by connecting to TCP port 1315 and sending a packet with many integer fields, which trigger many recursive calls of a certain function.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm soliddb 4.5.167
ibm soliddb 6.30.0044
ibm soliddb 6.5.0.1
ibm soliddb 6.1.20
ibm soliddb 4.5.178
ibm soliddb 6.5.0.2
ibm soliddb 06.30.0047
ibm soliddb 4.5.169
ibm soliddb 6.1
ibm soliddb 6.3.33
ibm soliddb *
ibm soliddb 6.5.0.0
ibm soliddb 6.0.1061
ibm soliddb 6.3.37
ibm soliddb 4.5.168
ibm soliddb 6.30.0039
ibm soliddb 4.5.176
ibm soliddb 6.0.1064
ibm soliddb 6.30.0040
ibm soliddb 4.5.173
ibm soliddb 6.0.1066
ibm soliddb 06.00.1018
ibm soliddb 4.5.175
ibm soliddb 6.0.1065
ibm soliddb 6.0.1060
CVE-2010-4056 MEDIUM

solid.exe in IBM solidDB 6.5.0.3 and earlier does not properly perform a recursive call to a certain function upon receiving packet data containing a single integer field, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a TCP session on port 1315.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm soliddb 4.5.167
ibm soliddb 6.30.0044
ibm soliddb 6.5.0.1
ibm soliddb 6.1.20
ibm soliddb 4.5.178
ibm soliddb 6.5.0.2
ibm soliddb 06.30.0047
ibm soliddb 4.5.169
ibm soliddb 6.1
ibm soliddb 6.3.33
ibm soliddb *
ibm soliddb 6.5.0.0
ibm soliddb 6.0.1061
ibm soliddb 6.3.37
ibm soliddb 4.5.168
ibm soliddb 6.30.0039
ibm soliddb 4.5.176
ibm soliddb 6.0.1064
ibm soliddb 6.30.0040
ibm soliddb 4.5.173
ibm soliddb 6.0.1066
ibm soliddb 4.5.175
ibm soliddb 6.0.1065
ibm soliddb 6.0.1060
CVE-2010-4057 MEDIUM

solid.exe in IBM solidDB 6.5.0.3 and earlier does not properly perform a recursive call to a certain function upon receiving packet data containing many integer fields with two different values, which allows remote attackers to cause a denial of service (invalid memory access and daemon crash) via a TCP session on port 1315.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-189,

Products Affected

Vendor Product Version
ibm soliddb 4.5.167
ibm soliddb 6.30.0044
ibm soliddb 6.5.0.1
ibm soliddb 6.1.20
ibm soliddb 4.5.178
ibm soliddb 6.5.0.2
ibm soliddb 06.30.0047
ibm soliddb 4.5.169
ibm soliddb 6.1
ibm soliddb 6.3.33
ibm soliddb *
ibm soliddb 6.5.0.0
ibm soliddb 6.0.1061
ibm soliddb 6.3.37
ibm soliddb 4.5.168
ibm soliddb 6.30.0039
ibm soliddb 4.5.176
ibm soliddb 6.0.1064
ibm soliddb 6.30.0040
ibm soliddb 4.5.173
ibm soliddb 6.0.1066
ibm soliddb 4.5.175
ibm soliddb 6.0.1065
ibm soliddb 6.0.1060
CVE-2010-4069 HIGH

Stack-based buffer overflow in IBM Informix Dynamic Server (IDS) 7.x through 7.31, 9.x through 9.40, 10.00 before 10.00.xC10, 11.10 before 11.10.xC3, and 11.50 before 11.50.xC3 allows remote authenticated users to execute arbitrary code via long DBINFO keyword arguments in a SQL statement, aka idsdb00165017, idsdb00165019, idsdb00165021, idsdb00165022, and idsdb00165023.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm informix_dynamic_server 10.00.tc3tl
ibm informix_dynamic_server 11.10.xc1de
ibm informix_dynamic_server 10.00.xc4
ibm informix_dynamic_server 9.40.uc1
ibm informix_dynamic_server 9.40.xc5
ibm informix_dynamic_server 10.00.xc7w1
ibm informix_dynamic_server 10.00.xc2
ibm informix_dynamic_server 9.40.uc3
ibm informix_dynamic_server 10.00.xc6
ibm informix_dynamic_server 10.00.xc1
ibm informix_dynamic_server 10.00.xc9
ibm informix_dynamic_server 7.31
ibm informix_dynamic_server 11.10.xc1
ibm informix_dynamic_server 11.50.xc1
ibm informix_dynamic_server 9.40.uc2
ibm informix_dynamic_server 9.40.xc7
ibm informix_dynamic_server 11.10.xc2
ibm informix_dynamic_server 10.00.xc8
ibm informix_dynamic_server 10.00.xc10
ibm informix_dynamic_server 9.40.tc5
ibm informix_dynamic_server 11.10.tb4tl
ibm informix_dynamic_server 9.40.uc5
ibm informix_dynamic_server 11.10
ibm informix_dynamic_server 11.50.xc2
ibm informix_dynamic_server 10.00.xc5
ibm informix_dynamic_server 10.00
ibm informix_dynamic_server 11.50
ibm informix_dynamic_server 11.10.xc2e
ibm informix_dynamic_server 10.00.xc3
CVE-2010-4070 HIGH

Integer overflow in librpc.dll in portmap.exe (aka the ISM Portmapper service) in ISM before 2.20.TC1.117 in IBM Informix Dynamic Server (IDS) 7.x before 7.31.xD11, 9.x before 9.40.xC10, 10.00 before 10.00.xC8, and 11.10 before 11.10.xC2 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted parameter size, aka idsdb00146931, idsdb00146930, idsdb00146929, and idsdb00138308.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-189,

Products Affected

Vendor Product Version
ibm informix_dynamic_server 10.00.tc3tl
ibm informix_dynamic_server 11.10.xc1de
ibm informix_dynamic_server 10.00.xc4
ibm informix_dynamic_server 9.40.uc1
ibm informix_dynamic_server 9.40.xc5
ibm informix_dynamic_server 10.00.xc7w1
ibm informix_dynamic_server 10.00.xc2
ibm informix_dynamic_server 9.40.uc3
ibm informix_dynamic_server 10.00.xc6
ibm informix_dynamic_server 10.00.xc1
ibm informix_dynamic_server 10.00.xc9
ibm informix_dynamic_server 7.31
ibm informix_dynamic_server 11.10.xc1
ibm informix_dynamic_server 9.40.uc2
ibm informix_dynamic_server 9.40.xc7
ibm informix_dynamic_server 10.00.xc8
ibm informix_dynamic_server 10.00.xc10
ibm informix_dynamic_server 9.40.tc5
ibm informix_dynamic_server 11.10.tb4tl
ibm informix_dynamic_server 9.40.uc5
ibm informix_dynamic_server 11.10
ibm informix_dynamic_server 10.00.xc5
ibm informix_dynamic_server 10.00
ibm informix_dynamic_server 11.50
ibm informix_dynamic_server 10.00.xc3
CVE-2010-4094 MEDIUM

The Tomcat server in IBM Rational Quality Manager and Rational Test Lab Manager has a default password for the ADMIN account, which makes it easier for remote attackers to execute arbitrary code by leveraging access to the manager role. NOTE: this might overlap CVE-2009-3548.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
ibm rational_test_lab_manager *
CVE-2010-4120 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in the TAM console in IBM Tivoli Access Manager for e-business 6.1.0 before 6.1.0-TIV-TAM-FP0006 allow remote attackers to inject arbitrary web script or HTML via (1) the parm1 parameter to ivt/ivtserver, or the method parameter to (2) acl, (3) domain, (4) group, (5) gso, (6) gsogroup, (7) os, (8) pop, (9) rule, (10) user, or (11) webseal in ibm/wpm/.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_access_manager_for_e-business 6.1.1
ibm tivoli_access_manager_for_e-business 6.1.0
CVE-2010-4121 HIGH

The TCP-to-ODBC gateway in IBM Tivoli Provisioning Manager for OS Deployment 7.1.1.3 does not require authentication for SQL statements, which allows remote attackers to modify, create, or read database records via a session on TCP port 2020. NOTE: the vendor disputes this issue, stating that the "default Microsoft Access database is not password protected because it is intended to be used for evaluation purposes only.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm tivoli_provisioning_manager_os_deployment 7.1.1.3
CVE-2010-4216 MEDIUM

IBM Tivoli Directory Server (TDS) 6.0.0.x before 6.0.0.8-TIV-ITDS-IF0007 does not properly handle invalid buffer references in LDAP BER requests, which might allow remote attackers to cause a denial of service (daemon crash) via vectors involving a buffer that has a memory address near the maximum possible address.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm tivoli_directory_server 6.0.0.7
ibm tivoli_directory_server 6.0.0.8
ibm tivoli_directory_server 6.0
CVE-2010-4217 MEDIUM

Use-after-free vulnerability in the proxy server in IBM Tivoli Directory Server (TDS) 6.0.0.x before 6.0.0.8-TIV-ITDS-IF0007 and 6.1.x before 6.1.0-TIV-ITDS-FP0005 allows remote attackers to cause a denial of service (daemon crash) via an unbind request that occurs during a certain search operation.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm tivoli_directory_server 6.0.0.41
ibm tivoli_directory_server 6.0.0.7
ibm tivoli_directory_server 6.0.0.62
ibm tivoli_directory_server 6.0.0.52
ibm tivoli_directory_server 6.0.0.14
ibm tivoli_directory_server 6.0.0.56
ibm tivoli_directory_server 6.0.0.55
ibm tivoli_directory_server 6.0.0.63
ibm tivoli_directory_server 6.0.0.53
ibm tivoli_directory_server 6.0.0.19
ibm tivoli_directory_server 6.0.0.58
ibm tivoli_directory_server 6.0.0.60
ibm tivoli_directory_server 6.1.0.0
ibm tivoli_directory_server 6.0.0.45
ibm tivoli_directory_server 6.0.0.57
ibm tivoli_directory_server 6.0.0.54
ibm tivoli_directory_server 6.0.0.64
ibm tivoli_directory_server 6.0.0.1
ibm tivoli_directory_server 6.0.0.0
ibm tivoli_directory_server 6.0.0.61
ibm tivoli_directory_server 6.1.0.5
ibm tivoli_directory_server 6.0.0.8
ibm tivoli_directory_server 6.0.0.59
ibm tivoli_directory_server 6.0.0.33
CVE-2010-4218 HIGH

Unspecified vulnerability in Web Services in IBM ENOVIA 6 has unknown impact and attack vectors, related to a system that becomes "exposed to the internet."

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm enovia 6
CVE-2010-4219 MEDIUM

Cross-site scripting (XSS) vulnerability in SemanticTagService.js in IBM WebSphere Portal 6.1.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: some of these details are obtained from third party information.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 6.1.0.1
CVE-2010-4220 MEDIUM

Cross-site scripting (XSS) vulnerability in the Integrated Solution Console in the Administrative Console component in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related in part to "URL injection."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.12
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 7.0.0.10
ibm websphere_application_server 7.0.0.4
CVE-2010-4236 MEDIUM

Untrusted search path vulnerability in estaskwrapper in IBM OmniFind Enterprise Edition before 9.1 allows local users to gain privileges via an ES_LIBRARY_PATH environment variable and a modified PATH environment variable, which is used during execution of the estasklight program, a different vulnerability than CVE-2010-3895.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm omnifind *
ibm omnifind 8.0
ibm omnifind 6.1
ibm omnifind 8.4
ibm omnifind 8.5
CVE-2010-4274 MEDIUM

reset_diragent_keys in the Common agent in IBM Systems Director 6.2.0 has 754 permissions, which allows local users to gain privileges by leveraging system group membership.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm director_agent 6.2.0
CVE-2010-4544 MEDIUM

Cross-site scripting (XSS) vulnerability in the servlet in IBM Lotus Notes Traveler before 8.5.1.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm lotus_notes_traveler 8.5.1.1
ibm lotus_notes_traveler 8.0
ibm lotus_notes_traveler 8.5.0.0
ibm lotus_notes_traveler 8.0.1
ibm lotus_notes_traveler 8.0.1.3
ibm lotus_notes_traveler 8.5.0.1
ibm lotus_notes_traveler 8.5.0.2
ibm lotus_notes_traveler *
ibm lotus_notes_traveler 8.0.1.2
CVE-2010-4545 MEDIUM

IBM Lotus Notes Traveler before 8.5.1.2 allows remote authenticated users to cause a denial of service (resource consumption and sync outage) by syncing a large volume of data.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm lotus_notes_traveler 8.0
ibm lotus_notes_traveler 8.5.0.0
ibm lotus_notes_traveler 8.0.1
ibm lotus_notes_traveler 8.0.1.3
ibm lotus_notes_traveler 8.5.0.1
ibm lotus_notes_traveler 8.5.0.2
ibm lotus_notes_traveler *
ibm lotus_notes_traveler 8.0.1.2
CVE-2010-4546 MEDIUM

IBM Lotus Notes Traveler before 8.5.1.2 does not reject an attachment download request for an e-mail message with a Prevent Copy attribute, which allows remote authenticated users to bypass intended access restrictions via this request.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm lotus_notes_traveler 8.0
ibm lotus_notes_traveler 8.5.0.0
ibm lotus_notes_traveler 8.0.1
ibm lotus_notes_traveler 8.0.1.3
ibm lotus_notes_traveler 8.5.0.1
ibm lotus_notes_traveler 8.5.0.2
ibm lotus_notes_traveler *
ibm lotus_notes_traveler 8.0.1.2
CVE-2010-4547 LOW

IBM Lotus Notes Traveler before 8.5.1.3, when a multidomain environment is used, does not properly apply policy documents to mobile users from a different Domino domain than the Traveler server, which allows remote authenticated users to bypass intended access restrictions by using credentials from a different domain.

CVSS 2.0

Severity: LOW

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm lotus_notes_traveler 8.5.1.1
ibm lotus_notes_traveler 8.0
ibm lotus_notes_traveler 8.5.0.0
ibm lotus_notes_traveler 8.0.1
ibm lotus_notes_traveler 8.0.1.3
ibm lotus_notes_traveler 8.5.0.1
ibm lotus_notes_traveler 8.5.0.2
ibm lotus_notes_traveler *
ibm lotus_notes_traveler 8.0.1.2
CVE-2010-4548 LOW

IBM Lotus Notes Traveler before 8.5.1.2 allows remote authenticated users to cause a denial of service (daemon crash) by accepting a meeting invitation with an iNotes client and then accepting this meeting invitation with an iPhone client.

CVSS 2.0

Severity: LOW

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm lotus_notes_traveler 8.0
ibm lotus_notes_traveler 8.5.0.0
ibm lotus_notes_traveler 8.0.1
ibm lotus_notes_traveler 8.0.1.3
ibm lotus_notes_traveler 8.5.0.1
ibm lotus_notes_traveler 8.5.0.2
ibm lotus_notes_traveler *
ibm lotus_notes_traveler 8.0.1.2
CVE-2010-4549 MEDIUM

IBM Lotus Notes Traveler before 8.5.1.3 on the Nokia s60 device successfully performs a Replace Data operation for a prohibited application, which allows remote authenticated users to bypass intended access restrictions via this operation.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm lotus_notes_traveler 8.5.1.1
ibm lotus_notes_traveler 8.0
ibm lotus_notes_traveler 8.5.0.0
ibm lotus_notes_traveler 8.0.1
ibm lotus_notes_traveler 8.0.1.3
ibm lotus_notes_traveler 8.5.0.1
ibm lotus_notes_traveler 8.5.0.2
ibm lotus_notes_traveler *
ibm lotus_notes_traveler 8.0.1.2
CVE-2010-4550 MEDIUM

IBM Lotus Notes Traveler before 8.5.1.3 allows remote attackers to cause a denial of service (sync failure) via a malformed document.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm lotus_notes_traveler 8.5.1.1
ibm lotus_notes_traveler 8.0
ibm lotus_notes_traveler 8.5.0.0
ibm lotus_notes_traveler 8.0.1
ibm lotus_notes_traveler 8.0.1.3
ibm lotus_notes_traveler 8.5.0.1
ibm lotus_notes_traveler 8.5.0.2
ibm lotus_notes_traveler *
ibm lotus_notes_traveler 8.0.1.2
CVE-2010-4551 MEDIUM

IBM Lotus Notes Traveler before 8.5.1.2 allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) by omitting the Internet ID field in the person document, and then using an Apple device to (1) accept or (2) decline an invitation.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_notes_traveler 8.0
ibm lotus_notes_traveler 8.5.0.0
ibm lotus_notes_traveler 8.0.1
ibm lotus_notes_traveler 8.0.1.3
ibm lotus_notes_traveler 8.5.0.1
ibm lotus_notes_traveler 8.5.0.2
ibm lotus_notes_traveler *
ibm lotus_notes_traveler 8.0.1.2
CVE-2010-4552 MEDIUM

Memory leak in IBM Lotus Notes Traveler before 8.5.1.1 allows remote attackers to cause a denial of service (memory consumption and daemon outage) by sending many embedded objects in e-mail messages for iPhone clients.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm lotus_notes_traveler 8.0
ibm lotus_notes_traveler 8.5.0.0
ibm lotus_notes_traveler 8.0.1
ibm lotus_notes_traveler 8.0.1.3
ibm lotus_notes_traveler 8.5.0.1
ibm lotus_notes_traveler *
ibm lotus_notes_traveler 8.0.1.2
CVE-2010-4553 MEDIUM

An unspecified Domino API in IBM Lotus Notes Traveler before 8.5.1.1 does not properly handle MIME types, which allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm lotus_notes_traveler 8.0
ibm lotus_notes_traveler 8.5.0.0
ibm lotus_notes_traveler 8.0.1
ibm lotus_notes_traveler 8.0.1.3
ibm lotus_notes_traveler 8.5.0.1
ibm lotus_notes_traveler *
ibm lotus_notes_traveler 8.0.1.2
CVE-2010-4589 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM ENOVIA 6 allows remote attackers to inject arbitrary web script or HTML via vectors related to the emxFramework.FilterParameterPattern property.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm enovia 6
CVE-2010-4590 MEDIUM

Cross-site scripting (XSS) vulnerability in HTTP Access Services (HTTP-AS) in the Connection Manager in IBM Lotus Mobile Connect (LMC) before 6.1.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm lotus_mobile_connect *
ibm lotus_mobile_connect 6.1.1.1
ibm lotus_mobile_connect 6.1.2
ibm lotus_mobile_connect 6.1.1
CVE-2010-4591 MEDIUM

The Connection Manager in IBM Lotus Mobile Connect (LMC) before 6.1.4, when HTTP Access Services (HTTP-AS) is enabled, does not delete LTPA tokens in response to use of the iNotes Logoff button, which might allow physically proximate attackers to obtain access via an unattended client, related to a cookie domain mismatch.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm lotus_mobile_connect *
ibm lotus_mobile_connect 6.1.1.1
ibm lotus_mobile_connect 6.1.2
ibm lotus_mobile_connect 6.1.1
CVE-2010-4592 MEDIUM

The Mobile Network Connections functionality in the Connection Manager in IBM Lotus Mobile Connect before 6.1.4, when HTTP Access Services (HTTP-AS) is enabled, does not properly handle failed attempts at establishing HTTP-TCP sessions, which allows remote attackers to cause a denial of service (memory consumption and daemon crash) by making many TCP connection attempts.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm lotus_mobile_connect *
ibm lotus_mobile_connect 6.1.1.1
ibm lotus_mobile_connect 6.1.2
ibm lotus_mobile_connect 6.1.1
CVE-2010-4593 MEDIUM

The Connection Manager in IBM Lotus Mobile Connect before 6.1.4 does not properly maintain a certain reference count, which allows remote authenticated users to cause a denial of service (IP address exhaustion) by making invalid attempts to establish sessions with the same VPN ID from multiple devices.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm lotus_mobile_connect *
ibm lotus_mobile_connect 6.1.1.1
ibm lotus_mobile_connect 6.1.2
ibm lotus_mobile_connect 6.1.1
CVE-2010-4594 MEDIUM

The Connection Manager in IBM Lotus Mobile Connect before 6.1.4, when HTTP Access Services (HTTP-AS) is enabled, does not properly process TCP connection requests, which allows remote attackers to cause a denial of service (memory consumption and HTTP-AS hang) by making many connection requests that trigger "queue size delta errors," related to a "timing hole" issue.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm lotus_mobile_connect *
ibm lotus_mobile_connect 6.1.1.1
ibm lotus_mobile_connect 6.1.2
ibm lotus_mobile_connect 6.1.1
CVE-2010-4595 MEDIUM

The Connection Manager in IBM Lotus Mobile Connect before 6.1.4 disables the http.device.stanza blacklisting functionality for HTTP Access Services (HTTP-AS), which allows remote attackers to bypass intended access restrictions via an HTTP request that contains a disallowed User-Agent header.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm lotus_mobile_connect *
ibm lotus_mobile_connect 6.1.1.1
ibm lotus_mobile_connect 6.1.2
ibm lotus_mobile_connect 6.1.1
CVE-2010-4600 MEDIUM

Dojo Toolkit, as used in the Web client in IBM Rational ClearQuest 7.1.1.x before 7.1.1.4 and 7.1.2.x before 7.1.2.1, allows remote attackers to read cookies by navigating to a Dojo file, related to an "open direct" issue.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
dojofoundation dojo_toolkit *
ibm rational_clearquest 7.1.1.1
ibm rational_clearquest 7.1.1.3
ibm rational_clearquest 7.1.2
ibm rational_clearquest 7.1.1.2
CVE-2010-4601 HIGH

Multiple unspecified vulnerabilities in IBM Rational ClearQuest 7.0.x before 7.0.1.11, 7.1.1.x before 7.1.1.4, and 7.1.2.x before 7.1.2.1 allow attackers to have an unknown impact via vectors related to third-party .ocx files.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm rational_clearquest 7.0.0.4
ibm rational_clearquest 7.0.0.5
ibm rational_clearquest 7.1.2
ibm rational_clearquest 7.0.1.6
ibm rational_clearquest 7.0.0.0
ibm rational_clearquest 7.0.1.4
ibm rational_clearquest 7.0.1.1
ibm rational_clearquest 7.1.1.1
ibm rational_clearquest 7.1.1.3
ibm rational_clearquest 7.0.1
ibm rational_clearquest 7.0.1.8
ibm rational_clearquest 7.0.0.2
ibm rational_clearquest 7.0.0.7
ibm rational_clearquest 7.0.1.7
ibm rational_clearquest 7.0.1.9
ibm rational_clearquest 7.0.1.10
ibm rational_clearquest 7.0
ibm rational_clearquest 7.0.0.6
ibm rational_clearquest 7.0.0.9
ibm rational_clearquest 7.0.0.1
ibm rational_clearquest 7.0.0.8
ibm rational_clearquest 7.0.1.3
ibm rational_clearquest 7.0.1.2
ibm rational_clearquest 7.0.1.0
ibm rational_clearquest 7.0.1.5
ibm rational_clearquest 7.0.0.3
ibm rational_clearquest 7.1.1.2
CVE-2010-4602 MEDIUM

The Web client in IBM Rational ClearQuest 7.1.1.x before 7.1.1.4 and 7.1.2.x before 7.1.2.1 allows remote authenticated users to bypass "restricted user" limitations, and read arbitrary records, via a modified record number in the URL for a RECORD action, as demonstrated by a modified bookmark.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm rational_clearquest 7.1.1.1
ibm rational_clearquest 7.1.1.3
ibm rational_clearquest 7.1.2
ibm rational_clearquest 7.1.1.2
CVE-2010-4603 MEDIUM

IBM Rational ClearQuest 7.0.x before 7.0.1.11, 7.1.1.x before 7.1.1.4, and 7.1.2.x before 7.1.2.1 does not prevent modification of back-reference fields, which allows remote authenticated users to interfere with intended record relationships, and possibly cause a denial of service (loop) or have unspecified other impact, by (1) adding or (2) removing a back reference.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm rational_clearquest 7.0.0.4
ibm rational_clearquest 7.0.0.5
ibm rational_clearquest 7.1.2
ibm rational_clearquest 7.0.1.6
ibm rational_clearquest 7.0.0.0
ibm rational_clearquest 7.0.1.4
ibm rational_clearquest 7.0.1.1
ibm rational_clearquest 7.1.1.1
ibm rational_clearquest 7.1.1.3
ibm rational_clearquest 7.0.1
ibm rational_clearquest 7.0.1.8
ibm rational_clearquest 7.0.0.2
ibm rational_clearquest 7.0.0.7
ibm rational_clearquest 7.0.1.7
ibm rational_clearquest 7.0.1.9
ibm rational_clearquest 7.0.1.10
ibm rational_clearquest 7.0
ibm rational_clearquest 7.0.0.6
ibm rational_clearquest 7.0.0.9
ibm rational_clearquest 7.0.0.1
ibm rational_clearquest 7.0.0.8
ibm rational_clearquest 7.0.1.3
ibm rational_clearquest 7.0.1.2
ibm rational_clearquest 7.0.1.0
ibm rational_clearquest 7.0.1.5
ibm rational_clearquest 7.0.0.3
ibm rational_clearquest 7.1.1.2
CVE-2010-4604 HIGH

Stack-based buffer overflow in the GeneratePassword function in dsmtca (aka the Trusted Communications Agent or TCA) in the backup-archive client in IBM Tivoli Storage Manager (TSM) 5.3.x before 5.3.6.10, 5.4.x before 5.4.3.4, 5.5.x before 5.5.2.10, and 6.1.x before 6.1.3.1 on Unix and Linux allows local users to gain privileges by specifying a long LANG environment variable, and then sending a request over a pipe.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-787,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager *
CVE-2010-4605 MEDIUM

Unspecified vulnerability in the backup-archive client in IBM Tivoli Storage Manager (TSM) 5.3.x before 5.3.6.10, 5.4.x before 5.4.3.4, 5.5.x before 5.5.3, 6.1.x before 6.1.4, and 6.2.x before 6.2.2 on Unix and Linux allows local users to overwrite arbitrary files via unknown vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager 5.3.6.4
ibm tivoli_storage_manager 6.1.0
ibm tivoli_storage_manager 5.4.2
ibm tivoli_storage_manager 5.3.1
ibm tivoli_storage_manager 5.4.1
ibm tivoli_storage_manager 5.3.4
ibm tivoli_storage_manager 5.3.6.6
ibm tivoli_storage_manager 6.1.2
ibm tivoli_storage_manager 6.1.1
ibm tivoli_storage_manager 5.3.6.3
ibm tivoli_storage_manager 5.3.0
ibm tivoli_storage_manager 5.4.2.2
ibm tivoli_storage_manager 5.3.6.1
ibm tivoli_storage_manager 5.3.6.2
ibm tivoli_storage_manager 6.2.0
ibm tivoli_storage_manager 5.3.2
ibm tivoli_storage_manager 5.5.1
ibm tivoli_storage_manager 5.3.5.1
ibm tivoli_storage_manager 5.3.3
ibm tivoli_storage_manager 5.4.0
ibm tivoli_storage_manager 5.4.2.4
ibm tivoli_storage_manager 5.4.2.3
ibm tivoli_storage_manager 5.5.0
ibm tivoli_storage_manager 6.1.3
ibm tivoli_storage_manager 5.3.6.5
ibm tivoli_storage_manager 5.5.2
ibm tivoli_storage_manager 5.3.2.4
ibm tivoli_storage_manager 6.2.1
CVE-2010-4606 HIGH

Unspecified vulnerability in the Space Management client in the Hierarchical Storage Management (HSM) component in IBM Tivoli Storage Manager (TSM) 5.4.x before 5.4.3.4, 5.5.x before 5.5.3, 6.1.x before 6.1.4, and 6.2.x before 6.2.2 on Unix and Linux allows remote attackers to execute arbitrary commands via unknown vectors, related to a "script execution vulnerability."

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager *
CVE-2010-4622 MEDIUM

Directory traversal vulnerability in WebSEAL in IBM Tivoli Access Manager for e-business 6.1.1 before 6.1.1-TIV-AWS-FP0001 on AIX allows remote attackers to read arbitrary files via a %uff0e%uff0e (encoded dot dot) in a URI.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm tivoli_access_manager_for_e-business 6.1.1
CVE-2010-4623 MEDIUM

WebSEAL in IBM Tivoli Access Manager for e-business 6.1.1 before 6.1.1-TIV-AWS-FP0001 allows remote authenticated users to cause a denial of service (worker thread consumption) via shift-reload actions.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm tivoli_access_manager_for_e-business 6.1.1
CVE-2010-4785 MEDIUM

The do_extendedOp function in ibmslapd in IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.62 (aka 6.0.0.8-TIV-ITDS-IF0004) on Linux, Solaris, and Windows allows remote authenticated users to cause a denial of service (ABEND) via a malformed LDAP extended operation that triggers certain comparisons involving the NULL operation OID.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm tivoli_directory_server 6.0.0.19
ibm tivoli_directory_server 6.0.0.41
ibm tivoli_directory_server 6.0.0.58
ibm tivoli_directory_server 6.0.0.60
ibm tivoli_directory_server 6.0.0.45
ibm tivoli_directory_server 6.0.0.57
ibm tivoli_directory_server 6.0.0.54
ibm tivoli_directory_server 6.0.0.1
ibm tivoli_directory_server 6.0.0.7
ibm tivoli_directory_server 6.0.0.0
ibm tivoli_directory_server 6.0.0.61
ibm tivoli_directory_server 6.0.0.8
ibm tivoli_directory_server 6.0
ibm tivoli_directory_server 6.0.0.59
ibm tivoli_directory_server 6.0.0.52
ibm tivoli_directory_server 6.0.0.14
ibm tivoli_directory_server 6.0.0.56
ibm tivoli_directory_server 6.0.0.55
ibm tivoli_directory_server 6.0.0.33
ibm tivoli_directory_server 6.0.0.53
CVE-2010-4786 MEDIUM

IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.63 (aka 6.0.0.8-TIV-ITDS-IF0005) allows remote authenticated users to cause a denial of service (daemon crash or hang) via a paged search, as demonstrated by a certain idsldapsearch command, related to an improper ibm-slapdIdleTimeOut configuration setting.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm tivoli_directory_server 6.0.0.19
ibm tivoli_directory_server 6.0.0.41
ibm tivoli_directory_server 6.0.0.58
ibm tivoli_directory_server 6.0.0.60
ibm tivoli_directory_server 6.0.0.45
ibm tivoli_directory_server 6.0.0.57
ibm tivoli_directory_server 6.0.0.54
ibm tivoli_directory_server 6.0.0.1
ibm tivoli_directory_server 6.0.0.7
ibm tivoli_directory_server 6.0.0.0
ibm tivoli_directory_server 6.0.0.61
ibm tivoli_directory_server 6.0.0.8
ibm tivoli_directory_server 6.0
ibm tivoli_directory_server 6.0.0.62
ibm tivoli_directory_server 6.0.0.59
ibm tivoli_directory_server 6.0.0.52
ibm tivoli_directory_server 6.0.0.14
ibm tivoli_directory_server 6.0.0.56
ibm tivoli_directory_server 6.0.0.55
ibm tivoli_directory_server 6.0.0.33
ibm tivoli_directory_server 6.0.0.53
CVE-2010-4787 MEDIUM

IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.63 (aka 6.0.0.8-TIV-ITDS-IF0005) allows remote authenticated users to cause a denial of service (daemon hang) via a paged search that triggers improper mutex processing.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm tivoli_directory_server 6.0.0.19
ibm tivoli_directory_server 6.0.0.41
ibm tivoli_directory_server 6.0.0.58
ibm tivoli_directory_server 6.0.0.60
ibm tivoli_directory_server 6.0.0.45
ibm tivoli_directory_server 6.0.0.57
ibm tivoli_directory_server 6.0.0.54
ibm tivoli_directory_server 6.0.0.1
ibm tivoli_directory_server 6.0.0.7
ibm tivoli_directory_server 6.0.0.0
ibm tivoli_directory_server 6.0.0.61
ibm tivoli_directory_server 6.0.0.8
ibm tivoli_directory_server 6.0
ibm tivoli_directory_server 6.0.0.62
ibm tivoli_directory_server 6.0.0.59
ibm tivoli_directory_server 6.0.0.52
ibm tivoli_directory_server 6.0.0.14
ibm tivoli_directory_server 6.0.0.56
ibm tivoli_directory_server 6.0.0.55
ibm tivoli_directory_server 6.0.0.33
ibm tivoli_directory_server 6.0.0.53
CVE-2010-4788 MEDIUM

IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.62 (aka 6.0.0.8-TIV-ITDS-IF0004) does not perform certain locking of linked-list access, which allows remote authenticated users to cause a denial of service (daemon crash) via a paged search.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm tivoli_directory_server 6.0.0.19
ibm tivoli_directory_server 6.0.0.41
ibm tivoli_directory_server 6.0.0.58
ibm tivoli_directory_server 6.0.0.60
ibm tivoli_directory_server 6.0.0.45
ibm tivoli_directory_server 6.0.0.57
ibm tivoli_directory_server 6.0.0.54
ibm tivoli_directory_server 6.0.0.1
ibm tivoli_directory_server 6.0.0.7
ibm tivoli_directory_server 6.0.0.0
ibm tivoli_directory_server 6.0.0.61
ibm tivoli_directory_server 6.0.0.8
ibm tivoli_directory_server 6.0
ibm tivoli_directory_server 6.0.0.59
ibm tivoli_directory_server 6.0.0.52
ibm tivoli_directory_server 6.0.0.14
ibm tivoli_directory_server 6.0.0.56
ibm tivoli_directory_server 6.0.0.55
ibm tivoli_directory_server 6.0.0.33
ibm tivoli_directory_server 6.0.0.53
CVE-2010-4789 MEDIUM

Use-after-free vulnerability in the proxy-server implementation in IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.65 (aka 6.0.0.8-TIV-ITDS-IF0007) and 6.3 before 6.3.0.1 (aka 6.3.0.0-TIV-ITDS-IF0001) allows remote authenticated users to cause a denial of service (daemon crash) via a paged search that is interrupted by an LDAP Unbind operation.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm tivoli_directory_server 6.0.0.41
ibm tivoli_directory_server 6.0.0.7
ibm tivoli_directory_server 6.0
ibm tivoli_directory_server 6.0.0.62
ibm tivoli_directory_server 6.0.0.52
ibm tivoli_directory_server 6.0.0.14
ibm tivoli_directory_server 6.0.0.56
ibm tivoli_directory_server 6.0.0.55
ibm tivoli_directory_server 6.3.0.0
ibm tivoli_directory_server 6.0.0.63
ibm tivoli_directory_server 6.0.0.53
ibm tivoli_directory_server 6.0.0.19
ibm tivoli_directory_server 6.0.0.58
ibm tivoli_directory_server 6.0.0.60
ibm tivoli_directory_server 6.0.0.45
ibm tivoli_directory_server 6.0.0.57
ibm tivoli_directory_server 6.0.0.54
ibm tivoli_directory_server 6.0.0.64
ibm tivoli_directory_server 6.0.0.1
ibm tivoli_directory_server 6.0.0.0
ibm tivoli_directory_server 6.0.0.61
ibm tivoli_directory_server 6.0.0.8
ibm tivoli_directory_server 6.0.0.59
ibm tivoli_directory_server 6.0.0.33
CVE-2010-4806 MEDIUM

The authoring tool in IBM Web Content Manager (WCM) 6.1.5, and 7.0.0.1 before CF003, allows remote authenticated users to bypass intended access restrictions on draft creation by leveraging certain resource editor privileges.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm web_content_manager 7.0.01
ibm web_content_manager 6.1.5
CVE-2010-4807 LOW

Race condition in IBM Web Content Manager (WCM) 7.0.0.1 before CF003 allows remote authenticated users to cause a denial of service (infinite recursive query) via unspecified vectors, related to a StackOverflowError exception.

CVSS 2.0

Severity: LOW

Problem Type: CWE-362,

Products Affected

Vendor Product Version
ibm web_content_manager 7.0.0.1
CVE-2010-5204 MEDIUM

Multiple untrusted search path vulnerabilities in IBM Lotus Symphony 1.3.0 20090908.0900 allow local users to gain privileges via a Trojan horse (1) eclipse_1114.dll or (2) emser645mi.dll file in the current working directory, as demonstrated by a directory that contains a .odm, .odt, .otp, .stc, .stw, .sxg, or .sxw file. NOTE: some of these details are obtained from third party information.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_symphony 1.3.0.20090908.0900
CVE-2010-5251 MEDIUM

Multiple untrusted search path vulnerabilities in IBM Lotus Notes 8.5 allow local users to gain privileges via a Trojan horse (1) nnoteswc.dll or (2) nlsxbe.dll file in the current working directory, as demonstrated by a directory that contains a .vcf, .vcs, or .ics file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_notes 8.5
CVE-2011-0310 MEDIUM

Buffer overflow in IBM WebSphere MQ 7.0 before 7.0.1.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted header field in a message.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm websphere_mq 7.0.1.2
ibm websphere_mq 7.0.1.0
ibm websphere_mq 7.0.0.2
ibm websphere_mq 7.0.0.1
ibm websphere_mq 7.0.1.1
ibm websphere_mq 7.0
ibm websphere_mq 7.0.1.3
CVE-2011-0311 LOW

The class file parser in IBM Java before 1.4.2 SR13 FP9, as used in IBM Runtimes for Java Technology 5.0.0 before SR13 and 6.0.0 before SR10, allows remote authenticated users to cause a denial of service (JVM segmentation fault, and possibly memory consumption or an infinite loop) via a crafted attribute length field in a class file, which triggers a buffer over-read.

CVSS 2.0

Severity: LOW

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm runtimes_for_java_technology *
ibm java 1.4.2.13.2
ibm java 1.4.2.13.3
ibm java *
ibm runtimes_for_java_technology 5.0.12.3
ibm runtimes_for_java_technology 5.0.11.0
ibm java 1.4.2
ibm runtimes_for_java_technology 5.0.0
ibm runtimes_for_java_technology 6.0.8.1
ibm java 1.4.2.13.6
ibm java 1.4.2.13
ibm java 1.4.2.13.7
ibm runtimes_for_java_technology 6.0.6.0
ibm java 1.4.2.13.1
ibm runtimes_for_java_technology 5.0.12.2
ibm runtimes_for_java_technology 6.0.4.0
ibm java 1.4.2.13.5
ibm runtimes_for_java_technology 5.0.11.2
ibm runtimes_for_java_technology 6.0.7.0
ibm runtimes_for_java_technology 6.0.8.0
ibm runtimes_for_java_technology 5.0.12.1
ibm runtimes_for_java_technology 6.0.3.0
ibm java 1.4.2.13.4
ibm runtimes_for_java_technology 6.0.1.0
ibm runtimes_for_java_technology 5.0.12.0
ibm runtimes_for_java_technology 6.0.0
ibm runtimes_for_java_technology 6.0.5.0
ibm runtimes_for_java_technology 5.0.11.1
ibm runtimes_for_java_technology 6.0.2.0
CVE-2011-0314 MEDIUM

Heap-based buffer overflow in IBM WebSphere MQ 6.0 before 6.0.2.11 and 7.0 before 7.0.1.5 allows remote authenticated users to execute arbitrary code or cause a denial of service (queue manager crash) by inserting an invalid message into the queue.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm websphere_mq 6.0.2.0
ibm websphere_mq 6.0.2.7
ibm websphere_mq 6.0.2.3
ibm websphere_mq 7.0.1.0
ibm websphere_mq 6.0.2.8
ibm websphere_mq 7.0.0.2
ibm websphere_mq 6.0.2.9
ibm websphere_mq 7.0.1.1
ibm websphere_mq 7.0
ibm websphere_mq 7.0.1.3
ibm websphere_mq 7.0.1
ibm websphere_mq 6.0
ibm websphere_mq 7.0.1.4
ibm websphere_mq 7.0.1.2
ibm websphere_mq 6.0.1.0
ibm websphere_mq 6.0.1.1
ibm websphere_mq 6.0.2.6
ibm websphere_mq 6.0.2.10
ibm websphere_mq 7.0.0.1
ibm websphere_mq 6.0.2.4
ibm websphere_mq 6.0.2.5
ibm websphere_mq 6.0.2.1
ibm websphere_mq 6.0.2.2
CVE-2011-0315 MEDIUM

Cross-site scripting (XSS) vulnerability in the Servlet Engine / Web Container component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.35 and 7.0 before 7.0.0.15 allows remote attackers to inject arbitrary web script or HTML via vectors related to the lack of an error page for an application.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 6.1
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 7.0.0.4
CVE-2011-0316 MEDIUM

The Administrative Console component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.35 and 7.0 before 7.0.0.15 does not properly restrict access to console servlets, which allows remote attackers to obtain potentially sensitive status information via a direct request.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 6.1
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 7.0.0.4
CVE-2011-0486 MEDIUM

Cross-site scripting (XSS) vulnerability in cognos.cgi in IBM Cognos 8 Business Intelligence (BI) 8.4.1 before FP1 allows remote attackers to inject arbitrary web script or HTML via the pathinfo parameter.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm cognos_8_business_intelligence 8.4.1
CVE-2011-0494 MEDIUM

Directory traversal vulnerability in WebSEAL in IBM Tivoli Access Manager for e-business 5.1 before 5.1.0.39-TIV-AWS-IF0040, 6.0 before 6.0.0.25-TIV-AWS-IF0026, 6.1.0 before 6.1.0.5-TIV-AWS-IF0006, and 6.1.1 before 6.1.1-TIV-AWS-FP0001 has unspecified impact and attack vectors. NOTE: this might overlap CVE-2010-4622.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm tivoli_access_manager_for_e-business 6.0.0.23
ibm tivoli_access_manager_for_e-business 6.1.1
ibm tivoli_access_manager_for_e-business 5.1
ibm tivoli_access_manager_for_e-business 6.1.0
ibm tivoli_access_manager_for_e-business 6.1.0.3
ibm tivoli_access_manager_for_e-business 6.0.0
ibm tivoli_access_manager_for_e-business 6.1.0.4
ibm tivoli_access_manager_for_e-business 5.1.0.10
ibm tivoli_access_manager_for_e-business 6.0.0.17
CVE-2011-0637 MEDIUM

The FC SCSI protocol driver in IBM AIX 6.1 does not verify that a timer is unused before deallocating this timer, which might allow attackers to cause a denial of service (system crash) via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm aix 6.1
CVE-2011-0679 MEDIUM

IBM WebSphere Portal 6.0.1.1 through 7.0.0.0, as used in IBM Lotus Web Content Management (WCM) and IBM Lotus Quickr for WebSphere Portal, allows remote attackers to obtain sensitive information via a "modified message."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_portal 6.0.1.4
ibm websphere_portal 6.1.0.3
ibm websphere_portal 6.0.1.1
ibm websphere_portal 6.1.0.2
ibm websphere_portal 6.0.1.6
ibm websphere_portal 6.0.1.2
ibm websphere_portal 6.0.1.3
ibm websphere_portal 6.0.1.5
ibm websphere_portal 6.1.5.0
ibm websphere_portal 6.0.1.7
ibm websphere_portal 7.0.0.0
ibm websphere_portal 6.1.0.1
ibm websphere_portal 6.1.0.0
CVE-2011-0731 HIGH

Buffer overflow in the DB2 Administration Server (DAS) component in IBM DB2 9.1 before FP10, 9.5 before FP7, and 9.7 before FP3 on Linux, UNIX, and Windows allows remote attackers to execute arbitrary code via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm db2 9.1
ibm db2 9.5
ibm db2 *
ibm db2 9.7
CVE-2011-0732 HIGH

Multiple unspecified vulnerabilities in IBM Tivoli Integrated Portal (TIP) 1.1.1.1, as used in IBM Tivoli Common Reporting (TCR) 1.2.0 before Interim Fix 9, have unknown impact and attack vectors, related to "security vulnerabilities of Websphere Application Server bundled within" and "many internal defects and APARs."

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm tivoli_integrated_portal 1.1.1.1
ibm tivoli_common_reporting 1.2.0
CVE-2011-0757 MEDIUM

IBM DB2 9.1 before FP10, 9.5 before FP6a, and 9.7 before FP2 on Linux, UNIX, and Windows does not properly revoke the DBADM authority, which allows remote authenticated users to execute non-DDL statements by leveraging previous possession of this authority.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm db2 9.1
ibm db2 9.5
ibm db2 *
ibm db2 9.7
CVE-2011-0912 HIGH

Argument injection vulnerability in IBM Lotus Notes 8.0.x before 8.0.2 FP6 and 8.5.x before 8.5.1 FP5 allows remote attackers to execute arbitrary code via a cai:// URL containing a --launcher.library option that specifies a UNC share pathname for a DLL file, aka SPR PRAD82YJW2.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm lotus_notes 8.0.2.1
ibm lotus_notes 8.0.2.5
ibm lotus_notes 8.5.1.1
ibm lotus_notes 8.0.2.3
ibm lotus_notes 8.5.1.4
ibm lotus_notes 8.5.1.2
ibm lotus_notes 8.5.1.3
ibm lotus_notes 8.0.1
ibm lotus_notes 8.5.0.0
ibm lotus_notes 8.0.2.2
ibm lotus_notes 8.0.2.4
ibm lotus_notes 8.5.0.1
ibm lotus_notes 8.5.1.0
ibm lotus_notes 8.0
ibm lotus_notes 8.0.2.0
ibm lotus_notes 8.0.2
CVE-2011-0913 HIGH

Stack-based buffer overflow in ndiiop.exe in the DIIOP implementation in the server in IBM Lotus Domino before 8.5.3 allows remote attackers to execute arbitrary code via a GIOP getEnvironmentString request, related to the local variable cache.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm lotus_domino 6.5.1
ibm lotus_domino 6.0.5
ibm lotus_domino 6.5.4.3
ibm lotus_domino 8.0.2.3
ibm lotus_domino 7.0.3.1
ibm lotus_domino 8.5.1.4
ibm lotus_domino 8.0.2.4
ibm lotus_domino 8.0.2
ibm lotus_domino 6.5.4.2
ibm lotus_domino 6.5.5
ibm lotus_domino 5.0.10
ibm lotus_domino 5.0.9
ibm lotus_domino 5.0.8a
ibm lotus_domino 6.5.3
ibm lotus_domino 6.5.2.1
ibm lotus_domino 8.5.1.2
ibm lotus_domino 8.0.2.2
ibm lotus_domino 8.5.2
ibm lotus_domino 8.0.2.6
ibm lotus_domino 5.0.2
ibm lotus_domino 6.5.4
ibm lotus_domino 7.0.2
ibm lotus_domino 5.0.5
ibm lotus_domino 5.0.8
ibm lotus_domino 6.0
ibm lotus_domino 6.0.2_cf2
ibm lotus_domino 7.0.4.1
ibm lotus_domino 5.0.4a
ibm lotus_domino 6.0.1.2
ibm lotus_domino 5.0.1
ibm lotus_domino 6.5.0
ibm lotus_domino 6.0.4
ibm lotus_domino 7.0.1
ibm lotus_domino 7.0.4
ibm lotus_domino 8.0.2.1
ibm lotus_domino 6.0.1.1
ibm lotus_domino 6.0.3
ibm lotus_domino 6.5.6
ibm lotus_domino 5.0
ibm lotus_domino 6.0.2.2
ibm lotus_domino 5.0.6
ibm lotus_domino 5.0.7
ibm lotus_domino 6.0.2.1
ibm lotus_domino 6.0.1.3
ibm lotus_domino 7.0.2.3
ibm lotus_domino 5.0.9a
ibm lotus_domino 7.0.2.2
ibm lotus_domino 8.5.1.1
ibm lotus_domino *
ibm lotus_domino 6.5.3.1
ibm lotus_domino 7.0.1.1
ibm lotus_domino 8.5.1
ibm lotus_domino 6.5.4.1
ibm lotus_domino 6.0.1
ibm lotus_domino 7.0.4.2
ibm lotus_domino 5.0.3
ibm lotus_domino 8.5.1.3
ibm lotus_domino 5.0.7a
ibm lotus_domino 8.5.1.5
ibm lotus_domino 4.6.4
ibm lotus_domino 7.0
ibm lotus_domino 6.5
ibm lotus_domino 8.0.1
ibm lotus_domino 8.0.2.5
ibm lotus_domino 7.0.2.1
ibm lotus_domino 5.0.11
ibm lotus_domino 6.5.2
ibm lotus_domino 5.0.6a
ibm lotus_domino 4.6.3
ibm lotus_domino 6.0.2
ibm lotus_domino 8.5.2.1
ibm lotus_domino 4.6.1
ibm lotus_domino 5.0.4
ibm lotus_domino 7.0.3
CVE-2011-0914 HIGH

Integer signedness error in ndiiop.exe in the DIIOP implementation in the server in IBM Lotus Domino before 8.5.3 allows remote attackers to execute arbitrary code via a GIOP client request, leading to a heap-based buffer overflow.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-189,

Products Affected

Vendor Product Version
ibm lotus_domino 6.5.1
ibm lotus_domino 6.0.5
ibm lotus_domino 6.5.4.3
ibm lotus_domino 8.0.2.3
ibm lotus_domino 7.0.3.1
ibm lotus_domino 8.5.1.4
ibm lotus_domino 8.0.2.4
ibm lotus_domino 8.0.2
ibm lotus_domino 6.5.4.2
ibm lotus_domino 6.5.5
ibm lotus_domino 5.0.10
ibm lotus_domino 5.0.9
ibm lotus_domino 5.0.8a
ibm lotus_domino 6.5.3
ibm lotus_domino 6.5.2.1
ibm lotus_domino 8.5.1.2
ibm lotus_domino 8.0.2.2
ibm lotus_domino 8.5.2
ibm lotus_domino 8.0.2.6
ibm lotus_domino 5.0.2
ibm lotus_domino 6.5.4
ibm lotus_domino 7.0.2
ibm lotus_domino 5.0.5
ibm lotus_domino 5.0.8
ibm lotus_domino 6.0
ibm lotus_domino 6.0.2_cf2
ibm lotus_domino 7.0.4.1
ibm lotus_domino 5.0.4a
ibm lotus_domino 6.0.1.2
ibm lotus_domino 5.0.1
ibm lotus_domino 6.5.0
ibm lotus_domino 6.0.4
ibm lotus_domino 7.0.1
ibm lotus_domino 7.0.4
ibm lotus_domino 8.0.2.1
ibm lotus_domino 6.0.1.1
ibm lotus_domino 6.0.3
ibm lotus_domino 6.5.6
ibm lotus_domino 5.0
ibm lotus_domino 6.0.2.2
ibm lotus_domino 5.0.6
ibm lotus_domino 5.0.7
ibm lotus_domino 6.0.2.1
ibm lotus_domino 6.0.1.3
ibm lotus_domino 7.0.2.3
ibm lotus_domino 5.0.9a
ibm lotus_domino 7.0.2.2
ibm lotus_domino 8.5.1.1
ibm lotus_domino *
ibm lotus_domino 6.5.3.1
ibm lotus_domino 7.0.1.1
ibm lotus_domino 8.5.1
ibm lotus_domino 6.5.4.1
ibm lotus_domino 6.0.1
ibm lotus_domino 7.0.4.2
ibm lotus_domino 5.0.3
ibm lotus_domino 8.5.1.3
ibm lotus_domino 5.0.7a
ibm lotus_domino 8.5.1.5
ibm lotus_domino 4.6.4
ibm lotus_domino 7.0
ibm lotus_domino 6.5
ibm lotus_domino 8.0.1
ibm lotus_domino 8.0.2.5
ibm lotus_domino 7.0.2.1
ibm lotus_domino 5.0.11
ibm lotus_domino 6.5.2
ibm lotus_domino 5.0.6a
ibm lotus_domino 4.6.3
ibm lotus_domino 6.0.2
ibm lotus_domino 8.5.2.1
ibm lotus_domino 4.6.1
ibm lotus_domino 5.0.4
ibm lotus_domino 7.0.3
CVE-2011-0915 HIGH

Stack-based buffer overflow in nrouter.exe in IBM Lotus Domino before 8.5.3 allows remote attackers to execute arbitrary code via a long name parameter in a Content-Type header in a malformed Notes calendar (aka iCalendar or iCal) meeting request, aka SPR KLYH87LL23.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm lotus_domino 6.5.1
ibm lotus_domino 6.0.5
ibm lotus_domino 6.5.4.3
ibm lotus_domino 8.0.2.3
ibm lotus_domino 7.0.3.1
ibm lotus_domino 8.5.1.4
ibm lotus_domino 8.0.2.4
ibm lotus_domino 8.0.2
ibm lotus_domino 6.5.4.2
ibm lotus_domino 6.5.5
ibm lotus_domino 5.0.10
ibm lotus_domino 5.0.9
ibm lotus_domino 5.0.8a
ibm lotus_domino 6.5.3
ibm lotus_domino 6.5.2.1
ibm lotus_domino 8.5.1.2
ibm lotus_domino 8.0.2.2
ibm lotus_domino 8.5.2
ibm lotus_domino 8.0.2.6
ibm lotus_domino 5.0.2
ibm lotus_domino 6.5.4
ibm lotus_domino 7.0.2
ibm lotus_domino 5.0.5
ibm lotus_domino 5.0.8
ibm lotus_domino 6.0
ibm lotus_domino 6.0.2_cf2
ibm lotus_domino 7.0.4.1
ibm lotus_domino 5.0.4a
ibm lotus_domino 6.0.1.2
ibm lotus_domino 5.0.1
ibm lotus_domino 6.5.0
ibm lotus_domino 6.0.4
ibm lotus_domino 7.0.1
ibm lotus_domino 7.0.4
ibm lotus_domino 8.0.2.1
ibm lotus_domino 6.0.1.1
ibm lotus_domino 6.0.3
ibm lotus_domino 6.5.6
ibm lotus_domino 5.0
ibm lotus_domino 6.0.2.2
ibm lotus_domino 5.0.6
ibm lotus_domino 5.0.7
ibm lotus_domino 6.0.2.1
ibm lotus_domino 6.0.1.3
ibm lotus_domino 7.0.2.3
ibm lotus_domino 5.0.9a
ibm lotus_domino 7.0.2.2
ibm lotus_domino 8.5.1.1
ibm lotus_domino *
ibm lotus_domino 6.5.3.1
ibm lotus_domino 7.0.1.1
ibm lotus_domino 8.5.1
ibm lotus_domino 6.5.4.1
ibm lotus_domino 6.0.1
ibm lotus_domino 7.0.4.2
ibm lotus_domino 5.0.3
ibm lotus_domino 8.5.1.3
ibm lotus_domino 5.0.7a
ibm lotus_domino 8.5.1.5
ibm lotus_domino 4.6.4
ibm lotus_domino 7.0
ibm lotus_domino 6.5
ibm lotus_domino 8.0.1
ibm lotus_domino 8.0.2.5
ibm lotus_domino 7.0.2.1
ibm lotus_domino 5.0.11
ibm lotus_domino 6.5.2
ibm lotus_domino 5.0.6a
ibm lotus_domino 4.6.3
ibm lotus_domino 6.0.2
ibm lotus_domino 8.5.2.1
ibm lotus_domino 4.6.1
ibm lotus_domino 5.0.4
ibm lotus_domino 7.0.3
CVE-2011-0916 HIGH

Stack-based buffer overflow in the SMTP service in IBM Lotus Domino allows remote attackers to execute arbitrary code via long arguments in a filename parameter in a malformed MIME e-mail message, aka SPR KLYH889M8H.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm lotus_domino *
CVE-2011-0917 HIGH

Buffer overflow in nLDAP.exe in IBM Lotus Domino allows remote attackers to execute arbitrary code via a long string in an LDAP Bind operation, aka SPR KLYH87LMVX.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm lotus_domino *
CVE-2011-0918 HIGH

Stack-based buffer overflow in the NRouter (aka Router) service in IBM Lotus Domino allows remote attackers to execute arbitrary code via long filenames associated with Content-ID and ATTACH:CID headers in attachments in malformed calendar-request e-mail messages, aka SPR KLYH87LKRE.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm lotus_domino *
CVE-2011-0919 HIGH

Multiple stack-based buffer overflows in the (1) POP3 and (2) IMAP services in IBM Lotus Domino allow remote attackers to execute arbitrary code via non-printable characters in an envelope sender address, aka SPR KLYH87LLVJ.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm lotus_domino *
CVE-2011-0920 HIGH

The Remote Console in IBM Lotus Domino, when a certain unsupported configuration involving UNC share pathnames is used, allows remote attackers to bypass authentication and execute arbitrary code via unspecified vectors, aka SPR PRAD89WGRS.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm lotus_domino *
CVE-2011-1029 LOW

Cross-site scripting (XSS) vulnerability in IBM Rational Team Concert (RTC) 2.0.0.x allows remote authenticated users to inject arbitrary web script or HTML via the name of a shared report.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_team_concert 2.0.0.2
ibm rational_team_concert 2.0.0.1
CVE-2011-1030 MEDIUM

Cross-site scripting (XSS) vulnerability in the Wikis component in IBM Lotus Connections 3.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to the "Confirm New Page scene."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm lotus_connections 3.0
CVE-2011-1032 MEDIUM

IBM Lotus Connections 3.0, when IBM WebSphere Application Server 7.0.0.11 is used, does not properly restrict access to the internal login module, which has unspecified impact and attack vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm lotus_connections 3.0
CVE-2011-1033 HIGH

Stack-based buffer overflow in oninit in IBM Informix Dynamic Server (IDS) 11.50 allows remote attackers to execute arbitrary code via crafted arguments in the USELASTCOMMITTED session environment option in a SQL SET ENVIRONMENT statement.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm informix_dynamic_server 11.50
CVE-2011-1034 MEDIUM

Cross-site scripting (XSS) vulnerability in the UI in IBM Rational Build Forge 7.0.2 allows remote attackers to inject arbitrary web script or HTML via the mod parameter to the fullcontrol program. NOTE: some of these details are obtained from third party information.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_build_forge 7.0.2
CVE-2011-1038 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in stconf.nsf in the server in IBM Lotus Sametime 8.0.1 allow remote attackers to inject arbitrary web script or HTML via (1) the messageString parameter in a WebMessage action or (2) the PATH_INFO.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm lotus_sametime 8.0.1
CVE-2011-1045 MEDIUM

Unspecified vulnerability in the Rendition Engine (aka P8RE) 4.0.1 through 4.5.1 in IBM FileNet P8 Content Manager (CM) allows remote attackers to gain privileges via unknown vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm filenet_p8_rendition_engine 4.5.0
ibm filenet_p8_rendition_engine 4.0.1
ibm filenet_p8_rendition_engine 4.5.1
ibm filenet_p8_content_manager *
CVE-2011-1046 MEDIUM

IBM FileNet P8 Content Engine (aka P8CE) 4.0.1 through 5.0.0, as used in FileNet P8 Content Manager (CM) and FileNet P8 Business Process Manager (BPM), does not require the PRIVILEGED_WRITE access role for all intended Object Store modifications, which allows remote attackers to change a privileged property of an object via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm filenet_p8_content_engine 4.5.1.5
ibm filenet_p8_content_engine 4.5.1.3
ibm filenet_p8_content_engine 4.0.1
ibm filenet_p8_content_engine 4.0.1.13
ibm filenet_p8_content_engine 4.5.1.6
ibm filenet_p8_content_engine 5.0.0
ibm filenet_p8_content_engine 4.0.1.11
ibm filenet_p8_content_engine 4.0.1.10
ibm filenet_p8_content_engine 4.5.0
ibm filenet_p8_business_process_manager *
ibm filenet_p8_content_engine 4.5.1.4
ibm filenet_p8_content_manager *
ibm filenet_p8_content_engine 4.5.0.2
ibm filenet_p8_content_engine 4.0.1.12
CVE-2011-1106 MEDIUM

Cross-site scripting (XSS) vulnerability in stcenter.nsf in the server in IBM Lotus Sametime allows remote attackers to inject arbitrary web script or HTML via the authReasonCode parameter in an OpenDatabase action.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm lotus_sametime *
ibm lotus_sametime 8.0
ibm lotus_sametime 8.0.1
CVE-2011-1205 MEDIUM

Multiple buffer overflows in unspecified COM objects in Rational Common Licensing 7.0 through 7.1.1.4 in IBM Rational ClearCase 7.0.0.4 through 7.1.1.4, ClearQuest 7.0.0.4 through 7.1.1.4, and other products allow local users to gain privileges via a Trojan horse HTML document in the My Computer zone.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm rational_clearquest 7.0.0.4
ibm rational_clearcase 7.0.0.7
ibm rational_common_licensing 7.1
ibm rational_clearquest 7.0.1.6
ibm rational_clearquest 7.0.1.4
ibm rational_clearcase 7.0.0.9
ibm rational_common_licensing 7.0.0.2
ibm rational_clearcase 7.0.1.1
ibm rational_clearcase 7.0.1
ibm rational_clearquest 7.1.1.1
ibm rational_clearcase 7.0.1.10
ibm rational_common_licensing 7.1.1.2
ibm rational_clearquest 7.1.1.3
ibm rational_clearcase 7.0.0.6
ibm rational_clearquest 7.1
ibm rational_common_licensing 7.0.0.1
ibm rational_common_licensing 7.1.0.2
ibm rational_clearcase 7.1.1.1
ibm rational_clearcase 7.1.1.4
ibm rational_common_licensing 7.1.1
ibm rational_clearcase 7.0.1.7
ibm rational_clearquest 7.0.1.10
ibm rational_clearcase 7.0.0.5
ibm rational_clearquest 7.1.1.4
ibm rational_clearcase 7.0.1.4
ibm rational_clearcase 7.1.1.2
ibm rational_clearquest 7.0.0.8
ibm rational_clearquest 7.1.0.1
ibm rational_clearcase 7.1.1
ibm rational_clearcase 7.0.1.9
ibm rational_clearcase 7.1
ibm rational_clearcase 7.1.1.3
ibm rational_clearcase 7.0.0.8
ibm rational_common_licensing 7.0.1
ibm rational_clearquest 7.0.0.5
ibm rational_clearquest 7.1.0.2
ibm rational_common_licensing 7.1.1.4
ibm rational_clearcase 7.0.1.6
ibm rational_clearcase 7.0.1.3
ibm rational_clearquest 7.0.1.1
ibm rational_clearcase 7.1.0.1
ibm rational_common_licensing 7.0.1.1
ibm rational_clearcase 7.0.0.4
ibm rational_common_licensing 7.1.0.1
ibm rational_clearquest 7.0.1.11
ibm rational_clearquest 7.0.1
ibm rational_clearquest 7.0.1.8
ibm rational_common_licensing 7.0
ibm rational_clearquest 7.0.0.7
ibm rational_clearquest 7.0.1.7
ibm rational_clearquest 7.0.1.9
ibm rational_clearcase 7.0.1.11
ibm rational_clearcase 7.1.0.2
ibm rational_clearquest 7.0.0.6
ibm rational_clearcase 7.0.1.8
ibm rational_clearquest 7.0.0.9
ibm rational_clearquest 7.0.1.3
ibm rational_clearquest 7.0.1.2
ibm rational_clearquest 7.0.1.0
ibm rational_common_licensing 7.0.3.1
ibm rational_clearquest 7.0.1.5
ibm rational_clearcase 7.0.1.2
ibm rational_common_licensing 7.1.1.1
ibm rational_clearcase 7.0.1.5
ibm rational_clearquest 7.1.1.2
ibm rational_common_licensing 7.1.1.3
CVE-2011-1206 HIGH

Stack-based buffer overflow in the server process in ibmslapd.exe in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0010, 6.0 before 6.0.0.67 (aka 6.0.0.8-TIV-ITDS-IF0009), 6.1 before 6.1.0.40 (aka 6.1.0.5-TIV-ITDS-IF0003), 6.2 before 6.2.0.16 (aka 6.2.0.3-TIV-ITDS-IF0002), and 6.3 before 6.3.0.3 (aka 6.3.0.0-TIV-ITDS-IF0003) allows remote attackers to execute arbitrary code via a crafted LDAP request. NOTE: some of these details are obtained from third party information.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm tivoli_directory_server 5.2.0
ibm tivoli_directory_server 6.0.0.41
ibm tivoli_directory_server 6.2.0.8
ibm tivoli_directory_server 6.0.0.7
ibm tivoli_directory_server 6.2.0.15
ibm tivoli_directory_server 6.1.0.9
ibm tivoli_directory_server 6.0.0.52
ibm tivoli_directory_server 6.2.0.13
ibm tivoli_directory_server 6.2.0.6
ibm tivoli_directory_server 6.3.0.1
ibm tivoli_directory_server 6.0.0.14
ibm tivoli_directory_server 6.1.0.24
ibm tivoli_directory_server 6.0.0.56
ibm tivoli_directory_server 6.1.0.29
ibm tivoli_directory_server 6.1.0.36
ibm tivoli_directory_server 6.1.0.14
ibm tivoli_directory_server 6.1.0.35
ibm tivoli_directory_server 6.2.0.1
ibm tivoli_directory_server 6.2.0.12
ibm tivoli_directory_server 6.1.0.2
ibm tivoli_directory_server 6.0.0.60
ibm tivoli_directory_server 6.0.0.57
ibm tivoli_directory_server 6.2.0.7
ibm tivoli_directory_server 6.0.0.64
ibm tivoli_directory_server 6.0.0.1
ibm tivoli_directory_server 6.1.0.30
ibm tivoli_directory_server 6.0.0.8
ibm tivoli_directory_server 6.2.0.2
ibm tivoli_directory_server 6.0.0.65
ibm tivoli_directory_server 6.2.0.10
ibm tivoli_directory_server 6.2.0.5
ibm tivoli_directory_server 6.0.0.33
ibm tivoli_directory_server 6.1.0.23
ibm tivoli_directory_server 6.1.0.3
ibm tivoli_directory_server 6.2.0.0
ibm tivoli_directory_server 6.2.0.11
ibm tivoli_directory_server 6.1.0.8
ibm tivoli_directory_server 6.1.0.28
ibm tivoli_directory_server 6.1.0.19
ibm tivoli_directory_server 6.1.0.34
ibm tivoli_directory_server 6.0
ibm tivoli_directory_server 6.1.0.6
ibm tivoli_directory_server 6.1.0.4
ibm tivoli_directory_server 6.0.0.62
ibm tivoli_directory_server 6.1.0.20
ibm tivoli_directory_server 6.1.0.13
ibm tivoli_directory_server 6.0.0.55
ibm tivoli_directory_server 6.3.0.0
ibm tivoli_directory_server 6.1.0.22
ibm tivoli_directory_server 6.0.0.63
ibm tivoli_directory_server 6.1.0.37
ibm tivoli_directory_server 6.1.0.7
ibm tivoli_directory_server 6.1.0.15
ibm tivoli_directory_server 6.0.0.53
ibm tivoli_directory_server 6.2.0.4
ibm tivoli_directory_server 6.0.0.19
ibm tivoli_directory_server 6.0.0.58
ibm tivoli_directory_server 6.1.0.0
ibm tivoli_directory_server 6.0.0.45
ibm tivoli_directory_server 6.0.0.54
ibm tivoli_directory_server 6.1.0.12
ibm tivoli_directory_server 6.1.0.39
ibm tivoli_directory_server 6.2.0.14
ibm tivoli_directory_server 6.1.0.18
ibm tivoli_directory_server 6.0.0.0
ibm tivoli_directory_server 6.0.0.61
ibm tivoli_directory_server 6.1.0.33
ibm tivoli_directory_server 6.1.0.5
ibm tivoli_directory_server 6.3.0.2
ibm tivoli_directory_server 6.1.0.11
ibm tivoli_directory_server 6.1.0.27
ibm tivoli_directory_server 6.1.0.25
ibm tivoli_directory_server 6.0.0.59
ibm tivoli_directory_server 6.1.0.10
ibm tivoli_directory_server 6.1.0.21
ibm tivoli_directory_server 6.1.0.31
ibm tivoli_directory_server 5.2.0.4
ibm tivoli_directory_server 6.0.0.66
ibm tivoli_directory_server 6.1.0.26
ibm tivoli_directory_server 6.1.0.38
ibm tivoli_directory_server 6.2.0.3
ibm tivoli_directory_server 6.1.0.32
ibm tivoli_directory_server 6.1.0.1
ibm tivoli_directory_server 6.1.0.17
CVE-2011-1207 HIGH

The ActiveBar1 ActiveX control in the Data Dynamics ActiveBar ActiveX controls, as distributed in ActBar.ocx 1.0.6.5 in IBM Rational System Architect 11.4.0.2, 11.4.0.1, and earlier, does not properly restrict the SetLayoutData method, which allows remote attackers to execute arbitrary code via a crafted Data argument, a different vulnerability than CVE-2007-3883. NOTE: some of these details are obtained from third party information.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-863,

Products Affected

Vendor Product Version
ibm rational_system_architect 11.3.1.1
ibm rational_system_architect 11.3.1.2
ibm rational_system_architect 11.4.0.1
ibm rational_system_architect 11.3.1
ibm rational_system_architect 11.4
ibm rational_system_architect *
ibm rational_system_architect 11.3.1.3
ibm rational_system_architect 11.3
CVE-2011-1208 HIGH

IBM solidDB 4.5.x before 4.5.182, 6.0.x before 6.0.1069, 6.1.x and 6.3.x before 6.3 FP8 (aka 6.3.49), and 6.5.x before 6.5 FP4 (aka 6.5.0.4) does not properly handle the (1) rpc_test_svc_readwrite and (2) rpc_test_svc_done commands, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted command.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm soliddb 4.5.181
ibm soliddb 6.3.39
ibm soliddb 4.5.167
ibm soliddb 6.3.38
ibm soliddb 4.5.179
ibm soliddb 6.3.40
ibm soliddb 6.5.0.1
ibm soliddb 6.3.48
ibm soliddb 6.1.20
ibm soliddb 6.1.18
ibm soliddb 4.5.178
ibm soliddb 6.5.0.2
ibm soliddb 4.5.169
ibm soliddb 6.3.33
ibm soliddb 4.5.180
ibm soliddb 6.0.1068
ibm soliddb 6.0.1067
ibm soliddb 6.5.0.0
ibm soliddb 6.3.47
ibm soliddb 6.0.1061
ibm soliddb 6.3.37
ibm soliddb 4.5.168
ibm soliddb 6.5.0.3
ibm soliddb 4.5.176
ibm soliddb 6.0.1064
ibm soliddb 4.5.173
ibm soliddb 6.0.1066
ibm soliddb 6.3.44
ibm soliddb 4.5.175
ibm soliddb 6.0.1065
ibm soliddb 6.0.1060
CVE-2011-1209 MEDIUM

IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.39 and 7.0 before 7.0.0.17 uses a weak WS-Security XML encryption algorithm, which makes it easier for remote attackers to obtain plaintext data from a (1) JAX-RPC or (2) JAX-WS Web Services request via unspecified vectors related to a "decryption attack."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 7.0.0.12
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.1.0.24
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 6.1.0.22
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0
ibm websphere_application_server 6.1.0.35
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 6.1.6
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 7.0.0.10
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.1.0.32
ibm websphere_application_server 6.1.3
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.1.5
ibm websphere_application_server 6.1.14
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.7
ibm websphere_application_server 6.1.0.37
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.1
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.1.13
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 7.0.0.4
CVE-2011-1213 HIGH

Integer underflow in lzhsr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted header in a .lzh attachment that triggers a stack-based buffer overflow, aka SPR PRAD88MJ2W.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-189,

Products Affected

Vendor Product Version
ibm lotus_notes 8.0.2.1
ibm lotus_notes 7.0.3.1
ibm lotus_notes 7.0.4.1
ibm lotus_notes 8.0.0
ibm lotus_notes 6.5.6
ibm lotus_notes 8.5.2.1
ibm lotus_notes 4.6
ibm lotus_notes 8.0.2.4
ibm lotus_notes 7.0.4.2
ibm lotus_notes 8.0
ibm lotus_notes 3.0.0.2
ibm lotus_notes 5.0.7a
ibm lotus_notes 6.0.3
ibm lotus_notes 6.0.5
ibm lotus_notes 8.5.1.1
ibm lotus_notes 5.0.2b
ibm lotus_notes 5.0.6
ibm lotus_notes 5.0.8
ibm lotus_notes 8.5.1.2
ibm lotus_notes 8.5.0.0
ibm lotus_notes 5.0
ibm lotus_notes 5.0.5.01
ibm lotus_notes 3.0.0.1
ibm lotus_notes 6.0.4
ibm lotus_notes 8.0.2
ibm lotus_notes 5.0.12
ibm lotus_notes 6.5.3.1
ibm lotus_notes 8.5.1.5
ibm lotus_notes 5.02
ibm lotus_notes 5.0.6a.01
ibm lotus_notes 8.5.2.0
ibm lotus_notes 4.2.1
ibm lotus_notes 5.0.7
ibm lotus_notes 6.5.6.3
ibm lotus_notes 6.5
ibm lotus_notes 4.6.7a
ibm lotus_notes 5.0.4
ibm lotus_notes 6.5.3
ibm lotus_notes 8.5.0.1
ibm lotus_notes 6.5.5.2
ibm lotus_notes 4.2
ibm lotus_notes 7.0.2.1
ibm lotus_notes 5.0a
ibm lotus_notes 4.6.7h
ibm lotus_notes 8.5.1.3
ibm lotus_notes 5.0.5.02
ibm lotus_notes 6.5.4
ibm lotus_notes 6.0
ibm lotus_notes 6.5.6.1
ibm lotus_notes 6.5.4.2
ibm lotus_notes 6.0.2
ibm lotus_notes 8.0.2.3
ibm lotus_notes 8.5.1.4
ibm lotus_notes 7.0.2
ibm lotus_notes 4.2.2
ibm lotus_notes 6.5.2
ibm lotus_notes 8.0.1
ibm lotus_notes 5.0.1a
ibm lotus_notes 8.0.2.2
ibm lotus_notes 6.5.5.3
ibm lotus_notes 8.0.2.0
ibm lotus_notes 5.0.3
ibm lotus_notes 7.0.4
ibm lotus_notes 6.5.6.2
ibm lotus_notes 5.0.2
ibm lotus_notes 5.0.1.02
ibm lotus_notes 5.0.6a
ibm lotus_notes 5.0.9a
ibm lotus_notes 8.0.2.5
ibm lotus_notes 3.0
ibm lotus_notes 6.5.4.1
ibm lotus_notes 8.5.1
ibm lotus_notes 6.0.1
ibm lotus_notes 5.0.11
ibm lotus_notes 6.5.1
ibm lotus_notes 6.5.5
ibm lotus_notes 7.0.1
ibm lotus_notes 8.5.1.0
ibm lotus_notes 8.0.2.6
ibm lotus_notes 5.0.5
ibm lotus_notes 5.0.9
ibm lotus_notes 7.0.1.1
ibm lotus_notes 5.0.1
ibm lotus_notes 7.0.0
ibm lotus_notes 7.0.2.3
ibm lotus_notes 4.5
ibm lotus_notes *
ibm lotus_notes 5.0.10
ibm lotus_notes 6.0.2.2
ibm lotus_notes 6.5.4.3
ibm lotus_notes 7.0.3
ibm lotus_notes 7.0
ibm lotus_notes 5.0.1b
ibm lotus_notes 6.5.5.1
ibm lotus_notes 5.0.2a
ibm lotus_notes 7.0.2.2
ibm lotus_notes 5.0.1c
ibm lotus_notes 5.0.2c
ibm lotus_notes 7.0.4.0
ibm lotus_notes 8.5
ibm lotus_notes 5.0.4a
CVE-2011-1214 HIGH

Stack-based buffer overflow in rtfsr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted link in a .rtf attachment, aka SPR PRAD8823JQ.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm lotus_notes 8.0.2.1
ibm lotus_notes 7.0.3.1
ibm lotus_notes 7.0.4.1
ibm lotus_notes 8.0.0
ibm lotus_notes 6.5.6
ibm lotus_notes 8.5.2.1
ibm lotus_notes 4.6
ibm lotus_notes 8.0.2.4
ibm lotus_notes 7.0.4.2
ibm lotus_notes 8.0
ibm lotus_notes 3.0.0.2
ibm lotus_notes 5.0.7a
ibm lotus_notes 6.0.3
ibm lotus_notes 6.0.5
ibm lotus_notes 8.5.1.1
ibm lotus_notes 5.0.2b
ibm lotus_notes 5.0.6
ibm lotus_notes 5.0.8
ibm lotus_notes 8.5.1.2
ibm lotus_notes 8.5.0.0
ibm lotus_notes 5.0
ibm lotus_notes 5.0.5.01
ibm lotus_notes 3.0.0.1
ibm lotus_notes 6.0.4
ibm lotus_notes 8.0.2
ibm lotus_notes 5.0.12
ibm lotus_notes 6.5.3.1
ibm lotus_notes 8.5.1.5
ibm lotus_notes 5.02
ibm lotus_notes 5.0.6a.01
ibm lotus_notes 8.5.2.0
ibm lotus_notes 4.2.1
ibm lotus_notes 5.0.7
ibm lotus_notes 6.5.6.3
ibm lotus_notes 6.5
ibm lotus_notes 4.6.7a
ibm lotus_notes 5.0.4
ibm lotus_notes 6.5.3
ibm lotus_notes 8.5.0.1
ibm lotus_notes 6.5.5.2
ibm lotus_notes 4.2
ibm lotus_notes 7.0.2.1
ibm lotus_notes 5.0a
ibm lotus_notes 4.6.7h
ibm lotus_notes 8.5.1.3
ibm lotus_notes 5.0.5.02
ibm lotus_notes 6.5.4
ibm lotus_notes 6.0
ibm lotus_notes 6.5.6.1
ibm lotus_notes 6.5.4.2
ibm lotus_notes 6.0.2
ibm lotus_notes 8.0.2.3
ibm lotus_notes 8.5.1.4
ibm lotus_notes 7.0.2
ibm lotus_notes 4.2.2
ibm lotus_notes 6.5.2
ibm lotus_notes 8.0.1
ibm lotus_notes 5.0.1a
ibm lotus_notes 8.0.2.2
ibm lotus_notes 6.5.5.3
ibm lotus_notes 8.0.2.0
ibm lotus_notes 5.0.3
ibm lotus_notes 7.0.4
ibm lotus_notes 6.5.6.2
ibm lotus_notes 5.0.2
ibm lotus_notes 5.0.1.02
ibm lotus_notes 5.0.6a
ibm lotus_notes 5.0.9a
ibm lotus_notes 8.0.2.5
ibm lotus_notes 3.0
ibm lotus_notes 6.5.4.1
ibm lotus_notes 8.5.1
ibm lotus_notes 6.0.1
ibm lotus_notes 5.0.11
ibm lotus_notes 6.5.1
ibm lotus_notes 6.5.5
ibm lotus_notes 7.0.1
ibm lotus_notes 8.5.1.0
ibm lotus_notes 8.0.2.6
ibm lotus_notes 5.0.5
ibm lotus_notes 5.0.9
ibm lotus_notes 7.0.1.1
ibm lotus_notes 5.0.1
ibm lotus_notes 7.0.0
ibm lotus_notes 7.0.2.3
ibm lotus_notes 4.5
ibm lotus_notes *
ibm lotus_notes 5.0.10
ibm lotus_notes 6.0.2.2
ibm lotus_notes 6.5.4.3
ibm lotus_notes 7.0.3
ibm lotus_notes 7.0
ibm lotus_notes 5.0.1b
ibm lotus_notes 6.5.5.1
ibm lotus_notes 5.0.2a
ibm lotus_notes 7.0.2.2
ibm lotus_notes 5.0.1c
ibm lotus_notes 5.0.2c
ibm lotus_notes 7.0.4.0
ibm lotus_notes 8.5
ibm lotus_notes 5.0.4a
CVE-2011-1215 HIGH

Stack-based buffer overflow in mw8sr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted link in a Microsoft Office document attachment, aka SPR PRAD8823ND.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm lotus_notes 8.0.2.1
ibm lotus_notes 8.5.1.5
ibm lotus_notes 7.0.3.1
ibm lotus_notes 7.0.4.1
ibm lotus_notes 7.0.1.1
ibm lotus_notes 8.5.2.0
ibm lotus_notes 8.0.0
ibm lotus_notes 8.0.2.3
ibm lotus_notes 8.5.1.4
ibm lotus_notes 7.0.2
ibm lotus_notes 7.0.0
ibm lotus_notes 8.5.2.1
ibm lotus_notes 8.0.1
ibm lotus_notes 7.0.2.3
ibm lotus_notes 8.0.2.2
ibm lotus_notes *
ibm lotus_notes 8.0.2.4
ibm lotus_notes 8.5.0.1
ibm lotus_notes 7.0.4.2
ibm lotus_notes 8.0
ibm lotus_notes 8.0.2.0
ibm lotus_notes 7.0.4
ibm lotus_notes 8.0.2.5
ibm lotus_notes 8.5.1.1
ibm lotus_notes 7.0.3
ibm lotus_notes 7.0.2.1
ibm lotus_notes 7.0
ibm lotus_notes 8.5.1
ibm lotus_notes 8.5.1.2
ibm lotus_notes 8.5.1.3
ibm lotus_notes 8.5.0.0
ibm lotus_notes 7.0.1
ibm lotus_notes 8.5.1.0
ibm lotus_notes 7.0.2.2
ibm lotus_notes 8.0.2.6
ibm lotus_notes 8.5
ibm lotus_notes 8.0.2
CVE-2011-1216 HIGH

Stack-based buffer overflow in assr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via crafted tag data in an Applix spreadsheet attachment, aka SPR PRAD8823A7.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm lotus_notes 8.0.2.1
ibm lotus_notes 7.0.3.1
ibm lotus_notes 7.0.4.1
ibm lotus_notes 8.0.0
ibm lotus_notes 6.5.6
ibm lotus_notes 8.5.2.1
ibm lotus_notes 4.6
ibm lotus_notes 8.0.2.4
ibm lotus_notes 7.0.4.2
ibm lotus_notes 8.0
ibm lotus_notes 3.0.0.2
ibm lotus_notes 5.0.7a
ibm lotus_notes 6.0.3
ibm lotus_notes 6.0.5
ibm lotus_notes 8.5.1.1
ibm lotus_notes 5.0.2b
ibm lotus_notes 5.0.6
ibm lotus_notes 5.0.8
ibm lotus_notes 8.5.1.2
ibm lotus_notes 8.5.0.0
ibm lotus_notes 5.0
ibm lotus_notes 5.0.5.01
ibm lotus_notes 3.0.0.1
ibm lotus_notes 6.0.4
ibm lotus_notes 8.0.2
ibm lotus_notes 5.0.12
ibm lotus_notes 6.5.3.1
ibm lotus_notes 8.5.1.5
ibm lotus_notes 5.02
ibm lotus_notes 5.0.6a.01
ibm lotus_notes 8.5.2.0
ibm lotus_notes 4.2.1
ibm lotus_notes 5.0.7
ibm lotus_notes 6.5.6.3
ibm lotus_notes 6.5
ibm lotus_notes 4.6.7a
ibm lotus_notes 5.0.4
ibm lotus_notes 6.5.3
ibm lotus_notes 8.5.0.1
ibm lotus_notes 6.5.5.2
ibm lotus_notes 4.2
ibm lotus_notes 7.0.2.1
ibm lotus_notes 5.0a
ibm lotus_notes 4.6.7h
ibm lotus_notes 8.5.1.3
ibm lotus_notes 5.0.5.02
ibm lotus_notes 6.5.4
ibm lotus_notes 6.0
ibm lotus_notes 6.5.6.1
ibm lotus_notes 6.5.4.2
ibm lotus_notes 6.0.2
ibm lotus_notes 8.0.2.3
ibm lotus_notes 8.5.1.4
ibm lotus_notes 7.0.2
ibm lotus_notes 4.2.2
ibm lotus_notes 6.5.2
ibm lotus_notes 8.0.1
ibm lotus_notes 5.0.1a
ibm lotus_notes 8.0.2.2
ibm lotus_notes 6.5.5.3
ibm lotus_notes 8.0.2.0
ibm lotus_notes 5.0.3
ibm lotus_notes 7.0.4
ibm lotus_notes 6.5.6.2
ibm lotus_notes 5.0.2
ibm lotus_notes 5.0.1.02
ibm lotus_notes 5.0.6a
ibm lotus_notes 5.0.9a
ibm lotus_notes 8.0.2.5
ibm lotus_notes 3.0
ibm lotus_notes 6.5.4.1
ibm lotus_notes 8.5.1
ibm lotus_notes 6.0.1
ibm lotus_notes 5.0.11
ibm lotus_notes 6.5.1
ibm lotus_notes 6.5.5
ibm lotus_notes 7.0.1
ibm lotus_notes 8.5.1.0
ibm lotus_notes 8.0.2.6
ibm lotus_notes 5.0.5
ibm lotus_notes 5.0.9
ibm lotus_notes 7.0.1.1
ibm lotus_notes 5.0.1
ibm lotus_notes 7.0.0
ibm lotus_notes 7.0.2.3
ibm lotus_notes 4.5
ibm lotus_notes *
ibm lotus_notes 5.0.10
ibm lotus_notes 6.0.2.2
ibm lotus_notes 6.5.4.3
ibm lotus_notes 7.0.3
ibm lotus_notes 7.0
ibm lotus_notes 5.0.1b
ibm lotus_notes 6.5.5.1
ibm lotus_notes 5.0.2a
ibm lotus_notes 7.0.2.2
ibm lotus_notes 5.0.1c
ibm lotus_notes 5.0.2c
ibm lotus_notes 7.0.4.0
ibm lotus_notes 8.5
ibm lotus_notes 5.0.4a
CVE-2011-1217 HIGH

Buffer overflow in kpprzrdr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted .prz attachment. NOTE: some of these details are obtained from third party information.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm lotus_notes 8.0.2.1
ibm lotus_notes 7.0.3.1
ibm lotus_notes 7.0.4.1
ibm lotus_notes 8.0.0
ibm lotus_notes 6.5.6
ibm lotus_notes 8.5.2.1
ibm lotus_notes 4.6
ibm lotus_notes 8.0.2.4
ibm lotus_notes 7.0.4.2
ibm lotus_notes 8.0
ibm lotus_notes 3.0.0.2
ibm lotus_notes 5.0.7a
ibm lotus_notes 6.0.3
ibm lotus_notes 6.0.5
ibm lotus_notes 8.5.1.1
ibm lotus_notes 5.0.2b
ibm lotus_notes 5.0.6
ibm lotus_notes 5.0.8
ibm lotus_notes 8.5.1.2
ibm lotus_notes 8.5.0.0
ibm lotus_notes 5.0
ibm lotus_notes 5.0.5.01
ibm lotus_notes 3.0.0.1
ibm lotus_notes 6.0.4
ibm lotus_notes 8.0.2
ibm lotus_notes 5.0.12
ibm lotus_notes 6.5.3.1
ibm lotus_notes 8.5.1.5
ibm lotus_notes 5.02
ibm lotus_notes 5.0.6a.01
ibm lotus_notes 8.5.2.0
ibm lotus_notes 4.2.1
ibm lotus_notes 5.0.7
ibm lotus_notes 6.5.6.3
ibm lotus_notes 6.5
ibm lotus_notes 4.6.7a
ibm lotus_notes 5.0.4
ibm lotus_notes 6.5.3
ibm lotus_notes 8.5.0.1
ibm lotus_notes 6.5.5.2
ibm lotus_notes 4.2
ibm lotus_notes 7.0.2.1
ibm lotus_notes 5.0a
ibm lotus_notes 4.6.7h
ibm lotus_notes 8.5.1.3
ibm lotus_notes 5.0.5.02
ibm lotus_notes 6.5.4
ibm lotus_notes 6.0
ibm lotus_notes 6.5.6.1
ibm lotus_notes 6.5.4.2
ibm lotus_notes 6.0.2
ibm lotus_notes 8.0.2.3
ibm lotus_notes 8.5.1.4
ibm lotus_notes 7.0.2
ibm lotus_notes 4.2.2
ibm lotus_notes 6.5.2
ibm lotus_notes 8.0.1
ibm lotus_notes 5.0.1a
ibm lotus_notes 8.0.2.2
ibm lotus_notes 6.5.5.3
ibm lotus_notes 8.0.2.0
ibm lotus_notes 5.0.3
ibm lotus_notes 7.0.4
ibm lotus_notes 6.5.6.2
ibm lotus_notes 5.0.2
ibm lotus_notes 5.0.1.02
ibm lotus_notes 5.0.6a
ibm lotus_notes 5.0.9a
ibm lotus_notes 8.0.2.5
ibm lotus_notes 3.0
ibm lotus_notes 6.5.4.1
ibm lotus_notes 8.5.1
ibm lotus_notes 6.0.1
ibm lotus_notes 5.0.11
ibm lotus_notes 6.5.1
ibm lotus_notes 6.5.5
ibm lotus_notes 7.0.1
ibm lotus_notes 8.5.1.0
ibm lotus_notes 8.0.2.6
ibm lotus_notes 5.0.5
ibm lotus_notes 5.0.9
ibm lotus_notes 7.0.1.1
ibm lotus_notes 5.0.1
ibm lotus_notes 7.0.0
ibm lotus_notes 7.0.2.3
ibm lotus_notes 4.5
ibm lotus_notes *
ibm lotus_notes 5.0.10
ibm lotus_notes 6.0.2.2
ibm lotus_notes 6.5.4.3
ibm lotus_notes 7.0.3
ibm lotus_notes 7.0
ibm lotus_notes 5.0.1b
ibm lotus_notes 6.5.5.1
ibm lotus_notes 5.0.2a
ibm lotus_notes 7.0.2.2
ibm lotus_notes 5.0.1c
ibm lotus_notes 5.0.2c
ibm lotus_notes 7.0.4.0
ibm lotus_notes 8.5
ibm lotus_notes 5.0.4a
CVE-2011-1218 HIGH

Buffer overflow in kvarcve.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted .zip attachment, aka SPR PRAD8E3NSP. NOTE: some of these details are obtained from third party information.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm lotus_notes 8.0.2.1
ibm lotus_notes 7.0.3.1
ibm lotus_notes 7.0.4.1
ibm lotus_notes 8.0.0
autonomy keyview *
ibm lotus_notes 6.5.6
ibm lotus_notes 8.5.2.1
ibm lotus_notes 4.6
ibm lotus_notes 8.0.2.4
ibm lotus_notes 7.0.4.2
ibm lotus_notes 8.0
ibm lotus_notes 3.0.0.2
ibm lotus_notes 5.0.7a
ibm lotus_notes 6.0.3
ibm lotus_notes 6.0.5
ibm lotus_notes 8.5.1.1
ibm lotus_notes 5.0.2b
ibm lotus_notes 5.0.6
ibm lotus_notes 5.0.8
ibm lotus_notes 8.5.1.2
ibm lotus_notes 8.5.0.0
ibm lotus_notes 5.0
ibm lotus_notes 5.0.5.01
ibm lotus_notes 3.0.0.1
ibm lotus_notes 6.0.4
ibm lotus_notes 8.0.2
ibm lotus_notes 5.0.12
ibm lotus_notes 6.5.3.1
ibm lotus_notes 8.5.1.5
ibm lotus_notes 5.02
ibm lotus_notes 5.0.6a.01
ibm lotus_notes 8.5.2.0
ibm lotus_notes 4.2.1
ibm lotus_notes 5.0.7
ibm lotus_notes 6.5.6.3
ibm lotus_notes 6.5
ibm lotus_notes 4.6.7a
ibm lotus_notes 5.0.4
ibm lotus_notes 6.5.3
ibm lotus_notes 8.5.0.1
ibm lotus_notes 6.5.5.2
ibm lotus_notes 4.2
ibm lotus_notes 7.0.2.1
ibm lotus_notes 5.0a
ibm lotus_notes 4.6.7h
ibm lotus_notes 8.5.1.3
ibm lotus_notes 5.0.5.02
ibm lotus_notes 6.5.4
ibm lotus_notes 6.0
ibm lotus_notes 6.5.6.1
ibm lotus_notes 6.5.4.2
ibm lotus_notes 6.0.2
ibm lotus_notes 8.0.2.3
ibm lotus_notes 8.5.1.4
ibm lotus_notes 7.0.2
ibm lotus_notes 4.2.2
ibm lotus_notes 6.5.2
ibm lotus_notes 8.0.1
ibm lotus_notes 5.0.1a
ibm lotus_notes 8.0.2.2
ibm lotus_notes 6.5.5.3
ibm lotus_notes 8.0.2.0
ibm lotus_notes 5.0.3
ibm lotus_notes 7.0.4
ibm lotus_notes 6.5.6.2
ibm lotus_notes 5.0.2
ibm lotus_notes 5.0.1.02
ibm lotus_notes 5.0.6a
ibm lotus_notes 5.0.9a
ibm lotus_notes 8.0.2.5
ibm lotus_notes 3.0
ibm lotus_notes 6.5.4.1
ibm lotus_notes 8.5.1
ibm lotus_notes 6.0.1
ibm lotus_notes 5.0.11
ibm lotus_notes 6.5.1
ibm lotus_notes 6.5.5
ibm lotus_notes 7.0.1
ibm lotus_notes 8.5.1.0
ibm lotus_notes 8.0.2.6
ibm lotus_notes 5.0.5
ibm lotus_notes 5.0.9
ibm lotus_notes 7.0.1.1
ibm lotus_notes 5.0.1
ibm lotus_notes 7.0.0
ibm lotus_notes 7.0.2.3
ibm lotus_notes 4.5
ibm lotus_notes *
ibm lotus_notes 5.0.10
ibm lotus_notes 6.0.2.2
ibm lotus_notes 6.5.4.3
ibm lotus_notes 7.0.3
ibm lotus_notes 7.0
ibm lotus_notes 5.0.1b
ibm lotus_notes 6.5.5.1
ibm lotus_notes 5.0.2a
ibm lotus_notes 7.0.2.2
ibm lotus_notes 5.0.1c
ibm lotus_notes 5.0.2c
ibm lotus_notes 7.0.4.0
ibm lotus_notes 8.5
ibm lotus_notes 5.0.4a
CVE-2011-1220 HIGH

Stack-based buffer overflow in lcfd.exe in Tivoli Endpoint in IBM Tivoli Management Framework 3.7.1, 4.1, 4.1.1, and 4.3.1 allows remote authenticated users to execute arbitrary code via a long opts field.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm tivoli_management_framework 4.1
ibm tivoli_management_framework 4.3.1
ibm tivoli_management_framework 3.7.1
ibm tivoli_management_framework 4.1.1
CVE-2011-1222 HIGH

Buffer overflow in the Journal Based Backup (JBB) feature in the backup-archive client in IBM Tivoli Storage Manager (TSM) before 5.4.3.4, 5.5.x before 5.5.3, 6.x before 6.1.4, and 6.2.x before 6.2.2 on Windows and AIX allows local users to gain privileges via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager 5.3.6.4
ibm tivoli_storage_manager 6.1.0
ibm tivoli_storage_manager 5.4.2
ibm tivoli_storage_manager 5.4.3.2
ibm tivoli_storage_manager 5.1.8
ibm tivoli_storage_manager 5.3.1
ibm tivoli_storage_manager 5.4.1
ibm tivoli_storage_manager 5.3.6.6
ibm tivoli_storage_manager 6.1.2
ibm tivoli_storage_manager 6.1.1
ibm tivoli_storage_manager 4.2
ibm tivoli_storage_manager 5.3.6.3
ibm tivoli_storage_manager *
ibm tivoli_storage_manager 5.2.8
ibm tivoli_storage_manager 5.3.0
ibm tivoli_storage_manager 5.2.9
ibm tivoli_storage_manager 5.3.6.1
ibm tivoli_storage_manager 5.2.5.1
ibm tivoli_storage_manager 5.3.6.2
ibm tivoli_storage_manager 6.0
ibm tivoli_storage_manager 6.2.0
ibm tivoli_storage_manager 5.3.2
ibm tivoli_storage_manager 5.5.1
ibm tivoli_storage_manager 5.3.3
ibm tivoli_storage_manager 4.2.1
ibm tivoli_storage_manager 5.5.0
ibm tivoli_storage_manager 6.1.3
ibm tivoli_storage_manager 5.4.3.0
ibm tivoli_storage_manager 5.3.6.5
ibm tivoli_storage_manager 5.5.2
ibm tivoli_storage_manager 5.2.7
ibm tivoli_storage_manager 6.2.1
CVE-2011-1223 HIGH

Buffer overflow in the Alternate Data Stream (aka ADS or named stream) functionality in the backup-archive client in IBM Tivoli Storage Manager (TSM) before 5.4.3.4, 5.5.x before 5.5.3, 6.x before 6.1.4, and 6.2.x before 6.2.2 on Windows allows local users to gain privileges via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager 5.3.6.4
ibm tivoli_storage_manager 6.1.0
ibm tivoli_storage_manager 5.4.2
ibm tivoli_storage_manager 5.4.3.2
ibm tivoli_storage_manager 5.1.8
ibm tivoli_storage_manager 5.3.1
ibm tivoli_storage_manager 5.4.1
ibm tivoli_storage_manager 5.3.6.6
ibm tivoli_storage_manager 6.1.2
ibm tivoli_storage_manager 6.1.1
ibm tivoli_storage_manager 4.2
ibm tivoli_storage_manager 5.3.6.3
ibm tivoli_storage_manager *
ibm tivoli_storage_manager 5.2.8
ibm tivoli_storage_manager 5.3.0
ibm tivoli_storage_manager 5.2.9
ibm tivoli_storage_manager 5.3.6.1
ibm tivoli_storage_manager 5.2.5.1
ibm tivoli_storage_manager 5.3.6.2
ibm tivoli_storage_manager 6.0
ibm tivoli_storage_manager 6.2.0
ibm tivoli_storage_manager 5.3.2
ibm tivoli_storage_manager 5.5.1
ibm tivoli_storage_manager 5.3.3
ibm tivoli_storage_manager 4.2.1
ibm tivoli_storage_manager 5.5.0
ibm tivoli_storage_manager 6.1.3
ibm tivoli_storage_manager 5.4.3.0
ibm tivoli_storage_manager 5.3.6.5
ibm tivoli_storage_manager 5.5.2
ibm tivoli_storage_manager 5.2.7
ibm tivoli_storage_manager 6.2.1
CVE-2011-1224 MEDIUM

IBM WebSphere MQ 6.0 before 6.0.2.11 and 7.0 before 7.0.1.5 does not use the CRL Distribution Points (CDP) certificate extension, which might allow man-in-the-middle attackers to spoof an SSL partner via a revoked certificate for a (1) client, (2) queue manager, or (3) application.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_mq 6.0.2.0
ibm websphere_mq 6.0.2.7
ibm websphere_mq 6.0.2.3
ibm websphere_mq 7.0.1.0
ibm websphere_mq 6.0.2.8
ibm websphere_mq 7.0.0.2
ibm websphere_mq 6.0.2.9
ibm websphere_mq 7.0.1.1
ibm websphere_mq 7.0
ibm websphere_mq 7.0.1.3
ibm websphere_mq 6.0
ibm websphere_mq 7.0.1.4
ibm websphere_mq 7.0.1.2
ibm websphere_mq 6.0.1.0
ibm websphere_mq 6.0.1.1
ibm websphere_mq 6.0.2.6
ibm websphere_mq 6.0.2.10
ibm websphere_mq 7.0.0.1
ibm websphere_mq 6.0.2.4
ibm websphere_mq 6.0.2.5
ibm websphere_mq 6.0.2.1
ibm websphere_mq 6.0.2.2
CVE-2011-1307 LOW

The installer in IBM WebSphere Application Server (WAS) before 7.0.0.15 uses 777 permissions for a temporary log directory, which allows local users to have unintended access to log files via standard filesystem operations, a different vulnerability than CVE-2009-1173.

CVSS 2.0

Severity: LOW

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0
ibm websphere_application_server 6.0.2.19
ibm websphere_application_server 4.0.1
ibm websphere_application_server 6.0.2.7
ibm websphere_application_server 5.0.2.6
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 5.1.1.12
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server *
ibm websphere_application_server 5.1.0.2
ibm websphere_application_server 5.1.1.16
ibm websphere_application_server 6.0.2.25
ibm websphere_application_server 3.0
ibm websphere_application_server 6.0.2.9
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 5.1.1.9
ibm websphere_application_server 5.0.2.2
ibm websphere_application_server 4.0.2
ibm websphere_application_server 6.1.1
ibm websphere_application_server 5.1.1.8
ibm websphere_application_server 5.1.1
ibm websphere_application_server 6.0.2.13
ibm websphere_application_server 6.0.1.11
ibm websphere_application_server 3.0.2
ibm websphere_application_server 3.52
ibm websphere_application_server 5.0.2.4
ibm websphere_application_server 4.0.4
ibm websphere_application_server 5.0.2.15
ibm websphere_application_server 6.0.2.15
ibm websphere_application_server 5.0.2.10
ibm websphere_application_server 6.0.2.4
ibm websphere_application_server 6.1.0
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 6.1
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 5.1.1.11
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 5.0.2.7
ibm websphere_application_server 4.0.3
ibm websphere_application_server 5.0.2.9
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 5.1.1.3
ibm websphere_application_server 5.1.0.3
ibm websphere_application_server 6.0.2.6
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 5.0.2.3
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.0.2.24
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 6.0.2.5
ibm websphere_application_server 3.0.2.4
ibm websphere_application_server 5.1.0
ibm websphere_application_server 5.1.1.17
ibm websphere_application_server 5.0.2.13
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 3.5.3
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.0.1.1
ibm websphere_application_server 6.0.2.1
ibm websphere_application_server 6.1.13
ibm websphere_application_server 3.5.2
ibm websphere_application_server 6.0.1.5
ibm websphere_application_server 6.0.0.1
ibm websphere_application_server 5.1.1.14
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.0.0.2
ibm websphere_application_server 3.5.1
ibm websphere_application_server 3.0.2.2
ibm websphere_application_server 3.0.2.1
ibm websphere_application_server 5.1.1.15
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 6.1.6
ibm websphere_application_server 5.1.1.10
ibm websphere_application_server 6.0.1.2
ibm websphere_application_server 5.0.2.14
ibm websphere_application_server 6.1.3
ibm websphere_application_server 6.0.1.17
ibm websphere_application_server 6.0.1.13
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 5.0.2.16
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 5.0
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 6.0.2.31
ibm websphere_application_server 5.0.2.12
ibm websphere_application_server 6.1.7
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 5.1.1.5
ibm websphere_application_server 6.0.2.22
ibm websphere_application_server 5.0.0
ibm websphere_application_server 6.0
ibm websphere_application_server 5.0.2.8
ibm websphere_application_server 6.0.1.3
ibm websphere_application_server 5.0.2
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 5.1.0.4
ibm websphere_application_server 6.0.2.2
ibm websphere_application_server 6.0.2.11
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 3.5
ibm websphere_application_server 6.0.1.15
ibm websphere_application_server 5.1.1.2
ibm websphere_application_server 5.0.1
ibm websphere_application_server 3.0.2.3
ibm websphere_application_server 5.1.1.6
ibm websphere_application_server 6.0.2.30
ibm websphere_application_server 6.0.2.32
ibm websphere_application_server 2.0
ibm websphere_application_server 5.0.2.11
ibm websphere_application_server 5.0.2.1
ibm websphere_application_server 5.0.2.5
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 5.1.1.7
ibm websphere_application_server 5.1.1.1
ibm websphere_application_server 5.1.1.13
ibm websphere_application_server 6.0.2.23
ibm websphere_application_server 6.0.1
ibm websphere_application_server 6.0.1.7
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.0.2.17
ibm websphere_application_server 6.1.5
ibm websphere_application_server 6.1.14
ibm websphere_application_server 6.0.2.3
ibm websphere_application_server 6.0.2.29
ibm websphere_application_server 6.0.1.9
ibm websphere_application_server 6.0.2
ibm websphere_application_server 6.0.2.28
ibm websphere_application_server 6.0.2.27
ibm websphere_application_server 3.0.21
ibm websphere_application_server 5.1.0.5
ibm websphere_application_server 6.0.0.3
ibm websphere_application_server 5.1.1.4
ibm websphere_application_server 7.0.0.4
CVE-2011-1308 MEDIUM

Cross-site scripting (XSS) vulnerability in the Installation Verification Test (IVT) application in the Install component in IBM WebSphere Application Server (WAS) before 7.0.0.15 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0
ibm websphere_application_server 6.0.2.19
ibm websphere_application_server 4.0.1
ibm websphere_application_server 6.0.2.7
ibm websphere_application_server 5.0.2.6
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 5.1.1.12
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server *
ibm websphere_application_server 5.1.0.2
ibm websphere_application_server 5.1.1.16
ibm websphere_application_server 6.0.2.25
ibm websphere_application_server 3.0
ibm websphere_application_server 6.0.2.9
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 5.1.1.9
ibm websphere_application_server 5.0.2.2
ibm websphere_application_server 4.0.2
ibm websphere_application_server 6.1.1
ibm websphere_application_server 5.1.1.8
ibm websphere_application_server 5.1.1
ibm websphere_application_server 6.0.2.13
ibm websphere_application_server 6.0.1.11
ibm websphere_application_server 3.0.2
ibm websphere_application_server 3.52
ibm websphere_application_server 5.0.2.4
ibm websphere_application_server 4.0.4
ibm websphere_application_server 5.0.2.15
ibm websphere_application_server 6.0.2.15
ibm websphere_application_server 5.0.2.10
ibm websphere_application_server 6.0.2.4
ibm websphere_application_server 6.1.0
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 6.1
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 5.1.1.11
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 5.0.2.7
ibm websphere_application_server 4.0.3
ibm websphere_application_server 5.0.2.9
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 5.1.1.3
ibm websphere_application_server 5.1.0.3
ibm websphere_application_server 6.0.2.6
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 5.0.2.3
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.0.2.24
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 6.0.2.5
ibm websphere_application_server 3.0.2.4
ibm websphere_application_server 5.1.0
ibm websphere_application_server 5.1.1.17
ibm websphere_application_server 5.0.2.13
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 3.5.3
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.0.1.1
ibm websphere_application_server 6.0.2.1
ibm websphere_application_server 6.1.13
ibm websphere_application_server 3.5.2
ibm websphere_application_server 6.0.1.5
ibm websphere_application_server 6.0.0.1
ibm websphere_application_server 5.1.1.14
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.0.0.2
ibm websphere_application_server 3.5.1
ibm websphere_application_server 3.0.2.2
ibm websphere_application_server 3.0.2.1
ibm websphere_application_server 5.1.1.15
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 6.1.6
ibm websphere_application_server 5.1.1.10
ibm websphere_application_server 6.0.1.2
ibm websphere_application_server 5.0.2.14
ibm websphere_application_server 6.1.3
ibm websphere_application_server 6.0.1.17
ibm websphere_application_server 6.0.1.13
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 5.0.2.16
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 5.0
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 6.0.2.31
ibm websphere_application_server 5.0.2.12
ibm websphere_application_server 6.1.7
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 5.1.1.5
ibm websphere_application_server 6.0.2.22
ibm websphere_application_server 5.0.0
ibm websphere_application_server 6.0
ibm websphere_application_server 5.0.2.8
ibm websphere_application_server 6.0.1.3
ibm websphere_application_server 5.0.2
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 5.1.0.4
ibm websphere_application_server 6.0.2.2
ibm websphere_application_server 6.0.2.11
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 3.5
ibm websphere_application_server 6.0.1.15
ibm websphere_application_server 5.1.1.2
ibm websphere_application_server 5.0.1
ibm websphere_application_server 3.0.2.3
ibm websphere_application_server 5.1.1.6
ibm websphere_application_server 6.0.2.30
ibm websphere_application_server 6.0.2.32
ibm websphere_application_server 2.0
ibm websphere_application_server 5.0.2.11
ibm websphere_application_server 5.0.2.1
ibm websphere_application_server 5.0.2.5
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 5.1.1.7
ibm websphere_application_server 5.1.1.1
ibm websphere_application_server 5.1.1.13
ibm websphere_application_server 6.0.2.23
ibm websphere_application_server 6.0.1
ibm websphere_application_server 6.0.1.7
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.0.2.17
ibm websphere_application_server 6.1.5
ibm websphere_application_server 6.1.14
ibm websphere_application_server 6.0.2.3
ibm websphere_application_server 6.0.2.29
ibm websphere_application_server 6.0.1.9
ibm websphere_application_server 6.0.2
ibm websphere_application_server 6.0.2.28
ibm websphere_application_server 6.0.2.27
ibm websphere_application_server 3.0.21
ibm websphere_application_server 5.1.0.5
ibm websphere_application_server 6.0.0.3
ibm websphere_application_server 5.1.1.4
ibm websphere_application_server 7.0.0.4
CVE-2011-1309 HIGH

The Plug-in component in IBM WebSphere Application Server (WAS) before 7.0.0.15 does not properly handle trace requests, which has unspecified impact and attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0
ibm websphere_application_server 6.0.2.19
ibm websphere_application_server 4.0.1
ibm websphere_application_server 6.0.2.7
ibm websphere_application_server 5.0.2.6
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 5.1.1.12
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server *
ibm websphere_application_server 5.1.0.2
ibm websphere_application_server 5.1.1.16
ibm websphere_application_server 6.0.2.25
ibm websphere_application_server 3.0
ibm websphere_application_server 6.0.2.9
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 5.1.1.9
ibm websphere_application_server 5.0.2.2
ibm websphere_application_server 4.0.2
ibm websphere_application_server 6.1.1
ibm websphere_application_server 5.1.1.8
ibm websphere_application_server 5.1.1
ibm websphere_application_server 6.0.2.13
ibm websphere_application_server 6.0.1.11
ibm websphere_application_server 3.0.2
ibm websphere_application_server 3.52
ibm websphere_application_server 5.0.2.4
ibm websphere_application_server 4.0.4
ibm websphere_application_server 5.0.2.15
ibm websphere_application_server 6.0.2.15
ibm websphere_application_server 5.0.2.10
ibm websphere_application_server 6.0.2.4
ibm websphere_application_server 6.1.0
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 6.1
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 5.1.1.11
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 5.0.2.7
ibm websphere_application_server 4.0.3
ibm websphere_application_server 5.0.2.9
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 5.1.1.3
ibm websphere_application_server 5.1.0.3
ibm websphere_application_server 6.0.2.6
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 5.0.2.3
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.0.2.24
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 6.0.2.5
ibm websphere_application_server 3.0.2.4
ibm websphere_application_server 5.1.0
ibm websphere_application_server 5.1.1.17
ibm websphere_application_server 5.0.2.13
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 3.5.3
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.0.1.1
ibm websphere_application_server 6.0.2.1
ibm websphere_application_server 6.1.13
ibm websphere_application_server 3.5.2
ibm websphere_application_server 6.0.1.5
ibm websphere_application_server 6.0.0.1
ibm websphere_application_server 5.1.1.14
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.0.0.2
ibm websphere_application_server 3.5.1
ibm websphere_application_server 3.0.2.2
ibm websphere_application_server 3.0.2.1
ibm websphere_application_server 5.1.1.15
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 6.1.6
ibm websphere_application_server 5.1.1.10
ibm websphere_application_server 6.0.1.2
ibm websphere_application_server 5.0.2.14
ibm websphere_application_server 6.1.3
ibm websphere_application_server 6.0.1.17
ibm websphere_application_server 6.0.1.13
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 5.0.2.16
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 5.0
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 6.0.2.31
ibm websphere_application_server 5.0.2.12
ibm websphere_application_server 6.1.7
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 5.1.1.5
ibm websphere_application_server 6.0.2.22
ibm websphere_application_server 5.0.0
ibm websphere_application_server 6.0
ibm websphere_application_server 5.0.2.8
ibm websphere_application_server 6.0.1.3
ibm websphere_application_server 5.0.2
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 5.1.0.4
ibm websphere_application_server 6.0.2.2
ibm websphere_application_server 6.0.2.11
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 3.5
ibm websphere_application_server 6.0.1.15
ibm websphere_application_server 5.1.1.2
ibm websphere_application_server 5.0.1
ibm websphere_application_server 3.0.2.3
ibm websphere_application_server 5.1.1.6
ibm websphere_application_server 6.0.2.30
ibm websphere_application_server 6.0.2.32
ibm websphere_application_server 2.0
ibm websphere_application_server 5.0.2.11
ibm websphere_application_server 5.0.2.1
ibm websphere_application_server 5.0.2.5
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 5.1.1.7
ibm websphere_application_server 5.1.1.1
ibm websphere_application_server 5.1.1.13
ibm websphere_application_server 6.0.2.23
ibm websphere_application_server 6.0.1
ibm websphere_application_server 6.0.1.7
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.0.2.17
ibm websphere_application_server 6.1.5
ibm websphere_application_server 6.1.14
ibm websphere_application_server 6.0.2.3
ibm websphere_application_server 6.0.2.29
ibm websphere_application_server 6.0.1.9
ibm websphere_application_server 6.0.2
ibm websphere_application_server 6.0.2.28
ibm websphere_application_server 6.0.2.27
ibm websphere_application_server 3.0.21
ibm websphere_application_server 5.1.0.5
ibm websphere_application_server 6.0.0.3
ibm websphere_application_server 5.1.1.4
ibm websphere_application_server 7.0.0.4
CVE-2011-1310 LOW

The Administrative Scripting Tools component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.35 and 7.x before 7.0.0.15, when tracing is enabled, places wsadmin command parameters into the (1) wsadmin.traceout and (2) trace.log files, which allows local users to obtain potentially sensitive information by reading these files.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 7.0.0.4
CVE-2011-1311 MEDIUM

The Security component in IBM WebSphere Application Server (WAS) before 7.0.0.15, when a J2EE 1.4 application is used, determines the security role mapping on the basis of the ibm-application-bnd.xml file instead of the intended ibm-application-bnd.xmi file, which might allow remote authenticated users to gain privileges in opportunistic circumstances by requesting a service.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0
ibm websphere_application_server 6.0.2.19
ibm websphere_application_server 4.0.1
ibm websphere_application_server 6.0.2.7
ibm websphere_application_server 5.0.2.6
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 5.1.1.12
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server *
ibm websphere_application_server 5.1.0.2
ibm websphere_application_server 5.1.1.16
ibm websphere_application_server 6.0.2.25
ibm websphere_application_server 3.0
ibm websphere_application_server 6.0.2.9
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 5.1.1.9
ibm websphere_application_server 5.0.2.2
ibm websphere_application_server 4.0.2
ibm websphere_application_server 6.1.1
ibm websphere_application_server 5.1.1.8
ibm websphere_application_server 5.1.1
ibm websphere_application_server 6.0.2.13
ibm websphere_application_server 6.0.1.11
ibm websphere_application_server 3.0.2
ibm websphere_application_server 3.52
ibm websphere_application_server 5.0.2.4
ibm websphere_application_server 4.0.4
ibm websphere_application_server 5.0.2.15
ibm websphere_application_server 6.0.2.15
ibm websphere_application_server 5.0.2.10
ibm websphere_application_server 6.0.2.4
ibm websphere_application_server 6.1.0
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 6.1
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 5.1.1.11
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 5.0.2.7
ibm websphere_application_server 4.0.3
ibm websphere_application_server 5.0.2.9
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 5.1.1.3
ibm websphere_application_server 5.1.0.3
ibm websphere_application_server 6.0.2.6
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 5.0.2.3
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.0.2.24
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 6.0.2.5
ibm websphere_application_server 3.0.2.4
ibm websphere_application_server 5.1.0
ibm websphere_application_server 5.1.1.17
ibm websphere_application_server 5.0.2.13
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 3.5.3
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.0.1.1
ibm websphere_application_server 6.0.2.1
ibm websphere_application_server 6.1.13
ibm websphere_application_server 3.5.2
ibm websphere_application_server 6.0.1.5
ibm websphere_application_server 6.0.0.1
ibm websphere_application_server 5.1.1.14
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.0.0.2
ibm websphere_application_server 3.5.1
ibm websphere_application_server 3.0.2.2
ibm websphere_application_server 3.0.2.1
ibm websphere_application_server 5.1.1.15
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 6.1.6
ibm websphere_application_server 5.1.1.10
ibm websphere_application_server 6.0.1.2
ibm websphere_application_server 5.0.2.14
ibm websphere_application_server 6.1.3
ibm websphere_application_server 6.0.1.17
ibm websphere_application_server 6.0.1.13
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 5.0.2.16
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 5.0
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 6.0.2.31
ibm websphere_application_server 5.0.2.12
ibm websphere_application_server 6.1.7
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 5.1.1.5
ibm websphere_application_server 6.0.2.22
ibm websphere_application_server 5.0.0
ibm websphere_application_server 6.0
ibm websphere_application_server 5.0.2.8
ibm websphere_application_server 6.0.1.3
ibm websphere_application_server 5.0.2
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 5.1.0.4
ibm websphere_application_server 6.0.2.2
ibm websphere_application_server 6.0.2.11
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 3.5
ibm websphere_application_server 6.0.1.15
ibm websphere_application_server 5.1.1.2
ibm websphere_application_server 5.0.1
ibm websphere_application_server 3.0.2.3
ibm websphere_application_server 5.1.1.6
ibm websphere_application_server 6.0.2.30
ibm websphere_application_server 6.0.2.32
ibm websphere_application_server 2.0
ibm websphere_application_server 5.0.2.11
ibm websphere_application_server 5.0.2.1
ibm websphere_application_server 5.0.2.5
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 5.1.1.7
ibm websphere_application_server 5.1.1.1
ibm websphere_application_server 5.1.1.13
ibm websphere_application_server 6.0.2.23
ibm websphere_application_server 6.0.1
ibm websphere_application_server 6.0.1.7
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.0.2.17
ibm websphere_application_server 6.1.5
ibm websphere_application_server 6.1.14
ibm websphere_application_server 6.0.2.3
ibm websphere_application_server 6.0.2.29
ibm websphere_application_server 6.0.1.9
ibm websphere_application_server 6.0.2
ibm websphere_application_server 6.0.2.28
ibm websphere_application_server 6.0.2.27
ibm websphere_application_server 3.0.21
ibm websphere_application_server 5.1.0.5
ibm websphere_application_server 6.0.0.3
ibm websphere_application_server 5.1.1.4
ibm websphere_application_server 7.0.0.4
CVE-2011-1312 MEDIUM

The Administrative Console component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.31 and 7.x before 7.0.0.15 does not prevent modifications of the primary admin id, which allows remote authenticated administrators to bypass intended access restrictions by mapping a (1) user or (2) group to an administrator role.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 7.0.0.4
CVE-2011-1313 MEDIUM

Double free vulnerability in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.35 and 7.x before 7.0.0.15 allows remote backend IIOP servers to cause a denial of service (S0C4 ABEND and storage corruption) by rejecting IIOP requests at opportunistic time instants, as demonstrated by requests associated with an ORB_Request::getACRWorkElementPtr function call.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 7.0.0.4
CVE-2011-1314 MEDIUM

The Service Integration Bus (SIB) messaging engine in IBM WebSphere Application Server (WAS) before 7.0.0.15 allows remote attackers to cause a denial of service (daemon hang) by performing close operations via network connections to a queue manager.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0
ibm websphere_application_server 6.0.2.19
ibm websphere_application_server 4.0.1
ibm websphere_application_server 6.0.2.7
ibm websphere_application_server 5.0.2.6
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 5.1.1.12
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server *
ibm websphere_application_server 5.1.0.2
ibm websphere_application_server 5.1.1.16
ibm websphere_application_server 6.0.2.25
ibm websphere_application_server 3.0
ibm websphere_application_server 6.0.2.9
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 5.1.1.9
ibm websphere_application_server 5.0.2.2
ibm websphere_application_server 4.0.2
ibm websphere_application_server 6.1.1
ibm websphere_application_server 5.1.1.8
ibm websphere_application_server 5.1.1
ibm websphere_application_server 6.0.2.13
ibm websphere_application_server 6.0.1.11
ibm websphere_application_server 3.0.2
ibm websphere_application_server 3.52
ibm websphere_application_server 5.0.2.4
ibm websphere_application_server 4.0.4
ibm websphere_application_server 5.0.2.15
ibm websphere_application_server 6.0.2.15
ibm websphere_application_server 5.0.2.10
ibm websphere_application_server 6.0.2.4
ibm websphere_application_server 6.1.0
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 6.1
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 5.1.1.11
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 5.0.2.7
ibm websphere_application_server 4.0.3
ibm websphere_application_server 5.0.2.9
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 5.1.1.3
ibm websphere_application_server 5.1.0.3
ibm websphere_application_server 6.0.2.6
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 5.0.2.3
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.0.2.24
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 6.0.2.5
ibm websphere_application_server 3.0.2.4
ibm websphere_application_server 5.1.0
ibm websphere_application_server 5.1.1.17
ibm websphere_application_server 5.0.2.13
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 3.5.3
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.0.1.1
ibm websphere_application_server 6.0.2.1
ibm websphere_application_server 6.1.13
ibm websphere_application_server 3.5.2
ibm websphere_application_server 6.0.1.5
ibm websphere_application_server 6.0.0.1
ibm websphere_application_server 5.1.1.14
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.0.0.2
ibm websphere_application_server 3.5.1
ibm websphere_application_server 3.0.2.2
ibm websphere_application_server 3.0.2.1
ibm websphere_application_server 5.1.1.15
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 6.1.6
ibm websphere_application_server 5.1.1.10
ibm websphere_application_server 6.0.1.2
ibm websphere_application_server 5.0.2.14
ibm websphere_application_server 6.1.3
ibm websphere_application_server 6.0.1.17
ibm websphere_application_server 6.0.1.13
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 5.0.2.16
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 5.0
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 6.0.2.31
ibm websphere_application_server 5.0.2.12
ibm websphere_application_server 6.1.7
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 5.1.1.5
ibm websphere_application_server 6.0.2.22
ibm websphere_application_server 5.0.0
ibm websphere_application_server 6.0
ibm websphere_application_server 5.0.2.8
ibm websphere_application_server 6.0.1.3
ibm websphere_application_server 5.0.2
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 5.1.0.4
ibm websphere_application_server 6.0.2.2
ibm websphere_application_server 6.0.2.11
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 3.5
ibm websphere_application_server 6.0.1.15
ibm websphere_application_server 5.1.1.2
ibm websphere_application_server 5.0.1
ibm websphere_application_server 3.0.2.3
ibm websphere_application_server 5.1.1.6
ibm websphere_application_server 6.0.2.30
ibm websphere_application_server 6.0.2.32
ibm websphere_application_server 2.0
ibm websphere_application_server 5.0.2.11
ibm websphere_application_server 5.0.2.1
ibm websphere_application_server 5.0.2.5
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 5.1.1.7
ibm websphere_application_server 5.1.1.1
ibm websphere_application_server 5.1.1.13
ibm websphere_application_server 6.0.2.23
ibm websphere_application_server 6.0.1
ibm websphere_application_server 6.0.1.7
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.0.2.17
ibm websphere_application_server 6.1.5
ibm websphere_application_server 6.1.14
ibm websphere_application_server 6.0.2.3
ibm websphere_application_server 6.0.2.29
ibm websphere_application_server 6.0.1.9
ibm websphere_application_server 6.0.2
ibm websphere_application_server 6.0.2.28
ibm websphere_application_server 6.0.2.27
ibm websphere_application_server 3.0.21
ibm websphere_application_server 5.1.0.5
ibm websphere_application_server 6.0.0.3
ibm websphere_application_server 5.1.1.4
ibm websphere_application_server 7.0.0.4
CVE-2011-1315 MEDIUM

Memory leak in the messaging engine in IBM WebSphere Application Server (WAS) before 7.0.0.15 allows remote attackers to cause a denial of service (memory consumption) via network connections associated with a NULL return value from a synchronous JMS receive call.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0
ibm websphere_application_server 6.0.2.19
ibm websphere_application_server 4.0.1
ibm websphere_application_server 6.0.2.7
ibm websphere_application_server 5.0.2.6
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 5.1.1.12
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server *
ibm websphere_application_server 5.1.0.2
ibm websphere_application_server 5.1.1.16
ibm websphere_application_server 6.0.2.25
ibm websphere_application_server 3.0
ibm websphere_application_server 6.0.2.9
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 5.1.1.9
ibm websphere_application_server 5.0.2.2
ibm websphere_application_server 4.0.2
ibm websphere_application_server 6.1.1
ibm websphere_application_server 5.1.1.8
ibm websphere_application_server 5.1.1
ibm websphere_application_server 6.0.2.13
ibm websphere_application_server 6.0.1.11
ibm websphere_application_server 3.0.2
ibm websphere_application_server 3.52
ibm websphere_application_server 5.0.2.4
ibm websphere_application_server 4.0.4
ibm websphere_application_server 5.0.2.15
ibm websphere_application_server 6.0.2.15
ibm websphere_application_server 5.0.2.10
ibm websphere_application_server 6.0.2.4
ibm websphere_application_server 6.1.0
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 6.1
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 5.1.1.11
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 5.0.2.7
ibm websphere_application_server 4.0.3
ibm websphere_application_server 5.0.2.9
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 5.1.1.3
ibm websphere_application_server 5.1.0.3
ibm websphere_application_server 6.0.2.6
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 5.0.2.3
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.0.2.24
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 6.0.2.5
ibm websphere_application_server 3.0.2.4
ibm websphere_application_server 5.1.0
ibm websphere_application_server 5.1.1.17
ibm websphere_application_server 5.0.2.13
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 3.5.3
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.0.1.1
ibm websphere_application_server 6.0.2.1
ibm websphere_application_server 6.1.13
ibm websphere_application_server 3.5.2
ibm websphere_application_server 6.0.1.5
ibm websphere_application_server 6.0.0.1
ibm websphere_application_server 5.1.1.14
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.0.0.2
ibm websphere_application_server 3.5.1
ibm websphere_application_server 3.0.2.2
ibm websphere_application_server 3.0.2.1
ibm websphere_application_server 5.1.1.15
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 6.1.6
ibm websphere_application_server 5.1.1.10
ibm websphere_application_server 6.0.1.2
ibm websphere_application_server 5.0.2.14
ibm websphere_application_server 6.1.3
ibm websphere_application_server 6.0.1.17
ibm websphere_application_server 6.0.1.13
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 5.0.2.16
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 5.0
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 6.0.2.31
ibm websphere_application_server 5.0.2.12
ibm websphere_application_server 6.1.7
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 5.1.1.5
ibm websphere_application_server 6.0.2.22
ibm websphere_application_server 5.0.0
ibm websphere_application_server 6.0
ibm websphere_application_server 5.0.2.8
ibm websphere_application_server 6.0.1.3
ibm websphere_application_server 5.0.2
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 5.1.0.4
ibm websphere_application_server 6.0.2.2
ibm websphere_application_server 6.0.2.11
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 3.5
ibm websphere_application_server 6.0.1.15
ibm websphere_application_server 5.1.1.2
ibm websphere_application_server 5.0.1
ibm websphere_application_server 3.0.2.3
ibm websphere_application_server 5.1.1.6
ibm websphere_application_server 6.0.2.30
ibm websphere_application_server 6.0.2.32
ibm websphere_application_server 2.0
ibm websphere_application_server 5.0.2.11
ibm websphere_application_server 5.0.2.1
ibm websphere_application_server 5.0.2.5
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 5.1.1.7
ibm websphere_application_server 5.1.1.1
ibm websphere_application_server 5.1.1.13
ibm websphere_application_server 6.0.2.23
ibm websphere_application_server 6.0.1
ibm websphere_application_server 6.0.1.7
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.0.2.17
ibm websphere_application_server 6.1.5
ibm websphere_application_server 6.1.14
ibm websphere_application_server 6.0.2.3
ibm websphere_application_server 6.0.2.29
ibm websphere_application_server 6.0.1.9
ibm websphere_application_server 6.0.2
ibm websphere_application_server 6.0.2.28
ibm websphere_application_server 6.0.2.27
ibm websphere_application_server 3.0.21
ibm websphere_application_server 5.1.0.5
ibm websphere_application_server 6.0.0.3
ibm websphere_application_server 5.1.1.4
ibm websphere_application_server 7.0.0.4
CVE-2011-1316 MEDIUM

The Session Initiation Protocol (SIP) Proxy in the HTTP Transport component in IBM WebSphere Application Server (WAS) before 7.0.0.15 allows remote attackers to cause a denial of service (worker thread exhaustion and UDP messaging outage) by sending many UDP messages.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0
ibm websphere_application_server 6.0.2.19
ibm websphere_application_server 4.0.1
ibm websphere_application_server 6.0.2.7
ibm websphere_application_server 5.0.2.6
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 5.1.1.12
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server *
ibm websphere_application_server 5.1.0.2
ibm websphere_application_server 5.1.1.16
ibm websphere_application_server 6.0.2.25
ibm websphere_application_server 3.0
ibm websphere_application_server 6.0.2.9
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 5.1.1.9
ibm websphere_application_server 5.0.2.2
ibm websphere_application_server 4.0.2
ibm websphere_application_server 6.1.1
ibm websphere_application_server 5.1.1.8
ibm websphere_application_server 5.1.1
ibm websphere_application_server 6.0.2.13
ibm websphere_application_server 6.0.1.11
ibm websphere_application_server 3.0.2
ibm websphere_application_server 3.52
ibm websphere_application_server 5.0.2.4
ibm websphere_application_server 4.0.4
ibm websphere_application_server 5.0.2.15
ibm websphere_application_server 6.0.2.15
ibm websphere_application_server 5.0.2.10
ibm websphere_application_server 6.0.2.4
ibm websphere_application_server 6.1.0
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 6.1
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 5.1.1.11
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 5.0.2.7
ibm websphere_application_server 4.0.3
ibm websphere_application_server 5.0.2.9
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 5.1.1.3
ibm websphere_application_server 5.1.0.3
ibm websphere_application_server 6.0.2.6
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 5.0.2.3
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.0.2.24
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 6.0.2.5
ibm websphere_application_server 3.0.2.4
ibm websphere_application_server 5.1.0
ibm websphere_application_server 5.1.1.17
ibm websphere_application_server 5.0.2.13
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 3.5.3
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.0.1.1
ibm websphere_application_server 6.0.2.1
ibm websphere_application_server 6.1.13
ibm websphere_application_server 3.5.2
ibm websphere_application_server 6.0.1.5
ibm websphere_application_server 6.0.0.1
ibm websphere_application_server 5.1.1.14
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.0.0.2
ibm websphere_application_server 3.5.1
ibm websphere_application_server 3.0.2.2
ibm websphere_application_server 3.0.2.1
ibm websphere_application_server 5.1.1.15
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 6.1.6
ibm websphere_application_server 5.1.1.10
ibm websphere_application_server 6.0.1.2
ibm websphere_application_server 5.0.2.14
ibm websphere_application_server 6.1.3
ibm websphere_application_server 6.0.1.17
ibm websphere_application_server 6.0.1.13
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 5.0.2.16
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 5.0
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 6.0.2.31
ibm websphere_application_server 5.0.2.12
ibm websphere_application_server 6.1.7
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 5.1.1.5
ibm websphere_application_server 6.0.2.22
ibm websphere_application_server 5.0.0
ibm websphere_application_server 6.0
ibm websphere_application_server 5.0.2.8
ibm websphere_application_server 6.0.1.3
ibm websphere_application_server 5.0.2
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 5.1.0.4
ibm websphere_application_server 6.0.2.2
ibm websphere_application_server 6.0.2.11
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 3.5
ibm websphere_application_server 6.0.1.15
ibm websphere_application_server 5.1.1.2
ibm websphere_application_server 5.0.1
ibm websphere_application_server 3.0.2.3
ibm websphere_application_server 5.1.1.6
ibm websphere_application_server 6.0.2.30
ibm websphere_application_server 6.0.2.32
ibm websphere_application_server 2.0
ibm websphere_application_server 5.0.2.11
ibm websphere_application_server 5.0.2.1
ibm websphere_application_server 5.0.2.5
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 5.1.1.7
ibm websphere_application_server 5.1.1.1
ibm websphere_application_server 5.1.1.13
ibm websphere_application_server 6.0.2.23
ibm websphere_application_server 6.0.1
ibm websphere_application_server 6.0.1.7
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.0.2.17
ibm websphere_application_server 6.1.5
ibm websphere_application_server 6.1.14
ibm websphere_application_server 6.0.2.3
ibm websphere_application_server 6.0.2.29
ibm websphere_application_server 6.0.1.9
ibm websphere_application_server 6.0.2
ibm websphere_application_server 6.0.2.28
ibm websphere_application_server 6.0.2.27
ibm websphere_application_server 3.0.21
ibm websphere_application_server 5.1.0.5
ibm websphere_application_server 6.0.0.3
ibm websphere_application_server 5.1.1.4
ibm websphere_application_server 7.0.0.4
CVE-2011-1317 MEDIUM

Memory leak in com.ibm.ws.jsp.runtime.WASJSPStrBufferImpl in the JavaServer Pages (JSP) component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.37 and 7.x before 7.0.0.15 allows remote attackers to cause a denial of service (memory consumption) by sending many JSP requests that trigger large responses.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0
ibm websphere_application_server 6.1.0.35
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 7.0.0.4
CVE-2011-1318 MEDIUM

Memory leak in org.apache.jasper.runtime.JspWriterImpl.response in the JavaServer Pages (JSP) component in IBM WebSphere Application Server (WAS) before 7.0.0.15 allows remote attackers to cause a denial of service (memory consumption) by accessing a JSP page of an application that is repeatedly stopped and restarted.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0
ibm websphere_application_server 6.0.2.19
ibm websphere_application_server 4.0.1
ibm websphere_application_server 6.0.2.7
ibm websphere_application_server 5.0.2.6
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 5.1.1.12
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server *
ibm websphere_application_server 5.1.0.2
ibm websphere_application_server 5.1.1.16
ibm websphere_application_server 6.0.2.25
ibm websphere_application_server 3.0
ibm websphere_application_server 6.0.2.9
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 5.1.1.9
ibm websphere_application_server 5.0.2.2
ibm websphere_application_server 4.0.2
ibm websphere_application_server 6.1.1
ibm websphere_application_server 5.1.1.8
ibm websphere_application_server 5.1.1
ibm websphere_application_server 6.0.2.13
ibm websphere_application_server 6.0.1.11
ibm websphere_application_server 3.0.2
ibm websphere_application_server 3.52
ibm websphere_application_server 5.0.2.4
ibm websphere_application_server 4.0.4
ibm websphere_application_server 5.0.2.15
ibm websphere_application_server 6.0.2.15
ibm websphere_application_server 5.0.2.10
ibm websphere_application_server 6.0.2.4
ibm websphere_application_server 6.1.0
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 6.1
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 5.1.1.11
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 5.0.2.7
ibm websphere_application_server 4.0.3
ibm websphere_application_server 5.0.2.9
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 5.1.1.3
ibm websphere_application_server 5.1.0.3
ibm websphere_application_server 6.0.2.6
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 5.0.2.3
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.0.2.24
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 6.0.2.5
ibm websphere_application_server 3.0.2.4
ibm websphere_application_server 5.1.0
ibm websphere_application_server 5.1.1.17
ibm websphere_application_server 5.0.2.13
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 3.5.3
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.0.1.1
ibm websphere_application_server 6.0.2.1
ibm websphere_application_server 6.1.13
ibm websphere_application_server 3.5.2
ibm websphere_application_server 6.0.1.5
ibm websphere_application_server 6.0.0.1
ibm websphere_application_server 5.1.1.14
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.0.0.2
ibm websphere_application_server 3.5.1
ibm websphere_application_server 3.0.2.2
ibm websphere_application_server 3.0.2.1
ibm websphere_application_server 5.1.1.15
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 6.1.6
ibm websphere_application_server 5.1.1.10
ibm websphere_application_server 6.0.1.2
ibm websphere_application_server 5.0.2.14
ibm websphere_application_server 6.1.3
ibm websphere_application_server 6.0.1.17
ibm websphere_application_server 6.0.1.13
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 5.0.2.16
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 5.0
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 6.0.2.31
ibm websphere_application_server 5.0.2.12
ibm websphere_application_server 6.1.7
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 5.1.1.5
ibm websphere_application_server 6.0.2.22
ibm websphere_application_server 5.0.0
ibm websphere_application_server 6.0
ibm websphere_application_server 5.0.2.8
ibm websphere_application_server 6.0.1.3
ibm websphere_application_server 5.0.2
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 5.1.0.4
ibm websphere_application_server 6.0.2.2
ibm websphere_application_server 6.0.2.11
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 3.5
ibm websphere_application_server 6.0.1.15
ibm websphere_application_server 5.1.1.2
ibm websphere_application_server 5.0.1
ibm websphere_application_server 3.0.2.3
ibm websphere_application_server 5.1.1.6
ibm websphere_application_server 6.0.2.30
ibm websphere_application_server 6.0.2.32
ibm websphere_application_server 2.0
ibm websphere_application_server 5.0.2.11
ibm websphere_application_server 5.0.2.1
ibm websphere_application_server 5.0.2.5
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 5.1.1.7
ibm websphere_application_server 5.1.1.1
ibm websphere_application_server 5.1.1.13
ibm websphere_application_server 6.0.2.23
ibm websphere_application_server 6.0.1
ibm websphere_application_server 6.0.1.7
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.0.2.17
ibm websphere_application_server 6.1.5
ibm websphere_application_server 6.1.14
ibm websphere_application_server 6.0.2.3
ibm websphere_application_server 6.0.2.29
ibm websphere_application_server 6.0.1.9
ibm websphere_application_server 6.0.2
ibm websphere_application_server 6.0.2.28
ibm websphere_application_server 6.0.2.27
ibm websphere_application_server 3.0.21
ibm websphere_application_server 5.1.0.5
ibm websphere_application_server 6.0.0.3
ibm websphere_application_server 5.1.1.4
ibm websphere_application_server 7.0.0.4
CVE-2011-1319 MEDIUM

The Security component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.35 and 7.x before 7.0.0.15 allows remote authenticated users to cause a denial of service (memory consumption) by using a Lightweight Third-Party Authentication (LTPA) token for authentication.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 7.0.0.4
CVE-2011-1320 MEDIUM

The Security component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.35 and 7.x before 7.0.0.15, when the Tivoli Integrated Portal / embedded WebSphere Application Server (TIP/eWAS) framework is used, does not properly delete AuthCache entries upon a logout, which might allow remote attackers to access the server by leveraging an unattended workstation.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 7.0.0.4
CVE-2011-1321 MEDIUM

The AuthCache purge implementation in the Security component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.37 and 7.x before 7.0.0.15 does not purge a user from the PlatformCredential cache, which might allow remote authenticated users to gain privileges by leveraging a group membership specified in an old RACF Object (aka RACO).

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0
ibm websphere_application_server 6.1.0.35
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 7.0.0.4
CVE-2011-1322 MEDIUM

The SOAP with Attachments API for Java (SAAJ) implementation in the Web Services component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.37 and 7.x before 7.0.0.15 allows remote attackers to cause a denial of service (memory consumption) via encrypted SOAP messages.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0
ibm websphere_application_server 6.1.0.35
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 7.0.0.4
CVE-2011-1343 HIGH

SQL injection vulnerability in the Web GUI in IBM Tivoli Netcool/OMNIbus before 7.3.0.4 allows remote attackers to execute arbitrary SQL commands via "dynamic SQL parameters."

CVSS 2.0

Severity: HIGH

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm tivoli_netcool/omnibus 7.1.0.12
ibm tivoli_netcool/omnibus 7.1.0.0
ibm tivoli_netcool/omnibus 7.2.0.7
ibm tivoli_netcool/omnibus 7.2.1.7
ibm tivoli_netcool/omnibus 7.2.1.0
ibm tivoli_netcool/omnibus 7.2.1.5
ibm tivoli_netcool/omnibus *
ibm tivoli_netcool/omnibus 7.3.0.1
ibm tivoli_netcool/omnibus 7.2.1.8
ibm tivoli_netcool/omnibus 7.2.0.9
ibm tivoli_netcool/omnibus 7.1.0.13
ibm tivoli_netcool/omnibus 7.2.1.6
ibm tivoli_netcool/omnibus 7.3.0.2
ibm tivoli_netcool/omnibus 7.3.0.0
ibm tivoli_netcool/omnibus 7.2.0.8
ibm tivoli_netcool/omnibus 7.1.0.11
ibm tivoli_netcool/omnibus 7.2.1.9
ibm tivoli_netcool/omnibus 7.2.0.0
ibm tivoli_netcool/omnibus 7.3.0.3
ibm tivoli_netcool/omnibus 7.2.0.10
CVE-2011-1355 MEDIUM

Open redirect vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.39 and 7.0 before 7.0.0.19 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the logoutExitPage parameter.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0
ibm websphere_application_server 6.1.0.35
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 6.1
ibm websphere_application_server 6.1.6
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.1.3
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.1.5
ibm websphere_application_server 6.1.14
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.7
ibm websphere_application_server 6.1.0.37
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.1
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.1.13
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 7.0.0.4
CVE-2011-1356 LOW

IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.39 and 7.0 before 7.0.0.19 allows local users to obtain sensitive stack-trace information via a crafted Administration Console request.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0
ibm websphere_application_server 6.1.0.35
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 6.1
ibm websphere_application_server 6.1.6
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.1.3
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.1.5
ibm websphere_application_server 6.1.14
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.7
ibm websphere_application_server 6.1.0.37
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.1
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.1.13
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 7.0.0.4
CVE-2011-1357 MEDIUM

Cross-site scripting (XSS) vulnerability in agentDetect.jsp in the web UI in IBM WebSphere Service Registry and Repository (WSRR) 6.3 before 6.3.0.5, 7.0 before 7.0.0.5, and 7.5 before 7.5.0.1 allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_service_registry_and_repository 6.3.0
ibm websphere_service_registry_and_repository 7.0.0.3
ibm websphere_service_registry_and_repository 7.0.0.2
ibm websphere_service_registry_and_repository 6.3.0.1
ibm websphere_service_registry_and_repository 6.3.0.2
ibm websphere_service_registry_and_repository 7.5
ibm websphere_service_registry_and_repository 7.0.0
ibm websphere_service_registry_and_repository 7.0.0.4
ibm websphere_service_registry_and_repository 6.3.0.4
ibm websphere_service_registry_and_repository 7.0.0.1
ibm websphere_service_registry_and_repository 6.3.0.3
CVE-2011-1359 MEDIUM

Directory traversal vulnerability in the administration console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.41, 7.0 before 7.0.0.19, and 8.0 before 8.0.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0
ibm websphere_application_server 6.1.0.35
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 6.1
ibm websphere_application_server 6.1.6
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.1.3
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.1.5
ibm websphere_application_server 6.1.14
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.0.39
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 6.1.7
ibm websphere_application_server 6.1.0.37
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.1
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.1.13
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 7.0.0.4
CVE-2011-1360 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in IBM HTTP Server 2.0.47 and earlier, as used in WebSphere Application Server and other products, allow remote attackers to inject arbitrary web script or HTML via vectors involving unspecified documentation files in (1) manual/ibm/ and (2) htdocs/*/manual/ibm/.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm http_server 1.3.12.6
ibm http_server 1.3.12.7
ibm http_server 1.3.26.1
ibm http_server 1.3.26.2
ibm http_server *
ibm http_server 2.0.42.1
ibm http_server 2.0.42.2
ibm http_server 1.3.19.5
ibm http_server 1.3.28
ibm http_server 2.0.42
ibm http_server 1.3.19
ibm http_server 1.3.19.4
ibm http_server 1.3.26
ibm http_server 1.3.6.3
ibm http_server 1.0
ibm http_server 1.3.19.6
ibm http_server 1.3.28.1
ibm http_server 2.0
ibm http_server 1.3.12.2
ibm http_server 1.3.12
CVE-2011-1362 MEDIUM

Cross-site scripting (XSS) vulnerability in the Installation Verification Test (IVT) application in the Install component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.41 and 7.0 before 7.0.0.19 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1308.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0
ibm websphere_application_server 6.1.0.35
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 6.1
ibm websphere_application_server 6.1.6
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.1.3
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.1.5
ibm websphere_application_server 6.1.14
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.0.39
ibm websphere_application_server 6.1.7
ibm websphere_application_server 6.1.0.37
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.1
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.1.13
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 7.0.0.4
CVE-2011-1366 HIGH

Unspecified vulnerability in the Import feature in IBM Rational AppScan Enterprise and AppScan Reporting Console 5.2 through 7.9.x and 8.x before 8.0.1.1 allows remote attackers to execute arbitrary commands on an agent server via a crafted ZIP archive.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm rational_appscan 5.6.0
ibm rational_appscan 7.7.0.2
ibm rational_appscan 7.9.0
ibm rational_appscan 5.5.0
ibm rational_appscan 5.5.0.2
ibm rational_appscan 8.0.0.1
ibm rational_appscan 8.0.0.3
ibm rational_appscan 5.6.0.3
ibm rational_appscan 8.0.0
ibm rational_appscan 5.4
ibm rational_appscan 7.7.0
ibm rational_appscan 5.2
ibm rational_appscan 7.7.0.1
ibm rational_appscan 7.8.0
ibm rational_appscan 7.9.0.1
ibm rational_appscan 7.9.0.2
ibm rational_appscan 7.9.0.3
ibm rational_appscan 7.8.0.2
ibm rational_appscan 5.5
ibm rational_appscan 5.5.0.1
ibm rational_appscan 8.0.1
ibm rational_appscan 7.8.0.1
ibm rational_appscan 8.0.0.2
CVE-2011-1367 HIGH

Unspecified vulnerability in the File Load feature in IBM Rational AppScan Standard and Express 7.8.x, 7.9.x, and 8.0.x before 8.0.0.3 allows remote attackers to execute arbitrary commands via a crafted .scan file.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm rational_appscan 7.8.0
ibm rational_appscan 7.9.0
ibm rational_appscan 7.9.0.1
ibm rational_appscan 7.9.0.2
ibm rational_appscan 7.9.0.3
ibm rational_appscan 7.8.0.2
ibm rational_appscan 8.0.0.1
ibm rational_appscan 7.8.0.1
ibm rational_appscan 8.0.0
ibm rational_appscan 8.0.0.2
CVE-2011-1368 MEDIUM

The JavaServer Faces (JSF) application functionality in IBM WebSphere Application Server 8.x before 8.0.0.1 does not properly handle requests, which allows remote attackers to read unspecified files via unknown vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_application_server 8.0.0.0
CVE-2011-1370 MEDIUM

The default configuration of the Sametime configuration servlet (SCS) in the server in IBM Lotus Sametime 7.0 through 8.5.2 does not enable an authentication requirement, which allows remote attackers to read the configuration settings by examining a response message.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-16,

Products Affected

Vendor Product Version
ibm lotus_sametime 8.5
ibm lotus_sametime 8.0.1
ibm lotus_sametime 8.0.2
ibm lotus_sametime 8.5.1
ibm lotus_sametime 7.5
ibm lotus_sametime 7.0
ibm lotus_sametime 7.5.1.2
ibm lotus_sametime 7.5.0.1
ibm lotus_sametime 7.5.1
ibm lotus_sametime 8.0
ibm lotus_sametime 7.5.1.1
ibm lotus_sametime 8.5.2
CVE-2011-1371 MEDIUM

Cross-site scripting (XSS) vulnerability in content/error.jsp in IBM WebSphere ILOG Rule Team Server 7.1.1 allows remote attackers to inject arbitrary web script or HTML via vectors that trigger an Unknown Error document, a different vulnerability than CVE-2011-4171.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_ilog_rule_team_server 7.1.1
CVE-2011-1372 MEDIUM

The Web User Interface on the IBM TS3100 and TS3200 tape libraries with firmware before A.60 allows remote attackers to bypass authentication and obtain administrative access via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm ts3200_tape_library *
ibm ts3100_tape_library_firmware *
ibm ts3100_tape_library *
ibm ts3200_tape_library_firmware *
CVE-2011-1373 LOW

Unspecified vulnerability in IBM DB2 9.7 before FP5 on UNIX, when the Self Tuning Memory Manager (STMM) feature and the AUTOMATIC DATABASE_MEMORY setting are configured, allows local users to cause a denial of service (daemon crash) via unknown vectors.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm db2 9.7.0.3
ibm db2 9.7.0.2
ibm db2 *
ibm db2 9.7.0.1
CVE-2011-1375 MEDIUM

IBM AIX 6.1 and 7.1 does not restrict the wpar_limits_config and wpar_limits_modify system calls, which allows local users to cause a denial of service (system crash) via a crafted call.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm aix 6.1
ibm aix 7.1
CVE-2011-1376 MEDIUM

iscdeploy in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.43, 7.0 before 7.0.0.21, and 8.0 before 8.0.0.2 on the IBM i platform sets weak permissions under systemapps/isclite.ear/ and bin/client_ffdc/, which allows local users to read or modify files via standard filesystem operations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 7.0
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 6.1.0.35
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 6.1
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.41
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 8.0
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.0.39
ibm websphere_application_server 6.1.0.37
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 7.0.0.15
CVE-2011-1377 HIGH

The Web Services Security component in the Web Services Feature Pack before 6.1.0.41 for IBM WebSphere Application Server (WAS) 6.1 does not properly handle the enabling of WS-Security for a JAX-WS application, which has unspecified impact and attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0
ibm websphere_application_server 6.1.0.35
ibm websphere_application_server 6.1
ibm websphere_application_server 6.1.6
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.1.3
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.1.5
ibm websphere_application_server 6.1.14
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 6.1.0.39
ibm websphere_application_server 6.1.7
ibm websphere_application_server 6.1.0.37
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.1
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.1.13
CVE-2011-1378 LOW

IBM WebSphere MQ 6.0 on OpenVMS, when the default rights of the MQM group are established, does not properly verify User Authorization File (UAF) data, which allows local users to kill listener processes and the command server via a control command.

CVSS 2.0

Severity: LOW

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_mq 6.0
CVE-2011-1381 MEDIUM

Unspecified vulnerability in IBM OpenPages GRC Platform 6.1.0.1 before IF4 allows remote attackers to bypass intended access restrictions via unknown vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm openpages_grc_platform 6.1.0.1
CVE-2011-1384 MEDIUM

The (1) bin/invscoutClient_VPD_Survey and (2) sbin/invscout_lsvpd programs in invscout.rte before 2.2.0.19 on IBM AIX 7.1, 6.1, 5.3, and earlier allow local users to delete arbitrary files, or trigger inventory scout operations on arbitrary files, via a symlink attack on an unspecified file.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-59,

Products Affected

Vendor Product Version
ibm invscout.rte 2.2.0.14
ibm invscout.rte 2.2.0.10
ibm invscout.rte 2.2.0.17
ibm invscout.rte 2.2.0.2
ibm invscout.rte 2.2.0.8
ibm invscout.rte 2.2.0.12
ibm invscout.rte 2.2.0.11
ibm invscout.rte *
ibm invscout.rte 2.2.0.7
ibm invscout.rte 2.2.0.9
ibm invscout.rte 2.2.0.13
ibm invscout.rte 2.2.0.4
ibm invscout.rte 2.2.0.15
CVE-2011-1385 HIGH

IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.1.x and 2.2.x, allows remote attackers to cause a denial of service (system crash) via an ICMP Echo Reply packet that contains 1 in the Identifier field, a different vulnerability than CVE-2012-0194.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm vios 2.1.2.10
ibm aix 6.1
ibm vios 2.1.2.12
ibm vios 2.2.0.10
ibm vios 2.2.1.1
ibm aix 7.1
ibm vios 2.1.2.13
ibm vios 2.2.0.12
ibm vios 2.2.0.13
ibm vios 2.2.1.3
ibm aix 5.3
ibm vios 2.1.3.10
ibm vios 2.2.0.11
ibm vios 2.1.0.0
ibm vios 2.2.1.0
CVE-2011-1386 MEDIUM

IBM Tivoli Federated Identity Manager (TFIM) and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.1.1, 6.2.0, and 6.2.1 do not properly handle signature validations based on SAML 1.0, 1.1, and 2.0, which allows remote attackers to bypass intended authentication or authorization requirements via a non-conforming SAML signature.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm tivoli_federated_identity_manager_business_gateway 6.1.1
ibm tivoli_federated_identity_manager 6.1.1
ibm tivoli_federated_identity_manager 6.2.1
ibm tivoli_federated_identity_manager_business_gateway 6.2.0
ibm tivoli_federated_identity_manager_business_gateway 6.2.1
ibm tivoli_federated_identity_manager 6.2.0
CVE-2011-1389 HIGH

Multiple directory traversal vulnerabilities in the vendor daemon in Rational Common Licensing in Telelogic License Server 2.0, Rational License Server 7.x, and ibmratl in IBM Rational License Key Server (RLKS) 8.0 through 8.1.2 allow remote attackers to execute arbitrary code via vectors related to save, rename, and load operations on log files. NOTE: this might overlap CVE-2011-4135.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm rational_license_key_server 8.0
ibm rational_license_key_server 8.1
ibm rational_license_server 7.0
ibm telelogic_license_server 2.0
ibm rational_license_key_server 8.1.2
ibm rational_license_server 7.5
ibm rational_license_server 7.1
ibm rational_license_key_server 8.1.1
CVE-2011-1390 HIGH

SQL injection vulnerability in the Maintenance tool in IBM Rational ClearQuest 7.1.1.x before 7.1.1.9, 7.1.2.x before 7.1.2.6, and 8.x before 8.0.0.2 allows remote attackers to execute arbitrary SQL commands by leveraging an error in the user-database upgrade feature.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm rational_clearquest 7.1.2.1
ibm rational_clearquest 7.1.2.3
ibm rational_clearquest 7.1.2
ibm rational_clearquest 7.1.1.4
ibm rational_clearquest 7.1.2.5
ibm rational_clearquest 7.1.1.8
ibm rational_clearquest 7.1.1.1
ibm rational_clearquest 7.1.2.2
ibm rational_clearquest 7.1.1.6
ibm rational_clearquest 7.1.1.3
ibm rational_clearquest 8.0.0.1
ibm rational_clearquest 7.1.1.7
ibm rational_clearquest 8.0
ibm rational_clearquest 7.1.1.5
ibm rational_clearquest 7.1.1.2
ibm rational_clearquest 7.1.2.4
CVE-2011-1393 HIGH

Unspecified vulnerability in the authentication functionality in the server in IBM Lotus Domino 8.x before 8.5.2 FP4 allows remote attackers to cause a denial of service (daemon crash) via a crafted Notes RPC packet.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm lotus_domino 8.0.5
ibm lotus_domino 8.5.1.5
ibm lotus_domino 8.5.1.1
ibm lotus_domino *
ibm lotus_domino 8.0.1
ibm lotus_domino 8.0.2.3
ibm lotus_domino 8.0.2.5
ibm lotus_domino 8.5.1.4
ibm lotus_domino 8.0.2.4
ibm lotus_domino 8.0.2
ibm lotus_domino 8.0.2.1
ibm lotus_domino 8.5.0
ibm lotus_domino 8.5.1
ibm lotus_domino 8.0
ibm lotus_domino 8.5.1.2
ibm lotus_domino 8.0.2.2
ibm lotus_domino 8.5.1.3
ibm lotus_domino 8.0.2.6
CVE-2011-1394 MEDIUM

IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Management for IT 6.2, 7.1, and 7.2; IBM Tivoli Service Request Manager 7.1 and 7.2; IBM Maximo Service Desk 6.2; and IBM Tivoli Change and Configuration Management Database (CCMDB) 6.2, 7.1, and 7.2 allow remote attackers to cause a denial of service (memory consumption) by establishing many UI sessions within one HTTP session.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm tivoli_asset_management_for_it 7.2
ibm trivoli_service_request_manager 7.2
ibm tivoli_asset_management_for_it 6.2
ibm trivoli_service_request_manager 7.1
ibm maximo_asset_management 7.1
ibm tivoli_change_and_configuration_management_database 6.2
ibm maximo_asset_management 7.5
ibm maximo_asset_management_essentials 7.5
ibm tivoli_asset_management_for_it 7.1
ibm maximo_asset_management_essentials 7.1
ibm maximo_asset_management 6.2
ibm tivoli_change_and_configuration_management_database 7.2
ibm maximo_service_desk 6.2
ibm maximo_asset_management_essentials 6.2
ibm tivoli_change_and_configuration_management_database 7.1
CVE-2011-1395 MEDIUM

Cross-site scripting (XSS) vulnerability in imicon.jsp in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5 allows remote attackers to inject arbitrary web script or HTML via the controlid parameter.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm maximo_asset_management 6.2
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.5
ibm maximo_asset_management_essentials 7.5
ibm maximo_asset_management_essentials 6.2
ibm maximo_asset_management_essentials 7.1
CVE-2011-1396 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5 allows remote attackers to inject arbitrary web script or HTML via the reportType parameter to an unspecified component.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm maximo_asset_management 6.2
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.5
ibm maximo_asset_management_essentials 7.5
ibm maximo_asset_management_essentials 6.2
ibm maximo_asset_management_essentials 7.1
CVE-2011-1397 MEDIUM

Cross-site request forgery (CSRF) vulnerability in the Labor Reporting page in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Management for IT 6.2, 7.1, and 7.2; IBM Tivoli Service Request Manager 7.1 and 7.2; IBM Maximo Service Desk 6.2; and IBM Tivoli Change and Configuration Management Database (CCMDB) 6.2, 7.1, and 7.2 allows remote attackers to hijack the authentication of arbitrary users.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm tivoli_asset_management_for_it 7.2
ibm trivoli_service_request_manager 7.2
ibm tivoli_asset_management_for_it 6.2
ibm trivoli_service_request_manager 7.1
ibm maximo_asset_management 7.1
ibm tivoli_change_and_configuration_management_database 6.2
ibm maximo_asset_management 7.5
ibm maximo_asset_management_essentials 7.5
ibm tivoli_asset_management_for_it 7.1
ibm maximo_asset_management_essentials 7.1
ibm maximo_asset_management 6.2
ibm tivoli_change_and_configuration_management_database 7.2
ibm maximo_service_desk 6.2
ibm maximo_asset_management_essentials 6.2
ibm tivoli_change_and_configuration_management_database 7.1
CVE-2011-1505 HIGH

Unspecified vulnerability in IBM Lotus Quickr 8.1 before 8.1.0.27 services for Lotus Domino has unknown impact and attack vectors, aka SPR ESEO8DQME2.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm lotus_quickr 8.1
CVE-2011-1512 HIGH

Heap-based buffer overflow in xlssr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a malformed BIFF record in a .xls Excel spreadsheet attachment, aka SPR PRAD8E3HKR.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm lotus_notes 8.0.2.1
ibm lotus_notes 7.0.3.1
ibm lotus_notes 7.0.4.1
ibm lotus_notes 8.0.0
autonomy keyview *
ibm lotus_notes 6.5.6
ibm lotus_notes 8.5.2.1
ibm lotus_notes 4.6
ibm lotus_notes 8.0.2.4
ibm lotus_notes 7.0.4.2
ibm lotus_notes 8.0
ibm lotus_notes 3.0.0.2
ibm lotus_notes 5.0.7a
ibm lotus_notes 6.0.3
ibm lotus_notes 6.0.5
ibm lotus_notes 8.5.1.1
ibm lotus_notes 5.0.2b
ibm lotus_notes 5.0.6
ibm lotus_notes 5.0.8
ibm lotus_notes 8.5.1.2
ibm lotus_notes 8.5.0.0
ibm lotus_notes 5.0
ibm lotus_notes 5.0.5.01
ibm lotus_notes 3.0.0.1
ibm lotus_notes 6.0.4
ibm lotus_notes 8.0.2
ibm lotus_notes 5.0.12
ibm lotus_notes 6.5.3.1
ibm lotus_notes 8.5.1.5
ibm lotus_notes 5.02
ibm lotus_notes 5.0.6a.01
ibm lotus_notes 8.5.2.0
ibm lotus_notes 4.2.1
ibm lotus_notes 5.0.7
ibm lotus_notes 6.5.6.3
ibm lotus_notes 6.5
ibm lotus_notes 4.6.7a
ibm lotus_notes 5.0.4
ibm lotus_notes 6.5.3
ibm lotus_notes 8.5.0.1
ibm lotus_notes 6.5.5.2
ibm lotus_notes 4.2
ibm lotus_notes 7.0.2.1
ibm lotus_notes 5.0a
ibm lotus_notes 4.6.7h
ibm lotus_notes 8.5.1.3
ibm lotus_notes 5.0.5.02
ibm lotus_notes 6.5.4
ibm lotus_notes 6.0
ibm lotus_notes 6.5.6.1
ibm lotus_notes 6.5.4.2
ibm lotus_notes 6.0.2
ibm lotus_notes 8.0.2.3
ibm lotus_notes 8.5.1.4
ibm lotus_notes 7.0.2
ibm lotus_notes 4.2.2
ibm lotus_notes 6.5.2
ibm lotus_notes 8.0.1
ibm lotus_notes 5.0.1a
ibm lotus_notes 8.0.2.2
ibm lotus_notes 6.5.5.3
ibm lotus_notes 8.0.2.0
ibm lotus_notes 5.0.3
ibm lotus_notes 7.0.4
ibm lotus_notes 6.5.6.2
ibm lotus_notes 5.0.2
ibm lotus_notes 5.0.1.02
ibm lotus_notes 5.0.6a
ibm lotus_notes 5.0.9a
ibm lotus_notes 8.0.2.5
ibm lotus_notes 3.0
ibm lotus_notes 6.5.4.1
ibm lotus_notes 8.5.1
ibm lotus_notes 6.0.1
ibm lotus_notes 5.0.11
ibm lotus_notes 6.5.1
ibm lotus_notes 6.5.5
ibm lotus_notes 7.0.1
ibm lotus_notes 8.5.1.0
ibm lotus_notes 8.0.2.6
ibm lotus_notes 5.0.5
ibm lotus_notes 5.0.9
ibm lotus_notes 7.0.1.1
ibm lotus_notes 5.0.1
ibm lotus_notes 7.0.0
ibm lotus_notes 7.0.2.3
ibm lotus_notes 4.5
ibm lotus_notes *
ibm lotus_notes 5.0.10
ibm lotus_notes 6.0.2.2
ibm lotus_notes 6.5.4.3
ibm lotus_notes 7.0.3
ibm lotus_notes 7.0
ibm lotus_notes 5.0.1b
ibm lotus_notes 6.5.5.1
ibm lotus_notes 5.0.2a
ibm lotus_notes 7.0.2.2
ibm lotus_notes 5.0.1c
ibm lotus_notes 5.0.2c
ibm lotus_notes 7.0.4.0
ibm lotus_notes 8.5
ibm lotus_notes 5.0.4a
CVE-2011-1519 HIGH

The remote console in the Server Controller in IBM Lotus Domino 7.x and 8.x verifies credentials against a file located at a UNC share pathname specified by the client, which allows remote attackers to bypass authentication, and consequently execute arbitrary code, by placing this pathname in the COOKIEFILE field. NOTE: this might overlap CVE-2011-0920.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm lotus_domino 7.0.2.3
ibm lotus_domino 7.0.2.2
ibm lotus_domino 8.5.2.2
ibm lotus_domino 8.5.1.1
ibm lotus_domino 8.0.2.3
ibm lotus_domino 7.0.3.1
ibm lotus_domino 8.5.1.4
ibm lotus_domino 8.0.2.4
ibm lotus_domino 8.0.2
ibm lotus_domino 7.0.1.1
ibm lotus_domino 8.5.0
ibm lotus_domino 8.5.1
ibm lotus_domino 8.0
ibm lotus_domino 7.0.4.2
ibm lotus_domino 8.5.1.2
ibm lotus_domino 8.0.2.2
ibm lotus_domino 8.5.1.3
ibm lotus_domino 8.5.2
ibm lotus_domino 8.0.2.6
ibm lotus_domino 8.5.1.5
ibm lotus_domino 7.0.2
ibm lotus_domino 7.0
ibm lotus_domino 8.0.1
ibm lotus_domino 7.0.4.1
ibm lotus_domino 8.0.2.5
ibm lotus_domino 7.0.2.1
ibm lotus_domino 7.0.1
ibm lotus_domino 8.5.0.1
ibm lotus_domino 7.0.4
ibm lotus_domino 8.0.2.1
ibm lotus_domino 8.5.2.1
ibm lotus_domino 8.5.3
ibm lotus_domino 7.0.3
CVE-2011-1520 HIGH

The default configuration of the server console in IBM Lotus Domino does not require a password (aka Server_Console_Password), which allows physically proximate attackers to perform administrative changes or obtain sensitive information via a (1) Load, (2) Tell, or (3) Set Configuration command.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm lotus_domino *
CVE-2011-1558 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in the IBM Web Interface for Content Management (aka WEBi) 1.0.4 before FP3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2010-1242.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm webi 1.0.4
CVE-2011-1559 HIGH

Unspecified vulnerability in the IBM Web Interface for Content Management (aka WEBi) 1.0.4 before FP3 has unknown impact and attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm webi 1.0.4
CVE-2011-1560 HIGH

solid.exe in IBM solidDB before 4.5.181, 6.0.x before 6.0.1067, 6.1.x and 6.3.x before 6.3.47, and 6.5.x before 6.5.0.3 uses a password-hash length specified by the client, which allows remote attackers to bypass authentication via a short length value.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm soliddb 4.5.167
ibm soliddb 6.3.38
ibm soliddb 4.5.179
ibm soliddb 6.30.0044
ibm soliddb 6.5.0.1
ibm soliddb 6.1.20
ibm soliddb 6.1.18
ibm soliddb 4.5.178
ibm soliddb 6.5.0.2
ibm soliddb 4.5.169
ibm soliddb 6.1
ibm soliddb 6.3.33
ibm soliddb *
ibm soliddb 6.5.0.0
ibm soliddb 6.0.1061
ibm soliddb 6.3.37
ibm soliddb 4.5.168
ibm soliddb 6.30.0039
ibm soliddb 4.5.176
ibm soliddb 6.0.1064
ibm soliddb 6.30.0040
ibm soliddb 4.5.173
ibm soliddb 6.0.1066
ibm soliddb 4.5.175
ibm soliddb 6.0.1065
ibm soliddb 6.0.1060
CVE-2011-1561 MEDIUM

The LDAP login feature in bos.rte.security 6.1.6.4 in IBM AIX 6.1, when ldap_auth is enabled in ldap.cfg, allows remote attackers to bypass authentication via a login attempt with an arbitrary password.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm aix 6.1
CVE-2011-1683 MEDIUM

IBM WebSphere Application Server (WAS) 6.0.x through 6.0.2.43, 6.1.x before 6.1.0.37, and 7.0.x before 7.0.0.17 on z/OS, when a Local OS user registry or Federated Repository with RACF adapter is used, allows remote attackers to obtain unspecified application access via unknown vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 6.0.2.19
ibm websphere_application_server 7.0.0.12
ibm websphere_application_server 6.0.2.7
ibm websphere_application_server 6.1.0.24
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 7.0.0.10
ibm websphere_application_server 6.0.2.25
ibm websphere_application_server 6.0.2.9
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.0.2.41
ibm websphere_application_server 6.1.1
ibm websphere_application_server 6.0.2.21
ibm websphere_application_server 6.0.2.20
ibm websphere_application_server 6.0.2.13
ibm websphere_application_server 6.0.1.11
ibm websphere_application_server 6.0.2.15
ibm websphere_application_server 6.0.2.4
ibm websphere_application_server 6.1.0
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.0.2.6
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.0.2.37
ibm websphere_application_server 6.0.2.24
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 6.0.2.5
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.0.1.1
ibm websphere_application_server 6.0.2.1
ibm websphere_application_server 6.1.13
ibm websphere_application_server 6.0.1.5
ibm websphere_application_server 6.0.0.1
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.0.0.2
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0.35
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 6.1.6
ibm websphere_application_server 6.0.2.39
ibm websphere_application_server 6.0.2.33
ibm websphere_application_server 6.0.1.2
ibm websphere_application_server 6.1.0.32
ibm websphere_application_server 6.1.3
ibm websphere_application_server 6.0.1.17
ibm websphere_application_server 6.0.2.18
ibm websphere_application_server 6.0.1.13
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 6.0.2.12
ibm websphere_application_server 6.0.2.16
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 6.0.2.31
ibm websphere_application_server 6.1.7
ibm websphere_application_server 6.0.2.35
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 6.0.2.22
ibm websphere_application_server 6.0.2.10
ibm websphere_application_server 6.0
ibm websphere_application_server 6.0.1.3
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.0.2.43
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 6.0.2.2
ibm websphere_application_server 6.0.2.11
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 6.0.2.8
ibm websphere_application_server 6.0.1.15
ibm websphere_application_server 6.1.0.22
ibm websphere_application_server 6.0.2.30
ibm websphere_application_server 6.0.2.32
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 6.0.2.23
ibm websphere_application_server 6.0.1
ibm websphere_application_server 6.0.1.7
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.0.2.17
ibm websphere_application_server 6.1.5
ibm websphere_application_server 6.1.14
ibm websphere_application_server 6.0.2.3
ibm websphere_application_server 6.0.2.29
ibm websphere_application_server 6.0.1.9
ibm websphere_application_server 6.0.2
ibm websphere_application_server 6.0.2.28
ibm websphere_application_server 6.0.2.27
ibm websphere_application_server 6.0.0.3
ibm websphere_application_server 7.0.0.4
CVE-2011-1820 LOW

IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0010, 6.0 before 6.0.0.67 (aka 6.0.0.8-TIV-ITDS-IF0009), 6.1 before 6.1.0.40 (aka 6.1.0.5-TIV-ITDS-IF0003), 6.2 before 6.2.0.16 (aka 6.2.0.3-TIV-ITDS-IF0002), and 6.3 before 6.3.0.3 (aka 6.3.0.0-TIV-ITDS-IF0003) does not properly handle the ibm-auditAttributesOnGroupEvalOp setting for auditing of extended operations, which might allow attackers to obtain sensitive information by reading the audit log.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm tivoli_directory_server 5.2.0
ibm tivoli_directory_server 6.0.0.41
ibm tivoli_directory_server 6.2.0.8
ibm tivoli_directory_server 6.0.0.7
ibm tivoli_directory_server 6.2.0.15
ibm tivoli_directory_server 6.1.0.9
ibm tivoli_directory_server 6.0.0.52
ibm tivoli_directory_server 6.2.0.13
ibm tivoli_directory_server 6.2.0.6
ibm tivoli_directory_server 6.3.0.1
ibm tivoli_directory_server 6.0.0.14
ibm tivoli_directory_server 6.1.0.24
ibm tivoli_directory_server 6.0.0.56
ibm tivoli_directory_server 6.1.0.29
ibm tivoli_directory_server 6.1.0.36
ibm tivoli_directory_server 6.1.0.14
ibm tivoli_directory_server 6.1.0.35
ibm tivoli_directory_server 6.2.0.1
ibm tivoli_directory_server 6.2.0.12
ibm tivoli_directory_server 6.1.0.2
ibm tivoli_directory_server 6.0.0.60
ibm tivoli_directory_server 6.0.0.57
ibm tivoli_directory_server 6.2.0.7
ibm tivoli_directory_server 6.0.0.64
ibm tivoli_directory_server 6.0.0.1
ibm tivoli_directory_server 6.1.0.30
ibm tivoli_directory_server 6.0.0.8
ibm tivoli_directory_server 6.2.0.2
ibm tivoli_directory_server 6.0.0.65
ibm tivoli_directory_server 6.2.0.10
ibm tivoli_directory_server 6.2.0.5
ibm tivoli_directory_server 6.0.0.33
ibm tivoli_directory_server 6.1.0.23
ibm tivoli_directory_server 6.1.0.3
ibm tivoli_directory_server 6.2.0.0
ibm tivoli_directory_server 6.2.0.11
ibm tivoli_directory_server 6.1.0.8
ibm tivoli_directory_server 6.1.0.28
ibm tivoli_directory_server 6.1.0.19
ibm tivoli_directory_server 6.1.0.34
ibm tivoli_directory_server 6.0
ibm tivoli_directory_server 6.1.0.6
ibm tivoli_directory_server 6.1.0.4
ibm tivoli_directory_server 6.0.0.62
ibm tivoli_directory_server 6.1.0.20
ibm tivoli_directory_server 6.1.0.13
ibm tivoli_directory_server 6.0.0.55
ibm tivoli_directory_server 6.3.0.0
ibm tivoli_directory_server 6.1.0.22
ibm tivoli_directory_server 6.0.0.63
ibm tivoli_directory_server 6.1.0.37
ibm tivoli_directory_server 6.1.0.7
ibm tivoli_directory_server 6.1.0.15
ibm tivoli_directory_server 6.0.0.53
ibm tivoli_directory_server 6.2.0.4
ibm tivoli_directory_server 6.0.0.19
ibm tivoli_directory_server 6.0.0.58
ibm tivoli_directory_server 6.1.0.0
ibm tivoli_directory_server 6.0.0.45
ibm tivoli_directory_server 6.0.0.54
ibm tivoli_directory_server 6.1.0.12
ibm tivoli_directory_server 6.1.0.39
ibm tivoli_directory_server 6.2.0.14
ibm tivoli_directory_server 6.1.0.18
ibm tivoli_directory_server 6.0.0.0
ibm tivoli_directory_server 6.0.0.61
ibm tivoli_directory_server 6.1.0.33
ibm tivoli_directory_server 6.1.0.5
ibm tivoli_directory_server 6.3.0.2
ibm tivoli_directory_server 6.1.0.11
ibm tivoli_directory_server 6.1.0.27
ibm tivoli_directory_server 6.1.0.25
ibm tivoli_directory_server 6.0.0.59
ibm tivoli_directory_server 6.1.0.10
ibm tivoli_directory_server 6.1.0.21
ibm tivoli_directory_server 6.1.0.31
ibm tivoli_directory_server 5.2.0.4
ibm tivoli_directory_server 6.0.0.66
ibm tivoli_directory_server 6.1.0.26
ibm tivoli_directory_server 6.1.0.38
ibm tivoli_directory_server 6.2.0.3
ibm tivoli_directory_server 6.1.0.32
ibm tivoli_directory_server 6.1.0.1
ibm tivoli_directory_server 6.1.0.17
CVE-2011-1821 MEDIUM

IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0010 on Windows allows remote authenticated users to cause a denial of service (daemon hang) via a cn=changelog search.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm tivoli_directory_server 5.2.0
ibm tivoli_directory_server 5.2.0.4
CVE-2011-1822 LOW

The LDAP_ADD implementation in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0009 stores a cleartext SHA password in the change log, which might allow local users to obtain sensitive information by reading this log.

CVSS 2.0

Severity: LOW

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm tivoli_directory_server 5.2.0
ibm tivoli_directory_server 5.2.0.4
CVE-2011-1839 MEDIUM

IBM Rational Build Forge 7.1.0 uses the HTTP GET method during redirection from the authentication servlet to a PHP script, which makes it easier for context-dependent attackers to discover session IDs by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_build_forge 7.1.0
CVE-2011-1846 MEDIUM

IBM DB2 9.5 before FP7 and 9.7 before FP4 on Linux, UNIX, and Windows does not properly revoke role membership from groups, which allows remote authenticated users to execute non-DDL statements by leveraging previous inherited possession of a role, a different vulnerability than CVE-2011-0757. NOTE: some of these details are obtained from third party information.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm db2 9.5
ibm db2 *
ibm db2 9.7
CVE-2011-1847 MEDIUM

IBM DB2 9.5 before FP7 and 9.7 before FP4 on Linux, UNIX, and Windows does not properly enforce privilege requirements for table access, which allows remote authenticated users to modify SYSSTAT.TABLES statistics columns via an UPDATE statement. NOTE: some of these details are obtained from third party information.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm db2 9.5
ibm db2 *
ibm db2 9.7
CVE-2011-2141 HIGH

SQL injection vulnerability in TMWeb in IBM Datacap Taskmaster Capture 8.0.1 before FP1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm datacap_taskmaster_capture 8.0.1
CVE-2011-2142 MEDIUM

The Web Client Service in IBM Datacap Taskmaster Capture 8.0.1 before FP1 requires a cleartext password, which has unspecified impact and attack vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm datacap_taskmaster_capture 8.0.1
CVE-2011-2143 MEDIUM

IBM Datacap Taskmaster Capture 8.0.1 before FP1, when Windows Authentication is enabled, allows remote attackers to obtain login access by using an incorrect password in conjunction with an account name from a different domain.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm datacap_taskmaster_capture 8.0.1
CVE-2011-2144 MEDIUM

The eDocument Conversion Actions implementation in IBM Datacap Taskmaster Capture 8.0.1 FP1 and earlier allows remote attackers to cause a denial of service (batch abort) via a long subject line in an e-mail message that is represented in a .eml file.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm datacap_taskmaster_capture 8.0.1
ibm datacap_taskmaster_capture *
CVE-2011-2163 HIGH

Unspecified vulnerability in Virtualization Manager 1.2.2 in IBM Systems Director 1.2.2 has unknown impact and attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm virtualization_manager 1.2.2
ibm systems_director 1.2.2
CVE-2011-2172 MEDIUM

Cross-site scripting (XSS) vulnerability in the search center in IBM WebSphere Portal 7.0.0.1 before CF004 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 7.0.0.1
CVE-2011-2173 MEDIUM

The implementation of OutputMediator objects in IBM WebSphere Portal 6.0.1.7, and 7.0.0.1 before CF002, allows remote authenticated users to cause a denial of service (memory consumption) via requests.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm websphere_portal 7.0.0.1
ibm websphere_portal 6.0.1.7
CVE-2011-2330 HIGH

Tivoli Endpoint in IBM Tivoli Management Framework 3.7.1, 4.1, 4.1.1, and 4.3.1 has an unspecified "built-in account" that is "trivially" accessed, which makes it easier for remote attackers to send requests to restricted pages via a session on TCP port 9495, a different vulnerability than CVE-2011-1220.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm tivoli_management_framework 4.1
ibm tivoli_management_framework 4.3.1
ibm tivoli_management_framework 3.7.1
ibm tivoli_management_framework 4.1.1
CVE-2011-2606 MEDIUM

Cross-site scripting (XSS) vulnerability in the Web UI in IBM Rational Team Concert (RTC) 3.0 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Work Item 165511.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_team_concert 3.0
CVE-2011-2607 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Rational Team Concert (RTC) 3.0 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Work Item 165513.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_team_concert 3.0
CVE-2011-2679 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Rational DOORS Web Access 1.4.x before 1.4.0.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_doors_web_access 1.4.0.1
ibm rational_doors_web_access 1.4.0.3
ibm rational_doors_web_access 1.4.0.2
ibm rational_doors_web_access 1.4
CVE-2011-2680 HIGH

Unspecified vulnerability in IBM Rational DOORS Web Access 1.4.x before 1.4.0.4 has unknown impact and remote attack vectors related to the "server error response."

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm rational_doors_web_access 1.4.0.1
ibm rational_doors_web_access 1.4.0.3
ibm rational_doors_web_access 1.4.0.2
ibm rational_doors_web_access 1.4
CVE-2011-2681 HIGH

IBM Rational DOORS Web Access 1.4.x before 1.4.0.4 does not properly handle exceptions, which has unspecified impact and remote attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm rational_doors_web_access 1.4.0.1
ibm rational_doors_web_access 1.4.0.3
ibm rational_doors_web_access 1.4.0.2
ibm rational_doors_web_access 1.4
CVE-2011-2682 MEDIUM

The Login component in IBM Rational DOORS Web Access 1.4.x before 1.4.0.4 allows remote authenticated users to cause a denial of service (license consumption) by trying to login to DOORS Web Access with a new user account that has never been used for a DOORS login.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm rational_doors_web_access 1.4.0.1
ibm rational_doors_web_access 1.4.0.3
ibm rational_doors_web_access 1.4.0.2
ibm rational_doors_web_access 1.4
CVE-2011-2754 MEDIUM

Cross-site scripting (XSS) vulnerability in the PageBuilder2 (aka Page Builder) theme in IBM WebSphere Portal 7.x before 7.0.0.1 CF006, as used in IBM Web Content Manager (WCM) and other products, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm web_content_manager *
ibm websphere_portal 7.0.0.1
ibm websphere_portal 7.0.0.0
CVE-2011-2758 MEDIUM

IDSWebApp in the Web Administration Tool in IBM Tivoli Directory Server (TDS) 6.2 before 6.2.0.3-TIV-ITDS-IF0004 does not require authentication for access to LDAP Server log files, which allows remote attackers to obtain sensitive information via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm tivoli_directory_server 6.2
ibm tivoli_directory_server 6.2.0.2
ibm tivoli_directory_server 6.2.0.0
ibm tivoli_directory_server 6.2.0.1
CVE-2011-2759 MEDIUM

The login page of IDSWebApp in the Web Administration Tool in IBM Tivoli Directory Server (TDS) 6.2 before 6.2.0.3-TIV-ITDS-IF0004 does not have an off autocomplete attribute for authentication fields, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm tivoli_directory_server 6.2
ibm tivoli_directory_server 6.2.0.2
ibm tivoli_directory_server 6.2.0.0
ibm tivoli_directory_server 6.2.0.1
CVE-2011-2884 HIGH

Multiple unspecified vulnerabilities in IBM Lotus Symphony 3 before FP3 have unknown impact and attack vectors, related to "critical security vulnerability issues."

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm lotus_symphony 3.0.0.2
ibm lotus_symphony 3.0.0.1
ibm lotus_symphony 3.0.0
CVE-2011-2885 MEDIUM

IBM Lotus Symphony 3 before FP3 allows remote attackers to cause a denial of service (application crash) via the sample .doc document that incorporates a user-defined toolbar.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm lotus_symphony 3.0.0.2
ibm lotus_symphony 3.0.0.1
ibm lotus_symphony 3.0.0
CVE-2011-2886 MEDIUM

IBM Lotus Symphony 3 before FP3 allows remote attackers to cause a denial of service (application crash) via a .docx document with empty bullet styles for parent bullets.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm lotus_symphony 3.0.0.2
ibm lotus_symphony 3.0.0.1
ibm lotus_symphony 3.0.0
CVE-2011-2887 MEDIUM

IBM Lotus Symphony 3 before FP3 on Linux allows remote attackers to cause a denial of service (application crash) via a certain sample document.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm lotus_symphony 3.0.0.2
ibm lotus_symphony 3.0.0.1
ibm lotus_symphony 3.0.0
CVE-2011-2888 MEDIUM

IBM Lotus Symphony 3 before FP3 allows remote attackers to cause a denial of service (application hang) via complex graphics in a presentation.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm lotus_symphony 3.0.0.2
ibm lotus_symphony 3.0.0.1
ibm lotus_symphony 3.0.0
CVE-2011-2893 MEDIUM

The DataPilot feature in IBM Lotus Symphony 3 before FP3 allows user-assisted remote attackers to cause a denial of service (application crash) via a large .xls spreadsheet with an invalid Value reference.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm lotus_symphony 3.0.0.2
ibm lotus_symphony 3.0.0.1
ibm lotus_symphony 3.0.0
CVE-2011-3123 HIGH

IBM InfoSphere Information Server 8.5 and 8.5.0.1 on Unix and Linux, as used in IBM InfoSphere DataStage 8.5 and 8.5.0.1 and other products, uses weak permissions for unspecified files, which allows local users to gain privileges via unknown vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm infosphere_datastage 8.5
ibm infosphere_information_server 8.5.0.1
ibm infosphere_datastage 8.5.0.1
ibm infosphere_information_server 8.5
CVE-2011-3124 HIGH

IBM InfoSphere Information Server 8.5 and 8.5.0.1 on Unix and Linux, as used in IBM InfoSphere DataStage 8.5 and 8.5.0.1 and other products, assigns incorrect ownership to unspecified files, which allows local users to gain privileges via unknown vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm infosphere_datastage 8.5
ibm infosphere_information_server 8.5.0.1
ibm infosphere_datastage 8.5.0.1
ibm infosphere_information_server 8.5
CVE-2011-3135 HIGH

Unspecified vulnerability in the Runtime in IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.9 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.2.0 before 6.2.0.9 has unknown impact and attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm tivoli_federated_identity_manager 6.2.0.3
ibm tivoli_federated_identity_manager_business_gateway 6.2.0.1
ibm tivoli_federated_identity_manager_business_gateway 6.2.0.8
ibm tivoli_federated_identity_manager_business_gateway 6.2.0.2
ibm tivoli_federated_identity_manager 6.2.0.8
ibm tivoli_federated_identity_manager 6.2.0.2
ibm tivoli_federated_identity_manager_business_gateway 6.2.0.3
ibm tivoli_federated_identity_manager_business_gateway 6.2.0
ibm tivoli_federated_identity_manager 6.2.0
ibm tivoli_federated_identity_manager 6.2.0.1
CVE-2011-3136 HIGH

Unspecified vulnerability in the Management Console in IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.9 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.2.0 before 6.2.0.9 has unknown impact and attack vectors, aka APAR IV03048.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm tivoli_federated_identity_manager 6.2.0.3
ibm tivoli_federated_identity_manager_business_gateway 6.2.0.1
ibm tivoli_federated_identity_manager_business_gateway 6.2.0.8
ibm tivoli_federated_identity_manager_business_gateway 6.2.0.2
ibm tivoli_federated_identity_manager 6.2.0.8
ibm tivoli_federated_identity_manager 6.2.0.2
ibm tivoli_federated_identity_manager_business_gateway 6.2.0.3
ibm tivoli_federated_identity_manager_business_gateway 6.2.0
ibm tivoli_federated_identity_manager 6.2.0
ibm tivoli_federated_identity_manager 6.2.0.1
CVE-2011-3137 HIGH

Unspecified vulnerability in the Management Console in IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.9 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.2.0 before 6.2.0.9 has unknown impact and attack vectors, aka APAR IV03050.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm tivoli_federated_identity_manager 6.2.0.3
ibm tivoli_federated_identity_manager_business_gateway 6.2.0.1
ibm tivoli_federated_identity_manager_business_gateway 6.2.0.8
ibm tivoli_federated_identity_manager_business_gateway 6.2.0.2
ibm tivoli_federated_identity_manager 6.2.0.8
ibm tivoli_federated_identity_manager 6.2.0.2
ibm tivoli_federated_identity_manager_business_gateway 6.2.0.3
ibm tivoli_federated_identity_manager_business_gateway 6.2.0
ibm tivoli_federated_identity_manager 6.2.0
ibm tivoli_federated_identity_manager 6.2.0.1
CVE-2011-3138 MEDIUM

The LTPA STS module support implementation in IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.9 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.2.0 before 6.2.0.9 relies on a static instance of a Java Development Kit (JDK) class, which might allow attackers to bypass LTPA token signature verification by leveraging lack of thread safety.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm tivoli_federated_identity_manager 6.2.0.3
ibm tivoli_federated_identity_manager_business_gateway 6.2.0.1
ibm tivoli_federated_identity_manager_business_gateway 6.2.0.8
ibm tivoli_federated_identity_manager_business_gateway 6.2.0.2
ibm tivoli_federated_identity_manager 6.2.0.8
ibm tivoli_federated_identity_manager 6.2.0.2
ibm tivoli_federated_identity_manager_business_gateway 6.2.0.3
ibm tivoli_federated_identity_manager_business_gateway 6.2.0
ibm tivoli_federated_identity_manager 6.2.0
ibm tivoli_federated_identity_manager 6.2.0.1
CVE-2011-3140 MEDIUM

IBM Web Application Firewall, as used on the G400 IPS-G400-IB-1 and GX4004 IPS-GX4004-IB-2 appliances with update 31.030, does not properly handle query strings with multiple instances of the same parameter, which allows remote attackers to bypass intended intrusion prevention by dividing a dangerous parameter value into substrings, as demonstrated by a SQL statement that is split across multiple iid parameters and then sent to a .aspx file on an IIS web server.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm gx4004_ips-gx4004-ib-2_appliance 31.030
ibm web_application_firewall -
ibm g400_ips-g400-ib-1_appliance 31.030
CVE-2011-3387 MEDIUM

The class file parser in IBM Java 1.4.2 SR13 FP9 allows remote authenticated users to cause a denial of service (memory consumption or an infinite loop) via a crafted attribute length field in a class file, related to validation of a length field at the wrong time, a different vulnerability than CVE-2011-0311.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm java 1.4.2.13.9
CVE-2011-3390 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in index.php in IBM OpenAdmin Tool (OAT) before 2.72 for Informix allow remote attackers to inject arbitrary web script or HTML via the (1) informixserver, (2) host, or (3) port parameter in a login action.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm openadmin_tool 2.21
ibm openadmin_tool *
ibm openadmin_tool 2.27
ibm openadmin_tool 2.26
ibm openadmin_tool 2.22
ibm openadmin_tool 2.24
ibm openadmin_tool 2.28
ibm openadmin_tool 2.20
ibm openadmin_tool 2.23
ibm openadmin_tool 2.25
CVE-2011-3391 MEDIUM

IBM Rational Build Forge 7.1.2 relies on client-side JavaScript code to enforce the EditSecurity permission requirement for the Export Key File function, which allows remote authenticated users to read a key file by removing a disable attribute in the Security sub-menu.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm rational_build_forge 7.1.2
CVE-2011-3575 HIGH

Stack-based buffer overflow in the NSFComputeEvaluateExt function in Nnotes.dll in IBM Lotus Domino 8.5.2 allows remote authenticated users to execute arbitrary code via a long tHPRAgentName parameter in an fmHttpPostRequest OpenForm action to WebAdmin.nsf.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm lotus_domino 8.5.2
CVE-2011-3576 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Lotus Domino 8.5.2 allows remote attackers to inject arbitrary web script or HTML via the PanelIcon parameter in an fmpgPanelHeader ReadForm action to WebAdmin.nsf.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm lotus_domino 8.5.2
CVE-2011-3577 HIGH

IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.3 does not properly implement Activity Token authentication for Web Services, which has unspecified impact and attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm websphere_commerce 6.0.0.6
ibm websphere_commerce 6.0.0.11
ibm websphere_commerce 6.0.0.1
ibm websphere_commerce 6.0.0.2
ibm websphere_commerce 6.0.0.10
ibm websphere_commerce 7.0.0.3
ibm websphere_commerce 7.0.0.2
ibm websphere_commerce 7.0
ibm websphere_commerce 6.0.0.7
ibm websphere_commerce 6.0.0.8
ibm websphere_commerce 6.0.0.3
ibm websphere_commerce 6.0.0.0
ibm websphere_commerce 6.0.0.4
ibm websphere_commerce 6.0.0.9
ibm websphere_commerce 7.0.0.1
ibm websphere_commerce 6.0.0.5
CVE-2011-3982 LOW

The Fibre Channel driver for QLogic adapters in IBM AIX 6.1 and 7.1 does not properly handle DMA resource limitations, which allows local users to cause a denial of service (system hang) via vectors that generate a large amount of DMA I/O, related to a deadlock in timer processing across CPUs.

CVSS 2.0

Severity: LOW

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm aix 6.1
ibm aix 7.1
CVE-2011-4061 MEDIUM

Multiple untrusted search path vulnerabilities in (1) db2rspgn and (2) kbbacf1 in IBM DB2 Express Edition 9.7, as used in the IBM Tivoli Monitoring for Databases: DB2 Agent, allow local users to gain privileges via a Trojan horse libkbb.so in the current working directory, related to the DT_RPATH ELF header.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm tivoli_monitoring_for_databases *
ibm db2 9.7
CVE-2011-4171 MEDIUM

Cross-site scripting (XSS) vulnerability in content/error.jsp in IBM WebSphere ILOG Rule Team Server 7.1.1 allows remote attackers to inject arbitrary web script or HTML via the project parameter to teamserver/faces/home.jsp.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_ilog_rule_team_server 7.1.1
CVE-2011-4435 MEDIUM

The web-server component in the Consolidation and Analysis Engine (CAE) Server in DB2 Query Monitor in IBM DB2 Tools 2.3.0 for z/OS does not prevent directory browsing, which allows remote attackers to obtain sensitive information via HTTP requests.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm db2_tools_for_z/os 2.3.0
CVE-2011-4465 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Lotus Mobile Connect (LMC) 6.1.4 allows remote attackers to inject arbitrary web script or HTML via vectors related to a hidden redirect URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm lotus_mobile_connect 6.1.4
CVE-2011-4668 HIGH

IBM Tivoli Netcool/Reporter 2.2 before 2.2.0.8 allows remote attackers to execute arbitrary code via vectors related to an unspecified CGI program used with the Apache HTTP Server.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-94,

Products Affected

Vendor Product Version
ibm tivoli_netcool/reporter 2.2.0.3
ibm tivoli_netcool/reporter 2.2.0.4
ibm tivoli_netcool/reporter 2.2.0
ibm tivoli_netcool/reporter 2.2.0.7
ibm tivoli_netcool/reporter 2.2.0.5
ibm tivoli_netcool/reporter 2.2.0.6
ibm tivoli_netcool/reporter 2.2.0.2
ibm tivoli_netcool/reporter 2.2.0.1
CVE-2011-4708 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Rational Asset Manager before 7.5.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_asset_manager 7.1.1.1
ibm rational_asset_manager 7.5.0.1
ibm rational_asset_manager *
ibm rational_asset_manager 7.0.0.1
ibm rational_asset_manager 7.1.1.0
ibm rational_asset_manager 7.2.0.2
ibm rational_asset_manager 7.5.0.0
ibm rational_asset_manager 7.1.0.1
ibm rational_asset_manager 7.2.0.1
ibm rational_asset_manager 7.0.0.2
ibm rational_asset_manager 7.1.0.0
ibm rational_asset_manager 7.0.0.0
CVE-2011-4816 MEDIUM

SQL injection vulnerability in the KPI component in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Management for IT 6.2, 7.1, and 7.2; IBM Tivoli Service Request Manager 7.1 and 7.2; IBM Maximo Service Desk 6.2; and IBM Tivoli Change and Configuration Management Database (CCMDB) 6.2, 7.1, and 7.2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm tivoli_asset_management_for_it 7.2
ibm trivoli_service_request_manager 7.2
ibm tivoli_asset_management_for_it 6.2
ibm trivoli_service_request_manager 7.1
ibm maximo_asset_management 7.1
ibm tivoli_change_and_configuration_management_database 6.2
ibm maximo_asset_management 7.5
ibm maximo_asset_management_essentials 7.5
ibm tivoli_asset_management_for_it 7.1
ibm maximo_asset_management_essentials 7.1
ibm maximo_asset_management 6.2
ibm tivoli_change_and_configuration_management_database 7.2
ibm maximo_service_desk 6.2
ibm maximo_asset_management_essentials 6.2
ibm tivoli_change_and_configuration_management_database 7.1
CVE-2011-4817 MEDIUM

The About option on the Help menu in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Management for IT 6.2, 7.1, and 7.2; IBM Tivoli Service Request Manager 7.1 and 7.2; IBM Maximo Service Desk 6.2; and IBM Tivoli Change and Configuration Management Database (CCMDB) 6.2, 7.1, and 7.2 shows the username, which might allow remote authenticated users to have an unspecified impact via a targeted attack against the corresponding user account.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm tivoli_asset_management_for_it 7.2
ibm trivoli_service_request_manager 7.2
ibm tivoli_asset_management_for_it 6.2
ibm trivoli_service_request_manager 7.1
ibm maximo_asset_management 7.1
ibm tivoli_change_and_configuration_management_database 6.2
ibm maximo_asset_management 7.5
ibm maximo_asset_management_essentials 7.5
ibm tivoli_asset_management_for_it 7.1
ibm maximo_asset_management_essentials 7.1
ibm maximo_asset_management 6.2
ibm tivoli_change_and_configuration_management_database 7.2
ibm maximo_service_desk 6.2
ibm maximo_asset_management_essentials 6.2
ibm tivoli_change_and_configuration_management_database 7.1
CVE-2011-4818 MEDIUM

Open redirect vulnerability in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via the uisessionid parameter to an unspecified component.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm maximo_asset_management 6.2
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.5
ibm maximo_asset_management_essentials 7.5
ibm maximo_asset_management_essentials 6.2
ibm maximo_asset_management_essentials 7.1
CVE-2011-4819 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5 allow remote attackers to inject arbitrary web script or HTML via the uisesionid parameter to (1) maximo.jsp or (2) the default URI under ui/.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm maximo_asset_management 6.2
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.5
ibm maximo_asset_management_essentials 7.5
ibm maximo_asset_management_essentials 6.2
ibm maximo_asset_management_essentials 7.1
CVE-2011-4889 HIGH

The javax.naming.directory.AttributeInUseException class in the Virtual Member Manager in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.43, 7.0 before 7.0.0.21, and 8.0 before 8.0.0.2 does not properly update passwords on a configuration using Tivoli Directory Server, which might allow remote attackers to gain access to an application by leveraging knowledge of an old password. IBM X-Force ID: 72581.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-254,

Products Affected

Vendor Product Version
ibm websphere_application_server *
CVE-2011-4890 MEDIUM

The server in IBM solidDB 6.5 before FP9 and 7.0 before FP1 allows remote authenticated users to cause a denial of service (daemon crash) via a SELECT statement with a ROWNUM condition involving a subquery.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm soliddb 6.5.0.2
ibm soliddb 6.5.0.0
ibm soliddb 6.5.0.4
ibm soliddb *
ibm soliddb 6.5.0.5
ibm soliddb 6.5.0.7
ibm soliddb 6.5.0.6
ibm soliddb 6.5.0.1
ibm soliddb 6.5.0.3
ibm soliddb 7.0.0.0
CVE-2011-5048 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in IBM Web Experience Factory (aka WEF, formerly WebSphere Portlet Factory) 7.0 and 7.0.1 allow remote attackers to inject arbitrary web script or HTML via a (1) text INPUT element or (2) TEXTAREA element, related to an interaction between Smart Refresh and Dojo.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm web_experience_factory 7.0.1
ibm web_experience_factory 7.0
CVE-2011-5065 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.41 allows remote attackers to inject arbitrary web script or HTML via vectors related to web messaging.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0
ibm websphere_application_server 6.1.0.35
ibm websphere_application_server 6.1
ibm websphere_application_server 6.1.6
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.1.3
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.1.5
ibm websphere_application_server 6.1.14
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 6.1.0.39
ibm websphere_application_server 6.1.7
ibm websphere_application_server 6.1.0.37
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.1
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.1.13
CVE-2011-5066 LOW

The SibRaRecoverableSiXaResource class in the Default Messaging Component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.41 does not properly handle a Service Integration Bus (SIB) dump operation involving the First Failure Data Capture (FFDC) introspection code, which allows local users to obtain sensitive information by reading the FFDC log file.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0
ibm websphere_application_server 6.1.0.35
ibm websphere_application_server 6.1
ibm websphere_application_server 6.1.6
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.1.3
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.1.5
ibm websphere_application_server 6.1.14
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 6.1.0.39
ibm websphere_application_server 6.1.7
ibm websphere_application_server 6.1.0.37
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.1
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.1.13
CVE-2012-0186 MEDIUM

Directory traversal vulnerability in the Eclipse Help component in IBM Lotus Expeditor 6.1.x and 6.2.x before 6.2 FP5+Security Pack allows remote attackers to discover the locations of files via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm lotus_expeditor 6.2.3
ibm lotus_expeditor 6.2.2
ibm lotus_expeditor 6.1.1
ibm lotus_expeditor 6.2
ibm lotus_expeditor 6.1
ibm lotus_expeditor 6.2.1
CVE-2012-0187 HIGH

Untrusted search path vulnerability in IBM Lotus Expeditor 6.1.x and 6.2.x before 6.2 FP5+Security Pack allows local users to gain privileges via a Trojan horse DLL in the current working directory.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm lotus_expeditor 6.2.3
ibm lotus_expeditor 6.2.2
ibm lotus_expeditor 6.1.1
ibm lotus_expeditor 6.2
ibm lotus_expeditor 6.1
ibm lotus_expeditor 6.2.1
CVE-2012-0188 HIGH

Unspecified vulnerability in the SetLicenseInfoEx method in an ActiveX control in mraboutb.dll in IBM SPSS Dimensions 5.5 and SPSS Data Collection 5.6, 6.0, and 6.0.1 allows remote attackers to execute arbitrary code via a crafted HTML document.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm spss_data_collection 6.0
ibm spss_data_collection 6.0.1
ibm spss_data_collection 5.6
ibm spss_dimensions 5.5
CVE-2012-0189 HIGH

Multiple unspecified vulnerabilities in the (1) PrintFile and (2) SaveDoc methods in the VsVIEW6 ActiveX control in VsVIEW6.ocx in IBM SPSS SamplePower 3.0 allow remote attackers to execute arbitrary code via a crafted HTML document.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm spss_samplepower 3.0
CVE-2012-0190 HIGH

Unspecified vulnerability in the Render method in the ExportHTML.ocx ActiveX control in ExportHTML.dll in IBM SPSS Dimensions 5.5 and SPSS Data Collection 5.6, 6.0, and 6.0.1 allows remote attackers to execute arbitrary code via a crafted HTML document.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm spss_data_collection 6.0
ibm spss_data_collection 6.0.1
ibm spss_data_collection 5.6
ibm spss_dimensions 5.5
CVE-2012-0191 MEDIUM

The web container in IBM Lotus Expeditor 6.1.x and 6.2.x before 6.2 FP5+Security Pack does not properly perform access control for requests, which allows remote attackers to spoof a localhost request origin via crafted headers.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm lotus_expeditor 6.2.3
ibm lotus_expeditor 6.2.2
ibm lotus_expeditor 6.1.1
ibm lotus_expeditor 6.2
ibm lotus_expeditor 6.1
ibm lotus_expeditor 6.2.1
CVE-2012-0192 HIGH

Multiple integer overflows in vclmi.dll in the visual class library module in IBM Lotus Symphony before 3.0.1 might allow remote attackers to execute arbitrary code via an embedded (1) JPEG or (2) PNG image object in a Symphony document that triggers a heap-based buffer overflow, as demonstrated by a .doc file.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-189,

Products Affected

Vendor Product Version
ibm lotus_symphony 3.0.0.2
ibm lotus_symphony 3.0.0.1
ibm lotus_symphony *
ibm lotus_symphony 1.3
CVE-2012-0193 MEDIUM

IBM WebSphere Application Server (WAS) 6.0 through 6.0.2.43, 6.1 before 6.1.0.43, 7.0 before 7.0.0.23, and 8.0 before 8.0.0.3 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 6.0.2.19
ibm websphere_application_server 6.1.0.14
ibm websphere_application_server 6.0.2.7
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 6.0.0.2
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 6.1.0.35
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 6.0.2.33
ibm websphere_application_server 6.0.2.0
ibm websphere_application_server 6.0.2.25
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 6.0.0.0
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 6.0.2.31
ibm websphere_application_server 6.0.2.9
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.0.39
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 6.1.0.37
ibm websphere_application_server 6.0.2.35
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.0.2.43
ibm websphere_application_server 6.0.2.21
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 8.0.0.2
ibm websphere_application_server 6.0.2.2
ibm websphere_application_server 6.0.2.13
ibm websphere_application_server 6.0.1.11
ibm websphere_application_server 6.0.2.11
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 6.0.2.8
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 6.0.2.15
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 6.0.2.4
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.0.1.0
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.41
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.0.2.23
ibm websphere_application_server 6.0.2.6
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.0.2.17
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.0.2.37
ibm websphere_application_server 6.0.2.5
ibm websphere_application_server 6.0.1.12
ibm websphere_application_server 6.0.2.3
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.0.2.29
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.0.2.27
ibm websphere_application_server 6.0.0.3
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.0.2.1
CVE-2012-0194 HIGH

The TCP implementation in IBM AIX 5.3, 6.1, and 7.1, when the Large Send Offload option is enabled, allows remote attackers to cause a denial of service (assertion failure and panic) via an unspecified series of packets.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 6.1
ibm aix 7.1
CVE-2012-0195 MEDIUM

Cross-site scripting (XSS) vulnerability in the Start Center Layout and Configuration component in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Management for IT 6.2, 7.1, and 7.2; IBM Tivoli Service Request Manager 7.1 and 7.2; IBM Maximo Service Desk 6.2; and IBM Tivoli Change and Configuration Management Database (CCMDB) 6.2, 7.1, and 7.2 allows remote attackers to inject arbitrary web script or HTML via the display name.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_asset_management_for_it 7.2
ibm trivoli_service_request_manager 7.2
ibm tivoli_asset_management_for_it 6.2
ibm trivoli_service_request_manager 7.1
ibm maximo_asset_management 7.1
ibm tivoli_change_and_configuration_management_database 6.2
ibm maximo_asset_management 7.5
ibm maximo_asset_management_essentials 7.5
ibm tivoli_asset_management_for_it 7.1
ibm maximo_asset_management_essentials 7.1
ibm maximo_asset_management 6.2
ibm tivoli_change_and_configuration_management_database 7.2
ibm maximo_service_desk 6.2
ibm maximo_asset_management_essentials 6.2
ibm tivoli_change_and_configuration_management_database 7.1
CVE-2012-0198 HIGH

Stack-based buffer overflow in the RunAndUploadFile method in the Isig.isigCtl.1 ActiveX control in IBM Tivoli Provisioning Manager Express for Software Distribution 4.1.1 allows remote attackers to execute arbitrary code via vectors related to an Asset Information file.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm tivoli_provisioning_manager_express_for_software_distribution 4.1.1
CVE-2012-0199 HIGH

Multiple SQL injection vulnerabilities in IBM Tivoli Provisioning Manager Express for Software Distribution 4.1.1 allow remote attackers to execute arbitrary SQL commands via (1) a SOAP message to the Printer.getPrinterAgentKey function in the SoapServlet servlet, (2) the User.updateUserValue function in the register.do servlet, (3) the User.isExistingUser function in the logon.do servlet, (4) the Asset.getHWKey function in the CallHomeExec servlet, (5) the Asset.getMimeType function in the getAttachment (aka GetAttachmentServlet) servlet, (6) the addAsset.do servlet, or (7) a crafted EG2 file.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm tivoli_provisioning_manager_express_for_software_distribution 4.1.1
CVE-2012-0200 MEDIUM

The server in IBM solidDB 6.5 before Interim Fix 6 does not properly initialize data structures, which allows remote authenticated users to cause a denial of service (daemon crash) via a SELECT statement with a redundant WHERE condition.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm soliddb 6.5.0.2
ibm soliddb 6.5.0.0
ibm soliddb 6.5.0.4
ibm soliddb *
ibm soliddb 6.5.0.5
ibm soliddb 6.5.0.7
ibm soliddb 6.5.0.6
ibm soliddb 6.5.0.1
ibm soliddb 6.5.0.3
CVE-2012-0201 HIGH

Stack-based buffer overflow in pcspref.dll in pcsws.exe in IBM Personal Communications 5.9.x before 5.9.8 and 6.0.x before 6.0.4 might allow remote attackers to execute arbitrary code via a long profile string in a WorkStation (aka .ws) file.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm personal_communications 5.9.7.0
ibm personal_communications 5.9.7.1
ibm personal_communications 6.0.3.0
CVE-2012-0202 HIGH

Multiple stack-based buffer overflows in tm1admsd.exe in the Admin Server in IBM Cognos TM1 9.4.x and 9.5.x before 9.5.2 FP2 allow remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via crafted data.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm cognos_tm1 9.4.1.3
ibm cognos_tm1 9.5.2
ibm cognos_tm1 9.4.1
ibm cognos_tm1 9.5.1
CVE-2012-0203 MEDIUM

Cross-site scripting (XSS) vulnerability in InfoSphere Metadata Workbench (MWB) 8.1 through 8.7 in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm infosphere_information_server 8.5.0.2
ibm infosphere_metadata_workbench 8.1
ibm infosphere_information_server 8.5.0.1
ibm infosphere_metadata_workbench 8.5
ibm infosphere_information_server 8.1
ibm infosphere_metadata_workbench 8.7
ibm infosphere_information_server 8.5
ibm infosphere_metadata_workbench 8.1.2
ibm infosphere_metadata_workbench 8.1.1
CVE-2012-0204 HIGH

Untrusted search path vulnerability in InfoSphere Import Export Manager 8.1 through 9.1 in InfoSphere Information Server MetaBrokers & Bridges (MBB) in IBM InfoSphere Information Server 8.1, 8.5 before FP3, 8.7, and 9.1 allows local users to gain privileges via a Trojan horse DLL in the current working directory.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm infosphere_information_server 8.5.0.2
ibm infosphere_import_export_manager 8.5
ibm infosphere_information_server 8.5.0.1
ibm infosphere_information_server 8.5
ibm infosphere_information_server 9.1
ibm infosphere_import_export_manager 8.1.1
ibm infosphere_import_export_manager 8.1.2
ibm infosphere_import_export_manager 9.1
ibm infosphere_import_export_manager 8.1
ibm infosphere_information_server_metabrokers_&_bridges -
ibm infosphere_information_server 8.1
ibm infosphere_import_export_manager 8.7
ibm infosphere_information_server 8.7
CVE-2012-0205 MEDIUM

InfoSphere Metadata Workbench (MWB) 8.1 through 8.7 in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 does not properly restrict use of the troubleshooting feature, which allows remote authenticated users to bypass intended access restrictions or cause a denial of service (workbench outage) via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm infosphere_information_server 8.5.0.2
ibm infosphere_metadata_workbench 8.1
ibm infosphere_information_server 8.5.0.1
ibm infosphere_metadata_workbench 8.5
ibm infosphere_information_server 8.1
ibm infosphere_metadata_workbench 8.7
ibm infosphere_information_server 8.5
ibm infosphere_metadata_workbench 8.1.2
ibm infosphere_information_server 8.7
ibm infosphere_metadata_workbench 8.1.1
CVE-2012-0696 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in the Executive Viewer (EV) in IBM Cognos TM1 before 9.5 FP1 allow remote attackers to inject arbitrary web script or HTML via unspecified requests to (1) aspnet_client or (2) evserver/createcontrol.js.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm cognos_tm1 9.4.0
ibm cognos_executive_viewer *
ibm cognos_tm1 *
ibm cognos_tm1 9.4.1
CVE-2012-0700 LOW

The client in InfoSphere FastTrack 8.1 through 8.7 in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 does not properly store credentials, which allows local users to bypass intended access restrictions via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm infosphere_information_server 8.5.0.2
ibm infosphere_fasttrack 8.5
ibm infosphere_information_server 8.5.0.1
ibm infosphere_fasttrack 8.7
ibm infosphere_information_server 8.1
ibm infosphere_information_server 8.5
ibm infosphere_fasttrack 8.1
ibm infosphere_information_server 8.7
ibm infosphere_fasttrack 8.1.1
ibm infosphere_fasttrack 8.1.2
CVE-2012-0701 MEDIUM

The client applications in the DataStage Administrator client in InfoSphere DataStage in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 rely on client-side access control, which allows remote authenticated users to gain privileges via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm infosphere_information_server 8.5.0.2
ibm infosphere_information_server 8.5.0.1
ibm infosphere_datastage -
ibm infosphere_information_server 8.1
ibm infosphere_information_server 8.5
ibm infosphere_information_server 8.7
CVE-2012-0702 MEDIUM

Information Services Framework (ISF) in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 does not properly determine authorization, which allows remote authenticated users to gain privileges via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm infosphere_information_server 8.5.0.2
ibm infosphere_information_server 8.5.0.1
ibm infosphere_information_server 8.1
ibm infosphere_information_server 8.5
ibm infosphere_information_server 8.7
ibm infosphere_information_server_information_services_framework -
CVE-2012-0703 MEDIUM

Open redirect vulnerability in Information Services Framework (ISF) in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm infosphere_information_server 8.5.0.2
ibm infosphere_information_server 8.5.0.1
ibm infosphere_information_server 8.1
ibm infosphere_information_server 8.5
ibm infosphere_information_server 8.7
ibm infosphere_information_server_information_services_framework -
CVE-2012-0705 HIGH

InfoSphere Import Export Manager in InfoSphere Information Server MetaBrokers & Bridges (MBB) in IBM InfoSphere Information Server 8.1, 8.5 before FP3, 8.7, and 9.1 does not validate unspecified input data, which allows remote authenticated users to execute arbitrary commands via unknown vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm infosphere_information_server 8.5.0.2
ibm infosphere_information_server 8.5.0.1
ibm infosphere_information_server_metabrokers_&_bridges -
ibm infosphere_information_server 8.1
ibm infosphere_information_server 8.5
ibm infosphere_information_server 9.1
ibm infosphere_information_server 8.7
CVE-2012-0706 LOW

IBM Scale Out Network Attached Storage (SONAS) 1.3 before 1.3.2.3 requires cleartext storage of LDAP credentials without recommending a less privileged LDAP account, which might allow attackers to obtain sensitive server information by leveraging root access to a client machine.

CVSS 2.0

Severity: LOW

Problem Type: CWE-255,CWE-264,

Products Affected

Vendor Product Version
ibm scale_out_network_attached_storage 1.3
CVE-2012-0707 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM WebSphere Lombardi Edition 7.2 allows remote attackers to inject arbitrary web script or HTML via crafted text input to a coach that is configured with a document attachment control section.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.2
CVE-2012-0708 HIGH

Heap-based buffer overflow in the Ole API in the CQOle ActiveX control in cqole.dll in IBM Rational ClearQuest 7.1.1 before 7.1.1.9, 7.1.2 before 7.1.2.6, and 8.0.0 before 8.0.0.2 allows remote attackers to execute arbitrary code via a crafted web page that leverages a RegisterSchemaRepoFromFileByDbSet function-prototype mismatch.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm rational_clearquest 7.1.2.1
ibm rational_clearquest 7.1.2.3
ibm rational_clearquest 7.1.2
ibm rational_clearquest 7.1.1.4
ibm rational_clearquest 7.1.2.5
ibm rational_clearquest 7.1.2.6
ibm rational_clearquest 7.1.1.1
ibm rational_clearquest 7.1.2.2
ibm rational_clearquest 7.1.1.3
ibm rational_clearquest 8.0.0.1
ibm rational_clearquest 7.1.1.2
ibm rational_clearquest 7.1.2.4
ibm rational_clearquest 7.1.1
ibm rational_clearquest 8.0.0
CVE-2012-0709 MEDIUM

IBM DB2 9.5 before FP9, 9.7 through FP5, and 9.8 through FP4 does not properly check variables, which allows remote authenticated users to bypass intended restrictions on viewing table data by leveraging the CREATEIN privilege to execute crafted SQL CREATE VARIABLE statements.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm db2 9.5
ibm db2 9.8
ibm db2 9.7
CVE-2012-0710 MEDIUM

IBM DB2 9.1 before FP11, 9.5 before FP9, 9.7 before FP5, and 9.8 before FP4 allows remote attackers to cause a denial of service (daemon crash) via a crafted Distributed Relational Database Architecture (DRDA) request.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm db2 9.1
ibm db2 9.5
ibm db2 9.8
ibm db2 9.7
CVE-2012-0711 HIGH

Integer signedness error in the db2dasrrm process in the DB2 Administration Server (DAS) in IBM DB2 9.1 through FP11, 9.5 before FP9, and 9.7 through FP5 on UNIX platforms allows remote attackers to execute arbitrary code via a crafted request that triggers a heap-based buffer overflow.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-189,

Products Affected

Vendor Product Version
ibm db2 9.1
ibm db2 9.5
ibm db2 9.7
CVE-2012-0712 MEDIUM

The XML feature in IBM DB2 9.5 before FP9, 9.7 through FP5, and 9.8 through FP4 allows remote authenticated users to cause a denial of service (infinite loop) by calling the XMLPARSE function with a crafted string expression.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm db2 9.5
ibm db2 9.8
ibm db2 9.7
CVE-2012-0713 LOW

Unspecified vulnerability in the XML feature in IBM DB2 9.7 before FP6 on Linux, UNIX, and Windows allows remote authenticated users to read arbitrary XML files via unknown vectors.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm db2 9.7.0.3
ibm db2 9.7.0.5
ibm db2 9.7.0.2
ibm db2 9.7.0.1
ibm db2 9.7.0.4
ibm db2 9.7
CVE-2012-0714 MEDIUM

Cross-site request forgery (CSRF) vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm tivoli_asset_management_for_it 7.2
ibm tivoli_asset_management_for_it 6.0
ibm change_and_configuration_management_database 6.0
ibm tivoli_asset_management_for_it 6.2
ibm change_and_configuration_management_database 7.0
ibm tivoli_service_request_manager 7.0
ibm tivoli_asset_management_for_it 7.1
ibm maximo_asset_management 7.1.0.0
ibm maximo_asset_management 7.5.0.0
ibm tivoli_asset_management_for_it 7.0
ibm maximo_service_desk 6.2
ibm maximo_asset_management 6.2.0.0
ibm smartcloud_control_desk 7.0
CVE-2012-0715 MEDIUM

Cross-site scripting (XSS) vulnerability in the Gantt applet viewer in IBM Tivoli Change and Configuration Management Database (CCMDB) 7.2.1 and IBM ILOG JViews Gantt allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_change_and_configuration_management_database 7.2.1
ibm ilog_jviews_gantt -
CVE-2012-0716 MEDIUM

Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server 7.0 before 7.0.0.23 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 7.0.0.4
ibm websphere_application_server 7.0.0.13
CVE-2012-0717 LOW

IBM WebSphere Application Server 7.0 before 7.0.0.23, when a certain SSLv2 configuration with client authentication is used, allows remote attackers to bypass X.509 client-certificate authentication via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 7.0.0.4
ibm websphere_application_server 7.0.0.13
CVE-2012-0719 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Tivoli Endpoint Manager (TEM) 8 before 8.2 patch 3 allows remote attackers to inject arbitrary web script or HTML via the ScheduleParam parameter to the webreports program.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_endpoint_manager 8.2
ibm tivoli_endpoint_manager 8.0
ibm tivoli_endpoint_manager 8.1
CVE-2012-0720 MEDIUM

Cross-site scripting (XSS) vulnerability in the Integration Solution Console in the Administration Console in IBM WebSphere Application Server 7.0 before 7.0.0.23 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 7.0.0.4
ibm websphere_application_server 7.0.0.13
CVE-2012-0723 MEDIUM

The kernel in IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly implement the dupmsg system call, which allows local users to cause a denial of service (system crash) via a crafted application.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 6.1
ibm vios 2.2.1.4
ibm aix 7.1
CVE-2012-0726 MEDIUM

The default configuration of TLS in IBM Tivoli Directory Server (TDS) 6.3 and earlier supports the (1) NULL-MD5 and (2) NULL-SHA ciphers, which allows remote attackers to trigger unencrypted communication via the TLS Handshake Protocol.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm tivoli_directory_server 6.1.0.45
ibm tivoli_directory_server 5.2.0
ibm tivoli_directory_server 6.2.0.20
ibm tivoli_directory_server 6.0.0.7
ibm tivoli_directory_server 4.1
ibm tivoli_directory_server 6.2.0
ibm tivoli_directory_server 6.0.0.8
ibm tivoli_directory_server 6.0
ibm tivoli_directory_server 6.2.0.22
ibm tivoli_directory_server *
ibm tivoli_directory_server 6.1.0.48
ibm tivoli_directory_server 6.1.0
ibm tivoli_directory_server 6.0.0
ibm tivoli_directory_server 6.1.0.47
ibm tivoli_directory_server 6.2.0.21
ibm tivoli_directory_server 3.2.2
ibm tivoli_directory_server 6.1.0.46
ibm tivoli_directory_server 6.2.0.19
ibm tivoli_directory_server 6.0.0.69
CVE-2012-0727 MEDIUM

SQL injection vulnerability in IBM Maximo Asset Management 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm tivoli_asset_management_for_it 7.2
ibm tivoli_asset_management_for_it 7.0
ibm tivoli_asset_management_for_it 6.0
ibm change_and_configuration_management_database 6.0
ibm tivoli_asset_management_for_it 6.2
ibm maximo_service_desk 6.2
ibm change_and_configuration_management_database 7.0
ibm tivoli_service_request_manager 7.0
ibm tivoli_asset_management_for_it 7.1
ibm smartcloud_control_desk 7.0
ibm maximo_asset_management 7.5.0.0
CVE-2012-0728 MEDIUM

SQL injection vulnerability in IBM Maximo Asset Management 7.1 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm tivoli_asset_management_for_it 7.2
ibm tivoli_asset_management_for_it 6.0
ibm change_and_configuration_management_database 6.0
ibm tivoli_asset_management_for_it 6.2
ibm change_and_configuration_management_database 7.0
ibm tivoli_service_request_manager 7.0
ibm tivoli_asset_management_for_it 7.1
ibm maximo_asset_management 7.1.0.0
ibm maximo_asset_management 7.5.0.0
ibm tivoli_asset_management_for_it 7.0
ibm maximo_service_desk 6.2
ibm smartcloud_control_desk 7.0
CVE-2012-0729 MEDIUM

Unrestricted file upload vulnerability in IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 allows remote authenticated users to execute arbitrary ASP.NET code by uploading a .aspx file, and then accessing it via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm rational_appscan 5.6.0
ibm rational_appscan 5.5.0
ibm rational_appscan 8.0.1.1
ibm rational_appscan 5.5.0.2
ibm rational_appscan 8.0.0.1
ibm rational_appscan 8.0.0.3
ibm rational_appscan 5.6.0.3
ibm rational_appscan 8.0.0
ibm rational_appscan 5.4
ibm rational_appscan 5.2
ibm rational_appscan 8.5.0
ibm rational_appscan 5.5.0.1
ibm rational_appscan 8.0.1
ibm rational_appscan 8.5.0.0
ibm rational_appscan 8.0.0.2
CVE-2012-0730 MEDIUM

Multiple cross-site request forgery (CSRF) vulnerabilities in IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 allow remote attackers to hijack the authentication of administrators for requests that create administrative accounts.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm rational_appscan 5.6.0
ibm rational_appscan 5.5.0
ibm rational_appscan 8.0.1.1
ibm rational_appscan 5.5.0.2
ibm rational_appscan 8.0.0.1
ibm rational_appscan 8.0.0.3
ibm rational_appscan 5.6.0.3
ibm rational_appscan 8.0.0
ibm rational_appscan 5.4
ibm rational_appscan 5.2
ibm rational_appscan 8.5.0
ibm rational_appscan 5.5.0.1
ibm rational_appscan 8.0.1
ibm rational_appscan 8.5.0.0
ibm rational_appscan 8.0.0.2
CVE-2012-0731 MEDIUM

IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 does not prevent service-account impersonation, which allows remote authenticated users to read arbitrary files via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_appscan 5.6.0
ibm rational_appscan 5.5.0
ibm rational_appscan 8.0.1.1
ibm rational_appscan 5.5.0.2
ibm rational_appscan 8.0.0.1
ibm rational_appscan 8.0.0.3
ibm rational_appscan 5.6.0.3
ibm rational_appscan 8.0.0
ibm rational_appscan 5.4
ibm rational_appscan 5.2
ibm rational_appscan 8.5.0
ibm rational_appscan 5.5.0.1
ibm rational_appscan 8.0.1
ibm rational_appscan 8.5.0.0
ibm rational_appscan 8.0.0.2
CVE-2012-0732 MEDIUM

The Enterprise Console client in IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm rational_appscan 5.6.0
ibm rational_appscan 5.5.0
ibm rational_appscan 8.0.1.1
ibm rational_appscan 5.5.0.2
ibm rational_appscan 8.0.0.1
ibm rational_appscan 8.0.0.3
ibm rational_appscan 5.6.0.3
ibm rational_appscan 8.0.0
ibm rational_appscan 5.4
ibm rational_appscan 5.2
ibm rational_appscan 8.5.0
ibm rational_appscan 5.5.0.1
ibm rational_appscan 8.0.1
ibm rational_appscan 8.5.0.0
ibm rational_appscan 8.0.0.2
CVE-2012-0733 MEDIUM

IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1, when Integrated Windows authentication is used, allows remote authenticated users to obtain administrative privileges by hijacking a session associated with the service account.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm rational_appscan 5.6.0
ibm rational_appscan 5.5.0
ibm rational_appscan 8.0.1.1
ibm rational_appscan 5.5.0.2
ibm rational_appscan 8.0.0.1
ibm rational_appscan 8.0.0.3
ibm rational_appscan 5.6.0.3
ibm rational_appscan 8.0.0
ibm rational_appscan 5.4
ibm rational_appscan 5.2
ibm rational_appscan 8.5.0
ibm rational_appscan 5.5.0.1
ibm rational_appscan 8.0.1
ibm rational_appscan 8.5.0.0
ibm rational_appscan 8.0.0.2
CVE-2012-0734 HIGH

IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 does not properly import jobs, which allows man-in-the-middle attackers to obtain sensitive information or possibly have unspecified other impact via a crafted job.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm rational_appscan 5.6.0
ibm rational_appscan 5.5.0
ibm rational_appscan 8.0.1.1
ibm rational_appscan 5.5.0.2
ibm rational_appscan 8.0.0.1
ibm rational_appscan 8.0.0.3
ibm rational_appscan 5.6.0.3
ibm rational_appscan 8.0.0
ibm rational_appscan 5.4
ibm rational_appscan 5.2
ibm rational_appscan 8.5.0
ibm rational_appscan 5.5.0.1
ibm rational_appscan 8.0.1
ibm rational_appscan 8.5.0.0
ibm rational_appscan 8.0.0.2
CVE-2012-0735 HIGH

IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 does not properly scan file: URLs, which allows man-in-the-middle attackers to obtain sensitive information or possibly have unspecified other impact via a crafted URI.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm rational_appscan 5.6.0
ibm rational_appscan 5.5.0
ibm rational_appscan 8.0.1.1
ibm rational_appscan 5.5.0.2
ibm rational_appscan 8.0.0.1
ibm rational_appscan 8.0.0.3
ibm rational_appscan 5.6.0.3
ibm rational_appscan 8.0.0
ibm rational_appscan 5.4
ibm rational_appscan 5.2
ibm rational_appscan 8.5.0
ibm rational_appscan 5.5.0.1
ibm rational_appscan 8.0.1
ibm rational_appscan 8.5.0.0
ibm rational_appscan 8.0.0.2
CVE-2012-0736 HIGH

IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 does not properly create scan jobs, which allows remote attackers to execute arbitrary code via a crafted web site.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm rational_appscan 5.6.0
ibm rational_appscan 5.5.0
ibm rational_appscan 8.0.1.1
ibm rational_appscan 5.5.0.2
ibm rational_appscan 8.0.0.1
ibm rational_appscan 8.0.0.3
ibm rational_appscan 5.6.0.3
ibm rational_appscan 8.0.0
ibm rational_appscan 5.4
ibm rational_appscan 5.2
ibm rational_appscan 8.5.0
ibm rational_appscan 5.5.0.1
ibm rational_appscan 8.0.1
ibm rational_appscan 8.5.0.0
ibm rational_appscan 8.0.0.2
CVE-2012-0737 LOW

Cross-site scripting (XSS) vulnerability in IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_appscan 5.6.0
ibm rational_appscan 5.5.0
ibm rational_appscan 8.0.1.1
ibm rational_appscan 5.5.0.2
ibm rational_appscan 8.0.0.1
ibm rational_appscan 8.0.0.3
ibm rational_appscan 5.6.0.3
ibm rational_appscan 8.0.0
ibm rational_appscan 5.4
ibm rational_appscan 5.2
ibm rational_appscan 8.5.0
ibm rational_appscan 5.5.0.1
ibm rational_appscan 8.0.1
ibm rational_appscan 8.5.0.0
ibm rational_appscan 8.0.0.2
CVE-2012-0738 MEDIUM

IBM Security AppScan Enterprise before 8.6.0.2 and Rational Policy Tester before 8.5.0.3 do not validate X.509 certificates during scanning, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary certificate.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm security_appscan 8.0.0.1
ibm rational_policy_tester 8.0.0.0
ibm rational_policy_tester 5.6.0.0
ibm security_appscan 6.0.0.0
ibm security_appscan 6.0.2.0
ibm rational_policy_tester 8.5.0.1
ibm security_appscan 8.5.0.1
ibm security_appscan 6.1.1.0
ibm security_appscan 8.5.0.0
ibm security_appscan 6.0.1.0
ibm rational_policy_tester 5.5.0.1
ibm rational_policy_tester 8.0.1.0
ibm rational_policy_tester 8.5.0.0
ibm rational_policy_tester 5.5.0.2
ibm rational_policy_tester 8.0.1.1
ibm rational_policy_tester 5.5.0.0
ibm rational_policy_tester 5.6.0.2
ibm security_appscan 8.6.0.0
ibm rational_policy_tester *
ibm rational_policy_tester 8.0.0.1
ibm security_appscan *
ibm security_appscan 8.0.0.0
ibm rational_policy_tester 8.0.0.2
ibm rational_policy_tester 5.6.0.3
ibm rational_policy_tester 5.6.0.1
CVE-2012-0740 MEDIUM

Cross-site scripting (XSS) vulnerability in the Web Admin Tool in IBM Tivoli Directory Server (TDS) 6.2 before 6.2.0.22 and 6.3 before 6.3.0.11 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_directory_server 6.2
ibm tivoli_directory_server 6.2.0.20
ibm tivoli_directory_server 6.3.0.9
ibm tivoli_directory_server 6.3.0.10
ibm tivoli_directory_server 6.3.0
ibm tivoli_directory_server 6.3.0.0
ibm tivoli_directory_server 6.2.0.21
ibm tivoli_directory_server 6.2.0.19
ibm tivoli_directory_server 6.3.0.8
CVE-2012-0741 MEDIUM

IBM Security AppScan Enterprise before 8.6.0.2 and Rational Policy Tester before 8.5.0.3 do not validate X.509 certificates during use of the Manual Explore Proxy feature, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary certificate.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm security_appscan 8.0.0.1
ibm rational_policy_tester 8.0.0.0
ibm rational_policy_tester 5.6.0.0
ibm security_appscan 6.0.0.0
ibm security_appscan 6.0.2.0
ibm rational_policy_tester 8.5.0.1
ibm security_appscan 8.5.0.1
ibm security_appscan 6.1.1.0
ibm security_appscan 8.5.0.0
ibm security_appscan 6.0.1.0
ibm rational_policy_tester 5.5.0.1
ibm rational_policy_tester 8.0.1.0
ibm rational_policy_tester 8.5.0.0
ibm rational_policy_tester 5.5.0.2
ibm rational_policy_tester 8.0.1.1
ibm rational_policy_tester 5.5.0.0
ibm rational_policy_tester 5.6.0.2
ibm security_appscan 8.6.0.0
ibm rational_policy_tester *
ibm rational_policy_tester 8.0.0.1
ibm security_appscan *
ibm security_appscan 8.0.0.0
ibm rational_policy_tester 8.0.0.2
ibm rational_policy_tester 5.6.0.3
ibm rational_policy_tester 5.6.0.1
CVE-2012-0742 LOW

IBM Tivoli Event Pump 4.2.2, when the LOG_REQUESTS and VALIDATE_SOAP_USERS options are enabled, places credentials into the AOPSCLOG (aka AOPLOG) data set, which allows local users to obtain sensitive information by reading the data.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm tivoli_event_pump 4.2.2
CVE-2012-0743 MEDIUM

IBM Tivoli Directory Server (TDS) 6.3 and earlier allows remote attackers to cause a denial of service (daemon crash) via a malformed LDAP paged search request.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm tivoli_directory_server 6.1.0.45
ibm tivoli_directory_server 5.2.0
ibm tivoli_directory_server 6.2.0.20
ibm tivoli_directory_server 6.0.0.7
ibm tivoli_directory_server 4.1
ibm tivoli_directory_server 6.2.0
ibm tivoli_directory_server 6.0.0.8
ibm tivoli_directory_server 6.0
ibm tivoli_directory_server 6.2.0.22
ibm tivoli_directory_server *
ibm tivoli_directory_server 6.1.0.48
ibm tivoli_directory_server 6.1.0
ibm tivoli_directory_server 6.0.0
ibm tivoli_directory_server 6.1.0.47
ibm tivoli_directory_server 6.2.0.21
ibm tivoli_directory_server 3.2.2
ibm tivoli_directory_server 6.1.0.46
ibm tivoli_directory_server 6.2.0.19
ibm tivoli_directory_server 6.0.0.69
CVE-2012-0744 MEDIUM

IBM Rational ClearQuest 7.1.x through 7.1.2.7 and 8.x through 8.0.0.3 allows remote attackers to obtain potentially sensitive information via a request to a (1) snoop, (2) hello, (3) ivt/, (4) hitcount, (5) HitCount.jsp, (6) HelloHTMLError.jsp, (7) HelloHTML.jsp, (8) HelloVXMLError.jsp, (9) HelloVXML.jsp, (10) HelloWMLError.jsp, (11) HelloWML.jsp, or (12) cqweb/j_security_check sample script.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_clearquest 7.1.2.1
ibm rational_clearquest 7.1.2.3
ibm rational_clearquest 8.0.0.2
ibm rational_clearquest 7.1.2
ibm rational_clearquest 7.1.1.4
ibm rational_clearquest 7.1.2.5
ibm rational_clearquest 7.1.1.8
ibm rational_clearquest 7.1.2.6
ibm rational_clearquest 7.1.1.1
ibm rational_clearquest 7.1.2.2
ibm rational_clearquest 7.1.1.6
ibm rational_clearquest 7.1.1.3
ibm rational_clearquest 8.0.0.1
ibm rational_clearquest 8.0.0.3
ibm rational_clearquest 7.1.1.7
ibm rational_clearquest 8.0
ibm rational_clearquest 7.1.1.5
ibm rational_clearquest 7.1.1.2
ibm rational_clearquest 7.1.2.4
CVE-2012-0745 HIGH

The getpwnam function in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.1.0.10 through 2.2.1.3 does not properly interact with customer-extended LDAP user filtering, which allows local users to gain privileges via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm aix 6.1
ibm vios 2.1.2.12
ibm vios 2.2.0.10
ibm vios 2.2.1.1
ibm aix 7.1
ibm vios 2.1.2.13
ibm vios 2.2.0.12
ibm vios 2.2.0.13
ibm vios 2.2.1.3
ibm aix 5.3
ibm vios 2.1.3.10
ibm vios 2.2.0.11
ibm vios 2.1.0.10
ibm vios 2.2.1.0
CVE-2012-0746 LOW

Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_asset_management_for_it 7.2
ibm tivoli_asset_management_for_it 7.0
ibm tivoli_asset_management_for_it 6.0
ibm change_and_configuration_management_database 6.0
ibm tivoli_asset_management_for_it 6.2
ibm maximo_service_desk 6.2
ibm change_and_configuration_management_database 7.0
ibm tivoli_service_request_manager 7.0
ibm tivoli_asset_management_for_it 7.1
ibm smartcloud_control_desk 7.0
ibm maximo_asset_management 7.5.0.0
CVE-2012-0747 MEDIUM

SQL injection vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm tivoli_asset_management_for_it 7.2
ibm tivoli_asset_management_for_it 6.0
ibm change_and_configuration_management_database 6.0
ibm tivoli_asset_management_for_it 6.2
ibm change_and_configuration_management_database 7.0
ibm tivoli_service_request_manager 7.0
ibm tivoli_asset_management_for_it 7.1
ibm maximo_asset_management 7.1.0.0
ibm maximo_asset_management 7.5.0.0
ibm tivoli_asset_management_for_it 7.0
ibm maximo_service_desk 6.2
ibm maximo_asset_management 6.2.0.0
ibm smartcloud_control_desk 7.0
CVE-2012-0748 MEDIUM

Multiple cross-site request forgery (CSRF) vulnerabilities in unspecified services in IBM Rational Team Concert (RTC) 4.x before 4.0.0.1 allow remote attackers to hijack the authentication of arbitrary users for requests that modify work items.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm rational_team_concert 4.0
CVE-2012-1046 MEDIUM

Cross-site scripting (XSS) vulnerability in TM1 Web in IBM Cognos TM1 9.5.2 FP1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2012-0696.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm cognos_tm1 9.5.2
CVE-2012-1796 HIGH

Unspecified vulnerability in IBM Tivoli Monitoring Agent (ITMA), as used in IBM DB2 9.5 before FP9 on UNIX, allows local users to gain privileges via unknown vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm db2 9.5
CVE-2012-1797 HIGH

IBM DB2 9.5 uses world-writable permissions for nodes.reg, which has unspecified impact and attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm db2 9.5
CVE-2012-1837 MEDIUM

The (1) webreports, (2) post/create-role, and (3) post/update-role programs in IBM Tivoli Endpoint Manager (TEM) before 8.2 do not include the HTTPOnly flag in a Set-Cookie header for a cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm tivoli_endpoint_manager 8.0
ibm tivoli_endpoint_manager *
CVE-2012-1844 HIGH

The Quantum Scalar i500 tape library with firmware before i7.0.3 (604G.GS00100), also distributed as the Dell ML6000 tape library with firmware before A20-00 (590G.GS00100) and the IBM TS3310 tape library with firmware before R6C (606G.GS001), uses default passwords for unspecified user accounts, which makes it easier for remote attackers to obtain access via unknown vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-255,

Products Affected

Vendor Product Version
quantum scalar_i500_firmware i3.1
quantum scalar_i500_firmware i7
quantum scalar_i500_firmware i3
quantum scalar_i500_firmware i2
quantum scalar_i500_firmware *
quantum scalar_i500_firmware i7.0.1
dell powervault_ml6000 41u
dell powervault_ml6000 32u
dell powervault_ml6030 23u
quantum scalar_i500_firmware sp4
quantum scalar_i500_firmware i4
ibm ts3310_tape_library_firmware *
quantum scalar_i500_firmware i5.1
quantum scalar_i500 5u
dell powervault_ml6020 14u
ibm ts3310_tape_library 3573
quantum scalar_i500_firmware i5
quantum scalar_i500_firmware i6
quantum scalar_i500_firmware sp4.2
quantum scalar_i500 23u
ibm ts3310_tape_library 3576
quantum scalar_i500 14u
quantum scalar_i500_firmware i6.1
dell powervault_ml6000_firmware 585g.gs003
dell powervault_ml6010 5u
CVE-2012-2159 MEDIUM

Open redirect vulnerability in IBM Eclipse Help System (IEHS), as used in IBM Security AppScan Source 7.x and 8.x before 8.6 and IBM SPSS Data Collection Developer Library 6.0 and 6.0.1, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm spss_data_collection 6.0
ibm spss_data_collection 6.0.1
ibm security_appscan_source 8.5.0.1
ibm security_appscan_source 8.0.0.1
ibm security_appscan_source 8.5
ibm security_appscan_source 8.0.0.2
ibm security_appscan_source 7.0
ibm security_appscan_source 8.0
CVE-2012-2161 MEDIUM

Cross-site scripting (XSS) vulnerability in deferredView.jsp in IBM Eclipse Help System (IEHS), as used in IBM Security AppScan Source 7.x and 8.x before 8.6 and IBM SPSS Data Collection Developer Library 6.0 and 6.0.1, allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm spss_data_collection 6.0
ibm spss_data_collection 6.0.1
ibm security_appscan_source 8.5.0.1
ibm security_appscan_source 8.0.0.1
ibm security_appscan_source 8.5
ibm security_appscan_source 8.0.0.2
ibm security_appscan_source 7.0
ibm security_appscan_source 8.0
CVE-2012-2162 MEDIUM

The Web Server Plug-in in IBM WebSphere Application Server (WAS) 8.0 and earlier uses unencrypted HTTP communication after expiration of the plugin-key.kdb password, which allows remote attackers to obtain sensitive information by sniffing the network, or spoof arbitrary servers via a man-in-the-middle attack.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0
ibm websphere_application_server 6.0.2.19
ibm websphere_application_server 6.0.2.7
ibm websphere_application_server 5.0.2.6
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 5.1.1.12
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server *
ibm websphere_application_server 5.1.0.2
ibm websphere_application_server 5.1.1.16
ibm websphere_application_server 6.0.2.25
ibm websphere_application_server 6.0.2.9
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.0.37
ibm websphere_application_server 5.1.1.9
ibm websphere_application_server 5.0.2.2
ibm websphere_application_server 6.1.1
ibm websphere_application_server 5.1.1.8
ibm websphere_application_server 5.1.1
ibm websphere_application_server 6.0.2.13
ibm websphere_application_server 6.0.1.11
ibm websphere_application_server 5.0.2.4
ibm websphere_application_server 5.0.2.15
ibm websphere_application_server 6.0.2.15
ibm websphere_application_server 5.0.2.10
ibm websphere_application_server 6.0.2.4
ibm websphere_application_server 6.1.0
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 6.1
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 5.1.1.11
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 5.0.2.7
ibm websphere_application_server 6.1.0.41
ibm websphere_application_server 5.0.2.9
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 5.1.1.3
ibm websphere_application_server 5.1.0.3
ibm websphere_application_server 6.0.2.6
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 5.0.2.3
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.0.2.37
ibm websphere_application_server 6.0.2.24
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 6.0.2.5
ibm websphere_application_server 5.1.0
ibm websphere_application_server 5.1.1.17
ibm websphere_application_server 5.0.2.13
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.0.1.1
ibm websphere_application_server 6.0.2.1
ibm websphere_application_server 6.1.13
ibm websphere_application_server 6.0.1.5
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 6.0.0.1
ibm websphere_application_server 5.1.1.14
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 6.0.0.2
ibm websphere_application_server 5.1.1.15
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0.35
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 6.1.6
ibm websphere_application_server 6.0.2.33
ibm websphere_application_server 5.1.1.10
ibm websphere_application_server 6.0.1.2
ibm websphere_application_server 5.0.2.14
ibm websphere_application_server 6.1.3
ibm websphere_application_server 6.0.1.17
ibm websphere_application_server 6.0.1.13
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 5.0.2.16
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 5.0
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 6.0.2.31
ibm websphere_application_server 6.1.0.39
ibm websphere_application_server 5.0.2.12
ibm websphere_application_server 6.1.7
ibm websphere_application_server 6.0.2.35
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 5.1.1.5
ibm websphere_application_server 6.0.2.22
ibm websphere_application_server 5.0.0
ibm websphere_application_server 6.0
ibm websphere_application_server 5.0.2.8
ibm websphere_application_server 6.0.1.3
ibm websphere_application_server 5.0.2
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 5.1.0.4
ibm websphere_application_server 6.0.2.2
ibm websphere_application_server 6.0.2.11
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 6.0.1.15
ibm websphere_application_server 5.1.1.2
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 5.0.1
ibm websphere_application_server 5.1.1.6
ibm websphere_application_server 6.0.2.30
ibm websphere_application_server 6.0.2.32
ibm websphere_application_server 5.0.2.11
ibm websphere_application_server 5.0.2.1
ibm websphere_application_server 5.0.2.5
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 5.1.1.7
ibm websphere_application_server 5.1.1.1
ibm websphere_application_server 5.1.1.13
ibm websphere_application_server 6.0.2.23
ibm websphere_application_server 6.0.1
ibm websphere_application_server 6.0.1.7
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.0.2.17
ibm websphere_application_server 6.1.5
ibm websphere_application_server 6.1.14
ibm websphere_application_server 6.1.0.43
ibm websphere_application_server 6.0.2.3
ibm websphere_application_server 6.0.2.29
ibm websphere_application_server 6.0.1.9
ibm websphere_application_server 6.0.2
ibm websphere_application_server 6.0.2.28
ibm websphere_application_server 6.0.2.27
ibm websphere_application_server 5.1.0.5
ibm websphere_application_server 6.0.0.3
ibm websphere_application_server 5.1.1.4
ibm websphere_application_server 7.0.0.4
CVE-2012-2163 HIGH

IBM Scale Out Network Attached Storage (SONAS) 1.1 through 1.3.1 allows remote authenticated administrators to execute arbitrary Linux commands via the (1) Command Line Interface or (2) Graphical User Interface, related to a "code injection" issue.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm scale_out_network_attached_storage 1.3.1
ibm scale_out_network_attached_storage 1.1
CVE-2012-2164 MEDIUM

The Web client in IBM Rational ClearQuest 7.1.x before 7.1.2.7 and 8.x before 8.0.0.3 allows remote authenticated users to bypass intended access restrictions, and use the Site Administration menu to modify system settings, via a parameter-tampering attack.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm rational_clearquest 7.1.2.1
ibm rational_clearquest 7.1.2.3
ibm rational_clearquest 8.0.0.2
ibm rational_clearquest 7.1.2
ibm rational_clearquest 7.1.1.4
ibm rational_clearquest 7.1.2.5
ibm rational_clearquest 7.1.1.8
ibm rational_clearquest 7.1.2.6
ibm rational_clearquest 7.1.1.1
ibm rational_clearquest 7.1.2.2
ibm rational_clearquest 7.1.1.6
ibm rational_clearquest 7.1.1.3
ibm rational_clearquest 8.0.0.1
ibm rational_clearquest 7.1.1.7
ibm rational_clearquest 8.0
ibm rational_clearquest 7.1.1.5
ibm rational_clearquest 7.1.1.2
ibm rational_clearquest 7.1.2.4
CVE-2012-2165 LOW

IBM Rational ClearQuest 7.1.x before 7.1.2.7 and 8.x before 8.0.0.3, when ClearQuest Authentication is enabled, allows remote authenticated users to read password hashes via a user query.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_clearquest 7.1.2.1
ibm rational_clearquest 7.1.2.3
ibm rational_clearquest 8.0.0.2
ibm rational_clearquest 7.1.2
ibm rational_clearquest 7.1.1.4
ibm rational_clearquest 7.1.2.5
ibm rational_clearquest 7.1.1.8
ibm rational_clearquest 7.1.2.6
ibm rational_clearquest 7.1.1.1
ibm rational_clearquest 7.1.2.2
ibm rational_clearquest 7.1.1.6
ibm rational_clearquest 7.1.1.3
ibm rational_clearquest 8.0.0.1
ibm rational_clearquest 7.1.1.7
ibm rational_clearquest 7.1.1.5
ibm rational_clearquest 7.1.1.2
ibm rational_clearquest 7.1.2.4
ibm rational_clearquest 8.0.0
CVE-2012-2166 HIGH

IBM XIV Storage System 2810-A14 and 2812-A14 devices before level 10.2.4.e-2 and 2810-114 and 2812-114 devices before level 11.1.1 have hardcoded passwords for unspecified accounts, which allows remote attackers to gain user access via unknown vectors. IBM X-Force ID: 75041.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-798,

Products Affected

Vendor Product Version
ibm xiv_storage_system_2812-a14_firmware *
ibm xiv_storage_system_2810-114_firmware *
ibm xiv_storage_system_2810-a14_firmware *
ibm xiv_storage_system_2812-114_firmware *
CVE-2012-2167 HIGH

The IBM XIV Storage System Gen3 before 11.1.0.a allows remote attackers to cause a denial of service (device outage) via TCP packets to unspecified ports.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm xiv_storage_system_gen3 2810
ibm xiv_storage_system_gen3_firmware *
ibm xiv_storage_system_gen3 2812-114
CVE-2012-2168 MEDIUM

IBM Rational ClearQuest 7.1.x before 7.1.2.7 and 8.x before 8.0.0.3 allows remote authenticated users to obtain sensitive stack-trace information from CM server error messages via an invalid parameter.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_clearquest 7.1.2.1
ibm rational_clearquest 7.1.2.3
ibm rational_clearquest 8.0.0.2
ibm rational_clearquest 7.1.2
ibm rational_clearquest 7.1.1.4
ibm rational_clearquest 7.1.2.5
ibm rational_clearquest 7.1.1.8
ibm rational_clearquest 7.1.2.6
ibm rational_clearquest 7.1.1.1
ibm rational_clearquest 7.1.2.2
ibm rational_clearquest 7.1.1.6
ibm rational_clearquest 7.1.1.3
ibm rational_clearquest 8.0.0.1
ibm rational_clearquest 7.1.1.7
ibm rational_clearquest 7.1.1.5
ibm rational_clearquest 7.1.1.2
ibm rational_clearquest 7.1.2.4
ibm rational_clearquest 8.0.0
CVE-2012-2169 LOW

Cross-site scripting (XSS) vulnerability in the file-upload functionality in the Web client in IBM Rational ClearQuest 7.1.x before 7.1.2.7 allows remote authenticated users to inject arbitrary web script or HTML via the File Description field.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_clearquest 7.1.2.1
ibm rational_clearquest 7.1.2.3
ibm rational_clearquest 7.1.2
ibm rational_clearquest 7.1.1.4
ibm rational_clearquest 7.1.2.5
ibm rational_clearquest 7.1.1.8
ibm rational_clearquest 7.1.2.6
ibm rational_clearquest 7.1.1.1
ibm rational_clearquest 7.1.2.2
ibm rational_clearquest 7.1.1.6
ibm rational_clearquest 7.1.1.3
ibm rational_clearquest 7.1.1.7
ibm rational_clearquest 7.1.1.5
ibm rational_clearquest 7.1.1.2
ibm rational_clearquest 7.1.2.4
CVE-2012-2170 MEDIUM

The Application Snoop Servlet in IBM WebSphere Application Server 7.0 before 7.0.0.23 does not properly restrict access, which allows remote attackers to obtain sensitive client and request information via a direct request.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 7.0.0.4
ibm websphere_application_server 7.0.0.13
CVE-2012-2171 MEDIUM

SQL injection vulnerability in ModuleServlet.do in the Storage Manager Profiler in IBM System Storage DS Storage Manager before 10.83.xx.18 on DS Series devices allows remote authenticated users to execute arbitrary SQL commands via the selectedModuleOnly parameter in a state_viewmodulelog action to the ModuleServlet URI.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm system_storage_ds3524 1746
ibm system_storage_ds3512 1746
ibm ds_storage_manager_host_software 10.60.x5.14
ibm system_storage_ds3400 1726
ibm ds4700 1814
ibm system_storage_dcs3700_storage_subsystem 1818
ibm system_storage_ds5300_storage_controller 1818
ibm ds4100 *
ibm system_storage_ds3300 1726
ibm ds4100 1724
ibm system_storage_ds3950_express 1814
ibm ds4300 1722
ibm ds4800 1815
ibm system_storage_ds5020_disk_controller 1814-20a
ibm ds_storage_manager_host_software *
ibm ds_storage_manager_host_software 10.8
ibm system_storage_ds3200 1726
ibm system_storage_ds5100_storage_controller 1818
ibm ds4400 1742
ibm ds4500 1742
ibm ds4200 1814
CVE-2012-2172 MEDIUM

Cross-site scripting (XSS) vulnerability in SoftwareRegistration.do in the Storage Manager Profiler in IBM System Storage DS Storage Manager before 10.83.xx.18 on DS Series devices allows remote attackers to inject arbitrary web script or HTML via the updateRegn parameter.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm system_storage_ds3524 1746
ibm system_storage_ds3512 1746
ibm ds_storage_manager_host_software 10.60.x5.14
ibm system_storage_ds3400 1726
ibm ds4700 1814
ibm system_storage_dcs3700_storage_subsystem 1818
ibm system_storage_ds5300_storage_controller 1818
ibm ds4100 *
ibm system_storage_ds3300 1726
ibm ds4100 1724
ibm system_storage_ds3950_express 1814
ibm ds4300 1722
ibm ds4800 1815
ibm system_storage_ds5020_disk_controller 1814-20a
ibm ds_storage_manager_host_software *
ibm ds_storage_manager_host_software 10.8
ibm system_storage_ds3200 1726
ibm system_storage_ds5100_storage_controller 1818
ibm ds4400 1742
ibm ds4500 1742
ibm ds4200 1814
CVE-2012-2173 MEDIUM

The ODBC driver in IBM Security AppScan Source 7.x and 8.x before 8.6 sends an SHA-1 hash of the connection password during connections to a solidDB database, which allows remote attackers to obtain sensitive information by sniffing the network.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm security_appscan_source 8.5.0.1
ibm security_appscan_source 8.0.0.1
ibm security_appscan_source 8.5
ibm security_appscan_source 8.0.0.2
ibm security_appscan_source 7.0
ibm security_appscan_source 8.0
CVE-2012-2174 HIGH

The URL handler in IBM Lotus Notes 8.x before 8.5.3 FP2 allows remote attackers to execute arbitrary code via a crafted notes:// URL.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-94,

Products Affected

Vendor Product Version
ibm lotus_notes 8.0.2.1
ibm lotus_notes 8.5.1.5
ibm lotus_notes 8.5.2.0
ibm lotus_notes 8.0.0
ibm lotus_notes 8.0.2.3
ibm lotus_notes 8.5.1.4
ibm lotus_notes 8.5.2.1
ibm lotus_notes 8.0.1
ibm lotus_notes 8.0.2.2
ibm lotus_notes 8.0.2.4
ibm lotus_notes 8.5.0.1
ibm lotus_notes 8.0
ibm lotus_notes 8.0.2.0
ibm lotus_notes 8.5.3
ibm lotus_notes 8.0.2.5
ibm lotus_notes 8.5.1.1
ibm lotus_notes 8.5.2.2
ibm lotus_notes 8.5.1
ibm lotus_notes 8.5.1.2
ibm lotus_notes 8.5.1.3
ibm lotus_notes 8.5.0.0
ibm lotus_notes 8.5.2.3
ibm lotus_notes 8.5.1.0
ibm lotus_notes 8.0.2.6
ibm lotus_notes 8.5.3.1
ibm lotus_notes 8.5
ibm lotus_notes 8.0.2
CVE-2012-2175 HIGH

Buffer overflow in the Attachment_Times method in a certain ActiveX control in dwa85W.dll in IBM Lotus iNotes 8.5.x before 8.5.3 FP2 allows remote attackers to execute arbitrary code via a long argument.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm lotus_inotes 8.5.1.3
ibm lotus_inotes 8.5.1.0
ibm lotus_inotes 8.5.3.0
ibm lotus_inotes 8.5.2.2
ibm lotus_inotes 8.5.0.0
ibm lotus_inotes 8.5.1.5
ibm lotus_inotes 8.5.2.3
ibm lotus_inotes 8.5.2.1
ibm lotus_inotes 8.5.1.1
ibm lotus_inotes 8.5.2.0
ibm lotus_inotes 8.5.3.1
ibm lotus_inotes 8.5.1.4
ibm lotus_inotes 8.5.1.2
ibm lotus_inotes 8.5.0.1
CVE-2012-2176 HIGH

Multiple stack-based buffer overflows in a certain ActiveX control in qp2.cab in IBM Lotus Quickr 8.2 before 8.2.0.27-002a for Domino allow remote attackers to execute arbitrary code via a long argument to the (1) Attachment_Times or (2) Import_Times method.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm lotus_quickr 8.2
CVE-2012-2177 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 allows user-assisted remote attackers to inject arbitrary web script or HTML via vectors related to the search feature.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm cognos_business_intelligence 10.2
ibm cognos_business_intelligence 10.1
ibm cognos_business_intelligence 8.4.1
ibm cognos_business_intelligence 10.1.1
CVE-2012-2179 MEDIUM

libodm.a in IBM AIX 5.3, 6.1, and 7.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary file.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 6.1
ibm aix 7.1
CVE-2012-2180 MEDIUM

The chaining functionality in the Distributed Relational Database Architecture (DRDA) module in IBM DB2 9.7 before FP6 and 9.8 before FP5 allows remote attackers to cause a denial of service (NULL pointer dereference, and resource consumption or daemon crash) via a crafted request.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm db2 9.7.0.3
ibm db2 9.7.0.5
ibm db2 9.7.0.2
ibm db2 9.7.0.1
ibm db2 9.8.0.3
ibm db2 9.7.0.4
ibm db2 9.8
ibm db2 9.8.0.4
ibm db2 9.7
CVE-2012-2181 MEDIUM

Directory traversal vulnerability in the Dojo module in IBM WebSphere Portal 7.0.0.1 and 7.0.0.2 before CF14, and 8.0, allows remote attackers to read arbitrary files via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm websphere_portal 7.0.0.2
ibm websphere_portal 8.0
ibm websphere_portal 7.0.0.1
CVE-2012-2183 MEDIUM

Session fixation vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote attackers to hijack web sessions via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm tivoli_asset_management_for_it 7.2
ibm tivoli_asset_management_for_it 6.0
ibm change_and_configuration_management_database 6.0
ibm tivoli_asset_management_for_it 6.2
ibm change_and_configuration_management_database 7.0
ibm tivoli_service_request_manager 7.0
ibm tivoli_asset_management_for_it 7.1
ibm maximo_asset_management 7.1.0.0
ibm maximo_asset_management 7.5.0.0
ibm tivoli_asset_management_for_it 7.0
ibm maximo_service_desk 6.2
ibm maximo_asset_management 6.2.0.0
ibm smartcloud_control_desk 7.0
CVE-2012-2184 MEDIUM

Session fixation vulnerability in IBM Maximo Asset Management 7.1 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote attackers to hijack web sessions via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm tivoli_asset_management_for_it 7.2
ibm tivoli_asset_management_for_it 6.0
ibm change_and_configuration_management_database 6.0
ibm tivoli_asset_management_for_it 6.2
ibm change_and_configuration_management_database 7.0
ibm tivoli_service_request_manager 7.0
ibm tivoli_asset_management_for_it 7.1
ibm maximo_asset_management 7.1.0.0
ibm maximo_asset_management 7.5.0.0
ibm tivoli_asset_management_for_it 7.0
ibm maximo_service_desk 6.2
ibm smartcloud_control_desk 7.0
CVE-2012-2185 MEDIUM

IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote authenticated users to obtain sensitive information via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm tivoli_asset_management_for_it 7.2
ibm tivoli_asset_management_for_it 6.0
ibm change_and_configuration_management_database 6.0
ibm tivoli_asset_management_for_it 6.2
ibm change_and_configuration_management_database 7.0
ibm tivoli_service_request_manager 7.0
ibm tivoli_asset_management_for_it 7.1
ibm maximo_asset_management 7.1.0.0
ibm maximo_asset_management 7.5.0.0
ibm tivoli_asset_management_for_it 7.0
ibm maximo_service_desk 6.2
ibm maximo_asset_management 6.2.0.0
ibm smartcloud_control_desk 7.0
CVE-2012-2187 MEDIUM

IBM Remote Supervisor Adapter II firmware for System x3650, x3850 M2, and x3950 M2 1.13 and earlier generates weak RSA keys, which makes it easier for attackers to defeat cryptographic protection mechanisms via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm remote_supervisor_adapter_ii_firmware 1.3
ibm remote_supervisor_adapter_ii_firmware 1.1
ibm remote_supervisor_adapter_ii_firmware *
ibm remote_supervisor_adapter_ii_firmware 1.4
ibm remote_supervisor_adapter_ii_firmware 1.0
ibm remote_supervisor_adapter_ii_firmware 1.7
ibm remote_supervisor_adapter_ii_firmware 1.8
ibm remote_supervisor_adapter_ii_firmware 1.12
ibm remote_supervisor_adapter_ii_firmware 1.2
ibm remote_supervisor_adapter_ii_firmware 1.11
ibm remote_supervisor_adapter_ii_firmware 1.5
ibm remote_supervisor_adapter_ii_firmware 1.9
ibm remote_supervisor_adapter_ii_firmware 1.6
ibm remote_supervisor_adapter_ii_firmware 1.10
CVE-2012-2188 HIGH

IBM Power Hardware Management Console (HMC) 7R3.5.0 before SP4, 7R7.1.0 and 7R7.2.0 before 7R7.2.0 SP3, and 7R7.3.0 before SP2, and Systems Director Management Console (SDMC) 6R7.3.0 before SP2, does not properly restrict the VIOS viosrvcmd command, which allows local users to gain privileges via vectors involving a (1) $ (dollar sign) or (2) & (ampersand) character.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm power_hardware_management_console_firmware 7r3.5.0
ibm systems_director_management__console_firmware 6r7.3.0
ibm power_hardware_management_console_firmware 7r7.2.0
ibm power_hardware_management_console_firmware 7r7.1.0
ibm power_hardware_management_console_firmware 7r7.3.0
CVE-2012-2190 MEDIUM

IBM Global Security Kit (aka GSKit), as used in IBM HTTP Server in IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.45, 7.0.x before 7.0.0.25, 8.0.x before 8.0.0.4, and 8.5.x before 8.5.0.1, allows remote attackers to cause a denial of service (daemon crash) via a crafted ClientHello message in the TLS Handshake Protocol.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 7.0
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0
ibm websphere_application_server 6.1.0.35
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.41
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 6.1.0.43
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.0.39
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 6.1.0.37
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 7.0.0.4
ibm websphere_application_server 8.0.0.2
CVE-2012-2191 MEDIUM

IBM Global Security Kit (aka GSKit) before 8.0.14.22, as used in IBM Rational Directory Server, IBM Tivoli Directory Server, and other products, does not properly validate data during execution of a protection mechanism against the Vaudenay SSL CBC timing attack, which allows remote attackers to cause a denial of service (application crash) via crafted values in the TLS Record Layer, a different vulnerability than CVE-2012-2333.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm rational_directory_server *
ibm global_security_kit *
ibm global_security_kit 7.0.4.29
ibm tivoli_directory_server *
ibm global_security_kit 7.0.4.28
CVE-2012-2192 MEDIUM

The socketpair function in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.1.4-FP-25 SP-02 allows local users to cause a denial of service (system crash) via a crafted application that leverages the presence of a socket on the free list.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 6.1
ibm vios 2.2.1.4
ibm aix 7.1
CVE-2012-2193 MEDIUM

Cross-site scripting (XSS) vulnerability in Query Studio in IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 allows user-assisted remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm cognos_business_intelligence 10.2
ibm cognos_business_intelligence 10.1
ibm cognos_business_intelligence 8.4.1
ibm cognos_business_intelligence 10.1.1
CVE-2012-2194 MEDIUM

Directory traversal vulnerability in the SQLJ.DB2_INSTALL_JAR stored procedure in IBM DB2 9.1 before FP12, 9.5 through FP9, 9.7 through FP6, 9.8 through FP5, and 10.1 allows remote attackers to replace JAR files via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm db2 9.5.0.6
ibm db2 9.7.0.5
ibm db2 9.1.0.2
ibm db2 9.5.0.5
ibm db2 9.1.0.1
ibm db2 9.7.0.6
ibm db2 9.1.0.10
ibm db2 9.1.0.11
ibm db2 9.5.0.1
ibm db2 9.5.0.4
ibm db2 9.5.0.8
ibm db2 9.7.0.2
ibm db2 10.1
ibm db2 9.7.0.1
ibm db2 9.8.0.3
ibm db2 9.8
ibm db2 9.5.0.7
ibm db2 9.5.0.3
ibm db2 9.1.0.7
ibm db2 9.5.0.9
ibm db2 9.7.0.4
ibm db2 9.1.0.3
ibm db2 9.1.0.5
ibm db2 9.7
ibm db2 9.1.0.6
ibm db2 9.1
ibm db2 9.7.0.3
ibm db2 9.1.0.4
ibm db2 9.5.0.2
ibm db2 9.5
ibm db2 9.1.0.8
ibm db2 9.8.0.5
ibm db2 9.8.0.4
ibm db2 9.1.0.9
CVE-2012-2196 MEDIUM

IBM DB2 9.1 before FP12, 9.5 through FP9, 9.7 through FP6, 9.8 through FP5, and 10.1 allows remote attackers to read arbitrary XML files via the (1) GET_WRAP_CFG_C or (2) GET_WRAP_CFG_C2 stored procedure.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm db2 9.5.0.6
ibm db2 9.7.0.5
ibm db2 9.1.0.2
ibm db2 9.5.0.5
ibm db2 9.1.0.1
ibm db2 9.7.0.6
ibm db2 9.1.0.10
ibm db2 9.1.0.11
ibm db2 9.5.0.1
ibm db2 9.5.0.4
ibm db2 9.5.0.8
ibm db2 9.7.0.2
ibm db2 10.1
ibm db2 9.7.0.1
ibm db2 9.8.0.3
ibm db2 9.8
ibm db2 9.5.0.7
ibm db2 9.5.0.3
ibm db2 9.1.0.7
ibm db2 9.5.0.9
ibm db2 9.7.0.4
ibm db2 9.1.0.3
ibm db2 9.1.0.5
ibm db2 9.7
ibm db2 9.1.0.6
ibm db2 9.1
ibm db2 9.7.0.3
ibm db2 9.1.0.4
ibm db2 9.5.0.2
ibm db2 9.5
ibm db2 9.1.0.8
ibm db2 9.8.0.5
ibm db2 9.8.0.4
ibm db2 9.1.0.9
CVE-2012-2197 HIGH

Stack-based buffer overflow in the Java Stored Procedure infrastructure in IBM DB2 9.1 before FP12, 9.5 through FP9, 9.7 through FP6, 9.8 through FP5, and 10.1 allows remote authenticated users to execute arbitrary code by leveraging certain CONNECT and EXECUTE privileges.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm db2 9.5.0.6
ibm db2 9.7.0.5
ibm db2 9.1.0.2
ibm db2 9.5.0.5
ibm db2 9.1.0.1
ibm db2 9.7.0.6
ibm db2 9.1.0.10
ibm db2 9.1.0.11
ibm db2 9.5.0.1
ibm db2 9.5.0.4
ibm db2 9.5.0.8
ibm db2 9.7.0.2
ibm db2 10.1
ibm db2 9.7.0.1
ibm db2 9.8.0.3
ibm db2 9.8
ibm db2 9.5.0.7
ibm db2 9.5.0.3
ibm db2 9.1.0.7
ibm db2 9.5.0.9
ibm db2 9.7.0.4
ibm db2 9.1.0.3
ibm db2 9.1.0.5
ibm db2 9.7
ibm db2 9.1.0.6
ibm db2 9.1
ibm db2 9.7.0.3
ibm db2 9.1.0.4
ibm db2 9.5.0.2
ibm db2 9.5
ibm db2 9.1.0.8
ibm db2 9.8.0.5
ibm db2 9.8.0.4
ibm db2 9.1.0.9
CVE-2012-2199 MEDIUM

The server message channel agent in the queue manager in the server in IBM WebSphere MQ 7.0.1 before 7.0.1.9, 7.1, and 7.5 on Solaris allows remote attackers to cause a denial of service (invalid address alignment exception and daemon crash) via vectors involving a multiplexed channel.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm websphere_mq 7.0.1.2
ibm websphere_mq 7.0.1.0
ibm websphere_mq 7.0.1.7
ibm websphere_mq 7.0.1.5
ibm websphere_mq 7.0.1.1
ibm websphere_mq 7.0.1.3
ibm websphere_mq 7.5
ibm websphere_mq 7.1
ibm websphere_mq 7.0.1.8
ibm websphere_mq 7.0.1.6
ibm websphere_mq 7.0.1.4
CVE-2012-2200 HIGH

The default configuration of sendmail in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, allows local users to gain privileges by entering a command in a .forward file in a home directory.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm aix 6.1
ibm vios 2.2.1.4
ibm aix 7.1
CVE-2012-2202 LOW

Directory traversal vulnerability in javatester_init.php in IBM Lotus Protector for Mail Security 2.1, 2.5, 2.5.1, and 2.8 and IBM ISS Proventia Network Mail Security System allows remote authenticated administrators to read arbitrary files via a .. (dot dot) in the template parameter.

CVSS 2.0

Severity: LOW

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm proventia_network_mail_security_system_firmware 2.6
ibm lotus_protector_for_mail_security 2.8
ibm proventia_network_mail_security_system_firmware 2.5
ibm proventia_network_mail_security_system_firmware 2.8
ibm lotus_protector_for_mail_security 2.5
ibm proventia_network_mail_security_system_firmware 2.5.1
ibm lotus_protector_for_mail_security 2.5.1
ibm proventia_network_mail_security_system_firmware 2.5.0.2
ibm lotus_protector_for_mail_security 2.1
CVE-2012-2203 HIGH

IBM Global Security Kit (aka GSKit) before 8.0.14.22, as used in IBM Rational Directory Server, IBM Tivoli Directory Server, and other products, uses the PKCS #12 file format for certificate objects without enforcing file integrity, which makes it easier for remote attackers to spoof SSL servers via vectors involving insertion of an arbitrary root Certification Authority (CA) certificate.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm rational_directory_server *
ibm global_security_kit *
ibm global_security_kit 7.0.4.29
ibm tivoli_directory_server *
ibm global_security_kit 7.0.4.28
CVE-2012-2205 LOW

Cross-site scripting (XSS) vulnerability in IBM Rational ClearQuest 7.1.x before 7.1.2.7 and 8.x before 8.0.0.3 allows remote authenticated users to inject arbitrary web script or HTML via a workspace query.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_clearquest 7.1.2.1
ibm rational_clearquest 7.1.2.3
ibm rational_clearquest 8.0.0.2
ibm rational_clearquest 7.1.2
ibm rational_clearquest 7.1.1.4
ibm rational_clearquest 7.1.2.5
ibm rational_clearquest 7.1.1.8
ibm rational_clearquest 7.1.2.6
ibm rational_clearquest 7.1.1.1
ibm rational_clearquest 7.1.2.2
ibm rational_clearquest 7.1.1.6
ibm rational_clearquest 7.1.1.3
ibm rational_clearquest 8.0.0.1
ibm rational_clearquest 7.1.1.7
ibm rational_clearquest 7.1.1.5
ibm rational_clearquest 7.1.1.2
ibm rational_clearquest 7.1.2.4
ibm rational_clearquest 8.0.0
CVE-2012-2206 LOW

The Web Gateway component in IBM WebSphere MQ File Transfer Edition 7.0.4 and earlier allows remote authenticated users to read files of arbitrary users via vectors involving a username in a URI, as demonstrated by a modified metadata=fteSamplesUser field to the /transfer URI.

CVSS 2.0

Severity: LOW

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_mq 7.0.4
ibm websphere_mq 7.0.4.0
ibm websphere_mq 7.0.1.0
ibm websphere_mq 7.0.2.2
ibm websphere_mq 7.0.0.1
ibm websphere_mq 7.0
ibm websphere_mq 7.0.2.0
CVE-2012-2955 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in the administrative user interface in IBM Lotus Protector for Mail Security 2.1, 2.5, 2.5.1, and 2.8 and IBM ISS Proventia Network Mail Security System allow remote attackers to inject arbitrary web script or HTML via the query string.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm proventia_network_mail_security_system_firmware 2.6
ibm lotus_protector_for_mail_security 2.8
ibm proventia_network_mail_security_system_firmware 2.5
ibm proventia_network_mail_security_system_firmware 2.8
ibm proventia_network_mail_security_system ms3004
ibm proventia_network_mail_security_system *
ibm lotus_protector_for_mail_security 2.5
ibm proventia_network_mail_security_system_firmware 2.5.1
ibm lotus_protector_for_mail_security 2.5.1
ibm proventia_network_mail_security_system_firmware 2.5.0.2
ibm lotus_protector_for_mail_security 2.1
CVE-2012-3293 MEDIUM

Cross-site scripting (XSS) vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.45, 7.0.x before 7.0.0.25, 8.0.x before 8.0.0.4, and 8.5.x before 8.5.0.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving FRAME elements, related to a cross-frame scripting (XFS) issue.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 7.0
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0
ibm websphere_application_server 6.1.0.35
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.41
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 6.1.0.43
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.0.39
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 6.1.0.37
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 7.0.0.4
ibm websphere_application_server 8.0.0.2
CVE-2012-3294 MEDIUM

Multiple cross-site request forgery (CSRF) vulnerabilities in the Web Gateway component in IBM WebSphere MQ File Transfer Edition 7.0.4 and earlier, and WebSphere MQ - Managed File Transfer 7.5, allow remote attackers to hijack the authentication of arbitrary users for requests that (1) add user accounts via the /wmqfteconsole/Filespaces URI, (2) modify permissions via the /wmqfteconsole/FileSpacePermisssions URI, or (3) add MQ Message Descriptor (MQMD) user accounts via the /wmqfteconsole/UploadUsers URI.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm websphere_mq *
ibm websphere_mq 7.0.4.0
ibm websphere_mq 7.0.1.0
ibm websphere_mq 7.0.2.2
ibm websphere_mq 7.0.0.1
ibm websphere_mq_managed_file_transfer 7.5
ibm websphere_mq 7.0
ibm websphere_mq 7.0.2.0
CVE-2012-3295 MEDIUM

IBM WebSphere MQ 7.1, when an SVRCONN channel is used, allows remote attackers to bypass the security-configuration setup step and obtain queue-manager access via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_mq 7.1
CVE-2012-3296 MEDIUM

Cross-site scripting (XSS) vulnerability in the Help link in the login panel in IBM Power Hardware Management Console (HMC) 7R7.1.0 before SP4, 7R7.2.0 before SP2, and 7R7.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm power_hardware_management_console 7r7.2.0
ibm power_hardware_management_console 7r7.1.0
ibm power_hardware_management_console 7r7.3.0
CVE-2012-3297 MEDIUM

Cross-site scripting (XSS) vulnerability in the embedded HTTP server in the Service Console in IBM Tivoli Monitoring 6.2.2 before 6.2.2-TIV-ITM-FP0009 and 6.3.2 before 6.2.3-TIV-ITM-FP0001 allows remote attackers to inject arbitrary web script or HTML via a crafted URI.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_monitoring 6.2.3
ibm tivoli_monitoring 6.2.2
CVE-2012-3298 HIGH

Unspecified vulnerability in the REST services framework in IBM WebSphere Commerce 7.0 Feature Pack 4 allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_commerce 7.0
CVE-2012-3300 LOW

IBM WebSphere Commerce 7.0 before 7.0.0.6, when persistent sessions and personalization IDs are enabled, allows remote attackers to cause a denial of service (resource consumption) via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm websphere_commerce 7.0.0.4
ibm websphere_commerce 7.0.0.3
ibm websphere_commerce 7.0.0.2
ibm websphere_commerce 7.0
ibm websphere_commerce 7.0.0.1
ibm websphere_commerce 7.0.0.5
CVE-2012-3301 MEDIUM

Multiple CRLF injection vulnerabilities in the HTTP server in IBM Lotus Domino 8.5.x before 8.5.4 allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input involving (1) Mozilla Firefox 3.0.9 and earlier or (2) unspecified browsers.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm lotus_domino 8.5.2.4
ibm lotus_domino 8.5.1.5
ibm lotus_domino 8.5.2.2
ibm lotus_domino 8.5.1.1
ibm lotus_domino 8.5.2.3
ibm lotus_domino 8.5.1.4
ibm lotus_domino 8.5.2.0
ibm lotus_domino 8.5.0.1
ibm lotus_domino 8.5.3.1
ibm lotus_domino 8.5.2.1
ibm lotus_domino 8.5.0
ibm lotus_domino 8.5.3.0
ibm lotus_domino 8.5.1.2
ibm lotus_domino 8.5.3.2
ibm lotus_domino 8.5.1.3
CVE-2012-3302 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Domino 7.x and 8.x before 8.5.4 allow remote attackers to inject arbitrary web script or HTML via (1) a URL accessed during use of the Mail template in the WebMail UI or (2) a URL accessed during use of Domino Help through the Domino HTTP server.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm lotus_domino 7.0.2.2
ibm lotus_domino 8.5.2.2
ibm lotus_domino 7.0.4.0
ibm lotus_domino 8.5.1.1
ibm lotus_domino 7.0.3.1
ibm lotus_domino 8.5.1.4
ibm lotus_domino 8.5.2.0
ibm lotus_domino 8.5.3.1
ibm lotus_domino 7.0.1.1
ibm lotus_domino 8.5.0
ibm lotus_domino 8.5.3.0
ibm lotus_domino 7.0.4.2
ibm lotus_domino 8.5.1.2
ibm lotus_domino 8.5.3.2
ibm lotus_domino 8.5.1.3
ibm lotus_domino 8.5.2.4
ibm lotus_domino 8.5.1.5
ibm lotus_domino 7.0.2
ibm lotus_domino 8.5.2.3
ibm lotus_domino 7.0.4.1
ibm lotus_domino 7.0.1
ibm lotus_domino 8.5.0.1
ibm lotus_domino 8.5.2.1
ibm lotus_domino 7.0.3.0
CVE-2012-3304 MEDIUM

The Administrative Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1 allows remote attackers to hijack sessions via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 7.0.0.16
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0.35
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 7.0.0.14
ibm websphere_application_server 7.0.0.10
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.0.39
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 6.1.0.37
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 8.0.0.2
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 6.1.0
ibm websphere_application_server 6.1.0.4
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.41
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 6.1.0.43
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 7.0.0.4
CVE-2012-3305 MEDIUM

Directory traversal vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1 allows remote attackers to overwrite arbitrary files via a crafted application file.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 7.0
ibm websphere_application_server 6.1.0.14
ibm websphere_application_server 7.0.0.12
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 6.1.0.20
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 6.1.0.24
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 7.0.0.16
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0.35
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 7.0.0.14
ibm websphere_application_server 6.1.0.44
ibm websphere_application_server 7.0.0.22
ibm websphere_application_server 7.0.0.10
ibm websphere_application_server 6.1.0.32
ibm websphere_application_server 6.1.0.10
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 6.1.0.28
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.0.39
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 6.1.0.37
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 7.0.0.18
ibm websphere_application_server 6.1.0.18
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 8.0.0.2
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 6.1.0.45
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 6.1.0.36
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 6.1.0.22
ibm websphere_application_server 6.1.0
ibm websphere_application_server 6.1.0.4
ibm websphere_application_server 6.1
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.26
ibm websphere_application_server 6.1.0.41
ibm websphere_application_server 6.1.0.42
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 8.0
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.34
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 6.1.0.43
ibm websphere_application_server 6.1.0.38
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.16
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.19
CVE-2012-3306 MEDIUM

IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1, when multi-domain support is configured, does not purge password data from the authentication cache, which has unspecified impact and remote attack vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 7.0.0.16
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0.35
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 7.0.0.14
ibm websphere_application_server 7.0.0.10
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.0.39
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 6.1.0.37
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 8.0.0.2
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 6.1.0
ibm websphere_application_server 6.1.0.4
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.41
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 6.1.0.43
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 7.0.0.4
CVE-2012-3308 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Sametime 8.0.2 through 8.5.2.1 allows remote attackers to inject arbitrary web script or HTML via an IM chat.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm sametime 8.5.0.0
ibm sametime 8.5.1.1
ibm sametime 8.5.2.0
ibm sametime 8.5.2.1
ibm sametime 8.5.1.0
ibm sametime 8.0.2.0
ibm sametime 8.0.2.1
CVE-2012-3309 MEDIUM

Cross-site request forgery (CSRF) vulnerability in the account-creation panel in IBM InfoSphere Guardium 8.2 and earlier, when the CSRF filtering (aka csrf_status) feature is disabled, allows remote attackers to hijack the authentication of administrators for requests that create administrative accounts.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm infosphere_guardium 8.01
ibm infosphere_guardium *
ibm infosphere_guardium 8.00
CVE-2012-3310 LOW

IBM Tivoli Federated Identity Manager (TFIM) before 6.1.1.14, 6.2.0 before 6.2.0.12, and 6.2.1 before 6.2.1.4 allows context-dependent attackers to discover (1) a cleartext LDAP Bind Password, (2) keystore passwords, (3) a cleartext Basic Authentication password from a client, or (4) a cleartext user password by leveraging a logging configuration with a log trace setting of all.

CVSS 2.0

Severity: LOW

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm tivoli_federated_identity_manager 6.2.0.3
ibm tivoli_federated_identity_manager 6.2.1.1
ibm tivoli_federated_identity_manager 6.1.1
ibm tivoli_federated_identity_manager 6.2.1
ibm tivoli_federated_identity_manager *
ibm tivoli_federated_identity_manager 6.2.0
ibm tivoli_federated_identity_manager 6.2.0.1
ibm tivoli_federated_identity_manager 6.2.0.9
ibm tivoli_federated_identity_manager 6.2.0.8
ibm tivoli_federated_identity_manager 6.2.1.3
ibm tivoli_federated_identity_manager 6.2.0.2
ibm tivoli_federated_identity_manager 6.2.0.11
ibm tivoli_federated_identity_manager 6.2.0.10
ibm tivoli_federated_identity_manager 6.1.1.12
ibm tivoli_federated_identity_manager 6.2.1.2
CVE-2012-3311 LOW

IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1 on z/OS, in certain configurations involving Federated Repositories for IIOP connections and Optimized Local Adapters, does not perform CBIND checks, which allows local users to bypass intended access restrictions, and read or modify application data, via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 7.0.0.16
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0.35
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 7.0.0.14
ibm websphere_application_server 7.0.0.10
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.0.39
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 6.1.0.37
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 8.0.0.2
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 6.1.0
ibm websphere_application_server 6.1.0.4
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.41
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 6.1.0.43
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 7.0.0.4
CVE-2012-3312 MEDIUM

The datasource definition editor in IBM InfoSphere Guardium 8.2 and earlier, when the save-password setting is enabled, transmits cleartext database credentials, which allows remote attackers to obtain sensitive information by sniffing the network.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm infosphere_guardium 8.01
ibm infosphere_guardium *
ibm infosphere_guardium 8.00
CVE-2012-3313 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_asset_management_for_it 7.2
ibm tivoli_asset_management_for_it 6.0
ibm change_and_configuration_management_database 6.0
ibm tivoli_asset_management_for_it 6.2
ibm change_and_configuration_management_database 7.0
ibm tivoli_service_request_manager 7.0
ibm tivoli_asset_management_for_it 7.1
ibm maximo_asset_management 7.1.0.0
ibm maximo_asset_management 7.5.0.0
ibm tivoli_asset_management_for_it 7.0
ibm maximo_service_desk 6.2
ibm maximo_asset_management 6.2.0.0
ibm smartcloud_control_desk 7.0
CVE-2012-3314 MEDIUM

IBM Tivoli Federated Identity Manager (TFIM) and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.1.1, 6.2.0, 6.2.1, and 6.2.2 allow remote attackers to establish sessions via a crafted message that leverages (1) a signature-validation bypass for SAML messages containing unsigned elements, (2) incorrect validation of XML messages, or (3) a certificate-chain validation bypass for an XML signature element that contains the signing certificate.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm tivoli_federated_identity_manager_business_gateway 6.1.1
ibm tivoli_federated_identity_manager_business_gateway 6.2.2
ibm tivoli_federated_identity_manager 6.1.1
ibm tivoli_federated_identity_manager 6.2.1
ibm tivoli_federated_identity_manager 6.2.2
ibm tivoli_federated_identity_manager_business_gateway 6.2.0
ibm tivoli_federated_identity_manager_business_gateway 6.2.1
ibm tivoli_federated_identity_manager 6.2.0
CVE-2012-3315 MEDIUM

The Java servlets in the management console in IBM Tivoli Federated Identity Manager (TFIM) through 6.2.2 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) before 6.2.2 do not require authentication for all resource downloads, which allows remote attackers to bypass intended J2EE security constraints, and obtain sensitive information related to (1) federation metadata or (2) a web plugin configuration template, via a crafted request.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm tivoli_federated_identity_manager 6.2.0.3
ibm tivoli_federated_identity_manager_business_gateway 6.1.1
ibm tivoli_federated_identity_manager_business_gateway 6.2.0.1
ibm tivoli_federated_identity_manager_business_gateway 6.2.0.3
ibm tivoli_federated_identity_manager 6.1.1
ibm tivoli_federated_identity_manager 6.2.1
ibm tivoli_federated_identity_manager *
ibm tivoli_federated_identity_manager_business_gateway *
ibm tivoli_federated_identity_manager 6.2.0
ibm tivoli_federated_identity_manager 6.2.0.1
ibm tivoli_federated_identity_manager 6.2.0.9
ibm tivoli_federated_identity_manager_business_gateway 6.2.0.8
ibm tivoli_federated_identity_manager_business_gateway 6.2.0.2
ibm tivoli_federated_identity_manager 6.2.0.8
ibm tivoli_federated_identity_manager 6.2.0.2
ibm tivoli_federated_identity_manager_business_gateway 6.2.0
CVE-2012-3316 LOW

Cross-site scripting (XSS) vulnerability in the Tivoli Process Automation Engine (TPAE) in IBM Maximo Asset Management 6.2 through 7.5, Maximo Asset Management Essentials 6.2 through 7.5, Tivoli Asset Management for IT 6.2 through 7.2, Tivoli Service Request Manager 7.1 and 7.2, Maximo Service Desk 6.2, Change and Configuration Management Database (CCMDB) 7.1 and 7.2, and SmartCloud Control Desk 7.5 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_asset_management_for_it 7.2
ibm tivoli_asset_management_for_it 6.0
ibm maximo_asset_management 7.1.1.9
ibm tivoli_service_request_manager 7.2.0.0
ibm maximo_asset_management 6.2.6
ibm maximo_asset_management 6.2.7
ibm maximo_asset_management 6.2.6.1
ibm maximo_asset_management 7.1.1.10
ibm maximo_asset_management 6.2.3
ibm maximo_asset_management 6.2.5
ibm maximo_asset_management 7.1.1.1
ibm tivoli_asset_management_for_it 7.0
ibm smartcloud_control_desk 7.5.0.0
ibm maximo_asset_management_essentials 7.5.0.0
ibm change_and_configuration_management_database 7.1
ibm maximo_service_desk 6.2
ibm maximo_asset_management 6.2.8
ibm maximo_asset_management_essentials 6.2.0.0
ibm tivoli_service_request_manager 7.1.0
ibm maximo_asset_management 6.2.4
ibm tivoli_service_request_manager 7.1.0.0
ibm tivoli_asset_management_for_it 6.2
ibm maximo_asset_management 6.2.1
ibm change_and_configuration_management_database 7.2.0
ibm tivoli_asset_management_for_it 7.1
ibm maximo_asset_management 7.5.0.0
ibm maximo_asset_management 7.1.1.7
ibm maximo_asset_management 6.2
ibm maximo_asset_management 6.2.2
ibm maximo_asset_management 7.1.1.2
ibm maximo_asset_management 7.1.1.6
ibm maximo_asset_management 7.1.1.5
ibm maximo_asset_management 7.1.1.11
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
CVE-2012-3317 MEDIUM

IBM WebSphere Message Broker 6.1 before 6.1.0.11, 7.0 before 7.0.0.5, and 8.0 before 8.0.0.2 has incorrect ownership of certain uninstaller Java Runtime Environment (JRE) files, which might allow local users to gain privileges by leveraging access to uid 501 or gid 300.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_message_broker 6.1.0.3
ibm websphere_message_broker 7.0.0.1
ibm websphere_message_broker 6.1.0.5
ibm websphere_message_broker 6.1.0.10
ibm websphere_message_broker 7.0.0.2
ibm websphere_message_broker 8.0
ibm websphere_message_broker 6.1.0.6
ibm websphere_message_broker 7.0.0.4
ibm websphere_message_broker 6.1.0.4
ibm websphere_message_broker 6.1.0.9
ibm websphere_message_broker 6.1.0.2
ibm websphere_message_broker 7.0.0.3
ibm websphere_message_broker 6.1
ibm websphere_message_broker 6.1.0.8
ibm websphere_message_broker 7.0.
ibm websphere_message_broker 8.0.0.1
ibm websphere_message_broker 6.1.0.7
ibm websphere_message_broker 6.1.0.1
CVE-2012-3319 MEDIUM

IBM Rational Business Developer 8.x before 8.0.1.4 allows remote attackers to obtain potentially sensitive information via a connection to a web service created with the Rational Business Developer product.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_business_developer 8.0.1
ibm rational_business_developer 8.0.1.2
ibm rational_business_developer 8.0.1.1
ibm rational_business_developer *
CVE-2012-3321 MEDIUM

IBM SmartCloud Control Desk 7.5 allows remote authenticated users to bypass intended access restrictions via vectors involving an expired password.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm smartcloud_control_desk 7.5
CVE-2012-3322 LOW

Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 7.5, Maximo Asset Management Essentials 6.2 through 7.5, Tivoli Asset Management for IT 6.2 through 7.2, Tivoli Service Request Manager 7.1 and 7.2, Maximo Service Desk 6.2, Change and Configuration Management Database (CCMDB) 7.1 and 7.2, and SmartCloud Control Desk 7.5 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to a display name.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_asset_management_for_it 7.2
ibm tivoli_asset_management_for_it 6.0
ibm maximo_asset_management 7.1.1.9
ibm tivoli_service_request_manager 7.2.0.0
ibm maximo_asset_management 6.2.6
ibm maximo_asset_management 6.2.7
ibm maximo_asset_management 6.2.6.1
ibm maximo_asset_management 7.1.1.10
ibm maximo_asset_management 6.2.3
ibm maximo_asset_management 6.2.5
ibm maximo_asset_management 7.1.1.1
ibm tivoli_asset_management_for_it 7.0
ibm smartcloud_control_desk 7.5.0.0
ibm maximo_asset_management_essentials 7.5.0.0
ibm maximo_service_desk 6.2
ibm maximo_asset_management 6.2.8
ibm maximo_asset_management_essentials 6.2.0.0
ibm tivoli_service_request_manager 7.1.0
ibm maximo_asset_management 6.2.4
ibm tivoli_service_request_manager 7.1.0.0
ibm tivoli_asset_management_for_it 6.2
ibm maximo_asset_management 6.2.1
ibm change_and_configuration_management_database 7.2.0
ibm tivoli_asset_management_for_it 7.1
ibm maximo_asset_management 7.5.0.0
ibm maximo_asset_management 7.1.1.7
ibm maximo_asset_management 6.2
ibm maximo_asset_management 6.2.2
ibm change_and_configuration_management_database 7.1.
ibm maximo_asset_management 7.1.1.2
ibm maximo_asset_management 7.1.1.6
ibm maximo_asset_management 7.1.1.5
ibm maximo_asset_management 7.1.1.11
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
CVE-2012-3323 MEDIUM

IBM Maximo Asset Management 6.2 before 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.3 allows remote attackers to gain privileges via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm maximo_asset_management 6.2.1
ibm maximo_asset_management 7.1.1.9
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.5.0.1
ibm maximo_asset_management 6.2.6
ibm maximo_asset_management 6.2.7
ibm maximo_asset_management 6.2.6.1
ibm maximo_asset_management 7.1.1.10
ibm maximo_asset_management 6.2.3
ibm maximo_asset_management 6.2.5
ibm maximo_asset_management 7.1.1.1
ibm maximo_asset_management 7.5.0.0
ibm maximo_asset_management 7.1.1.7
ibm maximo_asset_management 6.2
ibm maximo_asset_management 6.2.2
ibm maximo_asset_management 7.1.1.2
ibm maximo_asset_management 7.1.1.6
ibm maximo_asset_management 7.1.1.5
ibm maximo_asset_management 7.1.1.11
ibm maximo_asset_management 6.2.4
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
CVE-2012-3324 HIGH

Directory traversal vulnerability in the UTL_FILE module in IBM DB2 and DB2 Connect 10.1 before FP1 on Windows allows remote authenticated users to modify, delete, or read arbitrary files via a pathname in the file field.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm db2_connect 10.1
ibm db2 *
CVE-2012-3325 MEDIUM

IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.45, 7.0.x before 7.0.0.25, 8.0.x before 8.0.0.5, and 8.5.x Full Profile before 8.5.0.1, when the PM44303 fix is installed, does not properly validate credentials, which allows remote authenticated users to obtain administrative access via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 7.0
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0.35
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 6.1.6
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 6.1.3
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.0.39
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 6.1.7
ibm websphere_application_server 6.1.0.37
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 6.1.1
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 8.0.0.2
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 6.1.0
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 6.1
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.41
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.1.5
ibm websphere_application_server 6.1.14
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 6.1.0.43
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.1.13
ibm websphere_application_server 7.0.0.4
CVE-2012-3326 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_asset_management_for_it 7.2
ibm tivoli_asset_management_for_it 7.0
ibm tivoli_asset_management_for_it 6.0
ibm change_and_configuration_management_database 6.0
ibm tivoli_asset_management_for_it 6.2
ibm maximo_service_desk 6.2
ibm change_and_configuration_management_database 7.0
ibm tivoli_service_request_manager 7.0
ibm tivoli_asset_management_for_it 7.1
ibm smartcloud_control_desk 7.0
ibm maximo_asset_management 7.5.0.0
CVE-2012-3327 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 7.5, Maximo Asset Management Essentials 6.2 through 7.5, Tivoli Asset Management for IT 6.2 through 7.2, Tivoli Service Request Manager 7.1 and 7.2, Maximo Service Desk 6.2, Change and Configuration Management Database (CCMDB) 7.1 and 7.2, and SmartCloud Control Desk 7.5 allows remote attackers to inject arbitrary web script or HTML via vectors related to a login action.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_asset_management_for_it 7.2
ibm tivoli_asset_management_for_it 6.0
ibm maximo_asset_management 7.1.1.9
ibm tivoli_service_request_manager 7.2.0.0
ibm maximo_asset_management 6.2.6
ibm maximo_asset_management 6.2.7
ibm maximo_asset_management 6.2.6.1
ibm maximo_asset_management 7.1.1.10
ibm maximo_asset_management 6.2.3
ibm maximo_asset_management 6.2.5
ibm maximo_asset_management 7.1.1.1
ibm tivoli_asset_management_for_it 7.0
ibm smartcloud_control_desk 7.5.0.0
ibm maximo_asset_management_essentials 7.5.0.0
ibm maximo_service_desk 6.2
ibm maximo_asset_management 6.2.8
ibm maximo_asset_management_essentials 6.2.0.0
ibm tivoli_service_request_manager 7.1.0
ibm maximo_asset_management 6.2.4
ibm tivoli_service_request_manager 7.1.0.0
ibm tivoli_asset_management_for_it 6.2
ibm maximo_asset_management 6.2.1
ibm change_and_configuration_management_database 7.2.0
ibm tivoli_asset_management_for_it 7.1
ibm maximo_asset_management 7.5.0.0
ibm maximo_asset_management 7.1.1.7
ibm maximo_asset_management 6.2
ibm maximo_asset_management 6.2.2
ibm change_and_configuration_management_database 7.1.
ibm maximo_asset_management 7.1.1.2
ibm maximo_asset_management 7.1.1.6
ibm maximo_asset_management 7.1.1.5
ibm maximo_asset_management 7.1.1.11
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
CVE-2012-3328 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.1, Maximo Asset Management Essentials 7.1, Tivoli Asset Management for IT 7.1 and 7.2, Tivoli Service Request Manager 7.1 and 7.2, and Change and Configuration Management Database (CCMDB) 7.1 and 7.2 allows remote attackers to inject arbitrary web script or HTML via vectors related to a hidden frame footer.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_asset_management_for_it 7.2
ibm change_and_configuration_management_database 7.1.
ibm maximo_asset_management 7.1
ibm change_and_configuration_management_database 7.2.0
ibm tivoli_service_request_manager 7.2.0.0
ibm tivoli_asset_management_for_it 7.1
ibm tivoli_service_request_manager 7.1.0
ibm maximo_asset_management_essentials 7.1
ibm tivoli_service_request_manager 7.1.0.0
CVE-2012-3329 LOW

IBM Advanced Settings Utility (ASU) through 3.62 and 3.70 through 9.21 and Bootable Media Creator (BoMC) through 2.30 and 3.00 through 9.21 on Linux allow local users to overwrite arbitrary files via a symlink attack on a (1) temporary file or (2) log file.

CVSS 2.0

Severity: LOW

Problem Type: CWE-59,

Products Affected

Vendor Product Version
ibm bootable_media_creator 3.00
ibm bootable_media_creator 2.30
ibm bootable_media_creator 9.21
ibm advanced_settings_utility 9.21
ibm advanced_settings_utility 3.70
ibm advanced_settings_utility 3.62
CVE-2012-3330 MEDIUM

The proxy server in IBM WebSphere Application Server 7.0 before 7.0.0.27, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1, and WebSphere Virtual Enterprise, allows remote attackers to cause a denial of service (daemon outage) via a crafted request.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 7.0
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 7.0.0.25
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 7.0.0.4
ibm websphere_application_server 8.0.0.2
CVE-2012-3331 MEDIUM

IBM Sametime allows remote attackers to obtain sensitive information from the Sametime Log database via a direct request to STLOG.NSF. IBM X-Force ID: 78048.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm sametime 8.5.0.0
ibm sametime 7.5.1.0
ibm sametime 8.5.2.0
ibm sametime 8.5.2.1
ibm sametime 7.0.0.0
ibm sametime 8.0.0.0
ibm sametime 8.0.2.0
ibm sametime 8.5.1.1
ibm sametime 7.5.1.2
ibm sametime 7.5.0.0
ibm sametime 8.5.1.0
ibm sametime 7.5.1.1
ibm sametime 8.5.1.2
ibm sametime 6.5.1.0
ibm sametime 8.0.1.0
CVE-2012-3333 MEDIUM

CRLF injection vulnerability in IBM Maximo Asset Management 7.x before 7.5.0.6 and SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted parameter in a URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm maximo_asset_management 7.1.1.9
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.5.0.1
ibm maximo_asset_management 7.1.1.10
ibm maximo_asset_management 7.1.1.1
ibm smartcloud_control_desk 7.5.0.0
ibm maximo_asset_management 7.1.1.12
ibm maximo_asset_management 7.5.0.3
ibm smartcloud_control_desk 7.0
ibm maximo_asset_management 7.5.0.0
ibm maximo_asset_management 7.1.1.7
ibm smartcloud_control_desk 7.5.1.1
ibm maximo_asset_management 7.5.0.4
ibm smartcloud_control_desk 7.5.0.2
ibm smartcloud_control_desk 7.5
ibm maximo_asset_management 7.5.0.5
ibm maximo_asset_management 7.1.1.2
ibm smartcloud_control_desk 7.5.0.1
ibm maximo_asset_management 7.1.1.6
ibm maximo_asset_management 7.1.1.5
ibm smartcloud_control_desk 7.5.1.0
ibm maximo_asset_management 7.1.1.11
ibm maximo_asset_management 7.1.2
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
CVE-2012-3334 HIGH

Stack-based buffer overflow in IBM Informix Dynamic Server (IDS) 11.50 before 11.50.xC9W2 and 11.70 before 11.70.xC5 allows remote authenticated users to execute arbitrary code via crafted arguments in a SET COLLATION statement.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm informix_dynamic_server 11.70.xc3
ibm informix_dynamic_server 11.70.xc2
ibm informix_dynamic_server 11.50.xc7
ibm informix_dynamic_server 11.50.xc5
ibm informix_dynamic_server 11.50.xc5w3
ibm informix_dynamic_server 11.50.xc8w1
ibm informix_dynamic_server 11.50.xc7w2
ibm informix_dynamic_server 11.50.xc7w3
ibm informix_dynamic_server 11.50.xc8w4
ibm informix_dynamic_server 11.50.xc3
ibm informix_dynamic_server 11.50.xc4
ibm informix_dynamic_server 11.70.xc1
ibm informix_dynamic_server 11.50.xc1
ibm informix_dynamic_server 11.50.xc8w2
ibm informix_dynamic_server 11.50.xc6w3
ibm informix_dynamic_server 11.50.xc9
ibm informix_dynamic_server 11.50.xc3w1
ibm informix_dynamic_server 11.50.xc6w4
ibm informix_dynamic_server 11.50.xc5w4
ibm informix_dynamic_server 11.50.xc6
ibm informix_dynamic_server 11.70.xc4
ibm informix_dynamic_server 11.50.xc8
ibm informix_dynamic_server 11.50.xc4w1
ibm informix_dynamic_server 11.50.xc6w1
ibm informix_dynamic_server 11.50.xc8w3
ibm informix_dynamic_server 11.50.xc9w1
ibm informix_dynamic_server 11.50.xc5w2
ibm informix_dynamic_server 11.50.xc2
ibm informix_dynamic_server 11.50.xc6w2
ibm informix_dynamic_server 11.50
ibm informix_dynamic_server 11.50.xc7w1
ibm informix_dynamic_server 11.50.xc7w4
CVE-2012-4816 HIGH

IBM Rational Automation Framework (RAF) 3.x through 3.0.0.5 allows remote attackers to bypass intended Env Gen Wizard (aka Environment Generation Wizard) access restrictions by visiting context roots in HTTP sessions on port 8080.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm rational_automation_framework 3.0.0.3
ibm rational_automation_framework 3.0.0.4
ibm rational_automation_framework 3.0.0.2
ibm rational_automation_framework 3.0.0.5
ibm rational_automation_framework 3.0
ibm rational_automation_framework 3.0.0.1
CVE-2012-4817 MEDIUM

The NFSv4 client implementation in IBM AIX 5.3, 6.1, and 7.1, and VIOS before 2.2.1.4-FP-25 SP-02, does not properly handle GID values, which allows remote attackers to cause a denial of service via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm vios 2.1.2.10
ibm vios 1.5.1.1
ibm aix 6.1
ibm vios 2.1.2.12
ibm vios 2.2.0.10
ibm vios 2.2.1.1
ibm vios 2.2.1.4
ibm aix 7.1
ibm vios 1.5.2.1
ibm vios 1.5.2.6
ibm vios 2.1.2.13
ibm vios 2.2.0.12
ibm vios 2.2.0.13
ibm vios 2.2.1.3
ibm aix 5.3
ibm vios 2.1.3.10
ibm vios 1.4.1.2
ibm vios 2.2.0.11
ibm vios 2.1.0.0
ibm vios 2.2.1.0
CVE-2012-4819 MEDIUM

Cross-site scripting (XSS) vulnerability in InfoSphere Business Glossary 8.1.1 and 8.1.2, InfoSphere DataStage Operation Console, InfoSphere Administration, and Reporting and Repository Management Web Console in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm infosphere_information_server 8.5.0.2
ibm infosphere_information_server 8.5.0.1
ibm infosphere_information_server 8.1
ibm infosphere_business_glossary 8.1.2
ibm infosphere_information_server 8.5
ibm infosphere_information_server 8.7
ibm infosphere_business_glossary 8.1.1
CVE-2012-4820 HIGH

Unspecified vulnerability in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control 5.1.2, WebSphere Real Time, Lotus Notes & Domino, Tivoli Storage Productivity Center, and Service Deliver Manager; and other products from other vendors such as Red Hat, when running under a security manager, allows remote attackers to gain privileges by modifying or removing the security manager via vectors related to "insecure use of the java.lang.reflect.Method invoke() method."

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm lotus_notes 8.0.2.1
ibm tivoli_monitoring 6.2.3
ibm lotus_notes 8.0.0
ibm lotus_notes_traveler 8.5.0.2
ibm lotus_domino 8.5.1.4
ibm lotus_notes 8.5.2.1
ibm lotus_domino 8.5.2.0
ibm lotus_notes_traveler 8.5.1.1
ibm tivoli_monitoring 6.2.1.3
ibm lotus_notes 8.0.2.4
ibm lotus_notes 8.0
ibm rational_host_on-demand 10.0.9.0
ibm lotus_domino 8.5.1.2
ibm lotus_domino 8.0.2.2
ibm tivoli_monitoring 6.2.2.7
ibm rational_change 5.1
ibm rational_host_on-demand 11.0.5.1
ibm lotus_notes 8.5.1.1
ibm rational_host_on-demand 11.0.4.0
ibm tivoli_monitoring 6.2.0.2
ibm lotus_notes_traveler 8.0.1
ibm lotus_notes_traveler 8.0.1.3
ibm lotus_notes 8.5.1.2
ibm rational_host_on-demand 11.0.3.0
ibm lotus_notes 8.5.0.0
ibm rational_change 5.3
ibm tivoli_monitoring 6.1.0.7
ibm rational_host_on-demand 9.0.8.0
ibm tivoli_monitoring 6.2.1.1
ibm lotus_notes 8.0.2
ibm rational_host_on-demand 1.6.0.12
ibm rational_host_on-demand 10.0.10.0
ibm lotus_notes 8.5.1.5
ibm lotus_notes 8.5.2.0
ibm smart_analytics_system_5600_software 9.7
ibm tivoli_monitoring 6.2.2.4
ibm lotus_domino 8.5.1.1
tivoli_storage_productivity_center 5.1 *
ibm lotus_notes 8.5.4
ibm java *
ibm tivoli_remote_control 5.1.2
ibm rational_host_on-demand 11.0.6.0
ibm lotus_notes_sametime 8.0.80407
ibm websphere_real_time 2.0
ibm lotus_notes_traveler 8.5.0.0
ibm lotus_domino 8.5.1
ibm lotus_notes 8.5.0.1
ibm service_delivery_manager 7.2.2.0
ibm lotus_domino 8.5.1.3
ibm websphere_real_time 3.0
ibm lotus_domino 8.5.1.5
ibm rational_host_on-demand 11.0.5.0
ibm lotus_notes 8.5.1.3
ibm lotus_domino 8.5.2.1
ibm tivoli_monitoring 6.2.3.2
ibm lotus_notes_traveler 8.5.3
ibm lotus_notes 8.5.3.1
ibm tivoli_monitoring 6.2.0.3
ibm tivoli_monitoring 6.2.0.1
ibm tivoli_monitoring 6.2.2.1
ibm tivoli_monitoring 6.2.2.6
ibm smart_analytics_system_5600 7200
ibm tivoli_monitoring 6.2.1.4
tivoli_storage_productivity_center 5.1.1 *
ibm tivoli_monitoring 6.2.2.8
ibm lotus_notes 8.0.2.3
ibm lotus_notes 8.5.1.4
ibm lotus_domino 8.0.2.3
ibm lotus_domino 8.0.2.4
ibm tivoli_monitoring 6.2.3.1
ibm lotus_domino 8.0.2
ibm lotus_notes 8.0.1
ibm lotus_notes 8.0.2.2
ibm tivoli_monitoring 6.2.2.3
ibm rational_change 4.7
ibm lotus_notes 8.0.2.0
tivoli_storage_productivity_center 5.0 *
ibm lotus_notes_traveler 8.5.0.1
ibm tivoli_monitoring 6.2.0
ibm lotus_notes 8.5.3
ibm lotus_domino 8.5.2.4
ibm lotus_notes 8.0.2.5
ibm lotus_notes 8.5.2.2
ibm tivoli_monitoring 6.2.3.0
ibm lotus_notes_traveler 8.0
ibm lotus_notes 8.5.1
ibm lotus_notes_sametime 8.5.1.20100709-1631
ibm lotus_notes_traveler 8.0.1.2
ibm lotus_domino 8.0.2.1
ibm lotus_notes_traveler 8.5.3.1
ibm rational_host_on-demand 8.0.8.0
ibm tivoli_monitoring 6.2.2.9
ibm lotus_notes_traveler 8.5.1.3
ibm lotus_notes 8.5.1.0
ibm tivoli_monitoring 6.2.1.2
ibm lotus_notes 8.0.2.6
ibm rational_host_on-demand 11.0.6.1
ibm tivoli_monitoring 6.2.2.0
ibm lotus_domino 8.5.2.2
ibm tivoli_monitoring 6.2.2.5
ibm tivoli_monitoring 6.2.1.0
ibm lotus_notes 8.5.3.2
ibm lotus_domino 8.5.3.1
ibm smart_analytics_system_5600_software -
ibm tivoli_monitoring 6.1.0
ibm lotus_domino 8.5.0
ibm lotus_domino 8.5.3.0
ibm lotus_domino 8.0
ibm lotus_notes_traveler 8.5.2.1
ibm lotus_notes_traveler 8.5.3.2
ibm lotus_domino 8.5.3.2
ibm service_delivery_manager 7.2.1.0
ibm lotus_notes_sametime 8.0.80822
ibm lotus_notes_traveler 8.5.3.3
ibm lotus_domino 8.5.2.3
ibm lotus_domino 8.0.1
ibm lotus_notes_traveler 8.5.1.2
ibm lotus_domino 8.5.0.1
ibm lotus_notes 8.5.2.3
ibm tivoli_monitoring 6.2.2
ibm rational_change 5.2
ibm tivoli_monitoring 6.2.1
ibm lotus_notes 8.5
ibm tivoli_monitoring 6.2.2.2
CVE-2012-4821 HIGH

Multiple unspecified vulnerabilities in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control 5.1.2, WebSphere Real Time, Lotus Notes & Domino, Tivoli Storage Productivity Center, and Service Deliver Manager; and other products from other vendors such as Red Hat, allow remote attackers to execute arbitrary code via "insecure use" of the (1) java.lang.Class getDeclaredMethods or nd (2) java.lang.reflect.AccessibleObject setAccessible() methods.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm lotus_notes 8.0.2.1
ibm tivoli_monitoring 6.2.3
ibm lotus_notes 8.0.0
ibm lotus_notes_traveler 8.5.0.2
ibm lotus_domino 8.5.1.4
ibm lotus_notes 8.5.2.1
ibm lotus_domino 8.5.2.0
ibm lotus_notes_traveler 8.5.1.1
ibm tivoli_monitoring 6.2.1.3
ibm lotus_notes 8.0.2.4
ibm lotus_notes 8.0
ibm rational_host_on-demand 10.0.9.0
ibm lotus_domino 8.5.1.2
ibm lotus_domino 8.0.2.2
ibm tivoli_monitoring 6.2.2.7
ibm rational_change 5.1
ibm rational_host_on-demand 11.0.5.1
ibm lotus_notes 8.5.1.1
ibm rational_host_on-demand 11.0.4.0
ibm tivoli_monitoring 6.2.0.2
ibm lotus_notes_traveler 8.0.1
ibm lotus_notes_traveler 8.0.1.3
ibm lotus_notes 8.5.1.2
ibm rational_host_on-demand 11.0.3.0
ibm lotus_notes 8.5.0.0
ibm rational_change 5.3
ibm tivoli_monitoring 6.1.0.7
ibm rational_host_on-demand 9.0.8.0
ibm tivoli_monitoring 6.2.1.1
ibm lotus_notes 8.0.2
ibm rational_host_on-demand 1.6.0.12
ibm rational_host_on-demand 10.0.10.0
ibm lotus_notes 8.5.1.5
ibm lotus_notes 8.5.2.0
ibm smart_analytics_system_5600_software 9.7
ibm tivoli_monitoring 6.2.2.4
ibm lotus_domino 8.5.1.1
tivoli_storage_productivity_center 5.1 *
ibm lotus_notes 8.5.4
ibm java *
ibm tivoli_remote_control 5.1.2
ibm rational_host_on-demand 11.0.6.0
ibm lotus_notes_sametime 8.0.80407
ibm websphere_real_time 2.0
ibm lotus_notes_traveler 8.5.0.0
ibm lotus_domino 8.5.1
ibm lotus_notes 8.5.0.1
ibm service_delivery_manager 7.2.2.0
ibm lotus_domino 8.5.1.3
ibm websphere_real_time 3.0
ibm lotus_domino 8.5.1.5
ibm rational_host_on-demand 11.0.5.0
ibm lotus_notes 8.5.1.3
ibm lotus_domino 8.5.2.1
ibm tivoli_monitoring 6.2.3.2
ibm lotus_notes_traveler 8.5.3
ibm lotus_notes 8.5.3.1
ibm tivoli_monitoring 6.2.0.3
ibm tivoli_monitoring 6.2.0.1
ibm tivoli_monitoring 6.2.2.1
ibm tivoli_monitoring 6.2.2.6
ibm smart_analytics_system_5600 7200
ibm tivoli_monitoring 6.2.1.4
tivoli_storage_productivity_center 5.1.1 *
ibm tivoli_monitoring 6.2.2.8
ibm lotus_notes 8.0.2.3
ibm lotus_notes 8.5.1.4
ibm lotus_domino 8.0.2.3
ibm lotus_domino 8.0.2.4
ibm tivoli_monitoring 6.2.3.1
ibm lotus_domino 8.0.2
ibm lotus_notes 8.0.1
ibm lotus_notes 8.0.2.2
ibm tivoli_monitoring 6.2.2.3
ibm rational_change 4.7
ibm lotus_notes 8.0.2.0
tivoli_storage_productivity_center 5.0 *
ibm lotus_notes_traveler 8.5.0.1
ibm tivoli_monitoring 6.2.0
ibm lotus_notes 8.5.3
ibm lotus_domino 8.5.2.4
ibm lotus_notes 8.0.2.5
ibm lotus_notes 8.5.2.2
ibm tivoli_monitoring 6.2.3.0
ibm lotus_notes_traveler 8.0
ibm lotus_notes 8.5.1
ibm lotus_notes_sametime 8.5.1.20100709-1631
ibm lotus_notes_traveler 8.0.1.2
ibm lotus_domino 8.0.2.1
ibm lotus_notes_traveler 8.5.3.1
ibm rational_host_on-demand 8.0.8.0
ibm tivoli_monitoring 6.2.2.9
ibm lotus_notes_traveler 8.5.1.3
ibm lotus_notes 8.5.1.0
ibm tivoli_monitoring 6.2.1.2
ibm lotus_notes 8.0.2.6
ibm rational_host_on-demand 11.0.6.1
ibm tivoli_monitoring 6.2.2.0
ibm lotus_domino 8.5.2.2
ibm tivoli_monitoring 6.2.2.5
ibm tivoli_monitoring 6.2.1.0
ibm lotus_notes 8.5.3.2
ibm lotus_domino 8.5.3.1
ibm smart_analytics_system_5600_software -
ibm tivoli_monitoring 6.1.0
ibm lotus_domino 8.5.0
ibm lotus_domino 8.5.3.0
ibm lotus_domino 8.0
ibm lotus_notes_traveler 8.5.2.1
ibm lotus_notes_traveler 8.5.3.2
ibm lotus_domino 8.5.3.2
ibm service_delivery_manager 7.2.1.0
ibm lotus_notes_sametime 8.0.80822
ibm lotus_notes_traveler 8.5.3.3
ibm lotus_domino 8.5.2.3
ibm lotus_domino 8.0.1
ibm lotus_notes_traveler 8.5.1.2
ibm lotus_domino 8.5.0.1
ibm lotus_notes 8.5.2.3
ibm tivoli_monitoring 6.2.2
ibm rational_change 5.2
ibm tivoli_monitoring 6.2.1
ibm lotus_notes 8.5
ibm tivoli_monitoring 6.2.2.2
CVE-2012-4822 HIGH

Multiple unspecified vulnerabilities in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control 5.1.2, WebSphere Real Time, Lotus Notes & Domino, Tivoli Storage Productivity Center, and Service Deliver Manager; and other products from other vendors such as Red Hat, allow remote attackers to execute arbitrary code via vectors related to "insecure use [of] multiple methods in the java.lang.class class."

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm lotus_notes 8.0.2.1
ibm tivoli_monitoring 6.2.3
ibm lotus_notes 8.0.0
ibm lotus_notes_traveler 8.5.0.2
ibm lotus_domino 8.5.1.4
ibm lotus_notes 8.5.2.1
ibm lotus_domino 8.5.2.0
ibm lotus_notes_traveler 8.5.1.1
ibm tivoli_monitoring 6.2.1.3
ibm lotus_notes 8.0.2.4
ibm lotus_notes 8.0
ibm rational_host_on-demand 10.0.9.0
ibm lotus_domino 8.5.1.2
ibm lotus_domino 8.0.2.2
ibm tivoli_monitoring 6.2.2.7
ibm rational_change 5.1
ibm rational_host_on-demand 11.0.5.1
ibm lotus_notes 8.5.1.1
ibm rational_host_on-demand 11.0.4.0
ibm tivoli_monitoring 6.2.0.2
ibm lotus_notes_traveler 8.0.1
ibm lotus_notes_traveler 8.0.1.3
ibm lotus_notes 8.5.1.2
ibm rational_host_on-demand 11.0.3.0
ibm lotus_notes 8.5.0.0
ibm rational_change 5.3
ibm tivoli_monitoring 6.1.0.7
ibm rational_host_on-demand 9.0.8.0
ibm tivoli_monitoring 6.2.1.1
ibm lotus_notes 8.0.2
ibm rational_host_on-demand 1.6.0.12
ibm rational_host_on-demand 10.0.10.0
ibm lotus_notes 8.5.1.5
ibm lotus_notes 8.5.2.0
ibm smart_analytics_system_5600_software 9.7
ibm tivoli_monitoring 6.2.2.4
ibm lotus_domino 8.5.1.1
tivoli_storage_productivity_center 5.1 *
ibm lotus_notes 8.5.4
ibm java *
ibm tivoli_remote_control 5.1.2
ibm rational_host_on-demand 11.0.6.0
ibm lotus_notes_sametime 8.0.80407
ibm websphere_real_time 2.0
ibm lotus_notes_traveler 8.5.0.0
ibm lotus_domino 8.5.1
ibm lotus_notes 8.5.0.1
ibm service_delivery_manager 7.2.2.0
ibm lotus_domino 8.5.1.3
ibm websphere_real_time 3.0
ibm lotus_domino 8.5.1.5
ibm rational_host_on-demand 11.0.5.0
ibm lotus_notes 8.5.1.3
ibm lotus_domino 8.5.2.1
ibm tivoli_monitoring 6.2.3.2
ibm lotus_notes_traveler 8.5.3
ibm lotus_notes 8.5.3.1
ibm tivoli_monitoring 6.2.0.3
ibm tivoli_monitoring 6.2.0.1
ibm tivoli_monitoring 6.2.2.1
ibm tivoli_monitoring 6.2.2.6
ibm smart_analytics_system_5600 7200
ibm tivoli_monitoring 6.2.1.4
tivoli_storage_productivity_center 5.1.1 *
ibm tivoli_monitoring 6.2.2.8
ibm lotus_notes 8.0.2.3
ibm lotus_notes 8.5.1.4
ibm lotus_domino 8.0.2.3
ibm lotus_domino 8.0.2.4
ibm tivoli_monitoring 6.2.3.1
ibm lotus_domino 8.0.2
ibm lotus_notes 8.0.1
ibm lotus_notes 8.0.2.2
ibm tivoli_monitoring 6.2.2.3
ibm rational_change 4.7
ibm lotus_notes 8.0.2.0
tivoli_storage_productivity_center 5.0 *
ibm lotus_notes_traveler 8.5.0.1
ibm tivoli_monitoring 6.2.0
ibm lotus_notes 8.5.3
ibm lotus_domino 8.5.2.4
ibm lotus_notes 8.0.2.5
ibm lotus_notes 8.5.2.2
ibm tivoli_monitoring 6.2.3.0
ibm lotus_notes_traveler 8.0
ibm lotus_notes 8.5.1
ibm lotus_notes_sametime 8.5.1.20100709-1631
ibm lotus_notes_traveler 8.0.1.2
ibm lotus_domino 8.0.2.1
ibm lotus_notes_traveler 8.5.3.1
ibm rational_host_on-demand 8.0.8.0
ibm tivoli_monitoring 6.2.2.9
ibm lotus_notes_traveler 8.5.1.3
ibm lotus_notes 8.5.1.0
ibm tivoli_monitoring 6.2.1.2
ibm lotus_notes 8.0.2.6
ibm rational_host_on-demand 11.0.6.1
ibm tivoli_monitoring 6.2.2.0
ibm lotus_domino 8.5.2.2
ibm tivoli_monitoring 6.2.2.5
ibm tivoli_monitoring 6.2.1.0
ibm lotus_notes 8.5.3.2
ibm lotus_domino 8.5.3.1
ibm smart_analytics_system_5600_software -
ibm tivoli_monitoring 6.1.0
ibm lotus_domino 8.5.0
ibm lotus_domino 8.5.3.0
ibm lotus_domino 8.0
ibm lotus_notes_traveler 8.5.2.1
ibm lotus_notes_traveler 8.5.3.2
ibm lotus_domino 8.5.3.2
ibm service_delivery_manager 7.2.1.0
ibm lotus_notes_sametime 8.0.80822
ibm lotus_notes_traveler 8.5.3.3
ibm lotus_domino 8.5.2.3
ibm lotus_domino 8.0.1
ibm lotus_notes_traveler 8.5.1.2
ibm lotus_domino 8.5.0.1
ibm lotus_notes 8.5.2.3
ibm tivoli_monitoring 6.2.2
ibm rational_change 5.2
ibm tivoli_monitoring 6.2.1
ibm lotus_notes 8.5
ibm tivoli_monitoring 6.2.2.2
CVE-2012-4823 HIGH

Unspecified vulnerability in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control 5.1.2, WebSphere Real Time, Lotus Notes & Domino, Tivoli Storage Productivity Center, and Service Deliver Manager; and other products from other vendors such as Red Hat, allows remote attackers to execute arbitrary code via vectors related to "insecure use of the java.lang.ClassLoder defineClass() method."

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm lotus_notes 8.0.2.1
ibm tivoli_monitoring 6.2.3
ibm lotus_notes 8.0.0
ibm lotus_notes_traveler 8.5.0.2
ibm lotus_domino 8.5.1.4
ibm lotus_notes 8.5.2.1
ibm lotus_domino 8.5.2.0
ibm lotus_notes_traveler 8.5.1.1
ibm tivoli_monitoring 6.2.1.3
ibm lotus_notes 8.0.2.4
ibm lotus_notes 8.0
ibm rational_host_on-demand 10.0.9.0
ibm lotus_domino 8.5.1.2
ibm lotus_domino 8.0.2.2
ibm tivoli_monitoring 6.2.2.7
ibm rational_change 5.1
ibm rational_host_on-demand 11.0.5.1
ibm lotus_notes 8.5.1.1
ibm rational_host_on-demand 11.0.4.0
ibm tivoli_monitoring 6.2.0.2
ibm lotus_notes_traveler 8.0.1
ibm lotus_notes_traveler 8.0.1.3
ibm lotus_notes 8.5.1.2
ibm rational_host_on-demand 11.0.3.0
ibm lotus_notes 8.5.0.0
ibm rational_change 5.3
ibm tivoli_monitoring 6.1.0.7
ibm rational_host_on-demand 9.0.8.0
ibm tivoli_monitoring 6.2.1.1
ibm lotus_notes 8.0.2
ibm rational_host_on-demand 1.6.0.12
ibm rational_host_on-demand 10.0.10.0
ibm lotus_notes 8.5.1.5
ibm lotus_notes 8.5.2.0
ibm smart_analytics_system_5600_software 9.7
ibm tivoli_monitoring 6.2.2.4
ibm lotus_domino 8.5.1.1
tivoli_storage_productivity_center 5.1 *
ibm lotus_notes 8.5.4
ibm java *
ibm tivoli_remote_control 5.1.2
ibm rational_host_on-demand 11.0.6.0
ibm lotus_notes_sametime 8.0.80407
ibm websphere_real_time 2.0
ibm lotus_notes_traveler 8.5.0.0
ibm lotus_domino 8.5.1
ibm lotus_notes 8.5.0.1
ibm service_delivery_manager 7.2.2.0
ibm lotus_domino 8.5.1.3
ibm websphere_real_time 3.0
ibm lotus_domino 8.5.1.5
ibm rational_host_on-demand 11.0.5.0
ibm lotus_notes 8.5.1.3
ibm lotus_domino 8.5.2.1
ibm tivoli_monitoring 6.2.3.2
ibm lotus_notes_traveler 8.5.3
ibm lotus_notes 8.5.3.1
ibm tivoli_monitoring 6.2.0.3
ibm tivoli_monitoring 6.2.0.1
ibm tivoli_monitoring 6.2.2.1
ibm tivoli_monitoring 6.2.2.6
ibm smart_analytics_system_5600 7200
ibm tivoli_monitoring 6.2.1.4
tivoli_storage_productivity_center 5.1.1 *
ibm tivoli_monitoring 6.2.2.8
ibm lotus_notes 8.0.2.3
ibm lotus_notes 8.5.1.4
ibm lotus_domino 8.0.2.3
ibm lotus_domino 8.0.2.4
ibm tivoli_monitoring 6.2.3.1
ibm lotus_domino 8.0.2
ibm lotus_notes 8.0.1
ibm lotus_notes 8.0.2.2
ibm tivoli_monitoring 6.2.2.3
ibm rational_change 4.7
ibm lotus_notes 8.0.2.0
tivoli_storage_productivity_center 5.0 *
ibm lotus_notes_traveler 8.5.0.1
ibm tivoli_monitoring 6.2.0
ibm lotus_notes 8.5.3
ibm lotus_domino 8.5.2.4
ibm lotus_notes 8.0.2.5
ibm lotus_notes 8.5.2.2
ibm tivoli_monitoring 6.2.3.0
ibm lotus_notes_traveler 8.0
ibm lotus_notes 8.5.1
ibm lotus_notes_sametime 8.5.1.20100709-1631
ibm lotus_notes_traveler 8.0.1.2
ibm lotus_domino 8.0.2.1
ibm lotus_notes_traveler 8.5.3.1
ibm rational_host_on-demand 8.0.8.0
ibm tivoli_monitoring 6.2.2.9
ibm lotus_notes_traveler 8.5.1.3
ibm lotus_notes 8.5.1.0
ibm tivoli_monitoring 6.2.1.2
ibm lotus_notes 8.0.2.6
ibm rational_host_on-demand 11.0.6.1
ibm tivoli_monitoring 6.2.2.0
ibm lotus_domino 8.5.2.2
ibm tivoli_monitoring 6.2.2.5
ibm tivoli_monitoring 6.2.1.0
ibm lotus_notes 8.5.3.2
ibm lotus_domino 8.5.3.1
ibm smart_analytics_system_5600_software -
ibm tivoli_monitoring 6.1.0
ibm lotus_domino 8.5.0
ibm lotus_domino 8.5.3.0
ibm lotus_domino 8.0
ibm lotus_notes_traveler 8.5.2.1
ibm lotus_notes_traveler 8.5.3.2
ibm lotus_domino 8.5.3.2
ibm service_delivery_manager 7.2.1.0
ibm lotus_notes_sametime 8.0.80822
ibm lotus_notes_traveler 8.5.3.3
ibm lotus_domino 8.5.2.3
ibm lotus_domino 8.0.1
ibm lotus_notes_traveler 8.5.1.2
ibm lotus_domino 8.5.0.1
ibm lotus_notes 8.5.2.3
ibm tivoli_monitoring 6.2.2
ibm rational_change 5.2
ibm tivoli_monitoring 6.2.1
ibm lotus_notes 8.5
ibm tivoli_monitoring 6.2.2.2
CVE-2012-4824 MEDIUM

Open redirect vulnerability in servlet/traveler in IBM Lotus Notes Traveler 8.5.3 before 8.5.3.3 Interim Fix 1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirectURL parameter.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm lotus_notes_traveler 8.5.3.1
ibm lotus_notes_traveler 8.5.3.3
ibm lotus_notes_traveler 8.5.3
ibm lotus_notes_traveler 8.5.3.2
CVE-2012-4825 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in servlet/traveler/ILNT.mobileconfig in IBM Lotus Notes Traveler before 8.5.3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) userId or (2) address parameter in a getClientConfigFile action.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm lotus_notes_traveler 8.5.1.1
ibm lotus_notes_traveler 8.5.3
ibm lotus_notes_traveler 8.5.0.0
ibm lotus_notes_traveler 8.5.1.3
ibm lotus_notes_traveler 8.5.1.2
ibm lotus_notes_traveler 8.5.0.1
ibm lotus_notes_traveler 8.5.0.2
ibm lotus_notes_traveler 8.5.2.1
ibm lotus_notes_traveler *
CVE-2012-4826 HIGH

Stack-based buffer overflow in the SQL/PSM (aka SQL Persistent Stored Module) Stored Procedure (SP) infrastructure in IBM DB2 9.1, 9.5, 9.7 before FP7, 9.8, and 10.1 might allow remote authenticated users to execute arbitrary code by debugging a stored procedure.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm db2 9.1
ibm db2 9.7.0.3
ibm db2 9.7.0.5
ibm db2 9.5
ibm db2 9.7.0.2
ibm db2 10.1
ibm db2 9.7.0.1
ibm db2 9.7.0.4
ibm db2 9.7.0.6
ibm db2 9.8
ibm db2 9.7
CVE-2012-4829 MEDIUM

IBM XIV Storage System Gen3 before 11.2 relies on a default X.509 v3 certificate for authentication, which allows man-in-the-middle attackers to spoof servers by leveraging an inappropriate certificate-trust relationship.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm xiv_storage_system_gen3 *
CVE-2012-4830 MEDIUM

Unspecified vulnerability in IBM WebSphere Commerce 6.0 through 6.0.0.11 and 7.0 through 7.0.0.6 allows remote attackers to obtain users' personal data via unknown vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_commerce 6.0.0.6
ibm websphere_commerce 7.0.0.4
ibm websphere_commerce 7.0.0.6
ibm websphere_commerce 6.0.0.11
ibm websphere_commerce 6.0.0.1
ibm websphere_commerce 6.0.0.2
ibm websphere_commerce 6.0.0.10
ibm websphere_commerce 7.0.0.3
ibm websphere_commerce 7.0.0.2
ibm websphere_commerce 6.0.0.7
ibm websphere_commerce 6.0.0.8
ibm websphere_commerce 7.0.0.5
ibm websphere_commerce 6.0.0.3
ibm websphere_commerce 6.0.0.4
ibm websphere_commerce 6.0.0.9
ibm websphere_commerce 7.0.0.1
ibm websphere_commerce 6.0.0.5
CVE-2012-4832 LOW

Information Services Framework (ISF) in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 and InfoSphere Business Glossary 8.1.1 and 8.1.2 does not have an off autocomplete attribute for the password field on the login page, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm infosphere_information_server 8.5.0.2
ibm infosphere_information_server 8.5.0.1
ibm infosphere_information_server 8.1
ibm infosphere_business_glossary 8.1.2
ibm infosphere_information_server 8.5
ibm infosphere_information_server 8.7
ibm infosphere_business_glossary 8.1.1
CVE-2012-4833 LOW

fuser in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly restrict the -k option, which allows local users to kill arbitrary processes via a crafted command line.

CVSS 2.0

Severity: LOW

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm aix 6.1
ibm vios 2.2.1.4
ibm aix 7.1
CVE-2012-4834 MEDIUM

Directory traversal vulnerability in LayerLoader.jsp in the theme component in IBM WebSphere Portal 7.0.0.1 and 7.0.0.2 before CF19 and 8.0 before CF03 allows remote attackers to read arbitrary files via a crafted URI.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.0
ibm websphere_portal 7.0.0.2
ibm websphere_portal 7.0.0.1
CVE-2012-4835 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm cognos_business_intelligence 10.2
ibm cognos_business_intelligence 10.1
ibm cognos_business_intelligence 8.4.1
ibm cognos_business_intelligence 10.1.1
CVE-2012-4836 LOW

Cross-site scripting (XSS) vulnerability in IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted string that is not properly handled during rendering of stored data.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm cognos_business_intelligence 10.2
ibm cognos_business_intelligence 10.1
ibm cognos_business_intelligence 8.4.1
ibm cognos_business_intelligence 10.1.1
CVE-2012-4837 MEDIUM

IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 allows remote authenticated users to conduct XPath injection attacks, and read arbitrary XML files, via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm cognos_business_intelligence 10.2
ibm cognos_business_intelligence 10.1
ibm cognos_business_intelligence 8.4.1
ibm cognos_business_intelligence 10.1.1
CVE-2012-4838 LOW

IBM Flex System Chassis Management Module (CMM) and Integrated Management Module 2 (IMM2) allow local users to obtain sensitive information about (1) local accounts, (2) SSH private keys, (3) SSL/TLS private keys, (4) SNMPv3 communities, and (5) LDAP credentials by leveraging unspecified side effects of service or maintenance activity.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm integrated_management_module_ii -
ibm flex_system_chassis_management_module -
CVE-2012-4839 MEDIUM

The OSLC interface in the Web Client (aka CQ Web) in IBM Rational ClearQuest 7.1.2.x before 7.1.2.9 and 8.0.0.x before 8.0.0.5 allows remote attackers to conduct phishing attacks via a FRAME element.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm rational_clearquest 7.1.2.1
ibm rational_clearquest 7.1.2.3
ibm rational_clearquest 8.0.0.2
ibm rational_clearquest 7.1.2
ibm rational_clearquest 8.0.0.4
ibm rational_clearquest 7.1.2.5
ibm rational_clearquest 7.1.2.6
ibm rational_clearquest 7.1.2.8
ibm rational_clearquest 7.1.2.2
ibm rational_clearquest 8.0.0.1
ibm rational_clearquest 8.0.0.3
ibm rational_clearquest 7.1.2.4
ibm rational_clearquest 8.0.0
ibm rational_clearquest 7.1.2.7
CVE-2012-4840 MEDIUM

IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 allows remote attackers to conduct XPath injection attacks, and call XPath extension functions, via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-94,

Products Affected

Vendor Product Version
ibm cognos_business_intelligence 10.2
ibm cognos_business_intelligence 10.1
ibm cognos_business_intelligence 8.4.1
ibm cognos_business_intelligence 10.1.1
CVE-2012-4841 MEDIUM

Unspecified vulnerability in Tivoli Endpoint Manager for Remote Control Broker 8.2 before 8.2.1-TIV-TEMRC821-IF0002 allows remote attackers to cause a denial of service (resource consumption) via unknown vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm tivoli_endpoint_manager 8.2
CVE-2012-4842 MEDIUM

Open redirect vulnerability in the web server in IBM Lotus Domino 8.5.x through 8.5.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm lotus_domino 8.5.2.4
ibm lotus_domino 8.5.1.5
ibm lotus_domino 8.5.2.2
ibm lotus_domino 8.5.1.1
ibm lotus_domino 8.5.2.3
ibm lotus_domino 8.5.1.4
ibm lotus_domino 8.5.2.0
ibm lotus_domino 8.5.0.1
ibm lotus_domino 8.5.2.1
ibm lotus_domino 8.5.0
ibm lotus_domino 8.5.3.0
ibm lotus_domino 8.5.1
ibm lotus_domino 8.5.1.2
ibm lotus_domino 8.5.1.3
CVE-2012-4844 MEDIUM

Cross-site scripting (XSS) vulnerability in the web server in IBM Lotus Domino 8.5.x through 8.5.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm lotus_domino 8.5.2.4
ibm lotus_domino 8.5.1.5
ibm lotus_domino 8.5.2.2
ibm lotus_domino 8.5.1.1
ibm lotus_domino 8.5.2.3
ibm lotus_domino 8.5.1.4
ibm lotus_domino 8.5.2.0
ibm lotus_domino 8.5.0.1
ibm lotus_domino 8.5.2.1
ibm lotus_domino 8.5.0
ibm lotus_domino 8.5.3.0
ibm lotus_domino 8.5.1
ibm lotus_domino 8.5.1.2
ibm lotus_domino 8.5.1.3
CVE-2012-4845 MEDIUM

The FTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly manage privileges in an RBAC environment, which allows attackers to bypass intended file-read restrictions by leveraging the setuid installation of the ftp executable file.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm aix 6.1
ibm vios 2.2.1.4
ibm aix 7.1
CVE-2012-4846 MEDIUM

IBM Lotus Notes 8.5.x before 8.5.3 FP3 does not include the HTTPOnly flag in a Set-Cookie header for a web-application cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie, aka SPRs JMAS7TRNLN and SRAO8U3Q68.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm lotus_notes 8.5.1.5
ibm lotus_notes 8.5.1.1
ibm lotus_notes 8.5.2.0
ibm lotus_notes 8.5.2.2
ibm lotus_notes 8.5.1.4
ibm lotus_notes 8.5.1
ibm lotus_notes 8.5.1.2
ibm lotus_notes 8.5.3.2
ibm lotus_notes 8.5.1.3
ibm lotus_notes 8.5.2.1
ibm lotus_notes 8.5.0.0
ibm lotus_notes 8.5.2.3
ibm lotus_notes 8.5.0.1
ibm lotus_notes 8.5.1.0
ibm lotus_notes 8.5.3.1
ibm lotus_notes 8.5.3
CVE-2012-4847 MEDIUM

IBM Cognos Business Intelligence (BI) 8.4 and 8.4.1 allows remote authenticated users to cause a denial of service (CPU consumption) via a crafted request containing a zero-valued byte.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-189,

Products Affected

Vendor Product Version
ibm cognos_business_intelligence 8.4
ibm cognos_business_intelligence 8.4.1
CVE-2012-4848 LOW

Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Foundations Start before 1.2.2c allow remote authenticated users to inject arbitrary web script or HTML via a Webconfig Users user-attribute field, as demonstrated by the (1) First Name or (2) Last Name field.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm lotus_foundations_start 1.1
ibm lotus_foundations_start *
ibm lotus_foundations_start 1.0
ibm lotus_foundations_start 1.2
CVE-2012-4850 HIGH

IBM WebSphere Application Server 8.5 Liberty Profile before 8.5.0.1, when JAX-RS is used, does not properly validate requests, which allows remote attackers to gain privileges via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm websphere_application_server 8.5.0.0
CVE-2012-4851 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server 8.5 Liberty Profile before 8.5.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URI.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_application_server *
CVE-2012-4853 MEDIUM

Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Application Server 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1 allows remote attackers to hijack the authentication of arbitrary users for requests that trigger information disclosure.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 7.0
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0.35
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 6.1.6
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 6.1.3
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.0.39
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 6.1.7
ibm websphere_application_server 6.1.0.37
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 6.1.1
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 8.0.0.2
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 6.1.0
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 6.1
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.41
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.1.5
ibm websphere_application_server 6.1.14
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 6.1.0.43
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.1.13
ibm websphere_application_server 7.0.0.4
CVE-2012-4855 MEDIUM

Unspecified vulnerability in the web services framework in IBM WebSphere Commerce 6.0 through 6.0.0.11 and 7.0 through 7.0.0.6 allows remote attackers to cause a denial of service (login outage) via unknown vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_commerce 6.0.0.6
ibm websphere_commerce 7.0.0.4
ibm websphere_commerce 7.0.0.6
ibm websphere_commerce 6.0.0.11
ibm websphere_commerce 6.0.0.1
ibm websphere_commerce 6.0.0.2
ibm websphere_commerce 6.0.0.10
ibm websphere_commerce 7.0.0.3
ibm websphere_commerce 7.0.0.2
ibm websphere_commerce 7.0
ibm websphere_commerce 6.0.0.7
ibm websphere_commerce 6.0.0.8
ibm websphere_commerce 7.0.0.5
ibm websphere_commerce 6.0.0.3
ibm websphere_commerce 6.0.0.0
ibm websphere_commerce 6.0.0.4
ibm websphere_commerce 6.0.0.9
ibm websphere_commerce 7.0.0.1
ibm websphere_commerce 6.0.0.5
CVE-2012-4856 HIGH

The Service Processor in the IBM Power 5 91##-### and 940#-### before SF240_418_382 does not ensure that firewall code is executed, which allows remote attackers to execute arbitrary code via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm power_5_system_firmware sf240_358_201
ibm power_5_system_firmware sf240_415_382
ibm power_5_system_firmware sf240_299_201
ibm power_5_system_firmware sf240_201_201
ibm power_5 9133-55a
ibm power_5_system_firmware sf240_284_201
ibm power_5_system_firmware sf240_332_201
ibm power_5 9131-52a
ibm power_5_system_firmware sf240_259_201
ibm power_5 9118-575
ibm power_5 9406-520
ibm power_5_system_firmware sf240_222_201
ibm power_5 9115-505
ibm power_5_system_firmware sf240_338_201
ibm power_5_system_firmware *
ibm power_5 9111-520
ibm power_5_system_firmware sf240_417
ibm power_5 9406-570
ibm power_5_system_firmware sf240_233_201
ibm power_5_system_firmware sf240_261_201
ibm power_5_system_firmware sf240_298_201
ibm power_5 9110-51a
ibm power_5_system_firmware sf240_258_201
ibm power_5 9406-550
ibm power_5_system_firmware sf240_202_201
ibm power_5 9110-510
ibm power_5_system_firmware sf240_403_382
ibm power_5 9405-520
ibm power_5 9116-561
ibm power_5 9406-525
ibm power_5 9111-285
ibm power_5_system_firmware sf240_219_201
ibm power_5_system_firmware sf240_320_201
ibm power_5_system_firmware sf240_382_382
ibm power_5 9123-710
ibm power_5 9113-550
ibm power_5 9117-570
ibm power_5 9124-720
ibm power_5_system_firmware sf240_371
ibm power_5 9407-515
CVE-2012-4857 HIGH

Buffer overflow in IBM Informix 11.50 through 11.50.xC9W2 and 11.70 before 11.70.xC7 allows remote authenticated users to execute arbitrary code via a crafted SQL statement.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm informix_dynamic_server 11.70.xc3
ibm informix_dynamic_server 11.70.xc2
ibm informix_dynamic_server 11.50.xc7
ibm informix_dynamic_server 11.50.xc5
ibm informix_dynamic_server 11.50.xc5w3
ibm informix_dynamic_server 11.50.xc8w1
ibm informix_dynamic_server 11.50.xc7w2
ibm informix_dynamic_server 11.50.xc7w3
ibm informix_dynamic_server 11.50.xc8w4
ibm informix_dynamic_server 11.50.xc3
ibm informix_dynamic_server 11.50.xc4
ibm informix_dynamic_server 11.70.xc1
ibm informix_dynamic_server 11.50.xc1
ibm informix_dynamic_server 11.50.xc8w2
ibm informix_dynamic_server 11.50.xc6w3
ibm informix_dynamic_server 11.50.xc9
ibm informix_dynamic_server 11.50.xc3w1
ibm informix_dynamic_server 11.50.xc6w4
ibm informix_dynamic_server 11.50.xc5w4
ibm informix_dynamic_server 11.50.xc6
ibm informix_dynamic_server 11.50.xc8
ibm informix_dynamic_server 11.50.xc4w1
ibm informix_dynamic_server 11.50.xc6w1
ibm informix_dynamic_server 11.50.xc8w3
ibm informix_dynamic_server 11.50.xc5w2
ibm informix_dynamic_server 11.50.xc2
ibm informix_dynamic_server 11.50.xc6w2
ibm informix_dynamic_server 11.50
ibm informix_dynamic_server 11.50.xc7w1
ibm informix_dynamic_server 11.50.xc7w4
CVE-2012-4858 HIGH

IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 does not properly validate Java serialized input, which allows remote attackers to execute arbitrary commands via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm cognos_business_intelligence 10.2
ibm cognos_business_intelligence 10.1
ibm cognos_business_intelligence 8.4.1
ibm cognos_business_intelligence 10.1.1
CVE-2012-4859 HIGH

Unspecified vulnerability in IBM Tivoli Storage Manager for Space Management (aka TSM HSM) before 6.2.5.0 and 6.3.x before 6.3.1.0 allows local users to read or modify file system objects via unknown vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_for_space_management 6.1.0
ibm tivoli_storage_manager_for_space_management *
ibm tivoli_storage_manager_for_space_management 6.3.0
CVE-2012-4861 MEDIUM

The web server in InfoSphere Data Replication Dashboard in IBM InfoSphere Replication Server 9.7 and 10.1 through 10.1.0.4 allows remote authenticated users to list directories via a direct request for a directory URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm infosphere_replication_server 10.1.0.3
ibm infosphere_replication_server 10.1.0.4
ibm infosphere_replication_server 9.7
ibm infosphere_replication_server 10.1.0.1
ibm infosphere_replication_server 10.1.0
CVE-2012-4862 LOW

The Host Connect emulator in IBM Rational Developer for System z 7.1 through 8.5.1 does not properly store the SSL certificate password, which allows local users to obtain sensitive information via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm rational_developer_for_system_z 7.1
ibm rational_developer_for_system_z 8.5.0.1
ibm rational_developer_for_system_z 8.5.0
ibm rational_developer_for_system_z 7.6.2.2
ibm rational_developer_for_system_z 8.0.3.3
ibm rational_developer_for_system_z 8.0.3.2
ibm rational_developer_for_system_z 8.5.1
ibm rational_developer_for_system_z 8.0.1.0
ibm rational_developer_for_system_z 7.6.2.3
ibm rational_developer_for_system_z 8.0.3
ibm rational_developer_for_system_z 7.6.2.1
ibm rational_developer_for_system_z 7.6.2.4
ibm rational_developer_for_system_z 8.0.2
ibm rational_developer_for_system_z 8.0.3.1
CVE-2012-5307 LOW

Cross-site scripting (XSS) vulnerability in servlet/traveler in IBM Lotus Notes Traveler before 8.5.3.3 Interim Fix 1, when Firefox is used, allows remote attackers to inject arbitrary web script or HTML via the redirectURL parameter, a different vulnerability than CVE-2012-4824 and CVE-2012-4825.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm lotus_notes_traveler 8.5.1.1
ibm lotus_notes_traveler 8.5.3.1
ibm lotus_notes_traveler 8.5.3
ibm lotus_notes_traveler 8.5.0.0
ibm lotus_notes_traveler 8.5.1.3
ibm lotus_notes_traveler 8.5.1.2
ibm lotus_notes_traveler 8.5.0.1
ibm lotus_notes_traveler 8.5.0.2
ibm lotus_notes_traveler 8.5.2.1
ibm lotus_notes_traveler 8.5.3.2
ibm lotus_notes_traveler *
CVE-2012-5308 MEDIUM

Cross-site request forgery (CSRF) vulnerability in servlet/traveler in IBM Lotus Notes Traveler through 8.5.3.3 Interim Fix 1 allows remote attackers to hijack the authentication of arbitrary users for requests that create problem reports via a getReportProblem upload action.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm lotus_notes_traveler 8.5.1.1
ibm lotus_notes_traveler 8.5.3.1
ibm lotus_notes_traveler 8.5.3.3
ibm lotus_notes_traveler 8.5.3
ibm lotus_notes_traveler 8.5.0.0
ibm lotus_notes_traveler 8.5.1.3
ibm lotus_notes_traveler 8.5.1.2
ibm lotus_notes_traveler 8.5.0.1
ibm lotus_notes_traveler 8.5.0.2
ibm lotus_notes_traveler 8.5.2.1
ibm lotus_notes_traveler 8.5.3.2
CVE-2012-5309 MEDIUM

servlet/traveler in IBM Lotus Notes Traveler through 8.5.3.3 Interim Fix 1 does not properly restrict invalid authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attack.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm lotus_notes_traveler 8.5.1.1
ibm lotus_notes_traveler 8.5.3.1
ibm lotus_notes_traveler 8.5.3.3
ibm lotus_notes_traveler 8.5.3
ibm lotus_notes_traveler 8.5.0.0
ibm lotus_notes_traveler 8.5.1.3
ibm lotus_notes_traveler 8.5.1.2
ibm lotus_notes_traveler 8.5.0.1
ibm lotus_notes_traveler 8.5.0.2
ibm lotus_notes_traveler 8.5.2.1
ibm lotus_notes_traveler 8.5.3.2
CVE-2012-5756 MEDIUM

The IBM WebSphere DataPower XC10 Appliance 2.0.0.0 through 2.0.0.3 and 2.1.0.0 through 2.1.0.2, when a collective configuration is enabled, has a single secret key that is shared across different customers' installations, which allows remote attackers to spoof a container server by (1) sniffing the network to locate a cleartext transmission of this key or (2) leveraging knowledge of this key from another installation.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm websphere_datapower_xc10_appliance 2.0.0.2
ibm websphere_datapower_xc10_appliance 2.0.0.1
ibm websphere_datapower_xc10_appliance 2.0.0.3
ibm websphere_datapower_xc10_appliance 2.0.0.0
ibm websphere_datapower_xc10_appliance 2.1.0.0
ibm websphere_datapower_xc10_appliance 2.1.0.2
ibm websphere_datapower_xc10_appliance 2.1.0.1
CVE-2012-5757 MEDIUM

Cross-site scripting (XSS) vulnerability in the Web Client in IBM Rational ClearQuest 7.1.x before 7.1.2.10 and 8.x before 8.0.0.6 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_clearquest 7.1.2
ibm rational_clearquest 8.0.0.5
ibm rational_clearquest 7.1.1.1
ibm rational_clearquest 7.1.2.2
ibm rational_clearquest 7.1.1.3
ibm rational_clearquest 8.0.0.1
ibm rational_clearquest 8.0.0.3
ibm rational_clearquest 8.0
ibm rational_clearquest 7.1.1.5
ibm rational_clearquest 7.1.2.7
ibm rational_clearquest 7.1.2.1
ibm rational_clearquest 7.1.2.3
ibm rational_clearquest 8.0.0.2
ibm rational_clearquest 7.1.1.4
ibm rational_clearquest 8.0.0.4
ibm rational_clearquest 7.1.2.5
ibm rational_clearquest 7.1.1.8
ibm rational_clearquest 7.1.2.6
ibm rational_clearquest 7.1.2.8
ibm rational_clearquest 7.1.1.6
ibm rational_clearquest 7.1.2.9
ibm rational_clearquest 7.1.1.7
ibm rational_clearquest 7.1.1.2
ibm rational_clearquest 7.1.2.4
CVE-2012-5758 HIGH

The IBM WebSphere DataPower XC10 Appliance 2.0.0.0 through 2.0.0.3 and 2.1.0.0 through 2.1.0.2 does not require authentication for an unspecified interface, which allows remote attackers to cause a denial of service (process exit) via unknown vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm websphere_datapower_xc10_appliance 2.0.0.2
ibm websphere_datapower_xc10_appliance 2.0.0.1
ibm websphere_datapower_xc10_appliance 2.0.0.3
ibm websphere_datapower_xc10_appliance 2.0.0.0
ibm websphere_datapower_xc10_appliance 2.1.0.0
ibm websphere_datapower_xc10_appliance 2.1.0.2
ibm websphere_datapower_xc10_appliance 2.1.0.1
CVE-2012-5759 HIGH

The IBM WebSphere DataPower XC10 Appliance 2.0.0.0 through 2.0.0.3 and 2.1.0.0 through 2.1.0.2 allows remote authenticated users to bypass intended administrative-role requirements and perform arbitrary JMX operations via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_datapower_xc10_appliance 2.0.0.2
ibm websphere_datapower_xc10_appliance 2.0.0.1
ibm websphere_datapower_xc10_appliance 2.0.0.3
ibm websphere_datapower_xc10_appliance 2.0.0.0
ibm websphere_datapower_xc10_appliance 2.1.0.0
ibm websphere_datapower_xc10_appliance 2.1.0.2
ibm websphere_datapower_xc10_appliance 2.1.0.1
CVE-2012-5760 MEDIUM

SQL injection vulnerability in the WebAdmin application 6.0.5, 6.0.8, and 7.0 before P2 in IBM Netezza allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm netezza 6.0.5
ibm netezza 6.0.8
ibm netezza 7.0
CVE-2012-5761 LOW

Cross-site scripting (XSS) vulnerability in the WebAdmin application 6.0.5, 6.0.8, and 7.0 before P2 in IBM Netezza allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm netezza 6.0.5
ibm netezza 6.0.8
ibm netezza 7.0
CVE-2012-5762 LOW

Cross-site scripting (XSS) vulnerability in the WebAdmin application 6.0.5, 6.0.8, and 7.0 before P2 in IBM Netezza allows remote authenticated users to inject arbitrary web script or HTML via vectors involving the MHTML protocol.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm netezza 6.0.5
ibm netezza 6.0.8
ibm netezza 7.0
CVE-2012-5763 MEDIUM

Cross-site request forgery (CSRF) vulnerability in the WebAdmin application 6.0.5, 6.0.8, and 7.0 before P2 in IBM Netezza allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm netezza 6.0.5
ibm netezza 6.0.8
ibm netezza 7.0
CVE-2012-5765 MEDIUM

The Web Client (aka CQ Web) in IBM Rational ClearQuest 7.1.2.x before 7.1.2.9 and 8.0.0.x before 8.0.0.5 allows remote attackers to obtain sensitive information via unspecified vectors that trigger a SQL error message.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_clearquest 7.1.2.1
ibm rational_clearquest 7.1.2.3
ibm rational_clearquest 8.0.0.2
ibm rational_clearquest 7.1.2
ibm rational_clearquest 8.0.0.4
ibm rational_clearquest 7.1.2.5
ibm rational_clearquest 7.1.2.6
ibm rational_clearquest 7.1.2.8
ibm rational_clearquest 7.1.2.2
ibm rational_clearquest 8.0.0.1
ibm rational_clearquest 8.0.0.3
ibm rational_clearquest 7.1.2.4
ibm rational_clearquest 8.0.0
ibm rational_clearquest 7.1.2.7
CVE-2012-5766 MEDIUM

Multiple SQL injection vulnerabilities in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to execute arbitrary SQL commands via vectors involving the RNVisibility page and unspecified screens, a different vulnerability than CVE-2013-0560.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2
ibm sterling_b2b_integrator 5.1
ibm sterling_file_gateway 2.2
ibm sterling_file_gateway 2.1
CVE-2012-5767 MEDIUM

Unspecified vulnerability in the web interface on the IBM TS3500 Tape Library with firmware before C260 allows remote authenticated users to gain privileges via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm ts3500_tape_library_firmware *
ibm ts3500_tape_library 3584
CVE-2012-5769 MEDIUM

IBM SPSS Modeler 14.0, 14.1, 14.2 through FP3, and 15.0 before FP2 allows remote attackers to read arbitrary files, and possibly send HTTP requests to intranet servers or cause a denial of service (CPU and memory consumption), via an XML external entity declaration in conjunction with an entity reference.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm spss_modeler 14.1.0.0
ibm spss_modeler 14.0.0.0
ibm spss_modeler 14.2.0.1
ibm spss_modeler 14.0.0.1
ibm spss_modeler 14.2.0.3
ibm spss_modeler 14.2.0.0
ibm spss_modeler 15.0.0.0
ibm spss_modeler 15.0.0.1
ibm spss_modeler 14.2.0.2
ibm spss_modeler 14.0.0.2
ibm spss_modeler 14.1.0.1
ibm spss_modeler 14.1.0.2
CVE-2012-5770 MEDIUM

The SSL configuration in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.x before 7.2.1.4 supports the MD5 hash algorithm, which makes it easier for man-in-the-middle attackers to spoof servers and decrypt network traffic via a brute-force attack.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-16,

Products Affected

Vendor Product Version
ibm tivoli_application_dependency_discovery_manager 7.2.0.0
ibm tivoli_application_dependency_discovery_manager 7.2.1.3
ibm tivoli_application_dependency_discovery_manager 7.2.1
CVE-2012-5936 MEDIUM

IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 do not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2
ibm sterling_b2b_integrator 5.1
ibm sterling_file_gateway 2.2
ibm sterling_file_gateway 2.1
CVE-2012-5937 HIGH

Unspecified vulnerability in the CLA2 server in IBM Gentran Integration Suite 4.3, Sterling Integrator 5.0 and 5.1, and Sterling B2B Integrator 5.2, as used in IBM Sterling File Gateway 1.1 through 2.2 and other products, allows remote attackers to execute arbitrary commands via unknown vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm sterling_integrator 5.0
ibm sterling_b2b_integrator 5.2
ibm sterling_integrator 5.1
ibm sterling_file_gateway 1.1
ibm gentran_integration_suite 4.3
ibm sterling_file_gateway 2.2
ibm sterling_file_gateway 2.1
ibm sterling_file_gateway 2.0
CVE-2012-5938 HIGH

The installation process in IBM InfoSphere Information Server 8.1, 8.5, 8.7, and 9.1 on UNIX and Linux sets incorrect permissions and ownerships for unspecified files, which allows local users to bypass intended access restrictions via standard filesystem operations.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm infosphere_information_server 8.1
ibm infosphere_information_server 8.5
ibm infosphere_information_server 9.1
ibm infosphere_information_server 8.7
CVE-2012-5939 LOW

Cross-site scripting (XSS) vulnerability in Welcome.do in the Data Management Portal Web User Interface in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.x before 7.2.1.4 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_application_dependency_discovery_manager 7.2.0.0
ibm tivoli_application_dependency_discovery_manager 7.2.1.3
ibm tivoli_application_dependency_discovery_manager 7.2.1
CVE-2012-5940 MEDIUM

The WebAdmin application 6.0.5, 6.0.8, and 7.0 before P2 in IBM Netezza, when SSL is not enabled, allows remote attackers to discover credentials by sniffing the network during the authentication process.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm netezza 6.0.5
ibm netezza 6.0.8
ibm netezza 7.0
CVE-2012-5941 LOW

Cross-site scripting (XSS) vulnerability in the WebAdmin application 6.0.5, 6.0.8, and 7.0 before P2 in IBM Netezza allows remote authenticated users to inject content, and conduct phishing attacks, via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm netezza 6.0.5
ibm netezza 6.0.8
ibm netezza 7.0
CVE-2012-5942 LOW

Cross-site scripting (XSS) vulnerability in the Data Management Portal Web User Interface in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.x before 7.2.1.4 allows remote authenticated users to inject content, and conduct phishing attacks, via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_application_dependency_discovery_manager 7.2.0.0
ibm tivoli_application_dependency_discovery_manager 7.2.1.3
ibm tivoli_application_dependency_discovery_manager 7.2.1
CVE-2012-5943 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM iNotes 8.5.x before 8.5.3 FP4 allows user-assisted remote attackers to inject arbitrary web script or HTML via vectors involving mail, aka SPR JDOE8ZZS9.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm lotus_inotes 8.5.1.3
ibm lotus_inotes 8.5.1.0
ibm lotus_inotes 8.5.3.0
ibm lotus_inotes 8.5.2.2
ibm lotus_inotes 8.5.0.0
ibm lotus_inotes 8.5.1.5
ibm lotus_inotes 8.5.2.3
ibm lotus_inotes 8.5.2.1
ibm lotus_inotes 8.5.1.1
ibm lotus_inotes 8.5.2.0
ibm lotus_inotes 8.5.3.1
ibm lotus_inotes 8.5.1.4
ibm lotus_inotes 8.5.1.2
ibm lotus_inotes 8.5.0.1
ibm lotus_inotes 8.5.3.2
CVE-2012-5945 HIGH

Multiple buffer overflows in the Vsflex8l ActiveX control in IBM SPSS SamplePower 3.0 before FP1 allow remote attackers to execute arbitrary code via a long (1) ComboList or (2) ColComboList property value.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm spss_samplepower 3.0.0.0
CVE-2012-5946 HIGH

Buffer overflow in the c1sizer ActiveX control in C1sizer.ocx in IBM SPSS SamplePower 3.0 before FP1 allows remote attackers to execute arbitrary code via a long TabCaption string.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm spss_samplepower 3.0.0.0
CVE-2012-5947 HIGH

Buffer overflow in the vsflex7l ActiveX control in IBM SPSS SamplePower 3.0 before FP1 allows remote attackers to execute arbitrary code via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm spss_samplepower 3.0.0.0
CVE-2012-5948 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in IBM TRIRIGA Application Platform 2.x and 3.x before 3.3, and 8, allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) WebProcess.srv, (2) the html/en/default/ directory, (3) Widget/resource, (4) birt/frameset, or (5) ganttlib/gantt-jws.jnlp.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tririga_application_platform 2.6
ibm tririga_application_platform 2.5
ibm tririga_application_platform 3.2
ibm tririga_application_platform 8.0
ibm tririga_application_platform 2.7
ibm tririga_application_platform 3.0
ibm tririga_application_platform 3.1
ibm tririga_application_platform 2.1
ibm tririga_application_platform 3.2.1
CVE-2012-5949 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in IBM TRIRIGA Application Platform 2.x and 3.x before 3.3, and 8, allow remote attackers to inject content, and conduct phishing attacks, via vectors involving (1) the html/en/default/ directory, (2) birt/frameset, (3) WebProcess.srv, (4) sqa/html/en/default/reportTemplate/reportTemplateOrderCols.jsp, or (5) a/html/en/default/om2/omObjectFinder.jsp.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tririga_application_platform 2.6
ibm tririga_application_platform 2.5
ibm tririga_application_platform 3.2
ibm tririga_application_platform 8.0
ibm tririga_application_platform 2.7
ibm tririga_application_platform 3.0
ibm tririga_application_platform 3.1
ibm tririga_application_platform 2.1
ibm tririga_application_platform 3.2.1
CVE-2012-5950 MEDIUM

Multiple cross-site request forgery (CSRF) vulnerabilities in IBM TRIRIGA Application Platform 2.x and 3.x before 3.3, and 8, allow remote attackers to hijack the authentication of arbitrary users for requests that modify data records via vectors involving (1) the html/en/default/ directory or (2) sqa/html/en/default/process/comm/saveProps.jsp.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm tririga_application_platform 2.6
ibm tririga_application_platform 2.5
ibm tririga_application_platform 3.2
ibm tririga_application_platform 8.0
ibm tririga_application_platform 2.7
ibm tririga_application_platform 3.0
ibm tririga_application_platform 3.1
ibm tririga_application_platform 2.1
ibm tririga_application_platform 3.2.1
CVE-2012-5951 HIGH

Unspecified vulnerability in IBM Tivoli NetView 1.4, 5.1 through 5.4, and 6.1 on z/OS allows local users to gain privileges by leveraging access to the normal Unix System Services (USS) security level.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm tivoli_netview 5.3
ibm tivoli_netview 6.1
ibm tivoli_netview 5.1
ibm tivoli_netview 5.4
ibm tivoli_netview 1.4
ibm tivoli_netview 5.2
CVE-2012-5952 MEDIUM

IBM WebSphere Message Broker 6.1 before 6.1.0.12, 7.0 before 7.0.0.6, and 8.0 before 8.0.0.2 does not validate Basic Authentication credentials before proceeding to WS-Addressing and WS-Security operations, which allows remote attackers to trigger transmission of unauthenticated messages via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm websphere_message_broker 6.1.0.3
ibm websphere_message_broker 7.0.0.1
ibm websphere_message_broker 6.1.0.5
ibm websphere_message_broker 6.1.0.10
ibm websphere_message_broker 7.0.0.2
ibm websphere_message_broker 8.0
ibm websphere_message_broker 7.0.0.5
ibm websphere_message_broker 6.1.0.6
ibm websphere_message_broker 7.0.0.4
ibm websphere_message_broker 6.1.0.4
ibm websphere_message_broker 6.1.0.9
ibm websphere_message_broker 6.1.0.2
ibm websphere_message_broker 7.0.0.3
ibm websphere_message_broker 6.1
ibm websphere_message_broker 6.1.0.8
ibm websphere_message_broker 7.0.
ibm websphere_message_broker 8.0.0.1
ibm websphere_message_broker 6.1.0.7
ibm websphere_message_broker 6.1.0.11
ibm websphere_message_broker 6.1.0.1
CVE-2012-5953 MEDIUM

IBM WebSphere Message Broker 6.1 before 6.1.0.12, 7.0 before 7.0.0.6, and 8.0 before 8.0.0.2, when the Parse Query Strings option is enabled on an HTTPInput node, allows remote attackers to cause a denial of service (infinite loop) via a crafted query string.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm websphere_message_broker 6.1.0.3
ibm websphere_message_broker 7.0.0.1
ibm websphere_message_broker 6.1.0.5
ibm websphere_message_broker 6.1.0.10
ibm websphere_message_broker 7.0.0.2
ibm websphere_message_broker 8.0
ibm websphere_message_broker 7.0.0.5
ibm websphere_message_broker 6.1.0.6
ibm websphere_message_broker 7.0.0.4
ibm websphere_message_broker 6.1.0.4
ibm websphere_message_broker 6.1.0.9
ibm websphere_message_broker 6.1.0.2
ibm websphere_message_broker 7.0.0.3
ibm websphere_message_broker 6.1
ibm websphere_message_broker 6.1.0.8
ibm websphere_message_broker 7.0.
ibm websphere_message_broker 8.0.0.1
ibm websphere_message_broker 6.1.0.7
ibm websphere_message_broker 6.1.0.11
ibm websphere_message_broker 6.1.0.1
CVE-2012-5954 MEDIUM

Unspecified vulnerability in IBM Tivoli Storage Manager for Space Management (aka TSM HSM) before 6.2.5.0 and 6.3.x before 6.3.1.0 allows remote attackers to read or modify HSM-managed file system objects via unknown vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_for_space_management 6.1.0.0
ibm tivoli_storage_manager_for_space_management 6.3.0.0
ibm tivoli_storage_manager_for_space_management 5.5.0.0
ibm tivoli_storage_manager_for_space_management 6.3.0.17
ibm tivoli_storage_manager_for_space_management 6.2.0.0
ibm tivoli_storage_manager_for_space_management *
CVE-2012-5955 HIGH

Unspecified vulnerability in the IBM HTTP Server component 5.3 in IBM WebSphere Application Server (WAS) for z/OS allows remote attackers to execute arbitrary commands via unknown vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_application_server -
ibm http_server 5.3
CVE-2012-6349 HIGH

Buffer overflow in the .mdb parser in Autonomy KeyView IDOL, as used in IBM Notes 8.5.x before 8.5.3 FP4, allows remote attackers to execute arbitrary code via a crafted file, aka SPR KLYH92XL3W.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
autonomy keyview_idol -
ibm lotus_notes 8.5.1.5
ibm lotus_notes 8.5.1.1
ibm lotus_notes 8.5.2.0
ibm lotus_notes 8.5.2.2
ibm lotus_notes 8.5.1.4
ibm lotus_notes 8.5.1
ibm lotus_notes 8.5.1.2
ibm lotus_notes 8.5.3.2
ibm lotus_notes 8.5.1.3
ibm lotus_notes 8.5.2.1
ibm lotus_notes 8.5.0.0
ibm lotus_notes 8.5.2.3
ibm lotus_notes 8.5.0.1
ibm lotus_notes 8.5.3.3
ibm lotus_notes 8.5.1.0
ibm lotus_notes 8.5.3.1
ibm lotus_notes 8.5
ibm lotus_notes 8.5.3
CVE-2012-6350 MEDIUM

Cross-site scripting (XSS) vulnerability in the Web component in IBM Cognos TM1 before 9.5.2 FP3 and 10.1 before 10.1 FP1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm cognos_tm1 9.4.1.3
ibm cognos_tm1 10.1.0
ibm cognos_tm1 *
ibm cognos_tm1 9.4.1
ibm cognos_tm1 9.5.1
ibm cognos_tm1 9.5.0
CVE-2012-6352 MEDIUM

The Session Manager in IBM Sterling Connect:Direct through 4.1.0.3 on UNIX allows remote attackers to cause a denial of service (daemon crash and disk consumption) via crafted data.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm sterling_connect 4.1.0.0
ibm sterling_connect 4.1.0.3
ibm sterling_connect 4.1.0.2
ibm sterling_connect 4.1.0.1
CVE-2012-6354 HIGH

The management GUI on the IBM SAN Volume Controller and Storwize V7000 6.x before 6.4.1.3 allows remote attackers to bypass authentication and obtain superuser access via IP packets.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm san_volume_controller_software 6.2.0.0
ibm san_volume_controller_software 6.1.0.0
ibm san_volume_controller_software 6.3.0.0
ibm san_volume_controller_software 6.4.0.0
ibm storwize_v7000 -
CVE-2012-6355 MEDIUM

IBM Maximo Asset Management 6.2 through 7.5, Maximo Asset Management Essentials 6.2 through 7.5, Tivoli Asset Management for IT 6.2 through 7.2, Tivoli Service Request Manager 7.1 and 7.2, Maximo Service Desk 6.2, Change and Configuration Management Database (CCMDB) 7.1 and 7.2, and SmartCloud Control Desk 7.5 allow remote authenticated users to gain privileges via vectors related to a work order.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm tivoli_asset_management_for_it 7.2
ibm tivoli_asset_management_for_it 6.0
ibm maximo_asset_management 7.1.1.9
ibm tivoli_service_request_manager 7.2.0.0
ibm maximo_asset_management 6.2.6
ibm maximo_asset_management 6.2.7
ibm maximo_asset_management 6.2.6.1
ibm maximo_asset_management 7.1.1.10
ibm maximo_asset_management 6.2.3
ibm maximo_asset_management 6.2.5
ibm maximo_asset_management 7.1.1.1
ibm tivoli_asset_management_for_it 7.0
ibm smartcloud_control_desk 7.5.0.0
ibm maximo_asset_management_essentials 7.5.0.0
ibm maximo_service_desk 6.2
ibm maximo_asset_management 6.2.8
ibm maximo_asset_management_essentials 6.2.0.0
ibm tivoli_service_request_manager 7.1.0
ibm maximo_asset_management 6.2.4
ibm tivoli_service_request_manager 7.1.0.0
ibm tivoli_asset_management_for_it 6.2
ibm maximo_asset_management 6.2.1
ibm change_and_configuration_management_database 7.2.0
ibm tivoli_asset_management_for_it 7.1
ibm maximo_asset_management 7.5.0.0
ibm maximo_asset_management 7.1.1.7
ibm maximo_asset_management 6.2
ibm maximo_asset_management 6.2.2
ibm change_and_configuration_management_database 7.1.
ibm maximo_asset_management 7.1.1.2
ibm maximo_asset_management 7.1.1.6
ibm maximo_asset_management 7.1.1.5
ibm maximo_asset_management 7.1.1.11
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
CVE-2012-6356 MEDIUM

IBM Maximo Asset Management 7.5, Maximo Asset Management Essentials 7.5, and SmartCloud Control Desk 7.5 allow remote authenticated users to gain privileges via vectors related to an import operation.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm smartcloud_control_desk 7.5.0.0
ibm maximo_asset_management_essentials 7.5.0.0
ibm maximo_asset_management 7.5.0.0
CVE-2012-6357 MEDIUM

IBM Maximo Asset Management 7.5, Maximo Asset Management Essentials 7.5, and SmartCloud Control Desk 7.5 allow remote authenticated users to gain privileges and bypass intended restrictions on asset-lookup operations via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm smartcloud_control_desk 7.5.0.0
ibm maximo_asset_management_essentials 7.5.0.0
ibm maximo_asset_management 7.5.0.0
CVE-2012-6359 MEDIUM

IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.11, 6.2.1 before 6.2.1.3, and 6.2.2 before 6.2.2.2 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.2.0 before 6.2.0.11, 6.2.1 before 6.2.1.3, and 6.2.2 before 6.2.2.2 do not check whether an OpenID attribute is signed in the (1) SREG (aka simple registration extension) and (2) AX (aka attribute exchange extension) cases, which allows man-in-the-middle attackers to spoof OpenID provider data by inserting unsigned attributes.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm tivoli_federated_identity_manager 6.2.0.3
ibm tivoli_federated_identity_manager_business_gateway 6.2.0.1
ibm tivoli_federated_identity_manager 6.2.1.1
ibm tivoli_federated_identity_manager_business_gateway 6.2.0.3
ibm tivoli_federated_identity_manager 6.2.1
ibm tivoli_federated_identity_manager_business_gateway 6.2.0.9
ibm tivoli_federated_identity_manager_business_gateway 6.2.1
ibm tivoli_federated_identity_manager 6.2.0
ibm tivoli_federated_identity_manager 6.2.0.1
ibm tivoli_federated_identity_manager 6.2.0.9
ibm tivoli_federated_identity_manager_business_gateway 6.2.0.10
ibm tivoli_federated_identity_manager_business_gateway 6.2.2
ibm tivoli_federated_identity_manager_business_gateway 6.2.0.8
ibm tivoli_federated_identity_manager_business_gateway 6.2.0.2
ibm tivoli_federated_identity_manager 6.2.0.8
ibm tivoli_federated_identity_manager 6.2.0.2
ibm tivoli_federated_identity_manager 6.2.2
ibm tivoli_federated_identity_manager_business_gateway 6.2.0
ibm tivoli_federated_identity_manager 6.2.0.10
ibm tivoli_federated_identity_manager 6.2.1.2
CVE-2012-6360 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Intelligent Operations Center 1.5.0 allows remote attackers to inject arbitrary web script or HTML via event data fields.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm intelligent_operations_center 1.5.0
CVE-2013-0127 MEDIUM

IBM Lotus Notes 8.x before 8.5.3 FP4 Interim Fix 1 and 9.0 before Interim Fix 1 does not block APPLET elements in HTML e-mail, which allows remote attackers to bypass intended restrictions on Java code execution and X-Confirm-Reading-To functionality via a crafted message, aka SPRs JMOY95BLM6 and JMOY95BN49.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm lotus_notes 8.0.2.1
ibm lotus_notes 8.5.1.5
ibm lotus_notes 8.5.2.0
ibm lotus_notes 8.0.0
ibm lotus_notes 8.0.2.3
ibm lotus_notes 8.5.1.4
ibm lotus_notes 8.5.3.2
ibm lotus_notes 8.5.2.1
ibm lotus_notes 8.0.1
ibm lotus_notes 8.0.2.2
ibm lotus_notes 8.0.2.4
ibm lotus_notes 8.5.0.1
ibm lotus_notes 8.0
ibm lotus_notes 8.0.2.0
ibm lotus_notes 8.5.3
ibm lotus_notes 8.0.2.5
ibm lotus_notes 8.5.1.1
ibm lotus_notes 8.5.2.2
ibm lotus_notes 9.0.0.0
ibm lotus_notes 8.5.1
ibm lotus_notes 8.5.1.2
ibm lotus_notes 8.5.1.3
ibm lotus_notes 8.5.0.0
ibm lotus_notes 8.5.2.3
ibm lotus_notes 8.5.3.3
ibm lotus_notes 8.5.1.0
ibm lotus_notes 8.0.2.6
ibm lotus_notes 8.5.3.1
ibm lotus_notes 8.5
ibm lotus_notes 8.0.2
CVE-2013-0451 MEDIUM

SQL injection vulnerability in IBM Maximo Asset Management 6.2 through 6.2.8 and 7.1 through 7.1.1.12 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm maximo_asset_management 6.2.1
ibm maximo_asset_management 7.1.1.9
ibm maximo_asset_management 7.1
ibm maximo_asset_management 6.2.6
ibm maximo_asset_management 6.2.7
ibm maximo_asset_management 6.2.6.1
ibm maximo_asset_management 7.1.1.10
ibm maximo_asset_management 6.2.3
ibm maximo_asset_management 6.2.5
ibm maximo_asset_management 7.1.1.1
ibm maximo_asset_management 7.1.1.7
ibm maximo_asset_management 6.2
ibm maximo_asset_management 6.2.2
ibm maximo_asset_management 6.2.8
ibm maximo_asset_management 7.1.1.2
ibm maximo_asset_management 7.1.1.12
ibm maximo_asset_management 7.1.1.6
ibm maximo_asset_management 7.1.1.5
ibm maximo_asset_management 7.1.1.11
ibm maximo_asset_management 6.2.4
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
CVE-2013-0452 MEDIUM

Cross-site request forgery (CSRF) vulnerability in the Software Use Analysis (SUA) application before 1.3.3 in IBM Tivoli Endpoint Manager 8.2 allows remote attackers to hijack the authentication of arbitrary users via a web site that contains crafted Flash Action Message Format (AMF) messages.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm tivoli_endpoint_manager 8.2
ibm software_use_analysis *
CVE-2013-0453 LOW

Cross-site scripting (XSS) vulnerability in Web Reports in IBM Tivoli Endpoint Manager (TEM) before 8.2.1372 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_endpoint_manager 8.0
ibm tivoli_endpoint_manager 8.1
ibm tivoli_endpoint_manager *
CVE-2013-0454 MEDIUM

The SMB2 implementation in Samba 3.6.x before 3.6.6, as used on the IBM Storwize V7000 Unified 1.3 before 1.3.2.3 and 1.4 before 1.4.0.1 and possibly other products, does not properly enforce CIFS share attributes, which allows remote authenticated users to (1) write to a read-only share; (2) trigger data-integrity problems related to the oplock, locking, coherency, or leases attribute; or (3) have an unspecified impact by leveraging incorrect handling of the browseable or "hide unreadable" parameter.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
samba samba 3.6.0
samba samba 3.6.4
ibm storwize v7000
samba samba 3.6.1
samba samba 3.6.3
canonical ubuntu_linux 12.04
samba samba *
samba samba 3.6.2
CVE-2013-0455 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in IBM Sterling B2B Integrator 5.2.4 and Sterling File Gateway allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm sterling_file_gateway -
ibm sterling_b2b_integrator 5.2.4
CVE-2013-0456 MEDIUM

IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to hijack sessions via a modified cookie path.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2
ibm sterling_b2b_integrator 5.1
ibm sterling_file_gateway 2.2
ibm sterling_file_gateway 2.1
CVE-2013-0457 LOW

Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5, Maximo Asset Management Essentials 7.5, and SmartCloud Control Desk 7.5 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to a uisessionid.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm smartcloud_control_desk 7.5.0.0
ibm maximo_asset_management_essentials 7.5.0.0
ibm maximo_asset_management 7.5.0.0
CVE-2013-0458 MEDIUM

Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.27, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2, when login security is disabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 7.0
ibm websphere_application_server 6.1.0.14
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0.35
ibm websphere_application_server 7.0.0.25
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.0.39
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 6.1.0.37
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 8.0.0.2
ibm websphere_application_server 8.0.0.5
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 6.1.0.45
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.41
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 6.1.0.43
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 8.5.0.1
CVE-2013-0459 MEDIUM

Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.27, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 7.0
ibm websphere_application_server 6.1.0.14
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0.35
ibm websphere_application_server 7.0.0.25
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.0.39
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 6.1.0.37
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 8.0.0.2
ibm websphere_application_server 8.0.0.5
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 6.1.0.45
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.41
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 6.1.0.43
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 8.5.0.1
CVE-2013-0460 MEDIUM

Cross-site request forgery (CSRF) vulnerability in the portlet subsystem in the administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47 and 7.0 before 7.0.0.27 allows remote attackers to hijack the authentication of arbitrary users for requests that insert cross-site scripting (XSS) sequences.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 7.0
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 6.1.0.14
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 6.1.0.45
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0.35
ibm websphere_application_server 7.0.0.25
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.41
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 6.1.0.43
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.0.39
ibm websphere_application_server 6.1.0.37
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 7.0.0.15
CVE-2013-0461 MEDIUM

Cross-site scripting (XSS) vulnerability in the virtual member manager (VMM) administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.27, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 7.0
ibm websphere_application_server 6.1.0.14
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0.35
ibm websphere_application_server 7.0.0.25
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.0.39
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 6.1.0.37
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 8.0.0.2
ibm websphere_application_server 8.0.0.5
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 6.1.0.45
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.41
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 6.1.0.43
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 8.5.0.1
CVE-2013-0462 HIGH

Unspecified vulnerability in IBM WebSphere Application Server (WAS) 6.1, 7.0 before 7.0.0.27, 8.0, and 8.5 has unknown impact and attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 7.0.0.25
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 7.0.0.13
CVE-2013-0463 MEDIUM

IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to obtain sensitive information about application implementation via unspecified vectors, a different vulnerability than CVE-2013-2985, CVE-2013-2987, CVE-2013-3020, CVE-2013-0568, CVE-2013-0475, and CVE-2013-0567.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2
ibm sterling_b2b_integrator 5.1
ibm sterling_file_gateway 2.2
ibm sterling_file_gateway 2.1
CVE-2013-0464 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in IBM Eclipse Help System (IEHS) 3.4.3 and 3.6.2, as used in IBM SPSS Data Collection 6.0, 6.0.1, and 7.0, allow remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm eclipse_help_system 3.6.2
ibm spss_data_collection 6.0
ibm spss_data_collection 6.0.1
ibm spss_data_collection 7.0
ibm eclipse_help_system 3.4.3
CVE-2013-0465 MEDIUM

Unspecified vulnerability in the IBM WebSphere Cast Iron physical and virtual appliance 6.0 and 6.1 before 6.1.0.15 and 6.3 before 6.3.0.1, when LDAP authentication is enabled, allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unknown vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm webshere_cast_iron_cloud_integration 6.1.0.3
ibm webshere_cast_iron_cloud_integration 6.1.0.0
ibm webshere_cast_iron_cloud_integration 6.1.0.9
ibm webshere_cast_iron_cloud_integration 6.1.0.6
ibm webshere_cast_iron_cloud_integration 6.1.0.1
ibm webshere_cast_iron_cloud_integration 6.0.0.0
ibm webshere_cast_iron_cloud_integration 6.3.0.0
ibm webshere_cast_iron_cloud_integration 6.1.0.2
ibm webshere_cast_iron_cloud_integration 6.1.0.12
CVE-2013-0466 LOW

Cross-site scripting (XSS) vulnerability in IBM WebSphere Message Broker 7.0 before 7.0.0.6 and 8.0 before 8.0.0.2, when wsdl support is enabled on a SOAPInput node, allows remote attackers to inject arbitrary web script or HTML via a wsdl request that is not properly handled during construction of an error message.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_message_broker 7.0.0.1
ibm websphere_message_broker 7.0.0.2
ibm websphere_message_broker 8.0
ibm websphere_message_broker 7.0.0.5
ibm websphere_message_broker 7.0.0.3
ibm websphere_message_broker 7.0.
ibm websphere_message_broker 7.0.0.4
ibm websphere_message_broker 8.0.0.1
CVE-2013-0467 MEDIUM

IBM Eclipse Help System (IEHS), as used in IBM Data Studio 3.1 and 3.1.1 and other products, allows remote authenticated users to read source code via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm data_studio 3.1.1
ibm data_studio 3.1.0
CVE-2013-0468 LOW

Cross-site scripting (XSS) vulnerability in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2013-2983.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2
ibm sterling_b2b_integrator 5.1
ibm sterling_file_gateway 2.2
ibm sterling_file_gateway 2.1
CVE-2013-0470 MEDIUM

HTTPD in IBM Netezza Performance Portal 1.0.2 allows remote authenticated users to list application directories containing asset files via a direct request to a directory URI, as demonstrated by listing image files.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-16,

Products Affected

Vendor Product Version
ibm netezza_performance_portal 1.0.2
CVE-2013-0471 MEDIUM

The traditional scheduler in the client in IBM Tivoli Storage Manager (TSM) before 6.2.5.0, 6.3 before 6.3.1.0, and 6.4 before 6.4.0.1, when Prompted mode is enabled, allows remote attackers to cause a denial of service (scheduling outage) via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager 5.3.6.4
ibm tivoli_storage_manager 5.2
ibm tivoli_storage_manager 5.4.3.2
ibm tivoli_storage_manager 5.1.6
ibm tivoli_storage_manager 5.1.8
ibm tivoli_storage_manager 5.3.1
ibm tivoli_storage_manager 6.1.1
ibm tivoli_storage_manager 4.2
ibm tivoli_storage_manager 5.2.5.3
ibm tivoli_storage_manager 5.1.0
ibm tivoli_storage_manager *
ibm tivoli_storage_manager 5.4.3.3
ibm tivoli_storage_manager 4.2.2
ibm tivoli_storage_manager 5.2.5.1
ibm tivoli_storage_manager 6.0
ibm tivoli_storage_manager 5.3.2
ibm tivoli_storage_manager 5.5.1
ibm tivoli_storage_manager 5.3.5.1
ibm tivoli_storage_manager 5.2.1
ibm tivoli_storage_manager 3.1.0
ibm tivoli_storage_manager 6.3.0.0
ibm tivoli_storage_manager 6.4.0.0
ibm tivoli_storage_manager 4.2.1
ibm tivoli_storage_manager 5.1.7
ibm tivoli_storage_manager 5.4.2.3
ibm tivoli_storage_manager 5.5.0
ibm tivoli_storage_manager 6.1.3
ibm tivoli_storage_manager 5.4.3.0
ibm tivoli_storage_manager 5.2.2
ibm tivoli_storage_manager 5.3.6.5
ibm tivoli_storage_manager 5.3.2.4
ibm tivoli_storage_manager 5.1.9
ibm tivoli_storage_manager 6.2.1
ibm tivoli_storage_manager 6.1.0
ibm tivoli_storage_manager 5.4.2
ibm tivoli_storage_manager 5.3
ibm tivoli_storage_manager 5.4.1
ibm tivoli_storage_manager 5.1.5
ibm tivoli_storage_manager 5.4.4.0
ibm tivoli_storage_manager 5.3.4
ibm tivoli_storage_manager 5.3.6.6
ibm tivoli_storage_manager 5.2.5.2
ibm tivoli_storage_manager 6.1.2
ibm tivoli_storage_manager 5.2.0
ibm tivoli_storage_manager 5.3.6.3
ibm tivoli_storage_manager 5.1.1
ibm tivoli_storage_manager 5.2.8
ibm tivoli_storage_manager 6.2.0.0
ibm tivoli_storage_manager 5.3.0
ibm tivoli_storage_manager 5.4.2.2
ibm tivoli_storage_manager 5.2.9
ibm tivoli_storage_manager 5.3.6.1
ibm tivoli_storage_manager 5.4
ibm tivoli_storage_manager 5.3.6.2
ibm tivoli_storage_manager 5.2.4
ibm tivoli_storage_manager 4.2.3
ibm tivoli_storage_manager 6.2.0
ibm tivoli_storage_manager 4.2.4
ibm tivoli_storage_manager 5.1.10
ibm tivoli_storage_manager 5.3.3
ibm tivoli_storage_manager 3.2.1
ibm tivoli_storage_manager 5.4.0
ibm tivoli_storage_manager 5.4.2.4
ibm tivoli_storage_manager 5.5.2
ibm tivoli_storage_manager 5.2.7
CVE-2013-0472 MEDIUM

The Web GUI in the client in IBM Tivoli Storage Manager (TSM) 6.3 before 6.3.1.0 and 6.4 before 6.4.0.1 allows man-in-the-middle attackers to obtain unspecified client access, and consequently obtain unspecified server access, via unknown vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager 5.3.6.4
ibm tivoli_storage_manager 5.2
ibm tivoli_storage_manager 5.4.3.2
ibm tivoli_storage_manager 5.1.6
ibm tivoli_storage_manager 5.1.8
ibm tivoli_storage_manager 5.3.1
ibm tivoli_storage_manager 6.1.1
ibm tivoli_storage_manager 4.2
ibm tivoli_storage_manager 5.2.5.3
ibm tivoli_storage_manager 5.1.0
ibm tivoli_storage_manager *
ibm tivoli_storage_manager 5.4.3.3
ibm tivoli_storage_manager 4.2.2
ibm tivoli_storage_manager 5.2.5.1
ibm tivoli_storage_manager 6.0
ibm tivoli_storage_manager 5.3.2
ibm tivoli_storage_manager 5.5.1
ibm tivoli_storage_manager 5.3.5.1
ibm tivoli_storage_manager 5.2.1
ibm tivoli_storage_manager 3.1.0
ibm tivoli_storage_manager 6.3.0.0
ibm tivoli_storage_manager 6.4.0.0
ibm tivoli_storage_manager 4.2.1
ibm tivoli_storage_manager 5.1.7
ibm tivoli_storage_manager 5.4.2.3
ibm tivoli_storage_manager 5.5.0
ibm tivoli_storage_manager 6.1.3
ibm tivoli_storage_manager 5.4.3.0
ibm tivoli_storage_manager 5.2.2
ibm tivoli_storage_manager 5.3.6.5
ibm tivoli_storage_manager 5.3.2.4
ibm tivoli_storage_manager 5.1.9
ibm tivoli_storage_manager 6.2.1
ibm tivoli_storage_manager 6.1.0
ibm tivoli_storage_manager 5.4.2
ibm tivoli_storage_manager 5.3
ibm tivoli_storage_manager 5.4.1
ibm tivoli_storage_manager 5.1.5
ibm tivoli_storage_manager 5.4.4.0
ibm tivoli_storage_manager 5.3.4
ibm tivoli_storage_manager 5.3.6.6
ibm tivoli_storage_manager 5.2.5.2
ibm tivoli_storage_manager 6.1.2
ibm tivoli_storage_manager 5.2.0
ibm tivoli_storage_manager 5.3.6.3
ibm tivoli_storage_manager 5.1.1
ibm tivoli_storage_manager 5.2.8
ibm tivoli_storage_manager 6.2.0.0
ibm tivoli_storage_manager 5.3.0
ibm tivoli_storage_manager 5.4.2.2
ibm tivoli_storage_manager 5.2.9
ibm tivoli_storage_manager 5.3.6.1
ibm tivoli_storage_manager 5.4
ibm tivoli_storage_manager 5.3.6.2
ibm tivoli_storage_manager 5.2.4
ibm tivoli_storage_manager 4.2.3
ibm tivoli_storage_manager 6.2.0
ibm tivoli_storage_manager 4.2.4
ibm tivoli_storage_manager 5.1.10
ibm tivoli_storage_manager 5.3.3
ibm tivoli_storage_manager 3.2.1
ibm tivoli_storage_manager 5.4.0
ibm tivoli_storage_manager 5.4.2.4
ibm tivoli_storage_manager 5.5.2
ibm tivoli_storage_manager 5.2.7
CVE-2013-0473 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in IBM Security AppScan Enterprise 5.6 and 8.x before 8.7 and IBM Rational Policy Tester 5.6 and 8.x before 8.5.0.4 allow remote attackers to inject arbitrary web script or HTML via a crafted report.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm security_appscan 8.0.0.1
ibm rational_policy_tester 8.0.1.0
ibm rational_policy_tester 8.5.0.0
ibm rational_policy_tester 8.0.0.0
ibm security_appscan 8.0.11
ibm security_appscan 8.6.0.2
ibm security_appscan 5.6.0.0
ibm security_appscan 8.6.0.1
ibm rational_policy_tester 8.0.1.1
ibm rational_policy_tester 5.6.0.0
ibm security_appscan 8.6.0.0
ibm rational_policy_tester 8.5.0.1
ibm rational_policy_tester 8.5.0.2
ibm security_appscan 8.0.1.0
ibm security_appscan 8.0.1.1
ibm security_appscan 8.5.0.1
ibm rational_policy_tester 8.0.0.1
ibm security_appscan 8.0.0.2
ibm security_appscan 8.0.0.0
ibm rational_policy_tester 8.0.0.2
ibm security_appscan 8.5.0.0
ibm rational_policy_tester 8.5.0.3
CVE-2013-0474 MEDIUM

The Manual Explore browser plug-in in IBM Security AppScan Enterprise 5.6 and 8.x before 8.7 and IBM Rational Policy Tester 5.6 and 8.x before 8.5.0.4 allows remote attackers to discover test Platform Authentication credentials via a crafted web site.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_appscan 8.0.0.1
ibm rational_policy_tester 8.0.1.0
ibm rational_policy_tester 8.5.0.0
ibm rational_policy_tester 8.0.0.0
ibm security_appscan 8.0.11
ibm security_appscan 8.6.0.2
ibm security_appscan 5.6.0.0
ibm security_appscan 8.6.0.1
ibm rational_policy_tester 8.0.1.1
ibm rational_policy_tester 5.6.0.0
ibm security_appscan 8.6.0.0
ibm rational_policy_tester 8.5.0.1
ibm rational_policy_tester 8.5.0.2
ibm security_appscan 8.0.1.0
ibm security_appscan 8.0.1.1
ibm security_appscan 8.5.0.1
ibm rational_policy_tester 8.0.0.1
ibm security_appscan 8.0.0.2
ibm security_appscan 8.0.0.0
ibm rational_policy_tester 8.0.0.2
ibm security_appscan 8.5.0.0
ibm rational_policy_tester 8.5.0.3
CVE-2013-0475 MEDIUM

IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to obtain sensitive information about application implementation via unspecified vectors, a different vulnerability than CVE-2013-0463, CVE-2013-2985, CVE-2013-2987, CVE-2013-3020, CVE-2013-0568, and CVE-2013-0567.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2
ibm sterling_b2b_integrator 5.1
ibm sterling_file_gateway 2.2
ibm sterling_file_gateway 2.1
CVE-2013-0476 MEDIUM

IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote attackers to inject arbitrary FTP commands via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2
ibm sterling_b2b_integrator 5.1
ibm sterling_file_gateway 2.2
ibm sterling_file_gateway 2.1
CVE-2013-0477 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in IBM InfoSphere Master Data Management - Collaborative Edition 10.0 and 10.1 before FP1 and InfoSphere Master Data Management Server for Product Information Management 6.0, 9.0, and 9.1 allow remote authenticated users to inject content, and conduct phishing attacks, via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm infosphere_master_data_management_server_for_product_information_management 9.0.0
ibm infosphere_master_data_management_collaboration_server 10.0.0
ibm infosphere_master_data_management_collaboration_server 10.0.1
ibm infosphere_master_data_management_server_for_product_information_management 9.1.0
ibm infosphere_master_data_management_server_for_product_information_management 6.0.0
CVE-2013-0478 LOW

Cross-site scripting (XSS) vulnerability in IBM InfoSphere Master Data Management - Collaborative Edition 10.0 and 10.1 before FP1 and InfoSphere Master Data Management Server for Product Information Management 6.0, 9.0, and 9.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm infosphere_master_data_management_server_for_product_information_management 9.0.0
ibm infosphere_master_data_management_collaboration_server 10.0.0
ibm infosphere_master_data_management_collaboration_server 10.0.1
ibm infosphere_master_data_management_server_for_product_information_management 9.1.0
ibm infosphere_master_data_management_server_for_product_information_management 6.0.0
CVE-2013-0479 MEDIUM

IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 do not properly restrict file types and extensions, which allows remote authenticated users to bypass intended access restrictions via a crafted filename.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2
ibm sterling_b2b_integrator 5.1
ibm sterling_file_gateway 2.2
ibm sterling_file_gateway 2.1
CVE-2013-0481 MEDIUM

The console in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allows remote attackers to read stack traces by triggering (1) an error or (2) an exception.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2
ibm sterling_b2b_integrator 5.1
ibm sterling_file_gateway 2.2
ibm sterling_file_gateway 2.1
CVE-2013-0482 MEDIUM

IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 through 8.5.0.2 and WebSphere Message Broker 6.1, 7.0 through 7.0.0.5, and 8.0 through 8.0.0.2, when WS-Security is used, allows remote attackers to spoof the signatures of messages via a crafted SOAP message, related to a "Signature Wrap attack," a different vulnerability than CVE-2011-1377 and CVE-2013-0489.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0.0.19
ibm websphere_message_broker 7.0.0.1
ibm websphere_application_server 7.0
ibm websphere_application_server 8.0.0.5
ibm websphere_message_broker 7.0.0.5
ibm websphere_application_server 7.0.0.12
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 7.0.0.16
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 7.0.0.25
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 7.0.0.14
ibm websphere_message_broker 7.0.0.3
ibm websphere_message_broker 6.1
ibm websphere_application_server 7.0.0.22
ibm websphere_application_server 7.0.0.10
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 7.0.0.3
ibm websphere_message_broker 7.0.0.2
ibm websphere_message_broker 8.0
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 7.0.0.24
ibm websphere_application_server 7.0.0.11
ibm websphere_message_broker 7.0.0.4
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 7.0.0.27
ibm websphere_message_broker 8.0.0.2
ibm websphere_application_server 7.0.0.18
ibm websphere_message_broker 7.0.
ibm websphere_message_broker 8.0.0.1
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 7.0.0.4
ibm websphere_application_server 8.0.0.2
CVE-2013-0483 MEDIUM

The login component in SOAP Gateway in IBM IMS Enterprise Suite 1.1, 2.1, and 2.2 uses cleartext credentials, which allows remote attackers to obtain sensitive information by sniffing the network.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm ims_enterprise_suite 2.2
ibm ims_enterprise_suite 1.1
ibm ims_enterprise_suite 2.1
CVE-2013-0484 MEDIUM

The server process in IBM Cognos TM1 10.1.x before 10.1.1 FP1 allows remote attackers to cause a denial of service (daemon crash) via an undocumented API call that triggers the transmission of unexpected data.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm cognos_tm1 10.1.0
ibm cognos_tm1 10.1.0.1
ibm cognos_tm1 10.1.1
CVE-2013-0485 HIGH

Unspecified vulnerability in IBM Java SDK 7 before SR4-FP1, 6 before SR13-FP1, 5.0 before SR16-FP1, and 1.4.2 before SR13-FP16 has unknown impact and attack vectors related to Class Libraries.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm java 7.0.0.0
ibm java 5.0.0.0
ibm java 1.4.2
ibm java 6.0.0.0
CVE-2013-0486 MEDIUM

Memory leak in the HTTP server in IBM Domino 8.5.x allows remote attackers to cause a denial of service (memory consumption and daemon crash) via GET requests, aka SPR KLYH92NKZY.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm lotus_domino 8.5.2.4
ibm lotus_domino 8.5.1.5
ibm lotus_domino 8.5.2.2
ibm lotus_domino 8.5.1.1
ibm lotus_domino 8.5.2.3
ibm lotus_domino 8.5.1.4
ibm lotus_domino 8.5.2.0
ibm lotus_domino 8.5.0.1
ibm lotus_domino 8.5.3.1
ibm lotus_domino 8.5.2.1
ibm lotus_domino 8.5.0
ibm lotus_domino 8.5.3.0
ibm lotus_domino 8.5.1
ibm lotus_domino 8.5.1.2
ibm lotus_domino 8.5.3.2
ibm lotus_domino 8.5.1.3
CVE-2013-0487 HIGH

The Java Console in IBM Domino 8.5.x allows remote authenticated users to hijack temporary credentials by leveraging knowledge of configuration details, aka SPR KLYH8TNNDN.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm lotus_domino 8.5.2.4
ibm lotus_domino 8.5.1.5
ibm lotus_domino 8.5.2.2
ibm lotus_domino 8.5.1.1
ibm lotus_domino 8.5.2.3
ibm lotus_domino 8.5.1.4
ibm lotus_domino 8.5.2.0
ibm lotus_domino 8.5.0.1
ibm lotus_domino 8.5.3.1
ibm lotus_domino 8.5.2.1
ibm lotus_domino 8.5.0
ibm lotus_domino 8.5.3.0
ibm lotus_domino 8.5.1
ibm lotus_domino 8.5.1.2
ibm lotus_domino 8.5.3.2
ibm lotus_domino 8.5.1.3
CVE-2013-0488 MEDIUM

Cross-site scripting (XSS) vulnerability in webadmin.nsf (aka the Web Administrator client) in IBM Domino 8.5.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm lotus_domino 8.5.2.4
ibm lotus_domino 8.5.1.5
ibm lotus_domino 8.5.2.2
ibm lotus_domino 8.5.1.1
ibm lotus_domino 8.5.2.3
ibm lotus_domino 8.5.1.4
ibm lotus_domino 8.5.2.0
ibm lotus_domino 8.5.0.1
ibm lotus_domino 8.5.3.1
ibm lotus_domino 8.5.2.1
ibm lotus_domino 8.5.0
ibm lotus_domino 8.5.3.0
ibm lotus_domino 8.5.1
ibm lotus_domino 8.5.1.2
ibm lotus_domino 8.5.3.2
ibm lotus_domino 8.5.1.3
CVE-2013-0489 MEDIUM

Cross-site request forgery (CSRF) vulnerability in webadmin.nsf (aka the Web Administrator client) in IBM Domino 8.5.x allows remote authenticated users to hijack the authentication of administrators.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm lotus_domino 8.5.2.4
ibm lotus_domino 8.5.1.5
ibm lotus_domino 8.5.2.2
ibm lotus_domino 8.5.1.1
ibm lotus_domino 8.5.2.3
ibm lotus_domino 8.5.1.4
ibm lotus_domino 8.5.2.0
ibm lotus_domino 8.5.0.1
ibm lotus_domino 8.5.3.1
ibm lotus_domino 8.5.2.1
ibm lotus_domino 8.5.0
ibm lotus_domino 8.5.3.0
ibm lotus_domino 8.5.1
ibm lotus_domino 8.5.1.2
ibm lotus_domino 8.5.3.2
ibm lotus_domino 8.5.1.3
CVE-2013-0490 HIGH

Unspecified vulnerability in IBM InfoSphere Guardium S-TAP 8.1 for DB2 on z/OS allows local users to gain privileges via unknown vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm infosphere_guardium 8.00
CVE-2013-0492 LOW

Cross-site scripting (XSS) vulnerability in IBM Informix Open Admin Tool (OAT) 2.x and 3.x before 3.11.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm informix_open_admin_tool 3.0
ibm informix_open_admin_tool 2.0
CVE-2013-0494 MEDIUM

IBM Sterling B2B Integrator 5.0 and 5.1 allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted HTTP (1) Range or (2) Request-Range header.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.1
ibm sterling_b2b_integrator 5.0
CVE-2013-0499 MEDIUM

Cross-site scripting (XSS) vulnerability in the echo functionality on IBM WebSphere DataPower SOA appliances with firmware 3.8.2, 4.0, 4.0.1, 4.0.2, and 5.0.0 allows remote attackers to inject arbitrary web script or HTML via a SOAP message, as demonstrated by the XML Firewall, Multi Protocol Gateway (MPGW), Web Service Proxy, and Web Token services.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_datapower_xc10_appliance_firmware 5.0.0
ibm websphere_datapower_service_gateway_xg45_virtual_edition_firmware 4.0
ibm websphere_datapower_integration_appliance_xi52_firmware 4.0.1
ibm websphere_datapower_integration_appliance_xi52_firmware 5.0.0
ibm websphere_datapower_service_gateway_xg45_firmware 4.0
ibm websphere_datapower_integration_appliance_xi52_virtual_edition_firmware 3.8.2
ibm websphere_datapower_integration_appliance_xi50_firmware 5.0.0
ibm websphere_datapower_service_gateway_xg45_virtual_edition -
ibm websphere_datapower_integration_appliance_xi52_virtual_edition_firmware 4.0.2
ibm websphere_datapower_integration_appliance_xi50_firmware 4.0.2
ibm websphere_datapower_integration_appliance_xi52_firmware 4.0
ibm websphere_datapower_integration_appliance_xi52_firmware 3.8.2
ibm websphere_datapower_integration_appliance_xi52_firmware 4.0.2
ibm websphere_datapower_service_gateway_xg45 -
ibm websphere_datapower_integration_appliance_xi50 -
ibm websphere_datapower_xc10_appliance_firmware 4.0.2
ibm websphere_datapower_integration_appliance_xi50_firmware 3.8.2
ibm websphere_datapower_b2b_appliance_xb62_firmware 3.8.2
ibm websphere_datapower_service_gateway_xg45_firmware 4.0.1
ibm websphere_datapower_b2b_appliance_xb62_firmware 5.0.0
ibm websphere_datapower_service_gateway_xg45_firmware 5.0.0
ibm websphere_datapower_integration_appliance_xi52 -
ibm websphere_datapower_service_gateway_xg45_virtual_edition_firmware 5.0.0
ibm websphere_datapower_integration_appliance_xi52_virtual_edition_firmware 5.0.0
ibm websphere_datapower_service_gateway_xg45_virtual_edition_firmware 3.8.2
ibm websphere_datapower_xc10_appliance_firmware 4.0
ibm websphere_datapower_service_gateway_xg45_virtual_edition_firmware 4.0.1
ibm websphere_datapower_b2b_appliance_xb62 -
ibm websphere_datapower_service_gateway_xg45_firmware 3.8.2
ibm websphere_datapower_service_gateway_xg45_virtual_edition_firmware 4.0.2
ibm websphere_datapower_xc10_appliance_firmware 4.0.1
ibm websphere_datapower_integration_appliance_xi52_virtual_edition_firmware 4.0
ibm websphere_datapower_integration_appliance_xi50_firmware 4.0.1
ibm websphere_datapower_xc10_appliance -
ibm websphere_datapower_integration_appliance_xi52_virtual_edition_firmware 4.0.1
ibm websphere_datapower_xc10_appliance_firmware 3.8.2
ibm websphere_datapower_integration_appliance_xi52_virtual_edition -
ibm websphere_datapower_integration_appliance_xi50_firmware 4.0
ibm websphere_datapower_b2b_appliance_xb62_firmware 4.0
ibm websphere_datapower_b2b_appliance_xb62_firmware 4.0.1
ibm websphere_datapower_service_gateway_xg45_firmware 4.0.2
ibm websphere_datapower_b2b_appliance_xb62_firmware 4.0.2
CVE-2013-0500 MEDIUM

IBM Storwize V7000 Unified 1.3.x and 1.4.x before 1.4.2.0 does not properly handle device files that are created with the NFS protocol but accessed with a non-NFS protocol, which allows remote authenticated users to obtain sensitive information, modify programs or files, or cause a denial of service (device crash) via a (1) CIFS, (2) HTTPS, (3) SCP, or (4) SFTP operation.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm storwize_v7000_unified_software 1.3.2.0
ibm storwize_v7000_unified_software 1.3.0.0
ibm storwize_v7000_unified -
ibm storwize_v7000_unified_software 1.3.2.3
ibm storwize_v7000_unified_software 1.4.1.1
ibm storwize_v7000_unified_software 1.4.0.0
ibm storwize_v7000_unified_software 1.4.1.0
ibm storwize_v7000_unified_software 1.4.0.4
CVE-2013-0501 HIGH

The EdrawSoft EDOFFICE.EDOfficeCtrl.1 ActiveX control, as used in Edraw Office Viewer Component, the client in IBM Cognos Disclosure Management (CDM) 10.2.0, and other products, allows remote attackers to read arbitrary files, or download an arbitrary program onto a client machine and execute this program, via a crafted web site.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm cognos_disclosure_management 10.2.0
CVE-2013-0502 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM InfoSphere Information Server 8.1, 8.5 through FP3, 8.7 through FP2, and 9.1 allows remote attackers to inject arbitrary web script or HTML via a malformed URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm infosphere_information_server 8.5.0.2
ibm infosphere_information_server 8.5.0.3
ibm infosphere_information_server 8.7.0.1
ibm infosphere_information_server 8.5.0.1
ibm infosphere_information_server 8.1
ibm infosphere_information_server 8.5
ibm infosphere_information_server 9.1
ibm infosphere_information_server 8.7
ibm infosphere_information_server 8.7.0.2
CVE-2013-0503 MEDIUM

Cross-site scripting (XSS) vulnerability in the Bookmarks component in IBM Lotus Connections before 4.0 CR3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm lotus_connections *
ibm lotus_connections 2.0.0.0
ibm lotus_connections 1.0.2.0
ibm lotus_connections 2.0.1.1
ibm lotus_connections 2.5.0.3
ibm lotus_connections 1.0.1.0
ibm lotus_connections 2.5.0.2
ibm lotus_connections 3.0.1.0
ibm lotus_connections 1.0.0.0
ibm lotus_connections 3.0.1.1
ibm lotus_connections 3.0.0.0
ibm lotus_connections 2.5.0.1
ibm lotus_connections 2.0.1.0
CVE-2013-0505 MEDIUM

IBM Sterling Order Management 8.0 before HF127, 8.5 before HF89, 9.0 before HF69, 9.1.0 before FP41, and 9.2.0 before FP13 allows remote authenticated users to conduct XPath injection attacks, and read arbitrary XML files, via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,CWE-200,

Products Affected

Vendor Product Version
ibm sterling_multi-channel_fulfillment_solution 8.0
ibm sterling_selling_and_fulfillment_foundation 9.1.0
ibm sterling_selling_and_fulfillment_foundation 9.2.0
ibm sterling_selling_and_fulfillment_foundation 8.5
ibm sterling_selling_and_fulfillment_foundation 9.0
CVE-2013-0506 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Sterling Order Management 8.0 before HF127, 8.5 before HF89, 9.0 before HF69, 9.1.0 before FP41, and 9.2.0 before FP13 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm sterling_multi-channel_fulfillment_solution 8.0
ibm sterling_selling_and_fulfillment_foundation 9.1.0
ibm sterling_selling_and_fulfillment_foundation 9.2.0
ibm sterling_selling_and_fulfillment_foundation 8.5
ibm sterling_selling_and_fulfillment_foundation 9.0
CVE-2013-0508 HIGH

Multiple buffer overflows in IBM Tivoli Netcool System Service Monitors (SSM) and Application Service Monitors (ASM) 4.0.0 before FP14 and 4.0.1 before FP1 allow context-dependent attackers to execute arbitrary code or cause a denial of service via a long line in (1) hrfstable.idx, (2) hrdevice.idx, (3) hrstorage.idx, or (4) lotusmapfile in the SSM Config directory, or (5) .manifest.hive in the main agent directory.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm tivoli_netcool_application_service_monitors 4.0.0
ibm tivoli_netcool_application_service_monitors 4.0.1
ibm tivoli_netcool_system_service_monitors 4.0.0
ibm tivoli_netcool_system_service_monitors 4.0.1
CVE-2013-0509 HIGH

Buffer overflow in the Transaction MIB agent in IBM Tivoli Netcool System Service Monitors (SSM) and Application Service Monitors (ASM) 4.0.0 before FP14 allows remote attackers to execute arbitrary code via a SQL transaction with a long table name that is not properly handled by a packet decoder.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm tivoli_netcool_application_service_monitors 4.0.0
ibm tivoli_netcool_system_service_monitors 4.0.0
CVE-2013-0510 MEDIUM

IBM Security AppScan Enterprise 5.6 and 8.x before 8.7 includes a security test that sends session cookies to a specific external server, which allows man-in-the-middle attackers to hijack the test account by capturing these cookies.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm security_appscan 8.0.0.1
ibm security_appscan 8.0.11
ibm security_appscan 8.6.0.2
ibm security_appscan 5.6.0.0
ibm security_appscan 8.6.0.1
ibm security_appscan 8.6.0.0
ibm security_appscan 8.0.1.0
ibm security_appscan 8.0.1.1
ibm security_appscan 8.5.0.1
ibm security_appscan 8.0.0.2
ibm security_appscan 8.0.0.0
ibm security_appscan 8.5.0.0
CVE-2013-0511 MEDIUM

Multiple SQL injection vulnerabilities in IBM Security AppScan Enterprise 5.6 and 8.x before 8.7 allow remote authenticated users to execute arbitrary SQL commands via unspecified parameters.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm security_appscan 8.0.0.1
ibm security_appscan 8.0.11
ibm security_appscan 8.6.0.2
ibm security_appscan 5.6.0.0
ibm security_appscan 8.6.0.1
ibm security_appscan 8.6.0.0
ibm security_appscan 8.0.1.0
ibm security_appscan 8.0.1.1
ibm security_appscan 8.5.0.1
ibm security_appscan 8.0.0.2
ibm security_appscan 8.0.0.0
ibm security_appscan 8.5.0.0
CVE-2013-0512 MEDIUM

Stack-based buffer overflow in the Manual Explore browser plug-in for Firefox in IBM Security AppScan Enterprise 5.6 and 8.x before 8.7 and IBM Rational Policy Tester 5.6 and 8.x before 8.5.0.4 allows remote attackers to cause a denial of service (plug-in crash) via a crafted web page.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm security_appscan 8.0.0.1
ibm rational_policy_tester 8.0.1.0
ibm rational_policy_tester 8.5.0.0
ibm rational_policy_tester 8.0.0.0
ibm security_appscan 8.0.11
ibm security_appscan 8.6.0.2
ibm security_appscan 5.6.0.0
ibm security_appscan 8.6.0.1
ibm rational_policy_tester 8.0.1.1
ibm rational_policy_tester 5.6.0.0
ibm security_appscan 8.6.0.0
ibm rational_policy_tester 8.5.0.1
ibm rational_policy_tester 8.5.0.2
ibm security_appscan 8.0.1.0
ibm security_appscan 8.0.1.1
ibm security_appscan 8.5.0.1
ibm rational_policy_tester 8.0.0.1
ibm security_appscan 8.0.0.2
ibm security_appscan 8.0.0.0
ibm rational_policy_tester 8.0.0.2
ibm security_appscan 8.5.0.0
ibm rational_policy_tester 8.5.0.3
CVE-2013-0513 HIGH

IBM Security AppScan Enterprise 5.6 and 8.x before 8.7 and IBM Rational Policy Tester 5.6 and 8.x before 8.5.0.4 create a service that lacks " (double quote) characters in the service path, which allows local users to gain privileges via a Trojan horse program, related to an "Unquoted Service Path Enumeration" vulnerability.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm security_appscan 8.0.0.1
ibm rational_policy_tester 8.0.1.0
ibm rational_policy_tester 8.5.0.0
ibm rational_policy_tester 8.0.0.0
ibm security_appscan 8.0.11
ibm security_appscan 8.6.0.2
ibm security_appscan 5.6.0.0
ibm security_appscan 8.6.0.1
ibm rational_policy_tester 8.0.1.1
ibm rational_policy_tester 5.6.0.0
ibm security_appscan 8.6.0.0
ibm rational_policy_tester 8.5.0.1
ibm rational_policy_tester 8.5.0.2
ibm security_appscan 8.0.1.0
ibm security_appscan 8.0.1.1
ibm security_appscan 8.5.0.1
ibm rational_policy_tester 8.0.0.1
ibm security_appscan 8.0.0.2
ibm security_appscan 8.0.0.0
ibm rational_policy_tester 8.0.0.2
ibm security_appscan 8.5.0.0
ibm rational_policy_tester 8.5.0.3
CVE-2013-0518 MEDIUM

IBM Sterling Secure Proxy 3.2.0 and 3.3.01 before 3.3.01.23 Interim Fix 1, 3.4.0 before 3.4.0.6 Interim Fix 1, and 3.4.1 before 3.4.1.7 does not refuse to be rendered in different-origin frames, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm sterling_secure_proxy 3.2.0.0
ibm sterling_secure_proxy 3.4.1.0
ibm sterling_secure_proxy 3.4.1.6
ibm sterling_secure_proxy 3.4.1.2
ibm sterling_secure_proxy 3.4.1.5
ibm sterling_secure_proxy 3.4.0.0
ibm sterling_secure_proxy 3.3.0.1
CVE-2013-0519 MEDIUM

IBM Sterling Secure Proxy 3.2.0 and 3.3.01 before 3.3.01.23 Interim Fix 1, 3.4.0 before 3.4.0.6 Interim Fix 1, and 3.4.1 before 3.4.1.7 provides web-server version data in (1) an unspecified page title and (2) an unspecified HTTP header field, which allows remote attackers to obtain potentially sensitive information by reading a version string.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm sterling_secure_proxy 3.2.0.0
ibm sterling_secure_proxy 3.4.1.0
ibm sterling_secure_proxy 3.4.1.6
ibm sterling_secure_proxy 3.4.1.2
ibm sterling_secure_proxy 3.4.1.5
ibm sterling_secure_proxy 3.4.0.0
ibm sterling_secure_proxy 3.3.0.1
CVE-2013-0520 MEDIUM

IBM Sterling Secure Proxy 3.2.0 and 3.3.01 before 3.3.01.23 Interim Fix 1, 3.4.0 before 3.4.0.6 Interim Fix 1, and 3.4.1 before 3.4.1.7 allows remote authenticated users to obtain sensitive Java stack-trace information by providing invalid input data.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm sterling_secure_proxy 3.2.0.0
ibm sterling_secure_proxy 3.4.1.0
ibm sterling_secure_proxy 3.4.1.6
ibm sterling_secure_proxy 3.4.1.2
ibm sterling_secure_proxy 3.4.1.5
ibm sterling_secure_proxy 3.4.0.0
ibm sterling_secure_proxy 3.3.0.1
CVE-2013-0522 LOW

The Notes Client Single Logon feature in IBM Notes 8.0, 8.0.1, 8.0.2, 8.5, 8.5.1, 8.5.2, 8.5.3, and 9.0 on Windows allows local users to discover passwords via vectors involving an unspecified operating system communication mechanism for password transmission between Windows and Notes. IBM X-Force ID: 82531.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm lotus_notes 8.0
ibm lotus_notes 8.5.1
ibm lotus_notes 8.5
ibm lotus_notes 8.0.1
ibm lotus_notes 8.0.2
ibm lotus_notes 8.5.3
ibm lotus_notes 8.5.2
ibm lotus_notes 9.0
CVE-2013-0523 MEDIUM

IBM WebSphere Commerce Enterprise 5.6.x through 5.6.1.5, 6.0.x through 6.0.0.11, and 7.0.x through 7.0.0.7 does not use a suitable encryption algorithm for storefront web requests, which allows remote attackers to obtain sensitive information via a padding oracle attack that targets certain UTF-8 processing of the krypto parameter, and leverages unspecified browser access or traffic-log access.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_commerce 6.0.0.6
ibm websphere_commerce 7.0.0.6
ibm websphere_commerce 7.0.0.7
ibm websphere_commerce 6.0.0.11
ibm websphere_commerce 6.0.0.10
ibm websphere_commerce 7.0.0.3
ibm websphere_commerce 7.0.0.2
ibm websphere_commerce 7.0
ibm websphere_commerce 6.0.0.7
ibm websphere_commerce 6.0.0.8
ibm websphere_commerce 7.0.0.5
ibm websphere_commerce 6.0.0.0
ibm websphere_commerce 7.0.0.1
ibm websphere_commerce 6.0.0.5
ibm websphere_commerce 5.6.1.3
ibm websphere_commerce 7.0.0.4
ibm websphere_commerce 5.6.1.2
ibm websphere_commerce 6.0.0.1
ibm websphere_commerce 6.0.0.2
ibm websphere_commerce 5.6.1.4
ibm websphere_commerce 5.6.1.5
ibm websphere_commerce 6.0.0.3
ibm websphere_commerce 5.6.1
ibm websphere_commerce 6.0.0.4
ibm websphere_commerce 6.0.0.9
ibm websphere_commerce 5.6.1.1
CVE-2013-0525 LOW

Multiple cross-site scripting (XSS) vulnerabilities in IBM iNotes 8.5.x allow local users to inject arbitrary web script or HTML via a shared mail file, aka SPR DKEN8PDNTX.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm lotus_inotes 8.5.1.3
ibm lotus_inotes 8.5.1.0
ibm lotus_inotes 8.5.3.0
ibm lotus_inotes 8.5.2.2
ibm lotus_inotes 8.5.0.0
ibm lotus_inotes 8.5.1.5
ibm lotus_inotes 8.5.2.3
ibm lotus_inotes 8.5.2.1
ibm lotus_inotes 8.5.1.1
ibm lotus_inotes 8.5.2.0
ibm lotus_inotes 8.5.3.1
ibm lotus_inotes 8.5.1.4
ibm lotus_inotes 8.5.1.2
ibm lotus_inotes 8.5.0.1
ibm lotus_inotes 8.5.3.2
CVE-2013-0526 HIGH

ping.php in Global Console Manager 16 (GCM16) and Global Console Manager 32 (GCM32) before 1.20.0.22575 on the IBM Avocent 1754 KVM switch allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) count or (2) size parameter.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm global_console_manager_32_firmware *
ibm global_console_manager_16_firmware *
CVE-2013-0527 LOW

The Browser in IBM Sterling Connect:Direct 1.4 before 1.4.0.11 and 1.5 through 1.5.0.1 does not close pages upon the timeout of a session, which allows physically proximate attackers to obtain sensitive administrative-console information by reading the screen of an unattended workstation.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm sterling_connect_direct_user_interface 1.4.0.2
ibm sterling_connect_direct_user_interface 1.4.0.7
ibm sterling_connect_direct_user_interface 1.4.0.3
ibm sterling_connect_direct_user_interface 1.5.0.1
ibm sterling_connect_direct_user_interface 1.5.0.0
ibm sterling_connect_direct_user_interface 1.4.0.6
ibm sterling_connect_direct_user_interface 1.4.0.10
ibm sterling_connect_direct_user_interface 1.4.0.0
CVE-2013-0529 MEDIUM

The Browser in IBM Sterling Connect:Direct 1.4 before 1.4.0.11 and 1.5 through 1.5.0.1 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm sterling_connect_direct_user_interface 1.4.0.2
ibm sterling_connect_direct_user_interface 1.4.0.7
ibm sterling_connect_direct_user_interface 1.4.0.3
ibm sterling_connect_direct_user_interface 1.5.0.1
ibm sterling_connect_direct_user_interface 1.5.0.0
ibm sterling_connect_direct_user_interface 1.4.0.6
ibm sterling_connect_direct_user_interface 1.4.0.10
ibm sterling_connect_direct_user_interface 1.4.0.0
CVE-2013-0531 MEDIUM

The SSL implementation in IBM Security AppScan Enterprise before 8.7.0.1 enables cipher suites with weak encryption algorithms, which makes it easier for remote attackers to obtain sensitive information by sniffing the network.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm security_appscan 8.0.0.1
ibm security_appscan 8.0.11
ibm security_appscan 8.6.0.2
ibm security_appscan 5.6.0.0
ibm security_appscan 8.6.0.1
ibm security_appscan 6.0.0.0
ibm security_appscan 8.6.0.0
ibm security_appscan 6.0.2.0
ibm security_appscan 8.0.1.0
ibm security_appscan 8.0.1.1
ibm security_appscan 8.5.0.1
ibm security_appscan 8.0.0.2
ibm security_appscan 6.1.1.0
ibm security_appscan *
ibm security_appscan 8.0.0.0
ibm security_appscan 8.5.0.0
ibm security_appscan 6.0.1.0
CVE-2013-0532 MEDIUM

Cross-site request forgery (CSRF) vulnerability in IBM Security AppScan Enterprise 5.6 and 8.x before 8.7 and IBM Rational Policy Tester 5.6 and 8.x before 8.5.0.4 allows remote attackers to hijack the authentication of arbitrary users for requests that cause a denial of service via malformed HTTP data.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm security_appscan 8.0.0.1
ibm rational_policy_tester 8.0.1.0
ibm rational_policy_tester 8.5.0.0
ibm rational_policy_tester 8.0.0.0
ibm security_appscan 8.0.11
ibm security_appscan 8.6.0.2
ibm security_appscan 5.6.0.0
ibm security_appscan 8.6.0.1
ibm rational_policy_tester 8.0.1.1
ibm rational_policy_tester 5.6.0.0
ibm security_appscan 8.6.0.0
ibm rational_policy_tester 8.5.0.1
ibm rational_policy_tester 8.5.0.2
ibm security_appscan 8.0.1.0
ibm security_appscan 8.0.1.1
ibm security_appscan 8.5.0.1
ibm rational_policy_tester 8.0.0.1
ibm security_appscan 8.0.0.2
ibm security_appscan 8.0.0.0
ibm rational_policy_tester 8.0.0.2
ibm security_appscan 8.5.0.0
ibm rational_policy_tester 8.5.0.3
CVE-2013-0533 LOW

Cross-site scripting (XSS) vulnerability in the Sametime Links server in IBM Sametime 8.0.2 through 8.5.2.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm lotus_sametime 8.5
ibm lotus_sametime 8.5.2
ibm lotus_sametime 8.5.1.1
ibm lotus_sametime 8.0.2
ibm lotus_sametime 8.0.2.1
ibm lotus_sametime 8.5.1
ibm lotus_sametime 8.5.2.1
CVE-2013-0534 LOW

The Connect client in IBM Sametime 8.5.1, 8.5.1.1, 8.5.1.2, 8.5.2, and 8.5.2.1, as used in the Lotus Notes client and separately, might allow local users to obtain sensitive information by leveraging the persistence of cleartext password strings within process memory.

CVSS 2.0

Severity: LOW

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm lotus_sametime 8.5.2
ibm sametime 8.5.1.1
ibm sametime 8.5.2.1
ibm lotus_sametime 8.5.1.1
ibm sametime 8.5.1
ibm lotus_sametime 8.5.1.2
ibm lotus_sametime 8.5.1
ibm sametime 8.5.2
ibm lotus_sametime 8.5.2.1
ibm sametime 8.5.1.2
CVE-2013-0535 LOW

Multiple cross-site scripting (XSS) vulnerabilities in the Classic Meeting Server in IBM Sametime 7.5.1.2 through 8.5.2.1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm classic_meeting_server 7.5.1.2
ibm lotus_sametime 8.5
ibm lotus_sametime 8.5.1.1
ibm lotus_sametime 8.0.1
ibm lotus_sametime 8.0.2
ibm lotus_sametime 8.0.1.1
ibm lotus_sametime 8.5.1
ibm lotus_sametime 7.5.1.2
ibm lotus_sametime 8.5.2.1
ibm classic_meeting_server 8.5.1.2
ibm lotus_sametime 8.0
ibm lotus_sametime 8.5.2
ibm lotus_sametime 8.0.2.1
ibm classic_meeting_server 8.5
ibm classic_meeting_server 8.0.1
ibm classic_meeting_server 8.0.2
ibm classic_meeting_server 8.5.2.1
CVE-2013-0536 HIGH

ntmulti.exe in the Multi User Profile Cleanup service in IBM Notes 8.0, 8.0.1, 8.0.2, 8.5, 8.5.1, 8.5.2, 8.5.3 before FP5, and 9.0 before IF2 allows local users to gain privileges via vectors that arrange for code to be executed during the next login session of a different user, aka SPR PJOK959J24.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm lotus_inotes 8.5.3.0
ibm lotus_notes 8.0
ibm lotus_notes 8.5.1
ibm lotus_notes_traveler 9.0
ibm lotus_notes 8.5
ibm lotus_inotes 8.5.2.0
ibm lotus_notes 8.0.1
ibm lotus_notes 8.0.2
CVE-2013-0537 LOW

The Enterprise Meeting Server in IBM Lotus Sametime 8.5.2 and 8.5.2.1 allows remote authenticated users to spoof the origin of shared links by leveraging meeting-attendance privileges.

CVSS 2.0

Severity: LOW

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm lotus_sametime 8.5.2
ibm lotus_sametime 8.5.2.1
CVE-2013-0538 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Lotus Notes 8.x before 8.5.3 FP4 Interim Fix 1 and 9.0 before Interim Fix 1 allows remote attackers to inject arbitrary web script or HTML via a SCRIPT element in an HTML e-mail message, aka SPRs JMOY95BLM6 and JMOY95BN49.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm lotus_notes 8.0.2.1
ibm lotus_notes 8.5.1.5
ibm lotus_notes 8.5.2.0
ibm lotus_notes 8.0.0
ibm lotus_notes 8.0.2.3
ibm lotus_notes 8.5.1.4
ibm lotus_notes 8.5.3.2
ibm lotus_notes 8.5.2.1
ibm lotus_notes 8.0.1
ibm lotus_notes 8.0.2.2
ibm lotus_notes 8.0.2.4
ibm lotus_notes 8.5.0.1
ibm lotus_notes 8.0
ibm lotus_notes 8.0.2.0
ibm lotus_notes 8.5.3
ibm lotus_notes 8.0.2.5
ibm lotus_notes 8.5.1.1
ibm lotus_notes 8.5.2.2
ibm lotus_notes 9.0.0.0
ibm lotus_notes 8.5.1
ibm lotus_notes 8.5.1.2
ibm lotus_notes 8.5.1.3
ibm lotus_notes 8.5.0.0
ibm lotus_notes 8.5.2.3
ibm lotus_notes 8.5.3.3
ibm lotus_notes 8.5.1.0
ibm lotus_notes 8.0.2.6
ibm lotus_notes 8.5.3.1
ibm lotus_notes 8.5
ibm lotus_notes 8.0.2
CVE-2013-0539 MEDIUM

An unspecified third-party component in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 uses short session ID values, which makes it easier for remote attackers to hijack sessions, and consequently obtain sensitive information, via a brute-force attack.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2
ibm sterling_b2b_integrator 5.1
ibm sterling_file_gateway 2.2
ibm sterling_file_gateway 2.1
CVE-2013-0540 LOW

IBM WebSphere Application Server (WAS) Liberty Profile 8.5 before 8.5.0.2, when SSL is not enabled, does not properly validate authentication cookies, which allows remote authenticated users to bypass intended access restrictions via an HTTP session.

CVSS 2.0

Severity: LOW

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 8.5.0.1
CVE-2013-0541 LOW

Buffer overflow in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2 on Windows, when a localOS registry is used in conjunction with WebSphere Identity Manger (WIM), allows local users to cause a denial of service (daemon crash) via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 6.1.0.14
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0.35
ibm websphere_application_server 7.0.0.25
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.0.39
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 6.1.0.37
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 7.0.0.27
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 8.0.0.2
ibm websphere_application_server 8.0.0.5
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 6.1.0.45
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.41
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 6.1.0.43
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 7.0.0.4
CVE-2013-0542 MEDIUM

Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2 allows remote attackers to inject arbitrary web script or HTML via crafted field values.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 6.1.0.14
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0.35
ibm websphere_application_server 7.0.0.25
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server *
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.0.39
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 6.1.0.37
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 7.0.0.27
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 8.0.0.2
ibm websphere_application_server 8.0.0.5
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 6.1.0
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.41
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 6.1.0.43
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 7.0.0.4
CVE-2013-0543 MEDIUM

IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2 on Linux, Solaris, and HP-UX, when a Local OS registry is used, does not properly validate user accounts, which allows remote attackers to bypass intended access restrictions via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-863,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 6.1.0.14
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0.35
ibm websphere_application_server 7.0.0.25
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.0.39
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 6.1.0.37
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 7.0.0.27
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 8.0.0.2
ibm websphere_application_server 8.0.0.5
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 6.1.0.45
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.41
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 6.1.0.43
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 7.0.0.4
CVE-2013-0544 MEDIUM

Directory traversal vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2 on Linux and UNIX allows remote authenticated users to modify data via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 6.1.0.14
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0.35
ibm websphere_application_server 7.0.0.25
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.0.39
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 6.1.0.37
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 7.0.0.27
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 8.0.0.2
ibm websphere_application_server 8.0.0.5
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 6.1.0.45
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.41
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 6.1.0.43
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 7.0.0.4
CVE-2013-0548 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in the Basic Services component in IBM Tivoli Monitoring (ITM) 6.2.0 through FP3, 6.2.1 through FP4, 6.2.2 through FP9, and 6.2.3 before FP3, as used in IBM Application Manager for Smart Business (formerly Tivoli Foundations Application Manager) 1.2.1 before 1.2.1.0-TIV-IAMSB-FP0004 and other products, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_monitoring 6.2.1.4
ibm tivoli_monitoring 6.2.3
ibm tivoli_monitoring 6.2.0.2
ibm tivoli_monitoring 6.2.2.4
ibm tivoli_monitoring 6.2.2.5
ibm tivoli_monitoring 6.2.2.8
ibm tivoli_monitoring 6.2.3.1
ibm tivoli_monitoring 6.2.3.2
ibm tivoli_monitoring 6.2.2.9
ibm tivoli_monitoring 6.2.1.3
ibm tivoli_monitoring 6.2.2.3
ibm tivoli_monitoring 6.2.1.2
ibm tivoli_monitoring 6.2.2
ibm application_manager_for_smart_business 1.2.1
ibm tivoli_monitoring 6.2.0.3
ibm tivoli_monitoring 6.2.1
ibm tivoli_monitoring 6.2.0.1
ibm tivoli_monitoring 6.2.1.1
ibm tivoli_monitoring 6.2.2.7
ibm tivoli_monitoring 6.2.0
ibm tivoli_monitoring 6.2.2.1
ibm tivoli_monitoring 6.2.2.2
ibm tivoli_monitoring 6.2.2.6
CVE-2013-0549 MEDIUM

Cross-site scripting (XSS) vulnerability in the Web Content Manager - Web Content Viewer Portlet in the server in IBM WebSphere Portal 7.0.0.x through 7.0.0.2 CF22 and 8.0.0.x through 8.0.0.1 CF5, when the IBM Portlet API is used, allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.1
ibm websphere_portal 8.0.0.0
ibm websphere_portal 7.0.0.2
ibm websphere_portal 8.0
ibm websphere_portal 7.0.0.1
ibm websphere_portal 7.0.0.0
CVE-2013-0551 MEDIUM

The Basic Services component in IBM Tivoli Monitoring (ITM) 6.2.0 through FP3, 6.2.1 through FP4, 6.2.2 through FP9, and 6.2.3 before FP3, as used in IBM Application Manager for Smart Business (formerly Tivoli Foundations Application Manager) 1.2.1 before 1.2.1.0-TIV-IAMSB-FP0004 and other products, allows remote attackers to cause a denial of service (abend) via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm tivoli_monitoring 6.2.1.4
ibm tivoli_monitoring 6.2.3
ibm tivoli_monitoring 6.2.0.2
ibm tivoli_monitoring 6.2.2.4
ibm tivoli_monitoring 6.2.2.5
ibm tivoli_monitoring 6.2.2.8
ibm tivoli_monitoring 6.2.3.1
ibm tivoli_monitoring 6.2.3.2
ibm tivoli_monitoring 6.2.2.9
ibm tivoli_monitoring 6.2.1.3
ibm tivoli_monitoring 6.2.2.3
ibm tivoli_monitoring 6.2.1.2
ibm tivoli_monitoring 6.2.2
ibm application_manager_for_smart_business 1.2.1
ibm tivoli_monitoring 6.2.0.3
ibm tivoli_monitoring 6.2.1
ibm tivoli_monitoring 6.2.0.1
ibm tivoli_monitoring 6.2.1.1
ibm tivoli_monitoring 6.2.2.7
ibm tivoli_monitoring 6.2.0
ibm tivoli_monitoring 6.2.2.1
ibm tivoli_monitoring 6.2.2.2
ibm tivoli_monitoring 6.2.2.6
CVE-2013-0553 LOW

The client implementation in IBM Sametime 8.5.1 through 8.5.2.1, as used in Sametime Connect client, Sametime Advanced Connect client, Sametime Advanced Web client, and other products, allows remote authenticated users to send commands to individual chat users, or to all participants in a chat room, via a crafted Sametime Instant Message (IM).

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm sametime 8.5.2.0
ibm sametime 8.5.2.1
ibm lotus_sametime 8.5.1.1
ibm lotus_sametime 8.5.1
CVE-2013-0558 MEDIUM

IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote attackers to obtain sensitive information about application implementation via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2
ibm sterling_b2b_integrator 5.1
ibm sterling_file_gateway 2.2
ibm sterling_file_gateway 2.1
CVE-2013-0559 MEDIUM

Unspecified vulnerability in IBM API Management 2.0 before 2.0.0.1 allows remote attackers to access tenant APIs, and consequently obtain sensitive information or modify data, via unknown vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm api_management 2.0.0.0
CVE-2013-0560 MEDIUM

Multiple SQL injection vulnerabilities in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2012-5766.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2
ibm sterling_b2b_integrator 5.1
ibm sterling_file_gateway 2.2
ibm sterling_file_gateway 2.1
CVE-2013-0565 MEDIUM

Cross-site scripting (XSS) vulnerability in the RPC adapter for the Web 2.0 and Mobile toolkit in IBM WebSphere Application Server (WAS) 8.5 before 8.5.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted response.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 8.5.0.1
CVE-2013-0566 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in the (1) Accelerator JSPs, (2) Organization Administration Console JSPs, and (3) Administration Console JSPs in WebSphere Commerce Tools in IBM WebSphere Commerce 5.6.1.0 through 5.6.1.5, 6.0.0.0 through 6.0.0.11, and 7.0.0.0 through 7.0.0.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_commerce 6.0.0.6
ibm websphere_commerce 7.0.0.6
ibm websphere_commerce 7.0.0.7
ibm websphere_commerce 6.0.0.11
ibm websphere_commerce 6.0.0.10
ibm websphere_commerce 7.0.0.3
ibm websphere_commerce 7.0.0.2
ibm websphere_commerce 7.0
ibm websphere_commerce 6.0.0.7
ibm websphere_commerce 6.0.0.8
ibm websphere_commerce 7.0.0.5
ibm websphere_commerce 6.0.0.0
ibm websphere_commerce 7.0.0.1
ibm websphere_commerce 6.0.0.5
ibm websphere_commerce 5.6.1.3
ibm websphere_commerce 7.0.0.4
ibm websphere_commerce 5.6.1.2
ibm websphere_commerce 6.0.0.1
ibm websphere_commerce 6.0.0.2
ibm websphere_commerce 5.6.1.4
ibm websphere_commerce 5.6.1.5
ibm websphere_commerce 6.0.0.3
ibm websphere_commerce 5.6.1
ibm websphere_commerce 6.0.0.4
ibm websphere_commerce 6.0.0.9
ibm websphere_commerce 5.6.1.1
CVE-2013-0567 MEDIUM

IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to obtain sensitive information about application implementation via unspecified vectors, a different vulnerability than CVE-2013-0463, CVE-2013-2985, CVE-2013-2987, CVE-2013-3020, CVE-2013-0568, and CVE-2013-0475.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2
ibm sterling_b2b_integrator 5.1
ibm sterling_file_gateway 2.2
ibm sterling_file_gateway 2.1
CVE-2013-0568 MEDIUM

IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to obtain sensitive information about application implementation via unspecified vectors, a different vulnerability than CVE-2013-0463, CVE-2013-2985, CVE-2013-2987, CVE-2013-3020, CVE-2013-0475, and CVE-2013-0567.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2
ibm sterling_b2b_integrator 5.1
ibm sterling_file_gateway 2.2
ibm sterling_file_gateway 2.1
CVE-2013-0569 MEDIUM

Cross-site scripting (XSS) vulnerability in the Communities component in IBM Connections 4.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm connections 4.5.0.0
CVE-2013-0570 LOW

The Fibre Channel over Ethernet (FCoE) feature in IBM System Networking and Blade Network Technology (BNT) switches running IBM Networking Operating System (aka NOS, formerly BLADE Operating System) floods data frames with unknown MAC addresses out on all interfaces on the same VLAN, which might allow remote attackers to obtain sensitive information in opportunistic circumstances by eavesdropping on the broadcast domain. IBM X-Force ID: 83166.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm network_operating_system -
CVE-2013-0571 LOW

Cross-site scripting (XSS) vulnerability in IBM Document Connect for Application Support Facility (aka DC4ASF) before 1.0.0.1218 in Application Support Facility (ASF) 3.4 for z/OS on Windows, Linux, and AIX allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm application_support_facility 3.4.0
ibm document_connect_for_application_support_facility *
CVE-2013-0572 LOW

Cross-site scripting (XSS) vulnerability in IBM Document Connect for Application Support Facility (aka DC4ASF) before 1.0.0.1218 in Application Support Facility (ASF) 3.4 for z/OS on Windows, Linux, and AIX allows remote authenticated users to inject content, and conduct phishing attacks, via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm application_support_facility 3.4.0
ibm document_connect_for_application_support_facility *
CVE-2013-0576 MEDIUM

Cross-site scripting (XSS) vulnerability in the Tivoli Enterprise Portal browser client in IBM Tivoli Monitoring 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP09, and 6.2.3 through FP02 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_monitoring 6.2.1.4
ibm tivoli_monitoring 6.2.3
ibm tivoli_monitoring 6.2.0.2
ibm tivoli_monitoring 6.2.2.4
ibm tivoli_monitoring 6.2.2.5
ibm tivoli_monitoring 6.2.2.8
ibm tivoli_monitoring 6.2.3.1
ibm tivoli_monitoring 6.2.3.2
ibm tivoli_monitoring 6.2.2.9
ibm tivoli_monitoring 6.2.1.3
ibm tivoli_monitoring 6.2.2.3
ibm tivoli_monitoring 6.2.1.2
ibm tivoli_monitoring 6.2.2
ibm tivoli_monitoring 6.2.0.3
ibm tivoli_monitoring 6.2.1
ibm tivoli_monitoring 6.2.0.1
ibm tivoli_monitoring 6.2.1.1
ibm tivoli_monitoring 6.2.2.7
ibm tivoli_monitoring 6.2.0
ibm tivoli_monitoring 6.2.2.1
ibm tivoli_monitoring 6.2.2.2
ibm tivoli_monitoring 6.2.2.6
CVE-2013-0577 MEDIUM

The Optim E-Business Console in IBM Data Growth Solution for Oracle E-business Suite 6.0 through 9.1 allows remote authenticated users to bypass intended access restrictions and create, modify, or delete documents or scripts via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.4.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.3.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.5.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.3.3
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.3.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.1.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.2.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.4.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.2.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.1.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.3.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 9.1.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.5.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.1.2
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.2.2
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.3.2
CVE-2013-0578 LOW

The Sterling Order Management APIs in IBM Sterling Multi-Channel Fulfillment Solution 8.0 before HF128 and IBM Sterling Selling and Fulfillment Foundation 8.5 before HF93, 9.0 before HF73, 9.1.0 before FP45, and 9.2.0 before FP17, when the API tester is enabled, do not require administrative credentials, which allows remote authenticated users to obtain sensitive database information via a request to the API tester URI.

CVSS 2.0

Severity: LOW

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm sterling_selling_and_fulfillment_foundation 9.1.0.38
ibm sterling_selling_and_fulfillment_foundation 9.1.0.14
ibm sterling_selling_and_fulfillment_foundation 9.1.0
ibm sterling_selling_and_fulfillment_foundation 9.2.0.2
ibm sterling_selling_and_fulfillment_foundation 9.1.0.1
ibm sterling_selling_and_fulfillment_foundation 9.2.0
ibm sterling_selling_and_fulfillment_foundation 9.1.0.36
ibm sterling_selling_and_fulfillment_foundation 9.1.0.11
ibm sterling_selling_and_fulfillment_foundation 9.2.0.12
ibm sterling_selling_and_fulfillment_foundation 9.1.0.16
ibm sterling_selling_and_fulfillment_foundation 9.1.0.23
ibm sterling_selling_and_fulfillment_foundation 9.2.0.13
ibm sterling_selling_and_fulfillment_foundation 9.1.0.15
ibm sterling_selling_and_fulfillment_foundation 9.1.0.28
ibm sterling_selling_and_fulfillment_foundation 9.2.0.11
ibm sterling_selling_and_fulfillment_foundation 9.1.0.3
ibm sterling_selling_and_fulfillment_foundation 9.1.0.10
ibm sterling_selling_and_fulfillment_foundation 9.2.0.9
ibm sterling_selling_and_fulfillment_foundation 9.2.0.16
ibm sterling_selling_and_fulfillment_foundation 9.1.0.2
ibm sterling_selling_and_fulfillment_foundation 9.2.0.1
ibm sterling_selling_and_fulfillment_foundation 9.2.0.3
ibm sterling_selling_and_fulfillment_foundation 9.2.0.6
ibm sterling_selling_and_fulfillment_foundation 9.1.0.34
ibm sterling_selling_and_fulfillment_foundation 9.2.0.5
ibm sterling_selling_and_fulfillment_foundation 9.1.0.9
ibm sterling_selling_and_fulfillment_foundation 9.2.0.7
ibm sterling_selling_and_fulfillment_foundation 9.1.0.17
ibm sterling_selling_and_fulfillment_foundation 9.1.0.39
ibm sterling_selling_and_fulfillment_foundation 9.1.0.27
ibm sterling_selling_and_fulfillment_foundation 9.1.0.8
ibm sterling_selling_and_fulfillment_foundation 9.2.0.14
ibm sterling_selling_and_fulfillment_foundation 9.2.0.4
ibm sterling_selling_and_fulfillment_foundation 9.1.0.22
ibm sterling_selling_and_fulfillment_foundation 9.1.0.26
ibm sterling_selling_and_fulfillment_foundation 9.1.0.41
ibm sterling_selling_and_fulfillment_foundation 9.1.0.44
ibm sterling_multi-channel_fulfillment_solution 8.0
ibm sterling_selling_and_fulfillment_foundation 9.1.0.33
ibm sterling_selling_and_fulfillment_foundation 9.1.0.35
ibm sterling_selling_and_fulfillment_foundation 9.1.0.43
ibm sterling_selling_and_fulfillment_foundation 9.1.0.21
ibm sterling_selling_and_fulfillment_foundation 9.1.0.12
ibm sterling_selling_and_fulfillment_foundation 9.1.0.24
ibm sterling_selling_and_fulfillment_foundation 9.2.0.8
ibm sterling_selling_and_fulfillment_foundation 9.1.0.4
ibm sterling_selling_and_fulfillment_foundation 9.1.0.7
ibm sterling_selling_and_fulfillment_foundation 9.1.0.29
ibm sterling_selling_and_fulfillment_foundation 9.1.0.42
ibm sterling_selling_and_fulfillment_foundation 9.1.0.6
ibm sterling_selling_and_fulfillment_foundation 9.1.0.30
ibm sterling_selling_and_fulfillment_foundation 9.1.0.18
ibm sterling_selling_and_fulfillment_foundation 9.1.0.32
ibm sterling_selling_and_fulfillment_foundation 9.1.0.19
ibm sterling_selling_and_fulfillment_foundation 9.1.0.13
ibm sterling_selling_and_fulfillment_foundation 9.1.0.25
ibm sterling_selling_and_fulfillment_foundation 9.2.0.15
ibm sterling_selling_and_fulfillment_foundation 9.0
ibm sterling_selling_and_fulfillment_foundation 9.1.0.37
ibm sterling_selling_and_fulfillment_foundation 9.1.0.31
ibm sterling_selling_and_fulfillment_foundation 9.1.0.20
ibm sterling_selling_and_fulfillment_foundation 9.1.0.5
ibm sterling_selling_and_fulfillment_foundation 8.5
ibm sterling_selling_and_fulfillment_foundation 9.2.0.10
ibm sterling_selling_and_fulfillment_foundation 9.1.0.40
CVE-2013-0579 MEDIUM

The Optim E-Business Console in IBM Data Growth Solution for Oracle E-business Suite 6.0 through 9.1 allows remote attackers to impersonate arbitrary users by leveraging access to a legitimate user's web browser either (1) before or (2) after authentication.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.4.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.3.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.5.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.3.3
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.3.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.1.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.2.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.4.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.2.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.1.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.3.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 9.1.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.5.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.1.2
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.2.2
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.3.2
CVE-2013-0580 MEDIUM

Cross-site request forgery (CSRF) vulnerability in the Optim E-Business Console in IBM Data Growth Solution for Oracle E-business Suite 6.0 through 9.1 allows remote authenticated users to hijack the authentication of arbitrary users.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.4.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.3.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.5.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.3.3
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.3.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.1.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.2.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.4.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.2.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.1.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.3.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 9.1.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.5.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.1.2
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.2.2
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.3.2
CVE-2013-0581 LOW

Multiple cross-site scripting (XSS) vulnerabilities in IBM Business Process Manager (BPM) 7.5.1.x, 8.0.0.x, and 8.0.1 before FP1 allow remote authenticated users to inject arbitrary web script or HTML via vectors involving (1) ProcessPortal/jsp/socialPortal/dashboard.jsp, (2) teamworks/executeServiceByName, (3) portal/jsp/viewAdHocReportWizard.do, or (4) rest/bpm/wle/v1/process.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm business_process_manager 8.0.1.0
ibm business_process_manager 8.0.0.0
ibm business_process_manager 7.5.1.0
ibm business_process_manager 7.5.1.1
CVE-2013-0582 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.12, 6.2.1 before 6.2.1.5, and 6.2.2 before 6.2.2.4 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.2.0 before 6.2.0.12 and 6.2.1 before 6.2.1.5 allows remote attackers to inject arbitrary web script or HTML via a crafted URL that triggers a SAML 2.0 response.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_federated_identity_manager 6.2.0.3
ibm tivoli_federated_identity_manager_business_gateway 6.2.0.1
ibm tivoli_federated_identity_manager 6.2.1.1
ibm tivoli_federated_identity_manager_business_gateway 6.2.0.3
ibm tivoli_federated_identity_manager_business_gateway 6.2.0.9
ibm tivoli_federated_identity_manager 6.2.0.1
ibm tivoli_federated_identity_manager 6.2.1.4
ibm tivoli_federated_identity_manager 6.2.0.9
ibm tivoli_federated_identity_manager_business_gateway 6.2.0.2
ibm tivoli_federated_identity_manager 6.2.0.8
ibm tivoli_federated_identity_manager 6.2.0.11
ibm tivoli_federated_identity_manager_business_gateway 6.2.0.11
ibm tivoli_federated_identity_manager 6.2.0.10
ibm tivoli_federated_identity_manager 6.2.2.3
ibm tivoli_federated_identity_manager 6.2.1
ibm tivoli_federated_identity_manager_business_gateway 6.2.1.4
ibm tivoli_federated_identity_manager_business_gateway 6.2.1.3
ibm tivoli_federated_identity_manager_business_gateway 6.2.1
ibm tivoli_federated_identity_manager 6.2.0
ibm tivoli_federated_identity_manager_business_gateway 6.2.0.10
ibm tivoli_federated_identity_manager 6.2.2.2
ibm tivoli_federated_identity_manager_business_gateway 6.2.0.8
ibm tivoli_federated_identity_manager 6.2.1.3
ibm tivoli_federated_identity_manager 6.2.0.2
ibm tivoli_federated_identity_manager 6.2.2
ibm tivoli_federated_identity_manager_business_gateway 6.2.0
ibm tivoli_federated_identity_manager 6.2.1.2
CVE-2013-0584 MEDIUM

The Data Replication Dashboard component in IBM InfoSphere Replication Server 9.7 and 10.x before 10.2.0.0-b113 allows remote attackers to obtain a list of all user accounts, along with information about whether each account requires a password, via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm infosphere_replication_server 10.1.0.2
ibm infosphere_replication_server 10.1.0.3
ibm infosphere_replication_server 10.2.0.0
ibm infosphere_replication_server 10.1.0.4
ibm infosphere_replication_server 9.7
ibm infosphere_replication_server 10.1.0.1
ibm infosphere_replication_server 10.1.0
CVE-2013-0585 LOW

Multiple cross-site scripting (XSS) vulnerabilities in IBM InfoSphere Information Server through 8.5 FP3, 8.7 through FP2, and 9.1 allow remote authenticated users to inject arbitrary web script or HTML via vectors related to the (1) web console and (2) repository management user interfaces.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm infosphere_information_server 8.1
ibm infosphere_information_server 8.5
ibm infosphere_information_server 9.1
ibm infosphere_information_server 8.7
CVE-2013-0586 LOW

Cross-site scripting (XSS) vulnerability in the server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1, 10.1.1, 10.2, and 10.2.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm cognos_business_intelligence 10.2.1
ibm cognos_business_intelligence 10.2
ibm cognos_business_intelligence 10.1
ibm cognos_business_intelligence 8.4.1
ibm cognos_business_intelligence 10.1.1
CVE-2013-0587 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in IBM WebSphere Portal before 8.0.0.1 CF07 allow remote attackers to inject arbitrary web script or HTML via vectors involving the (1) Portal, (2) Portal 7.0.0.2, (3) Portal 8.0, or (4) PortalWeb2 theme.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 6.0.0.2
ibm websphere_portal 8.0.0.0
ibm websphere_portal 6.1.0.3
ibm websphere_portal 6.0.1.0
ibm websphere_portal 5.1.0.4
ibm websphere_portal 6.0.1.1
ibm websphere_portal 6.0.0.4
ibm websphere_portal 5.1.0.2
ibm websphere_portal 5.1.0.3
ibm websphere_portal 5.1.0.0
ibm websphere_portal 8.0.0.1
ibm websphere_portal 6.0.1.3
ibm websphere_portal *
ibm websphere_portal 6.0.0.1
ibm websphere_portal 6.1.5.0
ibm websphere_portal 6.1.0.1
ibm websphere_portal 6.1.0.0
ibm websphere_portal 6.0.1.4
ibm websphere_portal 8.0
ibm websphere_portal 6.0.0.0
ibm websphere_portal 7.0.0.1
ibm websphere_portal 6.1.0.2
ibm websphere_portal 6.0.1.6
ibm websphere_portal 6.0.1.2
ibm websphere_portal 6.0.1.5
ibm websphere_portal 7.0.0.2
ibm websphere_portal 6.0.0.3
ibm websphere_portal 6.0.1.7
ibm websphere_portal 7.0.0.0
ibm websphere_portal 5.1.0.5
ibm websphere_portal 5.1.0.1
CVE-2013-0589 MEDIUM

IBM iNotes before 8.5.3 Fix Pack 6 and 9.x before 9.0.1 allows remote attackers to bypass the remote image filtering mechanism and obtain sensitive information via a crafted e-mail message. IBM X-Force ID: 83371.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm inotes 8.5.2.0
ibm inotes 8.5.0.0
ibm inotes 9.0.0.0
ibm inotes 8.5.1.0
ibm inotes 8.0.0.0
ibm inotes 8.5.3.0
ibm inotes 8.0.2.0
ibm inotes 8.0.1.0
CVE-2013-0590 LOW

Cross-site scripting (XSS) vulnerability in iNotes 8.5.x in IBM Lotus Domino 8.5 before 8.5.3 FP5 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, aka SPR PTHN95XNR3, a different vulnerability than CVE-2013-0591.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm lotus_domino 8.5.2.4
ibm lotus_domino 8.5.1.5
ibm lotus_inotes 8.5.1.0
ibm lotus_inotes 8.5.3.0
ibm lotus_domino 8.5.2.2
ibm lotus_domino 8.5.1.1
ibm lotus_domino 8.5.2.3
ibm lotus_domino 8.5.3.4
ibm lotus_inotes 8.5.0.0
ibm lotus_domino 8.5.1.4
ibm lotus_inotes 8.5.2.0
ibm lotus_domino 8.5.2.0
ibm lotus_domino 8.5.0.1
ibm lotus_domino 8.5.3.1
ibm lotus_domino 8.5.2.1
ibm lotus_domino 8.5.0
ibm lotus_domino 8.5.3.0
ibm lotus_domino 8.5.1
ibm lotus_domino 8.5.3.3
ibm lotus_domino 8.5.1.2
ibm lotus_domino 8.5.3.2
ibm lotus_domino 8.5.1.3
CVE-2013-0591 LOW

Cross-site scripting (XSS) vulnerability in iNotes 8.5.x in IBM Lotus Domino 8.5 before 8.5.3 FP5 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, aka SPR PTHN95XNR3, a different vulnerability than CVE-2013-0590.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm lotus_domino 8.5.2.4
ibm lotus_domino 8.5.1.5
ibm lotus_inotes 8.5.1.0
ibm lotus_inotes 8.5.3.0
ibm lotus_domino 8.5.2.2
ibm lotus_domino 8.5.1.1
ibm lotus_domino 8.5.2.3
ibm lotus_domino 8.5.3.4
ibm lotus_inotes 8.5.0.0
ibm lotus_domino 8.5.1.4
ibm lotus_inotes 8.5.2.0
ibm lotus_domino 8.5.2.0
ibm lotus_domino 8.5.0.1
ibm lotus_domino 8.5.3.1
ibm lotus_domino 8.5.2.1
ibm lotus_domino 8.5.0
ibm lotus_domino 8.5.3.0
ibm lotus_domino 8.5.1
ibm lotus_domino 8.5.3.3
ibm lotus_domino 8.5.1.2
ibm lotus_domino 8.5.3.2
ibm lotus_domino 8.5.1.3
CVE-2013-0592 LOW

Cross-site scripting (XSS) vulnerability in IBM iNotes before 8.5.3 Fix Pack 6 and 9.x before 9.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 83815.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm inotes 8.5.2.0
ibm inotes 8.5.0.0
ibm inotes 9.0.0.0
ibm inotes 8.5.1.0
ibm inotes 8.0.0.0
ibm inotes 8.5.3.0
ibm inotes 8.0.2.0
ibm inotes 8.0.1.0
CVE-2013-0593 HIGH

Unspecified vulnerability in the olch2x32 ActiveX control in IBM SPSS SamplePower 3.0 before 3.0-IM-S3SAMPC-WIN32-FP001 allows remote attackers to execute arbitrary code via unknown vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm spss_samplepower 3.0.0.0
CVE-2013-0594 MEDIUM

Open redirect vulnerability in IBM iNotes before 8.5.3 Fix Pack 6 and 9.x before 9.0.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. IBM X-Force ID: 83383.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-601,

Products Affected

Vendor Product Version
ibm inotes 8.5.2.0
ibm inotes 8.5.0.0
ibm inotes 9.0.0.0
ibm inotes 8.5.1.0
ibm inotes 8.0.0.0
ibm inotes 8.5.3.0
ibm inotes 8.0.2.0
ibm inotes 8.0.1.0
CVE-2013-0595 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in iNotes 8.5.x in IBM Lotus Domino 8.5 before 8.5.3 FP5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka SPR PTHN95XNR3.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm lotus_domino 8.5.2.4
ibm lotus_domino 8.5.1.5
ibm lotus_inotes 8.5.1.0
ibm lotus_inotes 8.5.3.0
ibm lotus_domino 8.5.2.2
ibm lotus_domino 8.5.1.1
ibm lotus_domino 8.5.2.3
ibm lotus_domino 8.5.3.4
ibm lotus_inotes 8.5.0.0
ibm lotus_domino 8.5.1.4
ibm lotus_inotes 8.5.2.0
ibm lotus_domino 8.5.2.0
ibm lotus_domino 8.5.0.1
ibm lotus_domino 8.5.3.1
ibm lotus_domino 8.5.2.1
ibm lotus_domino 8.5.0
ibm lotus_domino 8.5.3.0
ibm lotus_domino 8.5.1
ibm lotus_domino 8.5.3.3
ibm lotus_domino 8.5.1.2
ibm lotus_domino 8.5.3.2
ibm lotus_domino 8.5.1.3
CVE-2013-0596 MEDIUM

Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 6.1.0.14
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.1.0.45
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0
ibm websphere_application_server 6.1.0.35
ibm websphere_application_server 6.1
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.41
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 6.1.0.43
ibm websphere_application_server 6.1.0.39
ibm websphere_application_server 6.1.0.37
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.1.0.19
CVE-2013-0597 LOW

Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.29, 8.0 before 8.0.0.7, and 8.5 before 8.5.5.0, when OAuth is used, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 7.0
ibm websphere_application_server 8.0.0.5
ibm websphere_application_server 7.0.0.12
ibm websphere_application_server 8.5.0.2
ibm websphere_application_server 8.0.0.6
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 7.0.0.16
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 7.0.0.25
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 7.0.0.14
ibm websphere_application_server 7.0.0.22
ibm websphere_application_server 7.0.0.10
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 7.0.0.24
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 7.0.0.27
ibm websphere_application_server 7.0.0.18
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 7.0.0.4
ibm websphere_application_server 8.0.0.2
CVE-2013-0598 MEDIUM

Cross-site request forgery (CSRF) vulnerability in the Web Client in IBM Rational ClearQuest 7.1 before 7.1.2.12, 8.0 before 8.0.0.8, and 8.0.1 before 8.0.1.1 allows remote attackers to hijack the authentication of arbitrary users.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm rational_clearquest 7.1.2
ibm rational_clearquest 8.0.0.5
ibm rational_clearquest 8.0.0.7
ibm rational_clearquest 8.0.1
ibm rational_clearquest 7.1.1.1
ibm rational_clearquest 7.1.2.2
ibm rational_clearquest 7.1.1.3
ibm rational_clearquest 8.0.0.1
ibm rational_clearquest 8.0.0.3
ibm rational_clearquest 8.0
ibm rational_clearquest 7.1.1.5
ibm rational_clearquest 7.1.2.7
ibm rational_clearquest 7.1.2.1
ibm rational_clearquest 7.1.2.3
ibm rational_clearquest 8.0.0.2
ibm rational_clearquest 7.1.1.4
ibm rational_clearquest 7.1.2.11
ibm rational_clearquest 8.0.0.4
ibm rational_clearquest 7.1.2.5
ibm rational_clearquest 7.1.1.8
ibm rational_clearquest 7.1.2.6
ibm rational_clearquest 7.1.2.8
ibm rational_clearquest 7.1.1.6
ibm rational_clearquest 7.1.2.9
ibm rational_clearquest 7.1.1.7
ibm rational_clearquest 7.1.2.10
ibm rational_clearquest 7.1.1.2
ibm rational_clearquest 7.1.2.4
ibm rational_clearquest 8.0.0.6
CVE-2013-0599 MEDIUM

IBM Eclipse Help System (IEHS), as used in IBM Rational Directory Server 5.1.1 through 5.1.1.2 and 5.2 through 5.2.1 and other products, allows remote attackers to obtain sensitive information by providing a crafted parameter path and then reading the debug information associated with the 500 HTTP status code.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_directory_server 5.2
ibm rational_directory_server 5.2.0.2
ibm rational_directory_server *
ibm rational_directory_server 5.1.1.1
ibm rational_directory_server 5.2.0.1
ibm rational_directory_server 5.1.1
CVE-2013-0600 HIGH

Unspecified vulnerability on IBM WebSphere DataPower XC10 Appliance devices 2.0 and 2.1 through 2.1 FP3 allows remote attackers to bypass authentication and perform administrative actions via unknown vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_datapower_xc10_appliance_firmware 2.0.0.2
ibm websphere_datapower_xc10_appliance_firmware 2.1.0.3
ibm websphere_datapower_xc10_appliance_firmware 2.1.0.1
ibm websphere_datapower_xc10_appliance_firmware 2.1.0.2
ibm websphere_datapower_xc10_appliance_firmware 2.0.0.1
ibm websphere_datapower_xc10_appliance_firmware 2.1.0.0
ibm websphere_datapower_xc10_appliance_firmware 2.0.0.0
ibm websphere_datapower_xc10_appliance_firmware 2.0.0.3
ibm websphere_datapower_xc10_appliance -
CVE-2013-1777 HIGH

The JMX Remoting functionality in Apache Geronimo 3.x before 3.0.1, as used in IBM WebSphere Application Server (WAS) Community Edition 3.0.0.3 and other products, does not properly implement the RMI classloader, which allows remote attackers to execute arbitrary code by using the JMX connector to send a crafted serialized object.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-94,

Products Affected

Vendor Product Version
apache geronimo 3.0
ibm websphere_application_server 3.0.0.3
CVE-2013-2366 HIGH

Unspecified vulnerability in HP Business Process Monitor 9.13.1 patch 1 and 9.22 patch 1 allows remote attackers to execute arbitrary code and obtain sensitive information via unknown vectors, aka ZDI-CAN-1802.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm business_process_monitor 9.22
ibm business_process_monitor 9.13.1
CVE-2013-2950 LOW

CRLF injection vulnerability in IBM WebSphere Portal 6.1.0.x before 6.1.0.3 CF26, 6.1.5.x before 6.1.5 CF26, 7.0.0.x before 7.0.0.2 CF21, and 8.0.0.x through 8.0.0.1 CF5, when home substitution (aka uri.home.substitution) is enabled, allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-94,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.1
ibm websphere_portal 8.0.0.0
ibm websphere_portal 6.1.0.3
ibm websphere_portal 7.0.0.2
ibm websphere_portal 8.0
ibm websphere_portal 6.1.5.0
ibm websphere_portal 7.0.0.1
ibm websphere_portal 7.0.0.0
ibm websphere_portal 6.1.0.2
ibm websphere_portal 6.1.0.1
ibm websphere_portal 6.1.0.0
CVE-2013-2951 LOW

IBM WebSphere Portal 7.0.0.x and 8.0.0.x write passwords to a trace file when tracing is enabled for the Selfcare Portlet (Profile Management), which allows local users to obtain sensitive information by reading the file. IBM X-Force ID: 83621.

CVSS 2.0

Severity: LOW

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.1
ibm websphere_portal 8.0.0.0
ibm websphere_portal 7.0.0.2
ibm websphere_portal 7.0.0.1
ibm websphere_portal 7.0.0.0
CVE-2013-2953 MEDIUM

IBM InfoSphere Optim Data Growth for Oracle E-Business Suite 6.x, 7.x, and 9.x before 9.1.0.3 relies on the MD5 algorithm for signatures in X.509 certificates, which makes it easier for man-in-the-middle attackers to spoof SSL servers via a crafted certificate.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.4.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.3.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.5.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.3.3
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.3.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.1.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.2.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.4.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.2.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.1.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.3.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 9.1.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.5.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.1.2
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.2.2
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.3.2
CVE-2013-2954 MEDIUM

The login page in the Console in IBM InfoSphere Optim Data Growth for Oracle E-Business Suite 6.x, 7.x, and 9.x before 9.1.0.3 does not limit the number of incorrect authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attack.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.4.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.3.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.5.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.3.3
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.3.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.1.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.2.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.4.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.2.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.1.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.3.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 9.1.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.5.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.1.2
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.2.2
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.3.2
CVE-2013-2955 LOW

Cross-site scripting (XSS) vulnerability in IBM InfoSphere Optim Data Growth for Oracle E-Business Suite 6.x, 7.x, and 9.x before 9.1.0.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, related to a stored XSS issue.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.4.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.3.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.5.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.3.3
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.3.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.1.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.2.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.4.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.2.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.1.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.3.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 9.1.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.5.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.1.2
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.2.2
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.3.2
CVE-2013-2956 HIGH

SQL injection vulnerability in the Console in IBM InfoSphere Optim Data Growth for Oracle E-Business Suite 6.x, 7.x, and 9.x before 9.1.0.3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.4.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.3.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.5.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.3.3
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.3.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.1.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.2.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.4.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.2.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.1.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.3.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 9.1.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.5.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.1.2
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.2.2
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.3.2
CVE-2013-2957 LOW

Cross-site scripting (XSS) vulnerability in IBM InfoSphere Optim Data Growth for Oracle E-Business Suite 6.x, 7.x, and 9.x before 9.1.0.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.4.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.3.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.5.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.3.3
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.3.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.1.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.2.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.4.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.2.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.1.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.3.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 9.1.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.5.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.1.2
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.2.2
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.3.2
CVE-2013-2959 MEDIUM

The Console in IBM InfoSphere Optim Data Growth for Oracle E-Business Suite 6.x, 7.x, and 9.x before 9.1.0.3 does not provide an encrypted session for transmitting login credentials, which allows remote attackers to obtain sensitive information by sniffing the network.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.4.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.3.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.5.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.3.3
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.3.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.1.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.2.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.4.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.2.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.1.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.3.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 9.1.0
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.5.1
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.1.2
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 7.2.2
ibm infosphere_optim_data_growth_for_oracle_e-business_suite 6.3.2
CVE-2013-2960 MEDIUM

Buffer overflow in KDSMAIN in the Basic Services component in IBM Tivoli Monitoring (ITM) 6.2.0 through FP3, 6.2.1 through FP4, 6.2.2 through FP9, and 6.2.3 before FP3, as used in IBM Application Manager for Smart Business (formerly Tivoli Foundations Application Manager) 1.2.1 before 1.2.1.0-TIV-IAMSB-FP0004 and other products, allows remote attackers to cause a denial of service (segmentation fault) via a crafted http URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm tivoli_monitoring 6.2.1.4
ibm tivoli_monitoring 6.2.3
ibm tivoli_monitoring 6.2.0.2
ibm tivoli_monitoring 6.2.2.4
ibm tivoli_monitoring 6.2.2.5
ibm tivoli_monitoring 6.2.2.8
ibm tivoli_monitoring 6.2.3.1
ibm tivoli_monitoring 6.2.3.2
ibm tivoli_monitoring 6.2.2.9
ibm tivoli_monitoring 6.2.1.3
ibm tivoli_monitoring 6.2.2.3
ibm tivoli_monitoring 6.2.1.2
ibm tivoli_monitoring 6.2.2
ibm application_manager_for_smart_business 1.2.1
ibm tivoli_monitoring 6.2.0.3
ibm tivoli_monitoring 6.2.1
ibm tivoli_monitoring 6.2.0.1
ibm tivoli_monitoring 6.2.1.1
ibm tivoli_monitoring 6.2.2.7
ibm tivoli_monitoring 6.2.0
ibm tivoli_monitoring 6.2.2.1
ibm tivoli_monitoring 6.2.2.2
ibm tivoli_monitoring 6.2.2.6
CVE-2013-2961 MEDIUM

The internal web server in the Basic Services component in IBM Tivoli Monitoring (ITM) 6.2.0 through FP3, 6.2.1 through FP4, 6.2.2 through FP9, and 6.2.3 before FP3, as used in IBM Application Manager for Smart Business (formerly Tivoli Foundations Application Manager) 1.2.1 before 1.2.1.0-TIV-IAMSB-FP0004 and other products, allows remote attackers to perform unspecified redirection of HTTP requests, and bypass the proxy-server configuration, via crafted HTTP traffic.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm tivoli_monitoring 6.2.1.4
ibm tivoli_monitoring 6.2.3
ibm tivoli_monitoring 6.2.0.2
ibm tivoli_monitoring 6.2.2.4
ibm tivoli_monitoring 6.2.2.5
ibm tivoli_monitoring 6.2.2.8
ibm tivoli_monitoring 6.2.3.1
ibm tivoli_monitoring 6.2.3.2
ibm tivoli_monitoring 6.2.2.9
ibm tivoli_monitoring 6.2.1.3
ibm tivoli_monitoring 6.2.2.3
ibm tivoli_monitoring 6.2.1.2
ibm tivoli_monitoring 6.2.2
ibm application_manager_for_smart_business 1.2.1
ibm tivoli_monitoring 6.2.0.3
ibm tivoli_monitoring 6.2.1
ibm tivoli_monitoring 6.2.0.1
ibm tivoli_monitoring 6.2.1.1
ibm tivoli_monitoring 6.2.2.7
ibm tivoli_monitoring 6.2.0
ibm tivoli_monitoring 6.2.2.1
ibm tivoli_monitoring 6.2.2.2
ibm tivoli_monitoring 6.2.2.6
CVE-2013-2962 MEDIUM

Buffer overflow in the Launcher in IBM WebSphere Transformation Extender 8.4.x before 8.4.0.4 allows local users to cause a denial of service (process crash or Admin Console command-stream outage) via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm websphere_transformation_extender 8.4.0.1
ibm websphere_transformation_extender 8.4.0.3
ibm websphere_transformation_extender 8.4.0.0
ibm websphere_transformation_extender 8.4.0.2
CVE-2013-2964 HIGH

Buffer overflow in dsmtca in IBM Tivoli Storage Manager (TSM) through 5.5.4.0, 6.1.0 through 6.1.5.4, 6.2.0 through 6.2.4.7, and 6.3.0 through 6.3.0.17 on UNIX and Linux allows local users to gain privileges via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager 5.3.6.4
ibm tivoli_storage_manager 5.2
ibm tivoli_storage_manager 5.4.3.2
ibm tivoli_storage_manager 5.1.6
ibm tivoli_storage_manager 5.1.8
ibm tivoli_storage_manager 5.3.1
ibm tivoli_storage_manager 6.2.4.7
ibm tivoli_storage_manager 6.1.1
ibm tivoli_storage_manager 6.1.5
ibm tivoli_storage_manager 6.2.4
ibm tivoli_storage_manager 6.2.3
ibm tivoli_storage_manager 5.2.5.3
ibm tivoli_storage_manager 5.1.0
ibm tivoli_storage_manager *
ibm tivoli_storage_manager 5.4.3.3
ibm tivoli_storage_manager 6.3.0
ibm tivoli_storage_manager 5.2.5.1
ibm tivoli_storage_manager 5.3.2
ibm tivoli_storage_manager 5.5.1
ibm tivoli_storage_manager 5.3.5.1
ibm tivoli_storage_manager 5.2.1
ibm tivoli_storage_manager 5.1.7
ibm tivoli_storage_manager 5.4.2.3
ibm tivoli_storage_manager 5.5.0
ibm tivoli_storage_manager 6.1.3
ibm tivoli_storage_manager 5.4.3.0
ibm tivoli_storage_manager 5.2.2
ibm tivoli_storage_manager 5.3.6.5
ibm tivoli_storage_manager 5.3.2.4
ibm tivoli_storage_manager 5.1.9
ibm tivoli_storage_manager 6.2.1
ibm tivoli_storage_manager 6.1.0
ibm tivoli_storage_manager 5.4.2
ibm tivoli_storage_manager 5.3
ibm tivoli_storage_manager 5.4.1
ibm tivoli_storage_manager 5.1.5
ibm tivoli_storage_manager 5.4.4.0
ibm tivoli_storage_manager 5.3.4
ibm tivoli_storage_manager 5.3.6.6
ibm tivoli_storage_manager 5.2.5.2
ibm tivoli_storage_manager 6.1.2
ibm tivoli_storage_manager 5.2.0
ibm tivoli_storage_manager 5.3.6.3
ibm tivoli_storage_manager 5.1.1
ibm tivoli_storage_manager 5.2.8
ibm tivoli_storage_manager 5.3.0
ibm tivoli_storage_manager 5.4.2.2
ibm tivoli_storage_manager 5.2.9
ibm tivoli_storage_manager 6.3.0.17
ibm tivoli_storage_manager 5.3.6.1
ibm tivoli_storage_manager 5.4
ibm tivoli_storage_manager 5.3.6.2
ibm tivoli_storage_manager 5.2.4
ibm tivoli_storage_manager 6.2.0
ibm tivoli_storage_manager 5.1.10
ibm tivoli_storage_manager 5.3.3
ibm tivoli_storage_manager 5.5.3
ibm tivoli_storage_manager 6.1.4
ibm tivoli_storage_manager 5.4.0
ibm tivoli_storage_manager 5.4.2.4
ibm tivoli_storage_manager 5.5.2
ibm tivoli_storage_manager 5.2.7
ibm tivoli_storage_manager 6.2.2
ibm tivoli_storage_manager 6.1.5.4
CVE-2013-2967 MEDIUM

Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.7, and 8.5 before 8.5.5.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 7.0
ibm websphere_application_server 6.1.0.14
ibm websphere_application_server 7.0.0.12
ibm websphere_application_server 8.0.0.6
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 7.0.0.16
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0.35
ibm websphere_application_server 7.0.0.25
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 6.1.6
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 7.0.0.14
ibm websphere_application_server 7.0.0.22
ibm websphere_application_server 7.0.0.10
ibm websphere_application_server 6.1.3
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.0.39
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 6.1.7
ibm websphere_application_server 6.1.0.37
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 7.0.0.27
ibm websphere_application_server 7.0.0.18
ibm websphere_application_server 6.1.1
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 8.0.0.2
ibm websphere_application_server 8.0.0.5
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 8.5.0.2
ibm websphere_application_server 6.1.0.45
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 6.1.0
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 6.1
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.41
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 7.0.0.24
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.1.5
ibm websphere_application_server 6.1.14
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 6.1.0.43
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.1.13
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 7.0.0.4
CVE-2013-2968 MEDIUM

An unspecified buffer-read method in IBM Sterling Control Center (SCC) 5.2 before 5.2.0.9, 5.3 before 5.3.0.4, and 5.4 through 5.4.0.1 allows remote authenticated users to cause a denial of service via a large file that lacks end-of-line characters.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm sterling_control_center 5.3.0.3
ibm sterling_control_center 5.4.0.1
ibm sterling_control_center 5.3.0.1
ibm sterling_control_center 5.4.0
ibm sterling_control_center 5.2.0
ibm sterling_control_center 5.3.0
ibm sterling_control_center 5.3.0.2
CVE-2013-2969 LOW

Cross-site scripting (XSS) vulnerability in IBM Sterling Control Center (SCC) 5.2 before 5.2.0.9, 5.3 before 5.3.0.4, and 5.4 through 5.4.0.1 allows remote authenticated users to inject arbitrary web script or HTML via vectors involving invalid characters.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm sterling_control_center 5.3.0.3
ibm sterling_control_center 5.4.0.1
ibm sterling_control_center 5.3.0.1
ibm sterling_control_center 5.4.0
ibm sterling_control_center 5.2.0
ibm sterling_control_center 5.3.0
ibm sterling_control_center 5.3.0.2
CVE-2013-2970 MEDIUM

Unspecified vulnerability in IBM QRadar Security Information and Event Manager (SIEM) 7.x before 7.1 MR2 Patch 1 allows remote authenticated users to execute operating-system commands via unknown vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.0.0
ibm qradar_security_information_and_event_manager 7.1.0
ibm qradar_security_information_and_event_manager 7.0.1
CVE-2013-2972 HIGH

IBM WebSphere Cast Iron 6.3 allows remote attackers to bypass intended access restrictions via unspecified vectors. IBM X-Force ID: 83868.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm websphere_cast_iron_cloud_integration 6.1.0.0
ibm websphere_cast_iron_cloud_integration 6.3.0.0
ibm websphere_cast_iron_cloud_integration 6.0.0.0
CVE-2013-2974 HIGH

The BIRT viewer in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.1.x before 7.2.1.5 allows remote authenticated users to bypass authorization checks and obtain report-administration privileges, and consequently create or delete reports or conduct SQL injection attacks, via crafted parameters to the BIRT reporting URL.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm tivoli_application_dependency_discovery_manager 7.2.1.3
ibm tivoli_application_dependency_discovery_manager 7.2.1.4
ibm tivoli_application_dependency_discovery_manager 7.2.1.2
ibm tivoli_application_dependency_discovery_manager 7.2.1.1
CVE-2013-2976 LOW

The Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.7, and 8.5 before 8.5.5.0 does not properly perform caching, which allows local users to obtain sensitive information via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 7.0
ibm websphere_application_server 6.1.0.14
ibm websphere_application_server 7.0.0.12
ibm websphere_application_server 8.0.0.6
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 7.0.0.16
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0.35
ibm websphere_application_server 7.0.0.25
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 6.1.6
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 7.0.0.14
ibm websphere_application_server 7.0.0.22
ibm websphere_application_server 7.0.0.10
ibm websphere_application_server 6.1.3
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.0.39
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 6.1.7
ibm websphere_application_server 6.1.0.37
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 7.0.0.27
ibm websphere_application_server 7.0.0.18
ibm websphere_application_server 6.1.1
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 8.0.0.2
ibm websphere_application_server 8.0.0.5
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 8.5.0.2
ibm websphere_application_server 6.1.0.45
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 6.1.0
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 6.1
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.41
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 7.0.0.24
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.1.5
ibm websphere_application_server 6.1.14
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 6.1.0.43
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.1.13
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 7.0.0.4
CVE-2013-2977 MEDIUM

Integer overflow in IBM Notes 8.5.x before 8.5.3 FP4 Interim Fix 1 and 9.x before 9.0 Interim Fix 1 on Windows, and 8.5.x before 8.5.3 FP5 and 9.x before 9.0.1 on Linux, allows remote attackers to execute arbitrary code via a malformed PNG image in a previewed e-mail message, aka SPR NPEI96K82Q.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-189,

Products Affected

Vendor Product Version
ibm lotus_notes 8.5.1.5
ibm lotus_notes 8.5.1.1
ibm lotus_notes 8.5.2.0
ibm lotus_notes 8.5.2.2
ibm lotus_notes 9.0.0.0
ibm lotus_notes 8.5.3.4
ibm lotus_notes 8.5.1.4
ibm lotus_notes 8.5.1
ibm lotus_notes 8.5.1.2
ibm lotus_notes 8.5.3.2
ibm lotus_notes 8.5.1.3
ibm lotus_notes 8.5.2.1
ibm lotus_notes 8.5.0.0
ibm lotus_notes 8.5.2.3
ibm lotus_notes 8.5.0.1
ibm lotus_notes 8.5.3.3
ibm lotus_notes 8.5.1.0
ibm lotus_notes 8.5.3.1
ibm lotus_notes 8.5
ibm lotus_notes 8.5.3
CVE-2013-2978 LOW

Absolute path traversal vulnerability in the server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1, 10.1.1, 10.2, and 10.2.1 allows remote authenticated users to read files by leveraging the Report Author privilege, a different vulnerability than CVE-2013-2988.

CVSS 2.0

Severity: LOW

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm cognos_business_intelligence 10.2.1
ibm cognos_business_intelligence 10.2
ibm cognos_business_intelligence 10.1
ibm cognos_business_intelligence 8.4.1
ibm cognos_business_intelligence 10.1.1
CVE-2013-2979 MEDIUM

Directory traversal vulnerability in IBM Optim Performance Manager 4.1.1 and IBM InfoSphere Optim Performance Manager 5.x before 5.2 allows remote authenticated users to read arbitrary files via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm infosphere_optim_performance_manager 5.1.1.1
ibm infosphere_optim_performance_manager 5.1.0
ibm optim_performance_manager 4.1.1
ibm infosphere_optim_performance_manager 5.1.1.0
CVE-2013-2980 MEDIUM

Cross-site request forgery (CSRF) vulnerability in the Web Console in IBM Data Studio 3.1.0 and 3.1.1 allows remote attackers to hijack the authentication of arbitrary users for requests that access monitored database information.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm data_studio 3.1.1
ibm data_studio 3.1.0
CVE-2013-2981 MEDIUM

Directory traversal vulnerability in the Web Console in IBM Data Studio 3.1.0 and 3.1.1 allows remote attackers to read arbitrary files via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm data_studio 3.1.1
ibm data_studio 3.1.0
CVE-2013-2982 MEDIUM

IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to upload arbitrary files via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2
ibm sterling_b2b_integrator 5.1
ibm sterling_file_gateway 2.2
ibm sterling_file_gateway 2.1
CVE-2013-2983 LOW

Multiple cross-site scripting (XSS) vulnerabilities in IBM Sterling File Gateway 2.2 and Sterling B2B Integrator allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different issue than CVE-2013-0468.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator -
ibm sterling_file_gateway 2.2
CVE-2013-2984 MEDIUM

Directory traversal vulnerability in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allows remote authenticated users to read or modify files via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2
ibm sterling_b2b_integrator 5.1
ibm sterling_file_gateway 2.2
ibm sterling_file_gateway 2.1
CVE-2013-2985 MEDIUM

IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to obtain sensitive information about application implementation via unspecified vectors, a different vulnerability than CVE-2013-0463, CVE-2013-2987, CVE-2013-3020, CVE-2013-0568, CVE-2013-0475, and CVE-2013-0567.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2
ibm sterling_b2b_integrator 5.1
ibm sterling_file_gateway 2.2
ibm sterling_file_gateway 2.1
CVE-2013-2987 MEDIUM

IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to obtain sensitive information about application implementation via unspecified vectors, a different vulnerability than CVE-2013-0463, CVE-2013-2985, CVE-2013-3020, CVE-2013-0568, CVE-2013-0475, and CVE-2013-0567.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2
ibm sterling_b2b_integrator 5.1
ibm sterling_file_gateway 2.2
ibm sterling_file_gateway 2.1
CVE-2013-2988 LOW

Absolute path traversal vulnerability in the server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1, 10.1.1, 10.2, and 10.2.1 allows remote authenticated users to read files by leveraging the Report Author privilege, a different vulnerability than CVE-2013-2978.

CVSS 2.0

Severity: LOW

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm cognos_business_intelligence 10.2.1
ibm cognos_business_intelligence 10.2
ibm cognos_business_intelligence 10.1
ibm cognos_business_intelligence 8.4.1
ibm cognos_business_intelligence 10.1.1
CVE-2013-2989 MEDIUM

The file-copying functionality in IBM Sterling Connect:Direct 3.8.00, 4.0.00, and 4.1.0 for UNIX on AIX 6.1 through 7.1 uses incorrect privileges, which allows local users to bypass filesystem read permissions and write permissions by leveraging authentication to the Connect:Direct product.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm sterling_connect 4.1.0.0
ibm sterling_connect 3.8.00
ibm sterling_connect 4.0.00
CVE-2013-2992 MEDIUM

The Search component in IBM WebSphere Commerce 7.0 FP4 through FP6, in certain search-term association configurations, allows remote attackers to cause a denial of service via a crafted query.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm websphere_commerce 7.0.0.4
ibm websphere_commerce 7.0.0.6
ibm websphere_commerce 7.0.0.5
CVE-2013-2993 MEDIUM

IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.7 does not properly perform authentication for unspecified web services, which allows remote attackers to issue requests in the context of an arbitrary user's active session via unknown vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm websphere_commerce 6.0.0.6
ibm websphere_commerce 7.0.0.4
ibm websphere_commerce 7.0.0.6
ibm websphere_commerce 7.0.0.7
ibm websphere_commerce 6.0.0.11
ibm websphere_commerce 6.0.0.1
ibm websphere_commerce 6.0.0.2
ibm websphere_commerce 6.0.0.10
ibm websphere_commerce 7.0.0.3
ibm websphere_commerce 7.0.0.2
ibm websphere_commerce 7.0
ibm websphere_commerce 6.0.0.7
ibm websphere_commerce 6.0.0.8
ibm websphere_commerce 7.0.0.5
ibm websphere_commerce 6.0.0.3
ibm websphere_commerce 6.0.0.4
ibm websphere_commerce 6.0.0.9
ibm websphere_commerce 7.0.0.1
ibm websphere_commerce 6.0.0.5
CVE-2013-2994 MEDIUM

IBM WebSphere Commerce 7.0 Feature Pack 4 and Feature Pack 5 incorrectly maintains a valid session after unspecified interaction with REST services, which allows remote attackers to issue REST requests in the context of an arbitrary user's active session via unknown vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm websphere_commerce 7.0
CVE-2013-2997 LOW

IBM Security AppScan Enterprise before 8.7 does not invalidate the session context upon a logout action, which allows remote attackers to hijack sessions by leveraging an unattended workstation.

CVSS 2.0

Severity: LOW

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm security_appscan 8.0.0.1
ibm security_appscan 8.0.11
ibm security_appscan 5.6.0.0
ibm security_appscan 8.6.0.1
ibm security_appscan 6.0.0.0
ibm security_appscan 8.6.0.0
ibm security_appscan 6.0.2.0
ibm security_appscan 8.0.1.0
ibm security_appscan 8.0.1.1
ibm security_appscan 8.5.0.1
ibm security_appscan 8.0.0.2
ibm security_appscan 6.1.1.0
ibm security_appscan *
ibm security_appscan 8.0.0.0
ibm security_appscan 8.5.0.0
ibm security_appscan 6.0.1.0
CVE-2013-2998 LOW

frontcontroller.jsp in IBM Maximo Asset Management 7.x before 7.5.0.6 and SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2 allows remote authenticated users to obtain sensitive information via an invalid action_code.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm maximo_asset_management 7.1.1.9
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.5.0.1
ibm maximo_asset_management 7.1.1.10
ibm maximo_asset_management 7.1.1.1
ibm smartcloud_control_desk 7.5.0.0
ibm maximo_asset_management 7.1.1.12
ibm maximo_asset_management 7.5.0.3
ibm smartcloud_control_desk 7.0
ibm maximo_asset_management 7.5.0.0
ibm maximo_asset_management 7.1.1.7
ibm smartcloud_control_desk 7.5.1.1
ibm maximo_asset_management 7.5.0.4
ibm smartcloud_control_desk 7.5.0.2
ibm smartcloud_control_desk 7.5
ibm maximo_asset_management 7.5.0.5
ibm maximo_asset_management 7.1.1.2
ibm smartcloud_control_desk 7.5.0.1
ibm maximo_asset_management 7.1.1.6
ibm maximo_asset_management 7.1.1.5
ibm smartcloud_control_desk 7.5.1.0
ibm maximo_asset_management 7.1.1.11
ibm maximo_asset_management 7.1.2
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
CVE-2013-2999 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM InfoSphere Data Replication Dashboard 9.7 and 10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 84115.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm infosphere_data_replication_dashboard 9.7
ibm infosphere_data_replication_dashboard 10.1
CVE-2013-3000 HIGH

SQL injection vulnerability in IBM InfoSphere Data Replication Dashboard 9.7 and 10.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. IBM X-Force ID: 84116.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm infosphere_data_replication_dashboard 9.7
ibm infosphere_data_replication_dashboard 10.1
CVE-2013-3001 MEDIUM

Directory traversal vulnerability in IBM InfoSphere Data Replication Dashboard 9.7 and 10.1 allows remote attackers to read arbitrary files via unspecified vectors. IBM X-Force ID: 84127.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm infosphere_data_replication_dashboard 9.7
ibm infosphere_data_replication_dashboard 10.1
CVE-2013-3003 HIGH

Unspecified vulnerability in SOAP Gateway in IBM IMS Enterprise Suite 1.1, 2.1, and 2.2 allows remote authenticated users to execute arbitrary commands via unknown vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm ims_enterprise_suite 2.2
ibm ims_enterprise_suite 1.1
ibm ims_enterprise_suite 2.1
CVE-2013-3004 LOW

Directory traversal vulnerability in BIRT-Report Viewer in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.1.x and 7.2.x before 7.2.1.5 allows remote authenticated users to read arbitrary files via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm tivoli_application_dependency_discovery_manager 7.1.2.8
ibm tivoli_application_dependency_discovery_manager 7.2.0.5
ibm tivoli_application_dependency_discovery_manager 7.2.0.10
ibm tivoli_application_dependency_discovery_manager 7.2.1.2
ibm tivoli_application_dependency_discovery_manager 7.1.2.4
ibm tivoli_application_dependency_discovery_manager 7.1.2
ibm tivoli_application_dependency_discovery_manager 7.1.2.6
ibm tivoli_application_dependency_discovery_manager 7.2.0
ibm tivoli_application_dependency_discovery_manager 7.1.2.7
ibm tivoli_application_dependency_discovery_manager 7.2.0.6
ibm tivoli_application_dependency_discovery_manager 7.2.0.7
ibm tivoli_application_dependency_discovery_manager 7.2.0.4
ibm tivoli_application_dependency_discovery_manager 7.2.0.3
ibm tivoli_application_dependency_discovery_manager 7.2.0.2
ibm tivoli_application_dependency_discovery_manager 7.2.0.8
ibm tivoli_application_dependency_discovery_manager 7.2.1.3
ibm tivoli_application_dependency_discovery_manager 7.2.1.5
ibm tivoli_application_dependency_discovery_manager 7.2.1.1
ibm tivoli_application_dependency_discovery_manager 7.1.2.2
ibm tivoli_application_dependency_discovery_manager 7.2.0.9
ibm tivoli_application_dependency_discovery_manager 7.1.2.3
ibm tivoli_application_dependency_discovery_manager 7.1.2.5
ibm tivoli_application_dependency_discovery_manager 7.2.0.1
ibm tivoli_application_dependency_discovery_manager 7.2.1
ibm tivoli_application_dependency_discovery_manager 7.2.1.4
CVE-2013-3005 HIGH

The TFTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, when RBAC is enabled, allows remote authenticated users to bypass intended file-ownership restrictions, and read or overwrite arbitrary files, via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm aix 6.1
ibm aix 7.1
ibm vios 2.2.2.2
CVE-2013-3006 HIGH

Unspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 7 before 7 SR5 allows remote attackers to affect confidentiality, availability, and integrity via unknown vectors, a different vulnerability than CVE-2013-3008.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm java 7.0.0.0
ibm java 7.0.4.2
ibm java 7.0.2.0
ibm java 7.0.3.0
ibm java 7.0.1.0
ibm java 7.0.4.1
ibm java 7.0.4.0
CVE-2013-3007 HIGH

Unspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 6.0.1 before 6.0.1 SR6 and 7 before 7 SR5 allows remote attackers to affect confidentiality, availability, and integrity via unknown vectors, a different vulnerability than CVE-2013-3006.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm java 7.0.0.0
ibm java 7.0.4.2
ibm java 7.0.2.0
ibm java 7.0.3.0
ibm java 7.0.1.0
ibm java 7.0.4.1
ibm java 7.0.4.0
ibm java 6.0.1.0
CVE-2013-3008 HIGH

Unspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 7 before 7 SR5 allows remote attackers to affect confidentiality, availability, and integrity via unknown vectors, a different vulnerability than CVE-2013-3006.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm java 7.0.0.0
ibm java 7.0.4.2
ibm java 7.0.2.0
ibm java 7.0.3.0
ibm java 7.0.1.0
ibm java 7.0.4.1
ibm java 7.0.4.0
CVE-2013-3009 HIGH

The com.ibm.CORBA.iiop.ClientDelegate class in IBM Java 1.4.2 before 1.4.2 SR13-FP18, 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 improperly exposes the invoke method of the java.lang.reflect.Method class, which allows remote attackers to call setSecurityManager and bypass a sandbox protection mechanism via vectors related to the AccessController doPrivileged block.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm java 5.0.15.0
ibm java 1.4.2.13.2
ibm java 5.0.16.0
ibm java 1.4.2.13.12
ibm java 5.0.12.1
ibm java 6.0.0.0
ibm java 6.0.5.0
ibm java 1.4.2.13.10
ibm java 7.0.0.0
ibm java 5.0.12.2
ibm java 5.0.11.2
ibm java 1.4.2.13.6
ibm java 7.0.4.0
ibm java 5.0.11.1
ibm java 6.0.10.0
ibm java 1.4.2.13
ibm java 6.0.8.0
ibm java 6.0.9.2
ibm java 7.0.1.0
ibm java 1.4.2.13.5
ibm java 5.0.11.0
ibm java 7.0.2.0
ibm java 6.0.4.0
ibm java 7.0.3.0
ibm java 6.0.7.0
ibm java 6.0.12.0
ibm java 1.4.2.13.15
ibm java 6.0.3.0
ibm java 5.0.0.0
ibm java 5.0.12.5
ibm java 6.0.13.2
ibm java 5.0.12.4
ibm java 5.0.16.1
ibm java 6.0.9.0
ibm java 1.4.2.13.3
ibm java 5.0.16.2
ibm java 6.0.8.1
ibm java 7.0.4.1
ibm java 1.4.2.13.8
ibm java 1.4.2.13.17
ibm java 1.4.2
ibm java 6.0.11.0
ibm java 5.0.14.0
ibm java 6.0.1.0
ibm java 7.0.4.2
ibm java 6.0.10.1
ibm java 5.0.13.0
ibm java 1.4.2.13.11
ibm java 1.4.2.13.7
ibm java 1.4.2.13.13
ibm java 5.0.12.0
ibm java 1.4.2.13.1
ibm java 5.0.12.3
ibm java 6.0.6.0
ibm java 1.4.2.13.9
ibm java 1.4.2.13.14
ibm java 6.0.2.0
ibm java 1.4.2.13.4
ibm java 6.0.13.1
ibm java 6.0.13.0
ibm java 1.4.2.13.16
ibm java 6.0.9.1
CVE-2013-3010 HIGH

Unspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 6.0.1 before 6.0.1 SR6 and 7 before 7 SR5 allows remote attackers to affect confidentiality, availability, and integrity via unknown vectors, a different vulnerability than CVE-2013-3007.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm java 7.0.0.0
ibm java 7.0.4.2
ibm java 7.0.2.0
ibm java 7.0.3.0
ibm java 7.0.1.0
ibm java 7.0.4.1
ibm java 7.0.4.0
ibm java 6.0.1.0
CVE-2013-3011 HIGH

Unspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 1.4.2 before 1.4.2 SR13-FP18, 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 allows remote attackers to affect confidentiality, availability, and integrity via unknown vectors, a different vulnerability than CVE-2013-3009 and CVE-2013-3012.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm java 5.0.15.0
ibm java 1.4.2.13.2
ibm java 5.0.16.0
ibm java 1.4.2.13.12
ibm java 5.0.12.1
ibm java 6.0.0.0
ibm java 6.0.5.0
ibm java 1.4.2.13.10
ibm java 7.0.0.0
ibm java 5.0.12.2
ibm java 5.0.11.2
ibm java 1.4.2.13.6
ibm java 7.0.4.0
ibm java 5.0.11.1
ibm java 6.0.10.0
ibm java 1.4.2.13
ibm java 6.0.8.0
ibm java 6.0.9.2
ibm java 7.0.1.0
ibm java 1.4.2.13.5
ibm java 5.0.11.0
ibm java 7.0.2.0
ibm java 6.0.4.0
ibm java 7.0.3.0
ibm java 6.0.7.0
ibm java 6.0.12.0
ibm java 1.4.2.13.15
ibm java 6.0.3.0
ibm java 5.0.0.0
ibm java 5.0.12.5
ibm java 6.0.13.2
ibm java 5.0.12.4
ibm java 5.0.16.1
ibm java 6.0.9.0
ibm java 1.4.2.13.3
ibm java 5.0.16.2
ibm java 6.0.8.1
ibm java 7.0.4.1
ibm java 1.4.2.13.8
ibm java 1.4.2.13.17
ibm java 1.4.2
ibm java 6.0.11.0
ibm java 5.0.14.0
ibm java 6.0.1.0
ibm java 7.0.4.2
ibm java 6.0.10.1
ibm java 5.0.13.0
ibm java 1.4.2.13.11
ibm java 1.4.2.13.7
ibm java 1.4.2.13.13
ibm java 5.0.12.0
ibm java 1.4.2.13.1
ibm java 5.0.12.3
ibm java 6.0.6.0
ibm java 1.4.2.13.9
ibm java 1.4.2.13.14
ibm java 6.0.2.0
ibm java 1.4.2.13.4
ibm java 6.0.13.1
ibm java 6.0.13.0
ibm java 1.4.2.13.16
ibm java 6.0.9.1
CVE-2013-3012 HIGH

Unspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 1.4.2 before 1.4.2 SR13-FP18, 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 allows remote attackers to affect confidentiality, availability, and integrity via unknown vectors, a different vulnerability than CVE-2013-3009 and CVE-2013-3011.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm java 5.0.15.0
ibm java 1.4.2.13.2
ibm java 5.0.16.0
ibm java 1.4.2.13.12
ibm java 5.0.12.1
ibm java 6.0.0.0
ibm java 6.0.5.0
ibm java 1.4.2.13.10
ibm java 7.0.0.0
ibm java 5.0.12.2
ibm java 5.0.11.2
ibm java 1.4.2.13.6
ibm java 7.0.4.0
ibm java 5.0.11.1
ibm java 6.0.10.0
ibm java 1.4.2.13
ibm java 6.0.8.0
ibm java 6.0.9.2
ibm java 7.0.1.0
ibm java 1.4.2.13.5
ibm java 5.0.11.0
ibm java 7.0.2.0
ibm java 6.0.4.0
ibm java 7.0.3.0
ibm java 6.0.7.0
ibm java 6.0.12.0
ibm java 1.4.2.13.15
ibm java 6.0.3.0
ibm java 5.0.0.0
ibm java 5.0.12.5
ibm java 6.0.13.2
ibm java 5.0.12.4
ibm java 5.0.16.1
ibm java 6.0.9.0
ibm java 1.4.2.13.3
ibm java 5.0.16.2
ibm java 6.0.8.1
ibm java 7.0.4.1
ibm java 1.4.2.13.8
ibm java 1.4.2.13.17
ibm java 1.4.2
ibm java 6.0.11.0
ibm java 5.0.14.0
ibm java 6.0.1.0
ibm java 7.0.4.2
ibm java 6.0.10.1
ibm java 5.0.13.0
ibm java 1.4.2.13.11
ibm java 1.4.2.13.7
ibm java 1.4.2.13.13
ibm java 5.0.12.0
ibm java 1.4.2.13.1
ibm java 5.0.12.3
ibm java 6.0.6.0
ibm java 1.4.2.13.9
ibm java 1.4.2.13.14
ibm java 6.0.2.0
ibm java 1.4.2.13.4
ibm java 6.0.13.1
ibm java 6.0.13.0
ibm java 1.4.2.13.16
ibm java 6.0.9.1
CVE-2013-3016 MEDIUM

IBM WebSphere Portal 6.1, 7.0, and 8.0 allows remote attackers to access the user directory via a crafted request for a servlet, related to the serveServletsByClassnameEnabled setting.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.0
ibm websphere_portal 8.0
ibm websphere_portal 7.0.0.0
ibm websphere_portal 6.1.0.0
CVE-2013-3017 MEDIUM

IBM Tivoli Application Dependency Discovery Manager (TADDM) before 7.2.1.5 and 7.2.x before 7.2.2 make it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging support for weak SSL ciphers. IBM X-Force ID: 84353.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm tivoli_application_dependency_discovery_manager 7.1.2
ibm tivoli_application_dependency_discovery_manager *
CVE-2013-3018 MEDIUM

The AXIS webapp in deploy-tomcat/axis in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.1.2 and 7.2.0 through 7.2.1.4 allows remote attackers to obtain sensitive configuration information via a direct request, as demonstrated by happyaxis.jsp. IBM X-Force ID: 84354.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm tivoli_application_dependency_discovery_manager 7.1.2
ibm tivoli_application_dependency_discovery_manager *
CVE-2013-3020 MEDIUM

IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to obtain sensitive information about application implementation via unspecified vectors, a different vulnerability than CVE-2013-0463, CVE-2013-2985, CVE-2013-2987, CVE-2013-0568, CVE-2013-0475, and CVE-2013-0567.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2
ibm sterling_b2b_integrator 5.1
ibm sterling_file_gateway 2.2
ibm sterling_file_gateway 2.1
CVE-2013-3023 MEDIUM

IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.1.2 and 7.2.0 through 7.2.1.4 might allow remote attackers to obtain sensitive information about Tomcat credentials by sniffing the network for a session in which HTTP is used. IBM X-Force ID: 84361.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm tivoli_application_dependency_discovery_manager 7.1.2
ibm tivoli_application_dependency_discovery_manager *
CVE-2013-3024 HIGH

IBM WebSphere Application Server (WAS) 8.5 through 8.5.0.2 on UNIX allows local users to gain privileges by leveraging improper process initialization. IBM X-Force ID: 84362.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_application_server *
CVE-2013-3025 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in IBM Rational Focal Point 6.5.x and 6.6.x before 6.6.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_focal_point 6.5.2.2
ibm rational_focal_point 6.6
ibm rational_focal_point 6.5.2.1
ibm rational_focal_point 6.5.2.3
ibm rational_focal_point 6.5.2
CVE-2013-3026 HIGH

Buffer overflow in the Lotus Quickr for Domino ActiveX control in qp2.cab in IBM Lotus Quickr 8.1 before FP 8.1.0.32-001a, 8.2 before FP 8.2.0.28-001a, and 8.5.1 before FP 8.5.1.39-002a for Domino allows remote attackers to execute arbitrary code via a crafted web site.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm lotus_quickr_for_domino 8.1.0
ibm lotus_quickr_for_domino 8.5.1
ibm lotus_quickr_for_domino 8.2.0
CVE-2013-3027 HIGH

Integer overflow in the DWA9W ActiveX control in iNotes in IBM Domino 9.0 before IF3 allows remote attackers to execute arbitrary code via a crafted web page, aka SPR PTHN97XHFW.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-189,

Products Affected

Vendor Product Version
ibm lotus_domino 9.0.0.0
CVE-2013-3028 MEDIUM

Multiple buffer overflows in mqm programs in IBM WebSphere MQ 7.0.x before 7.0.1.11, 7.1.x before 7.1.0.3, and 7.5.x before 7.5.0.2 on non-Windows platforms allow local users to gain privileges via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm websphere_mq 7.0.1.0
ibm websphere_mq 7.5.0.1
ibm websphere_mq 7.0.0.2
ibm websphere_mq 7.0.1.7
ibm websphere_mq 7.0.1.5
ibm websphere_mq 7.0.1.1
ibm websphere_mq 7.0
ibm websphere_mq 7.0.1.3
ibm websphere_mq 7.5
ibm websphere_mq 7.1
ibm websphere_mq 7.0.1.8
ibm websphere_mq 7.0.1.10
ibm websphere_mq 7.0.1.4
ibm websphere_mq 7.0.1.2
ibm websphere_mq 7.1.0.1
ibm websphere_mq 7.0.1.9
ibm websphere_mq 7.0.0.1
ibm websphere_mq 7.1.0.2
ibm websphere_mq 7.0.1.6
CVE-2013-3029 MEDIUM

Cross-site request forgery (CSRF) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.31, 8.0 before 8.0.0.7, and 8.5 before 8.5.5.1 allows remote attackers to hijack the authentication of arbitrary users for requests that insert cross-site scripting (XSS) sequences.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 7.0
ibm websphere_application_server 6.1.0.14
ibm websphere_application_server 7.0.0.12
ibm websphere_application_server 8.0.0.6
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 7.0.0.16
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0.35
ibm websphere_application_server 7.0.0.25
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 6.1.6
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 7.0.0.14
ibm websphere_application_server 7.0.0.22
ibm websphere_application_server 7.0.0.10
ibm websphere_application_server 6.1.3
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.0.39
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 6.1.7
ibm websphere_application_server 6.1.0.37
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 7.0.0.27
ibm websphere_application_server 7.0.0.18
ibm websphere_application_server 6.1.1
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 8.0.0.2
ibm websphere_application_server 8.0.0.5
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 8.5.0.2
ibm websphere_application_server 6.1.0.45
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 6.1.0
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 6.1
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.41
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 7.0.0.29
ibm websphere_application_server 7.0.0.24
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.1.5
ibm websphere_application_server 6.1.14
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 6.1.0.43
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.1.13
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 7.0.0.4
CVE-2013-3030 MEDIUM

The servlet gateway in IBM Cognos Business Intelligence 8.4.1 before IF3, 10.1.0 before IF4, 10.1.1 before IF4, 10.2.0 before IF4, 10.2.1 before IF2, and 10.2.1.1 before IF1 allows remote attackers to cause a denial of service (temporary gateway outage) via crafted HTTP requests.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm cognos_business_intelligence 10.2.1
ibm cognos_business_intelligence 10.2
ibm cognos_business_intelligence 10.1
ibm cognos_business_intelligence 10.2.1.1
ibm cognos_business_intelligence 8.4.1
ibm cognos_business_intelligence 10.1.1
CVE-2013-3031 LOW

A SQL stored procedure in the Universal Cache component in IBM solidDB 6.0.x before 6.0.1070, 6.3.x before 6.3.0.56, 6.5.x before 6.5.0.12, and 7.0.x before 7.0.0.4 allows remote authenticated users to cause a denial of service (uninitialized-memory access and daemon crash) via a call that includes named arguments and default parameter values, but does not include all of the expected arguments.

CVSS 2.0

Severity: LOW

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm soliddb 6.3.52
ibm soliddb 6.3.49
ibm soliddb 6.3.39
ibm soliddb 6.5.0.7
ibm soliddb 6.3.38
ibm soliddb 6.3.40
ibm soliddb 6.5.0.1
ibm soliddb 6.3.48
ibm soliddb 7.0.0.3
ibm soliddb 6.5.0.2
ibm soliddb 6.3.54
ibm soliddb 6.3.53
ibm soliddb 6.5.0.4
ibm soliddb 6.3.33
ibm soliddb 6.0.1068
ibm soliddb 6.3.34
ibm soliddb 6.5.11
ibm soliddb 6.5.0.6
ibm soliddb 6.0
ibm soliddb 6.5.0.8
ibm soliddb 6.5.10
ibm soliddb 6.3.42
ibm soliddb 6.0.1067
ibm soliddb 6.5.0.0
ibm soliddb 6.5.09
ibm soliddb 6.3.47
ibm soliddb 7.0.0.1
ibm soliddb 6.0.1061
ibm soliddb 6.5.0.5
ibm soliddb 6.3.37
ibm soliddb 6.3.55
ibm soliddb 6.5.0.3
ibm soliddb 6.0.1064
ibm soliddb 6.3.41
ibm soliddb 6.0.1066
ibm soliddb 6.3.44
ibm soliddb 6.0.1065
ibm soliddb 7.0.0.2
ibm soliddb 6.0.1060
ibm soliddb 7.0.0.0
ibm soliddb 6.0.1069
CVE-2013-3032 MEDIUM

Cross-site scripting (XSS) vulnerability in the MIME e-mail functionality in iNotes in IBM Domino 9.0 before IF3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka SPR PTHN986NAA.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm lotus_domino 8.5.2.4
ibm lotus_domino 8.5.1.5
ibm lotus_domino 8.5.2.2
ibm lotus_domino 8.5.1.1
ibm lotus_domino 8.5.2.3
ibm lotus_domino 8.5.1.4
ibm lotus_domino 8.5.2.0
ibm lotus_domino 8.5.0.1
ibm lotus_domino 8.5.3.1
ibm lotus_domino 8.5.2.1
ibm lotus_domino 8.5.0
ibm lotus_domino 8.5.3.0
ibm lotus_domino 8.5.1
ibm lotus_domino 9.0.0.0
ibm lotus_domino 8.5.1.2
ibm lotus_domino 8.5.3.2
ibm lotus_domino 8.5.1.3
CVE-2013-3033 MEDIUM

SQL injection vulnerability in the server component in IBM Tivoli Remote Control 5.1.2 before 5.1.2-TIV-TRC512-IF0015 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm tivoli_remote_control 5.1.2
CVE-2013-3034 LOW

Cross-site scripting (XSS) vulnerability in IBM InfoSphere Information Server through 8.5 FP3, 8.7 through FP2, and 9.1 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to the web console.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm infosphere_information_server 8.1
ibm infosphere_information_server 9.1
ibm infosphere_information_server *
ibm infosphere_information_server 8.7
CVE-2013-3035 HIGH

The IPv6 implementation in the inet subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, allows remote attackers to cause a denial of service (system hang) via a crafted packet to an IPv6 interface.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm aix 6.1
ibm vios 2.2.1.4
ibm aix 7.1
CVE-2013-3036 MEDIUM

Open redirect vulnerability in IBM Rational Requirements Composer before 4.0.4 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm rational_requirements_composer *
ibm rational_requirements_composer 4.0.2
ibm rational_requirements_composer 4.0.0
ibm rational_requirements_composer 4.0.1
CVE-2013-3037 MEDIUM

Unspecified vulnerability in IBM Rational Requirements Composer before 4.0.4 makes it easier for local users to gain privileges via unknown vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm rational_requirements_composer *
ibm rational_requirements_composer 4.0.2
ibm rational_requirements_composer 4.0.0
ibm rational_requirements_composer 4.0.1
CVE-2013-3038 MEDIUM

Unspecified vulnerability in IBM Rational Requirements Composer before 4.0.4 makes it easier for remote attackers to discover credentials via unknown vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm rational_requirements_composer *
ibm rational_requirements_composer 4.0.2
ibm rational_requirements_composer 4.0.0
ibm rational_requirements_composer 4.0.1
CVE-2013-3039 MEDIUM

IBM Rational Requirements Composer before 4.0.4 does not properly perform authentication, which has unspecified impact and remote attack vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm rational_requirements_composer *
ibm rational_requirements_composer 4.0.2
ibm rational_requirements_composer 4.0.0
ibm rational_requirements_composer 4.0.1
CVE-2013-3040 MEDIUM

IBM InfoSphere Information Server through 8.5 FP3, 8.7 through FP2, and 9.1 produces login-failure messages indicating whether the username or password is incorrect, which allows remote attackers to enumerate user accounts via a brute-force attack.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm infosphere_information_server 8.5.0.2
ibm infosphere_information_server 8.5.0.3
ibm infosphere_information_server 8.7.0.1
ibm infosphere_information_server 8.5.0.1
ibm infosphere_information_server 8.5
ibm infosphere_information_server 9.1
ibm infosphere_information_server 8.7
ibm infosphere_information_server 8.7.0.2
CVE-2013-3041 MEDIUM

The Web Client in IBM Rational ClearQuest 7.1 before 7.1.2.12, 8.0 before 8.0.0.8, and 8.0.1 before 8.0.1.1 allows remote attackers to obtain sensitive information from the client-server data stream via unspecified vectors associated with a "JSON hijacking attack."

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm rational_clearquest 7.1.2
ibm rational_clearquest 7.1.0.2
ibm rational_clearquest 8.0.0.5
ibm rational_clearquest 8.0.0.7
ibm rational_clearquest 8.0.1
ibm rational_clearquest 7.1.1.1
ibm rational_clearquest 7.1.2.2
ibm rational_clearquest 7.1.1.3
ibm rational_clearquest 8.0.0.1
ibm rational_clearquest 8.0.0.3
ibm rational_clearquest 7.1
ibm rational_clearquest 8.0
ibm rational_clearquest 7.1.1.5
ibm rational_clearquest 7.1.2.7
ibm rational_clearquest 7.1.2.1
ibm rational_clearquest 7.1.1.9
ibm rational_clearquest 7.1.2.3
ibm rational_clearquest 8.0.0.2
ibm rational_clearquest 7.1.1.4
ibm rational_clearquest 7.1.2.11
ibm rational_clearquest 8.0.0.4
ibm rational_clearquest 7.1.2.5
ibm rational_clearquest 7.1.1.8
ibm rational_clearquest 7.1.2.6
ibm rational_clearquest 7.1.2.8
ibm rational_clearquest 7.1.1.6
ibm rational_clearquest 7.1.0.1
ibm rational_clearquest 7.1.2.9
ibm rational_clearquest 7.1.1.7
ibm rational_clearquest 7.1.2.10
ibm rational_clearquest 7.1.1.2
ibm rational_clearquest 7.1.2.4
ibm rational_clearquest 7.1.1
ibm rational_clearquest 8.0.0.6
CVE-2013-3042 LOW

Directory traversal vulnerability in the server in IBM Rational Software Architect Design Manager and Rhapsody Design Manager 3.x and 4.x before 4.0.5 allows local users to read arbitrary files via vectors involving temporary files.

CVSS 2.0

Severity: LOW

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm rational_software_architect_design_manager 3.0.0.1
ibm rhapsody_design_manager 4.0.3
ibm rhapsody_design_manager 3.0.1
ibm rational_software_architect_design_manager 3.0.1
ibm rhapsody_design_manager 3.0.0
ibm rhapsody_design_manager 4.0.1
ibm rational_software_architect_design_manager 4.0.2
ibm rational_software_architect_design_manager 4.0.3
ibm rational_software_architect_design_manager 3.0.0
ibm rational_software_architect_design_manager 4.0.0
ibm rhapsody_design_manager 4.0.2
ibm rhapsody_design_manager 4.0.4
ibm rhapsody_design_manager 3.0.0.1
ibm rhapsody_design_manager 4.0.0
ibm rational_software_architect_design_manager 4.0.1
ibm rational_software_architect_design_manager 4.0.4
CVE-2013-3043 LOW

Directory traversal vulnerability in the client in IBM Rational Software Architect Design Manager and Rhapsody Design Manager 3.x and 4.x before 4.0.5 allows local users to read arbitrary files via vectors involving temporary files.

CVSS 2.0

Severity: LOW

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm rational_software_architect_design_manager 3.0.0.1
ibm rhapsody_design_manager 4.0.3
ibm rhapsody_design_manager 3.0.1
ibm rational_software_architect_design_manager 3.0.1
ibm rhapsody_design_manager 3.0.0
ibm rhapsody_design_manager 4.0.1
ibm rational_software_architect_design_manager 4.0.2
ibm rational_software_architect_design_manager 4.0.3
ibm rational_software_architect_design_manager 3.0.0
ibm rational_software_architect_design_manager 4.0.0
ibm rhapsody_design_manager 4.0.2
ibm rhapsody_design_manager 4.0.4
ibm rhapsody_design_manager 3.0.0.1
ibm rhapsody_design_manager 4.0.0
ibm rational_software_architect_design_manager 4.0.1
ibm rational_software_architect_design_manager 4.0.4
CVE-2013-3044 LOW

The Enterprise Meeting Server in IBM Lotus Sametime 8.5.2 and 8.5.2.1 allows remote authenticated users to spoof the origin of chat messages, or compose anonymous chat messages, by leveraging meeting-attendance privileges.

CVSS 2.0

Severity: LOW

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm lotus_sametime 8.5.2
ibm lotus_sametime 8.5.2.1
CVE-2013-3045 LOW

The Enterprise Meeting Server in IBM Lotus Sametime 8.5.2 and 8.5.2.1 allows remote authenticated users to share crafted links via the Library function.

CVSS 2.0

Severity: LOW

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm lotus_sametime 8.5.2
ibm lotus_sametime 8.5.2.1
CVE-2013-3046 MEDIUM

The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 does not send the HSTS Strict-Transport-Security header, which makes it easier for man-in-the-middle attackers to hijack sessions or obtain sensitive information by leveraging the presence of HTTP requests.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm sametime 8.5.0.0
ibm sametime 8.5.2.0
ibm sametime 8.5.2.1
ibm sametime 9.0.0.1
ibm sametime 8.0.0.0
ibm sametime 8.0.2.0
ibm sametime 8.0.2.1
ibm sametime 8.5.1.1
ibm sametime 9.0.0.0
ibm sametime 8.0.1.1
ibm sametime 8.5.1.0
ibm sametime 8.0.1.0
CVE-2013-3047 MEDIUM

IBM Maximo Asset Management 7.1 before 7.1.1.12 and 7.5 before 7.5.0.5 allows remote authenticated users to gain privileges via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm maximo_asset_management 7.1.1.9
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management 7.5.0.1
ibm maximo_asset_management 7.1.1.10
ibm maximo_asset_management 7.1.1.1
ibm maximo_asset_management 7.5.0.0
ibm maximo_asset_management 7.1.1.7
ibm maximo_asset_management 7.5.0.4
ibm maximo_asset_management 7.1.1.2
ibm maximo_asset_management 7.1.1.6
ibm maximo_asset_management 7.1.1.5
ibm maximo_asset_management 7.5.0.3
ibm maximo_asset_management 7.1.1.11
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
CVE-2013-3048 LOW

Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.12, and 7.5 before 7.5.0.3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm maximo_asset_management 6.2.1
ibm maximo_asset_management 7.1.1.9
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.5.0.1
ibm maximo_asset_management 6.2.6
ibm maximo_asset_management 6.2.7
ibm maximo_asset_management 6.2.6.1
ibm maximo_asset_management 7.1.1.10
ibm maximo_asset_management 6.2.3
ibm maximo_asset_management 6.2.5
ibm maximo_asset_management 7.1.1.1
ibm maximo_asset_management 7.5.0.0
ibm maximo_asset_management 7.1.1.7
ibm maximo_asset_management 6.2
ibm maximo_asset_management 6.2.2
ibm maximo_asset_management 7.1.1.2
ibm maximo_asset_management 7.1.1.6
ibm maximo_asset_management 7.1.1.5
ibm maximo_asset_management 7.1.1.11
ibm maximo_asset_management 6.2.4
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
CVE-2013-3049 MEDIUM

IBM Maximo Asset Management 7.1 through 7.1.1.12 and 7.5 before 7.5.0.5 allows remote authenticated users to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2013-3971.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm maximo_asset_management 7.1.1.9
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.5.0.1
ibm maximo_asset_management 7.1.1.10
ibm maximo_asset_management 7.1.1.1
ibm maximo_asset_management 7.5.0.0
ibm maximo_asset_management 7.1.1.7
ibm maximo_asset_management 7.5.0.4
ibm maximo_asset_management 7.1.1.2
ibm maximo_asset_management 7.1.1.12
ibm maximo_asset_management 7.1.1.6
ibm maximo_asset_management 7.1.1.5
ibm maximo_asset_management 7.5.0.3
ibm maximo_asset_management 7.1.1.11
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
CVE-2013-3475 HIGH

Stack-based buffer overflow in db2aud in the Audit Facility in IBM DB2 and DB2 Connect 9.1, 9.5, 9.7, 9.8, and 10.1, as used in Smart Analytics System 7600 and other products, allows local users to gain privileges via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm db2 9.1
ibm db2_connect 10.1
ibm db2_connect 9.1
ibm db2_connect 9.5
ibm db2 9.5
ibm db2 10.1
ibm db2 9.8
ibm db2_connect 9.8
ibm db2_connect 9.7
ibm smart_analytics_system_7600 -
ibm db2 9.7
CVE-2013-3971 MEDIUM

IBM Maximo Asset Management 7.1 through 7.1.1.12 and 7.5 before 7.5.0.5 allows remote authenticated users to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2013-3049.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm maximo_asset_management 7.1.1.9
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.5.0.1
ibm maximo_asset_management 7.1.1.10
ibm maximo_asset_management 7.1.1.1
ibm maximo_asset_management 7.5.0.0
ibm maximo_asset_management 7.1.1.7
ibm maximo_asset_management 7.5.0.4
ibm maximo_asset_management 7.1.1.2
ibm maximo_asset_management 7.1.1.12
ibm maximo_asset_management 7.1.1.6
ibm maximo_asset_management 7.1.1.5
ibm maximo_asset_management 7.5.0.3
ibm maximo_asset_management 7.1.1.11
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
CVE-2013-3972 MEDIUM

IBM Maximo Asset Management 7.1 before 7.1.1.12 and 7.5 before 7.5.0.5 allows remote authenticated users to obtain sensitive information via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm maximo_asset_management 7.1.1.9
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.5.0.1
ibm maximo_asset_management 7.1.1.10
ibm maximo_asset_management 7.1.1.1
ibm maximo_asset_management 7.5.0.0
ibm maximo_asset_management 7.1.1.7
ibm maximo_asset_management 7.5.0.4
ibm maximo_asset_management 7.1.1.2
ibm maximo_asset_management 7.1.1.6
ibm maximo_asset_management 7.1.1.5
ibm maximo_asset_management 7.5.0.3
ibm maximo_asset_management 7.1.1.11
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
CVE-2013-3973 MEDIUM

SQL injection vulnerability in IBM Maximo Asset Management 7.1 before 7.1.1.12 and 7.5 before 7.5.0.5 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm maximo_asset_management 7.1.1.9
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.5.0.1
ibm maximo_asset_management 7.1.1.10
ibm maximo_asset_management 7.1.1.1
ibm maximo_asset_management 7.5.0.0
ibm maximo_asset_management 7.1.1.7
ibm maximo_asset_management 7.5.0.4
ibm maximo_asset_management 7.1.1.2
ibm maximo_asset_management 7.1.1.6
ibm maximo_asset_management 7.1.1.5
ibm maximo_asset_management 7.5.0.3
ibm maximo_asset_management 7.1.1.11
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
CVE-2013-3975 MEDIUM

Unspecified vulnerability in the Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to discover user names, full names, and e-mail addresses via a search.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm sametime 8.5.0.0
ibm sametime 8.5.2.0
ibm sametime 8.5.2.1
ibm sametime 9.0.0.1
ibm sametime 8.0.0.0
ibm sametime 8.0.2.0
ibm sametime 8.0.2.1
ibm sametime 8.5.1.1
ibm sametime 9.0.0.0
ibm sametime 8.0.1.1
ibm sametime 8.5.1.0
ibm sametime 8.0.1.0
CVE-2013-3976 LOW

The (1) Data Protection for Exchange component 6.1 before 6.1.3.4 and 6.3 before 6.3.1 in IBM Tivoli Storage Manager for Mail and the (2) FlashCopy Manager for Exchange component 2.2 and 3.1 before 3.1.1 in IBM Tivoli Storage FlashCopy Manager do not properly constrain mailbox contents during certain PST restore operations, which allows remote authenticated users to read the personal e-mail of other users in opportunistic circumstances by launching an e-mail client after an administrator performs a multiple-mailbox restore.

CVSS 2.0

Severity: LOW

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm flashcopy_manager 3.1
ibm tivoli_storage_flashcopy_manager -
ibm tivoli_storage_manager_for_mail -
ibm flashcopy_manager 2.1
ibm data_protection 6.1
ibm data_protection 6.3
ibm flashcopy_manager 2.2
CVE-2013-3977 MEDIUM

The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to determine which meeting rooms are owned by a user by leveraging knowledge of valid user names.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm sametime 8.5.0.0
ibm sametime 8.5.2.0
ibm sametime 8.5.2.1
ibm sametime 9.0.0.1
ibm sametime 8.0.0.0
ibm sametime 8.0.2.0
ibm sametime 8.0.2.1
ibm sametime 8.5.1.1
ibm sametime 9.0.0.0
ibm sametime 8.0.1.1
ibm sametime 8.5.1.0
ibm sametime 8.0.1.0
CVE-2013-3978 MEDIUM

The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 does not send the appropriate HTTP response headers to prevent unwanted caching by a web browser, which allows remote attackers to obtain sensitive information by leveraging an unattended workstation.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm sametime 8.5.2.0
ibm sametime 8.5.2.1
ibm sametime 9.0.0.1
ibm sametime 9.0.0.0
CVE-2013-3979 LOW

Multiple cross-site scripting (XSS) vulnerabilities in the help pages in Web\Content\Help\ in the Web Client in IBM Cognos Command Center (aka Star Command Center or Star Analytics) before 10.1, when Internet Explorer is used, allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm star_command_center 3.0.1
ibm star_command_center 3.0.6
ibm star_command_center 3.0.0
ibm star_command_center 3.0.5
ibm star_command_center 3.0.3
ibm star_command_center 3.0.4
ibm star_command_center 1.6.1
ibm star_command_center 3.0.2
ibm star_command_center 3.0.7
CVE-2013-3980 MEDIUM

The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to cause a denial of service (room unusability) by generating a large number of fictitious users to enter a meeting room.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm sametime 8.5.0.0
ibm sametime 8.5.2.0
ibm sametime 8.5.2.1
ibm sametime 9.0.0.1
ibm sametime 8.0.0.0
ibm sametime 8.0.2.0
ibm sametime 8.0.2.1
ibm sametime 8.5.1.1
ibm sametime 9.0.0.0
ibm sametime 8.0.1.1
ibm sametime 8.5.1.0
ibm sametime 8.0.1.0
CVE-2013-3981 MEDIUM

The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to download avatar photos of arbitrary users via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm sametime 8.5.0.0
ibm sametime 8.5.2.0
ibm sametime 8.5.2.1
ibm sametime 9.0.0.1
ibm sametime 8.0.0.0
ibm sametime 8.0.2.0
ibm sametime 8.0.2.1
ibm sametime 8.5.1.1
ibm sametime 9.0.0.0
ibm sametime 8.0.1.1
ibm sametime 8.5.1.0
ibm sametime 8.0.1.0
CVE-2013-3982 MEDIUM

The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to obtain unspecified installation information and technical data via a request to a public page.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm sametime 8.5.0.0
ibm sametime 8.5.2.0
ibm sametime 8.5.2.1
ibm sametime 9.0.0.1
ibm sametime 8.0.0.0
ibm sametime 8.0.2.0
ibm sametime 8.0.2.1
ibm sametime 8.5.1.1
ibm sametime 9.0.0.0
ibm sametime 8.0.1.1
ibm sametime 8.5.1.0
ibm sametime 8.0.1.0
CVE-2013-3983 HIGH

The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 does not validate URLs in Cookie headers before using them in redirects, which has unspecified impact and remote attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm sametime 8.5.2.0
ibm sametime 8.5.2.1
ibm sametime 9.0.0.1
ibm sametime 9.0.0.0
CVE-2013-3984 LOW

The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 does not set the secure flag for an unspecified cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm sametime 8.5.0.0
ibm sametime 8.5.1.1
ibm sametime 8.5.2.0
ibm sametime 8.5.2.1
ibm sametime 9.0.0.0
ibm sametime 8.0.0.0
ibm sametime 8.0.1.1
ibm sametime 8.5.1.0
ibm sametime 8.0.2.0
ibm sametime 8.0.2.1
ibm sametime 8.0.1.0
CVE-2013-3985 LOW

The Enterprise Meeting Server in IBM Lotus Sametime 8.5.2 and 8.5.2.1 does not properly restrict application cookies, which allows remote attackers to read session variables by leveraging a weak setting of the Domain variable.

CVSS 2.0

Severity: LOW

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm lotus_sametime 8.5.2
ibm lotus_sametime 8.5.2.1
CVE-2013-3986 MEDIUM

IBM Lotus Sametime 8.5.2 and 8.5.2.1 allows remote attackers to cause a denial of service (WebPlayer Firefox extension crash) via a crafted Audio Visual (AV) session.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm lotus_sametime 8.5.2
ibm lotus_sametime 8.5.2.1
CVE-2013-3988 MEDIUM

The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to conduct clickjacking attacks via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm sametime 8.5.2.0
ibm sametime 8.5.2.1
ibm sametime 9.0.0.1
ibm sametime 9.0.0.0
CVE-2013-3989 LOW

IBM Security AppScan Enterprise 8.x before 8.8 sends a cleartext AppScan Source database password in a response, which allows remote authenticated users to obtain sensitive information, and subsequently conduct man-in-the-middle attacks, by examining the response content.

CVSS 2.0

Severity: LOW

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm security_appscan 8.0.0.1
ibm security_appscan 8.0.11
ibm security_appscan 8.6.0.2
ibm security_appscan 8.6.0.1
ibm security_appscan 8.6.0.0
ibm security_appscan 8.0.1.0
ibm security_appscan 8.0.1.1
ibm security_appscan 8.5.0.1
ibm security_appscan 8.0.0.2
ibm security_appscan 8.0.0.0
ibm security_appscan 8.7.0.0
ibm security_appscan 8.7.0.1
ibm security_appscan 8.5.0.0
CVE-2013-3990 MEDIUM

Cross-site scripting (XSS) vulnerability in the MIME e-mail functionality in iNotes in IBM Domino 9.0 before IF3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka SPR PTHN98FLQ2.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm lotus_domino 8.5.2.4
ibm lotus_domino 8.5.1.5
ibm lotus_domino 8.5.2.2
ibm lotus_domino 8.5.1.1
ibm lotus_domino 8.5.2.3
ibm lotus_domino 8.5.3.4
ibm lotus_domino 8.5.1.4
ibm lotus_domino 8.5.2.0
ibm lotus_domino 8.5.0.1
ibm lotus_domino 8.5.3.1
ibm lotus_domino 8.5.2.1
ibm lotus_domino 8.5.0
ibm lotus_domino 8.5.3.0
ibm lotus_domino 8.5.1
ibm lotus_domino 9.0.0.0
ibm lotus_domino 8.5.3.3
ibm lotus_domino 8.5.1.2
ibm lotus_domino 8.5.3.2
ibm lotus_domino 8.5.1.3
CVE-2013-3992 MEDIUM

Cross-site request forgery (CSRF) vulnerability in IBM InfoSphere BigInsights 2.0 through 2.1 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm infosphere_biginsights 2.0.0.0
ibm infosphere_biginsights 2.1.0.0
CVE-2013-3993 LOW

IBM InfoSphere BigInsights before 2.1.0.3 allows remote authenticated users to bypass intended file and directory restrictions, or access untrusted data or code, via crafted parameters in unspecified API calls.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
134c704f-9b21-4f2e-91b3-4a467353bcc0 6.5 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N 2.8 3.6

CVSS 2.0

Severity: LOW

Problem Type: CWE-22,CWE-22,

Products Affected

Vendor Product Version
ibm infosphere_biginsights *
CVE-2013-3995 LOW

Cross-site scripting (XSS) vulnerability in IBM InfoSphere BigInsights 1.1 through 2.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm infosphere_biginsights 1.1.0.1
ibm infosphere_biginsights 1.1.0.2
ibm infosphere_biginsights 1.4.0.0
ibm infosphere_biginsights 2.0.0.0
ibm infosphere_biginsights 2.1.0.0
ibm infosphere_biginsights 1.1.0.0
ibm infosphere_biginsights 1.3.0.0
ibm infosphere_biginsights 1.2.0.0
ibm infosphere_biginsights 1.3.0.1
CVE-2013-3996 MEDIUM

IBM InfoSphere BigInsights 1.1 through 2.1 does not properly handle FRAME elements, which makes it easier for remote authenticated users to conduct phishing attacks via a crafted web site.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm infosphere_biginsights 1.1.0.1
ibm infosphere_biginsights 1.1.0.2
ibm infosphere_biginsights 1.4.0.0
ibm infosphere_biginsights 2.0.0.0
ibm infosphere_biginsights 2.1.0.0
ibm infosphere_biginsights 1.1.0.0
ibm infosphere_biginsights 1.3.0.0
ibm infosphere_biginsights 1.2.0.0
ibm infosphere_biginsights 1.3.0.1
CVE-2013-3997 MEDIUM

Open redirect vulnerability in the Web Application Enterprise Console in IBM InfoSphere BigInsights 1.1 and 2.x before 2.1 FP2 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm infosphere_biginsights 2.1.0.1
ibm infosphere_biginsights 1.1.0.1
ibm infosphere_biginsights 1.1.0.2
ibm infosphere_biginsights 1.4.0.0
ibm infosphere_biginsights 2.0.0.0
ibm infosphere_biginsights 2.1.0.0
ibm infosphere_biginsights 1.1.0.0
ibm infosphere_biginsights 1.3.0.0
ibm infosphere_biginsights 1.2.0.0
ibm infosphere_biginsights 1.3.0.1
CVE-2013-3998 LOW

CRLF injection vulnerability in the Web Application Enterprise Console in IBM InfoSphere BigInsights 1.1 and 2.x before 2.1 FP2 allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-94,

Products Affected

Vendor Product Version
ibm infosphere_biginsights 2.1.0.1
ibm infosphere_biginsights 1.1.0.1
ibm infosphere_biginsights 1.1.0.2
ibm infosphere_biginsights 1.4.0.0
ibm infosphere_biginsights 2.0.0.0
ibm infosphere_biginsights 2.1.0.0
ibm infosphere_biginsights 1.1.0.0
ibm infosphere_biginsights 1.3.0.0
ibm infosphere_biginsights 1.2.0.0
ibm infosphere_biginsights 1.3.0.1
CVE-2013-3999 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Social Media Analytics 1.2 before FP1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm social_media_analytics 1.2.0.0
CVE-2013-4000 MEDIUM

Multiple cross-site request forgery (CSRF) vulnerabilities in IBM Cognos Command Center before 10.2 allow remote attackers to hijack the authentication of administrators for requests that (1) start or (2) stop services.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm cognos_command_center 10.0
ibm cognos_command_center *
CVE-2013-4001 MEDIUM

Session fixation vulnerability in IBM Cognos Command Center before 10.2 allows remote attackers to hijack web sessions via an authorization cookie.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm cognos_command_center 10.0
ibm cognos_command_center *
CVE-2013-4002 HIGH

XMLscanner.java in Apache Xerces2 Java Parser before 2.12.0, as used in the Java Runtime Environment (JRE) in IBM Java 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 as well as Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, Java SE Embedded 7u40 and earlier, and possibly other products allows remote attackers to cause a denial of service via vectors related to XML attribute names.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm host_on-demand 11.0.7
ibm java 5.0.15.0
suse linux_enterprise_desktop 11
ibm host_on-demand 11.0.3
ibm java 5.0.16.0
oracle jre 1.5.0
canonical ubuntu_linux 13.10
ibm java 5.0.12.1
ibm java 6.0.0.0
ibm java 6.0.5.0
ibm java 7.0.0.0
suse linux_enterprise_java 11
ibm java 5.0.12.2
apache xerces2_java *
ibm sterling_b2b_integrator 5.2.4
ibm java 5.0.11.2
ibm sterling_file_gateway 2.1
ibm host_on-demand 11.0.6.1
ibm host_on-demand 11.0.8
ibm java 7.0.4.0
ibm java 5.0.11.1
ibm host_on-demand 11.0.4
ibm java 6.0.10.0
suse linux_enterprise_server 10
canonical ubuntu_linux 13.04
ibm java 6.0.8.0
ibm host_on-demand 11.0
ibm java 6.0.9.2
canonical ubuntu_linux 12.04
ibm java 7.0.1.0
ibm host_on-demand 11.0.6
suse linux_enterprise_server 9
ibm tivoli_application_dependency_discovery_manager 7.2.2
ibm host_on-demand 11.0.5
ibm sterling_b2b_integrator 5.2
ibm sterling_b2b_integrator 5.1
ibm host_on-demand 11.0.5.1
ibm java 5.0.11.0
ibm java 7.0.2.0
canonical ubuntu_linux 10.04
ibm java 6.0.4.0
ibm java 7.0.3.0
ibm java 6.0.7.0
ibm java 6.0.12.0
ibm java 6.0.3.0
ibm java 5.0.0.0
ibm java 5.0.12.5
suse linux_enterprise_java 10
ibm java 6.0.13.2
ibm java 5.0.12.4
oracle jre 1.7.0
opensuse opensuse 12.2
ibm java 5.0.16.1
ibm host_on-demand 11.0.1
oracle jrockit *
ibm java 6.0.9.0
suse linux_enterprise_sdk 11
ibm java 5.0.16.2
ibm sterling_file_gateway 2.2
ibm java 6.0.8.1
oracle jdk 1.6.0
ibm java 7.0.4.1
ibm host_on-demand 11.0.2
ibm java 6.0.11.0
oracle jre 1.6.0
ibm java 5.0.14.0
ibm java 6.0.1.0
suse linux_enterprise_server 11
ibm java 7.0.4.2
ibm java 6.0.10.1
ibm java 5.0.13.0
oracle jdk 1.7.0
opensuse opensuse 12.3
suse linux_enterprise_desktop 10
ibm java 5.0.12.0
ibm java 5.0.12.3
ibm java 6.0.6.0
oracle jdk 1.5.0
canonical ubuntu_linux 12.10
ibm java 6.0.2.0
ibm java 6.0.13.1
ibm java 6.0.13.0
ibm java 6.0.9.1
CVE-2013-4003 LOW

Multiple cross-site scripting (XSS) vulnerabilities in IBM TRIRIGA Application Platform 2.x and 3.x before 3.3.1.1, and 8, allow remote authenticated users to inject arbitrary web script or HTML via (1) unspecified input to WebProcess.srv, (2) unspecified input to html/en/default/actionHandler/queryHandler.jsp, or (3) unspecified input in a portalSectionId action to html/en/default/reportTemplate/hGridTopQuery.jsp.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tririga_application_platform 2.6
ibm tririga_application_platform 2.5
ibm tririga_application_platform 3.2
ibm tririga_application_platform 2.7
ibm tririga_application_platform *
ibm tririga_application_platform 3.0
ibm tririga_application_platform 3.1
ibm tririga_application_platform 2.1
ibm tririga_application_platform 3.2.1
ibm tririga_application_platform 3.3.0.0
CVE-2013-4004 LOW

Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 8.0 before 8.0.0.7 and 8.5 before 8.5.5.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_application_server 8.0.0.5
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 8.5.0.2
ibm websphere_application_server 8.0.0.6
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 8.0.0.2
CVE-2013-4005 LOW

Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.31, 8.0 before 8.0.0.7, and 8.5 before 8.5.5.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified fields.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 7.0
ibm websphere_application_server 6.1.0.14
ibm websphere_application_server 7.0.0.12
ibm websphere_application_server 8.0.0.6
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 7.0.0.16
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0.35
ibm websphere_application_server 7.0.0.25
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 6.1.6
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 7.0.0.14
ibm websphere_application_server 7.0.0.22
ibm websphere_application_server 7.0.0.10
ibm websphere_application_server 6.1.3
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.0.39
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 6.1.7
ibm websphere_application_server 6.1.0.37
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 7.0.0.27
ibm websphere_application_server 7.0.0.18
ibm websphere_application_server 6.1.1
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 8.0.0.2
ibm websphere_application_server 8.0.0.5
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 8.5.0.2
ibm websphere_application_server 6.1.0.45
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 6.1.0
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 6.1
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.41
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 7.0.0.29
ibm websphere_application_server 7.0.0.24
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.1.5
ibm websphere_application_server 6.1.14
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 6.1.0.43
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.1.13
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 7.0.0.4
CVE-2013-4006 MEDIUM

IBM WebSphere Application Server (WAS) Liberty Profile 8.5 before 8.5.5.1 uses weak permissions for unspecified files, which allows local users to obtain sensitive information via standard filesystem operations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm websphere_application_server 8.5.5.0
ibm websphere_application_server 8.5.0.2
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 8.5.0.1
CVE-2013-4007 LOW

Cross-site scripting (XSS) vulnerability in adv_sw.php in the Advanced Management Module (AMM) with firmware BBET before BBET64G and BPET before BPET64G for IBM BladeCenter systems allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm advanced_management_module 1.01
ibm advanced_management_module 1.25
ibm advanced_management_module 1.32
ibm advanced_management_module 1.42
ibm advanced_management_module 1.00
ibm advanced_management_module 1.36
ibm advanced_management_module *
ibm advanced_management_module 2.50
ibm advanced_management_module 2.48
ibm advanced_management_module 1.28
ibm advanced_management_module 3.54
ibm advanced_management_module 1.34
ibm advanced_management_module 1.20
ibm advanced_management_module 1.26
ibm advanced_management_module 2.46
CVE-2013-4011 HIGH

Multiple unspecified vulnerabilities in the InfiniBand subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, allow local users to gain privileges via vectors involving (1) arp.ib or (2) ibstat.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm aix 6.1
ibm aix 7.1
ibm vios 2.2.2.2
CVE-2013-4012 MEDIUM

IBM WebSphere Portal 8.0.0.x before 8.0.0.1 CF09, when Content Template Catalog 4.0 is used, does not require administrative privileges for Portal Application Archive (PAA) file installation, which allows remote authenticated users to modify data or cause a denial of service via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.1
ibm websphere_portal 8.0.0.0
CVE-2013-4013 MEDIUM

IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.12, and 7.5 before 7.5.0.2 allows remote attackers to obtain sensitive information via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm maximo_asset_management 6.2.1
ibm maximo_asset_management 7.1.1.9
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.5.0.1
ibm maximo_asset_management 6.2.6
ibm maximo_asset_management 6.2.7
ibm maximo_asset_management 6.2.6.1
ibm maximo_asset_management 7.1.1.10
ibm maximo_asset_management 6.2.3
ibm maximo_asset_management 6.2.5
ibm maximo_asset_management 7.1.1.1
ibm maximo_asset_management 7.5.0.0
ibm maximo_asset_management 7.1.1.7
ibm maximo_asset_management 6.2
ibm maximo_asset_management 6.2.2
ibm maximo_asset_management 7.1.1.2
ibm maximo_asset_management 7.1.1.6
ibm maximo_asset_management 7.1.1.5
ibm maximo_asset_management 7.1.1.11
ibm maximo_asset_management 6.2.4
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
CVE-2013-4014 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm maximo_asset_management 7.1.1.9
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.5.0.1
ibm maximo_asset_management 6.2.6
ibm maximo_asset_management 6.2.7
ibm maximo_asset_management 6.2.6.1
ibm maximo_asset_management 7.1.1.10
ibm maximo_asset_management 6.2.3
ibm maximo_asset_management 6.2.5
ibm maximo_asset_management 7.1.1.1
ibm maximo_asset_management 6.2.8
ibm maximo_asset_management 7.5.0.3
ibm maximo_asset_management 6.2.4
ibm maximo_asset_management 6.2.1
ibm maximo_asset_management 7.5.0.0
ibm maximo_asset_management 7.1.1.7
ibm maximo_asset_management 6.2
ibm maximo_asset_management 6.2.2
ibm maximo_asset_management 7.5.0.4
ibm maximo_asset_management 7.1.1.2
ibm maximo_asset_management 7.1.1.6
ibm maximo_asset_management 7.1.1.5
ibm maximo_asset_management 7.1.1.11
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
CVE-2013-4016 MEDIUM

SQL injection vulnerability in IBM Maximo Asset Management 7.x before 7.1.1.7 LAFIX.20140319-0837, 7.1.1.11 before IFIX.20140323-0749, 7.1.1.12 before IFIX.20140321-1336, 7.5.x before 7.5.0.3 IFIX027, 7.5.0.4 before IFIX011, and 7.5.0.5 before IFIX006; SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2; and Tivoli IT Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB) 7.x before 7.1.1.7 LAFIX.20140319-0837, 7.1.1.11 before IFIX.20140207-1801, and 7.1.1.12 before IFIX.20140218-1510 allows remote authenticated users to execute arbitrary SQL commands via a Birt report with a WHERE clause in plain text.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm tivoli_it_asset_management_for_it 7.1.1.12
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.5.0.1
ibm maximo_service_desk 7.1.1.11
ibm maximo_asset_management 7.1.1.1
ibm tivoli_asset_management_for_it 7.0
ibm smartcloud_control_desk 7.5.0.0
ibm tivoli_it_asset_management_for_it 7.1.1.7
ibm change_and_configuration_management_database 7.1.1.7
ibm maximo_asset_management 7.1.1.12
ibm maximo_asset_management 7.5.0.3
ibm tivoli_service_request_manager 7.1.1.11
ibm smartcloud_control_desk 7.0
ibm change_and_configuration_management_database 7.1.1.11
ibm change_and_configuration_management_database 7.1.1.12
ibm tivoli_service_request_manager 7.1.1.7
ibm tivoli_asset_management_for_it 7.1
ibm maximo_service_desk 7.1.1.12
ibm maximo_asset_management 7.5.0.0
ibm maximo_asset_management 7.1.1.7
ibm tivoli_service_request_manager 7.1.1.12
ibm smartcloud_control_desk 7.5.1.1
ibm maximo_asset_management 7.5.0.4
ibm smartcloud_control_desk 7.5.0.2
ibm smartcloud_control_desk 7.5
ibm maximo_asset_management 7.5.0.5
ibm tivoli_service_request_manager 7.1.1
ibm maximo_asset_management 7.1.1.2
ibm maximo_service_desk 7.1.1.7
ibm smartcloud_control_desk 7.5.0.1
ibm maximo_asset_management 7.1.1.6
ibm maximo_asset_management 7.1.1.5
ibm smartcloud_control_desk 7.5.1.0
ibm maximo_asset_management 7.1.1.11
ibm maximo_asset_management 7.1.1
ibm tivoli_it_asset_management_for_it 7.1.1.11
CVE-2013-4017 MEDIUM

SQL injection vulnerability in IBM Maximo Asset Management 7.1 before 7.1.1.12 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm maximo_asset_management 7.1.1.9
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.1.1.2
ibm maximo_asset_management 7.1.1.6
ibm maximo_asset_management 7.1.1.5
ibm maximo_asset_management 7.1.1.10
ibm maximo_asset_management 7.1.1.11
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.1
ibm maximo_asset_management 7.1.1.8
ibm maximo_asset_management 7.1.1.7
CVE-2013-4018 MEDIUM

IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows remote authenticated users to obtain sensitive information via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm maximo_asset_management 7.1.1.9
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.5.0.1
ibm maximo_asset_management 6.2.6
ibm maximo_asset_management 6.2.7
ibm maximo_asset_management 6.2.6.1
ibm maximo_asset_management 7.1.1.10
ibm maximo_asset_management 6.2.3
ibm maximo_asset_management 6.2.5
ibm maximo_asset_management 7.1.1.1
ibm maximo_asset_management 7.5.0.3
ibm maximo_asset_management 6.2.4
ibm maximo_asset_management 6.2.1
ibm maximo_asset_management 7.5.0.0
ibm maximo_asset_management 7.1.1.7
ibm maximo_asset_management 6.2
ibm maximo_asset_management 6.2.2
ibm maximo_asset_management 7.5.0.4
ibm maximo_asset_management 7.1.1.2
ibm maximo_asset_management 7.1.1.6
ibm maximo_asset_management 7.1.1.5
ibm maximo_asset_management 7.1.1.11
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
CVE-2013-4019 LOW

Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 6.2.8 and 7.1 before 7.1.1.12 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm maximo_asset_management 6.2.1
ibm maximo_asset_management 7.1.1.9
ibm maximo_asset_management 7.1
ibm maximo_asset_management 6.2.6
ibm maximo_asset_management 6.2.7
ibm maximo_asset_management 6.2.6.1
ibm maximo_asset_management 7.1.1.10
ibm maximo_asset_management 6.2.3
ibm maximo_asset_management 6.2.5
ibm maximo_asset_management 7.1.1.1
ibm maximo_asset_management 7.1.1.7
ibm maximo_asset_management 6.2
ibm maximo_asset_management 6.2.2
ibm maximo_asset_management 6.2.8
ibm maximo_asset_management 7.1.1.2
ibm maximo_asset_management 7.1.1.6
ibm maximo_asset_management 7.1.1.5
ibm maximo_asset_management 7.1.1.11
ibm maximo_asset_management 6.2.4
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
CVE-2013-4020 MEDIUM

IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.12, and 7.5 before 7.5.0.3 allows remote authenticated users to bypass intended access restrictions via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm maximo_asset_management 6.2.1
ibm maximo_asset_management 7.1.1.9
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.5.0.1
ibm maximo_asset_management 6.2.6
ibm maximo_asset_management 6.2.7
ibm maximo_asset_management 6.2.6.1
ibm maximo_asset_management 7.1.1.10
ibm maximo_asset_management 6.2.3
ibm maximo_asset_management 6.2.5
ibm maximo_asset_management 7.1.1.1
ibm maximo_asset_management 7.5.0.0
ibm maximo_asset_management 7.1.1.7
ibm maximo_asset_management 6.2
ibm maximo_asset_management 6.2.2
ibm maximo_asset_management 7.1.1.2
ibm maximo_asset_management 7.1.1.6
ibm maximo_asset_management 7.1.1.5
ibm maximo_asset_management 7.1.1.11
ibm maximo_asset_management 6.2.4
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
CVE-2013-4021 MEDIUM

IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows remote authenticated users to conduct unspecified file-inclusion attacks via unknown vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm maximo_asset_management 7.1.1.9
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.5.0.1
ibm maximo_asset_management 6.2.6
ibm maximo_asset_management 6.2.7
ibm maximo_asset_management 6.2.6.1
ibm maximo_asset_management 7.1.1.10
ibm maximo_asset_management 6.2.3
ibm maximo_asset_management 6.2.5
ibm maximo_asset_management 7.1.1.1
ibm maximo_asset_management 6.2.8
ibm maximo_asset_management 7.5.0.3
ibm maximo_asset_management 6.2.4
ibm maximo_asset_management 6.2.1
ibm maximo_asset_management 7.5.0.0
ibm maximo_asset_management 7.1.1.7
ibm maximo_asset_management 6.2
ibm maximo_asset_management 6.2.2
ibm maximo_asset_management 7.5.0.4
ibm maximo_asset_management 7.1.1.2
ibm maximo_asset_management 7.1.1.6
ibm maximo_asset_management 7.1.1.5
ibm maximo_asset_management 7.1.1.11
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
CVE-2013-4022 LOW

IBM Data Studio Web Console 3.x before 3.2, Optim Performance Manager 5.x before 5.2, InfoSphere Optim Configuration Manager 2.x before 2.2, and DB2 Recovery Expert 2.x store unspecified authentication information in a cookie, which allows remote authenticated users to bypass intended access restrictions via unknown vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm infosphere_optim_configuration_manager 2.1
ibm db2_recovery_expert 2.0
ibm optim_performance_manager 5.1.0
ibm data_studio_web_console 3.1.0
ibm infosphere_optim_configuration_manager 2.0
CVE-2013-4024 MEDIUM

IBM Data Studio Web Console 3.x before 3.2, Optim Performance Manager 5.x before 5.2, InfoSphere Optim Configuration Manager 2.x before 2.2, and DB2 Recovery Expert 2.x support HTTP access to the Web Console, which allows remote attackers to read session cookies by sniffing the network.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm infosphere_optim_configuration_manager 2.1
ibm db2_recovery_expert 2.0
ibm optim_performance_manager 5.1.0
ibm data_studio_web_console 3.1.0
ibm infosphere_optim_configuration_manager 2.0
CVE-2013-4025 LOW

IBM Data Studio Web Console 3.x before 3.2, Optim Performance Manager 5.x before 5.2, InfoSphere Optim Configuration Manager 2.x before 2.2, and DB2 Recovery Expert 2.x do not have an off autocomplete attribute for the login-password field, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.

CVSS 2.0

Severity: LOW

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm infosphere_optim_configuration_manager 2.1
ibm db2_recovery_expert 2.0
ibm optim_performance_manager 5.1.0
ibm data_studio_web_console 3.1.0
ibm infosphere_optim_configuration_manager 2.0
CVE-2013-4027 MEDIUM

IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.12, and 7.5 before 7.5.0.5 allows remote authenticated users to bypass intended access restrictions via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm maximo_asset_management 7.1.1.9
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.5.0.1
ibm maximo_asset_management 6.2.6
ibm maximo_asset_management 6.2.7
ibm maximo_asset_management 6.2.6.1
ibm maximo_asset_management 7.1.1.10
ibm maximo_asset_management 6.2.3
ibm maximo_asset_management 6.2.5
ibm maximo_asset_management 7.1.1.1
ibm maximo_asset_management 6.2.8
ibm maximo_asset_management 7.1.1.12
ibm maximo_asset_management 7.5.0.3
ibm maximo_asset_management 6.2.4
ibm maximo_asset_management 6.2.1
ibm maximo_asset_management 7.5.0.0
ibm maximo_asset_management 7.1.1.7
ibm maximo_asset_management 6.2
ibm maximo_asset_management 6.2.2
ibm maximo_asset_management 7.5.0.4
ibm maximo_asset_management 7.1.1.2
ibm maximo_asset_management 7.1.1.6
ibm maximo_asset_management 7.1.1.5
ibm maximo_asset_management 7.1.1.11
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
CVE-2013-4030 MEDIUM

Integrated Management Module (IMM) 2 1.00 through 2.00 on IBM System X and Flex System servers supports SSL cipher suites with short keys, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack against (1) SSL or (2) TLS traffic.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm flex_system_manager_node_8731 -
ibm system_x3650_m3 -
ibm system_x3650_m4_hd -
ibm bladecenter hs23e
ibm system_x3630_m4_hd -
ibm system_x_idataplex_dx360_m4_server -
ibm flex_system_x440_compute_node -
ibm system_x3750_m4 -
ibm system_x3630_m3 -
ibm flex_system_manager_node_8734 -
ibm system_x3250_m4 -
ibm system_x3630_m4 -
ibm system_x3650_m4 -
ibm system_x3550_m2 -
ibm system_x3500_m3 -
ibm system_x3550_m4 -
ibm flex_system_x220_compute_node -
ibm flex_system_x240_compute_node -
ibm integrated_management_module_2 1.00
ibm system_x3690_x5 -
ibm system_x_idataplex_direct_water_cooled_dx360_m4_server -
ibm system_x3500_m4 -
ibm system_x3550_m3 -
ibm integrated_management_module_2 2.00
ibm flex_system_manager_node_7955 -
ibm system_x3500_m2 -
ibm system_x3850_x5 -
ibm system_x3950_x5 -
ibm bladecenter hs23
ibm system_x3300_m4 -
ibm system_x3650_m2 -
ibm system_x3530_m4 -
ibm system_x3100_m4 -
CVE-2013-4031 HIGH

The Intelligent Platform Management Interface (IPMI) implementation in Integrated Management Module (IMM) and Integrated Management Module II (IMM2) on IBM BladeCenter, Flex System, System x iDataPlex, and System x3### servers has a default password for the IPMI user account, which makes it easier for remote attackers to perform power-on, power-off, or reboot actions, or add or modify accounts, via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm system_x3400_m2 -
ibm system_x3650_m3 -
ibm bladecenter hs23e
ibm system_x_idataplex_dx360_m4_server -
ibm flex_system_x440_compute_node -
ibm system_x3750_m4 -
ibm system_x3400_m3 -
ibm system_x3630_m3 -
ibm system_x3250_m4 -
ibm system_x3630_m4 -
ibm bladecenter hs22v
ibm system_x3650_m4 -
ibm system_x_idataplex_dx360_m2_server -
ibm bladecenter hx5
ibm system_x3550_m2 -
ibm system_x3250_m3 -
ibm system_x3500_m3 -
ibm system_x3550_m4 -
ibm flex_system_x220_compute_node -
ibm flex_system_x240_compute_node -
ibm system_x3200_m3 -
ibm system_x3690_x5 -
ibm system_x3500_m4 -
ibm system_x3550_m3 -
ibm bladecenter hs22
ibm system_x3500_m2 -
ibm system_x3850_x5 -
ibm system_x3950_x5 -
ibm bladecenter hs23
ibm system_x3650_m2 -
ibm system_x_idataplex_dx360_m3_server -
ibm system_x3530_m4 -
ibm system_x3100_m4 -
ibm system_x3620_m3 -
CVE-2013-4032 MEDIUM

The Fast Communications Manager (FCM) in IBM DB2 Enterprise Server Edition and Advanced Enterprise Server Edition 10.1 before FP3 and 10.5, when a multi-node configuration is used, allows remote attackers to cause a denial of service via vectors involving arbitrary data.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2 10.1
CVE-2013-4033 MEDIUM

IBM DB2 and DB2 Connect 9.7 through FP8, 9.8 through FP5, 10.1 through FP2, and 10.5 through FP1 allow remote authenticated users to execute DML statements by leveraging EXPLAIN authority.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2_connect 10.1
ibm db2_connect 9.5
ibm db2_connect 10.5
ibm db2 10.1
ibm db2 9.8
ibm db2_connect 9.8
ibm db2_connect 9.7
ibm db2 9.7
CVE-2013-4034 MEDIUM

IBM Cognos Business Intelligence 8.4.1 before IF3, 10.1.0 before IF4, 10.1.1 before IF4, 10.2.0 before IF4, 10.2.1 before IF2, and 10.2.1.1 before IF1 allows remote authenticated users to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm cognos_business_intelligence 10.2.1
ibm cognos_business_intelligence 10.2
ibm cognos_business_intelligence 10.1
ibm cognos_business_intelligence 10.2.1.1
ibm cognos_business_intelligence 8.4.1
ibm cognos_business_intelligence 10.1.1
CVE-2013-4035 MEDIUM

IBM Sterling Connect:Direct for OpenVMS 3.4.00, 3.4.01, 3.5.00, 3.6.0, and 3.6.0.1 allow remote attackers to have unspecified impact by leveraging failure to reject client requests for an unencrypted session when used as the server in a TCP/IP session and configured for SSL encryption with the client. IBM X-Force ID: 86138.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm sterling_connect 3.6.0
ibm sterling_connect 3.4.0.1
ibm sterling_connect 3.5.0.0
ibm sterling_connect 3.6.0.1
ibm sterling_connect 3.4.0.0
CVE-2013-4036 LOW

Cross-site scripting (XSS) vulnerability in IBM InfoSphere Master Data Management Server for Product Information Management 9.x before 9.1 FP13, and IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1 FP7 and 11.0 before FP2, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm infosphere_master_data_management_collaboration_server 10.0
ibm infosphere_master_data_management_server_for_product_information_management 9.1
ibm infosphere_master_data_management_collaboration_server 10.1
ibm infosphere_master_data_management_server_for_product_information_management 9.0
ibm infosphere_master_data_management_collaboration_server 11.0
CVE-2013-4037 MEDIUM

The RAKP protocol support in the Intelligent Platform Management Interface (IPMI) implementation in Integrated Management Module (IMM) and Integrated Management Module II (IMM2) on IBM BladeCenter, Flex System, System x iDataPlex, and System x3### servers sends a password hash to the client, which makes it easier for remote attackers to obtain access via a brute-force attack.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm system_x3400_m2 -
ibm system_x3650_m3 -
ibm bladecenter hs23e
ibm system_x_idataplex_dx360_m4_server -
ibm flex_system_x440_compute_node -
ibm system_x3750_m4 -
ibm system_x3400_m3 -
ibm system_x3630_m3 -
ibm system_x3250_m4 -
ibm system_x3630_m4 -
ibm bladecenter hs22v
ibm system_x3650_m4 -
ibm system_x_idataplex_dx360_m2_server -
ibm bladecenter hx5
ibm system_x3550_m2 -
ibm system_x3250_m3 -
ibm system_x3500_m3 -
ibm system_x3550_m4 -
ibm flex_system_x220_compute_node -
ibm flex_system_x240_compute_node -
ibm system_x3200_m3 -
ibm system_x3690_x5 -
ibm system_x3500_m4 -
ibm system_x3550_m3 -
ibm bladecenter hs22
ibm system_x3500_m2 -
ibm system_x3850_x5 -
ibm system_x3950_x5 -
ibm bladecenter hs23
ibm system_x3650_m2 -
ibm system_x_idataplex_dx360_m3_server -
ibm system_x3530_m4 -
ibm system_x3100_m4 -
ibm system_x3620_m3 -
CVE-2013-4038 MEDIUM

The Intelligent Platform Management Interface (IPMI) implementation in Integrated Management Module (IMM) on IBM BladeCenter, Flex System, System x iDataPlex, and System x3### servers uses cleartext for password storage, which allows context-dependent attackers to obtain sensitive information by reading a file.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm system_x3400_m2 -
ibm system_x3650_m3 -
ibm bladecenter hs23e
ibm system_x_idataplex_dx360_m4_server -
ibm flex_system_x440_compute_node -
ibm system_x3750_m4 -
ibm system_x3400_m3 -
ibm system_x3630_m3 -
ibm system_x3250_m4 -
ibm system_x3630_m4 -
ibm bladecenter hs22v
ibm system_x3650_m4 -
ibm system_x_idataplex_dx360_m2_server -
ibm bladecenter hx5
ibm system_x3550_m2 -
ibm system_x3250_m3 -
ibm system_x3500_m3 -
ibm system_x3550_m4 -
ibm flex_system_x220_compute_node -
ibm flex_system_x240_compute_node -
ibm system_x3200_m3 -
ibm system_x3690_x5 -
ibm system_x3500_m4 -
ibm system_x3550_m3 -
ibm bladecenter hs22
ibm system_x3500_m2 -
ibm system_x3850_x5 -
ibm system_x3950_x5 -
ibm bladecenter hs23
ibm system_x3650_m2 -
ibm system_x_idataplex_dx360_m3_server -
ibm system_x3530_m4 -
ibm system_x3100_m4 -
ibm system_x3620_m3 -
CVE-2013-4039 MEDIUM

IBM WebSphere Extended Deployment Compute Grid 8.0 before 8.0.0.3 allows remote authenticated users to obtain sensitive information, and consequently bypass intended access restrictions on jobs, via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_extended_deployment_compute_grid 8.5.0.0
ibm websphere_extended_deployment_compute_grid 8.0.0.0
ibm websphere_extended_deployment_compute_grid 8.0.0.1
ibm websphere_extended_deployment_compute_grid *
CVE-2013-4040 LOW

IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.1.2.x before 7.2.1.5 and 7.2.x before 7.2.2.0 on Unix use weak permissions (755) for unspecified configuration and log files, which allows local users to obtain sensitive information by reading the files. IBM X-Force ID: 86176.

CVSS 2.0

Severity: LOW

Problem Type: CWE-275,

Products Affected

Vendor Product Version
ibm tivoli_application_dependency_discovery_manager 7.1.2
ibm tivoli_application_dependency_discovery_manager *
CVE-2013-4041 MEDIUM

Unspecified vulnerability in IBM Java SDK 5.0.0 before SR16 FP4, 7.0.0 before SR6, 6.0.1 before SR7, and 6.0.0 before SR15 allows remote attackers to access restricted classes via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm java 7.0.0.0
ibm java 5.0.0.0
ibm java 6.0.0.0
ibm java 6.0.1.0
CVE-2013-4042 HIGH

Unspecified vulnerability in IBM SPSS Collaboration and Deployment Services 4.2.1 and 5.0 through FP2 allows remote attackers to execute arbitrary code via unknown vectors, a different vulnerability than CVE-2013-5370.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm spss_collaboration_and_deployment_services 5.0.0
ibm spss_collaboration_and_deployment_services 5.0.1
ibm spss_collaboration_and_deployment_services 4.2.1
ibm spss_collaboration_and_deployment_services 5.0.2
CVE-2013-4043 MEDIUM

The server in IBM SPSS Collaboration and Deployment Services 4.x before 4.2.1.3 IF3, 5.x before 5.0 FP3, and 6.x before 6.0 IF1 allows remote attackers to read arbitrary files via an unspecified HTTP request.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm spss_collaboration_and_deployment_services 5.0.0.1
ibm spss_collaboration_and_deployment_services 4.2.1.1
ibm spss_collaboration_and_deployment_services 4.1.1.1
ibm spss_collaboration_and_deployment_services 5.0.0.2
ibm spss_collaboration_and_deployment_services 5.0.1
ibm spss_collaboration_and_deployment_services 4.2.1
ibm spss_collaboration_and_deployment_services 5.0.2
ibm spss_collaboration_and_deployment_services 4.1.1.3
ibm spss_collaboration_and_deployment_services 4.2.1.3
ibm spss_collaboration_and_deployment_services 5.0.0
ibm spss_collaboration_and_deployment_services 4.1.1.2
ibm spss_collaboration_and_deployment_services 6.0.0.0
ibm spss_collaboration_and_deployment_services 4.2.1.2
CVE-2013-4044 MEDIUM

IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote authenticated users to read application log files via a direct HTTP request.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm spss_collaboration_and_deployment_services 5.0.0.1
ibm spss_collaboration_and_deployment_services 4.2.1.3
ibm spss_collaboration_and_deployment_services 4.2.1.1
ibm spss_collaboration_and_deployment_services 5.0.0
ibm spss_collaboration_and_deployment_services 5.0.0.2
ibm spss_collaboration_and_deployment_services 4.2.1
ibm spss_collaboration_and_deployment_services 4.2.1.2
CVE-2013-4045 MEDIUM

Cross-site scripting (XSS) vulnerability in the Portal application in IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm spss_collaboration_and_deployment_services 5.0.0.1
ibm spss_collaboration_and_deployment_services 4.2.1.3
ibm spss_collaboration_and_deployment_services 4.2.1.1
ibm spss_collaboration_and_deployment_services 5.0.0
ibm spss_collaboration_and_deployment_services 5.0.0.2
ibm spss_collaboration_and_deployment_services 4.2.1
ibm spss_collaboration_and_deployment_services 4.2.1.2
CVE-2013-4046 MEDIUM

Open redirect vulnerability in IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm spss_collaboration_and_deployment_services 5.0.0.1
ibm spss_collaboration_and_deployment_services 4.2.1.3
ibm spss_collaboration_and_deployment_services 4.2.1.1
ibm spss_collaboration_and_deployment_services 5.0.0
ibm spss_collaboration_and_deployment_services 5.0.0.2
ibm spss_collaboration_and_deployment_services 4.2.1
ibm spss_collaboration_and_deployment_services 4.2.1.2
CVE-2013-4047 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM SPSS Analytical Decision Management 6.1 before IF1, 6.2 before IF1, and 7.0 before FP1 IF6 allows remote attackers to inject arbitrary web script or HTML via a crafted link.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm spss_analytical_decision_management 6.1.0.0
ibm spss_analytical_decision_management 7.0.0.0
ibm spss_analytical_decision_management 6.2.0.0
CVE-2013-4048 LOW

Cross-site scripting (XSS) vulnerability in IBM SPSS Analytical Decision Management 6.1 before IF1, 6.2 before IF1, and 7.0 before FP1 IF6 allows remote authenticated users to inject arbitrary web script or HTML via vectors involving addition of script to a page.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm spss_analytical_decision_management 6.1.0.0
ibm spss_analytical_decision_management 7.0.0.0
ibm spss_analytical_decision_management 6.2.0.0
CVE-2013-4049 HIGH

Unrestricted file upload vulnerability in IBM SPSS Analytical Decision Management 6.1 before IF1, 6.2 before IF1, and 7.0 before FP1 IF6 allows remote authenticated users to execute arbitrary code by uploading and accessing a JSP file.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm spss_analytical_decision_management 6.1.0.0
ibm spss_analytical_decision_management 7.0.0.0
ibm spss_analytical_decision_management 6.2.0.0
CVE-2013-4050 MEDIUM

Cross-site request forgery (CSRF) vulnerability in webadmin.nsf in Domino Web Administrator in IBM Domino 8.5 and 9.0 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm lotus_domino 8.5.0
ibm lotus_domino 9.0.0.0
CVE-2013-4051 LOW

Cross-site scripting (XSS) vulnerability in webadmin.nsf in Domino Web Administrator in IBM Domino 8.5 and 9.0 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2013-4055.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm lotus_domino 8.5.0
ibm lotus_domino 9.0.0.0
CVE-2013-4052 MEDIUM

Cross-site scripting (XSS) vulnerability in the UDDI Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.31, 8.0 before 8.0.0.8, and 8.5 before 8.5.5.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 7.0
ibm websphere_application_server 6.1.0.14
ibm websphere_application_server 7.0.0.12
ibm websphere_application_server 8.0.0.6
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 7.0.0.16
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0.35
ibm websphere_application_server 7.0.0.25
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 7.0.0.14
ibm websphere_application_server 7.0.0.22
ibm websphere_application_server 7.0.0.10
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 8.0.0.7
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.0.39
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 6.1.0.37
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 7.0.0.27
ibm websphere_application_server 7.0.0.18
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 8.0.0.2
ibm websphere_application_server 8.0.0.5
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 8.5.0.2
ibm websphere_application_server 6.1.0.45
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 6.1.0
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 6.1
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.41
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 7.0.0.29
ibm websphere_application_server 7.0.0.24
ibm websphere_application_server 8.5.5.0
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 6.1.0.43
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 7.0.0.4
CVE-2013-4053 MEDIUM

The WS-Security implementation in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.31, 8.0 before 8.0.0.8, and 8.5 before 8.5.5.1, and WAS Feature Pack for Web Services 6.1 before 6.1.0.47, when a trust store is configured for XML Digital Signatures, does not properly verify X.509 certificates, which allows remote attackers to obtain privileged access via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server_feature_pack_for_web_services 6.1.0.35
ibm websphere_application_server 7.0
ibm websphere_application_server 6.1.0.14
ibm websphere_application_server 7.0.0.12
ibm websphere_application_server 8.0.0.6
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 7.0.0.16
ibm websphere_application_server_feature_pack_for_web_services 6.1.0.25
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0.35
ibm websphere_application_server 7.0.0.25
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 7.0.0.14
ibm websphere_application_server 7.0.0.22
ibm websphere_application_server_feature_pack_for_web_services 6.1.0.27
ibm websphere_application_server 7.0.0.10
ibm websphere_application_server_feature_pack_for_web_services 6.1.0.37
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server_feature_pack_for_web_services 6.1.0.13
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server_feature_pack_for_web_services 6.1.0.29
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 8.0.0.7
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.0.39
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 6.1.0.37
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server_feature_pack_for_web_services 6.1.0.45
ibm websphere_application_server 7.0.0.27
ibm websphere_application_server 7.0.0.18
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server_feature_pack_for_web_services 6.1.0.33
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 8.0.0.2
ibm websphere_application_server 8.0.0.5
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server_feature_pack_for_web_services 6.1.0.21
ibm websphere_application_server 8.5.0.2
ibm websphere_application_server 6.1.0.45
ibm websphere_application_server_feature_pack_for_web_services 6.1.0.19
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server_feature_pack_for_web_services 6.1.0.41
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server_feature_pack_for_web_services 6.1.0.23
ibm websphere_application_server 6.1.0
ibm websphere_application_server_feature_pack_for_web_services 6.1.0.47
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 6.1
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.41
ibm websphere_application_server_feature_pack_for_web_services 6.1.0.17
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server_feature_pack_for_web_services 6.1.0.43
ibm websphere_application_server 7.0.0.29
ibm websphere_application_server 7.0.0.24
ibm websphere_application_server 8.5.5.0
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server_feature_pack_for_web_services 6.1.0.31
ibm websphere_application_server_feature_pack_for_web_services 6.1.0.39
ibm websphere_application_server_feature_pack_for_web_services 6.1.0.11
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 6.1.0.43
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server_feature_pack_for_web_services 6.1.0.15
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 7.0.0.4
CVE-2013-4054 MEDIUM

Directory traversal vulnerability in WMQ Telemetry in IBM WebSphere MQ 7.5 before 7.5.0.3 allows remote attackers to read arbitrary files via a crafted URI.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm websphere_mq 7.5.0.2
ibm websphere_mq 7.5.0.1
ibm websphere_mq 7.5
CVE-2013-4055 LOW

Cross-site scripting (XSS) vulnerability in webadmin.nsf in Domino Web Administrator in IBM Domino 8.5 and 9.0 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2013-4051.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm lotus_domino 8.5.0
ibm lotus_domino 9.0.0.0
CVE-2013-4056 MEDIUM

Cross-site request forgery (CSRF) vulnerability in the Data Quality Console and Information Analyzer components in IBM InfoSphere Information Server 8.7 through FP2 and 9.1 through 9.1.2.0 allows remote attackers to hijack the authentication of arbitrary users.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm infosphere_information_server 8.7.0.1
ibm infosphere_information_server 9.1.0.1
ibm infosphere_information_server 9.1.2
ibm infosphere_information_server 9.1
ibm infosphere_information_server 8.7
ibm infosphere_information_server 8.7.0.2
CVE-2013-4057 MEDIUM

Cross-site request forgery (CSRF) vulnerability in the XML Pack in IBM InfoSphere Information Server 8.5.x through 8.5 FP3, 8.7.x through 8.7 FP2, and 9.1.x through 9.1.2.0 allows remote attackers to hijack the authentication of arbitrary users.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm infosphere_information_server 8.5.0.2
ibm infosphere_information_server 8.5.0.3
ibm infosphere_information_server 8.7.0.1
ibm infosphere_information_server 9.1.0.1
ibm infosphere_information_server 8.5.0.1
ibm infosphere_information_server 9.1.2
ibm infosphere_information_server 8.5
ibm infosphere_information_server 9.1
ibm infosphere_information_server 8.7
ibm infosphere_information_server 8.7.0.2
CVE-2013-4058 MEDIUM

Multiple SQL injection vulnerabilities in IBM InfoSphere Information Server 8.x through 8.5 FP3, 8.7.x through 8.7 FP2, and 9.1.x through 9.1.2.0 allow remote authenticated users to execute arbitrary SQL commands via unspecified interfaces.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm infosphere_information_server 8.5.0.2
ibm infosphere_information_server 8.5.0.3
ibm infosphere_information_server 8.7.0.1
ibm infosphere_information_server 9.1.0.1
ibm infosphere_information_server 8.5.0.1
ibm infosphere_information_server 9.1.2
ibm infosphere_information_server 8.5
ibm infosphere_information_server 9.1
ibm infosphere_information_server 8.7
ibm infosphere_information_server 8.7.0.2
CVE-2013-4059 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in IBM InfoSphere Information Server 8.x through 8.5 FP3, 8.7.x through 8.7 FP2, and 9.1.x through 9.1.2.0 allow remote attackers to inject arbitrary web script or HTML via unspecified interfaces.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm infosphere_information_server 8.5.0.2
ibm infosphere_information_server 8.5.0.3
ibm infosphere_information_server 8.7.0.1
ibm infosphere_information_server 9.1.0.1
ibm infosphere_information_server 8.5.0.1
ibm infosphere_information_server 9.1.2
ibm infosphere_information_server 8.5
ibm infosphere_information_server 9.1
ibm infosphere_information_server 8.7
ibm infosphere_information_server 8.7.0.2
CVE-2013-4061 MEDIUM

IBM Rational Policy Tester 8.5 before 8.5.0.5 does not properly check authorization for changes to the set of authentication hosts, which allows remote authenticated users to perform spoofing attacks involving an HTTP redirect via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm rational_policy_tester 8.5.0.2
ibm rational_policy_tester 8.5.0.0
ibm rational_policy_tester 8.5.0.1
ibm rational_policy_tester 8.5.0.3
ibm rational_policy_tester 8.5.0.4
CVE-2013-4062 MEDIUM

IBM Rational Policy Tester 8.5 before 8.5.0.5 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof Jazz Team servers, obtain sensitive information, and modify the client-server data stream via a crafted certificate.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm rational_policy_tester 8.5.0.2
ibm rational_policy_tester 8.5.0.0
ibm rational_policy_tester 8.5.0.1
ibm rational_policy_tester 8.5.0.3
ibm rational_policy_tester 8.5.0.4
CVE-2013-4063 MEDIUM

Cross-site scripting (XSS) vulnerability in iNotes in IBM Domino 8.5.x before 8.5.3 FP6 and 9.0.x before 9.0.1 allows remote attackers to inject arbitrary web script or HTML via active content in an e-mail message, aka SPRs PTHN9AQMV7 and TCLE98ZKRP.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm lotus_inotes 8.5.3.0
ibm lotus_domino 8.5.3.5
ibm lotus_domino 8.5.3.4
ibm lotus_inotes 9.0.0.0
ibm lotus_inotes 8.5.3.1
ibm lotus_domino 8.5.3.1
ibm lotus_inotes 8.5.3.3
ibm lotus_domino 8.5.3.0
ibm lotus_domino 9.0.0.0
ibm lotus_domino 8.5.3.3
ibm lotus_inotes 8.5.3.4
ibm lotus_domino 8.5.3.2
ibm lotus_inotes 8.5.3.5
ibm lotus_inotes 8.5.3.2
CVE-2013-4064 LOW

Cross-site scripting (XSS) vulnerability in iNotes in IBM Domino 8.5.x before 8.5.3 FP6 and 9.0.x before 9.0.1, when ultra-light mode is enabled, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, aka SPR PTHN9ARMFA.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm lotus_inotes 8.5.3.0
ibm lotus_domino 8.5.3.5
ibm lotus_domino 8.5.3.4
ibm lotus_inotes 9.0.0.0
ibm lotus_inotes 8.5.3.1
ibm lotus_domino 8.5.3.1
ibm lotus_inotes 8.5.3.3
ibm lotus_domino 8.5.3.0
ibm lotus_domino 9.0.0.0
ibm lotus_domino 8.5.3.3
ibm lotus_inotes 8.5.3.4
ibm lotus_domino 8.5.3.2
ibm lotus_inotes 8.5.3.5
ibm lotus_inotes 8.5.3.2
CVE-2013-4065 LOW

Cross-site scripting (XSS) vulnerability in iNotes in IBM Domino 8.5.x before 8.5.3 FP6 and 9.0.x before 9.0.1, when ultra-light mode is enabled, allows remote attackers to inject arbitrary web script or HTML via active content in an e-mail message, aka SPR TCLE98ZKRP.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm lotus_inotes 8.5.3.0
ibm lotus_domino 8.5.3.5
ibm lotus_domino 8.5.3.4
ibm lotus_inotes 9.0.0.0
ibm lotus_inotes 8.5.3.1
ibm lotus_domino 8.5.3.1
ibm lotus_inotes 8.5.3.3
ibm lotus_domino 8.5.3.0
ibm lotus_domino 9.0.0.0
ibm lotus_domino 8.5.3.3
ibm lotus_inotes 8.5.3.4
ibm lotus_domino 8.5.3.2
ibm lotus_inotes 8.5.3.5
ibm lotus_inotes 8.5.3.2
CVE-2013-4066 MEDIUM

IBM InfoSphere Information Server 8.0, 8.1, 8.5 through FP3, 8.7, and 9.1 allows remote attackers to conduct clickjacking attacks by creating an overlay interface on top of the Web Console interface.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm infosphere_information_server 8.5.0.2
ibm infosphere_information_server 8.5.0.3
ibm infosphere_information_server 8.5.0.1
ibm infosphere_information_server 8.1
ibm infosphere_information_server 8.5
ibm infosphere_information_server 9.1
ibm infosphere_information_server 8.0
ibm infosphere_information_server 8.7
CVE-2013-4067 MEDIUM

IBM InfoSphere Information Server 8.0, 8.1, 8.5 through FP3, 8.7, and 9.1 allows remote attackers to hijack sessions and read cookie values, or conduct phishing attacks to capture credentials, via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm infosphere_information_server 8.5.0.2
ibm infosphere_information_server 8.5.0.3
ibm infosphere_information_server 8.5.0.1
ibm infosphere_information_server 8.1
ibm infosphere_information_server 8.5
ibm infosphere_information_server 9.1
ibm infosphere_information_server 8.0
ibm infosphere_information_server 8.7
CVE-2013-4068 HIGH

Buffer overflow in iNotes in IBM Domino 8.5.3 before FP5 IF1 and 9.0 before IF4 allows remote authenticated users to execute arbitrary code via unspecified vectors, aka SPR PTHN9ADPA8.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm lotus_domino 8.5.3.0
ibm lotus_domino 9.0.0.0
ibm lotus_domino 8.5.3.4
ibm lotus_domino 8.5.3.3
ibm lotus_inotes -
ibm lotus_domino 8.5.3.2
ibm lotus_domino 8.5.3.1
CVE-2013-4069 MEDIUM

The Portal application in IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm spss_collaboration_and_deployment_services 5.0.0.1
ibm spss_collaboration_and_deployment_services 4.2.1.3
ibm spss_collaboration_and_deployment_services 4.2.1.1
ibm spss_collaboration_and_deployment_services 5.0.0
ibm spss_collaboration_and_deployment_services 5.0.0.2
ibm spss_collaboration_and_deployment_services 4.2.1
ibm spss_collaboration_and_deployment_services 4.2.1.2
CVE-2013-4070 MEDIUM

The Portal application in IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote attackers to discover an internal password via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm spss_collaboration_and_deployment_services 5.0.0.1
ibm spss_collaboration_and_deployment_services 4.2.1.3
ibm spss_collaboration_and_deployment_services 4.2.1.1
ibm spss_collaboration_and_deployment_services 5.0.0
ibm spss_collaboration_and_deployment_services 5.0.0.2
ibm spss_collaboration_and_deployment_services 4.2.1
ibm spss_collaboration_and_deployment_services 4.2.1.2
CVE-2013-4804 HIGH

Unspecified vulnerability in HP Business Process Monitor 9.13.1 patch 1 and 9.22 patch 1 allows remote attackers to execute arbitrary code and obtain sensitive information via unknown vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm business_process_monitor 9.22
ibm business_process_monitor 9.13.1
CVE-2013-5369 HIGH

IBM SPSS Analytical Decision Management 6.1 before IF1, 6.2 before IF1, and 7.0 before FP1 IF6 might allow remote attackers to execute arbitrary code by deploying and accessing a service.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-94,

Products Affected

Vendor Product Version
ibm spss_analytical_decision_management 6.1.0.0
ibm spss_analytical_decision_management 7.0.0.0
ibm spss_analytical_decision_management 6.2.0.0
CVE-2013-5370 HIGH

Unspecified vulnerability in IBM SPSS Collaboration and Deployment Services 4.2.1 and 5.0 through FP2 allows remote attackers to execute arbitrary code via unknown vectors, a different vulnerability than CVE-2013-4042.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm spss_collaboration_and_deployment_services 5.0.0
ibm spss_collaboration_and_deployment_services 5.0.1
ibm spss_collaboration_and_deployment_services 4.2.1
ibm spss_collaboration_and_deployment_services 5.0.2
CVE-2013-5371 LOW

The client in IBM Tivoli Storage Manager (TSM) 6.3.1 and 6.4.0 on Windows does not preserve permissions of Resilient File System (ReFS) files across backup and restore operations, which allows local users to bypass intended access restrictions via standard filesystem operations.

CVSS 2.0

Severity: LOW

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager 6.4.0
ibm tivoli_storage_manager 6.3.1
CVE-2013-5372 MEDIUM

The XML4J parser in IBM WebSphere Message Broker 6.1 before 6.1.0.12, 7.0 before 7.0.0.7, and 8.0 before 8.0.0.4 and IBM Integration Bus 9.0 before 9.0.0.1 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document that triggers expansion for many entities.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm websphere_message_broker 6.1.0.3
ibm websphere_message_broker 7.0.0.1
ibm websphere_message_broker 6.1.0.5
ibm websphere_message_broker 6.1.0.10
ibm websphere_message_broker 7.0.0.2
ibm websphere_message_broker 8.0
ibm websphere_message_broker 7.0.0.5
ibm websphere_message_broker 6.1.0.6
ibm websphere_message_broker 7.0.0.4
ibm websphere_message_broker 6.1.0.4
ibm websphere_message_broker 6.1.0.9
ibm websphere_message_broker 6.1.0.2
ibm websphere_message_broker 7.0.0.6
ibm websphere_message_broker 8.0.0.3
ibm websphere_message_broker 8.0.0.2
ibm websphere_message_broker 7.0.0.3
ibm websphere_message_broker 6.1
ibm websphere_message_broker 6.1.0.8
ibm websphere_message_broker 7.0.
ibm websphere_message_broker 8.0.0.1
ibm websphere_message_broker 6.1.0.7
ibm websphere_message_broker 6.1.0.11
ibm websphere_message_broker 6.1.0.1
CVE-2013-5373 MEDIUM

The RemoteClient component in IBM Rational ClearCase 8.0.0.03 through 8.0.0.07, and 8.0.1, uses world-writable permissions for the rcleartool script, which allows local users to gain privileges by appending commands.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm rational_clearcase 8.0.0.7
ibm rational_clearcase 8.0.0.3
ibm rational_clearcase 8.0.0.4
ibm rational_clearcase 8.0.0.6
ibm rational_clearcase 8.0.0.5
ibm rational_clearcase 8.0.1
CVE-2013-5375 MEDIUM

Unspecified vulnerability in IBM Java SDK 7.0.0 before SR6, 6.0.1 before SR7, 6.0.0 before SR15, and 5.0.0 before SR16 FP4 allows remote attackers to access restricted classes via unspecified vectors related to XML and XSL.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm java 7.0.0.0
ibm java 5.0.0.0
ibm java 6.0.0.0
ibm java 6.0.1.0
CVE-2013-5376 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Storwize V7000 Unified 1.3.x and 1.4.x before 1.4.2.0 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, related to a "cross frame scripting" attack against an administrative user.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm storwize_v7000_unified_software 1.3.2.0
ibm storwize_v7000_unified_software 1.3.0.0
ibm storwize_v7000_unified -
ibm storwize_v7000_unified_software 1.3.2.3
ibm storwize_v7000_unified_software 1.4.1.1
ibm storwize_v7000_unified_software 1.4.0.0
ibm storwize_v7000_unified_software 1.4.1.0
ibm storwize_v7000_unified_software 1.4.0.4
CVE-2013-5378 LOW

Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.x before 8.0.0.1 CF8 allows remote authenticated users to inject arbitrary web script or HTML by leveraging incorrect IBM Connections integration.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.1
ibm websphere_portal 8.0.0.0
CVE-2013-5379 LOW

Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 7.x before 7.0.0.2 CF25 and 8.x before 8.0.0.1 CF8 allows remote authenticated users to inject arbitrary web script or HTML by leveraging improper tagging functionality.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.1
ibm websphere_portal 8.0.0.0
ibm websphere_portal 7.0.0.2
ibm websphere_portal 7.0.0.1
ibm websphere_portal 7.0.0.0
CVE-2013-5380 LOW

IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows local users to obtain sensitive information via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm maximo_asset_management 7.1.1.9
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.5.0.1
ibm maximo_asset_management 6.2.6
ibm maximo_asset_management 6.2.7
ibm maximo_asset_management 6.2.6.1
ibm maximo_asset_management 7.1.1.10
ibm maximo_asset_management 6.2.3
ibm maximo_asset_management 6.2.5
ibm maximo_asset_management 7.1.1.1
ibm maximo_asset_management 6.2.8
ibm maximo_asset_management 7.5.0.3
ibm maximo_asset_management 6.2.4
ibm maximo_asset_management 6.2.1
ibm maximo_asset_management 7.5.0.0
ibm maximo_asset_management 7.1.1.7
ibm maximo_asset_management 6.2
ibm maximo_asset_management 6.2.2
ibm maximo_asset_management 7.5.0.4
ibm maximo_asset_management 7.1.1.2
ibm maximo_asset_management 7.1.1.6
ibm maximo_asset_management 7.1.1.5
ibm maximo_asset_management 7.1.1.11
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
CVE-2013-5381 MEDIUM

IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.12, and 7.5 before 7.5.0.3 allows remote authenticated users to gain privileges via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm maximo_asset_management 7.1.1.9
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.5.0.1
ibm maximo_asset_management 6.2.6
ibm maximo_asset_management 6.2.7
ibm maximo_asset_management 6.2.6.1
ibm maximo_asset_management 7.1.1.10
ibm maximo_asset_management 6.2.3
ibm maximo_asset_management 6.2.5
ibm maximo_asset_management 7.1.1.1
ibm maximo_asset_management 6.2.8
ibm maximo_asset_management 7.1.1.12
ibm maximo_asset_management 6.2.4
ibm maximo_asset_management 6.2.1
ibm maximo_asset_management 7.5.0.0
ibm maximo_asset_management 7.1.1.7
ibm maximo_asset_management 6.2
ibm maximo_asset_management 6.2.2
ibm maximo_asset_management 7.1.1.2
ibm maximo_asset_management 7.1.1.6
ibm maximo_asset_management 7.1.1.5
ibm maximo_asset_management 7.1.1.11
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
CVE-2013-5382 MEDIUM

IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows remote authenticated users to gain privileges via unspecified vectors, a different vulnerability than CVE-2013-5383.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm maximo_asset_management 7.1.1.9
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.5.0.1
ibm maximo_asset_management 6.2.6
ibm maximo_asset_management 6.2.7
ibm maximo_asset_management 6.2.6.1
ibm maximo_asset_management 7.1.1.10
ibm maximo_asset_management 6.2.3
ibm maximo_asset_management 6.2.5
ibm maximo_asset_management 7.1.1.1
ibm maximo_asset_management 6.2.8
ibm maximo_asset_management 7.5.0.3
ibm maximo_asset_management 6.2.4
ibm maximo_asset_management 6.2.1
ibm maximo_asset_management 7.5.0.0
ibm maximo_asset_management 7.1.1.7
ibm maximo_asset_management 6.2
ibm maximo_asset_management 6.2.2
ibm maximo_asset_management 7.5.0.4
ibm maximo_asset_management 7.1.1.2
ibm maximo_asset_management 7.1.1.6
ibm maximo_asset_management 7.1.1.5
ibm maximo_asset_management 7.1.1.11
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
CVE-2013-5383 MEDIUM

IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows remote authenticated users to gain privileges via unspecified vectors, a different vulnerability than CVE-2013-5382.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm maximo_asset_management 7.1.1.9
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.5.0.1
ibm maximo_asset_management 6.2.6
ibm maximo_asset_management 6.2.7
ibm maximo_asset_management 6.2.6.1
ibm maximo_asset_management 7.1.1.10
ibm maximo_asset_management 6.2.3
ibm maximo_asset_management 6.2.5
ibm maximo_asset_management 7.1.1.1
ibm maximo_asset_management 6.2.8
ibm maximo_asset_management 7.5.0.3
ibm maximo_asset_management 6.2.4
ibm maximo_asset_management 6.2.1
ibm maximo_asset_management 7.5.0.0
ibm maximo_asset_management 7.1.1.7
ibm maximo_asset_management 6.2
ibm maximo_asset_management 6.2.2
ibm maximo_asset_management 7.5.0.4
ibm maximo_asset_management 7.1.1.2
ibm maximo_asset_management 7.1.1.6
ibm maximo_asset_management 7.1.1.5
ibm maximo_asset_management 7.1.1.11
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
CVE-2013-5385 HIGH

The OSPF implementation in IBM i 6.1 and 7.1, in z/OS on zSeries servers, and in Networking Operating System (aka NOS, formerly BLADE Operating System) does not properly validate Link State Advertisement (LSA) type 1 packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet information via a crafted LSA packet, a related issue to CVE-2013-0149.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm i 7.1
ibm z/os *
ibm i 6.1
CVE-2013-5387 MEDIUM

Buffer overflow in IBM Platform Symphony 5.2, 6.1, and 6.1.1 allows remote attackers to cause a denial of service (process crash or hang) via a malformed SOAP request with a large amount of request data.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm platform_symphony 5.2
ibm platform_symphony 6.1
ibm platform_symphony 6.1.1
CVE-2013-5388 MEDIUM

Cross-site scripting (XSS) vulnerability in iNotes in IBM Domino 8.5.3 before FP5 IF2 and 9.0 before IF5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka SPR PTHN9AYK5F.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm lotus_domino 8.5.3.0
ibm lotus_domino 9.0.0.0
CVE-2013-5389 MEDIUM

Cross-site scripting (XSS) vulnerability in iNotes in IBM Domino 8.5.3 before FP5 IF2 and 9.0 before IF5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka SPR PTHN9AYK2X.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm lotus_domino 8.5.3.0
ibm lotus_domino 9.0.0.0
CVE-2013-5390 LOW

Cross-site scripting (XSS) vulnerability in the monitoring console in IBM WebSphere eXtreme Scale 7.1.0, 7.1.1, 8.5.0, and 8.6.0 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_extreme_scale 8.6.0
ibm websphere_extreme_scale 7.1.0
ibm websphere_extreme_scale 8.5.0
ibm websphere_extreme_scale 7.1.1
CVE-2013-5391 LOW

IBM Worklight Consumer and Enterprise Editions 5.0.x before 5.0.6 Fix Pack 2 and 6.0.x before 6.0.0 Fix Pack 2, and Mobile Foundation Consumer and Enterprise Editions 5.0.x before 5.0.6 Fix Pack 2 and 6.0.0 Fix Pack 2 make it easier for attackers to defeat cryptographic protection mechanisms by leveraging improper initialization of the pseudo random number generator (PRNG) in Android and use of the Java Cryptography Architecture (JCA) by a Worklight program. IBM X-Force ID: 87128.

CVSS 2.0

Severity: LOW

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm worklight 5.0.5.0
ibm worklight 6.0.0.0
ibm worklight 5.0.0.0
ibm mobile_foundation 5.0.0.0
ibm mobile_foundation 5.0.5.0
ibm mobile_foundation 6.0.0.0
ibm worklight 5.0.6.0
ibm mobile_foundation 5.0.6.0
CVE-2013-5393 HIGH

The monitoring console in IBM WebSphere eXtreme Scale 7.1.0, 7.1.1, 8.5.0, and 8.6.0 does not properly process logoff actions, which has unspecified impact and remote attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_extreme_scale 8.6.0
ibm websphere_extreme_scale 7.1.0
ibm websphere_extreme_scale 8.5.0
ibm websphere_extreme_scale 7.1.1
CVE-2013-5394 MEDIUM

The monitoring console in IBM WebSphere eXtreme Scale 7.1.0, 7.1.1, 8.5.0, and 8.6.0 allows remote authenticated users to conduct phishing attacks via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm websphere_extreme_scale 8.6.0
ibm websphere_extreme_scale 7.1.0
ibm websphere_extreme_scale 8.5.0
ibm websphere_extreme_scale 7.1.1
CVE-2013-5395 HIGH

IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows remote attackers to bypass intended access restrictions via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm maximo_asset_management 7.1.1.9
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.5.0.1
ibm maximo_asset_management 6.2.6
ibm maximo_asset_management 6.2.7
ibm maximo_asset_management 6.2.6.1
ibm maximo_asset_management 7.1.1.10
ibm maximo_asset_management 6.2.3
ibm maximo_asset_management 6.2.5
ibm maximo_asset_management 7.1.1.1
ibm maximo_asset_management 6.2.8
ibm maximo_asset_management 7.5.0.3
ibm maximo_asset_management 6.2.4
ibm maximo_asset_management 6.2.1
ibm maximo_asset_management 7.5.0.0
ibm maximo_asset_management 7.1.1.7
ibm maximo_asset_management 6.2
ibm maximo_asset_management 6.2.2
ibm maximo_asset_management 7.5.0.4
ibm maximo_asset_management 7.1.1.2
ibm maximo_asset_management 7.1.1.6
ibm maximo_asset_management 7.1.1.5
ibm maximo_asset_management 7.1.1.11
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
CVE-2013-5397 LOW

Unspecified vulnerability in the Webservice Axis Gateway in IBM Rational Focal Point 6.4 before devfix1, 6.4.1.3 before devfix1, 6.5.1 before devfix1, 6.5.2 before devfix4, 6.5.2.3 before devfix9, 6.6 before devfix5, 6.6.0.1 before devfix2, and 6.6.1 allows remote attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2013-5398.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm rational_focal_point 6.4.1.3
ibm rational_focal_point 6.5.1
ibm rational_focal_point 6.6
ibm rational_focal_point 6.6.1
ibm rational_focal_point 6.5.2.3
ibm rational_focal_point 6.6.0.1
ibm rational_focal_point 6.5.2
ibm rational_focal_point 6.4
CVE-2013-5398 LOW

Unspecified vulnerability in the Webservice Axis Gateway in IBM Rational Focal Point 6.4 before devfix1, 6.4.1.3 before devfix1, 6.5.1 before devfix1, 6.5.2 before devfix4, 6.5.2.3 before devfix9, 6.6 before devfix5, 6.6.0.1 before devfix2, and 6.6.1 allows remote attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2013-5397.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm rational_focal_point 6.4.1.3
ibm rational_focal_point 6.5.1
ibm rational_focal_point 6.6
ibm rational_focal_point 6.6.1
ibm rational_focal_point 6.5.2.3
ibm rational_focal_point 6.6.0.1
ibm rational_focal_point 6.5.2
ibm rational_focal_point 6.4
CVE-2013-5400 HIGH

An unspecified servlet in IBM Platform Symphony Developer Edition (DE) 5.2 and 6.1.x through 6.1.1 has hardcoded credentials, which allows remote attackers to bypass authentication and obtain "local environment" access via unknown vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm platform_symphony 5.2
ibm platform_symphony 6.1.1
ibm platform_symphony 6.1.0
CVE-2013-5401 MEDIUM

The command-port listener in IBM WebSphere MQ Internet Pass-Thru (MQIPT) 2.x before 2.1.0.1 allows remote attackers to cause a denial of service (remote-administration outage) via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_mq_internet_pass_thru 2.1.0.0
CVE-2013-5402 LOW

Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management, Maximo Asset Management Essentials, Maximo for Government, Maximo for Nuclear Power, Maximo for Transportation, Maximo for Life Sciences, Maximo for Oil and Gas, and Maximo for Utilities 7.1.x through 7.1.1.12, 7.1.2, 7.5 before 7.5.0.3 IFIX014, and 7.5.0.5 before IFIX003; SmartCloud Control Desk (SCCD) 7.5 before 7.5.0.3 IFIX014 and 7.5.0.5 before IFIX003; and Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB) 7.1.x through 7.1.1.12, 7.1.2, and 7.2.x through 7.2.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_asset_management_for_it 7.2
ibm maximo_for_life_sciences 7.5.0.2
ibm maximo_asset_management 7.1.1.9
ibm maximo_for_government 7.5.0.4
ibm maximo_for_life_sciences 7.5.0.1
ibm tivoli_asset_management_for_it 7.1.2
ibm maximo_for_government 7.1
ibm maximo_for_nuclear_power 7.5.0.4
ibm maximo_asset_management 7.1.1.10
ibm maximo_asset_management 7.1.1.1
ibm tivoli_service_request_manager 7.1.2
ibm maximo_for_nuclear_power 7.5.0.0
ibm smartcloud_control_desk 7.5.0.5
ibm maximo_asset_management_essentials 7.5.0.0
ibm maximo_for_oil_and_gas 7.5.0.5
ibm maximo_for_nuclear_power 7.5.0.1
ibm maximo_for_life_sciences 7.5.0.4
ibm maximo_for_nuclear_power 7.1
ibm maximo_for_transportation 7.5.0.1
ibm maximo_for_utilities 7.5.0.2
ibm maximo_for_nuclear_power 7.5.0.3
ibm change_and_configuration_management_database 7.1.1.12
ibm maximo_for_government 7.5.0.1
ibm maximo_for_utilities 7.5.0.5
ibm maximo_asset_management_essentials 7.5.0.1
ibm maximo_asset_management_essentials 7.5.0.4
ibm maximo_for_life_sciences 7.1
ibm maximo_for_transportation 7.5.0.2
ibm maximo_for_transportation 7.5.0.4
ibm maximo_asset_management 7.1.1.7
ibm tivoli_service_request_manager 7.1.1.12
ibm maximo_for_utilities 7.5.0.3
ibm smartcloud_control_desk 7.5.0.2
ibm maximo_asset_management 7.5.0.5
ibm maximo_asset_management 7.1.1.2
ibm maximo_for_oil_and_gas 7.1
ibm maximo_asset_management 7.1.1.5
ibm tivoli_service_request_manager 7.2
ibm maximo_asset_management 7.1.1.11
ibm tivoli_asset_management_for_it 7.2.0.1
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
ibm change_and_configuration_management_database 7.2.0.1
ibm maximo_for_nuclear_power 7.5.0.5
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.5.0.1
ibm maximo_for_transportation 7.5.0.0
ibm tivoli_service_request_manager 7.2.0.1
ibm maximo_asset_management_essentials 7.5.0.5
ibm maximo_for_life_sciences 7.5.0.0
ibm maximo_for_utilities 7.1
ibm maximo_for_oil_and_gas 7.5.0.2
ibm smartcloud_control_desk 7.5.0.0
ibm maximo_for_oil_and_gas 7.5.0.3
ibm maximo_for_government 7.5.0.0
ibm maximo_asset_management 7.1.1.12
ibm change_and_configuration_management_database 7.2
ibm maximo_for_life_sciences 7.5.0.5
ibm maximo_asset_management 7.5.0.3
ibm maximo_asset_management_essentials 7.5.0.2
ibm maximo_for_government 7.5.0.2
ibm maximo_for_oil_and_gas 7.5.0.1
ibm maximo_for_nuclear_power 7.5.0.2
ibm maximo_for_utilities 7.5.0.0
ibm tivoli_service_request_manager 7.2.1.0
ibm maximo_for_life_sciences 7.5.0.3
ibm maximo_for_government 7.5.0.5
ibm maximo_for_transportation 7.1
ibm maximo_for_transportation 7.5.0.5
ibm maximo_asset_management_essentials 7.1
ibm maximo_asset_management 7.5.0.0
ibm maximo_for_oil_and_gas 7.5.0.4
ibm maximo_for_oil_and_gas 7.5.0.0
ibm tivoli_asset_management_for_it 7.1.1.12
ibm smartcloud_control_desk 7.5.0.1
ibm maximo_asset_management 7.1.1.6
ibm maximo_asset_management_essentials 7.5.0.3
ibm maximo_for_transportation 7.5.0.3
ibm maximo_asset_management 7.1.2
ibm change_and_configuration_management_database 7.1.2
ibm maximo_for_utilities 7.5.0.1
ibm maximo_for_government 7.5.0.3
ibm maximo_for_utilities 7.5.0.4
ibm smartcloud_control_desk 7.5.0.3
CVE-2013-5403 HIGH

Unspecified vulnerability on the IBM WebSphere DataPower XC10 appliance 2.0 through 2.5.0.1 allows remote attackers to obtain administrative access via unknown vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_datapower_xc10_appliance_firmware 2.0.0.2
ibm websphere_datapower_xc10_appliance_firmware 2.1.0.3
ibm websphere_datapower_xc10_appliance_firmware 2.1.0.1
ibm websphere_datapower_xc10_appliance_firmware 2.1.0.2
ibm websphere_datapower_xc10_appliance_firmware 2.0.0.1
ibm websphere_datapower_xc10_appliance_firmware 2.1.0.0
ibm websphere_datapower_xc10_appliance_firmware 2.0.0.0
ibm websphere_datapower_xc10_appliance_firmware 2.5.0.0
ibm websphere_datapower_xc10_appliance_firmware 2.5.0.1
ibm websphere_datapower_xc10_appliance_firmware 2.0.0.3
CVE-2013-5404 LOW

Cross-site scripting (XSS) vulnerability in the search implementation in IBM Rational Quality Manager (RQM) 2.0 through 2.0.1.1, 3.x before 3.0.1.6 iFix 1, and 4.x before 4.0.5, as used in Rational Team Concert, Rational Requirements Composer, and other products, allows remote authenticated users to inject arbitrary web script or HTML via vectors involving an IFRAME element.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_requirements_composer 3.0.1.4
ibm rational_quality_manager 2.0.0.2
ibm rational_requirements_composer 3.0.1.1
ibm rational_quality_manager 4.0.0.1
ibm rational_quality_manager 4.0.0.2
ibm rational_requirements_composer 2.0
ibm rational_requirements_composer 3.0.1.6
ibm rational_team_concert 2.0.0.2
ibm rational_quality_manager 2.0.1
ibm rational_team_concert 2.0.0.1
ibm rational_quality_manager 4.0.3
ibm rational_quality_manager 3.0.1.5
ibm rational_team_concert 4.0.1
ibm rational_team_concert 3.0.1.2
ibm rational_team_concert 4.0.5
ibm rational_team_concert 4.0.2
ibm rational_requirements_composer 2.0.0.3
ibm rational_requirements_composer 2.0.0.1
ibm rational_requirements_composer 3.0.1
ibm rational_requirements_composer 3.0.1.3
ibm rational_team_concert 3.0.1.4
ibm rational_quality_manager 3.0.1.6
ibm rational_team_concert 2.0
ibm rational_requirements_composer 4.0
ibm rational_quality_manager 2.0.0.1
ibm rational_quality_manager 3.0.1.1
ibm rational_requirements_composer 3.0
ibm rational_team_concert 4.0
ibm rational_requirements_composer 4.0.4
ibm rational_requirements_composer 4.0.1
ibm rational_requirements_composer 3.0.1.2
ibm rational_quality_manager 2.0.1.1
ibm rational_team_concert 4.0.3
ibm rational_team_concert 3.0
ibm rational_quality_manager 3.0.1.3
ibm rational_requirements_composer 2.0.0.4
ibm rational_team_concert 3.0.1
ibm rational_quality_manager 4.0
ibm rational_quality_manager 3.0
ibm rational_requirements_composer 2.0.0.2
ibm rational_quality_manager 2.0
ibm rational_quality_manager 4.0.1
ibm rational_requirements_composer 3.0.1.5
ibm rational_team_concert 3.0.1.5
ibm rational_team_concert 3.0.1.3
ibm rational_quality_manager 3.0.1.2
ibm rational_quality_manager 3.0.1
ibm rational_requirements_composer 4.0.2
ibm rational_requirements_composer 4.0.3
ibm rational_quality_manager 3.0.1.4
ibm rational_quality_manager 4.0.4
ibm rational_team_concert 4.0.4
ibm rational_quality_manager 4.0.2
ibm rational_team_concert 3.0.1.6
CVE-2013-5405 LOW

Multiple cross-site scripting (XSS) vulnerabilities in IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 allow remote authenticated users to inject arbitrary web script or HTML via unspecified parameters.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2
ibm sterling_file_gateway 2.2
CVE-2013-5406 LOW

Multiple cross-site scripting (XSS) vulnerabilities in IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 allow remote authenticated users to inject arbitrary web script or HTML via unspecified parameters, leading to improper interaction with the Windows MHTML protocol handler.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2
ibm sterling_file_gateway 2.2
CVE-2013-5407 MEDIUM

IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 do not properly restrict use of FRAME elements, which allows remote authenticated users to bypass intended access restrictions or obtain sensitive information via a crafted web site, related to a "frame injection" issue.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2
ibm sterling_file_gateway 2.2
CVE-2013-5409 MEDIUM

Multiple SQL injection vulnerabilities in IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2
ibm sterling_file_gateway 2.2
CVE-2013-5411 MEDIUM

IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 allow remote attackers to inject links and trigger unintended navigation or actions via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2
ibm sterling_file_gateway 2.2
CVE-2013-5413 MEDIUM

IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 do not invalidate a session upon a logout action, which allows remote attackers to bypass authentication by leveraging an unattended workstation.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2
ibm sterling_file_gateway 2.2
CVE-2013-5414 LOW

The migration functionality in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.31, 8.0 before 8.0.0.8, and 8.5 before 8.5.5.1 does not properly support the distinction between the admin role and the adminsecmanager role, which allows remote authenticated users to gain privileges in opportunistic circumstances by accessing resources in between a migration and a role evaluation.

CVSS 2.0

Severity: LOW

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 7.0
ibm websphere_application_server 8.0.0.5
ibm websphere_application_server 7.0.0.12
ibm websphere_application_server 8.5.0.2
ibm websphere_application_server 8.0.0.6
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 7.0.0.16
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 7.0.0.25
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 7.0.0.14
ibm websphere_application_server 7.0.0.22
ibm websphere_application_server 7.0.0.10
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0.0.29
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 7.0.0.24
ibm websphere_application_server 8.5.5.0
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 8.0.0.7
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 7.0.0.27
ibm websphere_application_server 7.0.0.18
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 7.0.0.4
ibm websphere_application_server 8.0.0.2
CVE-2013-5415 HIGH

Buffer overflow in IBM Rational ClearCase through 7.1.2.12, 8.0.0.x before 8.0.0.9, and 8.0.1.x before 8.0.1.2 allows local users to gain privileges via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm rational_clearcase 7.1.2.3
ibm rational_clearcase 8.0.0.1
ibm rational_clearcase 8.0.1
ibm rational_clearcase 7.1.0.1
ibm rational_clearcase 7.1.2.4
ibm rational_clearcase 8.0.0.7
ibm rational_clearcase 7.1.1.9
ibm rational_clearcase 7.1.2.11
ibm rational_clearcase 8.0.0.3
ibm rational_clearcase 8.0.0.6
ibm rational_clearcase 7.1.2.1
ibm rational_clearcase 8.0.0.8
ibm rational_clearcase 7.1.1.1
ibm rational_clearcase 7.1.2.2
ibm rational_clearcase 7.1.1.4
ibm rational_clearcase 7.1.1.6
ibm rational_clearcase 8.0.0.2
ibm rational_clearcase 7.1.0.2
ibm rational_clearcase 7.1.1.5
ibm rational_clearcase 7.1.1.7
ibm rational_clearcase 7.1.1.8
ibm rational_clearcase 7.1.1.2
ibm rational_clearcase 8.0.1.1
ibm rational_clearcase 7.1.2.5
ibm rational_clearcase 8.0
ibm rational_clearcase 7.1.1
ibm rational_clearcase 7.1.2.12
ibm rational_clearcase 7.1.2
ibm rational_clearcase 7.1
ibm rational_clearcase 8.0.0.4
ibm rational_clearcase 7.1.2.9
ibm rational_clearcase 8.0.0.5
ibm rational_clearcase 7.1.2.7
ibm rational_clearcase 7.1.1.3
ibm rational_clearcase 7.1.2.6
ibm rational_clearcase 7.1.2.10
CVE-2013-5416 HIGH

Unspecified vulnerability in IBM Rational ClearCase through 7.1.2.12, 8.0.0.x before 8.0.0.9, and 8.0.1.x before 8.0.1.2 allows local users to gain privileges via unknown vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm rational_clearcase 7.1.2.3
ibm rational_clearcase 8.0.0.1
ibm rational_clearcase 8.0.1
ibm rational_clearcase 7.1.0.1
ibm rational_clearcase 7.1.2.4
ibm rational_clearcase 8.0.0.7
ibm rational_clearcase 7.1.1.9
ibm rational_clearcase 7.1.2.11
ibm rational_clearcase 8.0.0.3
ibm rational_clearcase 8.0.0.6
ibm rational_clearcase 7.1.2.1
ibm rational_clearcase 8.0.0.8
ibm rational_clearcase 7.1.1.1
ibm rational_clearcase 7.1.2.2
ibm rational_clearcase 7.1.1.4
ibm rational_clearcase 7.1.1.6
ibm rational_clearcase 8.0.0.2
ibm rational_clearcase 7.1.0.2
ibm rational_clearcase 7.1.1.5
ibm rational_clearcase 7.1.1.7
ibm rational_clearcase 7.1.1.8
ibm rational_clearcase 7.1.1.2
ibm rational_clearcase 8.0.1.1
ibm rational_clearcase 7.1.2.5
ibm rational_clearcase 8.0
ibm rational_clearcase 7.1.1
ibm rational_clearcase 7.1.2.12
ibm rational_clearcase 7.1.2
ibm rational_clearcase 7.1
ibm rational_clearcase 8.0.0.4
ibm rational_clearcase 7.1.2.9
ibm rational_clearcase 8.0.0.5
ibm rational_clearcase 7.1.2.7
ibm rational_clearcase 7.1.1.3
ibm rational_clearcase 7.1.2.6
ibm rational_clearcase 7.1.2.10
CVE-2013-5417 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.31, 8.0 before 8.0.0.8, and 8.5 before 8.5.5.1 allows remote attackers to inject arbitrary web script or HTML via HTTP response data.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 7.0
ibm websphere_application_server 8.0.0.5
ibm websphere_application_server 7.0.0.12
ibm websphere_application_server 8.5.0.2
ibm websphere_application_server 8.0.0.6
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 7.0.0.16
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 7.0.0.25
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 7.0.0.14
ibm websphere_application_server 7.0.0.22
ibm websphere_application_server 7.0.0.10
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0.0.29
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 7.0.0.24
ibm websphere_application_server 8.5.5.0
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 8.0.0.7
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 7.0.0.27
ibm websphere_application_server 7.0.0.18
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 7.0.0.4
ibm websphere_application_server 8.0.0.2
CVE-2013-5418 LOW

Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.31, 8.0 before 8.0.0.8, and 8.5 before 8.5.5.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 7.0
ibm websphere_application_server 8.0.0.5
ibm websphere_application_server 7.0.0.12
ibm websphere_application_server 8.5.0.2
ibm websphere_application_server 8.0.0.6
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 7.0.0.16
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 7.0.0.25
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 7.0.0.14
ibm websphere_application_server 7.0.0.22
ibm websphere_application_server 7.0.0.10
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0.0.29
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 7.0.0.24
ibm websphere_application_server 8.5.5.0
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 8.0.0.7
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 7.0.0.27
ibm websphere_application_server 7.0.0.18
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 7.0.0.4
ibm websphere_application_server 8.0.0.2
CVE-2013-5419 MEDIUM

Multiple buffer overflows in (1) mkque and (2) mkquedev in bos.rte.printers in IBM AIX 6.1 and 7.1 allow local users to gain privileges by leveraging printq group membership.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm aix 6.1
ibm aix 7.1
CVE-2013-5420 LOW

The IMS server before Ifix 6 in IBM Security Access Manager for Enterprise Single Sign-On (ISAM ESSO) 8.2 allows remote authenticated users to read log files by leveraging helpdesk privileges for a direct request.

CVSS 2.0

Severity: LOW

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm security_access_manager_for_enterprise_single_sign-on 8.2
CVE-2013-5421 MEDIUM

Cross-site scripting (XSS) vulnerability in the IMS server before Ifix 6 in IBM Security Access Manager for Enterprise Single Sign-On (ISAM ESSO) 8.2 allows remote attackers to inject arbitrary web script or HTML via crafted input to an unspecified dynamic web form.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm security_access_manager_for_enterprise_single_sign-on 8.2
CVE-2013-5422 MEDIUM

The Web Client in IBM Rational ClearQuest 7.1 through 7.1.2.12, 8.0.0.x before 8.0.0.9, and 8.0.1.x before 8.0.1.2, when a multi-database dataset exists, allows remote attackers to read database names via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_clearcase 7.1.2.3
ibm rational_clearcase 8.0.0.1
ibm rational_clearcase 8.0.1
ibm rational_clearcase 7.1.0.1
ibm rational_clearcase 7.1.2.4
ibm rational_clearcase 8.0.0.7
ibm rational_clearcase 7.1.1.9
ibm rational_clearcase 7.1.2.11
ibm rational_clearcase 8.0.0.3
ibm rational_clearcase 8.0.0.6
ibm rational_clearcase 7.1.2.1
ibm rational_clearcase 8.0.0.8
ibm rational_clearcase 7.1.1.1
ibm rational_clearcase 7.1.2.2
ibm rational_clearcase 7.1.1.4
ibm rational_clearcase 7.1.1.6
ibm rational_clearcase 8.0.0.2
ibm rational_clearcase 7.1.0.2
ibm rational_clearcase 7.1.1.5
ibm rational_clearcase 7.1.1.7
ibm rational_clearcase 7.1.1.8
ibm rational_clearcase 7.1.1.2
ibm rational_clearcase 8.0.1.1
ibm rational_clearcase 7.1.2.5
ibm rational_clearcase 8.0
ibm rational_clearcase 7.1.1
ibm rational_clearcase 7.1.2.12
ibm rational_clearcase 7.1.2
ibm rational_clearcase 7.1
ibm rational_clearcase 8.0.0.4
ibm rational_clearcase 7.1.2.9
ibm rational_clearcase 8.0.0.5
ibm rational_clearcase 7.1.2.7
ibm rational_clearcase 7.1.1.3
ibm rational_clearcase 7.1.2.6
ibm rational_clearcase 7.1.2.10
CVE-2013-5423 MEDIUM

IBM Flex System Manager (FSM) 1.1 through 1.3 before 1.3.2.0 allows remote attackers to enumerate user accounts via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm flex_system_manager 1.2.0
ibm flex_system_manager 1.1.0
ibm flex_system_manager 1.3.0
ibm flex_system_manager 1.2.1
ibm flex_system_manager 1.3.1
CVE-2013-5424 MEDIUM

IBM Flex System Manager (FSM) 1.3.0 allows remote attackers to bypass intended access restrictions, and create new user accounts or execute tasks, by leveraging an expired password for the system-level account.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm flex_system_manager 1.3.0
CVE-2013-5425 LOW

Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Virtual Enterprise 6.1 before 6.1.1.6 and 7.0 before 7.0.0.4 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_virtual_enterprise 6.1
ibm websphere_virtual_enterprise 6.1.1.1
ibm websphere_virtual_enterprise 7.0.0.2
ibm websphere_virtual_enterprise 7.0.0.1
ibm websphere_virtual_enterprise 6.1.1.3
ibm websphere_virtual_enterprise 6.1.1.2
ibm websphere_virtual_enterprise 6.1.1.5
ibm websphere_virtual_enterprise 7.0.0.3
ibm websphere_virtual_enterprise 6.1.1
ibm websphere_virtual_enterprise 6.1.1.4
ibm websphere_virtual_enterprise 7.0
CVE-2013-5426 MEDIUM

Session fixation vulnerability in IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1 IF5 and 11.0 before IF1 and InfoSphere Master Data Management Server for Product Information Management 9.x before 9.1 IF11 allows remote authenticated users to hijack web sessions via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm infosphere_master_data_management_collaboration_server 10.0
ibm infosphere_master_data_management_server_for_product_information_management 9.1
ibm infosphere_master_data_management_collaboration_server 10.1
ibm infosphere_master_data_management_server_for_product_information_management 9.0
ibm infosphere_master_data_management_collaboration_server 11.0
CVE-2013-5427 MEDIUM

Cross-site request forgery (CSRF) vulnerability in IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1 FP8 through 11.0 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 allows remote attackers to hijack the authentication of arbitrary users.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm infosphere_master_data_management_collaboration_server 10.0
ibm infosphere_master_data_management_server_for_product_information_management 9.1
ibm infosphere_master_data_management_collaboration_server 10.1
ibm infosphere_master_data_management_server_for_product_information_management 9.0
ibm infosphere_master_data_management_collaboration_server 11.0
CVE-2013-5428 HIGH

IBM WebSphere DataPower XC10 appliances 2.5.0 do not require authentication for all administrative actions, which allows remote attackers to cause a denial of service via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_datapower_xc10_appliance_firmware 2.5.0.0
ibm websphere_datapower_xc10_appliance -
CVE-2013-5429 LOW

The Risk Based Access functionality in IBM Tivoli Federated Identity Manager (TFIM) 6.2.2 before FP9 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.2.2 before FP9 does not prevent reuse of One Time Password (OTP) tokens, which makes it easier for remote authenticated users to complete transactions by leveraging access to an already-used token.

CVSS 2.0

Severity: LOW

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm tivoli_federated_identity_manager 6.2.2.2
ibm tivoli_federated_identity_manager 6.2.2.5
ibm tivoli_federated_identity_manager 6.2.2.7
ibm tivoli_federated_identity_manager 6.2.2
ibm tivoli_federated_identity_manager 6.2.2.6
ibm tivoli_federated_identity_manager 6.2.2.4
ibm tivoli_federated_identity_manager 6.2.2.8
ibm tivoli_federated_identity_manager 6.2.2.1
ibm tivoli_federated_identity_manager 6.2.2.3
CVE-2013-5430 MEDIUM

The Jazz Team Server component in IBM Security AppScan Enterprise 8.x before 8.8 has a default username and password, which makes it easier for remote authenticated users to obtain unspecified access to this component by leveraging this credential information in an environment with applicable component installation details.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm security_appscan 8.0.0.1
ibm security_appscan 8.0.11
ibm security_appscan 8.6.0.2
ibm security_appscan 8.6.0.1
ibm security_appscan 8.6.0.0
ibm security_appscan 8.0.1.0
ibm security_appscan 8.0.1.1
ibm security_appscan 8.5.0.1
ibm security_appscan 8.0.0.2
ibm security_appscan 8.0.0.0
ibm security_appscan 8.7.0.0
ibm security_appscan 8.7.0.1
ibm security_appscan 8.5.0.0
CVE-2013-5431 MEDIUM

Open redirect vulnerability in IBM Tivoli Federated Identity Manager (TFIM) 6.1.1 before IF 15, 6.2.0 before IF 14, 6.2.1, and 6.2.2 before IF 8 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.1.1 before IF 15, 6.2.0 before IF 14, 6.2.1, and 6.2.2 before IF 8 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm tivoli_federated_identity_manager_business_gateway 6.1.1
ibm tivoli_federated_identity_manager_business_gateway 6.2.2
ibm tivoli_federated_identity_manager 6.1.1
ibm tivoli_federated_identity_manager 6.2.1
ibm tivoli_federated_identity_manager 6.2.2
ibm tivoli_federated_identity_manager_business_gateway 6.2.0
ibm tivoli_federated_identity_manager_business_gateway 6.2.1
ibm tivoli_federated_identity_manager 6.2.0
CVE-2013-5433 MEDIUM

The Data Growth Solution for JD Edwards EnterpriseOne in IBM InfoSphere Optim 3.0 through 9.1 has hardcoded database credentials, which allows remote authenticated users to obtain sensitive information by reading an unspecified field in an XML document.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm infosphere_optim_data_growth_solution_for_siebel_crm 3.2.3
ibm infosphere_optim_data_growth_solution_for_siebel_crm 3.2
ibm infosphere_optim_data_growth_solution_for_siebel_crm 3.2.1
ibm infosphere_optim_data_growth_solution_for_siebel_crm 3.2.2
ibm infosphere_optim_data_growth_solution_for_siebel_crm 9.1
CVE-2013-5438 MEDIUM

Cross-site scripting (XSS) vulnerability in the web server in IBM Flex System Manager (FSM) 1.1.0 through 1.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm flex_system_manager 1.1.0
ibm flex_system_manager 1.3.0
CVE-2013-5440 LOW

IBM InfoSphere Information Server 8.0, 8.1, 8.5, 8.7, and 9.1 allows local users to obtain sensitive information in opportunistic circumstances by leveraging the presence of file content after a failed installation.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm infosphere_information_server 8.1
ibm infosphere_information_server 8.5
ibm infosphere_information_server 9.1
ibm infosphere_information_server 8.0
ibm infosphere_information_server 8.7
CVE-2013-5442 MEDIUM

Cross-site scripting (XSS) vulnerability in the Local Management Interface (LMI) in IBM Security Network Protection on XGS 5100 devices with firmware 5.1 before 5.1.0.6 and 5.1.1 before 5.1.1.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm security_network_protection_firmware 5.1
ibm security_network_protection_firmware 5.1.1
ibm security_network_protection_xgs_5100 -
CVE-2013-5443 MEDIUM

Cross-site request forgery (CSRF) vulnerability in IBM Cognos Express 9.0 before IFIX 2, 9.5 before IFIX 2, 10.1 before IFIX 2, and 10.2.1 before FP1 allows remote attackers to hijack the authentication of arbitrary users.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm cognos_express 9.0
ibm cognos_express 10.1
ibm cognos_express 10.2.1
ibm cognos_express 9.5
CVE-2013-5444 MEDIUM

The server in IBM Cognos Express 9.0 before IFIX 2, 9.5 before IFIX 2, 10.1 before IFIX 2, and 10.2.1 before FP1 allows remote attackers to read encrypted credentials via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm cognos_express 9.0
ibm cognos_express 10.1
ibm cognos_express 10.2.1
ibm cognos_express 9.5
CVE-2013-5445 MEDIUM

IBM Cognos Express 9.0 before IFIX 2, 9.5 before IFIX 2, 10.1 before IFIX 2, and 10.2.1 before FP1 allows local users to obtain sensitive cleartext information by leveraging knowledge of a static decryption key.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm cognos_express 9.0
ibm cognos_express 10.1
ibm cognos_express 10.2.1
ibm cognos_express 9.5
CVE-2013-5446 HIGH

The console on IBM WebSphere DataPower XC10 appliances 2.1.0 and 2.5.0 does not properly process logoff actions, which has unspecified impact and remote attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_datapower_xc10_appliance_firmware 2.1.0.0
ibm websphere_datapower_xc10_appliance_firmware 2.5.0.0
ibm websphere_datapower_xc10_appliance -
CVE-2013-5447 MEDIUM

Stack-based buffer overflow in IBM Forms Viewer 4.x before 4.0.0.3 and 8.x before 8.0.1.1 allows remote attackers to execute arbitrary code via an XFDL form with a long fontname value.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm forms_viewer 8.0.0
ibm forms_viewer 4.0.0
ibm forms_viewer 4.0.0.2
ibm forms_viewer 8.0.1
ibm forms_viewer 4.0.0.1
CVE-2013-5448 LOW

Cross-site scripting (XSS) vulnerability in the Right Click Plugin context menus in IBM Security QRadar SIEM 7.1 and 7.2 before 7.2 MR1 Patch 1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.0
ibm qradar_security_information_and_event_manager 7.1.0
CVE-2013-5449 MEDIUM

Cross-site scripting (XSS) vulnerability in workingSet.jsp in IBM Eclipse Help System (IEHS), as used in the installable InfoCenter component in IBM FileNet Content Manager 4.5.1, 5.0.0, 5.1.0, and 5.2.0, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm filenet_content_manager 4.5.1
ibm filenet_content_manager 5.0.0
ibm filenet_content_manager 5.1.0
ibm filenet_content_manager 5.2.0
CVE-2013-5450 MEDIUM

IBM Security AppScan Enterprise 8.5 through 8.7.0.1, when Jazz authentication is enabled, allows man-in-the-middle attackers to obtain sensitive information or modify data by leveraging an improperly protected URL to obtain a session token.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm security_appscan 8.5.0.1
ibm security_appscan 8.6.0.2
ibm security_appscan 8.6.0.1
ibm security_appscan 8.7.0.0
ibm security_appscan 8.7.0.1
ibm security_appscan 8.6.0.0
ibm security_appscan 8.5.0.0
CVE-2013-5452 LOW

IBM FileNet Business Process Framework 4.1.0 allows remote authenticated users to read arbitrary files or send TCP requests to intranet servers via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm filenet_business_process_framework 4.1.0
CVE-2013-5453 LOW

IBM Security AppScan Enterprise 5.6 through 8.7.0.1 allows remote authenticated users to read arbitrary report files by leveraging knowledge of filenames that cannot be easily predicted.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_appscan 8.0.0.1
ibm security_appscan 8.0.11
ibm security_appscan 8.6.0.2
ibm security_appscan 5.6.0.0
ibm security_appscan 8.6.0.1
ibm security_appscan 6.0.0.0
ibm security_appscan 8.6.0.0
ibm security_appscan 6.0.2.0
ibm security_appscan 8.0.1.0
ibm security_appscan 8.0.1.1
ibm security_appscan 8.5.0.1
ibm security_appscan 8.0.0.2
ibm security_appscan 6.1.1.0
ibm security_appscan 8.0.0.0
ibm security_appscan 8.7.0.0
ibm security_appscan 8.7.0.1
ibm security_appscan 8.5.0.0
ibm security_appscan 6.0.1.0
CVE-2013-5454 MEDIUM

IBM WebSphere Portal 6.0 through 6.0.1.7, 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF25, and 8.0 through 8.0.0.1 CF08 allows remote attackers to read arbitrary files via a modified URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.0
ibm websphere_portal 6.1.0.3
ibm websphere_portal 6.0.1.0
ibm websphere_portal 6.0.1.1
ibm websphere_portal 6.1.0.4
ibm websphere_portal 8.0.0.1
ibm websphere_portal 6.0.1.3
ibm websphere_portal 6.0.0.1
ibm websphere_portal 6.1.5.0
ibm websphere_portal 6.1.5.3
ibm websphere_portal 6.1.0.1
ibm websphere_portal 6.1.5.1
ibm websphere_portal 6.1.0.0
ibm websphere_portal 6.0.1.4
ibm websphere_portal 8.0
ibm websphere_portal 6.0.0.0
ibm websphere_portal 6.1
ibm websphere_portal 7.0.0.1
ibm websphere_portal 6.1.5.2
ibm websphere_portal 6.1.0.2
ibm websphere_portal 6.0.1.6
ibm websphere_portal 6.0.1.2
ibm websphere_portal 6.0.1.5
ibm websphere_portal 7.0.0.2
ibm websphere_portal 7.0.0.0
ibm websphere_portal 6.1.0.5
CVE-2013-5455 MEDIUM

IBM SmartCloud Provisioning 2.1 before FP3 IF0001 allows remote authenticated users to modify virtual-system deployment via deployer.virtualsystems CLI commands, as demonstrated by a deletion using a deployer.virtualsystems[#].delete command.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm smartcloud_provisioning 2.1.0
CVE-2013-5456 HIGH

The com.ibm.rmi.io.SunSerializableFactory class in IBM Java SDK 7.0.0 before SR6 allows remote attackers to bypass a sandbox protection mechanism and execute arbitrary code via vectors related to deserialization inside the AccessController doPrivileged block.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm java 7.0.0.0
CVE-2013-5457 HIGH

Unspecified vulnerability in IBM Java SDK 7.0.0 before SR6, 6.0.1 before SR7, and 6.0.0 before SR15 allows remote attackers to execute arbitrary code via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm java 7.0.0.0
ibm java 6.0.0.0
ibm java 6.0.1.0
CVE-2013-5458 HIGH

Unspecified vulnerability in IBM Java SDK 7.0.0 before SR6 allows remote attackers to execute arbitrary code via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm java 7.0.0.0
CVE-2013-5459 MEDIUM

Unspecified vulnerability in IBM Rational Software Architect (RSA) Design Manager and Rational Rhapsody Design Manager 3.x through 3.0.1 and 4.x before 4.0.6 allows remote authenticated users to modify data by leveraging improper parameter checking.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm rational_software_architect_design_manager 3.0.0.1
ibm rhapsody_design_manager 4.0.3
ibm rhapsody_design_manager 3.0.1
ibm rational_software_architect_design_manager 3.0.1
ibm rhapsody_design_manager 3.0.0
ibm rhapsody_design_manager 4.0.1
ibm rational_software_architect_design_manager 4.0.2
ibm rational_software_architect_design_manager 4.0.3
ibm rational_software_architect_design_manager 3.0.0
ibm rational_software_architect_design_manager 4.0.0
ibm rational_software_architect_design_manager 4.0.5
ibm rhapsody_design_manager 4.0.2
ibm rhapsody_design_manager 4.0.4
ibm rhapsody_design_manager 3.0.0.1
ibm rhapsody_design_manager 4.0.0
ibm rhapsody_design_manager 4.0.5
ibm rational_software_architect_design_manager 4.0.1
ibm rational_software_architect_design_manager 4.0.4
CVE-2013-5460 LOW

IBM Maximo Asset Management 7.x before 7.5.0.6 and SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2 allow remote authenticated users to bypass intended access restrictions, and read communication logs associated with unrelated records, via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm maximo_asset_management 7.1.1.9
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.5.0.1
ibm maximo_asset_management 7.1.1.10
ibm maximo_asset_management 7.1.1.1
ibm smartcloud_control_desk 7.5.0.0
ibm maximo_asset_management 7.1.1.12
ibm maximo_asset_management 7.5.0.3
ibm smartcloud_control_desk 7.0
ibm maximo_asset_management 7.5.0.0
ibm maximo_asset_management 7.1.1.7
ibm smartcloud_control_desk 7.5.1.1
ibm maximo_asset_management 7.5.0.4
ibm smartcloud_control_desk 7.5.0.2
ibm smartcloud_control_desk 7.5
ibm maximo_asset_management 7.5.0.5
ibm maximo_asset_management 7.1.1.2
ibm smartcloud_control_desk 7.5.0.1
ibm maximo_asset_management 7.1.1.6
ibm maximo_asset_management 7.1.1.5
ibm smartcloud_control_desk 7.5.1.0
ibm maximo_asset_management 7.1.1.11
ibm maximo_asset_management 7.1.2
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
CVE-2013-5461 MEDIUM

IBM Endpoint Manager for Remote Control 9.0.0 and 9.0.1 and Tivoli Remote Control 5.1.2 store multiple hashes of partial passwords, which makes it easier for remote attackers to decrypt passwords by leveraging access to the hashes. IBM X-Force ID: 88309.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm tivoli_remote_control 5.1.2
ibm endpoint_manager_for_remote_control 9.0.1
ibm endpoint_manager_for_remote_control 9.0.0
CVE-2013-5462 MEDIUM

IBM/ECMClient/configure/explodedformat/navigator/header.jsp in IBM Content Navigator 2.0.0, 2.0.1 before 2.0.1.2-ICN-FP002, and 2.0.2 before 2.0.2.1-ICN-FP001 allows remote attackers to conduct clickjacking attacks via vectors involving FRAME elements.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm content_navigator 2.0.1
ibm content_navigator 2.0.2
ibm content_navigator 2.0.0
CVE-2013-5463 MEDIUM

The WinCollect agent in IBM Security QRadar SIEM before 7.1.1.569824 allows remote attackers to bypass intended access restrictions by injecting a (1) DLL or (2) configuration file.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.0.0
ibm qradar_security_information_and_event_manager 7.0.1
ibm qradar_security_information_and_event_manager *
CVE-2013-5464 MEDIUM

IBM Maximo Asset Management 7.5.x before 7.5.0.3 IFIX027, 7.5.0.4 before IFIX011, and 7.5.0.5 before IFIX006 and SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2 allow remote authenticated users to bypass intended access restrictions, and modify physical counts associated with restricted storerooms, via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management 7.5.0.1
ibm maximo_asset_management 7.5.0.0
ibm smartcloud_control_desk 7.5.0.0
ibm smartcloud_control_desk 7.5.1.1
ibm maximo_asset_management 7.5.0.4
ibm smartcloud_control_desk 7.5.0.2
ibm smartcloud_control_desk 7.5
ibm maximo_asset_management 7.5.0.5
ibm smartcloud_control_desk 7.5.0.1
ibm smartcloud_control_desk 7.5.1.0
ibm maximo_asset_management 7.5.0.3
ibm smartcloud_control_desk 7.0
CVE-2013-5465 MEDIUM

IBM Maximo Asset Management 7.x before 7.1.1.7 LAFIX.20140319-0837, 7.1.1.11 before IFIX.20140323-0749, 7.1.1.12 before IFIX.20140321-1336, 7.5.x before 7.5.0.3 IFIX027, and 7.5.0.4 before IFIX011; SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2; and Tivoli IT Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB) 7.x before 7.1.1.7 LAFIX.20140319-0837, 7.1.1.11 before IFIX.20140207-1801, and 7.1.1.12 before IFIX.20140218-1510 do not properly restrict file types during uploads, which allows remote authenticated users to have an unspecified impact via an invalid type.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm tivoli_it_asset_management_for_it 7.1.1.12
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.5.0.1
ibm maximo_service_desk 7.1.1.11
ibm maximo_asset_management 7.1.1.1
ibm tivoli_asset_management_for_it 7.0
ibm smartcloud_control_desk 7.5.0.0
ibm tivoli_it_asset_management_for_it 7.1.1.7
ibm change_and_configuration_management_database 7.1.1.7
ibm maximo_asset_management 7.1.1.12
ibm maximo_asset_management 7.5.0.3
ibm tivoli_service_request_manager 7.1.1.11
ibm smartcloud_control_desk 7.0
ibm change_and_configuration_management_database 7.1.1.11
ibm change_and_configuration_management_database 7.1.1.12
ibm tivoli_service_request_manager 7.1.1.7
ibm tivoli_asset_management_for_it 7.1
ibm maximo_service_desk 7.1.1.12
ibm maximo_asset_management 7.5.0.0
ibm maximo_asset_management 7.1.1.7
ibm tivoli_service_request_manager 7.1.1.12
ibm smartcloud_control_desk 7.5.1.1
ibm maximo_asset_management 7.5.0.4
ibm smartcloud_control_desk 7.5.0.2
ibm smartcloud_control_desk 7.5
ibm tivoli_service_request_manager 7.1.1
ibm maximo_asset_management 7.1.1.2
ibm maximo_service_desk 7.1.1.7
ibm smartcloud_control_desk 7.5.0.1
ibm maximo_asset_management 7.1.1.6
ibm maximo_asset_management 7.1.1.5
ibm smartcloud_control_desk 7.5.1.0
ibm maximo_asset_management 7.1.1.11
ibm maximo_asset_management 7.1.1
ibm tivoli_it_asset_management_for_it 7.1.1.11
CVE-2013-5466 MEDIUM

The XSLT library in IBM DB2 and DB2 Connect 9.5 through 10.5, and the DB2 pureScale Feature 9.8 for Enterprise Server Edition, allows remote authenticated users to cause a denial of service via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2_connect 10.1
ibm db2_connect 9.5
ibm db2_connect 10.5
ibm db2 9.5
ibm db2 10.1
ibm db2 9.8
ibm db2_connect 9.8
ibm db2_purescale_feature_9.8 -
ibm db2_connect 9.7
ibm db2 9.7
CVE-2013-5467 HIGH

Monitoring Agent for UNIX Logs 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP09, and 6.2.3 through FP04 and Monitoring Server (ms) and Shared Libraries (ax) 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP08, 6.2.3 through FP01, and 6.3.0 through FP01 in IBM Tivoli Monitoring (ITM) on UNIX allow local users to gain privileges via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm monitoring_agent_for_unix_logs 6.2.3
ibm monitoring_server_(ms)_and_shared_libraries_(ax) 6.2.0
ibm monitoring_server_(ms)_and_shared_libraries_(ax) 6.2.1
ibm monitoring_agent_for_unix_logs 6.2.1
ibm monitoring_agent_for_unix_logs 6.2.2
ibm monitoring_server_(ms)_and_shared_libraries_(ax) 6.2.2
ibm monitoring_server_(ms)_and_shared_libraries_(ax) 6.2.3
ibm monitoring_server_(ms)_and_shared_libraries_(ax) 6.3.0
ibm monitoring_agent_for_unix_logs 6.2.0
CVE-2013-5468 MEDIUM

IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Security Access Control Management 4.7.0 through 4.9.0, and ACSWeb in AlgoWebApps 5.0.0, does not encrypt login requests, which allows remote attackers to obtain sensitive information by sniffing the network.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm algo_one 4.9.0
ibm algo_one 4.7.1
ibm algo_one 4.7.0
ibm algo_one 4.8.0
ibm algo_one 4.9.1
ibm algo_one 5.0.0
CVE-2013-6299 LOW

Cross-site scripting (XSS) vulnerability in IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Security Access Control Management 4.7.0 through 4.9.0, and ACSWeb in AlgoWebApps 5.0.0, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2013-6300, CVE-2013-6301, CVE-2013-6320, and CVE-2013-6333.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm algo_one 4.9.0
ibm algo_one 4.7.1
ibm algo_one 4.7.0
ibm algo_one 4.8.0
ibm algo_one 4.9.1
ibm algo_one 5.0.0
CVE-2013-6300 LOW

Cross-site scripting (XSS) vulnerability in IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Security Access Control Management 4.7.0 through 4.9.0, and ACSWeb in AlgoWebApps 5.0.0, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2013-6299, CVE-2013-6301, CVE-2013-6320, and CVE-2013-6333.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm algo_one 4.9.0
ibm algo_one 4.7.1
ibm algo_one 4.7.0
ibm algo_one 4.8.0
ibm algo_one 4.9.1
ibm algo_one 5.0.0
CVE-2013-6301 LOW

Cross-site scripting (XSS) vulnerability in IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Security Access Control Management 4.7.0 through 4.9.0, and ACSWeb in AlgoWebApps 5.0.0, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2013-6299, CVE-2013-6300, CVE-2013-6320, and CVE-2013-6333.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm algo_one 4.9.0
ibm algo_one 4.7.1
ibm algo_one 4.7.0
ibm algo_one 4.8.0
ibm algo_one 4.9.1
ibm algo_one 5.0.0
CVE-2013-6302 MEDIUM

SQL injection vulnerability in IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Security Access Control Management 4.7.0 through 4.9.0, and ACSWeb in AlgoWebApps 5.0.0, allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2013-6331.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm algo_one 4.9.0
ibm algo_one 4.7.1
ibm algo_one 4.7.0
ibm algo_one 4.8.0
ibm algo_one 4.9.1
ibm algo_one 5.0.0
CVE-2013-6303 MEDIUM

Directory traversal vulnerability in IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Security Access Control Management 4.7.0 through 4.9.0, and ACSWeb in AlgoWebApps 5.0.0, allows remote authenticated users to read arbitrary files via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm algo_one 4.9.0
ibm algo_one 4.7.1
ibm algo_one 4.7.0
ibm algo_one 4.8.0
ibm algo_one 4.9.1
ibm algo_one 5.0.0
CVE-2013-6304 MEDIUM

Multiple directory traversal vulnerabilities in Algo Risk Application (ARA) 2.4.0.1 through 4.9.1 in IBM Algo One allow remote authenticated users to bypass intended access restrictions via a crafted pathname for a (1) configuration or (2) JAR file.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm algo_risk_application 4.9.1
ibm algo_risk_application 2.4.2
ibm algo_risk_application 2.5.7.1
ibm algo_risk_application 4.7.1
ibm algo_one 4.9.1
ibm algo_risk_application 2.5.5.2
ibm algo_risk_application 2.5.6
ibm algo_risk_application 2.5.0
ibm algo_risk_application 2.5.1
ibm algo_risk_application 4.7.0
ibm algo_risk_application 2.5.8
ibm algo_risk_application 4.8.0
ibm algo_risk_application 4.9.0
ibm algo_risk_application 2.5.7.2
ibm algo_risk_application 4.6.1
ibm algo_risk_application 4.5.1
ibm algo_risk_application 4.6.0
ibm algo_risk_application 2.5.2
ibm algo_risk_application 2.5.3
ibm algo_risk_application 2.5.4
ibm algo_risk_application 2.4.0.1
ibm algo_risk_application 4.5.4
ibm algo_risk_application 2.5.5
ibm algo_risk_application 4.5.2
ibm algo_risk_application 2.4.1
ibm algo_risk_application 4.5.3
CVE-2013-6305 MEDIUM

IBM Platform Symphony 5.2 before build 229037 and 6.1.0.1 before build 229073 uses the same credentials encryption key across different customers' installations, which makes it easier for context-dependent attackers to obtain sensitive information by leveraging knowledge of this key.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm platform_symphony 5.2
ibm platform_symphony 6.1.0.1
CVE-2013-6306 MEDIUM

Unspecified vulnerability on IBM Power 7 Systems 740 before 740.70 01Ax740_121, 760 before 760.40 Ax760_078, and 770 before 770.30 01Ax770_062 allows local users to gain Service Processor privileges via unknown vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm power_740_firmware 740.10_01ax740_043_042
ibm power_730 8231-e2d
ibm powerlinux_7r1 8246-l1d
ibm power_770_firmware 770.10_01ax770_038_032
ibm power_750 8408-e8d
ibm power_760_firmware 760.10_ax760_043_043
ibm power_760_firmware 760.31_ah760_069_043
ibm power_740_firmware 740.20_01ax740_075_042
ibm power_720 8202-e4d
ibm power_770_firmware 770.21_01ax770_052_032
ibm power_760_firmware 760.11_ax760_051_034
ibm power_740_firmware 740.15_01ax740_045_042
ibm power_760_firmware 760.10_ax760_043_034
ibm power_ese 8412-ead
ibm power_760 9109-rmd
ibm power_720 8202-e4c
ibm power_740_firmware 740.21_01ax740_077_042
ibm power_740_firmware 740.16_01ax740_046_042
ibm power_740_firmware 740.40_01ax740_088_042
ibm power_740_firmware 740.61_01ax740_112_042
ibm power_760_firmware 760.30_ah760_068_043
ibm powerlinux_7r2 8246-l2d
ibm power_795 9119-fhb
ibm power_770 9117-mmc
ibm power_760_firmware 760.00_ax760_034_034
ibm power_760_firmware 760.30_am760_068_034
ibm power_740 8205-e6c
ibm power_760_firmware 760.20_am760_062_034
ibm power_740_firmware 740.51_01ax740_098_042
ibm power_770_firmware 770.00_01al770_032_032
ibm power_710 8268-e1d
ibm power_770 9117-mmd
ibm power_770_firmware 770.20_01ax770_048_032
ibm power_740_firmware 740.60_01ax740_110_042
ibm power_740 8205-e6d
ibm power_760_firmware 760.10_am760_044_034
ibm power_730 8231-e2c
ibm power_780 9179-mhd
ibm power_770_firmware 770.22_01ax770_055_032
ibm power_780 9179-mhc
ibm power_710 8231-e1c
ibm power_710 8231-e1d
ibm power_760_firmware 760.20_ah760_062_043
ibm powerlinux_7r1 8246-l1t
ibm power_760_firmware 760.31_am760_069_034
ibm powerlinux_7r2 8246-l2t
ibm power_740_firmware 740.00_01ax740_042_042
ibm power_740_firmware 740.50_01ax740_095_042
ibm power_740_firmware 740.52_01ax740_100_042
CVE-2013-6307 LOW

Cross-site scripting (XSS) vulnerability in IBM Security QRadar SIEM 7.0 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.0.0
CVE-2013-6308 MEDIUM

IBM Marketing Platform 9.1 before FP2 allows remote authenticated users to conduct phishing attacks and capture login credentials via an unspecified injection.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm marketing_platform 9.1.0.1
ibm marketing_platform 9.1.0.0
CVE-2013-6309 MEDIUM

IBM Marketing Platform 9.1 before FP2 allows remote authenticated users to hijack sessions, and consequently read records, modify records, or conduct transactions, via an unspecified link injection.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-94,

Products Affected

Vendor Product Version
ibm marketing_platform 9.1.0.1
ibm marketing_platform 9.1.0.0
CVE-2013-6310 LOW

Cross-site scripting (XSS) vulnerability in IBM Marketing Platform 9.1 before FP2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm marketing_platform 9.1.0.1
ibm marketing_platform 9.1.0.0
CVE-2013-6311 MEDIUM

SQL injection vulnerability in IBM Marketing Platform 9.1 before FP2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm marketing_platform 9.1.0.1
ibm marketing_platform 9.1.0.0
CVE-2013-6312 MEDIUM

Unspecified vulnerability in IBM Rational Service Tester 8.3.x and 8.5.x before 8.5.1 and Rational Performance Tester 8.3.x and 8.5.x before 8.5.1 allows remote attackers to read arbitrary files via unknown vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm rational_performance_tester 8.3.0.3
ibm rational_service_tester 8.3.0.2
ibm rational_service_tester 8.5.0.1
ibm rational_service_tester 8.3.0.1
ibm rational_performance_tester 8.3.0.2
ibm rational_service_tester 8.5.0
ibm rational_service_tester 8.5.0.2
ibm rational_performance_tester 8.3.0
ibm rational_service_tester 8.3.0.3
ibm rational_performance_tester 8.5.0.1
ibm rational_performance_tester 8.5.0
ibm rational_service_tester 8.3.0
ibm rational_performance_tester 8.3.0.1
ibm rational_performance_tester 8.5.0.2
CVE-2013-6314 LOW

Cross-site scripting (XSS) vulnerability in IBM InfoSphere Enterprise Records 4.5.1 before 4.5.1.7-IER-IF001 and Enterprise Records 5.1.1 before 5.1.1.1-IER-IF003 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm enterprise_records 5.1.1
ibm infosphere_enterprise_records 4.5.1
CVE-2013-6315 MEDIUM

IBM InfoSphere Enterprise Records 4.5.1 before 4.5.1.7-IER-IF001 and Enterprise Records 5.1.1 before 5.1.1.1-IER-IF003 do not properly restrict use of FRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm enterprise_records 5.1.1
ibm infosphere_enterprise_records 4.5.1
CVE-2013-6316 MEDIUM

IBM WebSphere Portal 7.0.0.x before 7.0.0.2 CF26 and 8.0.0.x before 8.0.0.1 CF09 does not properly handle content-selection changes during Taxonomy component rendering, which allows remote attackers to obtain sensitive property information in opportunistic circumstances by leveraging an error in a Web Content Manager (WCM) context processor.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.1
ibm websphere_portal 8.0.0.0
ibm websphere_portal 7.0.0.2
ibm websphere_portal 7.0.0.1
ibm websphere_portal 7.0.0.0
CVE-2013-6318 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Security Access Control Management 4.7.0 through 4.9.0, and ACSWeb in AlgoWebApps 5.0.0, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm algo_one 4.9.0
ibm algo_one 4.7.1
ibm algo_one 4.7.0
ibm algo_one 4.8.0
ibm algo_one 4.9.1
ibm algo_one 5.0.0
CVE-2013-6319 MEDIUM

IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Security Access Control Management 4.7.0 through 4.9.0, and ACSWeb in AlgoWebApps 5.0.0, allows remote authenticated users to bypass intended access restrictions and read content via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm algo_one 4.9.0
ibm algo_one 4.7.1
ibm algo_one 4.7.0
ibm algo_one 4.8.0
ibm algo_one 4.9.1
ibm algo_one 5.0.0
CVE-2013-6320 LOW

Cross-site scripting (XSS) vulnerability in IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Security Access Control Management 4.7.0 through 4.9.0, and ACSWeb in AlgoWebApps 5.0.0, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2013-6299, CVE-2013-6300, CVE-2013-6301, and CVE-2013-6333.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm algo_one 4.9.0
ibm algo_one 4.7.1
ibm algo_one 4.7.0
ibm algo_one 4.8.0
ibm algo_one 4.9.1
ibm algo_one 5.0.0
CVE-2013-6321 HIGH

SQL injection vulnerability in IBM Atlas eDiscovery Process Management 6.0.1.5 and earlier and 6.0.2, Disposal and Governance Management for IT 6.0.1.5 and earlier and 6.0.2, and Global Retention Policy and Schedule Management 6.0.1.5 and earlier and 6.0.2 in IBM Atlas Suite (aka Atlas Policy Suite) allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm disposal_and_governance_management_for_it 6.0.2
ibm atlas_ediscovery_process_management *
ibm disposal_and_governance_management_for_it *
ibm atlas_suite -
ibm global_retention_policy_and_schedule_management 6.0.2
ibm atlas_ediscovery_process_management 6.0.2
ibm global_retention_policy_and_schedule_management *
CVE-2013-6322 LOW

Cross-site scripting (XSS) vulnerability in Sterling Order Management in IBM Sterling Selling and Fulfillment Suite 8.0 before HF128 and 8.5 before HF93 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm sterling_selling_and_fulfillment_foundation 8.0
ibm sterling_selling_and_fulfillment_foundation 8.5
CVE-2013-6323 LOW

Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 7.x before 7.0.0.33, 8.x before 8.0.0.9, and 8.5.x before 8.5.5.2, and WebSphere Virtual Enterprise 7.x before 7.0.0.5, allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0.0.19
ibm websphere_virtual_enterprise 7.0.0.2
ibm websphere_application_server 7.0
ibm websphere_application_server 8.0.0.5
ibm websphere_virtual_enterprise 7.0.0.1
ibm websphere_application_server 7.0.0.12
ibm websphere_application_server 8.5.0.2
ibm websphere_application_server 8.0.0.6
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 7.0.0.21
ibm websphere_virtual_enterprise 7.0.0.4
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 7.0.0.16
ibm websphere_application_server 7.0.0.6
ibm websphere_virtual_enterprise 7.0
ibm websphere_application_server 7.0.0.25
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 7.0.0.14
ibm websphere_application_server 7.0.0.22
ibm websphere_application_server 7.0.0.31
ibm websphere_application_server 7.0.0.10
ibm websphere_virtual_enterprise 7.0.0.3
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 8.0.0.8
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0.0.29
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 7.0.0.24
ibm websphere_application_server 8.5.5.0
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 8.0.0.7
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 7.0.0.27
ibm websphere_application_server 7.0.0.18
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 8.5.5.1
ibm websphere_application_server 7.0.0.4
ibm websphere_application_server 8.0.0.2
CVE-2013-6325 MEDIUM

IBM WebSphere Application Server 7.x before 7.0.0.31, 8.0.x before 8.0.0.8, and 8.5.x before 8.5.5.2 allows remote attackers to cause a denial of service (resource consumption) via a crafted request to a web services endpoint.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 7.0
ibm websphere_application_server 8.0.0.5
ibm websphere_application_server 7.0.0.12
ibm websphere_application_server 8.5.0.2
ibm websphere_application_server 8.0.0.6
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 7.0.0.16
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 7.0.0.25
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 7.0.0.14
ibm websphere_application_server 7.0.0.22
ibm websphere_application_server 7.0.0.10
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0.0.29
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 7.0.0.24
ibm websphere_application_server 8.5.5.0
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 8.0.0.7
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 7.0.0.27
ibm websphere_application_server 7.0.0.18
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 8.5.5.1
ibm websphere_application_server 7.0.0.4
ibm websphere_application_server 8.0.0.2
CVE-2013-6327 MEDIUM

Cross-site scripting (XSS) vulnerability in the HTTP Option in IBM Sterling Connect:Enterprise 1.3 before 1.3.0.2 iFix 1 and 1.4 before 1.4.0.0 iFix 1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to a "cross-frame scripting" issue.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm sterling_connect_enterprise_http_option 1.4.00
ibm sterling_connect_enterprise_http_option 1.3.02
CVE-2013-6328 MEDIUM

Cross-site scripting (XSS) vulnerability in the Web Content Manager (WCM) UI in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x through 7.0.0.2 CF26, and 8.0.0.x before 8.0.0.1 CF09 allows remote attackers to inject arbitrary web script or HTML via vectors involving IFRAME elements.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.0
ibm websphere_portal 6.1.0.3
ibm websphere_portal 7.0.0.1
ibm websphere_portal 6.1.5.2
ibm websphere_portal 6.1.0.2
ibm websphere_portal 6.1.0.4
ibm websphere_portal 8.0.0.1
ibm websphere_portal 7.0.0.2
ibm websphere_portal 6.1.5.0
ibm websphere_portal 6.1.0.6
ibm websphere_portal 6.1.5.3
ibm websphere_portal 7.0.0.0
ibm websphere_portal 6.1.0.1
ibm websphere_portal 6.1.5.1
ibm websphere_portal 6.1.0.5
ibm websphere_portal 6.1.0.0
CVE-2013-6329 HIGH

IBM Global Security Kit (aka GSKit), as used in Content Manager OnDemand 8.5 and 9.0 and other products, allows remote attackers to cause a denial of service via a crafted handshake during resumption of an SSLv2 session.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm security_access_manager_for_web 6.1.1
ibm content_manager_ondemand_for_multiplatforms 8.5
ibm security_access_manager_for_web 6.1
ibm content_manager_ondemand_for_multiplatforms 9.0
ibm security_access_manager_for_web 6.0
ibm global_security_kit -
ibm security_access_manager_for_web 7.0
CVE-2013-6330 LOW

IBM WebSphere Application Server 7.x before 7.0.0.31, when simpleFileServlet static file caching is enabled, allows remote authenticated users to obtain sensitive information via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0
ibm websphere_application_server 7.0.0.29
ibm websphere_application_server 7.0.0.24
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.12
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 7.0.0.16
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 7.0.0.25
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 7.0.0.27
ibm websphere_application_server 7.0.0.14
ibm websphere_application_server 7.0.0.18
ibm websphere_application_server 7.0.0.22
ibm websphere_application_server 7.0.0.28
ibm websphere_application_server 7.0.0.10
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 7.0.0.13
CVE-2013-6331 MEDIUM

SQL injection vulnerability in IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Security Access Control Management 4.7.0 through 4.9.0, and ACSWeb in AlgoWebApps 5.0.0, allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2013-6302.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm algo_one 4.9.0
ibm algo_one 4.7.1
ibm algo_one 4.7.0
ibm algo_one 4.8.0
ibm algo_one 4.9.1
ibm algo_one 5.0.0
CVE-2013-6332 HIGH

Unrestricted file upload vulnerability in IBM Algo One UDS 4.7.0 through 5.0.0 allows remote authenticated users to execute arbitrary code by uploading a .jsp file and then launching it.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm algo_one 4.9.0
ibm algo_one 4.7.1
ibm algo_one 4.7.0
ibm algo_one 4.8.0
ibm algo_one 4.9.1
ibm algo_one 5.0.0
CVE-2013-6333 LOW

Cross-site scripting (XSS) vulnerability in IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Security Access Control Management 4.7.0 through 4.9.0, and ACSWeb in AlgoWebApps 5.0.0, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2013-6299, CVE-2013-6300, CVE-2013-6301, and CVE-2013-6320.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm algo_one 4.9.0
ibm algo_one 4.7.1
ibm algo_one 4.7.0
ibm algo_one 4.8.0
ibm algo_one 4.9.1
ibm algo_one 5.0.0
CVE-2013-6334 MEDIUM

IBM Atlas eDiscovery Process Management 6.0.1.5 and earlier and 6.0.2, Disposal and Governance Management for IT 6.0.1.5 and earlier and 6.0.2, and Global Retention Policy and Schedule Management 6.0.1.5 and earlier and 6.0.2 in IBM Atlas Suite (aka Atlas Policy Suite) do not properly validate sessions, which allows remote attackers to bypass intended access restrictions, and visit PolicyAtlas/ResponseDraftServlet (aka the Compliance Questionnaire Save Draft servlet), via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm disposal_and_governance_management_for_it 6.0.2
ibm atlas_ediscovery_process_management *
ibm disposal_and_governance_management_for_it *
ibm atlas_suite -
ibm global_retention_policy_and_schedule_management 6.0.2
ibm atlas_ediscovery_process_management 6.0.2
ibm global_retention_policy_and_schedule_management *
CVE-2013-6335 LOW

The Backup-Archive client in IBM Tivoli Storage Manager (TSM) for Space Management 5.x and 6.x before 6.2.5.3, 6.3.x before 6.3.2, 6.4.x before 6.4.2, and 7.1.x before 7.1.0.3 on Linux and AIX, and 5.x and 6.x before 6.1.5.6 on Solaris and HP-UX, does not preserve file permissions across backup and restore operations, which allows local users to bypass intended access restrictions via standard filesystem operations.

CVSS 2.0

Severity: LOW

Problem Type: CWE-281,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager *
CVE-2013-6713 MEDIUM

The Data Protection for VMware component in IBM Tivoli Storage Manager for Virtual Environments (TSMVE) 6.3 through 7.1.0.2 does not properly check authorization for backup and restore operations, which allows local users to obtain sensitive VM data or cause a denial of service (disk consumption) via unspecified GUI actions.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_for_virtual_environments 6.3.2.1
ibm tivoli_storage_manager_for_virtual_environments 6.4.0.0
ibm tivoli_storage_manager_for_virtual_environments 6.4.1.0
ibm tivoli_storage_manager_for_virtual_environments 6.3.0.0
ibm tivoli_storage_manager_for_virtual_environments 6.3.2.0
ibm tivoli_storage_manager_for_virtual_environments 7.1.0.2
ibm tivoli_storage_manager_for_virtual_environments 7.1.0.0
ibm tivoli_storage_manager_for_virtual_environments 6.3.3.0
ibm tivoli_storage_manager_for_virtual_environments 7.1.0.1
ibm tivoli_storage_manager_for_virtual_environments 6.3.1.0
CVE-2013-6714 MEDIUM

The FlashCopy Manager for VMware component in IBM Tivoli Storage FlashCopy Manager 3.1 through 4.1.0.1 does not properly check authorization for backup and restore operations, which allows local users to obtain sensitive VM data or cause a denial of service (data overwrite or disk consumption) via unspecified GUI actions.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm tivoli_storage_flashcopy_manager 3.2.0
ibm tivoli_storage_flashcopy_manager 3.1.0
ibm tivoli_storage_flashcopy_manager 3.2.1
ibm tivoli_storage_flashcopy_manager 4.1.0
ibm tivoli_storage_flashcopy_manager 3.1.1
ibm tivoli_storage_flashcopy_manager 4.1.0.1
CVE-2013-6717 MEDIUM

The OLAP query engine in IBM DB2 and DB2 Connect 9.7 through FP9, 9.8 through FP5, 10.1 through FP3, and 10.5 through FP2, and the DB2 pureScale Feature 9.8 for Enterprise Server Edition, allows remote authenticated users to cause a denial of service (database outage and deactivation) via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2_connect 10.1
ibm db2 9.7.0.9
ibm db2_connect 9.7.0.5
ibm db2 10.1.0.1
ibm db2_connect 10.5.0.2
ibm db2_connect 9.8.0.4
ibm db2 9.7.0.5
ibm db2 9.7.0.6
ibm db2_connect 10.1.0.3
ibm db2_connect 9.7.0.8
ibm db2 9.7.0.8
ibm db2_connect 9.7.0.6
ibm db2 10.5.0.1
ibm db2 10.5.0.2
ibm db2 9.7.0.2
ibm db2 10.1
ibm db2 9.7.0.1
ibm db2 9.8.0.3
ibm db2_connect 9.8.0.3
ibm db2 9.8
ibm db2_connect 9.8
ibm db2_connect 9.7
ibm db2_connect 10.1.0.1
ibm db2_connect 9.7.0.7
ibm db2 10.1.0.2
ibm db2_connect 9.7.0.3
ibm db2 10.1.0.3
ibm db2 9.7.0.4
ibm db2 9.7.0.7
ibm db2 9.7
ibm db2 9.7.0.3
ibm db2_connect 10.5.0.1
ibm db2_connect 9.7.0.4
ibm db2_connect 9.8.0.5
ibm db2_connect 10.1.0.2
ibm db2_connect 10.5
ibm db2 9.8.0.5
ibm db2_connect 9.7.0.1
ibm db2_connect 9.7.0.2
ibm db2_purescale_feature_9.8 -
ibm db2 9.8.0.4
ibm db2_connect 9.7.0.9
CVE-2013-6718 MEDIUM

The Advanced Management Module (AMM) with firmware 3.64B, 3.64C, and 3.64G for IBM BladeCenter systems allows remote attackers to discover account names and passwords via use of an unspecified interface.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm advanced_management_module_firmware 3.64
CVE-2013-6719 MEDIUM

delivery.php in the Passive Capture Application (PCA) web console in IBM Tealeaf CX 7.x, 8.x through 8.6, 8.7 before FP2, and 8.8 before FP2 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the testconn_host parameter.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-78,

Products Affected

Vendor Product Version
ibm tealeaf_cx 8.4
ibm tealeaf_cx 8.8
ibm tealeaf_cx 7.2
ibm tealeaf_cx 8.0
ibm tealeaf_cx 8.1
ibm tealeaf_cx 8.5
ibm tealeaf_cx 8.6
ibm tealeaf_cx 8.2
ibm tealeaf_cx 8.7
ibm tealeaf_cx 7.1
ibm tealeaf_cx 8.3
CVE-2013-6720 MEDIUM

Directory traversal vulnerability in download.php in the Passive Capture Application (PCA) web console in IBM Tealeaf CX 7.x, 8.x through 8.6, 8.7 before FP2, and 8.8 before FP2 allows remote authenticated users to bypass intended access restrictions via a .. (dot dot) in the log parameter, as demonstrated using a crafted request for a customer-support file, as demonstrated by a log file.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm tealeaf_cx 8.4
ibm tealeaf_cx 8.8
ibm tealeaf_cx 7.2
ibm tealeaf_cx 8.0
ibm tealeaf_cx 8.1
ibm tealeaf_cx 8.5
ibm tealeaf_cx 8.6
ibm tealeaf_cx 8.2
ibm tealeaf_cx 8.7
ibm tealeaf_cx 7.1
ibm tealeaf_cx 8.3
CVE-2013-6721 LOW

Cross-site scripting (XSS) vulnerability in IBM WebSphere Service Registry and Repository (WSRR) 7.5.x before 7.5.0.4 and 8.x through 8.0.0.2 allows remote authenticated users to inject arbitrary web script or HTML via vectors involving widgets.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_service_registry_and_repository 7.5.0.3
ibm websphere_service_registry_and_repository 7.5.0.2
ibm websphere_service_registry_and_repository 8.0.0
ibm websphere_service_registry_and_repository 8.0.0.2
ibm websphere_service_registry_and_repository 8.0.0.1
CVE-2013-6722 MEDIUM

Unrestricted file upload vulnerability in the Registration/Edit My Profile portlet in IBM WebSphere Portal 7.x before 7.0.0.2 CF27 and 8.x through 8.0.0.1 CF09 allows remote attackers to cause a denial of service or modify data via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.1
ibm websphere_portal 8.0.0.0
ibm websphere_portal 7.0.0.2
ibm websphere_portal 8.0
ibm websphere_portal 7.0.0.1
ibm websphere_portal 7.0.0.0
CVE-2013-6723 MEDIUM

IBM WebSphere Portal 8.0.0.1 before CF09 does not properly handle references in compute="always" Web Content Manager (WCM) navigator components, which allows remote attackers to obtain sensitive component information via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.1
CVE-2013-6724 HIGH

Unspecified vulnerability in the vsflex8l ActiveX control in IBM SPSS SamplePower 3.0.1 before FP1 IF1 allows remote attackers to execute arbitrary code via a crafted ComboList property value.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm spss_samplepower 3.0.1.0
CVE-2013-6725 LOW

Cross-site scripting (XSS) vulnerability in the Administrative Console in IBM WebSphere Application Server 7.x before 7.0.0.31, 8.0.x before 8.0.0.8, and 8.5.x before 8.5.5.2 allows remote authenticated administrators to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 7.0
ibm websphere_application_server 8.0.0.5
ibm websphere_application_server 7.0.0.12
ibm websphere_application_server 8.5.0.2
ibm websphere_application_server 8.0.0.6
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 7.0.0.16
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 7.0.0.25
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 6.1
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 7.0.0.14
ibm websphere_application_server 7.0.0.22
ibm websphere_application_server 7.0.0.10
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0.0.29
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 7.0.0.24
ibm websphere_application_server 8.5.5.0
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 8.0.0.7
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 7.0.0.27
ibm websphere_application_server 7.0.0.18
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 8.5.5.1
ibm websphere_application_server 7.0.0.4
ibm websphere_application_server 8.0.0.2
CVE-2013-6726 LOW

Multiple cross-site scripting (XSS) vulnerabilities in WebProcess.srv in IBM TRIRIGA Application Platform 3.2.x and 3.3.x before 3.3.1.2 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tririga_application_platform 3.2
ibm tririga_application_platform 3.3.0.1
ibm tririga_application_platform 3.3.1.1
ibm tririga_application_platform 3.3.1.0
ibm tririga_application_platform 3.2.1
ibm tririga_application_platform 3.3.0.0
CVE-2013-6727 MEDIUM

The Connect client in IBM Sametime 8.5.2 through 8.5.2.1 and 9.0 before HF1 does not properly restrict unsigned Java plugins, which allows remote attackers to obtain sensitive information via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm sametime 8.5.2.0
ibm sametime 8.5.2.1
ibm sametime 9.0.0.0
CVE-2013-6728 MEDIUM

The charting component in IBM WebSphere Dashboard Framework (WDF) 6.1.5 and 7.0.1 allows remote attackers to view or delete image files by leveraging incorrect security constraints for a temporary directory.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_dashboard_framework 7.0.1
ibm websphere_dashboard_framework 6.1.5
CVE-2013-6729 LOW

Cross-site scripting (XSS) vulnerability in IBM QuickFile 1.0.0.0 before iFix 4 and 1.1.0.1 before iFix 3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm quickfile 1.0.0.0
ibm quickfile 1.1.0.1
CVE-2013-6730 MEDIUM

IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x before 7.0.0.2 CF27, and 8.0.0.x before 8.0.0.1 CF10, when the wcm.path.traversal.security setting is enabled, allows remote attackers to bypass intended read restrictions on an item by accessing that item within search results.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.0
ibm websphere_portal 6.1.0.3
ibm websphere_portal 7.0.0.1
ibm websphere_portal 6.1.5.2
ibm websphere_portal 6.1.0.2
ibm websphere_portal 6.1.0.4
ibm websphere_portal 8.0.0.1
ibm websphere_portal 7.0.0.2
ibm websphere_portal 6.1.5.0
ibm websphere_portal 6.1.0.6
ibm websphere_portal 6.1.5.3
ibm websphere_portal 7.0.0.0
ibm websphere_portal 6.1.0.1
ibm websphere_portal 6.1.5.1
ibm websphere_portal 6.1.0.5
ibm websphere_portal 6.1.0.0
CVE-2013-6731 MEDIUM

IBM Netezza Performance Portal 2.x before 2.0.0.3 allows remote authenticated users to change arbitrary passwords via an HTTP POST request.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm netezza_performance_portal 2.0.0.1
ibm netezza_performance_portal 2.0.0.2
ibm netezza_performance_portal 2.0
CVE-2013-6732 MEDIUM

Cross-site scripting (XSS) vulnerability in the server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1 before IF6, 10.1.1 before IF5, 10.2 before IF7, 10.2.1 before IF4, and 10.2.1.1 before IF4 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm cognos_business_intelligence 10.2.1
ibm cognos_business_intelligence 10.2
ibm cognos_business_intelligence 10.1
ibm cognos_business_intelligence 10.2.1.1
ibm cognos_business_intelligence 8.4.1
ibm cognos_business_intelligence 10.1.1
CVE-2013-6733 MEDIUM

Cross-site scripting (XSS) vulnerability in the Web Application in the Classic Meeting Server in IBM Sametime 7.5.1.2 through 8.5.2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm sametime 8.5.0.0
ibm sametime 8.5.1.1
ibm sametime 8.5.2.0
ibm sametime 8.5.2.1
ibm sametime 7.5.1.2
ibm sametime 8.0.0.0
ibm sametime 8.0.1.1
ibm sametime 8.5.1.0
ibm sametime 8.0.2.0
ibm sametime 8.0.2.1
ibm sametime 8.0.1.0
CVE-2013-6734 LOW

IBM WebSphere eXtreme Scale Client 7.1 through 8.6.0.4 does not properly isolate the cached data of different users, which allows remote authenticated users to obtain sensitive information in opportunistic circumstances by leveraging access to the same web container.

CVSS 2.0

Severity: LOW

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_extreme_scale_client 8.5.0.2
ibm websphere_extreme_scale_client 8.5.0.3
ibm websphere_extreme_scale_client 8.6.0.3
ibm websphere_extreme_scale_client 8.6.0.2
ibm websphere_extreme_scale_client 7.0.0.0
ibm websphere_extreme_scale_client 8.6.0.0
ibm websphere_extreme_scale_client *
ibm websphere_extreme_scale_client 8.6.0.1
ibm websphere_extreme_scale_client 7.1.1.0
ibm websphere_extreme_scale_client 8.5.0.0
ibm websphere_extreme_scale_client 8.5.0.1
ibm websphere_extreme_scale_client 7.1.0.0
ibm websphere_extreme_scale_client 7.1.0.2
ibm websphere_extreme_scale_client 7.1.0.3
ibm websphere_extreme_scale_client 7.1.1.1
CVE-2013-6735 MEDIUM

IBM WebSphere Portal 6.0.0.x through 6.0.0.1, 6.0.1.x through 6.0.1.7, 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x through 7.0.0.2 CF26, and 8.0.0.x through 8.0.0.1 CF08 allows remote attackers to obtain sensitive Java Content Repository (JCR) information via a modified Web Content Manager (WCM) URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.0
ibm websphere_portal 6.1.0.3
ibm websphere_portal 6.0.1.0
ibm websphere_portal 6.0.1.1
ibm websphere_portal 6.1.0.4
ibm websphere_portal 8.0.0.1
ibm websphere_portal 6.0.1.3
ibm websphere_portal 6.0.0.1
ibm websphere_portal 6.1.5.0
ibm websphere_portal 6.1.0.6
ibm websphere_portal 6.1.5.3
ibm websphere_portal 6.1.0.1
ibm websphere_portal 6.1.5.1
ibm websphere_portal 6.1.0.0
ibm websphere_portal 6.0.1.4
ibm websphere_portal 6.0.0.0
ibm websphere_portal 7.0.0.1
ibm websphere_portal 6.1.5.2
ibm websphere_portal 6.1.0.2
ibm websphere_portal 6.0.1.6
ibm websphere_portal 6.0.1.2
ibm websphere_portal 6.0.1.5
ibm websphere_portal 7.0.0.2
ibm websphere_portal 6.0.1.7
ibm websphere_portal 7.0.0.0
ibm websphere_portal 6.1.0.5
CVE-2013-6737 MEDIUM

IBM System Storage Storwize V7000 Unified 1.3.x and 1.4.x before 1.4.3.0 does not properly restrict the content of a dump file upon encountering a 1691 hardware fault, which allows remote authenticated users to obtain sensitive customer-data fragments by reading this file after it is copied.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm storwize_unified_v7000_software 1.4.0.4
ibm storwize_unified_v7000 -
ibm storwize_unified_v7000_software 1.3.0.0
ibm storwize_unified_v7000_software 1.3.1.0
ibm storwize_unified_v7000_software 1.4.0.2
ibm storwize_unified_v7000_software 1.4.0.5
ibm storwize_unified_v7000_software 1.4.2.0
ibm storwize_unified_v7000_software 1.4.0.3
ibm storwize_unified_v7000_software 1.4.2.1
ibm storwize_unified_v7000_software 1.4.1.1
ibm storwize_unified_v7000_software 1.4.0.0
ibm storwize_unified_v7000_software 1.4.1.0
ibm storwize_unified_v7000_software 1.4.0.1
CVE-2013-6738 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM SmartCloud Analytics Log Analysis 1.1 and 1.2 before 1.2.0.0-CSI-SCALA-IF0003 allows remote attackers to inject arbitrary web script or HTML via an invalid query parameter in a response from an OAuth authorization endpoint.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm smartcloud_analytics_log_analysis 1.1.0
ibm smartcloud_analytics_log_analysis 1.2.0
CVE-2013-6739 MEDIUM

IBM SPSS Modeler before 16 on UNIX allows remote authenticated users to bypass intended access restrictions via an SSO token. IBM X-Force ID: 89855.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm spss_modeler *
CVE-2013-6741 LOW

IBM Maximo Asset Management 7.x before 7.1.1.7 LAFIX.20140319-0837 and 7.5.x before 7.5.0.5 IFIX006; SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2; and Tivoli IT Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB) 7.x before 7.1.1.7 LAFIX.20140319-0837 allow remote authenticated users to obtain potentially sensitive stack-trace information by triggering a Birt error.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.5.0.1
ibm maximo_asset_management 7.1.1.1
ibm tivoli_asset_management_for_it 7.0
ibm smartcloud_control_desk 7.5.0.0
ibm tivoli_it_asset_management_for_it 7.1.1.7
ibm change_and_configuration_management_database 7.1.1.7
ibm maximo_asset_management 7.5.0.3
ibm smartcloud_control_desk 7.0
ibm tivoli_service_request_manager 7.1.1.7
ibm tivoli_asset_management_for_it 7.1
ibm maximo_asset_management 7.5.0.0
ibm maximo_asset_management 7.1.1.7
ibm smartcloud_control_desk 7.5.1.1
ibm maximo_asset_management 7.5.0.4
ibm smartcloud_control_desk 7.5.0.2
ibm smartcloud_control_desk 7.5
ibm maximo_asset_management 7.5.0.5
ibm tivoli_service_request_manager 7.1.1
ibm maximo_asset_management 7.1.1.2
ibm maximo_service_desk 7.1.1.7
ibm smartcloud_control_desk 7.5.0.1
ibm maximo_asset_management 7.1.1.6
ibm maximo_asset_management 7.1.1.5
ibm smartcloud_control_desk 7.5.1.0
ibm maximo_asset_management 7.1.1
CVE-2013-6742 HIGH

The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 do not have an off autocomplete attribute for a password field, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm sametime 8.5.2.0
ibm sametime 8.5.2.1
ibm sametime 9.0.0.1
ibm sametime 9.0.0.0
CVE-2013-6743 LOW

Cross-site scripting (XSS) vulnerability in the Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 allows remote authenticated users to inject arbitrary web script or HTML via vectors involving an IMG element.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm sametime 8.5.2.0
ibm sametime 8.5.2.1
ibm sametime 9.0.0.1
ibm sametime 9.0.0.0
CVE-2013-6744 HIGH

The Stored Procedure infrastructure in IBM DB2 9.5, 9.7 before FP9a, 10.1 before FP3a, and 10.5 before FP3a on Windows allows remote authenticated users to gain privileges by leveraging the CONNECT privilege and the CREATE_EXTERNAL_ROUTINE authority.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2 9.7.0.9
ibm db2 10.1.0.1
ibm db2 10.1.0.3
ibm db2 9.7.0.5
ibm db2 9.7.0.4
ibm db2 9.7.0.6
ibm db2 9.7.0.7
ibm db2 9.7
ibm db2 9.7.0.3
ibm db2 9.7.0.8
ibm db2 10.5.0.1
ibm db2 10.5.0.2
ibm db2 9.5
ibm db2 9.7.0.2
ibm db2 10.1
ibm db2 9.7.0.1
ibm db2 10.1.0.2
CVE-2013-6745 LOW

Cross-site scripting (XSS) vulnerability in the IMS server before Ifix 6 in IBM Security Access Manager for Enterprise Single Sign-On (ISAM ESSO) 8.2 allows remote authenticated users to inject arbitrary web script or HTML via crafted input to an unspecified dynamic web form.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm security_access_manager_for_enterprise_single_sign-on 8.2
CVE-2013-6746 MEDIUM

Cross-site scripting (XSS) vulnerability in FileNet P8 Platform Documentation Installable Info Center 4.5.1 through 5.2.0 in IBM FileNet Business Process Manager 4.5.1 through 5.1.0, FileNet Content Manager 4.5.1 through 5.2.0, and Case Foundation 5.2.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm filenet_p8_business_process_manager 5.0.0
ibm filenet_p8_business_process_manager 5.1.0
ibm filenet_content_manager 4.5.1
ibm filenet_content_manager 5.0.0
ibm filenet_case_foundation 5.2.0
ibm filenet_p8_business_process_manager 4.5.1
ibm filenet_content_manager 5.1.0
ibm filenet_content_manager 4.5.0
ibm filenet_content_manager 5.2.0
CVE-2013-6747 HIGH

IBM GSKit 7.x before 7.0.4.48 and 8.x before 8.0.50.16, as used in IBM Security Directory Server (ISDS) and Tivoli Directory Server (TDS), allows remote attackers to cause a denial of service (application crash or hang) via a malformed X.509 certificate chain.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm security_directory_server -
ibm tivoli_directory_server -
ibm global_security_kit 8.5
ibm global_security_kit 8.0.13
ibm global_security_kit 7.0
ibm global_security_kit 7.0.4.29
ibm global_security_kit 8.0
ibm global_security_kit 7.0.4.28
CVE-2013-6748 HIGH

Buffer overflow in the ActiveX control in qp2.cab in IBM Lotus Quickr for Domino 8.5.1 before 8.5.1.42-001b allows remote attackers to execute arbitrary code via a crafted HTML document, a different vulnerability than CVE-2013-6749.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm lotus_quickr_for_domino 8.5.1
CVE-2013-6749 HIGH

Buffer overflow in the ActiveX control in qp2.cab in IBM Lotus Quickr for Domino 8.5.1 before 8.5.1.42-001b allows remote attackers to execute arbitrary code via a crafted HTML document, a different vulnerability than CVE-2013-6748.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm lotus_quickr_for_domino 8.5.1
CVE-2014-0429 HIGH

Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
debian debian_linux 8.0
oracle jre 1.7.0
oracle jdk 1.8.0
oracle jdk 1.7.0
oracle jre 1.5.0
canonical ubuntu_linux 13.10
canonical ubuntu_linux 12.04
oracle jdk 1.6.0
oracle jdk 1.5.0
canonical ubuntu_linux 12.10
oracle jre 1.8.0
debian debian_linux 7.0
oracle jrockit r27.8.1
canonical ubuntu_linux 14.04
ibm forms_viewer *
canonical ubuntu_linux 10.04
juniper junos_space *
oracle jrockit r28.3.1
oracle jre 1.6.0
debian debian_linux 6.0
CVE-2014-0448 HIGH

Unspecified vulnerability in Oracle Java SE 7u51 and 8 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
oracle jre 1.7.0
ibm forms_viewer *
oracle jdk 1.8.0
oracle jdk 1.7.0
oracle jre 1.8.0
CVE-2014-0453 MEDIUM

Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Security.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
debian debian_linux 8.0
oracle jre 1.7.0
oracle jdk 1.8.0
oracle jdk 1.7.0
oracle jre 1.5.0
canonical ubuntu_linux 13.10
canonical ubuntu_linux 12.04
oracle jdk 1.6.0
oracle jdk 1.5.0
canonical ubuntu_linux 12.10
oracle jre 1.8.0
debian debian_linux 7.0
oracle jrockit r27.8.1
canonical ubuntu_linux 14.04
ibm forms_viewer *
canonical ubuntu_linux 10.04
juniper junos_space *
oracle jrockit r28.3.1
oracle jre 1.6.0
debian debian_linux 6.0
CVE-2014-0454 HIGH

Unspecified vulnerability in Oracle Java SE 7u51 and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Security.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
canonical ubuntu_linux 14.04
oracle jre 1.7.0
ibm forms_viewer *
oracle jdk 1.8.0
oracle jdk 1.7.0
canonical ubuntu_linux 13.10
canonical ubuntu_linux 12.10
oracle jre 1.8.0
CVE-2014-0455 HIGH

Unspecified vulnerability in Oracle Java SE 7u51 and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2014-0432 and CVE-2014-2402.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
canonical ubuntu_linux 14.04
oracle jre 1.7.0
ibm forms_viewer *
oracle jdk 1.8.0
oracle jdk 1.7.0
canonical ubuntu_linux 13.10
canonical ubuntu_linux 12.10
oracle jre 1.8.0
CVE-2014-0456 HIGH

Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
debian debian_linux 8.0
oracle jre 1.7.0
oracle jdk 1.8.0
oracle jdk 1.7.0
oracle jre 1.5.0
canonical ubuntu_linux 13.10
canonical ubuntu_linux 12.04
oracle jdk 1.6.0
oracle jdk 1.5.0
canonical ubuntu_linux 12.10
oracle jre 1.8.0
debian debian_linux 7.0
oracle jrockit r27.8.1
canonical ubuntu_linux 14.04
ibm forms_viewer *
canonical ubuntu_linux 10.04
juniper junos_space *
oracle jrockit r28.3.1
oracle jre 1.6.0
debian debian_linux 6.0
CVE-2014-0457 HIGH

Unspecified vulnerability in Oracle Java SE 5.0u61, SE 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
debian debian_linux 8.0
oracle jre 1.7.0
oracle jdk 1.8.0
oracle jdk 1.7.0
oracle jre 1.5.0
canonical ubuntu_linux 13.10
canonical ubuntu_linux 12.04
oracle jdk 1.6.0
oracle jdk 1.5.0
canonical ubuntu_linux 12.10
oracle jre 1.8.0
debian debian_linux 7.0
oracle jrockit r27.8.1
canonical ubuntu_linux 14.04
ibm forms_viewer *
canonical ubuntu_linux 10.04
juniper junos_space *
oracle jrockit r28.3.1
oracle jre 1.6.0
debian debian_linux 6.0
CVE-2014-0461 HIGH

Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
debian debian_linux 8.0
oracle jre 1.7.0
oracle jdk 1.8.0
oracle jdk 1.7.0
canonical ubuntu_linux 13.10
canonical ubuntu_linux 12.04
oracle jdk 1.6.0
canonical ubuntu_linux 12.10
oracle jre 1.8.0
debian debian_linux 7.0
canonical ubuntu_linux 14.04
ibm forms_viewer *
canonical ubuntu_linux 10.04
oracle jre 1.6.0
debian debian_linux 6.0
CVE-2014-0822 HIGH

The IMAP server in IBM Domino 8.5.x before 8.5.3 FP6 IF1 and 9.0.x before 9.0.1 FP1 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, aka SPR KLYH9F4S2Z.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm lotus_domino 8.5.2.4
ibm lotus_domino 8.5.1.5
ibm lotus_domino 8.5.3.5
ibm lotus_domino 8.5.2.2
ibm lotus_domino 8.5.1.1
ibm lotus_domino 8.5.2.3
ibm lotus_domino 8.5.3.4
ibm lotus_domino 8.5.1.4
ibm lotus_domino 8.5.2.0
ibm lotus_domino 8.5.0.1
ibm lotus_domino 8.5.3.1
ibm lotus_domino 8.5.2.1
ibm lotus_domino 8.5.0
ibm lotus_domino 8.5.3.0
ibm lotus_domino 9.0.1.0
ibm lotus_domino 8.5.1
ibm lotus_domino 9.0.0.0
ibm lotus_domino 8.5.3.3
ibm lotus_domino 8.5.1.2
ibm lotus_domino 8.5.3.2
ibm lotus_domino 8.5.1.3
CVE-2014-0823 MEDIUM

IBM WebSphere Application Server (WAS) 8.x before 8.0.0.9 and 8.5.x before 8.5.5.2 allows remote attackers to read arbitrary files via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_application_server 8.0.0.8
ibm websphere_application_server 7.0
ibm websphere_application_server 8.0.0.5
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 8.5.5.0
ibm websphere_application_server 8.5.0.2
ibm websphere_application_server 8.0.0.6
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 8.0.0.7
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 8.5.5.1
ibm websphere_application_server 8.0.0.2
CVE-2014-0824 LOW

Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.x before 7.1.1.8 LAFIX.20140319-0839 and 7.1.1.12 before IFIX.20140321-1336 and Tivoli IT Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB) 7.x before 7.1.1.8 LAFIX.20140319-0839 and 7.1.1.12 before IFIX.20140218-1510 allows remote authenticated users to inject arbitrary web script or HTML via an attachment URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_it_asset_management_for_it 7.1.1.12
ibm maximo_asset_management 7.1
ibm change_and_configuration_management_database 7.0
ibm tivoli_service_request_manager 7.0
ibm maximo_asset_management 7.1.1.1
ibm change_and_configuration_management_database 7.1
ibm tivoli_it_asset_management_for_it 7.1.1.7
ibm tivoli_service_request_manager 7.1.1.8
ibm change_and_configuration_management_database 7.1.1.7
ibm maximo_asset_management 7.1.1.12
ibm tivoli_service_request_manager 7.1.0
ibm change_and_configuration_management_database 7.1.1.12
ibm tivoli_service_request_manager 7.1.1.7
ibm maximo_service_desk 7.1.1.12
ibm tivoli_it_asset_management_for_it 7.1.1.8
ibm maximo_asset_management 7.1.1.7
ibm tivoli_service_request_manager 7.1.1.12
ibm change_and_configuration_management_database 7.1.1.8
ibm tivoli_service_request_manager 7.1.1
ibm maximo_asset_management 7.1.1.2
ibm maximo_service_desk 7.1.1.7
ibm maximo_asset_management 7.1.1.6
ibm maximo_service_desk 7.1.1.8
ibm maximo_asset_management 7.1.1.5
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
CVE-2014-0825 LOW

Cross-site scripting (XSS) vulnerability in openreport.jsp in IBM Maximo Asset Management 7.x before 7.1.1.12 IFIX.20140321-1336 and 7.5.x before 7.5.0.5 IFIX006; SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2; and Tivoli IT Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB) 7.x before 7.1.1.12 IFIX.20140218-1510 allows remote authenticated users to inject arbitrary web script or HTML via a crafted report parameter.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_it_asset_management_for_it 7.1.1.12
ibm maximo_asset_management 7.1.1.9
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management 7.1
ibm change_and_configuration_management_database 7.0
ibm tivoli_service_request_manager 7.0
ibm maximo_asset_management 7.5.0.1
ibm maximo_service_desk 7.1.1.11
ibm maximo_asset_management 7.1.1.10
ibm maximo_asset_management 7.1.1.1
ibm smartcloud_control_desk 7.5.0.0
ibm change_and_configuration_management_database 7.1
ibm tivoli_it_asset_management_for_it 7.1.1.7
ibm change_and_configuration_management_database 7.1.1.7
ibm maximo_asset_management 7.1.1.12
ibm tivoli_service_request_manager 7.1.0
ibm maximo_asset_management 7.5.0.3
ibm tivoli_service_request_manager 7.1.1.11
ibm smartcloud_control_desk 7.0
ibm tivoli_service_request_manager 7.1.0.0
ibm change_and_configuration_management_database 7.1.1.11
ibm change_and_configuration_management_database 7.1.1.12
ibm tivoli_service_request_manager 7.1.1.7
ibm maximo_service_desk 7.1.1.12
ibm maximo_asset_management 7.5.0.0
ibm maximo_asset_management 7.1.1.7
ibm tivoli_service_request_manager 7.1.1.12
ibm smartcloud_control_desk 7.5.1.1
ibm maximo_asset_management 7.5.0.4
ibm smartcloud_control_desk 7.5.0.2
ibm smartcloud_control_desk 7.5
ibm maximo_asset_management 7.5.0.5
ibm tivoli_service_request_manager 7.1.1
ibm maximo_asset_management 7.1.1.2
ibm maximo_service_desk 7.1.1.7
ibm smartcloud_control_desk 7.5.0.1
ibm maximo_asset_management 7.1.1.6
ibm maximo_asset_management 7.1.1.5
ibm smartcloud_control_desk 7.5.1.0
ibm maximo_asset_management 7.1.1.11
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
ibm tivoli_it_asset_management_for_it 7.1.1.11
CVE-2014-0827 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM InfoSphere Optim Workload Replay 1.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm optim_workload_replay 1.1
CVE-2014-0828 MEDIUM

Cross-site scripting (XSS) vulnerability in the WCM (Web Content Manager) UI in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x through 7.0.0.2 CF27, and 8.0.0.x before 8.0.0.1 CF11 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.0
ibm websphere_portal 6.1.0.3
ibm websphere_portal 7.0.0.1
ibm websphere_portal 6.1.5.2
ibm websphere_portal 6.1.0.2
ibm websphere_portal 6.1.0.4
ibm websphere_portal 8.0.0.1
ibm websphere_portal 7.0.0.2
ibm websphere_portal 6.1.5.0
ibm websphere_portal 6.1.0.6
ibm websphere_portal 6.1.5.3
ibm websphere_portal 7.0.0.0
ibm websphere_portal 6.1.0.1
ibm websphere_portal 6.1.5.1
ibm websphere_portal 6.1.0.5
ibm websphere_portal 6.1.0.0
CVE-2014-0829 MEDIUM

Multiple buffer overflows in IBM Rational ClearCase 7.x before 7.1.2.13, 8.0.0.x before 8.0.0.10, and 8.0.1.x before 8.0.1.3 allow remote authenticated users to obtain privileged access via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm rational_clearcase 7.0.0.7
ibm rational_clearcase 8.0.0.1
ibm rational_clearcase 7.0.0.9
ibm rational_clearcase 7.0.1.1
ibm rational_clearcase 8.0.1
ibm rational_clearcase 7.0.1
ibm rational_clearcase 7.0.1.10
ibm rational_clearcase 7.1.1.9
ibm rational_clearcase 7.0.0.6
ibm rational_clearcase 8.0.0.3
ibm rational_clearcase 8.0.0.6
ibm rational_clearcase 7.1.1.1
ibm rational_clearcase 7.1.1.4
ibm rational_clearcase 7.0.1.7
ibm rational_clearcase 8.0.0.9
ibm rational_clearcase 7.1.1.6
ibm rational_clearcase 8.0.0
ibm rational_clearcase 7.0.0.5
ibm rational_clearcase 7.0.1.4
ibm rational_clearcase 7.1.1.7
ibm rational_clearcase 7.1.1.8
ibm rational_clearcase 7.1.1.2
ibm rational_clearcase 8.0.1.1
ibm rational_clearcase 8.0.1.2
ibm rational_clearcase 8.0
ibm rational_clearcase 7.1.1
ibm rational_clearcase 7.1.2.12
ibm rational_clearcase 7.0.1.9
ibm rational_clearcase 7.1.2
ibm rational_clearcase 7.0.0.3
ibm rational_clearcase 7.1
ibm rational_clearcase 7.1.1.3
ibm rational_clearcase 7.1.2.6
ibm rational_clearcase 7.0.0.8
ibm rational_clearcase 7.1.2.10
ibm rational_clearcase 7.1.2.3
ibm rational_clearcase 7.0.1.6
ibm rational_clearcase 7.0.1.3
ibm rational_clearcase 7.1.0.1
ibm rational_clearcase 7.1.2.4
ibm rational_clearcase 8.0.0.7
ibm rational_clearcase 7.0.0.4
ibm rational_clearcase 7.1.2.11
ibm rational_clearcase 7.1.2.1
ibm rational_clearcase 8.0.0.8
ibm rational_clearcase 7.1.2.2
ibm rational_clearcase 7.0.1.11
ibm rational_clearcase 8.0.0.2
ibm rational_clearcase 7.1.0.2
ibm rational_clearcase 7.1.1.5
ibm rational_clearcase 7.0.1.8
ibm rational_clearcase 7.1.2.5
ibm rational_clearcase 7.0.1.2
ibm rational_clearcase 8.0.0.4
ibm rational_clearcase 7.1.2.9
ibm rational_clearcase 8.0.0.5
ibm rational_clearcase 7.1.2.7
ibm rational_clearcase 7.0.1.5
CVE-2014-0830 MEDIUM

Directory traversal vulnerability in the table-export implementation in the OAC component in IBM Financial Transaction Manager (FTM) 2.0 before 2.0.0.3 and 2.1 before 2.1.0.1 allows remote authenticated users to read arbitrary files via a modified pathname.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm financial_transaction_manager 2.0.0.2
ibm financial_transaction_manager 2.0.0.0
ibm financial_transaction_manager 2.0.0.1
ibm financial_transaction_manager 2.1.0.0
CVE-2014-0831 MEDIUM

Cross-site request forgery (CSRF) vulnerability in the OAC component in IBM Financial Transaction Manager (FTM) 2.0 before 2.0.0.3 allows remote attackers to hijack the authentication of arbitrary users for requests that modify configuration data.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm financial_transaction_manager 2.0.0.2
ibm financial_transaction_manager 2.0.0.0
ibm financial_transaction_manager 2.0.0.1
CVE-2014-0832 LOW

Multiple cross-site scripting (XSS) vulnerabilities in configuration-details screens in the OAC component in IBM Financial Transaction Manager (FTM) 2.0 before 2.0.0.3 allow remote authenticated users to inject arbitrary web script or HTML via a crafted text value.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm financial_transaction_manager 2.0.0.2
ibm financial_transaction_manager 2.0.0.0
ibm financial_transaction_manager 2.0.0.1
CVE-2014-0833 MEDIUM

The OAC component in IBM Financial Transaction Manager (FTM) 2.0 before 2.0.0.3 does not properly enforce operator-intervention requirements, which allows remote authenticated users to bypass intended access restrictions via an unspecified process step.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm financial_transaction_manager 2.0.0.2
ibm financial_transaction_manager 2.0.0.0
ibm financial_transaction_manager 2.0.0.1
CVE-2014-0834 MEDIUM

IBM General Parallel File System (GPFS) 3.4 through 3.4.0.27 and 3.5 through 3.5.0.16 allows attackers to cause a denial of service (daemon crash) via crafted arguments to a setuid program.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm general_parallel_file_system 3.4.0.7
ibm general_parallel_file_system 3.4.0.16
ibm general_parallel_file_system 3.5.0.0
ibm general_parallel_file_system 3.4.0.12
ibm general_parallel_file_system 3.4.0.2
ibm general_parallel_file_system 3.4.0.27
ibm general_parallel_file_system 3.4.0.8
ibm general_parallel_file_system 3.4.0.10
ibm general_parallel_file_system 3.4.0.13
ibm general_parallel_file_system 3.4.0.4
ibm general_parallel_file_system 3.4.0.14
ibm general_parallel_file_system 3.4.0.23
ibm general_parallel_file_system 3.5.0.9
ibm general_parallel_file_system 3.5.0.14
ibm general_parallel_file_system 3.5.0.10
ibm general_parallel_file_system 3.4.0.17
ibm general_parallel_file_system 3.4.0.19
ibm general_parallel_file_system 3.4.0.22
ibm general_parallel_file_system 3.5.0.4
ibm general_parallel_file_system 3.5.0.16
ibm general_parallel_file_system 3.5.0.15
ibm general_parallel_file_system 3.4.0.5
ibm general_parallel_file_system 3.4.0.15
ibm general_parallel_file_system 3.5.0.2
ibm general_parallel_file_system 3.5.0.3
ibm general_parallel_file_system 3.4.0.0
ibm general_parallel_file_system 3.4.0.25
ibm general_parallel_file_system 3.4.0.3
ibm general_parallel_file_system 3.4.0.20
ibm general_parallel_file_system 3.5.0.12
ibm general_parallel_file_system 3.4.0.24
ibm general_parallel_file_system 3.5.0.6
ibm general_parallel_file_system 3.5.0.13
ibm general_parallel_file_system 3.5.0.8
ibm general_parallel_file_system 3.4.0.11
ibm general_parallel_file_system 3.4.0.6
ibm general_parallel_file_system 3.4.0.18
ibm general_parallel_file_system 3.4.0.26
ibm general_parallel_file_system 3.4.0.9
ibm general_parallel_file_system 3.5.0.11
ibm general_parallel_file_system 3.4.0.21
ibm general_parallel_file_system 3.5.0.7
CVE-2014-0835 MEDIUM

Cross-site request forgery (CSRF) vulnerability in IBM Security QRadar SIEM 7.2 MR1 and earlier allows remote attackers to hijack the authentication of administrators for requests that modify console Auto Update settings.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager *
CVE-2014-0836 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Security QRadar SIEM 7.2 MR1 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager *
CVE-2014-0837 MEDIUM

The AutoUpdate process in IBM Security QRadar SIEM 7.2 MR1 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager *
CVE-2014-0838 HIGH

The AutoUpdate package before 6.4 for IBM Security QRadar SIEM 7.2 MR1 and earlier allows remote attackers to execute arbitrary console commands by leveraging control of the server.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager *
CVE-2014-0839 MEDIUM

IBM Rational Focal Point 6.4.x and 6.5.x before 6.5.2.3 and 6.6.x before 6.6.1 allows remote authenticated users to modify data via vectors involving a direct object reference.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm rational_focal_point 6.4.1.3
ibm rational_focal_point 6.5.1
ibm rational_focal_point 6.5.2.2
ibm rational_focal_point 6.4.0.1
ibm rational_focal_point 6.5.2.1
ibm rational_focal_point 6.5
ibm rational_focal_point 6.5.2.3
ibm rational_focal_point 6.4.1.2
ibm rational_focal_point 6.6.0.1
ibm rational_focal_point 6.4
ibm rational_focal_point 6.5.0.2
ibm rational_focal_point 6.5.1.1
ibm rational_focal_point 6.6
ibm rational_focal_point 6.5.0.1
ibm rational_focal_point 6.4.1.1
ibm rational_focal_point 6.4.1.0
ibm rational_focal_point 6.5.2
CVE-2014-0840 LOW

Multiple cross-site scripting (XSS) vulnerabilities in IBM Rational Focal Point 6.4.x and 6.5.x before 6.5.2.3 and 6.6.x before 6.6.1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_focal_point 6.4.1.3
ibm rational_focal_point 6.5.1
ibm rational_focal_point 6.5.2.2
ibm rational_focal_point 6.4.0.1
ibm rational_focal_point 6.5.2.1
ibm rational_focal_point 6.5
ibm rational_focal_point 6.5.2.3
ibm rational_focal_point 6.4.1.2
ibm rational_focal_point 6.6.0.1
ibm rational_focal_point 6.4
ibm rational_focal_point 6.5.0.2
ibm rational_focal_point 6.5.1.1
ibm rational_focal_point 6.6
ibm rational_focal_point 6.5.0.1
ibm rational_focal_point 6.4.1.1
ibm rational_focal_point 6.4.1.0
ibm rational_focal_point 6.5.2
CVE-2014-0841 LOW

IBM Rational Focal Point 6.4.0, 6.4.1, 6.5.1, 6.5.2, and 6.6.0 use a weak algorithm to hash passwords, which makes it easier for context-dependent attackers to obtain cleartext values via a brute-force attack. IBM X-Force ID: 90704.

CVSS 2.0

Severity: LOW

Problem Type: CWE-326,

Products Affected

Vendor Product Version
ibm rational_focal_point 6.5.1
ibm rational_focal_point 6.6
ibm rational_focal_point 6.5.2
ibm rational_focal_point 6.4
ibm rational_focal_point 6.4.1
CVE-2014-0842 MEDIUM

The account-creation functionality in IBM Rational Focal Point 6.4.x and 6.5.x before 6.5.2.3 and 6.6.x before 6.6.1 places the new user's default password within the creation page, which allows remote attackers to obtain sensitive information by reading the HTML source code.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm rational_focal_point 6.4.1.3
ibm rational_focal_point 6.5.1
ibm rational_focal_point 6.5.2.2
ibm rational_focal_point 6.4.0.1
ibm rational_focal_point 6.5.2.1
ibm rational_focal_point 6.5
ibm rational_focal_point 6.5.2.3
ibm rational_focal_point 6.4.1.2
ibm rational_focal_point 6.6.0.1
ibm rational_focal_point 6.4
ibm rational_focal_point 6.5.0.2
ibm rational_focal_point 6.5.1.1
ibm rational_focal_point 6.6
ibm rational_focal_point 6.5.0.1
ibm rational_focal_point 6.4.1.1
ibm rational_focal_point 6.4.1.0
ibm rational_focal_point 6.5.2
CVE-2014-0843 LOW

Cross-site scripting (XSS) vulnerability in IBM Rational Focal Point 6.4.x and 6.5.x before 6.5.2.3 and 6.6.x before 6.6.1 allows remote authenticated users to inject arbitrary web script or HTML by uploading a file.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_focal_point 6.4.1.3
ibm rational_focal_point 6.5.1
ibm rational_focal_point 6.5.2.2
ibm rational_focal_point 6.4.0.1
ibm rational_focal_point 6.5.2.1
ibm rational_focal_point 6.5
ibm rational_focal_point 6.5.2.3
ibm rational_focal_point 6.4.1.2
ibm rational_focal_point 6.6.0.1
ibm rational_focal_point 6.4
ibm rational_focal_point 6.5.0.2
ibm rational_focal_point 6.5.1.1
ibm rational_focal_point 6.6
ibm rational_focal_point 6.5.0.1
ibm rational_focal_point 6.4.1.1
ibm rational_focal_point 6.4.1.0
ibm rational_focal_point 6.5.2
CVE-2014-0844 LOW

Unspecified vulnerability in IBM Rational Requirements Composer 3.x before 3.0.1.6 iFix2 and 4.x before 4.0.6, and Rational DOORS Next Generation 4.x before 4.0.6, allows remote authenticated users to read arbitrary data via unknown vectors.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm rational_doors_next_generation 4.0.1
ibm rational_requirements_composer 3.0.1.5
ibm rational_doors_next_generation 4.0.0
ibm rational_requirements_composer 4.0.4
ibm rational_requirements_composer 4.0.2
ibm rational_doors_next_generation 4.0.5
ibm rational_requirements_composer 4.0.1
ibm rational_requirements_composer 3.0.1.2
ibm rational_requirements_composer 4.0.3
ibm rational_doors_next_generation 4.0.4
ibm rational_requirements_composer 3.0.1.4
ibm rational_requirements_composer 4.0.0.1
ibm rational_requirements_composer 3.0.1.1
ibm rational_doors_next_generation 4.0.2
ibm rational_requirements_composer 3.0.1
ibm rational_doors_next_generation 4.0.3
ibm rational_requirements_composer 3.0.1.3
ibm rational_requirements_composer 3.0.1.6
ibm rational_requirements_composer 4.0.0
ibm rational_requirements_composer 4.0.0.2
ibm rational_requirements_composer 4.0.5
CVE-2014-0845 MEDIUM

Open redirect vulnerability in IBM Rational Requirements Composer 3.x before 3.0.1.6 iFix2 and 4.x before 4.0.6, and Rational DOORS Next Generation 4.x before 4.0.6, allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm rational_doors_next_generation 4.0.1
ibm rational_requirements_composer 3.0.1.5
ibm rational_doors_next_generation 4.0.0
ibm rational_requirements_composer 4.0.4
ibm rational_requirements_composer 4.0.2
ibm rational_doors_next_generation 4.0.5
ibm rational_requirements_composer 4.0.1
ibm rational_requirements_composer 3.0.1.2
ibm rational_requirements_composer 4.0.3
ibm rational_doors_next_generation 4.0.4
ibm rational_requirements_composer 3.0.1.4
ibm rational_requirements_composer 4.0.0.1
ibm rational_requirements_composer 3.0.1.1
ibm rational_doors_next_generation 4.0.2
ibm rational_requirements_composer 3.0.1
ibm rational_doors_next_generation 4.0.3
ibm rational_requirements_composer 3.0.1.3
ibm rational_requirements_composer 3.0.1.6
ibm rational_requirements_composer 4.0.0
ibm rational_requirements_composer 4.0.0.2
ibm rational_requirements_composer 4.0.5
CVE-2014-0846 LOW

Cross-site scripting (XSS) vulnerability in IBM Rational Requirements Composer 3.x before 3.0.1.6 iFix2 and 4.x before 4.0.6, and Rational DOORS Next Generation 4.x before 4.0.6, allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_doors_next_generation 4.0.1
ibm rational_requirements_composer 3.0.1.5
ibm rational_doors_next_generation 4.0.0
ibm rational_requirements_composer 4.0.4
ibm rational_requirements_composer 4.0.2
ibm rational_doors_next_generation 4.0.5
ibm rational_requirements_composer 4.0.1
ibm rational_requirements_composer 3.0.1.2
ibm rational_requirements_composer 4.0.3
ibm rational_doors_next_generation 4.0.4
ibm rational_requirements_composer 3.0.1.4
ibm rational_requirements_composer 4.0.0.1
ibm rational_requirements_composer 3.0.1.1
ibm rational_doors_next_generation 4.0.2
ibm rational_requirements_composer 3.0.1
ibm rational_doors_next_generation 4.0.3
ibm rational_requirements_composer 3.0.1.3
ibm rational_requirements_composer 3.0.1.6
ibm rational_requirements_composer 4.0.0
ibm rational_requirements_composer 4.0.0.2
ibm rational_requirements_composer 4.0.5
CVE-2014-0848 LOW

The (1) ssl.conf and (2) httpd.conf files in the Apache HTTP Server component in IBM Netezza Performance Portal 2.0 before 2.0.0.4 have weak SSLCipherSuite values, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack.

CVSS 2.0

Severity: LOW

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm netezza_performance_portal 2.0.0.1
ibm netezza_performance_portal 2.0.0.2
ibm netezza_performance_portal 2.0.0.0
ibm netezza_performance_portal 2.0.0.3
CVE-2014-0849 MEDIUM

IBM Maximo Asset Management 7.x before 7.5.0.3 IFIX027 and SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2 allow remote authenticated users to gain privileges by leveraging membership in two security groups.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm maximo_asset_management 7.1.1.9
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.5.0.1
ibm maximo_asset_management 7.1.1.10
ibm maximo_asset_management 7.1.1.1
ibm smartcloud_control_desk 7.5.0.0
ibm maximo_asset_management 7.1.1.12
ibm maximo_asset_management 7.5.0.3
ibm smartcloud_control_desk 7.0
ibm maximo_asset_management 7.5.0.0
ibm maximo_asset_management 7.1.1.7
ibm smartcloud_control_desk 7.5.1.1
ibm smartcloud_control_desk 7.5.0.2
ibm smartcloud_control_desk 7.5
ibm maximo_asset_management 7.1.1.2
ibm smartcloud_control_desk 7.5.0.1
ibm maximo_asset_management 7.1.1.6
ibm maximo_asset_management 7.1.1.5
ibm smartcloud_control_desk 7.5.1.0
ibm maximo_asset_management 7.1.1.11
ibm maximo_asset_management 7.1.2
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
ibm smartcloud_control_desk 7.5.0.3
CVE-2014-0850 LOW

Cross-site scripting (XSS) vulnerability in IBM InfoSphere Master Data Management Reference Data Management (RDM) Hub 10.1 and 11.0 before 11.0.0.0-MDM-IF008 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm infosphere_master_data_management_reference_data_management_hub 10.1
ibm infosphere_master_data_management_reference_data_management_hub 11.0
CVE-2014-0852 MEDIUM

IBM WebSphere DataPower SOA appliances through 4.0.2.15, 5.x through 5.0.0.17, 6.0.0.x through 6.0.0.9, and 6.0.1.x through 6.0.1.5 make it easier for remote attackers to obtain a PreMasterSecret value and defeat cryptographic protection mechanisms by sending a large number of requests in an SSL/TLS side-channel timing attack.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm websphere_datapower_soa_appliance -
ibm websphere_datapower_soa_appliance_firmware 5.0.0
ibm websphere_datapower_soa_appliance_firmware 6.0.0
ibm websphere_datapower_soa_appliance_firmware 6.0.1
ibm websphere_datapower_soa_appliance_firmware *
CVE-2014-0853 LOW

Multiple cross-site scripting (XSS) vulnerabilities in the (1) ForwardController and (2) AttributeEditor scripts in IBM Rational Focal Point 6.4.x and 6.5.x before 6.5.2.3 and 6.6.x before 6.6.1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_focal_point 6.4.1.3
ibm rational_focal_point 6.5.1
ibm rational_focal_point 6.5.2.2
ibm rational_focal_point 6.4.0.1
ibm rational_focal_point 6.5.2.1
ibm rational_focal_point 6.5
ibm rational_focal_point 6.5.2.3
ibm rational_focal_point 6.4.1.2
ibm rational_focal_point 6.6.0.1
ibm rational_focal_point 6.4
ibm rational_focal_point 6.5.0.2
ibm rational_focal_point 6.5.1.1
ibm rational_focal_point 6.6
ibm rational_focal_point 6.5.0.1
ibm rational_focal_point 6.4.1.1
ibm rational_focal_point 6.4.1.0
ibm rational_focal_point 6.5.2
CVE-2014-0854 MEDIUM

The server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1 before IF6, 10.1.1 before IF5, 10.2 before IF7, 10.2.1 before IF4, and 10.2.1.1 before IF4 allows remote authenticated users to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm cognos_business_intelligence 10.2.1
ibm cognos_business_intelligence 10.2
ibm cognos_business_intelligence 10.1
ibm cognos_business_intelligence 10.2.1.1
ibm cognos_business_intelligence 8.4.1
ibm cognos_business_intelligence 10.1.1
CVE-2014-0855 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in IBM Connections Portlets 4.x before 4.5.1 FP1 for IBM WebSphere Portal 7.0.0.2 and 8.0.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm connections_portlets 4.5.1
ibm connections_portlets 4.0
ibm connections_portlets 4.5
CVE-2014-0857 MEDIUM

The Administrative Console in IBM WebSphere Application Server (WAS) 8.x before 8.0.0.9 and 8.5.x before 8.5.5.2 allows remote authenticated users to obtain sensitive information via a crafted request.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_application_server 8.0.0.8
ibm websphere_application_server 7.0
ibm websphere_application_server 8.0.0.5
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 8.5.5.0
ibm websphere_application_server 8.5.0.2
ibm websphere_application_server 8.0.0.6
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 8.0.0.7
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 8.5.5.1
ibm websphere_application_server 8.0.0.2
CVE-2014-0858 LOW

IBM Content Navigator 2.x before 2.0.2.2-ICN-FP002 allows remote authenticated users to bypass intended access restrictions and conduct deleteAction attacks via a modified URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm content_navigator 2.0.1
ibm content_navigator 2.0.2
ibm content_navigator 2.0.0
CVE-2014-0859 MEDIUM

The web-server plugin in IBM WebSphere Application Server (WAS) 7.x before 7.0.0.33, 8.x before 8.0.0.9, and 8.5.x before 8.5.5.2, when POST retries are enabled, allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 7.0
ibm websphere_application_server 8.0.0.5
ibm websphere_application_server 7.0.0.12
ibm websphere_application_server 8.5.0.2
ibm websphere_application_server 8.0.0.6
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 7.0.0.16
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 7.0.0.25
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 7.0.0.14
ibm websphere_application_server 7.0.0.22
ibm websphere_application_server 7.0.0.31
ibm websphere_application_server 7.0.0.10
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 8.0.0.8
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0.0.29
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 7.0.0.24
ibm websphere_application_server 8.5.5.0
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 8.0.0.7
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 7.0.0.27
ibm websphere_application_server 7.0.0.18
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 8.5.5.1
ibm websphere_application_server 7.0.0.4
ibm websphere_application_server 8.0.0.2
CVE-2014-0860 MEDIUM

The firmware before 3.66E in IBM BladeCenter Advanced Management Module (AMM), the firmware before 1.43 in IBM Integrated Management Module (IMM), and the firmware before 4.15 in IBM Integrated Management Module II (IMM2) contains cleartext IPMI credentials, which allows attackers to execute arbitrary IPMI commands, and consequently establish a blade remote-control session, by leveraging access to (1) the chassis internal network or (2) the Ethernet-over-USB interface.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm integrated_management_module -
ibm advanced_management_module -
ibm integrated_management_module_firmware *
ibm integrated_management_module_ii_firmware *
ibm advanced_management_module_firmware *
ibm integrated_management_module_ii -
CVE-2014-0861 LOW

Cross-site scripting (XSS) vulnerability in the server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1 before IF6, 10.1.1 before IF5, 10.2 before IF7, 10.2.1 before IF4, and 10.2.1.1 before IF4 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter that is not properly handled during use of the Back button.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm cognos_business_intelligence 10.2.1
ibm cognos_business_intelligence 10.2
ibm cognos_business_intelligence 10.1
ibm cognos_business_intelligence 10.2.1.1
ibm cognos_business_intelligence 8.4.1
ibm cognos_business_intelligence 10.1.1
CVE-2014-0862 HIGH

Unspecified vulnerability in Jazz Team Server in IBM Rational Collaborative Lifecycle Management (CLM) 3.x before 3.0.1.6 iFix 2 and 4.x before 4.0.6 allows remote attackers to execute arbitrary code via unknown vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm rational_collaborative_lifecycle_management 3.0.1.2
ibm rational_collaborative_lifecycle_management 3.0.1
ibm rational_collaborative_lifecycle_management 3.0.1.1
ibm rational_collaborative_lifecycle_management 3.0.0
ibm rational_collaborative_lifecycle_management 3.0.1.3
ibm rational_collaborative_lifecycle_management 4.0.1
ibm rational_collaborative_lifecycle_management 4.0.5
ibm rational_collaborative_lifecycle_management 4.0.3
ibm rational_collaborative_lifecycle_management 3.0.1.5
ibm rational_collaborative_lifecycle_management 3.0.1.4
ibm rational_collaborative_lifecycle_management 4.0.0
ibm rational_collaborative_lifecycle_management 3.0.1.6
ibm rational_collaborative_lifecycle_management 4.0.2
ibm rational_collaborative_lifecycle_management 4.0.4
CVE-2014-0863 MEDIUM

The client in IBM Cognos TM1 9.5.2.3 before IF5, 10.1.1.2 before IF1, 10.2.0.2 before IF1, and 10.2.2.0 before IF1 stores obfuscated passwords in memory, which allows remote authenticated users to obtain sensitive cleartext information via an unspecified security tool.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm cognos_tm1 10.2.2
ibm cognos_tm1 10.1.1.2
ibm cognos_tm1 10.2.0.2
ibm cognos_tm1 9.5.2.3
CVE-2014-0864 MEDIUM

Multiple cross-site request forgery (CSRF) vulnerabilities in Executer in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allow remote attackers to hijack the authentication of arbitrary users for requests that change (1) a deal's currency or (2) a limit via a crafted XML document.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm algo_credit_limits 4.7.0
ibm algo_credit_limits 4.5.0
CVE-2014-0865 MEDIUM

RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics relies on client-side input validation, which allows remote authenticated users to bypass intended dual-control restrictions and modify data via crafted serialized objects, as demonstrated by limit manipulations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm algo_credit_limits 4.7.0
ibm algorithmics -
ibm algo_credit_limits 4.5.0
CVE-2014-0866 MEDIUM

RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics sends cleartext credentials over HTTP, which allows remote attackers to obtain sensitive information by sniffing the network.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm algo_credit_limits 4.7.0
ibm algorithmics -
ibm algo_credit_limits 4.5.0
CVE-2014-0867 MEDIUM

rcore6/main/addcookie.jsp in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allows remote attackers to create or modify cookies via the query string.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm algo_credit_limits 4.7.0
ibm algorithmics -
ibm algo_credit_limits 4.5.0
CVE-2014-0868 MEDIUM

RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics relies on client-side input validation, which allows remote authenticated users to bypass intended dual-control restrictions and modify data via a crafted XML document, as demonstrated by manipulation of read-only limit data.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm algo_credit_limits 4.7.0
ibm algorithmics -
ibm algo_credit_limits 4.5.0
CVE-2014-0869 MEDIUM

The decrypt function in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics does not require a key, which makes it easier for remote attackers to obtain cleartext passwords by sniffing the network and then providing a string argument to this function.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm algo_credit_limits 4.7.0
ibm algorithmics -
ibm algo_credit_limits 4.5.0
CVE-2014-0870 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allow remote attackers to inject arbitrary web script or HTML via (1) the Message parameter to rcore6/main/showerror.jsp, (2) the ButtonsetClass parameter to rcore6/main/buttonset.jsp, (3) the MBName parameter to rcore6/frameset.jsp, (4) the Init parameter to algopds/rcore6/main/browse.jsp, or the (5) Name, (6) StoreName, or (7) STYLESHEET parameter to algopds/rcore6/main/ibrowseheader.jsp.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm algo_credit_limits 4.7.0
ibm algorithmics -
ibm algo_credit_limits 4.5.0
CVE-2014-0871 MEDIUM

RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allows remote attackers to obtain potentially sensitive Tomcat stack-trace information via non-printing characters in a cookie to the /classes/ URI, as demonstrated by the \x00 character.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm algo_credit_limits 4.7.0
ibm algorithmics -
ibm algo_credit_limits 4.5.0
CVE-2014-0872 LOW

The installation process in IBM Security Key Lifecycle Manager 2.5 stores unencrypted credentials, which might allow local users to obtain sensitive information by leveraging root access. IBM X-Force ID: 90988.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,CWE-255,

Products Affected

Vendor Product Version
ibm security_key_lifecycle_manager 2.5.0
CVE-2014-0873 MEDIUM

Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) Data Stewardship, (2) Business Admin, and (3) Product interfaces in IBM InfoSphere Master Data Management (MDM) Server 8.5 before 8.5.0.82, 9.0.1 before 9.0.1.38, 9.0.2 before 9.0.2.35, 10.0 before 10.0.0.0.26, and 10.1 before 10.1.0.0.15 allow remote attackers to hijack the authentication of arbitrary users.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm infosphere_master_data_management_server 10.1
ibm infosphere_master_data_management_server 9.0.1
ibm infosphere_master_data_management_server 10.0
ibm infosphere_master_data_management_server 8.5
ibm infosphere_master_data_management_server 9.0.2
CVE-2014-0874 LOW

Cross-site scripting (XSS) vulnerability in IBM Content Navigator 2.x before 2.0.2.2-ICN-FP002 allows remote authenticated users to inject arbitrary web script or HTML via an unspecified parameter.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm content_navigator 2.0.1
ibm content_navigator 2.0.2
ibm content_navigator 2.0.0
CVE-2014-0875 LOW

Active Cloud Engine (ACE) in IBM Storwize V7000 Unified 1.3.0.0 through 1.4.3.x allows remote attackers to bypass intended ACL restrictions in opportunistic circumstances by leveraging incorrect ACL synchronization over an unreliable NFS connection that requires retransmissions.

CVSS 2.0

Severity: LOW

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm storwize_unified_v7000_software 1.4.0.4
ibm storwize_unified_v7000 -
ibm storwize_unified_v7000_software 1.3.0.0
ibm storwize_unified_v7000_software 1.4.3.2
ibm storwize_unified_v7000_software 1.3.1.0
ibm storwize_unified_v7000_software 1.4.0.2
ibm storwize_unified_v7000_software 1.4.0.5
ibm storwize_unified_v7000_software 1.4.2.0
ibm storwize_unified_v7000_software 1.4.0.3
ibm storwize_unified_v7000_software 1.4.2.1
ibm storwize_unified_v7000_software 1.4.3.1
ibm storwize_unified_v7000_software 1.4.1.1
ibm storwize_unified_v7000_software 1.4.0.0
ibm storwize_unified_v7000_software 1.4.1.0
ibm storwize_unified_v7000_software 1.4.3.0
ibm storwize_unified_v7000_software 1.4.0.1
CVE-2014-0876 LOW

Buffer overflow in the Java GUI Configuration Wizard and Preferences Editor in the backup-archive client in IBM Tivoli Storage Manager (TSM) 5.x and 6.x before 6.2.5.2, 6.3.x before 6.3.2, and 6.4.x before 6.4.2 on Windows and OS X allows local users to cause a denial of service (application crash or hang) via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager 6.1.0
ibm tivoli_storage_manager 5.4.0
ibm tivoli_storage_manager 6.4.0
ibm tivoli_storage_manager 5.5.0
ibm tivoli_storage_manager 6.2.0
ibm tivoli_storage_manager 6.3.0
CVE-2014-0877 MEDIUM

IBM Cognos TM1 10.2.0.2 before IF1 and 10.2.2.0 before IF1 allows remote attackers to bypass intended access restrictions by visiting the Rights page and then following a generated link.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm cognos_tm1 10.2.0.2
ibm cognos_tm1 10.2.2.0
CVE-2014-0878 MEDIUM

The IBMSecureRandom component in the IBMJCE and IBMSecureRandom cryptographic providers in IBM SDK Java Technology Edition 5.0 before Service Refresh 16 FP6, 6 before Service Refresh 16, 6.0.1 before Service Refresh 8, 7 before Service Refresh 7, and 7R1 before Service Refresh 1 makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms by predicting the random number generator's output.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm java_sdk 6.0.4.0
ibm java_sdk 5.0.11.2
ibm java_sdk 7.0.6.1
ibm java_sdk 6.0.9.0
ibm java_sdk 7.0.2.0
ibm java_sdk 7.0.4.2
ibm java_sdk 7.0.4.0
ibm java_sdk 5.0.12.2
ibm java_sdk 6.0.13.0
ibm java_sdk 6.0.13.1
ibm java_sdk 6.0.15.0
ibm java_sdk 5.0.11.1
ibm java_sdk 6.0.5.0
ibm java_sdk 6.0.9.2
ibm java_sdk 5.0.12.4
ibm java_sdk 6.0.3.0
ibm java_sdk 6.0.6.0
ibm java_sdk 5.0.12.0
ibm java_sdk 5.0.16.1
ibm java_sdk 6.0.0.0
ibm java_sdk 6.0.1.0
ibm java_sdk 5.0.16.0
ibm java_sdk 6.0.11.0
ibm java_sdk 5.0.12.5
ibm java_sdk 6.0.8.1
ibm java_sdk 5.0.11.0
ibm java_sdk 6.0.10.1
ibm java_sdk 7.0.1.0
ibm java_sdk 5.0.14.0
ibm java_sdk 5.0.13.0
ibm java_sdk 7.0.3.0
ibm java_sdk 6.0.10.0
ibm java_sdk 5.0.16.2
ibm java_sdk 6.0.12.0
ibm java_sdk 5.0.12.3
ibm java_sdk 6.0.15.1
ibm java_sdk 5.0.0.0
ibm java_sdk 5.0.15.0
ibm java_sdk 7.0.5.0
ibm java_sdk 6.0.14.0
ibm java_sdk 6.0.8.0
ibm java_sdk 6.0.2.0
ibm java_sdk 7.0.6.0
ibm java_sdk 7.0.4.1
ibm java_sdk 6.0.13.2
ibm java_sdk 5.0.16.5
ibm java_sdk 7.1.0.0
ibm java_sdk 6.0.7.0
ibm java_sdk 6.0.9.1
ibm java_sdk 5.0.16.4
ibm java_sdk 5.0.12.1
ibm java_sdk 5.0.16.3
ibm java_sdk 7.0.0.0
CVE-2014-0879 HIGH

Stack-based buffer overflow in the Taskmaster Capture ActiveX control in IBM Datacap Taskmaster Capture 8.0.1, and 8.1 before FP2, allows remote attackers to execute arbitrary code via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm datacap_taskmaster_capture 8.0.1
ibm datacap_taskmaster_capture 8.1
CVE-2014-0880 HIGH

IBM SAN Volume Controller; Storwize V3500, V3700, V5000, and V7000; and Flex System V7000 with software 6.3 and 6.4 before 6.4.1.8, and 7.1 and 7.2 before 7.2.0.3, allow remote attackers to obtain CLI access, and consequently cause a denial of service, via unspecified traffic to the administrative IP address.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm storwize_v5000_software 7.1.0.5
ibm storwize_v3500_software 6.4.1.1
ibm san_volume_controller_software 6.2.0.5
ibm storwize_v3700_software 7.1.0.0
ibm storwize_v7000_software 6.4.1.3
ibm storwize_v7000_software 7.1.0.3
ibm san_volume_controller_software 7.1.0.2
ibm storwize_v3700_software 7.2.0.0
ibm storwize_v7000_software 6.4.1.7
ibm flex_system_v7000_software 6.4.1.6
ibm storwize_v3500_software 7.1.0.3
ibm storwize_v7000_software 6.3.0.6
ibm storwize_v3700_software 6.4.1.3
ibm san_volume_controller_software 7.1.0.6
ibm storwize_v5000_software 7.2.0.1
ibm storwize_v3500_software 6.4.1.4
ibm storwize_v7000_software 6.4.1.4
ibm storwize_v7000_software 6.4.1.5
ibm storwize_v3700_software 7.1.0.3
ibm san_volume_controller_software 7.1.0.0
ibm storwize_v3700_software 6.4.1.5
ibm san_volume_controller_software 6.4.0.2
ibm san_volume_controller_software 7.1.0.1
ibm san_volume_controller_software 7.1.0.3
ibm san_volume_controller_software 6.1.0.9
ibm flex_system_v7000_software 6.4.1.7
ibm san_volume_controller_software 6.2.0.3
ibm storwize_v7000_software 6.4.1.6
ibm flex_system_v7000_software 7.1.0.1
ibm san_volume_controller_software 6.1.0.5
ibm storwize_v7000_software 6.4.0.0
ibm storwize_v3500_software 7.1.0.2
ibm san_volume_controller_software 7.2.0.1
ibm storwize_v3500_software 7.1.0.6
ibm flex_system_v7000_software 7.1.0.5
ibm storwize_v5000_software 7.1.0.7
ibm storwize_v3700_software 7.1.0.2
ibm san_volume_controller_software 6.1.0.3
ibm storwize_v3700_software 7.1.0.5
ibm storwize_v3500_software 7.2.0.2
ibm san_volume_controller_software 6.1.0.4
ibm san_volume_controller_software 6.2.0.1
ibm san_volume_controller_software 6.4.1.6
ibm storwize_v3500_software 6.4.1.3
ibm san_volume_controller -
ibm flex_system_v7000_software 6.4.1.3
ibm san_volume_controller_software 6.3.0.3
ibm san_volume_controller_software 6.3.0.2
ibm storwize_v5000_software 7.1.0.4
ibm storwize_v7000_software 6.3.0.7
ibm storwize_v3700_software 7.1.0.1
ibm san_volume_controller_software 6.4.0.4
ibm storwize_v3500_software 6.4.1.2
ibm storwize_v3500_software 7.1.0.1
ibm storwize_v7000_software 7.1.0.5
ibm storwize_v7000_software 7.1.0.2
ibm flex_system_v7000 -
ibm storwize_v5000_software 7.2.0.0
ibm san_volume_controller_software 6.1.0.6
ibm san_volume_controller_software 6.4.0.1
ibm storwize_v3500_software 6.4.1.7
ibm flex_system_v7000_software 6.4.1.2
ibm storwize_v7000_software 7.2.0.2
ibm san_volume_controller_software 6.1.0.0
ibm flex_system_v7000_software 7.2.0.1
ibm san_volume_controller_software 6.3.0.1
ibm storwize_v7000_software 6.3.0.4
ibm storwize_v7000_software 7.2.0.1
ibm flex_system_v7000_software 7.2.0.2
ibm storwize_v5000_software 7.1.0.2
ibm san_volume_controller_software 6.1.0.10
ibm san_volume_controller_software 6.4.1.7
ibm storwize_v3700_software 6.4.1.4
ibm san_volume_controller_software 6.4.1.2
ibm san_volume_controller_software 6.3.0.5
ibm san_volume_controller_software 6.4.1.3
ibm storwize_v3700_software 6.4.1.1
ibm storwize_v7000_software 6.4.0.1
ibm storwize_v3700_software 6.4.1.7
ibm storwize_v3700 -
ibm san_volume_controller_software 6.4.1.4
ibm storwize_v3700_software 7.1.0.6
ibm san_volume_controller_software 7.1.0.5
ibm flex_system_v7000_software 6.4.1.4
ibm san_volume_controller_software 6.4.0.3
ibm storwize_v7000_software 6.3.0.2
ibm storwize_v3500_software 6.4.1.6
ibm storwize_v7000_software 7.1.0.6
ibm storwize_v7000_software 6.4.0.4
ibm flex_system_v7000_software 7.2.0.0
ibm san_volume_controller_software 6.2.0.4
ibm san_volume_controller_software 6.1.0.2
ibm storwize_v7000_software 6.4.1.2
ibm san_volume_controller_software 6.2.0.2
ibm storwize_v5000_software 7.2.0.2
ibm storwize_v3500_software 7.2.0.0
ibm storwize_v3700_software 7.1.0.7
ibm storwize_v7000_software 6.4.1.1
ibm storwize_v3500 -
ibm flex_system_v7000_software 6.4.1.5
ibm storwize_v3700_software 6.4.1.0
ibm san_volume_controller_software 6.4.1.1
ibm san_volume_controller_software 6.3.0.4
ibm flex_system_v7000_software 7.1.0.3
ibm san_volume_controller_software 6.1.0.1
ibm storwize_v3700_software 7.2.0.2
ibm storwize_v5000_software 7.1.0.6
ibm san_volume_controller_software 6.2.0.0
ibm storwize_v3500_software 6.4.1.0
ibm storwize_v7000_software 7.1.0.0
ibm storwize_v7000_software 7.1.0.1
ibm storwize_v3500_software 7.1.0.0
ibm san_volume_controller_software 6.4.1.5
ibm storwize_v3700_software 7.2.0.1
ibm san_volume_controller_software 6.2.0.6
ibm san_volume_controller_software 6.1.0.7
ibm san_volume_controller_software 6.3.0.7
ibm storwize_v5000_software 7.1.0.3
ibm storwize_v3700_software 6.4.1.6
ibm san_volume_controller_software 6.1.0.8
ibm storwize_v3500_software 7.1.0.5
ibm san_volume_controller_software 7.2.0.2
ibm storwize_v7000_software 6.3.0.1
ibm san_volume_controller_software 6.3.0.6
ibm flex_system_v7000_software 7.1.0.7
ibm san_volume_controller_software 6.4.0.0
ibm storwize_v7000 -
ibm storwize_v7000_software 6.3.0.0
ibm storwize_v7000_software 7.1.0.7
ibm storwize_v7000_software 6.3.0.3
ibm storwize_v7000_software 6.4.0.2
ibm san_volume_controller_software 7.1.0.7
ibm storwize_v7000_software 7.2.0.0
ibm storwize_v5000 -
ibm storwize_v7000_software 6.4.0.3
ibm san_volume_controller_software 7.2.0.0
ibm flex_system_v7000_software 7.1.0.2
ibm storwize_v3700_software 6.4.1.2
ibm flex_system_v7000_software 7.1.0.6
ibm storwize_v3500_software 6.4.1.5
ibm san_volume_controller_software 6.3.0.0
ibm storwize_v7000_software 6.3.0.5
ibm storwize_v3500_software 7.2.0.1
CVE-2014-0881 MEDIUM

The TPM on Integrated Management Module II (IMM2) on IBM Flex System x222 servers with firmware 1.00 through 3.56 allows remote attackers to obtain sensitive key information or cause a denial of service by leveraging an incorrect configuration. IBM X-Force ID: 91146.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm integrated_management_module_firmware *
CVE-2014-0882 MEDIUM

Integrated Management Module II (IMM2) on IBM Flex System, NeXtScale, System x3xxx, and System x iDataPlex systems might allow remote authenticated users to obtain sensitive account information via vectors related to generated Service Advisor data (FFDC). IBM X-Force ID: 91149.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm integrated_management_module_firmware 3.50
ibm integrated_management_module_firmware 3.67
ibm integrated_management_module_firmware 3.65
ibm integrated_management_module_firmware 3.55
ibm integrated_management_module_firmware 3.56
CVE-2014-0883 MEDIUM

IBM Power HMC 7.1.0 through 7.8.0 and 7.3.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.  IBM X-Force ID:  91163.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,CWE-79,

Products Affected

Vendor Product Version
ibm power_hardware_management_console 7r7.2.0
ibm power_hardware_management_console 7r7.6.0
ibm power_hardware_management_console 7r7.8.0
ibm power_hardware_management_console 7r7.5.0
ibm power_hardware_management_console 7r7.4.0
ibm power_hardware_management_console 7r7.1.0
ibm power_hardware_management_console 7r7.3.5
ibm power_hardware_management_console 7r7.7.0
ibm power_hardware_management_console 7r7.3.0
CVE-2014-0884 LOW

Cross-site scripting (XSS) vulnerability in the Admin Web UI in IBM Lotus Protector for Mail Security 2.8.x before 2.8.1-22905 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm lotus_protector_for_mail_security 2.8
ibm lotus_protector_for_mail_security 2.8.1
CVE-2014-0885 MEDIUM

Cross-site request forgery (CSRF) vulnerability in the Admin Web UI in IBM Lotus Protector for Mail Security 2.8.x before 2.8.1-22905 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm lotus_protector_for_mail_security 2.8
ibm lotus_protector_for_mail_security 2.8.1
CVE-2014-0886 HIGH

The Admin Web UI in IBM Lotus Protector for Mail Security 2.8.x before 2.8.1-22905 allows remote authenticated users to bypass intended access restrictions and execute arbitrary commands via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-78,

Products Affected

Vendor Product Version
ibm lotus_protector_for_mail_security 2.8
ibm lotus_protector_for_mail_security 2.8.1
CVE-2014-0887 HIGH

The Admin Web UI in IBM Lotus Protector for Mail Security 2.8.x before 2.8.1-22905 allows remote authenticated users to execute arbitrary commands with root privileges via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-78,

Products Affected

Vendor Product Version
ibm lotus_protector_for_mail_security 2.8
ibm lotus_protector_for_mail_security 2.8.1
CVE-2014-0888 MEDIUM

IBM Worklight Foundation 5.x and 6.x before 6.2.0.0, as used in Worklight and Mobile Foundation, allows remote authenticated users to bypass the application-authenticity feature via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm worklight 5.0.6.1
ibm mobile_foundation 5.0.5.0
ibm worklight 5.0.0.1
ibm worklight 6.0.0.1
ibm worklight 5.0.0.0
ibm worklight 6.0.0.2
ibm mobile_foundation 5.0.5.1
ibm worklight 5.0.5.1
ibm mobile_foundation 5.0.0.1
ibm mobile_foundation 6.1.0.0
ibm worklight 5.0.0.2
ibm worklight 5.0.6.0
ibm worklight 6.1.0.1
ibm mobile_foundation 5.0.6.1
ibm mobile_foundation 5.0.0.0
ibm mobile_foundation 6.0.0.0
ibm worklight 5.0.6.2
ibm mobile_foundation 5.0.0.2
ibm mobile_foundation 5.0.0.3
ibm worklight 5.0.5.0
ibm worklight 6.0.0.0
ibm mobile_foundation 6.0.0.1
ibm worklight 6.1.0.0
ibm mobile_foundation 6.0.0.2
ibm mobile_foundation 6.1.0.1
ibm worklight 5.0.0.3
ibm mobile_foundation 5.0.6.2
ibm mobile_foundation 5.0.6.0
CVE-2014-0889 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in IBM Atlas Suite (aka Atlas Policy Suite), as used in Atlas eDiscovery Process Management through 6.0.3, Disposal and Governance Management for IT through 6.0.3, and Global Retention Policy and Schedule Management through 6.0.3, allow remote attackers to inject arbitrary web script or HTML via unspecified parameters.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm atlas_ediscovery_process_management 6.0.1.6
ibm atlas_ediscovery_process_management *
ibm disposal_and_governance_management_for_it *
ibm disposal_and_governance_management_for_it 6.0.1.6
ibm global_retention_policy_and_schedule_management 6.0.2
ibm global_retention_policy_and_schedule_management 6.0.1.6
ibm global_retention_policy_and_schedule_management *
ibm disposal_and_governance_management_for_it 6.0.2
ibm disposal_and_governance_management_for_it 6.0.1.5
ibm atlas_suite -
ibm atlas_ediscovery_process_management 6.0.2
ibm global_retention_policy_and_schedule_management 6.0.1.5
ibm atlas_ediscovery_process_management 6.0.1.5
CVE-2014-0890 LOW

The Connect client in IBM Sametime 8.5.1, 8.5.1.1, 8.5.1.2, 8.5.2, 8.5.2.1, 9.0, and 9.0.0.1, when a certain com.ibm.collaboration.realtime.telephony.*.level setting is used, logs cleartext passwords during Audio/Video chat sessions, which allows local users to obtain sensitive information by reading a log file.

CVSS 2.0

Severity: LOW

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm sametime 8.5.1.1
ibm sametime 8.5.2.0
ibm sametime 8.5.2.1
ibm sametime 9.0.0.1
ibm sametime 9.0.0.0
ibm sametime 8.5.1.0
ibm sametime 8.5.1.2
CVE-2014-0891 MEDIUM

IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.33, 8.0.x before 8.0.0.9, and 8.5.x before 8.5.5.2 allows remote attackers to obtain sensitive information by leveraging incorrect request handling by the (1) Proxy or (2) ODR server.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 7.0
ibm websphere_application_server 8.0.0.5
ibm websphere_application_server 7.0.0.12
ibm websphere_application_server 8.5.0.2
ibm websphere_application_server 8.0.0.6
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 7.0.0.16
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 7.0.0.25
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 7.0.0.14
ibm websphere_application_server 7.0.0.22
ibm websphere_application_server 7.0.0.31
ibm websphere_application_server 7.0.0.10
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 8.0.0.8
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0.0.29
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 7.0.0.24
ibm websphere_application_server 8.5.5.0
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 8.0.0.7
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 7.0.0.27
ibm websphere_application_server 7.0.0.18
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 8.5.5.1
ibm websphere_application_server 7.0.0.4
ibm websphere_application_server 8.0.0.2
CVE-2014-0892 MEDIUM

IBM Notes and Domino 8.5.x before 8.5.3 FP6 IF3 and 9.x before 9.0.1 FP1 on 32-bit Linux platforms use incorrect gcc options, which makes it easier for remote attackers to execute arbitrary code by leveraging the absence of the NX protection mechanism and placing crafted x86 code on the stack, aka SPR KLYH9GGS9W.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm lotus_notes 8.5.1.5
ibm lotus_notes 8.5.2.0
ibm lotus_domino 8.5.3.5
ibm lotus_domino 8.5.2.2
ibm lotus_domino 8.5.1.1
ibm lotus_notes 8.5.1.4
ibm lotus_domino 8.5.3.4
ibm lotus_notes 8.5.3.5
ibm lotus_domino 8.5.1.4
ibm lotus_notes 8.5.3.2
ibm lotus_notes 8.5.2.1
ibm lotus_domino 8.5.2.0
ibm lotus_domino 8.5.3.1
ibm lotus_domino 8.5.0
ibm lotus_domino 8.5.3.0
ibm lotus_domino 9.0.1.0
ibm lotus_domino 8.5.1
ibm lotus_notes 8.5.0.1
ibm lotus_domino 9.0.0.0
ibm lotus_domino 8.5.3.3
ibm lotus_domino 8.5.1.2
ibm lotus_notes 9.0.1.0
ibm lotus_domino 8.5.3.6
ibm lotus_domino 8.5.3.2
ibm lotus_notes 8.5.3.6
ibm lotus_domino 8.5.1.3
ibm lotus_notes 8.5.3
ibm lotus_domino 8.5.2.4
ibm lotus_domino 8.5.1.5
ibm lotus_notes 8.5.1.1
ibm lotus_notes 8.5.2.2
ibm lotus_notes 9.0.0.0
ibm lotus_notes 8.5.3.4
ibm lotus_domino 8.5.2.3
ibm lotus_notes 8.5.1
ibm lotus_notes 8.5.1.2
ibm lotus_notes 8.5.1.3
ibm lotus_domino 8.5.0.1
ibm lotus_notes 8.5.0.0
ibm lotus_domino 8.5.2.1
ibm lotus_notes 8.5.2.3
ibm lotus_notes 8.5.3.3
ibm lotus_notes 8.5.1.0
ibm lotus_notes 8.5.3.1
ibm lotus_notes 8.5
CVE-2014-0893 MEDIUM

Cross-site scripting (XSS) vulnerability in customreport.jsp in IBM Maximo Asset Management 7.5.x before 7.5.0.5 IFIX006 and SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified parameters.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management 7.5.0.1
ibm maximo_asset_management 7.5.0.0
ibm smartcloud_control_desk 7.5.0.0
ibm smartcloud_control_desk 7.5.1.1
ibm smartcloud_control_desk 7.5.0.5
ibm maximo_asset_management 7.5.0.4
ibm smartcloud_control_desk 7.5.0.2
ibm smartcloud_control_desk 7.5
ibm maximo_asset_management 7.5.0.5
ibm smartcloud_control_desk 7.5.0.1
ibm smartcloud_control_desk 7.5.1.0
ibm maximo_asset_management 7.5.0.3
ibm smartcloud_control_desk 7.0
ibm smartcloud_control_desk 7.5.0.3
CVE-2014-0894 LOW

RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allows context-dependent attackers to discover database credentials by reading the DbUser and DbPass fields in an XML document.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm algo_credit_limits 4.7.0
ibm algorithmics -
ibm algo_credit_limits 4.5.0
CVE-2014-0895 HIGH

Buffer overflow in the vsflex8l ActiveX control in IBM SPSS SamplePower 3.0.1 before FP1 3.0.1-IM-S3SAMPC-WIN32-FP001-IF02 allows remote attackers to execute arbitrary code via a crafted ComboList property value.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm spss_samplepower 3.0.1.0
CVE-2014-0896 MEDIUM

IBM WebSphere Application Server (WAS) Liberty Profile 8.5.x before 8.5.5.2 allows remote attackers to obtain sensitive information via a crafted request.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_application_server 8.5.5.0
ibm websphere_application_server 8.5.0.2
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 8.5.5.1
CVE-2014-0897 LOW

The Configuration Patterns component in IBM Flex System Manager (FSM) 1.2.0.x, 1.2.1.x, 1.3.0.x, and 1.3.1.x uses a weak algorithm in an encryption step during Chassis Management Module (CMM) account creation, which makes it easier for remote authenticated users to defeat cryptographic protection mechanisms via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm flex_system_manager 1.2.0
ibm flex_system_manager 1.3.0
ibm flex_system_manager 1.2.1
ibm flex_system_manager 1.3.1
CVE-2014-0899 MEDIUM

ftpd in IBM AIX 7.1.1 before SP10 and 7.1.2 before SP5, when a Workload Partition (aka WPAR) for AIX 5.2 or 5.3 is used, allows remote authenticated users to bypass intended permission settings and modify arbitrary files via FTP commands.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm aix 7.1.1
ibm aix 7.1.2
CVE-2014-0901 LOW

Cross-site scripting (XSS) vulnerability in the Social Rendering implementation in the IBM Connections integration in IBM WebSphere Portal 8.0.0.x before 8.0.0.1 CF11 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.1
ibm websphere_portal 8.0.0.0
CVE-2014-0904 HIGH

The update process in IBM Security AppScan Standard 7.9 through 8.8 does not require integrity checks of downloaded files, which allows remote attackers to execute arbitrary code via a crafted file.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm security_appscan 8.8
ibm security_appscan 8.6
ibm security_appscan 8.5
ibm security_appscan 8.0
ibm security_appscan 7.9
ibm security_appscan 8.7
CVE-2014-0905 LOW

IBM InfoSphere BigInsights 2.0 through 2.1.2 does not set the secure flag for the LTPA cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

CVSS 2.0

Severity: LOW

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm infosphere_biginsights 2.1.1.0
ibm infosphere_biginsights 2.0.0.0
ibm infosphere_biginsights 2.1.0.0
ibm infosphere_biginsights 2.1.2.0
CVE-2014-0906 MEDIUM

The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 does not check whether a session cookie is current, which allows remote attackers to conduct user-search actions by leveraging possession of a (1) expired or (2) invalidated cookie.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm sametime 8.5.0.0
ibm sametime 8.5.1.1
ibm sametime 8.5.2.0
ibm sametime 8.5.2.1
ibm sametime 9.0.0.0
ibm sametime 8.0.0.0
ibm sametime 8.0.1.1
ibm sametime 8.5.1.0
ibm sametime 8.0.2.0
ibm sametime 8.0.2.1
ibm sametime 8.0.1.0
CVE-2014-0907 HIGH

Multiple untrusted search path vulnerabilities in unspecified (1) setuid and (2) setgid programs in IBM DB2 9.5, 9.7 before FP9a, 9.8, 10.1 before FP3a, and 10.5 before FP3a on Linux and UNIX allow local users to gain root privileges via a Trojan horse library.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2 9.7.0.9
ibm db2 10.1.0.1
ibm db2 10.1.0.3
ibm db2 9.7.0.5
ibm db2 9.7.0.4
ibm db2 9.7.0.6
ibm db2 9.7.0.7
ibm db2 9.7
ibm db2 9.7.0.3
ibm db2 9.7.0.8
ibm db2 10.5.0.1
ibm db2 10.5.0.2
ibm db2 9.5
ibm db2 9.7.0.2
ibm db2 10.1
ibm db2 9.7.0.1
ibm db2 10.1.0.2
CVE-2014-0908 MEDIUM

The User Attribute implementation in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.2, and 8.5.x through 8.5.0.1 does not verify authorization for read or write access to attribute values, which allows remote authenticated users to obtain sensitive information, configure e-mail notifications, or modify task assignments via REST API calls.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm business_process_manager 8.0.1.2
ibm business_process_manager 8.0.1.1
ibm business_process_manager 8.0.1.0
ibm business_process_manager 7.5.0.1
ibm business_process_manager 7.5.1.2
ibm business_process_manager 8.0.0.0
ibm business_process_manager 8.5.0.1
ibm business_process_manager 8.5.0.0
ibm business_process_manager 7.5.1.0
ibm business_process_manager 7.5.1.1
ibm business_process_manager 7.5.0.0
CVE-2014-0909 MEDIUM

The Administration and Reporting Tool in IBM Rational License Key Server (RLKS) 8.1.4.x before 8.1.4.4 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_license_key_server 8.1.4
ibm rational_license_key_server 8.1.4.3
ibm rational_license_key_server 8.1.4.2
CVE-2014-0910 LOW

Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.0 through 6.1.0.6 CF27, 6.1.5.0 through 6.1.5.3 CF27, and 7.0.0 through 7.0.0.2 CF28 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 6.1.0.3
ibm websphere_portal 7.0.0.1
ibm websphere_portal 6.1.5.2
ibm websphere_portal 6.1.0.2
ibm websphere_portal 6.1.0.4
ibm websphere_portal 7.0.0.2
ibm websphere_portal 6.1.5.0
ibm websphere_portal 6.1.0.6
ibm websphere_portal 6.1.5.3
ibm websphere_portal 7.0.0.0
ibm websphere_portal 6.1.0.1
ibm websphere_portal 6.1.5.1
ibm websphere_portal 6.1.0.5
ibm websphere_portal 6.1.0.0
CVE-2014-0911 MEDIUM

inetd in IBM WebSphere MQ 7.1.x before 7.1.0.5 and 7.5.x before 7.5.0.4 allows remote attackers to cause a denial of service (disk or CPU consumption) via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_mq 7.5.0.2
ibm websphere_mq 7.1.0.3
ibm websphere_mq 7.1.0.1
ibm websphere_mq 7.5.0.1
ibm websphere_mq 7.5.0.3
ibm websphere_mq 7.1.0.4
ibm websphere_mq 7.1.0.2
ibm websphere_mq 7.5
ibm websphere_mq 7.1
CVE-2014-0912 MEDIUM

IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote attackers to obtain sensitive product information via vectors related to an error page. IBM X-Force ID: 92072.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2
ibm sterling_b2b_integrator 5.1
ibm sterling_file_gateway 2.2
ibm sterling_file_gateway 2.1
CVE-2014-0913 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM iNotes and Domino 8.5.3 FP6 before IF2 and 9.0.1 before FP1 allows remote attackers to inject arbitrary web script or HTML via an e-mail message, aka SPR BFEY9GXHZE.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm lotus_inotes 8.5.3.6
ibm lotus_domino 9.0.1.0
ibm lotus_inotes 9.0.1.0
ibm lotus_domino 8.5.3.6
CVE-2014-0914 LOW

Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 6.2.8 and 6.x and 7.x through 7.5.0.6, Maximo Asset Management 7.5 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk, and Maximo Asset Management 6.2 through 6.2.8 for Tivoli IT Asset Management for IT and Maximo Service Desk allows remote authenticated users to inject arbitrary web script or HTML via the Query Description Field.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm maximo_for_life_sciences 7.5.0.2
ibm maximo_for_life_sciences *
ibm maximo_for_government 7.1
ibm maximo_for_nuclear_power 7.5.0.4
ibm maximo_asset_management 6.2.3
ibm maximo_asset_management 7.1.1.1
ibm maximo_for_nuclear_power 7.5.0.0
ibm maximo_asset_management_essentials *
ibm maximo_for_nuclear_power 7.5.0.1
ibm maximo_for_life_sciences 7.5.0.4
ibm smartcloud_control_desk 7.5.1.2
ibm maximo_for_transportation 7.5.0.1
ibm maximo_for_nuclear_power 7.5.0.3
ibm maximo_for_government 7.5.0.1
ibm maximo_for_utilities 7.5.0.5
ibm maximo_asset_management_essentials 7.5.0.1
ibm maximo_asset_management_essentials 7.5.0.4
ibm maximo_asset_management 7.5.0.6
ibm maximo_for_transportation 7.5.0.2
ibm maximo_asset_management 7.1.1.7
ibm smartcloud_control_desk 7.5.1.1
ibm maximo_asset_management 6.2.2
ibm maximo_for_oil_and_gas 7.1
ibm maximo_for_nuclear_power *
ibm maximo_asset_management 7.1.1.5
ibm smartcloud_control_desk 7.5.1.0
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management 6.2.6
ibm maximo_for_utilities *
ibm maximo_asset_management 6.2.7
ibm maximo_asset_management 7.5.0.10
ibm maximo_asset_management 6.2.5
ibm maximo_for_life_sciences 7.5.0.0
ibm maximo_for_oil_and_gas 7.5.0.2
ibm maximo_for_oil_and_gas 7.5.0.3
ibm maximo_asset_management 7.1.1.12
ibm maximo_for_life_sciences 7.5.0.5
ibm maximo_asset_management 7.5.0.3
ibm maximo_for_oil_and_gas 7.5.0.1
ibm maximo_for_nuclear_power 7.5.0.2
ibm maximo_for_utilities 7.5.0.0
ibm maximo_for_life_sciences 7.5.0.3
ibm maximo_for_government 7.5.0.5
ibm maximo_for_transportation 7.1
ibm maximo_asset_management_essentials 7.1
ibm maximo_asset_management 7.5.0.4
ibm smartcloud_control_desk 7.5.0.1
ibm maximo_for_transportation 7.5.0.3
ibm maximo_asset_management 7.1.2
ibm maximo_for_utilities 7.5.0.1
ibm maximo_for_government 7.5.0.3
ibm smartcloud_control_desk 7.5.0.3
ibm maximo_asset_management 7.1.1.9
ibm maximo_for_government 7.5.0.4
ibm maximo_for_life_sciences 7.5.0.1
ibm maximo_asset_management 7.1.1.10
ibm maximo_asset_management_essentials 7.5.0.0
ibm maximo_for_oil_and_gas 7.5.0.5
ibm maximo_for_nuclear_power 7.1
ibm maximo_for_utilities 7.5.0.2
ibm maximo_for_life_sciences 7.1
ibm maximo_for_government *
ibm maximo_for_transportation 7.5.0.4
ibm maximo_service_desk *
ibm maximo_for_utilities 7.5.0.3
ibm smartcloud_control_desk 7.5.0.2
ibm maximo_asset_management 7.5.0.5
ibm maximo_asset_management 7.1.1.2
ibm smartcloud_control_desk *
ibm maximo_asset_management 7.1.1.11
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
ibm maximo_for_nuclear_power 7.5.0.5
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.5.0.1
ibm maximo_for_transportation 7.5.0.0
ibm maximo_for_oil_and_gas *
ibm maximo_asset_management_essentials 7.5.0.5
ibm maximo_asset_management 6.2.6.1
ibm maximo_for_utilities 7.1
ibm smartcloud_control_desk 7.5.0.0
ibm maximo_for_government 7.5.0.0
ibm tivoli_it_asset_management_for_it *
ibm maximo_asset_management 6.2.8
ibm maximo_asset_management_essentials 6.2.0.0
ibm maximo_asset_management 6.2.4
ibm maximo_asset_management_essentials 7.5.0.2
ibm maximo_for_government 7.5.0.2
ibm maximo_asset_management 6.2.1
ibm maximo_for_transportation 7.5.0.5
ibm maximo_asset_management 7.5.0.0
ibm maximo_for_transportation *
ibm maximo_asset_management 6.2
ibm maximo_for_oil_and_gas 7.5.0.4
ibm smartcloud_control_desk 7.5
ibm maximo_for_oil_and_gas 7.5.0.0
ibm maximo_asset_management 7.1.1.6
ibm maximo_asset_management_essentials 7.5.0.3
ibm maximo_for_utilities 7.5.0.4
CVE-2014-0915 LOW

Multiple cross-site scripting (XSS) vulnerabilities in IBM Maximo Asset Management 6.2 through 6.2.8, 6.x and 7.1 through 7.1.1.2, and 7.5 through 7.5.0.6; Maximo Asset Management 7.5 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk; and Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.2, and 7.2 for Tivoli Asset Management for IT and certain other products allow remote authenticated users to inject arbitrary web script or HTML via (1) the KPI display name field or (2) a portlet field.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm maximo_for_life_sciences 7.5.0.2
ibm maximo_for_life_sciences *
ibm maximo_for_government 7.1
ibm maximo_for_nuclear_power 7.5.0.4
ibm maximo_asset_management 6.2.3
ibm maximo_asset_management 7.1.1.1
ibm maximo_for_nuclear_power 7.5.0.0
ibm maximo_asset_management_essentials *
ibm maximo_for_nuclear_power 7.5.0.1
ibm maximo_for_life_sciences 7.5.0.4
ibm smartcloud_control_desk 7.5.1.2
ibm maximo_for_transportation 7.5.0.1
ibm maximo_for_nuclear_power 7.5.0.3
ibm maximo_for_government 7.5.0.1
ibm maximo_for_utilities 7.5.0.5
ibm maximo_asset_management_essentials 7.5.0.1
ibm maximo_asset_management_essentials 7.5.0.4
ibm maximo_asset_management 7.5.0.6
ibm maximo_for_transportation 7.5.0.2
ibm maximo_asset_management 7.1.1.7
ibm smartcloud_control_desk 7.5.1.1
ibm maximo_asset_management 6.2.2
ibm maximo_for_oil_and_gas 7.1
ibm maximo_for_nuclear_power *
ibm maximo_asset_management 7.1.1.5
ibm smartcloud_control_desk 7.5.1.0
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management 6.2.6
ibm maximo_for_utilities *
ibm maximo_asset_management 6.2.7
ibm maximo_asset_management 7.5.0.10
ibm maximo_asset_management 6.2.5
ibm maximo_for_life_sciences 7.5.0.0
ibm maximo_for_oil_and_gas 7.5.0.2
ibm maximo_for_oil_and_gas 7.5.0.3
ibm maximo_asset_management 7.1.1.12
ibm maximo_for_life_sciences 7.5.0.5
ibm maximo_asset_management 7.5.0.3
ibm maximo_for_oil_and_gas 7.5.0.1
ibm maximo_for_nuclear_power 7.5.0.2
ibm maximo_for_utilities 7.5.0.0
ibm maximo_for_life_sciences 7.5.0.3
ibm maximo_for_government 7.5.0.5
ibm maximo_for_transportation 7.1
ibm maximo_asset_management_essentials 7.1
ibm maximo_asset_management 7.5.0.4
ibm smartcloud_control_desk 7.5.0.1
ibm maximo_for_transportation 7.5.0.3
ibm maximo_asset_management 7.1.2
ibm maximo_for_utilities 7.5.0.1
ibm maximo_for_government 7.5.0.3
ibm smartcloud_control_desk 7.5.0.3
ibm maximo_asset_management 7.1.1.9
ibm maximo_for_government 7.5.0.4
ibm maximo_for_life_sciences 7.5.0.1
ibm maximo_asset_management 7.1.1.10
ibm maximo_asset_management_essentials 7.5.0.0
ibm maximo_for_oil_and_gas 7.5.0.5
ibm maximo_for_nuclear_power 7.1
ibm maximo_for_utilities 7.5.0.2
ibm maximo_for_life_sciences 7.1
ibm maximo_for_government *
ibm maximo_for_transportation 7.5.0.4
ibm maximo_service_desk *
ibm maximo_for_utilities 7.5.0.3
ibm smartcloud_control_desk 7.5.0.2
ibm maximo_asset_management 7.5.0.5
ibm maximo_asset_management 7.1.1.2
ibm smartcloud_control_desk *
ibm maximo_asset_management 7.1.1.11
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
ibm maximo_for_nuclear_power 7.5.0.5
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.5.0.1
ibm maximo_for_transportation 7.5.0.0
ibm maximo_for_oil_and_gas *
ibm maximo_asset_management_essentials 7.5.0.5
ibm maximo_asset_management 6.2.6.1
ibm maximo_for_utilities 7.1
ibm smartcloud_control_desk 7.5.0.0
ibm maximo_for_government 7.5.0.0
ibm tivoli_it_asset_management_for_it *
ibm maximo_asset_management 6.2.8
ibm maximo_asset_management_essentials 6.2.0.0
ibm maximo_asset_management 6.2.4
ibm maximo_asset_management_essentials 7.5.0.2
ibm maximo_for_government 7.5.0.2
ibm maximo_asset_management 6.2.1
ibm maximo_for_transportation 7.5.0.5
ibm maximo_asset_management 7.5.0.0
ibm maximo_for_transportation *
ibm maximo_asset_management 6.2
ibm maximo_for_oil_and_gas 7.5.0.4
ibm smartcloud_control_desk 7.5
ibm maximo_for_oil_and_gas 7.5.0.0
ibm maximo_asset_management 7.1.1.6
ibm maximo_asset_management_essentials 7.5.0.3
ibm maximo_for_utilities 7.5.0.4
CVE-2014-0917 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Eclipse Help System (IEHS) in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF27, and 8.0 before 8.0.0.1 CF06 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.0
ibm websphere_portal 6.1.0.3
ibm websphere_portal 7.0.0.1
ibm websphere_portal 6.1.5.2
ibm websphere_portal 6.1.0.2
ibm websphere_portal 6.1.0.4
ibm websphere_portal 8.0.0.1
ibm websphere_portal 7.0.0.2
ibm websphere_portal 6.1.5.0
ibm websphere_portal 6.1.0.6
ibm websphere_portal 6.1.5.3
ibm websphere_portal 7.0.0.0
ibm websphere_portal 6.1.0.1
ibm websphere_portal 6.1.5.1
ibm websphere_portal 6.1.0.5
ibm websphere_portal 6.1.0.0
CVE-2014-0918 HIGH

Directory traversal vulnerability in IBM Eclipse Help System (IEHS) in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF27, and 8.0 before 8.0.0.1 CF06 allows remote attackers to read arbitrary files via a crafted URL.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.0
ibm websphere_portal 6.1.0.3
ibm websphere_portal 7.0.0.1
ibm websphere_portal 6.1.5.2
ibm websphere_portal 6.1.0.2
ibm websphere_portal 6.1.0.4
ibm websphere_portal 8.0.0.1
ibm websphere_portal 7.0.0.2
ibm websphere_portal 6.1.5.0
ibm websphere_portal 6.1.0.6
ibm websphere_portal 6.1.5.3
ibm websphere_portal 7.0.0.0
ibm websphere_portal 6.1.0.1
ibm websphere_portal 6.1.5.1
ibm websphere_portal 6.1.0.5
ibm websphere_portal 6.1.0.0
CVE-2014-0919 MEDIUM

IBM DB2 9.5 through 10.5 on Linux, UNIX, and Windows stores passwords during the processing of certain SQL statements by the monitoring and audit facilities, which allows remote authenticated users to obtain sensitive information via commands associated with these facilities.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2 9.5
ibm db2 10.1
ibm db2 9.8
ibm db2 9.7
CVE-2014-0920 MEDIUM

IBM SPSS Analytic Server 1.0 before IF002 and 1.0.1 before IF004 logs cleartext passwords, which allows remote authenticated users to obtain sensitive information via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm spss_analytic_server 1.0.1.0
ibm spss_analytic_server 1.0.0.0
CVE-2014-0921 MEDIUM

The server in IBM MessageSight 1.x before 1.1.0.0-IBM-IMA-IT01015 allows remote attackers to cause a denial of service (daemon crash and message data loss) via malformed headers during a WebSockets connection upgrade.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm messagesight -
ibm messagesight_jms_client 1.0.0.0
ibm messagesight_jms_client 1.1.0.0
ibm messagesight_jms_client 1.0.0.1
CVE-2014-0922 MEDIUM

IBM MessageSight 1.x before 1.1.0.0-IBM-IMA-IT01015 allows remote attackers to cause a denial of service (resource consumption) via WebSockets MQ Telemetry Transport (MQTT) data.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm messagesight -
ibm messagesight_jms_client 1.0.0.0
ibm messagesight_jms_client 1.1.0.0
ibm messagesight_jms_client 1.0.0.1
CVE-2014-0923 MEDIUM

IBM MessageSight 1.x before 1.1.0.0-IBM-IMA-IT01015 allows remote attackers to cause a denial of service (daemon restart) via crafted MQ Telemetry Transport (MQTT) authentication data.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm messagesight -
ibm messagesight_jms_client 1.0.0.0
ibm messagesight_jms_client 1.1.0.0
ibm messagesight_jms_client 1.0.0.1
CVE-2014-0924 MEDIUM

IBM MessageSight 1.x before 1.1.0.0-IBM-IMA-IT01015 does not verify that all of the characters of a password are correct, which makes it easier for remote authenticated users to bypass intended access restrictions by leveraging knowledge of a password substring.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm messagesight -
ibm messagesight_jms_client 1.0.0.0
ibm messagesight_jms_client 1.1.0.0
ibm messagesight_jms_client 1.0.0.1
CVE-2014-0925 LOW

Open redirect vulnerability in IBM Sterling Control Center 5.4.0 before 5.4.0.1 iFix 3 and 5.4.1 before 5.4.1.0 iFix 2 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm sterling_control_center 5.4.0.1
ibm sterling_control_center 5.4.1.0
ibm sterling_control_center 5.4.0
CVE-2014-0927 MEDIUM

The ActiveMQ admin user interface in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allows remote attackers to bypass authentication by leveraging knowledge of the port number and webapp path. IBM X-Force ID: 92259.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2
ibm sterling_b2b_integrator 5.1
ibm sterling_file_gateway 2.2
ibm sterling_file_gateway 2.1
CVE-2014-0929 MEDIUM

Cross-site request forgery (CSRF) vulnerability in the Profiles component in IBM Connections through 3.0.1.1 CR3 allows remote authenticated users to hijack the authentication of arbitrary users for requests that trigger follow actions.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm connections 1.0.2.0
ibm connections 2.0.0.0
ibm connections 2.0.1.0
ibm connections 3.0.0.0
ibm connections 2.5.0.1
ibm connections 1.0.0.0
ibm connections 2.0.1.1
ibm connections *
ibm connections 1.0.1.0
ibm connections 2.5.0.0
ibm connections 2.5.0.3
ibm connections 3.0.1.0
ibm connections 2.5.0.2
CVE-2014-0930 MEDIUM

The ptrace system call in IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.2.x, allows local users to cause a denial of service (system crash) or obtain sensitive information from kernel memory via a crafted PT_LDINFO operation.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm aix 6.1
ibm vios 2.2.0.10
ibm vios 2.2.1.1
ibm vios 2.2.1.4
ibm aix 7.1
ibm vios 2.2.0.12
ibm vios 2.2.0.13
ibm vios 2.2.1.3
ibm aix 5.3
ibm vios 2.2.3.0
ibm vios 2.2.2.0
ibm vios 2.2.0.11
ibm vios 2.2.1.0
CVE-2014-0931 MEDIUM

Multiple XML external entity (XXE) vulnerabilities in the (1) CCRC WAN Server / CM Server, (2) Perl CC/CQ integration trigger scripts, (3) CMAPI Java interface, (4) ClearCase remote client, and (5) CMI and OSLC-based ClearQuest integrations components in IBM Rational ClearCase 7.1.0.x, 7.1.1.x, 7.1.2 through 7.1.2.13, 8.0 through 8.0.0.10, and 8.0.1 through 8.0.1.3 allow remote attackers to cause a denial of service or access other servers via crafted XML data. IBM X-Force ID: 92263.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm rational_clearcase *
CVE-2014-0932 LOW

Cross-site scripting (XSS) vulnerability in IBM Sterling Order Management 8.5 before HF105 and Sterling Selling and Fulfillment Foundation 9.0 before HF85 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm sterling_order_management 8.5
ibm sterling_selling_and_fulfillment_foundation 9.0
CVE-2014-0933 MEDIUM

Cross-site request forgery (CSRF) vulnerability in IBM InfoSphere Information Server Metadata Workbench 8.1 through 9.1 allows remote attackers to hijack the authentication of arbitrary users.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm infosphere_information_server_metadata_workbench 8.7.0
ibm infosphere_information_server_metadata_workbench 8.1.1
ibm infosphere_information_server_metadata_workbench 9.1.0.1
ibm infosphere_information_server_metadata_workbench 8.5.0.3
ibm infosphere_information_server_metadata_workbench 8.5.0
ibm infosphere_information_server_metadata_workbench 8.7.0.1
ibm infosphere_information_server_metadata_workbench 8.1.0
ibm infosphere_information_server_metadata_workbench 8.5.0.2
ibm infosphere_information_server_metadata_workbench 8.1.0.2
ibm infosphere_information_server_metadata_workbench 8.1.0.1
ibm infosphere_information_server_metadata_workbench 8.7.0.2
ibm infosphere_information_server_metadata_workbench 9.1.0
ibm infosphere_information_server_metadata_workbench 8.5.0.1
CVE-2014-0935 MEDIUM

Unspecified vulnerability in IBM Smart Analytics System 7700 before FP 2.1.3.0 and 7710 before FP 2.1.3.0 allows local users to gain privileges via vectors related to events.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm smart_analytics_system_7700 2.0.2.0
ibm smart_analytics_system_7710 2.0.3.0
ibm smart_analytics_system_7700 1.3.0.1
ibm smart_analytics_system_7700 *
ibm smart_analytics_system_7710 1.2.0
ibm smart_analytics_system_7710 1.2.0.100
ibm smart_analytics_system_7700 2.0.4.0
ibm smart_analytics_system_7700 1.2.2.0
ibm smart_analytics_system_7700 2.0.1.0
ibm smart_analytics_system_7700 1.3.0.0
ibm smart_analytics_system_7710 2.0.0.100
ibm smart_analytics_system_7710 2.0.2.0
ibm smart_analytics_system_7700 2.0.0
ibm smart_analytics_system_7710 1.3.0.1
ibm smart_analytics_system_7710 2.0.1.0
ibm smart_analytics_system_7700 2.1.1.0
ibm smart_analytics_system_7700 2.0.0.100
ibm smart_analytics_system_7710 2.0.4.0
ibm smart_analytics_system_7700 2.0.3.0
ibm smart_analytics_system_7700 1.2.4.0
ibm smart_analytics_system_7700 1.2.0.100
ibm smart_analytics_system_7710 1.2.2.0
ibm smart_analytics_system_7710 2.0.0
ibm smart_analytics_system_7710 2.1.1.0
ibm smart_analytics_system_7710 1.2.4.0
ibm smart_analytics_system_7700 1.2.1.0
ibm smart_analytics_system_7710 1.3.0.0
ibm smart_analytics_system_7710 1.2.1.0
ibm smart_analytics_system_7700 1.2.0
ibm smart_analytics_system_7710 *
CVE-2014-0936 MEDIUM

IBM Security AppScan Source 8.0 through 9.0, when the publish-assessment permission is not properly restricted for the configured database server, transmits cleartext assessment data, which allows remote attackers to obtain sensitive information by sniffing the network.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,CWE-310,

Products Affected

Vendor Product Version
ibm security_appscan_source 8.6
ibm security_appscan_source 8.7
ibm security_appscan_source 8.5
ibm security_appscan_source 9.0
ibm security_appscan_source 8.0
ibm security_appscan_source 8.8
CVE-2014-0940 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in IBM Tivoli Service Automation Manager 7.2.2.2 before 7.2.2.2-TIV-TSAM-LA0041 allow remote attackers to inject arbitrary web script or HTML via vectors involving the (1) REST API or (2) Self Service UI.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_service_automation_manager 7.2.2.2
CVE-2014-0941 LOW

Cross-site scripting (XSS) vulnerability in webtop/eventviewer/eventViewer.jsp in the Web GUI in IBM Netcool/OMNIbus 7.4.0 before FP2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2014-0942.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_netcool/omnibus 7.4.0
CVE-2014-0942 LOW

Cross-site scripting (XSS) vulnerability in webtop/eventviewer/eventViewer.jsp in the Web GUI in IBM Netcool/OMNIbus 7.4.0 before FP2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2014-0941.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_netcool/omnibus 7.4.0
CVE-2014-0943 HIGH

IBM WebSphere Commerce 6.0 Feature Pack 2 through Feature Pack 5, 7.0.0.0 through 7.0.0.8, and 7.0 Feature Pack 1 through Feature Pack 7 allows remote attackers to cause a denial of service (resource consumption and daemon crash) via a malformed id parameter in a request.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm websphere_commerce 6.0.0.0
ibm websphere_commerce 7.0.0.4
ibm websphere_commerce 7.0.0.6
ibm websphere_commerce 7.0.0.7
ibm websphere_commerce 7.0.0.3
ibm websphere_commerce 7.0.0.2
ibm websphere_commerce 7.0
ibm websphere_commerce 7.0.0.1
ibm websphere_commerce 7.0.0.5
ibm websphere_commerce 7.0.0.8
CVE-2014-0944 MEDIUM

Cross-site request forgery (CSRF) vulnerability in the RES Console in Rule Execution Server in IBM Operational Decision Manager 7.5 before FP3 IF37, 8.0 before MP1 FP2, and 8.5 before MP1 IF26 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm operational_decision_manager 8.0
ibm operational_decision_manager 8.5
ibm operational_decision_manager 7.5
CVE-2014-0945 LOW

Cross-site scripting (XSS) vulnerability in the RES Console in Rule Execution Server in IBM Operational Decision Manager 7.5 before FP3 IF37, 8.0 before MP1 FP2, and 8.5 before MP1 IF26 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm operational_decision_manager 8.0
ibm operational_decision_manager 8.5
ibm operational_decision_manager 7.5
CVE-2014-0946 MEDIUM

The RES Console in Rule Execution Server in IBM Operational Decision Manager 7.5 before FP3 IF37, 8.0 before MP1 FP2, and 8.5 before MP1 IF26 does not send appropriate Cache-Control HTTP headers, which allows remote attackers to obtain sensitive information by leveraging an unattended workstation.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm operational_decision_manager 8.0
ibm operational_decision_manager 8.5
ibm operational_decision_manager 7.5
CVE-2014-0947 MEDIUM

Unspecified vulnerability in the server in IBM Rational Software Architect Design Manager 4.0.6 allows remote authenticated users to execute arbitrary code via a crafted update site.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm rational_software_architect_design_manager 4.0.6
CVE-2014-0948 MEDIUM

Unspecified vulnerability in IBM Rational Software Architect Design Manager and Rational Rhapsody Design Manager 3.x and 4.x before 4.0.7 allows remote authenticated users to execute arbitrary code via a crafted ZIP archive.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm rational_software_architect_design_manager 3.0.0.1
ibm rhapsody_design_manager 4.0.3
ibm rhapsody_design_manager 3.0.1
ibm rational_software_architect_design_manager 3.0.1
ibm rhapsody_design_manager 3.0.0
ibm rhapsody_design_manager 4.0.1
ibm rational_software_architect_design_manager 4.0.2
ibm rational_software_architect_design_manager 4.0.3
ibm rhapsody_design_manager 4.0.6
ibm rational_software_architect_design_manager 3.0.0
ibm rational_software_architect_design_manager 4.0.0
ibm rational_software_architect_design_manager 4.0.5
ibm rhapsody_design_manager 4.0.2
ibm rhapsody_design_manager 4.0.4
ibm rational_software_architect_design_manager 4.0.6
ibm rhapsody_design_manager 3.0.0.1
ibm rhapsody_design_manager 4.0.0
ibm rhapsody_design_manager 4.0.5
ibm rational_software_architect_design_manager 4.0.1
ibm rational_software_architect_design_manager 4.0.4
CVE-2014-0949 MEDIUM

IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, and 8.0 before 8.0.0.1 CF12 allows remote attackers to cause a denial of service (resource consumption and daemon crash) via a crafted web request.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.0
ibm websphere_portal 6.1.0.3
ibm websphere_portal 7.0.0.1
ibm websphere_portal 6.1.5.2
ibm websphere_portal 6.1.0.2
ibm websphere_portal 6.1.0.4
ibm websphere_portal 8.0.0.1
ibm websphere_portal 7.0.0.2
ibm websphere_portal 6.1.5.0
ibm websphere_portal 6.1.0.6
ibm websphere_portal 6.1.5.3
ibm websphere_portal 7.0.0.0
ibm websphere_portal 6.1.0.1
ibm websphere_portal 6.1.5.1
ibm websphere_portal 6.1.0.5
ibm websphere_portal 6.1.0.0
CVE-2014-0950 MEDIUM

Multiple XML external entity (XXE) vulnerabilities in (1) CQWeb / CM Server, (2) ClearQuest Native client, (3) ClearQuest Eclipse client, and (4) ClearQuest Eclipse Designer components in IBM Rational ClearQuest 7.1.1 through 7.1.1.9, 7.1.2 through 7.1.2.13, 8.0.0 through 8.0.0.10, and 8.0.1 through 8.0.1.3 allow remote attackers to cause a denial of service or access other servers via crafted XML data. IBM X-Force ID: 92623.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm rational_clearquest *
CVE-2014-0951 MEDIUM

Cross-site scripting (XSS) vulnerability in FilterForm.jsp in IBM WebSphere Portal 7.0 before 7.0.0.2 CF28 and 8.0 before 8.0.0.1 CF12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.1
ibm websphere_portal 8.0.0.0
ibm websphere_portal 7.0.0.2
ibm websphere_portal 7.0.0.1
ibm websphere_portal 6.1.0.6
ibm websphere_portal 6.1.5.3
ibm websphere_portal 7.0.0.0
CVE-2014-0952 MEDIUM

Cross-site scripting (XSS) vulnerability in boot_config.jsp in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF28, 7.0 through 7.0.0.2 CF28, and 8.0 before 8.0.0.1 CF12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.0
ibm websphere_portal 6.1.0.3
ibm websphere_portal 7.0.0.1
ibm websphere_portal 6.1.5.2
ibm websphere_portal 6.1.0.2
ibm websphere_portal 6.1.0.4
ibm websphere_portal 8.0.0.1
ibm websphere_portal 7.0.0.2
ibm websphere_portal 6.1.5.0
ibm websphere_portal 6.1.0.6
ibm websphere_portal 6.1.5.3
ibm websphere_portal 7.0.0.0
ibm websphere_portal 6.1.0.1
ibm websphere_portal 6.1.5.1
ibm websphere_portal 6.1.0.5
ibm websphere_portal 6.1.0.0
CVE-2014-0953 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.0 through 6.1.0.6 CF27, 6.1.5.0 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF28, and 8.0.0 before 8.0.0.1 CF12 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.0
ibm websphere_portal 6.1.0.3
ibm websphere_portal 7.0.0.1
ibm websphere_portal 6.1.5.2
ibm websphere_portal 6.1.0.2
ibm websphere_portal 6.1.0.4
ibm websphere_portal 7.0.0.2
ibm websphere_portal 6.1.5.0
ibm websphere_portal 6.1.0.6
ibm websphere_portal 6.1.5.3
ibm websphere_portal 7.0.0.0
ibm websphere_portal 6.1.0.1
ibm websphere_portal 6.1.5.1
ibm websphere_portal 6.1.0.5
ibm websphere_portal 6.1.0.0
CVE-2014-0954 MEDIUM

IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, and 8.0 before 8.0.0.1 CF12 does not validate JSP includes, which allows remote attackers to obtain sensitive information, bypass intended request-dispatcher access restrictions, or cause a denial of service (memory consumption) via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.0
ibm websphere_portal 6.1.0.3
ibm websphere_portal 7.0.0.1
ibm websphere_portal 6.1.5.2
ibm websphere_portal 6.1.0.2
ibm websphere_portal 6.1.0.4
ibm websphere_portal 8.0.0.1
ibm websphere_portal 7.0.0.2
ibm websphere_portal 6.1.5.0
ibm websphere_portal 6.1.0.6
ibm websphere_portal 6.1.5.3
ibm websphere_portal 7.0.0.0
ibm websphere_portal 6.1.0.1
ibm websphere_portal 6.1.5.1
ibm websphere_portal 6.1.0.5
ibm websphere_portal 6.1.0.0
CVE-2014-0955 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0 before 8.0.0.1 CF12, when Social Rendering in Connections integration is enabled, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.1
ibm websphere_portal 8.0.0.0
CVE-2014-0956 MEDIUM

Cross-site scripting (XSS) vulnerability in googlemap.jsp in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, and 8.0 before 8.0.0.1 CF12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.0
ibm websphere_portal 6.1.0.3
ibm websphere_portal 7.0.0.1
ibm websphere_portal 6.1.5.2
ibm websphere_portal 6.1.0.2
ibm websphere_portal 6.1.0.4
ibm websphere_portal 8.0.0.1
ibm websphere_portal 7.0.0.2
ibm websphere_portal 6.1.5.0
ibm websphere_portal 6.1.0.6
ibm websphere_portal 6.1.5.3
ibm websphere_portal 7.0.0.0
ibm websphere_portal 6.1.0.1
ibm websphere_portal 6.1.5.1
ibm websphere_portal 6.1.0.5
ibm websphere_portal 6.1.0.0
CVE-2014-0957 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Business Process Manager 7.5 through 8.5.5, and WebSphere Lombardi Edition 7.2, allows remote attackers to inject arbitrary web script or HTML via a crafted URL that triggers a service failure.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm business_process_manager 8.0.1.2
ibm business_process_manager 8.0.1.1
ibm business_process_manager 7.5.0.1
ibm websphere_application_server 7.2
ibm business_process_manager 7.5.1.0
ibm business_process_manager 7.5.1.1
ibm business_process_manager 8.5.5.0
ibm business_process_manager 8.0.1.0
ibm business_process_manager 7.5.1.2
ibm business_process_manager 8.0.0.0
ibm business_process_manager 8.5.0.1
ibm business_process_manager 8.5.0.0
ibm business_process_manager 7.5.0.0
CVE-2014-0958 MEDIUM

Open redirect vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, and 8.0 before 8.0.0.1 CF12 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.0
ibm websphere_portal 6.1.0.3
ibm websphere_portal 7.0.0.1
ibm websphere_portal 6.1.5.2
ibm websphere_portal 6.1.0.2
ibm websphere_portal 6.1.0.4
ibm websphere_portal 8.0.0.1
ibm websphere_portal 7.0.0.2
ibm websphere_portal 6.1.5.0
ibm websphere_portal 6.1.0.6
ibm websphere_portal 6.1.5.3
ibm websphere_portal 7.0.0.0
ibm websphere_portal 6.1.0.1
ibm websphere_portal 6.1.5.1
ibm websphere_portal 6.1.0.5
ibm websphere_portal 6.1.0.0
CVE-2014-0959 MEDIUM

IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, and 8.0 before 8.0.0.1 CF12 allows remote authenticated users to cause a denial of service (infinite loop) via a login redirect.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.0
ibm websphere_portal 6.1.0.3
ibm websphere_portal 7.0.0.1
ibm websphere_portal 6.1.5.2
ibm websphere_portal 6.1.0.2
ibm websphere_portal 6.1.0.4
ibm websphere_portal 8.0.0.1
ibm websphere_portal 7.0.0.2
ibm websphere_portal 6.1.5.0
ibm websphere_portal 6.1.0.6
ibm websphere_portal 6.1.5.3
ibm websphere_portal 7.0.0.0
ibm websphere_portal 6.1.0.1
ibm websphere_portal 6.1.5.1
ibm websphere_portal 6.1.0.5
ibm websphere_portal 6.1.0.0
CVE-2014-0960 MEDIUM

IBM PureApplication System 1.0 before 1.0.0.4 cfix8 and 1.1 before 1.1.0.4 IF1 allows remote authenticated users to bypass intended access restrictions by establishing an SSH session from a deployed virtual machine.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm pureapplication_system 1.1.0.2
ibm pureapplication_system 1.0.0.0
ibm pureapplication_system 1.1.0.3
ibm pureapplication_system 1.0.0.1
ibm pureapplication_system 1.0.0.4
ibm pureapplication_system 1.1.0.0
ibm pureapplication_system 1.1.0.4
ibm pureapplication_system 1.0.0.2
ibm pureapplication_system 1.0.0.3
ibm pureapplication_system 1.1.0.1
CVE-2014-0961 MEDIUM

Cross-site request forgery (CSRF) vulnerability in IBM Tivoli Identity Manager (ITIM) 5.0 before 5.0.0.15 and 5.1 before 5.1.0.15 and IBM Security Identity Manager (ISIM) 6.0 before 6.0.0.2 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm tivoli_identity_manager 5.1.0.5
ibm tivoli_identity_manager 5.0.0.11
ibm tivoli_identity_manager 5.1.0.11
ibm tivoli_identity_manager 5.1.0.6
ibm security_identity_manager 6.0.0
ibm tivoli_identity_manager 5.0.0.12
ibm tivoli_identity_manager 5.1.0
ibm tivoli_identity_manager 5.1.0.12
ibm security_identity_manager 6.0.0.1
ibm tivoli_identity_manager 5.1.0.10
ibm tivoli_identity_manager 5.1.0.9
ibm tivoli_identity_manager 5.1.0.3
ibm tivoli_identity_manager 5.0.0.6
ibm tivoli_identity_manager 5.1.0.8
ibm tivoli_identity_manager 5.1.0.13
ibm tivoli_identity_manager 5.0.0.10
ibm tivoli_identity_manager 5.0.0.13
ibm tivoli_identity_manager 5.1.0.14
ibm tivoli_identity_manager 5.1.0.7
ibm tivoli_identity_manager 5.0.0
ibm tivoli_identity_manager 5.1.0.4
ibm tivoli_identity_manager 5.0.0.14
CVE-2014-0963 HIGH

The Reverse Proxy feature in IBM Global Security Kit (aka GSKit) in IBM Security Access Manager (ISAM) for Web 7.0 before 7.0.0-ISS-SAM-IF0006 and 8.0 before 8.0.0.3-ISS-WGA-IF0002 allows remote attackers to cause a denial of service (infinite loop) via crafted SSL messages.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm security_access_manager_for_web_appliance 7.0
ibm security_access_manager_for_web_software 7.0
ibm security_access_manager_for_web_software 8.0
ibm security_access_manager_for_web_appliance 8.0
CVE-2014-0964 HIGH

IBM WebSphere Application Server (WAS) 6.1.0.0 through 6.1.0.47 and 6.0.2.0 through 6.0.2.43 allows remote attackers to cause a denial of service via crafted TLS traffic, as demonstrated by traffic from a CVE-2014-0160 vulnerability-assessment tool.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 6.0.2.19
ibm websphere_application_server 6.1.0.14
ibm websphere_application_server 6.0.2.7
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0.35
ibm websphere_application_server 6.0.2.39
ibm websphere_application_server 6.0.2.33
ibm websphere_application_server 6.0.2.25
ibm websphere_application_server 6.0.2.31
ibm websphere_application_server 6.0.2.9
ibm websphere_application_server 6.1.0.39
ibm websphere_application_server 6.1.0.37
ibm websphere_application_server 6.0.2.35
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 6.0.2.22
ibm websphere_application_server 6.0.2.41
ibm websphere_application_server 6.1.0.47
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 6.0.2.43
ibm websphere_application_server 6.0.2.2
ibm websphere_application_server 6.0.2.13
ibm websphere_application_server 6.0.2.11
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 6.1.0.45
ibm websphere_application_server 6.0.2.15
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 6.0.2.4
ibm websphere_application_server 6.0.2.30
ibm websphere_application_server 6.0.2.32
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.41
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.0.2.23
ibm websphere_application_server 6.0.2.6
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.0.2.17
ibm websphere_application_server 6.0.2.37
ibm websphere_application_server 6.0.2.24
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 6.1.0.43
ibm websphere_application_server 6.0.2.5
ibm websphere_application_server 6.0.2.3
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.0.2.29
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.0.2
ibm websphere_application_server 6.0.2.28
ibm websphere_application_server 6.0.2.27
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.0.2.1
CVE-2014-0965 MEDIUM

IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.33, 8.0.x before 8.0.0.9, and 8.5.x before 8.5.5.3 allows remote attackers to obtain sensitive information via a crafted SOAP response.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 7.0
ibm websphere_application_server 8.0.0.5
ibm websphere_application_server 7.0.0.12
ibm websphere_application_server 8.5.0.2
ibm websphere_application_server 8.0.0.6
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 8.5.5.2
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 7.0.0.16
ibm websphere_application_server 7.0.0.25
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 7.0.0.14
ibm websphere_application_server 7.0.0.22
ibm websphere_application_server 7.0.0.31
ibm websphere_application_server 7.0.0.10
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 8.0.0.8
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0.0.29
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 7.0.0.24
ibm websphere_application_server 8.5.5.0
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 8.0.0.7
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 7.0.0.27
ibm websphere_application_server 7.0.0.18
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 8.5.5.1
ibm websphere_application_server 8.0.0.2
CVE-2014-0966 MEDIUM

SQL injection vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0-FP5 and InfoSphere Master Data Management Server for Product Information Management 9.x through 11.x before 11.3-IF2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm infosphere_master_data_management_server_for_product_information_management 10.1.0.1
ibm infosphere_master_data_management_server_for_product_information_management 10.1
ibm infosphere_master_data_management_server_for_product_information_management 10.0
ibm infosphere_master_data_management_server_for_product_information_management 9.1
ibm infosphere_master_data_management_server_for_product_information_management 9.0
ibm infosphere_master_data_management_server_for_product_information_management 10.0.0.1
ibm infosphere_master_data_management_server_for_product_information_management 10.0.1
ibm infosphere_master_data_management_server_for_product_information_management 10.1.0.2
ibm infosphere_master_data_management 10.0
ibm infosphere_master_data_management_server_for_product_information_management 11.0
ibm infosphere_master_data_management 11.0
ibm infosphere_master_data_management_server_for_product_information_management 11.3
ibm infosphere_master_data_management 10.1
ibm infosphere_master_data_management 11.3
CVE-2014-0967 LOW

Cross-site scripting (XSS) vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0 FP4 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm infosphere_master_data_management_collaboration_server 10.0
ibm infosphere_master_data_management_server_for_product_information_management 9.1
ibm infosphere_master_data_management_collaboration_server 10.1
ibm infosphere_master_data_management_server_for_product_information_management 9.0
ibm infosphere_master_data_management_collaboration_server 11.0
CVE-2014-0968 LOW

Cross-site scripting (XSS) vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0 FP4 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL for an MHTML document.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm infosphere_master_data_management_collaboration_server 10.0
ibm infosphere_master_data_management_server_for_product_information_management 9.1
ibm infosphere_master_data_management_collaboration_server 10.1
ibm infosphere_master_data_management_server_for_product_information_management 9.0
ibm infosphere_master_data_management_collaboration_server 11.0
CVE-2014-0969 MEDIUM

Cross-site request forgery (CSRF) vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0-FP5 and InfoSphere Master Data Management Server for Product Information Management 9.x through 11.x before 11.3-IF2 allows remote authenticated users to hijack the authentication of arbitrary users.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm infosphere_master_data_management_server_for_product_information_management 10.1.0.1
ibm infosphere_master_data_management_server_for_product_information_management 10.1
ibm infosphere_master_data_management_server_for_product_information_management 10.0
ibm infosphere_master_data_management_server_for_product_information_management 9.1
ibm infosphere_master_data_management_server_for_product_information_management 9.0
ibm infosphere_master_data_management_server_for_product_information_management 10.0.0.1
ibm infosphere_master_data_management_server_for_product_information_management 10.0.1
ibm infosphere_master_data_management_server_for_product_information_management 10.1.0.2
ibm infosphere_master_data_management 10.0
ibm infosphere_master_data_management_server_for_product_information_management 11.0
ibm infosphere_master_data_management 11.0
ibm infosphere_master_data_management_server_for_product_information_management 11.3
ibm infosphere_master_data_management 10.1
ibm infosphere_master_data_management 11.3
CVE-2014-0970 LOW

The GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0 FP4 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 allows remote authenticated users to inject links via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm infosphere_master_data_management_collaboration_server 10.0
ibm infosphere_master_data_management_server_for_product_information_management 9.1
ibm infosphere_master_data_management_collaboration_server 10.1
ibm infosphere_master_data_management_server_for_product_information_management 9.0
ibm infosphere_master_data_management_collaboration_server 11.0
CVE-2014-2398 LOW

Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JavaFX 2.2.51; and JRockit R27.8.1 and R28.3.1 allows remote authenticated users to affect integrity via unknown vectors related to Javadoc.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
debian debian_linux 8.0
oracle jre 1.7.0
oracle jdk 1.8.0
oracle jdk 1.7.0
oracle jre 1.5.0
canonical ubuntu_linux 13.10
canonical ubuntu_linux 12.04
oracle jdk 1.6.0
oracle jdk 1.5.0
canonical ubuntu_linux 12.10
oracle jre 1.8.0
debian debian_linux 7.0
oracle jrockit r27.8.1
canonical ubuntu_linux 14.04
ibm forms_viewer *
canonical ubuntu_linux 10.04
oracle jrockit r28.3.1
oracle jre 1.6.0
debian debian_linux 6.0
oracle javafx 2.2.51
CVE-2014-2401 MEDIUM

Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JavaFX 2.2.51; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality via unknown vectors related to 2D.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
oracle jre 1.7.0
ibm forms_viewer *
oracle jdk 1.8.0
oracle jdk 1.7.0
oracle jre 1.5.0
oracle jre 1.6.0
oracle jdk 1.6.0
oracle jdk 1.5.0
oracle jre 1.8.0
oracle javafx 2.2.51
CVE-2014-2421 HIGH

Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JavaFX 2.2.51; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
debian debian_linux 8.0
oracle jre 1.7.0
oracle jdk 1.8.0
oracle jdk 1.7.0
oracle jre 1.5.0
canonical ubuntu_linux 13.10
canonical ubuntu_linux 12.04
oracle jdk 1.6.0
oracle jdk 1.5.0
canonical ubuntu_linux 12.10
oracle jre 1.8.0
debian debian_linux 7.0
oracle jrockit r27.8.1
canonical ubuntu_linux 14.04
ibm forms_viewer *
canonical ubuntu_linux 10.04
juniper junos_space *
oracle jrockit r28.3.1
oracle jre 1.6.0
debian debian_linux 6.0
CVE-2014-2428 HIGH

Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
oracle jre 1.7.0
ibm forms_viewer *
oracle jdk 1.8.0
oracle jdk 1.7.0
oracle jre 1.6.0
oracle jdk 1.6.0
oracle jre 1.8.0
CVE-2014-3009 LOW

The GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.0 through 11.0 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 does not properly handle FRAME elements, which makes it easier for remote authenticated users to conduct phishing attacks via a crafted web site.

CVSS 2.0

Severity: LOW

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm infosphere_master_data_management 10.0
ibm infosphere_master_data_management_server_for_product_information_management 9.1
ibm infosphere_master_data_management_server_for_product_information_management 9.0
ibm infosphere_master_data_management 11.0
ibm infosphere_master_data_management 10.1
CVE-2014-3010 MEDIUM

Cross-site scripting (XSS) vulnerability in the Web UI in IBM WebSphere Service Registry and Repository (WSRR) 6.2, 6.3 before 6.3.0.6, 7.0 before 7.0.0.6, 7.5 before 7.5.0.5, and 8.0 before 8.0.0.3 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_service_registry_and_repository 6.3.0
ibm websphere_service_registry_and_repository 8.0.0
ibm websphere_service_registry_and_repository 6.3.0.4
ibm websphere_service_registry_and_repository 7.0.0.1
ibm websphere_service_registry_and_repository 6.3.0.3
ibm websphere_service_registry_and_repository 8.0.0.2
ibm websphere_service_registry_and_repository 8.0.0.1
ibm websphere_service_registry_and_repository 7.5.0.5
ibm websphere_service_registry_and_repository 7.0.0.3
ibm websphere_service_registry_and_repository 7.5.0.3
ibm websphere_service_registry_and_repository 7.0.0.2
ibm websphere_service_registry_and_repository 6.2.0
ibm websphere_service_registry_and_repository 7.5.0.1
ibm websphere_service_registry_and_repository 7.5.0.2
ibm websphere_service_registry_and_repository 6.3.0.1
ibm websphere_service_registry_and_repository 6.3.0.2
ibm websphere_service_registry_and_repository 7.0.0.5
ibm websphere_service_registry_and_repository 7.0.0
ibm websphere_service_registry_and_repository 6.3.0.5
ibm websphere_service_registry_and_repository 7.0.0.4
ibm websphere_service_registry_and_repository 7.5.0.4
CVE-2014-3011 MEDIUM

IBM OpenPages GRC Platform 6.1.0.1 before IF4 allows remote attackers to conduct link injection attacks via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-94,

Products Affected

Vendor Product Version
ibm openpages_grc_platform 6.1.0.1
CVE-2014-3012 LOW

Multiple CRLF injection vulnerabilities in IBM Curam Social Program Management 5.2 SP1 through 6.0.5.4 allow remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified parameters to custom JSPs.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm curam_social_program_management 6.0
ibm curam_social_program_management 6.0.4.3
ibm curam_social_program_management 6.0.5.4
ibm curam_social_program_management 6.0.4.4
ibm curam_social_program_management 5.2
ibm curam_social_program_management 6.0.4.1
ibm curam_social_program_management 6.0.4.0
ibm curam_social_program_management 6.0.5.0
ibm curam_social_program_management 6.0.5.2
ibm curam_social_program_management 6.0.5.1
ibm curam_social_program_management 6.0.3.0
ibm curam_social_program_management 6.0.5.3
ibm curam_social_program_management 6.0.4.2
ibm curam_social_program_management 6.0.4.5
CVE-2014-3013 LOW

Multiple cross-site scripting (XSS) vulnerabilities in IBM Curam Social Program Management 4.5 SP10 through 6.0.5.4 allow remote authenticated users to inject arbitrary web script or HTML via crafted input to a (1) custom JSP or (2) custom renderer.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm curam_social_program_management 6.0
ibm curam_social_program_management 4.5
ibm curam_social_program_management 6.0.4.3
ibm curam_social_program_management 6.0.5.4
ibm curam_social_program_management 6.0.4.4
ibm curam_social_program_management 5.2
ibm curam_social_program_management 6.0.4.1
ibm curam_social_program_management 6.0.4.0
ibm curam_social_program_management 6.0.5.0
ibm curam_social_program_management 6.0.5.2
ibm curam_social_program_management 6.0.5.1
ibm curam_social_program_management 6.0.3.0
ibm curam_social_program_management 6.0.5.3
ibm curam_social_program_management 6.0.4.2
ibm curam_social_program_management 6.0.4.5
ibm curam_social_program_management 5.0
CVE-2014-3014 LOW

Cross-site scripting (XSS) vulnerability in the Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm sametime 8.5.0.0
ibm sametime 8.5.2.0
ibm sametime 8.5.2.1
ibm sametime 9.0.0.1
ibm sametime 8.0.0.0
ibm sametime 8.0.2.0
ibm sametime 8.0.2.1
ibm sametime 8.5.1.1
ibm sametime 9.0.0.0
ibm sametime 8.0.1.1
ibm sametime 8.5.1.0
ibm sametime 8.0.1.0
CVE-2014-3015 MEDIUM

Cross-site request forgery (CSRF) vulnerability in the Web player in IBM Sametime Proxy Server and Web Client 9.0 through 9.0.0.1 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm sametime_proxy_server_and_web_client 9.0.0.1
ibm sametime_proxy_server_and_web_client 9.0.0.0
CVE-2014-3018 HIGH

IBM BladeCenter SAS Connectivity Module (aka NSSM) and SAS RAID Module (aka RSSM) before 1.3.3.006 allow remote attackers to cause a denial of service (reboot) via a flood of IP packets.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm sas_raid_module_firmware *
ibm sas_connectivity_module_firmware *
CVE-2014-3019 MEDIUM

IBM BladeCenter SAS Connectivity Module (aka NSSM) and SAS RAID Module (aka RSSM) before 1.3.3.006 allow remote attackers to obtain blade and storage-pool access via a TELNET session.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm sas_raid_module_firmware *
ibm sas_connectivity_module_firmware *
CVE-2014-3020 MEDIUM

install.sh in the Embedded WebSphere Application Server (eWAS) 7.0 before FP33 in IBM Tivoli Integrated Portal (TIP) 2.1 and 2.2 sets world-writable permissions for the installRoot directory tree, which allows local users to gain privileges via a Trojan horse program.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm tivoli_integrated_portal 2.2
ibm embedded_websphere_application_server 7.0
ibm tivoli_integrated_portal 2.1
CVE-2014-3021 MEDIUM

IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.35, 8.0 before 8.0.0.10, and 8.5 before 8.5.5.4 does not properly handle HTTP headers, which allows remote attackers to obtain sensitive cookie and authentication data via an unspecified HTTP method.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 7.0
ibm websphere_application_server 7.0.0.12
ibm websphere_application_server 8.0.0.6
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 8.5.5.2
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 7.0.0.16
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 7.0.0.25
ibm websphere_application_server 8.0.0.9
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 7.0.0.14
ibm websphere_application_server 7.0.0.22
ibm websphere_application_server 7.0.0.31
ibm websphere_application_server 7.0.0.10
ibm websphere_application_server 8.0.0.8
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 8.0.0.7
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 7.0.0.27
ibm websphere_application_server 7.0.0.18
ibm websphere_application_server 8.5.5.3
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 8.0.0.2
ibm websphere_application_server 8.0.0.5
ibm websphere_application_server 8.5.0.2
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 7.0.0.33
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 7.0.0.32
ibm websphere_application_server 8.0
ibm websphere_application_server 7.0.0.29
ibm websphere_application_server 7.0.0.24
ibm websphere_application_server 8.5.5.0
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 7.0.0.28
ibm websphere_application_server 7.0.0.34
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 8.5.5.1
ibm websphere_application_server 7.0.0.4
CVE-2014-3022 MEDIUM

IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.33, 8.0.x before 8.0.0.9, and 8.5.x before 8.5.5.3 allows remote attackers to obtain sensitive information via a crafted URL that triggers an error condition.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 7.0
ibm websphere_application_server 8.0.0.5
ibm websphere_application_server 7.0.0.12
ibm websphere_application_server 8.5.0.2
ibm websphere_application_server 8.0.0.6
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 8.5.5.2
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 7.0.0.16
ibm websphere_application_server 7.0.0.25
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 7.0.0.14
ibm websphere_application_server 7.0.0.22
ibm websphere_application_server 7.0.0.31
ibm websphere_application_server 7.0.0.10
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 8.0.0.8
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0.0.29
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 7.0.0.24
ibm websphere_application_server 8.5.5.0
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 8.0.0.7
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 7.0.0.27
ibm websphere_application_server 7.0.0.18
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 8.5.5.1
ibm websphere_application_server 8.0.0.2
CVE-2014-3024 MEDIUM

Cross-site request forgery (CSRF) vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.12 and 7.5 through 7.5.0.6 and Maximo Asset Management 7.5.0 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk allows remote authenticated users to hijack the authentication of arbitrary users.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm maximo_asset_management 7.1.1.9
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.5.0.1
ibm maximo_asset_management 7.1.1.10
ibm maximo_asset_management 7.1.1.1
ibm smartcloud_control_desk 7.5.0.0
ibm maximo_asset_management 7.1.1.12
ibm smartcloud_control_desk 7.5.1.2
ibm maximo_asset_management 7.5.0.3
ibm maximo_asset_management 7.5.0.6
ibm maximo_asset_management 7.5.0.0
ibm maximo_asset_management 7.1.1.7
ibm smartcloud_control_desk 7.5.1.1
ibm maximo_asset_management 7.5.0.4
ibm smartcloud_control_desk 7.5.0.2
ibm maximo_asset_management 7.5.0.5
ibm maximo_asset_management 7.1.1.2
ibm smartcloud_control_desk 7.5.0.1
ibm maximo_asset_management 7.1.1.6
ibm maximo_asset_management 7.1.1.5
ibm smartcloud_control_desk 7.5.1.0
ibm maximo_asset_management 7.1.1.11
ibm maximo_asset_management 7.1.2
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
ibm smartcloud_control_desk 7.5.0.3
CVE-2014-3025 LOW

Multiple cross-site scripting (XSS) vulnerabilities in IBM Maximo Asset Management 6.2 through 6.2.8, 6.x and 7.1 through 7.1.1.2, and 7.5 through 7.5.0.6; Maximo Asset Management 7.5 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk; and Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.2, and 7.2 for Tivoli Asset Management for IT and certain other products allow remote authenticated users to inject arbitrary web script or HTML via unspecified input to a .jsp file under webclient/utility/.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm maximo_for_life_sciences 7.5.0.2
ibm maximo_for_life_sciences *
ibm maximo_for_government 7.1
ibm maximo_for_nuclear_power 7.5.0.4
ibm maximo_asset_management 6.2.3
ibm maximo_asset_management 7.1.1.1
ibm maximo_for_nuclear_power 7.5.0.0
ibm maximo_asset_management_essentials *
ibm maximo_for_nuclear_power 7.5.0.1
ibm maximo_for_life_sciences 7.5.0.4
ibm smartcloud_control_desk 7.5.1.2
ibm maximo_for_transportation 7.5.0.1
ibm maximo_for_nuclear_power 7.5.0.3
ibm maximo_for_government 7.5.0.1
ibm maximo_for_utilities 7.5.0.5
ibm maximo_asset_management_essentials 7.5.0.1
ibm maximo_asset_management_essentials 7.5.0.4
ibm maximo_asset_management 7.5.0.6
ibm maximo_for_transportation 7.5.0.2
ibm maximo_asset_management 7.1.1.7
ibm smartcloud_control_desk 7.5.1.1
ibm maximo_asset_management 6.2.2
ibm maximo_for_oil_and_gas 7.1
ibm maximo_for_nuclear_power *
ibm maximo_asset_management 7.1.1.5
ibm smartcloud_control_desk 7.5.1.0
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management 6.2.6
ibm maximo_for_utilities *
ibm maximo_asset_management 6.2.7
ibm maximo_asset_management 7.5.0.10
ibm maximo_asset_management 6.2.5
ibm maximo_for_life_sciences 7.5.0.0
ibm maximo_for_oil_and_gas 7.5.0.2
ibm maximo_for_oil_and_gas 7.5.0.3
ibm maximo_asset_management 7.1.1.12
ibm maximo_for_life_sciences 7.5.0.5
ibm maximo_asset_management 7.5.0.3
ibm maximo_for_oil_and_gas 7.5.0.1
ibm maximo_for_nuclear_power 7.5.0.2
ibm maximo_for_utilities 7.5.0.0
ibm maximo_for_life_sciences 7.5.0.3
ibm maximo_for_government 7.5.0.5
ibm maximo_for_transportation 7.1
ibm maximo_asset_management_essentials 7.1
ibm maximo_asset_management 7.5.0.4
ibm smartcloud_control_desk 7.5.0.1
ibm maximo_for_transportation 7.5.0.3
ibm maximo_asset_management 7.1.2
ibm maximo_for_utilities 7.5.0.1
ibm maximo_for_government 7.5.0.3
ibm smartcloud_control_desk 7.5.0.3
ibm maximo_asset_management 7.1.1.9
ibm maximo_for_government 7.5.0.4
ibm maximo_for_life_sciences 7.5.0.1
ibm maximo_asset_management 7.1.1.10
ibm maximo_asset_management_essentials 7.5.0.0
ibm maximo_for_oil_and_gas 7.5.0.5
ibm maximo_for_nuclear_power 7.1
ibm maximo_for_utilities 7.5.0.2
ibm maximo_for_life_sciences 7.1
ibm maximo_for_government *
ibm maximo_for_transportation 7.5.0.4
ibm maximo_service_desk *
ibm maximo_for_utilities 7.5.0.3
ibm smartcloud_control_desk 7.5.0.2
ibm maximo_asset_management 7.5.0.5
ibm maximo_asset_management 7.1.1.2
ibm smartcloud_control_desk *
ibm maximo_asset_management 7.1.1.11
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
ibm maximo_for_nuclear_power 7.5.0.5
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.5.0.1
ibm maximo_for_transportation 7.5.0.0
ibm maximo_for_oil_and_gas *
ibm maximo_asset_management_essentials 7.5.0.5
ibm maximo_asset_management 6.2.6.1
ibm maximo_for_utilities 7.1
ibm smartcloud_control_desk 7.5.0.0
ibm maximo_for_government 7.5.0.0
ibm tivoli_it_asset_management_for_it *
ibm maximo_asset_management 6.2.8
ibm maximo_asset_management_essentials 6.2.0.0
ibm maximo_asset_management 6.2.4
ibm maximo_asset_management_essentials 7.5.0.2
ibm maximo_for_government 7.5.0.2
ibm maximo_asset_management 6.2.1
ibm maximo_for_transportation 7.5.0.5
ibm maximo_asset_management 7.5.0.0
ibm maximo_for_transportation *
ibm maximo_asset_management 6.2
ibm maximo_for_oil_and_gas 7.5.0.4
ibm smartcloud_control_desk 7.5
ibm maximo_for_oil_and_gas 7.5.0.0
ibm maximo_asset_management 7.1.1.6
ibm maximo_asset_management_essentials 7.5.0.3
ibm maximo_for_utilities 7.5.0.4
CVE-2014-3026 LOW

CRLF injection vulnerability in IBM Maximo Asset Management 7.5 through 7.5.0.6, and 7.5 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk, allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm maximo_industry_solutions 7.5.0.6
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management 7.5.0.1
ibm maximo_asset_management_essentials 7.5.0.5
ibm smartcloud_control_desk 7.5.1.3
ibm smartcloud_control_desk 7.5.0.0
ibm maximo_asset_management_essentials 7.5.0.0
ibm maximo_asset_management_essentials 7.5.0.6
ibm smartcloud_control_desk 7.5.1.2
ibm maximo_industry_solutions 7.5.0.4
ibm maximo_asset_management 7.5.0.3
ibm maximo_asset_management_essentials 7.5.0.2
ibm maximo_asset_management_essentials 7.5.0.1
ibm maximo_asset_management_essentials 7.5.0.4
ibm maximo_asset_management 7.5.0.6
ibm maximo_industry_solutions 7.5.0.1
ibm maximo_industry_solutions 7.5.0.3
ibm maximo_asset_management 7.5.0.0
ibm smartcloud_control_desk 7.5.1.1
ibm maximo_industry_solutions 7.5.0.0
ibm maximo_asset_management 7.5.0.4
ibm smartcloud_control_desk 7.5.0.2
ibm maximo_asset_management 7.5.0.5
ibm maximo_industry_solutions 7.5.0.2
ibm smartcloud_control_desk 7.5.0.1
ibm maximo_asset_management_essentials 7.5.0.3
ibm smartcloud_control_desk 7.5.1.0
ibm maximo_industry_solutions 7.5.0.5
ibm smartcloud_control_desk 7.5.0.3
CVE-2014-3031 LOW

Cross-site scripting (XSS) vulnerability in IBM Tivoli Business Service Manager 4.2.0 before 4.2.0.0 IF12 and 4.2.1 before 4.2.1.3 IF9 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_business_service_manager 4.2
ibm tivoli_business_service_manager 4.2.1
CVE-2014-3032 LOW

Cross-site scripting (XSS) vulnerability in the Web GUI in IBM Tivoli Netcool/OMNIbus 7.3.0 before 7.3.0.6, 7.3.1 before 7.3.1.7, and 7.4.0 before 7.4.0.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_netcool/omnibus 7.3.1.0
ibm tivoli_netcool/omnibus 7.3.0
ibm tivoli_netcool/omnibus 7.3.1.3
ibm tivoli_netcool/omnibus 7.3.0.4
ibm tivoli_netcool/omnibus 7.3.0.1
ibm tivoli_netcool/omnibus 7.4.0
ibm tivoli_netcool/omnibus 7.3.0.2
ibm tivoli_netcool/omnibus 7.4.0.1
ibm tivoli_netcool/omnibus 7.3.0.5
ibm tivoli_netcool/omnibus 7.3.1.2
ibm tivoli_netcool/omnibus 7.3.1.1
ibm tivoli_netcool/omnibus 7.3.1.6
ibm tivoli_netcool/omnibus 7.4.0.2
ibm tivoli_netcool/omnibus 7.3.0.3
ibm tivoli_netcool/omnibus 7.3.1.4
ibm tivoli_netcool/omnibus 7.3.1.5
CVE-2014-3033 LOW

Cross-site scripting (XSS) vulnerability in IBM Emptoris Sourcing Portfolio 9.5.x before 9.5.1.3, 10.0.0.x before 10.0.0.1, 10.0.1.x before 10.0.1.3, and 10.0.2.x before 10.0.2.4 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm emptoris_sourcing_portfolio 9.5.1.0
ibm emptoris_sourcing_portfolio 10.0.2.2
ibm emptoris_sourcing_portfolio 9.5.0.2
ibm emptoris_sourcing_portfolio 9.5.1.2
ibm emptoris_sourcing_portfolio 10.0.0.0
ibm emptoris_sourcing_portfolio 9.5.0.1
ibm emptoris_sourcing_portfolio 10.0.1.0
ibm emptoris_sourcing_portfolio 9.5.1.1
ibm emptoris_sourcing_portfolio 10.0.2.0
ibm emptoris_sourcing_portfolio 10.0.2.3
ibm emptoris_sourcing_portfolio 10.0.1.1
ibm emptoris_sourcing_portfolio 9.5.0.0
ibm emptoris_sourcing_portfolio 10.0.1.2
CVE-2014-3034 LOW

Cross-site scripting (XSS) vulnerability in IBM Emptoris Contract Management 9.5.x before 9.5.0.6 iFix 10, 10.0.0.x before 10.0.0.1 iFix 10, 10.0.1.x before 10.0.1.4, and 10.0.2.x before 10.0.2.2 iFix 2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm emptoris_contract_management 9.5.0.1
ibm emptoris_contract_management 9.5.0.4
ibm emptoris_contract_management 10.0.1.1
ibm emptoris_contract_management 10.0.2.1
ibm emptoris_contract_management 10.0.2.0
ibm emptoris_contract_management 9.5.0.5
ibm emptoris_contract_management 10.0.0.1
ibm emptoris_contract_management 10.0.1.2
ibm emptoris_contract_management 10.0.1.3
ibm emptoris_contract_management 10.0.0.0
ibm emptoris_contract_management 10.0.1.0
ibm emptoris_contract_management 9.5.0.2
ibm emptoris_contract_management 9.5.0.3
ibm emptoris_contract_management 9.5.0.0
ibm emptoris_contract_management 10.0.2.2
ibm emptoris_contract_management 9.5.0.6
CVE-2014-3035 LOW

Cross-site scripting (XSS) vulnerability in IBM Emptoris Spend Analysis 9.5.x before 9.5.0.4, 10.0.1.x before 10.0.1.3, and 10.0.2.x before 10.0.2.4 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm emptoris_spend_analysis 9.5.0.0
ibm emptoris_spend_analysis 10.0.2.0
ibm emptoris_spend_analysis 10.0.1.2
ibm emptoris_spend_analysis 10.0.1.0
ibm emptoris_spend_analysis 10.0.2.2
ibm emptoris_spend_analysis 9.5.0.3
ibm emptoris_spend_analysis 9.5.0.2
ibm emptoris_spend_analysis 10.0.1.1
ibm emptoris_spend_analysis 9.5.0.1
CVE-2014-3036 MEDIUM

Unspecified vulnerability in IBM API Management 3.0.0.0, when basic authentication is used for APIs, allows remote attackers to bypass intended restrictions on topology access, and obtain sensitive information, via unknown vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm api_management 3.0.0.0
CVE-2014-3037 MEDIUM

Cross-site request forgery (CSRF) vulnerability in IBM Configuration Management Application (aka VVC) in IBM Rational Engineering Lifecycle Manager before 4.0.7 and 5.x before 5.0.1, Rational Software Architect Design Manager before 4.0.7 and 5.x before 5.0.1, and Rational Rhapsody Design Manager before 4.0.7 and 5.x before 5.0.1 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm rational_software_architect_design_manager 3.0.0.1
ibm rational_rhapsody_design_manager 4.0.4
ibm rational_rhapsody_design_manager 4.0.5
ibm rational_engineering_lifecycle_manager 5.0
ibm rational_software_architect_design_manager 4.0.2
ibm rational_software_architect_design_manager *
ibm rational_engineering_lifecycle_manager 4.03
ibm rational_rhapsody_design_manager 5.0
ibm rational_rhapsody_design_manager *
ibm rational_engineering_lifecycle_manager 1.0
ibm rational_software_architect_design_manager 5.0
ibm rational_software_architect_design_manager 4.0.4
ibm rational_engineering_lifecycle_manager *
ibm rational_engineering_lifecycle_manager 4.05
ibm rational_rhapsody_design_manager 3.0.0.1
ibm rational_engineering_lifecycle_manager 1.0.0.1
ibm rational_software_architect_design_manager 4.0.3
ibm rational_engineering_lifecycle_manager 4.04
ibm rational_rhapsody_design_manager 3.0
ibm rational_software_architect_design_manager 4.0.0
ibm rational_software_architect_design_manager 4.0.5
ibm rational_rhapsody_design_manager 4.0.3
ibm rational_rhapsody_design_manager 4.0.1
ibm rational_rhapsody_design_manager 4.0.2
ibm rational_rhapsody_design_manager 3.0.1
ibm rational_rhapsody_design_manager 4.0
ibm rational_software_architect_design_manager 3.0
ibm rational_software_architect_design_manager 4.0.1
CVE-2014-3038 LOW

IBM SPSS Modeler 16.0 before 16.0.0.1 on UNIX does not properly drop group privileges, which allows local users to bypass intended file-access restrictions by leveraging (1) gid 0 or (2) root's group memberships.

CVSS 2.0

Severity: LOW

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm spss_modeler 16.0.0.0
CVE-2014-3040 MEDIUM

Cross-site request forgery (CSRF) vulnerability in IBM Emptoris Contract Management 9.5.x before 9.5.0.6 iFix 10, 10.0.0.x before 10.0.0.1 iFix 10, 10.0.1.x before 10.0.1.4, and 10.0.2.x before 10.0.2.2 iFix 2; Emptoris Sourcing Portfolio 9.5.x before 9.5.1.3, 10.0.0.x before 10.0.0.1, 10.0.1.x before 10.0.1.3, and 10.0.2.x before 10.0.2.4; and Emptoris Spend Analysis 9.5.x before 9.5.0.4, 10.0.1.x before 10.0.1.3, and 10.0.2.x before 10.0.2.4 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm emptoris_contract_management 9.5.0.1
ibm emptoris_contract_management 9.5.0.4
ibm emptoris_sourcing_portfolio 9.5.0.2
ibm emptoris_spend_analysis 9.5.0.3
ibm emptoris_spend_analysis 10.0.0.0
ibm emptoris_contract_management 10.0.0.1
ibm emptoris_contract_management 10.0.1.2
ibm emptoris_contract_management 10.0.0.0
ibm emptoris_contract_management 10.0.1.0
ibm emptoris_spend_analysis 9.5.0.0
ibm emptoris_sourcing_portfolio 10.0.1.1
ibm emptoris_spend_analysis 10.0.1.2
ibm emptoris_contract_management 9.5.0.3
ibm emptoris_contract_management 9.5.0.0
ibm emptoris_contract_management 10.0.2.2
ibm emptoris_spend_analysis 10.0.0.1
ibm emptoris_contract_management 10.0.1.5
ibm emptoris_sourcing_portfolio 10.0.1.2
ibm emptoris_sourcing_portfolio 9.5.1.0
ibm emptoris_sourcing_portfolio 10.0.2.2
ibm emptoris_spend_analysis 10.0.2.0
ibm emptoris_contract_management 10.0.1.1
ibm emptoris_sourcing_portfolio 9.5.1.2
ibm emptoris_sourcing_portfolio 10.0.0.0
ibm emptoris_contract_management 10.0.2.1
ibm emptoris_sourcing_portfolio 9.5.0.1
ibm emptoris_contract_management 10.0.2.0
ibm emptoris_sourcing_portfolio 10.0.1.0
ibm emptoris_sourcing_portfolio 9.5.1.1
ibm emptoris_spend_analysis 10.0.1.1
ibm emptoris_sourcing_portfolio 10.0.2.0
ibm emptoris_contract_management 9.5.0.5
ibm emptoris_contract_management 10.0.1.3
ibm emptoris_sourcing_portfolio 10.0.2.3
ibm emptoris_contract_management 9.5.0.2
ibm emptoris_spend_analysis 10.0.1.0
ibm emptoris_spend_analysis 10.0.2.2
ibm emptoris_sourcing_portfolio 9.5.0.0
ibm emptoris_spend_analysis 9.5.0.2
ibm emptoris_contract_management 9.5.0.6
ibm emptoris_spend_analysis 9.5.0.1
CVE-2014-3041 MEDIUM

SQL injection vulnerability in IBM Emptoris Contract Management 9.5.x before 9.5.0.6 iFix 10, 10.0.0.x before 10.0.0.1 iFix 10, 10.0.1.x before 10.0.1.4, and 10.0.2.x before 10.0.2.2 iFix 2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm emptoris_contract_management 9.5.0.1
ibm emptoris_contract_management 9.5.0.4
ibm emptoris_contract_management 10.0.1.1
ibm emptoris_contract_management 10.0.2.1
ibm emptoris_contract_management 10.0.2.0
ibm emptoris_contract_management 9.5.0.5
ibm emptoris_contract_management 10.0.0.1
ibm emptoris_contract_management 10.0.1.2
ibm emptoris_contract_management 10.0.1.3
ibm emptoris_contract_management 10.0.0.0
ibm emptoris_contract_management 10.0.1.0
ibm emptoris_contract_management 9.5.0.2
ibm emptoris_contract_management 9.5.0.3
ibm emptoris_contract_management 9.5.0.0
ibm emptoris_contract_management 10.0.2.2
ibm emptoris_contract_management 9.5.0.6
CVE-2014-3042 MEDIUM

IBM CICS Transaction Server 3.1, 3.2, 4.1, 4.2, and 5.1 on z/OS does not properly implement CEMT transactions, which allows remote authenticated users to cause a denial of service (storage overlay) by using a 3270 emulator to send an invalid 3270 data stream.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm cics_transaction_server 3.1
ibm cics_transaction_server 3.2
ibm cics_transaction_server 5.1
ibm cics_transaction_server -
ibm cics_transaction_server 4.1
CVE-2014-3043 MEDIUM

IBM Storwize V7000 Unified 1.3.x and 1.4.x before 1.4.3.3 allows remote authenticated users to gain privileges by leveraging access to the service account.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm storwize_unified_v7000_software 1.4.0.4
ibm storwize_unified_v7000 -
ibm storwize_unified_v7000_software 1.3.0.0
ibm storwize_unified_v7000_software 1.4.3.2
ibm storwize_unified_v7000_software 1.3.1.0
ibm storwize_unified_v7000_software 1.4.0.2
ibm storwize_unified_v7000_software 1.4.0.5
ibm storwize_unified_v7000_software 1.4.2.0
ibm storwize_unified_v7000_software 1.4.0.3
ibm storwize_unified_v7000_software 1.4.2.1
ibm storwize_unified_v7000_software 1.4.3.1
ibm storwize_unified_v7000_software 1.4.1.1
ibm storwize_unified_v7000_software 1.4.0.0
ibm storwize_unified_v7000_software 1.4.1.0
ibm storwize_unified_v7000_software 1.4.3.0
ibm storwize_unified_v7000_software 1.4.0.1
CVE-2014-3045 LOW

IBM Scale Out Network Attached Storage (SONAS) 1.3.x and 1.4.x before 1.4.3.3 places an administrative password in the shell history upon use of the -p option to chuser, which allows local users to obtain sensitive information by leveraging root access.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm scale_out_network_attached_storage *
CVE-2014-3048 MEDIUM

Unspecified vulnerability on the IBM System Storage Virtualization Engine TS7700 allows local users to gain privileges by leveraging the TSSC service-user role to enter a crafted SSH command.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm system_storage_virtualization_engine_ts7700 -
ibm system_storage_virtualization_engine_ts7700_firmware -
CVE-2014-3050 LOW

IBM Rational Team Concert (RTC) 3.x before 3.0.1.6 IF3 and 4.x before 4.0.7 does not properly integrate with build engines, which allows remote authenticated users to discover credentials via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_team_concert 3.0.1.1
ibm rational_team_concert 4.0.0.1
ibm rational_team_concert 3.0.1.5
ibm rational_team_concert 3.0.1.3
ibm rational_team_concert 4.0.1
ibm rational_team_concert 3.0.1.2
ibm rational_team_concert 4.0
ibm rational_team_concert 4.0.5
ibm rational_team_concert 4.0.2
ibm rational_team_concert 4.0.4
ibm rational_team_concert 4.0.3
ibm rational_team_concert 3.0
ibm rational_team_concert 4.0.0.2
ibm rational_team_concert 3.0.1
ibm rational_team_concert 3.0.1.4
ibm rational_team_concert 4.0.6
ibm rational_team_concert 3.0.1.6
CVE-2014-3051 MEDIUM

The Internet Service Monitor (ISM) agent in IBM Tivoli Composite Application Manager (ITCAM) for Transactions 7.1 and 7.2 before 7.2.0.3 IF28, 7.3 before 7.3.0.1 IF30, and 7.4 before 7.4.0.0 IF18 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain credential information via a crafted certificate.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm tivoli_composite_application_manager_for_transactions 7.2.0.0
ibm tivoli_composite_application_manager_for_transactions 7.2.0.2
ibm tivoli_composite_application_manager_for_transactions 7.1.0.0
ibm tivoli_composite_application_manager_for_transactions 7.1.0.2
ibm tivoli_composite_application_manager_for_transactions 7.1.0.3
ibm tivoli_composite_application_manager_for_transactions 7.1.0.4
ibm tivoli_composite_application_manager_for_transactions 7.2.0.1
ibm tivoli_composite_application_manager_for_transactions 7.1.0.1
ibm tivoli_composite_application_manager_for_transactions 7.3.0.0
CVE-2014-3052 LOW

The reverse-proxy feature in IBM Security Access Manager (ISAM) for Web 8.0 with firmware 8.0.0.2 and 8.0.0.3 interprets the jct-nist-compliance parameter in the opposite of the intended manner, which makes it easier for remote attackers to obtain sensitive information by leveraging weak SSL encryption settings that lack NIST SP 800-131A compliance.

CVSS 2.0

Severity: LOW

Problem Type: CWE-16,

Products Affected

Vendor Product Version
ibm security_access_manager_for_web_appliance 8.0
ibm security_access_manager_for_web_8.0_firmware 8.0.0.2
ibm security_access_manager_for_web_8.0_firmware 8.0.0.3
CVE-2014-3053 HIGH

The Local Management Interface (LMI) in IBM Security Access Manager (ISAM) for Mobile 8.0 with firmware 8.0.0.0 through 8.0.0.3 and IBM Security Access Manager for Web 7.0, and 8.0 with firmware 8.0.0.2 and 8.0.0.3, allows remote attackers to bypass authentication via a login action with invalid credentials.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm security_access_manager_for_web_appliance 7.0
ibm security_access_manager_for_web_software 7.0
ibm security_access_manager_for_web_software 8.0
ibm security_access_manager_for_mobile_software 8.0
ibm security_access_manager_for_web_appliance 8.0
ibm security_access_manager_for_web_8.0_firmware 8.0.0.2
ibm security_access_manager_for_mobile_appliance 8.0
ibm security_access_manager_for_web_8.0_firmware 8.0.0.3
CVE-2014-3054 MEDIUM

Multiple open redirect vulnerabilities in the Unified Task List (UTL) Portlet for IBM WebSphere Portal 7.x and 8.x through 8.0.0.1 CF12 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.1
ibm websphere_portal 8.0.0.0
ibm websphere_portal 7.0.0.2
ibm websphere_portal 7.0.0.1
ibm websphere_portal_unified_task_list_portlet 6.0.1
ibm websphere_portal 7.0.0.0
CVE-2014-3055 HIGH

SQL injection vulnerability in the Unified Task List (UTL) Portlet for IBM WebSphere Portal 7.x and 8.x through 8.0.0.1 CF12 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.1
ibm websphere_portal 8.0.0.0
ibm websphere_portal 7.0.0.2
ibm websphere_portal 7.0.0.1
ibm websphere_portal_unified_task_list_portlet 6.0.1
ibm websphere_portal 7.0.0.0
CVE-2014-3056 MEDIUM

The Unified Task List (UTL) Portlet for IBM WebSphere Portal 7.x and 8.x through 8.0.0.1 CF12 allows remote attackers to obtain potentially sensitive information about environment variables and JAR versions via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.1
ibm websphere_portal 8.0.0.0
ibm websphere_portal 7.0.0.2
ibm websphere_portal 7.0.0.1
ibm websphere_portal_unified_task_list_portlet 6.0.1
ibm websphere_portal 7.0.0.0
CVE-2014-3057 MEDIUM

Cross-site scripting (XSS) vulnerability in the Unified Task List (UTL) Portlet for IBM WebSphere Portal 7.x and 8.x through 8.0.0.1 CF12 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.1
ibm websphere_portal 8.0.0.0
ibm websphere_portal 7.0.0.2
ibm websphere_portal 7.0.0.1
ibm websphere_portal_unified_task_list_portlet 6.0.1
ibm websphere_portal 7.0.0.0
CVE-2014-3058 MEDIUM

Cross-site request forgery (CSRF) vulnerability on the IBM WebSphere DataPower XC10 appliance 2.1 and 2.5 before FP4 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm websphere_datapower_xc10_appliance_firmware 2.1.0.0
ibm websphere_datapower_xc10_appliance_firmware 2.5.0.0
CVE-2014-3059 HIGH

Unspecified vulnerability in the Administrative Console on the IBM WebSphere DataPower XC10 appliance 2.5 allows remote attackers to obtain administrative privileges by leveraging access to an eXtreme Scale distributed ObjectGrid network.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_datapower_xc10_appliance_firmware 2.5.0.0
ibm websphere_datapower_xc10_appliance -
CVE-2014-3060 HIGH

Unspecified vulnerability on the IBM WebSphere DataPower XC10 appliance 2.5 allows remote attackers to obtain administrative privileges by leveraging access to an eXtreme Scale distributed ObjectGrid network and capturing a session cookie.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_datapower_xc10_appliance_firmware 2.5.0.0
ibm websphere_datapower_xc10_appliance -
CVE-2014-3061 MEDIUM

Cross-site request forgery (CSRF) vulnerability in IBM Emptoris Spend Analysis 9.5.x before 9.5.0.4, 10.0.1.x before 10.0.1.3, and 10.0.2.x before 10.0.2.4 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm emptoris_spend_analysis 9.5.0.0
ibm emptoris_spend_analysis 10.0.2.0
ibm emptoris_spend_analysis 10.0.1.2
ibm emptoris_spend_analysis 10.0.1.0
ibm emptoris_spend_analysis 10.0.2.2
ibm emptoris_spend_analysis 9.5.0.3
ibm emptoris_spend_analysis 9.5.0.2
ibm emptoris_spend_analysis 10.0.1.1
ibm emptoris_spend_analysis 9.5.0.1
CVE-2014-3062 HIGH

Unspecified vulnerability in IBM Security QRadar SIEM 7.1 MR2 and 7.2 MR2 allows remote attackers to execute arbitrary code via unknown vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.0
ibm qradar_security_information_and_event_manager 7.1.0
CVE-2014-3063 HIGH

IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1-FP11 and 11.x before 11.0-FP5 and InfoSphere Master Data Management Server for Product Information Management 9.x before 9.1-FP15 and 10.x and 11.x before 11.3-IF2 allow local users to obtain administrator privileges via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm infosphere_master_data_management_server_for_product_information_management 10.1.0.1
ibm infosphere_master_data_management_server_for_product_information_management 10.1
ibm infosphere_master_data_management_server_for_product_information_management 10.0
ibm infosphere_master_data_management_server_for_product_information_management 9.1
ibm infosphere_master_data_management_server_for_product_information_management 9.0
ibm infosphere_master_data_management_server_for_product_information_management 10.0.0.1
ibm infosphere_master_data_management_server_for_product_information_management 10.0.1
ibm infosphere_master_data_management_server_for_product_information_management 10.1.0.2
ibm infosphere_master_data_management 10.0
ibm infosphere_master_data_management_server_for_product_information_management 11.0
ibm infosphere_master_data_management 11.0
ibm infosphere_master_data_management_server_for_product_information_management 11.3
ibm infosphere_master_data_management 10.1
ibm infosphere_master_data_management 11.3
CVE-2014-3064 MEDIUM

The GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0 FP4 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 allows remote authenticated users to read arbitrary files via a crafted UNIX file parameter.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm infosphere_master_data_management_collaboration_server 10.0
ibm infosphere_master_data_management_server_for_product_information_management 9.1
ibm infosphere_master_data_management_collaboration_server 10.1
ibm infosphere_master_data_management_server_for_product_information_management 9.0
ibm infosphere_master_data_management_collaboration_server 11.0
CVE-2014-3065 MEDIUM

Unspecified vulnerability in IBM Java Runtime Environment (JRE) 7 R1 before SR2 (7.1.2.0), 7 before SR8 (7.0.8.0), 6 R1 before SR8 FP2 (6.1.8.2), 6 before SR16 FP2 (6.0.16.2), and before SR16 FP8 (5.0.16.8) allows local users to execute arbitrary code via vectors related to the shared classes cache.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-94,

Products Affected

Vendor Product Version
ibm java 5.0.0.0
ibm java 5.0.12.5
ibm java 6.0.13.2
ibm java 5.0.12.4
ibm java 5.0.15.0
ibm java 5.0.16.1
ibm java 6.0.9.0
ibm java 5.0.16.0
ibm java 5.0.16.2
ibm java 5.0.12.1
ibm java 6.0.0.0
ibm java 6.0.5.0
ibm java 6.0.8.1
ibm java 7.0.4.1
ibm java 7.0.0.0
ibm java 6.0.11.0
ibm java 5.0.12.2
ibm java 5.0.11.2
ibm java 5.0.14.0
ibm java 5.0.16.3
ibm java 7.0.4.0
ibm java 6.0.1.0
ibm java 7.0.4.2
ibm java 6.0.14.0
ibm java 6.0.10.1
ibm java 5.0.11.1
ibm java 5.0.13.0
ibm java 7.0.5.0
ibm java 6.0.10.0
ibm java 6.0.8.0
ibm java 6.0.9.2
ibm java 5.0.12.0
ibm java 7.0.1.0
ibm java 5.0.12.3
ibm java 6.0.6.0
ibm java 5.0.11.0
ibm java 7.0.2.0
ibm java 6.0.2.0
ibm java 6.0.4.0
ibm java 7.0.3.0
ibm java 6.0.7.0
ibm java 6.0.13.1
ibm java 6.0.12.0
ibm java 6.0.13.0
ibm java 6.0.3.0
ibm java 6.0.9.1
CVE-2014-3066 MEDIUM

IBM Tivoli Endpoint Manager 9.1 before 9.1.1088.0 allows remote attackers to read arbitrary files via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm tivoli_endpoint_manager 9.1
CVE-2014-3068 MEDIUM

IBM Java Runtime Environment (JRE) 7 R1 before SR1 FP1 (7.1.1.1), 7 before SR7 FP1 (7.0.7.1), 6 R1 before SR8 FP1 (6.1.8.1), 6 before SR16 FP1 (6.0.16.1), and before 5.0 SR16 FP7 (5.0.16.7) allows attackers to obtain the private key from a Certificate Management System (CMS) keystore via a brute force attack.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm java 5.0.0.0
ibm java 5.0.12.5
ibm java 6.0.13.2
ibm java 5.0.12.4
ibm java 5.0.15.0
ibm java 5.0.16.1
ibm java 6.0.9.0
ibm java 5.0.16.0
ibm java 5.0.16.2
ibm java 5.0.12.1
ibm java 6.0.0.0
ibm java 6.0.5.0
ibm java 6.0.8.1
ibm java 7.0.4.1
ibm java 7.0.0.0
ibm java 6.0.11.0
ibm java 5.0.12.2
ibm java 5.0.11.2
ibm java 5.0.14.0
ibm java 5.0.16.3
ibm java 7.0.4.0
ibm java 6.0.1.0
ibm java 7.0.4.2
ibm java 6.0.14.0
ibm java 6.0.10.1
ibm java 5.0.11.1
ibm java 5.0.13.0
ibm java 7.0.5.0
ibm java 6.0.10.0
ibm java 6.0.8.0
ibm java 6.0.9.2
ibm java 5.0.12.0
ibm java 7.0.1.0
ibm java 5.0.12.3
ibm java 6.0.6.0
ibm java 5.0.11.0
ibm java 7.0.2.0
ibm java 6.0.2.0
ibm java 6.0.4.0
ibm java 7.0.3.0
ibm java 6.0.7.0
ibm java 6.0.13.1
ibm java 6.0.12.0
ibm java 6.0.13.0
ibm java 6.0.3.0
ibm java 6.0.9.1
CVE-2014-3069 LOW

Multiple CRLF injection vulnerabilities in the Universal Access component in IBM Curam Social Program Management (SPM) 6.0.5.5, when WebSphere Application Server is not used, allow remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified parameters.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm curam_social_program_management 6.0.5.5
CVE-2014-3070 MEDIUM

The addFileRegistryAccount Virtual Member Manager (VMM) SPI Admin Task in IBM WebSphere Application Server (WAS) 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.3 does not properly create accounts, which allows remote attackers to bypass intended access restrictions via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_application_server 8.0.0.8
ibm websphere_application_server 8.0.0.5
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 8.5.5.0
ibm websphere_application_server 8.5.0.2
ibm websphere_application_server 8.0.0.6
ibm websphere_application_server 8.5.5.2
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 8.0.0.7
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 8.0.0.9
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 8.5.5.1
ibm websphere_application_server 8.0.0.2
CVE-2014-3071 MEDIUM

Cross-site scripting (XSS) vulnerability in the Data Quality Console in IBM InfoSphere Information Server 11.3 allows remote attackers to inject arbitrary web script or HTML via a crafted URL for adding a project connection.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm infosphere_information_server 11.3
CVE-2014-3072 HIGH

Unspecified vulnerability in the Automation Server in IBM Security AppScan Source 8 through 8.0.0.2, 8.5 through 8.5.0.1, 8.6 through 8.6.0.2, 8.7 through 8.7.0.1, 8.8, and 9.0 through 9.0.0.1 allows local users to gain privileges by executing a crafted service.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm security_appscan_source 8.6
ibm security_appscan_source 8.6.0.1
ibm security_appscan_source 8.5.0.1
ibm security_appscan_source 8.6.0.2
ibm security_appscan_source 8.7.0.1
ibm security_appscan_source 8.5
ibm security_appscan_source 8.0
ibm security_appscan_source 8.0.0.1
ibm security_appscan_source 9.0
ibm security_appscan_source 8.7.0.0
ibm security_appscan_source 8.0.0.2
ibm security_appscan_source 8.8
ibm security_appscan_source 9.0.0.1
CVE-2014-3073 HIGH

Unspecified vulnerability in IBM Security Access Manager (ISAM) for Mobile 8.0 and IBM Security Access Manager for Web 7.0 and 8.0 allows remote attackers to execute arbitrary code via unknown vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm security_access_manager_for_web_appliance 7.0
ibm security_access_manager_for_web_software 7.0
ibm security_access_manager_for_web_software 8.0
ibm security_access_manager_for_mobile_software 8.0
ibm security_access_manager_for_web_appliance 8.0
ibm security_access_manager_for_mobile_appliance 8.0
CVE-2014-3074 HIGH

The runtime linker in IBM AIX 6.1 and 7.1 and VIOS 2.2.x allows local users to create a mode-666 root-owned file, and consequently gain privileges, by setting crafted MALLOCOPTIONS and MALLOCBUCKETS environment-variable values and then executing a setuid program.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm vios 2.2.1.8
ibm aix 6.1
ibm vios 2.2.0.10
ibm vios 2.2.1.1
ibm vios 2.2.1.4
ibm vios 2.2.3.3
ibm aix 7.1
ibm vios 2.2.3.2
ibm vios 2.2.1.9
ibm vios 2.2.0.12
ibm vios 2.2.0.13
ibm vios 2.2.2.5
ibm vios 2.2.1.3
ibm vios 2.2.3.0
ibm vios 2.2.2.0
ibm vios 2.2.2.4
ibm vios 2.2.0.11
ibm vios 2.2.1.0
CVE-2014-3075 LOW

Cross-site scripting (XSS) vulnerability in IBM Business Process Manager (BPM) 7.5.x through 8.5.5 and WebSphere Lombardi Edition 7.2.0.x allows remote authenticated users to inject arbitrary web script or HTML via an uploaded file.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm business_process_manager 8.0.1.2
ibm business_process_manager 8.0.1.1
ibm business_process_manager 7.5.0.1
ibm websphere_application_server 7.2
ibm websphere_application_server 7.2.0.3
ibm websphere_application_server 7.2.0.2
ibm websphere_application_server 7.2.0.4
ibm business_process_manager 7.5.1.0
ibm websphere_application_server 7.2.0.1
ibm business_process_manager 7.5.1.1
ibm business_process_manager 8.5.5.0
ibm business_process_manager 8.0.1.0
ibm business_process_manager 7.5.1.2
ibm business_process_manager 8.0.0.0
ibm business_process_manager 8.5.0.1
ibm websphere_application_server 7.2.0.5
ibm business_process_manager 8.5.0.0
ibm business_process_manager 7.5.0.0
CVE-2014-3076 MEDIUM

IBM Business Process Manager (BPM) 8.5 through 8.5.5 allows remote attackers to obtain potentially sensitive information by visiting an unspecified JSP diagnostic page.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm business_process_manager 8.5.5.0
ibm business_process_manager 8.5.0.1
ibm business_process_manager 8.5.0.0
CVE-2014-3077 LOW

IBM SONAS and System Storage Storwize V7000 Unified (aka V7000U) 1.3.x and 1.4.x before 1.4.3.4 store the chkauth password in the audit log, which allows local users to obtain sensitive information by reading this log file.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm storwize_unified_v7000 -
ibm storwize_v7000_unified_software 1.3.2.0
ibm storwize_v7000_unified_software 1.3.0.0
ibm storwize_v7000_unified_software 1.4.3.0
ibm storwize_v7000_unified_software 1.3.2.3
ibm storwize_v7000_unified_software 1.4.1.1
ibm storwize_v7000_unified_software 1.4.0.0
ibm storwize_v7000_unified_software 1.4.1.0
ibm storwize_v7000_unified_software 1.4.2.0
ibm storwize_v7000_unified_software 1.4.3.3
ibm storwize_v7000_unified_software 1.4.0.4
CVE-2014-3079 LOW

The Administration and Reporting Tool in IBM Rational License Key Server (RLKS) 8.1.4.x before 8.1.4.4 allows remote authenticated users to bypass authorization checks and visit unspecified URLs with license-usage data via a DESCRIBE clause in a SPARQL query.

CVSS 2.0

Severity: LOW

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm rational_license_key_server 8.1.4
ibm rational_license_key_server 8.1.4.3
ibm rational_license_key_server 8.1.4.2
CVE-2014-3080 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to kvm.cgi or (2) the key parameter to avctalert.php.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm global_console_manager_32_firmware *
ibm global_console_manager_16_firmware *
CVE-2014-3081 MEDIUM

prodtest.php on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allows remote authenticated users to read arbitrary files via the filename parameter.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm global_console_manager_32_firmware *
ibm global_console_manager_16_firmware *
CVE-2014-3083 MEDIUM

IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.35, 8.0.x before 8.0.0.10, and 8.5.x before 8.5.5.3 does not properly restrict resource access, which allows remote attackers to obtain sensitive information via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 7.0
ibm websphere_application_server 8.0.0.5
ibm websphere_application_server 7.0.0.12
ibm websphere_application_server 8.5.0.2
ibm websphere_application_server 8.0.0.6
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 8.5.5.2
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 7.0.0.16
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 7.0.0.33
ibm websphere_application_server 7.0.0.25
ibm websphere_application_server 8.0.0.9
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 7.0.0.14
ibm websphere_application_server 7.0.0.22
ibm websphere_application_server 7.0.0.31
ibm websphere_application_server 7.0.0.10
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 8.0.0.8
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0.0.29
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 7.0.0.24
ibm websphere_application_server 8.5.5.0
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 8.0.0.7
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 7.0.0.27
ibm websphere_application_server 7.0.0.18
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 8.5.5.1
ibm websphere_application_server 7.0.0.4
ibm websphere_application_server 8.0.0.2
CVE-2014-3084 MEDIUM

IBM Maximo Asset Management 6.1 through 6.5, 7.1 through 7.1.1.13, and 7.5 through 7.5.0.6; Maximo Asset Management 7.5.0 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk; and Maximo Asset Management 6.2.8, 7.1, and 7.2 for Tivoli IT Asset Management for IT and certain other products allow remote authenticated users to bypass intended write-access restrictions on calendar entries via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm tivoli_asset_management_for_it 7.2
ibm maximo_asset_management 7.1.1.9
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.5.0.1
ibm maximo_asset_management 6.2.6
ibm maximo_asset_management 6.2.7
ibm maximo_asset_management 7.1.1.13
ibm maximo_asset_management 6.2.6.1
ibm maximo_asset_management 7.1.1.10
ibm maximo_asset_management 6.2.3
ibm maximo_asset_management 6.2.5
ibm maximo_asset_management 7.1.1.1
ibm smartcloud_control_desk 7.5.0.0
ibm maximo_asset_management 6.2.8
ibm maximo_asset_management 7.1.1.12
ibm smartcloud_control_desk 7.5.1.2
ibm maximo_asset_management 7.5.0.3
ibm smartcloud_control_desk 7.0
ibm maximo_asset_management 6.2.4
ibm tivoli_asset_management_for_it 6.2
ibm maximo_asset_management 6.2.1
ibm maximo_asset_management 7.5.0.6
ibm maximo_asset_management 6.5
ibm tivoli_asset_management_for_it 7.1
ibm maximo_asset_management 6.1
ibm maximo_asset_management 7.5.0.0
ibm maximo_asset_management 7.1.1.7
ibm smartcloud_control_desk 7.5.1.1
ibm maximo_asset_management 6.2
ibm maximo_asset_management 6.2.2
ibm maximo_asset_management 7.5.0.4
ibm smartcloud_control_desk 7.5.0.2
ibm smartcloud_control_desk 7.5
ibm maximo_asset_management 7.5.0.5
ibm maximo_asset_management 7.1.1.2
ibm smartcloud_control_desk 7.5.0.1
ibm maximo_asset_management 7.1.1.6
ibm maximo_asset_management 7.1.1.5
ibm smartcloud_control_desk 7.5.1.0
ibm maximo_asset_management 7.1.1.11
ibm maximo_asset_management 7.1.2
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
ibm smartcloud_control_desk 7.5.0.3
CVE-2014-3085 HIGH

systest.php on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the lpres parameter.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-78,

Products Affected

Vendor Product Version
ibm global_console_manager_32_firmware *
ibm global_console_manager_16_firmware *
CVE-2014-3086 HIGH

Unspecified vulnerability in the IBM Java Virtual Machine, as used in IBM WebSphere Real Time 3 before Service Refresh 7 FP1 and other products, allows remote attackers to gain privileges by leveraging the ability to execute code in the context of a security manager.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_real_time 3.0
ibm lotus_notes 8.5.3.0
ibm lotus_domino 8.5.3.0
ibm lotus_domino 9.0.1.0
ibm lotus_notes 9.0.1.0
CVE-2014-3087 MEDIUM

callService.do in IBM Business Process Manager (BPM) 7.5 through 8.5.5 and WebSphere Lombardi Edition 7.2 through 7.2.0.5 allows remote authenticated users to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm business_process_manager 8.0.1.2
ibm business_process_manager 8.0.1.1
ibm business_process_manager 7.5.0.1
ibm websphere_application_server 7.2
ibm business_process_manager 7.5.1.0
ibm business_process_manager 7.5.1.1
ibm business_process_manager 8.5.5.0
ibm business_process_manager 8.0.1.0
ibm business_process_manager 7.5.1.2
ibm business_process_manager 8.0.0.0
ibm business_process_manager 8.5.0.1
ibm business_process_manager 8.5.0.0
ibm business_process_manager 7.5.0.0
CVE-2014-3088 MEDIUM

stconf.nsf in IBM Sametime Meeting Server 8.5.1 relies on the client to validate the file format used in wAttach?OpenForm multipart/form-data POST requests, which allows remote authenticated users to bypass intended upload restrictions by modifying the Content-Type header and file extension, as demonstrated by replacing a text/plain .txt upload with an application/octet-stream .exe upload.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm sametime_meeting_server 8.5.1
CVE-2014-3089 MEDIUM

The RDS Java Client library in IBM Rational Directory Server (RDS) 5.1.1.x before 5.1.1.2 iFix004 and 5.2.x before 5.2.1 iFix003, and Rational Directory Administrator (RDA) 6.0 before iFix002, includes the cleartext root password, which allows local users to obtain sensitive information by reading a library file.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm rational_directory_server 5.2
ibm rational_directory_server 5.2.0.2
ibm rational_directory_server 5.1.1.2
ibm rational_directory_administrator 6.0
ibm rational_directory_administrator 6.0.0.1
ibm rational_directory_server 5.2.1
ibm rational_directory_server 5.1.1.1
ibm rational_directory_server 5.2.0.1
ibm rational_directory_server 5.1.1
CVE-2014-3090 MEDIUM

IBM Rational ClearCase 7.1 before 7.1.2.15, 8.0.0 before 8.0.0.12, and 8.0.1 before 8.0.1.5 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm rational_clearcase 8.0.0.10
ibm rational_clearcase 7.1.2.3
ibm rational_clearcase 8.0.0.1
ibm rational_clearcase 7.1.2.13
ibm rational_clearcase 8.0.1
ibm rational_clearcase 7.1.0.1
ibm rational_clearcase 7.1.2.4
ibm rational_clearcase 8.0.0.7
ibm rational_clearcase 7.1.1.9
ibm rational_clearcase 7.1.2.11
ibm rational_clearcase 8.0.0.3
ibm rational_clearcase 8.0.0.6
ibm rational_clearcase 7.1.2.1
ibm rational_clearcase 8.0.0.8
ibm rational_clearcase 7.1.2.14
ibm rational_clearcase 7.1.1.1
ibm rational_clearcase 7.1.2.2
ibm rational_clearcase 7.1.1.4
ibm rational_clearcase 8.0.0.9
ibm rational_clearcase 7.1.1.6
ibm rational_clearcase 8.0.0
ibm rational_clearcase 8.0.1.3
ibm rational_clearcase 8.0.0.2
ibm rational_clearcase 8.0.0.11
ibm rational_clearcase 7.1.0.2
ibm rational_clearcase 7.1.1.5
ibm rational_clearcase 7.1.1.7
ibm rational_clearcase 7.1.1.8
ibm rational_clearcase 7.1.1.2
ibm rational_clearcase 8.0.1.1
ibm rational_clearcase 8.0.1.2
ibm rational_clearcase 7.1.2.5
ibm rational_clearcase 8.0
ibm rational_clearcase 7.1.1
ibm rational_clearcase 7.1.2.12
ibm rational_clearcase 7.1.2
ibm rational_clearcase 7.1
ibm rational_clearcase 8.0.0.4
ibm rational_clearcase 7.1.2.9
ibm rational_clearcase 8.0.0.5
ibm rational_clearcase 7.1.2.7
ibm rational_clearcase 7.1.1.3
ibm rational_clearcase 7.1.2.6
ibm rational_clearcase 8.0.1.4
ibm rational_clearcase 7.1.2.10
CVE-2014-3091 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Security QRadar SIEM 7.1.x and 7.2.x allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.0
ibm qradar_security_information_and_event_manager 7.1.0
CVE-2014-3092 MEDIUM

IBM Jazz Team Server, as used in Rational Collaborative Lifecycle Management; Rational Quality Manager 3.x before 3.0.1.6 iFix 3, 4.x before 4.0.7, and 5.x before 5.0.1; and other Rational products, does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_rhapsody_design_manager 4.0.4
ibm rational_rhapsody_design_manager 4.0.5
ibm rational_doors_next_generation 4.0.0
ibm rational_quality_manager 4.0.6
ibm rational_requirements_composer 3.0.1.4
ibm rational_requirements_composer 3.0.1.1
ibm rational_team_concert 5.0
ibm rational_requirements_composer 2.0
ibm rational_team_concert 2.0.0.2
ibm rational_quality_manager 2.0.1
ibm rational_team_concert 2.0.0.1
ibm rational_quality_manager 4.0.3
ibm rational_engineering_lifecycle_manager 4.05
ibm rational_rhapsody_design_manager 3.0.0.1
ibm rational_team_concert 4.0.1
ibm rational_team_concert 4.0.5
ibm rational_doors_next_generation 5.0
ibm rational_team_concert 4.0.2
ibm rational_engineering_lifecycle_manager 4.04
ibm rational_quality_manager 5.0
ibm rational_requirements_composer 2.0.0.1
ibm rational_software_architect_design_manager 4.0.6
ibm rational_doors_next_generation 4.0.2
ibm rational_team_concert 3.0.1.4
ibm rational_requirements_composer 4.0
ibm rational_team_concert 3.0.1.1
ibm rational_engineering_lifecycle_manager 4.06
ibm rational_quality_manager 2.0.0.1
ibm rational_requirements_composer 3.0
ibm rational_requirements_composer 4.0.4
ibm rational_engineering_lifecycle_manager 5.0
ibm rational_requirements_composer 4.0.1
ibm rational_requirements_composer 3.0.1.2
ibm rational_quality_manager 2.0.1.1
ibm rational_rhapsody_design_manager 5.0
ibm rational_team_concert 4.0.3
ibm rational_quality_manager 3.0.1.3
ibm rational_team_concert 3.0.1
ibm rational_requirements_composer 4.0.0
ibm rational_quality_manager 3.0
ibm rational_requirements_composer 2.0.0.2
ibm rational_quality_manager 2.0
ibm rational_quality_manager 4.0.1
ibm rational_team_concert 4.0.6
ibm rational_engineering_lifecycle_manager 1.0.0.1
ibm rational_quality_manager 3.0.1.2
ibm rational_requirements_composer 4.0.2
ibm rational_requirements_composer 4.0.3
ibm rational_doors_next_generation 4.0.4
ibm rational_quality_manager 3.0.1.4
ibm rational_quality_manager 4.0.4
ibm rational_software_architect_design_manager 4.0.0
ibm rational_rhapsody_design_manager 4.0.3
ibm rational_quality_manager 4.0.2
ibm rational_requirements_composer 4.0.0.2
ibm rational_requirements_composer 4.0.5
ibm rational_software_architect_design_manager 4.0.1
ibm rational_team_concert 3.0.1.6
ibm rational_software_architect_design_manager 3.0.0.1
ibm rational_team_concert 4.0.0.1
ibm rational_software_architect_design_manager 3.0.1
ibm rational_software_architect_design_manager 4.0.2
ibm rational_engineering_lifecycle_manager 4.03
ibm rational_quality_manager 2.0.0.2
ibm rational_quality_manager 4.0.0.1
ibm rational_quality_manager 4.0.0.2
ibm rational_requirements_composer 3.0.1.6
ibm rational_rhapsody_design_manager 4.0.6
ibm rational_engineering_lifecycle_manager 1.0
ibm rational_requirements_composer 4.0.6
ibm rational_software_architect_design_manager 5.0
ibm rational_software_architect_design_manager 4.0.4
ibm rational_doors_next_generation 4.0.1
ibm rational_quality_manager 3.0.1.5
ibm rational_team_concert 3.0.1.2
ibm rational_software_architect_design_manager 4.0.3
ibm rational_requirements_composer 2.0.0.3
ibm rational_rhapsody_design_manager 4.0.1
ibm rational_rhapsody_design_manager 4.0.2
ibm rational_team_concert 4.0.0.2
ibm rational_rhapsody_design_manager 3.0.1
ibm rational_rhapsody_design_manager 4.0
ibm rational_requirements_composer 3.0.1
ibm rational_requirements_composer 3.0.1.3
ibm rational_software_architect_design_manager 3.0
ibm rational_quality_manager 3.0.1.6
ibm rational_team_concert 2.0
ibm rational_quality_manager 3.0.1.1
ibm rational_team_concert 4.0
ibm rational_doors_next_generation 4.0.5
ibm rational_requirements_composer 4.0.0.1
ibm rational_doors_next_generation 4.0.6
ibm rational_team_concert 3.0
ibm rational_doors_next_generation 4.0.3
ibm rational_requirements_composer 2.0.0.4
ibm rational_quality_manager 4.0
ibm rational_requirements_composer 3.0.1.5
ibm rational_team_concert 3.0.1.5
ibm rational_team_concert 3.0.1.3
ibm rational_quality_manager 3.0.1
ibm rational_rhapsody_design_manager 3.0
ibm rational_software_architect_design_manager 3.0.0
ibm rational_software_architect_design_manager 4.0.5
ibm rational_team_concert 4.0.4
ibm rational_quality_manager 4.0.5
CVE-2014-3093 LOW

IBM PowerVC 1.2.0 before FP3 and 1.2.1 before FP2 uses cleartext passwords in (1) api-paste.ini, (2) debug logs, (3) the installation process, (4) environment checks, (5) powervc-ldap-config, (6) powervc-restore, and (7) powervc-diag, which allows local users to obtain sensitive information by entering a ps command or reading a file.

CVSS 2.0

Severity: LOW

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm powervc 1.2.0.2
ibm powervc 1.2.0.1
ibm powervc 1.2.0.0
ibm powervc 1.2.1.1
ibm powervc 1.2.1.0
CVE-2014-3094 HIGH

Stack-based buffer overflow in IBM DB2 9.7 through FP9a, 9.8 through FP5, 10.1 through FP4, and 10.5 before FP4 on Linux, UNIX, and Windows allows remote authenticated users to execute arbitrary code via a crafted ALTER MODULE statement.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2 9.7.0.9
ibm db2 10.1.0.1
ibm db2 10.1.0.3
ibm db2 9.7.0.5
ibm db2 9.7.0.4
ibm db2 9.7.0.6
ibm db2 9.7.0.7
ibm db2 9.7
ibm db2 9.7.0.3
ibm db2 9.7.0.8
ibm db2 10.5.0.1
ibm db2 10.1.0.4
ibm db2 10.5.0.3
ibm db2 10.5.0.2
ibm db2 9.7.0.2
ibm db2 10.1
ibm db2 9.7.0.1
ibm db2 9.8.0.3
ibm db2 9.8.0.5
ibm db2 9.8
ibm db2 9.8.0.4
ibm db2 10.1.0.2
CVE-2014-3095 LOW

The SQL engine in IBM DB2 9.5 through FP10, 9.7 through FP9a, 9.8 through FP5, 10.1 through FP4, and 10.5 before FP4 on Linux, UNIX, and Windows allows remote authenticated users to cause a denial of service (daemon crash) via a crafted UNION clause in a subquery of a SELECT statement.

CVSS 2.0

Severity: LOW

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2 9.5.0.6
ibm db2 9.7.0.9
ibm db2 10.1.0.1
ibm db2 9.7.0.5
ibm db2 9.5.0.5
ibm db2 9.7.0.6
ibm db2 9.5.0.10
ibm db2 9.5.0.1
ibm db2 9.7.0.8
ibm db2 10.5.0.1
ibm db2 10.1.0.4
ibm db2 9.5.0.4
ibm db2 9.5.0.8
ibm db2 10.5.0.2
ibm db2 9.7.0.2
ibm db2 10.1
ibm db2 9.7.0.1
ibm db2 9.8.0.3
ibm db2 9.8
ibm db2 9.5.0.7
ibm db2 9.5.0.3
ibm db2 10.1.0.2
ibm db2 9.5.0.9
ibm db2 10.1.0.3
ibm db2 9.7.0.4
ibm db2 9.7.0.7
ibm db2 9.7
ibm db2 9.7.0.3
ibm db2 10.5.0.3
ibm db2 9.5.0.2
ibm db2 9.5
ibm db2 9.8.0.5
ibm db2 9.8.0.4
CVE-2014-3096 LOW

Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management before 6.0.5.5a allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm curam_social_program_management *
CVE-2014-3097 MEDIUM

Open redirect vulnerability in IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0-TIV-TFIM-IF0015, 6.2.1 before 6.2.1-TIV-TFIM-IF0007, and 6.2.2 before 6.2.2-TIV-TFIM-IF0011 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm tivoli_federated_identity_manager 6.2.1
ibm tivoli_federated_identity_manager 6.2.2
ibm tivoli_federated_identity_manager 6.2.0
CVE-2014-3099 LOW

Unspecified vulnerability in the Security component in IBM Systems Director 6.3.0 through 6.3.5 allows local users to obtain sensitive information via unknown vectors.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm systems_director 6.3.2.0
ibm systems_director 6.3.1.1
ibm systems_director 6.3.3.0
ibm systems_director 6.3.5.0
ibm systems_director 6.3.0.0
ibm systems_director 6.3.1.0
ibm systems_director 6.3.2.1
ibm systems_director 6.3.3.1
ibm systems_director 6.3.2.2
CVE-2014-3101 MEDIUM

The login form in the Web component in IBM Rational ClearQuest 7.1 before 7.1.2.15, 8.0.0 before 8.0.0.12, and 8.0.1 before 8.0.1.5 does not insert a delay after a failed authentication attempt, which makes it easier for remote attackers to obtain access via a brute-force attack.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm rational_clearcase 8.0.0.10
ibm rational_clearcase 7.1.2.3
ibm rational_clearcase 8.0.0.1
ibm rational_clearcase 7.1.2.13
ibm rational_clearcase 8.0.1
ibm rational_clearcase 7.1.0.1
ibm rational_clearcase 7.1.2.4
ibm rational_clearcase 8.0.0.7
ibm rational_clearcase 7.1.1.9
ibm rational_clearcase 7.1.2.11
ibm rational_clearcase 8.0.0.3
ibm rational_clearcase 8.0.0.6
ibm rational_clearcase 7.1.2.1
ibm rational_clearcase 8.0.0.8
ibm rational_clearcase 7.1.2.14
ibm rational_clearcase 7.1.1.1
ibm rational_clearcase 7.1.2.2
ibm rational_clearcase 7.1.1.4
ibm rational_clearcase 8.0.0.9
ibm rational_clearcase 7.1.1.6
ibm rational_clearcase 8.0.1.3
ibm rational_clearcase 8.0.0.2
ibm rational_clearcase 8.0.0.11
ibm rational_clearcase 7.1.0.2
ibm rational_clearcase 7.1.1.5
ibm rational_clearcase 7.1.1.7
ibm rational_clearcase 7.1.1.8
ibm rational_clearcase 7.1.1.2
ibm rational_clearcase 8.0.1.1
ibm rational_clearcase 8.0.1.2
ibm rational_clearcase 7.1.2.5
ibm rational_clearcase 8.0
ibm rational_clearcase 7.1.1
ibm rational_clearcase 7.1.2.12
ibm rational_clearcase 7.1.2
ibm rational_clearcase 7.1
ibm rational_clearcase 8.0.0.4
ibm rational_clearcase 7.1.2.9
ibm rational_clearcase 8.0.0.5
ibm rational_clearcase 7.1.2.7
ibm rational_clearcase 7.1.1.3
ibm rational_clearcase 7.1.2.6
ibm rational_clearcase 8.0.1.4
ibm rational_clearcase 7.1.2.10
CVE-2014-3102 LOW

Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 7.0.0 through 7.0.0.2 CF28 and 8.0.0 before 8.0.0.1 CF13 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.0
ibm websphere_portal 7.0.0.2
ibm websphere_portal 7.0.0.1
ibm websphere_portal 7.0.0.0
CVE-2014-3103 MEDIUM

The Web component in IBM Rational ClearQuest 7.1 before 7.1.2.15, 8.0.0 before 8.0.0.12, and 8.0.1 before 8.0.1.5 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_clearcase 8.0.0.10
ibm rational_clearcase 7.1.2.3
ibm rational_clearcase 8.0.0.1
ibm rational_clearcase 7.1.2.13
ibm rational_clearcase 8.0.1
ibm rational_clearcase 7.1.0.1
ibm rational_clearcase 7.1.2.4
ibm rational_clearcase 8.0.0.7
ibm rational_clearcase 7.1.1.9
ibm rational_clearcase 7.1.2.11
ibm rational_clearcase 8.0.0.3
ibm rational_clearcase 8.0.0.6
ibm rational_clearcase 7.1.2.1
ibm rational_clearcase 8.0.0.8
ibm rational_clearcase 7.1.2.14
ibm rational_clearcase 7.1.1.1
ibm rational_clearcase 7.1.2.2
ibm rational_clearcase 7.1.1.4
ibm rational_clearcase 8.0.0.9
ibm rational_clearcase 7.1.1.6
ibm rational_clearcase 8.0.1.3
ibm rational_clearcase 8.0.0.2
ibm rational_clearcase 8.0.0.11
ibm rational_clearcase 7.1.0.2
ibm rational_clearcase 7.1.1.5
ibm rational_clearcase 7.1.1.7
ibm rational_clearcase 7.1.1.8
ibm rational_clearcase 7.1.1.2
ibm rational_clearcase 8.0.1.1
ibm rational_clearcase 8.0.1.2
ibm rational_clearcase 7.1.2.5
ibm rational_clearcase 8.0
ibm rational_clearcase 7.1.1
ibm rational_clearcase 7.1.2.12
ibm rational_clearcase 7.1.2
ibm rational_clearcase 7.1
ibm rational_clearcase 8.0.0.4
ibm rational_clearcase 7.1.2.9
ibm rational_clearcase 8.0.0.5
ibm rational_clearcase 7.1.2.7
ibm rational_clearcase 7.1.1.3
ibm rational_clearcase 7.1.2.6
ibm rational_clearcase 8.0.1.4
ibm rational_clearcase 7.1.2.10
CVE-2014-3104 MEDIUM

IBM Rational ClearQuest 7.1 before 7.1.2.15, 8.0.0 before 8.0.0.12, and 8.0.1 before 8.0.1.5 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm rational_clearcase 8.0.0.10
ibm rational_clearcase 7.1.2.3
ibm rational_clearcase 8.0.0.1
ibm rational_clearcase 7.1.2.13
ibm rational_clearcase 8.0.1
ibm rational_clearcase 7.1.0.1
ibm rational_clearcase 7.1.2.4
ibm rational_clearcase 8.0.0.7
ibm rational_clearcase 7.1.1.9
ibm rational_clearcase 7.1.2.11
ibm rational_clearcase 8.0.0.3
ibm rational_clearcase 8.0.0.6
ibm rational_clearcase 7.1.2.1
ibm rational_clearcase 8.0.0.8
ibm rational_clearcase 7.1.2.14
ibm rational_clearcase 7.1.1.1
ibm rational_clearcase 7.1.2.2
ibm rational_clearcase 7.1.1.4
ibm rational_clearcase 8.0.0.9
ibm rational_clearcase 7.1.1.6
ibm rational_clearcase 8.0.1.3
ibm rational_clearcase 8.0.0.2
ibm rational_clearcase 8.0.0.11
ibm rational_clearcase 7.1.0.2
ibm rational_clearcase 7.1.1.5
ibm rational_clearcase 7.1.1.7
ibm rational_clearcase 7.1.1.8
ibm rational_clearcase 7.1.1.2
ibm rational_clearcase 8.0.1.1
ibm rational_clearcase 8.0.1.2
ibm rational_clearcase 7.1.2.5
ibm rational_clearcase 8.0
ibm rational_clearcase 7.1.1
ibm rational_clearcase 7.1.2.12
ibm rational_clearcase 7.1.2
ibm rational_clearcase 7.1
ibm rational_clearcase 8.0.0.4
ibm rational_clearcase 7.1.2.9
ibm rational_clearcase 8.0.0.5
ibm rational_clearcase 7.1.2.7
ibm rational_clearcase 7.1.1.3
ibm rational_clearcase 7.1.2.6
ibm rational_clearcase 8.0.1.4
ibm rational_clearcase 7.1.2.10
CVE-2014-3105 MEDIUM

The OSLC integration feature in the Web component in IBM Rational ClearQuest 7.1 before 7.1.2.15, 8.0.0 before 8.0.0.12, and 8.0.1 before 8.0.1.5 provides different error messages for failed login attempts depending on whether the username exists, which allows remote attackers to enumerate account names via a series of requests.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_clearcase 8.0.0.10
ibm rational_clearcase 7.1.2.3
ibm rational_clearcase 8.0.0.1
ibm rational_clearcase 7.1.2.13
ibm rational_clearcase 8.0.1
ibm rational_clearcase 7.1.0.1
ibm rational_clearcase 7.1.2.4
ibm rational_clearcase 8.0.0.7
ibm rational_clearcase 7.1.1.9
ibm rational_clearcase 7.1.2.11
ibm rational_clearcase 8.0.0.3
ibm rational_clearcase 8.0.0.6
ibm rational_clearcase 7.1.2.1
ibm rational_clearcase 8.0.0.8
ibm rational_clearcase 7.1.2.14
ibm rational_clearcase 7.1.1.1
ibm rational_clearcase 7.1.2.2
ibm rational_clearcase 7.1.1.4
ibm rational_clearcase 8.0.0.9
ibm rational_clearcase 7.1.1.6
ibm rational_clearcase 8.0.1.3
ibm rational_clearcase 8.0.0.2
ibm rational_clearcase 8.0.0.11
ibm rational_clearcase 7.1.0.2
ibm rational_clearcase 7.1.1.5
ibm rational_clearcase 7.1.1.7
ibm rational_clearcase 7.1.1.8
ibm rational_clearcase 7.1.1.2
ibm rational_clearcase 8.0.1.1
ibm rational_clearcase 8.0.1.2
ibm rational_clearcase 7.1.2.5
ibm rational_clearcase 8.0
ibm rational_clearcase 7.1.1
ibm rational_clearcase 7.1.2.12
ibm rational_clearcase 7.1.2
ibm rational_clearcase 7.1
ibm rational_clearcase 8.0.0.4
ibm rational_clearcase 7.1.2.9
ibm rational_clearcase 8.0.0.5
ibm rational_clearcase 7.1.2.7
ibm rational_clearcase 7.1.1.3
ibm rational_clearcase 7.1.2.6
ibm rational_clearcase 8.0.1.4
ibm rational_clearcase 7.1.2.10
CVE-2014-3106 MEDIUM

IBM Rational ClearQuest 7.1 before 7.1.2.15, 8.0.0 before 8.0.0.12, and 8.0.1 before 8.0.1.5 does not properly implement the Local Access Only protection mechanism, which allows remote attackers to bypass authentication and read files via the Help Server Administration feature.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm rational_clearcase 8.0.0.10
ibm rational_clearcase 7.1.2.3
ibm rational_clearcase 8.0.0.1
ibm rational_clearcase 7.1.2.13
ibm rational_clearcase 8.0.1
ibm rational_clearcase 7.1.0.1
ibm rational_clearcase 7.1.2.4
ibm rational_clearcase 8.0.0.7
ibm rational_clearcase 7.1.1.9
ibm rational_clearcase 7.1.2.11
ibm rational_clearcase 8.0.0.3
ibm rational_clearcase 8.0.0.6
ibm rational_clearcase 7.1.2.1
ibm rational_clearcase 8.0.0.8
ibm rational_clearcase 7.1.2.14
ibm rational_clearcase 7.1.1.1
ibm rational_clearcase 7.1.2.2
ibm rational_clearcase 7.1.1.4
ibm rational_clearcase 8.0.0.9
ibm rational_clearcase 7.1.1.6
ibm rational_clearcase 8.0.1.3
ibm rational_clearcase 8.0.0.2
ibm rational_clearcase 8.0.0.11
ibm rational_clearcase 7.1.0.2
ibm rational_clearcase 7.1.1.5
ibm rational_clearcase 7.1.1.7
ibm rational_clearcase 7.1.1.8
ibm rational_clearcase 7.1.1.2
ibm rational_clearcase 8.0.1.1
ibm rational_clearcase 8.0.1.2
ibm rational_clearcase 7.1.2.5
ibm rational_clearcase 8.0
ibm rational_clearcase 7.1.1
ibm rational_clearcase 7.1.2.12
ibm rational_clearcase 7.1.2
ibm rational_clearcase 7.1
ibm rational_clearcase 8.0.0.4
ibm rational_clearcase 7.1.2.9
ibm rational_clearcase 8.0.0.5
ibm rational_clearcase 7.1.2.7
ibm rational_clearcase 7.1.1.3
ibm rational_clearcase 7.1.2.6
ibm rational_clearcase 8.0.1.4
ibm rational_clearcase 7.1.2.10
CVE-2014-3566 MEDIUM

The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 3.4 LOW CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N 1.6 1.4
134c704f-9b21-4f2e-91b3-4a467353bcc0 3.4 LOW CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N 1.6 1.4

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,CWE-329,

Products Affected

Vendor Product Version
openssl openssl 0.9.8d
netbsd netbsd 6.1.1
netbsd netbsd 5.2.1
netbsd netbsd 6.0.3
openssl openssl 1.0.1e
redhat enterprise_linux_workstation 7.0
openssl openssl 1.0.1g
netbsd netbsd 6.0.2
openssl openssl 1.0.1h
debian debian_linux 7.0
netbsd netbsd 6.0.6
redhat enterprise_linux_workstation 6.0
openssl openssl 1.0.1a
novell suse_linux_enterprise_desktop 12.0
netbsd netbsd 6.1.4
netbsd netbsd 5.2.2
openssl openssl 0.9.8u
novell suse_linux_enterprise_desktop 10.0
netbsd netbsd 6.1.5
ibm vios 2.2.1.0
netbsd netbsd 6.1.2
openssl openssl 1.0.1i
ibm vios 2.2.1.8
ibm vios 2.2.2.1
ibm vios 2.2.1.4
openssl openssl 0.9.8y
novell suse_linux_enterprise_server 12.0
redhat enterprise_linux_desktop 6.0
fedoraproject fedora 19
ibm aix 7.1
ibm vios 2.2.3.2
fedoraproject fedora 20
redhat enterprise_linux_server_supplementary 5.0
mageia mageia 3.0
openssl openssl 0.9.8g
openssl openssl 0.9.8r
openssl openssl 0.9.8b
ibm vios 2.2.0.11
ibm vios 2.2.2.3
netbsd netbsd 5.1.4
redhat enterprise_linux 5
netbsd netbsd 6.1
openssl openssl 1.0.1c
redhat enterprise_linux_desktop_supplementary 5.0
ibm aix 5.3
ibm vios 2.2.3.1
openssl openssl 0.9.8f
openssl openssl 0.9.8x
ibm vios 2.2.2.4
openssl openssl 1.0.0f
netbsd netbsd 6.0
netbsd netbsd 5.1
redhat enterprise_linux_desktop 7.0
openssl openssl 1.0.0
redhat enterprise_linux_workstation_supplementary 6.0
openssl openssl 0.9.8e
opensuse opensuse 12.3
ibm aix 6.1
ibm vios 2.2.1.1
openssl openssl 0.9.8c
openssl openssl 1.0.0m
ibm vios 2.2.3.3
openssl openssl 0.9.8n
openssl openssl 0.9.8a
netbsd netbsd 6.1.3
openssl openssl 1.0.0k
netbsd netbsd 5.2
netbsd netbsd 6.0.4
netbsd netbsd 5.1.1
openssl openssl 1.0.0h
openssl openssl 0.9.8s
openssl openssl 1.0.0n
openssl openssl 1.0.1
openssl openssl 0.9.8q
ibm vios 2.2.2.2
novell suse_linux_enterprise_software_development_kit 11.0
redhat enterprise_linux_desktop_supplementary 6.0
openssl openssl 0.9.8w
openssl openssl 0.9.8m
openssl openssl 0.9.8z
novell suse_linux_enterprise_software_development_kit 12.0
openssl openssl 0.9.8p
openssl openssl 0.9.8l
openssl openssl 1.0.0i
ibm vios 2.2.1.6
redhat enterprise_linux_server 7.0
ibm vios 2.2.0.10
oracle database 11.2.0.4
ibm vios 2.2.1.9
fedoraproject fedora 21
ibm vios 2.2.0.12
ibm vios 2.2.0.13
openssl openssl 1.0.1f
openssl openssl 1.0.0g
novell suse_linux_enterprise_server 11.0
redhat enterprise_linux_workstation_supplementary 7.0
openssl openssl 0.9.8za
openssl openssl 0.9.8k
ibm vios 2.2.1.7
openssl openssl 1.0.1d
openssl openssl 0.9.8zb
debian debian_linux 8.0
openssl openssl 0.9.8o
opensuse opensuse 13.1
openssl openssl 0.9.8v
openssl openssl 1.0.0e
redhat enterprise_linux_server_supplementary 6.0
openssl openssl 0.9.8t
ibm vios 2.2.2.5
redhat enterprise_linux_server 6.0
oracle database 12.1.0.2
openssl openssl 1.0.0d
ibm vios 2.2.3.0
redhat enterprise_linux_server_supplementary 7.0
openssl openssl 0.9.8
openssl openssl 1.0.0a
openssl openssl 1.0.0b
ibm vios 2.2.2.0
netbsd netbsd 6.0.1
openssl openssl 1.0.0j
apple mac_os_x *
ibm vios 2.2.3.4
ibm vios 2.2.1.5
openssl openssl 0.9.8j
openssl openssl 1.0.0l
netbsd netbsd 5.1.2
mageia mageia 4.0
netbsd netbsd 6.0.5
openssl openssl 0.9.8h
openssl openssl 1.0.0c
ibm vios 2.2.1.3
openssl openssl 1.0.1b
novell suse_linux_enterprise_desktop 11.0
netbsd netbsd 5.1.3
novell suse_linux_enterprise_desktop 9.0
openssl openssl 0.9.8i
CVE-2014-3867 MEDIUM

The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 does not include the HTTPOnly flag in a Set-Cookie header for an unspecified cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie, a different vulnerability than CVE-2013-3984.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm sametime 8.5.0.0
ibm sametime 8.5.2.0
ibm sametime 8.5.2.1
ibm sametime 9.0.0.1
ibm sametime 8.0.0.0
ibm sametime 8.0.2.0
ibm sametime 8.0.2.1
ibm sametime 8.5.1.1
ibm sametime 9.0.0.0
ibm sametime 8.0.1.1
ibm sametime 8.5.1.0
ibm sametime 8.0.1.0
CVE-2014-3977 MEDIUM

libodm.a in IBM AIX 6.1 and 7.1, and VIOS 2.2.x, allows local users to overwrite arbitrary files via a symlink attack on a temporary file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-2179.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-59,

Products Affected

Vendor Product Version
ibm vios 2.2.1.8
ibm aix 6.1
ibm vios 2.2.0.10
ibm vios 2.2.1.1
ibm vios 2.2.1.4
ibm vios 2.2.3.3
ibm aix 7.1
ibm vios 2.2.3.2
ibm vios 2.2.1.9
ibm vios 2.2.0.12
ibm vios 2.2.0.13
ibm vios 2.2.2.5
ibm vios 2.2.1.3
ibm vios 2.2.3.0
ibm vios 2.2.2.0
ibm vios 2.2.2.4
ibm vios 2.2.0.11
ibm vios 2.2.1.0
CVE-2014-4746 MEDIUM

IBM WebSphere Portal 8.0.0 before 8.0.0.1 CF13 and 8.5.0 through CF01 provides different error codes for firewall-traversal requests depending on whether the intranet host exists, which allows remote attackers to map the intranet network via a series of requests.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.0
ibm websphere_portal 8.5.0.0
CVE-2014-4747 LOW

The Classic Meeting Server in IBM Sametime 8.x through 8.5.2.1 allows physically proximate attackers to discover a meeting password hash by leveraging access to an unattended workstation to read HTML source code within a victim's browser.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm sametime 8.5.0.0
ibm sametime 8.5.1.1
ibm sametime 8.5.2.0
ibm sametime 8.5.2.1
ibm sametime 8.0.0.0
ibm sametime 8.0.1.1
ibm sametime 8.5.1.0
ibm sametime 8.0.2.0
ibm sametime 8.0.2.1
ibm sametime 8.0.1.0
CVE-2014-4748 MEDIUM

Cross-site scripting (XSS) vulnerability in the Classic Meeting Server in IBM Sametime 8.x through 8.5.2.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm sametime 8.5.0.0
ibm sametime 8.5.1.1
ibm sametime 8.5.2.0
ibm sametime 8.5.2.1
ibm sametime 8.0.0.0
ibm sametime 8.0.1.1
ibm sametime 8.5.1.0
ibm sametime 8.0.2.0
ibm sametime 8.0.2.1
ibm sametime 8.0.1.0
CVE-2014-4749 MEDIUM

IBM PowerVC 1.2.0 before FixPack3 does not properly use the known_hosts file, which allows man-in-the-middle attackers to spoof SSH servers via an arbitrary server key.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm powervc 1.2.0.2
ibm powervc 1.2.0.1
ibm powervc 1.2.0.0
CVE-2014-4750 LOW

IBM PowerVC Express Edition 1.2.0 before FixPack3 establishes an FTP session for transferring files to a managed IVM, which allows remote attackers to discover credentials by sniffing the network.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm powervc 1.2.0.2
ibm powervc 1.2.0.1
ibm powervc 1.2.0.0
CVE-2014-4751 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Security Access Manager for Mobile 8.0.0.0, 8.0.0.1, and 8.0.0.3 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm security_access_manager_for_mobile 8.0.0.3
ibm security_access_manager_for_mobile 8.0.0.1
ibm security_access_manager_for_mobile 8.0.0.0
CVE-2014-4752 HIGH

IBM System Networking G8052, G8124, G8124-E, G8124-ER, G8264, G8316, and G8264-T switches before 7.9.10.0; EN4093, EN4093R, CN4093, SI4093, EN2092, and G8264CS switches before 7.8.6.0; Flex System Interconnect Fabric before 7.8.6.0; 1G L2-7 SLB switch for Bladecenter before 21.0.21.0; 10G VFSM for Bladecenter before 7.8.14.0; 1:10G switch for Bladecenter before 7.4.8.0; 1G switch for Bladecenter before 5.3.5.0; Server Connectivity Module before 1.1.3.4; System Networking RackSwitch G8332 before 7.7.17.0; and System Networking RackSwitch G8000 before 7.1.7.0 have hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm bladecenter_10g_vfsm_firmware *
ibm server_connectivity_module_firmware *
ibm system_networking_rackswitch__g8124e -
ibm bladecenter_1g -
ibm system_networking_rackswitch__en4093_firmware *
ibm system_networking_rackswitch__si4093_firmware *
ibm system_networking_rackswitch__si4093 -
ibm server_connectivity_module -
ibm system_networking_rackswitch__g8052_firmware *
ibm system_networking_rackswitch__g8264 -
ibm system_networking_rackswitch__g8124_firmware *
ibm system_networking_rackswitch__g8264t -
ibm system_networking_rackswitch__g8332_firmware *
ibm system_networking_rackswitch__en4093r_firmware *
ibm system_networking_rackswitch__g8124 -
ibm bladecenter_1/10g_firmware *
ibm bladecenter_1g_l2-7_slb -
ibm system_networking_rackswitch__g8124e_firmware *
ibm system_networking_rackswitch__g8264cs_firmware *
ibm system_networking_rackswitch__en4093r -
ibm system_networking_rackswitch__g8332 -
ibm system_networking_rackswitch__cn4093_firmware *
ibm system_networking_rackswitch__g8264_firmware *
ibm system_networking_rackswitch__g8316_firmware *
ibm system_networking_rackswitch__g8124er -
ibm system_networking_rackswitch__en2092 -
ibm system_networking_rackswitch__g8316 -
ibm system_networking_rackswitch__g8124er_firmware *
ibm bladecenter_10g_vfsm -
ibm bladecenter_1g_firmware *
ibm bladecenter_1/10g -
ibm system_networking_rackswitch__g8052 -
ibm flex_system_interconnect_fabric -
ibm system_networking_rackswitch__en4093 -
ibm flex_system_interconnect_fabric_firmware *
ibm system_networking_rackswitch__g8264t_firmware *
ibm bladecenter_1g_l2-7_slb_firmware *
ibm system_networking_rackswitch__g8264cs -
ibm system_networking_rackswitch__en2092_firmware *
ibm system_networking_rackswitch__cn4093 -
CVE-2014-4756 LOW

The Administration and Reporting Tool in IBM Rational License Key Server (RLKS) 8.1.4.x before 8.1.4.4 allows remote authenticated users to hijack sessions via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm rational_license_key_server 8.1.4
ibm rational_license_key_server 8.1.4.3
ibm rational_license_key_server 8.1.4.2
CVE-2014-4757 LOW

The Outlook Extension in IBM Content Collector 4.0.0.x before 4.0.0.0-ICC-OE-IF004 allows local users to bypass the intended Reviewer privilege requirement and read e-mail messages from an arbitrary mailbox by invoking the Search function.

CVSS 2.0

Severity: LOW

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm content_collector 4.0.0.1
ibm content_collector 4.0.0.0
ibm content_collector 4.0.0.2
CVE-2014-4758 MEDIUM

IBM Business Process Manager (BPM) 7.5.x through 8.5.5 and WebSphere Lombardi Edition 7.2.x allow remote authenticated users to bypass intended access restrictions and send requests to internal services via a callService URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm business_process_manager 8.0.1.2
ibm business_process_manager 8.0.1.1
ibm business_process_manager 7.5.0.1
ibm websphere_application_server 7.2
ibm websphere_application_server 7.2.0.3
ibm websphere_application_server 7.2.0.2
ibm websphere_application_server 7.2.0.4
ibm business_process_manager 7.5.1.0
ibm websphere_application_server 7.2.0.1
ibm business_process_manager 7.5.1.1
ibm business_process_manager 8.5.5.0
ibm business_process_manager 8.0.1.0
ibm business_process_manager 7.5.1.2
ibm business_process_manager 8.0.0.0
ibm business_process_manager 8.5.0.1
ibm websphere_application_server 7.2.0.5
ibm business_process_manager 8.5.0.0
ibm business_process_manager 7.5.0.0
CVE-2014-4759 MEDIUM

An unspecified Ajax service in the Content Management toolkit in IBM Business Process Manager (BPM) 8.5.x through 8.5.5 allows remote authenticated users to obtain sensitive information by performing a document-attachment search and then reading document properties in the search results.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm business_process_manager 8.5.5.0
ibm business_process_manager 8.5.0.1
ibm business_process_manager 8.5.0.0
CVE-2014-4760 MEDIUM

Open redirect vulnerability in IBM WebSphere Portal 6.1.0.0 through 6.1.0.6 CF27, 6.1.5.0 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF28, 8.0.0 before 8.0.0.1 CF13, and 8.5.0 before CF01 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.0
ibm websphere_portal 6.1.0.3
ibm websphere_portal 7.0.0.1
ibm websphere_portal 6.1.5.2
ibm websphere_portal 6.1.0.2
ibm websphere_portal 6.1.0.4
ibm websphere_portal 7.0.0.2
ibm websphere_portal 8.5.0.0
ibm websphere_portal 6.1.5.0
ibm websphere_portal 6.1.0.6
ibm websphere_portal 6.1.5.3
ibm websphere_portal 7.0.0.0
ibm websphere_portal 6.1.0.1
ibm websphere_portal 6.1.5.1
ibm websphere_portal 6.1.0.5
ibm websphere_portal 6.1.0.0
CVE-2014-4761 MEDIUM

IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, 8.0 before 8.0.0.1 CF14, and 8.5.0 through 8.5.0.0 CF02 allows remote authenticated users to discover credentials by reading HTML source code.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.0
ibm websphere_portal 6.1.0.3
ibm websphere_portal 8.0
ibm websphere_portal 7.0.0.1
ibm websphere_portal 6.1.5.2
ibm websphere_portal 6.1.0.2
ibm websphere_portal 6.1.0.4
ibm websphere_portal 8.0.0.1
ibm websphere_portal 7.0.0.2
ibm websphere_portal 8.5.0.0
ibm websphere_portal 6.1.5.0
ibm websphere_portal 6.1.0.6
ibm websphere_portal 6.1.5.3
ibm websphere_portal 7.0.0.0
ibm websphere_portal 6.1.0.1
ibm websphere_portal 6.1.5.1
ibm websphere_portal 6.1.0.5
ibm websphere_portal 6.1.0.0
CVE-2014-4762 LOW

Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.0 through 8.0.0.1 CF13 and 8.5.0 before CF02 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.1
ibm websphere_portal 8.0.0.0
ibm websphere_portal 8.0
ibm websphere_portal 8.5.0.0
CVE-2014-4763 LOW

Cross-site scripting (XSS) vulnerability in Content Navigator in Content Engine in IBM FileNet Content Manager 5.2.x before 5.2.0.3-P8CPE-IF003 and Content Foundation 5.2.x before 5.2.0.3-P8CPE-IF003 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm filenet_content_foundation 5.2.0
ibm filenet_content_manager 5.2.0
CVE-2014-4764 HIGH

IBM WebSphere Application Server (WAS) 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.3, when Load Balancer for IPv4 Dispatcher is enabled, allows remote attackers to cause a denial of service (Load Balancer crash) via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_application_server 8.0.0.8
ibm websphere_application_server 8.0.0.5
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 8.5.5.0
ibm websphere_application_server 8.5.0.2
ibm websphere_application_server 8.0.0.6
ibm websphere_application_server 8.5.5.2
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 8.0.0.7
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 8.0.0.9
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 8.5.5.1
ibm websphere_application_server 8.0.0.2
CVE-2014-4765 MEDIUM

IBM Maximo Asset Management 7.1 through 7.1.1.13 and 7.5 through 7.5.0.6, Maximo Asset Management 7.5.0 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk, and Maximo Asset Management 7.1 and 7.2 for Tivoli IT Asset Management for IT and certain other products allow remote attackers to obtain sensitive directory information by reading an unspecified error message.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm tivoli_asset_management_for_it 7.2
ibm maximo_asset_management 7.1.1.9
ibm maximo_for_government 7.1
ibm maximo_asset_management 7.1.1.13
ibm maximo_asset_management 7.1.1.10
ibm maximo_asset_management 7.1.1.1
ibm maximo_for_nuclear_power 7.5.0.0
ibm smartcloud_control_desk 7.5.0.5
ibm maximo_asset_management_essentials 7.5.0.0
ibm maximo_for_nuclear_power 7.1
ibm maximo_for_life_sciences 7.1
ibm maximo_asset_management 7.5.0.6
ibm maximo_asset_management 7.1.1.7
ibm smartcloud_control_desk 7.5.1.1
ibm smartcloud_control_desk 7.5.0.2
ibm maximo_asset_management 7.5.0.5
ibm maximo_asset_management 7.1.1.2
ibm maximo_for_oil_and_gas 7.1
ibm maximo_asset_management 7.1.1.5
ibm tivoli_service_request_manager 7.2
ibm smartcloud_control_desk 7.5.1.0
ibm maximo_asset_management 7.1.1.11
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.5.0.1
ibm maximo_for_transportation 7.5.0.0
ibm maximo_asset_management 7.5.0.10
ibm maximo_for_life_sciences 7.5.0.0
ibm maximo_for_utilities 7.1
ibm maximo_for_government 7.5.0.0
ibm change_and_configuration_management_database 7.1
ibm maximo_asset_management 7.1.1.12
ibm change_and_configuration_management_database 7.2
ibm maximo_asset_management 7.5.0.3
ibm maximo_for_utilities 7.5.0.0
ibm tivoli_asset_management_for_it 7.1
ibm maximo_for_transportation 7.1
ibm tivoli_service_request_manager 7.1
ibm maximo_asset_management_essentials 7.1
ibm maximo_asset_management 7.5.0.0
ibm maximo_asset_management 7.5.0.4
ibm maximo_for_oil_and_gas 7.5.0.0
ibm smartcloud_control_desk 7.5.0.1
ibm maximo_asset_management 7.1.1.6
ibm maximo_asset_management 7.1.2
ibm smartcloud_control_desk 7.5.0.3
CVE-2014-4766 MEDIUM

IBM Sametime Classic Meeting Server 8.0.x and 8.5.x allows remote attackers to obtain sensitive information by reading an exported Record and Playback (RAP) file.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm classic_meeting_server 8.5.1.2
ibm classic_meeting_server 8.5
ibm classic_meeting_server 8.0.1
ibm classic_meeting_server 8.0.2
ibm classic_meeting_server 8.5.2.1
CVE-2014-4767 MEDIUM

IBM WebSphere Application Server (WAS) Liberty Profile 8.5.x before 8.5.5.3 does not properly use the Liberty Repository for feature installation, which allows remote authenticated users to execute arbitrary code via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-94,

Products Affected

Vendor Product Version
ibm websphere_application_server 8.5.5.0
ibm websphere_application_server 8.5.0.2
ibm websphere_application_server 8.5.5.2
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 8.5.5.1
CVE-2014-4768 LOW

IBM Unified Extensible Firmware Interface (UEFI) on Flex System x880 X6, System x3850 X6, and System x3950 X6 devices allows remote authenticated users to cause an unspecified temporary denial of service by using privileged access to enable a legacy boot mode.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm uefi *
CVE-2014-4769 MEDIUM

IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.8 allows remote authenticated users to read arbitrary files or send TCP requests to intranet servers via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_commerce 6.0.0.6
ibm websphere_commerce 7.0.0.4
ibm websphere_commerce 7.0.0.6
ibm websphere_commerce 7.0.0.7
ibm websphere_commerce 6.0.0.11
ibm websphere_commerce 6.0.0.1
ibm websphere_commerce 6.0.0.2
ibm websphere_commerce 6.0.0.10
ibm websphere_commerce 7.0.0.3
ibm websphere_commerce 7.0.0.2
ibm websphere_commerce 7.0
ibm websphere_commerce 6.0.0.7
ibm websphere_commerce 6.0.0.8
ibm websphere_commerce 7.0.0.5
ibm websphere_commerce 6.0.0.3
ibm websphere_commerce 6.0.0.0
ibm websphere_commerce 6.0.0.4
ibm websphere_commerce 6.0.0.9
ibm websphere_commerce 7.0.0.1
ibm websphere_commerce 6.0.0.5
ibm websphere_commerce 7.0.0.8
CVE-2014-4770 LOW

Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) 6.x through 6.1.0.47, 7.0 before 7.0.0.35, 8.0 before 8.0.0.10, and 8.5 before 8.5.5.4 allows remote authenticated administrators to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0
ibm websphere_application_server 6.0.2.19
ibm websphere_application_server 6.1.0.14
ibm websphere_application_server 7.0.0.12
ibm websphere_application_server 8.0.0.6
ibm websphere_application_server 6.0.2.7
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 7.0.0.16
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 8.0.0.9
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 7.0.0.31
ibm websphere_application_server 7.0.0.10
ibm websphere_application_server 8.0.0.8
ibm websphere_application_server 6.0.2.25
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 8.0.0.7
ibm websphere_application_server 6.0.2.9
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.0.37
ibm websphere_application_server 6.0.2.41
ibm websphere_application_server 6.1.0.47
ibm websphere_application_server 8.0.0.2
ibm websphere_application_server 6.0.2.13
ibm websphere_application_server 6.0.1.11
ibm websphere_application_server 8.0.0.5
ibm websphere_application_server 6.0.2.15
ibm websphere_application_server 7.0.0.33
ibm websphere_application_server 6.0.2.4
ibm websphere_application_server 6.1.0
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 6.1
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.41
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.0.2.6
ibm websphere_application_server 7.0.0.24
ibm websphere_application_server 8.5.5.0
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.0.2.37
ibm websphere_application_server 6.0.2.24
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 6.0.2.5
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.0.1.1
ibm websphere_application_server 6.0.2.1
ibm websphere_application_server 6.0.1.5
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 6.0.0.1
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 8.5.5.2
ibm websphere_application_server 6.0.0.2
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0.35
ibm websphere_application_server 7.0.0.25
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.14
ibm websphere_application_server 6.0.2.39
ibm websphere_application_server 7.0.0.22
ibm websphere_application_server 6.0.2.33
ibm websphere_application_server 6.0.1.2
ibm websphere_application_server 6.0.1.17
ibm websphere_application_server 6.0.1.13
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 6.0.2.31
ibm websphere_application_server 6.1.0.39
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 6.0.2.35
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 7.0.0.27
ibm websphere_application_server 6.0.2.22
ibm websphere_application_server 7.0.0.18
ibm websphere_application_server 6.0
ibm websphere_application_server 6.0.1.3
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 8.5.5.3
ibm websphere_application_server 6.0.2.43
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 6.0.2.2
ibm websphere_application_server 6.0.2.11
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 6.0.1.15
ibm websphere_application_server 8.5.0.2
ibm websphere_application_server 6.1.0.45
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 6.0.2.30
ibm websphere_application_server 6.0.2.32
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 6.0.2.23
ibm websphere_application_server 7.0.0.29
ibm websphere_application_server 6.0.1
ibm websphere_application_server 6.0.1.7
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.0.2.17
ibm websphere_application_server 6.1.0.43
ibm websphere_application_server 6.0.2.3
ibm websphere_application_server 6.0.2.29
ibm websphere_application_server 6.0.1.9
ibm websphere_application_server 6.0.2
ibm websphere_application_server 6.0.2.28
ibm websphere_application_server 6.0.2.27
ibm websphere_application_server 6.0.0.3
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 7.0.0.4
CVE-2014-4771 LOW

IBM WebSphere MQ 7.0.1 before 7.0.1.13, 7.1 before 7.1.0.6, 7.5 before 7.5.0.5, and 8 before 8.0.0.1 allows remote authenticated users to cause a denial of service (queue-slot exhaustion) by leveraging PCF query privileges for a crafted query.

CVSS 2.0

Severity: LOW

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm websphere_mq 8.0.0.0
ibm websphere_mq 7.5.0.1
ibm websphere_mq 7.0.1.7
ibm websphere_mq 7.0.1.12
ibm websphere_mq 7.0.1.1
ibm websphere_mq 7.0.1.3
ibm websphere_mq 7.5
ibm websphere_mq 7.5.0.2
ibm websphere_mq 7.1.0.5
ibm websphere_mq 7.5.0.3
ibm websphere_mq 7.1.0.4
ibm websphere_mq 7.0.1.9
ibm websphere_mq 7.1.0.2
ibm websphere_mq 7.0.1.6
ibm websphere_mq 7.1.0.3
ibm websphere_mq 7.5.0.4
ibm websphere_mq 7.0.1.0
ibm websphere_mq 7.0.1.5
ibm websphere_mq 7.1
ibm websphere_mq 7.0.1.8
ibm websphere_mq 7.0.1.10
ibm websphere_mq 7.0.1.11
ibm websphere_mq 7.0.1.4
ibm websphere_mq 7.0.1.2
ibm websphere_mq 7.1.0.1
CVE-2014-4774 MEDIUM

Cross-site request forgery (CSRF) vulnerability in the login page in IBM License Metric Tool 9 before 9.1.0.2 and Endpoint Manager for Software Use Analysis 9 before 9.1.0.2 allows remote attackers to hijack the authentication of arbitrary users via vectors involving a FRAME element.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm endpoint_manager_family 9.1.0
ibm license_metric_tool 9.0
ibm endpoint_manager_family 9.0.1
ibm license_metric_tool 9.1.0.1
ibm license_metric_tool 9.0.1
CVE-2014-4775 MEDIUM

IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1-FP11 and 11.x before 11.0-FP5 and InfoSphere Master Data Management Server for Product Information Management 9.x before 9.1-FP15 and 10.x and 11.x before 11.3-IF2 do not properly protect credentials, which allows remote attackers to obtain sensitive information via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm infosphere_master_data_management 10.0
ibm infosphere_master_data_management_server_for_product_information_management 9.1
ibm infosphere_master_data_management_server_for_product_information_management 9.0
ibm infosphere_master_data_management 11.0
ibm infosphere_master_data_management 10.1
ibm infosphere_master_data_management 11.3
CVE-2014-4776 LOW

IBM License Metric Tool 9 before 9.1.0.2 does not have an off autocomplete attribute for authentication fields, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm license_metric_tool 9.0
ibm license_metric_tool 9.1.0.1
ibm license_metric_tool 9.0.1
CVE-2014-4778 MEDIUM

IBM License Metric Tool 9 before 9.1.0.2 and Endpoint Manager for Software Use Analysis 9 before 9.1.0.2 do not send an X-Frame-Options HTTP header in response to requests for the login page, which allows remote attackers to conduct clickjacking attacks via vectors involving a FRAME element.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm endpoint_manager_family 9.1.0
ibm license_metric_tool 9.0
ibm endpoint_manager_family 9.0.1
ibm license_metric_tool 9.1.0.1
ibm license_metric_tool 9.0.1
CVE-2014-4781 MEDIUM

The alert module in IBM InfoSphere BigInsights 2.1.2 and 3.x before 3.0.0.2 allows remote attackers to obtain sensitive Alert management-services API information via a network-tracing attack.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm infosphere_biginsights 3.0.0.1
ibm infosphere_biginsights 2.1.2.0
ibm infosphere_biginsights 3.0.0.0
CVE-2014-4782 MEDIUM

IBM InfoSphere BigInsights 2.1.2 allows remote authenticated users to discover SMTP server credentials via vectors related to the Alert management service. IBM X-Force ID: 95029.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm infosphere_biginsights 2.1.2
CVE-2014-4783 MEDIUM

Cross-site request forgery (CSRF) vulnerability in IBM Initiate Master Data Service 9.5 before 9.5.093013, 9.7 before 9.7.093013, 10.0 before 10.0.093013, and 10.1 before 10.1.093013 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm initiate_master_data_service 9.5
ibm initiate_master_data_service 10.0
ibm initiate_master_data_service 10.1
ibm initiate_master_data_service 9.7
CVE-2014-4784 MEDIUM

IBM Initiate Master Data Service 9.5 before 9.5.093013, 9.7 before 9.7.093013, 10.0 before 10.0.093013, and 10.1 before 10.1.093013 does not properly restrict use of FRAME elements, which allows remote attackers to conduct phishing attacks, and bypass intended access restrictions or obtain sensitive information, via a crafted web site, related to a "frame injection" issue.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm initiate_master_data_service 9.5
ibm initiate_master_data_service 10.0
ibm initiate_master_data_service 10.1
ibm initiate_master_data_service 9.7
CVE-2014-4785 MEDIUM

Cross-site request forgery (CSRF) vulnerability in IBM Initiate Master Data Service 9.5 before 9.5.093013, 9.7 before 9.7.093013, 10.0 before 10.0.093013, and 10.1 before 10.1.093013 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm initiate_master_data_service 9.5
ibm initiate_master_data_service 10.0
ibm initiate_master_data_service 10.1
ibm initiate_master_data_service 9.7
CVE-2014-4786 MEDIUM

IBM Initiate Master Data Service 9.5 before 9.5.093013, 9.7 before 9.7.093013, 10.0 before 10.0.093013, and 10.1 before 10.1.093013 does not properly restrict use of FRAME elements, which allows remote authenticated users to conduct phishing attacks, and bypass intended access restrictions or obtain sensitive information, via a crafted web site, related to a "frame injection" issue.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm initiate_master_data_service 9.5
ibm initiate_master_data_service 10.0
ibm initiate_master_data_service 10.1
ibm initiate_master_data_service 9.7
CVE-2014-4787 LOW

Cross-site scripting (XSS) vulnerability in IBM Initiate Master Data Service 9.5 before 9.5.093013, 9.7 before 9.7.093013, 10.0 before 10.0.093013, and 10.1 before 10.1.093013 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm initiate_master_data_service 9.5
ibm initiate_master_data_service 10.0
ibm initiate_master_data_service 10.1
ibm initiate_master_data_service 9.7
CVE-2014-4788 MEDIUM

IBM Initiate Master Data Service 9.5 before 9.5.093013, 9.7 before 9.7.093013, 10.0 before 10.0.093013, and 10.1 before 10.1.093013 does not have an off autocomplete attribute for authentication fields, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm initiate_master_data_service 9.5
ibm initiate_master_data_service 10.0
ibm initiate_master_data_service 10.1
ibm initiate_master_data_service 9.7
CVE-2014-4789 MEDIUM

Session fixation vulnerability in IBM Initiate Master Data Service 9.5 before 9.5.093013, 9.7 before 9.7.093013, 10.0 before 10.0.093013, and 10.1 before 10.1.093013 allows remote attackers to hijack web sessions via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-384,

Products Affected

Vendor Product Version
ibm initiate_master_data_service 9.5
ibm initiate_master_data_service 10.0
ibm initiate_master_data_service 10.1
ibm initiate_master_data_service 9.7
CVE-2014-4790 MEDIUM

IBM Emptoris Sourcing Portfolio 9.5.x before 9.5.1.3, 10.0.0.x before 10.0.0.1, 10.0.1.x before 10.0.1.3, and 10.0.2.x before 10.0.2.4 and Emptoris Spend Analysis 9.5.x before 9.5.0.4, 10.0.1.x before 10.0.1.3, and 10.0.2.x before 10.0.2.4 do not properly restrict use of FRAME elements, which allows remote authenticated users to conduct phishing attacks, and bypass intended access restrictions or obtain sensitive information, via a crafted web site, related to a "frame injection" issue.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm emptoris_sourcing_portfolio 9.5.1.0
ibm emptoris_sourcing_portfolio 10.0.2.2
ibm emptoris_spend_analysis 10.0.2.0
ibm emptoris_sourcing_portfolio 9.5.0.2
ibm emptoris_sourcing_portfolio 9.5.1.2
ibm emptoris_sourcing_portfolio 10.0.0.0
ibm emptoris_sourcing_portfolio 9.5.0.1
ibm emptoris_spend_analysis 9.5.0.3
ibm emptoris_sourcing_portfolio 10.0.1.0
ibm emptoris_sourcing_portfolio 9.5.1.1
ibm emptoris_spend_analysis 10.0.1.1
ibm emptoris_sourcing_portfolio 10.0.2.0
ibm emptoris_sourcing_portfolio 10.0.2.3
ibm emptoris_spend_analysis 9.5.0.0
ibm emptoris_sourcing_portfolio 10.0.1.1
ibm emptoris_spend_analysis 10.0.1.2
ibm emptoris_spend_analysis 10.0.1.0
ibm emptoris_spend_analysis 10.0.2.2
ibm emptoris_sourcing_portfolio 9.5.0.0
ibm emptoris_spend_analysis 9.5.0.2
ibm emptoris_sourcing_portfolio 10.0.1.2
ibm emptoris_spend_analysis 9.5.0.1
CVE-2014-4792 MEDIUM

IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF28, 8.0.0 through 8.0.0.1 CF13, and 8.5.0 before CF02 allows remote authenticated users to cause a denial of service (disk consumption) by uploading large files.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.0
ibm websphere_portal 6.1.0.3
ibm websphere_portal 8.0
ibm websphere_portal 6.0.0.0
ibm websphere_portal 7.0.0.1
ibm websphere_portal 6.1.5.2
ibm websphere_portal 6.1.0.2
ibm websphere_portal 6.0.1.6
ibm websphere_portal 6.1.0.4
ibm websphere_portal 8.0.0.1
ibm websphere_portal 7.0.0.2
ibm websphere_portal 8.5.0.0
ibm websphere_portal 6.0.0.1
ibm websphere_portal 6.1.5.0
ibm websphere_portal 6.1.0.6
ibm websphere_portal 6.1.5.3
ibm websphere_portal 7.0.0.0
ibm websphere_portal 6.1.0.1
ibm websphere_portal 6.1.5.1
ibm websphere_portal 6.1.0.5
ibm websphere_portal 6.1.0.0
CVE-2014-4793 MEDIUM

IBM WebSphere MQ 8.x before 8.0.0.1 does not properly enforce CHLAUTH rules for blocking client connections in certain circumstances related to the CONNAUTH attribute, which allows remote authenticated users to bypass intended queue-manager access restrictions via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_mq 8.0.0.0
CVE-2014-4801 LOW

Cross-site scripting (XSS) vulnerability in IBM Rational Quality Manager 2.x through 2.0.1.1, 3.x before 3.0.1.6 iFix 4, 4.x before 4.0.7 iFix 2, and 5.x before 5.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager 4.0.3
ibm rational_quality_manager 3.0.1.5
ibm rational_quality_manager 2.0.0.1
ibm rational_quality_manager 3.0.1.1
ibm rational_quality_manager 3.0.1.2
ibm rational_quality_manager 5.0.0
ibm rational_quality_manager 3.0.1
ibm rational_quality_manager 3.0.1.4
ibm rational_quality_manager 4.0.4
ibm rational_quality_manager 4.0.6
ibm rational_quality_manager 2.0.0.2
ibm rational_quality_manager 4.0.0.1
ibm rational_quality_manager 4.0.0.2
ibm rational_quality_manager 4.0.5
ibm rational_quality_manager 3.0.1.3
ibm rational_quality_manager 4.0.7
ibm rational_quality_manager 4.0.2
ibm rational_quality_manager 4.0
ibm rational_quality_manager 3.0
ibm rational_quality_manager 2.0.1
ibm rational_quality_manager 3.0.1.6
ibm rational_quality_manager 2.0
ibm rational_quality_manager 4.0.1
CVE-2014-4802 MEDIUM

The Saved Search Admin component in the Process Admin Console in IBM Business Process Manager (BPM) 8.0 through 8.5.5 does not properly restrict task and instance listings in result sets, which allows remote authenticated users to bypass authorization checks and obtain sensitive information by executing a saved search.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm business_process_manager 8.0.1.2
ibm business_process_manager 8.0.1.1
ibm business_process_manager 8.5.5.0
ibm business_process_manager 8.0.1.0
ibm business_process_manager 8.0.0.0
ibm business_process_manager 8.5.0.1
ibm business_process_manager 8.0.1.3
ibm business_process_manager 8.5.0.0
CVE-2014-4803 LOW

CRLF injection vulnerability in the Universal Access implementation in IBM Curam Social Program Management 6.0 SP2 before EP26, 6.0.4 before 6.0.4.5 iFix007, and 6.0.5 before 6.0.5.5 iFix003, when WebSphere Application Server is not used, allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via an unspecified parameter.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm curam_social_program_management 6.0.4.3
ibm curam_social_program_management 6.0.5.4
ibm curam_social_program_management 6.0.4.4
ibm curam_social_program_management 6.0.4.1
ibm curam_social_program_management 6.0.4.0
ibm curam_social_program_management 6.0.5.0
ibm curam_social_program_management 6.0.5.5
ibm curam_social_program_management 6.0.5.2
ibm curam_social_program_management 6.0.5.1
ibm curam_social_program_management *
ibm curam_social_program_management 6.0.5.3
ibm curam_social_program_management 6.0.4.2
ibm curam_social_program_management 6.0.4.5
CVE-2014-4804 MEDIUM

Curam Universal Access in IBM Curam Social Program Management 5.2 before SP6 EP6, 6.0 SP2 before EP26, 6.0.4.5 before iFix007, 6.0.5.4 before iFix005, and 6.0.5.5 before iFix003, when SPI inclusion is enabled, allows remote attackers to obtain sensitive user data by visiting an unspecified page.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm curam_social_program_management 6.0
ibm curam_social_program_management 6.0.5.4
ibm curam_social_program_management *
ibm curam_social_program_management 6.0.4.5
ibm curam_social_program_management 6.0.5.5
CVE-2014-4805 LOW

IBM DB2 10.5 before FP4 on Linux and AIX creates temporary files during CDE table LOAD operations, which allows local users to obtain sensitive information by reading a file while a LOAD is occurring.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2 10.5.0.1
ibm db2 10.5.0.3
ibm db2 10.5.0.2
CVE-2014-4806 LOW

The installation process in IBM Security AppScan Enterprise 8.x before 8.6.0.2 iFix 003, 8.7.x before 8.7.0.1 iFix 003, 8.8.x before 8.8.0.1 iFix 002, and 9.0.x before 9.0.0.1 iFix 001 on Linux places a cleartext password in a temporary file, which allows local users to obtain sensitive information by reading this file.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 5.5 MEDIUM CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N 1.8 3.6

CVSS 2.0

Severity: LOW

Problem Type: CWE-522,

Products Affected

Vendor Product Version
ibm security_appscan *
CVE-2014-4807 MEDIUM

Sterling Order Management in IBM Sterling Selling and Fulfillment Suite 9.3.0 before FP8 allows remote authenticated users to cause a denial of service (CPU consumption) via a '\0' character.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm sterling_selling_and_fulfillment_foundation *
ibm sterling_selling_and_fulfillment_foundation 9.3.0.4
ibm sterling_selling_and_fulfillment_foundation 9.3.0.2
ibm sterling_selling_and_fulfillment_foundation 9.3.0.5
ibm sterling_selling_and_fulfillment_foundation 9.3.0.3
ibm sterling_selling_and_fulfillment_foundation 9.3.0
ibm sterling_selling_and_fulfillment_foundation 9.3.0.6
ibm sterling_selling_and_fulfillment_foundation 9.3.0.1
CVE-2014-4808 MEDIUM

Unspecified vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, 8.0 through 8.0.0.1 CF14, and 8.5.0 before CF03 allows remote authenticated users to execute arbitrary code via unknown vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.0
ibm websphere_portal 6.1.0.3
ibm websphere_portal 7.0.0.1
ibm websphere_portal 6.1.5.2
ibm websphere_portal 6.1.0.2
ibm websphere_portal 6.1.0.4
ibm websphere_portal 8.0.0.1
ibm websphere_portal 7.0.0.2
ibm websphere_portal 6.1.5.0
ibm websphere_portal 6.1.0.6
ibm websphere_portal 6.1.5.3
ibm websphere_portal 7.0.0.0
ibm websphere_portal 6.1.0.1
ibm websphere_portal 6.1.5.1
ibm websphere_portal 6.1.0.5
ibm websphere_portal 6.1.0.0
CVE-2014-4809 HIGH

The WebSEAL component in IBM Security Access Manager for Web 7.x before 7.0.0-ISS-WGA-IF0009 and 8.x before 8.0.0-ISS-WGA-FP0005, when e-community SSO is enabled, allows remote attackers to cause a denial of service (component hang) via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm security_access_manager_for_web_7.0_firmware 7.0.0.5
ibm security_access_manager_for_web_7.0_firmware 7.0.0.6
ibm security_access_manager_for_web_7.0_firmware 7.0.0.1
ibm security_access_manager_for_web_7.0_firmware 7.0.0.7
ibm security_access_manager_for_web_7.0_firmware 7.0.0.2
ibm security_access_manager_for_web_8.0_firmware 8.0.0.2
ibm security_access_manager_for_web_7.0_firmware 7.0.0.4
ibm security_access_manager_for_web_8.0_firmware 8.0.0.4
ibm security_access_manager_for_web_8.0_firmware 8.0.0.3
ibm security_access_manager_for_web_appliance 7.0
ibm security_access_manager_for_web_7.0_firmware 7.0.0.0
ibm security_access_manager_for_web_7.0_firmware 7.0.0.3
ibm security_access_manager_for_web_7.0_firmware 7.0.0.8
ibm security_access_manager_for_web_appliance 8.0
CVE-2014-4810 MEDIUM

IBM Cognos Mobile 10.1.1 before FP3 IF1, 10.2.0 before FP2 IF1, and 10.2.1 before FP4 IF1 preserves a session between the Cognos Mobile server and the Cognos Business Intelligence server after a logoff action on a mobile device, which makes it easier for remote attackers to bypass intended Business Intelligence restrictions by leveraging access to authentication data that was captured before this logoff.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm cognos_mobile 10.2.1
ibm cognos_mobile 10.2.0
ibm cognos_mobile 10.1.1
CVE-2014-4811 HIGH

IBM Storwize 3500, 3700, 5000, and 7000 devices and SAN Volume Controller 6.x and 7.x before 7.2.0.8 allow remote attackers to reset the administrator superuser password to its default value via a direct request to the administrative IP address.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm san_volume_controller_software 7.2.0.5
ibm san_volume_controller_software 6.2.0.5
ibm san_volume_controller_software 6.4.0.3
ibm san_volume_controller_software 7.1.0.2
ibm san_volume_controller_software 6.2.0.4
ibm san_volume_controller_software 6.1.0.2
ibm san_volume_controller_software 7.1.0.6
ibm san_volume_controller_software 6.2.0.2
ibm san_volume_controller_software 7.2.0.3
ibm storwize_v3500 -
ibm san_volume_controller_software 7.1.0.0
ibm san_volume_controller_software 6.4.0.2
ibm san_volume_controller_software 6.4.1.1
ibm san_volume_controller_software 7.1.0.1
ibm san_volume_controller_software 7.1.0.3
ibm san_volume_controller_software 6.3.0.4
ibm san_volume_controller_software 7.2.0.7
ibm san_volume_controller_software 6.1.0.9
ibm san_volume_controller_software 6.2.0.3
ibm san_volume_controller_software 6.1.0.5
ibm san_volume_controller_software 6.1.0.1
ibm san_volume_controller_software 7.2.0.1
ibm san_volume_controller_software 6.2.0.0
ibm san_volume_controller_software 6.4.1.5
ibm san_volume_controller_software 6.4.1.8
ibm san_volume_controller_software 6.1.0.3
ibm san_volume_controller_software 6.2.0.6
ibm san_volume_controller_software 6.1.0.4
ibm san_volume_controller_software 6.1.0.7
ibm san_volume_controller_software 7.2.0.6
ibm san_volume_controller_software 6.2.0.1
ibm san_volume_controller_software 6.3.0.7
ibm san_volume_controller_software 6.4.1.6
ibm san_volume_controller_software 6.3.0.3
ibm san_volume_controller_software 6.3.0.2
ibm san_volume_controller_software 6.1.0.8
ibm san_volume_controller_software 7.2.0.4
ibm san_volume_controller_software 7.2.0.2
ibm san_volume_controller_software 6.4.0.4
ibm san_volume_controller_software 6.3.0.6
ibm san_volume_controller_software 6.4.0.0
ibm storwize_v7000 -
ibm san_volume_controller_software 6.1.0.6
ibm san_volume_controller_software 6.4.0.1
ibm san_volume_controller_software 6.1.0.0
ibm san_volume_controller_software 7.1.0.7
ibm san_volume_controller_software 6.3.0.1
ibm san_volume_controller_software 6.1.0.10
ibm san_volume_controller_software 6.4.1.7
ibm storwize_v5000 -
ibm san_volume_controller_software 6.4.1.2
ibm san_volume_controller_software 7.2.0.0
ibm san_volume_controller_software 6.3.0.5
ibm san_volume_controller_software 6.4.1.3
ibm san_volume_controller_software 6.3.0.0
ibm storwize_v3700 -
ibm san_volume_controller_software 6.4.1.4
ibm san_volume_controller_software 7.1.0.5
CVE-2014-4812 LOW

The installer in IBM Security AppScan Source 8.x and 9.x through 9.0.1 has an open network port for a debug service, which allows remote attackers to obtain sensitive information by connecting to this port.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_appscan_source 8.6
ibm security_appscan_source 8.7
ibm security_appscan_source 8.6.0.1
ibm security_appscan_source 8.5.0.1
ibm security_appscan_source 8.6.0.2
ibm security_appscan_source 8.7.0.1
ibm security_appscan_source 8.5
ibm security_appscan_source 8.0
ibm security_appscan_source 9.0.1
ibm security_appscan_source 8.0.0.1
ibm security_appscan_source 9.0
ibm security_appscan_source 8.7.0.0
ibm security_appscan_source 8.0.0.2
ibm security_appscan_source 8.8
ibm security_appscan_source 9.0.0.1
CVE-2014-4813 MEDIUM

Race condition in the client in IBM Tivoli Storage Manager (TSM) 5.4.0.0 through 5.4.3.6, 5.5.0.0 through 5.5.4.3, 6.1.0.0 through 6.1.5.6, 6.2 before 6.2.5.4, 6.3 before 6.3.2.3, 6.4 before 6.4.2.1, and 7.1 before 7.1.1 on UNIX and Linux allows local users to obtain root privileges via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-362,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager 6.1.0
ibm tivoli_storage_manager 5.5.4.1
ibm tivoli_storage_manager 5.4.2
ibm tivoli_storage_manager 5.4.3.2
ibm tivoli_storage_manager 5.4.1
ibm tivoli_storage_manager 5.4.3.4
ibm tivoli_storage_manager 5.5.4
ibm tivoli_storage_manager 6.2.4.7
ibm tivoli_storage_manager 6.3.1
ibm tivoli_storage_manager 6.2.4.4
ibm tivoli_storage_manager 6.1.5.5
ibm tivoli_storage_manager 6.1.2
ibm tivoli_storage_manager 6.1.1
ibm tivoli_storage_manager 6.1.5
ibm tivoli_storage_manager 6.2.4
ibm tivoli_storage_manager 7.1.0
ibm tivoli_storage_manager 6.2.3
ibm tivoli_storage_manager 6.3.2.1
ibm tivoli_storage_manager 5.5.4.2
ibm tivoli_storage_manager 5.4.3.3
ibm tivoli_storage_manager 6.2.0.0
ibm tivoli_storage_manager 5.4.2.2
ibm tivoli_storage_manager 6.3.0.17
ibm tivoli_storage_manager 5.4.3.6
ibm tivoli_storage_manager 6.1.5.6
ibm tivoli_storage_manager 6.3.0.1
ibm tivoli_storage_manager 5.5.1
ibm tivoli_storage_manager 5.5.4.3
ibm tivoli_storage_manager 5.5.3
ibm tivoli_storage_manager 6.3.0.0
ibm tivoli_storage_manager 6.3.2
ibm tivoli_storage_manager 6.4.0.0
ibm tivoli_storage_manager 6.1.4
ibm tivoli_storage_manager 6.4.2
ibm tivoli_storage_manager 5.4.2.4
ibm tivoli_storage_manager 5.4.2.3
ibm tivoli_storage_manager 5.5.0
ibm tivoli_storage_manager 6.1.3
ibm tivoli_storage_manager 5.4.3.0
ibm tivoli_storage_manager 5.5.2
ibm tivoli_storage_manager 6.2.2
ibm tivoli_storage_manager 6.1.5.4
ibm tivoli_storage_manager 6.2.1
CVE-2014-4814 LOW

IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, 8.0 through 8.0.0.1 CF14, and 8.5.0 before CF03 does not properly detect recursion during entity expansion, which allows remote authenticated users to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.

CVSS 2.0

Severity: LOW

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.0
ibm websphere_portal 6.1.0.3
ibm websphere_portal 7.0.0.1
ibm websphere_portal 6.1.5.2
ibm websphere_portal 6.1.0.2
ibm websphere_portal 6.1.0.4
ibm websphere_portal 8.0.0.1
ibm websphere_portal 7.0.0.2
ibm websphere_portal 8.5.0.0
ibm websphere_portal 6.1.5.0
ibm websphere_portal 6.1.0.6
ibm websphere_portal 6.1.5.3
ibm websphere_portal 7.0.0.0
ibm websphere_portal 6.1.0.1
ibm websphere_portal 6.1.5.1
ibm websphere_portal 6.1.0.5
ibm websphere_portal 6.1.0.0
CVE-2014-4815 MEDIUM

Session fixation vulnerability in IBM Rational Lifecycle Integration Adapter for Windchill 1.x before 1.0.1 allows remote attackers to hijack web sessions via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm _ibm_rational_lifecycle_integration_adapter_for_windchill 1.0.0
CVE-2014-4816 MEDIUM

Cross-site request forgery (CSRF) vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 6.x through 6.1.0.47, 7.0 before 7.0.0.35, 8.0 before 8.0.0.10, and 8.5 before 8.5.5.4 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0
ibm websphere_application_server 6.0.2.19
ibm websphere_application_server 6.1.0.14
ibm websphere_application_server 7.0.0.12
ibm websphere_application_server 8.0.0.6
ibm websphere_application_server 6.0.2.7
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 7.0.0.16
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 8.0.0.9
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 7.0.0.31
ibm websphere_application_server 7.0.0.10
ibm websphere_application_server 8.0.0.8
ibm websphere_application_server 6.0.2.25
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 8.0.0.7
ibm websphere_application_server 6.0.2.9
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.0.37
ibm websphere_application_server 6.0.2.41
ibm websphere_application_server 6.1.0.47
ibm websphere_application_server 8.0.0.2
ibm websphere_application_server 6.0.2.13
ibm websphere_application_server 6.0.1.11
ibm websphere_application_server 8.0.0.5
ibm websphere_application_server 6.0.2.15
ibm websphere_application_server 7.0.0.33
ibm websphere_application_server 6.0.2.4
ibm websphere_application_server 6.1.0
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 6.1
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.41
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 6.0.2.6
ibm websphere_application_server 7.0.0.24
ibm websphere_application_server 8.5.5.0
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.0.2.37
ibm websphere_application_server 6.0.2.24
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 6.0.2.5
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 6.0.1.1
ibm websphere_application_server 6.0.2.1
ibm websphere_application_server 6.0.1.5
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 6.0.0.1
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 8.5.5.2
ibm websphere_application_server 6.0.0.2
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0.35
ibm websphere_application_server 7.0.0.25
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.14
ibm websphere_application_server 6.0.2.39
ibm websphere_application_server 7.0.0.22
ibm websphere_application_server 6.0.2.33
ibm websphere_application_server 6.0.1.2
ibm websphere_application_server 6.0.1.17
ibm websphere_application_server 6.0.1.13
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 6.0.2.31
ibm websphere_application_server 6.1.0.39
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 6.0.2.35
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 7.0.0.27
ibm websphere_application_server 6.0.2.22
ibm websphere_application_server 7.0.0.18
ibm websphere_application_server 6.0
ibm websphere_application_server 6.0.1.3
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 8.5.5.3
ibm websphere_application_server 6.0.2.43
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 6.0.2.2
ibm websphere_application_server 6.0.2.11
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 6.0.1.15
ibm websphere_application_server 8.5.0.2
ibm websphere_application_server 6.1.0.45
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 6.0.2.30
ibm websphere_application_server 6.0.2.32
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 6.0.2.23
ibm websphere_application_server 7.0.0.29
ibm websphere_application_server 6.0.1
ibm websphere_application_server 6.0.1.7
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 6.0.2.17
ibm websphere_application_server 6.1.0.43
ibm websphere_application_server 6.0.2.3
ibm websphere_application_server 6.0.2.29
ibm websphere_application_server 6.0.1.9
ibm websphere_application_server 6.0.2
ibm websphere_application_server 6.0.2.28
ibm websphere_application_server 6.0.2.27
ibm websphere_application_server 6.0.0.3
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 7.0.0.4
CVE-2014-4817 LOW

The server in IBM Tivoli Storage Manager (TSM) 5.x and 6.x before 6.3.5.10 and 7.x before 7.1.1.100 allows remote attackers to bypass intended access restrictions and replace file backups by using a certain backup option in conjunction with a filename that matches a previously used filename.

CVSS 2.0

Severity: LOW

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager 5.3.6.4
ibm tivoli_storage_manager 5.5.4.1
ibm tivoli_storage_manager 5.2
ibm tivoli_storage_manager 5.4.3.2
ibm tivoli_storage_manager 5.1.6
ibm tivoli_storage_manager 5.1.8
ibm tivoli_storage_manager 5.3.1
ibm tivoli_storage_manager 5.5.4
ibm tivoli_storage_manager 6.2.4.7
ibm tivoli_storage_manager 6.2.4.4
ibm tivoli_storage_manager 6.3.3
ibm tivoli_storage_manager 6.1.1
ibm tivoli_storage_manager 6.1.5
ibm tivoli_storage_manager 6.2.4
ibm tivoli_storage_manager 6.2.3
ibm tivoli_storage_manager 5.2.5.3
ibm tivoli_storage_manager 5.1.0
ibm tivoli_storage_manager 6.3.2.1
ibm tivoli_storage_manager 5.4.3.3
ibm tivoli_storage_manager 6.3.0
ibm tivoli_storage_manager 5.2.5.1
ibm tivoli_storage_manager 6.0
ibm tivoli_storage_manager 5.3.2
ibm tivoli_storage_manager 5.5.1
ibm tivoli_storage_manager 5.3.5.1
ibm tivoli_storage_manager 5.2.1
ibm tivoli_storage_manager 6.4.1
ibm tivoli_storage_manager 6.3.0.0
ibm tivoli_storage_manager 6.3.2
ibm tivoli_storage_manager 6.4.0.0
ibm tivoli_storage_manager 6.4.2
ibm tivoli_storage_manager 5.1.7
ibm tivoli_storage_manager 5.4.2.3
ibm tivoli_storage_manager 6.4.0
ibm tivoli_storage_manager 5.5.0
ibm tivoli_storage_manager 6.1.3
ibm tivoli_storage_manager 5.4.3.0
ibm tivoli_storage_manager 5.2.2
ibm tivoli_storage_manager 5.3.6.5
ibm tivoli_storage_manager 5.3.2.4
ibm tivoli_storage_manager 5.1.9
ibm tivoli_storage_manager 6.2.1
ibm tivoli_storage_manager 6.1.0
ibm tivoli_storage_manager 5.4.2
ibm tivoli_storage_manager 5.3
ibm tivoli_storage_manager 5.4.1
ibm tivoli_storage_manager 5.1.5
ibm tivoli_storage_manager 5.4.4.0
ibm tivoli_storage_manager 5.3.4
ibm tivoli_storage_manager 5.3.6.6
ibm tivoli_storage_manager 5.2.5.2
ibm tivoli_storage_manager 6.3.1
ibm tivoli_storage_manager 6.1.2
ibm tivoli_storage_manager 5.2.0
ibm tivoli_storage_manager 7.1.0
ibm tivoli_storage_manager 5.3.6.3
ibm tivoli_storage_manager 5.1.1
ibm tivoli_storage_manager 6.3.4
ibm tivoli_storage_manager 5.2.8
ibm tivoli_storage_manager 6.2.0.0
ibm tivoli_storage_manager 5.3.0
ibm tivoli_storage_manager 5.4.2.2
ibm tivoli_storage_manager 6.3.5
ibm tivoli_storage_manager 5.2.9
ibm tivoli_storage_manager 6.3.0.17
ibm tivoli_storage_manager 5.3.6.1
ibm tivoli_storage_manager 5.4
ibm tivoli_storage_manager 5.3.6.2
ibm tivoli_storage_manager 6.3.0.1
ibm tivoli_storage_manager 5.2.4
ibm tivoli_storage_manager 6.2.0
ibm tivoli_storage_manager 5.1.10
ibm tivoli_storage_manager 6.3.5.1
ibm tivoli_storage_manager 5.3.3
ibm tivoli_storage_manager 5.5.3
ibm tivoli_storage_manager 6.1.4
ibm tivoli_storage_manager 5.4.0
ibm tivoli_storage_manager 5.4.2.4
ibm tivoli_storage_manager 6.2.6
ibm tivoli_storage_manager 5.5.2
ibm tivoli_storage_manager 5.2.7
ibm tivoli_storage_manager 6.2.2
ibm tivoli_storage_manager 6.1.5.4
ibm tivoli_storage_manager 6.2.7
CVE-2014-4818 LOW

dsmtca in the client in IBM Tivoli Storage Manager (TSM) 5.4.x, 5.5.x, 6.x before 6.4.3, and 7.1.x before 7.1.2 allows local users to discover the backup/restore encryption-key password via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager 6.3
ibm tivoli_storage_manager 7.1.1
ibm tivoli_storage_manager 6.3.3
ibm tivoli_storage_manager 5.5
ibm tivoli_storage_manager 7.1
ibm tivoli_storage_manager 6.4
ibm tivoli_storage_manager 6.4.1
ibm tivoli_storage_manager 5.4.0
ibm tivoli_storage_manager 6.4.2
ibm tivoli_storage_manager 6.2
ibm tivoli_storage_manager 6.3.4
ibm tivoli_storage_manager 6.1
ibm tivoli_storage_manager 6.3.5
CVE-2014-4819 MEDIUM

The web user interface in IBM WebSphere Message Broker 8.0 before 8.0.0.6 and IBM Integration Bus 9.0 before 9.0.0.3 allows remote authenticated users to obtain sensitive information by reading the error page.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_message_broker 8.0
ibm websphere_message_broker 8.0.0.3
ibm integration_bus 9.0
ibm websphere_message_broker 8.0.0.2
ibm integration_bus 9.0.0.2
ibm websphere_message_broker 8.0.0.5
ibm integration_bus 9.0.0.1
ibm websphere_message_broker 8.0.0.1
ibm websphere_message_broker 8.0.0.4
CVE-2014-4820 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Integration Bus Manufacturing Pack 1.x before 1.0.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm integration_bus_manufacturing_pack 1.0.0.0
CVE-2014-4821 MEDIUM

IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, 8.0 through 8.0.0.1 CF14, and 8.5.0 before CF03 provides different web-server error codes depending on whether a requested file exists, which allows remote attackers to determine the validity of filenames via a series of requests.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.0
ibm websphere_portal 6.1.0.3
ibm websphere_portal 7.0.0.1
ibm websphere_portal 6.1.5.2
ibm websphere_portal 6.1.0.2
ibm websphere_portal 6.1.0.4
ibm websphere_portal 8.0.0.1
ibm websphere_portal 7.0.0.2
ibm websphere_portal 8.5.0.0
ibm websphere_portal 6.1.5.0
ibm websphere_portal 6.1.0.6
ibm websphere_portal 6.1.5.3
ibm websphere_portal 7.0.0.0
ibm websphere_portal 6.1.0.1
ibm websphere_portal 6.1.5.1
ibm websphere_portal 6.1.0.5
ibm websphere_portal 6.1.0.0
CVE-2014-4822 LOW

IBM WebSphere MQ classes for Java libraries 8.0 before 8.0.0.1 and Websphere MQ Explorer 7.5 before 7.5.0.5 and 8.0 before 8.0.0.2 allow local users to discover preconfigured cleartext passwords via an unspecified trace operation.

CVSS 2.0

Severity: LOW

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm websphere_mq 8.0.0.0
ibm websphere_mq_explorer 7.5.0.0
ibm websphere_mq_explorer 7.5.0.4
ibm websphere_mq_explorer 7.5.0.3
ibm websphere_mq_explorer 8.0.0.1
ibm websphere_mq_explorer 7.5.0.1
ibm websphere_mq_explorer 7.5.0.2
ibm websphere_mq_explorer 8.0.0.0
CVE-2014-4823 HIGH

The administration console in IBM Security Access Manager for Web 7.x before 7.0.0-ISS-WGA-IF0009 and 8.x before 8.0.0-ISS-WGA-FP0005, and Security Access Manager for Mobile 8.x before 8.0.0-ISS-ISAM-FP0005, allows remote attackers to inject system commands via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-78,

Products Affected

Vendor Product Version
ibm security_access_manager_for_web_7.0_firmware 7.0.0.5
ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.3
ibm security_access_manager_for_web_7.0_firmware 7.0.0.6
ibm security_access_manager_for_web_7.0_firmware 7.0.0.1
ibm security_access_manager_for_web_7.0_firmware 7.0.0.7
ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.1
ibm security_access_manager_for_web_7.0_firmware 7.0.0.2
ibm security_access_manager_for_web_8.0_firmware 8.0.0.2
ibm security_access_manager_for_web_7.0_firmware 7.0.0.4
ibm security_access_manager_for_web_8.0_firmware 8.0.0.4
ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.4
ibm security_access_manager_for_mobile_appliance 8.0
ibm security_access_manager_for_web_8.0_firmware 8.0.0.3
ibm security_access_manager_for_web_appliance 7.0
ibm security_access_manager_for_web_7.0_firmware 7.0.0.0
ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.0
ibm security_access_manager_for_web_7.0_firmware 7.0.0.3
ibm security_access_manager_for_web_7.0_firmware 7.0.0.8
ibm security_access_manager_for_web_appliance 8.0
CVE-2014-4824 MEDIUM

SQL injection vulnerability in IBM Security QRadar SIEM 7.2 before 7.2.3 Patch 1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.0
CVE-2014-4825 MEDIUM

IBM Security QRadar SIEM QRM 7.1 MR1 and QRM/QVM 7.2 MR2 does not properly implement secure connections, which allows man-in-the-middle attackers to discover cleartext credentials via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.0
ibm qradar_security_information_and_event_manager 7.1.0
CVE-2014-4826 MEDIUM

IBM Security QRadar SIEM 7.2 before 7.2.3 Patch 1 does not properly handle SSH connections, which allows remote attackers to obtain sensitive cleartext information by sniffing the network.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.0
CVE-2014-4827 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Security QRadar SIEM QRM 7.1 MR1 and QRM/QVM 7.2 MR2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.0
ibm qradar_security_information_and_event_manager 7.1.0
CVE-2014-4828 MEDIUM

IBM Security QRadar SIEM QRM 7.1 MR1 and QRM/QVM 7.2 MR2 allows remote attackers to conduct clickjacking attacks via a crafted HTTP request.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.0
ibm qradar_security_information_and_event_manager 7.1.0
CVE-2014-4829 MEDIUM

Cross-site request forgery (CSRF) vulnerability in IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2.4 Patch 1, allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.2
ibm qradar_risk_manager 7.2.0
ibm qradar_vulnerability_manager 7.2.2
ibm qradar_vulnerability_manager 7.2.4
ibm qradar_vulnerability_manager 7.2.0
ibm qradar_risk_manager 7.2.2
ibm qradar_risk_manager 7.2.4
ibm qradar_vulnerability_manager 7.2.3
ibm qradar_security_information_and_event_manager 7.2.0
ibm qradar_risk_manager 7.2.3
ibm qradar_security_information_and_event_manager 7.1.0
ibm qradar_risk_manager 7.2.1
ibm qradar_security_information_and_event_manager 7.2.3
ibm qradar_risk_manager 7.1.0
ibm qradar_security_information_and_event_manager 7.2.4
ibm qradar_security_information_and_event_manager 7.2.1
ibm qradar_vulnerability_manager 7.2.1
CVE-2014-4830 MEDIUM

IBM Security QRadar SIEM QRM 7.1 MR1 and QRM/QVM 7.2 MR2 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.0
ibm qradar_security_information_and_event_manager 7.1.0
CVE-2014-4831 MEDIUM

IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2.4 Patch 1, allow remote attackers to hijack sessions via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm qradar_risk_manager 7.2.2
ibm qradar_risk_manager 7.2.4
ibm qradar_risk_manager 7.2.0
ibm qradar_vulnerability_manager 7.2.3
ibm qradar_risk_manager 7.2.3
ibm qradar_vulnerability_manager 7.2.2
ibm qradar_risk_manager 7.2.1
ibm qradar_vulnerability_manager 7.2.4
ibm qradar_risk_manager 7.1.0
ibm qradar_vulnerability_manager 7.2.1
ibm qradar_vulnerability_manager 7.2.0
CVE-2014-4832 MEDIUM

IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2.4 Patch 1, allow remote attackers to obtain sensitive cookie information by sniffing the network during an HTTP session.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.2
ibm qradar_risk_manager 7.2.0
ibm qradar_vulnerability_manager 7.2.2
ibm qradar_vulnerability_manager 7.2.4
ibm qradar_vulnerability_manager 7.2.0
ibm qradar_risk_manager 7.2.2
ibm qradar_risk_manager 7.2.4
ibm qradar_vulnerability_manager 7.2.3
ibm qradar_security_information_and_event_manager 7.2.0
ibm qradar_risk_manager 7.2.3
ibm qradar_security_information_and_event_manager 7.1.0
ibm qradar_risk_manager 7.2.1
ibm qradar_security_information_and_event_manager 7.2.3
ibm qradar_risk_manager 7.1.0
ibm qradar_security_information_and_event_manager 7.2.4
ibm qradar_security_information_and_event_manager 7.2.1
ibm qradar_vulnerability_manager 7.2.1
CVE-2014-4833 MEDIUM

IBM Security QRadar SIEM QRM 7.1 MR1 and QRM/QVM 7.2 MR2 allows remote authenticated users to gain privileges via invalid input.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.0
ibm qradar_security_information_and_event_manager 7.1.0
CVE-2014-4834 MEDIUM

IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.8 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption, and application crash) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_commerce 6.0.0.6
ibm websphere_commerce 7.0.0.4
ibm websphere_commerce 7.0.0.6
ibm websphere_commerce 7.0.0.7
ibm websphere_commerce 6.0.0.11
ibm websphere_commerce 6.0.0.1
ibm websphere_commerce 6.0.0.2
ibm websphere_commerce 6.0.0.10
ibm websphere_commerce 7.0.0.3
ibm websphere_commerce 7.0.0.2
ibm websphere_commerce 7.0
ibm websphere_commerce 6.0.0.7
ibm websphere_commerce 6.0.0.8
ibm websphere_commerce 7.0.0.5
ibm websphere_commerce 6.0.0.3
ibm websphere_commerce 6.0.0.0
ibm websphere_commerce 6.0.0.4
ibm websphere_commerce 6.0.0.9
ibm websphere_commerce 7.0.0.1
ibm websphere_commerce 6.0.0.5
ibm websphere_commerce 7.0.0.8
CVE-2014-4835 LOW

IBM ServerGuide before 9.63, UpdateXpress System Packs Installer (UXSPI) before 9.63, and ToolsCenter Suite before 9.63 place credentials in logs, which allows local users to obtain sensitive information by reading a file.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm serverguide *
ibm updatexpress_system_packs_installer *
ibm toolscenter_suite *
CVE-2014-4836 LOW

Cross-site scripting (XSS) vulnerability in breakOutWithName.jsp in IBM TRIRIGA Application Platform 3.2 and 3.3 before 3.3.0.2, 3.3.1 before 3.3.1.3, 3.3.2 before 3.3.2.2, and 3.4 before 3.4.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tririga_application_platform 3.4.0.0
ibm tririga_application_platform 3.2
ibm tririga_application_platform 3.3.0.1
ibm tririga_application_platform 3.3.1.1
ibm tririga_application_platform 3.3.1.0
ibm tririga_application_platform 3.3.2.1
ibm tririga_application_platform 3.3.2.0
ibm tririga_application_platform 3.2.1
ibm tririga_application_platform 3.3.1.2
ibm tririga_application_platform 3.3.0.0
CVE-2014-4837 LOW

Cross-site scripting (XSS) vulnerability in NewDocument.jsp in IBM TRIRIGA Application Platform 3.2 and 3.3 before 3.3.0.2, 3.3.1 before 3.3.1.3, 3.3.2 before 3.3.2.2, and 3.4 before 3.4.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tririga_application_platform 3.4.0.0
ibm tririga_application_platform 3.2
ibm tririga_application_platform 3.3.0.1
ibm tririga_application_platform 3.3.1.1
ibm tririga_application_platform 3.3.1.0
ibm tririga_application_platform 3.3.2.1
ibm tririga_application_platform 3.3.2.0
ibm tririga_application_platform 3.2.1
ibm tririga_application_platform 3.3.1.2
ibm tririga_application_platform 3.3.0.0
CVE-2014-4838 LOW

Cross-site scripting (XSS) vulnerability in GanttProjectSchedulerPopup.jsp in IBM TRIRIGA Application Platform 3.2 and 3.3 before 3.3.0.2, 3.3.1 before 3.3.1.3, 3.3.2 before 3.3.2.2, and 3.4 before 3.4.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tririga_application_platform 3.4.0.0
ibm tririga_application_platform 3.2
ibm tririga_application_platform 3.3.0.1
ibm tririga_application_platform 3.3.1.1
ibm tririga_application_platform 3.3.1.0
ibm tririga_application_platform 3.3.2.1
ibm tririga_application_platform 3.3.2.0
ibm tririga_application_platform 3.2.1
ibm tririga_application_platform 3.3.1.2
ibm tririga_application_platform 3.3.0.0
CVE-2014-4839 MEDIUM

Cross-site request forgery (CSRF) vulnerability in birtviewer.query in IBM TRIRIGA Application Platform 3.2 and 3.3 before 3.3.0.2, 3.3.1 before 3.3.1.3, 3.3.2 before 3.3.2.2, and 3.4 before 3.4.0.1 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm tririga_application_platform 3.4.0.0
ibm tririga_application_platform 3.2
ibm tririga_application_platform 3.3.0.1
ibm tririga_application_platform 3.3.1.1
ibm tririga_application_platform 3.3.2.1
ibm tririga_application_platform 3.3.2.0
ibm tririga_application_platform 3.3.1.2
ibm tririga_application_platform 3.3.0.0
CVE-2014-4840 HIGH

IBM TRIRIGA Application Platform 3.2 and 3.3 before 3.3.0.2, 3.3.1 before 3.3.1.3, 3.3.2 before 3.3.2.2, and 3.4 before 3.4.0.1 allows remote attackers to execute arbitrary code via a crafted URL.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm tririga_application_platform 3.4.0.0
ibm tririga_application_platform 3.2
ibm tririga_application_platform 3.3.0.1
ibm tririga_application_platform 3.3.1.1
ibm tririga_application_platform 3.3.1.0
ibm tririga_application_platform 3.3.2.1
ibm tririga_application_platform 3.3.2.0
ibm tririga_application_platform 3.2.1
ibm tririga_application_platform 3.3.1.2
ibm tririga_application_platform 3.3.0.0
CVE-2014-4843 MEDIUM

Curam Universal Access in IBM Curam Social Program Management (SPM) 6.0 SP2 before EP26, 6.0.4 before 6.0.4.6, and 6.0.5 before 6.0.5.5 iFix5 allows remote attackers to obtain sensitive information about internal caseworker usernames via vectors related to a URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-358,

Products Affected

Vendor Product Version
ibm curam_social_program_management 6.0
ibm curam_social_program_management 6.0.4.3
ibm curam_social_program_management 6.0.5.4
ibm curam_social_program_management 6.0.4.4
ibm curam_social_program_management 6.0.4.1
ibm curam_social_program_management 6.0.4.0
ibm curam_social_program_management 6.0.5.0
ibm curam_social_program_management 6.0.5.2
ibm curam_social_program_management 6.0.5.1
ibm curam_social_program_management 6.0.5.3
ibm curam_social_program_management 6.0.4.2
ibm curam_social_program_management 6.0.4.5
CVE-2014-4844 MEDIUM

The import/export functionality in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, and 8.5.x through 8.5.5 allows remote authenticated users to bypass intended access restrictions via a project action for a (1) process application or (2) toolkit.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm business_process_manager 8.0.1.2
ibm business_process_manager 8.0.1.1
ibm business_process_manager 7.5.0.1
ibm business_process_manager 7.5.1.0
ibm business_process_manager 7.5.1.1
ibm business_process_manager 8.5.5.0
ibm business_process_manager 8.0.1.0
ibm business_process_manager 7.5.1.2
ibm business_process_manager 8.0.0.0
ibm business_process_manager 8.5.0.1
ibm business_process_manager 8.5.0.0
ibm business_process_manager 7.5.0.0
CVE-2014-6074 MEDIUM

IBM UrbanCode Deploy 6.1.0.2 before IF1 allows remote authenticated users to read keystore secret keys via a direct request to a UI page.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm urbancode_deploy 6.1.0.2
CVE-2014-6075 MEDIUM

IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2.4 Patch 1, place credentials in URLs, which allows remote attackers to obtain sensitive information by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.2
ibm qradar_risk_manager 7.2.0
ibm qradar_vulnerability_manager 7.2.2
ibm qradar_vulnerability_manager 7.2.4
ibm qradar_vulnerability_manager 7.2.0
ibm qradar_risk_manager 7.2.2
ibm qradar_risk_manager 7.2.4
ibm qradar_vulnerability_manager 7.2.3
ibm qradar_security_information_and_event_manager 7.2.0
ibm qradar_risk_manager 7.2.3
ibm qradar_security_information_and_event_manager 7.1.0
ibm qradar_risk_manager 7.2.1
ibm qradar_security_information_and_event_manager 7.2.3
ibm qradar_risk_manager 7.1.0
ibm qradar_security_information_and_event_manager 7.2.4
ibm qradar_security_information_and_event_manager 7.2.1
ibm qradar_vulnerability_manager 7.2.1
CVE-2014-6076 MEDIUM

IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allow remote attackers to conduct clickjacking attacks via a crafted web site.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-254,

Products Affected

Vendor Product Version
ibm security_access_manager_for_mobile 8.0
ibm security_access_manager_for_web 8.0
ibm security_access_manager_for_web 7.0
CVE-2014-6077 MEDIUM

Cross-site request forgery (CSRF) vulnerability in IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm security_access_manager_for_mobile 8.0
ibm security_access_manager_for_web 8.0
ibm security_access_manager_for_web 7.0
CVE-2014-6078 MEDIUM

IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 do not have a lockout period after invalid login attempts, which makes it easier for remote attackers to obtain admin access via a brute-force attack.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm security_access_manager_for_mobile 8.0
ibm security_access_manager_for_web 8.0
ibm security_access_manager_for_web 7.0
CVE-2014-6079 MEDIUM

Cross-site scripting (XSS) vulnerability in the Local Management Interface in IBM Security Access Manager for Web 7.x before 7.0.0-ISS-WGA-IF0009 and 8.x before 8.0.0-ISS-WGA-FP0005, and Security Access Manager for Mobile 8.x before 8.0.0-ISS-ISAM-FP0005, allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm security_access_manager_for_web_7.0_firmware 7.0.0.5
ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.3
ibm security_access_manager_for_web_7.0_firmware 7.0.0.6
ibm security_access_manager_for_web_7.0_firmware 7.0.0.1
ibm security_access_manager_for_web_7.0_firmware 7.0.0.7
ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.1
ibm security_access_manager_for_web_7.0_firmware 7.0.0.2
ibm security_access_manager_for_web_8.0_firmware 8.0.0.2
ibm security_access_manager_for_web_7.0_firmware 7.0.0.4
ibm security_access_manager_for_web_8.0_firmware 8.0.0.4
ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.4
ibm security_access_manager_for_mobile_appliance 8.0
ibm security_access_manager_for_web_8.0_firmware 8.0.0.3
ibm security_access_manager_for_web_appliance 7.0
ibm security_access_manager_for_web_7.0_firmware 7.0.0.0
ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.0
ibm security_access_manager_for_web_7.0_firmware 7.0.0.3
ibm security_access_manager_for_web_7.0_firmware 7.0.0.8
ibm security_access_manager_for_web_appliance 8.0
CVE-2014-6080 MEDIUM

SQL injection vulnerability in IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm security_access_manager_for_mobile 8.0
ibm security_access_manager_for_web 8.0
ibm security_access_manager_for_web 7.0
CVE-2014-6082 MEDIUM

IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allow remote authenticated users to cause a denial of service (administration UI outage) via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm security_access_manager_for_mobile 8.0
ibm security_access_manager_for_web 8.0
ibm security_access_manager_for_web 7.0
CVE-2014-6083 MEDIUM

IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allow remote attackers to obtain sensitive cookie information by sniffing the network during an HTTP session.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_access_manager_for_mobile 8.0
ibm security_access_manager_for_web 8.0
ibm security_access_manager_for_web 7.0
CVE-2014-6084 MEDIUM

IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 make it easier for remote attackers to obtain sensitive information by sniffing the network during use of a weak SSL cipher.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm security_access_manager_for_mobile 8.0
ibm security_access_manager_for_web 8.0
ibm security_access_manager_for_web 7.0
CVE-2014-6086 MEDIUM

IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 do not ensure that HTTPS is used, which allows remote attackers to obtain sensitive information by sniffing the network during an HTTP session.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_access_manager_for_mobile 8.0
ibm security_access_manager_for_web 8.0
ibm security_access_manager_for_web 7.0
CVE-2014-6087 MEDIUM

IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 make it easier for remote attackers to obtain sensitive information by sniffing the network during use of a weak algorithm in an SSL cipher suite.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm security_access_manager_for_mobile 8.0
ibm security_access_manager_for_web 8.0
ibm security_access_manager_for_web 7.0
CVE-2014-6088 MEDIUM

IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allow remote attackers to obtain sensitive information by sniffing the network during use of the null SSL cipher.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_access_manager_for_mobile 8.0
ibm security_access_manager_for_web 8.0
ibm security_access_manager_for_web 7.0
CVE-2014-6089 MEDIUM

IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allow remote authenticated users to cause a denial of service (disrupted system operations) by uploading a file to a protected area.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-19,

Products Affected

Vendor Product Version
ibm security_access_manager_for_mobile 8.0
ibm security_access_manager_for_web 8.0
ibm security_access_manager_for_web 7.0
CVE-2014-6090 MEDIUM

Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) DataMappingEditorCommands, (2) DatastoreEditorCommands, and (3) IEGEditorCommands servlets in IBM Curam Social Program Management (SPM) 5.2 SP6 before EP6, 6.0 SP2 before EP26, 6.0.3 before 6.0.3.0 iFix8, 6.0.4 before 6.0.4.5 iFix10, and 6.0.5 before 6.0.5.6 allow remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm curam_social_program_management 6.0
ibm curam_social_program_management 6.0.3.0
ibm curam_social_program_management 5.2
ibm curam_social_program_management 6.0.4.0
ibm curam_social_program_management 6.0.5.0
CVE-2014-6091 LOW

Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management (SPM) 6.0.4 before 6.0.4.5 iFix7 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm curam_social_program_management 6.0.4.3
ibm curam_social_program_management 6.0.4.4
ibm curam_social_program_management 6.0.4.1
ibm curam_social_program_management 6.0.4.2
ibm curam_social_program_management 6.0.4.5
ibm curam_social_program_management 6.0.4.0
CVE-2014-6092 MEDIUM

IBM Curam Social Program Management (SPM) 5.2 before SP6 EP6, 6.0 SP2 before EP26, 6.0.4 before 6.0.4.6, and 6.0.5 before 6.0.5.6 requires failed-login handling for web-service accounts to have the same lockout policy as for standard user accounts, which makes it easier for remote attackers to cause a denial of service (web-service outage) by making many login attempts with a valid caseworker account name.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-17,

Products Affected

Vendor Product Version
ibm curam_social_program_management 6.0.4.3
ibm curam_social_program_management 6.0.5.4
ibm curam_social_program_management 6.0.4.4
ibm curam_social_program_management 6.0.4.1
ibm curam_social_program_management 6.0.4.0
ibm curam_social_program_management 6.0.5.0
ibm curam_social_program_management 6.0.5.5
ibm curam_social_program_management 6.0.5.2
ibm curam_social_program_management 6.0.5.1
ibm curam_social_program_management *
ibm curam_social_program_management 6.0.5.3
ibm curam_social_program_management 6.0.4.2
ibm curam_social_program_management 6.0.4.5
CVE-2014-6093 LOW

Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 7.0.x before 7.0.0.2 CF29, 8.0.x through 8.0.0.1 CF14, and 8.5.x before 8.5.0 CF02 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal *
ibm websphere_portal 8.0.0.0
ibm websphere_portal 7.0.0.1
ibm websphere_portal 7.0.0.0
CVE-2014-6095 MEDIUM

Directory traversal vulnerability in IBM Security Identity Manager 6.x before 6.0.0.3 IF14 allows remote attackers to read arbitrary files via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm security_identity_manager 6.0.0.1
ibm security_identity_manager 6.0.0.2
ibm security_identity_manager 6.0.0.0
ibm security_identity_manager 6.0.0.3
CVE-2014-6096 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Security Identity Manager 6.x before 6.0.0.3 IF14 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm security_identity_manager 6.0.0.1
ibm security_identity_manager 6.0.0.2
ibm security_identity_manager 6.0.0.0
ibm security_identity_manager 6.0.0.3
CVE-2014-6097 MEDIUM

IBM DB2 9.7 before FP10 and 9.8 through FP5 on Linux, UNIX, and Windows allows remote authenticated users to cause a denial of service (daemon crash) via a crafted ALTER TABLE statement.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm db2 9.8
ibm db2 9.7
CVE-2014-6098 MEDIUM

IBM Security Identity Manager 6.x before 6.0.0.3 IF14 allows remote attackers to discover cleartext passwords via a crafted request.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm security_identity_manager 6.0.0.1
ibm security_identity_manager 6.0.0.2
ibm security_identity_manager 6.0.0.0
ibm security_identity_manager 6.0.0.3
CVE-2014-6099 MEDIUM

The Change Password feature in IBM Sterling B2B Integrator 5.2.x through 5.2.4 does not have a lockout protection mechanism for invalid login requests, which makes it easier for remote attackers to obtain admin access via a brute-force approach.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2
ibm sterling_b2b_integrator 5.2.4
CVE-2014-6100 LOW

Cross-site scripting (XSS) vulnerability in the Admin UI in IBM Tivoli Directory Server 6.1 before 6.1.0.64-ISS-ITDS-IF0064, 6.2 before 6.2.0.39-ISS-ITDS-FP0039, and 6.3 before 6.3.0.33-ISS-ITDS-IF0033, and IBM Security Directory Server 6.3.1 before 6.3.1.7-ISS-ISDS-IF0007, allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_directory_server 6.2.0.8
ibm tivoli_directory_server 6.3.0
ibm security_directory_server 6.3.1.5
ibm tivoli_directory_server 6.1.0.63
ibm tivoli_directory_server 6.2.0.15
ibm tivoli_directory_server 6.1.0.9
ibm tivoli_directory_server 6.2.0.13
ibm tivoli_directory_server 6.2.0.6
ibm tivoli_directory_server 6.3.0.10
ibm tivoli_directory_server 6.3.0.1
ibm tivoli_directory_server 6.1.0.24
ibm tivoli_directory_server 6.1.0.29
ibm tivoli_directory_server 6.1.0.36
ibm tivoli_directory_server 6.1.0
ibm tivoli_directory_server 6.1.0.14
ibm security_directory_server 6.3.1
ibm tivoli_directory_server 6.1.0.35
ibm tivoli_directory_server 6.2.0.1
ibm tivoli_directory_server 6.2.0.12
ibm tivoli_directory_server 6.1.0.2
ibm tivoli_directory_server 6.2.0.19
ibm tivoli_directory_server 6.2.0.7
ibm tivoli_directory_server 6.1.0.30
ibm security_directory_server 6.3.1.1
ibm tivoli_directory_server 6.2.0
ibm tivoli_directory_server 6.2.0.2
ibm tivoli_directory_server 6.2.0.10
ibm security_directory_server 6.3.1.4
ibm tivoli_directory_server 6.2.0.5
ibm tivoli_directory_server 6.1.0.23
ibm tivoli_directory_server 6.1.0.3
ibm tivoli_directory_server 6.1.0.47
ibm tivoli_directory_server 6.2.0.0
ibm tivoli_directory_server 6.2.0.11
ibm tivoli_directory_server 6.1.0.8
ibm tivoli_directory_server 6.1.0.28
ibm tivoli_directory_server 6.1.0.19
ibm tivoli_directory_server 6.3.0.32
ibm tivoli_directory_server 6.2.0.20
ibm tivoli_directory_server 6.1.0.34
ibm tivoli_directory_server 6.2.0.22
ibm tivoli_directory_server 6.1.0.6
ibm tivoli_directory_server 6.1.0.4
ibm tivoli_directory_server 6.1.0.20
ibm tivoli_directory_server 6.2
ibm tivoli_directory_server 6.1.0.13
ibm tivoli_directory_server 6.3.0.0
ibm tivoli_directory_server 6.1.0.22
ibm tivoli_directory_server 6.1.0.37
ibm tivoli_directory_server 6.1.0.7
ibm tivoli_directory_server 6.1.0.15
ibm tivoli_directory_server 6.3.0.8
ibm tivoli_directory_server 6.2.0.4
ibm tivoli_directory_server 6.1.0.45
ibm tivoli_directory_server 6.2.0.38
ibm tivoli_directory_server 6.3.0.9
ibm tivoli_directory_server 6.1.0.0
ibm tivoli_directory_server 6.1.0.12
ibm tivoli_directory_server 6.1.0.39
ibm tivoli_directory_server 6.2.0.14
ibm tivoli_directory_server 6.1.0.18
ibm tivoli_directory_server 6.1.0.33
ibm security_directory_server 6.3.1.3
ibm tivoli_directory_server 6.1.0.5
ibm tivoli_directory_server 6.3.0.2
ibm tivoli_directory_server 6.1.0.11
ibm tivoli_directory_server 6.1.0.27
ibm tivoli_directory_server 6.1.0.48
ibm tivoli_directory_server 6.1.0.25
ibm tivoli_directory_server 6.1.0.10
ibm tivoli_directory_server 6.1.0.21
ibm tivoli_directory_server 6.1.0.31
ibm security_directory_server 6.3.1.2
ibm tivoli_directory_server 6.1.0.26
ibm tivoli_directory_server 6.1.0.38
ibm tivoli_directory_server 6.2.0.3
ibm tivoli_directory_server 6.1.0.32
ibm tivoli_directory_server 6.2.0.21
ibm tivoli_directory_server 6.1.0.46
ibm tivoli_directory_server 6.1.0.1
ibm security_directory_server 6.3.1.6
ibm tivoli_directory_server 6.1.0.17
CVE-2014-6101 MEDIUM

Cross-site scripting (XSS) vulnerability in the redirect-login feature in IBM Business Process Manager (BPM) Advanced 7.5 through 8.5.5 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm business_process_manager 8.0.1.2
ibm business_process_manager 8.0.1.1
ibm business_process_manager 7.5.0.1
ibm business_process_manager 7.5.1.0
ibm business_process_manager 7.5.1.1
ibm business_process_manager 8.5.5.0
ibm business_process_manager 8.0.1.0
ibm business_process_manager 7.5.1.2
ibm business_process_manager 8.0.0.0
ibm business_process_manager 8.5.0.1
ibm business_process_manager 8.5.0.0
ibm business_process_manager 7.5.0.0
CVE-2014-6102 LOW

IBM Maximo Asset Management 7.1 through 7.1.1.13 and 7.5.0 before 7.5.0.6 IFIX008, Maximo Asset Management 7.5.0 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk, and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products do not properly handle logout actions, which allows remote attackers to bypass intended Cognos BI Direct Integration access restrictions by leveraging an unattended workstation.

CVSS 2.0

Severity: LOW

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm tivoli_asset_management_for_it 7.2
ibm maximo_asset_management 7.1.1.9
ibm maximo_for_government 7.1
ibm maximo_asset_management 7.1.1.13
ibm maximo_asset_management 7.1.1.10
ibm maximo_asset_management 7.1.1.1
ibm maximo_for_nuclear_power 7.5.0.0
ibm smartcloud_control_desk 7.5.0.5
ibm maximo_asset_management_essentials 7.5.0.0
ibm maximo_for_nuclear_power 7.1
ibm maximo_for_life_sciences 7.1
ibm maximo_asset_management 7.5.0.6
ibm maximo_asset_management 7.1.1.7
ibm smartcloud_control_desk 7.5.1.1
ibm smartcloud_control_desk 7.5.0.2
ibm maximo_asset_management 7.5.0.5
ibm maximo_asset_management 7.1.1.2
ibm maximo_for_oil_and_gas 7.1
ibm maximo_asset_management 7.1.1.5
ibm tivoli_service_request_manager 7.2
ibm smartcloud_control_desk 7.5.1.0
ibm maximo_asset_management 7.1.1.11
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.5.0.1
ibm maximo_for_transportation 7.5.0.0
ibm maximo_asset_management 7.5.0.10
ibm maximo_for_life_sciences 7.5.0.0
ibm maximo_for_utilities 7.1
ibm maximo_for_government 7.5.0.0
ibm change_and_configuration_management_database 7.1
ibm maximo_asset_management 7.1.1.12
ibm change_and_configuration_management_database 7.2
ibm maximo_asset_management 7.5.0.3
ibm maximo_for_utilities 7.5.0.0
ibm tivoli_asset_management_for_it 7.1
ibm maximo_for_transportation 7.1
ibm tivoli_service_request_manager 7.1
ibm maximo_asset_management_essentials 7.1
ibm maximo_asset_management 7.5.0.0
ibm maximo_asset_management 7.5.0.4
ibm maximo_for_oil_and_gas 7.5.0.0
ibm smartcloud_control_desk 7.5.0.1
ibm maximo_asset_management 7.1.1.6
ibm maximo_asset_management 7.1.2
ibm smartcloud_control_desk 7.5.0.3
CVE-2014-6105 MEDIUM

IBM Security Identity Manager 6.x before 6.0.0.3 IF14 allows remote attackers to conduct clickjacking attacks via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm security_identity_manager 6.0.0.1
ibm security_identity_manager 6.0.0.2
ibm security_identity_manager 6.0.0.0
ibm security_identity_manager 6.0.0.3
CVE-2014-6106 MEDIUM

Cross-site request forgery (CSRF) vulnerability in IBM Security Identity Manager 5.1, 6.0, and 7.0 allows remote attackers to hijack the authentication of users for requests that can cause cross-site scripting attacks, web cache poisoning, or other unspecified impacts via unknown vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm security_identity_manager 5.1.0.11
ibm security_identity_manager 5.1.0
ibm security_identity_manager 5.1.0.8
ibm security_identity_manager 5.1.0.14
ibm security_identity_manager 5.1.0.4
ibm security_identity_manager 5.1.0.6
ibm security_identity_manager 5.1.0.5
ibm security_identity_manager 6.0.0.2
ibm security_identity_manager 5.1.0.7
ibm security_identity_manager 5.1.0.9
ibm security_identity_manager 5.1.0.10
ibm security_identity_manager 6.0.0.1
ibm security_identity_manager 5.1.0.13
ibm security_identity_manager 6.0.0.4
ibm security_identity_manager 5.1.0.3
ibm security_identity_manager 5.1.0.15
ibm security_identity_manager 7.0.0.0
ibm security_identity_manager 5.1.0.12
ibm security_identity_manager 6.0.0.0
ibm security_identity_manager 6.0.0.3
CVE-2014-6107 MEDIUM

IBM Security Identity Manager 6.x before 6.0.0.3 IF14 allows remote attackers to obtain sensitive cookie information by sniffing the network during an HTTP session.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_identity_manager 6.0.0.1
ibm security_identity_manager 6.0.0.2
ibm security_identity_manager 6.0.0.0
ibm security_identity_manager 6.0.0.3
CVE-2014-6108 MEDIUM

IBM Tivoli Identity Manager 5.1.x before 5.1.0.15-ISS-TIM-IF0057 and Security Identity Manager 6.0.x before 6.0.0.4-ISS-SIM-IF0001 and 7.0.x before 7.0.0.0-ISS-SIM-IF0003 might allow man-in-the-middle attackers to obtain sensitive information by leveraging an unencrypted connection for interfaces. IBM X-Force ID: 96172.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_identity_manager 6.0
ibm tivoli_identity_manager 5.1
ibm security_identity_manager 7.0
CVE-2014-6109 LOW

IBM Tivoli Identity Manager 5.1.x before 5.1.0.15-ISS-TIM-IF0057 and Security Identity Manager 6.0.x before 6.0.0.4-ISS-SIM-IF0001 and 7.0.x before 7.0.0.0-ISS-SIM-IF0003 allow remote authenticated users to bypass intended access restrictions and obtain sensitive information via vectors related to server side LDAP queries. IBM X-Force ID: 96173.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,CWE-284,

Products Affected

Vendor Product Version
ibm security_identity_manager 6.0
ibm tivoli_identity_manager 5.1
ibm security_identity_manager 7.0
CVE-2014-6110 LOW

IBM Security Identity Manager 6.x before 6.0.0.3 IF14 does not properly perform logout actions, which allows remote attackers to access sessions by leveraging an unattended workstation.

CVSS 2.0

Severity: LOW

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm security_identity_manager 6.0.0.1
ibm security_identity_manager 6.0.0.2
ibm security_identity_manager 6.0.0.0
ibm security_identity_manager 6.0.0.3
CVE-2014-6111 LOW

IBM Tivoli Identity Manager 5.1.x before 5.1.0.15-ISS-TIM-IF0057 and Security Identity Manager 6.0.x before 6.0.0.4-ISS-SIM-IF0001 and 7.0.x before 7.0.0.0-ISS-SIM-IF0003 store encrypted user credentials and the keystore password in cleartext in configuration files, which allows local users to decrypt SIM credentials via unspecified vectors. IBM X-Force ID: 96180.

CVSS 2.0

Severity: LOW

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm security_identity_manager 6.0
ibm tivoli_identity_manager 5.1
ibm security_identity_manager 7.0
CVE-2014-6112 MEDIUM

IBM Tivoli Identity Manager 5.1.x before 5.1.0.15-ISS-TIM-IF0057 and Security Identity Manager 6.0.x before 6.0.0.4-ISS-SIM-IF0001 and 7.0.x before 7.0.0.0-ISS-SIM-IF0003 make it easier for remote attackers to obtain sensitive information by leveraging support for weak SSL ciphers. IBM X-Force ID: 96184.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_identity_manager 6.0
ibm tivoli_identity_manager 5.1
ibm security_identity_manager 7.0
CVE-2014-6113 MEDIUM

Cross-site scripting (XSS) vulnerability in the Web Reports component in IBM Tivoli Endpoint Manager 9.1 before 9.1.1229 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_endpoint_manager *
CVE-2014-6114 MEDIUM

The Hosted Transparent Decision Service in the Rule Execution Server in IBM WebSphere ILOG JRules 7.1 before MP1 FP5 IF43; WebSphere Operational Decision Management 7.5 before FP3 IF41; and Operational Decision Manager 8.0 before MP1 FP2 IF34, 8.5 before MP1 FP1 IF43, and 8.6 before IF8 allows remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm operational_decision_manager 8.6
ibm operational_decision_manager 8.0
ibm operational_decision_manager 8.5
ibm websphere_ilog_jrules 7.1
ibm websphere_operational_decision_management 7.5
CVE-2014-6115 MEDIUM

IBM Rational Insight 1.1.1.5 allows remote attackers to bypass authentication and obtain sensitive information via a crafted request to a Jazz Reporting Service (JRS) report URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_insight 1.1.1.5
CVE-2014-6116 MEDIUM

The Telemetry Component in WebSphere MQ 8.0.0.1 before p000-001-L140910 allows remote attackers to bypass authentication by setting the JAASConfig property in an MQTT client configuration.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm websphere_mq 8.0.0.1
CVE-2014-6119 HIGH

IBM Security AppScan Enterprise 8.5 before 8.5 IFix 002, 8.6 before 8.6 IFix 004, 8.7 before 8.7 IFix 004, 8.8 before 8.8 iFix 003, 9.0 before 9.0.0.1 iFix 003, and 9.0.1 before 9.0.1 iFix 001 allows remote attackers to execute arbitrary code via a crafted executable file in an archive.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-94,

Products Affected

Vendor Product Version
ibm security_appscan 8.8
ibm security_appscan 9.0
ibm security_appscan_source 9.0.1
ibm security_appscan 8.6
ibm security_appscan 8.5
ibm security_appscan 9.0.0.1
ibm security_appscan 8.7
CVE-2014-6120 HIGH

IBM Rational AppScan Source 8.0 through 8.0.0.2 and 8.5 through 8.5.0.1 and Security AppScan Source 8.6 through 8.6.0.2, 8.7 through 8.7.0.1, 8.8, 9.0 through 9.0.0.1, and 9.0.1 allow remote attackers to execute arbitrary commands on the installation server via unspecified vectors. IBM X-Force ID: 96721.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-77,

Products Affected

Vendor Product Version
ibm rational_appscan_source 8.0.0.0
ibm security_appscan_source 8.7
ibm rational_appscan_source 8.0.0.1
ibm security_appscan_source 8.6.0.1
ibm security_appscan_source 8.6.0.2
ibm security_appscan_source 8.7.0.1
ibm rational_appscan_source 8.5.0.1
ibm security_appscan_source 9.0.0.0
ibm rational_appscan_source 8.0.0.2
ibm security_appscan_source 9.0.1
ibm rational_appscan_source 8.5.0.0
ibm security_appscan_source 8.6.0.0
ibm security_appscan_source 8.8
ibm security_appscan_source 9.0.0.1
CVE-2014-6121 LOW

Cross-site scripting (XSS) vulnerability in IBM Security AppScan Enterprise 8.5 before 8.5 IFix 002, 8.6 before 8.6 IFix 004, 8.7 before 8.7 IFix 004, 8.8 before 8.8 iFix 003, 9.0 before 9.0.0.1 iFix 003, and 9.0.1 before 9.0.1 iFix 001 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm security_appscan 8.8
ibm security_appscan 9.0
ibm security_appscan_source 9.0.1
ibm security_appscan 8.6
ibm security_appscan 8.5
ibm security_appscan 9.0.0.1
ibm security_appscan 8.7
CVE-2014-6122 MEDIUM

IBM Security AppScan Enterprise 8.5 before 8.5 IFix 002, 8.6 before 8.6 IFix 004, 8.7 before 8.7 IFix 004, 8.8 before 8.8 iFix 003, 9.0 before 9.0.0.1 iFix 003, and 9.0.1 before 9.0.1 iFix 001 allows remote authenticated users to write to arbitrary folders, and consequently execute arbitrary commands, via a modified argument.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm security_appscan 8.8
ibm security_appscan 9.0
ibm security_appscan_source 9.0.1
ibm security_appscan 8.6
ibm security_appscan 8.5
ibm security_appscan 9.0.0.1
ibm security_appscan 8.7
CVE-2014-6123 LOW

IBM Rational AppScan Source 8.0 through 8.0.0.2 and 8.5 through 8.5.0.1 and Security AppScan Source 8.6 through 8.6.0.2, 8.7 through 8.7.0.1, 8.8, 9.0 through 9.0.0.1, and 9.0.1 allow local users to obtain sensitive credential information by reading installation logs.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_appscan_source 8.0.0.0
ibm rational_appscan_source 8.0.0.1
ibm security_appscan_source 8.6.0.1
ibm security_appscan_source 8.6.0.2
ibm security_appscan_source 8.7.0.1
ibm rational_appscan_source 8.5.0.1
ibm security_appscan_source 9.0.0.0
ibm rational_appscan_source 8.0.0.2
ibm security_appscan_source 9.0.1
ibm rational_appscan_source 8.5.0.0
ibm security_appscan_source 8.6.0.0
ibm security_appscan_source 9.0
ibm security_appscan_source 8.7.0.0
ibm security_appscan_source 8.8
CVE-2014-6125 MEDIUM

Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Portal 8.5.0 before CF03 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm websphere_portal 8.5.0.0
CVE-2014-6126 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.5.0 before CF03 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 8.5.0.0
CVE-2014-6129 MEDIUM

IBM Rational Jazz Team Server (JTS), as used in Rational Collaborative Lifecycle Management 3.x and 4.x before 4.0.7 iFix4 and 5.x before 5.0.2 iFix2; Rational Quality Manager 2.x and 3.x before 3.0.1.6 iFix5, 4.x before 4.0.7 iFix4, and 5.x before 5.0.2 iFix2; Rational Team Concert 2.x and 3.x before 3.0.1.6 iFix5, 4.x before 4.0.7 iFix4, and 5.x before 5.0.2 iFix2; Rational DOORS Next Generation 4.x before 4.0.7 iFix4 and 5.x before 5.0.2 iFix2; Rational Requirements Composer 2.x and 3.x before 3.0.1.6 iFix5; and other products, allows remote authenticated users to delete the dashboards of arbitrary users via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm rational_collaborative_lifecycle_management 3.0.1.2
ibm rational_team_concert 4.0.0.1
ibm rational_doors_next_generation 4.0.0
ibm rational_collaborative_lifecycle_management 4.0.6
ibm rational_requirements_composer 3.0.1.4
ibm rational_quality_manager 2.0.0.2
ibm rational_requirements_composer 3.0.1.1
ibm rational_quality_manager 4.0.0.1
ibm rational_quality_manager 4.0.0.2
ibm rational_requirements_composer 2.0
ibm rational_quality_manager 4.0.7
ibm rational_requirements_composer 3.0.1.6
ibm rational_team_concert 2.0.0.2
ibm rational_quality_manager 2.0.1
ibm rational_team_concert 2.0.0.1
ibm rational_quality_manager 4.0.3
ibm rational_doors_next_generation 4.0.1
ibm rational_quality_manager 3.0.1.5
ibm rational_team_concert 4.0.7
ibm rational_team_concert 4.0.1
ibm rational_team_concert 3.0.1.2
ibm rational_team_concert 4.0.5
ibm rational_doors_next_generation 5.0
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_team_concert 4.0.2
ibm rational_quality_manager 5.0.2
ibm rational_collaborative_lifecycle_management 3.0.1.3
ibm rational_collaborative_lifecycle_management 4.0.5
ibm rational_collaborative_lifecycle_management 4.0.7
ibm rational_collaborative_lifecycle_management 5.0.0
ibm rational_requirements_composer 2.0.0.3
ibm rational_collaborative_lifecycle_management 4.0.3
ibm rational_requirements_composer 2.0.0.1
ibm rational_doors_next_generation 4.0.7
ibm rational_team_concert 4.0.0.2
ibm rational_doors_next_generation 4.0.2
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_requirements_composer 3.0.1
ibm rational_collaborative_lifecycle_management 4.0.0
ibm rational_requirements_composer 3.0.1.3
ibm rational_collaborative_lifecycle_management 3.0.1.6
ibm rational_team_concert 3.0.1.4
ibm rational_quality_manager 3.0.1.6
ibm rational_team_concert 3.0.1.1
ibm rational_quality_manager 2.0.0.1
ibm rational_quality_manager 3.0.1.1
ibm rational_requirements_composer 3.0
ibm rational_team_concert 4.0
ibm rational_doors_next_generation 4.0.5
ibm rational_team_concert 5.0.2
ibm rational_requirements_composer 3.0.1.2
ibm rational_quality_manager 2.0.1.1
ibm rational_collaborative_lifecycle_management 4.0.1
ibm rational_team_concert 4.0.3
ibm rational_doors_next_generation 4.0.6
ibm rational_team_concert 3.0
ibm rational_collaborative_lifecycle_management 3.0.1.4
ibm rational_quality_manager 3.0.1.3
ibm rational_doors_next_generation 4.0.3
ibm rational_quality_manager 5.0.1
ibm rational_requirements_composer 2.0.0.4
ibm rational_team_concert 3.0.1
ibm rational_collaborative_lifecycle_management 4.0.2
ibm rational_quality_manager 4.0
ibm rational_quality_manager 3.0
ibm rational_requirements_composer 2.0.0.2
ibm rational_quality_manager 2.0
ibm rational_quality_manager 4.0.1
ibm rational_team_concert 4.0.6
ibm rational_team_concert 5.0.0
ibm rational_collaborative_lifecycle_management 3.0.1
ibm rational_requirements_composer 3.0.1.5
ibm rational_team_concert 3.0.1.5
ibm rational_team_concert 3.0.1.3
ibm rational_quality_manager 3.0.1.2
ibm rational_quality_manager 5.0.0
ibm rational_quality_manager 3.0.1
ibm rational_collaborative_lifecycle_management 3.0.1.1
ibm rational_collaborative_lifecycle_management 3.0.0
ibm rational_doors_next_generation 4.0.4
ibm rational_quality_manager 3.0.1.4
ibm rational_quality_manager 4.0.4
ibm rational_team_concert 4.0.4
ibm rational_collaborative_lifecycle_management 3.0.1.5
ibm rational_quality_manager 4.0.5
ibm rational_doors_next_generation 5.0.2
ibm rational_quality_manager 4.0.2
ibm rational_doors_next_generation 5.0.1
ibm rational_team_concert 3.0.1.6
ibm rational_collaborative_lifecycle_management 4.0.4
ibm rational_team_concert 5.0.1
CVE-2014-6130 MEDIUM

The IBM Notes Traveler application before 9.0.1.3 for Android lacks a warning message during selection of an HTTP session, which makes it easier for remote attackers to obtain sensitive information by sniffing the network during a session in which the user had intended to use HTTPS.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm notes_traveler *
CVE-2014-6131 MEDIUM

IBM Rational Jazz Team Server (JTS), as used in Rational Collaborative Lifecycle Management 3.x and 4.x before 4.0.7 iFix4 and 5.x before 5.0.2 iFix2; Rational Quality Manager 2.x and 3.x before 3.0.1.6 iFix5, 4.x before 4.0.7 iFix4, and 5.x before 5.0.2 iFix2; Rational Team Concert 2.x and 3.x before 3.0.1.6 iFix5, 4.x before 4.0.7 iFix4, and 5.x before 5.0.2 iFix2; Rational DOORS Next Generation 4.x before 4.0.7 iFix4 and 5.x before 5.0.2 iFix2; Rational Requirements Composer 2.x and 3.x before 3.0.1.6 iFix5; and other products, allows remote authenticated users to read the dashboards of arbitrary users via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_collaborative_lifecycle_management 3.0.1.2
ibm rational_team_concert 4.0.0.1
ibm rational_doors_next_generation 4.0.0
ibm rational_collaborative_lifecycle_management 4.0.6
ibm rational_requirements_composer 3.0.1.4
ibm rational_quality_manager 2.0.0.2
ibm rational_requirements_composer 3.0.1.1
ibm rational_quality_manager 4.0.0.1
ibm rational_quality_manager 4.0.0.2
ibm rational_requirements_composer 2.0
ibm rational_quality_manager 4.0.7
ibm rational_requirements_composer 3.0.1.6
ibm rational_team_concert 2.0.0.2
ibm rational_quality_manager 2.0.1
ibm rational_team_concert 2.0.0.1
ibm rational_quality_manager 4.0.3
ibm rational_doors_next_generation 4.0.1
ibm rational_quality_manager 3.0.1.5
ibm rational_team_concert 4.0.7
ibm rational_team_concert 4.0.1
ibm rational_team_concert 3.0.1.2
ibm rational_team_concert 4.0.5
ibm rational_doors_next_generation 5.0
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_team_concert 4.0.2
ibm rational_quality_manager 5.0.2
ibm rational_collaborative_lifecycle_management 3.0.1.3
ibm rational_collaborative_lifecycle_management 4.0.5
ibm rational_collaborative_lifecycle_management 4.0.7
ibm rational_collaborative_lifecycle_management 5.0.0
ibm rational_requirements_composer 2.0.0.3
ibm rational_collaborative_lifecycle_management 4.0.3
ibm rational_requirements_composer 2.0.0.1
ibm rational_doors_next_generation 4.0.7
ibm rational_team_concert 4.0.0.2
ibm rational_doors_next_generation 4.0.2
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_requirements_composer 3.0.1
ibm rational_collaborative_lifecycle_management 4.0.0
ibm rational_requirements_composer 3.0.1.3
ibm rational_collaborative_lifecycle_management 3.0.1.6
ibm rational_team_concert 3.0.1.4
ibm rational_quality_manager 3.0.1.6
ibm rational_team_concert 3.0.1.1
ibm rational_quality_manager 2.0.0.1
ibm rational_quality_manager 3.0.1.1
ibm rational_requirements_composer 3.0
ibm rational_team_concert 4.0
ibm rational_doors_next_generation 4.0.5
ibm rational_team_concert 5.0.2
ibm rational_requirements_composer 3.0.1.2
ibm rational_quality_manager 2.0.1.1
ibm rational_collaborative_lifecycle_management 4.0.1
ibm rational_team_concert 4.0.3
ibm rational_doors_next_generation 4.0.6
ibm rational_team_concert 3.0
ibm rational_collaborative_lifecycle_management 3.0.1.4
ibm rational_quality_manager 3.0.1.3
ibm rational_doors_next_generation 4.0.3
ibm rational_quality_manager 5.0.1
ibm rational_requirements_composer 2.0.0.4
ibm rational_team_concert 3.0.1
ibm rational_collaborative_lifecycle_management 4.0.2
ibm rational_quality_manager 4.0
ibm rational_quality_manager 3.0
ibm rational_requirements_composer 2.0.0.2
ibm rational_quality_manager 2.0
ibm rational_quality_manager 4.0.1
ibm rational_team_concert 4.0.6
ibm rational_team_concert 5.0.0
ibm rational_collaborative_lifecycle_management 3.0.1
ibm rational_requirements_composer 3.0.1.5
ibm rational_team_concert 3.0.1.5
ibm rational_team_concert 3.0.1.3
ibm rational_quality_manager 3.0.1.2
ibm rational_quality_manager 5.0.0
ibm rational_quality_manager 3.0.1
ibm rational_collaborative_lifecycle_management 3.0.1.1
ibm rational_collaborative_lifecycle_management 3.0.0
ibm rational_doors_next_generation 4.0.4
ibm rational_quality_manager 3.0.1.4
ibm rational_quality_manager 4.0.4
ibm rational_team_concert 4.0.4
ibm rational_collaborative_lifecycle_management 3.0.1.5
ibm rational_quality_manager 4.0.5
ibm rational_doors_next_generation 5.0.2
ibm rational_quality_manager 4.0.2
ibm rational_doors_next_generation 5.0.1
ibm rational_team_concert 3.0.1.6
ibm rational_collaborative_lifecycle_management 4.0.4
ibm rational_team_concert 5.0.1
CVE-2014-6132 LOW

Cross-site scripting (XSS) vulnerability in the Web UI in IBM WebSphere Service Registry and Repository (WSRR) 6.3 through 6.3.0.5, 7.0.x through 7.0.0.5, 7.5.x through 7.5.0.4, 8.0.x before 8.0.0.3, and 8.5.x before 8.5.0.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_service_registry_and_repository 6.3.0
ibm websphere_service_registry_and_repository 8.5
ibm websphere_service_registry_and_repository 6.3.0.4
ibm websphere_service_registry_and_repository 7.0.0.1
ibm websphere_service_registry_and_repository 6.3.0.3
ibm websphere_service_registry_and_repository 8.0.0.2
ibm websphere_service_registry_and_repository 8.0.0.1
ibm websphere_service_registry_and_repository 8.0
ibm websphere_service_registry_and_repository 7.0.0.3
ibm websphere_service_registry_and_repository 7.5.0.3
ibm websphere_service_registry_and_repository 7.0.0.2
ibm websphere_service_registry_and_repository 7.5.0.1
ibm websphere_service_registry_and_repository 7.5.0.2
ibm websphere_service_registry_and_repository 6.3.0.1
ibm websphere_service_registry_and_repository 6.3.0.2
ibm websphere_service_registry_and_repository 7.0.0.5
ibm websphere_service_registry_and_repository 7.0.0
ibm websphere_service_registry_and_repository 6.3.0.5
ibm websphere_service_registry_and_repository 7.0.0.4
ibm websphere_service_registry_and_repository 7.5.0.4
ibm websphere_service_registry_and_repository 7.5.0.0
CVE-2014-6133 LOW

IBM API Management 3.x before 3.0.1.0 allows local users to obtain sensitive ciphertext information via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm api_management 3.0.0.0
ibm api_management 3.0.0.1
CVE-2014-6134 LOW

IBM Rational ClearCase 8.0.0 before 8.0.0.14 and 8.0.1 before 8.0.1.7, when Installation Manager before 1.8.2 is used, retains cleartext server passwords in process memory throughout the installation procedure, which might allow local users to obtain sensitive information by leveraging access to the installation account.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_clearcase 8.0.0.10
ibm rational_clearcase 8.0.1.5
ibm rational_clearcase 8.0.0.1
ibm rational_clearcase 8.0.0.9
ibm rational_clearcase 8.0.0
ibm rational_clearcase 8.0.1.3
ibm rational_clearcase 8.0.0.2
ibm rational_clearcase 8.0.0.11
ibm rational_clearcase 8.0.1.6
ibm rational_clearcase 8.0.1
ibm rational_clearcase 8.0.1.1
ibm rational_clearcase 8.0.0.13
ibm rational_clearcase 8.0.1.2
ibm rational_clearcase 8.0.0.12
ibm rational_clearcase 8.0.0.7
ibm rational_clearcase 8.0.0.3
ibm installation_manager *
ibm rational_clearcase 8.0.0.4
ibm rational_clearcase 8.0.0.6
ibm rational_clearcase 8.0.0.8
ibm rational_clearcase 8.0.0.5
ibm rational_clearcase 8.0.1.4
CVE-2014-6135 MEDIUM

IBM Security AppScan Enterprise 8.5 before 8.5 IFix 002, 8.6 before 8.6 IFix 004, 8.7 before 8.7 IFix 004, 8.8 before 8.8 iFix 003, 9.0 before 9.0.0.1 iFix 003, and 9.0.1 before 9.0.1 iFix 001 allows remote attackers to conduct clickjacking attacks via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm security_appscan 8.8
ibm security_appscan 9.0
ibm security_appscan_source 9.0.1
ibm security_appscan 8.6
ibm security_appscan 8.5
ibm security_appscan 9.0.0.1
ibm security_appscan 8.7
CVE-2014-6136 MEDIUM

IBM Security AppScan Standard 8.x and 9.x before 9.0.1.1 FP1 supports unencrypted sessions, which allows remote attackers to obtain sensitive information by sniffing the network.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm security_appscan 8.0.0.1
ibm security_appscan 9.0.1.0
ibm security_appscan 9.0.1.1
ibm security_appscan 9.0.0.0
ibm security_appscan 8.6.0.1
ibm security_appscan 8.6.0.0
ibm security_appscan 9.0.0.1
ibm security_appscan 8.0.0.3
ibm security_appscan 8.8.0.0
ibm security_appscan 8.5.0.1
ibm security_appscan 8.0.0.2
ibm security_appscan 8.0.0.0
ibm security_appscan 8.7.0.0
ibm security_appscan 8.7.0.1
ibm security_appscan 8.5.0.0
CVE-2014-6137 MEDIUM

Cross-site scripting (XSS) vulnerability in the Relay Diagnostic page in IBM Tivoli Endpoint Manager 9.1 before 9.1.1229 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_endpoint_manager *
CVE-2014-6138 MEDIUM

The IBM WebSphere DataPower XC10 appliance 2.1 and 2.5 before FP4 allows remote authenticated users to bypass intended grid-data access restrictions via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_datapower_xc10_appliance_firmware 2.1.0.0
ibm websphere_datapower_xc10_appliance_firmware 2.5.0.0
CVE-2014-6139 MEDIUM

The Search REST API in IBM Business Process Manager 8.0.1.3, 8.5.0.1, and 8.5.5.0 allows remote authenticated users to bypass intended access restrictions and perform task-instance and process-instance searches by specifying a false value for the filterByCurrentUser parameter.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm business_process_manager 8.5.5.0
ibm business_process_manager 8.5.0.1
ibm business_process_manager 8.0.1.3
CVE-2014-6140 HIGH

IBM Tivoli Endpoint Manager Mobile Device Management (MDM) before 9.0.60100 uses the same secret HMAC token across different customers' installations, which allows remote attackers to execute arbitrary code via crafted marshalled Ruby objects in cookies to (1) Enrollment and Apple iOS Management Extender, (2) Self-service portal, (3) Trusted Services provider, or (4) Admin Portal.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm tivoli_endpoint_manager_mobile_device_management *
CVE-2014-6141 HIGH

IBM Tivoli Monitoring (ITM) 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP09, 6.2.3 through FP05, and 6.3.0 before FP04 allows remote authenticated users to bypass intended access restrictions and execute arbitrary commands by leveraging Take Action view authority to modify in-progress commands.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm tivoli_monitoring 6.2.1.4
ibm tivoli_monitoring 6.2.3
ibm tivoli_monitoring 6.2.2.4
ibm tivoli_monitoring 6.2.2.5
ibm tivoli_monitoring 6.2.2.8
ibm tivoli_monitoring 6.2.1.0
ibm tivoli_monitoring 6.2.3.1
ibm tivoli_monitoring 6.2.3.5
ibm tivoli_monitoring 6.2.3.3
ibm tivoli_monitoring 6.3.0
ibm tivoli_monitoring 6.2.1.3
ibm tivoli_monitoring 6.2.2.3
ibm tivoli_monitoring 6.2.2.7
ibm tivoli_monitoring 6.2.0
ibm tivoli_monitoring 6.3.0.4
ibm tivoli_monitoring 6.2.3.0
ibm tivoli_monitoring 6.2.0.2
ibm tivoli_monitoring 6.3.0.1
ibm tivoli_monitoring 6.3.0.3
ibm tivoli_monitoring 6.2.3.2
ibm tivoli_monitoring 6.2.2.9
ibm tivoli_monitoring 6.2.3.4
ibm tivoli_monitoring 6.3.0.2
ibm tivoli_monitoring 6.2.1.2
ibm tivoli_monitoring 6.2.2
ibm tivoli_monitoring 6.2.0.3
ibm tivoli_monitoring 6.2.1
ibm tivoli_monitoring 6.2.0.1
ibm tivoli_monitoring 6.2.1.1
ibm tivoli_monitoring 6.2.2.0
ibm tivoli_monitoring 6.2.2.1
ibm tivoli_monitoring 6.2.2.2
ibm tivoli_monitoring 6.2.2.6
CVE-2014-6143 LOW

The IBM WebSphere DataPower XC10 appliance 2.1 and 2.5 before FP4 allows local users to obtain sensitive information by reading a response.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_datapower_xc10_appliance_firmware 2.1.0.0
ibm websphere_datapower_xc10_appliance_firmware 2.5.0.0
CVE-2014-6144 LOW

Cross-site scripting (XSS) vulnerability in IBM Rational Quality Manager (RQM) 2.x and 3.x before 3.0.1.6 iFix 5, 4.x before 4.0.7 iFix3, and 5.x before 5.0.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager 2.0.0.1
ibm rational_quality_manager 3.0.1.1
ibm rational_quality_manager 2.0.1.1
ibm rational_quality_manager 2.0.0.2
ibm rational_quality_manager 4.0.0.1
ibm rational_quality_manager 4.0.0.2
ibm rational_quality_manager 3.0.1.3
ibm rational_quality_manager 4.0.7
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 4.0
ibm rational_quality_manager 3.0
ibm rational_quality_manager 2.0.1
ibm rational_quality_manager 2.0
ibm rational_quality_manager 4.0.1
ibm rational_quality_manager 4.0.3
ibm rational_quality_manager 3.0.1.5
ibm rational_quality_manager 3.0.1.2
ibm rational_quality_manager 5.0.0
ibm rational_quality_manager 3.0.1
ibm rational_quality_manager 3.0.1.4
ibm rational_quality_manager 4.0.4
ibm rational_quality_manager 4.0.5
ibm rational_quality_manager 4.0.2
ibm rational_quality_manager 3.0.1.6
CVE-2014-6145 LOW

Cross-site scripting (XSS) vulnerability in the server in IBM Cognos Business Intelligence 10.1 before IF10, 10.1.1 before IF9, 10.2 before IF11, 10.2.1 before IF8, and 10.2.1.1 before IF7 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm cognos_business_intelligence 10.2.1
ibm cognos_business_intelligence 10.2
ibm cognos_business_intelligence 10.1
ibm cognos_business_intelligence 10.2.1.1
ibm cognos_business_intelligence 10.1.1
CVE-2014-6146 LOW

IBM Sterling B2B Integrator 5.2.x through 5.2.4, when the Connect:Direct Server Adapter is configured, does not properly process the logging configuration, which allows local users to obtain sensitive information by reading log files.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2.1
ibm sterling_b2b_integrator 5.2.4
ibm sterling_b2b_integrator 5.2.2
CVE-2014-6147 LOW

IBM Flex System Manager (FSM) 1.1.x.x, 1.2.0.x, 1.2.1.x, 1.3.0.0, 1.3.1.0, and 1.3.2.0 allows local users to obtain sensitive information, and consequently gain privileges or conduct impersonation attacks, via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm flex_system_manager 1.2.0
ibm flex_system_manager 1.1.0
ibm flex_system_manager 1.3.2.0
ibm flex_system_manager 1.3.0
ibm flex_system_manager 1.2.1
ibm flex_system_manager 1.3.1
CVE-2014-6148 LOW

IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.0.0 through 7.2.0.10, 7.2.1.0 through 7.2.1.6, and 7.2.2.0 through 7.2.2.2 does not require TADDM authentication for rptdesign downloads, which allows remote authenticated users to obtain sensitive database information via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm tivoli_application_dependency_discovery_manager 7.2.0.2
ibm tivoli_application_dependency_discovery_manager 7.2.0.8
ibm tivoli_application_dependency_discovery_manager 7.2.2.2
ibm tivoli_application_dependency_discovery_manager 7.2.2.1
ibm tivoli_application_dependency_discovery_manager 7.2.0.5
ibm tivoli_application_dependency_discovery_manager 7.2.0.10
ibm tivoli_application_dependency_discovery_manager 7.2.1.3
ibm tivoli_application_dependency_discovery_manager 7.2.1.2
ibm tivoli_application_dependency_discovery_manager 7.2.1.5
ibm tivoli_application_dependency_discovery_manager 7.2.1.1
ibm tivoli_application_dependency_discovery_manager 7.2.0.9
ibm tivoli_application_dependency_discovery_manager 7.2.0.1
ibm tivoli_application_dependency_discovery_manager 7.2.1
ibm tivoli_application_dependency_discovery_manager 7.2.2
ibm tivoli_application_dependency_discovery_manager 7.2.0.0
ibm tivoli_application_dependency_discovery_manager 7.2.1.6
ibm tivoli_application_dependency_discovery_manager 7.2.0.6
ibm tivoli_application_dependency_discovery_manager 7.2.1.4
ibm tivoli_application_dependency_discovery_manager 7.2.0.7
ibm tivoli_application_dependency_discovery_manager 7.2.0.4
ibm tivoli_application_dependency_discovery_manager 7.2.0.3
CVE-2014-6149 MEDIUM

Directory traversal vulnerability in BIRT-viewer in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.0.0 through 7.2.0.10, 7.2.1.0 through 7.2.1.6, and 7.2.2.0 through 7.2.2.2 allows remote authenticated users to read arbitrary files via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm tivoli_application_dependency_discovery_manager 7.2.0.2
ibm tivoli_application_dependency_discovery_manager 7.2.0.8
ibm tivoli_application_dependency_discovery_manager 7.2.2.2
ibm tivoli_application_dependency_discovery_manager 7.2.2.1
ibm tivoli_application_dependency_discovery_manager 7.2.0.5
ibm tivoli_application_dependency_discovery_manager 7.2.0.10
ibm tivoli_application_dependency_discovery_manager 7.2.1.3
ibm tivoli_application_dependency_discovery_manager 7.2.1.2
ibm tivoli_application_dependency_discovery_manager 7.2.1.5
ibm tivoli_application_dependency_discovery_manager 7.2.1.1
ibm tivoli_application_dependency_discovery_manager 7.2.0.9
ibm tivoli_application_dependency_discovery_manager 7.2.0.1
ibm tivoli_application_dependency_discovery_manager 7.2.1
ibm tivoli_application_dependency_discovery_manager 7.2.2
ibm tivoli_application_dependency_discovery_manager 7.2.0
ibm tivoli_application_dependency_discovery_manager 7.2.1.6
ibm tivoli_application_dependency_discovery_manager 7.2.0.6
ibm tivoli_application_dependency_discovery_manager 7.2.1.4
ibm tivoli_application_dependency_discovery_manager 7.2.0.7
ibm tivoli_application_dependency_discovery_manager 7.2.0.4
ibm tivoli_application_dependency_discovery_manager 7.2.0.3
CVE-2014-6150 LOW

Cross-site scripting (XSS) vulnerability in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.1.0 through 7.2.1.6 and 7.2.2.0 through 7.2.2.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_application_dependency_discovery_manager 7.2.2
ibm tivoli_application_dependency_discovery_manager 7.2.2.2
ibm tivoli_application_dependency_discovery_manager 7.2.1.6
ibm tivoli_application_dependency_discovery_manager 7.2.2.1
ibm tivoli_application_dependency_discovery_manager 7.2.1.3
ibm tivoli_application_dependency_discovery_manager 7.2.1.4
ibm tivoli_application_dependency_discovery_manager 7.2.1.2
ibm tivoli_application_dependency_discovery_manager 7.2.1.5
ibm tivoli_application_dependency_discovery_manager 7.2.1.1
ibm tivoli_application_dependency_discovery_manager 7.2.1
CVE-2014-6151 LOW

CRLF injection vulnerability in IBM Tivoli Integrated Portal (TIP) 2.2.x allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm tivoli_integrated_portal 2.2
ibm tivoli_integrated_portal 2.1
CVE-2014-6152 LOW

Multiple cross-site scripting (XSS) vulnerabilities in IBM Tivoli Integrated Portal (TIP) 2.2.x allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_integrated_portal 2.2
ibm tivoli_integrated_portal 2.1
CVE-2014-6153 MEDIUM

The Web UI in IBM WebSphere Service Registry and Repository (WSRR) 6.3.x through 6.3.0.5, 7.0.x through 7.0.0.5, 7.5.x through 7.5.0.4, 8.0.x before 8.0.0.3, and 8.5.x before 8.5.0.1 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm websphere_service_registry_and_repository 6.3.0
ibm websphere_service_registry_and_repository 8.5
ibm websphere_service_registry_and_repository 6.3.0.4
ibm websphere_service_registry_and_repository 7.0.0.1
ibm websphere_service_registry_and_repository 6.3.0.3
ibm websphere_service_registry_and_repository 8.0.0.2
ibm websphere_service_registry_and_repository 8.0.0.1
ibm websphere_service_registry_and_repository 8.0
ibm websphere_service_registry_and_repository 7.0.0.3
ibm websphere_service_registry_and_repository 7.5.0.3
ibm websphere_service_registry_and_repository 7.0.0.2
ibm websphere_service_registry_and_repository 7.5.0.1
ibm websphere_service_registry_and_repository 7.5.0.2
ibm websphere_service_registry_and_repository 6.3.0.1
ibm websphere_service_registry_and_repository 6.3.0.2
ibm websphere_service_registry_and_repository 7.0.0.5
ibm websphere_service_registry_and_repository 7.0.0
ibm websphere_service_registry_and_repository 6.3.0.5
ibm websphere_service_registry_and_repository 7.0.0.4
ibm websphere_service_registry_and_repository 7.5.0.4
ibm websphere_service_registry_and_repository 7.5.0.0
CVE-2014-6154 HIGH

Directory traversal vulnerability in IBM Optim Performance Manager for DB2 4.1.0.1 through 4.1.1 on Linux, UNIX, and Windows and IBM InfoSphere Optim Performance Manager for DB2 5.1 through 5.3.1 on Linux, UNIX, and Windows allows remote attackers to access arbitrary files via a .. (dot dot) in a URL.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm optim_performance_manager 4.1.1.1
ibm optim_performance_manager 5.1.0
ibm optim_performance_manager 4.1.1
CVE-2014-6155 MEDIUM

Multiple directory traversal vulnerabilities in the ServiceRegistry UI in IBM WebSphere Service Registry and Repository (WSRR) 7.5.x through 7.5.0.4, 8.0.x before 8.0.0.3, and 8.5.x before 8.5.0.1 allow remote authenticated users to read arbitrary files via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm websphere_service_registry_and_repository 8.0
ibm websphere_service_registry_and_repository 8.5
ibm websphere_service_registry_and_repository 7.5.0.3
ibm websphere_service_registry_and_repository 7.5.0.1
ibm websphere_service_registry_and_repository 7.5.0.2
ibm websphere_service_registry_and_repository 8.0.0.2
ibm websphere_service_registry_and_repository 8.0.0.1
ibm websphere_service_registry_and_repository 7.5.0.4
ibm websphere_service_registry_and_repository 7.5.0.0
CVE-2014-6158 HIGH

Multiple directory traversal vulnerabilities in the file-upload feature in IBM PureApplication System 1.0 before 1.0.0.4 iFix 10, 1.1 before 1.1.0.5, and 2.0 before 2.0.0.1 and Workload Deployer 3.1.0.7 before IF5 allow remote authenticated users to execute arbitrary code via a (1) Script Package, (2) Add-On, or (3) Emergency Fixes component.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm pureapplication_system 1.1.0.2
ibm pureapplication_system 1.0.0.0
ibm pureapplication_system 1.1.0.3
ibm pureapplication_system 1.0.0.1
ibm pureapplication_system 1.1.0.0
ibm pureapplication_system 1.1.0.4
ibm pureapplication_system 1.0.0.2
ibm pureapplication_system 1.0.0.3
ibm pureapplication_system 2.0.0.0
ibm pureapplication_system 1.1.0.1
ibm workload_deployer 3.1.0.7
CVE-2014-6159 LOW

IBM DB2 9.7 before FP10, 9.8 through FP5, 10.1 through FT4, and 10.5 through FP4 on Linux, UNIX, and Windows, when immediate AUTO_REVAL is enabled, allows remote authenticated users to cause a denial of service (daemon crash) via a crafted ALTER TABLE statement.

CVSS 2.0

Severity: LOW

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2 10.1
ibm db2 9.8
ibm db2 9.7
CVE-2014-6160 LOW

IBM WebSphere Service Registry and Repository (WSRR) 8.5 before 8.5.0.1, when Chrome and WebSEAL are used, does not properly process ServiceRegistryDashboard logout actions, which allows remote attackers to bypass intended access restrictions by leveraging an unattended workstation.

CVSS 2.0

Severity: LOW

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_service_registry_and_repository 8.5
CVE-2014-6161 LOW

Cross-site scripting (XSS) vulnerability in IBM Tivoli Netcool/Impact 6.1.1 before 6.1.1.1-TIV-NCI-IF0001 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_netcool/impact 6.1.1
CVE-2014-6163 LOW

Cross-site scripting (XSS) vulnerability on the IBM WebSphere DataPower XC10 appliance 2.1 and 2.5 before FP4 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_datapower_xc10_appliance_firmware 2.1.0.0
ibm websphere_datapower_xc10_appliance_firmware 2.5.0.0
CVE-2014-6164 MEDIUM

IBM WebSphere Application Server 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.4 allows remote attackers to spoof OpenID and OpenID Connect cookies, and consequently obtain sensitive information, via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_application_server 8.0.0.8
ibm websphere_application_server 8.0.0.5
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 8.5.5.0
ibm websphere_application_server 8.5.0.2
ibm websphere_application_server 8.0.0.6
ibm websphere_application_server 8.5.5.2
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 8.0.0.7
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 8.0.0.9
ibm websphere_application_server 8.5.5.3
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 8.5.5.1
ibm websphere_application_server 8.0.0.2
CVE-2014-6166 MEDIUM

The Communications Enabled Applications (CEA) service in IBM WebSphere Application Server 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.4, and Feature Pack for CEA 1.x before 1.0.0.15, allows remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_application_server 8.0.0.8
ibm websphere_application_server 8.0.0.5
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 8.5.5.0
ibm websphere_application_server 8.5.0.2
ibm websphere_application_server 8.0.0.6
ibm websphere_application_server 8.5.5.2
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 8.0.0.7
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 8.0.0.9
ibm websphere_application_server 8.5.5.3
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 8.5.5.1
ibm websphere_application_server 8.0.0.2
CVE-2014-6167 MEDIUM

Cross-site scripting (XSS) vulnerability in the URL rewriting feature in IBM WebSphere Application Server 7.x before 7.0.0.37, 8.0.x before 8.0.0.10, and 8.5.x before 8.5.5.4 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 7.0.0.12
ibm websphere_application_server 8.0.0.6
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 8.5.5.2
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 7.0.0.16
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 7.0.0.25
ibm websphere_application_server 8.0.0.9
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 7.0.0.14
ibm websphere_application_server 7.0.0.22
ibm websphere_application_server 7.0.0.31
ibm websphere_application_server 7.0.0.10
ibm websphere_application_server 8.0.0.8
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 8.0.0.7
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 7.0.0.27
ibm websphere_application_server 7.0.0.18
ibm websphere_application_server 8.5.5.3
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 8.0.0.2
ibm websphere_application_server 8.0.0.5
ibm websphere_application_server 8.5.0.2
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 7.0.0.33
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 7.0.0.32
ibm websphere_application_server 7.0.0.29
ibm websphere_application_server 7.0.0.24
ibm websphere_application_server 8.5.5.0
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 7.0.0.34
ibm websphere_application_server 7.0.0.35
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 8.5.5.1
ibm websphere_application_server 7.0.0.4
CVE-2014-6168 MEDIUM

Cross-site request forgery (CSRF) vulnerability in IBM Security Identity Manager 5.1 before 5.1.0.15 IF0056 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm security_identity_manager 5.1.0.11
ibm security_identity_manager 5.1.0
ibm security_identity_manager 5.1.0.8
ibm security_identity_manager 5.1.0.14
ibm security_identity_manager 5.1.0.4
ibm security_identity_manager 5.1.0.6
ibm security_identity_manager 5.1.0.5
ibm security_identity_manager 5.1.0.7
ibm security_identity_manager 5.1.0.9
ibm security_identity_manager 5.1.0.10
ibm security_identity_manager 5.1.0.13
ibm security_identity_manager 5.1.0.3
ibm security_identity_manager 5.1.0.15
ibm security_identity_manager 5.1.0.12
CVE-2014-6169 LOW

Cross-site scripting (XSS) vulnerability in IBM Forms Experience Builder 8.5.0 and 8.5.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 97777.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm forms_experience_builder 8.5.1
ibm forms_experience_builder 8.5
CVE-2014-6170 MEDIUM

The HTTPInput node in IBM WebSphere Message Broker 7.0 before 7.0.0.8 and 8.0 before 8.0.0.6 and IBM Integration Bus 9.0 before 9.0.0.4 allows remote attackers to obtain sensitive information by triggering a SOAP fault.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_message_broker 7.0.0.1
ibm websphere_message_broker 7.0.0.2
ibm websphere_message_broker 8.0
ibm websphere_message_broker 7.0.0.5
ibm integration_bus 9.0.0.2
ibm websphere_message_broker 7.0.0.4
ibm websphere_message_broker 7.0.0.6
ibm websphere_message_broker 8.0.0.4
ibm websphere_message_broker 8.0.0.3
ibm integration_bus 9.0
ibm websphere_message_broker 8.0.0.2
ibm websphere_message_broker 7.0.0.3
ibm websphere_message_broker 8.0.0.5
ibm websphere_message_broker 7.0.
ibm integration_bus 9.0.0.1
ibm websphere_message_broker 8.0.0.1
ibm integration_bus 9.0.0.3
ibm websphere_message_broker 7.0.0.7
CVE-2014-6171 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 through 8.0.0.1 CF14, and 8.5.0 before CF04 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.0
ibm websphere_portal 6.1.0.3
ibm websphere_portal 7.0.0.1
ibm websphere_portal 6.1.5.2
ibm websphere_portal 6.1.0.2
ibm websphere_portal 6.1.0.4
ibm websphere_portal 8.0.0.1
ibm websphere_portal 7.0.0.2
ibm websphere_portal 8.5.0.0
ibm websphere_portal 6.1.5.0
ibm websphere_portal 6.1.0.6
ibm websphere_portal 6.1.5.3
ibm websphere_portal 7.0.0.0
ibm websphere_portal 6.1.0.1
ibm websphere_portal 6.1.5.1
ibm websphere_portal 6.1.0.5
ibm websphere_portal 6.1.0.0
CVE-2014-6172 MEDIUM

IBM API Management 3.0 before 3.0.4.0 IF1 allows remote attackers to obtain sensitive analytics information in an encrypted form via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm api_management 3.0.2.0
ibm api_management 3.0.0.0
ibm api_management 3.0.4.0
ibm api_management 3.0.3.0
ibm api_management 3.0.0.1
ibm api_management 3.0.2.1
CVE-2014-6173 LOW

Cross-site scripting (XSS) vulnerability in the Process Inspector in IBM Business Process Manager (BPM) 8.0.x through 8.0.1.3 and 8.5.x through 8.5.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm business_process_manager 8.0.1.2
ibm business_process_manager 8.0.1.1
ibm business_process_manager 8.5.5.0
ibm business_process_manager 8.0.1.0
ibm business_process_manager 8.0.0.0
ibm business_process_manager 8.5.0.1
ibm business_process_manager 8.0.1.3
ibm business_process_manager 8.5.0.0
CVE-2014-6174 MEDIUM

IBM WebSphere Application Server 7.x before 7.0.0.37, 8.0.x before 8.0.0.10, and 8.5.x before 8.5.5.4 allows remote attackers to conduct clickjacking attacks via a crafted web site.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-254,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 7.0.0.12
ibm websphere_application_server 8.0.0.6
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 8.5.5.2
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 7.0.0.16
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 7.0.0.25
ibm websphere_application_server 8.0.0.9
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 7.0.0.14
ibm websphere_application_server 7.0.0.22
ibm websphere_application_server 7.0.0.31
ibm websphere_application_server 7.0.0.10
ibm websphere_application_server 8.0.0.8
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 8.0.0.7
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 7.0.0.27
ibm websphere_application_server 7.0.0.18
ibm websphere_application_server 8.5.5.3
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 8.0.0.2
ibm websphere_application_server 8.0.0.5
ibm websphere_application_server 8.5.0.2
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 7.0.0.33
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 7.0.0.32
ibm websphere_application_server 7.0.0.29
ibm websphere_application_server 7.0.0.24
ibm websphere_application_server 8.5.5.0
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 7.0.0.34
ibm websphere_application_server 7.0.0.35
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 8.5.5.1
ibm websphere_application_server 7.0.0.4
CVE-2014-6175 LOW

Cross-site scripting (XSS) vulnerability in IBM Marketing Operations 7.x and 8.x before 8.5.0.7.2, 8.6.x before 8.6.0.8, 9.0.x before 9.0.0.4.1, 9.1.0.x before 9.1.0.5, and 9.1.1.x before 9.1.1.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm marketing_operations 7.4.2.7
ibm marketing_operations 7.3.2.0
ibm marketing_operations 8.1.0.7
ibm marketing_operations 8.1.1.0
ibm marketing_operations 7.5.3.7
ibm marketing_operations 8.2.0.5
ibm marketing_operations 7.2.0.4
ibm marketing_operations 7.4.0.0
ibm marketing_operations 8.2.0.8
ibm marketing_operations 8.2.0.10
ibm marketing_operations 9.0.0.2
ibm marketing_operations 7.4.2.0
ibm marketing_operations 8.0.0.0
ibm marketing_operations 8.6.0.6
ibm marketing_operations 8.6.0.5
ibm marketing_operations 8.2.0.9
ibm marketing_operations 9.0.0.3
ibm marketing_operations 9.1.0.4
ibm marketing_operations 8.0.0.2
ibm marketing_operations 9.0.0.1
ibm marketing_operations 8.2.0.6
ibm marketing_operations 8.5.0.7
ibm marketing_operations 8.2.0.12
ibm marketing_operations 7.3.2.8
ibm marketing_operations 9.1.1.0
ibm marketing_operations 8.1.0.0
ibm marketing_operations 8.1.0.6
ibm marketing_operations 8.6.0.0
ibm marketing_operations 7.5.3.9
ibm marketing_operations 8.2.0.7
ibm marketing_operations 8.2.0.11
ibm marketing_operations 8.5.0.2
ibm marketing_operations 8.5.0.6
ibm marketing_operations 8.5.0.3
ibm marketing_operations 9.1.1.1
ibm marketing_operations 8.6.0.4
ibm marketing_operations 8.6.0.7
ibm marketing_operations 7.4.1.6
ibm marketing_operations 8.1.1.4
ibm marketing_operations 8.5.0.4
ibm marketing_operations 9.0.0.4
ibm marketing_operations 7.4.1.0
ibm marketing_operations 7.5.0.0
ibm marketing_operations 7.2.1.0
ibm marketing_operations 7.5.0.1
ibm marketing_operations 8.5.0.5
ibm marketing_operations 7.5.3.0
ibm marketing_operations 7.5.2.0
ibm marketing_operations 9.0.0.0
ibm marketing_operations 9.1.0.3
ibm marketing_operations 8.2.0.13
ibm marketing_operations 8.6.0.3
ibm marketing_operations 8.5.0.1
ibm marketing_operations 7.2.1.12
ibm marketing_operations 8.6.0.2
ibm marketing_operations 8.5.0.0
ibm marketing_operations 8.2.0.0
ibm marketing_operations 7.2.0.0
ibm marketing_operations 7.5.2.3
ibm marketing_operations 9.1.0.2
ibm marketing_operations 9.1.0.0
ibm marketing_operations 7.5.3.8
ibm marketing_operations 7.4.0.2
ibm marketing_operations 7.3.2.1
CVE-2014-6176 MEDIUM

IBM WebSphere Process Server 7.0, WebSphere Enterprise Service Bus 7.0, and Business Process Manager Advanced 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, and 8.5.x through 8.5.5 disregard the SSL setting in the SCA module HTTP import binding and unconditionally select the SSLv3 protocol, which makes it easier for remote attackers to hijack sessions or obtain sensitive information by leveraging the use of a weak cipher.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm business_process_manager 8.0.1.2
ibm business_process_manager 8.0.1.1
ibm business_process_manager 7.5.0.1
ibm business_process_manager 7.5.1.0
ibm business_process_manager 7.5.1.1
ibm websphere_enterprise_service_bus 7.0
ibm business_process_manager 8.5.5.0
ibm business_process_manager 8.0.1.0
ibm business_process_manager 8.0.0.0
ibm business_process_manager 8.5.0.1
ibm business_process_manager 8.0.1.3
ibm business_process_manager 8.5.0.0
ibm websphere_process_server 7.0
ibm business_process_manager 7.5.0.0
CVE-2014-6177 MEDIUM

IBM WebSphere Service Registry and Repository (WSRR) 7.0.x before 7.0.0.5 and 7.5.x before 7.5.0.3 does not perform access-control checks for depth-0 retrieve operations, which allows remote authenticated users to obtain sensitive information via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_service_registry_and_repository 7.0.0.3
ibm websphere_service_registry_and_repository 7.0.0.2
ibm websphere_service_registry_and_repository 7.5.0.1
ibm websphere_service_registry_and_repository 7.5.0.2
ibm websphere_service_registry_and_repository 7.0.0
ibm websphere_service_registry_and_repository 7.0.0.4
ibm websphere_service_registry_and_repository 7.0.0.1
ibm websphere_service_registry_and_repository 7.5.0.0
CVE-2014-6178 LOW

Cross-site scripting (XSS) vulnerability in the widgets in IBM WebSphere Service Registry and Repository (WSRR) 7.5.x before 7.5.0.4 and 8.0.x before 8.0.0.3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_service_registry_and_repository 8.0
ibm websphere_service_registry_and_repository 7.5.0.3
ibm websphere_service_registry_and_repository 7.5.0.1
ibm websphere_service_registry_and_repository 7.5.0.2
ibm websphere_service_registry_and_repository 8.0.0.2
ibm websphere_service_registry_and_repository 8.0.0.1
ibm websphere_service_registry_and_repository 7.5.0.0
CVE-2014-6179 MEDIUM

Cross-site scripting (XSS) vulnerability in the Web UI in IBM WebSphere Service Registry and Repository (WSRR) 7.5.x before 7.5.0.4 and 8.0.x before 8.0.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_service_registry_and_repository 8.0
ibm websphere_service_registry_and_repository 7.5.0.3
ibm websphere_service_registry_and_repository 7.5.0.1
ibm websphere_service_registry_and_repository 7.5.0.2
ibm websphere_service_registry_and_repository 8.0.0.1
ibm websphere_service_registry_and_repository 7.5.0.0
CVE-2014-6180 LOW

Cross-site scripting (XSS) vulnerability in the Web UI in IBM WebSphere Service Registry and Repository (WSRR) 7.0.x before 7.0.0.5 and 7.5.x before 7.5.0.1 allows remote authenticated users to inject arbitrary web script or HTML via the HTTP User-Agent header.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_service_registry_and_repository 7.0.0.3
ibm websphere_service_registry_and_repository 7.0.0.2
ibm websphere_service_registry_and_repository 7.0.0
ibm websphere_service_registry_and_repository 7.0.0.4
ibm websphere_service_registry_and_repository 7.0.0.1
ibm websphere_service_registry_and_repository 7.5.0.0
CVE-2014-6181 MEDIUM

IBM WebSphere Service Registry and Repository (WSRR) 7.0.x before 7.0.0.5 does not perform access-control checks for contained objects, which allows remote authenticated users to obtain sensitive information via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_service_registry_and_repository 7.0.0.3
ibm websphere_service_registry_and_repository 7.0.0.2
ibm websphere_service_registry_and_repository 7.0.0
ibm websphere_service_registry_and_repository 7.0.0.4
ibm websphere_service_registry_and_repository 7.0.0.1
CVE-2014-6182 MEDIUM

Directory traversal vulnerability in an export function in the Process Center in IBM Business Process Manager (BPM) 8.0.x through 8.0.1.3 and 8.5.x through 8.5.5 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm business_process_manager 8.0.1.2
ibm business_process_manager 8.0.1.1
ibm business_process_manager 8.5.5.0
ibm business_process_manager 8.0.1.0
ibm business_process_manager 8.0.0.0
ibm business_process_manager 8.5.0.1
ibm business_process_manager 8.0.1.3
ibm business_process_manager 8.5.0.0
CVE-2014-6183 MEDIUM

IBM Security Network Protection 5.1 before 5.1.0.0 FP13, 5.1.1 before 5.1.1.0 FP8, 5.1.2 before 5.1.2.0 FP9, 5.1.2.1 before FP5, 5.2 before 5.2.0.0 FP5, and 5.3 before 5.3.0.0 FP1 on XGS devices allows remote authenticated users to execute arbitrary commands via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm security_network_protection_firmware 5.1
ibm security_network_protection_firmware 5.1.1
ibm security_network_protection_firmware 5.2.0.0
ibm security_network_protection_firmware 5.3
ibm security_network_protection_xgs_5000 *
ibm security_network_protection_firmware 5.1.0.0
ibm security_network_protection_xgs_5100 -
ibm security_network_protection_firmware 5.1.1.0
ibm security_network_protection_firmware 5.1.2.1
ibm security_network_protection_firmware 5.1.2.0
CVE-2014-6184 HIGH

Stack-based buffer overflow in dsmtca in the client in IBM Tivoli Storage Manager (TSM) 5.4 through 5.4.3.6, 5.5 through 5.5.4.3, 6.1 through 6.1.5.6, 6.2 before 6.2.5.4, and 6.3 before 6.3.2.3 on UNIX, Linux, and OS X allows local users to gain privileges via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-787,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager *
CVE-2014-6185 HIGH

dsmtca in the client in IBM Tivoli Storage Manager (TSM) 6.3 before 6.3.2.3, 6.4 before 6.4.2.2, and 7.1 before 7.1.1.3 does not properly restrict shared-library loading, which allows local users to gain privileges via a crafted DSO file.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager 7.1.1.1
ibm tivoli_storage_manager 6.3.2.2
ibm tivoli_storage_manager 6.4.0.7
ibm tivoli_storage_manager 6.4.1.7
ibm tivoli_storage_manager 7.1.1
ibm tivoli_storage_manager 6.4.1.3
ibm tivoli_storage_manager 6.3.0.5
ibm tivoli_storage_manager 6.4.2.1
ibm tivoli_storage_manager 6.3.1.2
ibm tivoli_storage_manager 7.1.0.2
ibm tivoli_storage_manager 6.3.0.15
ibm tivoli_storage_manager 6.4.0.4
ibm tivoli_storage_manager 6.4.1
ibm tivoli_storage_manager 7.1.0
ibm tivoli_storage_manager 6.4.0.5
ibm tivoli_storage_manager 6.4.2
ibm tivoli_storage_manager 6.4.0.1
ibm tivoli_storage_manager 6.4.0
ibm tivoli_storage_manager 6.3.2.1
ibm tivoli_storage_manager 7.1.0.3
ibm tivoli_storage_manager 7.1.0.1
ibm tivoli_storage_manager 6.3.0
CVE-2014-6186 MEDIUM

IBM WebSphere Service Registry and Repository (WSRR) 6.3.x before 6.3.0.5, 7.0.x through 7.0.0.5, 7.5.x before 7.5.0.3, and 8.0.x before 8.0.0.1 allows remote authenticated users to bypass intended object-access restrictions via the datagraph.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_service_registry_and_repository 6.3.0
ibm websphere_service_registry_and_repository 6.3.0.4
ibm websphere_service_registry_and_repository 7.0.0.1
ibm websphere_service_registry_and_repository 6.3.0.3
ibm websphere_service_registry_and_repository 8.0
ibm websphere_service_registry_and_repository 7.0.0.3
ibm websphere_service_registry_and_repository 7.0.0.2
ibm websphere_service_registry_and_repository 7.5.0.1
ibm websphere_service_registry_and_repository 7.5.0.2
ibm websphere_service_registry_and_repository 6.3.0.1
ibm websphere_service_registry_and_repository 6.3.0.2
ibm websphere_service_registry_and_repository 7.0.0.5
ibm websphere_service_registry_and_repository 7.0.0
ibm websphere_service_registry_and_repository 7.0.0.4
ibm websphere_service_registry_and_repository 7.5.0.0
CVE-2014-6187 MEDIUM

Multiple cross-site request forgery (CSRF) vulnerabilities in IBM WebSphere Service Registry and Repository (WSRR) 6.3.x before 6.3.0.5, 7.0.x before 7.0.0.5, 7.5.x before 7.5.0.3, and 8.0.x before 8.0.0.2 allow remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm websphere_service_registry_and_repository 6.3.0
ibm websphere_service_registry_and_repository 6.3.0.4
ibm websphere_service_registry_and_repository 7.0.0.1
ibm websphere_service_registry_and_repository 6.3.0.3
ibm websphere_service_registry_and_repository 8.0.0.1
ibm websphere_service_registry_and_repository 8.0
ibm websphere_service_registry_and_repository 7.0.0.3
ibm websphere_service_registry_and_repository 7.0.0.2
ibm websphere_service_registry_and_repository 7.5.0.1
ibm websphere_service_registry_and_repository 7.5.0.2
ibm websphere_service_registry_and_repository 6.3.0.1
ibm websphere_service_registry_and_repository 6.3.0.2
ibm websphere_service_registry_and_repository 7.0.0
ibm websphere_service_registry_and_repository 7.0.0.4
ibm websphere_service_registry_and_repository 7.5.0.0
CVE-2014-6188 LOW

Multiple cross-site scripting (XSS) vulnerabilities in IBM WebSphere Service Registry and Repository (WSRR) 6.3.x before 6.3.0.5, 7.0.x through 7.0.0.5, 7.5.x before 7.5.0.3, and 8.0.x before 8.0.0.2 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_service_registry_and_repository 6.3.0
ibm websphere_service_registry_and_repository 6.3.0.4
ibm websphere_service_registry_and_repository 7.0.0.1
ibm websphere_service_registry_and_repository 6.3.0.3
ibm websphere_service_registry_and_repository 8.0.0.1
ibm websphere_service_registry_and_repository 8.0
ibm websphere_service_registry_and_repository 7.0.0.3
ibm websphere_service_registry_and_repository 7.0.0.2
ibm websphere_service_registry_and_repository 7.5.0.1
ibm websphere_service_registry_and_repository 7.5.0.2
ibm websphere_service_registry_and_repository 6.3.0.1
ibm websphere_service_registry_and_repository 6.3.0.2
ibm websphere_service_registry_and_repository 7.0.0.5
ibm websphere_service_registry_and_repository 7.0.0
ibm websphere_service_registry_and_repository 7.0.0.4
ibm websphere_service_registry_and_repository 7.5.0.0
CVE-2014-6189 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Security Network Protection 3100, 4100, 5100, and 7100 devices with firmware 5.2 before 5.2.0.0-ISS-XGS-All-Models-Hotfix-FP0008 and 5.3 before 5.3.0.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm security_network_protection_3100_firmware 5.3
ibm security_network_protection_4100_firmware 5.2
ibm security_network_protection_5100_firmware 5.2
ibm security_network_protection_7100_firmware 5.2
ibm security_network_protection_7100_firmware 5.3
ibm security_network_protection_5100_firmware 5.3
ibm security_network_protection_4100_firmware 5.3
ibm security_network_protection_3100_firmware 5.2
CVE-2014-6190 MEDIUM

The log viewer in IBM Workload Deployer 3.1 before 3.1.0.7 allows remote attackers to obtain sensitive information via a direct request for the URL of a log document.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm workload_deployer 3.1.0.6
ibm workload_deployer 3.1.0.2
ibm workload_deployer 3.1.0
ibm workload_deployer 3.1.0.1
CVE-2014-6191 LOW

Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management 6.0 SP2, 6.0.4, and 6.0.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 98568.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm curam_social_program_management 6.0
ibm curam_social_program_management 6.0.4.3
ibm curam_social_program_management 6.0.5.4
ibm curam_social_program_management 6.0.4.4
ibm curam_social_program_management 6.0.4.1
ibm curam_social_program_management 6.0.4.0
ibm curam_social_program_management 6.0.5.0
ibm curam_social_program_management 6.0.5.5
ibm curam_social_program_management 6.0.5.2
ibm curam_social_program_management 6.0.5.1
ibm curam_social_program_management 6.0.5.3
ibm curam_social_program_management 6.0.4.2
ibm curam_social_program_management 6.0.4.5
CVE-2014-6192 LOW

Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management 6.0 SP2 before EP26, 6.0.4 before 6.0.4.5 iFix10, 6.0.5 before 6.0.5.6, and 6.0.5.5a before 6.0.5.8 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm curam_social_program_management 6.0.5.5a
ibm curam_social_program_management 6.0
ibm curam_social_program_management 6.0.4.3
ibm curam_social_program_management 6.0.5.4
ibm curam_social_program_management 6.0.4.4
ibm curam_social_program_management 6.0.4.1
ibm curam_social_program_management 6.0.4.0
ibm curam_social_program_management 6.0.5.0
ibm curam_social_program_management 6.0.5.5
ibm curam_social_program_management 6.0.5.2
ibm curam_social_program_management 6.0.5.1
ibm curam_social_program_management 6.0.5.7
ibm curam_social_program_management 6.0.5.6
ibm curam_social_program_management 6.0.5.3
ibm curam_social_program_management 6.0.4.2
ibm curam_social_program_management 6.0.4.5
CVE-2014-6193 MEDIUM

IBM WebSphere Portal 8.0.0 through 8.0.0.1 CF14 and 8.5.0 before CF04, when the Managed Pages setting is enabled, allows remote authenticated users to write to pages via an XML injection attack.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.1
ibm websphere_portal 8.0.0.0
ibm websphere_portal 8.5.0.0
CVE-2014-6194 MEDIUM

Directory traversal vulnerability in an unspecified web form in IBM Maximo Asset Management 7.1 through 7.1.1.13 and 7.5.0 before 7.5.0.6 IFIX007, Maximo Asset Management 7.5.0 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk, and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products allows remote authenticated users to read arbitrary files via a .. (dot dot) in a pathname.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm tivoli_asset_management_for_it 7.2
ibm maximo_asset_management 7.1.1.9
ibm maximo_for_government 7.1
ibm maximo_asset_management 7.1.1.13
ibm maximo_asset_management 7.1.1.10
ibm maximo_asset_management 7.1.1.1
ibm maximo_for_nuclear_power 7.5.0.0
ibm smartcloud_control_desk 7.5.0.5
ibm maximo_asset_management_essentials 7.5.0.0
ibm maximo_for_nuclear_power 7.1
ibm maximo_for_life_sciences 7.1
ibm maximo_asset_management 7.5.0.6
ibm maximo_asset_management 7.1.1.7
ibm smartcloud_control_desk 7.5.1.1
ibm smartcloud_control_desk 7.5.0.2
ibm maximo_asset_management 7.5.0.5
ibm maximo_asset_management 7.1.1.2
ibm maximo_for_oil_and_gas 7.1
ibm maximo_asset_management 7.1.1.5
ibm tivoli_service_request_manager 7.2
ibm smartcloud_control_desk 7.5.1.0
ibm maximo_asset_management 7.1.1.11
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.5.0.1
ibm maximo_for_transportation 7.5.0.0
ibm maximo_asset_management 7.5.0.10
ibm maximo_for_life_sciences 7.5.0.0
ibm maximo_for_utilities 7.1
ibm maximo_for_government 7.5.0.0
ibm change_and_configuration_management_database 7.1
ibm maximo_asset_management 7.1.1.12
ibm change_and_configuration_management_database 7.2
ibm maximo_asset_management 7.5.0.3
ibm maximo_for_utilities 7.5.0.0
ibm tivoli_asset_management_for_it 7.1
ibm maximo_for_transportation 7.1
ibm tivoli_service_request_manager 7.1
ibm maximo_asset_management_essentials 7.1
ibm maximo_asset_management 7.5.0.0
ibm maximo_asset_management 7.5.0.4
ibm maximo_for_oil_and_gas 7.5.0.0
ibm smartcloud_control_desk 7.5.0.1
ibm maximo_asset_management 7.1.1.6
ibm maximo_asset_management 7.1.2
ibm smartcloud_control_desk 7.5.0.3
CVE-2014-6195 LOW

The (1) Java GUI and (2) Web GUI components in the IBM Tivoli Storage Manager (TSM) Backup-Archive client 5.4 and 5.5 before 5.5.4.4 on AIX, Linux, and Solaris; 5.4.x and 5.5.x on Windows and z/OS; 6.1 before 6.1.5.7 on z/OS; 6.1 and 6.2 before 6.2.5.2 on Windows, before 6.2.5.3 on AIX and Linux x86, and before 6.2.5.4 on Linux Z and Solaris; 6.3 before 6.3.2.1 on AIX, before 6.3.2.2 on Windows, and before 6.3.2.3 on Linux; 6.4 before 6.4.2.1; and 7.1 before 7.1.1 in IBM TSM for Mail, when the Data Protection for Lotus Domino component is used, allow local users to bypass authentication and restore a Domino database or transaction-log backup via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager 6.3
ibm tivoli_storage_manager 5.4
ibm tivoli_storage_manager 6.2
ibm tivoli_storage_manager 5.5
ibm tivoli_storage_manager 7.1
ibm tivoli_storage_manager 6.1
ibm tivoli_storage_manager 6.4
CVE-2014-6196 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Web Experience Factory (WEF) 6.1.5 through 8.5.0.1, as used in WebSphere Dashboard Framework (WDF) and Lotus Widget Factory (LWF), allows remote attackers to inject arbitrary web script or HTML by leveraging a Dojo builder error in an unspecified WebSphere Portal configuration, leading to improper construction of a response page by an application.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm web_experience_factory 7.0.1.1
ibm web_experience_factory 6.1.5
ibm web_experience_factory 8.0.0
ibm web_experience_factory 8.0.0.2
ibm web_experience_factory 7.0.1.2
ibm web_experience_factory 7.0.1.3
ibm web_experience_factory 8.0.0.1
ibm web_experience_factory 8.5.0.1
ibm web_experience_factory 7.0.1.4
ibm web_experience_factory 8.0
ibm web_experience_factory 7.0.1
ibm web_experience_factory 8.0.0.3
ibm web_experience_factory 8.5
CVE-2014-6197 MEDIUM

IBM Security Network Protection 5.1.x and 5.2.x before 5.2.0.0 FP5 and 5.3.x before 5.3.0.0 FP1 allows remote attackers to conduct clickjacking attacks via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm security_network_protection_xgs_firmware 5.1
ibm security_network_protection_xgs_firmware 5.3
ibm security_network_protection_xgs_firmware 5.1.2.1
ibm security_network_protection_xgs_firmware 5.1.2
ibm security_network_protection_xgs_firmware 5.2
ibm security_network_protection_xgs_firmware 5.1.1
CVE-2014-6198 MEDIUM

Cross-site request forgery (CSRF) vulnerability in IBM Security Network Protection 5.3 before 5.3.1 allows remote attackers to hijack the authentication of arbitrary users.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm security_network_protection_firmware 5.3
CVE-2014-6199 MEDIUM

The HTTP Server Adapter in IBM Sterling B2B Integrator 5.1 and 5.2.x and Sterling File Gateway 2.1 and 2.2 allows remote attackers to cause a denial of service (connection-slot exhaustion) via a crafted HTTP request.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2
ibm sterling_b2b_integrator 5.1
ibm sterling_b2b_integrator 5.2.1
ibm sterling_b2b_integrator 5.2.5.0
ibm sterling_b2b_integrator 5.2.4.2
ibm sterling_file_gateway 2.2
ibm sterling_b2b_integrator 5.2.4
ibm sterling_file_gateway 2.1
ibm sterling_b2b_integrator 5.2.2
ibm sterling_b2b_integrator 5.2.4.1
CVE-2014-6209 MEDIUM

IBM DB2 9.5 through FP10, 9.7 through FP10, 9.8 through FP5, 10.1 through FP4, and 10.5 before FP5 on Linux, UNIX, and Windows allows remote authenticated users to cause a denial of service (daemon crash) by specifying an identity column within a crafted ALTER TABLE statement.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2 9.5
ibm db2 10.1
ibm db2 9.7
CVE-2014-6210 MEDIUM

IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 through FP4, and 10.5 before FP5 on Linux, UNIX, and Windows allows remote authenticated users to cause a denial of service (daemon crash) by specifying the same column within multiple ALTER TABLE statements.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm db2_connect 10.1
ibm db2_connect 10.5
ibm db2 9.8
ibm db2 9.7
CVE-2014-6211 LOW

The command-line scripts in IBM WebSphere Commerce 6.0 through 6.0.0.11, 7.0 through 7.0.0.9, and 7.0 Feature Pack 2 through 8, when debugging is configured, do not properly restrict the logging of personal data, which allows local users to obtain sensitive information by reading a log file.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_commerce 6.0.0.6
ibm websphere_commerce 7.0.0.4
ibm websphere_commerce 7.0.0.6
ibm websphere_commerce 7.0.0.7
ibm websphere_commerce 6.0.0.11
ibm websphere_commerce 6.0.0.1
ibm websphere_commerce 6.0.0.2
ibm websphere_commerce 6.0.0.10
ibm websphere_commerce 7.0.0.3
ibm websphere_commerce 7.0.0.9
ibm websphere_commerce 7.0.0.2
ibm websphere_commerce 7.0
ibm websphere_commerce 6.0.0.7
ibm websphere_commerce 6.0.0.8
ibm websphere_commerce 7.0.0.5
ibm websphere_commerce 6.0.0.3
ibm websphere_commerce 6.0.0.0
ibm websphere_commerce 6.0.0.4
ibm websphere_commerce 6.0.0.9
ibm websphere_commerce 7.0.0.1
ibm websphere_commerce 6.0.0.5
ibm websphere_commerce 7.0.0.8
CVE-2014-6212 MEDIUM

The Echo API in IBM Emptoris Contract Management 9.5.x before 9.5.0.6 iFix11, 10.0.0.x before 10.0.0.1 iFix12, 10.0.1.x before 10.0.1.5 iFix2, and 10.0.2.x before 10.0.2.2 iFix5; Emptoris Sourcing 9.5 before 9.5.1.3 iFix2, 10.0.0.x before 10.0.0.1 iFix1, 10.0.1.x before 10.0.1.3 iFix1, and 10.0.2.x before 10.0.2.5; and Emptoris Program Management (aka PGM) and Strategic Supply Management (aka SSMP) 10.0.0.x before 10.0.0.3 iFix6, 10.0.1.x before 10.0.1.4 iFix1, and 10.0.2.x before 10.0.2.5 allows remote authenticated users to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm emptoris_sourcing_portfolio 10.0.1.3
ibm emptoris_contract_management 10.0.0.1
ibm emptoris_contract_management 10.0.1.2
ibm emptoris_program_management 10.0.0.1
ibm emptoris_contract_management 9.5.0.3
ibm emptoris_sourcing_portfolio 10.0.0.1
ibm emptoris_program_management 10.0.1.1
ibm emptoris_program_management 10.0.2.2
ibm emptoris_sourcing_portfolio 10.0.1.2
ibm emptoris_sourcing_portfolio 9.5.1.0
ibm emptoris_program_management 10.0.0.2
ibm emptoris_program_management 10.0.1.4
ibm emptoris_contract_management 10.0.1.1
ibm emptoris_contract_management 10.0.2.1
ibm emptoris_contract_management 10.0.2.0
ibm emptoris_sourcing_portfolio 10.0.1.0
ibm emptoris_program_management 10.0.1.0
ibm emptoris_program_management 10.0.1.3
ibm emptoris_sourcing_portfolio 10.0.2.0
ibm emptoris_sourcing_portfolio 10.0.2.3
ibm emptoris_contract_management 9.5.0.2
ibm emptoris_sourcing_portfolio 9.5.1.3
ibm emptoris_sourcing_portfolio 9.5.0.0
ibm emptoris_contract_management 9.5.0.1
ibm emptoris_contract_management 10.0.1.4
ibm emptoris_contract_management 9.5.0.4
ibm emptoris_sourcing_portfolio 9.5.0.2
ibm emptoris_program_management 10.0.2.1
ibm emptoris_contract_management 10.0.0.0
ibm emptoris_contract_management 10.0.1.0
ibm emptoris_sourcing_portfolio 10.0.1.1
ibm emptoris_contract_management 9.5.0.0
ibm emptoris_contract_management 10.0.2.2
ibm emptoris strategic_supply_management
ibm emptoris_contract_management 10.0.1.5
ibm emptoris_program_management 10.0.2.4
ibm emptoris_sourcing_portfolio 10.0.2.2
ibm emptoris_program_management 10.0.0.3
ibm emptoris_sourcing_portfolio 9.5.1.2
ibm emptoris_sourcing_portfolio 10.0.0.0
ibm emptoris_sourcing_portfolio 9.5.0.1
ibm emptoris_program_management 10.0.2.0
ibm emptoris_sourcing_portfolio 9.5.1.1
ibm emptoris_contract_management 9.5.0.5
ibm emptoris_contract_management 10.0.1.3
ibm emptoris_sourcing_portfolio 10.0.2.4
ibm emptoris_program_management 10.0.0.0
ibm emptoris_program_management 10.0.1.2
ibm emptoris_program_management 10.0.2.3
ibm emptoris_contract_management 9.5.0.6
CVE-2014-6214 MEDIUM

Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Portal 8.0.0 through 8.0.0.1 CF15 and 8.5.0 before CF05 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.1
ibm websphere_portal 8.0.0.0
ibm websphere_portal 8.5.0.0
CVE-2014-6215 LOW

Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 before 7.0.0.2 CF29, 8.0.0 through 8.0.0.1 CF14, and 8.5.0 before CF03 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 6.1.0
ibm websphere_portal 8.5.0
ibm websphere_portal 6.1.0.3
ibm websphere_portal 8.0.0
ibm websphere_portal 7.0.0.1
ibm websphere_portal 6.1.0.2
ibm websphere_portal 6.1.0.4
ibm websphere_portal 8.0.0.1
ibm websphere_portal 7.0.0
ibm websphere_portal 7.0.0.2
ibm websphere_portal 6.1.0.6
ibm websphere_portal 6.1.0.1
ibm websphere_portal 6.1.0.5
CVE-2014-6221 HIGH

The MSCAPI/MSCNG interface implementation in GSKit in IBM Rational ClearCase 7.1.2.x before 7.1.2.17, 8.0.0.x before 8.0.0.14, and 8.0.1.x before 8.0.1.7 does not properly generate random numbers, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm rational_clearcase 8.0.0.10
ibm rational_clearcase 7.1.2.3
ibm rational_clearcase 8.0.0.1
ibm rational_clearcase 8.0.1.6
ibm rational_clearcase 7.1.2.13
ibm rational_clearcase 8.0.1
ibm rational_clearcase 8.0.0.13
ibm rational_clearcase 8.0.0.12
ibm rational_clearcase 7.1.2.16
ibm rational_clearcase 7.1.2.4
ibm rational_clearcase 8.0.0.7
ibm rational_clearcase 7.1.2.11
ibm rational_clearcase 8.0.0.3
ibm rational_clearcase 8.0.0.6
ibm rational_clearcase 7.1.2.1
ibm rational_clearcase 8.0.0.8
ibm rational_clearcase 7.1.2.15
ibm rational_clearcase 7.1.2.14
ibm rational_clearcase 7.1.2.2
ibm rational_clearcase 8.0.1.5
ibm rational_clearcase 8.0.0.9
ibm rational_clearcase 8.0.0
ibm rational_clearcase 8.0.1.3
ibm rational_clearcase 8.0.0.2
ibm rational_clearcase 8.0.0.11
ibm rational_clearcase 8.0.1.1
ibm rational_clearcase 8.0.1.2
ibm rational_clearcase 7.1.2.5
ibm rational_clearcase 7.1.2.12
ibm rational_clearcase 7.1.2
ibm rational_clearcase 8.0.0.4
ibm rational_clearcase 7.1.2.9
ibm rational_clearcase 8.0.0.5
ibm rational_clearcase 7.1.2.7
ibm rational_clearcase 7.1.2.6
ibm rational_clearcase 8.0.1.4
ibm rational_clearcase 7.1.2.10
CVE-2014-6222 MEDIUM

Directory traversal vulnerability in IBM Marketing Operations 7.x and 8.x before 8.5.0.7.2, 8.6.x before 8.6.0.8, 9.0.x before 9.0.0.4.1, 9.1.0.x before 9.1.0.5, and 9.1.1.x before 9.1.1.2 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm marketing_operations 7.4.2.7
ibm marketing_operations 7.3.2.0
ibm marketing_operations 8.1.0.7
ibm marketing_operations 8.1.1.0
ibm marketing_operations 7.5.3.7
ibm marketing_operations 8.2.0.5
ibm marketing_operations 7.2.0.4
ibm marketing_operations 7.4.0.0
ibm marketing_operations 8.2.0.8
ibm marketing_operations 8.2.0.10
ibm marketing_operations 9.0.0.2
ibm marketing_operations 7.4.2.0
ibm marketing_operations 8.0.0.0
ibm marketing_operations 8.6.0.6
ibm marketing_operations 8.6.0.5
ibm marketing_operations 8.2.0.9
ibm marketing_operations 9.0.0.3
ibm marketing_operations 9.1.0.4
ibm marketing_operations 8.0.0.2
ibm marketing_operations 9.0.0.1
ibm marketing_operations 8.2.0.6
ibm marketing_operations 8.5.0.7
ibm marketing_operations 8.2.0.12
ibm marketing_operations 7.3.2.8
ibm marketing_operations 9.1.1.0
ibm marketing_operations 8.1.0.0
ibm marketing_operations 8.1.0.6
ibm marketing_operations 8.6.0.0
ibm marketing_operations 7.5.3.9
ibm marketing_operations 8.2.0.7
ibm marketing_operations 8.2.0.11
ibm marketing_operations 8.5.0.2
ibm marketing_operations 8.5.0.6
ibm marketing_operations 8.5.0.3
ibm marketing_operations 9.1.1.1
ibm marketing_operations 8.6.0.4
ibm marketing_operations 8.6.0.7
ibm marketing_operations 7.4.1.6
ibm marketing_operations 8.1.1.4
ibm marketing_operations 8.5.0.4
ibm marketing_operations 9.0.0.4
ibm marketing_operations 7.4.1.0
ibm marketing_operations 7.5.0.0
ibm marketing_operations 7.2.1.0
ibm marketing_operations 7.5.0.1
ibm marketing_operations 8.5.0.5
ibm marketing_operations 7.5.3.0
ibm marketing_operations 7.5.2.0
ibm marketing_operations 9.0.0.0
ibm marketing_operations 9.1.0.3
ibm marketing_operations 8.2.0.13
ibm marketing_operations 8.6.0.3
ibm marketing_operations 8.5.0.1
ibm marketing_operations 7.2.1.12
ibm marketing_operations 8.6.0.2
ibm marketing_operations 8.5.0.0
ibm marketing_operations 8.2.0.0
ibm marketing_operations 7.2.0.0
ibm marketing_operations 7.5.2.3
ibm marketing_operations 9.1.0.2
ibm marketing_operations 9.1.0.0
ibm marketing_operations 7.5.3.8
ibm marketing_operations 7.4.0.2
ibm marketing_operations 7.3.2.1
CVE-2014-6271 HIGH

GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 3.9 5.9
134c704f-9b21-4f2e-91b3-4a467353bcc0 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 3.9 5.9

CVSS 2.0

Severity: HIGH

Problem Type: CWE-78,CWE-78,

Products Affected

Vendor Product Version
ibm pureapplication_system *
redhat enterprise_linux_server_aus 5.9
redhat enterprise_linux_for_power_big_endian_eus 6.5_ppc64
redhat enterprise_linux_server_aus 6.2
ibm security_access_manager_for_web_7.0_firmware 7.0.0.7
redhat enterprise_linux_workstation 7.0
redhat enterprise_linux 5.0
suse linux_enterprise_software_development_kit 12
redhat enterprise_linux_server_aus 6.4
redhat enterprise_linux_for_power_big_endian 7.0_ppc64
vmware esx 4.1
ibm smartcloud_provisioning 2.1.0
suse linux_enterprise_desktop 12
redhat enterprise_linux_server_aus 7.7
redhat enterprise_linux_for_power_big_endian_eus 7.6_ppc64
redhat enterprise_linux 4.0
debian debian_linux 7.0
redhat enterprise_linux_workstation 6.0
f5 big-ip_global_traffic_manager *
ibm smartcloud_entry_appliance 3.2.0
ibm qradar_security_information_and_event_manager 7.1.0
ibm qradar_security_information_and_event_manager 7.2.3
gnu bash *
ibm qradar_security_information_and_event_manager 7.2.4
f5 big-ip_edge_gateway *
oracle linux 5
redhat enterprise_linux_server_from_rhui 7.0
redhat enterprise_linux_eus 7.3
novell open_enterprise_server 2.0
suse linux_enterprise_server 10
redhat enterprise_linux_for_power_big_endian 5.9_ppc
redhat enterprise_linux_for_power_big_endian 6.4_ppc64
ibm security_access_manager_for_web_7.0_firmware 7.0.0.6
redhat enterprise_linux_desktop 6.0
redhat enterprise_linux_for_ibm_z_systems 5.9_s390x
redhat enterprise_linux_server_aus 7.3
canonical ubuntu_linux 12.04
ibm smartcloud_entry_appliance 2.3.0
ibm security_access_manager_for_web_8.0_firmware 8.0.0.2
f5 big-ip_local_traffic_manager 11.6.0
f5 traffix_signaling_delivery_controller 3.5.1
vmware esx 4.0
canonical ubuntu_linux 14.04
redhat enterprise_linux_server_tus 7.7
f5 big-ip_access_policy_manager *
mageia mageia 3.0
redhat enterprise_linux_workstation 5.0
ibm security_access_manager_for_web_7.0_firmware 7.0.0.3
ibm qradar_security_information_and_event_manager 7.2.0
redhat virtualization 3.4
ibm starter_kit_for_cloud 2.2.0
ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.2
oracle linux 4
ibm qradar_security_information_and_event_manager 7.2.6
ibm flex_system_v7000_firmware *
redhat enterprise_linux_for_ibm_z_systems 7.3_s390x
redhat enterprise_linux_for_ibm_z_systems 7.6_s390x
checkpoint security_gateway *
f5 traffix_signaling_delivery_controller 3.3.2
ibm pureapplication_system 2.0.0.0
redhat enterprise_linux_for_ibm_z_systems 7.4_s390x
redhat enterprise_linux_server_aus 6.5
ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.5
f5 big-ip_local_traffic_manager *
ibm qradar_security_information_and_event_manager 7.2.8
f5 big-ip_wan_optimization_manager *
ibm qradar_vulnerability_manager 7.2.2
ibm security_access_manager_for_web_7.0_firmware 7.0.0.1
ibm security_access_manager_for_web_7.0_firmware 7.0.0.2
vmware vcenter_server_appliance 5.0
f5 big-ip_application_acceleration_manager *
ibm workload_deployer *
ibm stn6800_firmware *
redhat enterprise_linux_for_power_big_endian_eus 7.3_ppc64
ibm qradar_vulnerability_manager 7.2.3
ibm smartcloud_entry_appliance 2.4.0
ibm infosphere_guardium_database_activity_monitoring 9.1
novell zenworks_configuration_management 10.3
ibm qradar_security_information_and_event_manager 7.2.1
ibm qradar_security_information_and_event_manager 7.2.8.15
suse studio_onsite 1.3
suse linux_enterprise_server 11
redhat enterprise_linux_desktop 7.0
ibm storwize_v5000_firmware *
f5 big-iq_cloud *
vmware vcenter_server_appliance 5.5
ibm qradar_security_information_and_event_manager 7.2.9
ibm security_access_manager_for_web_7.0_firmware 7.0.0.5
opensuse opensuse 12.3
ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.3
ibm stn6500_firmware *
redhat enterprise_linux_for_ibm_z_systems 7.5_s390x
redhat enterprise_linux_for_power_big_endian 5.0_ppc
ibm infosphere_guardium_database_activity_monitoring 8.2
redhat enterprise_linux_server_from_rhui 6.0
f5 traffix_signaling_delivery_controller 4.1.0
redhat enterprise_linux_eus 7.5
redhat enterprise_linux_for_scientific_computing 7.0
ibm qradar_vulnerability_manager 7.2.6
redhat enterprise_linux 6.0
redhat enterprise_linux_for_power_big_endian 6.0_ppc64
redhat enterprise_linux_server_aus 7.4
redhat gluster_storage_server_for_on-premise 2.1
ibm infosphere_guardium_database_activity_monitoring 9.0
f5 big-ip_advanced_firewall_manager 11.6.0
redhat enterprise_linux_server_tus 7.6
ibm software_defined_network_for_virtual_environments *
oracle linux 6
ibm qradar_security_information_and_event_manager 7.1.1
suse linux_enterprise_desktop 11
vmware vcenter_server_appliance 5.1
ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.1
redhat enterprise_linux_for_scientific_computing 6.0
redhat enterprise_linux 7.0
redhat enterprise_linux_server_tus 7.3
ibm storwize_v3700_firmware *
f5 big-ip_application_security_manager *
ibm qradar_security_information_and_event_manager 7.2.7
ibm security_access_manager_for_web_7.0_firmware 7.0.0.8
f5 big-iq_device *
qnap qts 4.1.1
ibm qradar_security_information_and_event_manager 7.1.2
f5 big-ip_protocol_security_module *
opensuse opensuse 13.2
redhat enterprise_linux_eus 5.9
redhat enterprise_linux_eus 7.7
redhat enterprise_linux_server 7.0
ibm storwize_v3500_firmware *
redhat enterprise_linux_for_power_big_endian_eus 7.4_ppc64
ibm qradar_security_information_and_event_manager 7.2
f5 big-ip_analytics 11.6.0
f5 big-ip_application_security_manager 11.6.0
novell open_enterprise_server 11.0
ibm security_access_manager_for_web_8.0_firmware 8.0.0.3
suse linux_enterprise_server 12
citrix netscaler_sdx_firmware *
f5 big-ip_policy_enforcement_manager *
canonical ubuntu_linux 10.04
novell zenworks_configuration_management 11.3.0
f5 big-ip_link_controller 11.6.0
f5 big-ip_policy_enforcement_manager 11.6.0
ibm security_access_manager_for_web_8.0_firmware 8.0.0.5
f5 enterprise_manager *
f5 traffix_signaling_delivery_controller *
redhat enterprise_linux_eus 7.6
f5 big-ip_advanced_firewall_manager *
ibm qradar_security_information_and_event_manager 7.2.2
novell zenworks_configuration_management 11.2
opensuse opensuse 13.1
redhat enterprise_linux_eus 7.4
suse linux_enterprise_software_development_kit 11
arista eos *
ibm smartcloud_entry_appliance 3.1.0
f5 arx_firmware *
redhat enterprise_linux_eus 6.4
ibm security_access_manager_for_web_7.0_firmware 7.0.0.4
redhat enterprise_linux_for_ibm_z_systems 6.4_s390x
redhat enterprise_linux_for_power_big_endian_eus 7.5_ppc64
f5 big-ip_access_policy_manager 11.6.0
redhat enterprise_linux_for_power_big_endian_eus 7.7_ppc64
ibm storwize_v7000_firmware *
f5 traffix_signaling_delivery_controller 3.4.1
redhat enterprise_linux_server 6.0
redhat enterprise_linux_server_tus 6.5
f5 big-ip_application_acceleration_manager 11.6.0
f5 big-ip_analytics *
apple mac_os_x *
redhat enterprise_linux_server_aus 5.6
redhat enterprise_linux_eus 6.5
ibm qradar_vulnerability_manager 7.2.1
ibm san_volume_controller_firmware *
mageia mageia 4.0
redhat enterprise_linux_for_ibm_z_systems 7.7_s390x
novell zenworks_configuration_management 11
f5 big-iq_security *
f5 big-ip_global_traffic_manager 11.6.0
redhat enterprise_linux_desktop 5.0
novell zenworks_configuration_management 11.1
ibm qradar_vulnerability_manager 7.2.4
ibm qradar_security_information_and_event_manager 7.2.5
ibm qradar_vulnerability_manager 7.2.0
redhat enterprise_linux_server_from_rhui 5.0
ibm stn7800_firmware *
ibm qradar_vulnerability_manager 7.2.8
f5 big-ip_webaccelerator *
redhat enterprise_linux_for_ibm_z_systems 6.5_s390x
ibm qradar_risk_manager 7.1.0
qnap qts *
redhat enterprise_linux_server 5.0
f5 big-ip_link_controller *
redhat enterprise_linux_server_aus 7.6
CVE-2014-7169 HIGH

GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 3.9 5.9
134c704f-9b21-4f2e-91b3-4a467353bcc0 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 3.9 5.9

CVSS 2.0

Severity: HIGH

Problem Type: CWE-78,CWE-78,

Products Affected

Vendor Product Version
ibm pureapplication_system *
redhat enterprise_linux_server_aus 5.9
redhat enterprise_linux_for_power_big_endian_eus 6.5_ppc64
redhat enterprise_linux_server_aus 6.2
ibm security_access_manager_for_web_7.0_firmware 7.0.0.7
redhat enterprise_linux_workstation 7.0
redhat enterprise_linux 5.0
suse linux_enterprise_software_development_kit 12
redhat enterprise_linux_server_aus 6.4
redhat enterprise_linux_for_power_big_endian 7.0_ppc64
vmware esx 4.1
ibm smartcloud_provisioning 2.1.0
suse linux_enterprise_desktop 12
redhat enterprise_linux_server_aus 7.7
redhat enterprise_linux_for_power_big_endian_eus 7.6_ppc64
redhat enterprise_linux 4.0
debian debian_linux 7.0
redhat enterprise_linux_workstation 6.0
f5 big-ip_global_traffic_manager *
ibm smartcloud_entry_appliance 3.2.0
ibm qradar_security_information_and_event_manager 7.1.0
ibm qradar_security_information_and_event_manager 7.2.3
gnu bash *
ibm qradar_security_information_and_event_manager 7.2.4
f5 big-ip_edge_gateway *
oracle linux 5
redhat enterprise_linux_server_from_rhui 7.0
redhat enterprise_linux_eus 7.3
novell open_enterprise_server 2.0
suse linux_enterprise_server 10
redhat enterprise_linux_for_power_big_endian 5.9_ppc
redhat enterprise_linux_for_power_big_endian 6.4_ppc64
ibm security_access_manager_for_web_7.0_firmware 7.0.0.6
redhat enterprise_linux_desktop 6.0
redhat enterprise_linux_for_ibm_z_systems 5.9_s390x
redhat enterprise_linux_server_aus 7.3
canonical ubuntu_linux 12.04
ibm smartcloud_entry_appliance 2.3.0
ibm security_access_manager_for_web_8.0_firmware 8.0.0.2
f5 big-ip_local_traffic_manager 11.6.0
f5 traffix_signaling_delivery_controller 3.5.1
vmware esx 4.0
canonical ubuntu_linux 14.04
redhat enterprise_linux_server_tus 7.7
f5 big-ip_access_policy_manager *
mageia mageia 3.0
redhat enterprise_linux_workstation 5.0
ibm security_access_manager_for_web_7.0_firmware 7.0.0.3
ibm qradar_security_information_and_event_manager 7.2.0
redhat virtualization 3.4
ibm starter_kit_for_cloud 2.2.0
ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.2
oracle linux 4
ibm qradar_security_information_and_event_manager 7.2.6
ibm flex_system_v7000_firmware *
redhat enterprise_linux_for_ibm_z_systems 7.3_s390x
redhat enterprise_linux_for_ibm_z_systems 7.6_s390x
checkpoint security_gateway *
f5 traffix_signaling_delivery_controller 3.3.2
ibm pureapplication_system 2.0.0.0
redhat enterprise_linux_for_ibm_z_systems 7.4_s390x
redhat enterprise_linux_server_aus 6.5
ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.5
f5 big-ip_local_traffic_manager *
ibm qradar_security_information_and_event_manager 7.2.8
f5 big-ip_wan_optimization_manager *
ibm qradar_vulnerability_manager 7.2.2
ibm security_access_manager_for_web_7.0_firmware 7.0.0.1
ibm security_access_manager_for_web_7.0_firmware 7.0.0.2
vmware vcenter_server_appliance 5.0
f5 big-ip_application_acceleration_manager *
ibm workload_deployer *
ibm stn6800_firmware *
redhat enterprise_linux_for_power_big_endian_eus 7.3_ppc64
ibm qradar_vulnerability_manager 7.2.3
ibm smartcloud_entry_appliance 2.4.0
ibm infosphere_guardium_database_activity_monitoring 9.1
novell zenworks_configuration_management 10.3
ibm qradar_security_information_and_event_manager 7.2.1
ibm qradar_security_information_and_event_manager 7.2.8.15
suse studio_onsite 1.3
suse linux_enterprise_server 11
redhat enterprise_linux_desktop 7.0
ibm storwize_v5000_firmware *
f5 big-iq_cloud *
vmware vcenter_server_appliance 5.5
ibm qradar_security_information_and_event_manager 7.2.9
ibm security_access_manager_for_web_7.0_firmware 7.0.0.5
opensuse opensuse 12.3
ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.3
ibm stn6500_firmware *
redhat enterprise_linux_for_ibm_z_systems 7.5_s390x
redhat enterprise_linux_for_power_big_endian 5.0_ppc
ibm infosphere_guardium_database_activity_monitoring 8.2
redhat enterprise_linux_server_from_rhui 6.0
f5 traffix_signaling_delivery_controller 4.1.0
redhat enterprise_linux_eus 7.5
redhat enterprise_linux_for_scientific_computing 7.0
ibm qradar_vulnerability_manager 7.2.6
redhat enterprise_linux 6.0
redhat enterprise_linux_for_power_big_endian 6.0_ppc64
redhat enterprise_linux_server_aus 7.4
redhat gluster_storage_server_for_on-premise 2.1
ibm infosphere_guardium_database_activity_monitoring 9.0
f5 big-ip_advanced_firewall_manager 11.6.0
redhat enterprise_linux_server_tus 7.6
ibm software_defined_network_for_virtual_environments *
oracle linux 6
ibm qradar_security_information_and_event_manager 7.1.1
suse linux_enterprise_desktop 11
vmware vcenter_server_appliance 5.1
ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.1
redhat enterprise_linux_for_scientific_computing 6.0
redhat enterprise_linux 7.0
redhat enterprise_linux_server_tus 7.3
ibm storwize_v3700_firmware *
f5 big-ip_application_security_manager *
ibm qradar_security_information_and_event_manager 7.2.7
ibm security_access_manager_for_web_7.0_firmware 7.0.0.8
f5 big-iq_device *
qnap qts 4.1.1
ibm qradar_security_information_and_event_manager 7.1.2
f5 big-ip_protocol_security_module *
opensuse opensuse 13.2
redhat enterprise_linux_eus 5.9
redhat enterprise_linux_eus 7.7
redhat enterprise_linux_server 7.0
ibm storwize_v3500_firmware *
redhat enterprise_linux_for_power_big_endian_eus 7.4_ppc64
ibm qradar_security_information_and_event_manager 7.2
f5 big-ip_analytics 11.6.0
f5 big-ip_application_security_manager 11.6.0
novell open_enterprise_server 11.0
ibm security_access_manager_for_web_8.0_firmware 8.0.0.3
suse linux_enterprise_server 12
citrix netscaler_sdx_firmware *
f5 big-ip_policy_enforcement_manager *
canonical ubuntu_linux 10.04
novell zenworks_configuration_management 11.3.0
f5 big-ip_link_controller 11.6.0
f5 big-ip_policy_enforcement_manager 11.6.0
ibm security_access_manager_for_web_8.0_firmware 8.0.0.5
f5 enterprise_manager *
f5 traffix_signaling_delivery_controller *
redhat enterprise_linux_eus 7.6
f5 big-ip_advanced_firewall_manager *
ibm qradar_security_information_and_event_manager 7.2.2
novell zenworks_configuration_management 11.2
opensuse opensuse 13.1
redhat enterprise_linux_eus 7.4
suse linux_enterprise_software_development_kit 11
arista eos *
ibm smartcloud_entry_appliance 3.1.0
f5 arx_firmware *
redhat enterprise_linux_eus 6.4
ibm security_access_manager_for_web_7.0_firmware 7.0.0.4
redhat enterprise_linux_for_ibm_z_systems 6.4_s390x
redhat enterprise_linux_for_power_big_endian_eus 7.5_ppc64
f5 big-ip_access_policy_manager 11.6.0
redhat enterprise_linux_for_power_big_endian_eus 7.7_ppc64
ibm storwize_v7000_firmware *
f5 traffix_signaling_delivery_controller 3.4.1
redhat enterprise_linux_server 6.0
redhat enterprise_linux_server_tus 6.5
f5 big-ip_application_acceleration_manager 11.6.0
f5 big-ip_analytics *
apple mac_os_x *
redhat enterprise_linux_server_aus 5.6
redhat enterprise_linux_eus 6.5
ibm qradar_vulnerability_manager 7.2.1
ibm san_volume_controller_firmware *
mageia mageia 4.0
redhat enterprise_linux_for_ibm_z_systems 7.7_s390x
novell zenworks_configuration_management 11
f5 big-iq_security *
f5 big-ip_global_traffic_manager 11.6.0
redhat enterprise_linux_desktop 5.0
novell zenworks_configuration_management 11.1
ibm qradar_vulnerability_manager 7.2.4
ibm qradar_security_information_and_event_manager 7.2.5
ibm qradar_vulnerability_manager 7.2.0
redhat enterprise_linux_server_from_rhui 5.0
ibm stn7800_firmware *
ibm qradar_vulnerability_manager 7.2.8
f5 big-ip_webaccelerator *
redhat enterprise_linux_for_ibm_z_systems 6.5_s390x
ibm qradar_risk_manager 7.1.0
qnap qts *
redhat enterprise_linux_server 5.0
f5 big-ip_link_controller *
redhat enterprise_linux_server_aus 7.6
CVE-2014-8887 MEDIUM

IBM Marketing Operations 7.x and 8.x before 8.5.0.7.2, 8.6.x before 8.6.0.8, 9.0.x before 9.0.0.4.1, 9.1.0.x before 9.1.0.5, and 9.1.1.x before 9.1.1.2 allows remote authenticated users to upload arbitrary GIFAR files, and consequently modify data, via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm marketing_operations 7.4.2.7
ibm marketing_operations 7.3.2.0
ibm marketing_operations 8.1.0.7
ibm marketing_operations 8.1.1.0
ibm marketing_operations 7.5.3.7
ibm marketing_operations 8.2.0.5
ibm marketing_operations 7.2.0.4
ibm marketing_operations 7.4.0.0
ibm marketing_operations 8.2.0.8
ibm marketing_operations 8.2.0.10
ibm marketing_operations 9.0.0.2
ibm marketing_operations 7.4.2.0
ibm marketing_operations 8.0.0.0
ibm marketing_operations 8.6.0.6
ibm marketing_operations 8.6.0.5
ibm marketing_operations 8.2.0.9
ibm marketing_operations 9.0.0.3
ibm marketing_operations 9.1.0.4
ibm marketing_operations 8.0.0.2
ibm marketing_operations 9.0.0.1
ibm marketing_operations 8.2.0.6
ibm marketing_operations 8.5.0.7
ibm marketing_operations 8.2.0.12
ibm marketing_operations 7.3.2.8
ibm marketing_operations 9.1.1.0
ibm marketing_operations 8.1.0.0
ibm marketing_operations 8.1.0.6
ibm marketing_operations 8.6.0.0
ibm marketing_operations 7.5.3.9
ibm marketing_operations 8.2.0.7
ibm marketing_operations 8.2.0.11
ibm marketing_operations 8.5.0.2
ibm marketing_operations 8.5.0.6
ibm marketing_operations 8.5.0.3
ibm marketing_operations 9.1.1.1
ibm marketing_operations 8.6.0.4
ibm marketing_operations 8.6.0.7
ibm marketing_operations 7.4.1.6
ibm marketing_operations 8.1.1.4
ibm marketing_operations 8.5.0.4
ibm marketing_operations 9.0.0.4
ibm marketing_operations 7.4.1.0
ibm marketing_operations 7.5.0.0
ibm marketing_operations 7.2.1.0
ibm marketing_operations 7.5.0.1
ibm marketing_operations 8.5.0.5
ibm marketing_operations 7.5.3.0
ibm marketing_operations 7.5.2.0
ibm marketing_operations 9.0.0.0
ibm marketing_operations 9.1.0.3
ibm marketing_operations 8.2.0.13
ibm marketing_operations 8.6.0.3
ibm marketing_operations 8.5.0.1
ibm marketing_operations 7.2.1.12
ibm marketing_operations 8.6.0.2
ibm marketing_operations 8.5.0.0
ibm marketing_operations 8.2.0.0
ibm marketing_operations 7.2.0.0
ibm marketing_operations 7.5.2.3
ibm marketing_operations 9.1.0.2
ibm marketing_operations 9.1.0.0
ibm marketing_operations 7.5.3.8
ibm marketing_operations 7.4.0.2
ibm marketing_operations 7.3.2.1
CVE-2014-8890 MEDIUM

IBM WebSphere Application Server Liberty Profile 8.5.x before 8.5.5.4 allows remote attackers to gain privileges by leveraging the combination of a servlet's deployment descriptor security constraints and ServletSecurity annotations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_application_server 8.5.5.0
ibm websphere_application_server 8.5.0.2
ibm websphere_application_server 8.5.5.2
ibm websphere_application_server 8.5.5.3
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 8.5.5.1
CVE-2014-8891 HIGH

Unspecified vulnerability in the Java Virtual Machine (JVM) in IBM SDK, Java Technology Edition 5.0 before SR16-FP9, 6 before SR16-FP3, 6R1 before SR8-FP3, 7 before SR8-FP10, and 7R1 before SR2-FP10 allows remote attackers to escape the Java sandbox and execute arbitrary code via unspecified vectors related to the security manager.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm java_sdk *
CVE-2014-8892 HIGH

Unspecified vulnerability in the Java Virtual Machine (JVM) in IBM SDK, Java Technology Edition 5.0 before SR16-FP9, 6 before SR16-FP3, 6R1 before SR8-FP3, 7 before SR8-FP10, and 7R1 before SR2-FP10 allows remote attackers to bypass intended access permissions and obtain sensitive information via unspecified vectors related to the security manager.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm java_sdk *
CVE-2014-8893 LOW

Multiple cross-site scripting (XSS) vulnerabilities in (1) mainpage.jsp and (2) GetImageServlet.img in IBM TRIRIGA Application Platform 3.2.1.x, 3.3.2 before 3.3.2.3, and 3.4.1 before 3.4.1.1 allow remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tririga_application_platform 3.4.0.0
ibm tririga_application_platform 3.4.1.0
ibm tririga_application_platform 3.3.2.1
ibm tririga_application_platform 3.4.0.1
ibm tririga_application_platform 3.3.2.0
ibm tririga_application_platform 3.2.1
ibm tririga_application_platform 3.3.2.2
CVE-2014-8894 MEDIUM

Open redirect vulnerability in IBM TRIRIGA Application Platform 3.2.1.x, 3.3.2 before 3.3.2.3, and 3.4.1 before 3.4.1.1 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via the out parameter.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm tririga_application_platform 3.4.0.0
ibm tririga_application_platform 3.4.1.0
ibm tririga_application_platform 3.3.2.1
ibm tririga_application_platform 3.4.0.1
ibm tririga_application_platform 3.3.2.0
ibm tririga_application_platform 3.2.1
ibm tririga_application_platform 3.3.2.2
CVE-2014-8895 MEDIUM

IBM TRIRIGA Application Platform 3.2.1.x, 3.3.2 before 3.3.2.3, and 3.4.1 before 3.4.1.1 allows remote attackers to bypass intended access restrictions and read the image files of arbitrary users via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm tririga_application_platform 3.4.0.0
ibm tririga_application_platform 3.4.1.0
ibm tririga_application_platform 3.3.2.1
ibm tririga_application_platform 3.4.0.1
ibm tririga_application_platform 3.3.2.0
ibm tririga_application_platform 3.2.1
ibm tririga_application_platform 3.3.2.2
CVE-2014-8896 MEDIUM

The Collaboration Server in IBM InfoSphere Master Data Management Server for Product Information Management 9.x through 9.1 and InfoSphere Master Data Management - Collaborative Edition 10.x through 10.1, 11.0 before FP7, and 11.3 and 11.4 before 11.4 FP1 allows remote authenticated users to modify the administrator's credentials and consequently gain privileges via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm infosphere_master_data_management_server_for_product_information_management 9.0.0.1
ibm infosphere_master_data_management_collaborative_server 10.0.0.3
ibm infosphere_master_data_management_server_for_product_information_management 9.0.0.5
ibm infosphere_master_data_management_server_for_product_information_management 9.0.0.8
ibm infosphere_master_data_management_collaborative_server 10.0.0
ibm infosphere_master_data_management_collaborative_server 10.0.0.2
ibm infosphere_master_data_management_collaborative_server 10.0.0.5
ibm infosphere_master_data_management_server_for_product_information_management 9.0.0.4
ibm infosphere_master_data_management_server_for_product_information_management 9.0.0.7
ibm infosphere_master_data_management_server_for_product_information_management 9.0.0.2
ibm infosphere_master_data_management_collaborative_server 11.4
ibm infosphere_master_data_management_collaborative_server 10.1.0
ibm infosphere_master_data_management_server_for_product_information_management 9.0.0
ibm infosphere_master_data_management_server_for_product_information_management 9.0.0.6
ibm infosphere_master_data_management_server_for_product_information_management 9.0.0.3
ibm infosphere_master_data_management_collaborative_server 10.0.0.4
ibm infosphere_master_data_management_server_for_product_information_management 9.1.0
ibm infosphere_master_data_management_collaborative_server 11.0
ibm infosphere_master_data_management_collaborative_server 10.0.0.1
ibm infosphere_master_data_management_collaborative_server 11.3
CVE-2014-8897 LOW

Cross-site scripting (XSS) vulnerability in the Collaboration Server in IBM InfoSphere Master Data Management Server for Product Information Management 9.x through 9.1 and InfoSphere Master Data Management - Collaborative Edition 10.x through 10.1, 11.0 before FP7, and 11.3 and 11.4 before 11.4 FP1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2014-8898 and CVE-2014-8899.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm infosphere_master_data_management_server_for_product_information_management 9.0.0.1
ibm infosphere_master_data_management_collaborative_server 10.0.0.3
ibm infosphere_master_data_management_server_for_product_information_management 9.0.0.5
ibm infosphere_master_data_management_server_for_product_information_management 9.0.0.8
ibm infosphere_master_data_management_collaborative_server 10.0.0
ibm infosphere_master_data_management_collaborative_server 10.0.0.2
ibm infosphere_master_data_management_collaborative_server 10.0.0.5
ibm infosphere_master_data_management_server_for_product_information_management 9.0.0.4
ibm infosphere_master_data_management_server_for_product_information_management 9.0.0.7
ibm infosphere_master_data_management_server_for_product_information_management 9.0.0.2
ibm infosphere_master_data_management_collaborative_server 11.4
ibm infosphere_master_data_management_collaborative_server 10.1.0
ibm infosphere_master_data_management_server_for_product_information_management 9.0.0
ibm infosphere_master_data_management_server_for_product_information_management 9.0.0.6
ibm infosphere_master_data_management_server_for_product_information_management 9.0.0.3
ibm infosphere_master_data_management_collaborative_server 10.0.0.4
ibm infosphere_master_data_management_server_for_product_information_management 9.1.0
ibm infosphere_master_data_management_collaborative_server 11.0
ibm infosphere_master_data_management_collaborative_server 10.0.0.1
ibm infosphere_master_data_management_collaborative_server 11.3
CVE-2014-8898 LOW

Cross-site scripting (XSS) vulnerability in the Collaboration Server in IBM InfoSphere Master Data Management Server for Product Information Management 9.x through 9.1 and InfoSphere Master Data Management - Collaborative Edition 10.x through 10.1, 11.0 before FP7, and 11.3 and 11.4 before 11.4 FP1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2014-8897 and CVE-2014-8899.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm infosphere_master_data_management_server_for_product_information_management 9.0.0.1
ibm infosphere_master_data_management_collaborative_server 10.0.0.3
ibm infosphere_master_data_management_server_for_product_information_management 9.0.0.5
ibm infosphere_master_data_management_server_for_product_information_management 9.0.0.8
ibm infosphere_master_data_management_collaborative_server 10.0.0
ibm infosphere_master_data_management_collaborative_server 10.0.0.2
ibm infosphere_master_data_management_collaborative_server 10.0.0.5
ibm infosphere_master_data_management_server_for_product_information_management 9.0.0.4
ibm infosphere_master_data_management_server_for_product_information_management 9.0.0.7
ibm infosphere_master_data_management_server_for_product_information_management 9.0.0.2
ibm infosphere_master_data_management_collaborative_server 11.4
ibm infosphere_master_data_management_collaborative_server 10.1.0
ibm infosphere_master_data_management_server_for_product_information_management 9.0.0
ibm infosphere_master_data_management_server_for_product_information_management 9.0.0.6
ibm infosphere_master_data_management_server_for_product_information_management 9.0.0.3
ibm infosphere_master_data_management_collaborative_server 10.0.0.4
ibm infosphere_master_data_management_server_for_product_information_management 9.1.0
ibm infosphere_master_data_management_collaborative_server 11.0
ibm infosphere_master_data_management_collaborative_server 10.0.0.1
ibm infosphere_master_data_management_collaborative_server 11.3
CVE-2014-8899 LOW

Cross-site scripting (XSS) vulnerability in the Collaboration Server in IBM InfoSphere Master Data Management Server for Product Information Management 9.x through 9.1 and InfoSphere Master Data Management - Collaborative Edition 10.x through 10.1, 11.0 before FP7, and 11.3 and 11.4 before 11.4 FP1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2014-8897 and CVE-2014-8898.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm infosphere_master_data_management_server_for_product_information_management 9.0.0.1
ibm infosphere_master_data_management_collaborative_server 10.0.0.3
ibm infosphere_master_data_management_server_for_product_information_management 9.0.0.5
ibm infosphere_master_data_management_server_for_product_information_management 9.0.0.8
ibm infosphere_master_data_management_collaborative_server 10.0.0
ibm infosphere_master_data_management_collaborative_server 10.0.0.2
ibm infosphere_master_data_management_collaborative_server 10.0.0.5
ibm infosphere_master_data_management_server_for_product_information_management 9.0.0.4
ibm infosphere_master_data_management_server_for_product_information_management 9.0.0.7
ibm infosphere_master_data_management_server_for_product_information_management 9.0.0.2
ibm infosphere_master_data_management_collaborative_server 11.4
ibm infosphere_master_data_management_collaborative_server 10.1.0
ibm infosphere_master_data_management_server_for_product_information_management 9.0.0
ibm infosphere_master_data_management_server_for_product_information_management 9.0.0.6
ibm infosphere_master_data_management_server_for_product_information_management 9.0.0.3
ibm infosphere_master_data_management_collaborative_server 10.0.0.4
ibm infosphere_master_data_management_server_for_product_information_management 9.1.0
ibm infosphere_master_data_management_collaborative_server 11.0
ibm infosphere_master_data_management_collaborative_server 10.0.0.1
ibm infosphere_master_data_management_collaborative_server 11.3
CVE-2014-8900 MEDIUM

Cross-site request forgery (CSRF) vulnerability in IBM UrbanCode Release 6.0.1.6 and earlier, 6.1.0.7 and earlier, and 6.1.1.1 and earlier.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm urbancode_deploy *
CVE-2014-8901 MEDIUM

IBM DB2 9.5 through FP10, 9.7 through FP10, 9.8 through FP5, 10.1 through FP4, and 10.5 before FP5 allows remote authenticated users to cause a denial of service (CPU consumption) via a crafted XML query.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2 9.5
ibm db2 10.1
ibm db2 9.8
ibm db2 9.7
CVE-2014-8902 MEDIUM

Cross-site scripting (XSS) vulnerability in the Blog Portlet in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 through 8.0.0.1 CF14, and 8.5.0 before CF04 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.0
ibm websphere_portal 6.1.0.3
ibm websphere_portal 7.0.0.1
ibm websphere_portal 6.1.5.2
ibm websphere_portal 6.1.0.2
ibm websphere_portal 6.1.0.4
ibm websphere_portal 8.0.0.1
ibm websphere_portal 7.0.0.2
ibm websphere_portal 8.5.0.0
ibm websphere_portal 6.1.5.0
ibm websphere_portal 6.1.0.6
ibm websphere_portal 6.1.5.3
ibm websphere_portal 7.0.0.0
ibm websphere_portal 6.1.0.1
ibm websphere_portal 6.1.5.1
ibm websphere_portal 6.1.0.5
ibm websphere_portal 6.1.0.0
CVE-2014-8903 MEDIUM

IBM Curam Social Program Management 6.0 SP2 before EP26, 6.0.4 before 6.0.4.5iFix10 and 6.0.5 before 6.0.5.6 allows remote authenticated users to load arbitrary Java classes via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-77,

Products Affected

Vendor Product Version
ibm curam_social_program_management 6.0.4.7
ibm curam_social_program_management 6.0
ibm curam_social_program_management 6.0.4.8
ibm curam_social_program_management 6.0.5.9
ibm curam_social_program_management 6.0.4.3
ibm curam_social_program_management 6.0.5.4
ibm curam_social_program_management 6.0.4.4
ibm curam_social_program_management 6.0.4.9
ibm curam_social_program_management 6.0.5.10
ibm curam_social_program_management 6.0.5
ibm curam_social_program_management 6.0.4.1
ibm curam_social_program_management 6.0.4.0
ibm curam_social_program_management 6.0.5.0
ibm curam_social_program_management 6.0.5.5
ibm curam_social_program_management 6.0.5.2
ibm curam_social_program_management 6.0.5.8
ibm curam_social_program_management 6.0.5.1
ibm curam_social_program_management 6.0.5.7
ibm curam_social_program_management 6.0.5.6
ibm curam_social_program_management 6.0.5.3
ibm curam_social_program_management 6.0.4.2
ibm curam_social_program_management 6.0.4.5
ibm curam_social_program_management 6.0.4.6
CVE-2014-8904 HIGH

lquerylv in cmdlvm in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x allows local users to gain privileges via a crafted DBGCMD_LQUERYLV environment-variable value.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm vios 2.2.2.2
ibm vios 2.2.2.5
ibm aix 5.3
ibm vios 2.2.3.1
ibm vios 2.2.3.0
ibm vios 2.2.2.0
ibm vios 2.2.2.4
ibm vios 2.2.3.4
ibm vios 2.2.1.0
ibm vios 2.2.1.5
ibm vios 2.2.1.6
ibm vios 2.2.1.8
ibm vios 2.2.2.1
ibm aix 6.1
ibm vios 2.2.0.10
ibm vios 2.2.1.1
ibm vios 2.2.1.4
ibm vios 2.2.3.3
ibm aix 7.1
ibm vios 2.2.3.2
ibm vios 2.2.1.9
ibm vios 2.2.0.12
ibm vios 2.2.0.13
ibm vios 2.2.1.3
ibm vios 2.2.1.7
ibm vios 2.2.0.11
ibm vios 2.2.2.3
CVE-2014-8909 LOW

Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x through 7.0.0.2 CF29, 8.0.0.x before 8.0.0.1 CF15, and 8.5.0 before CF05 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.0
ibm websphere_portal 6.1.0.3
ibm websphere_portal 7.0.0.1
ibm websphere_portal 6.1.5.2
ibm websphere_portal 6.1.0.2
ibm websphere_portal 6.1.0.4
ibm websphere_portal 6.1.5.0
ibm websphere_portal 6.1.0.6
ibm websphere_portal 6.1.5.3
ibm websphere_portal 7.0.0.0
ibm websphere_portal 6.1.0.1
ibm websphere_portal 6.1.5.1
ibm websphere_portal 6.1.0.5
ibm websphere_portal 6.1.0.0
CVE-2014-8910 MEDIUM

IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and Windows allows remote authenticated users to read arbitrary text files via a crafted XML/XSLT function in a SELECT statement.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-74,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2 10.1
ibm db2 9.8
ibm db2 9.7
CVE-2014-8911 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Content Navigator 2.0.0 and 2.0.1 before 2.0.1.2 FP002 IF003 and 2.0.3 before 2.0.3.2 FP002 allows remote attackers to inject arbitrary web script or HTML via the Accept-Language HTTP header.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm content_navigator 2.0.1
ibm content_navigator 2.0.0
ibm content_navigator 2.0.3
CVE-2014-8912 MEDIUM

IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 through 8.0.0.1 CF18, and 8.5.0 before CF08 improperly restricts resource access, which allows remote attackers to obtain sensitive information via unspecified vectors, as demonstrated by configuration information.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm websphere_portal 6.0.0.2
ibm websphere_portal 6.1.0
ibm websphere_portal 8.0.0.0
ibm websphere_portal 6.1.0.3
ibm websphere_portal 6.0.1.0
ibm websphere_portal 6.0.1.1
ibm websphere_portal 6.0.0.4
ibm websphere_portal 6.1.0.4
ibm websphere_portal 8.0.0.1
ibm websphere_portal 6.0.1.3
ibm websphere_portal 6.0.0.1
ibm websphere_portal 6.1.5.0
ibm websphere_portal 6.1.0.6
ibm websphere_portal 6.1.5.3
ibm websphere_portal 6.1.0.1
ibm websphere_portal 6.1.5.1
ibm websphere_portal 6.1.0.0
ibm websphere_portal 6.0.1.4
ibm websphere_portal 6.1
ibm websphere_portal 7.0.0.1
ibm websphere_portal 6.1.5.2
ibm websphere_portal 6.1.0.2
ibm websphere_portal 6.0.1.6
ibm websphere_portal 6.0.1.2
ibm websphere_portal 6.0
ibm websphere_portal 6.0.1.5
ibm websphere_portal 7.0.0.2
ibm websphere_portal 6.0.0.3
ibm websphere_portal 8.5.0.0
ibm websphere_portal 6.0.1.7
ibm websphere_portal 7.0.0.0
ibm websphere_portal 6.1.0.5
CVE-2014-8913 LOW

Cross-site scripting (XSS) vulnerability in the Process Portal in IBM Business Process Manager 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.1, and 8.5.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2014-8914.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm business_process_manager 8.0.1.2
ibm business_process_manager 8.0.1.1
ibm business_process_manager 8.5.5.0
ibm business_process_manager 8.0.1.0
ibm business_process_manager 8.0.0.0
ibm business_process_manager 8.5.0.1
ibm business_process_manager 8.0.1.3
ibm business_process_manager 8.5.0.0
CVE-2014-8914 LOW

Cross-site scripting (XSS) vulnerability in the Process Portal in IBM Business Process Manager 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.1, and 8.5.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2014-8913.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm business_process_manager 8.0.1.2
ibm business_process_manager 8.0.1.1
ibm business_process_manager 8.5.5.0
ibm business_process_manager 8.0.1.0
ibm business_process_manager 8.0.0.0
ibm business_process_manager 8.5.0.1
ibm business_process_manager 8.0.1.3
ibm business_process_manager 8.5.0.0
CVE-2014-8916 LOW

Cross-site scripting (XSS) vulnerability in IBM OpenPages GRC Platform 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1 before FP1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2015-0144.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm openpages_grc_platform 7.1.0.0
ibm openpages_grc_platform 6.2.0.0
ibm openpages_grc_platform 6.2.1.1
ibm openpages_grc_platform 7.0.0.0
ibm openpages_grc_platform 6.2.1.0
CVE-2014-8917 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in (1) dojox/form/resources/uploader.swf (aka upload.swf), (2) dojox/form/resources/fileuploader.swf (aka fileupload.swf), (3) dojox/av/resources/audio.swf, and (4) dojox/av/resources/video.swf in the IBM Dojo Toolkit, as used in IBM Social Media Analytics 1.3 before IF11 and other products, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm financial_transaction_manager 2.0.0.0
ibm financial_transaction_manager_for_corporate_payment_services 2.1.1.0
ibm financial_transaction_manager 2.0.0.3
ibm financial_transaction_manager 2.1.0.2
ibm financial_transaction_manager 3.0.0.0
ibm financial_transaction_manager 2.1.0.0
ibm social_media_analytics *
ibm financial_transaction_manager 2.1.1.0
ibm financial_transaction_manager_for_check_services 2.1.1.8
ibm financial_transaction_manager 2.0.0.2
ibm financial_transaction_manager 2.1.1.1
ibm financial_transaction_manager 2.0.0.1
ibm financial_transaction_manager 2.1.0.1
CVE-2014-8918 MEDIUM

IBM Security AppScan Standard 8.x and 9.x before 9.0.1.1 FP1 does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm security_appscan 8.0.0.1
ibm security_appscan 9.0.1.0
ibm security_appscan 9.0.1.1
ibm security_appscan 9.0.0.0
ibm security_appscan 8.6.0.1
ibm security_appscan 8.6.0.0
ibm security_appscan 9.0.0.1
ibm security_appscan 8.0.0.3
ibm security_appscan 8.8.0.0
ibm security_appscan 8.5.0.1
ibm security_appscan 8.0.0.2
ibm security_appscan 8.0.0.0
ibm security_appscan 8.7.0.0
ibm security_appscan 8.7.0.1
ibm security_appscan 8.5.0.0
CVE-2014-8920 HIGH

Buffer overflow in the Data Transfer Program in IBM i Access 5770-XE1 5R4, 6.1, and 7.1 on Windows allows local users to gain privileges via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm i_access 5r4
ibm i_access 6.1
ibm i_access 7.1
CVE-2014-8921 MEDIUM

The IBM Notes Traveler Companion application 1.0 and 1.1 before 201411010515 for Window Phone, as distributed in IBM Notes Traveler 9.0.1, does not properly restrict the number of executions of the automatic configuration option, which makes it easier for remote attackers to capture credentials by conducting a phishing attack involving an encrypted e-mail message.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm notes_traveler_companion 1.1
ibm notes_traveler_companion 1.0
CVE-2014-8923 LOW

The (1) IBM Tivoli Identity Manager Active Directory adapter before 5.1.24 and (2) IBM Security Identity Manager Active Directory adapter before 6.0.14 for IBM Security Identity Manager on Windows, when certain log and trace levels are configured, store the cleartext administrator password in a log file, which allows local users to obtain sensitive information by reading a file.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_identity_manager_active_directory_adapter *
ibm tivoli_identity_manager_active_directory_adapter *
CVE-2014-8924 MEDIUM

The server in IBM License Metric Tool 7.2.2 before IF15 and 7.5 before IF24 and Tivoli Asset Discovery for Distributed 7.2.2 before IF15 and 7.5 before IF24 allows remote attackers to read arbitrary files or send TCP requests to intranet servers via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm license_metric_tool 7.5
ibm license_metric_tool 7.2.2
ibm tivoli_asset_discovery_for_distributed 7.5
ibm tivoli_asset_discovery_for_distributed 7.2.2
CVE-2014-8925 MEDIUM

Cross-site request forgery (CSRF) vulnerability in ClearQuest Web in IBM Rational ClearQuest 7.1.x before 7.1.2.17, 8.0.0.x before 8.0.0.14, and 8.0.1.x before 8.0.1.7 allows remote attackers to hijack the authentication of arbitrary users for requests that trigger a logout or insert XSS sequences.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm rational_clearquest 8.0.0.12
ibm rational_clearquest 8.0.0.5
ibm rational_clearquest 8.0.1.2
ibm rational_clearquest 7.1.1.1
ibm rational_clearquest 7.1.2.2
ibm rational_clearquest 8.0.1.1
ibm rational_clearquest 7.1.1.3
ibm rational_clearquest 8.0.0.1
ibm rational_clearquest 8.0.0.3
ibm rational_clearquest 7.1
ibm rational_clearquest 7.1.2.15
ibm rational_clearquest 8.0.0.9
ibm rational_clearquest 8.0.0.11
ibm rational_clearquest 7.1.1.5
ibm rational_clearquest 8.0.0
ibm rational_clearquest 8.0.0.2
ibm rational_clearquest 7.1.1.4
ibm rational_clearquest 7.1.2.11
ibm rational_clearquest 7.1.2.12
ibm rational_clearquest 7.1.0.1
ibm rational_clearquest 7.1.2.13
ibm rational_clearquest 7.1.1.7
ibm rational_clearquest 7.1.1
ibm rational_clearquest 7.1.2
ibm rational_clearquest 7.1.0.2
ibm rational_clearquest 8.0.0.7
ibm rational_clearquest 8.0.0.10
ibm rational_clearquest 8.0.1.3
ibm rational_clearquest 8.0.1.5
ibm rational_clearquest 8.0.1
ibm rational_clearquest 8.0.1.4
ibm rational_clearquest 7.1.2.7
ibm rational_clearquest 7.1.2.1
ibm rational_clearquest 7.1.1.9
ibm rational_clearquest 7.1.2.3
ibm rational_clearquest 8.0.0.8
ibm rational_clearquest 8.0.0.4
ibm rational_clearquest 7.1.2.5
ibm rational_clearquest 7.1.1.8
ibm rational_clearquest 7.1.2.6
ibm rational_clearquest 7.1.2.8
ibm rational_clearquest 7.1.2.14
ibm rational_clearquest 7.1.1.6
ibm rational_clearquest 7.1.2.9
ibm rational_clearquest 7.1.2.10
ibm rational_clearquest 7.1.1.2
ibm rational_clearquest 7.1.2.4
ibm rational_clearquest 8.0.0.6
CVE-2014-8926 MEDIUM

Common Inventory Technology (CIT) before 2.7.0.2050 in IBM License Metric Tool 7.2.2, 7.5, and 9; Endpoint Manger for Software Use Analysis 9; and Tivoli Asset Discovery for Distributed 7.2.2 and 7.5 allows remote attackers to cause a denial of service (CPU consumption or application crash) via a crafted XML query, a different vulnerability than CVE-2014-8927.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm endpoint_manager_family 9.0
ibm license_metric_tool 7.5
ibm license_metric_tool 7.2.2
ibm tivoli_asset_discovery_for_distributed 7.5
ibm tivoli_asset_discovery_for_distributed 7.2.2.0
ibm license_metric_tool 9.0.1
CVE-2014-8927 MEDIUM

Common Inventory Technology (CIT) before 2.7.0.2050 in IBM License Metric Tool 7.2.2, 7.5, and 9; Endpoint Manger for Software Use Analysis 9; and Tivoli Asset Discovery for Distributed 7.2.2 and 7.5 allows remote attackers to cause a denial of service (CPU consumption or application crash) via a crafted XML query, a different vulnerability than CVE-2014-8926.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm endpoint_manager_family 9.0
ibm license_metric_tool 7.5
ibm license_metric_tool 9.0
ibm license_metric_tool 7.2.2
ibm tivoli_asset_discovery_for_distributed 7.5
ibm tivoli_asset_discovery_for_distributed 7.2.2.0
CVE-2014-9564 MEDIUM

CRLF injection vulnerability in IBM Flex System EN6131 40Gb Ethernet and IB6131 40Gb Infiniband Switch firmware before 3.4.1110 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks and resulting web cache poisoning or cross-site scripting (XSS) attacks, or obtain sensitive information via multiple unspecified parameters.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-93,

Products Affected

Vendor Product Version
ibm en6131_firmware -
ibm ib6131_firmware -
CVE-2014-9565 MEDIUM

Cross-site request forgery (CSRF) vulnerability in IBM Flex System EN6131 40Gb Ethernet and IB6131 40Gb Infiniband Switch firmware 3.4.0000 and earlier.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm ib6131_firmware *
ibm en6131_firmware *
CVE-2014-9768 HIGH

IBM Tivoli NetView Access Services (NVAS) allows remote authenticated users to gain privileges by entering the ADM command and modifying a "page ID" field to the EMSPG2 transaction code. NOTE: the vendor's perspective is that configuration and use of available security controls in the NVAS product mitigates the reported vulnerability

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm tivoli_netview_access_services -
CVE-2015-0101 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Business Process Manager Standard 7.5.x before 7.5, 8.0.x before 8.0.1, 8.5.x before 8.5.5; IBM Business Process Manager Express 7.5.x before 7.5, 8.0.x before 8.0.1, 8.5.x before 8.5.5; and IBM Business Process Manager Advanced 7.5.x before 7.5, 8.0.x before 8.0.1, 8.5.x before 8.5.5.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm business_process_manager 8.0.1.2
ibm business_process_manager 8.0.1.1
ibm business_process_manager 7.5.0.1
ibm business_process_manager 8.5
ibm business_process_manager 7.5.1.1
ibm business_process_manager 8.5.5
ibm business_process_manager 8.0
ibm business_process_manager 8.0.1
ibm business_process_manager 7.5.1.2
ibm business_process_manager 7.5
ibm business_process_manager 7.5.1
ibm business_process_manager 8.5.0.1
ibm business_process_manager 8.0.1.3
CVE-2015-0103 LOW

Multiple cross-site scripting (XSS) vulnerabilities in the Process Portal in IBM Business Process Manager (BPM) 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.1, and 8.5.5 through 8.5.5.0 allow remote authenticated users to inject arbitrary web script or HTML via unspecified data fields.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm business_process_manager 8.0.1.2
ibm business_process_manager 8.0.1.1
ibm business_process_manager 8.5.5.0
ibm business_process_manager 8.0.1.0
ibm business_process_manager 8.0.0.0
ibm business_process_manager 8.5.0.1
ibm business_process_manager 8.0.1.3
ibm business_process_manager 8.5.0.0
CVE-2015-0104 MEDIUM

IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration Management Database 7.1 through 7.1.1.8 and 7.2 and Maximo Asset Management and Maximo Industry Solutions 7.1 through 7.1.1.8, 7.5 before 7.5.0.7 IFIX003, and 7.6 before 7.6.0.0 IFIX002 allow remote authenticated users to execute arbitrary code via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm tivoli_asset_management_for_it 7.2
ibm maximo_asset_management 7.1
ibm maximo_for_life_sciences 7.1
ibm maximo_for_government 7.1
ibm tivoli_asset_management_for_it 7.1
ibm maximo_for_transportation 7.1
ibm tivoli_service_request_manager 7.1
ibm maximo_asset_management_essentials 7.1
ibm maximo_asset_management 7.1.1.1
ibm maximo_for_utilities 7.1
ibm maximo_asset_management 7.1.1.7
ibm change_and_configuration_management_database 7.1
ibm maximo_asset_management 7.1.1.2
ibm maximo_for_oil_and_gas 7.1
ibm maximo_asset_management 7.1.1.6
ibm change_and_configuration_management_database 7.2
ibm maximo_asset_management 7.1.1.5
ibm maximo_for_nuclear_power 7.1
ibm tivoli_service_request_manager 7.2
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
CVE-2015-0105 MEDIUM

Cross-site scripting (XSS) vulnerability in the Process Portal in IBM Business Process Manager (BPM) 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.1, and 8.5.5 through 8.5.5.0 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm business_process_manager 8.0.1.2
ibm business_process_manager 8.0.1.1
ibm business_process_manager 8.5.5.0
ibm business_process_manager 8.0.1.0
ibm business_process_manager 8.0.0.0
ibm business_process_manager 8.5.0.1
ibm business_process_manager 8.0.1.3
ibm business_process_manager 8.5.0.0
CVE-2015-0106 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.1, and 8.5.5 through 8.5.5.0 and WebSphere Lombardi Edition (WLE) 7.2.x through 7.2.0.5 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm business_process_manager 8.0.1.2
ibm business_process_manager 8.0.1.1
ibm business_process_manager 7.5.0.1
ibm websphere_application_server 7.2
ibm websphere_application_server 7.2.0.3
ibm websphere_application_server 7.2.0.2
ibm websphere_application_server 7.2.0.4
ibm business_process_manager 7.5.1.0
ibm websphere_application_server 7.2.0.1
ibm business_process_manager 7.5.1.1
ibm business_process_manager 8.5.5.0
ibm business_process_manager 8.0.1.0
ibm business_process_manager 7.5.1.2
ibm business_process_manager 8.0.0.0
ibm business_process_manager 8.5.0.1
ibm websphere_application_server 7.2.0.5
ibm business_process_manager 8.0.1.3
ibm websphere_application_server 7.1
ibm business_process_manager 8.5.0.0
ibm business_process_manager 7.5.0.0
CVE-2015-0107 MEDIUM

IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration Management Database 7.1 through 7.1.1.8 and 7.2 and Maximo Asset Management and Maximo Industry Solutions 7.1 through 7.1.1.8, 7.5 before 7.5.0.7 IFIX003, and 7.6 before 7.6.0.0 IFIX002 allow remote authenticated users to conduct directory traversal attacks via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm tivoli_asset_management_for_it 7.2
ibm maximo_asset_management 7.1
ibm maximo_for_life_sciences 7.1
ibm maximo_for_government 7.1
ibm tivoli_asset_management_for_it 7.1
ibm maximo_for_transportation 7.1
ibm tivoli_service_request_manager 7.1
ibm maximo_asset_management_essentials 7.1
ibm maximo_asset_management 7.1.1.1
ibm maximo_for_utilities 7.1
ibm maximo_asset_management 7.1.1.7
ibm change_and_configuration_management_database 7.1
ibm maximo_asset_management 7.1.1.2
ibm maximo_for_oil_and_gas 7.1
ibm maximo_asset_management 7.1.1.6
ibm change_and_configuration_management_database 7.2
ibm maximo_asset_management 7.1.1.5
ibm maximo_for_nuclear_power 7.1
ibm tivoli_service_request_manager 7.2
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
CVE-2015-0108 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.8, and Maximo Asset Management 7.1 through 7.1.1.8 and 7.2 for Tivoli IT Asset Management for IT and certain other products, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-0104, CVE-2015-0107, and CVE-2015-0109.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_asset_management_for_it 7.2
ibm maximo_asset_management 7.1
ibm maximo_for_life_sciences 7.1
ibm maximo_for_government 7.1
ibm tivoli_asset_management_for_it 7.1
ibm maximo_for_transportation 7.1
ibm tivoli_service_request_manager 7.1
ibm maximo_asset_management_essentials 7.1
ibm maximo_asset_management 7.1.1.1
ibm maximo_for_utilities 7.1
ibm maximo_asset_management 7.1.1.7
ibm change_and_configuration_management_database 7.1
ibm maximo_asset_management 7.1.1.2
ibm maximo_for_oil_and_gas 7.1
ibm maximo_asset_management 7.1.1.6
ibm change_and_configuration_management_database 7.2
ibm maximo_asset_management 7.1.1.5
ibm maximo_for_nuclear_power 7.1
ibm tivoli_service_request_manager 7.2
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
CVE-2015-0109 LOW

Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.8, and Maximo Asset Management 7.1 through 7.1.1.8 and 7.2 for Tivoli IT Asset Management for IT and certain other products, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-0104, CVE-2015-0107, and CVE-2015-0108.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_asset_management_for_it 7.2
ibm maximo_asset_management 7.1
ibm maximo_for_life_sciences 7.1
ibm maximo_for_government 7.1
ibm tivoli_asset_management_for_it 7.1
ibm maximo_for_transportation 7.1
ibm tivoli_service_request_manager 7.1
ibm maximo_asset_management_essentials 7.1
ibm maximo_asset_management 7.1.1.1
ibm maximo_for_utilities 7.1
ibm maximo_asset_management 7.1.1.7
ibm change_and_configuration_management_database 7.1
ibm maximo_asset_management 7.1.1.2
ibm maximo_for_oil_and_gas 7.1
ibm maximo_asset_management 7.1.1.6
ibm change_and_configuration_management_database 7.2
ibm maximo_asset_management 7.1.1.5
ibm maximo_for_nuclear_power 7.1
ibm tivoli_service_request_manager 7.2
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
CVE-2015-0110 MEDIUM

IBM Business Process Manager (aka BPM) 7.5.x, 8.0.x, and 8.5.x and WebSphere Lombardi Edition (aka WLE) 7.2.x allow remote authenticated users to bypass intended access restrictions on internal service types via vectors involving the executeServiceByName URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm business_process_manager 8.0.1.2
ibm business_process_manager 8.0.1.1
ibm business_process_manager 7.5.0.1
ibm websphere_application_server 7.2.0.3
ibm websphere_application_server 7.2.0.2
ibm websphere_application_server 7.2.0.4
ibm business_process_manager 7.5.1.0
ibm websphere_application_server 7.2.0.1
ibm business_process_manager 7.5.1.1
ibm websphere_application_server 7.2.0.0
ibm business_process_manager 8.5.5.0
ibm business_process_manager 8.0.1.0
ibm business_process_manager 7.5.1.2
ibm business_process_manager 8.0.0.0
ibm business_process_manager 8.5.0.1
ibm websphere_application_server 7.2.0.5
ibm business_process_manager 8.0.1.3
ibm business_process_manager 8.5.0.0
ibm business_process_manager 7.5.0.0
CVE-2015-0112 MEDIUM

Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.0.1, 4.x before 4.0.7 IF5, and 5.x before 5.0.2 IF4; Rational Quality Manager (RQM) 2.0 through 2.0.1, 3.0 through 3.0.1.6, 4.0 through 4.0.7, and 5.0 through 5.0.2; Rational Team Concert (RTC) 2.0 through 2.0.0.2, 3.x before 3.0.1.6 IF6, 4.x before 4.0.7 IF5, and 5.x before 5.0.2 IF4; Rational Requirements Composer (RRC) 2.0 through 2.0.0.4, 3.x before 3.0.1.6 IF6, and 4.0 through 4.0.7; Rational DOORS Next Generation (RDNG) 4.x before 4.0.7 IF5 and 5.x before 5.0.2 IF4; Rational Engineering Lifecycle Manager (RELM) 1.0 through 1.0.0.1, 4.0.3 through 4.0.7, and 5.0 through 5.0.2; Rational Rhapsody Design Manager (DM) 3.0 through 3.0.1, 4.0 through 4.0.7, and 5.0 through 5.0.2; and Rational Software Architect Design Manager (RSA DM) 3.0 through 3.0.1, 4.0 through 4.0.7, and 5.0 through 5.0.2 allows remote authenticated users to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm rational_collaborative_lifecycle_management 3.0.1.2
ibm rational_doors_next_generation 4.0.0
ibm rational_collaborative_lifecycle_management 4.0.6
ibm rational_engineering_lifecycle_manager 4.0.7
ibm rational_requirements_composer 3.0.1.4
ibm rational_requirements_composer 3.0.1.1
ibm rational_requirements_composer 2.0
ibm rational_software_architect_design_manager 4.0.7
ibm rhapsody_design_manager 4.0.0
ibm rhapsody_design_manager 4.0.5
ibm rational_team_concert 2.0.0.2
ibm rational_quality_manager 2.0.1
ibm rational_engineering_lifecycle_manager 5.0.2
ibm rational_team_concert 2.0.0.1
ibm rational_quality_manager 4.0.3
ibm rational_team_concert 4.0.1
ibm rational_team_concert 4.0.5
ibm rational_team_concert 4.0.2
ibm rational_requirements_composer 3.5
ibm rhapsody_design_manager 4.0.6
ibm rational_collaborative_lifecycle_management 3.0.1.3
ibm rational_collaborative_lifecycle_management 4.0.5
ibm rational_collaborative_lifecycle_management 4.0.7
ibm rational_collaborative_lifecycle_management 5.0.0
ibm rhapsody_design_manager 4.0.4
ibm rational_collaborative_lifecycle_management 4.0.3
ibm rational_requirements_composer 2.0.0.1
ibm rational_software_architect_design_manager 4.0.6
ibm rational_doors_next_generation 4.0.7
ibm rational_doors_next_generation 4.0.2
ibm rational_team_concert 3.0.1.4
ibm rational_requirements_composer 4.0
ibm rational_team_concert 3.0.1.1
ibm rational_quality_manager 2.0.0.1
ibm rational_requirements_composer 3.0
ibm rational_requirements_composer 4.0.4
ibm rational_team_concert 5.0.2
ibm rational_requirements_composer 4.0.1
ibm rational_requirements_composer 3.0.1.2
ibm rational_requirements_composer 4.0.7
ibm rational_collaborative_lifecycle_management 4.0.1
ibm rhapsody_design_manager 4.0.7
ibm rational_team_concert 4.0.3
ibm rational_collaborative_lifecycle_management 3.0.1.4
ibm rational_quality_manager 3.0.1.3
ibm rational_team_concert 3.0.1
ibm rational_collaborative_lifecycle_management 4.0.2
ibm rational_requirements_composer 4.0.0
ibm rational_quality_manager 3.0
ibm rational_requirements_composer 2.0.0.2
ibm rational_quality_manager 2.0
ibm rational_quality_manager 4.0.1
ibm rational_team_concert 4.0.6
ibm rational_engineering_lifecycle_manager 1.0.0.1
ibm rational_quality_manager 3.0.1.2
ibm rational_quality_manager 5.0.0
ibm rational_engineering_lifecycle_manager 4.0.5
ibm rational_requirements_composer 4.0.2
ibm rational_software_architect_design_manager 5.0.2
ibm rational_requirements_composer 4.0.3
ibm rhapsody_design_manager 5.0.2
ibm rational_doors_next_generation 4.0.4
ibm rational_quality_manager 3.0.1.4
ibm rational_quality_manager 4.0.4
ibm rational_software_architect_design_manager 4.0.0
ibm rational_engineering_lifecycle_manager 4.0.6
ibm rational_collaborative_lifecycle_management 3.0.1.5
ibm rational_doors_next_generation 5.0.2
ibm rational_quality_manager 4.0.2
ibm rational_requirements_composer 4.0.0.2
ibm rational_requirements_composer 4.0.5
ibm rational_doors_next_generation 5.0.1
ibm rational_software_architect_design_manager 4.0.1
ibm rational_team_concert 3.0.1.6
ibm rational_collaborative_lifecycle_management 4.0.4
ibm rational_software_architect_design_manager 3.0.0.1
ibm rational_team_concert 4.0.0.1
ibm rational_software_architect_design_manager 3.0.1
ibm rational_engineering_lifecycle_manager 4.0.3
ibm rational_engineering_lifecycle_manager 4.0.4
ibm rational_software_architect_design_manager 4.0.2
ibm rhapsody_design_manager 4.0.2
ibm rational_quality_manager 2.0.0.2
ibm rational_quality_manager 4.0.0.1
ibm rational_quality_manager 4.0.0.2
ibm rhapsody_design_manager 3.0.0.1
ibm rational_quality_manager 4.0.7
ibm rational_requirements_composer 3.0.1.6
ibm rational_engineering_lifecycle_manager 1.0
ibm rational_requirements_composer 4.0.6
ibm rational_software_architect_design_manager 4.0.4
ibm rational_doors_next_generation 4.0.1
ibm rational_engineering_lifecycle_manager 5.0.1
ibm rational_quality_manager 3.0.1.5
ibm rational_team_concert 4.0.7
ibm rhapsody_design_manager 3.0.0
ibm rational_team_concert 3.0.1.2
ibm rational_software_architect_design_manager 4.0.3
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_quality_manager 5.0.2
ibm rational_requirements_composer 2.0.0.3
ibm rational_team_concert 4.0.0.2
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_requirements_composer 3.0.1
ibm rational_collaborative_lifecycle_management 4.0.0
ibm rational_requirements_composer 3.0.1.3
ibm rational_collaborative_lifecycle_management 3.0.1.6
ibm rational_quality_manager 3.0.1.6
ibm rational_team_concert 2.0
ibm rhapsody_design_manager 4.0.3
ibm rational_quality_manager 3.0.1.1
ibm rational_team_concert 4.0
ibm rational_doors_next_generation 4.0.5
ibm rational_requirements_composer 4.0.0.1
ibm rational_doors_next_generation 4.0.6
ibm rational_team_concert 3.0
ibm rational_doors_next_generation 4.0.3
ibm rational_requirements_composer 2.0.0.4
ibm rational_quality_manager 4.0
ibm rational_team_concert 5.0.0
ibm rational_collaborative_lifecycle_management 3.0.1
ibm rational_requirements_composer 3.0.1.5
ibm rhapsody_design_manager 3.0.1
ibm rational_team_concert 3.0.1.5
ibm rhapsody_design_manager 4.0.1
ibm rational_team_concert 3.0.1.3
ibm rational_quality_manager 3.0.1
ibm rational_collaborative_lifecycle_management 3.0.1.1
ibm rational_software_architect_design_manager 3.0.0
ibm rational_software_architect_design_manager 4.0.5
ibm rational_team_concert 4.0.4
ibm rational_software_architect_design_manager 5.0.1
ibm rational_quality_manager 4.0.5
ibm rational_team_concert 5.0.1
ibm rhapsody_design_manager 5.0
CVE-2015-0113 MEDIUM

The Jazz help system in IBM Rational Collaborative Lifecycle Management 4.0 through 5.0.2, Rational Quality Manager 4.0 through 4.0.7 and 5.0 through 5.0.2, Rational Team Concert 4.0 through 4.0.7 and 5.0 through 5.0.2, Rational Requirements Composer 4.0 through 4.0.7, Rational DOORS Next Generation 4.0 through 4.0.7 and 5.0 through 5.0.2, Rational Engineering Lifecycle Manager 4.0.3 through 4.0.7 and 5.0 through 5.0.2, Rational Rhapsody Design Manager 4.0 through 4.0.7 and 5.0 through 5.0.2, and Rational Software Architect Design Manager 4.0 through 4.0.7 and 5.0 through 5.0.2 allows remote attackers to read JSP source code via a crafted request.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_rhapsody_design_manager 4.0.4
ibm rational_team_concert 4.0.0.1
ibm rational_rhapsody_design_manager 4.0.5
ibm rational_doors_next_generation 4.0.0
ibm rational_engineering_lifecycle_manager 4.0.3
ibm rational_engineering_lifecycle_manager 4.0.4
ibm rational_software_architect_design_manager 4.0.2
ibm rational_collaborative_lifecycle_management 4.0.6
ibm rational_engineering_lifecycle_manager 4.0.7
ibm rational_quality_manager 4.0.0.1
ibm rational_quality_manager 4.0.0.2
ibm rational_software_architect_design_manager 4.0.7
ibm rational_quality_manager 4.0.7
ibm rational_rhapsody_design_manager 4.0.6
ibm rational_requirements_composer 4.0.6
ibm rational_software_architect_design_manager 5.0
ibm rational_engineering_lifecycle_manager 5.0.2
ibm rational_software_architect_design_manager 4.0.4
ibm rational_rhapsody_design_manager 5.0.2
ibm rational_quality_manager 4.0.3
ibm rational_doors_next_generation 4.0.1
ibm rational_engineering_lifecycle_manager 5.0.1
ibm rational_team_concert 4.0.7
ibm rational_team_concert 4.0.1
ibm rational_team_concert 4.0.5
ibm rational_software_architect_design_manager 4.0.3
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_team_concert 4.0.2
ibm rational_quality_manager 5.0.2
ibm rational_collaborative_lifecycle_management 4.0.5
ibm rational_collaborative_lifecycle_management 4.0.7
ibm rational_collaborative_lifecycle_management 5.0.0
ibm rational_collaborative_lifecycle_management 4.0.3
ibm rational_software_architect_design_manager 4.0.6
ibm rational_doors_next_generation 4.0.7
ibm rational_rhapsody_design_manager 4.0.1
ibm rational_rhapsody_design_manager 4.0.2
ibm rational_team_concert 4.0.0.2
ibm rational_doors_next_generation 4.0.2
ibm rational_rhapsody_design_manager 4.0
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_collaborative_lifecycle_management 4.0.0
ibm rational_rhapsody_design_manager 5.0.1
ibm rational_rhapsody_design_manager 4.0.7
ibm rational_team_concert 4.0
ibm rational_requirements_composer 4.0.4
ibm rational_engineering_lifecycle_manager 5.0
ibm rational_doors_next_generation 4.0.5
ibm rational_team_concert 5.0.2
ibm rational_requirements_composer 4.0.1
ibm rational_requirements_composer 4.0.7
ibm rational_collaborative_lifecycle_management 4.0.1
ibm rational_requirements_composer 4.0.0.1
ibm rational_rhapsody_design_manager 5.0
ibm rational_team_concert 4.0.3
ibm rational_doors_next_generation 4.0.6
ibm rational_doors_next_generation 4.0.3
ibm rational_quality_manager 5.0.1
ibm rational_collaborative_lifecycle_management 4.0.2
ibm rational_quality_manager 4.0
ibm rational_requirements_composer 4.0.0
ibm rational_quality_manager 4.0.1
ibm rational_team_concert 4.0.6
ibm rational_team_concert 5.0.0
ibm rational_quality_manager 5.0.0
ibm rational_engineering_lifecycle_manager 4.0.5
ibm rational_requirements_composer 4.0.2
ibm rational_software_architect_design_manager 5.0.2
ibm rational_requirements_composer 4.0.3
ibm rational_doors_next_generation 4.0.4
ibm rational_quality_manager 4.0.4
ibm rational_software_architect_design_manager 4.0.0
ibm rational_software_architect_design_manager 4.0.5
ibm rational_team_concert 4.0.4
ibm rational_software_architect_design_manager 5.0.1
ibm rational_engineering_lifecycle_manager 4.0.6
ibm rational_rhapsody_design_manager 4.0.3
ibm rational_quality_manager 4.0.5
ibm rational_doors_next_generation 5.0.2
ibm rational_quality_manager 4.0.2
ibm rational_requirements_composer 4.0.0.2
ibm rational_requirements_composer 4.0.5
ibm rational_doors_next_generation 5.0.1
ibm rational_software_architect_design_manager 4.0.1
ibm rational_collaborative_lifecycle_management 4.0.4
ibm rational_team_concert 5.0.1
CVE-2015-0114 MEDIUM

Stack-based buffer overflow in IBM V5R4, and IBM i Access for Windows 6.1 and 7.1.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm i_access_for_windows 7.1
ibm i_access_for_windows 6.1
ibm i_access_for_windows 5.4
CVE-2015-0115 MEDIUM

Cross-site request forgery (CSRF) vulnerability in IBM Leads 7.x, 8.1.0 before 8.1.0.14, 8.2, 8.5.0 before 8.5.0.7.3, 8.6.0 before 8.6.0.8.1, 9.0.0 through 9.0.0.4, 9.1.0 before 9.1.0.6.1, and 9.1.1 before 9.1.1.0.2 allows remote authenticated users to hijack the authentication of customer accounts.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm leads 9.1.1
ibm leads 9.0.0
ibm leads 7.1.1
ibm leads 8.2.0
ibm leads 9.1.0
ibm leads 7.1.0
ibm leads 8.5.0
ibm leads 8.1.0
ibm leads 7.5.0
ibm leads 8.6.0
CVE-2015-0116 LOW

IBM Leads 7.x, 8.1.0 before 8.1.0.14, 8.2, 8.5.0 before 8.5.0.7.3, 8.6.0 before 8.6.0.8.1, 9.0.0 through 9.0.0.4, 9.1.0 before 9.1.0.6.1, and 9.1.1 before 9.1.1.0.2 does not properly restrict the addition of links, which makes it easier for remote authenticated users to conduct cross-site request forgery (CSRF) attacks via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-74,

Products Affected

Vendor Product Version
ibm leads 9.1.1
ibm leads 9.0.0
ibm leads 7.1.1
ibm leads 8.2.0
ibm leads 9.1.0
ibm leads 7.1.0
ibm leads 8.5.0
ibm leads 8.1.0
ibm leads 7.5.0
ibm leads 8.6.0
CVE-2015-0117 HIGH

The LDAP Server in IBM Domino 8.5.x before 8.5.3 FP6 IF6 and 9.x before 9.0.1 FP3 IF1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, aka SPR KLYH9SLRGM.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm domino 8.5.0
ibm domino 8.5.1
ibm domino 8.5.2
ibm domino 9.0.1
ibm domino 8.5.3
CVE-2015-0118 MEDIUM

IBM WebSphere Message Broker Toolkit 7 before 7007 IF2 and 8 before 8005 IF1 and Integration Toolkit 9 before 9003 IF1 are distributed with MQ client JAR files that support only weak TLS ciphers, which might make it easier for remote attackers to obtain sensitive information by sniffing the network during a connection to an Integration Bus node.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm websphere_message_broker 7.0.0.1
ibm websphere_message_broker 7.0.0.2
ibm websphere_message_broker 8.0
ibm websphere_message_broker 7.0.0.5
ibm integration_bus 9.0.0.2
ibm websphere_message_broker 7.0.0.4
ibm websphere_message_broker 8.0.0.4
ibm websphere_message_broker 8.0.0.3
ibm integration_bus 9.0
ibm websphere_message_broker 8.0.0.2
ibm websphere_message_broker 7.0.0.3
ibm websphere_message_broker 8.0.0.5
ibm websphere_message_broker 7.0.
ibm integration_bus 9.0.0.1
ibm websphere_message_broker 8.0.0.1
ibm integration_bus 9.0.0.3
CVE-2015-0119 HIGH

FastBack Mount in IBM Tivoli Storage Manager FastBack 6.1.x before 6.1.11.1 allows remote attackers to execute arbitrary code by connecting to the Mount port.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_fastback 6.1.10.0
ibm tivoli_storage_manager_fastback 6.1.0.0
ibm tivoli_storage_manager_fastback 6.1.9.0
ibm tivoli_storage_manager_fastback 6.1.10.1
ibm tivoli_storage_manager_fastback 6.1.1.0
ibm tivoli_storage_manager_fastback 6.1.9.1
ibm tivoli_storage_manager_fastback *
CVE-2015-0120 HIGH

Buffer overflow in the FastBackMount process in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.11.1 has unspecified impact and remote attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_fastback 6.1.0.1
ibm tivoli_storage_manager_fastback 6.1.10.0
ibm tivoli_storage_manager_fastback 6.1.0.0
ibm tivoli_storage_manager_fastback 6.1.9.0
ibm tivoli_storage_manager_fastback 6.1.8.1
ibm tivoli_storage_manager_fastback 6.1.7.2
ibm tivoli_storage_manager_fastback 6.1.8.0
ibm tivoli_storage_manager_fastback 6.1.11.0
ibm tivoli_storage_manager_fastback 6.1.10.1
ibm tivoli_storage_manager_fastback 6.1.1.0
ibm tivoli_storage_manager_fastback 6.1.9.1
CVE-2015-0121 LOW

IBM Rational Requirements Composer 3.0 through 3.0.1.6 and 4.0 through 4.0.7 and Rational DOORS Next Generation (RDNG) 4.0 through 4.0.7 and 5.0 through 5.0.2, when LTPA single sign on is used with WebSphere Application Server, do not terminate a Requirements Management (RM) session upon LTPA token expiration, which allows remote attackers to obtain access by leveraging an unattended workstation.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm rational_doors_next_generation 4.0.0
ibm rational_requirements_composer 3.0
ibm rational_requirements_composer 4.0.4
ibm rational_doors_next_generation 4.0.5
ibm rational_requirements_composer 4.0.1
ibm rational_requirements_composer 3.0.1.2
ibm rational_requirements_composer 4.0.7
ibm rational_requirements_composer 3.0.1.4
ibm rational_requirements_composer 4.0.0.1
ibm rational_requirements_composer 3.0.1.1
ibm rational_doors_next_generation 4.0.6
ibm rational_doors_next_generation 4.0.3
ibm rational_requirements_composer 3.0.1.6
ibm rational_requirements_composer 4.0.0
ibm rational_requirements_composer 4.0.6
ibm rational_doors_next_generation 4.0.1
ibm rational_requirements_composer 3.0.1.5
ibm rational_requirements_composer 4.0.2
ibm rational_doors_next_generation 5.0
ibm rational_requirements_composer 4.0.3
ibm rational_doors_next_generation 4.0.4
ibm rational_doors_next_generation 4.0.7
ibm rational_doors_next_generation 5.0.2
ibm rational_doors_next_generation 4.0.2
ibm rational_requirements_composer 3.0.1
ibm rational_requirements_composer 3.0.1.3
ibm rational_requirements_composer 4.0.0.2
ibm rational_requirements_composer 4.0.5
ibm rational_doors_next_generation 5.0.1
ibm rational_requirements_composer 4.0
CVE-2015-0122 LOW

Cross-site scripting (XSS) vulnerability in IBM Rational Team Concert 2.x and 3.x before 3.0.1.6 iFix 5, 4.x before 4.0.7 iFix3, and 5.x before 5.0.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2015-0123.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_team_concert 3.0.1.1
ibm rational_team_concert 5.0.0
ibm rational_team_concert 4.0.0.1
ibm rational_team_concert 4.0.7
ibm rational_team_concert 3.0.1.5
ibm rational_team_concert 3.0.1.3
ibm rational_team_concert 4.0.1
ibm rational_team_concert 3.0.1.2
ibm rational_team_concert 4.0
ibm rational_team_concert 4.0.5
ibm rational_team_concert 4.0.2
ibm rational_team_concert 4.0.4
ibm rational_team_concert 4.0.3
ibm rational_team_concert 3.0
ibm rational_team_concert 4.0.0.2
ibm rational_team_concert 3.0.1
ibm rational_team_concert 3.0.1.4
ibm rational_team_concert 2.0.0.2
ibm rational_team_concert 4.0.6
ibm rational_team_concert 3.0.1.6
ibm rational_team_concert 5.0.1
CVE-2015-0123 LOW

Cross-site scripting (XSS) vulnerability in IBM Rational Team Concert 2.x and 3.x before 3.0.1.6 iFix 5, 4.x before 4.0.7 iFix3, and 5.x before 5.0.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2015-0122.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_team_concert 3.0.1.1
ibm rational_team_concert 5.0.0
ibm rational_team_concert 4.0.0.1
ibm rational_team_concert 4.0.7
ibm rational_team_concert 3.0.1.5
ibm rational_team_concert 3.0.1.3
ibm rational_team_concert 4.0.1
ibm rational_team_concert 3.0.1.2
ibm rational_team_concert 4.0
ibm rational_team_concert 4.0.5
ibm rational_team_concert 4.0.2
ibm rational_team_concert 4.0.4
ibm rational_team_concert 4.0.3
ibm rational_team_concert 3.0
ibm rational_team_concert 4.0.0.2
ibm rational_team_concert 3.0.1
ibm rational_team_concert 3.0.1.4
ibm rational_team_concert 2.0.0.2
ibm rational_team_concert 4.0.6
ibm rational_team_concert 3.0.1.6
ibm rational_team_concert 5.0.1
CVE-2015-0124 LOW

Cross-site scripting (XSS) vulnerability in IBM Rational Quality Manager 2.x and 3.x before 3.0.1.6 iFix4, 4.x before 4.0.7 iFix3, and 5.x before 5.0.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2015-0128.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager 2.0.0.1
ibm rational_quality_manager 3.0.1.1
ibm rational_quality_manager 4.0.6
ibm rational_quality_manager 2.0.1.1
ibm rational_quality_manager 2.0.0.2
ibm rational_quality_manager 4.0.0.1
ibm rational_quality_manager 4.0.0.2
ibm rational_quality_manager 3.0.1.3
ibm rational_quality_manager 4.0.7
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 4.0
ibm rational_quality_manager 3.0
ibm rational_quality_manager 2.0.1
ibm rational_quality_manager 2.0
ibm rational_quality_manager 4.0.1
ibm rational_quality_manager 4.0.3
ibm rational_quality_manager 3.0.1.5
ibm rational_quality_manager 3.0.1.2
ibm rational_quality_manager 5.0.0
ibm rational_quality_manager 3.0.1
ibm rational_quality_manager 3.0.1.4
ibm rational_quality_manager 4.0.4
ibm rational_quality_manager 4.0.5
ibm rational_quality_manager 4.0.2
ibm rational_quality_manager 3.0.1.6
CVE-2015-0125 LOW

Cross-site scripting (XSS) vulnerability in IBM Rational DOORS Next Generation 4.x before 4.0.7 iFix3 and 5.x before 5.0.2 and Rational Requirements Composer 4.x before 4.0.7 iFix3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_doors_next_generation 4.0.1
ibm rational_doors_next_generation 4.0.0
ibm rational_requirements_composer 4.0.4
ibm rational_requirements_composer 4.0.2
ibm rational_doors_next_generation 5.0
ibm rational_doors_next_generation 4.0.5
ibm rational_requirements_composer 4.0.1
ibm rational_requirements_composer 4.0.3
ibm rational_doors_next_generation 4.0.4
ibm rational_requirements_composer 4.0.7
ibm rational_requirements_composer 4.0.0.1
ibm rational_doors_next_generation 4.0.7
ibm rational_doors_next_generation 4.0.6
ibm rational_doors_next_generation 4.0.2
ibm rational_doors_next_generation 4.0.3
ibm rational_requirements_composer 4.0.0
ibm rational_requirements_composer 4.0.0.2
ibm rational_requirements_composer 4.0.5
ibm rational_requirements_composer 4.0.6
ibm rational_doors_next_generation 5.0.1
CVE-2015-0126 MEDIUM

IBM Leads 7.x, 8.1.0 before 8.1.0.14, 8.2, 8.5.0 before 8.5.0.7.3, 8.6.0 before 8.6.0.8.1, 9.0.0 through 9.0.0.4, 9.1.0 before 9.1.0.6.1, and 9.1.1 before 9.1.1.0.2 allows remote authenticated users to bypass intended file-upload restrictions via a modified extension.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm leads 9.1.1
ibm leads 9.0.0
ibm leads 7.1.1
ibm leads 8.2.0
ibm leads 9.1.0
ibm leads 7.1.0
ibm leads 8.5.0
ibm leads 8.1.0
ibm leads 7.5.0
ibm leads 8.6.0
CVE-2015-0127 LOW

IBM Leads 7.x, 8.1.0 before 8.1.0.14, 8.2, 8.5.0 before 8.5.0.7.3, 8.6.0 before 8.6.0.8.1, 9.0.0 through 9.0.0.4, 9.1.0 before 9.1.0.6.1, and 9.1.1 before 9.1.1.0.2 does not properly restrict use of FRAME elements, which allows remote authenticated users to conduct phishing attacks via a crafted web site.

CVSS 2.0

Severity: LOW

Problem Type: CWE-254,

Products Affected

Vendor Product Version
ibm leads 9.1.1
ibm leads 9.0.0
ibm leads 7.1.1
ibm leads 8.2.0
ibm leads 9.1.0
ibm leads 7.1.0
ibm leads 8.5.0
ibm leads 8.1.0
ibm leads 7.5.0
ibm leads 8.6.0
CVE-2015-0128 LOW

Cross-site scripting (XSS) vulnerability in IBM Rational Quality Manager 2.x and 3.x before 3.0.1.6 iFix4, 4.x before 4.0.7 iFix3, and 5.x before 5.0.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2015-0124.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager 2.0.0.1
ibm rational_quality_manager 3.0.1.1
ibm rational_quality_manager 4.0.6
ibm rational_quality_manager 2.0.1.1
ibm rational_quality_manager 2.0.0.2
ibm rational_quality_manager 4.0.0.1
ibm rational_quality_manager 4.0.0.2
ibm rational_quality_manager 3.0.1.3
ibm rational_quality_manager 4.0.7
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 4.0
ibm rational_quality_manager 3.0
ibm rational_quality_manager 2.0.1
ibm rational_quality_manager 2.0
ibm rational_quality_manager 4.0.1
ibm rational_quality_manager 4.0.3
ibm rational_quality_manager 3.0.1.5
ibm rational_quality_manager 3.0.1.2
ibm rational_quality_manager 5.0.0
ibm rational_quality_manager 3.0.1
ibm rational_quality_manager 3.0.1.4
ibm rational_quality_manager 4.0.4
ibm rational_quality_manager 4.0.5
ibm rational_quality_manager 4.0.2
ibm rational_quality_manager 3.0.1.6
CVE-2015-0129 LOW

Cross-site scripting (XSS) vulnerability in IBM Rational Quality Manager (RQM) 4.x before 4.0.7 iFix3 and 5.x before 5.0.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager 4.0.3
ibm rational_quality_manager 4.0.0.1
ibm rational_quality_manager 4.0.0.2
ibm rational_quality_manager 4.0.5
ibm rational_quality_manager 5.0.0
ibm rational_quality_manager 4.0.7
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 4.0.2
ibm rational_quality_manager 4.0
ibm rational_quality_manager 4.0.4
ibm rational_quality_manager 4.0.1
CVE-2015-0130 LOW

Cross-site scripting (XSS) vulnerability in Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 4.x before 4.0.7 IF6 and 5.x before 5.0.2 IF5; Rational Quality Manager (RQM) 4.x before 4.0.7 IF6 and 5.x before 5.0.2 IF5; Rational Team Concert (RTC) 4.x before 4.0.7 IF6 and 5.x before 5.0.2 IF5; Rational Requirements Composer (RRC) 4.x through 4.0.7; and Rational DOORS Next Generation (RDNG) 4.x before 4.0.7 IF6 and 5.x before 5.0.2 IF5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_team_concert 4.0.0.1
ibm rational_doors_next_generation 4.0.0
ibm rational_collaborative_lifecycle_management 4.0.6
ibm rational_quality_manager 4.0.0.1
ibm rational_quality_manager 4.0.0.2
ibm rational_quality_manager 4.0.7
ibm rational_requirements_composer 4.0.6
ibm rational_quality_manager 4.0.3
ibm rational_doors_next_generation 4.0.1
ibm rational_team_concert 4.0.7
ibm rational_team_concert 4.0.1
ibm rational_team_concert 4.0.5
ibm rational_team_concert 4.0.2
ibm rational_collaborative_lifecycle_management 4.0.5
ibm rational_collaborative_lifecycle_management 4.0.7
ibm rational_collaborative_lifecycle_management 5.0.0
ibm rational_collaborative_lifecycle_management 4.0.3
ibm rational_doors_next_generation 4.0.7
ibm rational_team_concert 4.0.0.2
ibm rational_doors_next_generation 4.0.2
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_collaborative_lifecycle_management 4.0.0
ibm rational_team_concert 4.0
ibm rational_requirements_composer 4.0.4
ibm rational_doors_next_generation 4.0.5
ibm rational_requirements_composer 4.0.1
ibm rational_requirements_composer 4.0.7
ibm rational_collaborative_lifecycle_management 4.0.1
ibm rational_requirements_composer 4.0.0.1
ibm rational_team_concert 4.0.3
ibm rational_doors_next_generation 4.0.6
ibm rational_doors_next_generation 4.0.3
ibm rational_quality_manager 5.0.1
ibm rational_collaborative_lifecycle_management 4.0.2
ibm rational_quality_manager 4.0
ibm rational_requirements_composer 4.0.0
ibm rational_quality_manager 4.0.1
ibm rational_team_concert 4.0.6
ibm rational_team_concert 5.0.0
ibm rational_quality_manager 5.0.0
ibm rational_requirements_composer 4.0.2
ibm rational_requirements_composer 4.0.3
ibm rational_doors_next_generation 4.0.4
ibm rational_quality_manager 4.0.4
ibm rational_team_concert 4.0.4
ibm rational_doors_next_generation 5.0.0
ibm rational_quality_manager 4.0.5
ibm rational_quality_manager 4.0.2
ibm rational_requirements_composer 4.0.0.2
ibm rational_requirements_composer 4.0.5
ibm rational_doors_next_generation 5.0.1
ibm rational_collaborative_lifecycle_management 4.0.4
ibm rational_team_concert 5.0.1
CVE-2015-0131 LOW

Cross-site scripting (XSS) vulnerability in IBM Leads 7.x, 8.1.0 before 8.1.0.14, 8.2, 8.5.0 before 8.5.0.7.3, 8.6.0 before 8.6.0.8.1, 9.0.0 through 9.0.0.4, 9.1.0 before 9.1.0.6.1, and 9.1.1 before 9.1.1.0.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm leads 9.1.1
ibm leads 9.0.0
ibm leads 7.1.1
ibm leads 8.2.0
ibm leads 9.1.0
ibm leads 7.1.0
ibm leads 8.5.0
ibm leads 8.1.0
ibm leads 7.5.0
ibm leads 8.6.0
CVE-2015-0132 HIGH

The XML parser in IBM Rational DOORS Next Generation 4.x before 4.0.7 iFix3 and 5.x before 5.0.2 and Rational Requirements Composer 2.x and 3.x before 3.0.1.6 iFix5 and 4.x before 4.0.7 iFix3 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm rational_doors_next_generation 4.0.0
ibm rational_requirements_composer 3.0
ibm rational_requirements_composer 4.0.4
ibm rational_doors_next_generation 4.0.5
ibm rational_requirements_composer 4.0.1
ibm rational_requirements_composer 3.0.1.2
ibm rational_requirements_composer 4.0.7
ibm rational_requirements_composer 3.0.1.4
ibm rational_requirements_composer 4.0.0.1
ibm rational_requirements_composer 3.0.1.1
ibm rational_doors_next_generation 4.0.6
ibm rational_requirements_composer 2.0
ibm rational_doors_next_generation 4.0.3
ibm rational_requirements_composer 2.0.0.4
ibm rational_requirements_composer 3.0.1.6
ibm rational_requirements_composer 4.0.0
ibm rational_requirements_composer 2.0.0.2
ibm rational_requirements_composer 4.0.6
ibm rational_doors_next_generation 4.0.1
ibm rational_requirements_composer 3.0.1.5
ibm rational_requirements_composer 4.0.2
ibm rational_doors_next_generation 5.0
ibm rational_requirements_composer 4.0.3
ibm rational_doors_next_generation 4.0.4
ibm rational_requirements_composer 2.0.0.3
ibm rational_requirements_composer 2.0.0.1
ibm rational_doors_next_generation 4.0.7
ibm rational_doors_next_generation 4.0.2
ibm rational_requirements_composer 3.0.1
ibm rational_requirements_composer 3.0.1.3
ibm rational_requirements_composer 4.0.0.2
ibm rational_requirements_composer 4.0.5
ibm rational_doors_next_generation 5.0.1
ibm rational_requirements_composer 4.0
CVE-2015-0133 MEDIUM

IBM WebSphere Commerce 7.0 Feature Pack 4 through 8 allows remote attackers to read arbitrary files and possibly obtain administrative privileges via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_commerce 7.0
CVE-2015-0134 HIGH

Buffer overflow in the SSLv2 implementation in IBM Domino 8.5.x before 8.5.1 FP5 IF3, 8.5.2 before FP4 IF3, 8.5.3 before FP6 IF6, 9.0 before IF7, and 9.0.1 before FP2 IF3 allows remote attackers to execute arbitrary code via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm domino 8.5.0
ibm domino 8.5.1
ibm domino 8.5.2
ibm domino 9.0.1
ibm domino 8.5.3
CVE-2015-0135 HIGH

IBM Domino 8.5 before 8.5.3 FP6 IF4 and 9.0 before 9.0.1 FP3 IF2 allows remote attackers to execute arbitrary code or cause a denial of service (integer truncation and application crash) via a crafted GIF image, aka SPR KLYH9T7NT9.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-189,

Products Affected

Vendor Product Version
ibm domino 8.5.0
ibm domino 8.5.1
ibm domino 8.5.2
ibm domino 9.0.1
CVE-2015-0136 LOW

powervc-iso-import in IBM PowerVC 1.2.0.x before 1.2.0.4 and 1.2.1.x before 1.2.2 places an access token on the command line during IVM and PowerKVM management, which allows local users to obtain sensitive information by listing the process.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm powervc 1.2.0.2
ibm powervc 1.2.0.3
ibm powervc 1.2.0.1
ibm powervc 1.2.0.0
ibm powervc 1.2.1.1
ibm powervc 1.2.1.0
CVE-2015-0137 MEDIUM

IBM PowerVC Standard 1.2.0.x before 1.2.0.4 and 1.2.1.x before 1.2.2 validates Hardware Management Console (HMC) certificates only during the pre-login stage, which allows man-in-the-middle attackers to spoof devices via a crafted certificate.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm powervc 1.2.0.2
ibm powervc 1.2.0.3
ibm powervc 1.2.0.1
ibm powervc 1.2.0.0
ibm powervc 1.2.1.1
ibm powervc 1.2.1.0
CVE-2015-0138 MEDIUM

GSKit in IBM Tivoli Directory Server (ITDS) 6.0 before 6.0.0.73-ISS-ITDS-IF0073, 6.1 before 6.1.0.66-ISS-ITDS-IF0066, 6.2 before 6.2.0.42-ISS-ITDS-IF0042, and 6.3 before 6.3.0.35-ISS-ITDS-IF0035 and IBM Security Directory Server (ISDS) 6.3.1 before 6.3.1.9-ISS-ISDS-IF0009 does not properly restrict TLS state transitions, which makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_RSA ciphers via crafted TLS traffic, related to the "FREAK" issue, a different vulnerability than CVE-2015-0204.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm tivoli_directory_server 6.3.1.5
ibm tivoli_directory_server *
ibm tivoli_directory_server 6.2.0.29
ibm tivoli_directory_server 6.2.0.6
ibm tivoli_directory_server 6.3.0.10
ibm tivoli_directory_server 6.3.0.1
ibm tivoli_directory_server 6.1.0.24
ibm tivoli_directory_server 6.1.0.36
ibm tivoli_directory_server 6.1.0
ibm tivoli_directory_server 6.1.0.14
ibm tivoli_directory_server 6.2.0.12
ibm tivoli_directory_server 6.1.0.2
ibm tivoli_directory_server 6.1.0.40
ibm tivoli_directory_server 6.3.1.8
ibm tivoli_directory_server 6.3.0.31
ibm tivoli_directory_server 6.2.0.26
ibm tivoli_directory_server 6.2.0.10
ibm tivoli_directory_server 6.2.0.32
ibm tivoli_directory_server 6.2.0.30
ibm tivoli_directory_server 6.2.0.35
ibm tivoli_directory_server 6.3.0.24
ibm tivoli_directory_server 6.3.0.25
ibm tivoli_directory_server 6.1.0.23
ibm tivoli_directory_server 6.1.0.3
ibm tivoli_directory_server 6.1.0.47
ibm tivoli_directory_server 6.2.0.0
ibm tivoli_directory_server 6.1.0.8
ibm tivoli_directory_server 6.1.0.52
ibm tivoli_directory_server 6.1.0.28
ibm tivoli_directory_server 6.1.0.54
ibm tivoli_directory_server 6.2.0.33
ibm tivoli_directory_server 6.2.0.20
ibm tivoli_directory_server 6.2.0.23
ibm tivoli_directory_server 6.1.0.34
ibm tivoli_directory_server 6.1.0.53
ibm tivoli_directory_server 6.3.0.11
ibm tivoli_directory_server 6.3.0.15
ibm tivoli_directory_server 6.1.0.51
ibm tivoli_directory_server 6.1.0.57
ibm tivoli_directory_server 6.3.0.0
ibm tivoli_directory_server 6.1.0.22
ibm tivoli_directory_server 6.1.0.61
ibm tivoli_directory_server 6.1.0.7
ibm tivoli_directory_server 6.2.0.36
ibm tivoli_directory_server 6.3.0.8
ibm tivoli_directory_server 6.3.0.34
ibm tivoli_directory_server 6.1.0.45
ibm tivoli_directory_server 6.2.0.38
ibm tivoli_directory_server 6.3.0.17
ibm tivoli_directory_server 6.3.0.9
ibm tivoli_directory_server 6.1.0.12
ibm tivoli_directory_server 6.1.0.18
ibm tivoli_directory_server 6.1.0.33
ibm tivoli_directory_server 6.3.0.2
ibm tivoli_directory_server 6.1.0.27
ibm tivoli_directory_server 6.1.0.58
ibm tivoli_directory_server 6.3.1.7
ibm tivoli_directory_server 6.1.0.10
ibm tivoli_directory_server 6.1.0.31
ibm tivoli_directory_server 6.1.0.38
ibm tivoli_directory_server 6.2.0.21
ibm tivoli_directory_server 6.1.0.50
ibm tivoli_directory_server 6.3.0.22
ibm tivoli_directory_server 6.1.0.42
ibm tivoli_directory_server 6.2.0.42
ibm tivoli_directory_server 6.3.0.19
ibm tivoli_directory_server 6.2.0.8
ibm tivoli_directory_server 6.1.0.44
ibm tivoli_directory_server 6.1.0.63
ibm tivoli_directory_server 6.2.0.15
ibm tivoli_directory_server 6.3.1.0
ibm tivoli_directory_server 6.3.0.27
ibm tivoli_directory_server 6.2.0.27
ibm tivoli_directory_server 6.1.0.41
ibm tivoli_directory_server 6.1.0.9
ibm tivoli_directory_server 6.2.0.13
ibm tivoli_directory_server 6.1.0.59
ibm tivoli_directory_server 6.1.0.29
ibm tivoli_directory_server 6.1.0.35
ibm tivoli_directory_server 6.2.0.1
ibm tivoli_directory_server 6.2.0.19
ibm tivoli_directory_server 6.3.0.26
ibm tivoli_directory_server 6.1.0.66
ibm tivoli_directory_server 6.2.0.7
ibm tivoli_directory_server 6.3.0.12
ibm tivoli_directory_server 6.3.0.30
ibm tivoli_directory_server 6.1.0.30
ibm tivoli_directory_server 6.3.1.9
ibm tivoli_directory_server 6.2.0.2
ibm tivoli_directory_server 6.2.0.31
ibm tivoli_directory_server 6.1.0.49
ibm tivoli_directory_server 6.3.0.33
ibm tivoli_directory_server 6.2.0.5
ibm tivoli_directory_server 6.2.0.24
ibm tivoli_directory_server 6.1.0.55
ibm tivoli_directory_server 6.2.0.25
ibm tivoli_directory_server 6.3.0.21
ibm tivoli_directory_server 6.2.0.11
ibm tivoli_directory_server 6.2.0.34
ibm tivoli_directory_server 6.3.1.6
ibm tivoli_directory_server 6.1.0.19
ibm tivoli_directory_server 6.3.0.32
ibm tivoli_directory_server 6.3.0.35
ibm tivoli_directory_server 6.3.0.18
ibm tivoli_directory_server 6.2.0.22
ibm tivoli_directory_server 6.1.0.62
ibm tivoli_directory_server 6.2.0.41
ibm tivoli_directory_server 6.1.0.6
ibm tivoli_directory_server 6.1.0.4
ibm tivoli_directory_server 6.1.0.20
ibm tivoli_directory_server 6.3.0.23
ibm tivoli_directory_server 6.1.0.13
ibm tivoli_directory_server 6.2.0.40
ibm tivoli_directory_server 6.1.0.37
ibm tivoli_directory_server 6.1.0.15
ibm tivoli_directory_server 6.2.0.4
ibm tivoli_directory_server 6.1.0.0
ibm tivoli_directory_server 6.3.0.14
ibm tivoli_directory_server 6.2.0.37
ibm tivoli_directory_server 6.1.0.39
ibm tivoli_directory_server 6.2.0.14
ibm tivoli_directory_server 6.1.0.60
ibm tivoli_directory_server 6.1.0.5
ibm tivoli_directory_server 6.1.0.64
ibm tivoli_directory_server 6.1.0.43
ibm tivoli_directory_server 6.1.0.65
ibm tivoli_directory_server 6.3.0.28
ibm tivoli_directory_server 6.1.0.11
ibm tivoli_directory_server 6.1.0.48
ibm tivoli_directory_server 6.3.0.29
ibm tivoli_directory_server 6.1.0.25
ibm tivoli_directory_server 6.1.0.56
ibm tivoli_directory_server 6.2.0.39
ibm tivoli_directory_server 6.1.0.21
ibm tivoli_directory_server 6.1.0.26
ibm tivoli_directory_server 6.2.0.3
ibm tivoli_directory_server 6.1.0.32
ibm tivoli_directory_server 6.1.0.46
ibm tivoli_directory_server 6.1.0.1
ibm tivoli_directory_server 6.1.0.17
CVE-2015-0139 LOW

Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.0 through 8.0.0.1 CF15 and 8.5.0 before CF05 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.1
ibm websphere_portal 8.0.0.0
ibm websphere_portal 8.5.0.0
CVE-2015-0140 MEDIUM

An unspecified ActiveX control in IBM SPSS Statistics 22.0 through FP1 on 32-bit platforms allows remote attackers to execute arbitrary code via a crafted HTML document.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm spss_statistics 22.0
CVE-2015-0141 MEDIUM

IBM OpenPages GRC Platform 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1 before FP1 allows remote authenticated users to modify arbitrary user filters via a JSON request.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm openpages_grc_platform 7.1.0.0
ibm openpages_grc_platform 6.2.0.0
ibm openpages_grc_platform 6.2.1.1
ibm openpages_grc_platform 7.0.0.0
ibm openpages_grc_platform 6.2.1.0
CVE-2015-0142 MEDIUM

IBM OpenPages GRC Platform 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1 before FP1 allows remote authenticated users to cause a denial of service (maintenance-mode transition and data-storage outage) by calling the System Administration Mode function.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm openpages_grc_platform 7.1.0.0
ibm openpages_grc_platform 6.2.0.0
ibm openpages_grc_platform 6.2.1.1
ibm openpages_grc_platform 7.0.0.0
ibm openpages_grc_platform 6.2.1.0
CVE-2015-0143 MEDIUM

IBM OpenPages GRC Platform 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1 before FP1 allows remote authenticated users to obtain sensitive information by reading error messages.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm openpages_grc_platform 7.1.0.0
ibm openpages_grc_platform 6.2.0.0
ibm openpages_grc_platform 6.2.1.1
ibm openpages_grc_platform 7.0.0.0
ibm openpages_grc_platform 6.2.1.0
CVE-2015-0144 LOW

Cross-site scripting (XSS) vulnerability in IBM OpenPages GRC Platform 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1 before FP1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2014-8916.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm openpages_grc_platform 7.1.0.0
ibm openpages_grc_platform 6.2.0.0
ibm openpages_grc_platform 6.2.1.1
ibm openpages_grc_platform 7.0.0.0
ibm openpages_grc_platform 6.2.1.0
CVE-2015-0145 MEDIUM

Cross-site request forgery (CSRF) vulnerability in IBM OpenPages GRC Platform 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1 before FP1 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm openpages_grc_platform 7.1.0.0
ibm openpages_grc_platform 6.2.0.0
ibm openpages_grc_platform 6.2.1.1
ibm openpages_grc_platform 7.0.0.0
ibm openpages_grc_platform 6.2.1.0
CVE-2015-0146 LOW

IBM Content Collector for Email 3.0 before 3.0.0.6-IBM-ICC-Server-IF001 and 4.0 before 4.0.0.3-IBM-ICC-Server-IF001 does not properly handle an unspecified query operator during searches of IBM FileNet P8 systems with IBM Content Search Services, which allows local users to bypass intended document-access restrictions and obtain sensitive information via a crafted search query.

CVSS 2.0

Severity: LOW

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm content_collector 3.0.0.1
ibm content_collector 3.0.0.2
ibm content_collector 4.0.0.1
ibm content_collector 4.0.0.0
ibm content_collector 3.0.0.0
ibm content_collector 3.0.0.3
ibm content_collector 3.0.0.4
ibm content_collector 4.0.0.2
ibm content_collector 3.0.0.5
CVE-2015-0149 MEDIUM

The developer portal in IBM API Management 3.0 before 3.0.4.1 does not properly restrict access to the public and private APIs, which allows remote authenticated users to obtain sensitive information or modify data via unspecified API calls.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm api_management 3.0.2.0
ibm api_management 3.0.0.0
ibm api_management 3.0.4.0
ibm api_management 3.0.3.0
ibm api_management 3.0.2.1
CVE-2015-0156 LOW

Cross-site scripting (XSS) vulnerability in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, and 8.5.x through 8.5.6.0 and WebSphere Lombardi Edition (WLE) 7.2.x through 7.2.0.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm business_process_manager 8.0.1.2
ibm websphere 7.2.0.2
ibm business_process_manager 8.5.6.0
ibm business_process_manager 8.0.1.1
ibm websphere 7.2.0.4
ibm business_process_manager 7.5.0.1
ibm business_process_manager 7.5.1.0
ibm business_process_manager 7.5.1.1
ibm websphere 7.2.0.1
ibm websphere 7.2.0.3
ibm business_process_manager 8.5.5.0
ibm business_process_manager 8.0.1.0
ibm business_process_manager 7.5.1.2
ibm websphere 7.2.0.5
ibm business_process_manager 8.0.0.0
ibm business_process_manager 8.5.0.1
ibm websphere 7.2
ibm business_process_manager 8.0.1.3
ibm business_process_manager 8.5.0.0
ibm business_process_manager 7.5.0.0
CVE-2015-0157 MEDIUM

IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and Windows allows remote authenticated users to cause a denial of service (daemon crash) by leveraging an unspecified scalar function in a SQL statement.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2 10.1
ibm db2 9.8
ibm db2 9.7
CVE-2015-0158 MEDIUM

Cross-site scripting (XSS) vulnerability in the Coach NG framework in IBM Business Process Manager (BPM) 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.1, and 8.5.5 through 8.5.5.0 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm business_process_manager 8.0.1.2
ibm business_process_manager 8.0.1.1
ibm business_process_manager 8.5.5.0
ibm business_process_manager 8.0.1.0
ibm business_process_manager 8.0.0.0
ibm business_process_manager 8.5.0.1
ibm business_process_manager 8.0.1.3
ibm business_process_manager 8.5.0.0
CVE-2015-0160 HIGH

IBM Security SiteProtector System 3.0 before 3.0.0.7, 3.1 before 3.1.0.4, and 3.1.1 before 3.1.1.2 allows remote authenticated users to execute arbitrary commands with SYSTEM privileges via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm security_siteprotector_system 3.1.0.2
ibm security_siteprotector_system 3.0.0.1
ibm security_siteprotector_system 3.0.0.3
ibm security_siteprotector_system 3.0.0.4
ibm security_siteprotector_system 3.0.0.2
ibm security_siteprotector_system 3.1.0.0
ibm security_siteprotector_system 3.1.0.1
ibm security_siteprotector_system 3.0.0.5
ibm security_siteprotector_system 3.0
ibm security_siteprotector_system 3.0.0.6
ibm security_siteprotector_system 3.1.0.3
ibm security_siteprotector_system 3.1.1.0
ibm security_siteprotector_system 3.1.1.1
CVE-2015-0161 MEDIUM

SQL injection vulnerability in IBM Security SiteProtector System 3.0 before 3.0.0.7, 3.1 before 3.1.0.4, and 3.1.1 before 3.1.1.2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm security_siteprotector_system 3.1.0.2
ibm security_siteprotector_system 3.0.0.1
ibm security_siteprotector_system 3.0.0.3
ibm security_siteprotector_system 3.0.0.4
ibm security_siteprotector_system 3.0.0.2
ibm security_siteprotector_system 3.1.0.0
ibm security_siteprotector_system 3.1.0.1
ibm security_siteprotector_system 3.0.0.5
ibm security_siteprotector_system 3.0
ibm security_siteprotector_system 3.0.0.6
ibm security_siteprotector_system 3.1.0.3
ibm security_siteprotector_system 3.1.1.0
ibm security_siteprotector_system 3.1.1.1
CVE-2015-0162 MEDIUM

IBM Security SiteProtector System 3.0, 3.1, and 3.1.1 allows local users to gain privileges.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm security_siteprotector_system 3.0
ibm security_siteprotector_system 3.1.0.0
ibm security_siteprotector_system 3.1.1.0
CVE-2015-0168 LOW

Cross-site scripting (XSS) vulnerability in IBM Security SiteProtector System 3.0 before 3.0.0.7, 3.1 before 3.1.0.4, and 3.1.1 before 3.1.1.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm security_siteprotector_system 3.1.0.2
ibm security_siteprotector_system 3.0.0.1
ibm security_siteprotector_system 3.0.0.3
ibm security_siteprotector_system 3.0.0.4
ibm security_siteprotector_system 3.0.0.2
ibm security_siteprotector_system 3.1.0.0
ibm security_siteprotector_system 3.1.0.1
ibm security_siteprotector_system 3.0.0.5
ibm security_siteprotector_system 3.0
ibm security_siteprotector_system 3.0.0.6
ibm security_siteprotector_system 3.1.0.3
ibm security_siteprotector_system 3.1.1.0
ibm security_siteprotector_system 3.1.1.1
CVE-2015-0169 MEDIUM

IBM Security SiteProtector System 3.0 before 3.0.0.7, 3.1 before 3.1.0.4, and 3.1.1 before 3.1.1.2 allows remote authenticated users to inject arguments via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-74,

Products Affected

Vendor Product Version
ibm security_siteprotector_system 3.1.0.2
ibm security_siteprotector_system 3.0.0.1
ibm security_siteprotector_system 3.0.0.3
ibm security_siteprotector_system 3.0.0.4
ibm security_siteprotector_system 3.0.0.2
ibm security_siteprotector_system 3.1.0.0
ibm security_siteprotector_system 3.1.0.1
ibm security_siteprotector_system 3.0.0.5
ibm security_siteprotector_system 3.0
ibm security_siteprotector_system 3.0.0.6
ibm security_siteprotector_system 3.1.0.3
ibm security_siteprotector_system 3.1.1.0
ibm security_siteprotector_system 3.1.1.1
CVE-2015-0170 LOW

IBM Security SiteProtector System 3.0 before 3.0.0.7, 3.1 before 3.1.0.4, and 3.1.1 before 3.1.1.2 allows local users to obtain sensitive information by reading cached data.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_siteprotector_system 3.1.0.2
ibm security_siteprotector_system 3.0.0.1
ibm security_siteprotector_system 3.0.0.3
ibm security_siteprotector_system 3.0.0.4
ibm security_siteprotector_system 3.0.0.2
ibm security_siteprotector_system 3.1.0.0
ibm security_siteprotector_system 3.1.0.1
ibm security_siteprotector_system 3.0.0.5
ibm security_siteprotector_system 3.0
ibm security_siteprotector_system 3.0.0.6
ibm security_siteprotector_system 3.1.0.3
ibm security_siteprotector_system 3.1.1.0
ibm security_siteprotector_system 3.1.1.1
CVE-2015-0171 MEDIUM

Directory traversal vulnerability in IBM Security SiteProtector System 3.0 before 3.0.0.7, 3.1 before 3.1.0.4, and 3.1.1 before 3.1.1.2 allows remote authenticated users to write to arbitrary files via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm security_siteprotector_system 3.1.0.2
ibm security_siteprotector_system 3.0.0.1
ibm security_siteprotector_system 3.0.0.3
ibm security_siteprotector_system 3.0.0.4
ibm security_siteprotector_system 3.0.0.2
ibm security_siteprotector_system 3.1.0.0
ibm security_siteprotector_system 3.1.0.1
ibm security_siteprotector_system 3.0.0.5
ibm security_siteprotector_system 3.0
ibm security_siteprotector_system 3.0.0.6
ibm security_siteprotector_system 3.1.0.3
ibm security_siteprotector_system 3.1.1.0
ibm security_siteprotector_system 3.1.1.1
CVE-2015-0172 MEDIUM

IBM Security SiteProtector System 3.0, 3.1.0 and 3.1.1 allows remote attackers to bypass intended security restrictions and consequently execute unspecified commands and obtain sensitive information via unknown vectors. IBM X-Force ID: 100927.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_siteprotector_system 3.0
ibm security_siteprotector_system 3.1.0.0
ibm security_siteprotector_system 3.1.1.0
CVE-2015-0173 MEDIUM

The HTTP connection-management functionality in Internet Pass-Thru (IPT) before 2.1.0.2 in IBM WebSphere MQ, when HTTPS is disabled, does not properly generate MQIPT Session IDs, which makes it easier for remote attackers to bypass intended restrictions on MQ message data by predicting an ID value.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-17,

Products Affected

Vendor Product Version
ibm websphere_mq_internet_pass_thru *
CVE-2015-0174 MEDIUM

The SNMP implementation in IBM WebSphere Application Server (WAS) 8.5 before 8.5.5.5 does not properly handle configuration data, which allows remote authenticated users to obtain sensitive information via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_application_server 8.5.5.0
ibm websphere_application_server 8.5.0.2
ibm websphere_application_server 8.5.5.2
ibm websphere_application_server 8.5.5.3
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 8.5.5.4
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 8.5.5.1
CVE-2015-0175 MEDIUM

IBM WebSphere Application Server (WAS) 8.5 Liberty Profile before 8.5.5.5 does not properly implement authData elements, which allows remote authenticated users to gain privileges via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_application_server 8.5.5.0
ibm websphere_application_server 8.5.0.2
ibm websphere_application_server 8.5.5.2
ibm websphere_application_server 8.5.5.3
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 8.5.5.4
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 8.5.5.1
CVE-2015-0176 MEDIUM

Cross-site scripting (XSS) vulnerability in MQ XR WebSockets Listener in WMQ Telemetry in IBM WebSphere MQ 8.0 before 8.0.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URI that is included in an error response.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_mq *
ibm websphere_mq 8.0.0.1
ibm websphere_mq 8.0
CVE-2015-0177 LOW

Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.5.0 before CF05 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 8.5.0.0
CVE-2015-0178 MEDIUM

The Java overlay feature in IBM Bluemix Liberty before 1.13-20150209-1122 for Java does not properly support WAR applications, which allows remote attackers to obtain sensitive information via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm liberty *
CVE-2015-0179 HIGH

Notes System Diagnostic (NSD) in IBM Domino 8.5.x before 8.5.3 FP6 IF6 and 9.x before 9.0.1 FP3 IF1 allows local users to obtain the System privilege via unspecified vectors, aka SPR TCHL9SST8V.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm domino 8.5.0
ibm domino 8.5.1
ibm domino 8.5.2
ibm domino 9.0.1
ibm domino 8.5.3
CVE-2015-0180 MEDIUM

The Connector Migration Tool in IBM InfoSphere Information Server 8.1 through 11.3 allows remote authenticated users to bypass intended restrictions on job creation and modification via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm infosphere_information_server 11.3
ibm infosphere_information_server 9.1.2
ibm infosphere_information_server 8.1
ibm infosphere_information_server 8.5
ibm infosphere_information_server 9.1
ibm infosphere_information_server 8.7
CVE-2015-0189 MEDIUM

The cluster repository manager in IBM WebSphere MQ 7.5 before 7.5.0.5 and 8.0 before 8.0.0.2 allows remote authenticated administrators to cause a denial of service (memory overwrite and daemon outage) by triggering multiple transmit-queue records.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm websphere_mq 7.5.0.2
ibm websphere_mq 7.5.0.4
ibm websphere_mq 8.0.0.1
ibm websphere_mq 7.5.0.1
ibm websphere_mq 7.5.0.3
ibm websphere_mq 7.5
ibm websphere_mq 8.0
CVE-2015-0192 HIGH

Unspecified vulnerability in IBM Java 8 before SR1, 7 R1 before SR2 FP11, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 FP10 allows remote attackers to gain privileges via unknown vectors related to the Java Virtual Machine.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
134c704f-9b21-4f2e-91b3-4a467353bcc0 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 3.9 5.9

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,CWE-269,

Products Affected

Vendor Product Version
suse linux_enterprise_server 11
redhat enterprise_linux_desktop 7.0
suse linux_enterprise_server 10
redhat enterprise_linux_server 7.0
redhat enterprise_linux_server_eus 7.3
redhat enterprise_linux_desktop 6.0
redhat enterprise_linux_workstation 7.0
redhat enterprise_linux_server_aus 6.6
suse linux_enterprise_software_development_kit 12
redhat enterprise_linux_desktop 5.0
ibm java *
redhat enterprise_linux_server_eus 7.4
suse linux_enterprise_server 12
redhat enterprise_linux_workstation 6.0
redhat enterprise_linux_server_eus 7.2
redhat enterprise_linux_server 6.0
redhat enterprise_linux_workstation 5.0
redhat enterprise_linux_server_eus 6.6
redhat enterprise_linux_server_eus 7.5
redhat enterprise_linux_server_eus 7.1
redhat enterprise_linux_server 5.0
CVE-2015-0193 LOW

Cross-site scripting (XSS) vulnerability in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, and 8.5.x through 8.5.5.0 and WebSphere Lombardi Edition (WLE) 7.2.x through 7.2.0.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL that triggers an error condition.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm business_process_manager 8.0.1.2
ibm websphere 7.2.0.2
ibm business_process_manager 8.0.1.1
ibm websphere 7.2.0.4
ibm business_process_manager 7.5.0.1
ibm business_process_manager 7.5.1.0
ibm business_process_manager 7.5.1.1
ibm websphere 7.2.0.1
ibm websphere 7.2.0.3
ibm business_process_manager 8.5.5.0
ibm business_process_manager 8.0.1.0
ibm business_process_manager 7.5.1.2
ibm websphere 7.2.0.5
ibm business_process_manager 8.0.0.0
ibm business_process_manager 8.5.0.1
ibm websphere 7.2
ibm business_process_manager 8.0.1.3
ibm business_process_manager 8.5.0.0
ibm business_process_manager 7.5.0.0
CVE-2015-0194 MEDIUM

XML External Entity (XXE) vulnerability in IBM Sterling B2B Integrator 5.1 and 5.2 and IBM Sterling File Gateway 2.1 and 2.2 allows remote attackers to read arbitrary files via a crafted XML data.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2
ibm sterling_b2b_integrator 5.1
ibm sterling_file_gateway 2.2
ibm sterling_file_gateway 2.1
CVE-2015-0195 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Content Template Catalog 4.x before 4.1.4 for WebSphere Portal 8.0.x and 4.x before 4.3.1 for WebSphere Portal 8.5.x allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm content_template_catalog *
CVE-2015-0196 MEDIUM

CRLF injection vulnerability in IBM WebSphere Commerce 6.0 through 6.0.0.11 and 7.0 before 7.0.0.8 Cumulative iFix 2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_commerce 6.0.0.6
ibm websphere_commerce 7.0.0.4
ibm websphere_commerce 7.0.0.6
ibm websphere_commerce 7.0.0.7
ibm websphere_commerce 6.0.0.11
ibm websphere_commerce 6.0.0.1
ibm websphere_commerce 6.0.0.2
ibm websphere_commerce 6.0.0.10
ibm websphere_commerce 7.0.0.3
ibm websphere_commerce 7.0.0.2
ibm websphere_commerce 7.0
ibm websphere_commerce 6.0.0.7
ibm websphere_commerce 6.0.0.8
ibm websphere_commerce 7.0.0.5
ibm websphere_commerce 6.0.0.3
ibm websphere_commerce 6.0.0.4
ibm websphere_commerce 6.0.0.9
ibm websphere_commerce 7.0.0.1
ibm websphere_commerce 6.0.0.5
ibm websphere_commerce 7.0.0.8
CVE-2015-0197 HIGH

IBM General Parallel File System (GPFS) 3.4 before 3.4.0.32, 3.5 before 3.5.0.24, and 4.1 before 4.1.0.7 allows local users to obtain root privileges for program execution via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm general_parallel_file_system 3.5
ibm general_parallel_file_system 4.1
ibm general_parallel_file_system 3.4
CVE-2015-0198 HIGH

IBM General Parallel File System (GPFS) 3.4 before 3.4.0.32, 3.5 before 3.5.0.24, and 4.1 before 4.1.0.7 in certain cipherList configurations allows remote attackers to bypass authentication and execute arbitrary programs as root via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm general_parallel_file_system 3.5
ibm general_parallel_file_system 4.1
ibm general_parallel_file_system 3.4
CVE-2015-0199 MEDIUM

The mmfslinux kernel module in IBM General Parallel File System (GPFS) 3.4 before 3.4.0.32, 3.5 before 3.5.0.24, and 4.1 before 4.1.0.7 allows local users to cause a denial of service (memory corruption) via unspecified character-device ioctl calls.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm general_parallel_file_system 3.5
ibm general_parallel_file_system 4.1
ibm general_parallel_file_system 3.4
CVE-2015-0200 LOW

IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x before 7.0.0.8 IF2 allows local users to obtain sensitive database information via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_commerce 6.0.0.6
ibm websphere_commerce 7.0.0.4
ibm websphere_commerce 7.0.0.6
ibm websphere_commerce 7.0.0.7
ibm websphere_commerce 6.0.0.11
ibm websphere_commerce 6.0.0.1
ibm websphere_commerce 6.0.0.2
ibm websphere_commerce 6.0.0.10
ibm websphere_commerce 7.0.0.3
ibm websphere_commerce 7.0.0.2
ibm websphere_commerce 7.0
ibm websphere_commerce 6.0.0.7
ibm websphere_commerce 6.0.0.8
ibm websphere_commerce 7.0.0.5
ibm websphere_commerce 6.0.0.3
ibm websphere_commerce 6.0.0.0
ibm websphere_commerce 6.0.0.4
ibm websphere_commerce 6.0.0.9
ibm websphere_commerce 7.0.0.1
ibm websphere_commerce 6.0.0.5
ibm websphere_commerce 7.0.0.8
CVE-2015-0235 HIGH

Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 function, aka "GHOST."

CVSS 2.0

Severity: HIGH

Problem Type: CWE-787,

Products Affected

Vendor Product Version
oracle communications_policy_management 9.7.3
php php *
debian debian_linux 8.0
oracle communications_policy_management 12.1.1
oracle communications_webrtc_session_controller 7.2
ibm pureapplication_system 1.1.0.0
oracle communications_policy_management 10.4.1
oracle communications_eagle_lnp_application_processor 10.0
oracle linux 7
redhat virtualization 6.0
debian debian_linux 7.0
oracle exalogic_infrastructure 1.0
oracle exalogic_infrastructure 2.0
ibm security_access_manager_for_enterprise_single_sign-on 8.2
oracle vm_virtualbox *
oracle communications_policy_management 9.9.1
oracle communications_application_session_controller *
apple mac_os_x *
oracle linux 5
oracle communications_session_border_controller 7.2.0
oracle communications_webrtc_session_controller 7.1
oracle communications_session_border_controller *
oracle communications_user_data_repository *
oracle communications_lsms 13.1
gnu glibc *
oracle communications_webrtc_session_controller 7.0
ibm pureapplication_system 1.0.0.0
oracle communications_policy_management 11.5
oracle communications_eagle_application_processor 16.0
ibm pureapplication_system 2.0.0.0
oracle communications_session_border_controller 8.0.0
CVE-2015-1772 MEDIUM

The LDAP implementation in HiveServer2 in Apache Hive before 1.0.1 and 1.1.x before 1.1.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.0.0.2 and other products, mishandles simple unauthenticated and anonymous bind configurations, which allows remote attackers to bypass authentication via a crafted LDAP request.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
apache hive 1.0.0
ibm infosphere_biginsights 3.0.0.1
apache hive 1.1.0
ibm infosphere_biginsights 3.0.0.0
ibm infosphere_biginsights 3.0.0.2
CVE-2015-1836 HIGH

Apache HBase 0.98 before 0.98.12.1, 1.0 before 1.0.1.1, and 1.1 before 1.1.0.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.0.0.2 and other products, uses incorrect ACLs for ZooKeeper coordination state, which allows remote attackers to cause a denial of service (daemon outage), obtain sensitive information, or modify data via unspecified client traffic.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-284,

Products Affected

Vendor Product Version
apache hbase 0.98.9
apache hbase 0.98.10
apache hbase 0.98.8
apache hbase 0.98.3
ibm infosphere_biginsights 3.0.0.1
apache hbase 0.98.11
apache hbase 0.98.0
ibm infosphere_biginsights 3.0.0.0
apache hbase 0.98.6.1
apache hbase 0.98.6
apache hbase 0.98.4
apache hbase 0.98.12
apache hbase 0.98.2
apache hbase 0.98.7
apache hbase 0.98.1
apache hbase 0.98.10.1
ibm infosphere_biginsights 3.0.0.2
apache hbase 0.98.5
CVE-2015-1882 HIGH

Multiple race conditions in IBM WebSphere Application Server (WAS) 8.5 Liberty Profile before 8.5.5.5 allow remote authenticated users to gain privileges by leveraging thread conflicts that result in Java code execution outside the context of the configured EJB Run-as user.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-362,

Products Affected

Vendor Product Version
ibm websphere_application_server 8.5.5.0
ibm websphere_application_server 8.5.0.2
ibm websphere_application_server 8.5.5.2
ibm websphere_application_server 8.5.5.3
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 8.5.5.4
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 8.5.5.1
CVE-2015-1883 MEDIUM

IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and Windows allows remote authenticated users to read certain administrative files via crafted use of an automated-maintenance policy stored procedure.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2 10.1
ibm db2 9.8
ibm db2 9.7
CVE-2015-1884 MEDIUM

Directory traversal vulnerability in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, and 8.5.5 through 8.5.5.0 and WebSphere Lombardi Edition (WLE) 7.2 through 7.2.0.5 allows remote authenticated users to read arbitrary files via a crafted internationalization-file URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm business_process_manager 8.0.1.2
ibm websphere 7.2.0.2
ibm business_process_manager 8.0.1.1
ibm websphere 7.2.0.4
ibm business_process_manager 7.5.0.1
ibm business_process_manager 7.5.1.0
ibm business_process_manager 7.5.1.1
ibm websphere 7.2.0.1
ibm websphere 7.2.0.3
ibm business_process_manager 8.5.5.0
ibm business_process_manager 8.0.1.0
ibm business_process_manager 7.5.1.2
ibm websphere 7.2.0.5
ibm business_process_manager 8.0.0.0
ibm business_process_manager 8.5.0.1
ibm websphere 7.2
ibm business_process_manager 8.0.1.3
ibm business_process_manager 8.5.0.0
ibm business_process_manager 7.5.0.0
CVE-2015-1885 HIGH

WebSphereOauth20SP.ear in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.39, 8.0 before 8.0.0.11, 8.5 Liberty Profile before 8.5.5.5, and 8.5 Full Profile before 8.5.5.6, when the OAuth grant type requires sending a password, allows remote attackers to gain privileges via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 7.0.0.36
ibm websphere_application_server 7.0
ibm websphere_application_server 7.0.0.38
ibm websphere_application_server 7.0.0.12
ibm websphere_application_server 8.5.0.2
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 8.5.5.2
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 7.0.0.16
ibm websphere_application_server 7.0.0.33
ibm websphere_application_server 7.0.0.25
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 7.0.0.14
ibm websphere_application_server 7.0.0.22
ibm websphere_application_server 7.0.0.31
ibm websphere_application_server 7.0.0.10
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0.0.32
ibm websphere_application_server 7.0.0.29
ibm websphere_application_server 7.0.0.24
ibm websphere_application_server 8.5.5.0
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.37
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 7.0.0.27
ibm websphere_application_server 7.0.0.18
ibm websphere_application_server 8.5.5.3
ibm websphere_application_server 7.0.0.34
ibm websphere_application_server 8.5.5.4
ibm websphere_application_server 7.0.0.35
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 8.5.5.1
CVE-2015-1886 HIGH

The Remote Document Conversion Service (DCS) in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF16, and 8.5.0 through CF05 allows remote attackers to cause a denial of service (memory consumption) via crafted requests.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.0
ibm websphere_portal 6.1.0.3
ibm websphere_portal 7.0.0.1
ibm websphere_portal 6.1.5.2
ibm websphere_portal 6.1.0.2
ibm websphere_portal 6.1.0.4
ibm websphere_portal 8.0.0.1
ibm websphere_portal 7.0.0.2
ibm websphere_portal 8.5.0.0
ibm websphere_portal 6.1.5.0
ibm websphere_portal 6.1.0.6
ibm websphere_portal 6.1.5.3
ibm websphere_portal 7.0.0.0
ibm websphere_portal 6.1.0.1
ibm websphere_portal 6.1.5.1
ibm websphere_portal 6.1.0.5
ibm websphere_portal 6.1.0.0
CVE-2015-1887 MEDIUM

IBM WebSphere Portal 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF17, and 8.5.0 before CF06 allows remote attackers to obtain sensitive Java Content Repository (JCR) information via a crafted request.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.1
ibm websphere_portal 8.0.0.0
ibm websphere_portal 7.0.0.2
ibm websphere_portal 8.5.0.0
ibm websphere_portal 7.0.0.1
ibm websphere_portal 7.0.0.0
CVE-2015-1888 LOW

Cross-site scripting (XSS) vulnerability in IBM Content Navigator 2.0.2 before 2.0.2-ICN-FP007 and 2.0.3 before 2.0.3-ICN-FP003, as used in Content Manager, FileNet Content Manager, Content Foundation, Content Manager OnDemand, and other products, allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm content_navigator 2.0.2
ibm content_navigator 2.0.3
CVE-2015-1889 MEDIUM

The Big SQL component in IBM InfoSphere BigInsights 3.0 through 3.0.0.2 allows remote authenticated users to bypass intended HDFS data-access restrictions via (1) a crafted CREATE HADOOP TABLE statement referencing the data of an arbitrary user or (2) an import of a certain Hive table definition with the HCAT_SYNC_OBJECTS procedure.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm infosphere_biginsights 3.0.0.1
ibm infosphere_biginsights 3.0.0.0
ibm infosphere_biginsights 3.0.0.2
CVE-2015-1890 LOW

/usr/lpp/mmfs/bin/gpfs.snap in IBM General Parallel File System (GPFS) 4.1 before 4.1.0.7 produces an archive potentially containing cleartext keys, and lacks a warning about reviewing this archive to detect included keys, which might allow remote attackers to obtain sensitive information by leveraging access to a technical-support data stream.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm general_parallel_file_system 4.1
CVE-2015-1892 MEDIUM

The Multicast DNS (mDNS) responder in IBM Security Access Manager for Web 7.x before 7.0.0 FP12 and 8.x before 8.0.1 FP1 inadvertently responds to unicast queries with source addresses that are not link-local, which allows remote attackers to cause a denial of service (traffic amplification) or obtain potentially sensitive information via port-5353 UDP packets.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_access_manager_for_web_7.0_firmware *
ibm security_access_manager_for_web_8.0_firmware 8.0.0.5
ibm security_access_manager_for_web_8.0_firmware 8.0.0.1
ibm security_access_manager_for_web_8.0_firmware 8.0.1.0
ibm security_access_manager_for_web_8.0_firmware 8.0.0.2
ibm security_access_manager_for_web_8.0_firmware 8.0.0.4
ibm security_access_manager_for_web_8.0_firmware 8.0.0.3
CVE-2015-1893 MEDIUM

The IBM WebSphere DataPower XC10 appliance 2.1 before 2.1.0.3 allows remote attackers to hijack the sessions of arbitrary users, and consequently obtain sensitive information or modify data, via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_datapower_xc10_appliance_firmware 2.1.0.1
ibm websphere_datapower_xc10_appliance_firmware 2.1.0.2
ibm websphere_datapower_xc10_appliance_firmware 2.1.0.0
CVE-2015-1894 MEDIUM

Cross-site request forgery (CSRF) vulnerability in IBM InfoSphere Optim Workload Replay 2.x before 2.1.0.3 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm optim_workload_replay 2.1
ibm optim_workload_replay 2.1.0.1
ibm optim_workload_replay 2.1.0.2
CVE-2015-1895 MEDIUM

IBM InfoSphere Optim Workload Replay 2.x before 2.1.0.3 relies on client-side code to verify authorization, which allows remote attackers to bypass intended access restrictions by modifying the client behavior.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm optim_workload_replay 2.1
ibm optim_workload_replay 2.1.0.1
ibm optim_workload_replay 2.1.0.2
CVE-2015-1896 HIGH

Stack-based buffer overflow in the FastBackMount process in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.11.1 allows remote attackers to execute arbitrary code via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_fastback 6.1.0.1
ibm tivoli_storage_manager_fastback 6.1.10.0
ibm tivoli_storage_manager_fastback 6.1.9.0
ibm tivoli_storage_manager_fastback 6.1.8.1
ibm tivoli_storage_manager_fastback 6.1.7.2
ibm tivoli_storage_manager_fastback 6.1.8.0
ibm tivoli_storage_manager_fastback 6.1.11.0
ibm tivoli_storage_manager_fastback 6.1.10.1
ibm tivoli_storage_manager_fastback 6.1.1.0
ibm tivoli_storage_manager_fastback 6.1.9.1
CVE-2015-1897 HIGH

Stack-based buffer overflow in the FastBackMount process in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.11.1 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-1898.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_fastback 6.1.10.0
ibm tivoli_storage_manager_fastback 6.1.0.0
ibm tivoli_storage_manager_fastback 6.1.9.0
ibm tivoli_storage_manager_fastback 6.1.11.0
ibm tivoli_storage_manager_fastback 6.1.10.1
ibm tivoli_storage_manager_fastback 6.1.1.0
ibm tivoli_storage_manager_fastback 6.1.9.1
CVE-2015-1898 HIGH

Stack-based buffer overflow in the FastBackMount process in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.11.1 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-1897.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_fastback 6.1.10.0
ibm tivoli_storage_manager_fastback 6.1.0.0
ibm tivoli_storage_manager_fastback 6.1.11.0
ibm tivoli_storage_manager_fastback 6.1.10.1
ibm tivoli_storage_manager_fastback 6.1.1.0
CVE-2015-1899 HIGH

IBM WebSphere Portal 8.5 through CF05 allows remote attackers to cause a denial of service (CPU consumption) via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm websphere_portal 8.5.0.0
CVE-2015-1900 HIGH

IBM InfoSphere DataStage 8.1, 8.5, 8.7, 9.1, and 11.3 through 11.3.1.2 on UNIX allows local users to write to executable files, and consequently obtain root privileges, via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm infosphere_datastage 11.3
ibm infosphere_datastage 11.3.1
ibm infosphere_datastage 8.5
ibm infosphere_datastage 9.1
ibm infosphere_datastage 8.7
ibm infosphere_datastage 11.3.1.2
ibm infosphere_datastage 8.1
CVE-2015-1901 LOW

The installer in IBM InfoSphere Information Server 8.5 through 11.3 before 11.3.1.2 allows local users to obtain sensitive information via unspecified commands.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm infosphere_information_server 8.5.0.2
ibm infosphere_information_server 9.1.0.1
ibm infosphere_information_server 8.5.0.1
ibm infosphere_information_server 9.1.2
ibm infosphere_information_server 8.5
ibm infosphere_information_server 9.1
ibm infosphere_information_server 11.3.1
ibm infosphere_information_server 8.7.0.2
ibm infosphere_information_server 11.3
ibm infosphere_information_server 8.5.0.3
ibm infosphere_information_server 8.7.0.1
ibm infosphere_information_server 8.7
CVE-2015-1902 HIGH

Stack-based buffer overflow in IBM Domino 8.5 before 8.5.3 FP6 IF7 and 9.0 before 9.0.1 FP3 IF3 allows remote attackers to execute arbitrary code via a crafted BMP image, aka SPR KLYH9TSMLA.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm domino 8.5.0
ibm domino 8.5.1
ibm domino 8.5.2
ibm domino 9.0.1
ibm domino 8.5.3
CVE-2015-1903 HIGH

Stack-based buffer overflow in IBM Domino 8.5 before 8.5.3 FP6 IF7 and 9.0 before 9.0.1 FP3 IF3 allows remote attackers to execute arbitrary code via a crafted BMP image, aka SPR KLYH9TSN3Y.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm domino 8.5.0
ibm domino 8.5.1
ibm domino 8.5.2
ibm domino 9.0.1
ibm domino 8.5.3
CVE-2015-1904 LOW

IBM Business Process Manager (BPM) 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, 8.5.5 through 8.5.5.0, and 8.5.6 through 8.5.6.0, when external Enterprise Content Management (ECM) integration is enabled with a certain technical system account configuration, allows remote authenticated users to bypass intended document-access restrictions via a (1) upload or (2) download action.

CVSS 2.0

Severity: LOW

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm business_process_manager 8.0.1.2
ibm business_process_manager 8.5.6.0
ibm business_process_manager 8.0.1.1
ibm business_process_manager 8.5.5.0
ibm business_process_manager 8.0.1.0
ibm business_process_manager 8.0.0.0
ibm business_process_manager 8.5.0.1
ibm business_process_manager 8.0.1.3
ibm business_process_manager 8.5.0.0
CVE-2015-1905 MEDIUM

The REST API in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, 8.5.5 through 8.5.5.0, and 8.5.6 through 8.5.6.0 allows remote authenticated users to bypass intended access restrictions on task-variable value changes via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm business_process_manager 8.0.1.2
ibm business_process_manager 8.5.6.0
ibm business_process_manager 8.0.1.1
ibm business_process_manager 7.5.0.1
ibm business_process_manager 7.5.1.0
ibm business_process_manager 7.5.1.1
ibm business_process_manager 8.0.1.0
ibm business_process_manager 7.5.1.2
ibm business_process_manager 8.0.0.0
ibm business_process_manager 8.5.0.1
ibm business_process_manager 8.0.1.3
ibm business_process_manager 8.5.0.0
ibm business_process_manager 7.5.0.0
CVE-2015-1906 LOW

Cross-site scripting (XSS) vulnerability in the REST API in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, 8.5.5 through 8.5.5.0, and 8.5.6 through 8.5.6.0 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm business_process_manager 8.0.1.2
ibm business_process_manager 8.5.6.0
ibm business_process_manager 8.0.1.1
ibm business_process_manager 7.5.0.1
ibm business_process_manager 7.5.1.0
ibm business_process_manager 7.5.1.1
ibm business_process_manager 8.5.5.0
ibm business_process_manager 8.0.1.0
ibm business_process_manager 7.5.1.2
ibm business_process_manager 8.0.0.0
ibm business_process_manager 8.5.0.1
ibm business_process_manager 8.0.1.3
ibm business_process_manager 8.5.0.0
ibm business_process_manager 7.5.0.0
CVE-2015-1907 MEDIUM

The Administration and Reporting Tool in IBM Rational License Key Server (RLKS) 8.1.4 before 8.1.4.7 allows remote authenticated users to read cookies via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_license_key_server 8.1.4.5
ibm rational_license_key_server 8.1.4
ibm rational_license_key_server 8.1.4.4
ibm rational_license_key_server 8.1.4.3
ibm rational_license_key_server 8.1.4.6
ibm rational_license_key_server 8.1.4.2
CVE-2015-1908 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF16, and 8.5.0 through CF05, as used in Web Content Manager and other products, allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.0
ibm websphere_portal 6.1.0.3
ibm websphere_portal 7.0.0.1
ibm websphere_portal 6.1.5.2
ibm websphere_portal 6.1.0.2
ibm websphere_portal 6.1.0.4
ibm websphere_portal 8.0.0.1
ibm websphere_portal 7.0.0.2
ibm websphere_portal 8.5.0.0
ibm websphere_portal 6.1.5.0
ibm websphere_portal 6.1.0.6
ibm websphere_portal 6.1.5.3
ibm websphere_portal 7.0.0.0
ibm websphere_portal 6.1.0.1
ibm websphere_portal 6.1.5.1
ibm websphere_portal 6.1.0.5
ibm websphere_portal 6.1.0.0
CVE-2015-1909 MEDIUM

The XML parser in the Reference Data Management component in the server in IBM InfoSphere Master Data Management (MDM) 10.1 before IF1, 11.0 before FP3, 11.3, and 11.4 before FP2 allows remote attackers to read arbitrary files, and consequently obtain administrative access, via an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm infosphere_master_data_management_server 10.1
ibm infosphere_master_data_management_server 11.0
ibm infosphere_master_data_management_server 11.3
ibm infosphere_master_data_management_server 11.4
CVE-2015-1910 LOW

Cross-site scripting (XSS) vulnerability in the Reference Data Management component in the server in IBM InfoSphere Master Data Management (MDM) 10.1 before IF1, 11.0 before FP3, and 11.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm infosphere_master_data_management_server 10.1
ibm infosphere_master_data_management_server 11.0
ibm infosphere_master_data_management_server 11.3
CVE-2015-1911 MEDIUM

Cross-site scripting (XSS) vulnerability in Sterling Order Management 8.5 before HF113, Sterling Selling and Fulfillment Foundation 9.0.0 before FP92, and Sterling Field Sales (SFS) 9.0 before HF7 in IBM Sterling Selling and Fulfillment Suite allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm sterling_field_sales 9.0
ibm sterling_order_management 8.5
ibm sterling_selling_and_fulfillment_foundation 9.0
CVE-2015-1913 MEDIUM

Rational Test Control Panel in IBM Rational Test Workbench and Rational Test Virtualization Server 8.0.0.x before 8.0.0.5, 8.0.1.x before 8.0.1.6, 8.5.0.x before 8.5.0.4, 8.5.1.x before 8.5.1.5, 8.6.0.x before 8.6.0.4, and 8.7.0.x before 8.7.0.2 uses the MD5 algorithm for password hashing, which makes it easier for remote attackers to bypass authentication via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm rational_test_workbench 8.5.1.1
ibm rational_test_virtualization_server 8.0.0.1
ibm rational_test_virtualization_server 8.5.0
ibm rational_test_virtualization_server 8.6.0.1
ibm rational_test_workbench 8.0.1
ibm rational_test_workbench 8.5.1.3
ibm rational_test_virtualization_server 8.5.1.2
ibm rational_test_virtualization_server 8.5.1
ibm rational_test_workbench 8.5.0.1
ibm rational_test_workbench 8.0.0.4
ibm rational_test_virtualization_server 8.5.1.4
ibm rational_test_workbench 8.5.1
ibm rational_test_workbench 8.0.1.2
ibm rational_test_workbench 8.0.1.3
ibm rational_test_virtualization_server 8.7.0.1
ibm rational_test_workbench 8.6.0.1
ibm rational_test_virtualization_server 8.6.0
ibm rational_test_workbench 8.7.0.1
ibm rational_test_virtualization_server 8.5.0.3
ibm rational_test_virtualization_server 8.0.1.4
ibm rational_test_workbench 8.0.0
ibm rational_test_workbench 8.7.0
ibm rational_test_virtualization_server 8.0.0.2
ibm rational_test_workbench 8.5.1.4
ibm rational_test_virtualization_server 8.5.0.1
ibm rational_test_workbench 8.6.0.3
ibm rational_test_workbench 8.5.0
ibm rational_test_workbench 8.5.0.3
ibm rational_test_workbench 8.0.0.1
ibm rational_test_workbench 8.6.0.2
ibm rational_test_virtualization_server 8.0.1.5
ibm rational_test_virtualization_server 8.7.0
ibm rational_test_workbench 8.0.0.2
ibm rational_test_virtualization_server 8.5.1.3
ibm rational_test_virtualization_server 8.5.0.2
ibm rational_test_virtualization_server 8.6.0.2
ibm rational_test_virtualization_server 8.0.1.2
ibm rational_test_workbench 8.0.1.4
ibm rational_test_workbench 8.6.0
ibm rational_test_workbench 8.0.1.1
ibm rational_test_virtualization_server 8.0.0.3
ibm rational_test_workbench 8.5.0.2
ibm rational_test_workbench 8.0.1.5
ibm rational_test_virtualization_server 8.0.1
ibm rational_test_virtualization_server 8.0.1.3
ibm rational_test_virtualization_server 8.5.1.1
ibm rational_test_virtualization_server 8.6.0.3
ibm rational_test_virtualization_server 8.0.0
ibm rational_test_virtualization_server 8.0.0.4
ibm rational_test_workbench 8.0.0.3
ibm rational_test_workbench 8.5.1.2
ibm rational_test_virtualization_server 8.0.1.1
CVE-2015-1914 MEDIUM

IBM Java 7 R1 before SR3, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 FP10 allows remote attackers to bypass "permission checks" and obtain sensitive information via vectors related to the Java Virtual Machine.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm java *
CVE-2015-1915 MEDIUM

The Endpoint Manager for Remote Control component in IBM Tivoli Endpoint Manager for Lifecycle Management 9.0.1 before IF6 and 9.1.0 before IF6 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm endpoint_manager_family 9.1.0
ibm endpoint_manager_family 9.0.1
CVE-2015-1916 MEDIUM

Unspecified vulnerability in IBM Java 8 before SR1 allows remote attackers to cause a denial of service via unknown vectors related to SSL/TLS and the Secure Socket Extension provider.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
134c704f-9b21-4f2e-91b3-4a467353bcc0 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 3.9 3.6

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,CWE-400,

Products Affected

Vendor Product Version
ibm java 8.0
CVE-2015-1917 MEDIUM

Cross-site scripting (XSS) vulnerability in the Active Content Filtering component in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF17, and 8.5.0 before CF06 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.0
ibm websphere_portal 6.1.0.3
ibm websphere_portal 7.0.0.1
ibm websphere_portal 6.1.5.2
ibm websphere_portal 6.1.0.2
ibm websphere_portal 6.1.0.4
ibm websphere_portal 8.0.0.1
ibm websphere_portal 7.0.0.2
ibm websphere_portal 6.1.5.0
ibm websphere_portal 6.1.0.6
ibm websphere_portal 6.1.5.3
ibm websphere_portal 7.0.0.0
ibm websphere_portal 6.1.0.1
ibm websphere_portal 6.1.5.1
ibm websphere_portal 6.1.0.5
ibm websphere_portal 6.1.0.0
CVE-2015-1919 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Security QRadar Incident Forensics before 7.2.5 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm security_qradar_incident_forensics *
CVE-2015-1920 HIGH

IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.47, 7.0 before 7.0.0.39, 8.0 before 8.0.0.11, and 8.5 before 8.5.5.6 allows remote attackers to execute arbitrary code by sending crafted instructions in a management-port session.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 7.0.0.36
ibm websphere_application_server 7.0
ibm websphere_application_server 7.0.0.38
ibm websphere_application_server 6.1.0.14
ibm websphere_application_server 7.0.0.12
ibm websphere_application_server 8.0.0.6
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 8.5.5.2
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 7.0.0.16
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0.35
ibm websphere_application_server 7.0.0.25
ibm websphere_application_server 8.0.0.9
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 7.0.0.14
ibm websphere_application_server 7.0.0.22
ibm websphere_application_server 7.0.0.31
ibm websphere_application_server 7.0.0.10
ibm websphere_application_server 8.5.5.5
ibm websphere_application_server 8.0.0.8
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 8.0.0.7
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.0.39
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 6.1.0.37
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 7.0.0.27
ibm websphere_application_server 7.0.0.18
ibm websphere_application_server 6.1.0.47
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 8.5.5.3
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 8.0.0.2
ibm websphere_application_server 8.0.0.5
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 8.5.0.2
ibm websphere_application_server 6.1.0.45
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 7.0.0.33
ibm websphere_application_server 6.1.0
ibm websphere_application_server 6.1
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.41
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 7.0.0.32
ibm websphere_application_server 7.0.0.29
ibm websphere_application_server 7.0.0.24
ibm websphere_application_server 8.5.5.0
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 7.0.0.37
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 6.1.0.43
ibm websphere_application_server 8.0.0.10
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 7.0.0.34
ibm websphere_application_server 8.5.5.4
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 8.5.5.1
CVE-2015-1921 MEDIUM

Open redirect vulnerability in IBM WebSphere Portal 8.0.0 before 8.0.0.1 CF17 and 8.5.0 before CF06 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.1
ibm websphere_portal 8.0.0.0
ibm websphere_portal 8.5.0.0
CVE-2015-1922 LOW

The Data Movement implementation in IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and Windows allows remote authenticated users to bypass intended access restrictions and delete table rows via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2 10.1
ibm db2 9.8
ibm db2 9.7
CVE-2015-1923 HIGH

Buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_fastback 6.1.10.0
ibm tivoli_storage_manager_fastback 6.1.11.1
ibm tivoli_storage_manager_fastback 6.1.0.0
ibm tivoli_storage_manager_fastback 6.1.9.0
ibm tivoli_storage_manager_fastback 6.1.8.1
ibm tivoli_storage_manager_fastback 6.1.7.2
ibm tivoli_storage_manager_fastback 6.1.8.0
ibm tivoli_storage_manager_fastback 6.1.11.0
ibm tivoli_storage_manager_fastback 6.1.10.1
ibm tivoli_storage_manager_fastback 6.1.1.0
ibm tivoli_storage_manager_fastback 6.1.9.1
CVE-2015-1924 HIGH

Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, a different vulnerability than CVE-2015-1925, CVE-2015-1929, CVE-2015-1930, CVE-2015-1948, CVE-2015-1953, CVE-2015-1954, CVE-2015-1962, CVE-2015-1963, CVE-2015-1964, and CVE-2015-1965.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_fastback 6.1.10.0
ibm tivoli_storage_manager_fastback 6.1.11.1
ibm tivoli_storage_manager_fastback 6.1.0.0
ibm tivoli_storage_manager_fastback 6.1.9.0
ibm tivoli_storage_manager_fastback 6.1.8.1
ibm tivoli_storage_manager_fastback 6.1.7.2
ibm tivoli_storage_manager_fastback 6.1.8.0
ibm tivoli_storage_manager_fastback 6.1.11.0
ibm tivoli_storage_manager_fastback 6.1.10.1
ibm tivoli_storage_manager_fastback 6.1.1.0
ibm tivoli_storage_manager_fastback 6.1.9.1
CVE-2015-1925 HIGH

Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, a different vulnerability than CVE-2015-1924, CVE-2015-1929, CVE-2015-1930, CVE-2015-1948, CVE-2015-1953, CVE-2015-1954, CVE-2015-1962, CVE-2015-1963, CVE-2015-1964, and CVE-2015-1965.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_fastback 6.1.10.0
ibm tivoli_storage_manager_fastback 6.1.11.1
ibm tivoli_storage_manager_fastback 6.1.0.0
ibm tivoli_storage_manager_fastback 6.1.9.0
ibm tivoli_storage_manager_fastback 6.1.8.1
ibm tivoli_storage_manager_fastback 6.1.7.2
ibm tivoli_storage_manager_fastback 6.1.8.0
ibm tivoli_storage_manager_fastback 6.1.11.0
ibm tivoli_storage_manager_fastback 6.1.10.1
ibm tivoli_storage_manager_fastback 6.1.1.0
ibm tivoli_storage_manager_fastback 6.1.9.1
CVE-2015-1927 MEDIUM

The default configuration of IBM WebSphere Application Server (WAS) 7.0.0 before 7.0.0.39, 8.0.0 before 8.0.0.11, and 8.5 before 8.5.5.6 has a false value for the com.ibm.ws.webcontainer.disallowServeServletsByClassname WebContainer property, which allows remote attackers to obtain privileged access via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 7.0.0.36
ibm websphere_application_server 7.0
ibm websphere_application_server 7.0.0.38
ibm websphere_application_server 7.0.0.12
ibm websphere_application_server 8.0.0.6
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 8.5.5.2
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 7.0.0.16
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 7.0.0.25
ibm websphere_application_server 8.0.0.9
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 7.0.0.14
ibm websphere_application_server 7.0.0.22
ibm websphere_application_server 7.0.0.31
ibm websphere_application_server 7.0.0.10
ibm websphere_application_server 8.5.5.5
ibm websphere_application_server 8.0.0.8
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 8.0.0.7
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 7.0.0.27
ibm websphere_application_server 7.0.0.18
ibm websphere_application_server 8.5.5.3
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 8.0.0.2
ibm websphere_application_server 8.0.0.5
ibm websphere_application_server 8.5.0.2
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 7.0.0.33
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 7.0.0.32
ibm websphere_application_server 7.0.0.29
ibm websphere_application_server 7.0.0.24
ibm websphere_application_server 8.5.5.0
ibm websphere_application_server 7.0.0.37
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 8.0.0.10
ibm websphere_application_server 7.0.0.34
ibm websphere_application_server 8.5.5.4
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 8.5.5.1
ibm websphere_application_server 7.0.0.4
CVE-2015-1928 LOW

Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.x and 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF11, and 6.x before 6.0.0 IF4; Rational Quality Manager (RQM) 3.x before 3.0.1.6 IF7, 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF11, and 6.0 before 6.0.0 IF4; Rational Team Concert (RTC) 3.x before 3.0.1.6 IF7, 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF11, and 6.0 before 6.0.0 IF4; Rational Requirements Composer (RRC) 3.x before 3.0.1.6 IF7 and 4.x before 4.0.7 IF9; Rational DOORS Next Generation (RDNG) 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF11, and 6.0 before 6.0.0 IF4; Rational Engineering Lifecycle Manager (RELM) 4.0.3 through 4.0.7, 5.0 through 5.0.2, and 6.0.0; Rational Rhapsody Design Manager (DM) 4.0 through 4.0.7, 5.0 through 5.0.2, and 6.0.0; and Rational Software Architect Design Manager (DM) 4.0 through 4.0.7, 5.0 through 5.0.2, and 6.0.0 allows remote authenticated users to conduct clickjacking attacks via a crafted web site.

CVSS 2.0

Severity: LOW

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm rational_rhapsody_design_manager 4.0.4
ibm rational_rhapsody_design_manager 4.0.5
ibm rational_collaborative_lifecycle_management 4.0.6
ibm rational_engineering_lifecycle_manager 4.0.7
ibm rational_quality_manager 4.0.6
ibm rational_requirements_composer 3.0.1.4
ibm rational_requirements_composer 3.0.1.1
ibm rational_team_concert 5.0
ibm rational_requirements_composer 2.0
ibm rational_software_architect_design_manager 4.0.7
ibm rational_team_concert 2.0.0.2
ibm rational_quality_manager 2.0.1
ibm rational_engineering_lifecycle_manager 5.0.2
ibm rational_team_concert 2.0.0.1
ibm rational_rhapsody_design_manager 5.0.2
ibm rational_quality_manager 4.0.3
ibm rational_rhapsody_design_manager 3.0.0.1
ibm rational_team_concert 4.0.1
ibm rational_team_concert 4.0.5
ibm rational_doors_next_generation 5.0
ibm rational_team_concert 4.0.2
ibm rational_quality_manager 5.0
ibm rational_collaborative_lifecycle_management 4.0.5
ibm rational_collaborative_lifecycle_management 4.0.7
ibm rational_collaborative_lifecycle_management 4.0.3
ibm rational_requirements_composer 2.0.0.1
ibm rational_software_architect_design_manager 4.0.6
ibm rational_doors_next_generation 4.0.7
ibm rational_doors_next_generation 4.0.2
ibm rational_team_concert 3.0.1.4
ibm rational_requirements_composer 4.0
ibm rational_team_concert 3.0.1.1
ibm rational_requirements_composer 3.0
ibm rational_rhapsody_design_manager 4.0.7
ibm rational_requirements_composer 4.0.4
ibm rational_engineering_lifecycle_manager 5.0
ibm rational_team_concert 5.0.2
ibm rational_requirements_composer 4.0.1
ibm rational_requirements_composer 3.0.1.2
ibm rational_requirements_composer 4.0.7
ibm rational_collaborative_lifecycle_management 4.0.1
ibm rational_rhapsody_design_manager 5.0
ibm rational_team_concert 4.0.3
ibm rational_quality_manager 3.0.1.3
ibm rational_team_concert 3.0.1
ibm rational_collaborative_lifecycle_management 4.0.2
ibm rational_quality_manager 3.0
ibm rational_requirements_composer 2.0.0.2
ibm rational_quality_manager 2.0
ibm rational_quality_manager 4.0.1
ibm rational_team_concert 4.0.6
ibm rational_engineering_lifecycle_manager 1.0.0.1
ibm rational_quality_manager 3.0.1.2
ibm rational_engineering_lifecycle_manager 4.0.5
ibm rational_requirements_composer 4.0.2
ibm rational_software_architect_design_manager 5.0.2
ibm rational_requirements_composer 4.0.3
ibm rational_doors_next_generation 4.0.4
ibm rational_quality_manager 3.0.1.4
ibm rational_quality_manager 4.0.4
ibm rational_engineering_lifecycle_manager 4.0.6
ibm rational_rhapsody_design_manager 4.0.3
ibm rational_doors_next_generation 5.0.2
ibm rational_quality_manager 4.0.2
ibm rational_doors_next_generation 4.0
ibm rational_requirements_composer 4.0.0.2
ibm rational_requirements_composer 4.0.5
ibm rational_doors_next_generation 5.0.1
ibm rational_software_architect_design_manager 4.0.1
ibm rational_team_concert 3.0.1.6
ibm rational_collaborative_lifecycle_management 4.0.4
ibm rational_software_architect_design_manager 3.0.0.1
ibm rational_team_concert 4.0.0.1
ibm rational_software_architect_design_manager 3.0.1
ibm rational_engineering_lifecycle_manager 4.0.3
ibm rational_engineering_lifecycle_manager 4.0.4
ibm rational_software_architect_design_manager 4.0.2
ibm rational_quality_manager 4.0.0.1
ibm rational_quality_manager 4.0.0.2
ibm rational_rhapsody_design_manager 6.0
ibm rational_quality_manager 4.0.7
ibm rational_requirements_composer 3.0.1.6
ibm rational_rhapsody_design_manager 4.0.6
ibm rational_engineering_lifecycle_manager 1.0
ibm rational_requirements_composer 4.0.6
ibm rational_software_architect_design_manager 5.0
ibm rational_software_architect_design_manager 4.0.4
ibm rational_doors_next_generation 4.0.1
ibm rational_engineering_lifecycle_manager 5.0.1
ibm rational_quality_manager 3.0.1.5
ibm rational_team_concert 4.0.7
ibm rational_team_concert 3.0.1.2
ibm rational_software_architect_design_manager 4.0.3
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_quality_manager 5.0.2
ibm rational_requirements_composer 2.0.0.3
ibm rational_rhapsody_design_manager 4.0.1
ibm rational_rhapsody_design_manager 4.0.2
ibm rational_team_concert 4.0.0.2
ibm rational_rhapsody_design_manager 3.0.1
ibm rational_rhapsody_design_manager 4.0
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_requirements_composer 3.0.1
ibm rational_requirements_composer 3.0.1.3
ibm rational_software_architect_design_manager 3.0
ibm rational_quality_manager 3.0.1.6
ibm rational_team_concert 2.0
ibm rational_rhapsody_design_manager 5.0.1
ibm rational_quality_manager 3.0.1.1
ibm rational_team_concert 4.0
ibm rational_doors_next_generation 4.0.5
ibm rational_requirements_composer 4.0.0.1
ibm rational_doors_next_generation 4.0.6
ibm rational_team_concert 3.0
ibm rational_doors_next_generation 4.0.3
ibm rational_quality_manager 5.0.1
ibm rational_requirements_composer 2.0.0.4
ibm rational_quality_manager 4.0
ibm rational_collaborative_lifecycle_management 5.0
ibm rational_collaborative_lifecycle_management 3.0.1
ibm rational_requirements_composer 3.0.1.5
ibm rational_team_concert 3.0.1.5
ibm rational_team_concert 3.0.1.3
ibm rational_quality_manager 3.0.1
ibm rational_rhapsody_design_manager 3.0
ibm rational_software_architect_design_manager 4.0.5
ibm rational_team_concert 4.0.4
ibm rational_software_architect_design_manager 5.0.1
ibm rational_software_architect_design_manager 4.0
ibm rational_quality_manager 4.0.5
ibm rational_team_concert 5.0.1
CVE-2015-1929 HIGH

Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, a different vulnerability than CVE-2015-1924, CVE-2015-1925, CVE-2015-1930, CVE-2015-1948, CVE-2015-1953, CVE-2015-1954, CVE-2015-1962, CVE-2015-1963, CVE-2015-1964, and CVE-2015-1965.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_fastback 6.1.10.0
ibm tivoli_storage_manager_fastback 6.1.11.1
ibm tivoli_storage_manager_fastback 6.1.0.0
ibm tivoli_storage_manager_fastback 6.1.9.0
ibm tivoli_storage_manager_fastback 6.1.8.1
ibm tivoli_storage_manager_fastback 6.1.7.2
ibm tivoli_storage_manager_fastback 6.1.8.0
ibm tivoli_storage_manager_fastback 6.1.11.0
ibm tivoli_storage_manager_fastback 6.1.10.1
ibm tivoli_storage_manager_fastback 6.1.1.0
ibm tivoli_storage_manager_fastback 6.1.9.1
CVE-2015-1930 HIGH

Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, a different vulnerability than CVE-2015-1924, CVE-2015-1925, CVE-2015-1929, CVE-2015-1948, CVE-2015-1953, CVE-2015-1954, CVE-2015-1962, CVE-2015-1963, CVE-2015-1964, and CVE-2015-1965.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_fastback 6.1.10.0
ibm tivoli_storage_manager_fastback 6.1.11.1
ibm tivoli_storage_manager_fastback 6.1.0.0
ibm tivoli_storage_manager_fastback 6.1.9.0
ibm tivoli_storage_manager_fastback 6.1.8.1
ibm tivoli_storage_manager_fastback 6.1.7.2
ibm tivoli_storage_manager_fastback 6.1.8.0
ibm tivoli_storage_manager_fastback 6.1.11.0
ibm tivoli_storage_manager_fastback 6.1.10.1
ibm tivoli_storage_manager_fastback 6.1.1.0
ibm tivoli_storage_manager_fastback 6.1.9.1
CVE-2015-1932 MEDIUM

IBM WebSphere Application Server 7.x before 7.0.0.39, 8.0.x before 8.0.0.11, and 8.5.x before 8.5.5.7 and WebSphere Virtual Enterprise before 7.0.0.7 allow remote attackers to obtain potentially sensitive information about the proxy-server software by reading the HTTP Via header.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 7.0.0.36
ibm websphere_application_server 7.0.0.38
ibm websphere_application_server 7.0.0.12
ibm websphere_application_server 8.0.0.6
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 8.5.5.2
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 7.0.0.16
ibm websphere_virtual_enterprise *
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 7.0.0.25
ibm websphere_application_server 8.0.0.9
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 7.0.0.14
ibm websphere_application_server 7.0.0.22
ibm websphere_application_server 7.0.0.31
ibm websphere_application_server 7.0.0.10
ibm websphere_application_server 8.5.5.5
ibm websphere_application_server 8.0.0.8
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 8.0.0.7
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 7.0.0.27
ibm websphere_application_server 7.0.0.18
ibm websphere_application_server 8.5.5.3
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 8.0.0.2
ibm websphere_application_server 8.0.0.5
ibm websphere_application_server 8.5.0.2
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 7.0.0.33
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 7.0.0.32
ibm websphere_application_server 7.0.0.29
ibm websphere_application_server 7.0.0.24
ibm websphere_application_server 8.5.5.0
ibm websphere_application_server 7.0.0.37
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 8.5.5.6
ibm websphere_application_server 8.0.0.10
ibm websphere_application_server 7.0.0.34
ibm websphere_application_server 8.5.5.4
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 8.5.5.1
ibm websphere_application_server 7.0.0.4
CVE-2015-1933 LOW

IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX001, and 7.6.0 before 7.6.0.1 IFIX001; Maximo Asset Management 7.5.x before 7.5.0.8 IFIX001 and 7.6.0 before 7.6.0.1 IFIX001 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products do not have an off autocomplete attribute for the password field, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm tivoli_asset_management_for_it 7.2
ibm maximo_for_life_sciences 7.5.0.2
ibm maximo_asset_management 7.1.1.9
ibm maximo_for_government 7.5.0.4
ibm tivoli_service_request_manager 7.2.0.0
ibm maximo_for_life_sciences 7.5.0.1
ibm maximo_for_government 7.1
ibm maximo_asset_management 7.1.1.13
ibm maximo_asset_management_essentials 7.5
ibm maximo_for_nuclear_power 7.5.0.4
ibm maximo_asset_management 7.1.1.10
ibm maximo_for_oil_and_gas 7.5.0.6
ibm maximo_asset_management 7.1.1.1
ibm maximo_for_nuclear_power 7.5.0.0
ibm maximo_for_oil_and_gas 7.5.0.5
ibm maximo_for_nuclear_power 7.5.0.1
ibm maximo_for_life_sciences 7.5.0.4
ibm maximo_for_nuclear_power 7.1
ibm maximo_for_transportation 7.5.0.1
ibm maximo_for_utilities 7.5.0.2
ibm maximo_for_nuclear_power 7.5.0.3
ibm maximo_for_government 7.5.0.1
ibm maximo_for_utilities 7.5.0.5
ibm maximo_for_life_sciences 7.1
ibm maximo_asset_management 7.5.0.6
ibm maximo_for_transportation 7.5.0.2
ibm maximo_for_nuclear_power 7.5.0.6
ibm maximo_for_transportation 7.5.0.4
ibm maximo_asset_management 7.1.1.7
ibm maximo_asset_management 7.5.0.7
ibm maximo_for_government 7.5.0.6
ibm maximo_for_utilities 7.5.0.3
ibm maximo_asset_management 7.5.0.5
ibm maximo_asset_management 7.1.1.2
ibm maximo_for_oil_and_gas 7.1
ibm maximo_asset_management 7.1.1.5
ibm maximo_asset_management 7.1.1.11
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
ibm maximo_asset_management 7.5.0.8
ibm maximo_for_nuclear_power 7.5.0.5
ibm maximo_for_transportation 7.5.0.6
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.5.0.1
ibm maximo_for_transportation 7.5.0.0
ibm maximo_for_life_sciences 7.5.0.0
ibm maximo_for_utilities 7.1
ibm maximo_for_oil_and_gas 7.5.0.2
ibm maximo_for_oil_and_gas 7.5.0.3
ibm maximo_for_government 7.5.0.0
ibm change_and_configuration_management_database 7.1
ibm maximo_asset_management 7.6.0.0
ibm maximo_asset_management 7.1.1.12
ibm change_and_configuration_management_database 7.2
ibm maximo_for_life_sciences 7.5.0.5
ibm tivoli_service_request_manager 7.1.0
ibm maximo_asset_management 7.5.0.3
ibm maximo_for_government 7.5.0.2
ibm maximo_for_oil_and_gas 7.5.0.1
ibm maximo_for_nuclear_power 7.5.0.2
ibm maximo_for_utilities 7.5.0.0
ibm maximo_for_life_sciences 7.5.0.3
ibm tivoli_asset_management_for_it 7.1
ibm maximo_for_government 7.5.0.5
ibm maximo_for_transportation 7.1
ibm maximo_for_utilities 7.5.0.6
ibm maximo_for_transportation 7.5.0.5
ibm maximo_asset_management_essentials 7.1
ibm maximo_asset_management 7.5.0.0
ibm maximo_for_oil_and_gas 7.5.0.4
ibm maximo_asset_management 7.5.0.4
ibm smartcloud_control_desk 7.5
ibm maximo_for_oil_and_gas 7.5.0.0
ibm maximo_for_life_sciences 7.5.0.6
ibm maximo_for_energy_optimization 7.1
ibm maximo_asset_management 7.1.1.6
ibm maximo_for_transportation 7.5.0.3
ibm maximo_for_utilities 7.5.0.1
ibm maximo_for_government 7.5.0.3
ibm maximo_for_utilities 7.5.0.4
CVE-2015-1934 MEDIUM

IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX002, and 7.6.0 before 7.6.0.1 IFIX001; Maximo Asset Management 7.5.x before 7.5.0.8 IFIX002 and 7.6.0 before 7.6.0.1 IFIX001 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products do not properly encrypt passwords, which makes it easier for context-dependent attackers to determine cleartext passwords by leveraging access to a password file.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm tivoli_asset_management_for_it 7.2
ibm maximo_for_life_sciences 7.5.0.2
ibm maximo_asset_management 7.1.1.9
ibm maximo_for_government 7.5.0.4
ibm tivoli_service_request_manager 7.2.0.0
ibm maximo_for_life_sciences 7.5.0.1
ibm maximo_for_government 7.1
ibm maximo_asset_management 7.1.1.13
ibm maximo_asset_management_essentials 7.5
ibm maximo_for_nuclear_power 7.5.0.4
ibm maximo_asset_management 7.1.1.10
ibm maximo_for_oil_and_gas 7.5.0.6
ibm maximo_asset_management 7.1.1.1
ibm maximo_for_nuclear_power 7.5.0.0
ibm maximo_for_oil_and_gas 7.5.0.5
ibm maximo_for_nuclear_power 7.5.0.1
ibm maximo_for_life_sciences 7.5.0.4
ibm maximo_for_nuclear_power 7.1
ibm maximo_for_transportation 7.5.0.1
ibm maximo_for_utilities 7.5.0.2
ibm maximo_for_nuclear_power 7.5.0.3
ibm maximo_for_government 7.5.0.1
ibm maximo_for_utilities 7.5.0.5
ibm maximo_for_life_sciences 7.1
ibm maximo_asset_management 7.5.0.6
ibm maximo_for_transportation 7.5.0.2
ibm maximo_for_nuclear_power 7.5.0.6
ibm maximo_for_transportation 7.5.0.4
ibm maximo_asset_management 7.1.1.7
ibm maximo_asset_management 7.5.0.7
ibm maximo_for_government 7.5.0.6
ibm maximo_for_utilities 7.5.0.3
ibm maximo_asset_management 7.5.0.5
ibm maximo_asset_management 7.1.1.2
ibm maximo_for_oil_and_gas 7.1
ibm maximo_asset_management 7.1.1.5
ibm maximo_asset_management 7.1.1.11
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
ibm maximo_asset_management 7.5.0.8
ibm maximo_for_nuclear_power 7.5.0.5
ibm maximo_for_transportation 7.5.0.6
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.5.0.1
ibm maximo_for_transportation 7.5.0.0
ibm maximo_for_life_sciences 7.5.0.0
ibm maximo_for_utilities 7.1
ibm maximo_for_oil_and_gas 7.5.0.2
ibm maximo_for_oil_and_gas 7.5.0.3
ibm maximo_for_government 7.5.0.0
ibm change_and_configuration_management_database 7.1
ibm maximo_asset_management 7.6.0.0
ibm maximo_asset_management 7.1.1.12
ibm change_and_configuration_management_database 7.2
ibm maximo_for_life_sciences 7.5.0.5
ibm tivoli_service_request_manager 7.1.0
ibm maximo_asset_management 7.5.0.3
ibm maximo_for_government 7.5.0.2
ibm maximo_for_oil_and_gas 7.5.0.1
ibm maximo_for_nuclear_power 7.5.0.2
ibm maximo_for_utilities 7.5.0.0
ibm maximo_for_life_sciences 7.5.0.3
ibm tivoli_asset_management_for_it 7.1
ibm maximo_for_government 7.5.0.5
ibm maximo_for_transportation 7.1
ibm maximo_for_utilities 7.5.0.6
ibm maximo_for_transportation 7.5.0.5
ibm maximo_asset_management_essentials 7.1
ibm maximo_asset_management 7.5.0.0
ibm maximo_for_oil_and_gas 7.5.0.4
ibm maximo_asset_management 7.5.0.4
ibm smartcloud_control_desk 7.5
ibm maximo_for_oil_and_gas 7.5.0.0
ibm maximo_for_life_sciences 7.5.0.6
ibm maximo_for_energy_optimization 7.1
ibm maximo_asset_management 7.1.1.6
ibm maximo_for_transportation 7.5.0.3
ibm maximo_for_utilities 7.5.0.1
ibm maximo_for_government 7.5.0.3
ibm maximo_for_utilities 7.5.0.4
CVE-2015-1935 HIGH

The scalar-function implementation in IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and Windows allows remote attackers to cause a denial of service or execute arbitrary code via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-17,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2 10.1
ibm db2 9.8
ibm db2 9.7
CVE-2015-1936 MEDIUM

The administrative console in IBM WebSphere Application Server (WAS) 8.0.0 before 8.0.0.11 and 8.5 before 8.5.5.6, when the Security feature is disabled, allows remote authenticated users to hijack sessions via the JSESSIONID parameter.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm websphere_application_server 8.0.0.8
ibm websphere_application_server 8.0.0.5
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 8.5.5.0
ibm websphere_application_server 8.5.0.2
ibm websphere_application_server 8.0.0.6
ibm websphere_application_server 8.5.5.2
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 8.0.0.7
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 8.0.0.9
ibm websphere_application_server 8.0.0.10
ibm websphere_application_server 8.5.5.3
ibm websphere_application_server 8.5.5.4
ibm websphere_application_server 8.5.5.5
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 8.5.5.1
ibm websphere_application_server 8.0.0.2
CVE-2015-1937 HIGH

IBM PowerVC 1.2.0.x through 1.2.0.4, 1.2.1.x through 1.2.1.2, and 1.2.2.x through 1.2.2.2 does not require authentication for the ceilometer NoSQL database, which allows remote attackers to read or write to arbitrary database records, and consequently obtain administrator privileges, via a session on port 27017.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm powervc 1.2.0.2
ibm powervc 1.2.1.2
ibm powervc 1.2.2.0
ibm powervc 1.2.0.3
ibm powervc 1.2.2.1
ibm powervc 1.2.0.1
ibm powervc 1.2.2.2
ibm powervc 1.2.0.0
ibm powervc 1.2.1.1
ibm powervc 1.2.0.4
ibm powervc 1.2.1.0
CVE-2015-1938 HIGH

The server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to execute arbitrary commands via unspecified vectors, a different vulnerability than CVE-2015-1986.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-77,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_fastback 6.1.10.0
ibm tivoli_storage_manager_fastback 6.1.11.1
ibm tivoli_storage_manager_fastback 6.1.0.0
ibm tivoli_storage_manager_fastback 6.1.9.0
ibm tivoli_storage_manager_fastback 6.1.8.1
ibm tivoli_storage_manager_fastback 6.1.7.2
ibm tivoli_storage_manager_fastback 6.1.8.0
ibm tivoli_storage_manager_fastback 6.1.11.0
ibm tivoli_storage_manager_fastback 6.1.10.1
ibm tivoli_storage_manager_fastback 6.1.1.0
ibm tivoli_storage_manager_fastback 6.1.9.1
CVE-2015-1941 HIGH

The server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to read arbitrary files via a crafted TCP packet to an unspecified port.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_fastback 6.1.10.0
ibm tivoli_storage_manager_fastback 6.1.11.1
ibm tivoli_storage_manager_fastback 6.1.0.0
ibm tivoli_storage_manager_fastback 6.1.9.0
ibm tivoli_storage_manager_fastback 6.1.8.1
ibm tivoli_storage_manager_fastback 6.1.7.2
ibm tivoli_storage_manager_fastback 6.1.8.0
ibm tivoli_storage_manager_fastback 6.1.11.0
ibm tivoli_storage_manager_fastback 6.1.10.1
ibm tivoli_storage_manager_fastback 6.1.1.0
ibm tivoli_storage_manager_fastback 6.1.9.1
CVE-2015-1942 HIGH

The server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to write to arbitrary files, and subsequently execute these files, via a crafted TCP packet to an unspecified port.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_fastback 6.1.10.0
ibm tivoli_storage_manager_fastback 6.1.11.1
ibm tivoli_storage_manager_fastback 6.1.0.0
ibm tivoli_storage_manager_fastback 6.1.9.0
ibm tivoli_storage_manager_fastback 6.1.8.1
ibm tivoli_storage_manager_fastback 6.1.7.2
ibm tivoli_storage_manager_fastback 6.1.8.0
ibm tivoli_storage_manager_fastback 6.1.11.0
ibm tivoli_storage_manager_fastback 6.1.10.1
ibm tivoli_storage_manager_fastback 6.1.1.0
ibm tivoli_storage_manager_fastback 6.1.9.1
CVE-2015-1943 HIGH

IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.x through 7.0.0.2 CF29, 8.0.x before 8.0.0.1 CF17, and 8.5.0 before CF06 allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted request.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.0
ibm websphere_portal 6.1.0.3
ibm websphere_portal 7.0.0.1
ibm websphere_portal 6.1.5.2
ibm websphere_portal 6.1.0.2
ibm websphere_portal 6.1.0.4
ibm websphere_portal 8.0.0.1
ibm websphere_portal 7.0.0.2
ibm websphere_portal 8.5.0.0
ibm websphere_portal 6.1.5.0
ibm websphere_portal 6.1.0.6
ibm websphere_portal 6.1.5.3
ibm websphere_portal 7.0.0.0
ibm websphere_portal 6.1.0.1
ibm websphere_portal 6.1.5.1
ibm websphere_portal 6.1.0.5
ibm websphere_portal 6.1.0.0
CVE-2015-1944 LOW

Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.0 before 8.0.0.1 CF17 and 8.5.0 before CF06 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.1
ibm websphere_portal 8.0.0.0
ibm websphere_portal 8.5.0.0
CVE-2015-1945 MEDIUM

Unspecified vulnerability in the Reference Data Management component in IBM InfoSphere Master Data Management 10.1, 11.0, 11.3 before FP3, and 11.4 allows remote authenticated users to gain privileges via unknown vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm infosphere_master_data_management_server 10.1
ibm infosphere_master_data_management_server 11.0
ibm infosphere_master_data_management_server 11.3
ibm infosphere_master_data_management_server 11.4
CVE-2015-1946 MEDIUM

IBM WebSphere Application Server (WAS) 8.5 before 8.5.5.6, and WebSphere Virtual Enterprise 7.0 before 7.0.0.6 for WebSphere Application Server (WAS) 7.0 and 8.0, does not properly implement user roles, which allows local users to gain privileges via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_virtual_enterprise 7.0.0.2
ibm websphere_application_server 7.0
ibm websphere_virtual_enterprise 7.0.0.1
ibm websphere_application_server 8.5.5.0
ibm websphere_application_server 8.5.0.2
ibm websphere_application_server 8.5.5.2
ibm websphere_virtual_enterprise 7.0.0.4
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 8.0.0.0
ibm websphere_virtual_enterprise 7.0
ibm websphere_virtual_enterprise 7.0.0.5
ibm websphere_application_server 8.5.5.3
ibm websphere_application_server 8.5.5.4
ibm websphere_application_server 8.5.5.5
ibm websphere_virtual_enterprise 7.0.0.3
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 8.5.5.1
CVE-2015-1947 MEDIUM

Untrusted search path vulnerability in IBM InfoSphere BigInsights 3.0, 3.0.0.1, 3.0.0.2, and 4.0, when a DB2 database is used, allows local users to gain privileges via a Trojan horse library that is loaded by a setuid or setgid program.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm infosphere_biginsights 3.0.0.1
ibm infosphere_biginsights 4.0.0.0
ibm infosphere_biginsights 3.0.0.0
ibm infosphere_biginsights 3.0.0.2
CVE-2015-1948 HIGH

Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, a different vulnerability than CVE-2015-1924, CVE-2015-1925, CVE-2015-1929, CVE-2015-1930, CVE-2015-1953, CVE-2015-1954, CVE-2015-1962, CVE-2015-1963, CVE-2015-1964, and CVE-2015-1965.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_fastback 6.1.10.0
ibm tivoli_storage_manager_fastback 6.1.11.1
ibm tivoli_storage_manager_fastback 6.1.0.0
ibm tivoli_storage_manager_fastback 6.1.9.0
ibm tivoli_storage_manager_fastback 6.1.8.1
ibm tivoli_storage_manager_fastback 6.1.7.2
ibm tivoli_storage_manager_fastback 6.1.8.0
ibm tivoli_storage_manager_fastback 6.1.11.0
ibm tivoli_storage_manager_fastback 6.1.10.1
ibm tivoli_storage_manager_fastback 6.1.1.0
ibm tivoli_storage_manager_fastback 6.1.9.1
CVE-2015-1949 HIGH

The server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to execute arbitrary commands with SYSTEM privileges via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-77,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_fastback 6.1.10.0
ibm tivoli_storage_manager_fastback 6.1.11.1
ibm tivoli_storage_manager_fastback 6.1.0.0
ibm tivoli_storage_manager_fastback 6.1.9.0
ibm tivoli_storage_manager_fastback 6.1.8.1
ibm tivoli_storage_manager_fastback 6.1.7.2
ibm tivoli_storage_manager_fastback 6.1.8.0
ibm tivoli_storage_manager_fastback 6.1.11.0
ibm tivoli_storage_manager_fastback 6.1.10.1
ibm tivoli_storage_manager_fastback 6.1.1.0
ibm tivoli_storage_manager_fastback 6.1.9.1
CVE-2015-1950 MEDIUM

IBM PowerVC Standard Edition 1.2.2.1 through 1.2.2.2 does not require authentication for access to the Python interpreter with nova credentials, which allows KVM guest OS users to discover certain PowerVC credentials and bypass intended access restrictions via unspecified Python code.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm powervc 1.2.2.1
ibm powervc 1.2.2.2
CVE-2015-1951 LOW

IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX001, and 7.6.0 before 7.6.0.0 IFIX005 does not prevent caching of HTTPS responses, which allows physically proximate attackers to obtain sensitive local-cache information by leveraging an unattended workstation.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm maximo_asset_management 7.1.1.9
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.5.0.1
ibm maximo_asset_management 7.5.0.6
ibm maximo_asset_management 7.1.1.13
ibm maximo_asset_management 7.1.1.10
ibm maximo_asset_management 7.1.1.1
ibm maximo_asset_management 7.5.0.0
ibm maximo_asset_management 7.1.1.7
ibm maximo_asset_management 7.5.0.7
ibm maximo_asset_management 7.5.0.4
ibm maximo_asset_management 7.5.0.5
ibm maximo_asset_management 7.6.0.0
ibm maximo_asset_management 7.1.1.2
ibm maximo_asset_management 7.1.1.12
ibm maximo_asset_management 7.1.1.6
ibm maximo_asset_management 7.1.1.5
ibm maximo_asset_management 7.5.0.3
ibm maximo_asset_management 7.1.1.11
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
ibm maximo_asset_management 7.5.0.8
CVE-2015-1952 LOW

Cross-site scripting (XSS) vulnerability in IBM AppScan Enterprise Edition 9.0.x before 9.0.2 iFix 001 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 103416.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm security_appscan 8.8.0.0
ibm security_appscan 9.0.1.0
ibm security_appscan 9.0.0.0
ibm security_appscan 9.0.2.0
ibm security_appscan 8.7.0.0
ibm security_appscan 8.6.0.0
ibm security_appscan 8.5.0.0
CVE-2015-1953 HIGH

Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, a different vulnerability than CVE-2015-1924, CVE-2015-1925, CVE-2015-1929, CVE-2015-1930, CVE-2015-1948, CVE-2015-1954, CVE-2015-1962, CVE-2015-1963, CVE-2015-1964, and CVE-2015-1965.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_fastback 6.1.10.0
ibm tivoli_storage_manager_fastback 6.1.11.1
ibm tivoli_storage_manager_fastback 6.1.0.0
ibm tivoli_storage_manager_fastback 6.1.9.0
ibm tivoli_storage_manager_fastback 6.1.8.1
ibm tivoli_storage_manager_fastback 6.1.7.2
ibm tivoli_storage_manager_fastback 6.1.8.0
ibm tivoli_storage_manager_fastback 6.1.11.0
ibm tivoli_storage_manager_fastback 6.1.10.1
ibm tivoli_storage_manager_fastback 6.1.1.0
ibm tivoli_storage_manager_fastback 6.1.9.1
CVE-2015-1954 HIGH

Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, a different vulnerability than CVE-2015-1924, CVE-2015-1925, CVE-2015-1929, CVE-2015-1930, CVE-2015-1948, CVE-2015-1953, CVE-2015-1962, CVE-2015-1963, CVE-2015-1964, and CVE-2015-1965.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_fastback 6.1.10.0
ibm tivoli_storage_manager_fastback 6.1.11.1
ibm tivoli_storage_manager_fastback 6.1.0.0
ibm tivoli_storage_manager_fastback 6.1.9.0
ibm tivoli_storage_manager_fastback 6.1.8.1
ibm tivoli_storage_manager_fastback 6.1.7.2
ibm tivoli_storage_manager_fastback 6.1.8.0
ibm tivoli_storage_manager_fastback 6.1.11.0
ibm tivoli_storage_manager_fastback 6.1.10.1
ibm tivoli_storage_manager_fastback 6.1.1.0
ibm tivoli_storage_manager_fastback 6.1.9.1
CVE-2015-1955 HIGH

IBM MQ Light before 1.0.0.2 allows remote attackers to cause a denial of service (CPU consumption) via a crafted byte sequence in authentication data.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm websphere_mq_light 1.0.0.1
ibm websphere_mq_light 1.0
CVE-2015-1956 HIGH

IBM MQ Light before 1.0.0.2 allows remote attackers to cause a denial of service (disk consumption) via a crafted byte sequence in authentication data, a different vulnerability than CVE-2015-1958 and CVE-2015-1987.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm websphere_mq_light 1.0.0.1
ibm websphere_mq_light 1.0
CVE-2015-1957 LOW

IBM WebSphere MQ 7.5.x before 7.5.0.6 and 8.0.x before 8.0.0.3 allows remote authenticated users to obtain sensitive information via a man-in-the-middle attack, related to duplication of message data in cleartext outside the protected payload. IBM X-Force ID: 103482.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_mq *
CVE-2015-1958 HIGH

IBM MQ Light before 1.0.0.2 allows remote attackers to cause a denial of service (disk consumption) via a crafted byte sequence in authentication data, a different vulnerability than CVE-2015-1956 and CVE-2015-1987.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm websphere_mq_light 1.0.0.1
ibm websphere_mq_light 1.0
CVE-2015-1959 MEDIUM

IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, 6.3 before iFix 37, 6.3.1 before iFix 11, and 6.4 before iFix 2 does not properly restrict encrypted files, which allows local users to obtain sensitive information or possibly have unspecified other impact via a (1) download or (2) upload action.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm tivoli_directory_server 6.3.0.0
ibm tivoli_directory_server 6.1.0
ibm tivoli_directory_server 6.3.1.0
ibm tivoli_directory_server 6.4.0
ibm tivoli_directory_server 6.0
ibm tivoli_directory_server 6.2.0.0
CVE-2015-1961 HIGH

The REST API in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, 8.5.5 through 8.5.5.0, and 8.5.6 through 8.5.6.0 allows remote authenticated users to bypass intended access restrictions and execute arbitrary JavaScript code on the server via an unspecified API call.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm business_process_manager 8.0.1.2
ibm business_process_manager 8.5.6.0
ibm business_process_manager 8.0.1.1
ibm business_process_manager 7.5.0.1
ibm business_process_manager 7.5.1.0
ibm business_process_manager 7.5.1.1
ibm business_process_manager 8.5.5.0
ibm business_process_manager 8.0.1.0
ibm business_process_manager 8.0.0.0
ibm business_process_manager 8.5.0.1
ibm business_process_manager 8.0.1.3
ibm business_process_manager 8.5.0.0
ibm business_process_manager 7.5.0.0
CVE-2015-1962 HIGH

Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, a different vulnerability than CVE-2015-1924, CVE-2015-1925, CVE-2015-1929, CVE-2015-1930, CVE-2015-1948, CVE-2015-1953, CVE-2015-1954, CVE-2015-1963, CVE-2015-1964, and CVE-2015-1965.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_fastback 6.1.10.0
ibm tivoli_storage_manager_fastback 6.1.11.1
ibm tivoli_storage_manager_fastback 6.1.0.0
ibm tivoli_storage_manager_fastback 6.1.9.0
ibm tivoli_storage_manager_fastback 6.1.8.1
ibm tivoli_storage_manager_fastback 6.1.7.2
ibm tivoli_storage_manager_fastback 6.1.8.0
ibm tivoli_storage_manager_fastback 6.1.11.0
ibm tivoli_storage_manager_fastback 6.1.10.1
ibm tivoli_storage_manager_fastback 6.1.1.0
ibm tivoli_storage_manager_fastback 6.1.9.1
CVE-2015-1963 HIGH

Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, a different vulnerability than CVE-2015-1924, CVE-2015-1925, CVE-2015-1929, CVE-2015-1930, CVE-2015-1948, CVE-2015-1953, CVE-2015-1954, CVE-2015-1962, CVE-2015-1964, and CVE-2015-1965.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_fastback 6.1.10.0
ibm tivoli_storage_manager_fastback 6.1.11.1
ibm tivoli_storage_manager_fastback 6.1.0.0
ibm tivoli_storage_manager_fastback 6.1.9.0
ibm tivoli_storage_manager_fastback 6.1.8.1
ibm tivoli_storage_manager_fastback 6.1.7.2
ibm tivoli_storage_manager_fastback 6.1.8.0
ibm tivoli_storage_manager_fastback 6.1.11.0
ibm tivoli_storage_manager_fastback 6.1.10.1
ibm tivoli_storage_manager_fastback 6.1.1.0
ibm tivoli_storage_manager_fastback 6.1.9.1
CVE-2015-1964 HIGH

Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, a different vulnerability than CVE-2015-1924, CVE-2015-1925, CVE-2015-1929, CVE-2015-1930, CVE-2015-1948, CVE-2015-1953, CVE-2015-1954, CVE-2015-1962, CVE-2015-1963, and CVE-2015-1965.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_fastback 6.1.10.0
ibm tivoli_storage_manager_fastback 6.1.11.1
ibm tivoli_storage_manager_fastback 6.1.0.0
ibm tivoli_storage_manager_fastback 6.1.9.0
ibm tivoli_storage_manager_fastback 6.1.8.1
ibm tivoli_storage_manager_fastback 6.1.7.2
ibm tivoli_storage_manager_fastback 6.1.8.0
ibm tivoli_storage_manager_fastback 6.1.11.0
ibm tivoli_storage_manager_fastback 6.1.10.1
ibm tivoli_storage_manager_fastback 6.1.1.0
ibm tivoli_storage_manager_fastback 6.1.9.1
CVE-2015-1965 HIGH

Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, a different vulnerability than CVE-2015-1924, CVE-2015-1925, CVE-2015-1929, CVE-2015-1930, CVE-2015-1948, CVE-2015-1953, CVE-2015-1954, CVE-2015-1962, CVE-2015-1963, and CVE-2015-1964.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_fastback 6.1.10.0
ibm tivoli_storage_manager_fastback 6.1.11.1
ibm tivoli_storage_manager_fastback 6.1.0.0
ibm tivoli_storage_manager_fastback 6.1.9.0
ibm tivoli_storage_manager_fastback 6.1.8.1
ibm tivoli_storage_manager_fastback 6.1.7.2
ibm tivoli_storage_manager_fastback 6.1.8.0
ibm tivoli_storage_manager_fastback 6.1.11.0
ibm tivoli_storage_manager_fastback 6.1.10.1
ibm tivoli_storage_manager_fastback 6.1.1.0
ibm tivoli_storage_manager_fastback 6.1.9.1
CVE-2015-1966 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before FP17, 6.2.1 before FP9, and 6.2.2 before FP15, as used in Security Access Manager for Mobile and other products, allow remote attackers to inject arbitrary web script or HTML via a crafted URL, related to the (1) ERROR_DESCRIPTION and (2) TOKEN:RelayState macros.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_federated_identity_manager 6.2.1
ibm tivoli_federated_identity_manager 6.2.2
ibm tivoli_federated_identity_manager 6.2.0
CVE-2015-1967 MEDIUM

MQ Explorer in IBM WebSphere MQ before 8.0.0.3 does not recognize the absence of the compatibility-mode option, which allows remote attackers to obtain sensitive information by sniffing the network for a session in which TLS is not used.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_mq 8.0.0.2
CVE-2015-1968 LOW

Cross-site scripting (XSS) vulnerability in IBM InfoSphere Master Data Management Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 before FP03 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm infosphere_master_data_management 11.0
ibm infosphere_master_data_management 9.1
ibm infosphere_master_data_management 11.4
ibm infosphere_master_data_management 10.1
ibm infosphere_master_data_management 11.3
CVE-2015-1969 LOW

Cross-site scripting (XSS) vulnerability in IBM Tivoli Common Reporting (TCR) 2.1 before IF13 and 2.1.1 before IF21, and TCR 3.1.x as used in Cognos Business Intelligence before 10.2 IF0015 and other products, allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_common_reporting 3.1.0.0
ibm tivoli_common_reporting 3.1.0.1
ibm tivoli_common_reporting 2.1.0.0
ibm tivoli_common_reporting 3.1.2
ibm tivoli_common_reporting 2.1.1.0
ibm tivoli_common_reporting 3.1.0.2
CVE-2015-1970 LOW

The IBM WebSphere DataPower XC10 appliance 2.1 through 2.1.0.3 and 2.5 through 2.5.0.4 retains data on SSD cards, which might allow physically proximate attackers to obtain sensitive information by extracting a card and attaching it elsewhere.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_datapower_xc10_appliance_firmware 2.1.0.3
ibm websphere_datapower_xc10_appliance_firmware 2.1.0.1
ibm websphere_datapower_xc10_appliance_firmware 2.5.0.2
ibm websphere_datapower_xc10_appliance_firmware 2.1.0.2
ibm websphere_datapower_xc10_appliance_firmware 2.1.0.0
ibm websphere_datapower_xc10_appliance_firmware 2.5.0.0
ibm websphere_datapower_xc10_appliance_firmware 2.5.0.1
ibm websphere_datapower_xc10_appliance_firmware 2.5.0.3
ibm websphere_datapower_xc10_appliance_firmware 2.5.0.4
CVE-2015-1971 LOW

Unspecified vulnerability in Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.x and 4.x before 4.0.7 IF8 and 5.x before 5.0.2 IF10; Rational Quality Manager (RQM) 2.x and 3.x before 3.0.1.6 IF7, 4.x before 4.0.7 IF8, and 5.x before 5.0.2 IF10; Rational Team Concert (RTC) 2.x and 3.x before 3.0.1.6 IF7, 4.x before 4.0.7 IF8, and 5.x before 5.0.2 IF10; Rational Requirements Composer (RRC) 2.x and 3.x before 3.0.1.6 IF7 and 4.0 through 4.0.7; Rational DOORS Next Generation (RDNG) 4.x before 4.0.7 IF8 and 5.x before 5.0.2 IF10; Rational Engineering Lifecycle Manager (RELM) 1.0 through 1.0.0.1, 4.0.3 through 4.0.7, and 5.0 through 5.0.2; Rational Rhapsody Design Manager (DM) 3.0 through 3.0.1, 4.0 through 4.0.7, 5.0 through 5.0.2, and 6.0; and Rational Software Architect Design Manager (DM) 3.0 through 3.0.1, 4.0 through 4.0.7, and 5.0 through 5.0.2 allows remote attackers to cause a denial of service via unknown vectors.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm rational_rhapsody_design_manager 4.0.4
ibm rational_rhapsody_design_manager 4.0.5
ibm rational_collaborative_lifecycle_management 4.0.6
ibm rational_engineering_lifecycle_manager 4.0.7
ibm rational_quality_manager 4.0.6
ibm rational_requirements_composer 3.0.1.4
ibm rational_requirements_composer 3.0.1.1
ibm rational_team_concert 5.0
ibm rational_requirements_composer 2.0
ibm rational_software_architect_design_manager 4.0.7
ibm rational_team_concert 2.0.0.2
ibm rational_quality_manager 2.0.1
ibm rational_engineering_lifecycle_manager 5.0.2
ibm rational_team_concert 2.0.0.1
ibm rational_rhapsody_design_manager 5.0.2
ibm rational_quality_manager 4.0.3
ibm rational_rhapsody_design_manager 3.0.0.1
ibm rational_team_concert 4.0.1
ibm rational_team_concert 4.0.5
ibm rational_doors_next_generation 5.0
ibm rational_team_concert 4.0.2
ibm rational_quality_manager 5.0
ibm rational_collaborative_lifecycle_management 4.0.5
ibm rational_collaborative_lifecycle_management 4.0.7
ibm rational_collaborative_lifecycle_management 4.0.3
ibm rational_requirements_composer 2.0.0.1
ibm rational_software_architect_design_manager 4.0.6
ibm rational_doors_next_generation 4.0.7
ibm rational_doors_next_generation 4.0.2
ibm rational_team_concert 3.0.1.4
ibm rational_requirements_composer 4.0
ibm rational_team_concert 3.0.1.1
ibm rational_requirements_composer 3.0
ibm rational_rhapsody_design_manager 4.0.7
ibm rational_requirements_composer 4.0.4
ibm rational_engineering_lifecycle_manager 5.0
ibm rational_team_concert 5.0.2
ibm rational_requirements_composer 4.0.1
ibm rational_requirements_composer 3.0.1.2
ibm rational_requirements_composer 4.0.7
ibm rational_collaborative_lifecycle_management 4.0.1
ibm rational_rhapsody_design_manager 5.0
ibm rational_team_concert 4.0.3
ibm rational_quality_manager 3.0.1.3
ibm rational_team_concert 3.0.1
ibm rational_collaborative_lifecycle_management 4.0.2
ibm rational_quality_manager 3.0
ibm rational_requirements_composer 2.0.0.2
ibm rational_quality_manager 2.0
ibm rational_quality_manager 4.0.1
ibm rational_team_concert 4.0.6
ibm rational_engineering_lifecycle_manager 1.0.0.1
ibm rational_quality_manager 3.0.1.2
ibm rational_engineering_lifecycle_manager 4.0.5
ibm rational_requirements_composer 4.0.2
ibm rational_software_architect_design_manager 5.0.2
ibm rational_requirements_composer 4.0.3
ibm rational_doors_next_generation 4.0.4
ibm rational_quality_manager 3.0.1.4
ibm rational_quality_manager 4.0.4
ibm rational_engineering_lifecycle_manager 4.0.6
ibm rational_rhapsody_design_manager 4.0.3
ibm rational_doors_next_generation 5.0.2
ibm rational_quality_manager 4.0.2
ibm rational_doors_next_generation 4.0
ibm rational_requirements_composer 4.0.0.2
ibm rational_requirements_composer 4.0.5
ibm rational_doors_next_generation 5.0.1
ibm rational_software_architect_design_manager 4.0.1
ibm rational_team_concert 3.0.1.6
ibm rational_collaborative_lifecycle_management 4.0.4
ibm rational_software_architect_design_manager 3.0.0.1
ibm rational_team_concert 4.0.0.1
ibm rational_software_architect_design_manager 3.0.1
ibm rational_engineering_lifecycle_manager 4.0.3
ibm rational_engineering_lifecycle_manager 4.0.4
ibm rational_software_architect_design_manager 4.0.2
ibm rational_quality_manager 4.0.0.1
ibm rational_quality_manager 4.0.0.2
ibm rational_rhapsody_design_manager 6.0
ibm rational_quality_manager 4.0.7
ibm rational_requirements_composer 3.0.1.6
ibm rational_rhapsody_design_manager 4.0.6
ibm rational_engineering_lifecycle_manager 1.0
ibm rational_requirements_composer 4.0.6
ibm rational_software_architect_design_manager 5.0
ibm rational_software_architect_design_manager 4.0.4
ibm rational_doors_next_generation 4.0.1
ibm rational_engineering_lifecycle_manager 5.0.1
ibm rational_quality_manager 3.0.1.5
ibm rational_team_concert 4.0.7
ibm rational_team_concert 3.0.1.2
ibm rational_software_architect_design_manager 4.0.3
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_quality_manager 5.0.2
ibm rational_requirements_composer 2.0.0.3
ibm rational_rhapsody_design_manager 4.0.1
ibm rational_rhapsody_design_manager 4.0.2
ibm rational_team_concert 4.0.0.2
ibm rational_rhapsody_design_manager 3.0.1
ibm rational_rhapsody_design_manager 4.0
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_requirements_composer 3.0.1
ibm rational_requirements_composer 3.0.1.3
ibm rational_software_architect_design_manager 3.0
ibm rational_quality_manager 3.0.1.6
ibm rational_team_concert 2.0
ibm rational_rhapsody_design_manager 5.0.1
ibm rational_quality_manager 3.0.1.1
ibm rational_team_concert 4.0
ibm rational_doors_next_generation 4.0.5
ibm rational_requirements_composer 4.0.0.1
ibm rational_doors_next_generation 4.0.6
ibm rational_team_concert 3.0
ibm rational_doors_next_generation 4.0.3
ibm rational_quality_manager 5.0.1
ibm rational_requirements_composer 2.0.0.4
ibm rational_quality_manager 4.0
ibm rational_collaborative_lifecycle_management 5.0
ibm rational_collaborative_lifecycle_management 3.0.1
ibm rational_requirements_composer 3.0.1.5
ibm rational_team_concert 3.0.1.5
ibm rational_team_concert 3.0.1.3
ibm rational_quality_manager 3.0.1
ibm rational_rhapsody_design_manager 3.0
ibm rational_software_architect_design_manager 4.0.5
ibm rational_team_concert 4.0.4
ibm rational_software_architect_design_manager 5.0.1
ibm rational_software_architect_design_manager 4.0
ibm rational_quality_manager 4.0.5
ibm rational_team_concert 5.0.1
CVE-2015-1972 MEDIUM

IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, 6.3 before iFix 37, 6.3.1 before iFix 11, and 6.4 before iFix 2 allows remote attackers to obtain sensitive error-log information via a crafted POST request.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm tivoli_directory_server 6.3.0.0
ibm tivoli_directory_server 6.1.0
ibm tivoli_directory_server 6.3.1.0
ibm tivoli_directory_server 6.4.0
ibm tivoli_directory_server 6.0
ibm tivoli_directory_server 6.2.0.0
CVE-2015-1974 MEDIUM

The web administration tool in IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, 6.3 before iFix 37, 6.3.1 before iFix 11, and 6.4 before iFix 2 allows remote authenticated users to bypass intended command restrictions via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm tivoli_directory_server 6.3.0.0
ibm tivoli_directory_server 6.1.0
ibm tivoli_directory_server 6.3.1.0
ibm tivoli_directory_server 6.4.0
ibm tivoli_directory_server 6.0
ibm tivoli_directory_server 6.2.0.0
CVE-2015-1975 MEDIUM

The web administration tool in IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, and 6.3 before iFix 37 and IBM Security Directory Server 6.3.1 before iFix 11 and 6.4 before iFix 2 allows local users to gain privileges via vectors related to argument injection. IBM X-Force ID: 103694.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-74,

Products Affected

Vendor Product Version
ibm tivoli_directory_server 6.3.0.0
ibm tivoli_directory_server 6.1.0
ibm tivoli_directory_server 6.3.1.0
ibm tivoli_directory_server 6.4.0
ibm tivoli_directory_server 6.0
ibm tivoli_directory_server 6.2.0.0
CVE-2015-1976 LOW

IBM Security Directory Server could allow an authenticated user to execute commands into the web administration tool that would cause the tool to crash.

CVSS 2.0

Severity: LOW

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm tivoli_directory_server *
ibm security_directory_server *
CVE-2015-1977 MEDIUM

Directory traversal vulnerability in the Web Administration tool in IBM Tivoli Directory Server (ITDS) before 6.1.0.74-ISS-ISDS-IF0074, 6.2.x before 6.2.0.50-ISS-ISDS-IF0050, and 6.3.x before 6.3.0.43-ISS-ISDS-IF0043 and IBM Security Directory Server (ISDS) before 6.3.1.18-ISS-ISDS-IF0018 and 6.4.x before 6.4.0.9-ISS-ISDS-IF0009 allows remote attackers to read arbitrary files via a .. (dot dot) in a URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm tivoli_directory_server 6.3.0.40
ibm tivoli_directory_server 6.3.1.5
ibm security_directory_server 6.3.1.10
ibm security_directory_server 6.3.1.17
ibm tivoli_directory_server 6.1.0.69
ibm tivoli_directory_server 6.2.0.29
ibm tivoli_directory_server 6.2.0.6
ibm tivoli_directory_server 6.3.0.10
ibm tivoli_directory_server 6.3.0.1
ibm tivoli_directory_server 6.1.0.24
ibm tivoli_directory_server 6.2.0.47
ibm security_directory_server 6.4.0.1
ibm tivoli_directory_server 6.1.0.36
ibm tivoli_directory_server 6.1.0
ibm tivoli_directory_server 6.1.0.14
ibm security_directory_server 6.3.1
ibm tivoli_directory_server 6.2.0.12
ibm tivoli_directory_server 6.1.0.2
ibm tivoli_directory_server 6.1.0.40
ibm tivoli_directory_server 6.3.1.8
ibm tivoli_directory_server 6.3.0.31
ibm tivoli_directory_server 6.1.0.70
ibm tivoli_directory_server 6.2.0
ibm tivoli_directory_server 6.2.0.26
ibm security_directory_server 6.3.1.13
ibm tivoli_directory_server 6.2.0.10
ibm tivoli_directory_server 6.2.0.32
ibm tivoli_directory_server 6.2.0.30
ibm tivoli_directory_server 6.2.0.35
ibm tivoli_directory_server 6.2.0.44
ibm security_directory_server 6.3.1.0
ibm security_directory_server 6.3.1.11
ibm tivoli_directory_server 6.3.0.24
ibm tivoli_directory_server 6.3.0.25
ibm tivoli_directory_server 6.1.0.23
ibm security_directory_server 6.4.0.6
ibm tivoli_directory_server 6.1.0.3
ibm tivoli_directory_server 6.1.0.47
ibm tivoli_directory_server 6.2.0.0
ibm tivoli_directory_server 6.1.0.8
ibm tivoli_directory_server 6.1.0.52
ibm tivoli_directory_server 6.1.0.28
ibm tivoli_directory_server 6.1.0.54
ibm tivoli_directory_server 6.2.0.33
ibm tivoli_directory_server 6.1.0.72
ibm tivoli_directory_server 6.2.0.20
ibm security_directory_server 6.3.1.15
ibm tivoli_directory_server 6.2.0.23
ibm tivoli_directory_server 6.1.0.34
ibm tivoli_directory_server 6.3.0.37
ibm tivoli_directory_server 6.1.0.53
ibm tivoli_directory_server 6.3.0.11
ibm tivoli_directory_server 6.3.0.15
ibm tivoli_directory_server 6.2.0.48
ibm tivoli_directory_server 6.1.0.51
ibm tivoli_directory_server 6.1.0.57
ibm tivoli_directory_server 6.3.0.0
ibm tivoli_directory_server 6.1.0.22
ibm security_directory_server 6.4.0.0
ibm tivoli_directory_server 6.1.0.61
ibm security_directory_server 6.3.1.8
ibm tivoli_directory_server 6.1.0.7
ibm tivoli_directory_server 6.2.0.36
ibm tivoli_directory_server 6.3.0.8
ibm tivoli_directory_server 6.3.0.34
ibm tivoli_directory_server 6.1.0.45
ibm tivoli_directory_server 6.2.0.38
ibm tivoli_directory_server 6.3.0.17
ibm tivoli_directory_server 6.3.0.9
ibm security_directory_server 6.4.0.8
ibm tivoli_directory_server 6.1.0.12
ibm tivoli_directory_server 6.1.0.18
ibm tivoli_directory_server 6.1.0.33
ibm tivoli_directory_server 6.3.0.2
ibm tivoli_directory_server 6.1.0.27
ibm tivoli_directory_server 6.1.0.58
ibm security_directory_server 6.3.1.14
ibm tivoli_directory_server 6.3.1.7
ibm tivoli_directory_server 6.3.0.36
ibm security_directory_server 6.4.0.5
ibm tivoli_directory_server 6.1.0.10
ibm tivoli_directory_server 6.1.0.31
ibm tivoli_directory_server 6.1.0.38
ibm security_directory_server 6.4.0.7
ibm tivoli_directory_server 6.2.0.21
ibm tivoli_directory_server 6.1.0.50
ibm tivoli_directory_server 6.3.0.22
ibm security_directory_server 6.3.1.9
ibm tivoli_directory_server 6.1.0.42
ibm tivoli_directory_server 6.2.0.42
ibm tivoli_directory_server 6.3.0.19
ibm tivoli_directory_server 6.2.0.8
ibm tivoli_directory_server 6.1.0.44
ibm tivoli_directory_server 6.3.0.38
ibm tivoli_directory_server 6.3.0
ibm security_directory_server 6.3.1.5
ibm tivoli_directory_server 6.1.0.63
ibm tivoli_directory_server 6.2.0.15
ibm tivoli_directory_server 6.3.1.0
ibm tivoli_directory_server 6.3.0.27
ibm tivoli_directory_server 6.2.0.27
ibm tivoli_directory_server 6.1.0.41
ibm tivoli_directory_server 6.1.0.9
ibm tivoli_directory_server 6.2.0.13
ibm tivoli_directory_server 6.1.0.59
ibm tivoli_directory_server 6.2.0.45
ibm tivoli_directory_server 6.1.0.29
ibm security_directory_server 6.4.0.4
ibm tivoli_directory_server 6.1.0.35
ibm tivoli_directory_server 6.2.0.1
ibm tivoli_directory_server 6.2.0.19
ibm tivoli_directory_server 6.2.0.43
ibm security_directory_server 6.3.1.7
ibm tivoli_directory_server 6.3.0.26
ibm tivoli_directory_server 6.1.0.66
ibm tivoli_directory_server 6.2.0.7
ibm tivoli_directory_server 6.3.0.12
ibm tivoli_directory_server 6.3.0.30
ibm tivoli_directory_server 6.1.0.30
ibm tivoli_directory_server 6.3.1.9
ibm security_directory_server 6.3.1.1
ibm security_directory_server 6.3.1.16
ibm tivoli_directory_server 6.2.0.2
ibm tivoli_directory_server 6.2.0.31
ibm tivoli_directory_server 6.1.0.49
ibm security_directory_server 6.3.1.4
ibm tivoli_directory_server 6.2.0.46
ibm security_directory_server 6.4.0
ibm tivoli_directory_server 6.3.0.33
ibm tivoli_directory_server 6.2.0.5
ibm tivoli_directory_server 6.2.0.24
ibm tivoli_directory_server 6.1.0.71
ibm tivoli_directory_server 6.1.0.55
ibm tivoli_directory_server 6.1.0.73
ibm tivoli_directory_server 6.2.0.25
ibm tivoli_directory_server 6.3.0.21
ibm tivoli_directory_server 6.2.0.11
ibm tivoli_directory_server 6.1.0.68
ibm tivoli_directory_server 6.2.0.34
ibm tivoli_directory_server 6.3.1.6
ibm tivoli_directory_server 6.2.0.49
ibm tivoli_directory_server 6.1.0.19
ibm tivoli_directory_server 6.3.0.32
ibm tivoli_directory_server 6.3.0.35
ibm tivoli_directory_server 6.3.0.18
ibm tivoli_directory_server 6.2.0.22
ibm tivoli_directory_server 6.1.0.62
ibm tivoli_directory_server 6.2.0.41
ibm tivoli_directory_server 6.1.0.6
ibm tivoli_directory_server 6.1.0.4
ibm tivoli_directory_server 6.1.0.20
ibm security_directory_server 6.4.0.2
ibm tivoli_directory_server 6.3.0.23
ibm tivoli_directory_server 6.1.0.67
ibm tivoli_directory_server 6.1.0.13
ibm tivoli_directory_server 6.2.0.40
ibm tivoli_directory_server 6.1.0.37
ibm tivoli_directory_server 6.1.0.15
ibm tivoli_directory_server 6.2.0.4
ibm tivoli_directory_server 6.3.0.39
ibm tivoli_directory_server 6.1.0.0
ibm tivoli_directory_server 6.3.0.14
ibm tivoli_directory_server 6.3.0.41
ibm tivoli_directory_server 6.2.0.37
ibm tivoli_directory_server 6.1.0.39
ibm tivoli_directory_server 6.2.0.14
ibm tivoli_directory_server 6.1.0.60
ibm security_directory_server 6.3.1.3
ibm tivoli_directory_server 6.1.0.5
ibm tivoli_directory_server 6.1.0.64
ibm security_directory_server 6.4.0.3
ibm tivoli_directory_server 6.1.0.43
ibm tivoli_directory_server 6.1.0.65
ibm tivoli_directory_server 6.3.0.28
ibm tivoli_directory_server 6.1.0.11
ibm tivoli_directory_server 6.1.0.48
ibm tivoli_directory_server 6.3.0.29
ibm tivoli_directory_server 6.1.0.25
ibm tivoli_directory_server 6.1.0.56
ibm tivoli_directory_server 6.2.0.39
ibm security_directory_server 6.3.1.12
ibm tivoli_directory_server 6.1.0.21
ibm security_directory_server 6.3.1.2
ibm tivoli_directory_server 6.3.0.42
ibm tivoli_directory_server 6.1.0.26
ibm tivoli_directory_server 6.2.0.3
ibm tivoli_directory_server 6.1.0.32
ibm tivoli_directory_server 6.1.0.46
ibm tivoli_directory_server 6.1.0.1
ibm security_directory_server 6.3.1.6
ibm tivoli_directory_server 6.1.0.17
CVE-2015-1978 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, 6.3 before iFix 37, 6.3.1 before iFix 11, and 6.4 before iFix 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_directory_server 6.3.0.0
ibm tivoli_directory_server 6.1.0
ibm tivoli_directory_server 6.3.1.0
ibm tivoli_directory_server 6.4.0
ibm tivoli_directory_server 6.0
ibm tivoli_directory_server 6.2.0.0
CVE-2015-1979 LOW

Multiple cross-site scripting (XSS) vulnerabilities in the Error dialog in IBM Case Manager 5.2.1 before 5.2.1.2 allow remote authenticated users to inject arbitrary web script or HTML via crafted input to the (1) addressability or (2) comments component.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm case_manager 5.2.1
ibm case_manager 5.2.1.1
CVE-2015-1980 LOW

IBM InfoSphere Master Data Management Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 before FP03 allows remote authenticated users to conduct clickjacking attacks via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm infosphere_master_data_management 11.0
ibm infosphere_master_data_management 9.1
ibm infosphere_master_data_management 11.4
ibm infosphere_master_data_management 10.1
ibm infosphere_master_data_management 11.3
CVE-2015-1981 LOW

Cross-site scripting (XSS) vulnerability in the web server in IBM Domino 8.5.x before 8.5.3 FP6 IF8 and 9.x before 9.0.1 FP4, when Webmail is enabled, allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, aka SPR KLYH9WYPR5.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm domino 8.5.0
ibm domino 8.5.1
ibm domino 8.5.2
ibm domino 9.0.1
ibm domino 8.5.3
CVE-2015-1982 MEDIUM

IBM InfoSphere Master Data Management Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 before FP03 allows remote authenticated users to obtain sensitive information via a crafted request, which reveals the full path in an error message.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm infosphere_master_data_management 11.0
ibm infosphere_master_data_management 9.1
ibm infosphere_master_data_management 11.4
ibm infosphere_master_data_management 10.1
ibm infosphere_master_data_management 11.3
CVE-2015-1983 LOW

Cross-site scripting (XSS) vulnerability in the Projects page in IBM UrbanCode Build 6.1.x before 6.1.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm urbancode_build 6.1.0.1
ibm urbancode_build 6.1.0.0
ibm urbancode_build 6.1.0.2
CVE-2015-1984 MEDIUM

IBM InfoSphere Master Data Management Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 before FP03 allows remote authenticated users to bypass intended access restrictions and read arbitrary profiles via unspecified vectors, as demonstrated by discovering usernames for use in brute-force attacks.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,CWE-264,

Products Affected

Vendor Product Version
ibm infosphere_master_data_management 11.0
ibm infosphere_master_data_management 9.1
ibm infosphere_master_data_management 11.4
ibm infosphere_master_data_management 10.1
ibm infosphere_master_data_management 11.3
CVE-2015-1985 LOW

The queue manager on IBM MQ M2000 appliances before 8.0.0.4 allows local users to bypass an intended password requirement and read private keys by leveraging the existence of a stash file.

CVSS 2.0

Severity: LOW

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm mq_appliance_m2000 *
CVE-2015-1986 HIGH

The server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to execute arbitrary commands via unspecified vectors, a different vulnerability than CVE-2015-1938.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-77,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_fastback 6.1.10.0
ibm tivoli_storage_manager_fastback 6.1.11.1
ibm tivoli_storage_manager_fastback 6.1.0.0
ibm tivoli_storage_manager_fastback 6.1.9.0
ibm tivoli_storage_manager_fastback 6.1.8.1
ibm tivoli_storage_manager_fastback 6.1.7.2
ibm tivoli_storage_manager_fastback 6.1.8.0
ibm tivoli_storage_manager_fastback 6.1.11.0
ibm tivoli_storage_manager_fastback 6.1.10.1
ibm tivoli_storage_manager_fastback 6.1.1.0
ibm tivoli_storage_manager_fastback 6.1.9.1
CVE-2015-1987 HIGH

IBM MQ Light before 1.0.0.2 allows remote attackers to cause a denial of service (disk consumption) via a crafted byte sequence in authentication data, a different vulnerability than CVE-2015-1956 and CVE-2015-1958.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm websphere_mq_light 1.0.0.1
ibm websphere_mq_light 1.0
CVE-2015-1988 LOW

Cross-site scripting (XSS) vulnerability in IBM Tivoli Storage Manger for Virtual Environments: Data Protection for VMware 6.3 before 6.3.2.5, 6.4 before 6.4.3.1, and 7.1 before 7.1.3 and Tivoli Storage FlashCopy Manager for VMware 3.1 before 3.1.1.3, 3.2 before 3.2.0.6, and 4.1 before 4.1.3.0 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_for_virtual_environments *
ibm tivoli_storage_flashcopy_manager *
CVE-2015-1989 MEDIUM

SQL injection vulnerability in IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm security_qradar_incident_forensics 7.2.0
ibm security_qradar_incident_forensics 7.2.2
ibm security_qradar_incident_forensics 7.2.1
ibm security_qradar_incident_forensics 7.2.5
ibm security_qradar_incident_forensics 7.2.3
ibm security_qradar_incident_forensics 7.2.4
CVE-2015-1992 HIGH

IBM Systems Director 5.2.x, 6.1.x, 6.2.0.x, 6.2.1.x, 6.3.0.0, 6.3.1.x, 6.3.2.x, 6.3.3.x, 6.3.5.0, and 6.3.6.0 improperly processes events, which allows local users to gain privileges via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm systems_director 6.3.2.0
ibm systems_director 6.3.1.1
ibm systems_director 6.3.3.0
ibm systems_director 6.3.5.0
ibm systems_director 6.3.0.0
ibm systems_director 6.3.1.0
ibm systems_director 6.3.2.1
ibm systems_director 5.20
ibm systems_director 6.3.6.0
ibm systems_director 6.3.3.1
ibm systems_director 6.3.2.2
CVE-2015-1993 MEDIUM

IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 does not set the secure flag for unspecified cookies in an https session, which makes it easier for remote attackers to capture these cookies by intercepting their transmission within an http session.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm security_qradar_incident_forensics 7.2.0
ibm security_qradar_incident_forensics 7.2.2
ibm security_qradar_incident_forensics 7.2.1
ibm security_qradar_incident_forensics 7.2.5
ibm security_qradar_incident_forensics 7.2.3
ibm security_qradar_incident_forensics 7.2.4
CVE-2015-1994 MEDIUM

IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_qradar_incident_forensics 7.2.0
ibm security_qradar_incident_forensics 7.2.2
ibm security_qradar_incident_forensics 7.2.1
ibm security_qradar_incident_forensics 7.2.5
ibm security_qradar_incident_forensics 7.2.3
ibm security_qradar_incident_forensics 7.2.4
CVE-2015-1995 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 allow remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm security_qradar_incident_forensics 7.2.0
ibm security_qradar_incident_forensics 7.2.2
ibm security_qradar_incident_forensics 7.2.1
ibm security_qradar_incident_forensics 7.2.5
ibm security_qradar_incident_forensics 7.2.3
ibm security_qradar_incident_forensics 7.2.4
CVE-2015-1996 LOW

IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 does not prevent caching of HTTPS responses, which allows physically proximate attackers to obtain sensitive local-cache information by leveraging an unattended workstation.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_qradar_incident_forensics 7.2.0
ibm security_qradar_incident_forensics 7.2.2
ibm security_qradar_incident_forensics 7.2.1
ibm security_qradar_incident_forensics 7.2.5
ibm security_qradar_incident_forensics 7.2.3
ibm security_qradar_incident_forensics 7.2.4
CVE-2015-1997 MEDIUM

Cross-site request forgery (CSRF) vulnerability in IBM Security QRadar Vulnerability Manager 7.2.x before 7.2.5 Patch 5 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm security_qradar_incident_forensics 7.2.0
ibm security_qradar_incident_forensics 7.2.2
ibm security_qradar_incident_forensics 7.2.1
ibm security_qradar_incident_forensics 7.2.5
ibm security_qradar_incident_forensics 7.2.3
ibm security_qradar_incident_forensics 7.2.4
CVE-2015-1999 MEDIUM

IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 places session IDs in https URLs, which allows remote attackers to obtain sensitive information by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_qradar_incident_forensics 7.2.0
ibm security_qradar_incident_forensics 7.2.2
ibm security_qradar_incident_forensics 7.2.1
ibm security_qradar_incident_forensics 7.2.5
ibm security_qradar_incident_forensics 7.2.3
ibm security_qradar_incident_forensics 7.2.4
CVE-2015-2005 MEDIUM

IBM Security QRadar SIEM 7.1.x before 7.1 MR2 Patch 12 and 7.2.x before 7.2.5 Patch 6 does not properly expire sessions, which allows remote attackers to obtain sensitive information by leveraging an unattended workstation.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.2
ibm qradar_security_information_and_event_manager 7.2.0
ibm qradar_security_information_and_event_manager 7.1.0
ibm qradar_security_information_and_event_manager 7.2.3
ibm qradar_security_information_and_event_manager 7.2.4
ibm qradar_security_information_and_event_manager 7.2.1
CVE-2015-2007 MEDIUM

Directory traversal vulnerability in IBM Security QRadar SIEM 7.2.x before 7.2.5 Patch 6 allows remote authenticated users to read arbitrary files via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.2
ibm qradar_security_information_and_event_manager 7.2.0
ibm qradar_security_information_and_event_manager 7.2.3
ibm qradar_security_information_and_event_manager 7.2.4
ibm qradar_security_information_and_event_manager 7.2.1
ibm qradar_security_information_and_event_manager 7.2.5
CVE-2015-2008 LOW

IBM Security QRadar SIEM 7.1.x before 7.1 MR2 Patch 12 and 7.2.x before 7.2.6 includes SSH private keys during backup operations, which allows remote authenticated administrators to obtain sensitive information by reading a backup archive.

CVSS 2.0

Severity: LOW

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.2
ibm qradar_security_information_and_event_manager 7.2.0
ibm qradar_security_information_and_event_manager 7.1.0
ibm qradar_security_information_and_event_manager 7.2.3
ibm qradar_security_information_and_event_manager 7.2.4
ibm qradar_security_information_and_event_manager 7.2.1
ibm qradar_security_information_and_event_manager 7.2.5
CVE-2015-2009 MEDIUM

Cross-site request forgery (CSRF) vulnerability in the xmlrpc.cgi service in IBM QRadar SIEM 7.1 before MR2 Patch 11 Interim Fix 02 and 7.2.x before 7.2.5 Patch 4 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences via vectors related to webmin. IBM X-Force ID: 103921.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.1.0
ibm qradar_security_information_and_event_manager *
ibm qradar_security_information_and_event_manager 7.2.5
CVE-2015-2011 HIGH

The xmlrpc.cgi Webmin script in IBM QRadar SIEM 7.1 MR2 before Patch 11 IF02 and 7.2.x before 7.2.5 Patch 4 allows remote authenticated users to execute arbitrary commands with root privileges via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-77,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.2
ibm qradar_security_information_and_event_manager 7.2.0
ibm qradar_security_information_and_event_manager 7.1.0
ibm qradar_security_information_and_event_manager 7.2.3
ibm qradar_security_information_and_event_manager 7.2.4
ibm qradar_security_information_and_event_manager 7.2.1
CVE-2015-2012 LOW

The MQXR service in WMQ Telemetry in IBM WebSphere MQ 7.1 before 7.1.0.7, 7.5 through 7.5.0.5, and 8.0 before 8.0.0.4 uses world-readable permissions for a cleartext file containing the SSL keystore password, which allows local users to obtain sensitive information by reading this file.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,CWE-255,

Products Affected

Vendor Product Version
ibm websphere_mq 7.1.0.3
ibm websphere_mq 7.5.0.4
ibm websphere_mq 8.0.0.3
ibm websphere_mq 7.5
ibm websphere_mq 8.0.0.2
ibm websphere_mq 7.5.0.2
ibm websphere_mq 8.0.0.1
ibm websphere_mq 7.1.0.5
ibm websphere_mq 7.5.0.3
ibm websphere_mq 7.1.0.4
ibm websphere_mq 7.1.0.6
ibm websphere_mq 7.5.0.5
ibm websphere_mq 8.0
CVE-2015-2013 MEDIUM

IBM WebSphere MQ 7.0.1 before 7.0.1.13 allows remote attackers to cause a denial of service (channel-agent abend and process outage) via a crafted selection string in an MQI call.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm websphere_mq 7.0.1.0
ibm websphere_mq 7.0.1.7
ibm websphere_mq 7.0.1.5
ibm websphere_mq 7.0.1.12
ibm websphere_mq 7.0.1.1
ibm websphere_mq 7.0.1.3
ibm websphere_mq 7.0.1.8
ibm websphere_mq 7.0.1.10
ibm websphere_mq 7.0.1.11
ibm websphere_mq 7.0.1.4
ibm websphere_mq 7.0.1.2
ibm websphere_mq 7.0.1.9
ibm websphere_mq 7.0.1.6
CVE-2015-2014 MEDIUM

Open redirect vulnerability in the web server in IBM Domino 8.5 before 8.5.3 FP6 IF9 and 9.0 before 9.0.1 FP4 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks or cross-site scripting (XSS) attacks via a crafted URL, aka SPR SJAR9DNGDA.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm domino 8.5.0
ibm domino 8.5.1
ibm domino 8.5.2
ibm domino 9.0.1
ibm domino 8.5.3
CVE-2015-2015 MEDIUM

Cross-site scripting (XSS) vulnerability in pubnames.ntf (aka the Directory template) in the web server in IBM Domino before 9.0.0 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka SPR KLYH8WBPRN.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm domino *
CVE-2015-2016 HIGH

Unspecified vulnerability in IBM QRadar SIEM 7.1 MR2 before Patch 11 IF02 and 7.2.x before 7.2.5 Patch 4 allows remote authenticated users to execute arbitrary commands with root privileges via unknown vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.2
ibm qradar_security_information_and_event_manager 7.2.0
ibm qradar_security_information_and_event_manager 7.1.0
ibm qradar_security_information_and_event_manager 7.2.3
ibm qradar_security_information_and_event_manager 7.2.4
ibm qradar_security_information_and_event_manager 7.2.1
CVE-2015-2017 MEDIUM

CRLF injection vulnerability in IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.47, 7.0 before 7.0.0.39, 8.0 before 8.0.0.12, and 8.5 before 8.5.5.8 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_application_server 6.1.0.2
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 7.0.0.36
ibm websphere_application_server 7.0
ibm websphere_application_server 7.0.0.38
ibm websphere_application_server 6.1.0.14
ibm websphere_application_server 7.0.0.12
ibm websphere_application_server 8.0.0.6
ibm websphere_application_server 6.1.0.7
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 8.5.5.2
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 7.0.0.16
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 6.1.0.12
ibm websphere_application_server 6.1.0.35
ibm websphere_application_server 7.0.0.25
ibm websphere_application_server 8.0.0.9
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 7.0.0.14
ibm websphere_application_server 7.0.0.22
ibm websphere_application_server 7.0.0.31
ibm websphere_application_server 7.0.0.10
ibm websphere_application_server 8.5.5.5
ibm websphere_application_server 8.0.0.8
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 8.0.0.7
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 6.1.0.39
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 6.1.0.37
ibm websphere_application_server 6.1.0.31
ibm websphere_application_server 7.0.0.27
ibm websphere_application_server 7.0.0.18
ibm websphere_application_server 6.1.0.47
ibm websphere_application_server 6.1.0.5
ibm websphere_application_server 8.5.5.3
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 8.0.0.2
ibm websphere_application_server 8.0.0.5
ibm websphere_application_server 6.1.0.27
ibm websphere_application_server 6.1.0.45
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 8.5.5.7
ibm websphere_application_server 6.1.0.13
ibm websphere_application_server 7.0.0.33
ibm websphere_application_server 6.1.0
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 6.1
ibm websphere_application_server 6.1.0.23
ibm websphere_application_server 6.1.0.25
ibm websphere_application_server 6.1.0.1
ibm websphere_application_server 6.1.0.41
ibm websphere_application_server 6.1.0.11
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 6.1.0.9
ibm websphere_application_server 7.0.0.32
ibm websphere_application_server 7.0.0.29
ibm websphere_application_server 7.0.0.24
ibm websphere_application_server 8.5.5.0
ibm websphere_application_server 6.1.0.21
ibm websphere_application_server 6.1.0.33
ibm websphere_application_server 7.0.0.37
ibm websphere_application_server 6.1.0.0
ibm websphere_application_server 6.1.0.3
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 6.1.0.29
ibm websphere_application_server 6.1.0.43
ibm websphere_application_server 8.5.5.6
ibm websphere_application_server 8.0.0.11
ibm websphere_application_server 8.0.0.10
ibm websphere_application_server 6.1.0.17
ibm websphere_application_server 6.1.0.15
ibm websphere_application_server 6.1.0.19
ibm websphere_application_server 7.0.0.34
ibm websphere_application_server 8.5.5.4
ibm websphere_application_server 8.5.5.1
ibm websphere_application_server 7.0.0.4
CVE-2015-2018 LOW

IBM Integration Bus 9 and 10 before 10.0.0.1 and WebSphere Message Broker 7 before 7.0.0.8 and 8 before 8.0.0.7 do not ensure that the correct security profile is selected, which allows remote authenticated users to obtain sensitive information via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_message_broker 7.0.0.1
ibm websphere_message_broker 7.0.0.2
ibm websphere_message_broker 8.0
ibm websphere_message_broker 7.0.0.5
ibm websphere_message_broker 7.0.0.4
ibm websphere_message_broker 8.0.0.6
ibm websphere_message_broker 7.0.0.6
ibm websphere_message_broker 8.0.0.4
ibm websphere_message_broker 8.0.0.3
ibm integration_bus 9.0
ibm websphere_message_broker 8.0.0.2
ibm websphere_message_broker 7.0.0.3
ibm integration_bus 10.0
ibm websphere_message_broker 8.0.0.5
ibm websphere_message_broker 7.0.
ibm websphere_message_broker 8.0.0.1
ibm websphere_message_broker 7.0.0.7
CVE-2015-2019 LOW

IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, 6.3 before iFix 37, 6.3.1 before iFix 11, and 6.4 before iFix 2 does not prevent caching of documents retrieved in SSL sessions, which allows physically proximate attackers to obtain sensitive information by leveraging an unattended workstation.

CVSS 2.0

Severity: LOW

Problem Type: CWE-17,

Products Affected

Vendor Product Version
ibm tivoli_directory_server 6.3.0.0
ibm tivoli_directory_server 6.1.0
ibm tivoli_directory_server 6.3.1.0
ibm tivoli_directory_server 6.4.0
ibm tivoli_directory_server 6.0
ibm tivoli_directory_server 6.2.0.0
CVE-2015-2023 HIGH

Buffer overflow in IBM i Access 7.1 on Windows allows local users to gain privileges via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm i_access 7.1
CVE-2015-2025 MEDIUM

IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_extreme_scale 7.1.0.2
ibm websphere_extreme_scale 7.1.0
ibm websphere_extreme_scale 7.1.1
CVE-2015-2026 MEDIUM

Cross-site request forgery (CSRF) vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm websphere_extreme_scale 7.1.0.2
ibm websphere_extreme_scale 7.1.0
ibm websphere_extreme_scale 7.1.1
CVE-2015-2027 LOW

IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 improperly performs logout actions, which allows remote attackers to bypass intended access restrictions by leveraging an unattended workstation.

CVSS 2.0

Severity: LOW

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_extreme_scale 7.1.0.2
ibm websphere_extreme_scale 7.1.0
ibm websphere_extreme_scale 7.1.1
CVE-2015-2028 MEDIUM

CRLF injection vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_extreme_scale 7.1.0.2
ibm websphere_extreme_scale 7.1.0
ibm websphere_extreme_scale 7.1.1
CVE-2015-2029 MEDIUM

Session fixation vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 allows remote attackers to hijack web sessions via a session identifier.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_extreme_scale 7.1.0.2
ibm websphere_extreme_scale 7.1.0
ibm websphere_extreme_scale 7.1.1
CVE-2015-2030 MEDIUM

IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 has an improper account-lockout setting, which makes it easier for remote attackers to obtain access via a brute-force attack.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_extreme_scale 7.1.0.2
ibm websphere_extreme_scale 7.1.0
ibm websphere_extreme_scale 7.1.1
CVE-2015-2031 LOW

Cross-site scripting (XSS) vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_extreme_scale 7.1.0.2
ibm websphere_extreme_scale 7.1.0
ibm websphere_extreme_scale 7.1.1
CVE-2015-2808 MEDIUM

The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial bytes of a stream by sniffing network traffic that occasionally relies on keys affected by the Invariance Weakness, and then using a brute-force approach involving LSB values, aka the "Bar Mitzvah" issue.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
134c704f-9b21-4f2e-91b3-4a467353bcc0 3.7 LOW CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N 2.2 1.4

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-327,CWE-327,

Products Affected

Vendor Product Version
oracle http_server 12.1.3.0.0
redhat enterprise_linux_workstation 7.0
suse linux_enterprise_software_development_kit 12
suse linux_enterprise_desktop 12
redhat enterprise_linux_server_aus 7.7
huawei 9700_firmware -
huawei s5700ei_firmware -
debian debian_linux 7.0
redhat enterprise_linux_workstation 6.0
huawei smc2.0 v100r002c03
redhat enterprise_linux_eus 7.1
huawei s5700hi_firmware -
huawei te60_firmware -
redhat enterprise_linux_eus 7.3
huawei oceanstor_9000_firmware -
canonical ubuntu_linux 15.04
suse linux_enterprise_server 10
huawei s5700si_firmware -
redhat enterprise_linux_desktop 6.0
oracle integrated_lights_out_manager_firmware *
redhat enterprise_linux_server_aus 7.3
canonical ubuntu_linux 12.04
canonical ubuntu_linux 14.04
redhat enterprise_linux_server_tus 7.7
huawei oceanstor_vis6600t_firmware -
fujitsu sparc_enterprise_m5000_firmware *
redhat enterprise_linux_workstation 5.0
huawei oceanstor_hvs85t_firmware -
redhat satellite 5.6
ibm cognos_metrics_manager 10.2
huawei oceanstor_18800_firmware -
huawei e6000_firmware -
huawei smc2.0 v100r002c02
redhat satellite 5.7
redhat enterprise_linux_eus 7.2
redhat enterprise_linux_eus 6.6
suse linux_enterprise_server 11
redhat enterprise_linux_desktop 7.0
huawei oceanstor_cse_firmware -
huawei s3700_firmware -
fujitsu sparc_enterprise_m4000_firmware *
redhat enterprise_linux_eus 7.5
oracle http_server 11.1.1.9.0
huawei oceanstor_18800f_firmware -
redhat enterprise_linux_server_aus 7.4
huawei oceanstor_s2600t_firmware -
redhat enterprise_linux_server_tus 7.6
huawei s2700_firmware -
suse linux_enterprise_debuginfo 11
suse linux_enterprise_desktop 11
ibm cognos_metrics_manager 10.1.1
huawei s2750_firmware -
huawei oceanstor_18500_firmware -
huawei e9000_firmware -
redhat enterprise_linux_server_tus 7.3
suse manager 1.7
opensuse opensuse 13.2
redhat enterprise_linux_eus 7.7
redhat enterprise_linux_server 7.0
huawei s5700li_firmware -
redhat enterprise_linux_server_aus 6.6
huawei policy_center v100r003c10
huawei ultravr v100r003c00
huawei oceanstor_s5500t_firmware -
oracle http_server 11.1.1.7.0
suse linux_enterprise_server 12
ibm cognos_metrics_manager 10.1
ibm cognos_metrics_manager 10.2.1
huawei oceanstor_s5600t_firmware -
ibm cognos_metrics_manager 10.2.2
redhat enterprise_linux_eus 7.6
huawei s6700_firmware -
debian debian_linux 8.0
opensuse opensuse 13.1
huawei s5700s-li_firmware -
redhat enterprise_linux_eus 7.4
suse linux_enterprise_software_development_kit 11
huawei oceanstor_s5800t_firmware -
huawei policy_center v100r003c00
oracle communications_policy_management *
huawei s12700_firmware -
huawei smc2.0 v100r002c04
huawei s5720ei_firmware -
redhat enterprise_linux_server 6.0
huawei smc2.0 v100r002c01
oracle communications_application_session_controller *
huawei s5710hi_firmware -
huawei oceanstor_replicationdirector v100r003c00
oracle http_server 12.2.1.1.0
oracle http_server 12.2.1.2.0
fujitsu sparc_enterprise_m8000_firmware *
huawei s5710ei_firmware -
redhat enterprise_linux_desktop 5.0
huawei oceanstor_s6800t_firmware -
fujitsu sparc_enterprise_m3000_firmware *
huawei s7700_firmware -
huawei s5720hi_firmware -
fujitsu sparc_enterprise_m9000_firmware *
huawei quidway_s9300_firmware -
redhat enterprise_linux_server 5.0
redhat enterprise_linux_server_aus 7.6
CVE-2015-3217 MEDIUM

PCRE 7.8 and 8.32 through 8.37, and PCRE2 10.10 mishandle group empty matches, which might allow remote attackers to cause a denial of service (stack-based buffer overflow) via a crafted regular expression, as demonstrated by /^(?:(?(1)\\.|([^\\\\W_])?)+)+$/.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
pcre pcre 8.33
pcre pcre 8.37
ibm powerkvm 3.1
pcre pcre2 10.10
pcre pcre 8.34
pcre pcre 7.8
pcre pcre 8.36
pcre pcre 8.32
pcre pcre 8.35
ibm powerkvm 2.1
CVE-2015-4000 MEDIUM

The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
134c704f-9b21-4f2e-91b3-4a467353bcc0 3.7 LOW CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N 2.2 1.4

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,CWE-295,

Products Affected

Vendor Product Version
microsoft internet_explorer -
debian debian_linux 8.0
mozilla seamonkey 2.35
oracle jre 1.7.0
oracle jdk 1.8.0
opera opera_browser -
mozilla firefox -
suse linux_enterprise_software_development_kit 12
oracle jdk 1.6.0
suse linux_enterprise_desktop 12
canonical ubuntu_linux 14.10
debian debian_linux 7.0
mozilla thunderbird 31.8
mozilla firefox 38.1.0
suse suse_linux_enterprise_server 12
mozilla firefox_esr 31.8
apple safari -
oracle jre 1.6.0
apple mac_os_x *
mozilla firefox 39.0
canonical ubuntu_linux 15.04
ibm content_manager 8.5
oracle jdk 1.7.0
openssl openssl *
canonical ubuntu_linux 12.04
apple iphone_os *
mozilla firefox_os 2.2
oracle sparc-opl_service_processor *
oracle jre 1.8.0
canonical ubuntu_linux 14.04
oracle jrockit r28.3.6
mozilla thunderbird 38.1
hp hp-ux b.11.31
suse linux_enterprise_server 11.0
google chrome -
mozilla network_security_services 3.19
CVE-2015-4927 HIGH

The Reporting and Monitoring component in Tivoli Monitoring in IBM Tivoli Storage Manager 6.3 before 6.3.6 and 7.1 before 7.1.3 on Linux and AIX uses world-writable permissions for unspecified files, which allows local users to gain privileges by writing to a file.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager 6.3.4
ibm tivoli_storage_manager 7.1.1
ibm tivoli_storage_manager 6.3.3
ibm tivoli_storage_manager 7.1.2
ibm tivoli_storage_manager 7.1
ibm tivoli_storage_manager 6.3.5
ibm tivoli_storage_manager 6.3.5.1
CVE-2015-4929 MEDIUM

IBM License Metric Tool 9 before 9.2.1.0 and Endpoint Manager for Software Use Analysis 9 before 9.2.1.0 allow remote authenticated users to bypass intended access restrictions and obtain sensitive information via a REST API request.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm license_metric_tool 9.2.0
ibm license_metric_tool 9.0
ibm license_metric_tool 9.1.0.1
ibm license_metric_tool 9.0.1
ibm license_metric_tool 9.1.0.2
CVE-2015-4930 HIGH

IBM QRadar SIEM 7.1 MR2 before Patch 11 IF02 and 7.2.x before 7.2.5 Patch 4 allows remote authenticated users to execute arbitrary commands with root privileges by leveraging admin access.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-77,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.2
ibm qradar_security_information_and_event_manager 7.2.0
ibm qradar_security_information_and_event_manager 7.1.0
ibm qradar_security_information_and_event_manager 7.2.3
ibm qradar_security_information_and_event_manager 7.2.4
ibm qradar_security_information_and_event_manager 7.2.1
CVE-2015-4931 HIGH

Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12.1 allows remote attackers to execute arbitrary code via a crafted packet, a different vulnerability than CVE-2015-4932, CVE-2015-4933, CVE-2015-4934, and CVE-2015-4935.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_fastback 6.1.10.0
ibm tivoli_storage_manager_fastback 6.1.11.1
ibm tivoli_storage_manager_fastback 6.1.0.0
ibm tivoli_storage_manager_fastback 6.1.9.0
ibm tivoli_storage_manager_fastback 6.1.8.1
ibm tivoli_storage_manager_fastback 6.1.7.2
ibm tivoli_storage_manager_fastback 6.1.8.0
ibm tivoli_storage_manager_fastback 6.1.11.0
ibm tivoli_storage_manager_fastback 6.1.10.1
ibm tivoli_storage_manager_fastback 6.1.1.0
ibm tivoli_storage_manager_fastback 6.1.9.1
CVE-2015-4932 HIGH

Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12.1 allows remote attackers to execute arbitrary code via a crafted packet, a different vulnerability than CVE-2015-4931, CVE-2015-4933, CVE-2015-4934, and CVE-2015-4935.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_fastback 6.1.10.0
ibm tivoli_storage_manager_fastback 6.1.11.1
ibm tivoli_storage_manager_fastback 6.1.0.0
ibm tivoli_storage_manager_fastback 6.1.9.0
ibm tivoli_storage_manager_fastback 6.1.8.1
ibm tivoli_storage_manager_fastback 6.1.7.2
ibm tivoli_storage_manager_fastback 6.1.8.0
ibm tivoli_storage_manager_fastback 6.1.11.0
ibm tivoli_storage_manager_fastback 6.1.10.1
ibm tivoli_storage_manager_fastback 6.1.1.0
ibm tivoli_storage_manager_fastback 6.1.9.1
CVE-2015-4933 HIGH

Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12.1 allows remote attackers to execute arbitrary code via a crafted packet, a different vulnerability than CVE-2015-4931, CVE-2015-4932, CVE-2015-4934, and CVE-2015-4935.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_fastback 6.1.10.0
ibm tivoli_storage_manager_fastback 6.1.11.1
ibm tivoli_storage_manager_fastback 6.1.0.0
ibm tivoli_storage_manager_fastback 6.1.9.0
ibm tivoli_storage_manager_fastback 6.1.8.1
ibm tivoli_storage_manager_fastback 6.1.7.2
ibm tivoli_storage_manager_fastback 6.1.8.0
ibm tivoli_storage_manager_fastback 6.1.11.0
ibm tivoli_storage_manager_fastback 6.1.10.1
ibm tivoli_storage_manager_fastback 6.1.1.0
ibm tivoli_storage_manager_fastback 6.1.9.1
CVE-2015-4934 HIGH

Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12.1 allows remote attackers to execute arbitrary code via a crafted packet, a different vulnerability than CVE-2015-4931, CVE-2015-4932, CVE-2015-4933, and CVE-2015-4935.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_fastback 6.1.10.0
ibm tivoli_storage_manager_fastback 6.1.11.1
ibm tivoli_storage_manager_fastback 6.1.0.0
ibm tivoli_storage_manager_fastback 6.1.9.0
ibm tivoli_storage_manager_fastback 6.1.8.1
ibm tivoli_storage_manager_fastback 6.1.7.2
ibm tivoli_storage_manager_fastback 6.1.8.0
ibm tivoli_storage_manager_fastback 6.1.11.0
ibm tivoli_storage_manager_fastback 6.1.10.1
ibm tivoli_storage_manager_fastback 6.1.1.0
ibm tivoli_storage_manager_fastback 6.1.9.1
CVE-2015-4935 HIGH

Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12.1 allows remote attackers to execute arbitrary code via a crafted packet, a different vulnerability than CVE-2015-4931, CVE-2015-4932, CVE-2015-4933, and CVE-2015-4934.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_fastback 6.1.10.0
ibm tivoli_storage_manager_fastback 6.1.11.1
ibm tivoli_storage_manager_fastback 6.1.0.0
ibm tivoli_storage_manager_fastback 6.1.9.0
ibm tivoli_storage_manager_fastback 6.1.8.1
ibm tivoli_storage_manager_fastback 6.1.7.2
ibm tivoli_storage_manager_fastback 6.1.8.0
ibm tivoli_storage_manager_fastback 6.1.11.0
ibm tivoli_storage_manager_fastback 6.1.10.1
ibm tivoli_storage_manager_fastback 6.1.1.0
ibm tivoli_storage_manager_fastback 6.1.9.1
CVE-2015-4936 MEDIUM

Unspecified vulnerability in IBM WebSphere eXtreme Scale 8.6 through 8.6.0.8 allows remote attackers to cause a denial of service via unknown vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_extreme_scale 8.6.0.1
ibm websphere_extreme_scale 8.6.0.5
ibm websphere_extreme_scale 8.6.0.7
ibm websphere_extreme_scale 8.6.0.8
ibm websphere_extreme_scale 8.6.0.4
ibm websphere_extreme_scale 8.6.0.6
ibm websphere_extreme_scale 8.6.0.3
ibm websphere_extreme_scale 8.6.0.2
ibm websphere_extreme_scale 8.6.0.0
CVE-2015-4938 MEDIUM

IBM WebSphere Application Server 7.x before 7.0.0.39, 8.0.x before 8.0.0.11, and 8.5.x before 8.5.5.7 allows remote attackers to spoof servlets and obtain sensitive information via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 7.0.0.36
ibm websphere_application_server 7.0.0.38
ibm websphere_application_server 7.0.0.12
ibm websphere_application_server 8.0.0.6
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 8.5.5.2
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 7.0.0.16
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 7.0.0.25
ibm websphere_application_server 8.0.0.9
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 7.0.0.14
ibm websphere_application_server 7.0.0.22
ibm websphere_application_server 7.0.0.31
ibm websphere_application_server 7.0.0.10
ibm websphere_application_server 8.5.5.5
ibm websphere_application_server 8.0.0.8
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 8.0.0.7
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 7.0.0.27
ibm websphere_application_server 7.0.0.18
ibm websphere_application_server 8.5.5.3
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 8.0.0.2
ibm websphere_application_server 8.0.0.5
ibm websphere_application_server 8.5.0.2
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 7.0.0.33
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 7.0.0.32
ibm websphere_application_server 7.0.0.29
ibm websphere_application_server 7.0.0.24
ibm websphere_application_server 8.5.5.0
ibm websphere_application_server 7.0.0.37
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 8.5.5.6
ibm websphere_application_server 8.0.0.10
ibm websphere_application_server 7.0.0.34
ibm websphere_application_server 8.5.5.4
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 8.5.5.1
ibm websphere_application_server 7.0.0.4
CVE-2015-4939 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Emptoris Supplier Lifecycle Management and Emptoris Program Management 10.x before 10.0.1.4_iFix3, 10.0.2.x before 10.0.2.7_iFix1, 10.0.3.x before 10.0.3.2, and 10.0.4.x before 10.0.4.0_iFix1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm emptoris_supplier_lifecycle_management 10.0.0.1
ibm emptoris_strategic_supply_management 10.0.2.0
ibm emptoris_strategic_supply_management 10.0.2.5
ibm emptoris_strategic_supply_management 10.0.0.0
ibm emptoris_strategic_supply_management 10.0.2.2
ibm emptoris_strategic_supply_management 10.0.2.4
ibm emptoris_strategic_supply_management 10.0.2.6
ibm emptoris_program_management 10.0.2.5
ibm emptoris_strategic_supply_management 10.0.1.3
ibm emptoris_supplier_lifecycle_management 10.0.0.2
ibm emptoris_strategic_supply_management 10.0.1.2
ibm emptoris_supplier_lifecycle_management 10.0.1.0
ibm emptoris_supplier_lifecycle_management 10.0.2.3
ibm emptoris_strategic_supply_management 10.0.1.4
ibm emptoris_program_management 10.0.0.1
ibm emptoris_strategic_supply_management 10.0.0.3
ibm emptoris_supplier_lifecycle_management 10.0.2.7
ibm emptoris_strategic_supply_management 10.0.0.1
ibm emptoris_program_management 10.0.1.1
ibm emptoris_program_management 10.0.2.2
ibm emptoris_supplier_lifecycle_management 10.0.1.1
ibm emptoris_strategic_supply_management 10.0.2.3
ibm emptoris_supplier_lifecycle_management 10.0.2.0
ibm emptoris_program_management 10.0.2.6
ibm emptoris_strategic_supply_management 10.0.1.0
ibm emptoris_supplier_lifecycle_management 10.0.0.3
ibm emptoris_strategic_supply_management 10.0.2.1
ibm emptoris_program_management 10.0.2.4
ibm emptoris_supplier_lifecycle_management 10.0.1.2
ibm emptoris_program_management 10.0.0.2
ibm emptoris_program_management 10.0.0.3
ibm emptoris_program_management 10.0.1.4
ibm emptoris_supplier_lifecycle_management 10.0.0.0
ibm emptoris_strategic_supply_management 10.0.0.2
ibm emptoris_strategic_supply_management 10.0.2.7
ibm emptoris_program_management 10.0.2.0
ibm emptoris_program_management 10.0.1.0
ibm emptoris_program_management 10.0.1.3
ibm emptoris_supplier_lifecycle_management 10.0.2.2
ibm emptoris_program_management 10.0.2.7
ibm emptoris_program_management 10.0.0.0
ibm emptoris_program_management 10.0.1.2
ibm emptoris_supplier_lifecycle_management 10.0.2.6
ibm emptoris_strategic_supply_management 10.0.1.1
ibm emptoris_program_management 10.0.2.3
ibm emptoris_supplier_lifecycle_management 10.0.2.5
CVE-2015-4941 MEDIUM

IBM WebSphere MQ Light 1.x before 1.0.2 mishandles abbreviated TLS handshakes, which allows remote attackers to cause a denial of service (MQXR service crash) via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-17,

Products Affected

Vendor Product Version
ibm websphere_mq_light 1.0.0.1
ibm websphere_mq_light 1.0
CVE-2015-4942 MEDIUM

IBM WebSphere MQ Light 1.x before 1.0.2 allows remote attackers to cause a denial of service (MQXR service crash) via a series of connect and disconnect actions, a different vulnerability than CVE-2015-4943.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm websphere_mq_light 1.0.0.1
ibm websphere_mq_light 1.0
CVE-2015-4943 MEDIUM

IBM WebSphere MQ Light 1.x before 1.0.2 allows remote attackers to cause a denial of service (MQXR service crash) via a series of connect and disconnect actions, a different vulnerability than CVE-2015-4942.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-17,

Products Affected

Vendor Product Version
ibm websphere_mq_light 1.0.0.1
ibm websphere_mq_light 1.0
CVE-2015-4944 LOW

Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX003, and 7.6.0 before 7.6.0.1 IFIX001; Maximo Asset Management 7.5.x before 7.5.0.8 IFIX003 and 7.6.0 before 7.6.0.1 IFIX001 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_asset_management_for_it 7.2
ibm maximo_for_life_sciences 7.5.0.2
ibm maximo_asset_management 7.1.1.9
ibm maximo_for_government 7.5.0.4
ibm tivoli_service_request_manager 7.2.0.0
ibm maximo_for_life_sciences 7.5.0.1
ibm maximo_for_government 7.1
ibm maximo_asset_management 7.1.1.13
ibm maximo_asset_management_essentials 7.5
ibm maximo_for_nuclear_power 7.5.0.4
ibm maximo_asset_management 7.1.1.10
ibm maximo_for_oil_and_gas 7.5.0.6
ibm maximo_asset_management 7.1.1.1
ibm maximo_for_nuclear_power 7.5.0.0
ibm maximo_for_oil_and_gas 7.5.0.5
ibm maximo_for_nuclear_power 7.5.0.1
ibm maximo_for_life_sciences 7.5.0.4
ibm maximo_for_nuclear_power 7.1
ibm maximo_for_transportation 7.5.0.1
ibm maximo_for_utilities 7.5.0.2
ibm maximo_for_nuclear_power 7.5.0.3
ibm maximo_for_government 7.5.0.1
ibm maximo_for_utilities 7.5.0.5
ibm maximo_for_life_sciences 7.1
ibm maximo_asset_management 7.5.0.6
ibm maximo_for_transportation 7.5.0.2
ibm maximo_for_nuclear_power 7.5.0.6
ibm maximo_for_transportation 7.5.0.4
ibm maximo_asset_management 7.1.1.7
ibm maximo_asset_management 7.5.0.7
ibm maximo_for_government 7.5.0.6
ibm maximo_for_utilities 7.5.0.3
ibm maximo_asset_management 7.5.0.5
ibm maximo_asset_management 7.1.1.2
ibm maximo_for_oil_and_gas 7.1
ibm maximo_asset_management 7.1.1.5
ibm maximo_asset_management 7.1.1.11
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
ibm maximo_asset_management 7.5.0.8
ibm maximo_for_nuclear_power 7.5.0.5
ibm maximo_for_transportation 7.5.0.6
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.5.0.1
ibm maximo_for_transportation 7.5.0.0
ibm maximo_for_life_sciences 7.5.0.0
ibm maximo_for_utilities 7.1
ibm maximo_for_oil_and_gas 7.5.0.2
ibm maximo_for_oil_and_gas 7.5.0.3
ibm maximo_for_government 7.5.0.0
ibm change_and_configuration_management_database 7.1
ibm maximo_asset_management 7.6.0.0
ibm maximo_asset_management 7.1.1.12
ibm change_and_configuration_management_database 7.2
ibm maximo_for_life_sciences 7.5.0.5
ibm tivoli_service_request_manager 7.1.0
ibm maximo_asset_management 7.5.0.3
ibm maximo_for_government 7.5.0.2
ibm maximo_for_oil_and_gas 7.5.0.1
ibm maximo_for_nuclear_power 7.5.0.2
ibm maximo_for_utilities 7.5.0.0
ibm maximo_for_life_sciences 7.5.0.3
ibm tivoli_asset_management_for_it 7.1
ibm maximo_for_government 7.5.0.5
ibm maximo_for_transportation 7.1
ibm maximo_for_utilities 7.5.0.6
ibm maximo_for_transportation 7.5.0.5
ibm maximo_asset_management_essentials 7.1
ibm maximo_asset_management 7.5.0.0
ibm maximo_for_oil_and_gas 7.5.0.4
ibm maximo_asset_management 7.5.0.4
ibm smartcloud_control_desk 7.5
ibm maximo_for_oil_and_gas 7.5.0.0
ibm maximo_for_life_sciences 7.5.0.6
ibm maximo_for_energy_optimization 7.1
ibm maximo_asset_management 7.1.1.6
ibm maximo_for_transportation 7.5.0.3
ibm maximo_for_utilities 7.5.0.1
ibm maximo_for_government 7.5.0.3
ibm maximo_for_utilities 7.5.0.4
CVE-2015-4945 MEDIUM

Unspecified vulnerability in the IBM Maximo Anywhere application 7.5.1 through 7.5.1.2 for Android allows attackers to bypass a passcode protection mechanism and obtain sensitive information via a crafted application.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm maximo_anywhere 7.5.1.0
ibm maximo_anywhere 7.5.1.1
ibm maximo_anywhere 7.5.1.2
CVE-2015-4946 LOW

Rational LifeCycle Project Administration in Jazz Team Server in IBM Rational Collaborative Lifecycle Management (CLM) 3.x and 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF9, and 6.x before 6.0.1; Rational Quality Manager (RQM) 3.x before 3.0.1.6 IF7, 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF9, and 6.x before 6.0.1; Rational Team Concert (RTC) 3.x before 3.0.1.6 IF7, 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF9, and 6.x before 6.0.1; Rational Requirements Composer (RRC) 3.x before 3.0.1.6 IF7 and 4.x before 4.0.7 IF9; Rational DOORS Next Generation (RDNG) 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF9, and 6.x before 6.0.1; Rational Engineering Lifecycle Manager (RELM) 4.x through 4.0.7, 5.x through 5.0.2, and 6.x before 6.0.1; Rational Rhapsody Design Manager (DM) 4.x through 4.0.7, 5.x through 5.0.2, and 6.x before 6.0.1; and Rational Software Architect Design Manager (DM) 4.x through 4.0.7, 5.x through 5.0.2, and 6.x before 6.0.1 allows local users to bypass intended access restrictions via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm rational_rhapsody_design_manager 4.0.4
ibm rational_rhapsody_design_manager 4.0.5
ibm rational_collaborative_lifecycle_management 4.0.6
ibm rational_engineering_lifecycle_manager 4.0.7
ibm rational_quality_manager 4.0.6
ibm rational_requirements_composer 3.0.1.4
ibm rational_requirements_composer 3.0.1.1
ibm rational_team_concert 5.0
ibm rational_requirements_composer 2.0
ibm rational_software_architect_design_manager 4.0.7
ibm rational_team_concert 2.0.0.2
ibm rational_quality_manager 2.0.1
ibm rational_engineering_lifecycle_manager 5.0.2
ibm rational_team_concert 2.0.0.1
ibm rational_rhapsody_design_manager 5.0.2
ibm rational_quality_manager 4.0.3
ibm rational_rhapsody_design_manager 3.0.0.1
ibm rational_team_concert 4.0.1
ibm rational_team_concert 4.0.5
ibm rational_doors_next_generation 5.0
ibm rational_team_concert 4.0.2
ibm rational_quality_manager 5.0
ibm rational_collaborative_lifecycle_management 4.0.5
ibm rational_collaborative_lifecycle_management 4.0.7
ibm rational_collaborative_lifecycle_management 4.0.3
ibm rational_requirements_composer 2.0.0.1
ibm rational_software_architect_design_manager 4.0.6
ibm rational_doors_next_generation 4.0.7
ibm rational_doors_next_generation 4.0.2
ibm rational_team_concert 3.0.1.4
ibm rational_requirements_composer 4.0
ibm rational_team_concert 3.0.1.1
ibm rational_requirements_composer 3.0
ibm rational_rhapsody_design_manager 4.0.7
ibm rational_requirements_composer 4.0.4
ibm rational_engineering_lifecycle_manager 5.0
ibm rational_team_concert 5.0.2
ibm rational_requirements_composer 4.0.1
ibm rational_requirements_composer 3.0.1.2
ibm rational_requirements_composer 4.0.7
ibm rational_collaborative_lifecycle_management 4.0.1
ibm rational_rhapsody_design_manager 5.0
ibm rational_team_concert 4.0.3
ibm rational_quality_manager 3.0.1.3
ibm rational_team_concert 3.0.1
ibm rational_collaborative_lifecycle_management 4.0.2
ibm rational_quality_manager 3.0
ibm rational_requirements_composer 2.0.0.2
ibm rational_quality_manager 2.0
ibm rational_quality_manager 4.0.1
ibm rational_team_concert 4.0.6
ibm rational_engineering_lifecycle_manager 1.0.0.1
ibm rational_quality_manager 3.0.1.2
ibm rational_engineering_lifecycle_manager 4.0.5
ibm rational_requirements_composer 4.0.2
ibm rational_software_architect_design_manager 5.0.2
ibm rational_requirements_composer 4.0.3
ibm rational_doors_next_generation 4.0.4
ibm rational_quality_manager 3.0.1.4
ibm rational_quality_manager 4.0.4
ibm rational_engineering_lifecycle_manager 4.0.6
ibm rational_rhapsody_design_manager 4.0.3
ibm rational_doors_next_generation 5.0.2
ibm rational_quality_manager 4.0.2
ibm rational_doors_next_generation 4.0
ibm rational_requirements_composer 4.0.0.2
ibm rational_requirements_composer 4.0.5
ibm rational_doors_next_generation 5.0.1
ibm rational_software_architect_design_manager 4.0.1
ibm rational_team_concert 3.0.1.6
ibm rational_collaborative_lifecycle_management 4.0.4
ibm rational_software_architect_design_manager 3.0.0.1
ibm rational_team_concert 4.0.0.1
ibm rational_software_architect_design_manager 3.0.1
ibm rational_engineering_lifecycle_manager 4.0.3
ibm rational_engineering_lifecycle_manager 4.0.4
ibm rational_software_architect_design_manager 4.0.2
ibm rational_quality_manager 4.0.0.1
ibm rational_quality_manager 4.0.0.2
ibm rational_rhapsody_design_manager 6.0
ibm rational_quality_manager 4.0.7
ibm rational_requirements_composer 3.0.1.6
ibm rational_rhapsody_design_manager 4.0.6
ibm rational_engineering_lifecycle_manager 1.0
ibm rational_requirements_composer 4.0.6
ibm rational_software_architect_design_manager 5.0
ibm rational_software_architect_design_manager 4.0.4
ibm rational_doors_next_generation 4.0.1
ibm rational_engineering_lifecycle_manager 5.0.1
ibm rational_quality_manager 3.0.1.5
ibm rational_team_concert 4.0.7
ibm rational_team_concert 3.0.1.2
ibm rational_software_architect_design_manager 4.0.3
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_quality_manager 5.0.2
ibm rational_requirements_composer 2.0.0.3
ibm rational_rhapsody_design_manager 4.0.1
ibm rational_rhapsody_design_manager 4.0.2
ibm rational_team_concert 4.0.0.2
ibm rational_rhapsody_design_manager 3.0.1
ibm rational_rhapsody_design_manager 4.0
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_requirements_composer 3.0.1
ibm rational_requirements_composer 3.0.1.3
ibm rational_software_architect_design_manager 3.0
ibm rational_quality_manager 3.0.1.6
ibm rational_team_concert 2.0
ibm rational_rhapsody_design_manager 5.0.1
ibm rational_quality_manager 3.0.1.1
ibm rational_team_concert 4.0
ibm rational_doors_next_generation 4.0.5
ibm rational_requirements_composer 4.0.0.1
ibm rational_doors_next_generation 4.0.6
ibm rational_team_concert 3.0
ibm rational_doors_next_generation 4.0.3
ibm rational_quality_manager 5.0.1
ibm rational_requirements_composer 2.0.0.4
ibm rational_quality_manager 4.0
ibm rational_collaborative_lifecycle_management 5.0
ibm rational_collaborative_lifecycle_management 3.0.1
ibm rational_requirements_composer 3.0.1.5
ibm rational_team_concert 3.0.1.5
ibm rational_team_concert 3.0.1.3
ibm rational_quality_manager 3.0.1
ibm rational_rhapsody_design_manager 3.0
ibm rational_software_architect_design_manager 4.0.5
ibm rational_team_concert 4.0.4
ibm rational_software_architect_design_manager 5.0.1
ibm rational_software_architect_design_manager 4.0
ibm rational_quality_manager 4.0.5
ibm rational_team_concert 5.0.1
CVE-2015-4947 HIGH

Stack-based buffer overflow in the Administration Server in IBM HTTP Server 6.1.0.x through 6.1.0.47, 7.0.0.x before 7.0.0.39, 8.0.0.x before 8.0.0.12, and 8.5.x before 8.5.5.7, as used in WebSphere Application Server and other products, allows remote authenticated users to execute arbitrary code via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm http_server *
CVE-2015-4948 MEDIUM

netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows local users to gain privileges via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm vios 2.2.0
ibm vios 2.2.1
ibm aix 5.3
ibm aix 6.1
ibm vios 2.2.3
ibm vios 2.2.2
ibm aix 7.1
CVE-2015-4949 LOW

IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server 7.1 before 7.1.2, Tivoli Storage Manager for Mail: Data Protection for Microsoft Exchange Server 7.1 before 7.1.2, and Tivoli Storage FlashCopy Manager 4.1 before 4.1.2 place cleartext passwords in exception messages, which allows physically proximate attackers to obtain sensitive information by reading GUI pop-up windows, a different vulnerability than CVE-2015-6557.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server 7.1
ibm tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server 7.1
ibm tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server 7.2
ibm tivoli_storage_flashcopy_manager 4.1.0
ibm tivoli_storage_flashcopy_manager 4.1.2
ibm tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server 7.2
CVE-2015-4950 MEDIUM

The mailbox-restore feature in IBM Tivoli Storage Manager for Mail: Data Protection for Microsoft Exchange Server 6.1 before 6.1.3.6, 6.3 before 6.3.1.3, 6.4 before 6.4.1.4, and 7.1 before 7.1.0.2; Tivoli Storage FlashCopy Manager: FlashCopy Manager for Microsoft Exchange Server 2.1, 2.2, 3.1 before 3.1.1.5, 3.2 before 3.2.1.7, and 4.1 before 4.1.1; and Tivoli Storage Manager FastBack for Microsoft Exchange 6.1 before 6.1.5.4 does not ensure that the correct mailbox is selected, which allows remote authenticated users to obtain sensitive information via a duplicate alias name.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server 7.1
ibm tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server 6.3.1
ibm tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server 6.4
ibm tivoli_storage_flashcopy_manager_for_microsoft_exchange_server 2.2
ibm tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server 6.1.1
ibm tivoli_storage_flashcopy_manager_for_microsoft_exchange_server 4.1
ibm tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server 6.1
ibm tivoli_storage_fastback_for_microsoft_exchange 6.1
ibm tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server 6.3
ibm tivoli_storage_flashcopy_manager_for_microsoft_exchange_server 3.1
ibm tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server 6.1.2
ibm tivoli_storage_flashcopy_manager_for_microsoft_exchange_server 2.1
ibm tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server 6.1.3
ibm tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server 6.4.1
ibm tivoli_storage_flashcopy_manager_for_microsoft_exchange_server 3.2
CVE-2015-4951 MEDIUM

Client Acceptor Daemon (CAD) in the client in IBM Spectrum Protect (formerly Tivoli Storage Manager) 5.5 and 6.x before 6.3.2.5, 6.4 before 6.4.3.1, and 7.1 before 7.1.3 allows remote attackers to cause a denial of service (daemon crash) via a crafted Web client URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager 6.3
ibm tivoli_storage_manager 6.2
ibm tivoli_storage_manager 5.5
ibm tivoli_storage_manager 7.1
ibm tivoli_storage_manager 6.1
ibm tivoli_storage_manager 6.4
CVE-2015-4952 MEDIUM

The on-demand plugin in IBM Endpoint Manager for Remote Control 9.0.1 and 9.1.0 allows user-assisted remote attackers to execute arbitrary code via unspecified vectors. IBM X-Force ID: 105196.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm endpoint_manager_for_remote_control 9.1.0
ibm endpoint_manager_for_remote_control 9.0.1
CVE-2015-4953 MEDIUM

IBM BigFix Remote Control before Interim Fix pack 9.1.2-TIV-IBRC912-IF0001 makes it easier for man-in-the-middle attackers to decrypt traffic by leveraging a weakness in its encryption protocol. IBM X-Force ID: 105197.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-326,

Products Affected

Vendor Product Version
ibm bigfix_remote_control 9.1.2
CVE-2015-4954 MEDIUM

IBM BigFix Remote Control before Interim Fix pack 9.1.2-TIV-IBRC912-IF0001 improperly allows self-signed certificates, which might allow remote attackers to conduct spoofing attacks via unspecified vectors. IBM X-Force ID: 105200.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-295,

Products Affected

Vendor Product Version
ibm bigfix_remote_control 9.1.2
CVE-2015-4955 LOW

Cross-site scripting (XSS) vulnerability in IBM Business Process Manager (BPM) 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, 8.5.5 through 8.5.5.0, and 8.5.6 before 8.5.6.0 CF1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm business_process_manager 8.0.1.2
ibm business_process_manager 8.5.6.0
ibm business_process_manager 8.0.1.1
ibm business_process_manager 8.5.5.0
ibm business_process_manager 8.0.1.0
ibm business_process_manager 8.0.0.0
ibm business_process_manager 8.5.0.1
ibm business_process_manager 8.0.1.3
ibm business_process_manager 8.5.0.0
CVE-2015-4956 MEDIUM

The Web UI in IBM Security QRadar SIEM 7.1.x before 7.1 MR2 Patch 12 allows remote authenticated users to execute unspecified OS commands via unknown vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-78,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.1.0
CVE-2015-4957 LOW

Cross-site scripting (XSS) vulnerability in the Web UI in IBM Security QRadar SIEM 7.1.x before 7.1 MR2 Patch 12 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.1.0
CVE-2015-4958 LOW

IBM InfoSphere Master Data Management - Collaborative Edition 9.1, 10.1, 11.0 before 11.0.0.0 IF11, 11.3 before 11.3.0.0 IF7, and 11.4 before 11.4.0.4 IF1 does not properly restrict browser caching, which allows local users to obtain sensitive information by reading cache files.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm infosphere_master_data_management 11.0
ibm infosphere_master_data_management 9.1
ibm infosphere_master_data_management 11.4
ibm infosphere_master_data_management 10.1
ibm infosphere_master_data_management 11.3
CVE-2015-4959 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Tivoli Federated Identity Manager (TFIM) 6.2.2 before FP16 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_federated_identity_manager 6.2.2
CVE-2015-4960 LOW

IBM InfoSphere Master Data Management - Collaborative Edition 9.1, 10.1, 11.0 before 11.0.0.0 IF11, 11.3 before 11.3.0.0 IF7, and 11.4 before 11.4.0.4 IF1 allows remote authenticated users to conduct clickjacking attacks via a crafted web site.

CVSS 2.0

Severity: LOW

Problem Type: CWE-254,

Products Affected

Vendor Product Version
ibm infosphere_master_data_management 11.0
ibm infosphere_master_data_management 9.1
ibm infosphere_master_data_management 11.4
ibm infosphere_master_data_management 10.1
ibm infosphere_master_data_management 11.3
CVE-2015-4961 LOW

IBM Tealeaf Customer Experience 8.x before 8.7.1.8847 FP10, 8.8.x before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108 FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A before 9.0.2.5224 FP3 does not encrypt connections between internal servers, which allows remote attackers to obtain sensitive information by sniffing the network for HTTP traffic.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm tealeaf_customer_experience *
ibm tealeaf_customer_experience 8.8
ibm tealeaf_customer_experience 9.0.0a
ibm tealeaf_customer_experience 9.0.1
ibm tealeaf_customer_experience 9.0.1a
ibm tealeaf_customer_experience 8.7
ibm tealeaf_customer_experience 9.0.0
ibm tealeaf_customer_experience 9.0.2a
ibm tealeaf_customer_experience 9.0.2
CVE-2015-4962 LOW

Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.x and 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF9, and 6.x before 6.0.1; Rational Quality Manager (RQM) 3.x before 3.0.1.6 IF7, 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF9, and 6.x before 6.0.1; Rational Team Concert (RTC) 3.x before 3.0.1.6 IF7, 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF9, and 6.x before 6.0.1; Rational Requirements Composer (RRC) 3.x before 3.0.1.6 IF7 and 4.x before 4.0.7 IF9; Rational DOORS Next Generation (RDNG) 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF9, and 6.x before 6.0.1; Rational Engineering Lifecycle Manager (RELM) 4.x through 4.0.7, 5.x through 5.0.2, and 6.x before 6.0.1; Rational Rhapsody Design Manager (DM) 4.x through 4.0.7, 5.x through 5.0.2, and 6.x before 6.0.1; and Rational Software Architect Design Manager (DM) 4.x through 4.0.7, 5.x through 5.0.2, and 6.x before 6.0.1 uses weak permissions for unspecified project areas, which allows remote authenticated users to obtain sensitive information via unknown vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_rhapsody_design_manager 4.0.4
ibm rational_rhapsody_design_manager 4.0.5
ibm rational_collaborative_lifecycle_management 4.0.6
ibm rational_engineering_lifecycle_manager 4.0.7
ibm rational_quality_manager 4.0.6
ibm rational_requirements_composer 3.0.1.4
ibm rational_requirements_composer 3.0.1.1
ibm rational_team_concert 5.0
ibm rational_requirements_composer 2.0
ibm rational_software_architect_design_manager 4.0.7
ibm rational_team_concert 2.0.0.2
ibm rational_quality_manager 2.0.1
ibm rational_engineering_lifecycle_manager 5.0.2
ibm rational_team_concert 2.0.0.1
ibm rational_rhapsody_design_manager 5.0.2
ibm rational_quality_manager 4.0.3
ibm rational_rhapsody_design_manager 3.0.0.1
ibm rational_team_concert 4.0.1
ibm rational_team_concert 4.0.5
ibm rational_doors_next_generation 5.0
ibm rational_team_concert 4.0.2
ibm rational_quality_manager 5.0
ibm rational_collaborative_lifecycle_management 4.0.5
ibm rational_collaborative_lifecycle_management 4.0.7
ibm rational_collaborative_lifecycle_management 4.0.3
ibm rational_requirements_composer 2.0.0.1
ibm rational_software_architect_design_manager 4.0.6
ibm rational_doors_next_generation 4.0.7
ibm rational_doors_next_generation 4.0.2
ibm rational_team_concert 3.0.1.4
ibm rational_requirements_composer 4.0
ibm rational_team_concert 3.0.1.1
ibm rational_requirements_composer 3.0
ibm rational_rhapsody_design_manager 4.0.7
ibm rational_requirements_composer 4.0.4
ibm rational_engineering_lifecycle_manager 5.0
ibm rational_team_concert 5.0.2
ibm rational_requirements_composer 4.0.1
ibm rational_requirements_composer 3.0.1.2
ibm rational_requirements_composer 4.0.7
ibm rational_collaborative_lifecycle_management 4.0.1
ibm rational_rhapsody_design_manager 5.0
ibm rational_team_concert 4.0.3
ibm rational_quality_manager 3.0.1.3
ibm rational_team_concert 3.0.1
ibm rational_collaborative_lifecycle_management 4.0.2
ibm rational_quality_manager 3.0
ibm rational_requirements_composer 2.0.0.2
ibm rational_quality_manager 2.0
ibm rational_quality_manager 4.0.1
ibm rational_team_concert 4.0.6
ibm rational_engineering_lifecycle_manager 1.0.0.1
ibm rational_quality_manager 3.0.1.2
ibm rational_engineering_lifecycle_manager 4.0.5
ibm rational_requirements_composer 4.0.2
ibm rational_software_architect_design_manager 5.0.2
ibm rational_requirements_composer 4.0.3
ibm rational_doors_next_generation 4.0.4
ibm rational_quality_manager 3.0.1.4
ibm rational_quality_manager 4.0.4
ibm rational_engineering_lifecycle_manager 4.0.6
ibm rational_rhapsody_design_manager 4.0.3
ibm rational_doors_next_generation 5.0.2
ibm rational_quality_manager 4.0.2
ibm rational_doors_next_generation 4.0
ibm rational_requirements_composer 4.0.0.2
ibm rational_requirements_composer 4.0.5
ibm rational_doors_next_generation 5.0.1
ibm rational_software_architect_design_manager 4.0.1
ibm rational_team_concert 3.0.1.6
ibm rational_collaborative_lifecycle_management 4.0.4
ibm rational_software_architect_design_manager 3.0.0.1
ibm rational_team_concert 4.0.0.1
ibm rational_software_architect_design_manager 3.0.1
ibm rational_engineering_lifecycle_manager 4.0.3
ibm rational_engineering_lifecycle_manager 4.0.4
ibm rational_software_architect_design_manager 4.0.2
ibm rational_quality_manager 4.0.0.1
ibm rational_quality_manager 4.0.0.2
ibm rational_rhapsody_design_manager 6.0
ibm rational_quality_manager 4.0.7
ibm rational_requirements_composer 3.0.1.6
ibm rational_rhapsody_design_manager 4.0.6
ibm rational_engineering_lifecycle_manager 1.0
ibm rational_requirements_composer 4.0.6
ibm rational_software_architect_design_manager 5.0
ibm rational_software_architect_design_manager 4.0.4
ibm rational_doors_next_generation 4.0.1
ibm rational_engineering_lifecycle_manager 5.0.1
ibm rational_quality_manager 3.0.1.5
ibm rational_team_concert 4.0.7
ibm rational_team_concert 3.0.1.2
ibm rational_software_architect_design_manager 4.0.3
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_quality_manager 5.0.2
ibm rational_requirements_composer 2.0.0.3
ibm rational_rhapsody_design_manager 4.0.1
ibm rational_rhapsody_design_manager 4.0.2
ibm rational_team_concert 4.0.0.2
ibm rational_rhapsody_design_manager 3.0.1
ibm rational_rhapsody_design_manager 4.0
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_requirements_composer 3.0.1
ibm rational_requirements_composer 3.0.1.3
ibm rational_software_architect_design_manager 3.0
ibm rational_quality_manager 3.0.1.6
ibm rational_team_concert 2.0
ibm rational_rhapsody_design_manager 5.0.1
ibm rational_quality_manager 3.0.1.1
ibm rational_team_concert 4.0
ibm rational_doors_next_generation 4.0.5
ibm rational_requirements_composer 4.0.0.1
ibm rational_doors_next_generation 4.0.6
ibm rational_team_concert 3.0
ibm rational_doors_next_generation 4.0.3
ibm rational_quality_manager 5.0.1
ibm rational_requirements_composer 2.0.0.4
ibm rational_quality_manager 4.0
ibm rational_collaborative_lifecycle_management 5.0
ibm rational_collaborative_lifecycle_management 3.0.1
ibm rational_requirements_composer 3.0.1.5
ibm rational_team_concert 3.0.1.5
ibm rational_team_concert 3.0.1.3
ibm rational_quality_manager 3.0.1
ibm rational_rhapsody_design_manager 3.0
ibm rational_software_architect_design_manager 4.0.5
ibm rational_team_concert 4.0.4
ibm rational_software_architect_design_manager 5.0.1
ibm rational_software_architect_design_manager 4.0
ibm rational_quality_manager 4.0.5
ibm rational_team_concert 5.0.1
CVE-2015-4963 HIGH

IBM Security Access Manager for Web 7.x before 7.0.0.16 and 8.x before 8.0.1.3 mishandles WebSEAL HTTPTransformation requests, which allows remote attackers to read or write to arbitrary files via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-17,

Products Affected

Vendor Product Version
ibm security_access_manager_for_web 7.0.0.9
ibm security_access_manager_for_web 7.0.0.15
ibm security_access_manager_for_web 7.0.0.7
ibm security_access_manager_for_web 8.0.0.2
ibm security_access_manager_for_web 8.0.1.0
ibm security_access_manager_for_web 7.0.0.8
ibm security_access_manager_for_web 8.0.0.31
ibm security_access_manager_for_web 7.0
ibm security_access_manager_for_web 8.0.0.4
ibm security_access_manager_for_web 7.0.0.5
ibm security_access_manager_for_web 7.0.0.6
ibm security_access_manager_for_web 8.0.0.5
ibm security_access_manager_for_web 7.0.0.14
ibm security_access_manager_for_web 7.0.0.13
ibm security_access_manager_for_web 8.0.0.22
ibm security_access_manager_for_web 8.0.1.2
ibm security_access_manager_for_web 7.0.0.10
ibm security_access_manager_for_web 7.0.0.3
ibm security_access_manager_for_web 8.0.1.1
ibm security_access_manager_for_web 7.0.0.2
ibm security_access_manager_for_web 7.0.0.4
ibm security_access_manager_for_web 7.0.0.1
ibm security_access_manager_for_web 8.0.0.3
ibm security_access_manager_for_web 7.0.0.12
ibm security_access_manager_for_web 8.0
ibm security_access_manager_for_web 7.0.0.11
CVE-2015-4964 MEDIUM

IBM UrbanCode Deploy 6.0 and 6.0.1.x before 6.0.1.10, 6.1.1.x before 6.1.1.8, and 6.1.2 writes admin AUTH_TOKEN values to execution logs, which allows remote authenticated users to gain privileges by leveraging the ability to create and execute a process.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm urbancode_deploy 6.0.1.3
ibm urbancode_deploy 6.0.1.4
ibm urbancode_deploy 6.1.2
ibm urbancode_deploy 6.0.1.7
ibm urbancode_deploy 6.1.1.1
ibm urbancode_deploy 6.1.1.2
ibm urbancode_deploy 6.0.1.6
ibm urbancode_deploy 6.0.1.8
ibm urbancode_deploy 6.1.1.5
ibm urbancode_deploy 6.0.1.0
ibm urbancode_deploy 6.0.1.9
ibm urbancode_deploy 6.1.1.3
ibm urbancode_deploy 6.0.1.2
ibm urbancode_deploy 6.0.1.5
ibm urbancode_deploy 6.1.1.6
ibm urbancode_deploy 6.1.1.7
ibm urbancode_deploy 6.1.1.0
ibm urbancode_deploy 6.1.1.4
ibm urbancode_deploy 6.0.1.1
ibm urbancode_deploy 6.0
CVE-2015-4965 MEDIUM

maximouiweb/webmodule/webclient/utility/merlin.jsp in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX004, and 7.6.0 before 7.6.0.1 IFIX002; Maximo Asset Management 7.5.x before 7.5.0.8 IFIX004 and 7.6.0 before 7.6.0.1 IFIX002 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products allows remote authenticated users to obtain sensitive information by reading a (1) backup or (2) debug application file.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm tivoli_asset_management_for_it 7.2
ibm maximo_for_life_sciences 7.5.0.2
ibm maximo_asset_management 7.1.1.9
ibm maximo_for_government 7.5.0.4
ibm tivoli_service_request_manager 7.2.0.0
ibm maximo_for_life_sciences 7.5.0.1
ibm maximo_for_government 7.1
ibm maximo_asset_management 7.1.1.13
ibm maximo_asset_management_essentials 7.5
ibm maximo_for_nuclear_power 7.5.0.4
ibm maximo_asset_management 7.1.1.10
ibm maximo_for_oil_and_gas 7.5.0.6
ibm maximo_asset_management 7.1.1.1
ibm maximo_for_nuclear_power 7.5.0.0
ibm maximo_for_oil_and_gas 7.5.0.5
ibm maximo_for_nuclear_power 7.5.0.1
ibm maximo_for_life_sciences 7.5.0.4
ibm maximo_for_nuclear_power 7.1
ibm maximo_for_transportation 7.5.0.1
ibm maximo_for_utilities 7.5.0.2
ibm maximo_for_nuclear_power 7.5.0.3
ibm maximo_for_government 7.5.0.1
ibm maximo_for_utilities 7.5.0.5
ibm maximo_for_life_sciences 7.1
ibm maximo_asset_management 7.5.0.6
ibm maximo_for_transportation 7.5.0.2
ibm maximo_for_nuclear_power 7.5.0.6
ibm maximo_for_transportation 7.5.0.4
ibm maximo_asset_management 7.1.1.7
ibm maximo_asset_management 7.5.0.7
ibm maximo_for_government 7.5.0.6
ibm maximo_for_utilities 7.5.0.3
ibm maximo_asset_management 7.5.0.5
ibm maximo_asset_management 7.1.1.2
ibm maximo_for_oil_and_gas 7.1
ibm maximo_asset_management 7.1.1.5
ibm maximo_asset_management 7.1.1.11
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
ibm maximo_asset_management 7.5.0.8
ibm maximo_for_nuclear_power 7.5.0.5
ibm maximo_for_transportation 7.5.0.6
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.5.0.1
ibm maximo_for_transportation 7.5.0.0
ibm maximo_for_life_sciences 7.5.0.0
ibm maximo_for_utilities 7.1
ibm maximo_for_oil_and_gas 7.5.0.2
ibm maximo_for_oil_and_gas 7.5.0.3
ibm maximo_for_government 7.5.0.0
ibm change_and_configuration_management_database 7.1
ibm maximo_asset_management 7.6.0.0
ibm maximo_asset_management 7.1.1.12
ibm change_and_configuration_management_database 7.2
ibm maximo_for_life_sciences 7.5.0.5
ibm tivoli_service_request_manager 7.1.0
ibm maximo_asset_management 7.5.0.3
ibm maximo_for_government 7.5.0.2
ibm maximo_for_oil_and_gas 7.5.0.1
ibm maximo_for_nuclear_power 7.5.0.2
ibm maximo_for_utilities 7.5.0.0
ibm maximo_for_life_sciences 7.5.0.3
ibm tivoli_asset_management_for_it 7.1
ibm maximo_for_government 7.5.0.5
ibm maximo_for_transportation 7.1
ibm maximo_for_utilities 7.5.0.6
ibm maximo_for_transportation 7.5.0.5
ibm maximo_asset_management_essentials 7.1
ibm maximo_asset_management 7.5.0.0
ibm maximo_for_oil_and_gas 7.5.0.4
ibm maximo_asset_management 7.5.0.4
ibm smartcloud_control_desk 7.5
ibm maximo_for_oil_and_gas 7.5.0.0
ibm maximo_for_life_sciences 7.5.0.6
ibm maximo_for_energy_optimization 7.1
ibm maximo_asset_management 7.1.1.6
ibm maximo_for_transportation 7.5.0.3
ibm maximo_for_utilities 7.5.0.1
ibm maximo_for_government 7.5.0.3
ibm maximo_for_utilities 7.5.0.4
CVE-2015-4966 MEDIUM

IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.9 FP009, and 7.6.0 before 7.6.0.2 IFIX001; Maximo Asset Management 7.5.0 before 7.5.0.9 FP009, 7.5.1, and 7.6.0 before 7.6.0.2 IFIX001 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products have a default administrator account, which makes it easier for remote authenticated users to obtain access via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm tivoli_asset_management_for_it 7.2
ibm maximo_for_life_sciences 7.5.0.2
ibm maximo_asset_management 7.1.1.9
ibm maximo_for_government 7.5.0.4
ibm tivoli_service_request_manager 7.2.0.0
ibm maximo_for_life_sciences 7.5.0.1
ibm maximo_for_government 7.1
ibm maximo_asset_management 7.1.1.13
ibm maximo_for_nuclear_power 7.5.0.4
ibm maximo_asset_management 7.1.1.10
ibm maximo_for_oil_and_gas 7.5.0.6
ibm maximo_asset_management 7.1.1.1
ibm maximo_for_nuclear_power 7.5.0.0
ibm maximo_for_oil_and_gas 7.5.0.5
ibm maximo_for_nuclear_power 7.5.0.1
ibm maximo_for_life_sciences 7.5.0.4
ibm maximo_for_nuclear_power 7.1
ibm maximo_for_transportation 7.5.0.1
ibm maximo_for_utilities 7.5.0.2
ibm maximo_for_nuclear_power 7.5.0.3
ibm maximo_for_government 7.5.0.1
ibm maximo_for_utilities 7.5.0.5
ibm maximo_asset_management 7.5.0.9
ibm maximo_for_life_sciences 7.1
ibm maximo_asset_management 7.5.0.6
ibm maximo_for_transportation 7.5.0.2
ibm maximo_for_nuclear_power 7.5.0.6
ibm maximo_for_transportation 7.5.0.4
ibm maximo_asset_management 7.1.1.7
ibm maximo_asset_management 7.5.0.7
ibm maximo_for_government 7.5.0.6
ibm maximo_for_utilities 7.5.0.3
ibm maximo_asset_management 7.5.0.5
ibm maximo_asset_management 7.1.1.2
ibm maximo_for_oil_and_gas 7.1
ibm maximo_asset_management 7.1.1.5
ibm maximo_asset_management 7.1.1.11
ibm maximo_asset_management 7.6.0.1
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
ibm maximo_asset_management 7.5.0.8
ibm maximo_for_nuclear_power 7.5.0.5
ibm maximo_for_transportation 7.5.0.6
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.5.0.1
ibm maximo_for_transportation 7.5.0.0
ibm smartcloud_control_desk 7.6
ibm maximo_for_life_sciences 7.5.0.0
ibm maximo_for_utilities 7.1
ibm maximo_for_oil_and_gas 7.5.0.2
ibm maximo_for_oil_and_gas 7.5.0.3
ibm maximo_for_government 7.5.0.0
ibm change_and_configuration_management_database 7.1
ibm maximo_asset_management 7.6.0.0
ibm maximo_asset_management 7.1.1.12
ibm change_and_configuration_management_database 7.2
ibm maximo_for_life_sciences 7.5.0.5
ibm tivoli_service_request_manager 7.1.0
ibm maximo_asset_management 7.5.0.3
ibm maximo_asset_management 7.6.0.2
ibm maximo_for_government 7.5.0.2
ibm maximo_for_oil_and_gas 7.5.0.1
ibm maximo_for_nuclear_power 7.5.0.2
ibm maximo_for_utilities 7.5.0.0
ibm maximo_for_life_sciences 7.5.0.3
ibm tivoli_asset_management_for_it 7.1
ibm maximo_for_government 7.5.0.5
ibm maximo_for_transportation 7.1
ibm maximo_for_utilities 7.5.0.6
ibm maximo_for_transportation 7.5.0.5
ibm maximo_asset_management 7.5.0.0
ibm maximo_for_oil_and_gas 7.5.0.4
ibm maximo_asset_management 7.5.0.4
ibm smartcloud_control_desk 7.5
ibm maximo_for_oil_and_gas 7.5.0.0
ibm maximo_for_life_sciences 7.5.0.6
ibm maximo_asset_management 7.1.1.6
ibm maximo_for_transportation 7.5.0.3
ibm maximo_for_utilities 7.5.0.1
ibm maximo_for_government 7.5.0.3
ibm maximo_for_utilities 7.5.0.4
CVE-2015-4967 MEDIUM

SQL injection vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX004, and 7.6.0 before 7.6.0.1 IFIX002; Maximo Asset Management 7.5.x before 7.5.0.8 IFIX004 and 7.6.0 before 7.6.0.1 IFIX002 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm tivoli_asset_management_for_it 7.2
ibm maximo_for_life_sciences 7.5.0.2
ibm maximo_asset_management 7.1.1.9
ibm maximo_for_government 7.5.0.4
ibm tivoli_service_request_manager 7.2.0.0
ibm maximo_for_life_sciences 7.5.0.1
ibm maximo_for_government 7.1
ibm maximo_asset_management 7.1.1.13
ibm maximo_asset_management_essentials 7.5
ibm maximo_for_nuclear_power 7.5.0.4
ibm maximo_asset_management 7.1.1.10
ibm maximo_for_oil_and_gas 7.5.0.6
ibm maximo_asset_management 7.1.1.1
ibm maximo_for_nuclear_power 7.5.0.0
ibm maximo_for_oil_and_gas 7.5.0.5
ibm maximo_for_nuclear_power 7.5.0.1
ibm maximo_for_life_sciences 7.5.0.4
ibm maximo_for_nuclear_power 7.1
ibm maximo_for_transportation 7.5.0.1
ibm maximo_for_utilities 7.5.0.2
ibm maximo_for_nuclear_power 7.5.0.3
ibm maximo_for_government 7.5.0.1
ibm maximo_for_utilities 7.5.0.5
ibm maximo_for_life_sciences 7.1
ibm maximo_asset_management 7.5.0.6
ibm maximo_for_transportation 7.5.0.2
ibm maximo_for_nuclear_power 7.5.0.6
ibm maximo_for_transportation 7.5.0.4
ibm maximo_asset_management 7.1.1.7
ibm maximo_asset_management 7.5.0.7
ibm maximo_for_government 7.5.0.6
ibm maximo_for_utilities 7.5.0.3
ibm maximo_asset_management 7.5.0.5
ibm maximo_asset_management 7.1.1.2
ibm maximo_for_oil_and_gas 7.1
ibm maximo_asset_management 7.1.1.5
ibm maximo_asset_management 7.1.1.11
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
ibm maximo_asset_management 7.5.0.8
ibm maximo_for_nuclear_power 7.5.0.5
ibm maximo_for_transportation 7.5.0.6
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.5.0.1
ibm maximo_for_transportation 7.5.0.0
ibm maximo_for_life_sciences 7.5.0.0
ibm maximo_for_utilities 7.1
ibm maximo_for_oil_and_gas 7.5.0.2
ibm maximo_for_oil_and_gas 7.5.0.3
ibm maximo_for_government 7.5.0.0
ibm change_and_configuration_management_database 7.1
ibm maximo_asset_management 7.6.0.0
ibm maximo_asset_management 7.1.1.12
ibm change_and_configuration_management_database 7.2
ibm maximo_for_life_sciences 7.5.0.5
ibm tivoli_service_request_manager 7.1.0
ibm maximo_asset_management 7.5.0.3
ibm maximo_for_government 7.5.0.2
ibm maximo_for_oil_and_gas 7.5.0.1
ibm maximo_for_nuclear_power 7.5.0.2
ibm maximo_for_utilities 7.5.0.0
ibm maximo_for_life_sciences 7.5.0.3
ibm tivoli_asset_management_for_it 7.1
ibm maximo_for_government 7.5.0.5
ibm maximo_for_transportation 7.1
ibm maximo_for_utilities 7.5.0.6
ibm maximo_for_transportation 7.5.0.5
ibm maximo_asset_management_essentials 7.1
ibm maximo_asset_management 7.5.0.0
ibm maximo_for_oil_and_gas 7.5.0.4
ibm maximo_asset_management 7.5.0.4
ibm smartcloud_control_desk 7.5
ibm maximo_for_oil_and_gas 7.5.0.0
ibm maximo_for_life_sciences 7.5.0.6
ibm maximo_for_energy_optimization 7.1
ibm maximo_asset_management 7.1.1.6
ibm maximo_for_transportation 7.5.0.3
ibm maximo_for_utilities 7.5.0.1
ibm maximo_for_government 7.5.0.3
ibm maximo_for_utilities 7.5.0.4
CVE-2015-4971 LOW

Cross-site scripting (XSS) vulnerability in IBM Emptoris Strategic Supply Management Platform and Emptoris Program Management 10.x before 10.0.1.4_iFix3, 10.0.2.x before 10.0.2.7_iFix1, 10.0.3.x before 10.0.3.2, and 10.0.4.x before 10.0.4.0_iFix1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm emptoris_program_management 10.0.2.4
ibm emptoris_program_management 10.0.0.2
ibm emptoris_program_management 10.0.0.3
ibm emptoris_program_management 10.0.1.4
ibm emptoris_program_management 10.0.2.1
ibm emptoris_program_management 10.0.2.0
ibm emptoris_program_management 10.0.1.0
ibm emptoris_program_management 10.0.1.3
ibm emptoris_program_management 10.0.2.5
ibm emptoris_program_management 10.0.2.7
ibm emptoris_program_management 10.0.0.0
ibm emptoris_program_management 10.0.1.2
ibm emptoris_program_management 10.0.0.1
ibm emptoris_program_management 10.0.1.1
ibm emptoris_program_management 10.0.2.2
ibm emptoris_program_management 10.0.2.3
ibm emptoris strategic_supply_management
ibm emptoris supplier_lifecycle_management
ibm emptoris_program_management 10.0.2.6
CVE-2015-4973 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Multi-Enterprise Integration Gateway 1.x through 1.0.0.1 and B2B Advanced Communications 1.0.0.2 and 1.0.0.3 before 1.0.0.3_2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm b2b_advanced_communications 1.0.0.2
ibm b2b_advanced_communications 1.0.0.1
ibm b2b_advanced_communications 1.0.0.3
CVE-2015-4974 HIGH

IBM General Parallel File System (GPFS) 3.5.x before 3.5.0.27 and 4.1.x before 4.1.1.2 and Spectrum Scale 4.1.1.x before 4.1.1.2 allow local users to obtain root privileges for command execution via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-77,

Products Affected

Vendor Product Version
ibm general_parallel_file_system 3.5.0.0
ibm general_parallel_file_system 3.5.0.20
ibm general_parallel_file_system 3.5.0.19
ibm general_parallel_file_system 3.5.0.22
ibm general_parallel_file_system 3.5.0.9
ibm general_parallel_file_system 3.5.0.14
ibm general_parallel_file_system 3.5.0.24
ibm general_parallel_file_system 3.5.0.10
ibm general_parallel_file_system 3.5.0.21
ibm spectrum_scale 4.1.1.1
ibm general_parallel_file_system 3.5.0.4
ibm general_parallel_file_system 3.5.0.16
ibm general_parallel_file_system 3.5.0.15
ibm general_parallel_file_system 3.5.0.2
ibm general_parallel_file_system 3.5.0.3
ibm general_parallel_file_system 3.5.0.17
ibm general_parallel_file_system 3.5.0.12
ibm general_parallel_file_system 3.5
ibm general_parallel_file_system 3.5.0.25
ibm general_parallel_file_system 3.5.0.6
ibm general_parallel_file_system 3.5.0.13
ibm spectrum_scale 4.1.1.0
ibm general_parallel_file_system 3.5.0.8
ibm general_parallel_file_system 3.5.0.23
ibm general_parallel_file_system 3.5.0.26
ibm general_parallel_file_system 3.5.0.18
ibm general_parallel_file_system 3.5.0.11
ibm general_parallel_file_system 3.5.0.7
CVE-2015-4980 MEDIUM

Unspecified vulnerability in IBM WebSphere Commerce 7.0.0.6 through 7.0.0.9 allows remote authenticated users to obtain sensitive personal information via unknown vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_commerce 7.0.0.6
ibm websphere_commerce 7.0.0.7
ibm websphere_commerce 7.0.0.9
ibm websphere_commerce 7.0.0.8
CVE-2015-4981 LOW

IBM General Parallel File System (GPFS) 3.5.x before 3.5.0.27 and 4.1.x before 4.1.1.2 and Spectrum Scale 4.1.1.x before 4.1.1.2 allow local users to obtain sensitive information from system memory via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm general_parallel_file_system 3.5.0.0
ibm general_parallel_file_system 3.5.0.20
ibm general_parallel_file_system 3.5.0.19
ibm general_parallel_file_system 3.5.0.22
ibm general_parallel_file_system 3.5.0.9
ibm general_parallel_file_system 3.5.0.14
ibm general_parallel_file_system 3.5.0.24
ibm general_parallel_file_system 3.5.0.10
ibm general_parallel_file_system 3.5.0.21
ibm spectrum_scale 4.1.1.1
ibm general_parallel_file_system 3.5.0.4
ibm general_parallel_file_system 3.5.0.16
ibm general_parallel_file_system 3.5.0.15
ibm general_parallel_file_system 3.5.0.2
ibm general_parallel_file_system 3.5.0.3
ibm general_parallel_file_system 3.5.0.17
ibm general_parallel_file_system 3.5.0.12
ibm general_parallel_file_system 3.5
ibm general_parallel_file_system 3.5.0.25
ibm general_parallel_file_system 3.5.0.6
ibm general_parallel_file_system 3.5.0.13
ibm spectrum_scale 4.1.1.0
ibm general_parallel_file_system 3.5.0.8
ibm general_parallel_file_system 3.5.0.23
ibm general_parallel_file_system 3.5.0.26
ibm general_parallel_file_system 3.5.0.18
ibm general_parallel_file_system 3.5.0.11
ibm general_parallel_file_system 3.5.0.7
CVE-2015-4987 MEDIUM

The search and replay servers in IBM Tealeaf Customer Experience 8.0 through 9.0.2 allow remote attackers to bypass authentication via unspecified vectors. IBM X-Force ID: 105896.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm tealeaf_customer_experience *
CVE-2015-4988 HIGH

Directory traversal vulnerability in the replay server in IBM Tealeaf Customer Experience before 8.7.1.8818, 8.8 before 8.8.0.9026, 9.0.0, 9.0.0A, 9.0.1 before 9.0.1.1083, 9.0.1A before 9.0.1.5073, 9.0.2 before 9.0.2.1095, and 9.0.2A before 9.0.2.5144 allows remote attackers to read arbitrary files via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm tealeaf_customer_experience *
ibm tealeaf_customer_experience 8.8
ibm tealeaf_customer_experience 9.0.0a
ibm tealeaf_customer_experience 9.0.1
ibm tealeaf_customer_experience 9.0.1a
ibm tealeaf_customer_experience 8.7
ibm tealeaf_customer_experience 9.0.0
ibm tealeaf_customer_experience 9.0.2a
ibm tealeaf_customer_experience 9.0.2
CVE-2015-4989 MEDIUM

The portal in IBM Tealeaf Customer Experience before 8.7.1.8814, 8.8 before 8.8.0.9026, 9.0.0, 9.0.0A, 9.0.1 before 9.0.1.1083, 9.0.1A before 9.0.1.5073, 9.0.2 before 9.0.2.1095, and 9.0.2A before 9.0.2.5144 allows remote attackers to read arbitrary charts by specifying an internal chart name.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm tealeaf_customer_experience *
ibm tealeaf_customer_experience 8.8
ibm tealeaf_customer_experience 9.0.0a
ibm tealeaf_customer_experience 9.0.1
ibm tealeaf_customer_experience 9.0.1a
ibm tealeaf_customer_experience 8.7
ibm tealeaf_customer_experience 9.0.0
ibm tealeaf_customer_experience 9.0.2a
ibm tealeaf_customer_experience 9.0.2
CVE-2015-4990 LOW

The portal in IBM Tealeaf Customer Experience before 8.7.1.8818, 8.8 before 8.8.0.9026, 9.0.0, 9.0.0A, 9.0.1 before 9.0.1.1083, 9.0.1A before 9.0.1.5073, 9.0.2 before 9.0.2.1095, and 9.0.2A before 9.0.2.5144 allows local users to discover credentials by leveraging privileges during an unspecified connection type.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm tealeaf_customer_experience *
ibm tealeaf_customer_experience 8.8
ibm tealeaf_customer_experience 9.0.0a
ibm tealeaf_customer_experience 9.0.1
ibm tealeaf_customer_experience 9.0.1a
ibm tealeaf_customer_experience 8.7
ibm tealeaf_customer_experience 9.0.0
ibm tealeaf_customer_experience 9.0.2a
ibm tealeaf_customer_experience 9.0.2
CVE-2015-4991 LOW

IBM SPSS Modeler 14.2 through FP3 IF027, 15 through FP3 IF015, 16 through FP2 IF012, 17 through FP1 IF018, and 17.1 through IF008 includes unspecified cleartext data in memory dumps, which allows local users to obtain sensitive information by reading a dump file.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm spss_modeler 14.2.0.1
ibm spss_modeler 14.2.0.3
ibm spss_modeler 16.0.0.0
ibm spss_modeler 15.0.0.2
ibm spss_modeler 17.0.0.1
ibm spss_modeler 14.2.0.0
ibm spss_modeler 17.1.0.0
ibm spss_modeler 15.0.0.0
ibm spss_modeler 15.0.0.1
ibm spss_modeler 16.0.0.2
ibm spss_modeler 17.0.0.0
ibm spss_modeler 15.0.0.3
ibm spss_modeler 14.2.0.2
ibm spss_modeler 16.0.0.1
CVE-2015-4992 LOW

IBM Sterling B2B Integrator 5.2 before 5020500_8 allows remote authenticated users to conduct clickjacking attacks via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2
CVE-2015-4993 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF19, and 8.5.0 before CF08 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2015-4998.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.0
ibm websphere_portal 6.1.0.3
ibm websphere_portal 7.0.0.1
ibm websphere_portal 6.1.5.2
ibm websphere_portal 6.1.0.2
ibm websphere_portal 6.1.0.4
ibm websphere_portal 8.0.0.1
ibm websphere_portal 7.0.0.2
ibm websphere_portal 8.5.0.0
ibm websphere_portal 6.1.5.0
ibm websphere_portal 6.1.0.6
ibm websphere_portal 6.1.5.3
ibm websphere_portal 7.0.0.0
ibm websphere_portal 6.1.0.1
ibm websphere_portal 6.1.5.1
ibm websphere_portal 6.1.0.5
ibm websphere_portal 6.1.0.0
CVE-2015-4994 HIGH

Buffer overflow in IBM Domino 8.5.1 through 8.5.3 before 8.5.3 FP6 IF10 and 9.x before 9.0.1 FP4 IF3 allows remote attackers to execute arbitrary code or cause a denial of service (SMTP daemon crash) via a crafted GIF image, aka SPRs KLYH9ZDKRE and KLYH9ZTLEZ, a different vulnerability than CVE-2015-5040.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm domino 8.5.0
ibm domino 8.5.1
ibm domino 8.5.2
ibm domino 9.0.1
ibm domino 8.5.3
CVE-2015-4996 LOW

IBM Rational ClearQuest 7.1.x and 8.0.0.x before 8.0.0.17 and 8.0.1.x before 8.0.1.10 allows local users to spoof database servers and discover credentials via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_clearquest 8.0.0.12
ibm rational_clearquest 8.0.0.5
ibm rational_clearquest 8.0.1.2
ibm rational_clearquest 8.0.0.15
ibm rational_clearquest 7.1.1.1
ibm rational_clearquest 7.1.2.2
ibm rational_clearquest 8.0.1.1
ibm rational_clearquest 7.1.1.3
ibm rational_clearquest 8.0.0.1
ibm rational_clearquest 8.0.0.3
ibm rational_clearquest 7.1
ibm rational_clearquest 8.0.0.9
ibm rational_clearquest 8.0.0.11
ibm rational_clearquest 7.1.1.5
ibm rational_clearquest 8.0.0
ibm rational_clearquest 8.0.0.2
ibm rational_clearquest 8.0.0.14
ibm rational_clearquest 8.0.1.7
ibm rational_clearquest 7.1.1.4
ibm rational_clearquest 7.1.2.11
ibm rational_clearquest 7.1.2.12
ibm rational_clearquest 7.1.0.1
ibm rational_clearquest 8.0.0.13
ibm rational_clearquest 8.0.1.8
ibm rational_clearquest 7.1.1.7
ibm rational_clearquest 7.1.1
ibm rational_clearquest 7.1.2
ibm rational_clearquest 7.1.0.2
ibm rational_clearquest 8.0.0.7
ibm rational_clearquest 8.0.0.10
ibm rational_clearquest 8.0.1.9
ibm rational_clearquest 8.0.0.16
ibm rational_clearquest 8.0.1.3
ibm rational_clearquest 8.0.1.5
ibm rational_clearquest 8.0.1
ibm rational_clearquest 8.0.1.4
ibm rational_clearquest 7.1.2.7
ibm rational_clearquest 7.1.2.1
ibm rational_clearquest 7.1.1.9
ibm rational_clearquest 7.1.2.3
ibm rational_clearquest 8.0.0.8
ibm rational_clearquest 8.0.0.4
ibm rational_clearquest 7.1.2.5
ibm rational_clearquest 7.1.1.8
ibm rational_clearquest 7.1.2.6
ibm rational_clearquest 7.1.2.8
ibm rational_clearquest 7.1.1.6
ibm rational_clearquest 7.1.2.9
ibm rational_clearquest 7.1.2.10
ibm rational_clearquest 7.1.1.2
ibm rational_clearquest 7.1.2.4
ibm rational_clearquest 8.0.0.6
CVE-2015-4997 MEDIUM

IBM WebSphere Portal 8.5.0 before CF08 allows remote attackers to bypass intended access restrictions via a crafted request.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_portal 8.5.0.0
CVE-2015-4998 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF19, and 8.5.0 before CF08 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2015-4993.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.0
ibm websphere_portal 6.1.0.3
ibm websphere_portal 7.0.0.1
ibm websphere_portal 6.1.5.2
ibm websphere_portal 6.1.0.2
ibm websphere_portal 6.1.0.4
ibm websphere_portal 8.0.0.1
ibm websphere_portal 7.0.0.2
ibm websphere_portal 8.5.0.0
ibm websphere_portal 6.1.5.0
ibm websphere_portal 6.1.0.6
ibm websphere_portal 6.1.5.3
ibm websphere_portal 7.0.0.0
ibm websphere_portal 6.1.0.1
ibm websphere_portal 6.1.5.1
ibm websphere_portal 6.1.0.5
ibm websphere_portal 6.1.0.0
CVE-2015-5001 MEDIUM

IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF19, and 8.5.0 before CF08 allows remote authenticated users to cause a denial of service (memory consumption) via a crafted document.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.0
ibm websphere_portal 6.1.0.3
ibm websphere_portal 7.0.0.1
ibm websphere_portal 6.1.5.2
ibm websphere_portal 6.1.0.2
ibm websphere_portal 6.1.0.4
ibm websphere_portal 8.0.0.1
ibm websphere_portal 7.0.0.2
ibm websphere_portal 8.5.0.0
ibm websphere_portal 6.1.5.0
ibm websphere_portal 6.1.0.6
ibm websphere_portal 6.1.5.3
ibm websphere_portal 7.0.0.0
ibm websphere_portal 6.1.0.1
ibm websphere_portal 6.1.5.1
ibm websphere_portal 6.1.0.5
ibm websphere_portal 6.1.0.0
CVE-2015-5002 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Host On-Demand 11.0 through 11.0.14 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm host_on-demand 11.0.9
ibm host_on-demand 11.0.4
ibm host_on-demand 11.0.7
ibm host_on-demand 11.0.1
ibm host_on-demand 11.0.3
ibm host_on-demand 11.0.12
ibm host_on-demand 11.0
ibm host_on-demand 11.0.13
ibm host_on-demand 11.0.6
ibm host_on-demand 11.0.2
ibm host_on-demand 11.0.5
ibm host_on-demand 11.0.11
ibm host_on-demand 11.0.8
ibm host_on-demand 11.0.10
CVE-2015-5003 HIGH

The portal in IBM Tivoli Monitoring (ITM) 6.2.2 through FP9, 6.2.3 through FP5, and 6.3.0 before FP7 allows remote authenticated users to execute arbitrary commands by leveraging Take Action view authority and providing crafted input.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-77,

Products Affected

Vendor Product Version
ibm tivoli_monitoring 6.2.3
ibm tivoli_monitoring 6.2.2
ibm tivoli_monitoring 6.3.0
CVE-2015-5004 MEDIUM

The Edge Component Caching Proxy in IBM WebSphere Application Server (WAS) 8.0 before 8.0.0.12 and 8.5 before 8.5.5.8 does not properly encrypt data, which allows remote authenticated users to obtain sensitive information via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_application_server 8.0.0.8
ibm websphere_application_server 8.0.0.5
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 8.5.5.0
ibm websphere_application_server 8.5.0.2
ibm websphere_application_server 8.0.0.6
ibm websphere_application_server 8.5.5.2
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 8.5.5.7
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 8.0.0.7
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 8.0.0.9
ibm websphere_application_server 8.5.5.6
ibm websphere_application_server 8.0.0.11
ibm websphere_application_server 8.0.0.10
ibm websphere_application_server 8.5.5.3
ibm websphere_application_server 8.5.5.4
ibm websphere_application_server 8.5.5.5
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 8.5.5.1
ibm websphere_application_server 8.0.0.2
CVE-2015-5005 HIGH

CSPOC in IBM PowerHA SystemMirror on AIX 6.1 and 7.1 allows remote authenticated users to perform an "su root" action by leveraging presence on the cluster-wide password-change list.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm powerha_system_mirror *
CVE-2015-5006 LOW

IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR2, 7 R1 before SR3 FP20, 7 before SR9 FP20, 6 R1 before SR8 FP15, and 6 before SR16 FP15 allow physically proximate attackers to obtain sensitive information by reading the Kerberos Credential Cache.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
suse linux_enterprise_server 11
redhat enterprise_linux_desktop 7.0
redhat satellite 5.6
redhat enterprise_linux_server 7.0
redhat enterprise_linux_server_eus 7.3
suse linux_enterprise_software_development_kit 11
redhat enterprise_linux_desktop 6.0
redhat enterprise_linux_workstation 7.0
suse linux_enterprise_software_development_kit 12
redhat enterprise_linux_desktop 5.0
redhat enterprise_linux_server_eus 6.7
redhat enterprise_linux_server_eus 7.4
ibm java_sdk *
redhat satellite 5.7
suse linux_enterprise_server 12
ibm java_2_sdk *
redhat enterprise_linux_workstation 6.0
redhat enterprise_linux_server_eus 7.2
redhat enterprise_linux_server 6.0
redhat enterprise_linux_workstation 5.0
redhat enterprise_linux_server_eus 7.5
redhat enterprise_linux_server 5.0
CVE-2015-5007 MEDIUM

Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Commerce 6.0 through 6.0.0.11, 7.0 through 7.0.0.9, and 7.0 Feature Pack 8 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm websphere_commerce 6.0.0.6
ibm websphere_commerce 7.0.0.4
ibm websphere_commerce 7.0.0.6
ibm websphere_commerce 7.0.0.7
ibm websphere_commerce 6.0.0.11
ibm websphere_commerce 6.0.0.1
ibm websphere_commerce 6.0.0.2
ibm websphere_commerce 6.0.0.10
ibm websphere_commerce 7.0.0.3
ibm websphere_commerce 7.0.0.9
ibm websphere_commerce 7.0.0.2
ibm websphere_commerce 7.0
ibm websphere_commerce 6.0.0.7
ibm websphere_commerce 6.0.0.8
ibm websphere_commerce 7.0.0.5
ibm websphere_commerce 6.0.0.3
ibm websphere_commerce 6.0.0.0
ibm websphere_commerce 6.0.0.4
ibm websphere_commerce 6.0.0.9
ibm websphere_commerce 7.0.0.1
ibm websphere_commerce 6.0.0.5
ibm websphere_commerce 7.0.0.8
CVE-2015-5008 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM WebSphere Commerce 6.0 through FP11, 6.0 Feature Pack 4, 7.0 through FP9, 7.0 Feature Pack 5 through 8, and 8.0 before 8.0.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_commerce 6.0.0.6
ibm websphere_commerce 7.0.0.4
ibm websphere_commerce 7.0.0.6
ibm websphere_commerce 7.0.0.7
ibm websphere_commerce 6.0.0.11
ibm websphere_commerce 6.0.0.1
ibm websphere_commerce 6.0.0.2
ibm websphere_commerce 6.0.0.10
ibm websphere_commerce 7.0.0.3
ibm websphere_commerce 7.0.0.9
ibm websphere_commerce 7.0.0.2
ibm websphere_commerce 7.0
ibm websphere_commerce 6.0.0.7
ibm websphere_commerce 6.0.0.8
ibm websphere_commerce 7.0.0.5
ibm websphere_commerce 8.0.0.0
ibm websphere_commerce 6.0.0.3
ibm websphere_commerce 6.0.0.0
ibm websphere_commerce 6.0.0.4
ibm websphere_commerce 6.0.0.9
ibm websphere_commerce 7.0.0.1
ibm websphere_commerce 6.0.0.5
ibm websphere_commerce 7.0.0.8
CVE-2015-5009 LOW

Cross-site scripting (XSS) vulnerability in IBM WebSphere Commerce 6.0 through FP11, 6.0 Feature Pack 4, 7.0 through FP9, 7.0 Feature Pack 5 through 8, and 8.0 before 8.0.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_commerce 6.0.0.6
ibm websphere_commerce 7.0.0.4
ibm websphere_commerce 7.0.0.6
ibm websphere_commerce 7.0.0.7
ibm websphere_commerce 6.0.0.11
ibm websphere_commerce 6.0.0.1
ibm websphere_commerce 6.0.0.2
ibm websphere_commerce 6.0.0.10
ibm websphere_commerce 7.0.0.3
ibm websphere_commerce 7.0.0.9
ibm websphere_commerce 7.0.0.2
ibm websphere_commerce 7.0
ibm websphere_commerce 6.0.0.7
ibm websphere_commerce 6.0.0.8
ibm websphere_commerce 7.0.0.5
ibm websphere_commerce 8.0.0.0
ibm websphere_commerce 6.0.0.3
ibm websphere_commerce 6.0.0.0
ibm websphere_commerce 6.0.0.4
ibm websphere_commerce 6.0.0.9
ibm websphere_commerce 7.0.0.1
ibm websphere_commerce 6.0.0.5
ibm websphere_commerce 7.0.0.8
CVE-2015-5010 MEDIUM

IBM Security Access Manager for Web 7.0 before 7.0.0 IF21, 8.0 before 8.0.1.3 IF4, and 9.0 before 9.0.0.1 IF1 does not have a lockout mechanism for invalid login attempts, which makes it easier for remote attackers to obtain access via a brute-force attack.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-254,

Products Affected

Vendor Product Version
ibm security_access_manager_for_web_7.0_firmware 7.0.0.13
ibm security_access_manager_for_web_7.0_firmware 7.0.0.18
ibm security_access_manager_for_web_7.0_firmware 7.0.0.19
ibm security_access_manager_for_web_7.0_firmware 7.0.0.1
ibm security_access_manager_for_web_7.0_firmware 7.0.0.7
ibm security_access_manager_for_web_7.0_firmware 7.0.0.2
ibm security_access_manager_for_web_8.0_firmware 8.0.1.0
ibm security_access_manager_for_web_7.0_firmware 7.0.0.4
ibm security_access_manager_9.0_firmware 9.0.0
ibm security_access_manager_for_web_7.0_firmware 7.0.0.11
ibm security_access_manager_for_web_7.0_firmware 7.0.0.8
ibm security_access_manager_for_web_7.0_firmware 7.0.0.14
ibm security_access_manager_for_web_8.0_firmware 8.0.1
ibm security_access_manager_for_web_7.0_firmware 7.0.0.10
ibm security_access_manager_for_web_8.0_firmware 8.0.1.3
ibm security_access_manager_for_web_7.0_firmware 7.0.0.15
ibm security_access_manager_for_web_7.0_firmware 7.0.0.5
ibm security_access_manager_for_web_7.0_firmware 7.0.0.6
ibm security_access_manager_for_web_7.0_firmware 7.0.0.16
ibm security_access_manager_for_web_8.0_firmware 8.0.0.2
ibm security_access_manager_for_web_8.0_firmware 8.0.0.3
ibm security_access_manager_for_web_7.0_firmware 7.0.0.3
ibm security_access_manager_for_web_7.0_firmware 7.0.0.9
ibm security_access_manager_for_web_8.0_firmware 8.0.1.2
ibm security_access_manager_for_web_8.0_firmware 8.0.0.5
ibm security_access_manager_for_web_8.0_firmware 8.0.0.1
ibm security_access_manager_for_web_7.0_firmware 7.0.0.12
ibm security_access_manager_for_web_7.0_firmware 7.0.0.17
ibm security_access_manager_for_web_7.0_firmware 7.0.0.20
CVE-2015-5011 LOW

IBM WebSphere Message Broker 8 before 8.0.0.6 and Integration Bus 9 before 9.0.0.4 do not check authorization for MQSISTARTMSGFLOW and MQSISTOPMSGFLOW commands, which allows local users to bypass intended access restrictions, and start or stop a service, by issuing a command.

CVSS 2.0

Severity: LOW

Problem Type: CWE-77,

Products Affected

Vendor Product Version
ibm websphere_message_broker 8.0
ibm websphere_message_broker 8.0.0.3
ibm integration_bus 9.0
ibm websphere_message_broker 8.0.0.2
ibm integration_bus 9.0.0.2
ibm websphere_message_broker 8.0.0.5
ibm integration_bus 9.0.0.1
ibm websphere_message_broker 8.0.0.1
ibm integration_bus 9.0.0.3
ibm websphere_message_broker 8.0.0.4
CVE-2015-5012 MEDIUM

The SSH implementation on IBM Security Access Manager for Web appliances 7.0 before 7.0.0 FP19, 8.0 before 8.0.1.3 IF3, and 9.0 before 9.0.0.0 IF1 does not properly restrict the set of MAC algorithms, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm security_access_manager_for_web_7.0_firmware 7.0.0.13
ibm security_access_manager_for_web_7.0_firmware 7.0.0.18
ibm security_access_manager_for_web_7.0_firmware 7.0.0.1
ibm security_access_manager_for_web_7.0_firmware 7.0.0.7
ibm security_access_manager_for_web_7.0_firmware 7.0.0.2
ibm security_access_manager_for_web_8.0_firmware 8.0.1.0
ibm security_access_manager_for_web_7.0_firmware 7.0.0.4
ibm security_access_manager_9.0_firmware 9.0.0
ibm security_access_manager_for_web_7.0_firmware 7.0.0.11
ibm security_access_manager_for_web_7.0_firmware 7.0.0.8
ibm security_access_manager_for_web_7.0_firmware 7.0.0.14
ibm security_access_manager_for_web_8.0_firmware 8.0.1
ibm security_access_manager_for_web_7.0_firmware 7.0.0.10
ibm security_access_manager_for_web_7.0_firmware 7.0.0.15
ibm security_access_manager_for_web_7.0_firmware 7.0.0.5
ibm security_access_manager_for_web_7.0_firmware 7.0.0.6
ibm security_access_manager_for_web_7.0_firmware 7.0.0.16
ibm security_access_manager_for_web_8.0_firmware 8.0.0.2
ibm security_access_manager_for_web_8.0_firmware 8.0.0.3
ibm security_access_manager_for_web_7.0_firmware 7.0.0.3
ibm security_access_manager_for_web_7.0_firmware 7.0.0.9
ibm security_access_manager_for_web_8.0_firmware 8.0.1.2
ibm security_access_manager_for_web_8.0_firmware 8.0.0.5
ibm security_access_manager_for_web_8.0_firmware 8.0.0.1
ibm security_access_manager_for_web_7.0_firmware 7.0.0.12
ibm security_access_manager_for_web_7.0_firmware 7.0.0.17
CVE-2015-5013 LOW

The IBM Security Access Manager appliance includes configuration files that contain obfuscated plaintext-passwords which authenticated users can access.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 5.5 MEDIUM CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N 1.8 3.6

CVSS 2.0

Severity: LOW

Problem Type: CWE-522,

Products Affected

Vendor Product Version
ibm security_access_manager_for_mobile *
ibm security_access_manager_for_web_8.0_firmware *
ibm security_access_manager_9.0_firmware *
CVE-2015-5014 HIGH

IBM Cognos Disclosure Management (CDM) 10.1.x and 10.2.x before 10.2.4 IF10 allows man-in-the-middle attackers to obtain access by spoofing an executable file during a client upload operation.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm cognos_disclosure_management 10.2.4
ibm cognos_disclosure_management 10.2.3
ibm cognos_disclosure_management 10.2.1
ibm cognos_disclosure_management 10.2.2
ibm cognos_disclosure_management 10.2.0
CVE-2015-5015 MEDIUM

IBM WebSphere Commerce Enterprise 7.0.0.9 and 8.x before Feature Pack 8 allows remote attackers to obtain sensitive information via a crafted REST URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_commerce_enterprise *
CVE-2015-5016 MEDIUM

IBM Maximo Asset Management 7.1, 7.5, and 7.6; Maximo Asset Management Essentials 7.1 and 7.5; Control Desk 7.5 and 7.6; Tivoli Asset Management for IT 7.1 and 7.2; and certain other IBM products allow remote authenticated users to bypass intended access restrictions and read arbitrary ticket worklog entries via unspecified vectors. IBM X-Force ID: 106460.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm tivoli_asset_management_for_it 7.2
ibm maximo_asset_management 7.1
ibm maximo_for_government 7.1
ibm maximo_asset_management_essentials 7.5
ibm maximo_for_utilities 7.5
ibm maximo_for_utilities 7.1
ibm maximo_asset_management 7.6
ibm change_and_configuration_management_database 7.1
ibm maximo_for_government 7.5
ibm change_and_configuration_management_database 7.2
ibm maximo_for_nuclear_power 7.1
ibm maximo_for_transportation 7.5
ibm maximo_for_life_sciences 7.5
ibm maximo_for_life_sciences 7.6
ibm maximo_for_life_sciences 7.1
ibm maximo_asset_management 7.5
ibm tivoli_asset_management_for_it 7.1
ibm maximo_for_transportation 7.1
ibm maximo_for_nuclear_power 7.5
ibm tivoli_service_request_manager 7.1
ibm maximo_asset_management_essentials 7.1
ibm maximo_for_oil_and_gas 7.1
ibm maximo_for_energy_optimization 7.1
ibm control_desk 7.5
ibm control_desk 7.6
ibm tivoli_service_request_manager 7.2
ibm maximo_for_transportation 7.6
ibm maximo_for_aviation 7.6
ibm maximo_for_oil_and_gas 7.5
CVE-2015-5017 MEDIUM

IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX005, and 7.6.0 before 7.6.0.2 IFIX002; Maximo Asset Management 7.5.0 before 7.5.0.8 IFIX005, 7.5.1, and 7.6.0 before 7.6.0.2 IFIX002 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products allow remote authenticated users to bypass intended access restrictions and establish a login session by entering an expired password.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm tivoli_asset_management_for_it 7.2
ibm maximo_asset_management 7.1
ibm maximo_for_government 7.1
ibm smartcloud_control_desk 7.6
ibm maximo_asset_management_essentials 7.5
ibm maximo_for_utilities 7.5
ibm maximo_for_utilities 7.1
ibm maximo_asset_management 7.6
ibm change_and_configuration_management_database 7.1
ibm maximo_for_government 7.5
ibm change_and_configuration_management_database 7.2
ibm maximo_for_nuclear_power 7.1
ibm maximo_for_transportation 7.5
ibm maximo_for_life_sciences 7.5
ibm maximo_for_life_sciences 7.6
ibm maximo_for_life_sciences 7.1
ibm maximo_asset_management 7.5
ibm tivoli_asset_management_for_it 7.1
ibm maximo_for_transportation 7.1
ibm maximo_for_nuclear_power 7.5
ibm tivoli_service_request_manager 7.1
ibm maximo_asset_management_essentials 7.1
ibm smartcloud_control_desk 7.5
ibm maximo_for_oil_and_gas 7.1
ibm maximo_for_energy_optimization 7.1
ibm tivoli_service_request_manager 7.2
ibm maximo_for_oil_and_gas 7.5
CVE-2015-5018 HIGH

IBM Security Access Manager for Web 7.0.0 before FP19 and 8.0 before 8.0.1.3 IF3, and Security Access Manager 9.0 before 9.0.0.0 IF1, allows remote authenticated users to execute arbitrary OS commands by leveraging Local Management Interface (LMI) access.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-78,

Products Affected

Vendor Product Version
ibm security_access_manager_for_web_7.0_firmware 7.0.0.13
ibm security_access_manager_for_web_7.0_firmware 7.0.0.1
ibm security_access_manager_for_web_7.0_firmware 7.0.0.7
ibm security_access_manager_for_web_7.0_firmware 7.0.0.2
ibm security_access_manager_for_web_8.0_firmware 8.0.1.0
ibm security_access_manager_for_web_7.0_firmware 7.0.0.4
ibm security_access_manager_9.0_firmware 9.0.0
ibm security_access_manager_for_web_7.0_firmware 7.0.0.11
ibm security_access_manager_for_web_7.0_firmware 7.0.0.8
ibm security_access_manager_for_web_7.0_firmware 7.0.0.14
ibm security_access_manager_for_web_8.0_firmware 8.0.1
ibm security_access_manager_for_web_7.0_firmware 7.0.0.10
ibm security_access_manager_for_web_8.0_firmware 8.0.1.3
ibm security_access_manager_for_web_7.0_firmware 7.0.0.15
ibm security_access_manager_for_web_7.0_firmware 7.0.0.5
ibm security_access_manager_for_web_7.0_firmware 7.0.0.6
ibm security_access_manager_for_web_7.0_firmware 7.0.0.16
ibm security_access_manager_for_web_8.0_firmware 8.0.0.2
ibm security_access_manager_for_web_8.0_firmware 8.0.0.3
ibm security_access_manager_for_web_7.0_firmware 7.0.0.3
ibm security_access_manager_for_web_7.0_firmware 7.0.0.9
ibm security_access_manager_for_web_8.0_firmware 8.0.1.2
ibm security_access_manager_for_web_8.0_firmware 8.0.0.5
ibm security_access_manager_for_web_8.0_firmware 8.0.0.1
ibm security_access_manager_for_web_7.0_firmware 7.0.0.12
CVE-2015-5019 MEDIUM

IBM Sterling Integrator 5.1 before 5010004_8 and Sterling B2B Integrator 5.2 before 5020500_9 allow remote authenticated users to read or upload files by leveraging a password-change requirement.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2
ibm sterling_integrator 5.1
CVE-2015-5020 MEDIUM

The Big SQL component in IBM InfoSphere BigInsights 3.0, 3.0.0.1, 3.0.0.2, and 4.0 allows remote authenticated users to bypass intended access restrictions and truncate arbitrary tables via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm infosphere_biginsights 3.0.0.1
ibm infosphere_biginsights 4.0.0.0
ibm infosphere_biginsights 3.0.0.0
ibm infosphere_biginsights 3.0.0.2
CVE-2015-5021 MEDIUM

IBM InfoSphere Information Server 11.3 and 11.5 allows remote authenticated DataStage users to bypass intended job-execution restrictions or obtain sensitive information via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm infosphere_information_server 11.3
ibm infosphere_information_server 11.5
CVE-2015-5022 MEDIUM

IBM Multi-Enterprise Integration Gateway 1.x through 1.0.0.1 and B2B Advanced Communications 1.0.0.2 and 1.0.0.3 before 1.0.0.3_2, when access by guests is enabled, place an internal hostname and a payload path in a response, which allows remote authenticated users to obtain sensitive information by leveraging a trading-partner relationship and reading response fields.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm b2b_advanced_communications 1.0.0.2
ibm b2b_advanced_communications 1.0.0.1
ibm b2b_advanced_communications 1.0.0.3
CVE-2015-5023 MEDIUM

SQL injection vulnerability in IBM Curam Social Program Management 6.1 before 6.1.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm curam_social_program_management 6.0.2
ibm curam_social_program_management 6.0
ibm curam_social_program_management 6.1
ibm curam_social_program_management 6.0.3
ibm curam_social_program_management 6.0.5
ibm curam_social_program_management 6.0.4
ibm curam_social_program_management 6.0.1
CVE-2015-5024 MEDIUM

IBM Emptoris Sourcing 10.0.2.0 before iFix6, 10.0.2.2 before iFix11, 10.0.2.3, 10.0.2.5 before iFix4, 10.0.2.6 before iFix8, 10.0.2.7 before iFix1, and 10.0.4.x before iFix2 allows remote authenticated users to obtain sensitive supplier-bid information via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm emptoris_sourcing 10.0.2.0
ibm emptoris_sourcing 10.0.2.3
ibm emptoris_sourcing 10.0.4.0
ibm emptoris_sourcing 10.0.2.7
ibm emptoris_sourcing 10.0.2.2
ibm emptoris_sourcing 10.0.2.6
ibm emptoris_sourcing 10.0.2.5
CVE-2015-5035 LOW

Cross-site scripting (XSS) vulnerability in IBM Connections 3.x before 3.0.1.1 CR3, 4.0 before CR4, 4.5 before CR5, and 5.0 before CR3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2015-5036.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm connections 5.0
ibm connections 4.5
ibm connections *
ibm connections 4.0
CVE-2015-5036 LOW

Cross-site scripting (XSS) vulnerability in IBM Connections 3.x before 3.0.1.1 CR3, 4.0 before CR4, 4.5 before CR5, and 5.0 before CR3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2015-5035.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm connections 5.0
ibm connections 4.5
ibm connections *
ibm connections 4.0
CVE-2015-5037 MEDIUM

Cross-site request forgery (CSRF) vulnerability in IBM Connections 3.x before 3.0.1.1 CR3, 4.0 before CR4, 4.5 before CR5, and 5.0 before CR3 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm connections 5.0
ibm connections 4.5
ibm connections *
ibm connections 4.0
CVE-2015-5038 HIGH

IBM Connections 3.x before 3.0.1.1 CR3, 4.0 before CR4, 4.5 before CR5, and 5.0 before CR3 does not properly detect recursion during XML entity expansion, which allows remote attackers to cause a denial of service (CPU consumption and application crash) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm connections 5.0
ibm connections 4.5
ibm connections *
ibm connections 4.0
CVE-2015-5039 MEDIUM

The Remote Client and change management integrations in IBM Rational ClearCase 7.1.x, 8.0.0.x before 8.0.0.18, and 8.0.1.x before 8.0.1.11 do not properly validate hostnames in X.509 certificates from SSL servers, which allows remote attackers to spoof servers and obtain sensitive information or modify network traffic via a crafted certificate. IBM X-Force ID: 106715.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm rational_clearcase *
CVE-2015-5040 HIGH

Buffer overflow in IBM Domino 8.5.1 through 8.5.3 before 8.5.3 FP6 IF10 and 9.x before 9.0.1 FP4 IF3 allows remote attackers to execute arbitrary code or cause a denial of service (SMTP daemon crash) via a crafted GIF image, aka SPRs KLYH9ZDKRE and KLYH9ZTLEZ, a different vulnerability than CVE-2015-4994.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm domino 8.5.0
ibm domino 8.5.1.1
ibm domino 8.5.1.5
ibm domino 8.5.1.2
ibm domino 8.5.3.5
ibm domino 8.5.2.1
ibm domino 9.0.1.1
ibm domino 8.5.3
ibm domino 8.5.3.1
ibm domino 9.0.1.2
ibm domino 9.0.1.4
ibm domino 8.5.1
ibm domino 8.5.0.1
ibm domino 9.0.1.3
ibm domino 9.0.1
ibm domino 8.5.3.4
ibm domino 8.5.2.3
ibm domino 8.5.3.2
ibm domino 8.5.2
ibm domino 8.5.3.6
ibm domino 8.5.2.2
ibm domino 8.5.1.4
ibm domino 8.5.3.3
ibm domino 8.5.2.4
ibm domino 8.5.1.3
CVE-2015-5041 MEDIUM

The J9 JVM in IBM SDK, Java Technology Edition 6 before SR16 FP20, 6 R1 before SR8 FP20, 7 before SR9 FP30, and 7 R1 before SR3 FP30 allows remote attackers to obtain sensitive information or inject data by invoking non-public interface methods.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
suse linux_enterprise_server 11
suse linux_enterprise_server 12
redhat satellite 5.6
suse suse_linux_enterprise_server 12
ibm websphere_application_server *
suse linux_enterprise_software_development_kit 11
suse linux_enterprise_software_development_kit 12
ibm java_sdk *
redhat satellite 5.7
CVE-2015-5042 MEDIUM

IBM Emptoris Contract Management 9.5.0.x before 9.5.0.6 iFix15, 10.0.0.x and 10.0.1.x before 10.0.1.5 iFix5, 10.0.2.x before 10.0.2.7 iFix4, and 10.0.4.x before 10.0.4.0 iFix3 allows remote attackers to execute arbitrary code by including a crafted Flash file.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm emptoris_contract_management 9.5.0.1
ibm emptoris_contract_management 10.0.1.4
ibm emptoris_contract_management 9.5.0.4
ibm emptoris_contract_management 10.0.2.4
ibm emptoris_contract_management 10.0.2.5
ibm emptoris_contract_management 10.0.0.1
ibm emptoris_contract_management 10.0.1.2
ibm emptoris_contract_management 10.0.0.0
ibm emptoris_contract_management 10.0.1.0
ibm emptoris_contract_management 9.5.0.3
ibm emptoris_contract_management 9.5.0.0
ibm emptoris_contract_management 10.0.2.2
ibm emptoris_contract_management 10.0.2.3
ibm emptoris_contract_management 10.0.1.5
ibm emptoris_contract_management 10.0.4.0
ibm emptoris_contract_management 10.0.1.1
ibm emptoris_contract_management 10.0.2.1
ibm emptoris_contract_management 10.0.2.0
ibm emptoris_contract_management 9.5.0.5
ibm emptoris_contract_management 10.0.1.3
ibm emptoris_contract_management 10.0.2.7
ibm emptoris_contract_management 9.5.0.2
ibm emptoris_contract_management 10.0.2.6
ibm emptoris_contract_management 9.5.0.6
CVE-2015-5043 HIGH

diag in IBM Security Guardium 8.2 before p6015, 9.0 before p6015, 9.1, 9.5, and 10.0 before p6015 allows local users to obtain root access via unspecified key sequences.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm security_guardium 9.0
ibm security_guardium 10.0
ibm security_guardium 9.1
ibm security_guardium 8.2
ibm security_guardium 9.5
CVE-2015-5044 LOW

The Flow Collector in IBM Security QRadar QFLOW 7.1.x before 7.1 MR2 Patch 11 IF3 and 7.2.x before 7.2.5 Patch 4 IF3 allows remote attackers to cause a denial of service via unspecified packets.

CVSS 2.0

Severity: LOW

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.0.0
ibm qradar_security_information_and_event_manager 7.2.2
ibm qradar_security_information_and_event_manager 7.2.0
ibm qradar_security_information_and_event_manager 7.1.0
ibm qradar_security_information_and_event_manager 7.2.3
ibm qradar_security_information_and_event_manager 7.0.1
ibm qradar_security_information_and_event_manager 7.2.4
ibm qradar_security_information_and_event_manager 7.2.1
ibm qradar_security_information_and_event_manager 7.2.5
CVE-2015-5045 LOW

The Administration and Reporting tool in IBM Rational License Key Server (RLKS) before 8.1.4.9 iFix 04 allows local users to obtain sensitive information via unspecified vectors. IBM X-Force ID: 106938.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_license_key_server 8.1.4.5
ibm rational_license_key_server 8.1.4.9
ibm rational_license_key_server 8.1.4
ibm rational_license_key_server 8.1.4.4
ibm rational_license_key_server 8.1.4.3
ibm rational_license_key_server 8.1.4.6
ibm rational_license_key_server 8.1.4.7
ibm rational_license_key_server 8.1.4.2
ibm rational_license_key_server 8.1.4.8
CVE-2015-5049 MEDIUM

SQL injection vulnerability in the API in IBM OpenPages GRC Platform 7.0 before 7.0.0.4 IF3 and 7.1 before 7.1.0.1 IF6 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm openpages_grc_platform 7.1.0.0
ibm openpages_grc_platform 7.0.0.3
ibm openpages_grc_platform 7.0.0.2
ibm openpages_grc_platform 7.0.0.0
ibm openpages_grc_platform 7.1.0.1
ibm openpages_grc_platform 7.0.0.1
ibm openpages_grc_platform 7.0.0.4
CVE-2015-5050 MEDIUM

Cross-site request forgery (CSRF) vulnerability in IBM Emptoris Contract Management 9.5.0.x before 9.5.0.6 iFix15, 10.0.0.x and 10.0.1.x before 10.0.1.5 iFix5, 10.0.2.x before 10.0.2.7 iFix4, and 10.0.4.x before 10.0.4.0 iFix3 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm emptoris_contract_management 9.5.0.1
ibm emptoris_contract_management 10.0.1.4
ibm emptoris_contract_management 9.5.0.4
ibm emptoris_contract_management 10.0.2.4
ibm emptoris_contract_management 10.0.2.5
ibm emptoris_contract_management 10.0.0.1
ibm emptoris_contract_management 10.0.1.2
ibm emptoris_contract_management 10.0.0.0
ibm emptoris_contract_management 10.0.1.0
ibm emptoris_contract_management 9.5.0.3
ibm emptoris_contract_management 9.5.0.0
ibm emptoris_contract_management 10.0.2.2
ibm emptoris_contract_management 10.0.2.3
ibm emptoris_contract_management 10.0.1.5
ibm emptoris_contract_management 10.0.4.0
ibm emptoris_contract_management 10.0.1.1
ibm emptoris_contract_management 10.0.2.1
ibm emptoris_contract_management 10.0.2.0
ibm emptoris_contract_management 9.5.0.5
ibm emptoris_contract_management 10.0.1.3
ibm emptoris_contract_management 10.0.2.7
ibm emptoris_contract_management 9.5.0.2
ibm emptoris_contract_management 10.0.2.6
ibm emptoris_contract_management 9.5.0.6
CVE-2015-5051 MEDIUM

IBM Maximo Asset Management 7.5 before 7.5.0.8 IF6 and 7.6 before 7.6.0.2 IF1 and Maximo Asset Management 7.5 before 7.5.0.8 IF6, 7.5.1, and 7.6 before 7.6.0.2 IF1 for SmartCloud Control Desk allow remote authenticated users to bypass intended access restrictions on query results via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm maximo_for_life_sciences 7.5
ibm maximo_for_life_sciences 7.6
ibm smartcloud_control_desk 7.6
ibm maximo_asset_management 7.5
ibm maximo_asset_management_essentials 7.5
ibm maximo_for_nuclear_power 7.5
ibm maximo_for_utilities 7.5
ibm maximo_asset_management 7.6
ibm maximo_for_government 7.5
ibm smartcloud_control_desk 7.5
ibm maximo_asset_management_essentials 7.6
ibm maximo_for_transportation 7.5
ibm maximo_for_oil_and_gas 7.5
CVE-2015-5073 MEDIUM

Heap-based buffer overflow in the find_fixedlength function in pcre_compile.c in PCRE before 8.38 allows remote attackers to cause a denial of service (crash) or obtain sensitive information from heap memory and possibly bypass the ASLR protection mechanism via a crafted regular expression with an excess closing parenthesis.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,CWE-200,

Products Affected

Vendor Product Version
pcre pcre *
ibm powerkvm 3.1
ibm powerkvm 2.1
CVE-2015-6557 LOW

IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server 5.5 before 5.5.6.1, 6.3 before 6.3.1.5, 6.4 before 6.4.1.7, and 7.1 before 7.1.2; Tivoli Storage Manager for Mail: Data Protection for Microsoft Exchange Server 5.5 before 5.5.1.1, 6.1 before 6.1.3.7, 6.3 before 6.3.1.5, 6.4 before 6.4.1.7, and 7.1 before 7.1.2; and Tivoli Storage FlashCopy Manager 3.1 before 3.1.1.5, 3.2 before 3.2.1.7, and 4.1 before 4.1.2, when application tracing is used, place cleartext passwords in exception messages, which allows physically proximate attackers to obtain sensitive information by reading trace output, a different vulnerability than CVE-2015-4949.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server 7.1
ibm tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server 7.1.1
ibm tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server 7.1.1
ibm tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server 6.4.1
ibm tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server 5.5.5
ibm tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server 6.3.1
ibm tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server 6.1.1
ibm tivoli_storage_flashcopy_manager 3.2.0
ibm tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server 6.1
ibm tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server 6.3
ibm tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server 6.4
ibm tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server 6.1.2
ibm tivoli_storage_flashcopy_manager 3.1.1
ibm tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server 6.3.1
ibm tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server 5.5
ibm tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server 6.1.3
ibm tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server 6.4.1
ibm tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server 5.5.4
ibm tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server 7.1
ibm tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server 5.5.1
ibm tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server 6.3
ibm tivoli_storage_flashcopy_manager 3.1.0
ibm tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server 6.4
ibm tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server 5.5.6
ibm tivoli_storage_flashcopy_manager 4.1.0
ibm tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server 5.5.2
ibm tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server 5.5.1
ibm tivoli_storage_flashcopy_manager 4.1.1
ibm tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server 5.5
ibm tivoli_storage_flashcopy_manager 3.2.1
ibm tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server 5.5.3
CVE-2015-7395 MEDIUM

IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX005, and 7.6.0 before 7.6.0.2 FP002; Maximo Asset Management 7.5.0 before 7.5.0.8 IFIX005, 7.5.1, and 7.6.0 before 7.6.0.2 FP002 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products allow remote authenticated users to bypass intended work-order change restrictions via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm tivoli_asset_management_for_it 7.2
ibm maximo_for_life_sciences 7.5.0.2
ibm maximo_asset_management 7.1.1.9
ibm maximo_for_government 7.5.0.4
ibm tivoli_service_request_manager 7.2.0.0
ibm maximo_for_life_sciences 7.5.0.1
ibm maximo_for_government 7.1
ibm maximo_asset_management 7.1.1.13
ibm maximo_for_nuclear_power 7.5.0.4
ibm maximo_asset_management 7.1.1.10
ibm maximo_for_oil_and_gas 7.5.0.6
ibm maximo_asset_management 7.1.1.1
ibm maximo_for_nuclear_power 7.5.0.0
ibm maximo_for_oil_and_gas 7.5.0.5
ibm maximo_for_nuclear_power 7.5.0.1
ibm maximo_for_life_sciences 7.5.0.4
ibm maximo_for_nuclear_power 7.1
ibm maximo_for_transportation 7.5.0.1
ibm maximo_for_utilities 7.5.0.2
ibm maximo_for_nuclear_power 7.5.0.3
ibm maximo_for_government 7.5.0.1
ibm maximo_for_utilities 7.5.0.5
ibm maximo_asset_management 7.5.0.9
ibm maximo_for_life_sciences 7.1
ibm maximo_asset_management 7.5.0.6
ibm maximo_for_transportation 7.5.0.2
ibm maximo_for_nuclear_power 7.5.0.6
ibm maximo_for_transportation 7.5.0.4
ibm maximo_asset_management 7.1.1.7
ibm maximo_asset_management 7.5.0.7
ibm maximo_for_government 7.5.0.6
ibm maximo_for_utilities 7.5.0.3
ibm maximo_asset_management 7.5.0.5
ibm maximo_asset_management 7.1.1.2
ibm maximo_for_oil_and_gas 7.1
ibm maximo_asset_management 7.1.1.5
ibm maximo_asset_management 7.1.1.11
ibm maximo_asset_management 7.6.0.1
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
ibm maximo_asset_management 7.5.0.8
ibm maximo_for_nuclear_power 7.5.0.5
ibm maximo_for_transportation 7.5.0.6
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.5.0.1
ibm maximo_for_transportation 7.5.0.0
ibm smartcloud_control_desk 7.6
ibm maximo_for_life_sciences 7.5.0.0
ibm maximo_for_utilities 7.1
ibm maximo_for_oil_and_gas 7.5.0.2
ibm maximo_for_oil_and_gas 7.5.0.3
ibm maximo_for_government 7.5.0.0
ibm change_and_configuration_management_database 7.1
ibm maximo_asset_management 7.6.0.0
ibm maximo_asset_management 7.1.1.12
ibm change_and_configuration_management_database 7.2
ibm maximo_for_life_sciences 7.5.0.5
ibm tivoli_service_request_manager 7.1.0
ibm maximo_asset_management 7.5.0.3
ibm maximo_asset_management 7.6.0.2
ibm maximo_for_government 7.5.0.2
ibm maximo_for_oil_and_gas 7.5.0.1
ibm maximo_for_nuclear_power 7.5.0.2
ibm maximo_for_utilities 7.5.0.0
ibm maximo_for_life_sciences 7.5.0.3
ibm tivoli_asset_management_for_it 7.1
ibm maximo_for_government 7.5.0.5
ibm maximo_for_transportation 7.1
ibm maximo_for_utilities 7.5.0.6
ibm maximo_for_transportation 7.5.0.5
ibm maximo_asset_management 7.5.0.0
ibm maximo_for_oil_and_gas 7.5.0.4
ibm maximo_asset_management 7.5.0.4
ibm smartcloud_control_desk 7.5
ibm maximo_for_oil_and_gas 7.5.0.0
ibm maximo_for_life_sciences 7.5.0.6
ibm maximo_asset_management 7.1.1.6
ibm maximo_for_transportation 7.5.0.3
ibm maximo_for_utilities 7.5.0.1
ibm maximo_for_government 7.5.0.3
ibm maximo_for_utilities 7.5.0.4
CVE-2015-7396 MEDIUM

The Scheduler in IBM Maximo Asset Management 7.5 before 7.5.0.8 IF6 and 7.6 before 7.6.0.1 FP1 and Maximo Asset Management 7.5 before 7.5.0.8 IF6, 7.5.1, and 7.6 before 7.6.0.1 FP1 for SmartCloud Control Desk allows remote authenticated users to bypass intended access restrictions, and obtain sensitive information or modify data, via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm maximo_for_life_sciences 7.5
ibm maximo_for_life_sciences 7.6
ibm smartcloud_control_desk 7.6
ibm maximo_asset_management 7.5
ibm maximo_asset_management_essentials 7.5
ibm maximo_for_nuclear_power 7.5
ibm maximo_for_utilities 7.5
ibm maximo_asset_management 7.6
ibm maximo_for_government 7.5
ibm smartcloud_control_desk 7.5
ibm maximo_for_transportation 7.5
ibm maximo_for_oil_and_gas 7.5
CVE-2015-7397 MEDIUM

Multiple open redirect vulnerabilities in the Aurora starter store in IBM WebSphere Commerce 7.0 through Feature Pack 8 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the referrer parameter.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_commerce 7.0
CVE-2015-7398 LOW

Cross-site scripting (XSS) vulnerability in IBM Emptoris Contract Management 9.5.0.x before 9.5.0.6 iFix15, 10.0.0.x and 10.0.1.x before 10.0.1.5 iFix5, 10.0.2.x before 10.0.2.7 iFix4, and 10.0.4.x before 10.0.4.0 iFix3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm emptoris_contract_management 9.5.0.1
ibm emptoris_contract_management 10.0.1.4
ibm emptoris_contract_management 9.5.0.4
ibm emptoris_contract_management 10.0.2.4
ibm emptoris_contract_management 10.0.2.5
ibm emptoris_contract_management 10.0.0.1
ibm emptoris_contract_management 10.0.1.2
ibm emptoris_contract_management 10.0.0.0
ibm emptoris_contract_management 10.0.1.0
ibm emptoris_contract_management 9.5.0.3
ibm emptoris_contract_management 9.5.0.0
ibm emptoris_contract_management 10.0.2.2
ibm emptoris_contract_management 10.0.2.3
ibm emptoris_contract_management 10.0.1.5
ibm emptoris_contract_management 10.0.4.0
ibm emptoris_contract_management 10.0.1.1
ibm emptoris_contract_management 10.0.2.1
ibm emptoris_contract_management 10.0.2.0
ibm emptoris_contract_management 9.5.0.5
ibm emptoris_contract_management 10.0.1.3
ibm emptoris_contract_management 10.0.2.7
ibm emptoris_contract_management 9.5.0.2
ibm emptoris_contract_management 10.0.2.6
ibm emptoris_contract_management 9.5.0.6
CVE-2015-7399 MEDIUM

IBM WebSphere Message Broker 7 before 7.0.0.8 and 8 before 8.0.0.6 and IBM Integration Bus 9 before 9.0.0.3 and 10 before 10.0.0.0 allow remote attackers to obtain sensitive information about the HTTP server via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_message_broker 7.0.0.1
ibm websphere_message_broker 7.0.0.2
ibm websphere_message_broker 8.0
ibm websphere_message_broker 7.0.0.5
ibm integration_bus 9.0.0.2
ibm websphere_message_broker 7.0.0.4
ibm websphere_message_broker 7.0.0.6
ibm websphere_message_broker 8.0.0.4
ibm websphere_message_broker 8.0.0.3
ibm integration_bus 9.0
ibm websphere_message_broker 8.0.0.2
ibm websphere_message_broker 7.0.0.3
ibm integration_bus 10.0
ibm websphere_message_broker 8.0.0.5
ibm websphere_message_broker 7.0.
ibm integration_bus 9.0.0.1
ibm websphere_message_broker 8.0.0.1
ibm websphere_message_broker 7.0.0.7
CVE-2015-7400 MEDIUM

The Lotus Mashups component in IBM Mashup Center 3.0.0.1 allows remote authenticated users to cause a denial of service (CPU consumption) via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm mashups_center 3.0.0.1
CVE-2015-7401 MEDIUM

IBM Curam Social Program Management 6.1.x before 6.1.1.1 allows remote authenticated users to bypass intended access restrictions and obtain sensitive document information by guessing the document id. IBM X-Force ID: 107106.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm curam_social_program_management *
CVE-2015-7402 LOW

Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management 6.1 before 6.1.1.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm curam_social_program_management 6.1
CVE-2015-7403 LOW

IBM Spectrum Scale 4.1.1.x before 4.1.1.3 and General Parallel File System (GPFS) 3.5.x before 3.5.0.29 and 4.1.x through 4.1.0.8 on AIX allow local users to cause a denial of service (incorrect pointer dereference and node crash) via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm spectrum_scale 4.1.1.0
ibm spectrum_scale 4.1.1.2
ibm general_parallel_file_system 3.5
ibm spectrum_scale 4.1.1.1
CVE-2015-7404 LOW

IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server (aka Spectrum Protect for Databases) 5.5 before 5.5.6.2, 6.3 before 6.3.1.6, 6.4 before 6.4.1.8, and 7.1 before 7.1.4; Tivoli Storage Manager for Mail: Data Protection for Microsoft Exchange Server (aka Spectrum Protect for Mail) 5.5 before 5.5.1.1, 6.1 and 6.3 before 6.3.1.6, 6.4 before 6.4.1.8, and 7.1 before 7.1.4; and Tivoli Storage FlashCopy Manager for Windows (aka Spectrum Protect Snapshot) 2.x and 3.1 before 3.1.1.6, 3.2 before 3.2.1.8, and 4.1 before 4.1.4, when application tracing is configured, write cleartext passwords during changetsmpassword command execution, which allows local users to obtain sensitive information by reading the application trace output.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server 7.1
ibm tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server 6.4.1
ibm tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server 6.1.1
ibm tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server 7.1.2.1
ibm tivoli_storage_flashcopy_manager 3.2.0
ibm tivoli_storage_flashcopy_manager 2.1.0
ibm tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server 6.3.1.3
ibm tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server 6.3
ibm tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server 6.4.0.2
ibm tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server 7.1.1.1
ibm tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server 6.1.2
ibm tivoli_storage_flashcopy_manager 3.1.1
ibm tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server 6.3.1
ibm tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server 6.1.3
ibm tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server 7.1.0.2
ibm tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server 6.3.1.2
ibm tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server 7.1
ibm tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server 6.3
ibm tivoli_storage_flashcopy_manager 3.1.0
ibm tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server 6.3.1.5
ibm tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server 5.5.2
ibm tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server 5.5.1
ibm tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server 5.5
ibm tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server 7.1.1
ibm tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server 5.5.5
ibm tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server 6.3.1
ibm tivoli_storage_flashcopy_manager 2.2.1
ibm tivoli_storage_flashcopy_manager 6.1.3
ibm tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server 6.4.1.3
ibm tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server 6.4.1.1
ibm tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server 7.1.3.0
ibm tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server 6.1
ibm tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server 6.4.1.7
ibm tivoli_storage_flashcopy_manager 2.2.0
ibm tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server 6.4
ibm tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server 5.5
ibm tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server 6.4.1
ibm tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server 5.5.4
ibm tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server 7.1.0.2
ibm tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server 5.5.1
ibm tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server 6.4
ibm tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server 6.3.1.1
ibm tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server 5.5.6
ibm tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server 6.4.0.1
ibm tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server 6.4.1.4
ibm tivoli_storage_flashcopy_manager 4.1.0
ibm tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server 6.4.1.2
ibm tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server 7.1.0.1
ibm tivoli_storage_flashcopy_manager 3.2.1
ibm tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server 7.1.2.0
ibm tivoli_storage_flashcopy_manager 4.1.0.1
ibm tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server 7.1.2.1
ibm tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server 7.1.0.1
ibm tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server 5.5.3
CVE-2015-7407 MEDIUM

Cross-site request forgery (CSRF) vulnerability in Lotus Mashups in IBM Mashup Center 3.0.0.1 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm mashups_center 3.0.0.1
CVE-2015-7408 LOW

The server in IBM Spectrum Protect (aka Tivoli Storage Manager) 5.5 and 6.x before 6.3.5.1 and 7.x before 7.1.4 does not properly restrict use of the ASNODENAME option, which allows remote attackers to read or write to backup data by leveraging proxy authority.

CVSS 2.0

Severity: LOW

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager 6.3.5.0
ibm tivoli_storage_manager 6.3.4.0
ibm tivoli_storage_manager 7.1.0.3
ibm tivoli_storage_manager 5.5.0.0
ibm tivoli_storage_manager 7.1.0.1
ibm tivoli_storage_manager 6.2.0.0
ibm tivoli_storage_manager 7.1.0.2
ibm tivoli_storage_manager 6.1.0.0
ibm tivoli_storage_manager 6.3.3.0
ibm tivoli_storage_manager 7.1.0.0
CVE-2015-7409 LOW

Cross-site scripting (XSS) vulnerability in IBM Security QRadar SIEM 7.2.x before 7.2.6 allows remote authenticated users to inject arbitrary web script or HTML via an unspecified field.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.2
ibm qradar_security_information_and_event_manager 7.2.0
ibm qradar_security_information_and_event_manager 7.2.3
ibm qradar_security_information_and_event_manager 7.2.4
ibm qradar_security_information_and_event_manager 7.2.1
ibm qradar_security_information_and_event_manager 7.2.5
CVE-2015-7410 MEDIUM

The Health Check tool in IBM Sterling B2B Integrator 5.2 does not properly use cookies in conjunction with HTTPS sessions, which allows man-in-the-middle attackers to obtain sensitive information or modify data via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-17,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2
CVE-2015-7411 HIGH

The portal client in IBM Tivoli Monitoring (ITM) 6.2.2 through FP9, 6.2.3 through FP5, and 6.3.0 through FP6 allows remote authenticated users to gain privileges via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm tivoli_monitoring 6.2.3
ibm tivoli_monitoring 6.2.2.4
ibm tivoli_monitoring 6.2.2.5
ibm tivoli_monitoring 6.2.2.8
ibm tivoli_monitoring 6.3.0
ibm tivoli_monitoring 6.2.2.9
ibm tivoli_monitoring 6.2.2.3
ibm tivoli_monitoring 6.2.2
ibm tivoli_monitoring 6.2.2.7
ibm tivoli_monitoring 6.2.2.1
ibm tivoli_monitoring 6.2.2.2
ibm tivoli_monitoring 6.2.2.6
CVE-2015-7412 LOW

The GatewayScript modules on IBM DataPower Gateways with software 7.2.0.x before 7.2.0.1, when the GatewayScript decryption API or a JWE decrypt action is enabled, do not require signed ciphertext data, which makes it easier for remote attackers to obtain plaintext data via a padding-oracle attack.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm datapower_gateway *
CVE-2015-7413 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.0 before 8.0.0.1 CF19 and 8.5.0 through CF08 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.1
ibm websphere_portal 8.0.0.0
ibm websphere_portal 8.5.0.0
CVE-2015-7414 LOW

Cross-site scripting (XSS) vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 9.1, 10.1, 11.0 before 11.0.0.0 IF11, 11.3 before 11.3.0.0 IF7, and 11.4 before 11.4.0.4 IF1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm infosphere_master_data_management 11.0
ibm infosphere_master_data_management 9.1
ibm infosphere_master_data_management 11.4
ibm infosphere_master_data_management 10.1
ibm infosphere_master_data_management 11.3
CVE-2015-7415 LOW

Multiple cross-site scripting (XSS) vulnerabilities in IBM UrbanCode Deploy 6.0 before 6.0.1.12, 6.1 before 6.1.3.2, and 6.2 before 6.2.0.2 allow remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm urbancode_deploy 6.0.1.3
ibm urbancode_deploy 6.1.1.8
ibm urbancode_deploy 6.0.1.4
ibm urbancode_deploy 6.0.1.7
ibm urbancode_deploy 6.1.1.1
ibm urbancode_deploy 6.1.1.2
ibm urbancode_deploy 6.1.1.5
ibm urbancode_deploy 6.0.1.0
ibm urbancode_deploy 6.2.0.0
ibm urbancode_deploy 6.0.1.5
ibm urbancode_deploy 6.1.1.6
ibm urbancode_deploy 6.1.1.0
ibm urbancode_deploy 6.1.3.1
ibm urbancode_deploy 6.2.0.1
ibm urbancode_deploy 6.1.2
ibm urbancode_deploy 6.0.1.6
ibm urbancode_deploy 6.0.1.11
ibm urbancode_deploy 6.0.1.8
ibm urbancode_deploy 6.1.3
ibm urbancode_deploy 6.0.1.9
ibm urbancode_deploy 6.1.1.3
ibm urbancode_deploy 6.0.1.10
ibm urbancode_deploy 6.0.1.2
ibm urbancode_deploy 6.1.1.7
ibm urbancode_deploy 6.1.1.4
ibm urbancode_deploy 6.0.1.1
ibm urbancode_deploy 6.0
CVE-2015-7416 LOW

AFP Workbench Viewer in IBM i Access 7.1 on Windows allows remote attackers to cause a denial of service (viewer crash) via a crafted workbench file.

CVSS 2.0

Severity: LOW

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm i_access 7.1
CVE-2015-7417 LOW

Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server 7.0 before 7.0.0.41, 8.0 before 8.0.0.12, and 8.5 before 8.5.5.9 allows remote authenticated users to inject arbitrary web script or HTML via crafted data from an OAuth provider.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 8.0.0.5
ibm websphere_application_server 8.5.0.2
ibm websphere_application_server 8.0.0.6
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 8.5.5.2
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 8.5.5.7
ibm websphere_application_server 7.0.0.33
ibm websphere_application_server 7.0.0.25
ibm websphere_application_server 8.0.0.9
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 7.0.0.31
ibm websphere_application_server 7.0.0.0
ibm websphere_application_server 8.5.5.5
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 8.5.5.8
ibm websphere_application_server 8.0.0.8
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 7.0.0.29
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 8.5.5.0
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.37
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 8.0.0.7
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 8.5.5.6
ibm websphere_application_server 8.0.0.11
ibm websphere_application_server 8.0.0.10
ibm websphere_application_server 7.0.0.27
ibm websphere_application_server 7.0.0.39
ibm websphere_application_server 8.5.5.3
ibm websphere_application_server 8.5.5.4
ibm websphere_application_server 7.0.0.35
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 8.5.5.1
ibm websphere_application_server 7.0.0.4
ibm websphere_application_server 8.0.0.2
CVE-2015-7418 LOW

IBM WebSphere eXtreme Scale and the WebSphere DataPower XC10 Appliance allow some sensitive data to linger in memory instead of being overwritten which could allow a local user with administrator privileges to obtain sensitive information.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_extreme_scale 8.5
ibm websphere_extreme_scale 8.6
ibm websphere_extreme_scale 7.1.0
ibm websphere_extreme_scale 7.1.1
CVE-2015-7419 HIGH

IBM WebSphere Portal 8.0.0.1 before CF19 and 8.5.0 before CF09 allows remote attackers to cause a denial of service (memory consumption) via crafted requests.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.1
ibm websphere_portal 8.5.0.0
CVE-2015-7420 MEDIUM

Unspecified vulnerability in GSKit on IBM MQ M2000 appliances before 8.0.0.4 allows remote attackers to obtain sensitive information via unknown vectors, a different vulnerability than CVE-2015-7421.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm mq_appliance_m2000 *
CVE-2015-7421 MEDIUM

Unspecified vulnerability in GSKit on IBM MQ M2000 appliances before 8.0.0.4 allows remote attackers to obtain sensitive information via unknown vectors, a different vulnerability than CVE-2015-7420.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm mq_appliance_m2000 *
CVE-2015-7422 LOW

Buffer overflow in IBM i Access 7.1 on Windows allows local users to cause a denial of service (application crash) via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm i_access 7.1
CVE-2015-7423 LOW

Multiple cross-site scripting (XSS) vulnerabilities in IBM InfoSphere Master Data Management (MDM) - Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 107771.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm infosphere_master_data_management 11.0
ibm infosphere_master_data_management 9.1
ibm infosphere_master_data_management 11.4
ibm infosphere_master_data_management 10.1
ibm infosphere_master_data_management 11.3
CVE-2015-7424 MEDIUM

IBM InfoSphere Master Data Management (MDM) - Collaborative Edition 9.1, 10.1, 11.0, 11.3, 11.4, and 11.5 allow remote authenticated users to bypass intended access restrictions and obtain sensitive information by leveraging Catalogs access. IBM X-Force ID: 107780.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm infosphere_master_data_management 11.0
ibm infosphere_master_data_management 9.1
ibm infosphere_master_data_management 11.4
ibm infosphere_master_data_management 10.1
ibm infosphere_master_data_management 11.3
ibm infosphere_master_data_management 11.5
CVE-2015-7425 HIGH

The Data Protection component in the VMware vSphere GUI in IBM Tivoli Storage Manager for Virtual Environments: Data Protection for VMware (aka Spectrum Protect for Virtual Environments) 6.3 before 6.3.2.5, 6.4 before 6.4.3.1, and 7.1 before 7.1.4 and Tivoli Storage FlashCopy Manager for VMware (aka Spectrum Protect Snapshot) 3.1 before 3.1.1.3, 3.2 before 3.2.0.6, and 4.1 before 4.1.4 allows remote attackers to obtain administrative privileges via a crafted URL that triggers back-end function execution.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm tivoli_storage_flashcopy_manager_for_vmware 6.4
ibm tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware 4.1.1
ibm tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware 7.1.2
ibm tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware 4.1.3
ibm tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware 7.1.0
ibm tivoli_storage_flashcopy_manager_for_vmware 6.4.3
ibm tivoli_storage_flashcopy_manager_for_vmware 3.1
ibm tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware 7.1.1
ibm tivoli_storage_flashcopy_manager_for_vmware 3.2
ibm tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware 7.1.3
ibm tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware 4.1.0
ibm tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware 4.1.2
ibm tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware 6.3.2
ibm tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware 6.4.1
ibm tivoli_storage_flashcopy_manager_for_vmware 3.1.1
ibm tivoli_storage_flashcopy_manager_for_vmware 6.3
ibm tivoli_storage_flashcopy_manager_for_vmware 6.4.2
ibm tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware 6.3.1
CVE-2015-7426 HIGH

The Data Protection extension in the VMware GUI in IBM Tivoli Storage Manager for Virtual Environments: Data Protection for VMware (aka Spectrum Protect for Virtual Environments) 7.1 before 7.1.3.0 and Tivoli Storage FlashCopy Manager for VMware (aka Spectrum Protect Snapshot) 4.1 before 4.1.3.0 allows remote attackers to execute arbitrary OS commands via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-78,

Products Affected

Vendor Product Version
ibm spectrum_protect_for_virtual_environments 7.1
ibm spectrum_protect_snapshot 4.1
CVE-2015-7427 MEDIUM

IBM DataPower Gateway appliances with firmware 6.x before 6.0.0.17, 6.0.1.x before 6.0.1.17, 7.x before 7.0.0.10, 7.1.0.x before 7.1.0.7, and 7.2.x before 7.2.0.1 do not set the secure flag for unspecified cookies in an https session, which makes it easier for remote attackers to capture these cookies by intercepting their transmission within an http session.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm datapower_gateway 7.2.0.0
ibm datapower_gateway 6.0.1.14
ibm datapower_gateway 6.0.1.1
ibm datapower_gateway 7.1.0.6
ibm datapower_gateway 7.0.0.0
ibm datapower_gateway 7.0.0.4
ibm datapower_gateway 6.0.1.16
ibm datapower_gateway 7.0.0.8
ibm datapower_gateway 6.0.1.2
ibm datapower_gateway 6.0.1.3
ibm datapower_gateway 7.0.0.9
ibm datapower_gateway 6.0.1.9
ibm datapower_gateway 7.0.0.2
ibm datapower_gateway 6.0.1.8
ibm datapower_gateway 7.1.0.4
ibm datapower_gateway 6.0.1.7
ibm datapower_gateway *
ibm datapower_gateway 7.0.0.5
ibm datapower_gateway 7.1.0.1
ibm datapower_gateway 6.0.1.0
ibm datapower_gateway 6.0.1.11
ibm datapower_gateway 6.0.1.12
ibm datapower_gateway 7.0.0.6
ibm datapower_gateway 6.0.1.13
ibm datapower_gateway 7.1.0.2
ibm datapower_gateway 6.0.1.4
ibm datapower_gateway 6.0.1.6
ibm datapower_gateway 7.1.0.0
ibm datapower_gateway 6.0.1.5
ibm datapower_gateway 6.0.1.15
ibm datapower_gateway 7.1.0.5
ibm datapower_gateway 6.0.1.10
ibm datapower_gateway 7.0.0.3
ibm datapower_gateway 7.1.0.3
ibm datapower_gateway 7.0.0.7
ibm datapower_gateway 7.0.0.1
CVE-2015-7428 MEDIUM

Open redirect vulnerability in IBM WebSphere Portal 8.0.x before 8.0.0.1 CF20 and 8.5.x before 8.5.0.0 CF09 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.1
ibm websphere_portal 8.0.0.0
ibm websphere_portal 8.5.0.0
CVE-2015-7429 MEDIUM

The Data Protection extension in the VMware GUI in IBM Tivoli Storage Manager for Virtual Environments: Data Protection for VMware (aka Spectrum Protect for Virtual Environments) 7.1 before 7.1.4 and Tivoli Storage FlashCopy Manager for VMware (aka Spectrum Protect Snapshot) 4.1 before 4.1.4 allows remote authenticated users to restore arbitrary virtual machines and consequently obtain sensitive information by visiting the vSphere inventory.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm spectrum_protect_for_virtual_environments 7.1
ibm spectrum_protect_snapshot 4.1
CVE-2015-7431 MEDIUM

Cross-site scripting (XSS) vulnerability in Queue Watcher in IBM Sterling B2B Integrator 5.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2
CVE-2015-7432 LOW

IBM Capacity Management Analytics 2.1.0.0 allows local users to decrypt usernames and passwords by leveraging access to setenv.sh and parameter.txt. IBM X-Force ID: 107861.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm capacity_management_analytics 2.1.0.0
CVE-2015-7433 LOW

IBM Capacity Management Analytics 2.1.0.0 allows local users to discover cleartext usernames and passwords by leveraging access to the CMA install machine. IBM X-Force ID: 107862.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm capacity_management_analytics 2.1.0.0
CVE-2015-7434 LOW

IBM Capacity Management Analytics 2.1.0.0 allows local users to discover encrypted usernames and passwords by leveraging access to the CMA install machine. IBM X-Force ID: 107863.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm capacity_management_analytics 2.1.0.0
CVE-2015-7435 LOW

IBM Tivoli Common Reporting (TCR) 2.1 before IF14, 2.1.1 before IF22, 2.1.1.2 before IF9, 3.1.0.0 through 3.1.2 as used in Cognos Business Intelligence before 10.2 IF16, and 3.1.2.1 as used in Cognos Business Intelligence before 10.2.1.1 IF12 allows local users to bypass the Cognos Application Firewall (CAF) protection mechanism via leading whitespace in the BackURL field.

CVSS 2.0

Severity: LOW

Problem Type: CWE-254,

Products Affected

Vendor Product Version
ibm tivoli_common_reporting 3.1.2.1
ibm tivoli_common_reporting 3.1.0.1
ibm tivoli_common_reporting 2.1.1.2
ibm tivoli_common_reporting 3.1.2
ibm tivoli_common_reporting 2.1.1
ibm tivoli_common_reporting 3.1.0.2
ibm tivoli_common_reporting 3.1
ibm tivoli_common_reporting 2.1
CVE-2015-7436 LOW

IBM Tivoli Common Reporting (TCR) 2.1 before IF14, 2.1.1 before IF22, 2.1.1.2 before IF9, 3.1.0.0 through 3.1.2 as used in Cognos Business Intelligence before 10.2 IF16, and 3.1.2.1 as used in Cognos Business Intelligence before 10.2.1.1 IF12 preserves user permissions across group-add and group-remove operations, which allows local users to bypass intended access restrictions in opportunistic circumstances by leveraging administrative changes to group membership.

CVSS 2.0

Severity: LOW

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm tivoli_common_reporting 3.1.2.1
ibm tivoli_common_reporting 3.1.0.1
ibm tivoli_common_reporting 2.1.1.2
ibm tivoli_common_reporting 3.1.2
ibm tivoli_common_reporting 2.1.1
ibm tivoli_common_reporting 3.1.0.2
ibm tivoli_common_reporting 3.1
ibm tivoli_common_reporting 2.1
CVE-2015-7437 LOW

Queue Watcher in IBM Sterling B2B Integrator 5.2 allows local users to obtain sensitive information via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2
CVE-2015-7438 LOW

IBM Sterling B2B Integrator 5.2 allows local users to obtain sensitive cleartext web-services information by leveraging database access.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2
CVE-2015-7439 MEDIUM

Cross-site scripting (XSS) vulnerability in InfoSphere Data Architect (IDA), as distributed in IBM Rational Software Architect 8.5 through 9.5, Rational Software Architect for WebSphere Software (RSA4WS) 8.5 through 9.5, and Rational Software Architect RealTime (RSART) 8.5 through 9.5, allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_software_architect 8.5.5
ibm rational_software_architect_realtime 9.0.0
ibm rational_software_architect_for_websphere_software 9.1.2
ibm rational_software_architect_realtime 8.5.0
ibm rational_software_architect_realtime 8.5.1
ibm rational_software_architect_for_websphere_software 8.5.5.4
ibm rational_software_architect 9.1.1
ibm rational_software_architect_for_websphere_software 9.1.1
ibm rational_software_architect_for_websphere_software' 8.5.5.1
ibm rational_software_architect_realtime 9.1.2
ibm rational_software_architect_realtime 9.5.0
ibm rational_software_architect_realtime 9.0.0.1
ibm rational_software_architect_realtime 8.5.5
ibm rational_software_architect 8.5.5.1
ibm rational_software_architect_realtime 9.1.0
ibm rational_software_architect_for_websphere_software 8.5.5
ibm rational_software_architect_for_websphere_software 8.5.5.3
ibm rational_software_architect_for_websphere_software 9.1.0
ibm rational_software_architect 8.5.5.4
ibm rational_software_architect 9.1.2
ibm rational_software_architect 8.5.0
ibm rational_software_architect_realtime 8.5.5.2
ibm rational_software_architect_realtime 9.1.1
ibm rational_software_architect_for_websphere_software 9.0.0
ibm rational_software_architect 8.5.5.2
ibm rational_software_architect 8.5.1.0
ibm rational_software_architect_for_websphere_software 9.1.2.1
ibm rational_software_architect_realtime 8.5.1.0
ibm rational_software_architect 8.5.5.3
ibm rational_software_architect 9.5.0
ibm rational_software_architect_realtime 8.5.5.4
ibm rational_software_architect_for_websphere_software 8.5.0
ibm rational_software_architect_for_websphere_software 9.5.0
ibm rational_software_architect_for_websphere_software 8.5.1
ibm rational_software_architect 9.0.0.1
ibm rational_software_architect 9.0.0
ibm rational_software_architect 9.1.2.1
ibm rational_software_architect_for_websphere_software 8.5.1.0
ibm rational_software_architect_realtime 8.5.5.1
ibm rational_software_architect 8.5.1
ibm rational_software_architect_realtime 8.5.5.3
ibm rational_software_architect_for_websphere_software 8.5.5.2
ibm rational_software_architect 9.1.0
ibm rational_software_architect_for_websphere_software 9.0.0.1
ibm rational_software_architect_realtime 9.1.2.1
CVE-2015-7440 MEDIUM

IBM Rational Collaborative Lifecycle Management (CLM) 3.0.1 before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; Rational Quality Manager (RQM) 3.0.x before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; Rational Team Concert (RTC) 3.0.x before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; Rational Requirements Composer (RRC) 3.0.x before 3.0.1.6 iFix7 Interim Fix 1 and 4.0.x before 4.0.7 iFix10; Rational DOORS Next Generation (RDNG) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; Rational Engineering Lifecycle Manager (RELM) 4.0.3, 4.0.4, 4.0.5, 4.0.6, and 4.0.7 before iFix10, 5.0.x before 5.0.2 iFix1, and 6.0.x before 6.0.2; Rational Rhapsody Design Manager (Rhapsody DM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; and Rational Software Architect Design Manager (RSA DM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4 might allow local users to gain privileges via unspecified vectors. IBM X-Force ID: 108098.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm rational_rhapsody_design_manager 5.0.1
ibm rational_software_architect_design_manager 6.0
ibm rational_engineering_lifecycle_manager 5.0
ibm rational_doors_next_generation 6.0.0
ibm rational_team_concert 5.0.2
ibm rational_software_architect_design_manager *
ibm rational_rhapsody_design_manager 5.0
ibm rational_software_architect_design_manager 6.0.1
ibm rational_team_concert 5.0
ibm rational_team_concert 6.0.1
ibm rational_requirements_composer *
ibm rational_rhapsody_design_manager *
ibm rational_rhapsody_design_manager 6.0
ibm rational_collaborative_lifecycle_management *
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 6.0.1
ibm rational_rhapsody_design_manager 6.0.1
ibm rational_software_architect_design_manager 5.0
ibm rational_engineering_lifecycle_manager 5.0.2
ibm rational_rhapsody_design_manager 5.0.2
ibm rational_doors_next_generation *
ibm rational_team_concert *
ibm rational_quality_manager *
ibm rational_engineering_lifecycle_manager *
ibm rational_engineering_lifecycle_manager 5.0.1
ibm rational_team_concert 6.0
ibm rational_doors_next_generation 5.0
ibm rational_software_architect_design_manager 5.0.2
ibm rational_engineering_lifecycle_manager 6.0.1
ibm rational_quality_manager 5.0.2
ibm rational_quality_manager 6.0
ibm rational_quality_manager 5.0
ibm rational_engineering_lifecycle_manager 6.0
ibm rational_software_architect_design_manager 5.0.1
ibm rational_doors_next_generation 5.0.2
ibm rational_doors_next_generation 5.0.1
ibm rational_team_concert 5.0.1
ibm rational_doors_next_generation 6.0.1
CVE-2015-7441 MEDIUM

Remote Artifact Loader (RAL) in IBM WebSphere Process Server 7 and Business Process Manager Advanced 7.5 through 7.5.1.2, 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.2, 8.5.5 through 8.5.5.0, and 8.5.6 through 8.5.6.2 does not properly use SSL for its HTTPS connection, which allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-17,

Products Affected

Vendor Product Version
ibm business_process_manager 8.0.1.2
ibm business_process_manager 8.5.6.0
ibm business_process_manager 8.0.1.1
ibm business_process_manager 7.5.0.1
ibm business_process_manager 8.5.6.1
ibm business_process_manager 7.5.1.0
ibm business_process_manager 7.5.1.1
ibm business_process_manager 8.5.6.2
ibm business_process_manager 8.5.5.0
ibm business_process_manager 8.0.1.0
ibm business_process_manager 7.5.1.2
ibm business_process_manager 8.0.0.0
ibm business_process_manager 8.5.0.1
ibm business_process_manager 8.0.1.3
ibm business_process_manager 8.5.0.0
ibm websphere_process_server 7.0
ibm business_process_manager 7.5.0.0
CVE-2015-7442 MEDIUM

consoleinst.sh in IBM Installation Manager before 1.7.4.4 and 1.8.x before 1.8.4 and Packaging Utility before 1.7.4.4 and 1.8.x before 1.8.4 allows local users to gain privileges via a Trojan horse program that is located in /tmp with a name based on a predicted PID value.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm installation_manager 1.8.2.1
ibm packaging_utility 1.8.2.0
ibm installation_manager 1.8.2.0
ibm packaging_utility 1.8.2.1
ibm packaging_utility 1.8.0.0
ibm installation_manager 1.8.1.0
ibm packaging_utility *
ibm installation_manager 1.8.0.0
ibm installation_manager 1.8.3.0
ibm packaging_utility 1.8.3.0
ibm installation_manager 1.7.4.3
ibm packaging_utility 1.8.1.0
CVE-2015-7444 MEDIUM

The Update Installer in IBM WebSphere Commerce Enterprise 7.0.0.8 and 7.0.0.9 does not properly replicate the search index, which allows attackers to obtain sensitive information via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_commerce 7.0.0.9
ibm websphere_commerce 7.0.0.8
CVE-2015-7445 LOW

IBM Multi-Enterprise Integration Gateway 1.0 through 1.0.0.1 and B2B Advanced Communications 1.x before 1.0.0.4, when guest access is configured, allow remote authenticated users to obtain sensitive information by reading error messages in responses.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm b2b_advanced_communications 1.0.0.2
ibm b2b_advanced_communications 1.0.0.1
ibm b2b_advanced_communications 1.0
ibm b2b_advanced_communications 1.0.0.3
ibm multi-enterprise_integration_gateway 1.0.0
CVE-2015-7446 MEDIUM

Cross-site request forgery (CSRF) vulnerability in IBM Flash System V9000 7.4 before 7.4.1.4, 7.5 before 7.5.1.3, and 7.6 before 7.6.0.4 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm flashsystem_v9000_firmware 7.5
ibm flashsystem_v9000_firmware 7.6
ibm flashsystem_v9000_firmware 7.4
CVE-2015-7447 MEDIUM

IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF20, and 8.5.0 before CF09 allows remote attackers to bypass intended Portal AccessControl REST API access restrictions and obtain sensitive information via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.0
ibm websphere_portal 6.1.0.3
ibm websphere_portal 7.0.0.1
ibm websphere_portal 6.1.5.2
ibm websphere_portal 6.1.0.2
ibm websphere_portal 6.1.0.4
ibm websphere_portal 8.0.0.1
ibm websphere_portal 7.0.0.2
ibm websphere_portal 8.5.0.0
ibm websphere_portal 6.1.5.0
ibm websphere_portal 6.1.0.6
ibm websphere_portal 6.1.5.3
ibm websphere_portal 7.0.0.0
ibm websphere_portal 6.1.0.1
ibm websphere_portal 6.1.5.1
ibm websphere_portal 6.1.0.5
ibm websphere_portal 6.1.0.0
CVE-2015-7448 MEDIUM

SQL injection vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.9 IFIX003, and 7.6.0 before 7.6.0.3 IFIX001; Maximo Asset Management 7.5.0 before 7.5.0.9 IFIX003, 7.5.1, and 7.6.0 before 7.6.0.3 IFIX001 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm tivoli_asset_management_for_it 7.2
ibm maximo_asset_management_essentials 7.5.0.7
ibm change_and_configuration_management_database 7.2.1.3
ibm tivoli_asset_management_for_it 7.2.2
ibm tivoli_service_request_manager 7.1.0.3
ibm maximo_for_government 7.1
ibm maximo_asset_management 7.1.1.13
ibm tivoli_service_request_manager 7.1.0.4
ibm change_and_configuration_management_database 7.1.1.3
ibm maximo_for_utilities 7.5
ibm maximo_asset_management 7.1.1.1
ibm maximo_for_government 7.5
ibm smartcloud_control_desk 7.5.3
ibm maximo_for_nuclear_power 7.5.0.1
ibm tivoli_service_request_manager 7.2.1.5
ibm smartcloud_control_desk 7.5.1.2
ibm maximo_for_life_sciences 7.6
ibm maximo_asset_management_essentials 7.5.0.1
ibm maximo_asset_management_essentials 7.5.0.4
ibm maximo_asset_management 7.5.0.9
ibm change_and_configuration_management_database 7.1.1.5
ibm maximo_asset_management 7.5.0.6
ibm change_and_configuration_management_database 7.1.1.2
ibm maximo_asset_management 7.1.1.7
ibm smartcloud_control_desk 7.5.3.1
ibm smartcloud_control_desk 7.5.1.1
ibm maximo_asset_management 7.5.0.7
ibm maximo_for_oil_and_gas 7.1.1.0
ibm maximo_for_oil_and_gas 7.1
ibm tivoli_service_request_manager 7.2.1.1
ibm maximo_asset_management 7.1.1.5
ibm smartcloud_control_desk 7.5.1.0
ibm tivoli_asset_management_for_it 7.2.0.1
ibm maximo_asset_management 7.5.0.8
ibm maximo_for_transportation 7.6.0.0
ibm maximo_for_oil_and_gas 7.5
ibm change_and_configuration_management_database 7.2.0.2
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management 7.6.0.3
ibm maximo_for_transportation 7.1.0.1
ibm change_and_configuration_management_database 7.1.1.6
ibm maximo_for_nuclear_power 7.5.1
ibm tivoli_service_request_manager 7.2.1.2
ibm maximo_asset_management 7.6.0.0
ibm maximo_asset_management 7.1.1.12
ibm maximo_asset_management 7.5.0.3
ibm change_and_configuration_management_database 7.1.1.4
ibm maximo_asset_management 7.6.0.2
ibm tivoli_service_request_manager 7.1.0.1
ibm tivoli_service_request_manager 7.2.1.6
ibm tivoli_asset_management_for_it 7.1
ibm maximo_for_transportation 7.1
ibm tivoli_service_request_manager 7.2.1.4
ibm maximo_asset_management_essentials 7.1
ibm maximo_asset_management_essentials 7.5.0.9
ibm maximo_asset_management 7.5.0.4
ibm maximo_for_government 7.1.1
ibm smartcloud_control_desk 7.5.0.1
ibm tivoli_asset_management_for_it 7.2.1.0
ibm maximo_for_utilities 7.5.0.1
ibm smartcloud_control_desk 7.5.0.3
ibm tivoli_asset_management_for_it 7.2.1.2
ibm maximo_asset_management 7.1.1.9
ibm maximo_for_utilities 7.1.1
ibm maximo_asset_management_essentials 7.5
ibm change_and_configuration_management_database 7.1.1
ibm maximo_asset_management 7.1.1.10
ibm tivoli_asset_management_for_it 7.2.2.2
ibm smartcloud_control_desk 7.5.1.3
ibm maximo_asset_management_essentials 7.5.0.0
ibm change_and_configuration_management_database 7.2.1.4
ibm maximo_for_nuclear_power 7.1
ibm maximo_for_life_sciences 7.5
ibm tivoli_service_request_manager 7.1.0.5
ibm maximo_for_life_sciences 7.1
ibm maximo_for_nuclear_power 7.5
ibm smartcloud_control_desk 7.5.0.2
ibm maximo_asset_management 7.5.0.5
ibm smartcloud_control_desk 7.6.0.1
ibm maximo_asset_management 7.1.1.2
ibm tivoli_service_request_manager 7.2
ibm maximo_asset_management 7.1.1.11
ibm maximo_asset_management 7.6.0.1
ibm maximo_for_utilities 7.1.2
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
ibm change_and_configuration_management_database 7.2.0.1
ibm maximo_asset_management 7.1
ibm maximo_for_transportation 7.1.1.1
ibm maximo_asset_management 7.5.0.1
ibm maximo_for_transportation 7.5.0.0
ibm tivoli_service_request_manager 7.2.0.1
ibm smartcloud_control_desk 7.6
ibm maximo_asset_management_essentials 7.5.0.5
ibm maximo_for_utilities 7.1
ibm change_and_configuration_management_database 7.2.1.1
ibm change_and_configuration_management_database 7.1
ibm maximo_asset_management_essentials 7.5.0.6
ibm maximo_asset_management_essentials 7.5.0.8
ibm tivoli_service_request_manager 7.2.1.3
ibm tivoli_service_request_manager 7.1.0.2
ibm change_and_configuration_management_database 7.2
ibm tivoli_service_request_manager 7.1.0
ibm maximo_for_transportation 7.1.1
ibm tivoli_asset_management_for_it 7.2.2.1
ibm maximo_asset_management_essentials 7.5.0.2
ibm tivoli_service_request_manager 7.2.1.0
ibm maximo_for_transportation 7.5.1.0
ibm maximo_for_oil_and_gas 7.5.1
ibm change_and_configuration_management_database 7.2.1
ibm change_and_configuration_management_database 7.2.1.2
ibm maximo_asset_management 7.5.0.0
ibm maximo_for_oil_and_gas 7.1.2
ibm smartcloud_control_desk 7.5
ibm maximo_for_energy_optimization 7.1
ibm maximo_asset_management 7.1.1.6
ibm maximo_asset_management_essentials 7.5.0.3
ibm maximo_for_nuclear_power 7.1.1
ibm maximo_for_oil_and_gas 7.1.0.1
CVE-2015-7449 LOW

IBM Rational Collaborative Lifecycle Management (CLM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, 6.0.x before 6.0.1 iFix5, and 6.0.2 before iFix2; Rational Quality Manager (RQM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, 6.0.x before 6.0.1 iFix5, and 6.0.2 before iFix2; Rational Team Concert (RTC) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, 6.0.x before 6.0.1 iFix5, and 6.0.2 before iFix2; Rational Requirements Composer (RRC) 4.0.x before 4.0.7 iFix10; Rational DOORS Next Generation (RDNG) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, 6.0.x before 6.0.1 iFix5, and 6.0.2 before iFix2; Rational Engineering Lifecycle Manager (RELM) 4.0.3, 4.0.4, 4.0.5, 4.0.6, 4.0.7 before iFix1, 5.0.x before 5.0.2 iFix1, and 6.0.x before 6.0.2; Rational Rhapsody Design Manager (Rhapsody DM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, 6.0.x before 6.0.1 iFix5, and 6.0.2 before iFix2; Rational Software Architect Design Manager (RSA DM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, 6.0.x before 6.0.1 iFix5, and 6.0.2 before iFix2 allow local users to obtain sensitive information by leveraging weak encryption. IBM X-Force ID: 108221.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,CWE-326,

Products Affected

Vendor Product Version
ibm rational_rhapsody_design_manager 5.0.1
ibm rational_software_architect_design_manager 5.0.0
ibm rational_rhapsody_design_manager 5.0.0
ibm rational_doors_next_generation 6.0.0
ibm rational_engineering_lifecycle_manager 6.0.0
ibm rational_team_concert 5.0.2
ibm rational_software_architect_design_manager *
ibm rational_engineering_lifecycle_manager 5.0.0
ibm rational_software_architect_design_manager 6.0.1
ibm rational_team_concert 6.0.1
ibm rational_requirements_composer *
ibm rational_rhapsody_design_manager *
ibm rational_collaborative_lifecycle_management *
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 6.0.1
ibm rational_rhapsody_design_manager 6.0.1
ibm rational_rhapsody_design_manager 6.0.2
ibm rational_engineering_lifecycle_manager 5.0.2
ibm rational_rhapsody_design_manager 5.0.2
ibm rational_team_concert 6.0.2
ibm rational_doors_next_generation *
ibm rational_team_concert *
ibm rational_quality_manager *
ibm rational_team_concert 5.0.0
ibm rational_engineering_lifecycle_manager *
ibm rational_engineering_lifecycle_manager 5.0.1
ibm rational_engineering_lifecycle_manager 6.0.2
ibm rational_team_concert 6.0.0
ibm rational_quality_manager 5.0.0
ibm rational_software_architect_design_manager 5.0.2
ibm rational_engineering_lifecycle_manager 6.0.1
ibm rational_software_architect_design_manager 6.0.0
ibm rational_quality_manager 5.0.2
ibm rational_software_architect_design_manager 6.0.2
ibm rational_software_architect_design_manager 5.0.1
ibm rational_doors_next_generation 5.0.0
ibm rational_doors_next_generation 5.0.2
ibm rational_quality_manager 6.0.2
ibm rational_doors_next_generation 6.0.2
ibm rational_quality_manager 6.0.0
ibm rational_doors_next_generation 5.0.1
ibm rational_team_concert 5.0.1
ibm rational_doors_next_generation 6.0.1
ibm rational_rhapsody_design_manager 6.0.0
CVE-2015-7450 HIGH

Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the InvokerTransformer class in the Apache Commons Collections library.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 3.9 5.9
134c704f-9b21-4f2e-91b3-4a467353bcc0 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 3.9 5.9

CVSS 2.0

Severity: HIGH

Problem Type: CWE-502,CWE-502,

Products Affected

Vendor Product Version
ibm websphere_application_server 8.5
ibm tivoli_common_reporting 3.1.2
ibm watson_explorer_analytical_components 11.0
ibm tivoli_common_reporting 2.1.1
ibm watson_content_analytics *
ibm websphere_application_server 8.5.0.0
ibm tivoli_common_reporting 3.1
ibm watson_explorer_annotation_administration_console *
ibm watson_explorer_annotation_administration_console 11.0
ibm websphere_application_server 8.0.0.0
ibm tivoli_common_reporting 2.1
ibm tivoli_common_reporting 3.1.2.1
ibm sterling_b2b_integrator 5.2
ibm sterling_integrator 5.1
ibm tivoli_common_reporting 3.1.0.1
ibm tivoli_common_reporting 2.1.1.2
ibm websphere_application_server 7.0.0.0
ibm tivoli_common_reporting 3.1.0.2
ibm websphere_application_server 8.5.5.5
ibm watson_explorer_analytical_components *
CVE-2015-7451 LOW

Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5 before 7.5.0.9 IF2 and 7.6 before 7.6.0.3 FP3 and Maximo Asset Management 7.5 before 7.5.0.9 IF2, 7.5.1, and 7.6 before 7.6.0.3 FP3 for SmartCloud Control Desk allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm maximo_for_life_sciences 7.5
ibm maximo_for_life_sciences 7.6
ibm smartcloud_control_desk 7.6
ibm maximo_asset_management 7.5
ibm maximo_asset_management_essentials 7.5
ibm maximo_for_nuclear_power 7.5
ibm maximo_for_utilities 7.5
ibm maximo_asset_management 7.6
ibm maximo_for_government 7.5
ibm smartcloud_control_desk 7.5
ibm maximo_for_transportation 7.5
ibm maximo_for_oil_and_gas 7.5
CVE-2015-7452 MEDIUM

IBM Maximo Asset Management 7.5 before 7.5.0.9 FP9 and 7.6 before 7.6.0.3 FP3 and Maximo Asset Management 7.5 before 7.5.0.9 FP9, 7.5.1, and 7.6 before 7.6.0.3 FP3 for SmartCloud Control Desk allow remote authenticated users to obtain sensitive information via the REST API.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm maximo_for_life_sciences 7.5
ibm maximo_for_life_sciences 7.6
ibm smartcloud_control_desk 7.6
ibm maximo_asset_management 7.5
ibm maximo_asset_management_essentials 7.5
ibm maximo_for_nuclear_power 7.5
ibm maximo_for_utilities 7.5
ibm maximo_asset_management 7.6
ibm maximo_for_government 7.5
ibm smartcloud_control_desk 7.5
ibm maximo_for_transportation 7.5
ibm maximo_for_oil_and_gas 7.5
CVE-2015-7453 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management (CLM) 3.0.1 before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; Rational Quality Manager (RQM) 3.0.x before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; Rational Team Concert (RTC) 3.0.x before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; Rational Requirements Composer (RRC) 3.0.x before 3.0.1.6 iFix7 Interim Fix 1 and 4.0.x before 4.0.7 iFix10; Rational DOORS Next Generation (RDNG) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; Rational Engineering Lifecycle Manager (RELM) 4.0.3, 4.0.4, 4.0.5, 4.0.6, and 4.0.7 before iFix10, 5.0.x before 5.0.2 iFix1, and 6.0.x before 6.0.2; Rational Rhapsody Design Manager (Rhapsody DM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; and Rational Software Architect Design Manager (RSA DM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 108296.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_rhapsody_design_manager 5.0.1
ibm rational_software_architect_design_manager 6.0
ibm rational_engineering_lifecycle_manager 5.0
ibm rational_doors_next_generation 6.0.0
ibm rational_team_concert 5.0.2
ibm rational_software_architect_design_manager *
ibm rational_rhapsody_design_manager 5.0
ibm rational_software_architect_design_manager 6.0.1
ibm rational_team_concert 5.0
ibm rational_team_concert 6.0.1
ibm rational_requirements_composer *
ibm rational_rhapsody_design_manager *
ibm rational_rhapsody_design_manager 6.0
ibm rational_collaborative_lifecycle_management *
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 6.0.1
ibm rational_rhapsody_design_manager 6.0.1
ibm rational_software_architect_design_manager 5.0
ibm rational_engineering_lifecycle_manager 5.0.2
ibm rational_rhapsody_design_manager 5.0.2
ibm rational_doors_next_generation *
ibm rational_team_concert *
ibm rational_quality_manager *
ibm rational_engineering_lifecycle_manager *
ibm rational_engineering_lifecycle_manager 5.0.1
ibm rational_team_concert 6.0
ibm rational_doors_next_generation 5.0
ibm rational_software_architect_design_manager 5.0.2
ibm rational_engineering_lifecycle_manager 6.0.1
ibm rational_quality_manager 5.0.2
ibm rational_quality_manager 6.0
ibm rational_quality_manager 5.0
ibm rational_engineering_lifecycle_manager 6.0
ibm rational_software_architect_design_manager 5.0.1
ibm rational_doors_next_generation 5.0.2
ibm rational_doors_next_generation 5.0.1
ibm rational_team_concert 5.0.1
ibm rational_doors_next_generation 6.0.1
CVE-2015-7454 MEDIUM

Business Space in IBM WebSphere Process Server 6.1.2.0 through 7.0.0.5 and Business Process Manager Advanced 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, 8.5.0.x through 8.5.0.2, 8.5.5.x through 8.5.5.0, and 8.5.6.x through 8.5.6.2 allows remote authenticated users to bypass intended access restrictions and create an arbitrary page or space via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_process_server 6.1.2
ibm business_process_manager 8.0.1.2
ibm business_process_manager 8.5.6.0
ibm websphere_process_server 6.2.0.3
ibm business_process_manager 8.0.1.1
ibm websphere_process_server 7.0.0.4
ibm business_process_manager 7.5.1.0
ibm websphere_process_server 7.0.0.2
ibm websphere_process_server 7.0.0.3
ibm websphere_process_server 6.2.0.2
ibm business_process_manager 8.0.1.0
ibm business_process_manager 7.5.1.2
ibm websphere_process_server 6.1.2.2
ibm business_process_manager 8.0.0.0
ibm business_process_manager 8.0.1.3
ibm websphere_process_server 6.2.0.1
ibm business_process_manager 7.5.0.1
ibm websphere_process_server 6.2
ibm websphere_process_server 7.0.0.1
ibm business_process_manager 8.5.6.1
ibm websphere_process_server 6.1.2.3
ibm business_process_manager 8.5.0.2
ibm business_process_manager 7.5.1.1
ibm business_process_manager 8.5.6.2
ibm business_process_manager 8.5.5.0
ibm websphere_process_server 7.0.0.5
ibm business_process_manager 8.5.0.1
ibm business_process_manager 8.5.0.0
ibm websphere_process_server 7.0
ibm websphere_process_server 6.1.2.1
ibm business_process_manager 7.5.0.0
CVE-2015-7455 MEDIUM

IBM WebSphere Portal 7.x through 7.0.0.2 CF29, 8.0.x before 8.0.0.1 CF20, and 8.5.x before 8.5.0.0 CF09 uses weak permissions for content items, which allows remote authenticated users to make modifications via the authoring UI.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.1
ibm websphere_portal 8.0.0.0
ibm websphere_portal 7.0.0.2
ibm websphere_portal 8.5.0.0
ibm websphere_portal 7.0.0.1
ibm websphere_portal 7.0.0.0
CVE-2015-7456 MEDIUM

IBM Spectrum Scale 4.1.1 before 4.1.1.4, and 4.2.0.0, allows remote authenticated users to discover object-storage admin passwords via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm spectrum_scale 4.1.1.0
ibm spectrum_scale 4.1.1.2
ibm spectrum_scale 4.2.2.0
ibm spectrum_scale 4.1.1.1
CVE-2015-7457 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.x before 8.0.0.1 CF20 and 8.5.x before 8.5.0.0 CF09 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.1
ibm websphere_portal 8.0.0.0
ibm websphere_portal 8.5.0.0
CVE-2015-7458 LOW

Cross-site scripting (XSS) vulnerability in IBM Connections 3.0.1.1 and earlier, 4.0, 4.5, and 5.0 before CR4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 108354.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm connections 5.0.0.0
ibm connections 4.5.0.0
ibm connections *
ibm connections 4.0.0.0
CVE-2015-7459 LOW

Cross-site scripting (XSS) vulnerability in IBM Connections 3.0.1.1 and earlier, 4.0, 4.5, and 5.0 before CR4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 108355.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm connections 5.0.0.0
ibm connections 4.5.0.0
ibm connections *
ibm connections 4.0.0.0
CVE-2015-7460 LOW

Cross-site scripting (XSS) vulnerability in IBM Connections 3.0.1.1 and earlier, 4.0, 4.5, and 5.0 before CR4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 108356.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm connections 5.0.0.0
ibm connections 4.5.0.0
ibm connections *
ibm connections 4.0.0.0
CVE-2015-7461 MEDIUM

XML external entity (XXE) vulnerability in IBM Connections 3.0.1.1 and earlier, 4.0, 4.5, and 5.0 before CR4 allows remote authenticated users to cause a denial of service (memory consumption) via crafted XML data. IBM X-Force ID: 108357.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,CWE-611,

Products Affected

Vendor Product Version
ibm connections 5.0.0.0
ibm connections 4.5.0.0
ibm connections *
ibm connections 4.0.0.0
CVE-2015-7462 LOW

IBM WebSphere MQ 8.0.0.4 on IBM i platforms allows local users to discover cleartext certificate-keystore passwords within MQ trace output by leveraging administrator privileges to execute the mqcertck program.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,CWE-255,

Products Affected

Vendor Product Version
ibm websphere_mq 8.0.0.4
CVE-2015-7463 MEDIUM

IBM Business Process Manager 7.5.x, 8.0.x, 8.5.0, 8.5.5, and 8.5.6.0 through cumulative fix 2 allow remote authenticated users to delete process and task data by leveraging incorrect authorization checks. IBM X-Force ID: 108393.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-285,

Products Affected

Vendor Product Version
ibm business_process_manager 8.0.1.2
ibm business_process_manager 8.5.6.0
ibm business_process_manager 8.0.1.1
ibm business_process_manager 7.5.0.1
ibm business_process_manager 8.5.0.2
ibm business_process_manager 7.5.1.0
ibm business_process_manager 7.5.1.1
ibm business_process_manager 8.5.5.0
ibm business_process_manager 8.0.1.0
ibm business_process_manager 7.5.1.2
ibm business_process_manager 8.0.0.0
ibm business_process_manager 8.5.0.1
ibm business_process_manager 8.0.1.3
ibm business_process_manager 8.5.0.0
ibm business_process_manager 7.5.0.0
CVE-2015-7464 MEDIUM

Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote attackers to cause a denial of service (Report Builder server outage) via a crafted request to a Report Builder instance URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm jazz_reporting_service 5.0.2
ibm jazz_reporting_service 6.0
ibm jazz_reporting_service 5.0
ibm jazz_reporting_service 5.0.1
CVE-2015-7465 MEDIUM

Cross-site request forgery (CSRF) vulnerability in Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service (JRS) 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm jazz_reporting_service 6.0
CVE-2015-7466 MEDIUM

Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service (JRS) 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to conduct LDAP injection attacks, and consequently bypass intended query restrictions or modify the LDAP directory, via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-74,

Products Affected

Vendor Product Version
ibm jazz_reporting_service 6.0
CVE-2015-7467 LOW

Cross-site scripting (XSS) vulnerability in Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm jazz_reporting_service 5.0.2
ibm jazz_reporting_service 6.0
ibm jazz_reporting_service 5.0
ibm jazz_reporting_service 5.0.1
CVE-2015-7468 MEDIUM

Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to bypass intended restrictions on administrator tasks via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm jazz_reporting_service 5.0.2
ibm jazz_reporting_service 6.0
ibm jazz_reporting_service 5.0
ibm jazz_reporting_service 5.0.1
CVE-2015-7469 MEDIUM

Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to bypass intended read-only restrictions by leveraging a JazzGuest role.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm jazz_reporting_service 5.0.2
ibm jazz_reporting_service 6.0
ibm jazz_reporting_service 5.0
ibm jazz_reporting_service 5.0.1
CVE-2015-7470 MEDIUM

Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows man-in-the-middle attackers to obtain sensitive information via unspecified vectors, as demonstrated by login information.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm jazz_reporting_service 5.0.2
ibm jazz_reporting_service 6.0
ibm jazz_reporting_service 5.0
ibm jazz_reporting_service 5.0.1
CVE-2015-7471 LOW

Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management (CLM) 3.0.1 before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; Rational Quality Manager (RQM) 3.0.x before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; Rational Team Concert (RTC) 3.0.x before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; Rational Requirements Composer (RRC) 3.0.x before 3.0.1.6 iFix7 Interim Fix 1 and 4.0.x before 4.0.7 iFix10; Rational DOORS Next Generation (RDNG) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; Rational Engineering Lifecycle Manager (RELM) 4.0.3, 4.0.4, 4.0.5, 4.0.6, and 4.0.7 before iFix10, 5.0.x before 5.0.2 iFix1, and 6.0.x before 6.0.2; Rational Rhapsody Design Manager (Rhapsody DM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; and Rational Software Architect Design Manager (RSA DM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4 allows remote authenticated users with project administrator privileges to inject arbitrary web script or HTML via a crafted project. IBM X-Force ID: 108429.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_rhapsody_design_manager 5.0.1
ibm rational_software_architect_design_manager 6.0
ibm rational_engineering_lifecycle_manager 5.0
ibm rational_doors_next_generation 6.0.0
ibm rational_team_concert 5.0.2
ibm rational_software_architect_design_manager *
ibm rational_rhapsody_design_manager 5.0
ibm rational_software_architect_design_manager 6.0.1
ibm rational_team_concert 5.0
ibm rational_team_concert 6.0.1
ibm rational_requirements_composer *
ibm rational_rhapsody_design_manager *
ibm rational_rhapsody_design_manager 6.0
ibm rational_collaborative_lifecycle_management *
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 6.0.1
ibm rational_rhapsody_design_manager 6.0.1
ibm rational_software_architect_design_manager 5.0
ibm rational_engineering_lifecycle_manager 5.0.2
ibm rational_rhapsody_design_manager 5.0.2
ibm rational_doors_next_generation *
ibm rational_team_concert *
ibm rational_quality_manager *
ibm rational_engineering_lifecycle_manager *
ibm rational_engineering_lifecycle_manager 5.0.1
ibm rational_team_concert 6.0
ibm rational_doors_next_generation 5.0
ibm rational_software_architect_design_manager 5.0.2
ibm rational_engineering_lifecycle_manager 6.0.1
ibm rational_quality_manager 5.0.2
ibm rational_quality_manager 6.0
ibm rational_quality_manager 5.0
ibm rational_engineering_lifecycle_manager 6.0
ibm rational_software_architect_design_manager 5.0.1
ibm rational_doors_next_generation 5.0.2
ibm rational_doors_next_generation 5.0.1
ibm rational_team_concert 5.0.1
ibm rational_doors_next_generation 6.0.1
CVE-2015-7472 MEDIUM

IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF20, and 8.5.0 before CF10 allows remote attackers to conduct LDAP injection attacks, and consequently read or write to repository data, via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.0
ibm websphere_portal 6.1.0.3
ibm websphere_portal 7.0.0.1
ibm websphere_portal 6.1.5.2
ibm websphere_portal 6.1.0.2
ibm websphere_portal 6.1.0.4
ibm websphere_portal 8.0.0.1
ibm websphere_portal 7.0.0.2
ibm websphere_portal 8.5.0.0
ibm websphere_portal 6.1.5.0
ibm websphere_portal 6.1.0.6
ibm websphere_portal 6.1.5.3
ibm websphere_portal 7.0.0.0
ibm websphere_portal 6.1.0.1
ibm websphere_portal 6.1.5.1
ibm websphere_portal 6.1.0.5
ibm websphere_portal 6.1.0.0
CVE-2015-7473 LOW

runmqsc in IBM WebSphere MQ 8.x before 8.0.0.5 allows local users to bypass intended queue-manager command access restrictions by leveraging authority for +connect and +dsp.

CVSS 2.0

Severity: LOW

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm websphere_mq 8.0.0.1
ibm websphere_mq 8.0.0.3
ibm websphere_mq 8.0.0.4
ibm websphere_mq 8.0.0.2
CVE-2015-7474 LOW

Cross-site scripting (XSS) vulnerability in Jazz Foundation in IBM Rational Engineering Lifecycle Manager 3.0 before 3.0.1.6 iFix7 Interim Fix 1, 4.0 before 4.0.7 iFix10, 5.0 before 5.0.2 iFix15, and 6.0 before 6.0.1 iFix4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 108501.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_engineering_lifecycle_manager *
CVE-2015-7484 MEDIUM

IBM Rational Engineering Lifecycle Manager 3.0 before 3.0.1.6 iFix7 Interim Fix 1 and 4.0 before 4.0.7 iFix10 allow remote authenticated users with access to lifecycle projects to obtain sensitive information by sending a crafted URL to the Lifecycle Query Engine. IBM X-Force ID: 108619.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_engineering_lifecycle_manager *
CVE-2015-7485 LOW

Cross-site scripting (XSS) vulnerability in IBM Rational Engineering Lifecycle Manager 3.0 before 3.0.1.6 iFix7 Interim Fix 1, 4.0 before 4.0.7 iFix10, 5.0 before 5.0.2 iFix15, and 6.0 before 6.0.1 iFix4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 108626.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_engineering_lifecycle_manager *
CVE-2015-7486 LOW

Cross-site scripting (XSS) vulnerability in IBM Rational Engineering Lifecycle Manager 3.0 before 3.0.1.6 iFix7 Interim Fix 1, 4.0 before 4.0.7 iFix10, 5.0 before 5.0.2 iFix15, and 6.0 before 6.0.1 iFix4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 108633.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_engineering_lifecycle_manager *
CVE-2015-7487 MEDIUM

IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.9 IFIX002, and 7.6.0 before 7.6.0.3 IFIX001; Maximo Asset Management 7.5.0 before 7.5.0.9 IFIX002, 7.5.1, and 7.6.0 before 7.6.0.3 IFIX001 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products allow local users to obtain sensitive information by leveraging administrative privileges and reading log files.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm tivoli_asset_management_for_it 7.2
ibm maximo_asset_management_essentials 7.5.0.7
ibm maximo_asset_management 7.1.1.9
ibm maximo_for_government 7.1
ibm maximo_asset_management 7.1.1.13
ibm maximo_asset_management 7.1.1.10
ibm maximo_for_utilities 7.5
ibm maximo_asset_management 7.1.1.1
ibm maximo_asset_management_essentials 7.5.0.0
ibm maximo_for_government 7.5
ibm maximo_for_nuclear_power 7.1
ibm maximo_for_life_sciences 7.5
ibm maximo_asset_management_essentials 7.5.0.1
ibm maximo_asset_management_essentials 7.5.0.4
ibm maximo_asset_management 7.5.0.9
ibm maximo_for_life_sciences 7.1
ibm maximo_asset_management 7.5.0.6
ibm maximo_for_nuclear_power 7.5
ibm maximo_asset_management 7.1.1.7
ibm maximo_asset_management 7.5.0.7
ibm maximo_asset_management 7.5.0.5
ibm maximo_asset_management 7.1.1.2
ibm maximo_for_oil_and_gas 7.1
ibm maximo_asset_management 7.1.1.5
ibm tivoli_service_request_manager 7.2
ibm smartcloud_control_desk 7.5.1.0
ibm maximo_asset_management 7.1.1.11
ibm maximo_asset_management 7.6.0.1
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
ibm maximo_asset_management 7.5.0.8
ibm maximo_for_oil_and_gas 7.5
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.6.0.3
ibm maximo_asset_management 7.5.0.1
ibm smartcloud_control_desk 7.6
ibm maximo_asset_management_essentials 7.5.0.5
ibm maximo_for_utilities 7.1
ibm maximo_asset_management 7.6
ibm change_and_configuration_management_database 7.1
ibm maximo_asset_management_essentials 7.5.0.6
ibm maximo_asset_management 7.6.0.0
ibm maximo_asset_management_essentials 7.5.0.8
ibm maximo_asset_management 7.1.1.12
ibm change_and_configuration_management_database 7.2
ibm maximo_for_transportation 7.5
ibm tivoli_service_request_manager 7.1.0
ibm maximo_asset_management 7.5.0.3
ibm maximo_asset_management 7.6.0.2
ibm maximo_asset_management_essentials 7.5.0.2
ibm maximo_asset_management 7.5
ibm tivoli_asset_management_for_it 7.1
ibm maximo_for_transportation 7.1
ibm maximo_asset_management 7.5.0.0
ibm maximo_asset_management 7.5.0.4
ibm maximo_for_energy_optimization 7.1
ibm maximo_asset_management 7.1.1.6
ibm maximo_asset_management_essentials 7.5.0.3
CVE-2015-7488 LOW

IBM Spectrum Scale 4.1.1.x before 4.1.1.4 and 4.2.x before 4.2.0.1, in certain LDAP File protocol configurations, allows remote attackers to discover an LDAP password via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm spectrum_scale 4.1.1.0
ibm spectrum_scale 4.2.0.0
ibm spectrum_scale 4.1.1.2
ibm spectrum_scale 4.1.1.1
CVE-2015-7489 HIGH

IBM SPSS Statistics 22.0.0.2 before IF10 and 23.0.0.2 before IF7 uses weak permissions (Everyone: Write) for Python scripts, which allows local users to gain privileges by modifying a script.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm spss_statistics 22.0.0.2
ibm spss_statistics 23.0.0.2
CVE-2015-7490 LOW

IBM InfoSphere Information Server 8.5 through FP3, 8.7 through FP2, 9.1 through 9.1.2.0, 11.3 through 11.3.1.2, and 11.5 allows remote authenticated users to bypass intended access restrictions via a modified cookie.

CVSS 2.0

Severity: LOW

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm infosphere_information_server 8.5.0.2
ibm infosphere_information_server 9.1.0.1
ibm infosphere_information_server 11.5
ibm infosphere_information_server 8.5.0.1
ibm infosphere_information_server 9.1.2
ibm infosphere_information_server 8.5
ibm infosphere_information_server 9.1
ibm infosphere_information_server 11.3.1
ibm infosphere_information_server 8.7.0.2
ibm infosphere_information_server 11.3
ibm infosphere_information_server 8.5.0.3
ibm infosphere_information_server 8.7.0.1
ibm infosphere_information_server 8.7
CVE-2015-7491 LOW

Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.x before 8.0.0.1 CF20 and 8.5.x before 8.5.0.0 CF09 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.1
ibm websphere_portal 8.0.0.0
ibm websphere_portal 8.5.0.0
CVE-2015-7492 LOW

Cross-site scripting (XSS) vulnerability in Reference Data Management (RDM) in IBM InfoSphere Master Data Management 10.1, 11.0 before FP5, 11.3, 11.4, and 11.5 before FP1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm infosphere_master_data_management_reference_data_management 10.1
ibm infosphere_master_data_management_reference_data_management 11.3
ibm infosphere_master_data_management_reference_data_management 11.5
ibm infosphere_master_data_management_reference_data_management 11.4
ibm infosphere_master_data_management_reference_data_management 11.0
CVE-2015-7493 LOW

IBM InfoSphere Information Server could allow a local user under special circumstances to execute commands during installation processes that could expose sensitive information.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm infosphere_information_server 11.3
ibm infosphere_information_server 11.5
ibm infosphere_information_server 8.5
ibm infosphere_information_server 9.1
ibm infosphere_information_server 8.7
CVE-2015-7494 LOW

A vulnerability has been identified in IBM Cloud Orchestrator services/[action]/launch API. An authenticated domain admin user might modify cross domain resources via a /services/[action]/launch API call, provided it would have been possible for the domain admin user to gain access to a resource identifier of the other domain.

CVSS 2.0

Severity: LOW

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm cloud_orchestrator 2.4.0.3
ibm smartcloud_orchestrator 2.3
ibm cloud_orchestrator 2.4.0.1
ibm smartcloud_orchestrator 2.3.0.1
ibm cloud_orchestrator 2.4.0.2
ibm cloud_orchestrator 2.4
ibm cloud_orchestrator 2.5
ibm cloud_orchestrator 2.5.01
CVE-2015-7817 HIGH

Race condition in the administration-panel web service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows remote attackers to obtain privileged-account access, and consequently provide FileReader.jsp input containing directory traversal sequences to read arbitrary text files, via a request to port 40080 or 40443.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-362,

Products Affected

Vendor Product Version
ibm system_networking_switch_center *
lenovo switch_center *
CVE-2015-7818 HIGH

The administration-panel web service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows local users to execute arbitrary JSP code with SYSTEM privileges by using the Apache Axis AdminService deployment method to install a .jsp file.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm system_networking_switch_center *
lenovo switch_center *
CVE-2015-7819 MEDIUM

The DB service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows remote attackers to obtain sensitive administrator-account information via a request on port 40999, as demonstrated by an improperly encrypted password.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm system_networking_switch_center *
lenovo switch_center *
CVE-2015-7820 HIGH

Race condition in the administration-panel web service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows remote attackers to obtain privileged-account access, and consequently provide ZipDownload.jsp input containing directory traversal sequences to read arbitrary files, via a request to port 40080 or 40443.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-362,

Products Affected

Vendor Product Version
ibm system_networking_switch_center *
lenovo switch_center *
CVE-2015-8519 HIGH

Buffer overflow in the server in IBM Tivoli Storage Manager FastBack 5.5.x and 6.x before 6.1.12.2 allows remote attackers to execute arbitrary code via a crafted command, a different vulnerability than CVE-2015-8520, CVE-2015-8521, and CVE-2015-8522.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_fastback 6.1.0.1
ibm tivoli_storage_manager_fastback 6.1.4.0
ibm tivoli_storage_manager_fastback 6.1.5.0
ibm tivoli_storage_manager_fastback 6.1.3
ibm tivoli_storage_manager_fastback 6.1.7.2
ibm tivoli_storage_manager_fastback 6.1.8.0
ibm tivoli_storage_manager_fastback 6.1.11.0
ibm tivoli_storage_manager_fastback 6.1.9
ibm tivoli_storage_manager_fastback 6.1.10.1
ibm tivoli_storage_manager_fastback 6.1.1
ibm tivoli_storage_manager_fastback 6.1.10.0
ibm tivoli_storage_manager_fastback 6.1.2.0
ibm tivoli_storage_manager_fastback 6.1.6.1
ibm tivoli_storage_manager_fastback 6.1.10
ibm tivoli_storage_manager_fastback 6.1.12.1
ibm tivoli_storage_manager_fastback 6.1.9.0
ibm tivoli_storage_manager_fastback 6.1.5
ibm tivoli_storage_manager_fastback 6.1.11
ibm tivoli_storage_manager_fastback 6.1.0
ibm tivoli_storage_manager_fastback 6.1.5.2
ibm tivoli_storage_manager_fastback 6.1.9.1
ibm tivoli_storage_manager_fastback 6.1.6.0
ibm tivoli_storage_manager_fastback 5.5.0
ibm tivoli_storage_manager_fastback 6.1.8
ibm tivoli_storage_manager_fastback 6.1.6.2
ibm tivoli_storage_manager_fastback 6.1.2
ibm tivoli_storage_manager_fastback 6.1.6
ibm tivoli_storage_manager_fastback 6.1.11.1
ibm tivoli_storage_manager_fastback 6.1.12
ibm tivoli_storage_manager_fastback 6.1.4
ibm tivoli_storage_manager_fastback 6.1.7
ibm tivoli_storage_manager_fastback 6.1.7.0
ibm tivoli_storage_manager_fastback 6.1.3.0
ibm tivoli_storage_manager_fastback 6.1.7.1
ibm tivoli_storage_manager_fastback 6.1.1.0
CVE-2015-8520 HIGH

Buffer overflow in the server in IBM Tivoli Storage Manager FastBack 5.5.x and 6.x before 6.1.12.2 allows remote attackers to execute arbitrary code via a crafted command, a different vulnerability than CVE-2015-8519, CVE-2015-8521, and CVE-2015-8522.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_fastback 6.1.0.1
ibm tivoli_storage_manager_fastback 6.1.4.0
ibm tivoli_storage_manager_fastback 6.1.5.0
ibm tivoli_storage_manager_fastback 6.1.3
ibm tivoli_storage_manager_fastback 6.1.7.2
ibm tivoli_storage_manager_fastback 6.1.8.0
ibm tivoli_storage_manager_fastback 6.1.11.0
ibm tivoli_storage_manager_fastback 6.1.9
ibm tivoli_storage_manager_fastback 6.1.10.1
ibm tivoli_storage_manager_fastback 6.1.1
ibm tivoli_storage_manager_fastback 6.1.10.0
ibm tivoli_storage_manager_fastback 6.1.2.0
ibm tivoli_storage_manager_fastback 6.1.6.1
ibm tivoli_storage_manager_fastback 6.1.10
ibm tivoli_storage_manager_fastback 6.1.12.1
ibm tivoli_storage_manager_fastback 6.1.9.0
ibm tivoli_storage_manager_fastback 6.1.5
ibm tivoli_storage_manager_fastback 6.1.11
ibm tivoli_storage_manager_fastback 6.1.0
ibm tivoli_storage_manager_fastback 6.1.5.2
ibm tivoli_storage_manager_fastback 6.1.9.1
ibm tivoli_storage_manager_fastback 6.1.6.0
ibm tivoli_storage_manager_fastback 5.5.0
ibm tivoli_storage_manager_fastback 6.1.8
ibm tivoli_storage_manager_fastback 6.1.6.2
ibm tivoli_storage_manager_fastback 6.1.2
ibm tivoli_storage_manager_fastback 6.1.6
ibm tivoli_storage_manager_fastback 6.1.11.1
ibm tivoli_storage_manager_fastback 6.1.12
ibm tivoli_storage_manager_fastback 6.1.4
ibm tivoli_storage_manager_fastback 6.1.7
ibm tivoli_storage_manager_fastback 6.1.7.0
ibm tivoli_storage_manager_fastback 6.1.3.0
ibm tivoli_storage_manager_fastback 6.1.7.1
ibm tivoli_storage_manager_fastback 6.1.1.0
CVE-2015-8521 HIGH

Buffer overflow in the server in IBM Tivoli Storage Manager FastBack 5.5.x and 6.x before 6.1.12.2 allows remote attackers to execute arbitrary code via a crafted command, a different vulnerability than CVE-2015-8519, CVE-2015-8520, and CVE-2015-8522.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_fastback 6.1.0.1
ibm tivoli_storage_manager_fastback 6.1.4.0
ibm tivoli_storage_manager_fastback 6.1.5.0
ibm tivoli_storage_manager_fastback 6.1.3
ibm tivoli_storage_manager_fastback 6.1.7.2
ibm tivoli_storage_manager_fastback 6.1.8.0
ibm tivoli_storage_manager_fastback 6.1.11.0
ibm tivoli_storage_manager_fastback 6.1.9
ibm tivoli_storage_manager_fastback 6.1.10.1
ibm tivoli_storage_manager_fastback 6.1.1
ibm tivoli_storage_manager_fastback 6.1.10.0
ibm tivoli_storage_manager_fastback 6.1.2.0
ibm tivoli_storage_manager_fastback 6.1.6.1
ibm tivoli_storage_manager_fastback 6.1.10
ibm tivoli_storage_manager_fastback 6.1.12.1
ibm tivoli_storage_manager_fastback 6.1.9.0
ibm tivoli_storage_manager_fastback 6.1.5
ibm tivoli_storage_manager_fastback 6.1.11
ibm tivoli_storage_manager_fastback 6.1.0
ibm tivoli_storage_manager_fastback 6.1.5.2
ibm tivoli_storage_manager_fastback 6.1.9.1
ibm tivoli_storage_manager_fastback 6.1.6.0
ibm tivoli_storage_manager_fastback 5.5.0
ibm tivoli_storage_manager_fastback 6.1.8
ibm tivoli_storage_manager_fastback 6.1.6.2
ibm tivoli_storage_manager_fastback 6.1.2
ibm tivoli_storage_manager_fastback 6.1.6
ibm tivoli_storage_manager_fastback 6.1.11.1
ibm tivoli_storage_manager_fastback 6.1.12
ibm tivoli_storage_manager_fastback 6.1.4
ibm tivoli_storage_manager_fastback 6.1.7
ibm tivoli_storage_manager_fastback 6.1.7.0
ibm tivoli_storage_manager_fastback 6.1.3.0
ibm tivoli_storage_manager_fastback 6.1.7.1
ibm tivoli_storage_manager_fastback 6.1.1.0
CVE-2015-8522 HIGH

Buffer overflow in the server in IBM Tivoli Storage Manager FastBack 5.5.x and 6.x before 6.1.12.2 allows remote attackers to execute arbitrary code via a crafted command, a different vulnerability than CVE-2015-8519, CVE-2015-8520, and CVE-2015-8521.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_fastback 6.1.0.1
ibm tivoli_storage_manager_fastback 6.1.4.0
ibm tivoli_storage_manager_fastback 6.1.5.0
ibm tivoli_storage_manager_fastback 6.1.3
ibm tivoli_storage_manager_fastback 6.1.7.2
ibm tivoli_storage_manager_fastback 6.1.8.0
ibm tivoli_storage_manager_fastback 6.1.11.0
ibm tivoli_storage_manager_fastback 6.1.9
ibm tivoli_storage_manager_fastback 6.1.10.1
ibm tivoli_storage_manager_fastback 6.1.1
ibm tivoli_storage_manager_fastback 6.1.10.0
ibm tivoli_storage_manager_fastback 6.1.2.0
ibm tivoli_storage_manager_fastback 6.1.6.1
ibm tivoli_storage_manager_fastback 6.1.10
ibm tivoli_storage_manager_fastback 6.1.12.1
ibm tivoli_storage_manager_fastback 6.1.9.0
ibm tivoli_storage_manager_fastback 6.1.5
ibm tivoli_storage_manager_fastback 6.1.11
ibm tivoli_storage_manager_fastback 6.1.0
ibm tivoli_storage_manager_fastback 6.1.5.2
ibm tivoli_storage_manager_fastback 6.1.9.1
ibm tivoli_storage_manager_fastback 6.1.6.0
ibm tivoli_storage_manager_fastback 5.5.0
ibm tivoli_storage_manager_fastback 6.1.8
ibm tivoli_storage_manager_fastback 6.1.6.2
ibm tivoli_storage_manager_fastback 6.1.2
ibm tivoli_storage_manager_fastback 6.1.6
ibm tivoli_storage_manager_fastback 6.1.11.1
ibm tivoli_storage_manager_fastback 6.1.12
ibm tivoli_storage_manager_fastback 6.1.4
ibm tivoli_storage_manager_fastback 6.1.7
ibm tivoli_storage_manager_fastback 6.1.7.0
ibm tivoli_storage_manager_fastback 6.1.3.0
ibm tivoli_storage_manager_fastback 6.1.7.1
ibm tivoli_storage_manager_fastback 6.1.1.0
CVE-2015-8523 MEDIUM

The server in IBM Tivoli Storage Manager FastBack 5.5.x and 6.x before 6.1.12.2 allows remote attackers to cause a denial of service (service crash) via crafted packets to a TCP port.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_fastback 6.1.0.1
ibm tivoli_storage_manager_fastback 6.1.4.0
ibm tivoli_storage_manager_fastback 6.1.5.0
ibm tivoli_storage_manager_fastback 6.1.3
ibm tivoli_storage_manager_fastback 6.1.7.2
ibm tivoli_storage_manager_fastback 6.1.8.0
ibm tivoli_storage_manager_fastback 6.1.11.0
ibm tivoli_storage_manager_fastback 6.1.9
ibm tivoli_storage_manager_fastback 6.1.10.1
ibm tivoli_storage_manager_fastback 6.1.1
ibm tivoli_storage_manager_fastback 6.1.10.0
ibm tivoli_storage_manager_fastback 6.1.2.0
ibm tivoli_storage_manager_fastback 6.1.6.1
ibm tivoli_storage_manager_fastback 6.1.10
ibm tivoli_storage_manager_fastback 6.1.12.1
ibm tivoli_storage_manager_fastback 6.1.9.0
ibm tivoli_storage_manager_fastback 6.1.5
ibm tivoli_storage_manager_fastback 6.1.11
ibm tivoli_storage_manager_fastback 6.1.0
ibm tivoli_storage_manager_fastback 6.1.5.2
ibm tivoli_storage_manager_fastback 6.1.9.1
ibm tivoli_storage_manager_fastback 6.1.6.0
ibm tivoli_storage_manager_fastback 5.5.0
ibm tivoli_storage_manager_fastback 6.1.8
ibm tivoli_storage_manager_fastback 6.1.6.2
ibm tivoli_storage_manager_fastback 6.1.2
ibm tivoli_storage_manager_fastback 6.1.6
ibm tivoli_storage_manager_fastback 6.1.11.1
ibm tivoli_storage_manager_fastback 6.1.12
ibm tivoli_storage_manager_fastback 6.1.4
ibm tivoli_storage_manager_fastback 6.1.7
ibm tivoli_storage_manager_fastback 6.1.7.0
ibm tivoli_storage_manager_fastback 6.1.3.0
ibm tivoli_storage_manager_fastback 6.1.7.1
ibm tivoli_storage_manager_fastback 6.1.1.0
CVE-2015-8524 MEDIUM

Cross-site scripting (XSS) vulnerability in Process Portal in IBM Business Process Manager 8.5.0.x through 8.5.0.2, 8.5.5.x through 8.5.5.0, and 8.5.6.x through 8.5.6.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm business_process_manager 8.5.6.0
ibm business_process_manager 8.5.6.2
ibm business_process_manager 8.5.5.0
ibm business_process_manager 8.5.0.1
ibm business_process_manager 8.5.0.0
ibm business_process_manager 8.5.0.2
CVE-2015-8530 MEDIUM

Stack-based buffer overflow in the Initialize function in an ActiveX control in IBM SPSS Statistics 19 and 20 before 20.0.0.2-IF0008, 21 before 21.0.0.2-IF0010, 22 before 22.0.0.2-IF0011, 23 before 23.0.0.3-IF0001, and 24 before 24.0.0.0-IF0003 allows remote authenticated users to execute arbitrary code via a long argument.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm spss_statistics *
ibm spss_statistics 24.0.0.0
CVE-2015-8531 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Security Access Manager for Web 8.0 before 8.0.1.3 IF4 and 9.0 before 9.0.0.1 IF1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm security_access_manager_9.0_firmware 9.0.0
ibm security_access_manager_for_web_8.0_firmware 8.0.1.2
ibm security_access_manager_for_web_8.0_firmware 8.0.0.5
ibm security_access_manager_for_web_8.0_firmware 8.0.0.1
ibm security_access_manager_for_web_8.0_firmware 8.0.1
ibm security_access_manager_for_web_8.0_firmware 8.0.1.0
ibm security_access_manager_for_web_8.0_firmware 8.0.0.2
ibm security_access_manager_for_web_8.0_firmware 8.0.0.3
CVE-2016-0201 MEDIUM

GSKit in IBM Security Network Protection 5.3.1 before 5.3.1.7 and 5.3.2 allows remote attackers to discover credentials by triggering an MD5 collision.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_network_protection_firmware 5.3.1
ibm security_network_protection_firmware 5.3.2
CVE-2016-0202 LOW

A vulnerability has been identified in tasks, backend object generated for handling any action performed by the application in IBM Cloud Orchestrator. It is possible for an authenticated user to view any task of the current users domain.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm cloud_orchestrator 2.4.0.3
ibm cloud_orchestrator 2.4.0.1
ibm cloud_orchestrator 2.3.0.1
ibm cloud_orchestrator 2.3
ibm cloud_orchestrator 2.4.0.2
ibm cloud_orchestrator 2.4
CVE-2016-0203 LOW

A vulnerability has been identified in the IBM Cloud Orchestrator task API. The task API might allow an authenticated user to view background information associated with actions performed on virtual machines in projects where the user belongs to.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm cloud_orchestrator 2.4.0.3
ibm smartcloud_orchestrator 2.3
ibm cloud_orchestrator 2.4.0.1
ibm smartcloud_orchestrator 2.3.0.1
ibm cloud_orchestrator 2.4.0.2
ibm cloud_orchestrator 2.4
ibm cloud_orchestrator 2.5
ibm cloud_orchestrator 2.5.01
CVE-2016-0204 MEDIUM

Open redirect vulnerability in IBM Cloud Orchestrator 2.4.x before 2.4.0 FP3 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-601,

Products Affected

Vendor Product Version
ibm cloud_orchestrator 2.4.0.1
ibm cloud_orchestrator 2.4.0.0
ibm cloud_orchestrator 2.4.0.2
CVE-2016-0205 LOW

A vulnerability has been identified in IBM Cloud Orchestrator 2.3, 2.3.0.1, 2.4, and 2.4.0.1 that could allow an attacker after authentication to enumerate valid users of the system. IBM X-Force ID: 109394.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm cloud_orchestrator 2.4.0.1
ibm cloud_orchestrator 2.3.0.1
ibm cloud_orchestrator 2.3.0.0
ibm cloud_orchestrator 2.4.0.0
CVE-2016-0206 LOW

IBM Cloud Orchestrator could allow a local authenticated attacker to cause the server to slow down for a short period of time by using a specially crafted and malformed URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm cloud_orchestrator 2.4.0.1
ibm cloud_orchestrator 2.3.0.1
ibm cloud_orchestrator 2.3
ibm cloud_orchestrator 2.4.0.2
ibm cloud_orchestrator 2.4
CVE-2016-0207 LOW

IBM Algorithmics One-Algo Risk Application (ARA) 4.9.1 through 5.1.0 allows remote authenticated users to conduct clickjacking attacks via unspecified vectors. IBM X-Force ID: 109399.

CVSS 2.0

Severity: LOW

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm algo_risk_application *
CVE-2016-0208 MEDIUM

IBM WebSphere Commerce 6.x through 6.0.0.11, 7.x through 7.0.0.9, and 8.x before 8.0.0.3 allows remote attackers to cause a denial of service (order-processing outage) via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm websphere_commerce 6.0.0.6
ibm websphere_commerce 7.0.0.6
ibm websphere_commerce 7.0.0.7
ibm websphere_commerce 6.0.0.11
ibm websphere_commerce 6.0.0.10
ibm websphere_commerce 7.0.0.3
ibm websphere_commerce 7.0.0.2
ibm websphere_commerce 7.0
ibm websphere_commerce 6.0.0.7
ibm websphere_commerce 6.0.0.8
ibm websphere_commerce 8.0.0.1
ibm websphere_commerce 7.0.0.5
ibm websphere_commerce 6.0.0.0
ibm websphere_commerce 7.0.0.1
ibm websphere_commerce 6.0.0.5
ibm websphere_commerce 7.0.0.8
ibm websphere_commerce 8.0.0.2
ibm websphere_commerce 7.0.0.4
ibm websphere_commerce 6.0.0.1
ibm websphere_commerce 6.0.0.2
ibm websphere_commerce 7.0.0.9
ibm websphere_commerce 8.0.0.0
ibm websphere_commerce 6.0.0.3
ibm websphere_commerce 6.0.0.4
ibm websphere_commerce 6.0.0.9
CVE-2016-0209 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.5.0 before CF09 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 8.5.0.0
CVE-2016-0210 MEDIUM

IBM Sterling B2B Integrator Standard Edition could allow a remote attacker to obtain sensitive information. By allowing HTTP OPTIONS method, a remote attacker could send a specially-crafted query to a vulnerable server running to cause the server to disclose sensitive information in the HTTP response.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2
ibm sterling_b2b_integrator 5.1
CVE-2016-0211 MEDIUM

IBM DB2 9.7 through FP11, 9.8, 10.1 through FP5, and 10.5 through FP7 on Linux, UNIX, and Windows allows remote authenticated users to cause a denial of service (daemon crash) via a crafted DRDA message.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm db2_connect 9.8.0.1
ibm db2_connect 10.1
ibm db2_connect 9.7.0.11
ibm db2 10.1.0.1
ibm db2_connect 10.1.0.3
ibm db2_connect 9.7.0.8
ibm db2_connect 9.7.0.6
ibm db2 10.5.0.1
ibm db2 10.5.0.2
ibm db2 9.7.0.2
ibm db2 9.7.0.1
ibm db2 9.8.0.3
ibm db2_connect 10.5.0.5
ibm db2 9.8
ibm db2_connect 9.8
ibm db2 10.1.0.5
ibm db2_connect 9.7
ibm db2 10.5.0.4
ibm db2 10.1.0.3
ibm db2_connect 10.1.0.5
ibm db2 10.5.0.7
ibm db2 9.7.0.7
ibm db2_connect 10.1.0.4
ibm db2 9.7
ibm db2 9.7.0.3
ibm db2 10.5.0.3
ibm db2 9.7.0.11
ibm db2_connect 9.7.0.4
ibm db2_connect 9.8.0.5
ibm db2_connect 10.1.0.2
ibm db2 9.8.0.4
ibm db2_connect 10.5.0.3
ibm db2_connect 9.7.0.9
ibm db2 10.5
ibm db2 9.7.0.9
ibm db2_connect 9.7.0.5
ibm db2_connect 10.5.0.2
ibm db2_connect 9.8.0.4
ibm db2 9.7.0.5
ibm db2_connect 10.5.0.4
ibm db2 9.7.0.6
ibm db2 9.8.0.2
ibm db2 9.7.0.10
ibm db2 9.8.0.1
ibm db2 9.7.0.8
ibm db2 10.1.0.4
ibm db2 10.1
ibm db2_connect 9.7.0.10
ibm db2_connect 9.8.0.3
ibm db2_connect 10.1.0.1
ibm db2_connect 10.5.0.6
ibm db2_connect 9.7.0.7
ibm db2 10.1.0.2
ibm db2_connect 9.7.0.3
ibm db2 9.7.0.4
ibm db2 10.5.0.5
ibm db2_connect 10.5.0.7
ibm db2_connect 10.5.0.1
ibm db2 10.5.0.6
ibm db2_connect 10.5
ibm db2 9.8.0.5
ibm db2_connect 9.7.0.1
ibm db2_connect 9.7.0.2
ibm db2_connect 9.8.0.2
CVE-2016-0212 HIGH

Stack-based buffer overflow in IBM Tivoli Storage Manager FastBack 5.5 and 6.1.x through 6.1.11.1 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, a different vulnerability than CVE-2016-0213 and CVE-2016-0216.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_fastback 6.1.0.1
ibm tivoli_storage_manager_fastback 6.1.4.0
ibm tivoli_storage_manager_fastback 6.1.5.0
ibm tivoli_storage_manager_fastback 6.1.0.0
ibm tivoli_storage_manager_fastback 6.1.3
ibm tivoli_storage_manager_fastback 6.1.7.2
ibm tivoli_storage_manager_fastback 6.1.8.0
ibm tivoli_storage_manager_fastback 6.1.11.0
ibm tivoli_storage_manager_fastback 6.1.9
ibm tivoli_storage_manager_fastback 6.1.10.1
ibm tivoli_storage_manager_fastback 6.1.1
ibm tivoli_storage_manager_fastback 6.1.10.0
ibm tivoli_storage_manager_fastback 6.1.2.0
ibm tivoli_storage_manager_fastback 6.1.6.1
ibm tivoli_storage_manager_fastback 6.1.10
ibm tivoli_storage_manager_fastback 6.1.9.0
ibm tivoli_storage_manager_fastback 6.1.5
ibm tivoli_storage_manager_fastback 6.1.11
ibm tivoli_storage_manager_fastback 6.1.0
ibm tivoli_storage_manager_fastback 6.1.5.2
ibm tivoli_storage_manager_fastback 6.1.9.1
ibm tivoli_storage_manager_fastback 6.1.6.0
ibm tivoli_storage_manager_fastback 5.5.0
ibm tivoli_storage_manager_fastback 6.1.8
ibm tivoli_storage_manager_fastback 6.1.6.2
ibm tivoli_storage_manager_fastback 6.1.2
ibm tivoli_storage_manager_fastback 6.1.6
ibm tivoli_storage_manager_fastback 6.1.11.1
ibm tivoli_storage_manager_fastback 6.1.4
ibm tivoli_storage_manager_fastback 6.1.7
ibm tivoli_storage_manager_fastback 6.1.7.0
ibm tivoli_storage_manager_fastback 6.1.8.1
ibm tivoli_storage_manager_fastback 6.1.3.0
ibm tivoli_storage_manager_fastback 6.1.7.1
ibm tivoli_storage_manager_fastback 6.1.1.0
CVE-2016-0213 HIGH

Stack-based buffer overflow in IBM Tivoli Storage Manager FastBack 5.5 and 6.1.x through 6.1.11.1 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, a different vulnerability than CVE-2016-0212 and CVE-2016-0216.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_fastback 6.1.0.1
ibm tivoli_storage_manager_fastback 6.1.4.0
ibm tivoli_storage_manager_fastback 6.1.5.0
ibm tivoli_storage_manager_fastback 6.1.0.0
ibm tivoli_storage_manager_fastback 6.1.3
ibm tivoli_storage_manager_fastback 6.1.7.2
ibm tivoli_storage_manager_fastback 6.1.8.0
ibm tivoli_storage_manager_fastback 6.1.11.0
ibm tivoli_storage_manager_fastback 6.1.9
ibm tivoli_storage_manager_fastback 6.1.10.1
ibm tivoli_storage_manager_fastback 6.1.1
ibm tivoli_storage_manager_fastback 6.1.10.0
ibm tivoli_storage_manager_fastback 6.1.2.0
ibm tivoli_storage_manager_fastback 6.1.6.1
ibm tivoli_storage_manager_fastback 6.1.10
ibm tivoli_storage_manager_fastback 6.1.9.0
ibm tivoli_storage_manager_fastback 6.1.5
ibm tivoli_storage_manager_fastback 6.1.11
ibm tivoli_storage_manager_fastback 6.1.0
ibm tivoli_storage_manager_fastback 6.1.5.2
ibm tivoli_storage_manager_fastback 6.1.9.1
ibm tivoli_storage_manager_fastback 6.1.6.0
ibm tivoli_storage_manager_fastback 5.5.0
ibm tivoli_storage_manager_fastback 6.1.8
ibm tivoli_storage_manager_fastback 6.1.6.2
ibm tivoli_storage_manager_fastback 6.1.2
ibm tivoli_storage_manager_fastback 6.1.6
ibm tivoli_storage_manager_fastback 6.1.11.1
ibm tivoli_storage_manager_fastback 6.1.4
ibm tivoli_storage_manager_fastback 6.1.7
ibm tivoli_storage_manager_fastback 6.1.7.0
ibm tivoli_storage_manager_fastback 6.1.8.1
ibm tivoli_storage_manager_fastback 6.1.3.0
ibm tivoli_storage_manager_fastback 6.1.7.1
ibm tivoli_storage_manager_fastback 6.1.1.0
CVE-2016-0214 MEDIUM

IBM Tivoli Endpoint Manager could allow a remote attacker to upload arbitrary files. A remote attacker could exploit this vulnerability to upload a malicious file. The only way that file would be executed would be through a phishing attack to trick an unsuspecting victim to execute the file.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm bigfix_platform 9.2
ibm bigfix_platform 9.1
ibm bigfix_platform 9.5
ibm bigfix_platform 9.0
CVE-2016-0215 MEDIUM

IBM DB2 9.7, 10.1 before FP6, and 10.5 before FP8 on AIX, Linux, HP, Solaris and Windows allow remote authenticated users to cause a denial of service (daemon crash) via a SELECT statement with a subquery containing the AVG OLAP function on an Oracle compatible database.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2 10.1
ibm db2 9.8
ibm db2 9.7
CVE-2016-0216 HIGH

Stack-based buffer overflow in IBM Tivoli Storage Manager FastBack 5.5 and 6.1.x through 6.1.11.1 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, a different vulnerability than CVE-2016-0212 and CVE-2016-0213.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_fastback 6.1.0.1
ibm tivoli_storage_manager_fastback 6.1.4.0
ibm tivoli_storage_manager_fastback 6.1.5.0
ibm tivoli_storage_manager_fastback 6.1.3
ibm tivoli_storage_manager_fastback 6.1.7.2
ibm tivoli_storage_manager_fastback 6.1.8.0
ibm tivoli_storage_manager_fastback 6.1.11.0
ibm tivoli_storage_manager_fastback 6.1.9
ibm tivoli_storage_manager_fastback 6.1.10.1
ibm tivoli_storage_manager_fastback 6.1.1
ibm tivoli_storage_manager_fastback 6.1.10.0
ibm tivoli_storage_manager_fastback 6.1.2.0
ibm tivoli_storage_manager_fastback 6.1.6.1
ibm tivoli_storage_manager_fastback 6.1.10
ibm tivoli_storage_manager_fastback 6.1.9.0
ibm tivoli_storage_manager_fastback 6.1.5
ibm tivoli_storage_manager_fastback 6.1.11
ibm tivoli_storage_manager_fastback 6.1.0
ibm tivoli_storage_manager_fastback 6.1.5.2
ibm tivoli_storage_manager_fastback 6.1.9.1
ibm tivoli_storage_manager_fastback 6.1.6.0
ibm tivoli_storage_manager_fastback 5.5.0
ibm tivoli_storage_manager_fastback 6.1.8
ibm tivoli_storage_manager_fastback 6.1.6.2
ibm tivoli_storage_manager_fastback 6.1.2
ibm tivoli_storage_manager_fastback 6.1.6
ibm tivoli_storage_manager_fastback 6.1.11.1
ibm tivoli_storage_manager_fastback 6.1.4
ibm tivoli_storage_manager_fastback 6.1.7
ibm tivoli_storage_manager_fastback 6.1.7.0
ibm tivoli_storage_manager_fastback 6.1.3.0
ibm tivoli_storage_manager_fastback 6.1.7.1
ibm tivoli_storage_manager_fastback 6.1.1.0
CVE-2016-0217 LOW

IBM Cognos Business Intelligence and IBM Cognos Analytics are vulnerable to stored cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim's Web browser within the security context of the hosting Web site, once the page is viewed. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm cognos_analytics 11.0.1
ibm cognos_analytics 11.0.3
ibm cognos_analytics 11.0.2
ibm cognos_analytics 11.0.0
ibm cognos_analytics 11.0.4
CVE-2016-0218 LOW

IBM Cognos Business Intelligence and IBM Cognos Analytics are vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm cognos_business_intelligence 10.2.1
ibm cognos_business_intelligence 10.2
ibm cognos_business_intelligence 10.2.1.1
ibm cognos_business_intelligence 10.1.1
ibm cognos_business_intelligence 10.2.2
CVE-2016-0219 MEDIUM

XML external entity (XXE) vulnerability in IBM Rational Team Concert 3.0 before 3.0.1.6 iFix7 Interim Fix 1, 4.0 before 4.0.7 iFix10, 5.0 before 5.0.2 iFix15, and 6.0 before 6.0.1 iFix4 allows remote authenticated users to cause a denial of service via crafted XML data. IBM X-Force ID: 109693.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm rational_collaborative_lifecycle_management 3.0.1.2
ibm rational_rhapsody_design_manager 4.0.4
ibm rational_rhapsody_design_manager 4.0.5
ibm rational_software_architect_design_manager 6.0
ibm rational_collaborative_lifecycle_management 4.0.6
ibm rational_engineering_lifecycle_manager 4.0.7
ibm rational_requirements_composer 3.0.1.4
ibm rational_requirements_composer 3.0.1.1
ibm rational_software_architect_design_manager 6.0.1
ibm rational_team_concert 5.0
ibm rational_software_architect_design_manager 4.0.7
ibm rational_quality_manager 6.0.1
ibm rational_engineering_lifecycle_manager 5.0.2
ibm rational_rhapsody_design_manager 5.0.2
ibm rational_quality_manager 4.0.3
ibm rational_team_concert 4.0.1
ibm rational_team_concert 4.0.5
ibm rational_doors_next_generation 5.0
ibm rational_team_concert 4.0.2
ibm rational_quality_manager 5.0
ibm rational_collaborative_lifecycle_management 3.0.1.3
ibm rational_collaborative_lifecycle_management 4.0.5
ibm rational_collaborative_lifecycle_management 4.0.7
ibm rational_collaborative_lifecycle_management 4.0.3
ibm rational_software_architect_design_manager 4.0.6
ibm rational_doors_next_generation 4.0.7
ibm rational_doors_next_generation 4.0.2
ibm rational_team_concert 3.0.1.4
ibm rational_requirements_composer 4.0
ibm rational_team_concert 3.0.1.1
ibm rational_doors_next_generation 6.0
ibm rational_requirements_composer 3.0
ibm rational_rhapsody_design_manager 4.0.7
ibm rational_requirements_composer 4.0.4
ibm rational_engineering_lifecycle_manager 5.0
ibm rational_team_concert 5.0.2
ibm rational_requirements_composer 4.0.1
ibm rational_requirements_composer 3.0.1.2
ibm rational_requirements_composer 4.0.7
ibm rational_collaborative_lifecycle_management 4.0.1
ibm rational_rhapsody_design_manager 5.0
ibm rational_team_concert 4.0.3
ibm rational_collaborative_lifecycle_management 3.0.1.4
ibm rational_quality_manager 3.0.1.3
ibm rational_team_concert 3.0.1
ibm rational_collaborative_lifecycle_management 4.0.2
ibm rational_quality_manager 3.0
ibm rational_quality_manager 4.0.1
ibm rational_team_concert 4.0.6
ibm rational_quality_manager 3.0.1.2
ibm rational_engineering_lifecycle_manager 4.0.5
ibm rational_requirements_composer 4.0.2
ibm rational_software_architect_design_manager 5.0.2
ibm rational_engineering_lifecycle_manager 6.0.1
ibm rational_requirements_composer 4.0.3
ibm rational_quality_manager 6.0
ibm rational_doors_next_generation 4.0.4
ibm rational_quality_manager 3.0.1.4
ibm rational_quality_manager 4.0.4
ibm rational_engineering_lifecycle_manager 4.0.6
ibm rational_rhapsody_design_manager 4.0.3
ibm rational_collaborative_lifecycle_management 3.0.1.5
ibm rational_doors_next_generation 5.0.2
ibm rational_quality_manager 4.0.2
ibm rational_doors_next_generation 4.0
ibm rational_requirements_composer 4.0.5
ibm rational_doors_next_generation 5.0.1
ibm rational_software_architect_design_manager 4.0.1
ibm rational_team_concert 3.0.1.6
ibm rational_collaborative_lifecycle_management 4.0.4
ibm rational_team_concert 4.0.0.1
ibm rational_engineering_lifecycle_manager 4.0.3
ibm rational_engineering_lifecycle_manager 4.0.4
ibm rational_software_architect_design_manager 4.0.2
ibm rational_collaborative_lifecycle_management 6.0
ibm rational_quality_manager 4.0.0.1
ibm rational_quality_manager 4.0.0.2
ibm rational_team_concert 6.0.1
ibm rational_rhapsody_design_manager 6.0
ibm rational_quality_manager 4.0.7
ibm rational_requirements_composer 3.0.1.6
ibm rational_rhapsody_design_manager 4.0.6
ibm rational_rhapsody_design_manager 6.0.1
ibm rational_requirements_composer 4.0.6
ibm rational_software_architect_design_manager 5.0
ibm rational_software_architect_design_manager 4.0.4
ibm rational_doors_next_generation 4.0.1
ibm rational_engineering_lifecycle_manager 5.0.1
ibm rational_quality_manager 3.0.1.5
ibm rational_team_concert 4.0.7
ibm rational_team_concert 3.0.1.2
ibm rational_team_concert 6.0
ibm rational_software_architect_design_manager 4.0.3
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_quality_manager 5.0.2
ibm rational_rhapsody_design_manager 4.0.1
ibm rational_rhapsody_design_manager 4.0.2
ibm rational_team_concert 4.0.0.2
ibm rational_rhapsody_design_manager 4.0
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_requirements_composer 3.0.1
ibm rational_requirements_composer 3.0.1.3
ibm rational_collaborative_lifecycle_management 3.0.1.6
ibm rational_quality_manager 3.0.1.6
ibm rational_doors_next_generation 6.0.1
ibm rational_rhapsody_design_manager 5.0.1
ibm rational_quality_manager 3.0.1.1
ibm rational_team_concert 4.0
ibm rational_doors_next_generation 4.0.5
ibm rational_collaborative_lifecycle_management 4.0
ibm rational_doors_next_generation 4.0.6
ibm rational_team_concert 3.0
ibm rational_doors_next_generation 4.0.3
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 4.0
ibm rational_collaborative_lifecycle_management 5.0
ibm rational_collaborative_lifecycle_management 3.0.1
ibm rational_requirements_composer 3.0.1.5
ibm rational_team_concert 3.0.1.5
ibm rational_team_concert 3.0.1.3
ibm rational_quality_manager 3.0.1
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_collaborative_lifecycle_management 3.0.1.1
ibm rational_software_architect_design_manager 4.0.5
ibm rational_engineering_lifecycle_manager 6.0
ibm rational_team_concert 4.0.4
ibm rational_software_architect_design_manager 5.0.1
ibm rational_software_architect_design_manager 4.0
ibm rational_quality_manager 4.0.5
ibm rational_team_concert 5.0.1
CVE-2016-0221 LOW

Cross-site scripting (XSS) vulnerability in IBM Cognos TM1, as used in IBM Cognos Business Intelligence 10.2 before IF20, 10.2.1 before IF17, 10.2.1.1 before IF16, 10.2.2 before IF12, and 10.1.1 before IF19, allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm cognos_business_intelligence 10.2.1
ibm cognos_business_intelligence 10.2
ibm cognos_business_intelligence 10.2.1.1
ibm cognos_business_intelligence 10.1.1
ibm cognos_business_intelligence 10.2.2
CVE-2016-0222 MEDIUM

IBM Maximo Asset Management 7.6 before 7.6.0.3 IFIX001 allows remote authenticated users to bypass intended access restrictions and read arbitrary purchase-order work logs via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm maximo_for_life_sciences -
ibm smartcloud_control_desk -
ibm maximo_asset_management 7.6.0.3
ibm maximo_for_transportation -
ibm maximo_asset_management 7.6.0.0
ibm maximo_for_oil_and_gas -
ibm maximo_for_government -
ibm maximo_for_nuclear_power -
ibm maximo_asset_management 7.6.0.1
ibm maximo_for_utilities -
ibm maximo_asset_management 7.6.0.2
CVE-2016-0223 MEDIUM

Cross-site scripting (XSS) vulnerability in the Webform Framework API in IBM Forms Server 4.0.x, 8.0.x, 8.1, and 8.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 110006.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm forms_server 8.0.0.0
ibm forms_server 4.0.0.0
ibm forms_server 8.1.0.0
ibm forms_server 8.0.1.0
ibm forms_server 8.2.0.0
CVE-2016-0224 HIGH

SQL injection vulnerability in IBM Marketing Platform 8.5.x, 8.6.x, and 9.x before 9.1.2.2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm marketing_platform 9.1.0.1
ibm marketing_platform 8.6.0.1
ibm marketing_platform 8.5.0.5
ibm marketing_platform 8.6.0.6
ibm marketing_platform 9.1.0.3
ibm marketing_platform 9.1.0.6
ibm marketing_platform 8.5.0.6
ibm marketing_platform 9.1.0.7
ibm marketing_platform 8.6.0.3
ibm marketing_platform 8.6.0.9
ibm marketing_platform 9.1.0.4
ibm marketing_platform 9.1.1.1
ibm marketing_platform 9.0.0.4
ibm marketing_platform 9.1.1.0
ibm marketing_platform 8.5.0.7
ibm marketing_platform 9.1.1.2
ibm marketing_platform 8.6.0.5
ibm marketing_platform 9.0.0.1
ibm marketing_platform 8.6.0.0
ibm marketing_platform 8.6.0.10
ibm marketing_platform 9.0.0.2
ibm marketing_platform 9.1.1.4
ibm marketing_platform 8.5.0.2
ibm marketing_platform 9.1.0.8
ibm marketing_platform 8.5.0.3
ibm marketing_platform 9.1.0.9
ibm marketing_platform 8.5.0.1
ibm marketing_platform 8.6.0.11
ibm marketing_platform 9.1.0.2
ibm marketing_platform 8.6.0.7
ibm marketing_platform 8.6.0.2
ibm marketing_platform 8.6.0.8
ibm marketing_platform 9.1.0.5
ibm marketing_platform 8.6.0.4
ibm marketing_platform 8.5.0.4
ibm marketing_platform 9.1.1.3
ibm marketing_platform 9.0.0.0
ibm marketing_platform 9.0.0.3
ibm marketing_platform 8.5.0.0
ibm marketing_platform 9.1.2.0
ibm marketing_platform 9.1.0.0
ibm marketing_platform 9.1.0.10
CVE-2016-0225 MEDIUM

IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.9 allows remote authenticated Commerce Accelerator administrators to obtain sensitive information via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,CWE-284,

Products Affected

Vendor Product Version
ibm websphere_commerce 6.0.0.6
ibm websphere_commerce 7.0.0.4
ibm websphere_commerce 7.0.0.6
ibm websphere_commerce 7.0.0.7
ibm websphere_commerce 6.0.0.11
ibm websphere_commerce 6.0.0.1
ibm websphere_commerce 6.0.0.2
ibm websphere_commerce 6.0.0.10
ibm websphere_commerce 7.0.0.3
ibm websphere_commerce 7.0.0.9
ibm websphere_commerce 7.0.0.2
ibm websphere_commerce 7.0
ibm websphere_commerce 6.0.0.7
ibm websphere_commerce 6.0.0.8
ibm websphere_commerce 7.0.0.5
ibm websphere_commerce 6.0.0.3
ibm websphere_commerce 6.0.0.0
ibm websphere_commerce 6.0.0.4
ibm websphere_commerce 6.0.0.9
ibm websphere_commerce 7.0.0.1
ibm websphere_commerce 6.0.0.5
ibm websphere_commerce 7.0.0.8
CVE-2016-0226 MEDIUM

The client implementation in IBM Informix Dynamic Server 11.70.xCn on Windows does not properly restrict access to the (1) nsrd, (2) nsrexecd, and (3) portmap executable files, which allows local users to gain privileges via a Trojan horse file.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm informix_dynamic_server 11.70.xcn
CVE-2016-0227 LOW

Cross-site scripting (XSS) vulnerability in the document-list control implementation in IBM Business Process Manager (BPM) 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.2, and 8.5.5 and 8.5.6 through 8.5.6.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm business_process_manager 8.0.1.2
ibm business_process_manager 8.5.6.0
ibm business_process_manager 8.5.6.2
ibm business_process_manager 8.0.1.1
ibm business_process_manager 8.5.5.0
ibm business_process_manager 8.0.1.0
ibm business_process_manager 8.0.0.0
ibm business_process_manager 8.5.0.1
ibm business_process_manager 8.0.1.3
ibm business_process_manager 8.5.0.0
ibm business_process_manager 8.5.0.2
CVE-2016-0228 MEDIUM

IBM Marketing Platform 10.0 could allow a remote attacker to conduct phishing attacks, caused by an open redirect vulnerability in various scripts. An attacker could exploit this vulnerability to redirect a victim to arbitrary Web sites. IBM X-Force ID: 110236.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-601,

Products Affected

Vendor Product Version
ibm marketing_platform 10.0
CVE-2016-0229 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Marketing Platform 8.6.x and 9.x before 9.1.2.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm marketing_platform 9.1.0.1
ibm marketing_platform 8.6.0.1
ibm marketing_platform 8.6.0.6
ibm marketing_platform 9.1.0.3
ibm marketing_platform 9.1.0.6
ibm marketing_platform 9.1.0.7
ibm marketing_platform 8.6.0.3
ibm marketing_platform 8.6.0.9
ibm marketing_platform 9.1.0.4
ibm marketing_platform 9.1.1.1
ibm marketing_platform 9.0.0.4
ibm marketing_platform 9.1.1.0
ibm marketing_platform 9.1.1.2
ibm marketing_platform 8.6.0.5
ibm marketing_platform 9.0.0.1
ibm marketing_platform 8.6.0.0
ibm marketing_platform 8.6.0.10
ibm marketing_platform 9.0.0.2
ibm marketing_platform 9.1.1.4
ibm marketing_platform 9.1.0.8
ibm marketing_platform 9.1.0.9
ibm marketing_platform 8.6.0.11
ibm marketing_platform 9.1.0.2
ibm marketing_platform 8.6.0.7
ibm marketing_platform 8.6.0.2
ibm marketing_platform 8.6.0.8
ibm marketing_platform 9.1.0.5
ibm marketing_platform 8.6.0.4
ibm marketing_platform 9.1.1.3
ibm marketing_platform 9.0.0.0
ibm marketing_platform 9.0.0.3
ibm marketing_platform 9.1.2.0
ibm marketing_platform 9.1.0.0
ibm marketing_platform 9.1.0.10
CVE-2016-0230 HIGH

IBM Power Hardware Management Console (HMC) 7.3 through 7.3.0 SP7, 7.9 through 7.9.0 SP3, 8.1 through 8.1.0 SP3, 8.2 through 8.2.0 SP2, 8.3 through 8.3.0 SP2, 8.4 through 8.4.0 SP1, and 8.5.0 allows physically proximate attackers to obtain root access via unspecified vectors.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 6.8 MEDIUM CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 0.9 5.9

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm hardware_management_console 8.3.0
ibm hardware_management_console 7.9.0
ibm hardware_management_console 8.1.0
ibm hardware_management_console 8.4.0
ibm hardware_management_console 8.5.0
ibm hardware_management_console 8.2.0
ibm hardware_management_console 7.3.0
CVE-2016-0231 MEDIUM

IBM Financial Transaction Manager (FTM) for ACH Services, Check Services and Corporate Payment Services (CPS) 3.0.0 before FP12 allows remote authenticated users to obtain sensitive information by reading exception details in error logs.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm financial_transaction_manager 3.0.0.0
CVE-2016-0232 MEDIUM

IBM Financial Transaction Manager (FTM) for ACH Services, Check Services and Corporate Payment Services (CPS) 3.0.0 before FP12 allows remote authenticated users to obtain sensitive information by reading README files.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm financial_transaction_manager 3.0.0.4
ibm financial_transaction_manager 3.0.0.9
ibm financial_transaction_manager 3.0.0.7
ibm financial_transaction_manager 3.0.0.0
ibm financial_transaction_manager 3.0.0.11
ibm financial_transaction_manager 3.0.0.3
ibm financial_transaction_manager 3.0.0.10
ibm financial_transaction_manager 3.0.0.2
ibm financial_transaction_manager 3.0.0.5
ibm financial_transaction_manager 3.0.0.8
ibm financial_transaction_manager 3.0.0.6
ibm financial_transaction_manager 3.0.0.1
CVE-2016-0233 MEDIUM

SQL injection vulnerability in IBM Marketing Platform 8.5.x, 8.6.x, and 9.x before 9.1.2.2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm marketing_platform 9.1.0.1
ibm marketing_platform 8.6.0.1
ibm marketing_platform 8.5.0.5
ibm marketing_platform 8.6.0.6
ibm marketing_platform 9.1.0.3
ibm marketing_platform 9.1.0.6
ibm marketing_platform 8.5.0.6
ibm marketing_platform 9.1.0.7
ibm marketing_platform 8.6.0.3
ibm marketing_platform 8.6.0.9
ibm marketing_platform 9.1.0.4
ibm marketing_platform 9.1.1.1
ibm marketing_platform 9.0.0.4
ibm marketing_platform 9.1.1.0
ibm marketing_platform 8.5.0.7
ibm marketing_platform 9.1.1.2
ibm marketing_platform 8.6.0.5
ibm marketing_platform 9.0.0.1
ibm marketing_platform 8.6.0.0
ibm marketing_platform 8.6.0.10
ibm marketing_platform 9.0.0.2
ibm marketing_platform 9.1.1.4
ibm marketing_platform 8.5.0.2
ibm marketing_platform 9.1.0.8
ibm marketing_platform 8.5.0.3
ibm marketing_platform 9.1.0.9
ibm marketing_platform 8.5.0.1
ibm marketing_platform 8.6.0.11
ibm marketing_platform 9.1.0.2
ibm marketing_platform 8.6.0.7
ibm marketing_platform 8.6.0.2
ibm marketing_platform 8.6.0.8
ibm marketing_platform 9.1.0.5
ibm marketing_platform 8.6.0.4
ibm marketing_platform 8.5.0.4
ibm marketing_platform 9.1.1.3
ibm marketing_platform 9.0.0.0
ibm marketing_platform 9.0.0.3
ibm marketing_platform 8.5.0.0
ibm marketing_platform 9.1.2.0
ibm marketing_platform 9.1.0.0
ibm marketing_platform 9.1.0.10
CVE-2016-0234 LOW

IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 could allow a local user to obtain sensitive information when a previous user has logged out of the system but neglected to close their browser. IBM X-Force ID: 110303.

CVSS 2.0

Severity: LOW

Problem Type: CWE-613,

Products Affected

Vendor Product Version
ibm openpages_grc_platform *
ibm openpages_grc_platform 7.3.0.0
CVE-2016-0235 HIGH

IBM Security Guardium Database Activity Monitor 10 allows local users to have unspecified impact by leveraging administrator access to a hardcoded password, related to use on GRUB systems. IBM X-Force ID: 110326.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-798,

Products Affected

Vendor Product Version
ibm security_guardium_database_activity_monitor 10.0
CVE-2016-0236 HIGH

IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote authenticated users to execute arbitrary commands with root privileges via the search field.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-77,

Products Affected

Vendor Product Version
ibm security_guardium_database_activity_monitor 8.2
ibm security_guardium_database_activity_monitor 10.0
ibm security_guardium_database_activity_monitor 9.1
ibm security_guardium_database_activity_monitor 9.0
ibm security_guardium_database_activity_monitor 10.01
ibm security_guardium_database_activity_monitor 10.1
ibm security_guardium_database_activity_monitor 9.5
CVE-2016-0237 LOW

IBM Security Guardium Database Activity Monitor 10 allows local users to obtain sensitive information by reading cached browser data. IBM X-Force ID: 110328.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_guardium_database_activity_monitor 10.0
CVE-2016-0238 MEDIUM

IBM Security Guardium 9.0, 9.1, 9.5, 10.0, and 10.1 transmits sensitive data in cleartext in the query of the request. This could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 110409

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_guardium 9.0
ibm security_guardium 10.0
ibm security_guardium 9.1
ibm security_guardium 10.1
ibm security_guardium 10.1.2
ibm security_guardium 9.5
CVE-2016-0239 MEDIUM

IBM Security Guardium Database Activity Monitor 9.x through 9.5 before p700 and 10.x through 10.0.1 before p100 allows remote authenticated users to make HTTP requests with administrator privileges via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm security_guardium_database_activity_monitor 10.0
ibm security_guardium_database_activity_monitor 9.1
ibm security_guardium_database_activity_monitor 9.0
ibm security_guardium_database_activity_monitor 10.0.1
ibm security_guardium_database_activity_monitor 9.5
CVE-2016-0240 MEDIUM

IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 does not enable the HSTS protection mechanism, which makes it easier for remote attackers to obtain sensitive information by leveraging use of HTTP.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-254,

Products Affected

Vendor Product Version
ibm security_guardium_database_activity_monitor 8.2
ibm security_guardium_database_activity_monitor 10.0
ibm security_guardium_database_activity_monitor 9.1
ibm security_guardium_database_activity_monitor 9.0
ibm security_guardium_database_activity_monitor 10.01
ibm security_guardium_database_activity_monitor 10.1
ibm security_guardium_database_activity_monitor 9.5
CVE-2016-0241 MEDIUM

IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote authenticated users to spoof administrator accounts by sending a modified login request over HTTP.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm security_guardium_database_activity_monitor 8.2
ibm security_guardium_database_activity_monitor 10.0
ibm security_guardium_database_activity_monitor 9.1
ibm security_guardium_database_activity_monitor 9.0
ibm security_guardium_database_activity_monitor 10.01
ibm security_guardium_database_activity_monitor 10.1
ibm security_guardium_database_activity_monitor 9.5
CVE-2016-0242 MEDIUM

IBM Security Guardium 10.x through 10.1 before p100 allows remote authenticated users to obtain sensitive information by reading an Application Error message.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_guardium 10.01
ibm security_guardium 10.0
ibm security_guardium 10.1
CVE-2016-0243 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.x through 7.0.0.2 CF29, 8.0.x before 8.0.0.1 CF20, and 8.5.x before 8.5.0.0 CF09 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-0244.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.0
ibm websphere_portal 6.1.0.3
ibm websphere_portal 7.0.0.1
ibm websphere_portal 6.1.5.2
ibm websphere_portal 6.1.0.2
ibm websphere_portal 6.1.0.4
ibm websphere_portal 8.0.0.1
ibm websphere_portal 7.0.0.2
ibm websphere_portal 8.5.0.0
ibm websphere_portal 6.1.5.0
ibm websphere_portal 6.1.0.6
ibm websphere_portal 6.1.5.3
ibm websphere_portal 7.0.0.0
ibm websphere_portal 6.1.0.1
ibm websphere_portal 6.1.5.1
ibm websphere_portal 6.1.0.5
ibm websphere_portal 6.1.0.0
CVE-2016-0244 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.x through 7.0.0.2 CF29, 8.0.x before 8.0.0.1 CF20, and 8.5.x before 8.5.0.0 CF09 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-0243.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.0
ibm websphere_portal 6.1.0.3
ibm websphere_portal 7.0.0.1
ibm websphere_portal 6.1.5.2
ibm websphere_portal 6.1.0.2
ibm websphere_portal 6.1.0.4
ibm websphere_portal 8.0.0.1
ibm websphere_portal 7.0.0.2
ibm websphere_portal 8.5.0.0
ibm websphere_portal 6.1.5.0
ibm websphere_portal 6.1.0.6
ibm websphere_portal 6.1.5.3
ibm websphere_portal 7.0.0.0
ibm websphere_portal 6.1.0.1
ibm websphere_portal 6.1.5.1
ibm websphere_portal 6.1.0.5
ibm websphere_portal 6.1.0.0
CVE-2016-0245 MEDIUM

The XML parser in IBM WebSphere Portal 8.0.x before 8.0.0.1 CF20 and 8.5.x before 8.5.0.0 CF10 allows remote authenticated users to read arbitrary files or cause a denial of service via an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.1
ibm websphere_portal 8.0.0.0
ibm websphere_portal 8.5.0.0
CVE-2016-0246 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Security Guardium 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm security_guardium 9.0
ibm security_guardium 10.01
ibm security_guardium 10.0
ibm security_guardium 9.1
ibm security_guardium 8.2
ibm security_guardium 10.1
ibm security_guardium 9.5
CVE-2016-0247 LOW

IBM Security Guardium 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows local users to obtain sensitive cleartext information via unspecified vectors, as demonstrated by password information.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_guardium 9.0
ibm security_guardium 10.01
ibm security_guardium 10.0
ibm security_guardium 9.1
ibm security_guardium 8.2
ibm security_guardium 10.1
ibm security_guardium 9.5
CVE-2016-0248 MEDIUM

IBM Security Guardium 9.0 before p700 and 10.0 before p100 allows man-in-the-middle attackers to obtain sensitive query-string information from SSL sessions via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_guardium 9.0
ibm security_guardium 10.0
CVE-2016-0249 HIGH

SQL injection vulnerability in IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm security_guardium 9.0
ibm security_guardium 10.0.1
ibm security_guardium 10.0
ibm security_guardium 9.1
ibm security_guardium 9.5
ibm security_guardium *
ibm security_guardium 10.1.0
CVE-2016-0250 MEDIUM

XML external entity (XXE) vulnerability in IBM InfoSphere Information Governance Catalog 11.3 before 11.3.1.2 and 11.5 before 11.5.0.1 allows remote authenticated users to read arbitrary files or cause a denial of service via crafted XML data. IBM X-Force ID: 110510.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm infosphere_information_server 11.5
ibm infosphere_information_server *
CVE-2016-0252 LOW

IBM Control Center 6.x before 6.0.0.1 iFix06 and Sterling Control Center 5.4.x before 5.4.2.1 iFix09 allow local users to decrypt the master key via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm sterling_control_center 5.4.0.1
ibm sterling_control_center 5.4.1
ibm sterling_control_center 5.4.1.0
ibm control_center 6.0.0.0
ibm sterling_control_center 5.4.2
ibm sterling_control_center 5.4.2.0
ibm sterling_control_center 5.4.0.0
CVE-2016-0253 LOW

Cross-site scripting (XSS) vulnerability in IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial Transaction Manager (FTM) for Check Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, and Financial Transaction Manager (FTM) for Corporate Payment Services (CPS) for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 110562.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm financial_transaction_manager *
ibm financial_transaction_manager 2.1.1.2
CVE-2016-0254 MEDIUM

IBM Cognos Business Intelligence 10.1 and 10.2 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote authenticated attacker could exploit this vulnerability to consume all available CPU resources and cause a denial of service. IBM X-Force ID: 110563.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm cognos_business_intelligence 10.2.1
ibm cognos_business_intelligence 10.2
ibm cognos_business_intelligence 10.2.1.1
ibm cognos_business_intelligence 10.1.1
ibm cognos_business_intelligence 10.2.2
CVE-2016-0255 MEDIUM

IBM Marketing Platform 9.1 and 10.0 is vulnerable to stored cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim's Web browser within the security context of the hosting Web site, once the page is viewed. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials. IBM X-Force ID: 110564.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm marketing_platform 10.0
ibm marketing_platform 9.1
ibm marketing_platform 9.1.2
ibm marketing_platform 9.1.1
CVE-2016-0259 LOW

runmqsc in IBM WebSphere MQ 8.x before 8.0.0.5 allows local users to bypass an intended +dsp authority requirement and obtain sensitive information via unspecified display commands.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_mq 8.0.0.1
ibm websphere_mq 8.0.0.3
ibm websphere_mq 8.0.0.4
ibm websphere_mq 8.0.0.2
CVE-2016-0260 MEDIUM

Memory leak in queue-manager agents in IBM WebSphere MQ 8.x before 8.0.0.5 allows remote attackers to cause a denial of service (heap memory consumption) by triggering many errors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm websphere_mq 8.0.0.1
ibm websphere_mq 8.0.0.3
ibm websphere_mq 8.0.0.4
ibm websphere_mq 8.0
ibm websphere_mq 8.0.0.2
CVE-2016-0261 LOW

Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management 6.0.0 before SP2 EP29, 6.0.4 before 6.0.4.6 iFix3, 6.0.5 before 6.0.5.9 iFix2, 6.1.0 before 6.1.0.1 iFix1, and 6.1.1 before 6.1.1.1 iFix1; and IBM Care Management 6.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 110604.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm curam_social_program_management 6.0
ibm curam_social_program_management 6.1.0.1
ibm care_management 6.0
ibm curam_social_program_management *
ibm curam_social_program_management 6.0.0
ibm curam_social_program_management 6.1.0.0
ibm curam_social_program_management 6.1.1.0
ibm curam_social_program_management 6.1.1.1
CVE-2016-0262 LOW

Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.1.1 through 7.1.1.3, 7.5.0 before 7.5.0.9 IFIX004, and 7.6.0 before 7.6.0.3 IFIX001 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management 7.5.0.9
ibm maximo_asset_management 7.6.0.3
ibm maximo_asset_management 7.5.0.1
ibm maximo_asset_management 7.5.0.6
ibm maximo_asset_management 7.1.1.1
ibm maximo_asset_management 7.5.0.0
ibm maximo_asset_management 7.5.0.7
ibm maximo_asset_management 7.5.0.4
ibm maximo_asset_management 7.5.0.5
ibm maximo_asset_management 7.6.0.0
ibm maximo_asset_management 7.1.1.2
ibm maximo_asset_management 7.1.1.3
ibm maximo_asset_management 7.5.0.3
ibm maximo_asset_management 7.6.0.1
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.5.0.8
ibm maximo_asset_management 7.6.0.2
CVE-2016-0263 HIGH

IBM Spectrum Scale 4.1 before 4.1.1.5 and 4.2 before 4.2.0.2 and General Parallel File System 3.5 before 3.5.0.30 allow local users to gain privileges or cause a denial of service via a crafted mmapplypolicy command.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm general_parallel_file_system_storage_server 3.5.0.3
ibm general_parallel_file_system_storage_server 3.5.0.2
ibm general_parallel_file_system_storage_server 3.5.0.27
ibm spectrum_scale 4.2.0.0
ibm general_parallel_file_system_storage_server 3.5.0.9
ibm general_parallel_file_system_storage_server 3.5.0.15
ibm general_parallel_file_system_storage_server 3.5.0.17
ibm general_parallel_file_system_storage_server 3.5.0.24
ibm general_parallel_file_system_storage_server 3.5.0.28
ibm general_parallel_file_system_storage_server 3.5.0.7
ibm general_parallel_file_system_storage_server 3.5.0.11
ibm spectrum_scale 4.1.1.3
ibm general_parallel_file_system_storage_server 3.5.0.8
ibm general_parallel_file_system_storage_server 3.5.0.29
ibm spectrum_scale 4.1.1.1
ibm general_parallel_file_system_storage_server 3.5.0.26
ibm general_parallel_file_system_storage_server 3.5.0.1
ibm general_parallel_file_system_storage_server 3.5.0.4
ibm general_parallel_file_system_storage_server 3.5.0.14
ibm spectrum_scale 4.1.1.4
ibm general_parallel_file_system_storage_server 3.5.0.10
ibm general_parallel_file_system_storage_server 3.5.0.5
ibm general_parallel_file_system_storage_server 3.5.0.12
ibm general_parallel_file_system_storage_server 3.5.0.16
ibm general_parallel_file_system_storage_server 3.5.0.6
ibm general_parallel_file_system_storage_server 3.5.0.21
ibm general_parallel_file_system_storage_server 3.5.0.22
ibm spectrum_scale 4.1.1.2
ibm general_parallel_file_system_storage_server 3.5.0.19
ibm general_parallel_file_system_storage_server 3.5.0.13
ibm general_parallel_file_system_storage_server 3.5.0.25
ibm general_parallel_file_system_storage_server 3.5.0.20
ibm general_parallel_file_system_storage_server 3.5.0.23
ibm general_parallel_file_system_storage_server 3.5.0.18
ibm spectrum_scale 4.2.0.1
CVE-2016-0264 MEDIUM

Buffer overflow in the Java Virtual Machine (JVM) in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) allows remote attackers to execute arbitrary code via unspecified vectors.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 5.6 MEDIUM CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L 2.2 3.4

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
redhat satellite 5.6
suse linux_enterprise_software_development_kit 11
redhat enterprise_linux_workstation 7.0
suse linux_enterprise_software_development_kit 12
suse manager_proxy 2.1
redhat enterprise_linux_server_eus 6.7
redhat enterprise_linux_hpc_node_supplementary 7.0
suse manager 2.1
suse openstack_cloud 5
redhat satellite 5.7
redhat enterprise_linux_workstation 6.0
redhat enterprise_linux_hpc_node_supplementary 6.0
redhat enterprise_linux_server 6.0
suse suse_linux_enterprise_server 12
suse linux_enterprise_server 11
redhat enterprise_linux_desktop 7.0
suse linux_enterprise_server 10
redhat enterprise_linux_server 7.0
redhat enterprise_linux_server_eus 7.3
redhat enterprise_linux_desktop 6.0
redhat enterprise_linux_desktop 5.0
redhat enterprise_linux_server_eus 7.4
ibm java_sdk *
suse linux_enterprise_server 12
redhat enterprise_linux_server_eus 7.2
redhat enterprise_linux_workstation 5.0
redhat enterprise_linux_server_eus 7.5
redhat enterprise_linux_server 5.0
CVE-2016-0265 LOW

IBM Campaign is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm campaign 8.6
ibm campaign 9.1
ibm campaign 9.1.1
ibm campaign 9.1.2
CVE-2016-0266 MEDIUM

IBM AIX 5.3, 6.1, 7.1, and 7.2 and VIOS 2.2.x do not default to the latest TLS version, which makes it easier for man-in-the-middle attackers to obtain sensitive information via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-254,

Products Affected

Vendor Product Version
ibm aix 7.2
ibm vios 2.2.3.70
ibm vios 2.2.2.2
ibm vios 2.2.2.5
ibm aix 5.3
ibm vios 2.2.3.1
ibm vios 2.2.3.0
ibm vios 2.2.4.0
ibm vios 2.2.2.0
ibm vios 2.2.2.4
ibm vios 2.2.3.4
ibm vios 2.2.1.0
ibm vios 2.2.1.5
ibm vios 2.2.1.6
ibm vios 2.2.1.8
ibm vios 2.2.2.1
ibm vios 2.2.4.22
ibm vios 2.2.3.52
ibm aix 6.1
ibm vios 2.2.0.10
ibm vios 2.2.1.1
ibm vios 2.2.1.4
ibm vios 2.2.3.3
ibm aix 7.1
ibm vios 2.2.3.2
ibm vios 2.2.3.50
ibm vios 2.2.1.9
ibm vios 2.2.0.12
ibm vios 2.2.0.13
ibm vios 2.2.1.3
ibm vios 2.2.3.51
ibm vios 2.2.3.60
ibm vios 2.2.4.10
ibm vios 2.2.1.7
ibm vios 2.2.4.21
ibm vios 2.2.0.11
ibm vios 2.2.2.3
CVE-2016-0267 MEDIUM

IBM UrbanCode Deploy 6.0.x before 6.0.1.13, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1 allows remote authenticated users to obtain sensitive cleartext secure-property information via (1) the server UI or (2) a database request.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm urbancode_deploy 6.1.0.3
ibm urbancode_deploy 6.0.1.3
ibm urbancode_deploy 6.1.1.8
ibm urbancode_deploy 6.0.1.4
ibm urbancode_deploy 6.0.1.7
ibm urbancode_deploy 6.1.1.1
ibm urbancode_deploy 6.1.1.2
ibm urbancode_deploy 6.1.1.5
ibm urbancode_deploy 6.2.1
ibm urbancode_deploy 6.0.1.0
ibm urbancode_deploy 6.1.0.1
ibm urbancode_deploy 6.2.0.0
ibm urbancode_deploy 6.0.1.5
ibm urbancode_deploy 6.1.1.6
ibm urbancode_deploy 6.1.0.4
ibm urbancode_deploy 6.1.1.0
ibm urbancode_deploy 6.1.3.1
ibm urbancode_deploy 6.2.0.1
ibm urbancode_deploy 6.1.3.2
ibm urbancode_deploy 6.1
ibm urbancode_deploy 6.1.2
ibm urbancode_deploy 6.0.1.6
ibm urbancode_deploy 6.0.1.11
ibm urbancode_deploy 6.2.0.2
ibm urbancode_deploy 6.1.0.2
ibm urbancode_deploy 6.0.1.8
ibm urbancode_deploy 6.1.3
ibm urbancode_deploy 6.0.1.9
ibm urbancode_deploy 6.1.1.3
ibm urbancode_deploy 6.0.1.10
ibm urbancode_deploy 6.0.1.12
ibm urbancode_deploy 6.0.1.2
ibm urbancode_deploy 6.1.1.7
ibm urbancode_deploy 6.1.1.4
ibm urbancode_deploy 6.0.1.1
ibm urbancode_deploy 6.0
CVE-2016-0268 MEDIUM

XML external entity (XXE) vulnerability in IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial Transaction Manager (FTM) for Check Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, and Financial Transaction Manager (FTM) for Corporate Payment Services (CPS) for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013 allows remote authenticated users to obtain sensitive information via crafted XML data. IBM X-Force ID: 110915.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm financial_transaction_manager *
ibm financial_transaction_manager 2.1.1.2
CVE-2016-0269 LOW

Cross-site scripting (XSS) vulnerability in IBM BigFix Platform 9.x before 9.1.8 and 9.2.x before 9.2.7 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm bigfix_platform 9.2.2
ibm bigfix_platform 9.0.5
ibm bigfix_platform 9.2.0
ibm bigfix_platform 9.1.7
ibm bigfix_platform 9.2.6
ibm bigfix_platform 9.2.1
ibm bigfix_platform 9.0.8
ibm bigfix_platform 9.1.3
ibm bigfix_platform 9.1.6
ibm bigfix_platform 9.2.4
ibm bigfix_platform 9.2.5
ibm bigfix_platform 9.0.7
ibm bigfix_platform 9.1.4
ibm bigfix_platform 9.1.5
ibm bigfix_platform 9.0.6
ibm bigfix_platform 9.2.3
CVE-2016-0270 MEDIUM

IBM Domino 9.0.1 Fix Pack 3 Interim Fix 2 through 9.0.1 Fix Pack 5 Interim Fix 1, when using TLS and AES GCM, uses random nonce generation, which makes it easier for remote attackers to obtain the authentication key and spoof data by leveraging the reuse of a nonce in a session and a "forbidden attack." NOTE: this CVE has been incorrectly used for GCM nonce reuse issues in other products; see CVE-2016-10213 for the A10 issue, CVE-2016-10212 for the Radware issue, and CVE-2017-5933 for the Citrix issue.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm domino 9.0.1.4
ibm client_application_access 1.0.0.1
ibm notes 9.0.1.5
ibm domino 9.0.1.3
ibm domino 9.0.1.5
ibm notes 9.0.1.3
ibm notes 9.0.1.4
CVE-2016-0271 HIGH

The agents in IBM UrbanCode Deploy 6.x before 6.0.1.14, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1 do not verify a server's identity in a JMS session or an HTTP session, which allows local users to obtain root access to arbitrary agents via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm urbancode_deploy 6.1.0.3
ibm urbancode_deploy 6.0.1.3
ibm urbancode_deploy 6.1.1.8
ibm urbancode_deploy 6.0.1.4
ibm urbancode_deploy 6.0.1.7
ibm urbancode_deploy 6.1.1.1
ibm urbancode_deploy 6.1.1.2
ibm urbancode_deploy 6.1.1.5
ibm urbancode_deploy 6.2.1
ibm urbancode_deploy 6.0.1.0
ibm urbancode_deploy 6.0.1.13
ibm urbancode_deploy 6.1.0.1
ibm urbancode_deploy 6.2.0.0
ibm urbancode_deploy 6.0.1.5
ibm urbancode_deploy 6.1.1.6
ibm urbancode_deploy 6.1.0.4
ibm urbancode_deploy 6.1.1.0
ibm urbancode_deploy 6.1.3.1
ibm urbancode_deploy 6.2.0.1
ibm urbancode_deploy 6.1.3.2
ibm urbancode_deploy 6.1
ibm urbancode_deploy 6.1.2
ibm urbancode_deploy 6.0.1.6
ibm urbancode_deploy 6.0.1.11
ibm urbancode_deploy 6.2.0.2
ibm urbancode_deploy 6.1.0.2
ibm urbancode_deploy 6.0.1.8
ibm urbancode_deploy 6.1.3
ibm urbancode_deploy 6.0.1.9
ibm urbancode_deploy 6.1.1.3
ibm urbancode_deploy 6.0.1.10
ibm urbancode_deploy 6.0.1.12
ibm urbancode_deploy 6.0.1.2
ibm urbancode_deploy 6.1.1.7
ibm urbancode_deploy 6.1.1.4
ibm urbancode_deploy 6.0.1.1
ibm urbancode_deploy 6.0
CVE-2016-0272 MEDIUM

Cross-site request forgery (CSRF) vulnerability in IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial Transaction Manager (FTM) for Check Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, and Financial Transaction Manager (FTM) for Corporate Payment Services (CPS) for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013 allows remote attackers to hijack the authentication of arbitrary users via unspecified vectors. IBM X-Force ID: 111052.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm financial_transaction_manager *
ibm financial_transaction_manager 2.1.1.2
CVE-2016-0273 LOW

Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Team Concert 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational DOORS Next Generation 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Engineering Lifecycle Manager 4.x before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Rhapsody Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; and Rational Software Architect Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_rhapsody_design_manager 4.0.4
ibm rational_rhapsody_design_manager 4.0.5
ibm rational_doors_next_generation 4.0.0
ibm rational_collaborative_lifecycle_management 4.0.6
ibm rational_engineering_lifecycle_manager 4.0.7
ibm rational_quality_manager 4.0.6
ibm rational_software_architect_design_manager 6.0.1
ibm rational_software_architect_design_manager 4.0.7
ibm rational_quality_manager 6.0.1
ibm rational_engineering_lifecycle_manager 5.0.2
ibm rational_rhapsody_design_manager 5.0.2
ibm rational_quality_manager 4.0.3
ibm rational_engineering_lifecycle_manager 6.0.2
ibm rational_team_concert 4.0.1
ibm rational_team_concert 6.0.0
ibm rational_team_concert 4.0.5
ibm rational_team_concert 4.0.2
ibm rational_collaborative_lifecycle_management 4.0.5
ibm rational_collaborative_lifecycle_management 4.0.7
ibm rational_collaborative_lifecycle_management 5.0.0
ibm rational_collaborative_lifecycle_management 4.0.3
ibm rational_software_architect_design_manager 4.0.6
ibm rational_doors_next_generation 4.0.7
ibm rational_doors_next_generation 4.0.2
ibm rational_engineering_lifecycle_manager 4.0.0
ibm rational_software_architect_design_manager 5.0.0
ibm rational_rhapsody_design_manager 4.0.7
ibm rational_doors_next_generation 6.0.0
ibm rational_engineering_lifecycle_manager 6.0.0
ibm rational_team_concert 5.0.2
ibm rational_collaborative_lifecycle_management 4.0.1
ibm rational_team_concert 4.0.3
ibm rational_collaborative_lifecycle_management 4.0.2
ibm rational_engineering_lifecycle_manager 4.0.2
ibm rational_team_concert 4.0.0
ibm rational_quality_manager 4.0.1
ibm rational_team_concert 4.0.6
ibm rational_quality_manager 4.0.0
ibm rational_quality_manager 5.0.0
ibm rational_engineering_lifecycle_manager 4.0.5
ibm rational_software_architect_design_manager 5.0.2
ibm rational_engineering_lifecycle_manager 6.0.1
ibm rational_software_architect_design_manager 6.0.0
ibm rational_doors_next_generation 4.0.4
ibm rational_quality_manager 4.0.4
ibm rational_software_architect_design_manager 4.0.0
ibm rational_engineering_lifecycle_manager 4.0.6
ibm rational_rhapsody_design_manager 4.0.3
ibm rational_doors_next_generation 5.0.0
ibm rational_doors_next_generation 5.0.2
ibm rational_quality_manager 4.0.2
ibm rational_doors_next_generation 5.0.1
ibm rational_software_architect_design_manager 4.0.1
ibm rational_team_concert 3.0.1.6
ibm rational_collaborative_lifecycle_management 4.0.4
ibm rational_engineering_lifecycle_manager 4.0.3
ibm rational_engineering_lifecycle_manager 4.0.4
ibm rational_rhapsody_design_manager 5.0.0
ibm rational_software_architect_design_manager 4.0.2
ibm rational_engineering_lifecycle_manager 4.0.1
ibm rational_engineering_lifecycle_manager 5.0.0
ibm rational_team_concert 6.0.1
ibm rational_quality_manager 4.0.7
ibm rational_rhapsody_design_manager 4.0.6
ibm rational_rhapsody_design_manager 6.0.1
ibm rational_rhapsody_design_manager 6.0.2
ibm rational_software_architect_design_manager 4.0.4
ibm rational_team_concert 6.0.2
ibm rational_doors_next_generation 4.0.1
ibm rational_engineering_lifecycle_manager 5.0.1
ibm rational_team_concert 4.0.7
ibm rational_collaborative_lifecycle_management 6.0.2
ibm rational_software_architect_design_manager 4.0.3
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_quality_manager 5.0.2
ibm rational_rhapsody_design_manager 4.0.1
ibm rational_rhapsody_design_manager 4.0.2
ibm rational_rhapsody_design_manager 4.0
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_collaborative_lifecycle_management 4.0.0
ibm rational_collaborative_lifecycle_management 3.0.1.6
ibm rational_quality_manager 3.0.1.6
ibm rational_doors_next_generation 6.0.1
ibm rational_rhapsody_design_manager 5.0.1
ibm rational_doors_next_generation 4.0.5
ibm rational_doors_next_generation 4.0.6
ibm rational_doors_next_generation 4.0.3
ibm rational_quality_manager 5.0.1
ibm rational_team_concert 5.0.0
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_software_architect_design_manager 6.0.2
ibm rational_software_architect_design_manager 4.0.5
ibm rational_team_concert 4.0.4
ibm rational_software_architect_design_manager 5.0.1
ibm rational_quality_manager 4.0.5
ibm rational_quality_manager 6.0.2
ibm rational_doors_next_generation 6.0.2
ibm rational_quality_manager 6.0.0
ibm rational_collaborative_lifecycle_management 6.0.0
ibm rational_team_concert 5.0.1
ibm rational_rhapsody_design_manager 6.0.0
CVE-2016-0274 LOW

IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial Transaction Manager (FTM) for Check Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, and Financial Transaction Manager (FTM) for Corporate Payment Services (CPS) for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013 allows remote attackers to conduct clickjacking attacks via a crafted web site. IBM X-Force ID: 111076.

CVSS 2.0

Severity: LOW

Problem Type: CWE-254,

Products Affected

Vendor Product Version
ibm financial_transaction_manager *
ibm financial_transaction_manager 2.1.1.2
CVE-2016-0275 LOW

IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial Transaction Manager (FTM) for Check Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, and Financial Transaction Manager (FTM) for Corporate Payment Services (CPS) for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013 allows local users to obtain sensitive information via vectors related to cacheable HTTPS responses.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm financial_transaction_manager *
ibm financial_transaction_manager 2.1.1.2
CVE-2016-0276 MEDIUM

IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial Transaction Manager (FTM) for Check Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, and Financial Transaction Manager (FTM) for Corporate Payment Services (CPS) for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013 allows remote attackers to execute arbitrary code via a crafted serialized Java Message Service (JMS) ObjectMessage object. IBM X-Force ID: 111084.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm financial_transaction_manager *
CVE-2016-0277 MEDIUM

Heap-based buffer overflow in the KeyView PDF filter in IBM Domino 8.5.x before 8.5.3 FP6 IF13 and 9.x before 9.0.1 FP6 allows remote attackers to execute arbitrary code via a crafted PDF document, a different vulnerability than CVE-2016-0278, CVE-2016-0279, and CVE-2016-0301.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm domino 8.5.0
ibm domino 8.5.1.1
ibm domino 8.5.3.2
ibm domino 8.5.1.2
ibm domino 8.5.3.5
ibm domino 8.5.2
ibm domino 8.5.2.1
ibm domino 9.0.1.5
ibm domino 9.0.1.1
ibm domino 8.5.3
ibm domino 8.5.2.2
ibm domino 8.5.1.4
ibm domino 8.5.3.1
ibm domino 8.5.3.3
ibm domino 9.0.1.2
ibm domino 9.0.1.4
ibm domino 8.5.1
ibm domino 9.0.1.3
ibm domino 9.0.1
ibm domino 8.5.3.4
ibm domino 8.5.1.3
ibm domino 8.5.2.3
CVE-2016-0278 MEDIUM

Heap-based buffer overflow in the KeyView PDF filter in IBM Domino 8.5.x before 8.5.3 FP6 IF13 and 9.x before 9.0.1 FP6 allows remote attackers to execute arbitrary code via a crafted PDF document, a different vulnerability than CVE-2016-0277, CVE-2016-0279, and CVE-2016-0301.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm domino 8.5.0
ibm domino 8.5.1.1
ibm domino 8.5.3.2
ibm domino 8.5.1.2
ibm domino 8.5.3.5
ibm domino 8.5.2
ibm domino 8.5.2.1
ibm domino 9.0.1.5
ibm domino 9.0.1.1
ibm domino 8.5.3
ibm domino 8.5.2.2
ibm domino 8.5.1.4
ibm domino 8.5.3.1
ibm domino 8.5.3.3
ibm domino 9.0.1.2
ibm domino 9.0.1.4
ibm domino 8.5.1
ibm domino 9.0.1.3
ibm domino 9.0.1
ibm domino 8.5.3.4
ibm domino 8.5.1.3
ibm domino 8.5.2.3
CVE-2016-0279 MEDIUM

Heap-based buffer overflow in the KeyView PDF filter in IBM Domino 8.5.x before 8.5.3 FP6 IF13 and 9.x before 9.0.1 FP6 allows remote attackers to execute arbitrary code via a crafted PDF document, a different vulnerability than CVE-2016-0277, CVE-2016-0278, and CVE-2016-0301.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm domino 8.5.0
ibm domino 8.5.1.1
ibm domino 8.5.3.2
ibm domino 8.5.1.2
ibm domino 8.5.3.5
ibm domino 8.5.2
ibm domino 8.5.2.1
ibm domino 9.0.1.5
ibm domino 9.0.1.1
ibm domino 8.5.3
ibm domino 8.5.2.2
ibm domino 8.5.1.4
ibm domino 8.5.3.1
ibm domino 8.5.3.3
ibm domino 9.0.1.2
ibm domino 9.0.1.4
ibm domino 8.5.1
ibm domino 9.0.1.3
ibm domino 9.0.1
ibm domino 8.5.3.4
ibm domino 8.5.1.3
ibm domino 8.5.2.3
CVE-2016-0280 LOW

Cross-site scripting (XSS) vulnerability in IBM Information Server Framework 8.5, Information Server Framework and InfoSphere Information Server Business Glossary 8.7 before FP2, Information Server Framework and InfoSphere Information Server Business Glossary 9.1 before 9.1.2.0, Information Server Framework and InfoSphere Information Governance Catalog 11.3 before 11.3.1.2, and Information Server Framework and InfoSphere Information Governance Catalog 11.5 before 11.5.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm information_server_framework 11.3
ibm infosphere_information_governance_catalog 11.3
ibm information_server_framework 11.5
ibm information_server_framework 8.7
ibm infosphere_information_server_business_glossary 9.1
ibm infosphere_information_server_business_glossary 8.7
ibm infosphere_information_governance_catalog 11.5
ibm information_server_framework 8.5
ibm information_server_framework 9.1
CVE-2016-0281 MEDIUM

The mustendd driver in IBM AIX 5.3, 6.1, 7.1, and 7.2 and VIOS 2.2.x, when the jumbo_frames feature is not enabled, allows remote attackers to cause a denial of service (FC1763 or FC5899 adapter crash) via crafted packets.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm aix 7.2
ibm vios 2.2.2.2
ibm vios 2.2.2.5
ibm aix 5.3
ibm vios 2.2.3.1
ibm vios 2.2.3.0
ibm vios 2.2.2.0
ibm vios 2.2.2.4
ibm vios 2.2.3.4
ibm vios 2.2.1.0
ibm vios 2.2.1.5
ibm vios 2.2.1.6
ibm vios 2.2.1.8
ibm vios 2.2.2.1
ibm aix 6.1
ibm vios 2.2.0.10
ibm vios 2.2.1.1
ibm vios 2.2.1.4
ibm vios 2.2.3.3
ibm aix 7.1
ibm vios 2.2.3.2
ibm vios 2.2.1.9
ibm vios 2.2.0.12
ibm vios 2.2.0.13
ibm vios 2.2.1.3
ibm vios 2.2.1.7
ibm vios 2.2.0.11
ibm vios 2.2.2.3
CVE-2016-0282 LOW

Cross-site scripting (XSS) vulnerability in IBM iNotes before 8.5.3 FP6 IF2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, aka SPR KLYHAAHNUS.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm lotus_inotes 8.5.1.3
ibm lotus_inotes 8.5.1.0
ibm lotus_inotes 8.5.3.0
ibm lotus_inotes 8.5.2.2
ibm lotus_inotes 8.5.0.0
ibm lotus_inotes 8.5.1.5
ibm lotus_inotes 8.5.2.3
ibm lotus_inotes 8.5.2.1
ibm lotus_inotes 8.5.1.1
ibm lotus_inotes 8.5.2.0
ibm lotus_inotes 8.5.3.1
ibm lotus_inotes 8.5.1.4
ibm lotus_inotes 8.5.3.3
ibm lotus_inotes 8.5.1.2
ibm lotus_inotes 8.5.3.6
ibm lotus_inotes 8.5.2.4
ibm lotus_inotes 8.5.3.4
ibm lotus_inotes 8.5.3.5
ibm lotus_inotes 8.5.0.1
ibm lotus_inotes 8.5.3.2
CVE-2016-0283 MEDIUM

Cross-site scripting (XSS) vulnerability in the OpenID Connect (OIDC) client web application in IBM WebSphere Application Server (WAS) Liberty Profile 8.5.5 before 8.5.5.9 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_application_server 8.5.5.6
ibm websphere_application_server 8.5.5.8
ibm websphere_application_server 8.5.5.0
ibm websphere_application_server 8.5.5.2
ibm websphere_application_server 8.5.5.3
ibm websphere_application_server 8.5.5.7
ibm websphere_application_server 8.5.5.4
ibm websphere_application_server 8.5.5.5
ibm websphere_application_server 8.5.5.1
CVE-2016-0284 MEDIUM

The XML parser in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Team Concert 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational DOORS Next Generation 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Engineering Lifecycle Manager 4.x before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Rhapsody Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; and Rational Software Architect Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5 allows remote authenticated users to read arbitrary files or cause a denial of service via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm rational_rhapsody_design_manager 4.0.4
ibm rational_rhapsody_design_manager 4.0.5
ibm rational_doors_next_generation 4.0.0
ibm rational_collaborative_lifecycle_management 4.0.6
ibm rational_engineering_lifecycle_manager 4.0.7
ibm rational_quality_manager 4.0.6
ibm rational_software_architect_design_manager 6.0.1
ibm rational_software_architect_design_manager 4.0.7
ibm rational_quality_manager 6.0.1
ibm rational_engineering_lifecycle_manager 5.0.2
ibm rational_rhapsody_design_manager 5.0.2
ibm rational_quality_manager 4.0.3
ibm rational_engineering_lifecycle_manager 6.0.2
ibm rational_team_concert 4.0.1
ibm rational_team_concert 6.0.0
ibm rational_team_concert 4.0.5
ibm rational_team_concert 4.0.2
ibm rational_collaborative_lifecycle_management 4.0.5
ibm rational_collaborative_lifecycle_management 4.0.7
ibm rational_collaborative_lifecycle_management 5.0.0
ibm rational_collaborative_lifecycle_management 4.0.3
ibm rational_software_architect_design_manager 4.0.6
ibm rational_doors_next_generation 4.0.7
ibm rational_doors_next_generation 4.0.2
ibm rational_engineering_lifecycle_manager 4.0.0
ibm rational_software_architect_design_manager 5.0.0
ibm rational_rhapsody_design_manager 4.0.7
ibm rational_doors_next_generation 6.0.0
ibm rational_engineering_lifecycle_manager 6.0.0
ibm rational_team_concert 5.0.2
ibm rational_collaborative_lifecycle_management 4.0.1
ibm rational_team_concert 4.0.3
ibm rational_collaborative_lifecycle_management 4.0.2
ibm rational_engineering_lifecycle_manager 4.0.2
ibm rational_team_concert 4.0.0
ibm rational_quality_manager 4.0.1
ibm rational_team_concert 4.0.6
ibm rational_quality_manager 4.0.0
ibm rational_quality_manager 5.0.0
ibm rational_engineering_lifecycle_manager 4.0.5
ibm rational_software_architect_design_manager 5.0.2
ibm rational_engineering_lifecycle_manager 6.0.1
ibm rational_software_architect_design_manager 6.0.0
ibm rational_doors_next_generation 4.0.4
ibm rational_quality_manager 4.0.4
ibm rational_software_architect_design_manager 4.0.0
ibm rational_engineering_lifecycle_manager 4.0.6
ibm rational_rhapsody_design_manager 4.0.3
ibm rational_doors_next_generation 5.0.0
ibm rational_doors_next_generation 5.0.2
ibm rational_quality_manager 4.0.2
ibm rational_doors_next_generation 5.0.1
ibm rational_software_architect_design_manager 4.0.1
ibm rational_team_concert 3.0.1.6
ibm rational_collaborative_lifecycle_management 4.0.4
ibm rational_engineering_lifecycle_manager 4.0.3
ibm rational_engineering_lifecycle_manager 4.0.4
ibm rational_rhapsody_design_manager 5.0.0
ibm rational_software_architect_design_manager 4.0.2
ibm rational_engineering_lifecycle_manager 4.0.1
ibm rational_engineering_lifecycle_manager 5.0.0
ibm rational_team_concert 6.0.1
ibm rational_quality_manager 4.0.7
ibm rational_rhapsody_design_manager 4.0.6
ibm rational_rhapsody_design_manager 6.0.1
ibm rational_rhapsody_design_manager 6.0.2
ibm rational_software_architect_design_manager 4.0.4
ibm rational_team_concert 6.0.2
ibm rational_doors_next_generation 4.0.1
ibm rational_engineering_lifecycle_manager 5.0.1
ibm rational_team_concert 4.0.7
ibm rational_collaborative_lifecycle_management 6.0.2
ibm rational_software_architect_design_manager 4.0.3
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_quality_manager 5.0.2
ibm rational_rhapsody_design_manager 4.0.1
ibm rational_rhapsody_design_manager 4.0.2
ibm rational_rhapsody_design_manager 4.0
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_collaborative_lifecycle_management 4.0.0
ibm rational_collaborative_lifecycle_management 3.0.1.6
ibm rational_quality_manager 3.0.1.6
ibm rational_doors_next_generation 6.0.1
ibm rational_rhapsody_design_manager 5.0.1
ibm rational_doors_next_generation 4.0.5
ibm rational_doors_next_generation 4.0.6
ibm rational_doors_next_generation 4.0.3
ibm rational_quality_manager 5.0.1
ibm rational_team_concert 5.0.0
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_software_architect_design_manager 6.0.2
ibm rational_software_architect_design_manager 4.0.5
ibm rational_team_concert 4.0.4
ibm rational_software_architect_design_manager 5.0.1
ibm rational_quality_manager 4.0.5
ibm rational_quality_manager 6.0.2
ibm rational_doors_next_generation 6.0.2
ibm rational_quality_manager 6.0.0
ibm rational_collaborative_lifecycle_management 6.0.0
ibm rational_team_concert 5.0.1
ibm rational_rhapsody_design_manager 6.0.0
CVE-2016-0285 LOW

Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Team Concert 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational DOORS Next Generation 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Engineering Lifecycle Manager 4.x before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Rhapsody Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; and Rational Software Architect Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted field.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_team_concert 5.0.0
ibm rational_team_concert 4.0.7
ibm rational_team_concert 4.0.1
ibm rational_team_concert 6.0.0
ibm rational_team_concert 4.0.5
ibm rational_team_concert 4.0.2
ibm rational_team_concert 5.0.2
ibm rational_team_concert 4.0.4
ibm rational_team_concert 4.0.3
ibm rational_team_concert 6.0.1
ibm rational_team_concert 4.0.0
ibm rational_team_concert 4.0.6
ibm rational_team_concert 3.0.1.6
ibm rational_team_concert 5.0.1
ibm rational_team_concert 6.0.2
CVE-2016-0286 MEDIUM

IBM Tivoli Business Service Manager 6.1.0 before 6.1.0-TIV-BSM-FP0004 and 6.1.1 before 6.1.1-TIV-BSM-FP0004 allows remote authenticated users to obtain administrator passwords by leveraging unspecified privileges. BM X-Force ID: 111234.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm tivoli_business_service_manager 6.1.0
ibm tivoli_business_service_manager 6.1.1
CVE-2016-0287 LOW

IBM i Access 7.1 on Windows allows local users to discover registry passwords via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,CWE-254,

Products Affected

Vendor Product Version
ibm i_access 7.1
CVE-2016-0288 MEDIUM

IBM Security AppScan Standard 8.7.x, 8.8.x, and 9.x before 9.0.3.2 and Security AppScan Enterprise allow remote authenticated users to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm security_appscan 8.8.0.0
ibm security_appscan 9.0.1.0
ibm security_appscan 9.0.1.1
ibm security_appscan 9.0.0.0
ibm security_appscan 9.0.3.0
ibm security_appscan 9.0.3.1
ibm security_appscan 9.0.2.0
ibm security_appscan 8.7.0.0
ibm security_appscan 8.7.0.1
ibm security_appscan 9.0.0.1
ibm security_appscan 9.0.2.1
CVE-2016-0289 MEDIUM

shiprec.xml in the SHIPREC application in IBM Maximo Asset Management 7.1 and 7.5 before 7.5.0.10 and 7.6 before 7.6.0.4 allows remote authenticated users to bypass intended item-selection restrictions via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management 7.5.0.9
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.6.0.3
ibm maximo_asset_management 7.5.0.1
ibm maximo_asset_management 7.5.0.6
ibm maximo_asset_management 7.5
ibm maximo_asset_management 7.5.0.0
ibm maximo_asset_management 7.5.0.7
ibm maximo_asset_management 7.6
ibm maximo_asset_management 7.5.0.4
ibm maximo_asset_management 7.5.0.5
ibm maximo_asset_management 7.6.0.0
ibm maximo_asset_management 7.5.0.3
ibm maximo_asset_management 7.6.0.1
ibm maximo_asset_management 7.5.0.8
ibm maximo_asset_management 7.6.0.2
CVE-2016-0291 HIGH

IBM BigFix Platform 9.0, 9.1 before 9.1.8, and 9.2 before 9.2.8 allow remote authenticated users to execute arbitrary commands by leveraging report server access. IBM X-Force ID: 111302.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-78,

Products Affected

Vendor Product Version
ibm bigfix_platform *
ibm bigfix_platform 9.0
CVE-2016-0292 LOW

WebReports in IBM BigFix Platform (formerly Tivoli Endpoint Manager) 9.x before 9.5.2 allows local users to discover the cleartext system password by reading a report.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm bigfix 9.5
ibm bigfix 9.1
ibm bigfix 9.0
ibm bigfix 9.2
CVE-2016-0293 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM BigFix Platform (formerly Tivoli Endpoint Manager) 9.x before 9.1.8 and 9.2.x before 9.2.8 allows remote attackers to inject arbitrary web script or HTML via a modified .beswrpt file.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm bigfix_platform 9.2.2
ibm bigfix_platform 9.0.5
ibm bigfix_platform 9.2.0
ibm bigfix_platform 9.1.7
ibm bigfix_platform 9.2.6
ibm bigfix_platform 9.2.1
ibm bigfix_platform 9.0.8
ibm bigfix_platform 9.1.3
ibm bigfix_platform 9.1.6
ibm bigfix_platform 9.2.4
ibm bigfix_platform 9.2.5
ibm bigfix_platform 9.0.7
ibm bigfix_platform 9.1.4
ibm bigfix_platform 9.1.5
ibm bigfix_platform 9.0.6
ibm bigfix_platform 9.2.7
ibm bigfix_platform 9.2.3
CVE-2016-0295 MEDIUM

Cross-site request forgery (CSRF) vulnerability in the IBM BigFix Platform 9.0, 9.1, 9.2, and 9.5 before 9.5.2 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences. IBM X-Force ID: 111363.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm bigfix_platform 9.2
ibm bigfix_platform *
ibm bigfix_platform 9.1
ibm bigfix_platform 9.0
CVE-2016-0296 LOW

IBM Tivoli Endpoint Manager - Mobile Device Management (MDM) stores potentially sensitive information in log files that could be available to a local user.

CVSS 2.0

Severity: LOW

Problem Type: CWE-532,

Products Affected

Vendor Product Version
ibm bigfix_platform 9.2
ibm bigfix_platform 9.1
ibm bigfix_platform 9.5
ibm bigfix_platform 9.0
CVE-2016-0297 MEDIUM

IBM Tivoli Endpoint Manager - Mobile Device Management (MDM) could allow a remote attacker to obtain sensitive information due to a missing HTTP Strict-Transport-Security Header through man in the middle techniques.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm bigfix_platform 9.2
ibm bigfix_platform 9.1
ibm bigfix_platform 9.5
ibm bigfix_platform 9.0
CVE-2016-0298 MEDIUM

Directory traversal vulnerability in IBM Security Guardium Database Activity Monitor 10 before 10.0p100 allows remote authenticated users to read arbitrary files via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_guardium *
CVE-2016-0299 MEDIUM

IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote attackers to obtain sensitive information via vectors involving a database query. IBM X-Force ID: 111382.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm tririga_application_platform 3.5.0.0
ibm tririga_application_platform *
CVE-2016-0300 MEDIUM

IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 might allow remote attackers to access arbitrary JSP pages via vectors related to improper input validation. IBM X-Force ID: 111412.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm tririga_application_platform 3.3.1.1
ibm tririga_application_platform 3.5.0.0
ibm tririga_application_platform 3.4.2.1
ibm tririga_application_platform 3.4.1.2
ibm tririga_application_platform 3.3.2.4
ibm tririga_application_platform 3.4.1.1
ibm tririga_application_platform 3.3.1.2
ibm tririga_application_platform 3.4.2.0
ibm tririga_application_platform 3.3.2.5
ibm tririga_application_platform 3.4.0.0
ibm tririga_application_platform 3.3.0.1
ibm tririga_application_platform 3.3.1.3
ibm tririga_application_platform 3.3.1.0
ibm tririga_application_platform 3.3.2.1
ibm tririga_application_platform 3.3.0.2
ibm tririga_application_platform 3.3.2.3
ibm tririga_application_platform 3.3.2.0
ibm tririga_application_platform 3.4.1.3
ibm tririga_application_platform 3.4.2.2
ibm tririga_application_platform 3.3.0.0
CVE-2016-0301 MEDIUM

Heap-based buffer overflow in the KeyView PDF filter in IBM Domino 8.5.x before 8.5.3 FP6 IF13 and 9.x before 9.0.1 FP6 allows remote attackers to execute arbitrary code via a crafted PDF document, a different vulnerability than CVE-2016-0277, CVE-2016-0278, and CVE-2016-0279.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm domino 8.5.0
ibm domino 8.5.1.1
ibm domino 8.5.3.2
ibm domino 8.5.1.2
ibm domino 8.5.3.5
ibm domino 8.5.2
ibm domino 8.5.2.1
ibm domino 9.0.1.5
ibm domino 9.0.1.1
ibm domino 8.5.3
ibm domino 8.5.2.2
ibm domino 8.5.1.4
ibm domino 8.5.3.1
ibm domino 8.5.3.3
ibm domino 9.0.1.2
ibm domino 9.0.1.4
ibm domino 8.5.1
ibm domino 9.0.1.3
ibm domino 9.0.1
ibm domino 8.5.3.4
ibm domino 8.5.1.3
ibm domino 8.5.2.3
CVE-2016-0303 LOW

Cross-site scripting (XSS) vulnerability in IBM Tivoli Integrated Portal 2.2.0.0 through 2.2.0.15 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_integrated_portal *
CVE-2016-0304 MEDIUM

The Java Console in IBM Domino 8.5.x before 8.5.3 FP6 IF13 and 9.x before 9.0.1 FP6, when a certain unsupported configuration involving UNC share pathnames is used, allows remote attackers to bypass authentication and possibly execute arbitrary code via unspecified vectors, aka SPR KLYHA7MM3J. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-0920.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm domino 8.5.0
ibm domino 8.5.1.1
ibm domino 8.5.1.5
ibm domino 8.5.1.2
ibm domino 8.5.3.5
ibm domino 8.5.2.1
ibm domino 9.0.1.5
ibm domino 9.0.1.1
ibm domino 8.5.3
ibm domino 8.5.3.1
ibm domino 9.0.1.2
ibm domino 9.0.1.4
ibm domino 8.5.1
ibm domino 9.0.1.3
ibm domino 9.0.1
ibm domino 8.5.3.4
ibm domino 8.5.2.3
ibm domino 8.5.3.2
ibm domino 8.5.2
ibm domino 8.5.3.6
ibm domino 8.5.2.2
ibm domino 8.5.1.4
ibm domino 8.5.3.3
ibm domino 8.5.2.4
ibm domino 8.5.1.3
CVE-2016-0305 LOW

IBM Connections is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm connections 5.0.0.0
ibm connections 4.5.0.0
ibm connections 4.0.0.0
ibm connections 5.5.0.0
CVE-2016-0306 MEDIUM

IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.41, 8.0 before 8.0.0.13, and 8.5 before 8.5.5.10, when FIPS 140-2 is enabled, misconfigures TLS, which allows man-in-the-middle attackers to obtain sensitive information via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 8.0.0.6
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 8.5.5.2
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 7.0.0.25
ibm websphere_application_server 8.0.0.9
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.31
ibm websphere_application_server 8.5.5.5
ibm websphere_application_server 8.0.0.8
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 8.0.0.7
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 8.0.0.12
ibm websphere_application_server 7.0.0.27
ibm websphere_application_server 7.0.0.39
ibm websphere_application_server 8.5.5.3
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 8.0.0.2
ibm websphere_application_server 8.0.0.5
ibm websphere_application_server 8.5.0.2
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 8.5.5.7
ibm websphere_application_server 7.0.0.33
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 7.0.0.0
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 8.5.5.8
ibm websphere_application_server 7.0.0.29
ibm websphere_application_server 8.5.5.0
ibm websphere_application_server 7.0.0.37
ibm websphere_application_server 8.5.5.9
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 8.5.5.6
ibm websphere_application_server 8.0.0.11
ibm websphere_application_server 8.0.0.10
ibm websphere_application_server 8.5.5.4
ibm websphere_application_server 7.0.0.35
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 8.5.5.1
ibm websphere_application_server 7.0.0.4
CVE-2016-0307 MEDIUM

IBM Connections 5.5 and earlier allows remote attackers to obtain sensitive information by reading stack traces in returned responses.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm connections 5.0.0.0
ibm connections 4.5.0.0
ibm connections 4.0.0.0
ibm connections 5.5.0.0
CVE-2016-0308 MEDIUM

IBM Connections 5.5 and earlier is vulnerable to possible link manipulation attack that could result in the display of inappropriate background images.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm connections 5.0.0.0
ibm connections 4.5.0.0
ibm connections 4.0.0.0
ibm connections 5.5.0.0
CVE-2016-0310 LOW

IBM Connections 5.5 and earlier is vulnerable to possible host header injection attack that could cause navigation to the attacker's domain.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm connections 5.0.0.0
ibm connections 4.5.0.0
ibm connections 4.0.0.0
ibm connections 5.5.0.0
CVE-2016-0311 LOW

Cross-site scripting (XSS) vulnerability in IBM Tivoli Business Service Manager 6.1.0 before 6.1.0-TIV-BSM-FP0004 and 6.1.1 before 6.1.1-TIV-BSM-FP0004 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 111480.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_business_service_manager 6.1.0
ibm tivoli_business_service_manager 6.1.1
CVE-2016-0312 MEDIUM

IBM TRIRIGA Application Platform before 3.3.2 allows remote attackers to obtain sensitive information via vectors related to granting unauthenticated access to Document Manager. IBM X-Force ID: 111486.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm tririga_application_platform *
CVE-2016-0313 LOW

Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-2888 and CVE-2016-0350.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm jazz_reporting_service 5.0.2
ibm jazz_reporting_service 6.0
ibm jazz_reporting_service 6.0.1
ibm jazz_reporting_service 5.0
ibm jazz_reporting_service 5.0.1
CVE-2016-0314 MEDIUM

The Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 allow remote authenticated users to conduct clickjacking attacks via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm jazz_reporting_service 5.0.2
ibm jazz_reporting_service 6.0
ibm jazz_reporting_service 6.0.1
ibm jazz_reporting_service 5.0
ibm jazz_reporting_service 5.0.1
CVE-2016-0315 MEDIUM

The Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 maintain session ID validity after a logout action, which allows remote authenticated users to hijack sessions by leveraging an unattended workstation.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm jazz_reporting_service 5.0.2
ibm jazz_reporting_service 6.0
ibm jazz_reporting_service 6.0.1
ibm jazz_reporting_service 5.0
ibm jazz_reporting_service 5.0.1
CVE-2016-0316 LOW

Cross-site scripting (XSS) vulnerability in Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 and 6.0.2 before iFix003 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm jazz_reporting_service 6.0
ibm jazz_reporting_service 6.0.2
ibm jazz_reporting_service 6.0.1
CVE-2016-0317 MEDIUM

Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 allows remote attackers to conduct clickjacking attacks via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm jazz_reporting_service 6.0
ibm jazz_reporting_service 6.0.1
CVE-2016-0318 MEDIUM

Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 does not destroy a Session ID upon a logout action, which allows remote attackers to obtain access by leveraging an unattended workstation.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm jazz_reporting_service 6.0
ibm jazz_reporting_service 6.0.1
CVE-2016-0319 MEDIUM

The XML parser in Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 allows remote authenticated administrators to read arbitrary files or cause a denial of service via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm jazz_reporting_service 6.0
ibm jazz_reporting_service 6.0.1
CVE-2016-0320 MEDIUM

IBM UrbanCode Deploy could allow an authenticated user to modify Ucd objects due to multiple REST endpoints not properly authorizing users editing UCD objects. This could affect the behavior of legitimately triggered processes.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm urbancode_deploy 6.1.0.3
ibm urbancode_deploy 6.2.2
ibm urbancode_deploy 6.0.1.3
ibm urbancode_deploy 6.1.1.8
ibm urbancode_deploy 6.0.1.4
ibm urbancode_deploy 6.0.1.7
ibm urbancode_deploy 6.1.1.1
ibm urbancode_deploy 6.1.1.2
ibm urbancode_deploy 6.1.3.3
ibm urbancode_deploy 6.1.1
ibm urbancode_deploy 6.1.1.5
ibm urbancode_deploy 6.2.1
ibm urbancode_deploy 6.0.1.13
ibm urbancode_deploy 6.1.0.1
ibm urbancode_deploy 6.2.0.0
ibm urbancode_deploy 6.0.1.14
ibm urbancode_deploy 6.0.1.5
ibm urbancode_deploy 6.1.1.6
ibm urbancode_deploy 6.1.0.4
ibm urbancode_deploy 6.1.3.1
ibm urbancode_deploy 6.2.0.1
ibm urbancode_deploy 6.1.3.2
ibm urbancode_deploy 6.2.1.1
ibm urbancode_deploy 6.1
ibm urbancode_deploy 6.1.2
ibm urbancode_deploy 6.0.1.6
ibm urbancode_deploy 6.0.1.11
ibm urbancode_deploy 6.2.0.2
ibm urbancode_deploy 6.1.0.2
ibm urbancode_deploy 6.0.1.8
ibm urbancode_deploy 6.1.3
ibm urbancode_deploy 6.0.1.9
ibm urbancode_deploy 6.1.1.3
ibm urbancode_deploy 6.0.1.10
ibm urbancode_deploy 6.0.1
ibm urbancode_deploy 6.0.1.12
ibm urbancode_deploy 6.0.1.2
ibm urbancode_deploy 6.1.1.7
ibm urbancode_deploy 6.1.1.4
ibm urbancode_deploy 6.2.2.1
ibm urbancode_deploy 6.0.1.1
ibm urbancode_deploy 6.0
CVE-2016-0321 LOW

IBM Personal Communications (aka PCOMM) 6.x before 6.0.17 and 12.x before 12.0.0.1 does not properly restrict credential extraction, which allows local users to discover passwords by leveraging access to the victim account and executing a PowerShell script.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm personal_communications 6.0.7
ibm personal_communications 6.0.5
ibm personal_communications 6.0.8
ibm personal_communications 6.0.10
ibm personal_communications 6.0.13
ibm personal_communications 12.0.0
ibm personal_communications 6.0.11
ibm personal_communications 6.0.0
ibm personal_communications 6.0.1
ibm personal_communications 6.0.9
ibm personal_communications 6.0.16
ibm personal_communications 6.0.15
ibm personal_communications 6.0.12
ibm personal_communications 6.0.2
ibm personal_communications 6.0.4
ibm personal_communications 6.0.3
ibm personal_communications 6.0.6
ibm personal_communications 6.0.14
CVE-2016-0322 LOW

Cross-site scripting (XSS) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 through CR4, and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML by uploading an HTML document.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm connections 5.0.0.0
ibm connections 4.5.0.0
ibm connections 4.0.0.0
ibm connections 5.5.0.0
CVE-2016-0323 MEDIUM

The Auto-Scaling agent in Liberty for Java in IBM Bluemix before 2.7-20160321-1358 allows remote authenticated users to disable X.509 certificate validation, and consequently bypass an intended HTTPS trust-management feature, via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm bluemix -
CVE-2016-0324 HIGH

IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows remote authenticated users to execute arbitrary code with administrator privileges via unspecified vectors. IBM X-Force ID: 111640.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-77,

Products Affected

Vendor Product Version
ibm security_identity_manager_virtual_appliance 7.0.0.2
ibm security_identity_manager_virtual_appliance 7.0.0.3
ibm security_identity_manager_virtual_appliance 7.0.1.0
ibm security_identity_manager_virtual_appliance 7.0.0.1
ibm security_identity_manager_virtual_appliance 7.0.0.0
CVE-2016-0325 HIGH

IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Team Concert 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational DOORS Next Generation 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Engineering Lifecycle Manager 4.x before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Rhapsody Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; and Rational Software Architect Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5 allow remote authenticated users to execute arbitrary OS commands via a crafted request.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-78,

Products Affected

Vendor Product Version
ibm rational_team_concert 5.0.0
ibm rational_team_concert 4.0.7
ibm rational_team_concert 4.0.1
ibm rational_team_concert 6.0.0
ibm rational_team_concert 4.0.5
ibm rational_team_concert 4.0.2
ibm rational_team_concert 5.0.2
ibm rational_team_concert 4.0.4
ibm rational_team_concert 4.0.3
ibm rational_team_concert 6.0.1
ibm rational_team_concert 4.0.0
ibm rational_team_concert 4.0.6
ibm rational_team_concert 3.0.1.6
ibm rational_team_concert 5.0.1
ibm rational_team_concert 6.0.2
CVE-2016-0326 MEDIUM

IBM Rational Quality Manager (RQM) and Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.x before 4.0.7 iFix11, 5.x before 5.0.2 iFix17, and 6.x before 6.0.1 ifix3 allow remote authenticated users to execute arbitrary OS commands via a crafted "HTML request."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-77,

Products Affected

Vendor Product Version
ibm rational_collaborative_lifecycle_management 4.0.6
ibm rational_quality_manager 4.0.6
ibm rational_collaborative_lifecycle_management 4.0.1
ibm rational_quality_manager 4.0.0.1
ibm rational_quality_manager 4.0.0.2
ibm rational_quality_manager 4.0.7
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 6.0.1
ibm rational_collaborative_lifecycle_management 4.0.2
ibm rational_quality_manager 4.0
ibm rational_quality_manager 4.0.1
ibm rational_quality_manager 4.0.3
ibm rational_quality_manager 5.0.0
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_quality_manager 5.0.2
ibm rational_quality_manager 4.0.4
ibm rational_collaborative_lifecycle_management 4.0.5
ibm rational_collaborative_lifecycle_management 4.0.7
ibm rational_collaborative_lifecycle_management 5.0.0
ibm rational_collaborative_lifecycle_management 4.0.3
ibm rational_quality_manager 4.0.5
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_quality_manager 6.0.0
ibm rational_collaborative_lifecycle_management 4.0.0
ibm rational_quality_manager 4.0.2
ibm rational_collaborative_lifecycle_management 6.0.0
ibm rational_quality_manager 3.0.1.6
ibm rational_collaborative_lifecycle_management 4.0.4
CVE-2016-0327 MEDIUM

IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows local users to gain administrator privileges via unspecified vectors. IBM X-Force ID: 111643.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm security_identity_manager_virtual_appliance 7.0.0.2
ibm security_identity_manager_virtual_appliance 7.0.0.3
ibm security_identity_manager_virtual_appliance 7.0.1.0
ibm security_identity_manager_virtual_appliance 7.0.0.1
ibm security_identity_manager_virtual_appliance 7.0.0.0
CVE-2016-0328 HIGH

IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows local users to obtain administrator privileges for command execution via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-77,

Products Affected

Vendor Product Version
ibm security_guardium_database_activity_monitor 8.2
ibm security_guardium_database_activity_monitor 10.0
ibm security_guardium_database_activity_monitor 9.1
ibm security_guardium_database_activity_monitor 9.0
ibm security_guardium_database_activity_monitor 10.01
ibm security_guardium_database_activity_monitor 10.1
ibm security_guardium_database_activity_monitor 9.5
CVE-2016-0329 MEDIUM

Open redirect vulnerability in IBM Emptoris Sourcing 10.0.0.x before 10.0.0.1_iFix3, 10.0.1.x before 10.0.1.3_iFix3, 10.0.2.x before 10.0.2.8_iFix1, 10.0.4.0 before 10.0.4.0_iFix8, and 10.1.0.0 before 10.1.0.0_iFix3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. IBM X-Force ID: 111692.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-601,

Products Affected

Vendor Product Version
ibm emptoris_sourcing *
CVE-2016-0330 MEDIUM

IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 mishandles password creation, which makes it easier for remote attackers to obtain access by leveraging an attack against the password algorithm.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm security_identity_manager_adapter 7.0.0.2
ibm security_identity_manager_adapter 7.0.0.3
ibm security_identity_manager_adapter 7.0.1.0
ibm security_identity_manager_adapter 7.0.0.1
ibm security_identity_manager_adapter 7.0.0.0
ibm security_identity_manager_adapter 7.0.1.1
CVE-2016-0331 LOW

Cross-site scripting (XSS) vulnerability in IBM Rational Team Concert 6.0.1 and 6.0.2 before 6.0.2 iFix2 and Rational Collaborative Lifecycle Management 6.0.1 and 6.0.2 before 6.0.2 iFix2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_team_concert 6.0.1
ibm rational_collaborative_lifecycle_management 6.0.2
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_team_concert 6.0.2
CVE-2016-0332 MEDIUM

IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 do not properly restrict failed login attempts, which makes it easier for remote attackers to obtain access via a brute-force approach. IBM X-Force ID: 111695.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-254,

Products Affected

Vendor Product Version
ibm security_identity_manager_virtual_appliance 7.0.0.2
ibm security_identity_manager_virtual_appliance 7.0.0.3
ibm security_identity_manager_virtual_appliance 7.0.1.0
ibm security_identity_manager_virtual_appliance 7.0.0.1
ibm security_identity_manager_virtual_appliance 7.0.0.0
CVE-2016-0335 MEDIUM

Cross-site request forgery (CSRF) vulnerability in IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows remote attackers to hijack the authentication of users for requests that have unspecified impact via unknown vectors. IBM X-Force ID: 111736.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm security_identity_manager 7.0.1.0
ibm security_identity_manager 7.0.0.1
ibm security_identity_manager 7.0.0.0
ibm security_identity_manager 7.0.0.3
ibm security_identity_manager 7.0.0.2
CVE-2016-0336 LOW

Cross-site scripting (XSS) vulnerability in IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 111737.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm security_identity_manager 7.0.1.0
ibm security_identity_manager 7.0.0.1
ibm security_identity_manager 7.0.0.0
ibm security_identity_manager 7.0.0.3
ibm security_identity_manager 7.0.0.2
CVE-2016-0338 LOW

IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 allows local users to discover cleartext passwords by (1) reading a configuration file or (2) examining a process.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_identity_manager_adapter 7.0.0.2
ibm security_identity_manager_adapter 7.0.0.3
ibm security_identity_manager_adapter 7.0.1.0
ibm security_identity_manager_adapter 7.0.0.1
ibm security_identity_manager_adapter 7.0.0.0
ibm security_identity_manager_adapter 7.0.1.1
CVE-2016-0339 MEDIUM

IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 mishandles session identifiers after logout, which makes it easier for remote attackers to spoof users by leveraging knowledge of "traffic records."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm security_identity_manager_adapter 7.0.0.2
ibm security_identity_manager_adapter 7.0.0.3
ibm security_identity_manager_adapter 7.0.1.0
ibm security_identity_manager_adapter 7.0.0.1
ibm security_identity_manager_adapter 7.0.0.0
ibm security_identity_manager_adapter 7.0.1.1
CVE-2016-0340 MEDIUM

IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 mishandles session expiration, which allows remote attackers to hijack sessions by leveraging an unattended workstation.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm security_identity_manager_adapter 7.0.0.2
ibm security_identity_manager_adapter 7.0.0.3
ibm security_identity_manager_adapter 7.0.1.0
ibm security_identity_manager_adapter 7.0.0.1
ibm security_identity_manager_adapter 7.0.0.0
ibm security_identity_manager_adapter 7.0.1.1
CVE-2016-0341 MEDIUM

IBM Multi-Enterprise Integration Gateway 1.0 through 1.0.0.1 and B2B Advanced Communications 1.0.0.2 through 1.0.0.4 do not require HTTPS, which might allow remote attackers to obtain sensitive information by sniffing the network.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm b2b_advanced_communications 1.0.0.2
ibm b2b_advanced_communications 1.0.0.1
ibm b2b_advanced_communications 1.0
ibm b2b_advanced_communications 1.0.0.3
ibm multi-enterprise_integration_gateway 1.0.0
CVE-2016-0342 MEDIUM

IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote authenticated users to read or modify arbitrary reports by leveraging an incorrect grant of access. IBM X-Force ID: 111783.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm tririga_application_platform 3.5.0.0
ibm tririga_application_platform *
CVE-2016-0343 MEDIUM

IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote authenticated users to obtain sensitive information by reading an error message. IBM X-Force ID: 111784.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm tririga_application_platform 3.5.0.0
ibm tririga_application_platform *
CVE-2016-0344 LOW

Cross-site scripting (XSS) vulnerability in the My Reports component in IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 111785.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tririga_application_platform 3.5.0.0
ibm tririga_application_platform *
CVE-2016-0345 MEDIUM

IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote authenticated users to obtain the installation path via vectors involving Birt report rendering. IBM X-Force ID: 111786.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm tririga_application_platform 3.5.0.0
ibm tririga_application_platform *
CVE-2016-0346 LOW

Cross-site scripting (XSS) vulnerability in IBM Cognos Business Intelligence 10.2 before IF20, 10.2.1 before IF17, 10.2.1.1 before IF16, 10.2.2 before IF12, and 10.1.1 before IF19 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm cognos_business_intelligence 10.2.1
ibm cognos_business_intelligence 10.2
ibm cognos_business_intelligence 10.2.1.1
ibm cognos_business_intelligence 10.1.1
ibm cognos_business_intelligence 10.2.2
CVE-2016-0348 MEDIUM

Cross-site request forgery (CSRF) vulnerability in IBM TRIRIGA Application Platform 3.3, 3.3.1, 3.3.2, and 3.4 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences. IBM X-Force ID: 111813.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm tririga_application_platform 3.4.0.0
ibm tririga_application_platform 3.3.1.0
ibm tririga_application_platform 3.3.2.0
ibm tririga_application_platform 3.3.0.0
CVE-2016-0349 MEDIUM

IBM Business Process Manager 8.5.6 through 8.5.6.2 and 8.5.7 before 8.5.7.CF201606 allows remote authenticated users to bypass intended access restrictions and update process-instance variables via a REST API call.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm business_process_manager 8.5.6.0
ibm business_process_manager 8.5.7.0
CVE-2016-0350 LOW

Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-2888 and CVE-2016-0313.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm jazz_reporting_service 5.0.2
ibm jazz_reporting_service 6.0
ibm jazz_reporting_service 6.0.1
ibm jazz_reporting_service 5.0
ibm jazz_reporting_service 5.0.1
CVE-2016-0351 MEDIUM

IBM Security Identity Manager Virtual Appliance 7.0.x before 7.0.1.3-ISS-SIM-IF0001 does not set the secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session. IBM X-Force ID: 111890.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_identity_manager_virtual_appliance 7.0.1.1
ibm security_identity_manager_virtual_appliance 7.0.0.2
ibm security_identity_manager_virtual_appliance 7.0.0.3
ibm security_identity_manager_virtual_appliance 7.0.1.0
ibm security_identity_manager_virtual_appliance 7.0.0.1
ibm security_identity_manager_virtual_appliance 7.0.1.3
ibm security_identity_manager_virtual_appliance 7.0.0.0
CVE-2016-0353 MEDIUM

IBM Security Privileged Identity Manager 2.0 before 2.0.2 FP8, when Virtual Appliance is used, does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,CWE-254,

Products Affected

Vendor Product Version
ibm security_privileged_identity_manager 2.0.2
ibm security_privileged_identity_manager 2.0.1
ibm security_privileged_identity_manager 2.0.0
CVE-2016-0354 MEDIUM

IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user to upload a malicious file to a Sametime meeting room, that could be downloaded by unsuspecting users which could be executed with user privileges. IBM X-Force ID: 111893.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-434,

Products Affected

Vendor Product Version
ibm sametime 8.5.2.0
ibm sametime 8.5.2.1
ibm sametime 9.0.0.1
ibm sametime 9.0.0.0
ibm sametime 9.0.1
CVE-2016-0355 MEDIUM

IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user that has been invited to a Sametime meeting room, to cause the screen sharing to cease through the use of cross-site request forgery. IBM X-Force ID: 111894.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm sametime 8.5.2.0
ibm sametime 8.5.2.1
ibm sametime 9.0.0.1
ibm sametime 9.0.0.0
ibm sametime 9.0.1
CVE-2016-0356 MEDIUM

IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user that has been invited to a Sametime meeting room, to cause the screen sharing to cease through the use of cross-site request forgery. IBM X-Force ID: 111895.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm sametime 8.5.2.0
ibm sametime 8.5.2.1
ibm sametime 9.0.0.1
ibm sametime 9.0.0.0
ibm sametime 9.0.1
CVE-2016-0357 MEDIUM

IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 allows remote attackers to conduct clickjacking attacks via a crafted web site.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm security_identity_manager_adapter 7.0.0.2
ibm security_identity_manager_adapter 7.0.0.3
ibm security_identity_manager_adapter 7.0.1.0
ibm security_identity_manager_adapter 7.0.0.1
ibm security_identity_manager_adapter 7.0.0.0
ibm security_identity_manager_adapter 7.0.1.1
CVE-2016-0358 MEDIUM

IBM Sametime 8.5.2 and 9.0 could allow an unauthorized authenticated user to enumerate group chat ID numbers and join meetings that he was not invited to. IBM X-Force ID: 111928.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm sametime 8.5.2.0
ibm sametime 8.5.2.1
ibm sametime 9.0.0.1
ibm sametime 9.0.0.0
ibm sametime 9.0.1
CVE-2016-0359 MEDIUM

CRLF injection vulnerability in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.43, 8.0 before 8.0.0.13, 8.5 Full before 8.5.5.10, and 8.5 Liberty before Liberty Fix Pack 16.0.0.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 7.0.0.36
ibm websphere_application_server 7.0
ibm websphere_application_server 7.0.0.38
ibm websphere_application_server 7.0.0.12
ibm websphere_application_server 8.0.0.6
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 7.0.0.16
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 7.0.0.25
ibm websphere_application_server 8.0.0.9
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 7.0.0.14
ibm websphere_application_server 7.0.0.22
ibm websphere_application_server 7.0.0.31
ibm websphere_application_server 7.0.0.10
ibm websphere_application_server 8.5.5.5
ibm websphere_application_server 8.0.0.8
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 8.0.0.7
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 8.0.0.12
ibm websphere_application_server 7.0.0.27
ibm websphere_application_server 7.0.0.18
ibm websphere_application_server 7.0.0.41
ibm websphere_application_server 7.0.0.39
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 8.0.0.2
ibm websphere_application_server 8.0.0.5
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 8.5.5.7
ibm websphere_application_server 7.0.0.33
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 7.0.0.0
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 8.5.5.8
ibm websphere_application_server 7.0.0.32
ibm websphere_application_server 8.0
ibm websphere_application_server 7.0.0.29
ibm websphere_application_server 7.0.0.24
ibm websphere_application_server 7.0.0.37
ibm websphere_application_server 8.5.5.9
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 8.5.5.6
ibm websphere_application_server 8.0.0.11
ibm websphere_application_server 8.0.0.10
ibm websphere_application_server 7.0.0.28
ibm websphere_application_server 7.0.0.34
ibm websphere_application_server 8.5.5.4
ibm websphere_application_server 7.0.0.35
ibm websphere_application_server 7.0.0.4
CVE-2016-0360 HIGH

IBM Websphere MQ JMS 7.0.1, 7.1, 7.5, 8.0, and 9.0 client provides classes that deserialize objects from untrusted sources which could allow a malicious user to execute arbitrary Java code by adding vulnerable classes to the classpath. IBM Reference #: 1983457.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-502,

Products Affected

Vendor Product Version
ibm websphere_mq_jms 8.0
ibm websphere_mq_jms 7.1
ibm websphere_mq_jms 7.0.1
ibm websphere_mq_jms 7.5
ibm websphere_mq_jms 9.0
CVE-2016-0361 MEDIUM

IBM General Parallel File System (GPFS) 3.5 before 3.5.0.29 efix 6 and 4.1.1 before 4.1.1.4 efix 9, when the Spectrum Scale GUI is used with DB2 on Linux, UNIX and Windows, allows remote authenticated users to obtain sensitive information via unspecified vectors, as demonstrated by discovering ADMIN passwords.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm general_parallel_file_system 3.5.0.3
ibm general_parallel_file_system 3.5
ibm general_parallel_file_system 3.5.0.9
ibm general_parallel_file_system 4.1.0.1
ibm general_parallel_file_system 3.5.0.11
ibm general_parallel_file_system 3.5.0.7
ibm general_parallel_file_system 3.5.0.16
CVE-2016-0362 MEDIUM

IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.4, and 3.5 before 3.5.0.2 allows remote authenticated users to conduct server-side request forgery (SSRF) attacks, and trigger network traffic to arbitrary intranet or Internet hosts, via a crafted proxy request to a web service.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm tririga_application_platform 3.4.1.2
ibm tririga_application_platform 3.4.2.0
ibm tririga_application_platform 3.3.2.5
ibm tririga_application_platform 3.3.0.1
ibm tririga_application_platform 3.3.1.0
ibm tririga_application_platform 3.3.2.1
ibm tririga_application_platform 3.3.0.2
ibm tririga_application_platform 3.3.2.0
ibm tririga_application_platform 3.3.2.2
ibm tririga_application_platform 3.4.2.2
ibm tririga_application_platform 3.3.1.1
ibm tririga_application_platform 3.5.0.0
ibm tririga_application_platform 3.4.2.1
ibm tririga_application_platform 3.4.2.3
ibm tririga_application_platform 3.5.0.1
ibm tririga_application_platform 3.4.1.0
ibm tririga_application_platform 3.4.0.1
ibm tririga_application_platform 3.3.2.4
ibm tririga_application_platform 3.4.1.1
ibm tririga_application_platform 3.3.1.2
ibm tririga_application_platform 3.4.0.0
ibm tririga_application_platform 3.3.1.3
ibm tririga_application_platform 3.3.2.3
ibm tririga_application_platform 3.4.1.3
ibm tririga_application_platform 3.3.0.0
CVE-2016-0363 MEDIUM

The com.ibm.CORBA.iiop.ClientDelegate class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) uses the invoke method of the java.lang.reflect.Method class in an AccessController doPrivileged block, which allows remote attackers to call setSecurityManager and bypass a sandbox protection mechanism via vectors related to a Proxy object instance implementing the java.lang.reflect.InvocationHandler interface. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-3009.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
novell suse_openstack_cloud 5
redhat satellite 5.6
redhat enterprise_linux_workstation 7.0
redhat enterprise_linux_server_eus 6.7
redhat enterprise_linux_hpc_node_supplementary 7.0
redhat satellite 5.7
redhat enterprise_linux_workstation 6.0
novell suse_linux_enterprise_software_development_kit 11.0
redhat enterprise_linux_hpc_node_supplementary 6.0
redhat enterprise_linux_server 6.0
novell suse_linux_enterprise_software_development_kit 12.0
novell suse_manager 2.1
novell suse_linux_enterprise_module_for_legacy_software 12
redhat enterprise_linux_desktop 7.0
redhat enterprise_linux_server 7.0
redhat enterprise_linux_server_eus 7.3
novell suse_linux_enterprise_server 12.0
redhat enterprise_linux_desktop 6.0
redhat enterprise_linux_server_eus 7.4
ibm java_sdk *
novell suse_linux_enterprise_server 11.0
redhat enterprise_linux_server_eus 7.2
novell suse_manager_proxy 2.1
redhat enterprise_linux_server_eus 7.5
CVE-2016-0364 MEDIUM

IBM UrbanCode Deploy 6.0.x before 6.0.1.13, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1 does not properly implement a logging-obfuscation feature for secure properties, which allows remote authenticated users to obtain sensitive information via vectors involving special characters.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm urbancode_deploy 6.1.0.3
ibm urbancode_deploy 6.0.1.3
ibm urbancode_deploy 6.1.1.8
ibm urbancode_deploy 6.0.1.4
ibm urbancode_deploy 6.0.1.7
ibm urbancode_deploy 6.1.1.1
ibm urbancode_deploy 6.1.1.2
ibm urbancode_deploy 6.1.1.5
ibm urbancode_deploy 6.2.1
ibm urbancode_deploy 6.0.1.0
ibm urbancode_deploy 6.1.0.1
ibm urbancode_deploy 6.2.0.0
ibm urbancode_deploy 6.0.1.5
ibm urbancode_deploy 6.1.1.6
ibm urbancode_deploy 6.1.0.4
ibm urbancode_deploy 6.1.1.0
ibm urbancode_deploy 6.1.3.1
ibm urbancode_deploy 6.2.0.1
ibm urbancode_deploy 6.1.3.2
ibm urbancode_deploy 6.1
ibm urbancode_deploy 6.1.2
ibm urbancode_deploy 6.0.1.6
ibm urbancode_deploy 6.0.1.11
ibm urbancode_deploy 6.2.0.2
ibm urbancode_deploy 6.1.0.2
ibm urbancode_deploy 6.0.1.8
ibm urbancode_deploy 6.1.3
ibm urbancode_deploy 6.0.1.9
ibm urbancode_deploy 6.1.1.3
ibm urbancode_deploy 6.0.1.10
ibm urbancode_deploy 6.0.1.12
ibm urbancode_deploy 6.0.1.2
ibm urbancode_deploy 6.1.1.7
ibm urbancode_deploy 6.1.1.4
ibm urbancode_deploy 6.0.1.1
ibm urbancode_deploy 6.0
CVE-2016-0365 MEDIUM

IBM UrbanCode Deploy 6.0.x before 6.0.1.13, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1, when agent-relay Codestation artifact caching is enabled, allows remote attackers to bypass authentication and obtain sensitive artifact information via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm urbancode_deploy 6.1.0.3
ibm urbancode_deploy 6.0.1.3
ibm urbancode_deploy 6.1.1.8
ibm urbancode_deploy 6.0.1.4
ibm urbancode_deploy 6.0.1.7
ibm urbancode_deploy 6.1.1.1
ibm urbancode_deploy 6.1.1.2
ibm urbancode_deploy 6.1.1.5
ibm urbancode_deploy 6.2.1
ibm urbancode_deploy 6.0.1.0
ibm urbancode_deploy 6.1.0.1
ibm urbancode_deploy 6.2.0.0
ibm urbancode_deploy 6.0.1.5
ibm urbancode_deploy 6.1.1.6
ibm urbancode_deploy 6.1.0.4
ibm urbancode_deploy 6.1.1.0
ibm urbancode_deploy 6.1.3.1
ibm urbancode_deploy 6.2.0.1
ibm urbancode_deploy 6.1.3.2
ibm urbancode_deploy 6.1
ibm urbancode_deploy 6.1.2
ibm urbancode_deploy 6.0.1.6
ibm urbancode_deploy 6.0.1.11
ibm urbancode_deploy 6.2.0.2
ibm urbancode_deploy 6.1.0.2
ibm urbancode_deploy 6.0.1.8
ibm urbancode_deploy 6.1.3
ibm urbancode_deploy 6.0.1.9
ibm urbancode_deploy 6.1.1.3
ibm urbancode_deploy 6.0.1.10
ibm urbancode_deploy 6.0.1.12
ibm urbancode_deploy 6.0.1.2
ibm urbancode_deploy 6.1.1.7
ibm urbancode_deploy 6.1.1.4
ibm urbancode_deploy 6.0.1.1
ibm urbancode_deploy 6.0
CVE-2016-0366 MEDIUM

IBM Security Identity Manager Virtual Appliance 7.0.x before 7.0.1.3-ISS-SIM-IF0001 might allow remote attackers to obtain sensitive information by leveraging weak encryption. IBM X-Force ID: 112071.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_privileged_identity_manager 2.0
CVE-2016-0367 MEDIUM

IBM Security Identity Manager Virtual Appliance 7.0.x before 7.0.1.3-ISS-SIM-IF0001 allows remote authenticated users to obtain sensitive information by reading an error message. IBM X-Force ID: 112072.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_identity_manager_virtual_appliance 7.0.1.1
ibm security_identity_manager_virtual_appliance 7.0.0.2
ibm security_identity_manager_virtual_appliance 7.0.0.3
ibm security_identity_manager_virtual_appliance 7.0.1.0
ibm security_identity_manager_virtual_appliance 7.0.0.1
ibm security_identity_manager_virtual_appliance 7.0.1.3
ibm security_identity_manager_virtual_appliance 7.0.0.0
CVE-2016-0369 MEDIUM

XML external entity (XXE) vulnerability in IBM Forms Experience Builder 8.5, 8.5.1, and 8.6 allows remote authenticated users to obtain sensitive information via crafted XML data. IBM X-Force ID: 112088.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm forms_experience_builder 8.5.1
ibm forms_experience_builder 8.6.0
ibm forms_experience_builder 8.5
CVE-2016-0370 LOW

Cross-site scripting (XSS) vulnerability in IBM Forms Experience Builder 8.5.x and 8.6.x before 8.6.3 allows remote authenticated users to inject arbitrary web script or HTML via crafted input to an application that was built with this product.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm forms_experience_builder 8.5.0.0
ibm forms_experience_builder 8.6.0.0
ibm forms_experience_builder 8.6.1.1
ibm forms_experience_builder 8.6.2
ibm forms_experience_builder 8.6.2.1
ibm forms_experience_builder 8.5.1.0
ibm forms_experience_builder 8.5.1.1
ibm forms_experience_builder 8.6.1
CVE-2016-0371 LOW

The Tivoli Storage Manager (TSM) password may be displayed in plain text via application trace output while application tracing is enabled.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 5.5 MEDIUM CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N 1.8 3.6

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager *
CVE-2016-0372 MEDIUM

IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Team Concert 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational DOORS Next Generation 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Engineering Lifecycle Manager 4.x before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Rhapsody Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; and Rational Software Architect Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5 do not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,CWE-254,

Products Affected

Vendor Product Version
ibm rational_rhapsody_design_manager 4.0.4
ibm rational_rhapsody_design_manager 4.0.5
ibm rational_doors_next_generation 4.0.0
ibm rational_collaborative_lifecycle_management 4.0.6
ibm rational_engineering_lifecycle_manager 4.0.7
ibm rational_quality_manager 4.0.6
ibm rational_software_architect_design_manager 6.0.1
ibm rational_software_architect_design_manager 4.0.7
ibm rational_quality_manager 6.0.1
ibm rational_engineering_lifecycle_manager 5.0.2
ibm rational_rhapsody_design_manager 5.0.2
ibm rational_quality_manager 4.0.3
ibm rational_engineering_lifecycle_manager 6.0.2
ibm rational_team_concert 4.0.1
ibm rational_team_concert 6.0.0
ibm rational_team_concert 4.0.5
ibm rational_team_concert 4.0.2
ibm rational_collaborative_lifecycle_management 4.0.5
ibm rational_collaborative_lifecycle_management 4.0.7
ibm rational_collaborative_lifecycle_management 5.0.0
ibm rational_collaborative_lifecycle_management 4.0.3
ibm rational_software_architect_design_manager 4.0.6
ibm rational_doors_next_generation 4.0.7
ibm rational_doors_next_generation 4.0.2
ibm rational_engineering_lifecycle_manager 4.0.0
ibm rational_software_architect_design_manager 5.0.0
ibm rational_rhapsody_design_manager 4.0.7
ibm rational_doors_next_generation 6.0.0
ibm rational_engineering_lifecycle_manager 6.0.0
ibm rational_team_concert 5.0.2
ibm rational_collaborative_lifecycle_management 4.0.1
ibm rational_team_concert 4.0.3
ibm rational_collaborative_lifecycle_management 4.0.2
ibm rational_engineering_lifecycle_manager 4.0.2
ibm rational_team_concert 4.0.0
ibm rational_quality_manager 4.0.1
ibm rational_team_concert 4.0.6
ibm rational_quality_manager 4.0.0
ibm rational_quality_manager 5.0.0
ibm rational_engineering_lifecycle_manager 4.0.5
ibm rational_software_architect_design_manager 5.0.2
ibm rational_engineering_lifecycle_manager 6.0.1
ibm rational_software_architect_design_manager 6.0.0
ibm rational_doors_next_generation 4.0.4
ibm rational_quality_manager 4.0.4
ibm rational_software_architect_design_manager 4.0.0
ibm rational_engineering_lifecycle_manager 4.0.6
ibm rational_rhapsody_design_manager 4.0.3
ibm rational_doors_next_generation 5.0.0
ibm rational_doors_next_generation 5.0.2
ibm rational_quality_manager 4.0.2
ibm rational_doors_next_generation 5.0.1
ibm rational_software_architect_design_manager 4.0.1
ibm rational_team_concert 3.0.1.6
ibm rational_collaborative_lifecycle_management 4.0.4
ibm rational_engineering_lifecycle_manager 4.0.3
ibm rational_engineering_lifecycle_manager 4.0.4
ibm rational_rhapsody_design_manager 5.0.0
ibm rational_software_architect_design_manager 4.0.2
ibm rational_engineering_lifecycle_manager 4.0.1
ibm rational_engineering_lifecycle_manager 5.0.0
ibm rational_team_concert 6.0.1
ibm rational_quality_manager 4.0.7
ibm rational_rhapsody_design_manager 4.0.6
ibm rational_rhapsody_design_manager 6.0.1
ibm rational_rhapsody_design_manager 6.0.2
ibm rational_software_architect_design_manager 4.0.4
ibm rational_team_concert 6.0.2
ibm rational_doors_next_generation 4.0.1
ibm rational_engineering_lifecycle_manager 5.0.1
ibm rational_team_concert 4.0.7
ibm rational_collaborative_lifecycle_management 6.0.2
ibm rational_software_architect_design_manager 4.0.3
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_quality_manager 5.0.2
ibm rational_rhapsody_design_manager 4.0.1
ibm rational_rhapsody_design_manager 4.0.2
ibm rational_rhapsody_design_manager 4.0
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_collaborative_lifecycle_management 4.0.0
ibm rational_collaborative_lifecycle_management 3.0.1.6
ibm rational_quality_manager 3.0.1.6
ibm rational_doors_next_generation 6.0.1
ibm rational_rhapsody_design_manager 5.0.1
ibm rational_doors_next_generation 4.0.5
ibm rational_doors_next_generation 4.0.6
ibm rational_doors_next_generation 4.0.3
ibm rational_quality_manager 5.0.1
ibm rational_team_concert 5.0.0
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_software_architect_design_manager 6.0.2
ibm rational_software_architect_design_manager 4.0.5
ibm rational_team_concert 4.0.4
ibm rational_software_architect_design_manager 5.0.1
ibm rational_quality_manager 4.0.5
ibm rational_quality_manager 6.0.2
ibm rational_doors_next_generation 6.0.2
ibm rational_quality_manager 6.0.0
ibm rational_collaborative_lifecycle_management 6.0.0
ibm rational_team_concert 5.0.1
ibm rational_rhapsody_design_manager 6.0.0
CVE-2016-0373 MEDIUM

IBM UrbanCode Deploy 6.0 through 6.2.2.1 could allow an authenticated user to read sensitive information due to UCD REST endpoints not properly authorizing users when determining who can read data. IBM X-Force ID: 112119.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-285,

Products Affected

Vendor Product Version
ibm urbancode_deploy *
CVE-2016-0374 MEDIUM

The builder tools in IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.4, and 3.5 before 3.5.0.2 allow remote authenticated users to gain privileges for application modification via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm tririga_application_platform 3.4.1.2
ibm tririga_application_platform 3.4.2.0
ibm tririga_application_platform 3.3.2.5
ibm tririga_application_platform 3.3.0.1
ibm tririga_application_platform 3.3.1.0
ibm tririga_application_platform 3.3.2.1
ibm tririga_application_platform 3.3.0.2
ibm tririga_application_platform 3.3.2.0
ibm tririga_application_platform 3.3.2.2
ibm tririga_application_platform 3.4.2.2
ibm tririga_application_platform 3.3.1.1
ibm tririga_application_platform 3.5.0.0
ibm tririga_application_platform 3.4.2.1
ibm tririga_application_platform 3.4.2.3
ibm tririga_application_platform 3.5.0.1
ibm tririga_application_platform 3.4.1.0
ibm tririga_application_platform 3.4.0.1
ibm tririga_application_platform 3.3.2.4
ibm tririga_application_platform 3.4.1.1
ibm tririga_application_platform 3.3.1.2
ibm tririga_application_platform 3.4.0.0
ibm tririga_application_platform 3.3.1.3
ibm tririga_application_platform 3.3.2.3
ibm tririga_application_platform 3.4.1.3
ibm tririga_application_platform 3.3.0.0
CVE-2016-0375 HIGH

JMS Client in IBM MessageSight 1.1.x through 1.1.0.1, 1.2.x through 1.2.0.3, and 2.0.x through 2.0.0.0 allows remote authenticated users to obtain administrator privileges for executing arbitrary commands via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm messagesight 1.1.0.0
ibm messagesight 1.2
ibm messagesight 2.0.0.0
ibm messagesight 1.1.0.1
ibm messagesight 1.2.0.2
ibm messagesight 1.2.0.0
ibm messagesight 1.2.0.1
ibm messagesight 1.2.0.3
CVE-2016-0376 MEDIUM

The com.ibm.rmi.io.SunSerializableFactory class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) does not properly deserialize classes in an AccessController doPrivileged block, which allows remote attackers to bypass a sandbox protection mechanism and execute arbitrary code as demonstrated by the readValue method of the com.ibm.rmi.io.ValueHandlerPool.ValueHandlerSingleton class, which implements the javax.rmi.CORBA.ValueHandler interface. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-5456.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
novell suse_openstack_cloud 5
redhat satellite 5.6
redhat enterprise_linux_workstation 7.0
redhat enterprise_linux_server_eus 6.7
redhat enterprise_linux_hpc_node_supplementary 7.0
redhat satellite 5.7
redhat enterprise_linux_workstation 6.0
novell suse_linux_enterprise_software_development_kit 11.0
redhat enterprise_linux_hpc_node_supplementary 6.0
redhat enterprise_linux_server 6.0
novell suse_linux_enterprise_software_development_kit 12.0
novell suse_manager 2.1
novell suse_linux_enterprise_module_for_legacy_software 12
redhat enterprise_linux_desktop 7.0
redhat enterprise_linux_server 7.0
redhat enterprise_linux_server_eus 7.3
novell suse_linux_enterprise_server 12.0
redhat enterprise_linux_desktop 6.0
redhat enterprise_linux_desktop 5.0
redhat enterprise_linux_server_eus 7.4
ibm java_sdk *
novell suse_linux_enterprise_server 11.0
redhat enterprise_linux_server_eus 7.2
novell suse_manager_proxy 2.1
redhat enterprise_linux_workstation 5.0
redhat enterprise_linux_server_eus 7.5
CVE-2016-0377 MEDIUM

The Administrative Console in IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.x before 8.0.0.13, and 8.5.x before 8.5.5.10 mishandles CSRFtoken cookies, which allows remote authenticated users to obtain sensitive information via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 7.0.0.36
ibm websphere_application_server 7.0.0.38
ibm websphere_application_server 7.0.0.12
ibm websphere_application_server 8.0.0.6
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 8.5.5.2
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 7.0.0.16
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 7.0.0.25
ibm websphere_application_server 8.0.0.9
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 7.0.0.14
ibm websphere_application_server 7.0.0.22
ibm websphere_application_server 7.0.0.31
ibm websphere_application_server 7.0.0.42
ibm websphere_application_server 7.0.0.10
ibm websphere_application_server 8.5.5.5
ibm websphere_application_server 8.0.0.8
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 8.0.0.7
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 8.0.0.12
ibm websphere_application_server 7.0.0.27
ibm websphere_application_server 7.0.0.18
ibm websphere_application_server 7.0.0.41
ibm websphere_application_server 7.0.0.39
ibm websphere_application_server 8.5.5.3
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 8.0.0.2
ibm websphere_application_server 8.0.0.5
ibm websphere_application_server 8.5.0.2
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 8.5.5.7
ibm websphere_application_server 7.0.0.33
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 7.0.0.0
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 8.5.5.8
ibm websphere_application_server 7.0.0.32
ibm websphere_application_server 7.0.0.29
ibm websphere_application_server 7.0.0.24
ibm websphere_application_server 8.5.5.0
ibm websphere_application_server 7.0.0.37
ibm websphere_application_server 8.5.5.9
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 8.5.5.6
ibm websphere_application_server 8.0.0.11
ibm websphere_application_server 8.0.0.10
ibm websphere_application_server 7.0.0.40
ibm websphere_application_server 7.0.0.28
ibm websphere_application_server 7.0.0.34
ibm websphere_application_server 8.5.5.4
ibm websphere_application_server 7.0.0.35
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 8.5.5.1
ibm websphere_application_server 7.0.0.4
CVE-2016-0378 MEDIUM

IBM WebSphere Application Server (WAS) Liberty before 16.0.0.3, when the installation lacks a default error page, allows remote attackers to obtain sensitive information by triggering an exception.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_application_server *
CVE-2016-0379 LOW

IBM WebSphere MQ 7.5 before 7.5.0.7 and 8.0 before 8.0.0.5 mishandles protocol flows, which allows remote authenticated users to cause a denial of service (channel outage) by leveraging queue-manager rights.

CVSS 2.0

Severity: LOW

Problem Type: CWE-19,

Products Affected

Vendor Product Version
ibm websphere_mq 7.5.0.4
ibm websphere_mq 7.5.0.1
ibm websphere_mq 8.0.0.3
ibm websphere_mq 8.0.0.4
ibm websphere_mq 7.5
ibm websphere_mq 8.0.0.2
ibm websphere_mq 7.5.0.2
ibm websphere_mq 8.0.0.1
ibm websphere_mq 7.5.0.3
ibm websphere_mq 7.5.0.5
ibm websphere_mq 8.0
ibm websphere_mq 7.5.0.6
CVE-2016-0380 LOW

IBM Sterling Connect:Direct for Unix 4.1.0 before 4.1.0.4 iFix073 and 4.2.0 before 4.2.0.4 iFix003 uses default file permissions of 0664, which allows local users to obtain sensitive information via standard filesystem operations.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 3.3 LOW CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N 1.8 1.4

CVSS 2.0

Severity: LOW

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm sterling_connect:direct 4.1.0.4
ibm sterling_connect:direct 4.1.0.1
ibm sterling_connect:direct 4.2.0.3
ibm sterling_connect:direct 4.2.0.0
ibm sterling_connect:direct 4.1.0.0
ibm sterling_connect:direct 4.2.0.4
ibm sterling_connect:direct 4.2.0.2
ibm sterling_connect:direct 4.2.0.1
ibm sterling_connect:direct 4.1.0.2
ibm sterling_connect:direct 4.1.0.3
CVE-2016-0381 MEDIUM

IBM Cognos TM1 10.2.2 before FP5, when the host/pmhub/pm/admin AdminGroups setting is empty, allows remote authenticated users to cause a denial of service (configuration outage) via a non-empty value.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm cognos_tm1 *
CVE-2016-0382 LOW

The IBM Tealeaf Consumer Experience 8.7, 8.8, and 9.0 portal exposes some of its operational state in a form that may be accidentally captured and exposed by network infrastructure components such as IIS. IBM X-Force ID: 112356.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm tealeaf_consumer_experience 8.7.0
ibm tealeaf_consumer_experience 8.8.0
ibm tealeaf_consumer_experience 8.8.1
ibm tealeaf_consumer_experience 9.0.1
ibm tealeaf_consumer_experience 8.7.1
ibm tealeaf_consumer_experience 9.0.2
ibm tealeaf_consumer_experience 8.8
ibm tealeaf_consumer_experience 8.8.2
ibm tealeaf_consumer_experience 8.7
ibm tealeaf_consumer_experience 9.0
CVE-2016-0385 LOW

Buffer overflow in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.43, 8.0 before 8.0.0.13, 8.5 before 8.5.5.10, 9.0 before 9.0.0.1, and Liberty before 16.0.0.3, when HttpSessionIdReuse is enabled, allows remote authenticated users to obtain sensitive information via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-119,CWE-200,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 7.0.0.36
ibm websphere_application_server 7.0
ibm websphere_application_server 7.0.0.38
ibm websphere_application_server 7.0.0.12
ibm websphere_application_server 8.0.0.6
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 8.5.5.2
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 7.0.0.16
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 7.0.0.25
ibm websphere_application_server 8.0.0.9
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 7.0.0.14
ibm websphere_application_server 7.0.0.22
ibm websphere_application_server 7.0.0.31
ibm websphere_application_server 7.0.0.10
ibm websphere_application_server 8.5.5.5
ibm websphere_application_server 8.0.0.8
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 8.0.0.7
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 8.0.0.12
ibm websphere_application_server 7.0.0.27
ibm websphere_application_server 7.0.0.18
ibm websphere_application_server 7.0.0.41
ibm websphere_application_server 7.0.0.39
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 8.0.0.2
ibm websphere_application_server 9.0.0.0
ibm websphere_application_server 8.0.0.5
ibm websphere_application_server 8.5.0.2
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 8.5.5.7
ibm websphere_application_server 7.0.0.33
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 7.0.0.0
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 8.5.5.8
ibm websphere_application_server 7.0.0.32
ibm websphere_application_server 8.0
ibm websphere_application_server 7.0.0.29
ibm websphere_application_server 7.0.0.24
ibm websphere_application_server 8.5.5.0
ibm websphere_application_server 7.0.0.37
ibm websphere_application_server 8.5.5.9
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 8.5.5.6
ibm websphere_application_server 8.0.0.11
ibm websphere_application_server 8.0.0.10
ibm websphere_application_server 7.0.0.28
ibm websphere_application_server 7.0.0.34
ibm websphere_application_server 8.5.5.4
ibm websphere_application_server 7.0.0.35
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 8.5.5.1
ibm websphere_application_server 7.0.0.4
CVE-2016-0386 MEDIUM

Cross-site request forgery (CSRF) vulnerability in IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.4, and 3.5 before 3.5.0.2 allows remote authenticated users to hijack the authentication of administrators for requests that delete employees.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm tririga_application_platform 3.3.1.1
ibm tririga_application_platform 3.5.0.0
ibm tririga_application_platform 3.4.2.1
ibm tririga_application_platform 3.4.2.3
ibm tririga_application_platform 3.4.1.2
ibm tririga_application_platform 3.5.0.1
ibm tririga_application_platform 3.3.2.4
ibm tririga_application_platform 3.4.1.1
ibm tririga_application_platform 3.3.1.2
ibm tririga_application_platform 3.4.2.0
ibm tririga_application_platform 3.3.2.5
ibm tririga_application_platform 3.4.0.0
ibm tririga_application_platform 3.3.0.1
ibm tririga_application_platform 3.3.1.3
ibm tririga_application_platform 3.3.1.0
ibm tririga_application_platform 3.3.2.1
ibm tririga_application_platform 3.3.0.2
ibm tririga_application_platform 3.3.2.3
ibm tririga_application_platform 3.3.2.0
ibm tririga_application_platform 3.4.1.3
ibm tririga_application_platform 3.4.2.2
ibm tririga_application_platform 3.3.0.0
CVE-2016-0387 LOW

Cross-site scripting (XSS) vulnerability in IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.4, and 3.5 before 3.5.0.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-2883.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tririga_application_platform 3.3.1.1
ibm tririga_application_platform 3.5.0.0
ibm tririga_application_platform 3.4.2.1
ibm tririga_application_platform 3.4.2.3
ibm tririga_application_platform 3.4.1.2
ibm tririga_application_platform 3.5.0.1
ibm tririga_application_platform 3.4.1.0
ibm tririga_application_platform 3.4.0.1
ibm tririga_application_platform 3.3.2.4
ibm tririga_application_platform 3.4.1.1
ibm tririga_application_platform 3.3.1.2
ibm tririga_application_platform 3.4.2.0
ibm tririga_application_platform 3.3.2.5
ibm tririga_application_platform 3.4.0.0
ibm tririga_application_platform 3.3.0.1
ibm tririga_application_platform 3.3.1.0
ibm tririga_application_platform 3.3.2.1
ibm tririga_application_platform 3.3.2.3
ibm tririga_application_platform 3.3.2.0
ibm tririga_application_platform 3.4.1.3
ibm tririga_application_platform 3.3.2.2
ibm tririga_application_platform 3.4.2.2
ibm tririga_application_platform 3.3.0.0
CVE-2016-0389 MEDIUM

Admin Center in IBM WebSphere Application Server (WAS) 8.5.5.2 through 8.5.5.9 Liberty before Liberty Fix Pack 16.0.0.2 allows remote attackers to obtain sensitive information via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_application_server 8.5.5.6
ibm websphere_application_server 8.5.5.8
ibm websphere_application_server 8.5.5.2
ibm websphere_application_server 8.5.5.9
ibm websphere_application_server 8.5.5.3
ibm websphere_application_server 8.5.5.7
ibm websphere_application_server 8.5.5.4
ibm websphere_application_server 8.5.5.5
CVE-2016-0390 LOW

Cross-site scripting (XSS) vulnerability in IBM Algorithmics Algo One Algo Risk Application (ARA) 4.9.1 through 5.1.0 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm algo_one 5.1.0
ibm algo_one 4.9.1
ibm algo_one 5.0.0
CVE-2016-0391 HIGH

The IBM Watson Developer Cloud services on Bluemix platforms do not properly generate random numbers for service-instance credentials, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm watson_developer_cloud -
CVE-2016-0392 MEDIUM

IBM General Parallel File System (GPFS) in GPFS Storage Server 2.0.0 through 2.0.7 and Elastic Storage Server 2.5.x through 2.5.5, 3.x before 3.5.5, and 4.x before 4.0.3, as distributed in Spectrum Scale RAID, allows local users to gain privileges via a crafted parameter to a setuid program.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm elastic_storage_server 3.5.1
ibm general_parallel_file_system_storage_server 2.0.5
ibm elastic_storage_server 2.5.3
ibm elastic_storage_server 3.0.1
ibm general_parallel_file_system_storage_server 2.0.4
ibm elastic_storage_server 3.5.4
ibm elastic_storage_server 3.5.2
ibm elastic_storage_server 3.0.2
ibm elastic_storage_server 3.0.3
ibm elastic_storage_server 3.5.3
ibm general_parallel_file_system_storage_server 2.0.1
ibm general_parallel_file_system_storage_server 2.0.2
ibm elastic_storage_server 4.0.0
ibm elastic_storage_server 2.5.2
ibm elastic_storage_server 4.0.1
ibm elastic_storage_server 2.5.1
ibm general_parallel_file_system_storage_server 2.0.3
ibm elastic_storage_server 3.0.5
ibm elastic_storage_server 4.0.2
ibm elastic_storage_server 2.5.5
ibm elastic_storage_server 2.5.0
ibm general_parallel_file_system_storage_server 2.0.7
ibm elastic_storage_server 3.5.0
ibm general_parallel_file_system_storage_server 2.0.0
ibm elastic_storage_server 2.5.4
ibm elastic_storage_server 3.0.4
ibm general_parallel_file_system_storage_server 2.0.6
ibm elastic_storage_server 3.0.0
CVE-2016-0393 MEDIUM

IBM Maximo Asset Management 7.5 before 7.5.0.10-TIV-MBS-IFIX002 and 7.6 before 7.6.0.5-TIV-MAMMT-FP001 allows remote attackers to obtain sensitive URL information by reading log files.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management 7.5.0.9
ibm maximo_asset_management 7.6.0.3
ibm maximo_asset_management 7.5.0.1
ibm maximo_asset_management 7.5.0.6
ibm maximo_asset_management 7.5.0.10
ibm maximo_asset_management 7.6.0.4
ibm maximo_asset_management 7.5.0.0
ibm maximo_asset_management 7.5.0.7
ibm maximo_asset_management 7.5.0.4
ibm maximo_asset_management 7.5.0.5
ibm maximo_asset_management 7.6.0.0
ibm maximo_asset_management 7.6.0.5
ibm maximo_asset_management 7.5.0.3
ibm maximo_asset_management 7.6.0.1
ibm maximo_asset_management 7.5.0.8
ibm maximo_asset_management 7.6.0.2
CVE-2016-0394 LOW

IBM Integration Bus and WebSphere Message broker sets incorrect permissions for an object that could allow a local attacker to manipulate certain files.

CVSS 2.0

Severity: LOW

Problem Type: CWE-275,

Products Affected

Vendor Product Version
ibm websphere_message_broker 8.0
ibm websphere_message_broker 8.0.0.3
ibm integration_bus 9.0
ibm websphere_message_broker 8.0.0.2
ibm integration_bus 9.0.0.2
ibm integration_bus 10.0
ibm websphere_message_broker 8.0.0.5
ibm integration_bus 9.0.0.1
ibm websphere_message_broker 8.0.0.1
ibm websphere_message_broker 8.0.0.4
CVE-2016-0396 MEDIUM

IBM Tivoli Endpoint Manager could allow a user under special circumstances to inject commands that would be executed with unnecessary higher privileges than expected.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-77,

Products Affected

Vendor Product Version
ibm bigfix_platform 9.2
ibm bigfix_platform 9.1
ibm bigfix_platform 9.5
ibm bigfix_platform 9.0
CVE-2016-0397 MEDIUM

WebReports in IBM BigFix Platform (formerly Tivoli Endpoint Manager) 9.x before 9.5.2 allows remote attackers to obtain sensitive information by sniffing the network for HTTP traffic.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm bigfix_webreports 9.0
ibm bigfix_webreports 9.1
ibm bigfix_webreports 9.5
ibm bigfix_webreports 9.2
CVE-2016-0398 MEDIUM

IBM Cognos Analytics (CA) 11.0 before 11.0.2 allows remote attackers to conduct content-spoofing attacks via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm cognos_analytics 11.0.0
CVE-2016-0399 LOW

Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5 before 7.5.0.9 IFIX007, and 7.6 before 7.6.0.5 FP005 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm maximo_asset_management 7.1.1.9
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.5.0.1
ibm maximo_asset_management 7.5.0.10
ibm maximo_asset_management 7.1.1.13
ibm maximo_asset_management 7.1.1.10
ibm maximo_asset_management 7.6.0.4
ibm maximo_asset_management 7.1.1.1
ibm maximo_asset_management 7.1.1.12
ibm maximo_asset_management 7.1.1.3
ibm maximo_asset_management 7.6.0.5
ibm maximo_asset_management 7.5.0.3
ibm maximo_asset_management 7.5.0.9
ibm maximo_asset_management 7.5.0.6
ibm maximo_asset_management 7.5.0.0
ibm maximo_asset_management 7.1.1.7
ibm maximo_asset_management 7.5.0.7
ibm maximo_asset_management 7.5.0.4
ibm maximo_asset_management 7.5.0.5
ibm maximo_asset_management 7.1.1.2
ibm maximo_asset_management 7.1.1.6
ibm maximo_asset_management 7.1.1.5
ibm maximo_asset_management 7.1.1.11
ibm maximo_asset_management 7.1.2
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
ibm maximo_asset_management 7.5.0.8
CVE-2016-0400 MEDIUM

CRLF injection vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3, 7.1.1 before 7.1.1.1, 8.5 before 8.5.0.3, and 8.6 before 8.6.0.8 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm websphere_extreme_scale 8.6.0.4
ibm websphere_extreme_scale 8.6.0.6
ibm websphere_extreme_scale 8.6.0.2
ibm websphere_extreme_scale 8.5.0.2
ibm websphere_extreme_scale 8.6.0.1
ibm websphere_extreme_scale 8.6.0.5
ibm websphere_extreme_scale 7.1.0.2
ibm websphere_extreme_scale 8.6.0.7
ibm websphere_extreme_scale 7.1.0
ibm websphere_extreme_scale 8.5.0
ibm websphere_extreme_scale 8.6.0.3
ibm websphere_extreme_scale 8.6.0.0
ibm websphere_extreme_scale 7.1.1
ibm websphere_extreme_scale 8.5.0.1
CVE-2016-0640 MEDIUM

Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.48, 10.0.x before 10.0.24, and 10.1.x before 10.1.12 allows local users to affect integrity and availability via vectors related to DML.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
mariadb mariadb *
debian debian_linux 8.0
redhat enterprise_linux 7.0
ibm powerkvm 3.1
opensuse leap 42.1
redhat enterprise_linux 6.0
oracle mysql *
oracle linux 7
ibm powerkvm 2.1
CVE-2016-0641 MEDIUM

Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.48, 10.0.x before 10.0.24, and 10.1.x before 10.1.12 allows local users to affect confidentiality and availability via vectors related to MyISAM.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
mariadb mariadb *
debian debian_linux 8.0
redhat enterprise_linux 7.0
ibm powerkvm 3.1
opensuse leap 42.1
redhat enterprise_linux 6.0
oracle mysql *
oracle linux 7
ibm powerkvm 2.1
CVE-2016-0643 MEDIUM

Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows local users to affect confidentiality via vectors related to DML.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
mariadb mariadb *
debian debian_linux 8.0
redhat enterprise_linux 7.0
ibm powerkvm 3.1
opensuse leap 42.1
redhat enterprise_linux 6.0
oracle mysql *
ibm powerkvm 2.1
CVE-2016-0644 MEDIUM

Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.48, 10.0.x before 10.0.24, and 10.1.x before 10.1.12 allows local users to affect availability via vectors related to DDL.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
mariadb mariadb *
debian debian_linux 8.0
redhat enterprise_linux 7.0
ibm powerkvm 3.1
opensuse leap 42.1
redhat enterprise_linux 6.0
oracle mysql *
oracle linux 7
ibm powerkvm 2.1
CVE-2016-0646 MEDIUM

Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.48, 10.0.x before 10.0.24, and 10.1.x before 10.1.12 allows local users to affect availability via vectors related to DML.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
mariadb mariadb *
debian debian_linux 8.0
redhat enterprise_linux 7.0
ibm powerkvm 3.1
opensuse leap 42.1
redhat enterprise_linux 6.0
oracle mysql *
oracle linux 7
ibm powerkvm 2.1
CVE-2016-0647 MEDIUM

Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows local users to affect availability via vectors related to FTS.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
mariadb mariadb *
debian debian_linux 8.0
redhat enterprise_linux 7.0
ibm powerkvm 3.1
opensuse leap 42.1
redhat enterprise_linux 6.0
oracle mysql *
oracle linux 7
ibm powerkvm 2.1
CVE-2016-0648 MEDIUM

Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows local users to affect availability via vectors related to PS.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
mariadb mariadb *
debian debian_linux 8.0
redhat enterprise_linux 7.0
ibm powerkvm 3.1
opensuse leap 42.1
redhat enterprise_linux 6.0
oracle mysql *
oracle linux 7
ibm powerkvm 2.1
CVE-2016-0649 MEDIUM

Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.48, 10.0.x before 10.0.24, and 10.1.x before 10.1.12 allows local users to affect availability via vectors related to PS.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
mariadb mariadb *
debian debian_linux 8.0
redhat enterprise_linux 7.0
ibm powerkvm 3.1
opensuse leap 42.1
redhat enterprise_linux 6.0
oracle mysql *
oracle linux 7
ibm powerkvm 2.1
CVE-2016-0650 MEDIUM

Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.48, 10.0.x before 10.0.24, and 10.1.x before 10.1.12 allows local users to affect availability via vectors related to Replication.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
mariadb mariadb *
debian debian_linux 8.0
redhat enterprise_linux 7.0
ibm powerkvm 3.1
opensuse leap 42.1
redhat enterprise_linux 6.0
oracle mysql *
oracle linux 7
ibm powerkvm 2.1
CVE-2016-0666 LOW

Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows local users to affect availability via vectors related to Security: Privileges.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
mariadb mariadb *
debian debian_linux 8.0
redhat enterprise_linux 7.0
ibm powerkvm 3.1
opensuse leap 42.1
redhat enterprise_linux 6.0
oracle mysql *
oracle linux 7
ibm powerkvm 2.1
CVE-2016-1000232 MEDIUM

NodeJS Tough-Cookie version 2.2.2 contains a Regular Expression Parsing vulnerability in HTTP request Cookie Header parsing that can result in Denial of Service. This attack appear to be exploitable via Custom HTTP header passed by client. This vulnerability appears to have been fixed in 2.3.0.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
redhat openshift_container_platform 3.2
redhat openshift_container_platform 3.1
ibm api_connect *
salesforce tough-cookie *
redhat openshift_container_platform 3.3
ibm api_connect 5.0.8.0
CVE-2016-10503 MEDIUM

IBM Sametime Meeting Server 8.5.2 and 9.0 could allow an authenticated and invited user of Sametime meeting to lower any or all hands in an e-meeting, thus spoofing results of votes in the meeting. IBM X-Force ID: 113803.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm sametime 8.5.2.0
ibm sametime 8.5.2.1
ibm sametime 9.0.0.1
ibm sametime 9.0.0.0
ibm sametime 9.0.1
CVE-2016-10577 MEDIUM

ibm_db is an asynchronous/synchronous interface for node.js to IBM DB2 and IBM Informix. ibm_db before 1.0.2 downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-311,CWE-310,

Products Affected

Vendor Product Version
ibm ibm_db *
CVE-2016-2861 MEDIUM

IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3, 7.1.1 before 7.1.1.1, 8.5 before 8.5.0.3, and 8.6 before 8.6.0.8 does not properly encrypt data, which makes it easier for remote attackers to obtain sensitive information by sniffing the network.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_extreme_scale 8.6.0
ibm websphere_extreme_scale 8.6.0.4
ibm websphere_extreme_scale 8.6.0.6
ibm websphere_extreme_scale 8.6.0.2
ibm websphere_extreme_scale 8.5.0.2
ibm websphere_extreme_scale 8.6.0.1
ibm websphere_extreme_scale 8.6.0.5
ibm websphere_extreme_scale 7.1.0.2
ibm websphere_extreme_scale 8.6.0.7
ibm websphere_extreme_scale 7.1.0
ibm websphere_extreme_scale 8.5.0
ibm websphere_extreme_scale 8.6.0.3
ibm websphere_extreme_scale 8.6.0.0
ibm websphere_extreme_scale 7.1.1
ibm websphere_extreme_scale 8.5.0.1
CVE-2016-2862 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM WebSphere Commerce 6.0 through 6.0.0.11, 7.0 before 7.0.0.9 cumulative iFix 3, and 8.0 before 8.0.0.5 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_commerce 6.0.0.6
ibm websphere_commerce 7.0.0.6
ibm websphere_commerce 7.0.0.7
ibm websphere_commerce 6.0.0.11
ibm websphere_commerce 6.0.0.10
ibm websphere_commerce 7.0.0.3
ibm websphere_commerce 7.0.0.2
ibm websphere_commerce 7.0
ibm websphere_commerce 8.0.0.4
ibm websphere_commerce 6.0.0.7
ibm websphere_commerce 6.0.0.8
ibm websphere_commerce 8.0.0.1
ibm websphere_commerce 7.0.0.5
ibm websphere_commerce 8.0.0.3
ibm websphere_commerce 6.0.0.0
ibm websphere_commerce 7.0.0.1
ibm websphere_commerce 6.0.0.5
ibm websphere_commerce 7.0.0.8
ibm websphere_commerce 8.0.0.2
ibm websphere_commerce 7.0.0.4
ibm websphere_commerce 6.0.0.1
ibm websphere_commerce 6.0.0.2
ibm websphere_commerce 7.0.0.9
ibm websphere_commerce 8.0.0.0
ibm websphere_commerce 6.0.0.3
ibm websphere_commerce 6.0.0.4
ibm websphere_commerce 6.0.0.9
CVE-2016-2863 MEDIUM

Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Commerce 7.0 Feature Pack 8, 8.0.0.x before 8.0.0.10, and 8.0.1.x before 8.0.1.2 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm websphere_commerce 8.0.0.9
ibm websphere_commerce 8.0.0.8
ibm websphere_commerce 8.0.0.5
ibm websphere_commerce 8.0.0.6
ibm websphere_commerce 7.0
ibm websphere_commerce 8.0.0.7
ibm websphere_commerce 8.0.0.1
ibm websphere_commerce 8.0.0.0
ibm websphere_commerce 8.0.0.3
ibm websphere_commerce 8.0.0.2
CVE-2016-2864 LOW

Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Team Concert 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational DOORS Next Generation 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Engineering Lifecycle Manager 4.x before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Rhapsody Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; and Rational Software Architect Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_rhapsody_design_manager 4.0.4
ibm rational_rhapsody_design_manager 4.0.5
ibm rational_doors_next_generation 4.0.0
ibm rational_collaborative_lifecycle_management 4.0.6
ibm rational_engineering_lifecycle_manager 4.0.7
ibm rational_quality_manager 4.0.6
ibm rational_software_architect_design_manager 6.0.1
ibm rational_software_architect_design_manager 4.0.7
ibm rational_quality_manager 6.0.1
ibm rational_engineering_lifecycle_manager 5.0.2
ibm rational_rhapsody_design_manager 5.0.2
ibm rational_quality_manager 4.0.3
ibm rational_engineering_lifecycle_manager 6.0.2
ibm rational_team_concert 4.0.1
ibm rational_team_concert 6.0.0
ibm rational_team_concert 4.0.5
ibm rational_team_concert 4.0.2
ibm rational_collaborative_lifecycle_management 4.0.5
ibm rational_collaborative_lifecycle_management 4.0.7
ibm rational_collaborative_lifecycle_management 5.0.0
ibm rational_collaborative_lifecycle_management 4.0.3
ibm rational_software_architect_design_manager 4.0.6
ibm rational_doors_next_generation 4.0.7
ibm rational_doors_next_generation 4.0.2
ibm rational_engineering_lifecycle_manager 4.0.0
ibm rational_software_architect_design_manager 5.0.0
ibm rational_rhapsody_design_manager 4.0.7
ibm rational_doors_next_generation 6.0.0
ibm rational_engineering_lifecycle_manager 6.0.0
ibm rational_team_concert 5.0.2
ibm rational_collaborative_lifecycle_management 4.0.1
ibm rational_team_concert 4.0.3
ibm rational_collaborative_lifecycle_management 4.0.2
ibm rational_engineering_lifecycle_manager 4.0.2
ibm rational_team_concert 4.0.0
ibm rational_quality_manager 4.0.1
ibm rational_team_concert 4.0.6
ibm rational_quality_manager 4.0.0
ibm rational_quality_manager 5.0.0
ibm rational_engineering_lifecycle_manager 4.0.5
ibm rational_software_architect_design_manager 5.0.2
ibm rational_engineering_lifecycle_manager 6.0.1
ibm rational_software_architect_design_manager 6.0.0
ibm rational_doors_next_generation 4.0.4
ibm rational_quality_manager 4.0.4
ibm rational_software_architect_design_manager 4.0.0
ibm rational_engineering_lifecycle_manager 4.0.6
ibm rational_rhapsody_design_manager 4.0.3
ibm rational_doors_next_generation 5.0.0
ibm rational_doors_next_generation 5.0.2
ibm rational_quality_manager 4.0.2
ibm rational_doors_next_generation 5.0.1
ibm rational_software_architect_design_manager 4.0.1
ibm rational_team_concert 3.0.1.6
ibm rational_collaborative_lifecycle_management 4.0.4
ibm rational_engineering_lifecycle_manager 4.0.3
ibm rational_engineering_lifecycle_manager 4.0.4
ibm rational_rhapsody_design_manager 5.0.0
ibm rational_software_architect_design_manager 4.0.2
ibm rational_engineering_lifecycle_manager 4.0.1
ibm rational_engineering_lifecycle_manager 5.0.0
ibm rational_team_concert 6.0.1
ibm rational_quality_manager 4.0.7
ibm rational_rhapsody_design_manager 4.0.6
ibm rational_rhapsody_design_manager 6.0.1
ibm rational_rhapsody_design_manager 6.0.2
ibm rational_software_architect_design_manager 4.0.4
ibm rational_team_concert 6.0.2
ibm rational_doors_next_generation 4.0.1
ibm rational_engineering_lifecycle_manager 5.0.1
ibm rational_team_concert 4.0.7
ibm rational_collaborative_lifecycle_management 6.0.2
ibm rational_software_architect_design_manager 4.0.3
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_quality_manager 5.0.2
ibm rational_rhapsody_design_manager 4.0.1
ibm rational_rhapsody_design_manager 4.0.2
ibm rational_rhapsody_design_manager 4.0
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_collaborative_lifecycle_management 4.0.0
ibm rational_collaborative_lifecycle_management 3.0.1.6
ibm rational_quality_manager 3.0.1.6
ibm rational_doors_next_generation 6.0.1
ibm rational_rhapsody_design_manager 5.0.1
ibm rational_doors_next_generation 4.0.5
ibm rational_doors_next_generation 4.0.6
ibm rational_doors_next_generation 4.0.3
ibm rational_quality_manager 5.0.1
ibm rational_team_concert 5.0.0
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_software_architect_design_manager 6.0.2
ibm rational_software_architect_design_manager 4.0.5
ibm rational_team_concert 4.0.4
ibm rational_software_architect_design_manager 5.0.1
ibm rational_quality_manager 4.0.5
ibm rational_quality_manager 6.0.2
ibm rational_doors_next_generation 6.0.2
ibm rational_quality_manager 6.0.0
ibm rational_collaborative_lifecycle_management 6.0.0
ibm rational_team_concert 5.0.1
ibm rational_rhapsody_design_manager 6.0.0
CVE-2016-2865 MEDIUM

The GIT Integration component in IBM Rational Team Concert (RTC) 5.x before 5.0.2 iFix14 and 6.x before 6.0.1 iFix5 and Rational Collaborative Lifecycle Management 5.x before 5.0.2 iFix14 and 6.x before 6.0.1 iFix5 allows remote authenticated users to obtain sensitive information via a malformed request.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_team_concert 5.0.0
ibm rational_team_concert 6.0.1
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_team_concert 6.0.0
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_collaborative_lifecycle_management 6.0.0
ibm rational_team_concert 5.0.2
ibm rational_collaborative_lifecycle_management 5.0.0
ibm rational_team_concert 5.0.1
CVE-2016-2866 MEDIUM

An unspecified vulnerability in IBM Jazz Team Server may disclose some deployment information to an authenticated user.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_collaborative_lifecycle_management 6.0.3
ibm rational_collaborative_lifecycle_management 6.0.2
ibm rational_collaborative_lifecycle_management 4.0.6
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_collaborative_lifecycle_management 4.0.1
ibm rational_collaborative_lifecycle_management 4.0.5
ibm rational_collaborative_lifecycle_management 4.0.7
ibm rational_collaborative_lifecycle_management 5.0.0
ibm rational_collaborative_lifecycle_management 4.0.3
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_collaborative_lifecycle_management 4.0.0
ibm rational_collaborative_lifecycle_management 4.0.2
ibm rational_collaborative_lifecycle_management 6.0.0
ibm rational_collaborative_lifecycle_management 4.0.4
CVE-2016-2867 MEDIUM

IBM InfoSphere Streams before 4.0.1.2 and IBM Streams before 4.1.1.1 do not properly implement the runAsUser feature, which allows local users to obtain root group privileges via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-254,

Products Affected

Vendor Product Version
ibm infosphere_streams *
ibm streams *
CVE-2016-2868 MEDIUM

IBM Security QRadar SIEM 7.2.x before 7.2.7 allows remote authenticated administrators to read arbitrary files via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager *
CVE-2016-2869 LOW

Multiple cross-site scripting (XSS) vulnerabilities in the UI in IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 allow remote authenticated users to inject arbitrary web script or HTML via crafted fields in a URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.2
ibm qradar_security_information_and_event_manager 7.2.0
ibm qradar_security_information_and_event_manager 7.2.3
ibm qradar_security_information_and_event_manager 7.2.6
ibm qradar_security_information_and_event_manager 7.2.4
ibm qradar_security_information_and_event_manager *
ibm qradar_security_information_and_event_manager 7.2.1
ibm qradar_security_information_and_event_manager 7.2.5
CVE-2016-2870 MEDIUM

Buffer overflow in the CLI on IBM WebSphere DataPower XC10 appliances 2.1 and 2.5 allows remote authenticated users to cause a denial of service via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm websphere_datapower_xc10_appliance_firmware 2.1
ibm websphere_datapower_xc10_appliance_firmware 2.5
CVE-2016-2871 MEDIUM

IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 uses cleartext storage for unspecified passwords, which allows local users to obtain sensitive information by reading a configuration file.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.2
ibm qradar_security_information_and_event_manager 7.2.0
ibm qradar_security_information_and_event_manager 7.2.3
ibm qradar_security_information_and_event_manager 7.2.6
ibm qradar_security_information_and_event_manager 7.2.4
ibm qradar_security_information_and_event_manager *
ibm qradar_security_information_and_event_manager 7.2.1
ibm qradar_security_information_and_event_manager 7.2.5
CVE-2016-2872 MEDIUM

Directory traversal vulnerability in IBM Security QRadar SIEM 7.2.x before 7.2.7 and QRadar Incident Forensics 7.2.x before 7.2.7 allows remote attackers to read arbitrary files via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.2
ibm security_qradar_incident_forensics 7.2.2
ibm security_qradar_incident_forensics 7.2.1
ibm qradar_security_information_and_event_manager 7.2.5
ibm security_qradar_incident_forensics 7.2.6
ibm security_qradar_incident_forensics 7.2.0
ibm qradar_security_information_and_event_manager 7.2.0
ibm security_qradar_incident_forensics 7.2.5
ibm security_qradar_incident_forensics 7.2.3
ibm qradar_security_information_and_event_manager 7.2.3
ibm qradar_security_information_and_event_manager 7.2.6
ibm qradar_security_information_and_event_manager 7.2.4
ibm security_qradar_incident_forensics 7.2.4
ibm qradar_security_information_and_event_manager 7.2.1
CVE-2016-2873 MEDIUM

SQL injection vulnerability in IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.2
ibm qradar_security_information_and_event_manager 7.2.0
ibm qradar_security_information_and_event_manager 7.2.3
ibm qradar_security_information_and_event_manager 7.2.6
ibm qradar_security_information_and_event_manager 7.2.4
ibm qradar_security_information_and_event_manager *
ibm qradar_security_information_and_event_manager 7.2.1
ibm qradar_security_information_and_event_manager 7.2.5
CVE-2016-2874 LOW

IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 mishandles authorization, which allows remote authenticated users to obtain sensitive information via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.2
ibm qradar_security_information_and_event_manager 7.2.0
ibm qradar_security_information_and_event_manager 7.2.3
ibm qradar_security_information_and_event_manager 7.2.6
ibm qradar_security_information_and_event_manager 7.2.4
ibm qradar_security_information_and_event_manager *
ibm qradar_security_information_and_event_manager 7.2.1
ibm qradar_security_information_and_event_manager 7.2.5
CVE-2016-2875 HIGH

IBM Security QRadar SIEM 7.1.x and 7.2.x before 7.2.7 allows remote authenticated users to execute arbitrary OS commands as root via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-77,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.2
ibm qradar_security_information_and_event_manager 7.2.0
ibm qradar_security_information_and_event_manager 7.1.0
ibm qradar_security_information_and_event_manager 7.2.3
ibm qradar_security_information_and_event_manager 7.2.6
ibm qradar_security_information_and_event_manager 7.2.4
ibm qradar_security_information_and_event_manager 7.2.1
ibm qradar_security_information_and_event_manager 7.2.5
CVE-2016-2876 HIGH

IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 executes unspecified processes at an incorrect privilege level, which makes it easier for remote authenticated users to obtain root access by leveraging a command-injection issue.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-78,CWE-264,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.2
ibm qradar_security_information_and_event_manager 7.2.0
ibm qradar_security_information_and_event_manager 7.2.3
ibm qradar_security_information_and_event_manager 7.2.6
ibm qradar_security_information_and_event_manager 7.2.4
ibm qradar_security_information_and_event_manager *
ibm qradar_security_information_and_event_manager 7.2.1
ibm qradar_security_information_and_event_manager 7.2.5
CVE-2016-2877 LOW

IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 uses weak permissions for unspecified directories under the web root, which allows local users to modify data by writing to a file.

CVSS 2.0

Severity: LOW

Problem Type: CWE-275,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.2
ibm qradar_security_information_and_event_manager 7.2.0
ibm qradar_security_information_and_event_manager 7.2.3
ibm qradar_security_information_and_event_manager 7.2.6
ibm qradar_security_information_and_event_manager 7.2.4
ibm qradar_security_information_and_event_manager *
ibm qradar_security_information_and_event_manager 7.2.1
ibm qradar_security_information_and_event_manager 7.2.5
CVE-2016-2878 MEDIUM

Multiple cross-site request forgery (CSRF) vulnerabilities in IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 allow remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.2
ibm qradar_security_information_and_event_manager 7.2.0
ibm qradar_security_information_and_event_manager 7.1.0
ibm qradar_security_information_and_event_manager 7.2.3
ibm qradar_security_information_and_event_manager 7.2.6
ibm qradar_security_information_and_event_manager 7.2.4
ibm qradar_security_information_and_event_manager 7.2.1
ibm qradar_security_information_and_event_manager 7.2.5
CVE-2016-2879 LOW

IBM QRadar 7.2 uses outdated hashing algorithms to hash certain passwords, which could allow a local user to obtain and decrypt user credentials. IBM Reference #: 1997341.

CVSS 2.0

Severity: LOW

Problem Type: CWE-326,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.2
ibm qradar_security_information_and_event_manager 7.2.0
ibm qradar_security_information_and_event_manager 7.2.7
ibm qradar_security_information_and_event_manager 7.2.3
ibm qradar_security_information_and_event_manager 7.2.6
ibm qradar_security_information_and_event_manager 7.2.4
ibm qradar_security_information_and_event_manager 7.2.1
ibm qradar_security_information_and_event_manager 7.2.5
CVE-2016-2880 LOW

IBM QRadar 7.2 stores the encryption key used to encrypt the service account password which can be obtained by a local user. IBM Reference #: 1997340.

CVSS 2.0

Severity: LOW

Problem Type: CWE-320,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.2
ibm qradar_security_information_and_event_manager 7.2.0
ibm qradar_security_information_and_event_manager 7.2.7
ibm qradar_security_information_and_event_manager 7.2.3
ibm qradar_security_information_and_event_manager 7.2.6
ibm qradar_security_information_and_event_manager 7.2.4
ibm qradar_security_information_and_event_manager 7.2.1
ibm qradar_security_information_and_event_manager 7.2.5
CVE-2016-2881 MEDIUM

IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 and QRadar Incident Forensics 7.2 before 7.2.7 allow remote attackers to bypass intended access restrictions via modified request parameters.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-254,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.2
ibm qradar_security_information_and_event_manager 7.2.0
ibm qradar_security_information_and_event_manager 7.2.3
ibm qradar_security_information_and_event_manager 7.2.6
ibm qradar_security_information_and_event_manager 7.2.4
ibm qradar_security_information_and_event_manager *
ibm qradar_security_information_and_event_manager 7.2.1
ibm qradar_security_information_and_event_manager 7.2.5
CVE-2016-2882 MEDIUM

IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.4, and 3.5 before 3.5.0.2 allows remote authenticated users to obtain sensitive information by reading HTTP responses.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm tririga_application_platform 3.3.1.1
ibm tririga_application_platform 3.5.0.0
ibm tririga_application_platform 3.4.2.1
ibm tririga_application_platform 3.4.2.3
ibm tririga_application_platform 3.4.1.2
ibm tririga_application_platform 3.5.0.1
ibm tririga_application_platform 3.3.2.4
ibm tririga_application_platform 3.4.1.1
ibm tririga_application_platform 3.3.1.2
ibm tririga_application_platform 3.4.2.0
ibm tririga_application_platform 3.3.2.5
ibm tririga_application_platform 3.4.0.0
ibm tririga_application_platform 3.3.0.1
ibm tririga_application_platform 3.3.1.3
ibm tririga_application_platform 3.3.1.0
ibm tririga_application_platform 3.3.2.1
ibm tririga_application_platform 3.3.0.2
ibm tririga_application_platform 3.3.2.3
ibm tririga_application_platform 3.3.2.0
ibm tririga_application_platform 3.4.1.3
ibm tririga_application_platform 3.4.2.2
ibm tririga_application_platform 3.3.0.0
CVE-2016-2883 LOW

Cross-site scripting (XSS) vulnerability in IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.4, and 3.5 before 3.5.0.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-0387.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tririga_application_platform 3.3.1.1
ibm tririga_application_platform 3.5.0.0
ibm tririga_application_platform 3.4.2.1
ibm tririga_application_platform 3.4.2.3
ibm tririga_application_platform 3.4.1.2
ibm tririga_application_platform 3.5.0.1
ibm tririga_application_platform 3.3.2.4
ibm tririga_application_platform 3.4.1.1
ibm tririga_application_platform 3.3.1.2
ibm tririga_application_platform 3.4.2.0
ibm tririga_application_platform 3.3.2.5
ibm tririga_application_platform 3.4.0.0
ibm tririga_application_platform 3.3.0.1
ibm tririga_application_platform 3.3.1.3
ibm tririga_application_platform 3.3.1.0
ibm tririga_application_platform 3.3.2.1
ibm tririga_application_platform 3.3.0.2
ibm tririga_application_platform 3.3.2.3
ibm tririga_application_platform 3.3.2.0
ibm tririga_application_platform 3.4.1.3
ibm tririga_application_platform 3.4.2.2
ibm tririga_application_platform 3.3.0.0
CVE-2016-2884 MEDIUM

Cross-site request forgery (CSRF) vulnerability in IBM Forms Experience Builder 8.5.x and 8.6.x before 8.6.3.1, in an unspecified non-default configuration, allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm forms_experience_builder 8.5.0.0
ibm forms_experience_builder 8.6.0.0
ibm forms_experience_builder 8.6.1.1
ibm forms_experience_builder 8.6.2
ibm forms_experience_builder 8.6.2.1
ibm forms_experience_builder 8.5.1.0
ibm forms_experience_builder 8.6.3
ibm forms_experience_builder 8.5.1.1
ibm forms_experience_builder 8.6.1
CVE-2016-2887 MEDIUM

IBM IMS Enterprise Suite Data Provider before 3.2.0.1 for Microsoft .NET allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,CWE-284,

Products Affected

Vendor Product Version
ibm ims_enterprise_suite *
CVE-2016-2888 MEDIUM

Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-0313 and CVE-2016-0350.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm jazz_reporting_service 5.0.2
ibm jazz_reporting_service 6.0
ibm jazz_reporting_service 6.0.1
ibm jazz_reporting_service 5.0
ibm jazz_reporting_service 5.0.1
CVE-2016-2889 MEDIUM

Cross-site request forgery (CSRF) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016, 6.0 and 6.0.1 before 6.0.1 ifix005, and 6.0.2 before ifix002 allows remote authenticated users to hijack the authentication of arbitrary users.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm jazz_reporting_service 5.0.2
ibm jazz_reporting_service 6.0
ibm jazz_reporting_service 6.0.2
ibm jazz_reporting_service 6.0.1
ibm jazz_reporting_service 5.0
ibm jazz_reporting_service 5.0.1
CVE-2016-2894 LOW

IBM Spectrum Protect (formerly Tivoli Storage Manager) 5.5 through 6.3 before 6.3.2.6, 6.4 before 6.4.3.3, and 7.1 before 7.1.6 allows local users to obtain sensitive retrieved data from arbitrary accounts in opportunistic circumstances by leveraging previous use of a symlink during archive and retrieve actions.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager 7.1.3.1
ibm tivoli_storage_manager 5.5.4.1
ibm tivoli_storage_manager 6.3.2.2
ibm tivoli_storage_manager 6.4.1.7
ibm tivoli_storage_manager 5.5.4
ibm tivoli_storage_manager 6.2.4.7
ibm tivoli_storage_manager 6.4.2.1
ibm tivoli_storage_manager 5.5
ibm tivoli_storage_manager 7.1.2
ibm tivoli_storage_manager 6.1.1
ibm tivoli_storage_manager 7.1.3
ibm tivoli_storage_manager 6.1.5
ibm tivoli_storage_manager 6.2.4
ibm tivoli_storage_manager 7.1..5.100
ibm tivoli_storage_manager 7.1.3.2
ibm tivoli_storage_manager 6.2.3
ibm tivoli_storage_manager 7.1.0.3
ibm tivoli_storage_manager 7.1.4
ibm tivoli_storage_manager 6.3.0
ibm tivoli_storage_manager 7.1.1.1
ibm tivoli_storage_manager 6.4.3
ibm tivoli_storage_manager 7.1.1.100
ibm tivoli_storage_manager 7.1.1
ibm tivoli_storage_manager 6.3.1.2
ibm tivoli_storage_manager 5.5.4.3
ibm tivoli_storage_manager 6.3.0.15
ibm tivoli_storage_manager 6.4.0.4
ibm tivoli_storage_manager 6.4
ibm tivoli_storage_manager 6.4.0
ibm tivoli_storage_manager 5.5.0
ibm tivoli_storage_manager 6.1.3
ibm tivoli_storage_manager 7.1.1.300
ibm tivoli_storage_manager 7.1.5.200
ibm tivoli_storage_manager 7.1.3.000
ibm tivoli_storage_manager 6.1
ibm tivoli_storage_manager 6.2.1
ibm tivoli_storage_manager 6.1.0
ibm tivoli_storage_manager 6.3
ibm tivoli_storage_manager 6.4.2.200
ibm tivoli_storage_manager 6.4.0.7
ibm tivoli_storage_manager 6.3.1
ibm tivoli_storage_manager 6.1.5.5
ibm tivoli_storage_manager 6.1.2
ibm tivoli_storage_manager 7.1.4.1
ibm tivoli_storage_manager 7.1
ibm tivoli_storage_manager 7.1.5
ibm tivoli_storage_manager 6.4.0.5
ibm tivoli_storage_manager 6.4.0.1
ibm tivoli_storage_manager 7.1.0.1
ibm tivoli_storage_manager 7.1.3.100
ibm tivoli_storage_manager 5.5.4.2
ibm tivoli_storage_manager 6.4.3.1
ibm tivoli_storage_manager 6.3.0.17
ibm tivoli_storage_manager 6.1.5.6
ibm tivoli_storage_manager 7.1.1.200
ibm tivoli_storage_manager 6.2.0
ibm tivoli_storage_manager 6.4.1.3
ibm tivoli_storage_manager 6.3.0.5
ibm tivoli_storage_manager 7.1.0.2
ibm tivoli_storage_manager 6.4.2.100
ibm tivoli_storage_manager 5.5.3
ibm tivoli_storage_manager 6.1.4
ibm tivoli_storage_manager 6.2
ibm tivoli_storage_manager 5.5.2
ibm tivoli_storage_manager 6.2.2
ibm tivoli_storage_manager 6.1.5.4
CVE-2016-2901 MEDIUM

Cross-site request forgery (CSRF) vulnerability in the PA_Theme_Creator application in IBM WebSphere Portal 8.5 CF08 through CF10 and Web Content Manager allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm web_content_manager *
ibm websphere_portal 8.5.0.0
CVE-2016-2908 MEDIUM

IBM Single Sign On for Bluemix could allow a remote attacker to obtain sensitive information, caused by a XML external entity (XXE) error when processing XML data by the XML parser. A remote attacker could exploit this vulnerability to read arbitrary files on the system or cause a denial of service.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm security_access_manager_9.0_firmware 9.0.0.1
ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.5
ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.3
ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.1
ibm security_access_manager_for_web_8.0_firmware 8.0.1.4
ibm security_access_manager_for_web_8.0_firmware 8.0.1.0
ibm security_access_manager_9.0_firmware 9.0.1.0
ibm security_access_manager_for_web_8.0_firmware 8.0.0.2
ibm security_access_manager_for_web_8.0_firmware 8.0.0.3
ibm security_access_manager_9.0_firmware 9.0.0
ibm security_access_manager_for_mobile_8.0_firmware 8.0.1.0
ibm security_access_manager_for_mobile_8.0_firmware 8.0.1.2
ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.2
ibm security_access_manager_for_web_8.0_firmware 8.0.1.2
ibm security_access_manager_for_mobile_8.0_firmware 8.0.1.3
ibm security_access_manager_for_mobile_8.0_firmware 8.0.1.4
ibm security_access_manager_for_web_8.0_firmware 8.0.0.5
ibm security_access_manager_for_web_8.0_firmware 8.0.0.1
ibm security_access_manager_for_web_8.0_firmware 8.0.1.3
CVE-2016-2912 LOW

Cross-site scripting (XSS) vulnerability in the Document Builder in IBM Rational Publishing Engine (aka RPENG) 2.0.1 before ifix002 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm engineering_lifecycle_optimization_-_publishing 2.0.1
CVE-2016-2914 MEDIUM

Unrestricted file upload vulnerability in the Document Builder in IBM Rational Publishing Engine (aka RPENG) 2.0.1 before ifix002 allows remote authenticated users to execute arbitrary code by specifying an unexpected file extension.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-434,

Products Affected

Vendor Product Version
ibm engineering_lifecycle_optimization_-_publishing 2.0.1
CVE-2016-2917 MEDIUM

The notifications component in IBM TRIRIGA Applications 10.4 and 10.5 before 10.5.1 allows remote authenticated users to obtain sensitive password information, and consequently gain privileges, via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm tririga_application_platform 10.4
ibm tririga_application_platform 10.5
CVE-2016-2922 MEDIUM

IBM Rational ClearQuest 8.0 through 8.0.1.9 and 9.0 through 9.0.1.3 (CQ OSLC linkages, EmailRelay) fails to check the SSL certificate against the requested hostname. It is subject to a man-in-the-middle attack with an impersonating server observing all the data transmitted to the real server. IBM X-Force ID: 113353.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-295,

Products Affected

Vendor Product Version
ibm rational_clearquest *
CVE-2016-2923 MEDIUM

IBM WebSphere Application Server (WAS) 8.5 through 8.5.5.9 Liberty before Liberty Fix Pack 16.0.0.2 does not include the HTTPOnly flag in a Set-Cookie header for an unspecified JAX-RS API cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_application_server 8.5.5.6
ibm websphere_application_server 8.5.5.8
ibm websphere_application_server 8.5.5.0
ibm websphere_application_server 8.5.5.2
ibm websphere_application_server 8.5.5.9
ibm websphere_application_server 8.5.5.3
ibm websphere_application_server 8.5.5.7
ibm websphere_application_server 8.5.5.4
ibm websphere_application_server 8.5.5.5
ibm websphere_application_server 8.5.5.1
CVE-2016-2924 LOW

IBM Infosphere BigInsights is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm biginsights 4.2
CVE-2016-2925 LOW

Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.x through 7.0.0.2 CF30, 8.0.0.x through 8.0.0.1 CF21, and 8.5.0 before CF10 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.0
ibm websphere_portal 6.1.0.3
ibm websphere_portal 7.0.0.1
ibm websphere_portal 6.1.5.2
ibm websphere_portal 6.1.0.2
ibm websphere_portal 6.1.0.4
ibm websphere_portal 8.0.0.1
ibm websphere_portal 7.0.0.2
ibm websphere_portal 8.5.0.0
ibm websphere_portal 6.1.5.0
ibm websphere_portal 6.1.0.6
ibm websphere_portal 6.1.5.3
ibm websphere_portal 7.0.0.0
ibm websphere_portal 6.1.0.1
ibm websphere_portal 6.1.5.1
ibm websphere_portal 6.1.0.5
ibm websphere_portal 6.1.0.0
CVE-2016-2926 LOW

Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix19, and 6.0 before 6.0.2 iFix3; Rational Quality Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix19, and 6.0 before 6.0.2 iFix3; Rational Team Concert 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix19, and 6.0 before 6.0.2 iFix3; Rational DOORS Next Generation 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix19, and 6.0 before 6.0.2 iFix3; Rational Engineering Lifecycle Manager 4.x before 4.0.7 iFix11, 5.0 before 5.0.2 iFix19, and 6.0 before 6.0.2 iFix3; Rational Rhapsody Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix19, and 6.0 before 6.0.2 iFix3; and Rational Software Architect Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix19, and 6.0 before 6.0.2 iFix3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_rhapsody_design_manager 4.0.4
ibm rational_rhapsody_design_manager 4.0.5
ibm rational_doors_next_generation 4.0.0
ibm rational_collaborative_lifecycle_management 4.0.6
ibm rational_engineering_lifecycle_manager 4.0.7
ibm rational_quality_manager 4.0.6
ibm rational_software_architect_design_manager 6.0.1
ibm rational_software_architect_design_manager 4.0.7
ibm rational_quality_manager 6.0.1
ibm rational_engineering_lifecycle_manager 5.0.2
ibm rational_rhapsody_design_manager 5.0.2
ibm rational_quality_manager 4.0.3
ibm rational_engineering_lifecycle_manager 6.0.2
ibm rational_team_concert 4.0.1
ibm rational_team_concert 6.0.0
ibm rational_team_concert 4.0.5
ibm rational_team_concert 4.0.2
ibm rational_collaborative_lifecycle_management 4.0.5
ibm rational_collaborative_lifecycle_management 4.0.7
ibm rational_collaborative_lifecycle_management 5.0.0
ibm rational_collaborative_lifecycle_management 4.0.3
ibm rational_software_architect_design_manager 4.0.6
ibm rational_doors_next_generation 4.0.7
ibm rational_doors_next_generation 4.0.2
ibm rational_engineering_lifecycle_manager 4.0.0
ibm rational_software_architect_design_manager 5.0.0
ibm rational_rhapsody_design_manager 4.0.7
ibm rational_doors_next_generation 6.0.0
ibm rational_engineering_lifecycle_manager 6.0.0
ibm rational_team_concert 5.0.2
ibm rational_collaborative_lifecycle_management 4.0.1
ibm rational_team_concert 4.0.3
ibm rational_collaborative_lifecycle_management 4.0.2
ibm rational_engineering_lifecycle_manager 4.0.2
ibm rational_team_concert 4.0.0
ibm rational_quality_manager 4.0.1
ibm rational_team_concert 4.0.6
ibm rational_quality_manager 4.0.0
ibm rational_quality_manager 5.0.0
ibm rational_engineering_lifecycle_manager 4.0.5
ibm rational_software_architect_design_manager 5.0.2
ibm rational_engineering_lifecycle_manager 6.0.1
ibm rational_software_architect_design_manager 6.0.0
ibm rational_doors_next_generation 4.0.4
ibm rational_quality_manager 4.0.4
ibm rational_software_architect_design_manager 4.0.0
ibm rational_engineering_lifecycle_manager 4.0.6
ibm rational_rhapsody_design_manager 4.0.3
ibm rational_doors_next_generation 5.0.0
ibm rational_doors_next_generation 5.0.2
ibm rational_quality_manager 4.0.2
ibm rational_doors_next_generation 5.0.1
ibm rational_software_architect_design_manager 4.0.1
ibm rational_team_concert 3.0.1.6
ibm rational_collaborative_lifecycle_management 4.0.4
ibm rational_engineering_lifecycle_manager 4.0.3
ibm rational_engineering_lifecycle_manager 4.0.4
ibm rational_rhapsody_design_manager 5.0.0
ibm rational_software_architect_design_manager 4.0.2
ibm rational_engineering_lifecycle_manager 4.0.1
ibm rational_engineering_lifecycle_manager 5.0.0
ibm rational_team_concert 6.0.1
ibm rational_quality_manager 4.0.7
ibm rational_rhapsody_design_manager 4.0.6
ibm rational_rhapsody_design_manager 6.0.1
ibm rational_rhapsody_design_manager 6.0.2
ibm rational_software_architect_design_manager 4.0.4
ibm rational_team_concert 6.0.2
ibm rational_doors_next_generation 4.0.1
ibm rational_engineering_lifecycle_manager 5.0.1
ibm rational_team_concert 4.0.7
ibm rational_collaborative_lifecycle_management 6.0.2
ibm rational_software_architect_design_manager 4.0.3
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_quality_manager 5.0.2
ibm rational_rhapsody_design_manager 4.0.1
ibm rational_rhapsody_design_manager 4.0.2
ibm rational_rhapsody_design_manager 4.0
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_collaborative_lifecycle_management 4.0.0
ibm rational_collaborative_lifecycle_management 3.0.1.6
ibm rational_quality_manager 3.0.1.6
ibm rational_doors_next_generation 6.0.1
ibm rational_rhapsody_design_manager 5.0.1
ibm rational_doors_next_generation 4.0.5
ibm rational_doors_next_generation 4.0.6
ibm rational_doors_next_generation 4.0.3
ibm rational_quality_manager 5.0.1
ibm rational_team_concert 5.0.0
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_software_architect_design_manager 6.0.2
ibm rational_software_architect_design_manager 4.0.5
ibm rational_team_concert 4.0.4
ibm rational_software_architect_design_manager 5.0.1
ibm rational_quality_manager 4.0.5
ibm rational_quality_manager 6.0.2
ibm rational_doors_next_generation 6.0.2
ibm rational_quality_manager 6.0.0
ibm rational_collaborative_lifecycle_management 6.0.0
ibm rational_team_concert 5.0.1
ibm rational_rhapsody_design_manager 6.0.0
CVE-2016-2927 MEDIUM

IBM BigFix Remote Control before 9.1.3 does not properly restrict the set of available encryption algorithms, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by sniffing the network and performing calculations on encrypted data.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm bigfix_remote_control *
CVE-2016-2928 MEDIUM

IBM BigFix Remote Control before 9.1.3 allows remote authenticated users to obtain sensitive information by reading error logs.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-532,

Products Affected

Vendor Product Version
ibm bigfix_remote_control *
CVE-2016-2929 MEDIUM

IBM BigFix Remote Control before 9.1.3 does not properly restrict password choices, which makes it easier for remote attackers to obtain access via a brute-force approach.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-254,CWE-284,

Products Affected

Vendor Product Version
ibm bigfix_remote_control *
CVE-2016-2930 MEDIUM

IBM BigFix Remote Control 9.1.3 could allow a remote attacker to perform actions reserved for an administrator without authentication. IBM X-Force ID: 5512.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm bigfix_remote_control 9.1.3
CVE-2016-2931 MEDIUM

IBM BigFix Remote Control before 9.1.3 allows remote attackers to obtain sensitive cleartext information by sniffing the network.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm bigfix_remote_control *
CVE-2016-2932 MEDIUM

IBM BigFix Remote Control before 9.1.3 allows remote attackers to conduct XML injection attacks via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-91,

Products Affected

Vendor Product Version
ibm bigfix_remote_control *
CVE-2016-2933 MEDIUM

Directory traversal vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote authenticated administrators to read arbitrary files via a crafted request.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm bigfix_remote_control *
CVE-2016-2934 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm bigfix_remote_control *
CVE-2016-2935 MEDIUM

The broker application in IBM BigFix Remote Control before 9.1.3 allows remote attackers to cause a denial of service via an invalid HTTP request.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm bigfix_remote_control *
CVE-2016-2936 MEDIUM

IBM BigFix Remote Control before 9.1.3 uses cleartext storage for unspecified passwords, which allows local users to obtain sensitive information via unknown vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm bigfix_remote_control *
CVE-2016-2937 MEDIUM

IBM BigFix Remote Control before 9.1.3 allows remote attackers to obtain sensitive information or spoof e-mail transmission via a crafted POST request, related to an "untrusted information vulnerability."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,CWE-200,

Products Affected

Vendor Product Version
ibm bigfix_remote_control *
CVE-2016-2938 MEDIUM

IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm inotes 8.5.2.1
ibm domino 8.5.1.5
ibm domino 8.5.1.2
ibm domino 8.5.2.1
ibm domino 9.0.1.1
ibm domino 8.5.3.0
ibm domino 8.5.3.1
ibm domino 9.0.1.4
ibm domino 9.0.1.0
ibm domino 8.5.3.4
ibm inotes 8.5.3.4
ibm inotes 8.5.3.1
ibm inotes 8.5.1.4
ibm domino 8.5.2.3
ibm inotes 8.5.3.3
ibm inotes 8.5.3.5
ibm domino 8.5.3.6
ibm domino 8.5.1.4
ibm inotes 8.5.2.0
ibm inotes 8.5.3.6
ibm inotes 8.5.2.2
ibm domino 8.5.1.0
ibm inotes 8.5.1.0
ibm inotes 9.0.1.5
ibm domino 8.5.1.3
ibm inotes 8.5.1.3
ibm domino 8.5.1.1
ibm inotes 8.5.2.3
ibm domino 8.5.3.5
ibm domino 9.0.1.5
ibm inotes 9.0.1.0
ibm inotes 8.5.3.2
ibm domino 9.0.1.2
ibm domino 9.0.1.3
ibm inotes 9.0.1.3
ibm inotes 9.0.1.6
ibm domino 8.5.2.0
ibm inotes 8.5.3.0
ibm domino 9.0.0.0
ibm inotes 9.0.1.1
ibm domino 8.5.3.2
ibm inotes 9.0.0.0
ibm inotes 9.0.1.2
ibm domino 8.5.2.2
ibm domino 8.5.3.3
ibm inotes 9.0.1.4
ibm domino 8.5.2.4
ibm inotes 8.5.1.1
ibm inotes 8.5.1.5
ibm domino 9.0.1.6
ibm inotes 8.5.1.2
CVE-2016-2939 MEDIUM

IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm inotes 8.5.2.1
ibm domino 8.5.1.5
ibm domino 8.5.1.2
ibm domino 8.5.2.1
ibm domino 9.0.1.1
ibm domino 8.5.3.0
ibm domino 8.5.3.1
ibm domino 9.0.1.4
ibm domino 9.0.1.0
ibm domino 8.5.3.4
ibm inotes 8.5.3.4
ibm inotes 8.5.3.1
ibm inotes 8.5.1.4
ibm domino 8.5.2.3
ibm inotes 8.5.3.3
ibm inotes 8.5.3.5
ibm domino 8.5.3.6
ibm domino 8.5.1.4
ibm inotes 8.5.2.0
ibm inotes 8.5.3.6
ibm inotes 8.5.2.2
ibm domino 8.5.1.0
ibm inotes 8.5.1.0
ibm inotes 9.0.1.5
ibm domino 8.5.1.3
ibm inotes 8.5.1.3
ibm domino 8.5.1.1
ibm inotes 8.5.2.3
ibm domino 8.5.3.5
ibm domino 9.0.1.5
ibm inotes 9.0.1.0
ibm inotes 8.5.3.2
ibm domino 9.0.1.2
ibm domino 9.0.1.3
ibm inotes 9.0.1.3
ibm inotes 9.0.1.6
ibm domino 8.5.2.0
ibm inotes 8.5.3.0
ibm domino 9.0.0.0
ibm inotes 9.0.1.1
ibm domino 8.5.3.2
ibm inotes 9.0.0.0
ibm inotes 9.0.1.2
ibm domino 8.5.2.2
ibm domino 8.5.3.3
ibm inotes 9.0.1.4
ibm domino 8.5.2.4
ibm inotes 8.5.1.1
ibm inotes 8.5.1.5
ibm domino 9.0.1.6
ibm inotes 8.5.1.2
CVE-2016-2940 MEDIUM

Multiple unspecified vulnerabilities in IBM BigFix Remote Control before 9.1.3 allow remote attackers to obtain sensitive information via unknown vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm bigfix_remote_control *
CVE-2016-2941 LOW

IBM UrbanCode Deploy creates temporary files during step execution that could contain sensitive information including passwords that could be read by a local user.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm urbancode_deploy 6.1.0.3
ibm urbancode_deploy 6.2.2
ibm urbancode_deploy 6.0.1.3
ibm urbancode_deploy 6.1.1.8
ibm urbancode_deploy 6.0.1.4
ibm urbancode_deploy 6.0.1.7
ibm urbancode_deploy 6.1.1.1
ibm urbancode_deploy 6.1.1.2
ibm urbancode_deploy 6.1.3.3
ibm urbancode_deploy 6.1.1
ibm urbancode_deploy 6.1.1.5
ibm urbancode_deploy 6.2.1
ibm urbancode_deploy 6.0.1.13
ibm urbancode_deploy 6.1.0.1
ibm urbancode_deploy 6.2.0.0
ibm urbancode_deploy 6.0.1.14
ibm urbancode_deploy 6.0.1.5
ibm urbancode_deploy 6.1.1.6
ibm urbancode_deploy 6.1.0.4
ibm urbancode_deploy 6.1.3.1
ibm urbancode_deploy 6.2.0.1
ibm urbancode_deploy 6.1.3.2
ibm urbancode_deploy 6.2.1.1
ibm urbancode_deploy 6.1
ibm urbancode_deploy 6.1.2
ibm urbancode_deploy 6.0.1.6
ibm urbancode_deploy 6.0.1.11
ibm urbancode_deploy 6.2.0.2
ibm urbancode_deploy 6.1.0.2
ibm urbancode_deploy 6.0.1.8
ibm urbancode_deploy 6.1.3
ibm urbancode_deploy 6.0.1.9
ibm urbancode_deploy 6.1.1.3
ibm urbancode_deploy 6.0.1.10
ibm urbancode_deploy 6.0.1
ibm urbancode_deploy 6.0.1.12
ibm urbancode_deploy 6.0.1.2
ibm urbancode_deploy 6.1.1.7
ibm urbancode_deploy 6.1.1.4
ibm urbancode_deploy 6.2.2.1
ibm urbancode_deploy 6.0.1.1
ibm urbancode_deploy 6.0
CVE-2016-2942 MEDIUM

IBM UrbanCode Deploy could allow an authenticated attacker with special permissions to craft a script on the server in a way that will cause processes to run on a remote UCD agent machine.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm urbancode_deploy 6.1.0.3
ibm urbancode_deploy 6.2.2
ibm urbancode_deploy 6.0.1.3
ibm urbancode_deploy 6.1.1.8
ibm urbancode_deploy 6.0.1.4
ibm urbancode_deploy 6.0.1.7
ibm urbancode_deploy 6.1.1.1
ibm urbancode_deploy 6.1.1.2
ibm urbancode_deploy 6.1.3.3
ibm urbancode_deploy 6.1.1
ibm urbancode_deploy 6.1.1.5
ibm urbancode_deploy 6.2.1
ibm urbancode_deploy 6.0.1.13
ibm urbancode_deploy 6.1.0.1
ibm urbancode_deploy 6.2.0.0
ibm urbancode_deploy 6.0.1.14
ibm urbancode_deploy 6.0.1.5
ibm urbancode_deploy 6.1.1.6
ibm urbancode_deploy 6.1.0.4
ibm urbancode_deploy 6.1.3.1
ibm urbancode_deploy 6.2.0.1
ibm urbancode_deploy 6.1.3.2
ibm urbancode_deploy 6.2.1.1
ibm urbancode_deploy 6.1
ibm urbancode_deploy 6.1.2
ibm urbancode_deploy 6.0.1.6
ibm urbancode_deploy 6.0.1.11
ibm urbancode_deploy 6.2.0.2
ibm urbancode_deploy 6.1.0.2
ibm urbancode_deploy 6.0.1.8
ibm urbancode_deploy 6.1.3
ibm urbancode_deploy 6.0.1.9
ibm urbancode_deploy 6.1.1.3
ibm urbancode_deploy 6.0.1.10
ibm urbancode_deploy 6.0.1
ibm urbancode_deploy 6.0.1.12
ibm urbancode_deploy 6.0.1.2
ibm urbancode_deploy 6.1.1.7
ibm urbancode_deploy 6.1.1.4
ibm urbancode_deploy 6.2.2.1
ibm urbancode_deploy 6.0.1.1
ibm urbancode_deploy 6.0
CVE-2016-2943 LOW

IBM BigFix Remote Control before 9.1.3 allows local users to obtain sensitive information by leveraging unspecified privileges to read a log file.

CVSS 2.0

Severity: LOW

Problem Type: CWE-532,

Products Affected

Vendor Product Version
ibm bigfix_remote_control *
CVE-2016-2944 MEDIUM

IBM BigFix Remote Control before 9.1.3 does not properly restrict failed login attempts, which makes it easier for remote attackers to obtain access via a brute-force approach.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm bigfix_remote_control *
CVE-2016-2945 MEDIUM

The API Discovery implementation in IBM WebSphere Application Server (WAS) 8.5.5.8 through 8.5.5.9 Liberty before Liberty Fix Pack 16.0.0.2 allows remote authenticated users to gain privileges via an external reference in a Swagger document.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm websphere_application_server 8.5.5.8
ibm websphere_application_server 8.5.5.9
CVE-2016-2946 HIGH

Stack-based buffer overflow in the ax Shared Libraries in the Agent in IBM Tivoli Monitoring (ITM) 6.2.2 before FP9, 6.2.3 before FP5, and 6.3.0 before FP2 on Linux and UNIX allows local users to gain privileges via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm tivoli_monitoring 6.2.3
ibm tivoli_monitoring 6.2.2.4
ibm tivoli_monitoring 6.2.2.5
ibm tivoli_monitoring 6.2.2.8
ibm tivoli_monitoring 6.3.0
ibm tivoli_monitoring 6.2.2.9
ibm tivoli_monitoring 6.2.2.3
ibm tivoli_monitoring 6.2.2
ibm tivoli_monitoring 6.2.2.7
ibm tivoli_monitoring 6.2.2.1
ibm tivoli_monitoring 6.2.2.2
ibm tivoli_monitoring 6.2.2.6
CVE-2016-2947 MEDIUM

IBM Rational Collaborative Lifecycle Management 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Team Concert 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational DOORS Next Generation 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Engineering Lifecycle Manager 4.x before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Rhapsody Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; and Rational Software Architect Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5 allow remote authenticated users to obtain sensitive information via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_rhapsody_design_manager 4.0.4
ibm rational_rhapsody_design_manager 4.0.5
ibm rational_doors_next_generation 4.0.0
ibm rational_collaborative_lifecycle_management 4.0.6
ibm rational_engineering_lifecycle_manager 4.0.7
ibm rational_quality_manager 4.0.6
ibm rational_software_architect_design_manager 6.0.1
ibm rational_software_architect_design_manager 4.0.7
ibm rational_quality_manager 6.0.1
ibm rational_engineering_lifecycle_manager 5.0.2
ibm rational_rhapsody_design_manager 5.0.2
ibm rational_quality_manager 4.0.3
ibm rational_engineering_lifecycle_manager 6.0.2
ibm rational_team_concert 4.0.1
ibm rational_team_concert 6.0.0
ibm rational_team_concert 4.0.5
ibm rational_team_concert 4.0.2
ibm rational_collaborative_lifecycle_management 4.0.5
ibm rational_collaborative_lifecycle_management 4.0.7
ibm rational_collaborative_lifecycle_management 5.0.0
ibm rational_collaborative_lifecycle_management 4.0.3
ibm rational_software_architect_design_manager 4.0.6
ibm rational_doors_next_generation 4.0.7
ibm rational_doors_next_generation 4.0.2
ibm rational_engineering_lifecycle_manager 4.0.0
ibm rational_software_architect_design_manager 5.0.0
ibm rational_rhapsody_design_manager 4.0.7
ibm rational_doors_next_generation 6.0.0
ibm rational_engineering_lifecycle_manager 6.0.0
ibm rational_team_concert 5.0.2
ibm rational_collaborative_lifecycle_management 4.0.1
ibm rational_team_concert 4.0.3
ibm rational_collaborative_lifecycle_management 4.0.2
ibm rational_engineering_lifecycle_manager 4.0.2
ibm rational_team_concert 4.0.0
ibm rational_quality_manager 4.0.1
ibm rational_team_concert 4.0.6
ibm rational_quality_manager 4.0.0
ibm rational_quality_manager 5.0.0
ibm rational_engineering_lifecycle_manager 4.0.5
ibm rational_software_architect_design_manager 5.0.2
ibm rational_engineering_lifecycle_manager 6.0.1
ibm rational_software_architect_design_manager 6.0.0
ibm rational_doors_next_generation 4.0.4
ibm rational_quality_manager 4.0.4
ibm rational_software_architect_design_manager 4.0.0
ibm rational_engineering_lifecycle_manager 4.0.6
ibm rational_rhapsody_design_manager 4.0.3
ibm rational_doors_next_generation 5.0.0
ibm rational_doors_next_generation 5.0.2
ibm rational_quality_manager 4.0.2
ibm rational_doors_next_generation 5.0.1
ibm rational_software_architect_design_manager 4.0.1
ibm rational_team_concert 3.0.1.6
ibm rational_collaborative_lifecycle_management 4.0.4
ibm rational_engineering_lifecycle_manager 4.0.3
ibm rational_engineering_lifecycle_manager 4.0.4
ibm rational_rhapsody_design_manager 5.0.0
ibm rational_software_architect_design_manager 4.0.2
ibm rational_engineering_lifecycle_manager 4.0.1
ibm rational_engineering_lifecycle_manager 5.0.0
ibm rational_team_concert 6.0.1
ibm rational_quality_manager 4.0.7
ibm rational_rhapsody_design_manager 4.0.6
ibm rational_rhapsody_design_manager 6.0.1
ibm rational_rhapsody_design_manager 6.0.2
ibm rational_software_architect_design_manager 4.0.4
ibm rational_team_concert 6.0.2
ibm rational_doors_next_generation 4.0.1
ibm rational_engineering_lifecycle_manager 5.0.1
ibm rational_team_concert 4.0.7
ibm rational_collaborative_lifecycle_management 6.0.2
ibm rational_software_architect_design_manager 4.0.3
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_quality_manager 5.0.2
ibm rational_rhapsody_design_manager 4.0.1
ibm rational_rhapsody_design_manager 4.0.2
ibm rational_rhapsody_design_manager 4.0
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_collaborative_lifecycle_management 4.0.0
ibm rational_collaborative_lifecycle_management 3.0.1.6
ibm rational_quality_manager 3.0.1.6
ibm rational_doors_next_generation 6.0.1
ibm rational_rhapsody_design_manager 5.0.1
ibm rational_doors_next_generation 4.0.5
ibm rational_doors_next_generation 4.0.6
ibm rational_doors_next_generation 4.0.3
ibm rational_quality_manager 5.0.1
ibm rational_team_concert 5.0.0
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_software_architect_design_manager 6.0.2
ibm rational_software_architect_design_manager 4.0.5
ibm rational_team_concert 4.0.4
ibm rational_software_architect_design_manager 5.0.1
ibm rational_quality_manager 4.0.5
ibm rational_quality_manager 6.0.2
ibm rational_doors_next_generation 6.0.2
ibm rational_quality_manager 6.0.0
ibm rational_collaborative_lifecycle_management 6.0.0
ibm rational_team_concert 5.0.1
ibm rational_rhapsody_design_manager 6.0.0
CVE-2016-2948 MEDIUM

IBM BigFix Remote Control before 9.1.3 allows local users to discover hardcoded credentials via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-798,

Products Affected

Vendor Product Version
ibm bigfix_remote_control 9.1.2
CVE-2016-2949 LOW

IBM BigFix Remote Control before 9.1.3 allows local users to obtain sensitive information by reading cached web pages from a different user's session.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm bigfix_remote_control *
CVE-2016-2950 MEDIUM

SQL injection vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm bigfix_remote_control *
CVE-2016-2951 MEDIUM

IBM BigFix Remote Control before 9.1.3 does not properly set the default encryption strength, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by sniffing the network and performing calculations on encrypted data.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm bigfix_remote_control *
CVE-2016-2952 MEDIUM

IBM BigFix Remote Control before 9.1.3 does not enable the HSTS protection mechanism, which makes it easier for remote attackers to obtain sensitive information by leveraging use of HTTP.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm bigfix_remote_control *
CVE-2016-2953 MEDIUM

IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 does not require SSL, which allows remote attackers to obtain sensitive cleartext information by sniffing the network.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm connections 5.0.0.0
ibm connections 4.5.0.0
ibm connections 4.0.0.0
CVE-2016-2954 LOW

Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 5.0 before CR4 and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-2956 and CVE-2016-3008.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm connections 5.0.0.0
ibm connections 5.5.0.0
CVE-2016-2955 LOW

Cross-site scripting (XSS) vulnerability in IBM Connections 5.0 before CR4 and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm connections 5.0.0.0
ibm connections 5.5.0.0
CVE-2016-2956 LOW

Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 5.0 before CR4 and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-2954 and CVE-2016-3008.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm connections 5.0.0.0
ibm connections 5.5.0.0
CVE-2016-2957 MEDIUM

IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to obtain sensitive information by reading a stack trace in a response.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm connections 5.0.0.0
ibm connections 4.5.0.0
ibm connections 4.0.0.0
CVE-2016-2958 MEDIUM

IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to obtain sensitive information by reading an "archaic" e-mail address in a response.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm connections 5.0.0.0
ibm connections 4.5.0.0
ibm connections 4.0.0.0
CVE-2016-2959 MEDIUM

IBM Sametime Meeting Server 8.5.2 and 9.0 could allow a meeting room manager to remove the primary managers privileges. IBM X-Force ID: 113804.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm sametime 8.5.2.0
ibm sametime 8.5.2.1
ibm sametime 9.0.0.1
ibm sametime 9.0.0.0
ibm sametime 9.0.1
CVE-2016-2960 MEDIUM

IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.0.x before 8.0.0.13, 8.5.0.x before 8.5.5.10, 8.5.0.x and 16.0.0.x Liberty before Liberty Fix Pack 16.0.0.3, and 9.0.0.x before 9.0.0.1 allows remote attackers to cause a denial of service via crafted SIP messages.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 7.0.0.36
ibm websphere_application_server 7.0
ibm websphere_application_server 7.0.0.38
ibm websphere_application_server 7.0.0.12
ibm websphere_application_server 8.0.0.6
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 8.5.5.2
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 7.0.0.16
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 7.0.0.25
ibm websphere_application_server 8.0.0.9
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 7.0.0.14
ibm websphere_application_server 7.0.0.22
ibm websphere_application_server 7.0.0.31
ibm websphere_application_server 7.0.0.10
ibm websphere_application_server 8.5.5.5
ibm websphere_application_server 8.0.0.8
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 8.0.0.7
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 8.0.0.12
ibm websphere_application_server 7.0.0.27
ibm websphere_application_server 7.0.0.18
ibm websphere_application_server 7.0.0.41
ibm websphere_application_server 7.0.0.39
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 8.0.0.2
ibm websphere_application_server 9.0.0.0
ibm websphere_application_server 8.0.0.5
ibm websphere_application_server 8.5.0.2
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 8.5.5.7
ibm websphere_application_server 7.0.0.33
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 7.0.0.0
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 8.5.5.8
ibm websphere_application_server 7.0.0.32
ibm websphere_application_server 8.0
ibm websphere_application_server 7.0.0.29
ibm websphere_application_server 7.0.0.24
ibm websphere_application_server 8.5.5.0
ibm websphere_application_server 7.0.0.37
ibm websphere_application_server 8.5.5.9
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 8.5.5.6
ibm websphere_application_server 8.0.0.11
ibm websphere_application_server 8.0.0.10
ibm websphere_application_server 7.0.0.28
ibm websphere_application_server 7.0.0.34
ibm websphere_application_server 8.5.5.4
ibm websphere_application_server 7.0.0.35
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 8.5.5.1
ibm websphere_application_server 7.0.0.4
CVE-2016-2961 MEDIUM

The integration server in IBM Integration Bus 9 before 9.0.0.6 and 10 before 10.0.0.5 and WebSphere Message Broker 8 before 8.0.0.8 allows remote attackers to obtain sensitive Tomcat version information by sending a malformed POST request and then reading the Java stack trace.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_message_broker 8.0
ibm integration_bus 10.0.0.4
ibm integration_bus 9.0.0.2
ibm integration_bus 10.0.0.3
ibm integration_bus 10.0.0.2
ibm websphere_message_broker 8.0.0.6
ibm integration_bus 9.0.0.5
ibm websphere_message_broker 8.0.0.4
ibm integration_bus 9.0.0.4
ibm websphere_message_broker 8.0.0.3
ibm integration_bus 9.0
ibm websphere_message_broker 8.0.0.2
ibm integration_bus 10.0
ibm websphere_message_broker 8.0.0.5
ibm integration_bus 9.0.0.1
ibm websphere_message_broker 8.0.0.1
ibm integration_bus 9.0.0.3
ibm integration_bus 10.0.0.1
ibm websphere_message_broker 8.0.0.7
CVE-2016-2963 MEDIUM

Cross-site request forgery (CSRF) vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm bigfix_remote_control *
CVE-2016-2964 MEDIUM

IBM Sametime 8.5.2 and 9.0 under certain conditions provides an error message to a user that is too detailed and may reveal details about the application. IBM X-Force ID: 113813.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm sametime 8.5.2.0
ibm sametime 8.5.2.1
ibm sametime 9.0.0.1
ibm sametime 9.0.0.0
ibm sametime 9.0.1
CVE-2016-2965 MEDIUM

IBM Sametime Meeting Server 8.5.2 and 9.0 is vulnerable to cross-site request forgery, caused by improper validation of user-supplied input. By persuading a user to visit a malicious link, a remote attacker could force the user to log out of Sametime. IBM X-Force ID: 113846.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm sametime 8.5.2.0
ibm sametime 8.5.2.1
ibm sametime 9.0.0.1
ibm sametime 9.0.0.0
ibm sametime 9.0.1
CVE-2016-2966 MEDIUM

IBM Sametime 8.5.1 and 9.0 could allow an authenticated user to enumerate meeting rooms by guessing the meeting room id. IBM X-Force ID: 113847.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm sametime 8.5.1.1
ibm sametime 8.5.2.0
ibm sametime 8.5.2.1
ibm sametime 9.0.0.1
ibm sametime 9.0.0.0
ibm sametime 8.5.1.0
ibm sametime 9.0.1
CVE-2016-2967 LOW

IBM Sametime 8.5.2 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Sametime away message altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 113848.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm sametime 8.5.2.0
ibm sametime 8.5.2.1
ibm sametime 9.0.0.1
ibm sametime 9.0.0.0
ibm sametime 9.0.1
CVE-2016-2968 MEDIUM

IBM Security QRadar Incident Forensics 7.2.x before 7.2.7 allows remote attackers to bypass authentication, and obtain sensitive information or modify data, via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm security_qradar_incident_forensics 7.2.0
ibm security_qradar_incident_forensics 7.2.2
ibm security_qradar_incident_forensics 7.2.1
ibm security_qradar_incident_forensics 7.2.5
ibm security_qradar_incident_forensics 7.2.3
ibm security_qradar_incident_forensics 7.2.4
ibm security_qradar_incident_forensics 7.2.6
CVE-2016-2969 MEDIUM

IBM Sametime Meeting Server 8.5.2 and 9.0 may send replies that contain emails of people that should not be in these messages. IBM X-Force ID: 113850.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm sametime 8.5.2.0
ibm sametime 8.5.2.1
ibm sametime 9.0.0.1
ibm sametime 9.0.0.0
ibm sametime 9.0.1
CVE-2016-2970 MEDIUM

IBM Sametime 8.5 and 9.0 meetings server may provide detailed information in an error message that may provide details about the application to possible attackers. IBM X-Force ID: 113851.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm sametime 8.5.2.0
ibm sametime 8.5.2.1
ibm sametime 9.0.0.1
ibm sametime 9.0.0.0
ibm sametime 9.0.1
CVE-2016-2971 MEDIUM

IBM Sametime Media Services 8.5.2 and 9.0 can disclose sensitive information in stack trace error logs that could aid an attacker in future attacks. IBM X-Force ID: 113898.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm sametime 8.5.2.0
ibm sametime 8.5.2.1
ibm sametime 9.0.0.1
ibm sametime 9.0.0.0
ibm sametime 9.0.1
CVE-2016-2972 LOW

IBM Sametime Meeting Server 8.5.2 and 9.0 could store credentials of the Sametime Meetings user in the local cache of their browser which could be accessed by a local user. IBM X-Force ID: 113855.

CVSS 2.0

Severity: LOW

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm sametime 8.5.2.0
ibm sametime 8.5.2.1
ibm sametime 9.0.0.1
ibm sametime 9.0.0.0
ibm sametime 9.0.1
CVE-2016-2973 LOW

IBM Sametime Media Services 8.5.2 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 113899.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm sametime 8.5.2.0
ibm sametime 8.5.2.1
ibm sametime 9.0.0.1
ibm sametime 9.0.0.0
ibm sametime 9.0.1
CVE-2016-2974 LOW

IBM Sametime Connect 8.5.2 and 9.0, after uninstalling the Sametime Rich Client, could disclose potentially sensitive information related to the Sametime environment as well as other users on the local machine of the user. IBM X-Force ID: 113934.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm sametime 8.5.2.0
ibm sametime 8.5.2.1
ibm sametime 9.0.0.1
ibm sametime 9.0.0.0
ibm sametime 9.0.1
CVE-2016-2975 LOW

IBM Sametime 8.5.2 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 113935.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm sametime 8.5.2.0
ibm sametime 8.5.2.1
ibm sametime 9.0.0.1
ibm sametime 9.0.0.0
ibm sametime 9.0.1
CVE-2016-2976 MEDIUM

IBM Sametime Meeting Server 8.5.2 and 9.0 could allow a meeting invitee to obtain previously cleared sensitive information by viewing the meeting report history. IBM X-Force ID: 113936.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm sametime 8.5.2.0
ibm sametime 8.5.2.1
ibm sametime 9.0.0.1
ibm sametime 9.0.0.0
ibm sametime 9.0.1
CVE-2016-2977 MEDIUM

IBM Sametime Meeting Server 8.5.2 and 9.0 could allow a malicious user to lower other users hands in the meeting. IBM X-Force ID: 113937.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm sametime 8.5.2.0
ibm sametime 8.5.2.1
ibm sametime 9.0.0.1
ibm sametime 9.0.0.0
ibm sametime 9.0.1
CVE-2016-2978 LOW

IBM Sametime 8.5.2 and 9.0 could store potentially sensitive information from the browser cache locally that could be available to a local user. IBM X-Force ID: 113938.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm sametime 8.5.2.0
ibm sametime 8.5.2.1
ibm sametime 9.0.0.1
ibm sametime 9.0.0.0
ibm sametime 9.0.1
CVE-2016-2979 LOW

IBM Sametime Meeting Server 8.5.2 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 113945.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm sametime 8.5.2.0
ibm sametime 8.5.2.1
ibm sametime 9.0.0.1
ibm sametime 9.0.0.0
ibm sametime 9.0.1
CVE-2016-2980 MEDIUM

The Sametime WebPlayer 8.5.2 and 9.0 is vulnerable to a script injection where a malicious site can inject their own script by exploiting a vulnerability in the way that the WebPlayer works. IBM X-Force ID: 113993.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-74,

Products Affected

Vendor Product Version
ibm sametime 8.5.2.0
ibm sametime 8.5.2.1
ibm sametime 9.0.0.1
ibm sametime 9.0.0.0
ibm sametime 9.0.1
CVE-2016-2981 LOW

An undisclosed vulnerability in the CLM applications in IBM Jazz Team Server may allow unauthorized access to user credentials. IBM Reference #: 1999965.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_collaborative_lifecycle_management 6.0.3
ibm rational_collaborative_lifecycle_management 6.0.2
ibm rational_collaborative_lifecycle_management 4.0.6
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_collaborative_lifecycle_management 6.0
ibm rational_collaborative_lifecycle_management 4.0
ibm rational_collaborative_lifecycle_management 4.0.1
ibm rational_collaborative_lifecycle_management 4.0.5
ibm rational_collaborative_lifecycle_management 4.0.7
ibm rational_collaborative_lifecycle_management 4.0.3
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_collaborative_lifecycle_management 4.0.2
ibm rational_collaborative_lifecycle_management 5.0
ibm rational_collaborative_lifecycle_management 4.0.4
CVE-2016-2983 MEDIUM

IBM Tealeaf Customer Experience 8.7, 8.8, and 9.0.2 could allow a remote attacker under unusual circumstances to read operational data or TLS session state for any active sessions, cause denial of service, or bypass security. IBM X-Force ID: 113999.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm tealeaf_customer_experience 8.8
ibm tealeaf_customer_experience 8.7
ibm tealeaf_customer_experience 9.0.2
CVE-2016-2984 MEDIUM

IBM Spectrum Scale 4.1.1.x before 4.1.1.8 and 4.2.x before 4.2.0.4 and General Parallel File System (GPFS) 3.5.x before 3.5.0.32 and 4.1.x before 4.1.1.8 allow local users to gain privileges via crafted command-line parameters to a /usr/lpp/mmfs/bin/ setuid program.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm spectrum_scale 4.2.0.2
ibm general_parallel_file_system 3.5.0.0
ibm spectrum_scale 4.2.0.0
ibm general_parallel_file_system 4.1.0.0
ibm general_parallel_file_system 4.1.0.1
ibm general_parallel_file_system 3.5.0.20
ibm general_parallel_file_system 3.5.0.14
ibm spectrum_scale 4.1.1.3
ibm general_parallel_file_system 3.5.0.10
ibm general_parallel_file_system 3.5.0.21
ibm general_parallel_file_system 3.5.0.4
ibm general_parallel_file_system 3.5.0.16
ibm spectrum_scale 4.1.1.8
ibm general_parallel_file_system 3.5.0.3
ibm spectrum_scale 4.1.1.4
ibm spectrum_scale 4.1.1.5
ibm general_parallel_file_system 4.1.0.7
ibm general_parallel_file_system 3.5.0.25
ibm general_parallel_file_system 3.5.0.6
ibm general_parallel_file_system 3.5.0.8
ibm spectrum_scale 4.1.1.2
ibm general_parallel_file_system 3.5.0.23
ibm general_parallel_file_system 3.5.0.26
ibm general_parallel_file_system 3.5.0.27
ibm general_parallel_file_system 3.5.0.18
ibm general_parallel_file_system 4.1.0.6
ibm general_parallel_file_system 3.5.0.11
ibm spectrum_scale 4.2.0.1
ibm spectrum_scale 4.1.1.6
ibm general_parallel_file_system 4.1.0.2
ibm general_parallel_file_system 4.1.0.8
ibm general_parallel_file_system 3.5.0.5
ibm general_parallel_file_system 3.5.0.19
ibm spectrum_scale 4.1.1.7
ibm general_parallel_file_system 3.5.0.30
ibm general_parallel_file_system 4.1.0.3
ibm general_parallel_file_system 3.5.0.22
ibm general_parallel_file_system 3.5.0.9
ibm general_parallel_file_system 3.5.0.24
ibm general_parallel_file_system 3.5.0.1
ibm spectrum_scale 4.1.1.1
ibm general_parallel_file_system 3.5.0.15
ibm general_parallel_file_system 4.1.0.4
ibm general_parallel_file_system 3.5.0.2
ibm general_parallel_file_system 3.5.0.17
ibm general_parallel_file_system 3.5.0.12
ibm general_parallel_file_system 3.5.0.31
ibm spectrum_scale 4.2.0.3
ibm general_parallel_file_system 3.5.0.13
ibm spectrum_scale 4.1.1.0
ibm general_parallel_file_system 3.5.0.29
ibm general_parallel_file_system 3.5.0.7
ibm general_parallel_file_system 3.5.0.28
ibm general_parallel_file_system 4.1.0.5
CVE-2016-2985 MEDIUM

IBM Spectrum Scale 4.1.1.x before 4.1.1.8 and 4.2.x before 4.2.0.4 and General Parallel File System (GPFS) 3.5.x before 3.5.0.32 and 4.1.x before 4.1.1.8 allow local users to gain privileges via crafted environment variables to a /usr/lpp/mmfs/bin/ setuid program.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm spectrum_scale 4.2.0.2
ibm general_parallel_file_system 3.5.0.0
ibm spectrum_scale 4.2.0.0
ibm general_parallel_file_system 4.1.0.0
ibm general_parallel_file_system 4.1.0.1
ibm general_parallel_file_system 3.5.0.20
ibm general_parallel_file_system 3.5.0.14
ibm spectrum_scale 4.1.1.3
ibm general_parallel_file_system 3.5.0.10
ibm general_parallel_file_system 3.5.0.21
ibm general_parallel_file_system 3.5.0.4
ibm general_parallel_file_system 3.5.0.16
ibm spectrum_scale 4.1.1.8
ibm general_parallel_file_system 3.5.0.3
ibm spectrum_scale 4.1.1.4
ibm spectrum_scale 4.1.1.5
ibm general_parallel_file_system 4.1.0.7
ibm general_parallel_file_system 3.5.0.25
ibm general_parallel_file_system 3.5.0.6
ibm general_parallel_file_system 3.5.0.8
ibm spectrum_scale 4.1.1.2
ibm general_parallel_file_system 3.5.0.23
ibm general_parallel_file_system 3.5.0.26
ibm general_parallel_file_system 3.5.0.27
ibm general_parallel_file_system 3.5.0.18
ibm general_parallel_file_system 4.1.0.6
ibm general_parallel_file_system 3.5.0.11
ibm spectrum_scale 4.2.0.1
ibm spectrum_scale 4.1.1.6
ibm general_parallel_file_system 4.1.0.2
ibm general_parallel_file_system 4.1.0.8
ibm general_parallel_file_system 3.5.0.5
ibm general_parallel_file_system 3.5.0.19
ibm spectrum_scale 4.1.1.7
ibm general_parallel_file_system 3.5.0.30
ibm general_parallel_file_system 4.1.0.3
ibm general_parallel_file_system 3.5.0.22
ibm general_parallel_file_system 3.5.0.9
ibm general_parallel_file_system 3.5.0.24
ibm general_parallel_file_system 3.5.0.1
ibm spectrum_scale 4.1.1.1
ibm general_parallel_file_system 3.5.0.15
ibm general_parallel_file_system 4.1.0.4
ibm general_parallel_file_system 3.5.0.2
ibm general_parallel_file_system 3.5.0.17
ibm general_parallel_file_system 3.5.0.12
ibm general_parallel_file_system 3.5.0.31
ibm spectrum_scale 4.2.0.3
ibm general_parallel_file_system 3.5.0.13
ibm spectrum_scale 4.1.1.0
ibm general_parallel_file_system 3.5.0.29
ibm general_parallel_file_system 3.5.0.7
ibm general_parallel_file_system 3.5.0.28
ibm general_parallel_file_system 4.1.0.5
CVE-2016-2986 LOW

Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 6.x before 6.0.1 iFix6, Rational Quality Manager 6.x before 6.0.1 iFix6, Rational Team Concert 6.x before 6.0.1 iFix6, Rational DOORS Next Generation 6.x before 6.0.1 iFix6, Rational Engineering Lifecycle Manager 6.x before 6.0.1 iFix6, and Rational Rhapsody Design Manager 6.x before 6.0.1 iFix6 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_engineering_lifecycle_manager 6.0.2
ibm rational_team_concert 6.0.0
ibm rational_doors_next_generation 6.0.0
ibm rational_engineering_lifecycle_manager 6.0.0
ibm rational_engineering_lifecycle_manager 6.0.1
ibm rational_team_concert 6.0.1
ibm rational_quality_manager 6.0.2
ibm rational_doors_next_generation 6.0.2
ibm rational_quality_manager 6.0.0
ibm rational_quality_manager 6.0.1
ibm rational_rhapsody_design_manager 6.0.1
ibm rational_rhapsody_design_manager 6.0.2
ibm rational_team_concert 6.0.2
ibm rational_doors_next_generation 6.0.1
ibm rational_rhapsody_design_manager 6.0.0
CVE-2016-2987 MEDIUM

An undisclosed vulnerability in CLM applications may result in some administrative deployment parameters being shown to an attacker.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_rhapsody_design_manager 4.0.4
ibm rational_team_concert 4.0.0.1
ibm rational_rhapsody_design_manager 4.0.5
ibm rational_doors_next_generation 4.0.0
ibm rational_engineering_lifecycle_manager 4.0.3
ibm rational_engineering_lifecycle_manager 4.0.4
ibm rational_rhapsody_design_manager 5.0.0
ibm rational_software_architect_design_manager 4.0.2
ibm rational_engineering_lifecycle_manager 4.0.7
ibm rational_quality_manager 4.0.6
ibm rational_engineering_lifecycle_manager 5.0.0
ibm rational_software_architect_design_manager 6.0.1
ibm rational_quality_manager 4.0.0.1
ibm rational_quality_manager 4.0.0.2
ibm rational_team_concert 5.0
ibm rational_team_concert 6.0.1
ibm rational_rhapsody_design_manager 6.0
ibm rational_software_architect_design_manager 4.0.7
ibm rational_quality_manager 4.0.7
ibm rational_rhapsody_design_manager 4.0.6
ibm rational_rhapsody_design_manager 6.0.1
ibm rational_rhapsody_design_manager 6.0.2
ibm rational_software_architect_design_manager 5.0
ibm rational_engineering_lifecycle_manager 5.0.2
ibm rational_software_architect_design_manager 4.0.4
ibm rational_rhapsody_design_manager 5.0.2
ibm rational_team_concert 6.0.2
ibm rational_quality_manager 4.0.3
ibm rational_doors_next_generation 4.0.1
ibm rational_engineering_lifecycle_manager 5.0.1
ibm rational_team_concert 4.0.7
ibm rational_engineering_lifecycle_manager 6.0.2
ibm rational_team_concert 4.0.1
ibm rational_team_concert 6.0
ibm rational_team_concert 4.0.5
ibm rational_software_architect_design_manager 4.0.3
ibm rational_doors_next_generation 5.0
ibm rational_team_concert 4.0.2
ibm rational_quality_manager 5.0.2
ibm rational_quality_manager 5.0
ibm rational_software_architect_design_manager 4.0.6
ibm rational_doors_next_generation 4.0.7
ibm rational_rhapsody_design_manager 4.0.1
ibm rational_rhapsody_design_manager 4.0.2
ibm rational_team_concert 4.0.0.2
ibm rational_doors_next_generation 4.0.2
ibm rational_rhapsody_design_manager 4.0
ibm rational_doors_next_generation 6.0.1
ibm rational_rhapsody_design_manager 5.0.1
ibm rational_software_architect_design_manager 5.0.0
ibm rational_rhapsody_design_manager 4.0.7
ibm rational_team_concert 4.0
ibm rational_engineering_lifecycle_manager 5.0
ibm rational_doors_next_generation 6.0.0
ibm rational_engineering_lifecycle_manager 6.0.0
ibm rational_doors_next_generation 4.0.5
ibm rational_team_concert 5.0.2
ibm rational_rhapsody_design_manager 5.0
ibm rational_team_concert 4.0.3
ibm rational_doors_next_generation 4.0.6
ibm rational_doors_next_generation 4.0.3
ibm rational_quality_manager 5.0.1
ibm rational_team_concert 4.0.0
ibm rational_quality_manager 4.0.1
ibm rational_team_concert 4.0.6
ibm rational_quality_manager 4.0.0
ibm rational_quality_manager 5.0.0
ibm rational_engineering_lifecycle_manager 4.0.5
ibm rational_software_architect_design_manager 5.0.2
ibm rational_engineering_lifecycle_manager 6.0.1
ibm rational_software_architect_design_manager 6.0.0
ibm rational_software_architect_design_manager 6.0.2
ibm rational_doors_next_generation 4.0.4
ibm rational_quality_manager 4.0.4
ibm rational_software_architect_design_manager 4.0.0
ibm rational_software_architect_design_manager 4.0.5
ibm rational_team_concert 4.0.4
ibm rational_software_architect_design_manager 5.0.1
ibm rational_engineering_lifecycle_manager 4.0.6
ibm rational_rhapsody_design_manager 4.0.3
ibm rational_software_architect_design_manager 4.0
ibm rational_doors_next_generation 5.0.0
ibm rational_quality_manager 4.0.5
ibm rational_doors_next_generation 5.0.2
ibm rational_quality_manager 6.0.2
ibm rational_doors_next_generation 6.0.2
ibm rational_quality_manager 4.0.2
ibm rational_doors_next_generation 4.0
ibm rational_doors_next_generation 5.0.1
ibm rational_software_architect_design_manager 4.0.1
ibm rational_team_concert 5.0.1
ibm rational_rhapsody_design_manager 6.0.0
CVE-2016-2988 MEDIUM

IBM Tivoli Storage Manger for Virtual Environments: Data Protection for VMware (aka Spectrum Protect for Virtual Environments) 6.4.x before 6.4.3.4 and 7.1.x before 7.1.6 allows remote authenticated users to bypass a TSM credential requirement and obtain administrative access by leveraging multiple simultaneous logins.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_for_virtual_environments 6.4
ibm tivoli_storage_manager_for_virtual_environments 7.1
CVE-2016-2989 MEDIUM

Open redirect vulnerability in the Connections Portlets component 5.x before 5.0.2 for IBM WebSphere Portal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm connections_portlets 5.0
CVE-2016-2991 LOW

Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Protector for Mail Security 2.8.0.0 through 2.8.1.0 before 2.8.1.0-22115 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm lotus_protector_for_mail_security 2.8
ibm lotus_protector_for_mail_security 2.8.1
CVE-2016-2992 LOW

IBM Infosphere BigInsights is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm biginsights 4.2
CVE-2016-2994 LOW

Cross-site scripting (XSS) vulnerability in IBM UrbanCode Deploy 6.2.x before 6.2.1.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm urbancode_deploy 6.2.1.1
ibm urbancode_deploy 6.2.0.0
ibm urbancode_deploy 6.2.0.1
ibm urbancode_deploy 6.2.0.2
ibm urbancode_deploy 6.2.1
ibm urbancode_deploy 6.2.0.201
CVE-2016-2995 LOW

Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-2997, CVE-2016-3005, and CVE-2016-3010.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm connections 5.0.0.0
ibm connections 4.5.0.0
ibm connections 4.0.0.0
ibm connections 5.5.0.0
CVE-2016-2996 MEDIUM

IBM Security Privileged Identity Manager 2.0 before 2.0.2 FP8, when Virtual Appliance is used, allows remote authenticated users to append to arbitrary files via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm security_privileged_identity_manager 2.0.2
ibm security_privileged_identity_manager 2.0.1
ibm security_privileged_identity_manager 2.0.0
CVE-2016-2997 LOW

Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-2995, CVE-2016-3005, and CVE-2016-3010.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm connections 5.0.0.0
ibm connections 4.5.0.0
ibm connections 4.0.0.0
ibm connections 5.5.0.0
CVE-2016-2998 LOW

Cross-site request forgery (CSRF) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to hijack the authentication of arbitrary users for requests that update data.

CVSS 2.0

Severity: LOW

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm connections 5.0.0.0
ibm connections 4.5.0.0
ibm connections 4.0.0.0
ibm connections 5.5.0.0
CVE-2016-2999 MEDIUM

IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to obtain sensitive information via an unspecified brute-force attack.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm connections *
CVE-2016-3000 MEDIUM

The help service in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to cause a denial of service (service degradation) via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm connections 5.0.0.0
ibm connections 4.5.0.0
ibm connections 4.0.0.0
ibm connections 5.5.0.0
CVE-2016-3001 LOW

Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML via an embedded string, a different vulnerability than CVE-2016-3003 and CVE-2016-3006.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm connections 5.0.0.0
ibm connections 4.5.0.0
ibm connections 4.0.0.0
ibm connections 5.5.0.0
CVE-2016-3002 LOW

IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows physically proximate attackers to obtain sensitive information by reading cached data on a client device.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm connections 5.0.0.0
ibm connections 4.5.0.0
ibm connections 4.0.0.0
CVE-2016-3003 LOW

Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML via an embedded string, a different vulnerability than CVE-2016-3001 and CVE-2016-3006.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm connections 5.0.0.0
ibm connections 4.5.0.0
ibm connections 4.0.0.0
ibm connections 5.5.0.0
CVE-2016-3004 MEDIUM

Cross-site request forgery (CSRF) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to hijack the authentication of arbitrary users for requests that modify the set of available applications.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm connections 5.0.0.0
ibm connections 4.5.0.0
ibm connections 4.0.0.0
CVE-2016-3005 LOW

Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-2995, CVE-2016-2997, and CVE-2016-3010.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm connections 5.0.0.0
ibm connections 4.5.0.0
ibm connections 4.0.0.0
ibm connections 5.5.0.0
CVE-2016-3006 LOW

Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML via an embedded string, a different vulnerability than CVE-2016-3001 and CVE-2016-3003.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm connections 5.0.0.0
ibm connections 4.5.0.0
ibm connections 4.0.0.0
ibm connections 5.5.0.0
CVE-2016-3007 MEDIUM

Cross-site request forgery (CSRF) vulnerability in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to hijack the authentication of arbitrary users.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm connections 5.0.0.0
ibm connections 4.5.0.0
ibm connections 4.0.0.0
ibm connections 5.5.0.0
CVE-2016-3008 LOW

Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 5.0 before CR4 and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-2954 and CVE-2016-2956.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm connections 5.0.0.0
ibm connections 5.5.0.0
CVE-2016-3009 LOW

Cross-site request forgery (CSRF) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to hijack the authentication of arbitrary users for requests that modify the Connections generic page.

CVSS 2.0

Severity: LOW

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm connections 5.0.0.0
ibm connections 4.5.0.0
ibm connections 4.0.0.0
CVE-2016-3010 LOW

Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-2995, CVE-2016-2997, and CVE-2016-3005.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm connections 5.0.0.0
ibm connections 4.5.0.0
ibm connections 4.0.0.0
ibm connections 5.5.0.0
CVE-2016-3012 MEDIUM

IBM API Connect (aka APIConnect) before 5.0.3.0 with NPM before 2.2.8 includes certain internal server credentials in the software package, which might allow remote attackers to bypass intended access restrictions by leveraging knowledge of these credentials.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm network_path_manager *
ibm api_connect *
CVE-2016-3013 MEDIUM

IBM WebSphere MQ 8.0 could allow an authenticated user to crash the MQ channel due to improper data conversion handling. IBM Reference #: 1998661.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-19,

Products Affected

Vendor Product Version
ibm websphere_mq *
CVE-2016-3014 LOW

Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 4.0 before 4.0.7 iFix11 and 5.0 before 5.0.2 iFix17, Rational Quality Manager 4.0 before 4.0.7 iFix11 and 5.0 before 5.0.2 iFix17, Rational Team Concert 4.0 before 4.0.7 iFix11 and 5.0 before 5.0.2 iFix17, Rational DOORS Next Generation 4.0 before 4.0.7 iFix11 and 5.0 before 5.0.2 iFix17, Rational Engineering Lifecycle Manager 4.x before 4.0.7 iFix11 and 5.0 before 5.0.2 iFix17, Rational Rhapsody Design Manager 4.0 before 4.0.7 iFix11 and 5.0 before 5.0.2 iFix17, and Rational Software Architect Design Manager 4.0 before 4.0.7 iFix11 and 5.0 before 5.0.2 iFix17 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_rhapsody_design_manager 4.0.4
ibm rational_rhapsody_design_manager 4.0.5
ibm rational_doors_next_generation 4.0.0
ibm rational_engineering_lifecycle_manager 4.0.3
ibm rational_engineering_lifecycle_manager 4.0.4
ibm rational_rhapsody_design_manager 5.0.0
ibm rational_software_architect_design_manager 4.0.2
ibm rational_collaborative_lifecycle_management 4.0.6
ibm rational_engineering_lifecycle_manager 4.0.7
ibm rational_quality_manager 4.0.6
ibm rational_engineering_lifecycle_manager 4.0.1
ibm rational_engineering_lifecycle_manager 5.0.0
ibm rational_software_architect_design_manager 4.0.7
ibm rational_quality_manager 4.0.7
ibm rational_rhapsody_design_manager 4.0.6
ibm rational_engineering_lifecycle_manager 5.0.2
ibm rational_software_architect_design_manager 4.0.4
ibm rational_rhapsody_design_manager 5.0.2
ibm rational_quality_manager 4.0.3
ibm rational_doors_next_generation 4.0.1
ibm rational_engineering_lifecycle_manager 5.0.1
ibm rational_team_concert 4.0.7
ibm rational_team_concert 4.0.1
ibm rational_team_concert 4.0.5
ibm rational_software_architect_design_manager 4.0.3
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_team_concert 4.0.2
ibm rational_quality_manager 5.0.2
ibm rational_collaborative_lifecycle_management 4.0.5
ibm rational_collaborative_lifecycle_management 4.0.7
ibm rational_collaborative_lifecycle_management 5.0.0
ibm rational_collaborative_lifecycle_management 4.0.3
ibm rational_software_architect_design_manager 4.0.6
ibm rational_doors_next_generation 4.0.7
ibm rational_rhapsody_design_manager 4.0.1
ibm rational_rhapsody_design_manager 4.0.2
ibm rational_doors_next_generation 4.0.2
ibm rational_rhapsody_design_manager 4.0
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_collaborative_lifecycle_management 4.0.0
ibm rational_engineering_lifecycle_manager 4.0.0
ibm rational_rhapsody_design_manager 5.0.1
ibm rational_software_architect_design_manager 5.0.0
ibm rational_rhapsody_design_manager 4.0.7
ibm rational_doors_next_generation 4.0.5
ibm rational_team_concert 5.0.2
ibm rational_collaborative_lifecycle_management 4.0.1
ibm rational_team_concert 4.0.3
ibm rational_doors_next_generation 4.0.6
ibm rational_doors_next_generation 4.0.3
ibm rational_quality_manager 5.0.1
ibm rational_collaborative_lifecycle_management 4.0.2
ibm rational_engineering_lifecycle_manager 4.0.2
ibm rational_team_concert 4.0.0
ibm rational_quality_manager 4.0.1
ibm rational_team_concert 4.0.6
ibm rational_quality_manager 4.0.0
ibm rational_team_concert 5.0.0
ibm rational_quality_manager 5.0.0
ibm rational_engineering_lifecycle_manager 4.0.5
ibm rational_software_architect_design_manager 5.0.2
ibm rational_doors_next_generation 4.0.4
ibm rational_quality_manager 4.0.4
ibm rational_software_architect_design_manager 4.0.0
ibm rational_software_architect_design_manager 4.0.5
ibm rational_team_concert 4.0.4
ibm rational_software_architect_design_manager 5.0.1
ibm rational_engineering_lifecycle_manager 4.0.6
ibm rational_rhapsody_design_manager 4.0.3
ibm rational_doors_next_generation 5.0.0
ibm rational_quality_manager 4.0.5
ibm rational_doors_next_generation 5.0.2
ibm rational_quality_manager 4.0.2
ibm rational_doors_next_generation 5.0.1
ibm rational_software_architect_design_manager 4.0.1
ibm rational_collaborative_lifecycle_management 4.0.4
ibm rational_team_concert 5.0.1
CVE-2016-3015 LOW

IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1998887.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm cognos_analytics 11.0.1
ibm cognos_analytics 11.0.3
ibm cognos_analytics 11.0.2
ibm cognos_analytics 11.0.0
ibm cognos_analytics 11.0.4
CVE-2016-3016 LOW

IBM Security Access Manager for Web processes patches, image backups and other updates without sufficiently verifying the origin and integrity of the code, which could allow an authenticated attacker to load malicious code.

CVSS 2.0

Severity: LOW

Problem Type: CWE-345,

Products Affected

Vendor Product Version
ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.5
ibm security_access_manager_for_web_7.0_firmware 7.0.0.13
ibm security_access_manager_for_web_7.0_firmware 7.0.0.1
ibm security_access_manager_for_web_7.0_firmware 7.0.0.7
ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.1
ibm security_access_manager_for_web_7.0_firmware 7.0.0.2
ibm security_access_manager_for_web_8.0_firmware 8.0.1.4
ibm security_access_manager_for_web_8.0_firmware 8.0.1.0
ibm security_access_manager_9.0_firmware 9.0.1.0
ibm security_access_manager_for_web_7.0_firmware 7.0.0.4
ibm security_access_manager_9.0_firmware 9.0.0
ibm security_access_manager_for_web_7.0_firmware 7.0.0.11
ibm security_access_manager_for_web_7.0_firmware 7.0.0.8
ibm security_access_manager_for_mobile_8.0_firmware 8.0.1.2
ibm security_access_manager_for_mobile_8.0_firmware 8.0.1.4
ibm security_access_manager_for_web_7.0_firmware 7.0.0.14
ibm security_access_manager_for_web_7.0_firmware 7.0.0.10
ibm security_access_manager_for_web_8.0_firmware 8.0.1.3
ibm security_access_manager_for_web_7.0_firmware 7.0.0.15
ibm security_access_manager_9.0_firmware 9.0.0.1
ibm security_access_manager_for_web_7.0_firmware 7.0.0.5
ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.3
ibm security_access_manager_for_web_7.0_firmware 7.0.0.6
ibm security_access_manager_for_web_7.0_firmware 7.0.0.16
ibm security_access_manager_for_web_8.0_firmware 8.0.0.2
ibm security_access_manager_for_web_8.0_firmware 8.0.0.3
ibm security_access_manager_for_mobile_8.0_firmware 8.0.1.0
ibm security_access_manager_for_web_7.0_firmware 7.0.0.3
ibm security_access_manager_for_web_7.0_firmware 7.0.0.9
ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.2
ibm security_access_manager_for_web_8.0_firmware 8.0.1.2
ibm security_access_manager_for_mobile_8.0_firmware 8.0.1.3
ibm security_access_manager_for_web_8.0_firmware 8.0.0.5
ibm security_access_manager_for_web_8.0_firmware 8.0.0.1
ibm security_access_manager_for_web_7.0_firmware 7.0.0.12
CVE-2016-3017 MEDIUM

IBM Security Access Manager for Web could allow a remote attacker to obtain sensitive information due to security misconfigurations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-358,

Products Affected

Vendor Product Version
ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.5
ibm security_access_manager_for_web_7.0_firmware 7.0.0.13
ibm security_access_manager_for_web_7.0_firmware 7.0.0.1
ibm security_access_manager_for_web_7.0_firmware 7.0.0.7
ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.1
ibm security_access_manager_for_web_7.0_firmware 7.0.0.2
ibm security_access_manager_for_web_8.0_firmware 8.0.1.4
ibm security_access_manager_for_web_8.0_firmware 8.0.1.0
ibm security_access_manager_9.0_firmware 9.0.1.0
ibm security_access_manager_for_web_7.0_firmware 7.0.0.4
ibm security_access_manager_9.0_firmware 9.0.0
ibm security_access_manager_for_web_7.0_firmware 7.0.0.11
ibm security_access_manager_for_web_7.0_firmware 7.0.0.8
ibm security_access_manager_for_mobile_8.0_firmware 8.0.1.2
ibm security_access_manager_for_mobile_8.0_firmware 8.0.1.4
ibm security_access_manager_for_web_7.0_firmware 7.0.0.14
ibm security_access_manager_for_web_7.0_firmware 7.0.0.10
ibm security_access_manager_for_web_8.0_firmware 8.0.1.3
ibm security_access_manager_for_web_7.0_firmware 7.0.0.15
ibm security_access_manager_9.0_firmware 9.0.0.1
ibm security_access_manager_for_web_7.0_firmware 7.0.0.5
ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.3
ibm security_access_manager_for_web_7.0_firmware 7.0.0.6
ibm security_access_manager_for_web_7.0_firmware 7.0.0.16
ibm security_access_manager_for_web_8.0_firmware 8.0.0.2
ibm security_access_manager_for_web_8.0_firmware 8.0.0.3
ibm security_access_manager_for_mobile_8.0_firmware 8.0.1.0
ibm security_access_manager_for_web_7.0_firmware 7.0.0.3
ibm security_access_manager_for_web_7.0_firmware 7.0.0.9
ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.2
ibm security_access_manager_for_web_8.0_firmware 8.0.1.2
ibm security_access_manager_for_mobile_8.0_firmware 8.0.1.3
ibm security_access_manager_for_web_8.0_firmware 8.0.0.5
ibm security_access_manager_for_web_8.0_firmware 8.0.0.1
ibm security_access_manager_for_web_7.0_firmware 7.0.0.12
CVE-2016-3018 MEDIUM

IBM Security Access Manager for Web is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm security_access_manager_for_mobile 8.0.0.2
ibm security_access_manager_for_mobile 8.0.1.4
ibm security_access_manager_for_web 8.0.1.3
ibm security_access_manager_for_web 8.0.0.2
ibm security_access_manager 9.0.0.1
ibm security_access_manager 9.0.1.0
ibm security_access_manager_for_web 8.0.1.0
ibm security_access_manager_for_web 8.0.0.1
ibm security_access_manager_for_mobile 8.0.0.0
ibm security_access_manager_for_web 8.0.1.4
ibm security_access_manager_for_web 8.0.0.0
ibm security_access_manager_for_mobile 8.0.0.3
ibm security_access_manager_for_web 8.0.0.5
ibm security_access_manager_for_web 8.0.0.3
ibm security_access_manager_for_mobile 8.0.0.1
ibm security_access_manager_for_mobile 8.0.1.2
ibm security_access_manager_for_mobile 8.0.1.3
ibm security_access_manager 9.0.0
ibm security_access_manager_for_mobile 8.0.1.0
ibm security_access_manager_for_mobile 8.0.0.5
ibm security_access_manager_for_web 8.0.1.2
CVE-2016-3019 MEDIUM

IBM Security Access Manager for Web 9.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 114462.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-326,

Products Affected

Vendor Product Version
ibm security_access_manager_9.0_firmware *
CVE-2016-3020 MEDIUM

IBM Security Access Manager for Web 7.0.0, 8.0.0, and 9.0.0 could allow a remote attacker to bypass security restrictions, caused by improper content validation. By persuading a victim to open specially-crafted content, an attacker could exploit this vulnerability to bypass validation and load a page with malicious content.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm security_access_manager_for_web_7.0_firmware *
ibm security_access_manager_for_mobile *
ibm security_access_manager_for_web_8.0_firmware *
ibm security_access_manager_9.0_firmware *
CVE-2016-3021 MEDIUM

IBM Security Access Manager for Web could allow an authenticated attacker to obtain sensitive information from error message using a specially crafted HTTP request.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.5
ibm security_access_manager_for_web_7.0_firmware 7.0.0.13
ibm security_access_manager_for_web_7.0_firmware 7.0.0.1
ibm security_access_manager_for_web_7.0_firmware 7.0.0.7
ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.1
ibm security_access_manager_for_web_7.0_firmware 7.0.0.2
ibm security_access_manager_for_web_8.0_firmware 8.0.1.4
ibm security_access_manager_for_web_8.0_firmware 8.0.1.0
ibm security_access_manager_9.0_firmware 9.0.1.0
ibm security_access_manager_for_web_7.0_firmware 7.0.0.4
ibm security_access_manager_9.0_firmware 9.0.0
ibm security_access_manager_for_web_7.0_firmware 7.0.0.11
ibm security_access_manager_for_web_7.0_firmware 7.0.0.8
ibm security_access_manager_for_mobile_8.0_firmware 8.0.1.2
ibm security_access_manager_for_mobile_8.0_firmware 8.0.1.4
ibm security_access_manager_for_web_7.0_firmware 7.0.0.14
ibm security_access_manager_for_web_7.0_firmware 7.0.0.10
ibm security_access_manager_for_web_8.0_firmware 8.0.1.3
ibm security_access_manager_for_web_7.0_firmware 7.0.0.15
ibm security_access_manager_9.0_firmware 9.0.0.1
ibm security_access_manager_for_web_7.0_firmware 7.0.0.5
ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.3
ibm security_access_manager_for_web_7.0_firmware 7.0.0.6
ibm security_access_manager_for_web_7.0_firmware 7.0.0.16
ibm security_access_manager_for_web_8.0_firmware 8.0.0.2
ibm security_access_manager_for_web_8.0_firmware 8.0.0.3
ibm security_access_manager_for_mobile_8.0_firmware 8.0.1.0
ibm security_access_manager_for_web_7.0_firmware 7.0.0.3
ibm security_access_manager_for_web_7.0_firmware 7.0.0.9
ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.2
ibm security_access_manager_for_web_8.0_firmware 8.0.1.2
ibm security_access_manager_for_mobile_8.0_firmware 8.0.1.3
ibm security_access_manager_for_web_8.0_firmware 8.0.0.5
ibm security_access_manager_for_web_8.0_firmware 8.0.0.1
ibm security_access_manager_for_web_7.0_firmware 7.0.0.12
CVE-2016-3022 MEDIUM

IBM Security Access Manager for Web could allow an authenticated user to gain access to highly sensitive information due to incorrect file permissions.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 6.5 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N 2.8 3.6

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-275,

Products Affected

Vendor Product Version
ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.5
ibm security_access_manager_for_web_7.0_firmware 7.0.0.13
ibm security_access_manager_for_web_7.0_firmware 7.0.0.1
ibm security_access_manager_for_web_7.0_firmware 7.0.0.7
ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.1
ibm security_access_manager_for_web_7.0_firmware 7.0.0.2
ibm security_access_manager_for_web_8.0_firmware 8.0.1.4
ibm security_access_manager_for_web_8.0_firmware 8.0.1.0
ibm security_access_manager_9.0_firmware 9.0.1.0
ibm security_access_manager_for_web_7.0_firmware 7.0.0.4
ibm security_access_manager_9.0_firmware 9.0.0
ibm security_access_manager_for_web_7.0_firmware 7.0.0.11
ibm security_access_manager_for_web_7.0_firmware 7.0.0.8
ibm security_access_manager_for_mobile_8.0_firmware 8.0.1.2
ibm security_access_manager_for_mobile_8.0_firmware 8.0.1.4
ibm security_access_manager_for_web_7.0_firmware 7.0.0.14
ibm security_access_manager_for_web_7.0_firmware 7.0.0.10
ibm security_access_manager_for_web_8.0_firmware 8.0.1.3
ibm security_access_manager_for_web_7.0_firmware 7.0.0.15
ibm security_access_manager_9.0_firmware 9.0.0.1
ibm security_access_manager_for_web_7.0_firmware 7.0.0.5
ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.3
ibm security_access_manager_for_web_7.0_firmware 7.0.0.6
ibm security_access_manager_for_web_7.0_firmware 7.0.0.16
ibm security_access_manager_for_web_8.0_firmware 8.0.0.2
ibm security_access_manager_for_web_8.0_firmware 8.0.0.3
ibm security_access_manager_for_mobile_8.0_firmware 8.0.1.0
ibm security_access_manager_for_web_7.0_firmware 7.0.0.3
ibm security_access_manager_for_web_7.0_firmware 7.0.0.9
ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.2
ibm security_access_manager_for_web_8.0_firmware 8.0.1.2
ibm security_access_manager_for_mobile_8.0_firmware 8.0.1.3
ibm security_access_manager_for_web_8.0_firmware 8.0.0.5
ibm security_access_manager_for_web_8.0_firmware 8.0.0.1
ibm security_access_manager_for_web_7.0_firmware 7.0.0.12
CVE-2016-3023 MEDIUM

IBM Security Access Manager for Web could allow an unauthenticated user to gain access to sensitive information by entering invalid file names.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.5
ibm security_access_manager_for_web_7.0_firmware 7.0.0.13
ibm security_access_manager_for_web_7.0_firmware 7.0.0.1
ibm security_access_manager_for_web_7.0_firmware 7.0.0.7
ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.1
ibm security_access_manager_for_web_7.0_firmware 7.0.0.2
ibm security_access_manager_for_web_8.0_firmware 8.0.1.4
ibm security_access_manager_for_web_8.0_firmware 8.0.1.0
ibm security_access_manager_9.0_firmware 9.0.1.0
ibm security_access_manager_for_web_7.0_firmware 7.0.0.4
ibm security_access_manager_9.0_firmware 9.0.0
ibm security_access_manager_for_web_7.0_firmware 7.0.0.11
ibm security_access_manager_for_web_7.0_firmware 7.0.0.8
ibm security_access_manager_for_mobile_8.0_firmware 8.0.1.2
ibm security_access_manager_for_mobile_8.0_firmware 8.0.1.4
ibm security_access_manager_for_web_7.0_firmware 7.0.0.14
ibm security_access_manager_for_web_7.0_firmware 7.0.0.10
ibm security_access_manager_for_web_8.0_firmware 8.0.1.3
ibm security_access_manager_for_web_7.0_firmware 7.0.0.15
ibm security_access_manager_9.0_firmware 9.0.0.1
ibm security_access_manager_for_web_7.0_firmware 7.0.0.5
ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.3
ibm security_access_manager_for_web_7.0_firmware 7.0.0.6
ibm security_access_manager_for_web_7.0_firmware 7.0.0.16
ibm security_access_manager_for_web_8.0_firmware 8.0.0.2
ibm security_access_manager_for_web_8.0_firmware 8.0.0.3
ibm security_access_manager_for_mobile_8.0_firmware 8.0.1.0
ibm security_access_manager_for_web_7.0_firmware 7.0.0.3
ibm security_access_manager_for_web_7.0_firmware 7.0.0.9
ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.2
ibm security_access_manager_for_web_8.0_firmware 8.0.1.2
ibm security_access_manager_for_mobile_8.0_firmware 8.0.1.3
ibm security_access_manager_for_web_8.0_firmware 8.0.0.5
ibm security_access_manager_for_web_8.0_firmware 8.0.0.1
ibm security_access_manager_for_web_7.0_firmware 7.0.0.12
CVE-2016-3024 LOW

IBM Security Access Manager for Web allows web pages to be stored locally which can be read by another user on the system.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_access_manager_9.0_firmware 9.0.0.1
ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.5
ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.3
ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.1
ibm security_access_manager_for_web_8.0_firmware 8.0.1.4
ibm security_access_manager_for_web_8.0_firmware 8.0.1.0
ibm security_access_manager_9.0_firmware 9.0.1.0
ibm security_access_manager_for_web_8.0_firmware 8.0.0.2
ibm security_access_manager_for_web_8.0_firmware 8.0.0.3
ibm security_access_manager_9.0_firmware 9.0.0
ibm security_access_manager_for_mobile_8.0_firmware 8.0.1.0
ibm security_access_manager_for_mobile_8.0_firmware 8.0.1.2
ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.2
ibm security_access_manager_for_web_8.0_firmware 8.0.1.2
ibm security_access_manager_for_mobile_8.0_firmware 8.0.1.3
ibm security_access_manager_for_mobile_8.0_firmware 8.0.1.4
ibm security_access_manager_for_web_8.0_firmware 8.0.0.5
ibm security_access_manager_for_web_8.0_firmware 8.0.0.1
ibm security_access_manager_for_web_8.0_firmware 8.0.1.3
CVE-2016-3025 MEDIUM

IBM Security Access Manager for Mobile 8.x before 8.0.1.4 IF3 and Security Access Manager 9.x before 9.0.1.0 IF5 do not properly restrict failed login attempts, which makes it easier for remote attackers to obtain access via a brute-force approach.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-254,

Products Affected

Vendor Product Version
ibm security_access_manager_for_mobile 8.0.1
ibm security_access_manager_for_mobile 8.0.0.2
ibm security_access_manager_for_mobile 8.0.1.4
ibm security_access_manager_for_mobile 8.0.0.4
ibm security_access_manager 9.0.0.1
ibm security_access_manager 9.0.1.0
ibm security_access_manager_for_mobile 8.0.0.0
ibm security_access_manager_for_mobile 8.0.0.3
ibm security_access_manager_for_mobile 8.0.0.1
ibm security_access_manager_for_mobile 8.0.1.2
ibm security_access_manager_for_mobile 8.0.1.3
ibm security_access_manager 9.0.0
ibm security_access_manager_for_mobile 8.0.0.5
CVE-2016-3027 MEDIUM

IBM Security Access Manager for Web is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm security_access_manager_9.0_firmware 9.0.0.1
ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.5
ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.3
ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.1
ibm security_access_manager_for_web_8.0_firmware 8.0.1.4
ibm security_access_manager_for_web_8.0_firmware 8.0.1.0
ibm security_access_manager_9.0_firmware 9.0.1.0
ibm security_access_manager_for_web_8.0_firmware 8.0.0.2
ibm security_access_manager_for_web_8.0_firmware 8.0.0.3
ibm security_access_manager_9.0_firmware 9.0.0
ibm security_access_manager_for_mobile_8.0_firmware 8.0.1.0
ibm security_access_manager_for_mobile_8.0_firmware 8.0.1.2
ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.2
ibm security_access_manager_for_web_8.0_firmware 8.0.1.2
ibm security_access_manager_for_mobile_8.0_firmware 8.0.1.3
ibm security_access_manager_for_mobile_8.0_firmware 8.0.1.4
ibm security_access_manager_for_web_8.0_firmware 8.0.0.5
ibm security_access_manager_for_web_8.0_firmware 8.0.0.1
ibm security_access_manager_for_web_8.0_firmware 8.0.1.3
CVE-2016-3028 HIGH

IBM Security Access Manager for Web 7.0 before IF2 and 8.0 before 8.0.1.4 IF3 and Security Access Manager 9.0 before 9.0.1.0 IF5 allow remote authenticated users to execute arbitrary commands by leveraging LMI admin access.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-78,

Products Affected

Vendor Product Version
ibm security_access_manager_for_web 8.0.1
ibm security_access_manager_for_web 8.0.1.3
ibm security_access_manager_for_web 8.0.0.2
ibm security_access_manager 9.0.0.1
ibm security_access_manager 9.0.1.0
ibm security_access_manager_for_web 8.0.1.4
ibm security_access_manager_for_web 8.0.0.4
ibm security_access_manager_for_web 7.0.0
ibm security_access_manager_for_web 8.0.0.5
ibm security_access_manager_for_web 8.0.0
ibm security_access_manager 9.0.0
ibm security_access_manager_for_web 8.0.1.2
CVE-2016-3029 MEDIUM

IBM Security Access Manager for Web is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm security_access_manager_9.0_firmware 9.0.0.1
ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.5
ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.3
ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.1
ibm security_access_manager_for_web_8.0_firmware 8.0.1.4
ibm security_access_manager_for_web_8.0_firmware 8.0.1.0
ibm security_access_manager_9.0_firmware 9.0.1.0
ibm security_access_manager_for_web_8.0_firmware 8.0.0.2
ibm security_access_manager_for_web_8.0_firmware 8.0.0.3
ibm security_access_manager_9.0_firmware 9.0.0
ibm security_access_manager_for_mobile_8.0_firmware 8.0.1.0
ibm security_access_manager_for_mobile_8.0_firmware 8.0.1.2
ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.2
ibm security_access_manager_for_web_8.0_firmware 8.0.1.2
ibm security_access_manager_for_mobile_8.0_firmware 8.0.1.3
ibm security_access_manager_for_mobile_8.0_firmware 8.0.1.4
ibm security_access_manager_for_web_8.0_firmware 8.0.0.5
ibm security_access_manager_for_web_8.0_firmware 8.0.0.1
ibm security_access_manager_for_web_8.0_firmware 8.0.1.3
CVE-2016-3031 LOW

IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1998887.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm cognos_analytics 11.0.1
ibm cognos_analytics 11.0.3
ibm cognos_analytics 11.0.2
ibm cognos_analytics 11.0.0
ibm cognos_analytics 11.0.4
CVE-2016-3032 LOW

IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 114516.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm cognos_analytics 11.0.5
ibm cognos_analytics 11.0.6
ibm cognos_analytics 11.0.1
ibm cognos_analytics 11.0.3
ibm cognos_analytics 11.0.2
ibm cognos_analytics 11.0.0
ibm cognos_analytics 11.0.4
CVE-2016-3033 MEDIUM

IBM AppScan Source 8.7 through 9.0.3.3 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm appscan_source 8.7
ibm appscan_source 9.0
ibm appscan_source 9.0.3.1
ibm appscan_source 9.0.2
ibm appscan_source 9.0.3.2
ibm appscan_source 8.7.0.1
ibm appscan_source 9.0.3
ibm appscan_source 8.8
ibm appscan_source 9.0.3.3
ibm appscan_source 9.0.0.1
ibm appscan_source 9.0.1
CVE-2016-3034 LOW

IBM AppScan Source uses a one-way hash without salt to encrypt highly sensitive information, which could allow a local attacker to decrypt information more easily.

CVSS 2.0

Severity: LOW

Problem Type: CWE-326,

Products Affected

Vendor Product Version
ibm security_appscan_source 9.0.3
ibm security_appscan_source 9.0.1
ibm security_appscan_source 9.0.2
CVE-2016-3035 MEDIUM

IBM AppScan Source could reveal some sensitive information through the browsing of testlinks on the server.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_appscan_source 9.0.3
ibm security_appscan_source 9.0.1
ibm security_appscan_source 9.0.2
CVE-2016-3036 MEDIUM

IBM Cognos TM1 10.1 and 10.2 is vulnerable to a denial of service, caused by a stack-based buffer overflow when parsing packets. A remote attacker could exploit this vulnerability to cause a denial of service. IBM X-Force ID: 114612.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm cognos_business_intelligence 10.2
ibm cognos_business_intelligence 10.1
ibm cognos_business_intelligence 10.2.2
CVE-2016-3037 LOW

IBM Cognos TM1 10.1 and 10.2 provides a service to return the victim's password with a valid session key. An authenticated attacker with user interaction could obtain this sensitive information. IBM X-Force ID: 114613.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm cognos_business_intelligence 10.2
ibm cognos_business_intelligence 10.1
ibm cognos_business_intelligence 10.2.2
CVE-2016-3038 LOW

IBM Cognos TM1 10.1 and 10.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 114614.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm cognos_business_intelligence 10.2
ibm cognos_business_intelligence 10.1
ibm cognos_business_intelligence 10.2.2
CVE-2016-3039 HIGH

IBM Traveler 8.x and 9.x before 9.0.1.12 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ibm traveler 8.5.3
ibm traveler 9.0
ibm traveler 9.0.1
CVE-2016-3040 MEDIUM

IBM WebSphere Application Server (WAS) Liberty, as used in IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8, allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-601,

Products Affected

Vendor Product Version
ibm security_privileged_identity_manager_virtual_appliance 2.0
CVE-2016-3042 LOW

Cross-site scripting (XSS) vulnerability in the Web UI in IBM WebSphere Application Server (WAS) Liberty before 16.0.0.3 allows remote authenticated users to inject arbitrary web script or HTML via vectors involving OpenID Connect clients.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_application_server *
CVE-2016-3043 MEDIUM

IBM Security Access Manager for Web could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_access_manager_for_web_7.0_firmware *
ibm security_access_manager_for_mobile *
ibm security_access_manager_for_web_8.0_firmware *
ibm security_access_manager_9.0_firmware *
CVE-2016-3044 MEDIUM

The Linux kernel component in IBM PowerKVM 2.1 before 2.1.1.3-65.10 and 3.1 before 3.1.0.2 allows guest OS users to cause a denial of service (host OS infinite loop and hang) via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,CWE-284,

Products Affected

Vendor Product Version
ibm powerkvm 2.1.1.3
ibm powerkvm 2.1.1.2
ibm powerkvm 3.1
ibm powerkvm 3.1.0.1
ibm powerkvm 2.1.0.2
ibm powerkvm 2.1.1.0
ibm powerkvm 2.1
CVE-2016-3045 MEDIUM

IBM Security Access Manager for Web stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referer header or browser history.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_access_manager_for_mobile 8.0.1
ibm security_access_manager_for_web 8.0.1.1
ibm security_access_manager_for_web 8.0.1
ibm security_access_manager_for_mobile 8.0.1.4
ibm security_access_manager_for_web 8.0.1.3
ibm security_access_manager 9.0.0.1
ibm security_access_manager 9.0.1.0
ibm security_access_manager_for_mobile 8.0.0.0
ibm security_access_manager_for_web 8.0.1.4
ibm security_access_manager_for_web 7.0.0
ibm security_access_manager_for_web 8.0.0
ibm security_access_manager_for_mobile 8.0.1.2
ibm security_access_manager_for_mobile 8.0.1.3
ibm security_access_manager 9.0.0
ibm security_access_manager_for_mobile 8.0.0.5
ibm security_access_manager_for_web 8.0.1.2
CVE-2016-3046 MEDIUM

IBM Security Access Manager for Web is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements which could allow the attacker to view information in the back-end database.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm security_access_manager_for_mobile *
ibm security_access_manager_for_web_8.0_firmware *
ibm security_access_manager_9.0_firmware *
CVE-2016-3047 MEDIUM

Open redirect vulnerability in IBM FileNet Workplace 4.0.2 through 4.0.2.14 IF001 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-601,

Products Affected

Vendor Product Version
ibm filenet_workplace 4.0.2
CVE-2016-3048 LOW

IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 114711.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm openpages_grc_platform 7.1.0.0
ibm openpages_grc_platform 7.2.0.0
ibm openpages_grc_platform 7.2.0.1
ibm openpages_grc_platform 7.1.0.2
ibm openpages_grc_platform 7.2.0.2
ibm openpages_grc_platform 7.1.0.1
ibm openpages_grc_platform 7.2.0.3
ibm openpages_grc_platform 7.3.0.0
ibm openpages_grc_platform 7.2.0.4
ibm openpages_grc_platform 7.1.0.3
CVE-2016-3049 LOW

IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 114712.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm openpages_grc_platform 7.1
ibm openpages_grc_platform 7.3
ibm openpages_grc_platform 7.2
CVE-2016-3051 MEDIUM

IBM Security Access Manager for Web 9.0.0 could allow an authenticated user to access some privileged functionality of the server. IBM X-Force ID: 114714.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm security_access_manager_9.0_firmware *
CVE-2016-3052 MEDIUM

Under non-standard configurations, IBM WebSphere MQ might send password data in clear text over the network. This data could be intercepted using man in the middle techniques.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_mq *
CVE-2016-3053 HIGH

IBM AIX contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm aix *
CVE-2016-3054 LOW

Cross-site scripting (XSS) vulnerability in IBM FileNet Workplace 4.0.2 allows remote authenticated users to inject arbitrary web script or HTML by uploading a file.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm filenet_workplace 4.0.2
CVE-2016-3055 MEDIUM

IBM FileNet Workplace 4.0.2 before 4.0.2.14 LA012 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm filenet_workplace 4.0.2
CVE-2016-3056 LOW

Cross-site scripting (XSS) vulnerability in Business Space in IBM Business Process Manager 7.5 through 7.5.1.2, 8.0 through 8.0.1.3, and 8.5 before 8.5.7.0 CF2016.09 allows remote authenticated users to inject arbitrary web script or HTML via crafted content.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm business_process_manager 8.0.1.2
ibm business_process_manager 8.5.6.0
ibm business_process_manager 8.0.1.1
ibm business_process_manager 7.5.0.1
ibm business_process_manager 8.5.0.2
ibm business_process_manager 7.5.1.0
ibm business_process_manager 7.5.1.1
ibm business_process_manager 8.5.6.2
ibm business_process_manager 8.5.5.0
ibm business_process_manager 8.0.1.0
ibm business_process_manager 7.5.1.2
ibm business_process_manager 8.0.0.0
ibm business_process_manager 8.5.7.0
ibm business_process_manager 8.5.0.1
ibm business_process_manager 8.0.1.3
ibm business_process_manager 8.5.0.0
ibm business_process_manager 7.5.0.0
CVE-2016-3057 MEDIUM

Cross-site scripting (XSS) vulnerability in IBM Sterling B2B Integrator 5.2 before 5020500_14 and 5.2 06 before 5020602_1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2
CVE-2016-3059 LOW

IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server (aka IBM Spectrum Protect for Databases) 6.3 before 6.3.1.7 and 6.4 before 6.4.1.9 and Tivoli Storage FlashCopy Manager for Microsoft SQL Server (aka IBM Spectrum Protect Snapshot) 3.1 before 3.1.1.7 and 3.2 before 3.2.1.9 allow local users to discover a cleartext SQL Server password by reading the Task List in the MMC GUI.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server *
ibm tivoli_storage_flashcopy_manager_for_sql_server *
CVE-2016-3060 LOW

Payments Director in IBM Financial Transaction Manager (FTM) for ACH Services, Check Services, and Corporate Payment Services (CPS) 3.0.0.x before fp0015 and 3.0.1.0 before iFix0002 allows remote authenticated users to conduct clickjacking attacks via a crafted web site.

CVSS 2.0

Severity: LOW

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm financial_transaction_manager 3.0.0.12
ibm financial_transaction_manager 3.0.0.4
ibm financial_transaction_manager 3.0.0.9
ibm financial_transaction_manager 3.0.0.7
ibm financial_transaction_manager 3.0.0.0
ibm financial_transaction_manager 3.0.0.11
ibm financial_transaction_manager 3.0.0.3
ibm financial_transaction_manager 3.0.0.10
ibm financial_transaction_manager 3.0.1.0
ibm financial_transaction_manager 3.0.0.2
ibm financial_transaction_manager 3.0.0.5
ibm financial_transaction_manager 3.0.0.8
ibm financial_transaction_manager 3.0.0.6
ibm financial_transaction_manager 3.0.0.1
ibm financial_transaction_manager 3.0.0.14
ibm financial_transaction_manager 3.0.0.13
CVE-2016-3452 MEDIUM

Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows remote attackers to affect confidentiality via vectors related to Server: Security: Encryption.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
mariadb mariadb *
redhat enterprise_linux 7.0
ibm powerkvm 3.1
redhat enterprise_linux 6.0
oracle mysql *
oracle linux 7
ibm powerkvm 2.1
CVE-2016-3477 MEDIUM

Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and earlier and MariaDB before 5.5.50, 10.0.x before 10.0.26, and 10.1.x before 10.1.15 allows local users to affect confidentiality, integrity, and availability via vectors related to Server: Parser.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
mariadb mariadb *
debian debian_linux 8.0
canonical ubuntu_linux 14.04
ibm powerkvm 3.1
canonical ubuntu_linux 16.04
oracle mysql *
canonical ubuntu_linux 12.04
canonical ubuntu_linux 15.10
oracle linux 7
ibm powerkvm 2.1
CVE-2016-3521 MEDIUM

Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and earlier and MariaDB before 5.5.50, 10.0.x before 10.0.26, and 10.1.x before 10.1.15 allows remote authenticated users to affect availability via vectors related to Server: Types.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
mariadb mariadb *
debian debian_linux 8.0
canonical ubuntu_linux 14.04
ibm powerkvm 3.1
canonical ubuntu_linux 16.04
oracle mysql *
canonical ubuntu_linux 12.04
canonical ubuntu_linux 15.10
oracle linux 7
ibm powerkvm 2.1
CVE-2016-3615 MEDIUM

Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and earlier and MariaDB before 5.5.50, 10.0.x before 10.0.26, and 10.1.x before 10.1.15 allows remote authenticated users to affect availability via vectors related to Server: DML.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
mariadb mariadb *
debian debian_linux 8.0
canonical ubuntu_linux 14.04
ibm powerkvm 3.1
canonical ubuntu_linux 16.04
oracle mysql *
canonical ubuntu_linux 12.04
canonical ubuntu_linux 15.10
oracle linux 7
ibm powerkvm 2.1
CVE-2016-3956 MEDIUM

The CLI in npm before 2.15.1 and 3.x before 3.8.3, as used in Node.js 0.10 before 0.10.44, 0.12 before 0.12.13, 4 before 4.4.2, and 5 before 5.10.0, includes bearer tokens with arbitrary requests, which allows remote HTTP servers to obtain sensitive information by reading Authorization headers.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 3.9 3.6

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
nodejs node.js 5.6.0
nodejs node.js 0.12.6
nodejs node.js 4.2.1
nodejs node.js 5.8.0
nodejs node.js 0.10.16-isaacs-manual
nodejs node.js 4.2.3
nodejs node.js 4.1.1
nodejs node.js 0.10.13
nodejs node.js 4.2.2
nodejs node.js 0.10.31
nodejs node.js 4.0.0
nodejs node.js 5.1.0
ibm sdk *
nodejs node.js 0.10.11
nodejs node.js 0.12.0
nodejs node.js 5.9.0
nodejs node.js 0.10.28
nodejs node.js 0.10.39
nodejs node.js 5.3.0
nodejs node.js 5.8.1
nodejs node.js 0.10.41
npmjs npm *
nodejs node.js 0.10.19
nodejs node.js 4.3.1
nodejs node.js 0.10.10
nodejs node.js 0.10.26
nodejs node.js 0.12.4
nodejs node.js 0.10.6
nodejs node.js 0.12.1
nodejs node.js 5.2.0
nodejs node.js 0.10.3
nodejs node.js 0.10.5
nodejs node.js 4.4.1
nodejs node.js 0.12.2
nodejs node.js 5.7.0
nodejs node.js 0.10.7
nodejs node.js 0.10.33
nodejs node.js 0.10.20
nodejs node.js 0.10.24
nodejs node.js 0.10.35
nodejs node.js 0.10.9
nodejs node.js 0.10.12
nodejs node.js 0.10.29
nodejs node.js 0.10.30
nodejs node.js 5.4.0
nodejs node.js 0.10.16
nodejs node.js 0.10.38
nodejs node.js 5.7.1
nodejs node.js 0.12.7
nodejs node.js 4.2.0
nodejs node.js 0.10.22
nodejs node.js 0.12.5
nodejs node.js 0.10.0
nodejs node.js 0.10.21
nodejs node.js 0.10.37
nodejs node.js 0.10.23
nodejs node.js 4.2.5
nodejs node.js 0.10.14
nodejs node.js 4.2.6
nodejs node.js 0.12.8
nodejs node.js 0.10.34
nodejs node.js 5.0.0
nodejs node.js 0.10.18
nodejs node.js 4.2.4
nodejs node.js 0.10.27
nodejs node.js 4.3.2
nodejs node.js 0.10.15
nodejs node.js 0.10.40
nodejs node.js 0.12.9
nodejs node.js 0.10.8
nodejs node.js 4.3.0
nodejs node.js 4.1.0
nodejs node.js 0.10.36
nodejs node.js 4.1.2
nodejs node.js 0.10.25
nodejs node.js 5.5.0
nodejs node.js 0.12.3
nodejs node.js 0.10.32
nodejs node.js 4.4.0
nodejs node.js 5.9.1
nodejs node.js 5.4.1
nodejs node.js 0.10.2
nodejs node.js 0.10.4
nodejs node.js 0.10.1
nodejs node.js 0.10.17
nodejs node.js 5.1.1
CVE-2016-5011 MEDIUM

The parse_dos_extended function in partitions/dos.c in the libblkid library in util-linux allows physically proximate attackers to cause a denial of service (memory consumption) via a crafted MSDOS partition table with an extended partition boot record at zero offset.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 4.6 MEDIUM CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 0.9 3.6

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
redhat enterprise_linux_desktop 7.0
redhat enterprise_linux_server_tus 7.6
kernel util-linux *
redhat enterprise_linux_eus 7.7
ibm powerkvm 3.1
redhat enterprise_linux_server 7.0
redhat enterprise_linux_eus 7.4
redhat enterprise_linux_workstation 7.0
redhat enterprise_linux_server_aus 7.3
redhat enterprise_linux_server_aus 7.7
ibm powerkvm 2.1
redhat enterprise_linux_server_tus 7.3
redhat enterprise_linux_server_tus 7.7
redhat enterprise_linux_eus 7.5
ibm power_hardware_management_console 8.8.6.0
redhat enterprise_linux_server_aus 7.4
redhat enterprise_linux_eus 7.3
redhat enterprise_linux_eus 7.6
redhat enterprise_linux_server_aus 7.6
CVE-2016-5440 MEDIUM

Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and earlier and MariaDB before 5.5.50, 10.0.x before 10.0.26, and 10.1.x before 10.1.15 allows remote administrators to affect availability via vectors related to Server: RBR.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
redhat enterprise_linux_desktop 7.0
redhat enterprise_linux_server_tus 7.6
redhat enterprise_linux_server_tus 7.2
mariadb mariadb *
debian debian_linux 8.0
ibm powerkvm 3.1
redhat enterprise_linux_server 7.0
redhat enterprise_linux_server_eus 7.3
redhat enterprise_linux_workstation 7.0
oracle mysql *
canonical ubuntu_linux 12.04
redhat enterprise_linux_server_eus 7.4
canonical ubuntu_linux 15.10
oracle linux 7
ibm powerkvm 2.1
redhat enterprise_linux_server_eus 7.6
redhat enterprise_linux_server_eus 7.2
redhat enterprise_linux_server_tus 7.3
canonical ubuntu_linux 14.04
redhat enterprise_linux_server_aus 7.2
canonical ubuntu_linux 16.04
redhat enterprise_linux_server_eus 7.5
redhat enterprise_linux_server_aus 7.6
CVE-2016-5444 MEDIUM

Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows remote attackers to affect confidentiality via vectors related to Server: Connection.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
redhat enterprise_linux_desktop 7.0
redhat enterprise_linux_server_tus 7.6
redhat enterprise_linux_server_tus 7.2
mariadb mariadb *
ibm powerkvm 3.1
redhat enterprise_linux_server 7.0
redhat enterprise_linux_server_eus 7.3
redhat enterprise_linux_workstation 7.0
redhat enterprise_linux_server_aus 7.3
oracle mysql *
redhat enterprise_linux_server_eus 7.4
oracle linux 7
ibm powerkvm 2.1
redhat enterprise_linux 7.0
redhat enterprise_linux_server_eus 7.6
redhat enterprise_linux_server_eus 7.2
redhat enterprise_linux_server_tus 7.3
redhat enterprise_linux_server_aus 7.2
redhat enterprise_linux_server_eus 7.5
redhat enterprise_linux 6.0
redhat enterprise_linux_server_aus 7.4
redhat enterprise_linux_server_aus 7.6
CVE-2016-5878 MEDIUM

Open redirect vulnerability in IBM FileNet Workplace 4.0.2 before 4.0.2.14 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-601,

Products Affected

Vendor Product Version
ibm filenet_workplace 4.0.2.7
ibm filenet_workplace 4.0.2.3
ibm filenet_workplace 4.0.2.10
ibm filenet_workplace 4.0.2.11
ibm filenet_workplace 4.0.2.6
ibm filenet_workplace 4.0.2.13
ibm filenet_workplace 4.0.2.9
ibm filenet_workplace 4.0.2.2
ibm filenet_workplace 4.0.2.4
ibm filenet_workplace 4.0.2.8
ibm filenet_workplace 4.0.2.0
ibm filenet_workplace 4.0.2.5
ibm filenet_workplace 4.0.2.12
ibm filenet_workplace 4.0.2.1
CVE-2016-5879 MEDIUM

MQCLI on IBM MQ Appliance M2000 and M2001 devices allows local users to execute arbitrary shell commands via a crafted (1) Disaster Recovery or (2) High Availability command.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm mq_appliance_firmware 8.0
CVE-2016-5880 LOW

IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm inotes 8.5.2.1
ibm domino 8.5.1.5
ibm domino 8.5.1.2
ibm domino 8.5.2.1
ibm domino 9.0.1.1
ibm domino 8.5.3.0
ibm domino 8.5.3.1
ibm domino 9.0.1.4
ibm domino 9.0.1.0
ibm domino 8.5.3.4
ibm inotes 8.5.3.4
ibm inotes 8.5.3.1
ibm inotes 8.5.1.4
ibm domino 8.5.2.3
ibm inotes 8.5.3.3
ibm inotes 8.5.3.5
ibm domino 8.5.3.6
ibm domino 8.5.1.4
ibm inotes 8.5.2.0
ibm inotes 8.5.3.6
ibm inotes 8.5.2.2
ibm domino 8.5.1.0
ibm inotes 8.5.1.0
ibm inotes 9.0.1.5
ibm domino 8.5.1.3
ibm inotes 8.5.1.3
ibm domino 8.5.1.1
ibm inotes 8.5.2.3
ibm domino 8.5.3.5
ibm domino 9.0.1.5
ibm inotes 9.0.1.0
ibm inotes 8.5.3.2
ibm domino 9.0.1.2
ibm domino 9.0.1.3
ibm inotes 9.0.1.3
ibm inotes 9.0.1.6
ibm domino 8.5.2.0
ibm inotes 8.5.3.0
ibm domino 9.0.0.0
ibm inotes 9.0.1.1
ibm domino 8.5.3.2
ibm inotes 9.0.0.0
ibm inotes 9.0.1.2
ibm domino 8.5.2.2
ibm domino 8.5.3.3
ibm inotes 9.0.1.4
ibm domino 8.5.2.4
ibm inotes 8.5.1.1
ibm inotes 8.5.1.5
ibm domino 9.0.1.6
ibm inotes 8.5.1.2
CVE-2016-5881 MEDIUM

IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm inotes 8.5.2.1
ibm inotes 8.5.2.3
ibm inotes 9.0.1.0
ibm inotes 8.5.3.2
ibm inotes 9.0.1.3
ibm inotes 9.0.1.6
ibm inotes 8.5.3.4
ibm inotes 8.5.3.1
ibm inotes 8.5.3.0
ibm inotes 8.5.1.4
ibm inotes 9.0.1.1
ibm inotes 8.5.3.3
ibm inotes 8.5.3.5
ibm inotes 9.0.0.0
ibm inotes 9.0.1.2
ibm inotes 9.0.1.4
ibm inotes 8.5.2.0
ibm inotes 8.5.3.6
ibm inotes 8.5.1.1
ibm inotes 8.5.1.5
ibm inotes 8.5.2.2
ibm inotes 8.5.1.0
ibm inotes 9.0.1.5
ibm inotes 8.5.1.2
ibm inotes 8.5.1.3
CVE-2016-5882 MEDIUM

IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm inotes 8.5.2.1
ibm domino 8.5.1.5
ibm domino 8.5.1.2
ibm domino 8.5.2.1
ibm domino 9.0.1.1
ibm domino 8.5.3.0
ibm domino 8.5.3.1
ibm domino 9.0.1.4
ibm domino 9.0.1.0
ibm domino 8.5.3.4
ibm inotes 8.5.3.4
ibm inotes 8.5.3.1
ibm inotes 8.5.1.4
ibm domino 8.5.2.3
ibm inotes 8.5.3.3
ibm inotes 8.5.3.5
ibm domino 8.5.3.6
ibm domino 8.5.1.4
ibm inotes 8.5.2.0
ibm inotes 8.5.3.6
ibm inotes 8.5.2.2
ibm domino 8.5.1.0
ibm inotes 8.5.1.0
ibm inotes 9.0.1.5
ibm domino 8.5.1.3
ibm inotes 8.5.1.3
ibm domino 8.5.1.1
ibm inotes 8.5.2.3
ibm domino 8.5.3.5
ibm domino 9.0.1.5
ibm inotes 9.0.1.0
ibm inotes 8.5.3.2
ibm domino 9.0.1.2
ibm domino 9.0.1.3
ibm inotes 9.0.1.3
ibm inotes 9.0.1.6
ibm domino 8.5.2.0
ibm inotes 8.5.3.0
ibm domino 9.0.0.0
ibm inotes 9.0.1.1
ibm domino 8.5.3.2
ibm inotes 9.0.0.0
ibm inotes 9.0.1.2
ibm domino 8.5.2.2
ibm domino 8.5.3.3
ibm inotes 9.0.1.4
ibm domino 8.5.2.4
ibm inotes 8.5.1.1
ibm inotes 8.5.1.5
ibm domino 9.0.1.6
ibm inotes 8.5.1.2
CVE-2016-5883 MEDIUM

IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1997010.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm inotes 8.5.2.1
ibm inotes 8.5.2.3
ibm inotes 9.0.1.0
ibm inotes 8.5.3.2
ibm inotes 9.0.1.3
ibm inotes 9.0.1.6
ibm inotes 8.5.3.4
ibm inotes 8.5.3.1
ibm inotes 8.5.3.0
ibm inotes 8.5.1.4
ibm inotes 9.0.1.1
ibm inotes 8.5.3.3
ibm inotes 8.5.3.5
ibm inotes 9.0.0.0
ibm inotes 9.0.1.2
ibm inotes 9.0.1.4
ibm inotes 8.5.2.0
ibm inotes 8.5.3.6
ibm inotes 8.5.1.1
ibm inotes 8.5.1.5
ibm inotes 8.5.2.2
ibm inotes 8.5.1.0
ibm inotes 9.0.1.5
ibm inotes 8.5.1.2
ibm inotes 8.5.1.3
CVE-2016-5884 MEDIUM

IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm inotes 8.5.2.1
ibm domino 8.5.1.5
ibm domino 8.5.1.2
ibm domino 8.5.2.1
ibm domino 9.0.1.1
ibm domino 8.5.3.0
ibm domino 8.5.3.1
ibm domino 9.0.1.4
ibm domino 9.0.1.0
ibm domino 8.5.3.4
ibm inotes 8.5.3.4
ibm inotes 8.5.3.1
ibm inotes 8.5.1.4
ibm domino 8.5.2.3
ibm inotes 8.5.3.3
ibm inotes 8.5.3.5
ibm domino 8.5.3.6
ibm domino 8.5.1.4
ibm inotes 8.5.2.0
ibm inotes 8.5.3.6
ibm inotes 8.5.2.2
ibm domino 8.5.1.0
ibm inotes 8.5.1.0
ibm inotes 9.0.1.5
ibm domino 8.5.1.3
ibm inotes 8.5.1.3
ibm domino 8.5.1.1
ibm inotes 8.5.2.3
ibm domino 8.5.3.5
ibm domino 9.0.1.5
ibm inotes 9.0.1.0
ibm inotes 8.5.3.2
ibm domino 9.0.1.2
ibm domino 9.0.1.3
ibm inotes 9.0.1.3
ibm inotes 9.0.1.6
ibm domino 8.5.2.0
ibm inotes 8.5.3.0
ibm domino 9.0.0.0
ibm inotes 9.0.1.1
ibm domino 8.5.3.2
ibm inotes 9.0.0.0
ibm inotes 9.0.1.2
ibm domino 8.5.2.2
ibm domino 8.5.3.3
ibm inotes 9.0.1.4
ibm domino 8.5.2.4
ibm inotes 8.5.1.1
ibm inotes 8.5.1.5
ibm domino 9.0.1.6
ibm inotes 8.5.1.2
CVE-2016-5888 LOW

IBM Interact 8.6, 9.0, 9.1, and 10.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 115084.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm interact 8.6
ibm interact 9.1.2
ibm interact 10.0
ibm interact 9.1
ibm interact 9.0
ibm interact 9.1.1
CVE-2016-5889 MEDIUM

IBM Interact 8.6, 9.0, 9.1, and 10.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 115085.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm interact 8.6
ibm interact 9.1.2
ibm interact 10.0
ibm interact 9.1
ibm interact 9.0
ibm interact 9.1.1
CVE-2016-5890 LOW

IBM Sterling B2B Integrator 5.2 before 5020500_14 and 5.2 06 before 5020602_1 allows remote authenticated users to change arbitrary passwords via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2
CVE-2016-5892 LOW

Cross-site scripting (XSS) vulnerability in IBM 10x, as used in Multi-Enterprise Integration Gateway 1.x through 1.0.0.1 and B2B Advanced Communications before 1.0.0.5_2, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm multi-enterprise_integration_gateway 1.0.0.1
ibm b2b_advanced_communications *
ibm multi-enterprise_integration_gateway 1.0.0
CVE-2016-5893 LOW

IBM Sterling B2B Integrator Standard Edition 5.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 115336.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2
CVE-2016-5894 LOW

IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 7.0 and 8.0 is vulnerable to information disclosure vulnerability. A local user could view a plain text password in a Unix console. IBM Reference #: 1997408.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_commerce 8.0.0.9
ibm websphere_commerce 7.0.0.6
ibm websphere_commerce 7.0.0.7
ibm websphere_commerce 7.0.0.3
ibm websphere_commerce 8.0.0.6
ibm websphere_commerce 7.0.0.2
ibm websphere_commerce 7.0
ibm websphere_commerce 8.0.0.4
ibm websphere_commerce 8.0.0.7
ibm websphere_commerce 8.0.1.1
ibm websphere_commerce 8.0.0.1
ibm websphere_commerce 7.0.0.5
ibm websphere_commerce 8.0.0.3
ibm websphere_commerce 8.0.1.12
ibm websphere_commerce 8.0.1.2
ibm websphere_commerce 8.0.0.15
ibm websphere_commerce 8.0.0.13
ibm websphere_commerce 8.0.0.10
ibm websphere_commerce 7.0.0.1
ibm websphere_commerce 8.0.1.8
ibm websphere_commerce 8.0.1.0
ibm websphere_commerce 7.0.0.8
ibm websphere_commerce 8.0.0.2
ibm websphere_commerce 8.0.0.8
ibm websphere_commerce 7.0.0.4
ibm websphere_commerce 7.0.0.9
ibm websphere_commerce 8.0.1.11
ibm websphere_commerce 8.0.0.16
ibm websphere_commerce 8.0.1.4
ibm websphere_commerce 8.0.0.11
ibm websphere_commerce 8.0.0.0
ibm websphere_commerce 8.0.0.19
ibm websphere_commerce 8.0.1.5
ibm websphere_commerce 8.0.1.6
ibm websphere_commerce 8.0.1.9
ibm websphere_commerce 8.0.0.14
ibm websphere_commerce 8.0.0.5
ibm websphere_commerce 8.0.1.3
ibm websphere_commerce 8.0.0.12
ibm websphere_commerce 8.0.1.7
ibm websphere_commerce 8.0.0.18
ibm websphere_commerce 8.0.0.17
CVE-2016-5896 MEDIUM

IBM Maximo Asset Management could disclose sensitive information from a stack trace after submitting incorrect login onto Cognos browser.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm maximo_asset_management 7.6
ibm maximo_for_life_sciences 7.6
ibm maximo_for_nuclear_power 7.6
ibm maximo_for_oil_and_gas 7.6
ibm maximo_for_transportation 7.6
ibm maximo_for_aviation 7.6
CVE-2016-5897 LOW

IBM Jazz Reporting Service (JRS) is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm jazz_reporting_service 6.0
ibm jazz_reporting_service 6.0.2
ibm jazz_reporting_service 6.0.1
CVE-2016-5898 MEDIUM

IBM Jazz Reporting Service (JRS) could allow a remote attacker to obtain sensitive information, caused by not restricting JSON serialization. By sending a direct request, an attacker could exploit this vulnerability to obtain sensitive information.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-254,

Products Affected

Vendor Product Version
ibm jazz_reporting_service 5.0.2
ibm jazz_reporting_service 6.0
ibm jazz_reporting_service 6.0.2
ibm jazz_reporting_service 6.0.1
ibm jazz_reporting_service 5.0
ibm jazz_reporting_service 5.0.1
CVE-2016-5899 LOW

IBM Jazz Reporting Service (JRS) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm jazz_reporting_service 5.0.2
ibm jazz_reporting_service 6.0
ibm jazz_reporting_service 6.0.2
ibm jazz_reporting_service 6.0.1
ibm jazz_reporting_service 5.0
ibm jazz_reporting_service 5.0.1
CVE-2016-5900 MEDIUM

IBM Tealeaf Customer Experience on Cloud Network Capture Add-On could allow a remote attacker to obtain sensitive information, caused by the failure to properly validate the TLS certificate. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm tealeaf_customer_experience_on_cloud_network_capture_add-on 16.1.01
CVE-2016-5901 LOW

Cross-site scripting (XSS) vulnerability in a test page in IBM Business Process Manager Advanced 8.5.6.0 through 8.5.7.0 before cumulative fix 2016.09 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm business_process_manager 8.5.6.0
ibm business_process_manager 8.5.6.2
ibm business_process_manager 8.5.7.0
ibm business_process_manager 8.5.6.1
CVE-2016-5902 MEDIUM

IBM Maximo Asset Management is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm maximo_asset_management 7.1
ibm maximo_for_government 7.1
ibm maximo_for_oil_and_gas 7.6
ibm maximo_for_energy_optimization 7.5
ibm maximo_for_utilities 7.6
ibm maximo_for_utilities 7.5
ibm maximo_for_utilities 7.1
ibm maximo_asset_management 7.6
ibm maximo_for_government 7.5
ibm maximo_for_aviation 7.5
ibm maximo_for_nuclear_power 7.1
ibm maximo_for_transportation 7.5
ibm maximo_for_life_sciences 7.5
ibm maximo_for_life_sciences 7.6
ibm maximo_for_life_sciences 7.1
ibm maximo_for_nuclear_power 7.6
ibm maximo_asset_management 7.5
ibm maximo_for_transportation 7.1
ibm maximo_for_nuclear_power 7.5
ibm maximo_for_aviation 7.1
ibm maximo_for_energy_optimization 7.6
ibm maximo_for_government 7.6
ibm maximo_for_oil_and_gas 7.1
ibm maximo_for_energy_optimization 7.1
ibm maximo_for_transportation 7.6
ibm maximo_for_aviation 7.6
ibm maximo_for_oil_and_gas 7.5
CVE-2016-5905 LOW

Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5 before 7.5.0.10 IF3 and 7.6 before 7.6.0.5 IF2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management 7.5.0.9
ibm maximo_asset_management 7.6.0.3
ibm maximo_asset_management 7.5.0.1
ibm maximo_asset_management 7.5.0.6
ibm maximo_asset_management 7.6.0.4
ibm maximo_asset_management 7.5.0.0
ibm maximo_asset_management 7.5.0.7
ibm maximo_asset_management 7.5.0.4
ibm maximo_asset_management 7.5.0.5
ibm maximo_asset_management 7.6.0.0
ibm maximo_asset_management 7.5.0.3
ibm maximo_asset_management 7.6.0.1
ibm maximo_asset_management 7.5.0.8
ibm maximo_asset_management 7.6.0.2
CVE-2016-5918 LOW

IBM Tivoli Storage Manager HSM for Windows displays the encrypted Tivoli Storage Manager password in application trace output if the password access option is prompt and the password is changed.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_for_space_management 6.4.0.0
ibm tivoli_storage_manager_for_space_management 7.1.0.0
ibm tivoli_storage_manager_for_space_management *
CVE-2016-5919 MEDIUM

IBM Security Access Manager for Web 7.0.0, 8.0.0, and 9.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM Reference #: 1996868.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-326,

Products Affected

Vendor Product Version
ibm security_access_manager_for_web_7.0_firmware *
ibm security_access_manager_for_mobile *
ibm security_access_manager_for_web_8.0_firmware *
ibm security_access_manager_9.0_firmware *
CVE-2016-5920 LOW

Cross-site scripting (XSS) vulnerability in the Web UI in IBM Financial Transaction Manager (FTM) for ACH Services 3.0.0.x before fp0015 and 3.0.1.0 before iFix0002 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm financial_transaction_manager 3.0.0.12
ibm financial_transaction_manager 3.0.0.4
ibm financial_transaction_manager 3.0.0.9
ibm financial_transaction_manager 3.0.0.7
ibm financial_transaction_manager 3.0.0.0
ibm financial_transaction_manager 3.0.0.11
ibm financial_transaction_manager 3.0.0.3
ibm financial_transaction_manager 3.0.0.10
ibm financial_transaction_manager 3.0.1.0
ibm financial_transaction_manager 3.0.0.2
ibm financial_transaction_manager 3.0.0.5
ibm financial_transaction_manager 3.0.0.8
ibm financial_transaction_manager 3.0.0.6
ibm financial_transaction_manager 3.0.0.1
ibm financial_transaction_manager 3.0.0.14
ibm financial_transaction_manager 3.0.0.13
CVE-2016-5927 LOW

IBM Tivoli Storage Manager for Space Management (aka Spectrum Protect for Space Management) 6.3.x before 6.3.2.6, 6.4.x before 6.4.3.3, and 7.1.x before 7.1.6, when certain dsmsetpw tracing is configured, allows local users to discover an encrypted password by reading application-trace output.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_for_space_management 6.4.0
ibm tivoli_storage_manager_for_space_management 6.4.3
ibm tivoli_storage_manager_for_space_management 6.3.0
ibm tivoli_storage_manager_for_space_management 6.3.2
ibm tivoli_storage_manager_for_space_management 6.4.1
ibm tivoli_storage_manager_for_space_management 7.1.4
ibm tivoli_storage_manager_for_space_management 7.1.3
ibm tivoli_storage_manager_for_space_management 6.4.0.0
ibm tivoli_storage_manager_for_space_management 7.1.2
ibm tivoli_storage_manager_for_space_management 7.1.1
ibm tivoli_storage_manager_for_space_management 7.1.0
ibm tivoli_storage_manager_for_space_management 6.4.2
CVE-2016-5932 LOW

IBM Connections 4.0, 4.5, 5.0, and 5.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1998294.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm connections 5.0
ibm connections 4.5
ibm connections 5.5.0.0
ibm connections 4.0
CVE-2016-5933 MEDIUM

IBM Tivoli Monitoring 6.2 and 6.3 is vulnerable to possible host header injection attack that could lead to HTTP cache poisoning or firewall bypass. IBM Reference #: 1997223.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-254,

Products Affected

Vendor Product Version
ibm tivoli_monitoring 6.3.0.6
ibm tivoli_monitoring 6.2.3
ibm tivoli_monitoring 6.2.2.4
ibm tivoli_monitoring 6.2.2.5
ibm tivoli_monitoring 6.2.2.8
ibm tivoli_monitoring 6.3.0.1
ibm tivoli_monitoring 6.2.3.1
ibm tivoli_monitoring 6.2.3.5
ibm tivoli_monitoring 6.3.0.5
ibm tivoli_monitoring 6.2.3.3
ibm tivoli_monitoring 6.3.0
ibm tivoli_monitoring 6.3.0.3
ibm tivoli_monitoring 6.3.0.7
ibm tivoli_monitoring 6.2.3.2
ibm tivoli_monitoring 6.2.2.9
ibm tivoli_monitoring 6.2.2.3
ibm tivoli_monitoring 6.2.3.4
ibm tivoli_monitoring 6.3.0.2
ibm tivoli_monitoring 6.2.2
ibm tivoli_monitoring 6.2.2.7
ibm tivoli_monitoring 6.2.2.2
ibm tivoli_monitoring 6.2.2.6
ibm tivoli_monitoring 6.3.0.4
CVE-2016-5934 MEDIUM

IBM Tivoli Storage Manager FastBack installer could allow a remote attacker to execute arbitrary code on the system. By placing a specially-crafted DLL in the victim's path, an attacker could exploit this vulnerability when the installer is executed to run arbitrary code on the system with privileges of the victim.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_fastback *
CVE-2016-5935 MEDIUM

IBM Jazz for Service Management could allow a remote attacker to obtain sensitive information, caused by the failure to properly validate the SSL certificate. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm dashboard_application_services_hub 3.1.3
CVE-2016-5937 MEDIUM

IBM Kenexa LCMS Premier on Cloud is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm kenexa_lcms_premier 9.5
ibm kenexa_lcms_premier 10.2
ibm kenexa_lcms_premier 9.0
ibm kenexa_lcms_premier 10.0
ibm kenexa_lcms_premier 10.1
ibm kenexa_lcms_premier 9.2
ibm kenexa_lcms_premier 9.2.1
ibm kenexa_lcms_premier 9.3
ibm kenexa_lcms_premier 9.4
CVE-2016-5938 LOW

IBM Kenexa LMS on Cloud allows web pages to be stored locally which can be read by another user on the system.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm kenexa_lms 4.2.3
ibm kenexa_lms 4.2
ibm kenexa_lms 5.0
ibm kenexa_lms 5.1
ibm kenexa_lms 4.2.2
ibm kenexa_lms 4.1
ibm kenexa_lms 5.2
ibm kenexa_lms 4.2.4
CVE-2016-5939 MEDIUM

IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm kenexa_lms_on_cloud 5.0
ibm kenexa_lms_on_cloud 4.2
ibm kenexa_lms_on_cloud 4.2.3
ibm kenexa_lms_on_cloud 5.1
ibm kenexa_lms_on_cloud 4.2.4
ibm kenexa_lms_on_cloud 4.1
ibm kenexa_lms_on_cloud 4.2.2
ibm kenexa_lms_on_cloud 5.2
CVE-2016-5940 LOW

IBM Kenexa LMS on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm kenexa_lms 4.2.3
ibm kenexa_lms 4.2
ibm kenexa_lms 5.0
ibm kenexa_lms 5.1
ibm kenexa_lms 4.2.2
ibm kenexa_lms 4.1
ibm kenexa_lms 5.2
ibm kenexa_lms 4.2.4
CVE-2016-5941 LOW

IBM Kenexa LMS on Cloud could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing dot dot sequences (/../) to view arbitrary files on the system.

CVSS 2.0

Severity: LOW

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm kenexa_lms 4.2.3
ibm kenexa_lms 4.2
ibm kenexa_lms 5.0
ibm kenexa_lms 5.1
ibm kenexa_lms 4.2.2
ibm kenexa_lms 4.1
ibm kenexa_lms 5.2
ibm kenexa_lms 4.2.4
CVE-2016-5942 LOW

IBM Kenexa LMS on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm kenexa_lms 4.2.3
ibm kenexa_lms 4.2
ibm kenexa_lms 5.0
ibm kenexa_lms 5.1
ibm kenexa_lms 4.2.2
ibm kenexa_lms 4.1
ibm kenexa_lms 5.2
ibm kenexa_lms 4.2.4
CVE-2016-5943 MEDIUM

IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to bypass intended access restrictions, and read task details or edit properties, via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm spectrum_control 5.2.5
ibm spectrum_control 5.2.1
ibm spectrum_control 5.2.6
ibm spectrum_control 5.2.10
ibm spectrum_control 5.2.8
ibm spectrum_control 5.2.1.1
ibm spectrum_control 5.2.3
ibm spectrum_control 5.2.4
ibm spectrum_control 5.2.4.1
ibm spectrum_control 5.2.7
ibm spectrum_control 5.2.9
ibm spectrum_control 5.2.0
ibm spectrum_control 5.2.10.1
ibm spectrum_control 5.2.5.1
ibm spectrum_control 5.2.7.1
ibm spectrum_control 5.2.2
CVE-2016-5944 LOW

Cross-site scripting (XSS) vulnerability in the Web UI in IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to inject arbitrary web script or HTML via an embedded string.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_storage_productivity_center 5.2.4
ibm spectrum_control 5.2.10
ibm spectrum_control 5.2.8
ibm tivoli_storage_productivity_center 5.2.5
ibm tivoli_storage_productivity_center 5.2.4.1
ibm tivoli_storage_productivity_center 5.2.7
ibm tivoli_storage_productivity_center 5.2.7.1
ibm tivoli_storage_productivity_center 5.2.2
ibm tivoli_storage_productivity_center 5.2.1
ibm tivoli_storage_productivity_center 5.2.1.1
ibm tivoli_storage_productivity_center 5.2.6
ibm spectrum_control 5.2.9
ibm spectrum_control 5.2.10.1
ibm tivoli_storage_productivity_center 5.2.0
ibm tivoli_storage_productivity_center 5.2.5.1
ibm tivoli_storage_productivity_center 5.2.3
CVE-2016-5945 MEDIUM

IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to upload non-executable files via a crafted HTTP request.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm tivoli_storage_productivity_center 5.2.4
ibm spectrum_control 5.2.10
ibm spectrum_control 5.2.8
ibm tivoli_storage_productivity_center 5.2.5
ibm tivoli_storage_productivity_center 5.2.4.1
ibm tivoli_storage_productivity_center 5.2.7
ibm tivoli_storage_productivity_center 5.2.7.1
ibm tivoli_storage_productivity_center 5.2.2
ibm tivoli_storage_productivity_center 5.2.1
ibm tivoli_storage_productivity_center 5.2.1.1
ibm tivoli_storage_productivity_center 5.2.6
ibm spectrum_control 5.2.9
ibm spectrum_control 5.2.10.1
ibm tivoli_storage_productivity_center 5.2.0
ibm tivoli_storage_productivity_center 5.2.5.1
ibm tivoli_storage_productivity_center 5.2.3
CVE-2016-5946 MEDIUM

Directory traversal vulnerability in IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm tivoli_storage_productivity_center 5.2.4
ibm spectrum_control 5.2.10
ibm spectrum_control 5.2.8
ibm tivoli_storage_productivity_center 5.2.5
ibm tivoli_storage_productivity_center 5.2.4.1
ibm tivoli_storage_productivity_center 5.2.7
ibm tivoli_storage_productivity_center 5.2.7.1
ibm tivoli_storage_productivity_center 5.2.2
ibm tivoli_storage_productivity_center 5.2.1
ibm tivoli_storage_productivity_center 5.2.1.1
ibm tivoli_storage_productivity_center 5.2.6
ibm spectrum_control 5.2.9
ibm spectrum_control 5.2.10.1
ibm tivoli_storage_productivity_center 5.2.0
ibm tivoli_storage_productivity_center 5.2.5.1
ibm tivoli_storage_productivity_center 5.2.3
CVE-2016-5947 LOW

IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to conduct clickjacking attacks via a crafted web site.

CVSS 2.0

Severity: LOW

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm tivoli_storage_productivity_center 5.2.4
ibm spectrum_control 5.2.10
ibm spectrum_control 5.2.8
ibm tivoli_storage_productivity_center 5.2.5
ibm tivoli_storage_productivity_center 5.2.4.1
ibm tivoli_storage_productivity_center 5.2.7
ibm tivoli_storage_productivity_center 5.2.7.1
ibm tivoli_storage_productivity_center 5.2.2
ibm tivoli_storage_productivity_center 5.2.1
ibm tivoli_storage_productivity_center 5.2.1.1
ibm tivoli_storage_productivity_center 5.2.6
ibm spectrum_control 5.2.9
ibm spectrum_control 5.2.10.1
ibm tivoli_storage_productivity_center 5.2.0
ibm tivoli_storage_productivity_center 5.2.5.1
ibm tivoli_storage_productivity_center 5.2.3
CVE-2016-5948 LOW

IBM Kenexa LCMS Premier on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm kenexa_lcms_premier 9.5
ibm kenexa_lcms_premier 10.2
ibm kenexa_lcms_premier 9.0
ibm kenexa_lcms_premier 10.0
ibm kenexa_lcms_premier 10.1
ibm kenexa_lcms_premier 9.2
ibm kenexa_lcms_premier 9.2.1
ibm kenexa_lcms_premier 9.3
ibm kenexa_lcms_premier 9.1
ibm kenexa_lcms_premier 9.4
CVE-2016-5949 MEDIUM

IBM Kenexa LCMS Premier on Cloud could allow an authenticated user to obtain sensitive user data with a specially crafted HTTP request.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-254,

Products Affected

Vendor Product Version
ibm kenexa_lcms_premier 9.5
ibm kenexa_lcms_premier 10.0
ibm kenexa_lcms_premier 10.1
ibm kenexa_lcms_premier 9.2
ibm kenexa_lcms_premier 9.3
ibm kenexa_lcms_premier 9.1
ibm kenexa_lcms_premier 9.4
CVE-2016-5950 MEDIUM

IBM Kenexa LCMS Premier on Cloud stores user credentials in plain in clear text which can be read by an authenticated user.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm kenexa_lcms_premier 9.5
ibm kenexa_lcms_premier 10.2
ibm kenexa_lcms_premier 9.0
ibm kenexa_lcms_premier 10.0
ibm kenexa_lcms_premier 10.1
ibm kenexa_lcms_premier 9.2
ibm kenexa_lcms_premier 9.2.1
ibm kenexa_lcms_premier 9.3
ibm kenexa_lcms_premier 9.1
ibm kenexa_lcms_premier 9.4
CVE-2016-5951 LOW

IBM Kenexa LCMS Premier on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm kenexa_lcms_premier 9.5
ibm kenexa_lcms_premier 10.2
ibm kenexa_lcms_premier 10.0
ibm kenexa_lcms_premier 10.1
ibm kenexa_lcms_premier 9.2
ibm kenexa_lcms_premier 9.3
ibm kenexa_lcms_premier 9.1
ibm kenexa_lcms_premier 9.4
CVE-2016-5952 MEDIUM

IBM Kenexa LCMS Premier on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm kenexa_lcms_premier 9.5
ibm kenexa_lcms_premier 9.0
ibm kenexa_lcms_premier 10.0
ibm kenexa_lcms_premier 9.2
ibm kenexa_lcms_premier 9.3
ibm kenexa_lcms_premier 9.1
ibm kenexa_lcms_premier 9.4
CVE-2016-5953 MEDIUM

IBM Sterling Order Management transmits the session identifier within the URL. When a user is unable to view a certain view due to not being allowed permissions, the website responds with an error page where the session identifier is encoded as Base64 in the URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm sterling_selling_and_fulfillment_foundation 9.1.0
ibm sterling_selling_and_fulfillment_foundation 9.2.1
ibm sterling_selling_and_fulfillment_foundation 9.5
ibm sterling_selling_and_fulfillment_foundation 9.4
ibm sterling_selling_and_fulfillment_foundation 9.2.0
ibm sterling_selling_and_fulfillment_foundation 9.3
CVE-2016-5954 MEDIUM

IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF30, 8.0.0 through 8.0.0.1 CF21, and 8.5.0 before CF12 allows remote authenticated users to cause a denial of service by uploading temporary files.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.0
ibm websphere_portal 6.1.0.3
ibm websphere_portal 7.0.0.1
ibm websphere_portal 6.1.5.2
ibm websphere_portal 6.1.0.2
ibm websphere_portal 6.1.0.4
ibm websphere_portal 8.0.0.1
ibm websphere_portal 7.0.0.2
ibm websphere_portal 8.5.0.0
ibm websphere_portal 6.1.5.0
ibm websphere_portal 6.1.0.6
ibm websphere_portal 6.1.5.3
ibm websphere_portal 7.0.0.0
ibm websphere_portal 6.1.0.1
ibm websphere_portal 6.1.5.1
ibm websphere_portal 6.1.0.5
ibm websphere_portal 6.1.0.0
CVE-2016-5955 LOW

Cross-site scripting (XSS) vulnerability in IBM Rational DOORS Next Generation 6.0.2 before iFix004 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_doors_next_generation 6.0.2
CVE-2016-5957 MEDIUM

IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 allows remote attackers to defeat cryptographic protection mechanisms and obtain sensitive information by leveraging a weak algorithm.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm security_privileged_identity_manager_virtual_appliance *
CVE-2016-5958 MEDIUM

IBM Security Privileged Identity Manager could allow a remote attacker to obtain sensitive information, caused by the failure to set the secure flag for the session cookie in SSL mode. By intercepting its transmission within an HTTP session, an attacker could exploit this vulnerability to capture the cookie and obtain sensitive information.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_privileged_identity_manager 2.0.2
ibm security_privileged_identity_manager 2.1
CVE-2016-5959 MEDIUM

IBM Security Privileged Identity Manager 2.0.2 and 2.1.0 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 116136.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_privileged_identity_manager 2.0.2
ibm security_privileged_identity_manager 2.1
CVE-2016-5960 LOW

IBM Security Privileged Identity Manager 2.0.2 and 2.1.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 116171.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_privileged_identity_manager 2.0.2
ibm security_privileged_identity_manager 2.1
CVE-2016-5963 MEDIUM

IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 does not properly validate updates, which allows remote authenticated users to execute arbitrary code via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm security_privileged_identity_manager_virtual_appliance 2.0
CVE-2016-5964 MEDIUM

IBM Security Privileged Identity Manager Virtual Appliance version 2.0.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm security_privileged_identity_manager 2.0.2
CVE-2016-5966 MEDIUM

IBM Security Privileged Identity Manager Virtual Appliance could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_privileged_identity_manager 2.0.2
ibm security_privileged_identity_manager 2.1
CVE-2016-5967 LOW

The installation component in IBM Rational Asset Analyzer (RAA) 6.1.0 before FP10 allows local users to discover the WAS Admin password by reading IM native logs.

CVSS 2.0

Severity: LOW

Problem Type: CWE-532,

Products Affected

Vendor Product Version
ibm rational_asset_analyzer 6.1.0.9
ibm rational_asset_analyzer 6.1.0
ibm rational_asset_analyzer 6.1.0.4
ibm rational_asset_analyzer 6.1.0.6
ibm rational_asset_analyzer 6.1.0.3
ibm rational_asset_analyzer 6.1.0.8
ibm rational_asset_analyzer 6.1.0.2
ibm rational_asset_analyzer 6.1.0.5
ibm rational_asset_analyzer 6.1.0.7
ibm rational_asset_analyzer 6.1.0.1
CVE-2016-5968 MEDIUM

The Replay Server in IBM Tealeaf Customer Experience 8.x before 8.7.1.8847 FP10, 8.8.x before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108 FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A before 9.0.2.5224 FP3 allows remote attackers to conduct SSRF attacks via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-918,

Products Affected

Vendor Product Version
ibm tealeaf_customer_experience *
ibm tealeaf_customer_experience 8.8
ibm tealeaf_customer_experience 9.0.0a
ibm tealeaf_customer_experience 9.0.1
ibm tealeaf_customer_experience 9.0.1a
ibm tealeaf_customer_experience 8.7
ibm tealeaf_customer_experience 9.0.0
ibm tealeaf_customer_experience 9.0.2a
ibm tealeaf_customer_experience 9.0.2
CVE-2016-5970 MEDIUM

Directory traversal vulnerability in IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,CWE-200,

Products Affected

Vendor Product Version
ibm security_privileged_identity_manager_virtual_appliance *
CVE-2016-5971 MEDIUM

IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,CWE-611,

Products Affected

Vendor Product Version
ibm security_privileged_identity_manager_virtual_appliance *
CVE-2016-5972 MEDIUM

IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 uses weak permissions for unspecified resources, which allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,CWE-284,

Products Affected

Vendor Product Version
ibm security_privileged_identity_manager_virtual_appliance *
CVE-2016-5974 LOW

Cross-site scripting (XSS) vulnerability in the Web UI in IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 allows remote authenticated users to inject arbitrary web script or HTML via an embedded string.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm security_privileged_identity_manager_virtual_appliance *
CVE-2016-5975 LOW

Cross-site scripting (XSS) vulnerability in the Web UI in the web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108_9.0.1A FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A before 9.0.2.5224_9.0.2A FP3 allows remote authenticated users to inject arbitrary web script or HTML via an embedded string, a different vulnerability than CVE-2016-5978.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tealeaf_customer_experience *
ibm tealeaf_customer_experience 8.8
ibm tealeaf_customer_experience 9.0.1
ibm tealeaf_customer_experience 9.0.1a
ibm tealeaf_customer_experience 9.0.0
ibm tealeaf_customer_experience 9.0.2a
ibm tealeaf_customer_experience 9.0.2
CVE-2016-5976 LOW

The web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108_9.0.1A FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A before 9.0.2.5224_9.0.2A FP3 allows remote authenticated users to discover component passwords via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm tealeaf_customer_experience *
ibm tealeaf_customer_experience 8.8
ibm tealeaf_customer_experience 9.0.1
ibm tealeaf_customer_experience 9.0.1a
ibm tealeaf_customer_experience 9.0.0
ibm tealeaf_customer_experience 9.0.2a
ibm tealeaf_customer_experience 9.0.2
CVE-2016-5977 MEDIUM

Open redirect vulnerability in the web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108_9.0.1A FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A before 9.0.2.5224_9.0.2A FP3 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-601,

Products Affected

Vendor Product Version
ibm tealeaf_customer_experience *
ibm tealeaf_customer_experience 8.8
ibm tealeaf_customer_experience 9.0.1
ibm tealeaf_customer_experience 9.0.1a
ibm tealeaf_customer_experience 9.0.0
ibm tealeaf_customer_experience 9.0.2a
ibm tealeaf_customer_experience 9.0.2
CVE-2016-5978 LOW

Cross-site scripting (XSS) vulnerability in the Web UI in the web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108_9.0.1A FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A before 9.0.2.5224_9.0.2A FP3 allows remote authenticated users to inject arbitrary web script or HTML via an embedded string, a different vulnerability than CVE-2016-5975.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tealeaf_customer_experience 8.8
ibm tealeaf_customer_experience 9.0.0a
ibm tealeaf_customer_experience 9.0.1
ibm tealeaf_customer_experience 9.0.1a
ibm tealeaf_customer_experience 8.7
ibm tealeaf_customer_experience 9.0.0
ibm tealeaf_customer_experience 9.0.2a
ibm tealeaf_customer_experience 9.0.2
CVE-2016-5979 MEDIUM

IBM Distributed Marketing 8.6, 9.0, and 10.0 could allow a privileged authenticated user to create an instance that gets created with security profile not valid for the templates, that results in the new instance not accessible for the intended user. IBM X-Force ID: 116379.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm distributed_marketing 9.1.0.0
ibm distributed_marketing 9.1.0.7
ibm distributed_marketing 9.1.0.10
ibm distributed_marketing 9.1.2.1
ibm distributed_marketing 8.6.0.3
ibm distributed_marketing 9.1.0.11
ibm distributed_marketing 9.1.0.2
ibm distributed_marketing 9.1.0.5
ibm distributed_marketing 8.6.0.8
ibm distributed_marketing 9.1.0.8
ibm distributed_marketing 10.0.0.1
ibm distributed_marketing 8.6.0.6
ibm distributed_marketing 10.0.0.0
ibm distributed_marketing 9.1.0.9
ibm distributed_marketing 9.1.0.3
ibm distributed_marketing 8.6.0.5
ibm distributed_marketing 9.1.0.4
ibm distributed_marketing 8.6.0.9
ibm distributed_marketing 8.6.0.4
ibm distributed_marketing 8.6.0.7
ibm distributed_marketing 8.6.0.0
ibm distributed_marketing 9.1.2.2
ibm distributed_marketing 8.6.0.2
ibm distributed_marketing 9.1.2.3
ibm distributed_marketing 9.1.0.6
ibm distributed_marketing 8.6.0.10
ibm distributed_marketing 9.1.2.0
CVE-2016-5980 LOW

IBM TRIRIGA Application Platform is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tririga_application_platform 3.4.1.2
ibm tririga_application_platform 3.4.2.4
ibm tririga_application_platform 3.4.2.0
ibm tririga_application_platform 3.3.2.5
ibm tririga_application_platform 3.3.0.1
ibm tririga_application_platform 3.3.1.0
ibm tririga_application_platform 3.3.2.1
ibm tririga_application_platform 3.3.0.2
ibm tririga_application_platform 3.3.2.0
ibm tririga_application_platform 3.3.2.2
ibm tririga_application_platform 3.4.2.2
ibm tririga_application_platform 3.3.1.1
ibm tririga_application_platform 3.5.0.0
ibm tririga_application_platform 3.4.2.1
ibm tririga_application_platform 3.4.2.3
ibm tririga_application_platform 3.5.0.1
ibm tririga_application_platform 3.4.1.0
ibm tririga_application_platform 3.4.0.1
ibm tririga_application_platform 3.3.2.4
ibm tririga_application_platform 3.4.1.1
ibm tririga_application_platform 3.3.1.2
ibm tririga_application_platform 3.5.1.1
ibm tririga_application_platform 3.5.1.0
ibm tririga_application_platform 3.4.0.0
ibm tririga_application_platform 3.3.1.3
ibm tririga_application_platform 3.3.2.3
ibm tririga_application_platform 3.4.1.3
ibm tririga_application_platform 3.3.0.0
CVE-2016-5981 LOW

Cross-site scripting (XSS) vulnerability in IBM FileNet Workplace XT through 1.1.5.2-WPXT-LA011 and FileNet Workplace (Application Engine) through 4.0.2.14-P8AE-IF001, when RegExpSecurityFilter and ScriptSecurityFilter are misconfigured, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm filenet_workplace *
ibm filenet_workplace_xt *
CVE-2016-5983 MEDIUM

IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.43, 8.0 before 8.0.0.13, 8.5 before 8.5.5.11, 9.0 before 9.0.0.2, and Liberty before 16.0.0.4 allows remote authenticated users to execute arbitrary Java code via a crafted serialized object.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 7.0.0.36
ibm websphere_application_server 7.0
ibm websphere_application_server 7.0.0.38
ibm websphere_application_server 7.0.0.12
ibm websphere_application_server 8.0.0.6
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 8.5.5.2
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 7.0.0.16
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 7.0.0.25
ibm websphere_application_server 8.0.0.9
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 8.5.5.10
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 7.0.0.14
ibm websphere_application_server 7.0.0.22
ibm websphere_application_server 7.0.0.31
ibm websphere_application_server 9.0.0.1
ibm websphere_application_server 7.0.0.10
ibm websphere_application_server 8.5.5.5
ibm websphere_application_server 8.0.0.8
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 8.0.0.7
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 8.0.0.12
ibm websphere_application_server 7.0.0.27
ibm websphere_application_server 7.0.0.18
ibm websphere_application_server 7.0.0.41
ibm websphere_application_server 7.0.0.39
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 8.0.0.2
ibm websphere_application_server 9.0.0.0
ibm websphere_application_server 8.0.0.5
ibm websphere_application_server 8.5.0.2
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 8.5.5.7
ibm websphere_application_server 7.0.0.33
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 7.0.0.0
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 8.5.5.8
ibm websphere_application_server 7.0.0.32
ibm websphere_application_server 8.0
ibm websphere_application_server 7.0.0.29
ibm websphere_application_server 7.0.0.24
ibm websphere_application_server 8.5.5.0
ibm websphere_application_server 7.0.0.37
ibm websphere_application_server 8.5.5.9
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 8.5.5.6
ibm websphere_application_server 8.0.0.11
ibm websphere_application_server 8.0.0.10
ibm websphere_application_server 7.0.0.28
ibm websphere_application_server 7.0.0.34
ibm websphere_application_server 8.5.5.4
ibm websphere_application_server 7.0.0.35
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 8.5.5.1
ibm websphere_application_server 7.0.0.4
CVE-2016-5984 MEDIUM

IBM InfoSphere Information Server is vulnerable to cross-frame scripting, caused by insufficient HTML iframe protection. A remote attacker could exploit this vulnerability using a specially-crafted URL to navigate to a web page the attacker controls. An attacker could use this vulnerability to conduct clickjacking or other client-side browser attacks.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm infosphere_information_server 11.3
ibm infosphere_information_server 11.5
ibm infosphere_information_server 9.1
ibm infosphere_information_server 8.7
ibm infosphere_information_server_on_cloud 11.5
CVE-2016-5985 HIGH

The IBM Tivoli Storage Manager (IBM Spectrum Protect) AIX client is vulnerable to a buffer overflow when Journal-Based Backup is enabled. A local attacker could overflow a buffer and execute arbitrary code on the system or cause a system crash.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager 6.3.0.0
ibm tivoli_storage_manager 6.4.0.0
ibm tivoli_storage_manager *
ibm tivoli_storage_manager 7.1.0.0
CVE-2016-5986 MEDIUM

IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.x before 8.0.0.13, 8.5.x before 8.5.5.11, 9.0.x before 9.0.0.2, and Liberty before 16.0.0.3 mishandles responses, which allows remote attackers to obtain sensitive information via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_application_server 7.0.0.19
ibm websphere_application_server 7.0.0.36
ibm websphere_application_server 7.0
ibm websphere_application_server 7.0.0.38
ibm websphere_application_server 7.0.0.12
ibm websphere_application_server 8.0.0.6
ibm websphere_application_server 7.0.0.17
ibm websphere_application_server 8.5.5.2
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 7.0.0.16
ibm websphere_application_server 7.0.0.6
ibm websphere_application_server 7.0.0.25
ibm websphere_application_server 8.0.0.9
ibm websphere_application_server 7.0.0.23
ibm websphere_application_server 8.5.5.10
ibm websphere_application_server 7.0.0.7
ibm websphere_application_server 7.0.0.8
ibm websphere_application_server 7.0.0.14
ibm websphere_application_server 7.0.0.22
ibm websphere_application_server 7.0.0.31
ibm websphere_application_server 9.0.0.1
ibm websphere_application_server 7.0.0.10
ibm websphere_application_server 8.5.5.5
ibm websphere_application_server 8.0.0.8
ibm websphere_application_server 7.0.0.3
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 7.0.0.11
ibm websphere_application_server 7.0.0.5
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 8.0.0.7
ibm websphere_application_server 7.0.0.1
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 8.0.0.12
ibm websphere_application_server 7.0.0.27
ibm websphere_application_server 7.0.0.18
ibm websphere_application_server 7.0.0.41
ibm websphere_application_server 7.0.0.39
ibm websphere_application_server 7.0.0.15
ibm websphere_application_server 8.0.0.2
ibm websphere_application_server 9.0.0.0
ibm websphere_application_server 8.0.0.5
ibm websphere_application_server 8.5.0.2
ibm websphere_application_server 7.0.0.21
ibm websphere_application_server 8.5.5.7
ibm websphere_application_server 7.0.0.33
ibm websphere_application_server 7.0.0.9
ibm websphere_application_server 7.0.0.0
ibm websphere_application_server 7.0.0.13
ibm websphere_application_server 8.5.5.8
ibm websphere_application_server 7.0.0.32
ibm websphere_application_server 8.0
ibm websphere_application_server 7.0.0.29
ibm websphere_application_server 7.0.0.24
ibm websphere_application_server 8.5.5.0
ibm websphere_application_server 7.0.0.37
ibm websphere_application_server 8.5.5.9
ibm websphere_application_server 7.0.0.2
ibm websphere_application_server 8.5.5.6
ibm websphere_application_server 8.0.0.11
ibm websphere_application_server 8.0.0.10
ibm websphere_application_server 7.0.0.28
ibm websphere_application_server 7.0.0.34
ibm websphere_application_server 8.5.5.4
ibm websphere_application_server 7.0.0.35
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 8.5.5.1
ibm websphere_application_server 7.0.0.4
CVE-2016-5987 MEDIUM

IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5 before 7.5.0.10 IF4, and 7.6 before 7.6.0.5 IF3 allows remote attackers to obtain sensitive information via a crafted HTTP request that triggers construction of a runtime error message.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm maximo_asset_management 7.1.1.9
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management 7.6.0.3
ibm maximo_asset_management 7.5.0.1
ibm maximo_asset_management 7.5.0.10
ibm maximo_asset_management 7.1.1.13
ibm maximo_asset_management 7.1.1.10
ibm maximo_asset_management 7.6.0.4
ibm maximo_asset_management 7.1.1.1
ibm maximo_asset_management 7.6.0.0
ibm maximo_asset_management 7.1.1.12
ibm maximo_asset_management 7.1.1.3
ibm maximo_asset_management 7.5.0.3
ibm maximo_asset_management 7.6.0.2
ibm maximo_asset_management 7.5.0.9
ibm maximo_asset_management 7.5.0.6
ibm maximo_asset_management 7.1.0.0
ibm maximo_asset_management 7.5.0.0
ibm maximo_asset_management 7.1.1.7
ibm maximo_asset_management 7.5.0.7
ibm maximo_asset_management 7.5.0.4
ibm maximo_asset_management 7.5.0.5
ibm maximo_asset_management 7.1.1.2
ibm maximo_asset_management 7.1.1.6
ibm maximo_asset_management 7.1.1.5
ibm maximo_asset_management 7.1.1.11
ibm maximo_asset_management 7.1.2
ibm maximo_asset_management 7.6.0.1
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
ibm maximo_asset_management 7.5.0.8
CVE-2016-5988 MEDIUM

IBM Security Privileged Identity Manager Virtual Appliance could disclose sensitive information in generated error messages that would be available to an authenticated user.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_privileged_identity_manager 2.0.2
ibm security_privileged_identity_manager 2.1
CVE-2016-5990 MEDIUM

IBM Security Privileged Identity Manager Virtual Appliance allows an authenticated user to upload malicious files that would be automatically executed by the server.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm security_privileged_identity_manager 2.0.2
ibm security_privileged_identity_manager 2.1
CVE-2016-5991 MEDIUM

IBM Sterling Connect:Direct 4.5.00, 4.5.01, 4.6.0 before 4.6.0.6 iFix008, and 4.7.0 before 4.7.0.4 on Windows allows local users to gain privileges via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm sterling_connect:direct 4.6
ibm sterling_connect:direct 4.5.01
ibm sterling_connect:direct 4.7
ibm sterling_connect:direct 4.5
CVE-2016-5992 LOW

IBM Sterling Connect:Direct 4.5.00, 4.5.01, 4.6.0 before 4.6.0.6 iFix008, and 4.7.0 before 4.7.0.4 on Windows allows local users to cause a denial of service via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm sterling_connect:direct 4.6
ibm sterling_connect:direct 4.5.01
ibm sterling_connect:direct 4.7
ibm sterling_connect:direct 4.5
CVE-2016-5994 MEDIUM

IBM InfoSphere Information Server contains a vulnerability that would allow an authenticated user to browse any file on the engine tier, and examine its contents.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm infosphere_information_server 11.5
CVE-2016-5995 MEDIUM

Untrusted search path vulnerability in IBM DB2 9.7 through FP11, 10.1 through FP5, 10.5 before FP8, and 11.1 GA on Linux, AIX, and HP-UX allows local users to gain privileges via a Trojan horse library that is accessed by a setuid or setgid program.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm db2_connect 10.1
ibm db2_connect 9.7.0.11
ibm db2 10.1.0.1
ibm db2_connect 10.1.0.3
ibm db2_connect 9.7.0.8
ibm db2 11.1.0.0
ibm db2_connect 9.7.0.6
ibm db2 10.5.0.1
ibm db2 10.5.0.2
ibm db2 9.7.0.2
ibm db2 9.7.0.1
ibm db2_connect 10.5.0.5
ibm db2 10.1.0.5
ibm db2_connect 9.7
ibm db2_connect 11.1.0.0
ibm db2 10.5.0.4
ibm db2 10.1.0.3
ibm db2_connect 10.1.0.5
ibm db2 10.5.0.7
ibm db2 9.7.0.7
ibm db2_connect 10.1.0.4
ibm db2 9.7
ibm db2 9.7.0.3
ibm db2 10.5.0.3
ibm db2 9.7.0.11
ibm db2_connect 9.7.0.4
ibm db2_connect 10.1.0.2
ibm db2_connect 10.5.0.3
ibm db2_connect 9.7.0.9
ibm db2 10.5
ibm db2 9.7.0.9
ibm db2_connect 9.7.0.5
ibm db2_connect 10.5.0.2
ibm db2 9.7.0.5
ibm db2_connect 10.5.0.4
ibm db2 9.7.0.6
ibm db2 9.7.0.10
ibm db2 9.7.0.8
ibm db2 10.1.0.4
ibm db2 10.1
ibm db2_connect 9.7.0.10
ibm db2_connect 10.1.0.1
ibm db2_connect 10.5.0.6
ibm db2_connect 9.7.0.7
ibm db2 10.1.0.2
ibm db2_connect 9.7.0.3
ibm db2 9.7.0.4
ibm db2 10.5.0.5
ibm db2_connect 10.5.0.7
ibm db2_connect 10.5.0.1
ibm db2 10.5.0.6
ibm db2_connect 10.5
ibm db2_connect 9.7.0.1
ibm db2_connect 9.7.0.2
CVE-2016-5996 MEDIUM

The web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108_9.0.1A FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A before 9.0.2.5224_9.0.2A FP3 does not enforce password-length restrictions, which makes it easier for remote attackers to obtain access via a brute-force attack.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-640,

Products Affected

Vendor Product Version
ibm tealeaf_customer_experience *
ibm tealeaf_customer_experience 8.8
ibm tealeaf_customer_experience 9.0.1
ibm tealeaf_customer_experience 9.0.1a
ibm tealeaf_customer_experience 9.0.0
ibm tealeaf_customer_experience 9.0.2a
ibm tealeaf_customer_experience 9.0.2
CVE-2016-5997 MEDIUM

The web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108_9.0.1A FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A before 9.0.2.5224_9.0.2A FP3 does not apply password-quality rules to password changes, which makes it easier for remote attackers to obtain access via a brute-force attack.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-640,

Products Affected

Vendor Product Version
ibm tealeaf_customer_experience *
ibm tealeaf_customer_experience 8.8
ibm tealeaf_customer_experience 9.0.1
ibm tealeaf_customer_experience 9.0.1a
ibm tealeaf_customer_experience 9.0.0
ibm tealeaf_customer_experience 9.0.2a
ibm tealeaf_customer_experience 9.0.2
CVE-2016-6000 MEDIUM

IBM TRIRIGA Application Platform is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tririga_application_platform 3.4.1.2
ibm tririga_application_platform 3.4.2.4
ibm tririga_application_platform 3.4.2.0
ibm tririga_application_platform 3.3.2.5
ibm tririga_application_platform 3.3.0.1
ibm tririga_application_platform 3.3.1.0
ibm tririga_application_platform 3.3.2.1
ibm tririga_application_platform 3.3.0.2
ibm tririga_application_platform 3.3.2.0
ibm tririga_application_platform 3.3.2.2
ibm tririga_application_platform 3.4.2.2
ibm tririga_application_platform 3.3.1.1
ibm tririga_application_platform 3.5.0.0
ibm tririga_application_platform 3.4.2.1
ibm tririga_application_platform 3.4.2.3
ibm tririga_application_platform 3.5.0.1
ibm tririga_application_platform 3.4.1.0
ibm tririga_application_platform 3.4.0.1
ibm tririga_application_platform 3.3.2.4
ibm tririga_application_platform 3.4.1.1
ibm tririga_application_platform 3.3.1.2
ibm tririga_application_platform 3.5.1.1
ibm tririga_application_platform 3.5.1.0
ibm tririga_application_platform 3.4.0.0
ibm tririga_application_platform 3.3.1.3
ibm tririga_application_platform 3.3.2.3
ibm tririga_application_platform 3.4.1.3
ibm tririga_application_platform 3.3.0.0
CVE-2016-6001 LOW

IBM Forms Experience Builder could be susceptible to a server-side request forgery (SSRF) from the application design interface allowing for some information disclosure of internal resources.

CVSS 2.0

Severity: LOW

Problem Type: CWE-918,

Products Affected

Vendor Product Version
ibm forms_experience_builder 8.5.1
ibm forms_experience_builder 8.6.0
ibm forms_experience_builder 8.5
CVE-2016-6018 MEDIUM

IBM Emptoris Contract Management 10.0 and 10.1 reveals detailed error messages in certain features that could cause an attacker to gain additional information to conduct further attacks. IBM X-Force ID: 116738.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm emptoris_contract_management 10.0.1.4
ibm emptoris_contract_management 10.0.2.13
ibm emptoris_contract_management 10.0.2.9
ibm emptoris_contract_management 10.0.2.5
ibm emptoris_contract_management 10.0.2.11
ibm emptoris_contract_management 10.0.0.1
ibm emptoris_contract_management 10.0.1.2
ibm emptoris_contract_management 10.0.2.8
ibm emptoris_contract_management 10.0.0.0
ibm emptoris_contract_management 10.0.1.0
ibm emptoris_contract_management 10.0.2.17
ibm emptoris_contract_management 10.0.2.15
ibm emptoris_contract_management 10.0.2.2
ibm emptoris_contract_management 10.0.2.3
ibm emptoris_contract_management 10.0.1.5
ibm emptoris_contract_management 10.0.4.0
ibm emptoris_contract_management 10.0.2.14
ibm emptoris_contract_management 10.0.2.16
ibm emptoris_contract_management 10.0.1.1
ibm emptoris_contract_management 10.0.2.1
ibm emptoris_contract_management 10.0.2.0
ibm emptoris_contract_management 10.0.1.3
ibm emptoris_contract_management 10.0.2.7
ibm emptoris_contract_management 10.0.2.6
ibm emptoris_contract_management 10.0.2.10
ibm emptoris_contract_management 10.0.2.12
ibm emptoris_contract_management 10.1.0.0
CVE-2016-6019 LOW

IBM Emptoris Strategic Supply Management Platform 10.0.0.x through 10.1.1.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 116739.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm emptoris_strategic_supply_management 10.0.2.5
ibm emptoris_strategic_supply_management 10.0.0.0
ibm emptoris_strategic_supply_management 10.1.0.1
ibm emptoris_strategic_supply_management 10.1.1.1
ibm emptoris_strategic_supply_management 10.0.2.9
ibm emptoris_strategic_supply_management 10.1.1.9
ibm emptoris_strategic_supply_management 10.0.2.4
ibm emptoris_strategic_supply_management 10.1.0.3
ibm emptoris_strategic_supply_management 10.1.1.3
ibm emptoris_strategic_supply_management 10.0.2.6
ibm emptoris_strategic_supply_management 10.1.1.0
ibm emptoris_strategic_supply_management 10.1.0.12
ibm emptoris_strategic_supply_management 10.0.1.2
ibm emptoris_strategic_supply_management 10.0.1.4
ibm emptoris_strategic_supply_management 10.1.1.6
ibm emptoris_strategic_supply_management 10.1.1.7
ibm emptoris_strategic_supply_management 10.0.2.11
ibm emptoris_strategic_supply_management 10.0.2.3
ibm emptoris_strategic_supply_management 10.0.2.8
ibm emptoris_strategic_supply_management 10.0.2.13
ibm emptoris_strategic_supply_management 10.0.2.14
ibm emptoris_strategic_supply_management 10.0.2.15
ibm emptoris_strategic_supply_management 10.1.0.9
ibm emptoris_strategic_supply_management 10.0.0.2
ibm emptoris_strategic_supply_management 10.0.4.0
ibm emptoris_strategic_supply_management 10.1.0.4
ibm emptoris_strategic_supply_management 10.1.0.7
ibm emptoris_strategic_supply_management 10.1.0.10
ibm emptoris_strategic_supply_management 10.0.2.17
ibm emptoris_strategic_supply_management 10.1.1.2
ibm emptoris_strategic_supply_management 10.0.2.10
ibm emptoris_strategic_supply_management 10.1.0.6
ibm emptoris_strategic_supply_management 10.0.1.1
ibm emptoris_strategic_supply_management 10.0.2.16
ibm emptoris_strategic_supply_management 10.1.1.10
ibm emptoris_strategic_supply_management 10.0.2.0
ibm emptoris_strategic_supply_management 10.0.2.2
ibm emptoris_strategic_supply_management 10.1.0.8
ibm emptoris_strategic_supply_management 10.1.1.5
ibm emptoris_strategic_supply_management 10.0.1.3
ibm emptoris_strategic_supply_management 10.1.0.2
ibm emptoris_strategic_supply_management 10.0.0.3
ibm emptoris_strategic_supply_management 10.0.0.1
ibm emptoris_strategic_supply_management 10.1.0.5
ibm emptoris_strategic_supply_management 10.1.0.11
ibm emptoris_strategic_supply_management 10.0.1.0
ibm emptoris_strategic_supply_management 10.1.1.8
ibm emptoris_strategic_supply_management 10.0.2.1
ibm emptoris_strategic_supply_management 10.0.2.7
ibm emptoris_strategic_supply_management 10.1.0.0
ibm emptoris_strategic_supply_management 10.0.2.12
ibm emptoris_strategic_supply_management 10.1.1.4
CVE-2016-6020 MEDIUM

IBM Sterling B2B Integrator Standard Edition could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-601,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2.6
ibm sterling_b2b_integrator 5.2
ibm sterling_b2b_integrator 5.2.1
ibm sterling_b2b_integrator 5.2.5
ibm sterling_b2b_integrator 5.2.4.2
ibm sterling_b2b_integrator 5.2.4
ibm sterling_b2b_integrator 5.2.2
ibm sterling_b2b_integrator 5.2.4.1
CVE-2016-6021 LOW

IBM Emptoris Strategic Supply Management Platform 10.0 and 10.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 116755.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm emptoris_strategic_supply_management 10.0.2.0
ibm emptoris_strategic_supply_management 10.0.2.5
ibm emptoris_strategic_supply_management 10.0.0.0
ibm emptoris_strategic_supply_management 10.0.2.2
ibm emptoris_strategic_supply_management 10.1.0.1
ibm emptoris_strategic_supply_management 10.1.1.1
ibm emptoris_strategic_supply_management 10.0.2.9
ibm emptoris_strategic_supply_management 10.0.2.4
ibm emptoris_strategic_supply_management 10.1.0.8
ibm emptoris_strategic_supply_management 10.1.0.3
ibm emptoris_strategic_supply_management 10.1.1.3
ibm emptoris_strategic_supply_management 10.0.2.6
ibm emptoris_strategic_supply_management 10.1.1.5
ibm emptoris_strategic_supply_management 10.1.1.0
ibm emptoris_strategic_supply_management 10.0.1.3
ibm emptoris_strategic_supply_management 10.0.1.2
ibm emptoris_strategic_supply_management 10.1.0.2
ibm emptoris_strategic_supply_management 10.0.1.4
ibm emptoris_strategic_supply_management 10.1.1.6
ibm emptoris_strategic_supply_management 10.1.1.7
ibm emptoris_strategic_supply_management 10.0.0.3
ibm emptoris_strategic_supply_management 10.0.0.1
ibm emptoris_strategic_supply_management 10.0.2.11
ibm emptoris_strategic_supply_management 10.0.2.3
ibm emptoris_strategic_supply_management 10.1.0.5
ibm emptoris_strategic_supply_management 10.0.2.8
ibm emptoris_strategic_supply_management 10.0.2.13
ibm emptoris_strategic_supply_management 10.0.1.0
ibm emptoris_strategic_supply_management 10.1.1.8
ibm emptoris_strategic_supply_management 10.0.2.1
ibm emptoris_strategic_supply_management 10.0.2.14
ibm emptoris_strategic_supply_management 10.0.2.15
ibm emptoris_strategic_supply_management 10.1.0.9
ibm emptoris_strategic_supply_management 10.0.0.2
ibm emptoris_strategic_supply_management 10.0.2.7
ibm emptoris_strategic_supply_management 10.0.4.0
ibm emptoris_strategic_supply_management 10.1.0.4
ibm emptoris_strategic_supply_management 10.1.0.7
ibm emptoris_strategic_supply_management 10.1.0.10
ibm emptoris_strategic_supply_management 10.1.0.0
ibm emptoris_strategic_supply_management 10.1.1.2
ibm emptoris_strategic_supply_management 10.0.2.10
ibm emptoris_strategic_supply_management 10.0.2.12
ibm emptoris_strategic_supply_management 10.1.0.6
ibm emptoris_strategic_supply_management 10.0.1.1
ibm emptoris_strategic_supply_management 10.1.1.4
CVE-2016-6022 LOW

IBM Quality Manager (RQM) 4.0, 5.0, and 6.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 2000784.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager 4.0.3
ibm rational_quality_manager 5.0.2
ibm rational_quality_manager 6.0
ibm rational_quality_manager 4.0.4
ibm rational_quality_manager 4.0.6
ibm rational_quality_manager 5.0
ibm rational_quality_manager 4.0.5
ibm rational_quality_manager 6.0.2
ibm rational_quality_manager 4.0.7
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 6.0.1
ibm rational_quality_manager 4.0.2
ibm rational_quality_manager 6.0.3
ibm rational_quality_manager 4.0
ibm rational_quality_manager 4.0.1
CVE-2016-6023 MEDIUM

Directory traversal vulnerability in the Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.0 iFix 1 allows remote attackers to read arbitrary files via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm sterling_secure_proxy 3.4.2.0
ibm sterling_secure_proxy 3.4.3.0
CVE-2016-6024 MEDIUM

IBM Jazz technology based products might divulge information that might be useful in helping attackers through error messages. IBM X-Force ID: 116868.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_rhapsody_design_manager 4.0.4
ibm rational_rhapsody_design_manager 4.0.5
ibm rational_software_architect_design_manager 6.0
ibm rational_collaborative_lifecycle_management 4.0.6
ibm rational_engineering_lifecycle_manager 4.0.7
ibm rational_quality_manager 4.0.6
ibm rational_software_architect_design_manager 6.0.1
ibm rational_team_concert 5.0
ibm rational_software_architect_design_manager 4.0.7
ibm rational_quality_manager 6.0.1
ibm rational_engineering_lifecycle_manager 5.0.2
ibm rational_rhapsody_design_manager 5.0.2
ibm rational_quality_manager 4.0.3
ibm rational_engineering_lifecycle_manager 6.0.2
ibm rational_collaborative_lifecycle_management 6.0.3
ibm rational_team_concert 4.0.1
ibm rational_team_concert 4.0.5
ibm rational_doors_next_generation 5.0
ibm rational_team_concert 4.0.2
ibm rational_quality_manager 5.0
ibm rational_collaborative_lifecycle_management 4.0.5
ibm rational_collaborative_lifecycle_management 4.0.7
ibm rational_collaborative_lifecycle_management 4.0.3
ibm rational_software_architect_design_manager 4.0.6
ibm rational_doors_next_generation 4.0.7
ibm rational_doors_next_generation 4.0.2
ibm rational_doors_next_generation 6.0
ibm rational_rhapsody_design_manager 4.0.7
ibm rational_engineering_lifecycle_manager 5.0
ibm rational_team_concert 5.0.2
ibm rational_collaborative_lifecycle_management 4.0.1
ibm rational_rhapsody_design_manager 5.0
ibm rational_engineering_lifecycle_manager 6.0.3
ibm rational_team_concert 6.0.4
ibm rational_team_concert 4.0.3
ibm rational_collaborative_lifecycle_management 4.0.2
ibm rational_quality_manager 4.0.1
ibm rational_team_concert 4.0.6
ibm rational_engineering_lifecycle_manager 4.0.5
ibm rational_software_architect_design_manager 5.0.2
ibm rational_engineering_lifecycle_manager 6.0.1
ibm rational_quality_manager 6.0
ibm rational_doors_next_generation 4.0.4
ibm rational_rhapsody_design_manager 6.0.3
ibm rational_quality_manager 4.0.4
ibm rational_rhapsody_design_manager 6.0.4
ibm rational_engineering_lifecycle_manager 4.0.6
ibm rational_rhapsody_design_manager 4.0.3
ibm rational_doors_next_generation 5.0.2
ibm rational_quality_manager 4.0.2
ibm rational_doors_next_generation 5.0.1
ibm rational_software_architect_design_manager 4.0.1
ibm rational_collaborative_lifecycle_management 4.0.4
ibm rational_team_concert 4.0.0.1
ibm rational_engineering_lifecycle_manager 4.0.3
ibm rational_engineering_lifecycle_manager 4.0.4
ibm rational_software_architect_design_manager 4.0.2
ibm rational_collaborative_lifecycle_management 6.0
ibm rational_quality_manager 4.0.0.1
ibm rational_quality_manager 4.0.0.2
ibm rational_team_concert 6.0.1
ibm rational_rhapsody_design_manager 6.0
ibm rational_quality_manager 4.0.7
ibm rational_rhapsody_design_manager 4.0.6
ibm rational_rhapsody_design_manager 6.0.1
ibm rational_rhapsody_design_manager 6.0.2
ibm rational_software_architect_design_manager 5.0
ibm rational_software_architect_design_manager 4.0.4
ibm rational_team_concert 6.0.2
ibm rational_doors_next_generation 4.0.1
ibm rational_engineering_lifecycle_manager 5.0.1
ibm rational_team_concert 4.0.7
ibm rational_team_concert 6.0
ibm rational_software_architect_design_manager 4.0.3
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_quality_manager 5.0.2
ibm rational_rhapsody_design_manager 4.0.1
ibm rational_rhapsody_design_manager 4.0.2
ibm rational_team_concert 4.0.0.2
ibm rational_rhapsody_design_manager 4.0
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_quality_manager 6.0.3
ibm rational_quality_manager 6.0.4
ibm rational_collaborative_lifecycle_management 6.0.4
ibm rational_doors_next_generation 6.0.1
ibm rational_rhapsody_design_manager 5.0.1
ibm rational_doors_next_generation 6.0.3
ibm rational_team_concert 4.0
ibm rational_doors_next_generation 4.0.5
ibm rational_collaborative_lifecycle_management 4.0
ibm rational_team_concert 6.0.3
ibm rational_engineering_lifecycle_manager 6.0.4
ibm rational_doors_next_generation 4.0.6
ibm rational_doors_next_generation 4.0.3
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 4.0
ibm rational_collaborative_lifecycle_management 5.0
ibm rational_doors_next_generation 6.0.4
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_software_architect_design_manager 4.0.5
ibm rational_engineering_lifecycle_manager 6.0
ibm rational_team_concert 4.0.4
ibm rational_software_architect_design_manager 5.0.1
ibm rational_software_architect_design_manager 4.0
ibm rational_quality_manager 4.0.5
ibm rational_quality_manager 6.0.2
ibm rational_doors_next_generation 6.0.2
ibm rational_team_concert 5.0.1
CVE-2016-6025 MEDIUM

The Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.0 iFix 1 allows remote attackers to obtain access by leveraging an unattended workstation to conduct a post-logoff session-reuse attack involving a modified URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm sterling_secure_proxy 3.4.2.0
ibm sterling_secure_proxy 3.4.3.0
CVE-2016-6026 LOW

The Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.0 iFix 1 allows man-in-the-middle attackers to obtain sensitive information via an HTTP method that is neither GET nor POST.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm sterling_secure_proxy 3.4.2.0
ibm sterling_secure_proxy 3.4.3.0
CVE-2016-6027 MEDIUM

The Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.0 iFix 1 does not enable the HSTS protection mechanism, which makes it easier for remote attackers to obtain sensitive information or modify data by leveraging use of HTTP.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm sterling_secure_proxy 3.4.2.0
ibm sterling_secure_proxy 3.4.3.0
CVE-2016-6028 MEDIUM

IBM Jazz technology based products might allow an attacker to view work item titles that they do not have privilege to view.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm rational_collaborative_lifecycle_management 6.0.2
ibm rational_collaborative_lifecycle_management 4.0.6
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_collaborative_lifecycle_management 4.0.1
ibm rational_collaborative_lifecycle_management 4.0.5
ibm rational_collaborative_lifecycle_management 4.0.7
ibm rational_collaborative_lifecycle_management 5.0.0
ibm rational_collaborative_lifecycle_management 4.0.3
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_collaborative_lifecycle_management 4.0.0
ibm rational_collaborative_lifecycle_management 4.0.2
ibm rational_collaborative_lifecycle_management 6.0.0
ibm rational_collaborative_lifecycle_management 4.0.4
CVE-2016-6029 MEDIUM

IBM Emptoris Strategic Supply Management Platform 10.0 and 10.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 116881.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm emptoris_strategic_supply_management 10.0.2.0
ibm emptoris_strategic_supply_management 10.0.2.5
ibm emptoris_strategic_supply_management 10.0.0.0
ibm emptoris_strategic_supply_management 10.0.2.2
ibm emptoris_strategic_supply_management 10.1.0.1
ibm emptoris_strategic_supply_management 10.1.1.1
ibm emptoris_strategic_supply_management 10.0.2.9
ibm emptoris_strategic_supply_management 10.0.2.4
ibm emptoris_strategic_supply_management 10.1.0.8
ibm emptoris_strategic_supply_management 10.1.0.3
ibm emptoris_strategic_supply_management 10.1.1.3
ibm emptoris_strategic_supply_management 10.0.2.6
ibm emptoris_strategic_supply_management 10.1.1.5
ibm emptoris_strategic_supply_management 10.1.1.0
ibm emptoris_strategic_supply_management 10.0.1.3
ibm emptoris_strategic_supply_management 10.0.1.2
ibm emptoris_strategic_supply_management 10.1.0.2
ibm emptoris_strategic_supply_management 10.0.1.4
ibm emptoris_strategic_supply_management 10.1.1.6
ibm emptoris_strategic_supply_management 10.1.1.7
ibm emptoris_strategic_supply_management 10.0.0.3
ibm emptoris_strategic_supply_management 10.0.0.1
ibm emptoris_strategic_supply_management 10.0.2.11
ibm emptoris_strategic_supply_management 10.0.2.3
ibm emptoris_strategic_supply_management 10.1.0.5
ibm emptoris_strategic_supply_management 10.0.2.8
ibm emptoris_strategic_supply_management 10.0.2.13
ibm emptoris_strategic_supply_management 10.0.1.0
ibm emptoris_strategic_supply_management 10.1.1.8
ibm emptoris_strategic_supply_management 10.0.2.1
ibm emptoris_strategic_supply_management 10.0.2.14
ibm emptoris_strategic_supply_management 10.0.2.15
ibm emptoris_strategic_supply_management 10.1.0.9
ibm emptoris_strategic_supply_management 10.0.0.2
ibm emptoris_strategic_supply_management 10.0.2.7
ibm emptoris_strategic_supply_management 10.0.4.0
ibm emptoris_strategic_supply_management 10.1.0.4
ibm emptoris_strategic_supply_management 10.1.0.7
ibm emptoris_strategic_supply_management 10.1.0.10
ibm emptoris_strategic_supply_management 10.1.0.0
ibm emptoris_strategic_supply_management 10.1.1.2
ibm emptoris_strategic_supply_management 10.0.2.10
ibm emptoris_strategic_supply_management 10.0.2.12
ibm emptoris_strategic_supply_management 10.1.0.6
ibm emptoris_strategic_supply_management 10.0.1.1
ibm emptoris_strategic_supply_management 10.1.1.4
CVE-2016-6030 LOW

IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_collaborative_lifecycle_management 6.0.2
ibm rational_collaborative_lifecycle_management 4.0.6
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_collaborative_lifecycle_management 4.0.1
ibm rational_collaborative_lifecycle_management 4.0.5
ibm rational_collaborative_lifecycle_management 4.0.7
ibm rational_collaborative_lifecycle_management 5.0.0
ibm rational_collaborative_lifecycle_management 4.0.3
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_collaborative_lifecycle_management 4.0.0
ibm rational_collaborative_lifecycle_management 4.0.2
ibm rational_collaborative_lifecycle_management 6.0.0
ibm rational_collaborative_lifecycle_management 4.0.4
CVE-2016-6031 LOW

IBM Rational Quality Manager 4.0, 5.0, and 6.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 2000784.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager 4.0.3
ibm rational_quality_manager 5.0.2
ibm rational_quality_manager 6.0
ibm rational_quality_manager 4.0.4
ibm rational_quality_manager 4.0.6
ibm rational_quality_manager 5.0
ibm rational_quality_manager 4.0.5
ibm rational_quality_manager 6.0.2
ibm rational_quality_manager 4.0.7
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 6.0.1
ibm rational_quality_manager 4.0.2
ibm rational_quality_manager 6.0.3
ibm rational_quality_manager 4.0
ibm rational_quality_manager 4.0.1
CVE-2016-6032 LOW

IBM Rational Team Concert 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_collaborative_lifecycle_management 6.0.3
ibm rational_collaborative_lifecycle_management 6.0.2
ibm rational_collaborative_lifecycle_management 4.0.6
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_collaborative_lifecycle_management 4.0.1
ibm rational_collaborative_lifecycle_management 4.0.5
ibm rational_collaborative_lifecycle_management 4.0.7
ibm rational_collaborative_lifecycle_management 5.0.0
ibm rational_collaborative_lifecycle_management 4.0.3
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_collaborative_lifecycle_management 4.0.0
ibm rational_collaborative_lifecycle_management 4.0.2
ibm rational_collaborative_lifecycle_management 6.0.0
ibm rational_collaborative_lifecycle_management 4.0.4
CVE-2016-6033 MEDIUM

IBM Tivoli Storage Manager for Virtual Environments 7.1 (VMware) is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM Reference #: 1995545.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm tivoli_storage_flashcopy_manager_for_vmware 4.1.3
ibm tivoli_storage_flashcopy_manager_for_vmware 4.1.6
ibm tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware 7.1.2
ibm tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware 7.1.4.0
ibm tivoli_storage_flashcopy_manager_for_vmware 4.1.0.0
ibm tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware 7.1.6.3
ibm tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware 7.1.0
ibm tivoli_storage_flashcopy_manager_for_vmware 4.1.4.1
ibm tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware 7.1.4
ibm tivoli_storage_flashcopy_manager_for_vmware 4.1.4
ibm tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware 7.1.1
ibm tivoli_storage_flashcopy_manager_for_vmware 4.1.4.0
ibm tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware 7.1.6
ibm tivoli_storage_flashcopy_manager_for_vmware 4.1.6.0
ibm tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware 7.1.3
ibm tivoli_storage_flashcopy_manager_for_vmware 4.1.1
ibm tivoli_storage_flashcopy_manager_for_vmware 4.1.2
ibm tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware 7.1.6.2
CVE-2016-6034 MEDIUM

IBM Tivoli Storage Manager for Virtual Environments (VMware) could disclose the Windows domain credentials to a user with a high level of privileges.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware 7.1.6
ibm tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware 7.1.3
ibm tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware 7.1.4.0
ibm tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware 7.1.6.3
ibm tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware 7.1.4
ibm tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware 7.1.6.2
CVE-2016-6035 LOW

IBM Rational Quality Manager is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 116896.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_team_concert 5.0.2
ibm rational_quality_manager 4.0.6
ibm rational_team_concert 6.0.3
ibm rational_team_concert 4.0.3
ibm rational_team_concert 6.0.1
ibm rational_quality_manager 4.0.7
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 6.0.1
ibm rational_team_concert 4.0.0
ibm rational_quality_manager 4.0.1
ibm rational_team_concert 4.0.6
ibm rational_team_concert 6.0.2
ibm rational_quality_manager 4.0.0
ibm rational_quality_manager 4.0.3
ibm rational_team_concert 5.0.0
ibm rational_team_concert 4.0.7
ibm rational_team_concert 4.0.1
ibm rational_team_concert 6.0.0
ibm rational_quality_manager 5.0.0
ibm rational_team_concert 4.0.5
ibm rational_team_concert 4.0.2
ibm rational_quality_manager 5.0.2
ibm rational_quality_manager 4.0.4
ibm rational_team_concert 4.0.4
ibm rational_quality_manager 4.0.5
ibm rational_quality_manager 6.0.2
ibm rational_quality_manager 6.0.0
ibm rational_quality_manager 4.0.2
ibm rational_team_concert 5.0.1
CVE-2016-6036 LOW

IBM Rational Quality Manager (RQM) 4.0, 5.0, and 6.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 2000784.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager 4.0.3
ibm rational_quality_manager 5.0.2
ibm rational_quality_manager 6.0
ibm rational_quality_manager 4.0.4
ibm rational_quality_manager 4.0.6
ibm rational_quality_manager 5.0
ibm rational_quality_manager 4.0.5
ibm rational_quality_manager 6.0.2
ibm rational_quality_manager 4.0.7
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 6.0.1
ibm rational_quality_manager 4.0.2
ibm rational_quality_manager 6.0.3
ibm rational_quality_manager 4.0
ibm rational_quality_manager 4.0.1
CVE-2016-6037 LOW

IBM Rational Team Concert (RTC) is vulnerable to HTML injection. A remote attacker with project administrator privileges could send a project that contains malicious HTML code, which when the project is viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 116918.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_team_concert 5.0.2
ibm rational_quality_manager 4.0.6
ibm rational_team_concert 6.0.3
ibm rational_team_concert 4.0.3
ibm rational_team_concert 6.0.1
ibm rational_quality_manager 4.0.7
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 6.0.1
ibm rational_team_concert 4.0.0
ibm rational_quality_manager 4.0.1
ibm rational_team_concert 4.0.6
ibm rational_team_concert 6.0.2
ibm rational_quality_manager 4.0.0
ibm rational_quality_manager 4.0.3
ibm rational_team_concert 5.0.0
ibm rational_team_concert 4.0.7
ibm rational_team_concert 4.0.1
ibm rational_team_concert 6.0.0
ibm rational_quality_manager 5.0.0
ibm rational_team_concert 4.0.5
ibm rational_team_concert 4.0.2
ibm rational_quality_manager 5.0.2
ibm rational_quality_manager 4.0.4
ibm rational_team_concert 4.0.4
ibm rational_quality_manager 4.0.5
ibm rational_quality_manager 6.0.2
ibm rational_quality_manager 6.0.0
ibm rational_quality_manager 4.0.2
ibm rational_team_concert 5.0.1
CVE-2016-6038 MEDIUM

Directory traversal vulnerability in Eclipse Help in IBM Tivoli Lightweight Infrastructure (aka LWI), as used in AIX 5.3, 6.1, and 7.1, allows remote authenticated users to read arbitrary files via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm aix 5.3
ibm aix 6.1
ibm aix 7.1
CVE-2016-6039 LOW

IBM Jazz Reporting Service (JRS) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm jazz_reporting_service 6.0
ibm jazz_reporting_service 6.0.2
ibm jazz_reporting_service 6.0.1
CVE-2016-6040 MEDIUM

IBM Jazz Foundation could allow an authenticated user to take over a previously logged in user due to session expiration not being enforced.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-384,

Products Affected

Vendor Product Version
ibm rational_collaborative_lifecycle_management 6.0.2
ibm rational_collaborative_lifecycle_management 4.0.6
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_collaborative_lifecycle_management 4.0.1
ibm rational_collaborative_lifecycle_management 4.0.5
ibm rational_collaborative_lifecycle_management 4.0.7
ibm rational_collaborative_lifecycle_management 5.0.0
ibm rational_collaborative_lifecycle_management 4.0.3
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_collaborative_lifecycle_management 4.0.0
ibm rational_collaborative_lifecycle_management 4.0.2
ibm rational_collaborative_lifecycle_management 6.0.0
ibm rational_collaborative_lifecycle_management 4.0.4
CVE-2016-6042 HIGH

IBM AppScan Enterprise Edition could allow a remote attacker to execute arbitrary code on the system, caused by improper handling of objects in memory. By persuading a victim to open specially-crafted content, an attacker could exploit this vulnerability to execute arbitrary code on the system in the same context as the victim.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm security_appscan 9.0.1.0
ibm security_appscan 9.0.1.1
ibm security_appscan 9.0.0.0
ibm security_appscan 9.0.3.0
ibm security_appscan 9.0.3.1
ibm security_appscan 9.0.2.0
ibm security_appscan 9.0.0.1
ibm security_appscan 9.0.2.1
CVE-2016-6043 MEDIUM

Tivoli Storage Manager Operations Center could allow a local user to take over a previously logged in user due to session expiration not being enforced.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-384,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager 7.1.1.1
ibm tivoli_storage_manager 7.1.3.1
ibm tivoli_storage_manager 6.4.2.2
ibm tivoli_storage_manager 7.1.1.2
ibm tivoli_storage_manager 6.4.2.1
ibm tivoli_storage_manager 7.1.4.1
ibm tivoli_storage_manager 7.1
ibm tivoli_storage_manager 7.1.3
ibm tivoli_storage_manager 7.1.0.2
ibm tivoli_storage_manager 6.4.1
ibm tivoli_storage_manager 7.1.7
ibm tivoli_storage_manager 6.4.2
ibm tivoli_storage_manager 7.1.3.2
ibm tivoli_storage_manager 7.1.4.2
ibm tivoli_storage_manager 7.1.0.1
ibm tivoli_storage_manager 7.1.4
ibm tivoli_storage_manager 6.4.2.4
ibm tivoli_storage_manager 6.4.2.3
ibm tivoli_storage_manager 6.4.1.1
CVE-2016-6044 MEDIUM

IBM Tivoli Storage Manager Operations Center could allow an authenticated attacker to enable or disable the application's REST API, which may let the attacker violate security policy.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager 7.1.1.1
ibm tivoli_storage_manager 7.1.3.1
ibm tivoli_storage_manager 6.4.2.2
ibm tivoli_storage_manager 7.1.1.2
ibm tivoli_storage_manager 6.4.2.1
ibm tivoli_storage_manager 7.1.4.1
ibm tivoli_storage_manager 7.1
ibm tivoli_storage_manager 7.1.3
ibm tivoli_storage_manager 7.1.0.2
ibm tivoli_storage_manager 6.4.1
ibm tivoli_storage_manager 7.1.7
ibm tivoli_storage_manager 6.4.2
ibm tivoli_storage_manager 7.1.3.2
ibm tivoli_storage_manager 7.1.4.2
ibm tivoli_storage_manager 7.1.0.1
ibm tivoli_storage_manager 7.1.4
ibm tivoli_storage_manager 6.4.2.4
ibm tivoli_storage_manager 6.4.2.3
ibm tivoli_storage_manager 6.4.1.1
CVE-2016-6045 MEDIUM

IBM Tivoli Storage Manager Operations Center is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager 7.1.1.1
ibm tivoli_storage_manager 7.1.3.1
ibm tivoli_storage_manager 6.4.2.2
ibm tivoli_storage_manager 7.1.1.2
ibm tivoli_storage_manager 6.4.2.1
ibm tivoli_storage_manager 7.1.4.1
ibm tivoli_storage_manager 7.1
ibm tivoli_storage_manager 7.1.3
ibm tivoli_storage_manager 7.1.0.2
ibm tivoli_storage_manager 6.4.1
ibm tivoli_storage_manager 7.1.7
ibm tivoli_storage_manager 6.4.2
ibm tivoli_storage_manager 7.1.3.2
ibm tivoli_storage_manager 7.1.4.2
ibm tivoli_storage_manager 7.1.0.1
ibm tivoli_storage_manager 7.1.4
ibm tivoli_storage_manager 6.4.2.4
ibm tivoli_storage_manager 6.4.2.3
ibm tivoli_storage_manager 6.4.1.1
CVE-2016-6046 LOW

IBM Tivoli Storage Manager Operations Center is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager 7.1.1.1
ibm tivoli_storage_manager 7.1.3.1
ibm tivoli_storage_manager 6.4.2.2
ibm tivoli_storage_manager 7.1.1.2
ibm tivoli_storage_manager 6.4.2.1
ibm tivoli_storage_manager 7.1.4.1
ibm tivoli_storage_manager 7.1
ibm tivoli_storage_manager 7.1.3
ibm tivoli_storage_manager 7.1.0.2
ibm tivoli_storage_manager 6.4.1
ibm tivoli_storage_manager 7.1.7
ibm tivoli_storage_manager 6.4.2
ibm tivoli_storage_manager 7.1.3.2
ibm tivoli_storage_manager 7.1.4.2
ibm tivoli_storage_manager 7.1.0.1
ibm tivoli_storage_manager 7.1.4
ibm tivoli_storage_manager 6.4.2.4
ibm tivoli_storage_manager 6.4.2.3
ibm tivoli_storage_manager 6.4.1.1
CVE-2016-6047 LOW

IBM Jazz Reporting Service (JRS) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm jazz_reporting_service 6.0.2
CVE-2016-6054 LOW

IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm jazz_reporting_service 5.0.2
ibm jazz_reporting_service 6.0
ibm jazz_reporting_service 6.0.2
ibm jazz_reporting_service 6.0.1
ibm jazz_reporting_service 5.0
ibm jazz_reporting_service 5.0.1
CVE-2016-6055 LOW

IBM Rational DOORS Next Generation 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1995515.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_requirements_composer 4.0.4
ibm rational_doors_next_generation 6.0.0
ibm rational_requirements_composer 4.0.2
ibm rational_doors_next_generation 5.0
ibm rational_requirements_composer 4.0.1
ibm rational_requirements_composer 4.0.3
ibm rational_requirements_composer 4.0.7
ibm rational_doors_next_generation 5.0.0
ibm rational_doors_next_generation 5.0.2
ibm rational_doors_next_generation 6.0.2
ibm rational_requirements_composer 4.0.5
ibm rational_requirements_composer 4.0.6
ibm rational_doors_next_generation 5.0.1
ibm rational_doors_next_generation 6.0.1
CVE-2016-6056 LOW

IBM Call Center for Commerce 9.3 and 9.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 2000442.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm call_center_for_commerce 9.3
ibm call_center_for_commerce 9.4
CVE-2016-6059 HIGH

IBM InfoSphere Information Server is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm infosphere_information_server 11.3
ibm infosphere_datastage 11.3
ibm infosphere_datastage 11.3.1
ibm infosphere_information_server 11.5
ibm infosphere_datastage 11.5
ibm infosphere_information_server 11.3.1
ibm infosphere_information_server_on_cloud 11.5
CVE-2016-6060 MEDIUM

An undisclosed vulnerability in IBM Rational DOORS Next Generation 4.0, 5.0, and 6.0 could allow a JazzGuest user to see project names. IBM Reference #: 1995547.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_requirements_composer 4.0.4
ibm rational_doors_next_generation 6.0.0
ibm rational_requirements_composer 4.0.2
ibm rational_doors_next_generation 5.0
ibm rational_requirements_composer 4.0.1
ibm rational_requirements_composer 4.0.3
ibm rational_requirements_composer 4.0.7
ibm rational_doors_next_generation 5.0.0
ibm rational_doors_next_generation 5.0.2
ibm rational_doors_next_generation 6.0.2
ibm rational_requirements_composer 4.0.5
ibm rational_requirements_composer 4.0.6
ibm rational_doors_next_generation 5.0.1
ibm rational_doors_next_generation 6.0.1
CVE-2016-6061 LOW

IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_collaborative_lifecycle_management 6.0.2
ibm rational_collaborative_lifecycle_management 4.0.6
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_collaborative_lifecycle_management 4.0.1
ibm rational_collaborative_lifecycle_management 4.0.5
ibm rational_collaborative_lifecycle_management 4.0.7
ibm rational_collaborative_lifecycle_management 5.0.0
ibm rational_collaborative_lifecycle_management 4.0.3
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_collaborative_lifecycle_management 4.0.0
ibm rational_collaborative_lifecycle_management 4.0.2
ibm rational_collaborative_lifecycle_management 6.0.0
ibm rational_collaborative_lifecycle_management 4.0.4
CVE-2016-6062 MEDIUM

IBM Resilient v26.0, v26.1, and v26.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference#: 213457065.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm resilient 26.0
ibm resilient 26.1
ibm resilient 26.2
CVE-2016-6065 HIGH

IBM Security Guardium Database Activity Monitor appliance could allow a local user to inject commands that would be executed as root.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-78,

Products Affected

Vendor Product Version
ibm security_guardium 9.0
ibm security_guardium 10.0.1
ibm security_guardium 10.0
ibm security_guardium 9.1
ibm security_guardium 8.2
ibm security_guardium 10.1
ibm security_guardium 10.1.2
ibm security_guardium 9.5
CVE-2016-6068 MEDIUM

IBM UrbanCode Deploy could allow an authenticated user with access to the REST endpoints to access API and CLI getResource secured role properties.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm urbancode_deploy 6.1.0.3
ibm urbancode_deploy 6.2.2
ibm urbancode_deploy 6.0.1.3
ibm urbancode_deploy 6.1.1.8
ibm urbancode_deploy 6.0.1.4
ibm urbancode_deploy 6.0.1.7
ibm urbancode_deploy 6.1.1.1
ibm urbancode_deploy 6.1.1.2
ibm urbancode_deploy 6.1.3.3
ibm urbancode_deploy 6.1.1
ibm urbancode_deploy 6.1.1.5
ibm urbancode_deploy 6.2.1
ibm urbancode_deploy 6.0.1.13
ibm urbancode_deploy 6.1.0.1
ibm urbancode_deploy 6.2.0.0
ibm urbancode_deploy 6.0.1.14
ibm urbancode_deploy 6.0.1.5
ibm urbancode_deploy 6.1.1.6
ibm urbancode_deploy 6.1.0.4
ibm urbancode_deploy 6.1.3.1
ibm urbancode_deploy 6.2.0.1
ibm urbancode_deploy 6.1.3.2
ibm urbancode_deploy 6.2.1.1
ibm urbancode_deploy 6.1
ibm urbancode_deploy 6.1.2
ibm urbancode_deploy 6.0.1.6
ibm urbancode_deploy 6.0.1.11
ibm urbancode_deploy 6.2.0.2
ibm urbancode_deploy 6.1.0.2
ibm urbancode_deploy 6.0.1.8
ibm urbancode_deploy 6.1.3
ibm urbancode_deploy 6.0.1.9
ibm urbancode_deploy 6.1.1.3
ibm urbancode_deploy 6.0.1.10
ibm urbancode_deploy 6.0.1
ibm urbancode_deploy 6.0.1.12
ibm urbancode_deploy 6.0.1.2
ibm urbancode_deploy 6.1.1.7
ibm urbancode_deploy 6.1.1.4
ibm urbancode_deploy 6.2.2.1
ibm urbancode_deploy 6.0.1.1
ibm urbancode_deploy 6.0
CVE-2016-6072 LOW

IBM Maximo Asset Management is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_asset_management_for_it -
ibm maximo_for_life_sciences -
ibm smartcloud_control_desk -
ibm tivoli_change_and_configuration_management_database -
ibm maximo_for_nuclear_power -
ibm maximo_for_aviation -
ibm tivoli_service_request_manager -
ibm maximo_for_transportation -
ibm maximo_asset_management 7.6.0.0
ibm maximo_for_oil_and_gas -
ibm tivoli_integration_composer -
ibm maximo_for_utilities -
CVE-2016-6077 MEDIUM

IBM Cognos Disclosure Management 10.2 could allow a malicious attacker to execute commands as a lower privileged user that opens a malicious document. IBM Reference #: 1991584.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm cognos_disclosure_management 10.2.4
ibm cognos_disclosure_management 10.2.3
ibm cognos_disclosure_management 10.2.1
ibm cognos_disclosure_management 10.2.2
ibm cognos_disclosure_management 10.2.6
ibm cognos_disclosure_management 10.2.0
ibm cognos_disclosure_management 10.2.5
CVE-2016-6079 HIGH

IBM AIX 5.3, 6.1, 7.1, and 7.2 contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges. IBM APARs: IV88658, IV87981, IV88419, IV87640, IV88053.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm aix 7.2
ibm vios 2.2.5.0
ibm vios 2.2.2.6
ibm vios 2.2.3.70
ibm vios 2.2.2.2
ibm aix 5.3
ibm vios 2.2.3.1
ibm vios 2.2.3.0
ibm vios 2.2.4.30
ibm vios 2.2.4.0
ibm vios 2.2.3.80
ibm vios 2.2.2.0
ibm vios 2.2.2.4
ibm vios 2.2.0.0
ibm vios 2.2.3.4
ibm vios 2.2.1.0
ibm vios 2.2.1.5
ibm vios 2.2.1.6
ibm vios 2.2.1.8
ibm vios 2.2.2.1
ibm vios 2.2.2.70
ibm vios 2.2.4.22
ibm vios 2.2.3.52
ibm aix 6.1
ibm vios 2.2.0.10
ibm vios 2.2.1.1
ibm vios 2.2.1.4
ibm vios 2.2.5.10
ibm vios 2.2.3.3
ibm aix 7.1
ibm vios 2.2.3.2
ibm vios 2.2.3.50
ibm vios 2.2.0.12
ibm vios 2.2.0.13
ibm vios 2.2.1.3
ibm vios 2.2.3.51
ibm vios 2.2.3.60
ibm vios 2.2.4.10
ibm vios 2.2.1.7
ibm vios 2.2.4.21
ibm vios 2.2.0.11
ibm vios 2.2.2.3
ibm vios 2.2.4.23
CVE-2016-6080 MEDIUM

The WebAdmin context for WebSphere Message Broker allows directory listings which could disclose sensitive information to the attacker.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_message_broker 8.0
CVE-2016-6082 HIGH

IBM BigFix Platform could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free race condition. An attacker could exploit this vulnerability to execute arbitrary code on the system.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-416,

Products Affected

Vendor Product Version
ibm bigfix_platform 9.2
ibm bigfix_platform 9.1
ibm bigfix_platform 9.5
ibm bigfix_platform 9.0
CVE-2016-6083 MEDIUM

IBM Tivoli Monitoring V6 could allow an unauthenticated user to access SOAP queries that could contain sensitive information. IBM X-Force ID: 117696.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm tivoli_monitoring 6.2.3
ibm tivoli_monitoring 6.2.2.4
ibm tivoli_monitoring 6.2.2.5
ibm tivoli_monitoring 6.2.2.8
ibm tivoli_monitoring 6.2.3.1
ibm tivoli_monitoring 6.2.3.5
ibm tivoli_monitoring 6.3.0.5
ibm tivoli_monitoring 6.2.3.3
ibm tivoli_monitoring 6.3.0
ibm tivoli_monitoring 6.3.0.7
ibm tivoli_monitoring 6.2.2.3
ibm tivoli_monitoring 6.2.2.7
ibm tivoli_monitoring 6.3.0.4
ibm tivoli_monitoring 6.2.3.0
ibm tivoli_monitoring 6.3.0.6
ibm tivoli_monitoring 6.3.0.1
ibm tivoli_monitoring 6.3.0.3
ibm tivoli_monitoring 6.2.3.2
ibm tivoli_monitoring 6.2.2.9
ibm tivoli_monitoring 6.2.3.4
ibm tivoli_monitoring 6.3.0.2
ibm tivoli_monitoring 6.2.2
ibm tivoli_monitoring 6.2.2.0
ibm tivoli_monitoring 6.2.2.1
ibm tivoli_monitoring 6.2.2.2
ibm tivoli_monitoring 6.2.2.6
CVE-2016-6084 LOW

IBM BigFix Platform could allow an attacker on the local network to crash the BES server using a specially crafted XMLSchema request.

CVSS 2.0

Severity: LOW

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm bigfix_platform 9.1
ibm bigfix_platform 9.0
CVE-2016-6085 LOW

IBM BigFix Platform could allow an attacker on the local network to crash the BES and relay servers.

CVSS 2.0

Severity: LOW

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm bigfix_platform 9.2
ibm bigfix_platform 9.1
ibm bigfix_platform 9.5
ibm bigfix_platform 9.0
CVE-2016-6087 MEDIUM

IBM Domino 8.5 and 9.0 could allow an attacker to steal credentials using multiple sessions and large amounts of data using Domino TLS Key Exchange validation. IBM X-Force ID: 117918.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 3.9 5.9

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm domino 8.5.1.1
ibm domino 8.5.1.5
ibm domino 8.5.1.2
ibm domino 8.5.3.5
ibm domino 8.5.2.1
ibm domino 9.0.1.5
ibm domino 9.0.1.1
ibm domino 8.5.3.0
ibm domino 8.5.3.1
ibm domino 9.0.1.2
ibm domino 9.0.1.4
ibm domino 9.0.1.3
ibm domino 9.0.1.0
ibm domino 8.5.3.4
ibm domino 8.5.2.0
ibm domino 8.5.2.3
ibm domino 9.0.0.0
ibm domino 8.5.3.2
ibm domino 8.5.3.6
ibm domino 8.5.2.2
ibm domino 8.5.1.4
ibm domino 8.5.3.3
ibm domino 9.0.1.7
ibm domino 8.5.2.4
ibm domino 8.5.1.0
ibm domino 9.0.1.6
ibm domino 8.5.1.3
CVE-2016-6089 LOW

IBM WebSphere MQ 9.0.0.1 and 9.0.2 could allow a local user to write to a file or delete files in a directory they should not have access to due to improper access controls. IBM X-Force ID: 117926.

CVSS 2.0

Severity: LOW

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm websphere_mq 9.0.1
ibm websphere_mq 9.0.0.0
CVE-2016-6090 HIGH

IBM WebSphere Commerce contains an unspecified vulnerability that could allow disclosure of user personal data, performing of unauthorized administrative operations, and potentially causing a denial of service.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 3.9 5.9

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_commerce *
ibm websphere_commerce 8.0.3.0
CVE-2016-6092 LOW

IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 stores user credentials in plain in clear text which can be read by a local user.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm tivoli_key_lifecycle_manager 2.0.1.4
ibm security_key_lifecycle_manager 2.5.0.5
ibm security_key_lifecycle_manager 2.5.0.0
ibm security_key_lifecycle_manager 2.5.0.1
ibm security_key_lifecycle_manager 2.5.0.3
ibm security_key_lifecycle_manager 2.5.0.7
ibm tivoli_key_lifecycle_manager 2.0.1.8
ibm tivoli_key_lifecycle_manager 2.0.1.7
ibm security_key_lifecycle_manager 2.5.0.6
ibm security_key_lifecycle_manager 2.5.0.2
ibm security_key_lifecycle_manager 2.5.0.4
ibm security_key_lifecycle_manager 2.6.0.1
ibm tivoli_key_lifecycle_manager 2.0.1.1
ibm tivoli_key_lifecycle_manager 2.0.1
ibm tivoli_key_lifecycle_manager 2.0.1.6
ibm tivoli_key_lifecycle_manager 2.0.1.2
ibm security_key_lifecycle_manager 2.6.0.0
ibm tivoli_key_lifecycle_manager 2.0.1.3
ibm tivoli_key_lifecycle_manager 2.0.1.5
ibm security_key_lifecycle_manager 2.6.0.2
CVE-2016-6093 MEDIUM

IBM Tivoli Key Lifecycle Manager does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm tivoli_key_lifecycle_manager 2.0.1.4
ibm security_key_lifecycle_manager 2.5.0.5
ibm security_key_lifecycle_manager 2.5.0.0
ibm security_key_lifecycle_manager 2.5.0.1
ibm security_key_lifecycle_manager 2.5.0.3
ibm security_key_lifecycle_manager 2.5.0.7
ibm tivoli_key_lifecycle_manager 2.0.1.8
ibm tivoli_key_lifecycle_manager 2.0.1.7
ibm security_key_lifecycle_manager 2.5.0.6
ibm security_key_lifecycle_manager 2.5.0.2
ibm security_key_lifecycle_manager 2.5.0.4
ibm security_key_lifecycle_manager 2.6.0.1
ibm tivoli_key_lifecycle_manager 2.0.1.1
ibm tivoli_key_lifecycle_manager 2.0.1
ibm tivoli_key_lifecycle_manager 2.0.1.6
ibm tivoli_key_lifecycle_manager 2.0.1.2
ibm security_key_lifecycle_manager 2.6.0.0
ibm tivoli_key_lifecycle_manager 2.0.1.3
ibm tivoli_key_lifecycle_manager 2.0.1.5
ibm security_key_lifecycle_manager 2.6.0.2
CVE-2016-6094 MEDIUM

IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 generates an error message that includes sensitive information about its environment, users, or associated data.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm tivoli_key_lifecycle_manager 2.0.1.4
ibm security_key_lifecycle_manager 2.5.0.5
ibm security_key_lifecycle_manager 2.5.0.0
ibm security_key_lifecycle_manager 2.5.0.1
ibm security_key_lifecycle_manager 2.5.0.3
ibm security_key_lifecycle_manager 2.5.0.7
ibm tivoli_key_lifecycle_manager 2.0.1.8
ibm tivoli_key_lifecycle_manager 2.0.1.7
ibm security_key_lifecycle_manager 2.5.0.6
ibm security_key_lifecycle_manager 2.5.0.2
ibm security_key_lifecycle_manager 2.5.0.4
ibm security_key_lifecycle_manager 2.6.0.1
ibm tivoli_key_lifecycle_manager 2.0.1.1
ibm tivoli_key_lifecycle_manager 2.0.1
ibm tivoli_key_lifecycle_manager 2.0.1.6
ibm tivoli_key_lifecycle_manager 2.0.1.2
ibm security_key_lifecycle_manager 2.6.0.0
ibm tivoli_key_lifecycle_manager 2.0.1.3
ibm tivoli_key_lifecycle_manager 2.0.1.5
ibm security_key_lifecycle_manager 2.6.0.2
CVE-2016-6095 MEDIUM

IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm security_key_lifecycle_manager 2.5.0.5
ibm security_key_lifecycle_manager 2.5.0.0
ibm security_key_lifecycle_manager 2.5.0.1
ibm security_key_lifecycle_manager 2.5.0
ibm security_key_lifecycle_manager 2.5.0.3
ibm security_key_lifecycle_manager 2.6.0
ibm security_key_lifecycle_manager 2.5.0.7
ibm security_key_lifecycle_manager 2.5.0.6
ibm security_key_lifecycle_manager 2.5.0.2
ibm security_key_lifecycle_manager 2.5.0.4
ibm security_key_lifecycle_manager 2.6.0.1
ibm security_key_lifecycle_manager 2.6.0.2
CVE-2016-6096 MEDIUM

IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_key_lifecycle_manager 2.0.1.4
ibm security_key_lifecycle_manager 2.5.0.5
ibm security_key_lifecycle_manager 2.5.0.0
ibm security_key_lifecycle_manager 2.5.0.1
ibm security_key_lifecycle_manager 2.5.0.3
ibm security_key_lifecycle_manager 2.5.0.7
ibm tivoli_key_lifecycle_manager 2.0.1.8
ibm tivoli_key_lifecycle_manager 2.0.1.7
ibm security_key_lifecycle_manager 2.5.0.6
ibm security_key_lifecycle_manager 2.5.0.2
ibm security_key_lifecycle_manager 2.5.0.4
ibm security_key_lifecycle_manager 2.6.0.1
ibm tivoli_key_lifecycle_manager 2.0.1.1
ibm tivoli_key_lifecycle_manager 2.0.1
ibm tivoli_key_lifecycle_manager 2.0.1.6
ibm tivoli_key_lifecycle_manager 2.0.1.2
ibm security_key_lifecycle_manager 2.6.0.0
ibm tivoli_key_lifecycle_manager 2.0.1.3
ibm tivoli_key_lifecycle_manager 2.0.1.5
ibm security_key_lifecycle_manager 2.6.0.2
CVE-2016-6097 LOW

IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 allows web pages to be stored locally which can be read by another user on the system.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm tivoli_key_lifecycle_manager 2.0.1.4
ibm security_key_lifecycle_manager 2.5.0.5
ibm security_key_lifecycle_manager 2.5.0.0
ibm security_key_lifecycle_manager 2.5.0.1
ibm security_key_lifecycle_manager 2.5.0.3
ibm security_key_lifecycle_manager 2.5.0.7
ibm tivoli_key_lifecycle_manager 2.0.1.8
ibm tivoli_key_lifecycle_manager 2.0.1.7
ibm security_key_lifecycle_manager 2.5.0.6
ibm security_key_lifecycle_manager 2.5.0.2
ibm security_key_lifecycle_manager 2.5.0.4
ibm security_key_lifecycle_manager 2.6.0.1
ibm tivoli_key_lifecycle_manager 2.0.1.1
ibm tivoli_key_lifecycle_manager 2.0.1
ibm tivoli_key_lifecycle_manager 2.0.1.6
ibm tivoli_key_lifecycle_manager 2.0.1.2
ibm security_key_lifecycle_manager 2.6.0.0
ibm tivoli_key_lifecycle_manager 2.0.1.3
ibm tivoli_key_lifecycle_manager 2.0.1.5
ibm security_key_lifecycle_manager 2.6.0.2
CVE-2016-6098 MEDIUM

IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm tivoli_key_lifecycle_manager 2.0.1.4
ibm security_key_lifecycle_manager 2.5.0.5
ibm security_key_lifecycle_manager 2.5.0.0
ibm security_key_lifecycle_manager 2.5.0.1
ibm security_key_lifecycle_manager 2.5.0.3
ibm security_key_lifecycle_manager 2.5.0.7
ibm tivoli_key_lifecycle_manager 2.0.1.8
ibm tivoli_key_lifecycle_manager 2.0.1.7
ibm security_key_lifecycle_manager 2.5.0.6
ibm security_key_lifecycle_manager 2.5.0.2
ibm security_key_lifecycle_manager 2.5.0.4
ibm security_key_lifecycle_manager 2.6.0.1
ibm tivoli_key_lifecycle_manager 2.0.1.1
ibm tivoli_key_lifecycle_manager 2.0.1
ibm tivoli_key_lifecycle_manager 2.0.1.6
ibm tivoli_key_lifecycle_manager 2.0.1.2
ibm security_key_lifecycle_manager 2.6.0.0
ibm tivoli_key_lifecycle_manager 2.0.1.3
ibm tivoli_key_lifecycle_manager 2.0.1.5
ibm security_key_lifecycle_manager 2.6.0.2
CVE-2016-6099 MEDIUM

IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_key_lifecycle_manager 2.5.0.5
ibm security_key_lifecycle_manager 2.5.0.0
ibm security_key_lifecycle_manager 2.5.0.1
ibm security_key_lifecycle_manager 2.5.0
ibm security_key_lifecycle_manager 2.5.0.3
ibm security_key_lifecycle_manager 2.6.0
ibm security_key_lifecycle_manager 2.5.0.7
ibm security_key_lifecycle_manager 2.5.0.6
ibm security_key_lifecycle_manager 2.5.0.2
ibm security_key_lifecycle_manager 2.5.0.4
ibm security_key_lifecycle_manager 2.6.0.1
ibm security_key_lifecycle_manager 2.6.0.2
CVE-2016-6100 MEDIUM

IBM Disposal and Governance Management for IT and IBM Global Retention Policy and Schedule Management, components of IBM Atlas Policy Suite 6.0.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM Reference #: 2000771.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm disposal_and_governance_management_for_it 6.0.3.1
ibm disposal_and_governance_management_for_it 6.0.1.1
ibm disposal_and_governance_management_for_it 6.0.1.7
ibm disposal_and_governance_management_for_it 6.0.1.0
ibm global_retention_policy_and_schedule_management 6.0.2
ibm global_retention_policy_and_schedule_management 6.0.1.6
ibm global_retention_policy_and_schedule_management 6.0.3.1
ibm global_retention_policy_and_schedule_management 6.0.1.1
ibm global_retention_policy_and_schedule_management 6.0.3.4
ibm disposal_and_governance_management_for_it 6.0.1.5
ibm disposal_and_governance_management_for_it 6.0.1.2
ibm global_retention_policy_and_schedule_management 6.0.3
ibm global_retention_policy_and_schedule_management 6.0.1.0
ibm global_retention_policy_and_schedule_management 6.0.1.5
ibm disposal_and_governance_management_for_it 6.0.1.4
ibm disposal_and_governance_management_for_it 6.0.3
ibm disposal_and_governance_management_for_it 6.0.3.2
ibm disposal_and_governance_management_for_it 6.0
ibm global_retention_policy_and_schedule_management 6.0.1.7
ibm global_retention_policy_and_schedule_management 6.0
ibm disposal_and_governance_management_for_it 6.0.1.6
ibm global_retention_policy_and_schedule_management 6.0.1.3
ibm global_retention_policy_and_schedule_management 6.0.3.3
ibm disposal_and_governance_management_for_it 6.0.3.3
ibm disposal_and_governance_management_for_it 6.0.2
ibm global_retention_policy_and_schedule_management 6.0.3.2
ibm global_retention_policy_and_schedule_management 6.0.1.4
ibm disposal_and_governance_management_for_it 6.0.1.3
ibm disposal_and_governance_management_for_it 6.0.3.4
ibm global_retention_policy_and_schedule_management 6.0.1.2
CVE-2016-6102 MEDIUM

IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM Reference #: 2000359.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_key_lifecycle_manager 2.5.0.5
ibm security_key_lifecycle_manager 2.5.0.0
ibm security_key_lifecycle_manager 2.5.0.1
ibm security_key_lifecycle_manager 2.5.0
ibm security_key_lifecycle_manager 2.5.0.3
ibm security_key_lifecycle_manager 2.6.0
ibm security_key_lifecycle_manager 2.5.0.7
ibm security_key_lifecycle_manager 2.5.0.6
ibm security_key_lifecycle_manager 2.5.0.2
ibm security_key_lifecycle_manager 2.5.0.4
ibm security_key_lifecycle_manager 2.6.0.1
ibm security_key_lifecycle_manager 2.6.0.2
CVE-2016-6103 MEDIUM

IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm security_key_lifecycle_manager 2.5.0.5
ibm security_key_lifecycle_manager 2.5.0.0
ibm security_key_lifecycle_manager 2.5.0.1
ibm security_key_lifecycle_manager 2.5.0
ibm security_key_lifecycle_manager 2.5.0.3
ibm security_key_lifecycle_manager 2.6.0
ibm security_key_lifecycle_manager 2.5.0.7
ibm security_key_lifecycle_manager 2.5.0.6
ibm security_key_lifecycle_manager 2.5.0.2
ibm security_key_lifecycle_manager 2.5.0.4
ibm security_key_lifecycle_manager 2.6.0.1
ibm security_key_lifecycle_manager 2.6.0.2
CVE-2016-6104 MEDIUM

IBM Tivoli Key Lifecycle Manager 2.5, and 2.6 could allow a remote attacker to upload arbitrary files, caused by the improper validation of file extensions, which could allow the attacker to execute arbitrary code on the vulnerable system.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-434,

Products Affected

Vendor Product Version
ibm security_key_lifecycle_manager 2.5.0.5
ibm security_key_lifecycle_manager 2.5.0.0
ibm security_key_lifecycle_manager 2.5.0.1
ibm security_key_lifecycle_manager 2.5.0
ibm security_key_lifecycle_manager 2.5.0.3
ibm security_key_lifecycle_manager 2.6.0
ibm security_key_lifecycle_manager 2.5.0.7
ibm security_key_lifecycle_manager 2.5.0.6
ibm security_key_lifecycle_manager 2.5.0.2
ibm security_key_lifecycle_manager 2.5.0.4
ibm security_key_lifecycle_manager 2.6.0.1
ibm security_key_lifecycle_manager 2.6.0.2
CVE-2016-6105 MEDIUM

IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 do not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm security_key_lifecycle_manager 2.5.0.5
ibm security_key_lifecycle_manager 2.5.0.0
ibm security_key_lifecycle_manager 2.5.0.1
ibm security_key_lifecycle_manager 2.5.0
ibm security_key_lifecycle_manager 2.5.0.3
ibm security_key_lifecycle_manager 2.6.0
ibm security_key_lifecycle_manager 2.5.0.7
ibm security_key_lifecycle_manager 2.5.0.6
ibm security_key_lifecycle_manager 2.5.0.2
ibm security_key_lifecycle_manager 2.5.0.4
ibm security_key_lifecycle_manager 2.6.0.1
ibm security_key_lifecycle_manager 2.6.0.2
CVE-2016-6110 LOW

IBM Tivoli Storage Manager discloses unencrypted login credentials to Vmware vCenter that could be obtained by a local user.

CVSS 2.0

Severity: LOW

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware *
ibm tivoli_storage_manager *
ibm tivoli_storage_manager 7.1.0.0
ibm tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware 7.1.0.0
CVE-2016-6111 HIGH

IBM Curam Social Program Management 6.0 and 7.0 are vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM Reference #: 2000833.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm curam_social_program_management 6.1.0.2
ibm curam_social_program_management 6.0.4.8
ibm curam_social_program_management 6.0.5.9
ibm curam_social_program_management 6.1.0.1
ibm curam_social_program_management 6.2.0.3
ibm curam_social_program_management 5.2
ibm curam_social_program_management 6.0.4.0
ibm curam_social_program_management 6.0.5.5
ibm curam_social_program_management 6.2.0.0
ibm curam_social_program_management 6.0.5.2
ibm curam_social_program_management 6.0.5.1
ibm curam_social_program_management 6.2.0.2
ibm curam_social_program_management 6.1.1.2
ibm curam_social_program_management 6.0.5.3
ibm curam_social_program_management 6.2.0.1
ibm curam_social_program_management 6.0.4.5
ibm curam_social_program_management 6.0.4.7
ibm curam_social_program_management 6.0
ibm curam_social_program_management 6.0.4.3
ibm curam_social_program_management 6.0.5.4
ibm curam_social_program_management 6.0.4.4
ibm curam_social_program_management 6.1.0.3
ibm curam_social_program_management 6.0.5
ibm curam_social_program_management 6.0.0
ibm curam_social_program_management 6.0.4.1
ibm curam_social_program_management 6.0.5.0
ibm curam_social_program_management 6.1.1.0
ibm curam_social_program_management 6.1.1.3
ibm curam_social_program_management 6.0.5.8
ibm curam_social_program_management 6.0.5.7
ibm curam_social_program_management 6.0.5.6
ibm curam_social_program_management 6.1.0.0
ibm curam_social_program_management 6.0.4.2
ibm curam_social_program_management 6.0.4.6
ibm curam_social_program_management 6.1.1.1
ibm curam_social_program_management 7.0.0.0
CVE-2016-6112 MEDIUM

IBM Distributed Marketing and Marketing Platform 8.6, 9.0, 9.1, and 10.0 could allow an authenticated user to escalate their privileges and gain administrative permissions over the web application. IBM X-Force ID: 118282.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm distributed_marketing 9.1.0.0
ibm marketing_operations 10.0.0.0
ibm distributed_marketing 10.0.0.0
ibm marketing_platform 10.0
ibm distributed_marketing 9.0.0.0
ibm marketing_operations 8.6.0.0
ibm marketing_operations 9.1.0.0
ibm marketing_platform 9.0.0.0
ibm distributed_marketing 8.6.0.0
ibm marketing_platform 8.6.0.0
ibm marketing_platform 9.1.2.0
ibm marketing_platform 9.1.0.0
ibm marketing_operations 9.0.0.0
CVE-2016-6113 MEDIUM

IBM Verse is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm inotes 8.5.2.1
ibm domino 8.5.1.5
ibm domino 8.5.1.2
ibm domino 8.5.2.1
ibm domino 9.0.1.1
ibm domino 8.5.3.0
ibm domino 8.5.3.1
ibm domino 9.0.1.4
ibm domino 9.0.1.0
ibm domino 8.5.3.4
ibm inotes 8.5.3.4
ibm inotes 8.5.3.1
ibm inotes 8.5.1.4
ibm domino 8.5.2.3
ibm inotes 8.5.3.3
ibm inotes 8.5.3.5
ibm domino 8.5.3.6
ibm domino 8.5.1.4
ibm inotes 8.5.2.0
ibm inotes 8.5.3.6
ibm inotes 8.5.2.2
ibm domino 8.5.1.0
ibm inotes 8.5.1.0
ibm inotes 9.0.1.5
ibm domino 8.5.1.3
ibm inotes 8.5.1.3
ibm domino 8.5.1.1
ibm inotes 8.5.2.3
ibm domino 8.5.3.5
ibm domino 9.0.1.5
ibm inotes 9.0.1.0
ibm inotes 8.5.3.2
ibm domino 9.0.1.2
ibm domino 9.0.1.3
ibm inotes 9.0.1.3
ibm inotes 9.0.1.6
ibm domino 8.5.2.0
ibm inotes 8.5.3.0
ibm domino 9.0.0.0
ibm inotes 9.0.1.1
ibm domino 8.5.3.2
ibm inotes 9.0.0.0
ibm inotes 9.0.1.2
ibm domino 8.5.2.2
ibm domino 8.5.3.3
ibm inotes 9.0.1.4
ibm domino 8.5.2.4
ibm inotes 8.5.1.1
ibm inotes 8.5.1.5
ibm domino 9.0.1.6
ibm inotes 8.5.1.2
CVE-2016-6114 LOW

IBM Emptoris Sourcing 9.5.x through 10.1.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 118352.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm emptoris_sourcing 10.0.1
ibm emptoris_sourcing 10.0.2
ibm emptoris_sourcing 10.0.4
ibm emptoris_sourcing 10.1.0
ibm emptoris_sourcing 10.1.1
ibm emptoris_sourcing 9.5
ibm emptoris_sourcing 10.0.0
CVE-2016-6115 HIGH

IBM General Parallel File System is vulnerable to a buffer overflow. A remote authenticated attacker could overflow a buffer and execute arbitrary code on the system with root privileges or cause the server to crash.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm spectrum_scale 4.2.0.2
ibm spectrum_scale 4.1.0.0
ibm spectrum_scale 4.1.1.6
ibm spectrum_scale 4.2.0.0
ibm general_parallel_file_system 4.1.0.2
ibm general_parallel_file_system 4.1.0.0
ibm general_parallel_file_system 4.1.0.8
ibm general_parallel_file_system 4.1.0.1
ibm spectrum_scale 4.1.1.7
ibm spectrum_scale 4.2.1
ibm general_parallel_file_system 4.1.0.3
ibm spectrum_scale 4.1.1.3
ibm spectrum_scale 4.1.1.1
ibm spectrum_scale 4.1.1.8
ibm general_parallel_file_system 4.1.0.4
ibm spectrum_scale 4.1.1.10
ibm spectrum_scale 4.1.1.4
ibm spectrum_scale 4.1.1.5
ibm general_parallel_file_system 4.1.0.7
ibm spectrum_scale 4.2.2.0
ibm spectrum_scale 4.2.0.3
ibm spectrum_scale 4.1.1.0
ibm spectrum_scale 4.1.1.2
ibm spectrum_scale 4.1.1.9
ibm general_parallel_file_system 4.1.0.6
ibm general_parallel_file_system 4.1.0.5
ibm spectrum_scale 4.2.0.1
CVE-2016-6116 MEDIUM

IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_key_lifecycle_manager 2.5.0.5
ibm security_key_lifecycle_manager 2.5.0.0
ibm security_key_lifecycle_manager 2.5.0.1
ibm security_key_lifecycle_manager 2.5.0
ibm security_key_lifecycle_manager 2.5.0.3
ibm security_key_lifecycle_manager 2.6.0
ibm security_key_lifecycle_manager 2.5.0.7
ibm security_key_lifecycle_manager 2.5.0.6
ibm security_key_lifecycle_manager 2.5.0.2
ibm security_key_lifecycle_manager 2.5.0.4
ibm security_key_lifecycle_manager 2.6.0.1
ibm security_key_lifecycle_manager 2.6.0.2
CVE-2016-6117 MEDIUM

IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 can be deployed with active debugging code that can disclose sensitive information.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_key_lifecycle_manager 2.5.0.5
ibm security_key_lifecycle_manager 2.5.0.0
ibm security_key_lifecycle_manager 2.5.0.1
ibm security_key_lifecycle_manager 2.5.0
ibm security_key_lifecycle_manager 2.5.0.3
ibm security_key_lifecycle_manager 2.6.0
ibm security_key_lifecycle_manager 2.5.0.7
ibm security_key_lifecycle_manager 2.5.0.6
ibm security_key_lifecycle_manager 2.5.0.2
ibm security_key_lifecycle_manager 2.5.0.4
ibm security_key_lifecycle_manager 2.6.0.1
ibm security_key_lifecycle_manager 2.6.0.2
CVE-2016-6118 LOW

IBM Emptoris Supplier Lifecycle Management 10.1.0.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 118356.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm emptoris_strategic_supply_management 10.1.1.1
ibm emptoris_strategic_supply_management 10.1.1.9
ibm emptoris_strategic_supply_management 10.1.1.3
ibm emptoris_strategic_supply_management 10.1.1.5
ibm emptoris_strategic_supply_management 10.1.1.0
ibm emptoris_strategic_supply_management 10.1.1.2
ibm emptoris_strategic_supply_management 10.1.1.6
ibm emptoris_strategic_supply_management 10.1.1.7
ibm emptoris_strategic_supply_management 10.1.1.11
ibm emptoris_strategic_supply_management 10.1.1.8
ibm emptoris_strategic_supply_management 10.1.1.4
ibm emptoris_strategic_supply_management 10.1.1.10
CVE-2016-6121 LOW

IBM Emptoris Supplier Lifecycle Management 10.0.x and 10.1.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 118383.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm emptoris_strategic_supply_management 10.0.2.5
ibm emptoris_strategic_supply_management 10.0.0.0
ibm emptoris_strategic_supply_management 10.1.0.1
ibm emptoris_strategic_supply_management 10.1.1.1
ibm emptoris_strategic_supply_management 10.0.2.9
ibm emptoris_strategic_supply_management 10.1.1.9
ibm emptoris_strategic_supply_management 10.0.2.4
ibm emptoris_strategic_supply_management 10.1.0.3
ibm emptoris_strategic_supply_management 10.1.1.3
ibm emptoris_strategic_supply_management 10.0.2.6
ibm emptoris_strategic_supply_management 10.1.1.0
ibm emptoris_supplier_lifecycle_management 10.0.0.2
ibm emptoris_strategic_supply_management 10.0.1.2
ibm emptoris_supplier_lifecycle_management 10.0.1.0
ibm emptoris_strategic_supply_management 10.0.1.4
ibm emptoris_strategic_supply_management 10.1.1.6
ibm emptoris_strategic_supply_management 10.1.1.7
ibm emptoris_strategic_supply_management 10.0.2.11
ibm emptoris_strategic_supply_management 10.0.2.3
ibm emptoris_supplier_lifecycle_management 10.0.2.0
ibm emptoris_strategic_supply_management 10.0.2.8
ibm emptoris_strategic_supply_management 10.0.2.13
ibm emptoris_supplier_lifecycle_management 10.0.0.3
ibm emptoris_strategic_supply_management 10.0.2.14
ibm emptoris_strategic_supply_management 10.0.2.15
ibm emptoris_supplier_lifecycle_management 10.0.1.2
ibm emptoris_strategic_supply_management 10.1.0.9
ibm emptoris_strategic_supply_management 10.0.0.2
ibm emptoris_strategic_supply_management 10.0.4.0
ibm emptoris_strategic_supply_management 10.1.0.4
ibm emptoris_supplier_lifecycle_management 10.0.2.2
ibm emptoris_strategic_supply_management 10.1.0.7
ibm emptoris_strategic_supply_management 10.1.0.10
ibm emptoris_strategic_supply_management 10.0.2.17
ibm emptoris_strategic_supply_management 10.1.1.2
ibm emptoris_strategic_supply_management 10.0.2.10
ibm emptoris_strategic_supply_management 10.1.0.6
ibm emptoris_strategic_supply_management 10.0.1.1
ibm emptoris_strategic_supply_management 10.0.2.16
ibm emptoris_strategic_supply_management 10.1.1.10
ibm emptoris_supplier_lifecycle_management 10.0.0.1
ibm emptoris_strategic_supply_management 10.0.2.0
ibm emptoris_strategic_supply_management 10.0.2.2
ibm emptoris_strategic_supply_management 10.1.0.8
ibm emptoris_strategic_supply_management 10.1.1.5
ibm emptoris_strategic_supply_management 10.0.1.3
ibm emptoris_strategic_supply_management 10.1.0.2
ibm emptoris_supplier_lifecycle_management 10.0.2.3
ibm emptoris_strategic_supply_management 10.0.0.3
ibm emptoris_supplier_lifecycle_management 10.0.2.7
ibm emptoris_strategic_supply_management 10.0.0.1
ibm emptoris_supplier_lifecycle_management 10.0.1.1
ibm emptoris_strategic_supply_management 10.1.0.5
ibm emptoris_strategic_supply_management 10.1.0.11
ibm emptoris_strategic_supply_management 10.0.1.0
ibm emptoris_strategic_supply_management 10.1.1.8
ibm emptoris_strategic_supply_management 10.0.2.1
ibm emptoris_supplier_lifecycle_management 10.0.0.0
ibm emptoris_strategic_supply_management 10.0.2.7
ibm emptoris_strategic_supply_management 10.1.0.0
ibm emptoris_strategic_supply_management 10.0.2.12
ibm emptoris_supplier_lifecycle_management 10.0.2.6
ibm emptoris_supplier_lifecycle_management 10.0.2.5
ibm emptoris_strategic_supply_management 10.1.1.4
CVE-2016-6122 MEDIUM

IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 discloses answers to security questions in a response to authenticated users.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm kenexa_lms_on_cloud 13.2.3
ibm kenexa_lms_on_cloud 13.2.2
ibm kenexa_lms_on_cloud 13.2.4
ibm kenexa_lms_on_cloud 13.2
ibm kenexa_lms_on_cloud 13.1
CVE-2016-6123 LOW

IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm kenexa_lms_on_cloud 13.2.3
ibm kenexa_lms_on_cloud 13.2.2
ibm kenexa_lms_on_cloud 13.2.4
ibm kenexa_lms_on_cloud 13.2
ibm kenexa_lms_on_cloud 13.1
CVE-2016-6124 MEDIUM

IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-434,

Products Affected

Vendor Product Version
ibm kenexa_lms_on_cloud 13.2.3
ibm kenexa_lms_on_cloud 13.2.2
ibm kenexa_lms_on_cloud 13.2.4
ibm kenexa_lms_on_cloud 13.2
ibm kenexa_lms_on_cloud 13.1
CVE-2016-6125 LOW

IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm kenexa_lms_on_cloud 13.2.3
ibm kenexa_lms_on_cloud 13.2.2
ibm kenexa_lms_on_cloud 13.2.4
ibm kenexa_lms_on_cloud 13.2
ibm kenexa_lms_on_cloud 13.1
CVE-2016-6126 MEDIUM

IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm kenexa_lms_on_cloud 13.2.3
ibm kenexa_lms_on_cloud 13.2.2
ibm kenexa_lms_on_cloud 13.2.4
ibm kenexa_lms_on_cloud 13.2
ibm kenexa_lms_on_cloud 13.1
CVE-2016-8232 MEDIUM

Document Object Model-(DOM) based cross-site scripting vulnerability in the Advanced Management Module (AMM) versions earlier than 66Z of Lenovo IBM BladeCenter HS22, HS22V, HS23, HS23E, HX5 allows an unauthenticated attacker with access to the AMM's IP address to send a crafted URL that could inject a malicious script to access a user's AMM data such as cookies or other session information.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm advanced_management_module_firmware -
CVE-2016-8911 LOW

IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim.

CVSS 2.0

Severity: LOW

Problem Type: CWE-254,

Products Affected

Vendor Product Version
ibm kenexa_lms_on_cloud 13.2.3
ibm kenexa_lms_on_cloud 13.2.2
ibm kenexa_lms_on_cloud 13.2.4
ibm kenexa_lms_on_cloud 13.2
ibm kenexa_lms_on_cloud 13.1
CVE-2016-8912 MEDIUM

IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 stores potentially sensitive information in in log files that could be read by an authenticated user.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-532,

Products Affected

Vendor Product Version
ibm kenexa_lms_on_cloud 13.2.3
ibm kenexa_lms_on_cloud 13.2.2
ibm kenexa_lms_on_cloud 13.2.4
ibm kenexa_lms_on_cloud 13.2
ibm kenexa_lms_on_cloud 13.1
CVE-2016-8913 MEDIUM

IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm kenexa_lms_on_cloud 13.2.3
ibm kenexa_lms_on_cloud 13.2.2
ibm kenexa_lms_on_cloud 13.2.4
ibm kenexa_lms_on_cloud 13.2
ibm kenexa_lms_on_cloud 13.1
CVE-2016-8915 MEDIUM

IBM WebSphere MQ 8.0 could allow an authenticated user with access to the queue manager and queue, to deny service to other channels running under the same process. IBM Reference #: 1998649.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm websphere_mq 8.0.0.0
ibm websphere_mq 8.0.0.5
ibm websphere_mq 8.0.0.1
ibm websphere_mq 8.0.0.3
ibm websphere_mq 8.0.0.4
ibm websphere_mq 8.0
ibm websphere_mq 8.0.0.2
CVE-2016-8916 LOW

IBM Tivoli Storage Manager 5.5, 6.1-6.4, and 7.1 stores password information in a log file that could be read by a local user when a set password command is issued. IBM X-Force ID: 118472.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager 7.1.3.1
ibm tivoli_storage_manager 6.4.2.200
ibm tivoli_storage_manager 6.4.2.500
ibm tivoli_storage_manager 7.1.1.2
ibm tivoli_storage_manager 7.1.4.1
ibm tivoli_storage_manager 7.1
ibm tivoli_storage_manager 7.1.5
ibm tivoli_storage_manager 7.1.3
ibm tivoli_storage_manager 7.1.6.3
ibm tivoli_storage_manager 7.1..5.100
ibm tivoli_storage_manager 7.1.3.2
ibm tivoli_storage_manager 7.1.0.3
ibm tivoli_storage_manager 7.1.4.2
ibm tivoli_storage_manager 7.1.0.1
ibm tivoli_storage_manager 7.1.3.100
ibm tivoli_storage_manager 7.1.4
ibm tivoli_storage_manager *
ibm tivoli_storage_manager 7.1.6
ibm tivoli_storage_manager 6.4.3.1
ibm tivoli_storage_manager 7.1.6.4
ibm tivoli_storage_manager 7.1.1.1
ibm tivoli_storage_manager 6.4.3
ibm tivoli_storage_manager 7.1.1.100
ibm tivoli_storage_manager 6.4.1.0
ibm tivoli_storage_manager 7.1.1
ibm tivoli_storage_manager 7.1.1.200
ibm tivoli_storage_manager 6.4.2.600
ibm tivoli_storage_manager 7.1.6.2
ibm tivoli_storage_manager 7.1.0.2
ibm tivoli_storage_manager 6.4.2.100
ibm tivoli_storage_manager 6.4.1
ibm tivoli_storage_manager 6.4.0.0
ibm tivoli_storage_manager 6.4.2
ibm tivoli_storage_manager 7.1.1.300
ibm tivoli_storage_manager 7.1.5.200
ibm tivoli_storage_manager 7.1.3.000
CVE-2016-8917 MEDIUM

IBM Sterling Order Management 9.2 - 9.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM Reference #: 2000943.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm sterling_selling_and_fulfillment_foundation 9.4.0
ibm sterling_selling_and_fulfillment_foundation 9.5.0
ibm sterling_selling_and_fulfillment_foundation 9.2.1
ibm sterling_selling_and_fulfillment_foundation 9.3.0
ibm sterling_selling_and_fulfillment_foundation 9.2.0
CVE-2016-8918 MEDIUM

IBM Integration Bus, under non default configurations, could allow a remote user to authenticate without providing valid credentials.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm integration_bus 10.0
CVE-2016-8919 HIGH

IBM WebSphere Application Server may be vulnerable to a denial of service, caused by allowing serialized objects from untrusted sources to run and cause the consumption of resources.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm websphere_application_server 9.0
ibm websphere_application_server 7.0
ibm websphere_application_server 8.0
ibm websphere_application_server 8.5.5
CVE-2016-8920 LOW

IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm kenexa_lms_on_cloud 13.2.3
ibm kenexa_lms_on_cloud 13.2.2
ibm kenexa_lms_on_cloud 13.2.4
ibm kenexa_lms_on_cloud 13.2
ibm kenexa_lms_on_cloud 13.1
CVE-2016-8921 MEDIUM

IBM FileNet WorkPlace XT could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-434,

Products Affected

Vendor Product Version
ibm filenet_workplace_xt 1.1.5
CVE-2016-8922 MEDIUM

Exphox WebRadar is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm web_content_manager_production_analytics 4.0
ibm websphere_portal 8.0
ibm websphere_portal 8.5
CVE-2016-8923 MEDIUM

IBM Curam Social Program Management 5.2, 6.0, and 7.0 contains a vulnerability that would allow an authorized user to obtain sensitive information from the profile of a higher privileged user that they should not have access to. IBM X-Force ID: 118536.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm curam_social_program_management 6.1.0.2
ibm curam_social_program_management 6.0.4.8
ibm curam_social_program_management 6.0.5.9
ibm curam_social_program_management 6.1.0.1
ibm curam_social_program_management 6.2.0.3
ibm curam_social_program_management 5.2
ibm curam_social_program_management 6.0.4.0
ibm curam_social_program_management 6.0.5.5
ibm curam_social_program_management 6.2.0.0
ibm curam_social_program_management 6.0.5.2
ibm curam_social_program_management 6.0.5.1
ibm curam_social_program_management 6.2.0.2
ibm curam_social_program_management 6.1.1.2
ibm curam_social_program_management 6.0.5.3
ibm curam_social_program_management 6.2.0.1
ibm curam_social_program_management 6.0.4.5
ibm curam_social_program_management 6.0.4.7
ibm curam_social_program_management 6.0
ibm curam_social_program_management 6.0.4.3
ibm curam_social_program_management 6.0.5.4
ibm curam_social_program_management 6.0.4.4
ibm curam_social_program_management 6.1.0.3
ibm curam_social_program_management 6.0.5
ibm curam_social_program_management 6.0.0
ibm curam_social_program_management 6.0.4.1
ibm curam_social_program_management 6.0.5.0
ibm curam_social_program_management 6.1.1.0
ibm curam_social_program_management 6.1.1.3
ibm curam_social_program_management 6.0.5.8
ibm curam_social_program_management 6.0.5.7
ibm curam_social_program_management 6.0.5.6
ibm curam_social_program_management 6.1.0.0
ibm curam_social_program_management 6.0.4.2
ibm curam_social_program_management 6.0.4.6
ibm curam_social_program_management 6.1.1.1
ibm curam_social_program_management 7.0.0.0
CVE-2016-8924 MEDIUM

IBM Maximo Asset Management 7.1, 7.5 and 7.6 could allow a remote attacker to hijack a user's session, caused by the failure to invalidate an existing session identifier. An attacker could exploit this vulnerability to gain access to another user's session. IBM X-Force ID: 118537.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm maximo_asset_management 7.6
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.5
CVE-2016-8925 MEDIUM

IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 could allow a remote attacker to include arbitrary files which could allow the attacker to read any file on the system. IBM X-Force ID: 118538.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm tivoli_application_dependency_discovery_manager 7.2.2.4
ibm tivoli_application_dependency_discovery_manager 7.3.0
ibm tivoli_application_dependency_discovery_manager 7.2.2.2
ibm tivoli_application_dependency_discovery_manager 7.2.2.1
ibm tivoli_application_dependency_discovery_manager 7.2.2.0
ibm tivoli_application_dependency_discovery_manager 7.3.0.3
ibm tivoli_application_dependency_discovery_manager 7.3.0.1
ibm tivoli_application_dependency_discovery_manager 7.2.2
ibm tivoli_application_dependency_discovery_manager 7.2.2.3
ibm tivoli_application_dependency_discovery_manager 7.3.0.2
ibm tivoli_application_dependency_discovery_manager 7.3.0.0
ibm tivoli_application_dependency_discovery_manager 7.2.2.5
CVE-2016-8926 MEDIUM

IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 could allow a remote attacker to read system files or data that is restricted to authorized users. IBM X-Force ID: 118539.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm tivoli_application_dependency_discovery_manager 7.2.2.4
ibm tivoli_application_dependency_discovery_manager 7.3.0
ibm tivoli_application_dependency_discovery_manager 7.2.2.2
ibm tivoli_application_dependency_discovery_manager 7.2.2.1
ibm tivoli_application_dependency_discovery_manager 7.2.2.0
ibm tivoli_application_dependency_discovery_manager 7.3.0.3
ibm tivoli_application_dependency_discovery_manager 7.3.0.1
ibm tivoli_application_dependency_discovery_manager 7.2.2
ibm tivoli_application_dependency_discovery_manager 7.2.2.3
ibm tivoli_application_dependency_discovery_manager 7.3.0.2
ibm tivoli_application_dependency_discovery_manager 7.3.0.0
ibm tivoli_application_dependency_discovery_manager 7.2.2.5
CVE-2016-8927 LOW

IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 118540.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_application_dependency_discovery_manager 7.2.2.4
ibm tivoli_application_dependency_discovery_manager 7.3.0
ibm tivoli_application_dependency_discovery_manager 7.2.2.2
ibm tivoli_application_dependency_discovery_manager 7.2.2.1
ibm tivoli_application_dependency_discovery_manager 7.2.2.0
ibm tivoli_application_dependency_discovery_manager 7.3.0.3
ibm tivoli_application_dependency_discovery_manager 7.3.0.1
ibm tivoli_application_dependency_discovery_manager 7.2.2
ibm tivoli_application_dependency_discovery_manager 7.2.2.3
ibm tivoli_application_dependency_discovery_manager 7.3.0.2
ibm tivoli_application_dependency_discovery_manager 7.3.0.0
ibm tivoli_application_dependency_discovery_manager 7.2.2.5
CVE-2016-8928 MEDIUM

IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm kenexa_lms 4.2.3
ibm kenexa_lms 4.2
ibm kenexa_lms 5.0
ibm kenexa_lms 5.1
ibm kenexa_lms 4.2.2
ibm kenexa_lms 4.1
ibm kenexa_lms 5.2
ibm kenexa_lms 4.2.4
CVE-2016-8929 MEDIUM

IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm kenexa_lms 4.2.3
ibm kenexa_lms 4.2
ibm kenexa_lms 5.0
ibm kenexa_lms 5.1
ibm kenexa_lms 4.2.2
ibm kenexa_lms 4.1
ibm kenexa_lms 5.2
ibm kenexa_lms 4.2.4
CVE-2016-8930 MEDIUM

IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm kenexa_lms 4.2.3
ibm kenexa_lms 4.2
ibm kenexa_lms 5.0
ibm kenexa_lms 5.1
ibm kenexa_lms 4.2.2
ibm kenexa_lms 4.1
ibm kenexa_lms 5.2
ibm kenexa_lms 4.2.4
CVE-2016-8931 MEDIUM

IBM Kenexa LMS on Cloud could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm kenexa_lms 4.2.3
ibm kenexa_lms 4.2
ibm kenexa_lms 5.0
ibm kenexa_lms 5.1
ibm kenexa_lms 4.2.2
ibm kenexa_lms 4.1
ibm kenexa_lms 5.2
ibm kenexa_lms 4.2.4
CVE-2016-8932 MEDIUM

IBM Kenexa LMS on Cloud could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm kenexa_lms 4.2.3
ibm kenexa_lms 4.2
ibm kenexa_lms 5.0
ibm kenexa_lms 5.1
ibm kenexa_lms 4.2.2
ibm kenexa_lms 4.1
ibm kenexa_lms 5.2
ibm kenexa_lms 4.2.4
CVE-2016-8933 MEDIUM

IBM Kenexa LMS on Cloud could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing dot dot sequences (/../) to view arbitrary files on the system.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm kenexa_lms 4.2.3
ibm kenexa_lms 4.2
ibm kenexa_lms 5.0
ibm kenexa_lms 5.1
ibm kenexa_lms 4.2.2
ibm kenexa_lms 4.1
ibm kenexa_lms 5.2
ibm kenexa_lms 4.2.4
CVE-2016-8934 LOW

IBM WebSphere Application Server is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_application_server 8.5.5.8
ibm websphere_application_server 9.0.0.2
ibm websphere_application_server 9.0.0.0
ibm websphere_application_server 8.5.5.0
ibm websphere_application_server 8.5.5.2
ibm websphere_application_server 8.5.5.9
ibm websphere_application_server 8.5.5.7
ibm websphere_application_server 8.5.5.6
ibm websphere_application_server 8.5.5.11
ibm websphere_application_server 8.5.5.10
ibm websphere_application_server 9.0.0.1
ibm websphere_application_server 8.5.5.3
ibm websphere_application_server 8.5.5.4
ibm websphere_application_server 8.5.5.5
ibm websphere_application_server 8.5.5.1
CVE-2016-8935 LOW

IBM Kenexa LMS on Cloud 13.1, 13.2, 13.2.2, 13.2.3, 13.2.4 and 14.0.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1999483.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm kenexa_lms 4.2.3
ibm kenexa_lms 4.2
ibm kenexa_lms 5.0
ibm kenexa_lms 4.2.2
ibm kenexa_lms 4.1
ibm kenexa_lms 4.2.4
CVE-2016-8936 MEDIUM

IBM Social Rendering Templates for Digital Data Connector is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm social_rendering_templates_for_digital_data_connector 1.0
CVE-2016-8937 MEDIUM

The IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) default authentication protocol is vulnerable to a brute force attack due to disclosing too much information during authentication. An attacker could gain user or administrative access to the TSM server. IBM X-Force ID: 118750.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager 7.1.3.1
ibm tivoli_storage_manager 6.3.2.2
ibm tivoli_storage_manager 6.3.6
ibm tivoli_storage_manager 6.3.3
ibm tivoli_storage_manager 6.1.1
ibm tivoli_storage_manager 7.1.3
ibm tivoli_storage_manager 6.1.5
ibm tivoli_storage_manager 6.2.4
ibm tivoli_storage_manager 7.1..5.100
ibm tivoli_storage_manager 7.1.3.2
ibm tivoli_storage_manager 6.2.3
ibm tivoli_storage_manager 7.1.0.3
ibm tivoli_storage_manager 7.1.4.2
ibm tivoli_storage_manager 7.1.4
ibm tivoli_storage_manager 7.1.6
ibm tivoli_storage_manager 7.1.7.100
ibm tivoli_storage_manager 7.1.1.1
ibm tivoli_storage_manager 6.4.3
ibm tivoli_storage_manager 7.1.1.100
ibm tivoli_storage_manager 7.1.1
ibm tivoli_storage_manager 6.4.2.600
ibm tivoli_storage_manager 6.3.1.2
ibm tivoli_storage_manager 6.3.0.15
ibm tivoli_storage_manager 6.4.1
ibm tivoli_storage_manager 6.4.2
ibm tivoli_storage_manager 6.1.3
ibm tivoli_storage_manager 7.1.1.300
ibm tivoli_storage_manager 7.1.5.200
ibm tivoli_storage_manager 7.1.3.000
ibm tivoli_storage_manager 7.1.7.200
ibm tivoli_storage_manager 6.1
ibm tivoli_storage_manager 6.2.1
ibm tivoli_storage_manager 6.1.0
ibm tivoli_storage_manager 6.3
ibm tivoli_storage_manager 6.4.2.200
ibm tivoli_storage_manager 6.4.2.500
ibm tivoli_storage_manager 7.1.1.2
ibm tivoli_storage_manager 6.3.1
ibm tivoli_storage_manager 6.1.5.5
ibm tivoli_storage_manager 6.1.2
ibm tivoli_storage_manager 7.1.4.1
ibm tivoli_storage_manager 7.1
ibm tivoli_storage_manager 7.1.5
ibm tivoli_storage_manager 8.1.1.100
ibm tivoli_storage_manager 7.1.7
ibm tivoli_storage_manager 6.3.4
ibm tivoli_storage_manager 7.1.0.1
ibm tivoli_storage_manager 7.1.3.100
ibm tivoli_storage_manager 6.4.3.1
ibm tivoli_storage_manager 6.3.5
ibm tivoli_storage_manager 6.3.0.17
ibm tivoli_storage_manager 6.1.5.6
ibm tivoli_storage_manager 6.4.1.0
ibm tivoli_storage_manager 7.1.1.200
ibm tivoli_storage_manager 8.1.0
ibm tivoli_storage_manager 6.2.0
ibm tivoli_storage_manager 6.3.0.5
ibm tivoli_storage_manager 6.3.6.100
ibm tivoli_storage_manager 7.1.0.2
ibm tivoli_storage_manager 6.4.2.100
ibm tivoli_storage_manager 6.3.5.1
ibm tivoli_storage_manager 6.1.4
ibm tivoli_storage_manager 8.1.1
ibm tivoli_storage_manager 6.2.2
ibm tivoli_storage_manager 6.1.5.4
CVE-2016-8938 HIGH

IBM UrbanCode Deploy could allow a user to execute code using a specially crafted file upload that would replace code on the server. This code could be executed on the UCD agent machines that host customer's production applications.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm urbancode_deploy 6.1.0.3
ibm urbancode_deploy 6.2.2
ibm urbancode_deploy 6.0.1.3
ibm urbancode_deploy 6.1.1.8
ibm urbancode_deploy 6.0.1.4
ibm urbancode_deploy 6.0.1.7
ibm urbancode_deploy 6.1.1.1
ibm urbancode_deploy 6.1.1.2
ibm urbancode_deploy 6.1.3.3
ibm urbancode_deploy 6.1.1
ibm urbancode_deploy 6.1.1.5
ibm urbancode_deploy 6.2.1
ibm urbancode_deploy 6.0.1.13
ibm urbancode_deploy 6.1.0.1
ibm urbancode_deploy 6.2.0.0
ibm urbancode_deploy 6.0.1.14
ibm urbancode_deploy 6.0.1.5
ibm urbancode_deploy 6.1.1.6
ibm urbancode_deploy 6.1.0.4
ibm urbancode_deploy 6.1.3.1
ibm urbancode_deploy 6.2.0.1
ibm urbancode_deploy 6.1.3.2
ibm urbancode_deploy 6.2.1.1
ibm urbancode_deploy 6.1
ibm urbancode_deploy 6.1.2
ibm urbancode_deploy 6.0.1.6
ibm urbancode_deploy 6.0.1.11
ibm urbancode_deploy 6.2.0.2
ibm urbancode_deploy 6.1.0.2
ibm urbancode_deploy 6.0.1.8
ibm urbancode_deploy 6.1.3
ibm urbancode_deploy 6.0.1.9
ibm urbancode_deploy 6.1.1.3
ibm urbancode_deploy 6.0.1.10
ibm urbancode_deploy 6.0.1
ibm urbancode_deploy 6.0.1.12
ibm urbancode_deploy 6.0.1.2
ibm urbancode_deploy 6.1.1.7
ibm urbancode_deploy 6.1.1.4
ibm urbancode_deploy 6.2.2.1
ibm urbancode_deploy 6.0.1.1
ibm urbancode_deploy 6.0
CVE-2016-8939 LOW

IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) clients/agents store password information in the Windows Registry in a manner which can be compromised. IBM X-Force ID: 118790.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager 7.1.3.1
ibm tivoli_storage_manager 6.3.2.2
ibm tivoli_storage_manager 6.3.6
ibm tivoli_storage_manager 6.3.3
ibm tivoli_storage_manager 6.1.1
ibm tivoli_storage_manager 7.1.3
ibm tivoli_storage_manager 6.1.5
ibm tivoli_storage_manager 6.2.4
ibm tivoli_storage_manager 7.1..5.100
ibm tivoli_storage_manager 7.1.3.2
ibm tivoli_storage_manager 6.2.3
ibm tivoli_storage_manager 7.1.0.3
ibm tivoli_storage_manager 7.1.4.2
ibm tivoli_storage_manager 7.1.4
ibm tivoli_storage_manager 7.1.6
ibm tivoli_storage_manager 7.1.7.100
ibm tivoli_storage_manager 7.1.1.1
ibm tivoli_storage_manager 6.4.3
ibm tivoli_storage_manager 7.1.1.100
ibm tivoli_storage_manager 7.1.1
ibm tivoli_storage_manager 6.4.2.600
ibm tivoli_storage_manager 6.3.1.2
ibm tivoli_storage_manager 6.3.0.15
ibm tivoli_storage_manager 6.4.1
ibm tivoli_storage_manager 6.4.2
ibm tivoli_storage_manager 6.1.3
ibm tivoli_storage_manager 7.1.1.300
ibm tivoli_storage_manager 7.1.5.200
ibm tivoli_storage_manager 7.1.3.000
ibm tivoli_storage_manager 7.1.7.200
ibm tivoli_storage_manager 6.1
ibm tivoli_storage_manager 6.2.1
ibm tivoli_storage_manager 6.1.0
ibm tivoli_storage_manager 6.3
ibm tivoli_storage_manager 6.4.2.200
ibm tivoli_storage_manager 6.4.2.500
ibm tivoli_storage_manager 7.1.1.2
ibm tivoli_storage_manager 6.3.1
ibm tivoli_storage_manager 6.1.5.5
ibm tivoli_storage_manager 6.1.2
ibm tivoli_storage_manager 7.1.4.1
ibm tivoli_storage_manager 7.1
ibm tivoli_storage_manager 7.1.5
ibm tivoli_storage_manager 8.1.1.100
ibm tivoli_storage_manager 7.1.7
ibm tivoli_storage_manager 6.3.4
ibm tivoli_storage_manager 7.1.0.1
ibm tivoli_storage_manager 7.1.3.100
ibm tivoli_storage_manager 6.4.3.1
ibm tivoli_storage_manager 6.3.5
ibm tivoli_storage_manager 6.3.0.17
ibm tivoli_storage_manager 6.1.5.6
ibm tivoli_storage_manager 6.4.1.0
ibm tivoli_storage_manager 7.1.1.200
ibm tivoli_storage_manager 8.1.0
ibm tivoli_storage_manager 6.2.0
ibm tivoli_storage_manager 6.3.0.5
ibm tivoli_storage_manager 6.3.6.100
ibm tivoli_storage_manager 7.1.0.2
ibm tivoli_storage_manager 6.4.2.100
ibm tivoli_storage_manager 6.3.5.1
ibm tivoli_storage_manager 6.1.4
ibm tivoli_storage_manager 8.1.1
ibm tivoli_storage_manager 6.2.2
ibm tivoli_storage_manager 6.1.5.4
CVE-2016-8940 MEDIUM

IBM Tivoli Storage Manager (IBM Spectrum Protect) 6.1, 6.2, 6.3, and 7.1 does not perform sufficient authority checking on SQL queries. As a result, an attacker is able to submit SQL queries that access database tables that are not intended for access or use by administrators. The access of these product specific database tables may allow access to passwords or other sensitive information for the product. IBM Reference #: 1998946.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager 7.1.3.1
ibm tivoli_storage_manager 6.3.2.2
ibm tivoli_storage_manager 6.3.6
ibm tivoli_storage_manager 6.3.3
ibm tivoli_storage_manager 6.1.1
ibm tivoli_storage_manager 7.1.3
ibm tivoli_storage_manager 6.1.5
ibm tivoli_storage_manager 6.2.4
ibm tivoli_storage_manager 7.1..5.100
ibm tivoli_storage_manager 7.1.3.2
ibm tivoli_storage_manager 6.2.3
ibm tivoli_storage_manager 7.1.0.3
ibm tivoli_storage_manager 7.1.4.2
ibm tivoli_storage_manager 7.1.4
ibm tivoli_storage_manager 7.1.6
ibm tivoli_storage_manager 7.1.1.1
ibm tivoli_storage_manager 7.1.1.100
ibm tivoli_storage_manager 7.1.1
ibm tivoli_storage_manager 6.3.1.2
ibm tivoli_storage_manager 6.3.0.15
ibm tivoli_storage_manager 6.1.3
ibm tivoli_storage_manager 7.1.1.300
ibm tivoli_storage_manager 7.1.5.200
ibm tivoli_storage_manager 7.1.3.000
ibm tivoli_storage_manager 6.1
ibm tivoli_storage_manager 6.2.1
ibm tivoli_storage_manager 6.1.0
ibm tivoli_storage_manager 6.3
ibm tivoli_storage_manager 7.1.1.2
ibm tivoli_storage_manager 6.3.1
ibm tivoli_storage_manager 6.1.5.5
ibm tivoli_storage_manager 6.1.2
ibm tivoli_storage_manager 7.1.4.1
ibm tivoli_storage_manager 7.1
ibm tivoli_storage_manager 7.1.5
ibm tivoli_storage_manager 7.1.7
ibm tivoli_storage_manager 6.3.4
ibm tivoli_storage_manager 7.1.0.1
ibm tivoli_storage_manager 7.1.3.100
ibm tivoli_storage_manager 6.3.5
ibm tivoli_storage_manager 6.3.0.17
ibm tivoli_storage_manager 6.1.5.6
ibm tivoli_storage_manager 7.1.1.200
ibm tivoli_storage_manager 6.2.0
ibm tivoli_storage_manager 6.3.0.5
ibm tivoli_storage_manager 7.1.0.2
ibm tivoli_storage_manager 6.3.5.1
ibm tivoli_storage_manager 6.1.4
ibm tivoli_storage_manager 6.2.2
ibm tivoli_storage_manager 6.1.5.4
CVE-2016-8941 MEDIUM

IBM Tivoli Storage Productivity Center is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm tivoli_storage_productivity_center 5.2.2.0
ibm spectrum_control 5.2.10
ibm tivoli_storage_productivity_center 5.2.4.0
ibm tivoli_storage_productivity_center 5.2.5.0
ibm spectrum_control 5.2.8
ibm tivoli_storage_productivity_center 5.2.4.1
ibm tivoli_storage_productivity_center 5.2.3.0
ibm tivoli_storage_productivity_center 5.2.7.1
ibm tivoli_storage_productivity_center 5.2.6.0
ibm tivoli_storage_productivity_center 5.2.0.0
ibm spectrum_control 5.2.11
ibm tivoli_storage_productivity_center 5.2.1.1
ibm spectrum_control 5.2.9
ibm tivoli_storage_productivity_center 5.2.1.0
ibm tivoli_storage_productivity_center 5.2.0
ibm tivoli_storage_productivity_center 5.2.5.1
ibm tivoli_storage_productivity_center 5.2.7.0
CVE-2016-8942 LOW

IBM Tivoli Storage Productivity Center could allow an authenticated user with intimate knowledge of the system to edit a limited set of properties on the server.

CVSS 2.0

Severity: LOW

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm tivoli_storage_productivity_center 5.2.2.0
ibm spectrum_control 5.2.10
ibm tivoli_storage_productivity_center 5.2.4.0
ibm tivoli_storage_productivity_center 5.2.5.0
ibm spectrum_control 5.2.8
ibm tivoli_storage_productivity_center 5.2.4.1
ibm tivoli_storage_productivity_center 5.2.3.0
ibm tivoli_storage_productivity_center 5.2.7.1
ibm tivoli_storage_productivity_center 5.2.6.0
ibm tivoli_storage_productivity_center 5.2.0.0
ibm spectrum_control 5.2.11
ibm tivoli_storage_productivity_center 5.2.1.1
ibm spectrum_control 5.2.9
ibm tivoli_storage_productivity_center 5.2.1.0
ibm tivoli_storage_productivity_center 5.2.0
ibm tivoli_storage_productivity_center 5.2.5.1
ibm tivoli_storage_productivity_center 5.2.4.1_+
ibm tivoli_storage_productivity_center 5.2.7.0
CVE-2016-8943 LOW

IBM Tivoli Storage Productivity Center is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_storage_productivity_center 5.2.2.0
ibm spectrum_control 5.2.10
ibm tivoli_storage_productivity_center 5.2.4.0
ibm tivoli_storage_productivity_center 5.2.5.0
ibm spectrum_control 5.2.8
ibm tivoli_storage_productivity_center 5.2.4.1
ibm tivoli_storage_productivity_center 5.2.3.0
ibm tivoli_storage_productivity_center 5.2.7.1
ibm tivoli_storage_productivity_center 5.2.6.0
ibm tivoli_storage_productivity_center 5.2.0.0
ibm spectrum_control 5.2.11
ibm tivoli_storage_productivity_center 5.2.1.1
ibm spectrum_control 5.2.9
ibm tivoli_storage_productivity_center 5.2.1.0
ibm tivoli_storage_productivity_center 5.2.0
ibm tivoli_storage_productivity_center 5.2.5.1
ibm tivoli_storage_productivity_center 5.2.4.1_+
ibm tivoli_storage_productivity_center 5.2.7.0
CVE-2016-8944 MEDIUM

IBM AIX 7.1 and 7.2 allows a local user to open a file with a specially crafted argument that would crash the system. IBM APARs: IV91488, IV91487, IV91456, IV90234.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm aix 7.2
ibm aix 7.1
CVE-2016-8946 LOW

IBM Emptoris Sourcing 9.5.x through 10.1.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 118833.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm emptoris_sourcing 10.0.1
ibm emptoris_sourcing 10.0.2
ibm emptoris_sourcing 10.0.4
ibm emptoris_sourcing 10.1.0
ibm emptoris_sourcing 10.1.1
ibm emptoris_sourcing 9.5
ibm emptoris_sourcing 10.0.0
CVE-2016-8947 MEDIUM

IBM Emptoris Sourcing 9.5.x through 10.1.x could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 118834

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-601,

Products Affected

Vendor Product Version
ibm emptoris_sourcing 10.0.1
ibm emptoris_sourcing 9.5.1.1
ibm emptoris_sourcing 10.0.2
ibm emptoris_sourcing 9.5.1.2
ibm emptoris_sourcing 10.0.4
ibm emptoris_sourcing 10.1.0
ibm emptoris_sourcing 10.1.1
ibm emptoris_sourcing 9.5
ibm emptoris_sourcing 9.5.1.3
ibm emptoris_sourcing 10.0.0
ibm emptoris_sourcing 9.5.0.1
CVE-2016-8948 LOW

IBM Emptoris Sourcing 9.5.x through 10.1.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 118835.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm emptoris_sourcing 10.0.1
ibm emptoris_sourcing 9.5.1.1
ibm emptoris_sourcing 10.0.2
ibm emptoris_sourcing 9.5.1.2
ibm emptoris_sourcing 10.0.4
ibm emptoris_sourcing 10.1.0
ibm emptoris_sourcing 10.1.1
ibm emptoris_sourcing 9.5
ibm emptoris_sourcing 9.5.1.3
ibm emptoris_sourcing 10.0.0
ibm emptoris_sourcing 9.5.0.1
CVE-2016-8949 MEDIUM

IBM Emptoris Supplier Lifecycle Management 10.0.x and 10.1.x could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 118836.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-601,

Products Affected

Vendor Product Version
ibm emptoris_strategic_supply_management 10.0.2.5
ibm emptoris_strategic_supply_management 10.0.0.0
ibm emptoris_strategic_supply_management 10.1.0.1
ibm emptoris_strategic_supply_management 10.1.1.1
ibm emptoris_strategic_supply_management 10.0.2.9
ibm emptoris_strategic_supply_management 10.1.1.9
ibm emptoris_strategic_supply_management 10.0.2.4
ibm emptoris_strategic_supply_management 10.1.0.3
ibm emptoris_strategic_supply_management 10.1.1.3
ibm emptoris_strategic_supply_management 10.0.2.6
ibm emptoris_strategic_supply_management 10.1.1.0
ibm emptoris_supplier_lifecycle_management 10.0.0.2
ibm emptoris_strategic_supply_management 10.0.1.2
ibm emptoris_supplier_lifecycle_management 10.0.1.0
ibm emptoris_strategic_supply_management 10.0.1.4
ibm emptoris_strategic_supply_management 10.1.1.6
ibm emptoris_strategic_supply_management 10.1.1.7
ibm emptoris_strategic_supply_management 10.0.2.11
ibm emptoris_strategic_supply_management 10.0.2.3
ibm emptoris_supplier_lifecycle_management 10.0.2.0
ibm emptoris_strategic_supply_management 10.0.2.8
ibm emptoris_strategic_supply_management 10.0.2.13
ibm emptoris_supplier_lifecycle_management 10.0.0.3
ibm emptoris_strategic_supply_management 10.0.2.14
ibm emptoris_strategic_supply_management 10.0.2.15
ibm emptoris_supplier_lifecycle_management 10.0.1.2
ibm emptoris_strategic_supply_management 10.1.0.9
ibm emptoris_strategic_supply_management 10.0.0.2
ibm emptoris_strategic_supply_management 10.0.4.0
ibm emptoris_strategic_supply_management 10.1.0.4
ibm emptoris_supplier_lifecycle_management 10.0.2.2
ibm emptoris_strategic_supply_management 10.1.0.7
ibm emptoris_strategic_supply_management 10.1.0.10
ibm emptoris_strategic_supply_management 10.0.2.17
ibm emptoris_strategic_supply_management 10.1.1.2
ibm emptoris_strategic_supply_management 10.0.2.10
ibm emptoris_strategic_supply_management 10.1.0.6
ibm emptoris_strategic_supply_management 10.0.1.1
ibm emptoris_strategic_supply_management 10.0.2.16
ibm emptoris_strategic_supply_management 10.1.1.10
ibm emptoris_supplier_lifecycle_management 10.0.0.1
ibm emptoris_strategic_supply_management 10.0.2.0
ibm emptoris_strategic_supply_management 10.0.2.2
ibm emptoris_strategic_supply_management 10.1.0.8
ibm emptoris_strategic_supply_management 10.1.1.5
ibm emptoris_strategic_supply_management 10.0.1.3
ibm emptoris_strategic_supply_management 10.1.0.2
ibm emptoris_supplier_lifecycle_management 10.0.2.3
ibm emptoris_strategic_supply_management 10.0.0.3
ibm emptoris_supplier_lifecycle_management 10.0.2.7
ibm emptoris_strategic_supply_management 10.0.0.1
ibm emptoris_supplier_lifecycle_management 10.0.1.1
ibm emptoris_strategic_supply_management 10.1.0.5
ibm emptoris_strategic_supply_management 10.1.0.11
ibm emptoris_strategic_supply_management 10.0.1.0
ibm emptoris_strategic_supply_management 10.1.1.8
ibm emptoris_strategic_supply_management 10.0.2.1
ibm emptoris_supplier_lifecycle_management 10.0.0.0
ibm emptoris_strategic_supply_management 10.0.2.7
ibm emptoris_strategic_supply_management 10.1.0.0
ibm emptoris_strategic_supply_management 10.0.2.12
ibm emptoris_supplier_lifecycle_management 10.0.2.6
ibm emptoris_supplier_lifecycle_management 10.0.2.5
ibm emptoris_strategic_supply_management 10.1.1.4
CVE-2016-8950 LOW

IBM Emptoris Sourcing 9.5.x through 10.1.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 118837.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm emptoris_sourcing 10.0.1
ibm emptoris_sourcing 9.5.1.1
ibm emptoris_sourcing 10.0.2
ibm emptoris_sourcing 9.5.1.2
ibm emptoris_sourcing 10.0.4
ibm emptoris_sourcing 10.1.0
ibm emptoris_sourcing 10.1.1
ibm emptoris_sourcing 9.5
ibm emptoris_sourcing 9.5.1.3
ibm emptoris_sourcing 10.0.0
ibm emptoris_sourcing 9.5.0.1
CVE-2016-8951 MEDIUM

IBM Emptoris Strategic Supply Management Platform 10.0.0.x through 10.1.1.x is vulnerable to a denial of service attack. An attacker can exploit a vulnerability in the authentication features that could log out users and flood user accounts with emails. IBM X-Force ID: 118838.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm emptoris_strategic_supply_management 10.0.2.5
ibm emptoris_strategic_supply_management 10.0.0.0
ibm emptoris_strategic_supply_management 10.1.0.1
ibm emptoris_strategic_supply_management 10.1.1.1
ibm emptoris_strategic_supply_management 10.0.2.9
ibm emptoris_strategic_supply_management 10.1.1.9
ibm emptoris_strategic_supply_management 10.0.2.4
ibm emptoris_strategic_supply_management 10.1.0.3
ibm emptoris_strategic_supply_management 10.1.1.3
ibm emptoris_strategic_supply_management 10.0.2.6
ibm emptoris_strategic_supply_management 10.1.1.0
ibm emptoris_strategic_supply_management 10.1.0.12
ibm emptoris_strategic_supply_management 10.0.1.2
ibm emptoris_strategic_supply_management 10.0.1.4
ibm emptoris_strategic_supply_management 10.1.1.6
ibm emptoris_strategic_supply_management 10.1.1.7
ibm emptoris_strategic_supply_management 10.0.2.11
ibm emptoris_strategic_supply_management 10.0.2.3
ibm emptoris_strategic_supply_management 10.0.2.8
ibm emptoris_strategic_supply_management 10.0.2.13
ibm emptoris_strategic_supply_management 10.0.2.14
ibm emptoris_strategic_supply_management 10.0.2.15
ibm emptoris_strategic_supply_management 10.1.0.9
ibm emptoris_strategic_supply_management 10.0.0.2
ibm emptoris_strategic_supply_management 10.0.4.0
ibm emptoris_strategic_supply_management 10.1.0.4
ibm emptoris_strategic_supply_management 10.1.0.7
ibm emptoris_strategic_supply_management 10.1.0.10
ibm emptoris_strategic_supply_management 10.0.2.17
ibm emptoris_strategic_supply_management 10.1.1.2
ibm emptoris_strategic_supply_management 10.0.2.10
ibm emptoris_strategic_supply_management 10.1.0.6
ibm emptoris_strategic_supply_management 10.0.1.1
ibm emptoris_strategic_supply_management 10.0.2.16
ibm emptoris_strategic_supply_management 10.1.1.10
ibm emptoris_strategic_supply_management 10.0.2.0
ibm emptoris_strategic_supply_management 10.0.2.2
ibm emptoris_strategic_supply_management 10.1.0.8
ibm emptoris_strategic_supply_management 10.1.1.5
ibm emptoris_strategic_supply_management 10.0.1.3
ibm emptoris_strategic_supply_management 10.1.0.2
ibm emptoris_strategic_supply_management 10.0.0.3
ibm emptoris_strategic_supply_management 10.0.0.1
ibm emptoris_strategic_supply_management 10.1.0.5
ibm emptoris_strategic_supply_management 10.1.0.11
ibm emptoris_strategic_supply_management 10.0.1.0
ibm emptoris_strategic_supply_management 10.1.1.8
ibm emptoris_strategic_supply_management 10.0.2.1
ibm emptoris_strategic_supply_management 10.0.2.7
ibm emptoris_strategic_supply_management 10.1.0.0
ibm emptoris_strategic_supply_management 10.0.2.12
ibm emptoris_strategic_supply_management 10.1.1.4
CVE-2016-8952 LOW

IBM Emptoris Strategic Supply Management Platform 10.0.0.x through 10.1.1.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 118839.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm emptoris_strategic_supply_management 10.0.2.5
ibm emptoris_strategic_supply_management 10.0.0.0
ibm emptoris_strategic_supply_management 10.1.0.1
ibm emptoris_strategic_supply_management 10.1.1.1
ibm emptoris_strategic_supply_management 10.0.2.9
ibm emptoris_strategic_supply_management 10.1.1.9
ibm emptoris_strategic_supply_management 10.0.2.4
ibm emptoris_strategic_supply_management 10.1.0.3
ibm emptoris_strategic_supply_management 10.1.1.3
ibm emptoris_strategic_supply_management 10.0.2.6
ibm emptoris_strategic_supply_management 10.1.1.0
ibm emptoris_strategic_supply_management 10.1.0.12
ibm emptoris_strategic_supply_management 10.0.1.2
ibm emptoris_strategic_supply_management 10.0.1.4
ibm emptoris_strategic_supply_management 10.1.1.6
ibm emptoris_strategic_supply_management 10.1.1.7
ibm emptoris_strategic_supply_management 10.0.2.11
ibm emptoris_strategic_supply_management 10.0.2.3
ibm emptoris_strategic_supply_management 10.0.2.8
ibm emptoris_strategic_supply_management 10.0.2.13
ibm emptoris_strategic_supply_management 10.0.2.14
ibm emptoris_strategic_supply_management 10.0.2.15
ibm emptoris_strategic_supply_management 10.1.0.9
ibm emptoris_strategic_supply_management 10.0.0.2
ibm emptoris_strategic_supply_management 10.0.4.0
ibm emptoris_strategic_supply_management 10.1.0.4
ibm emptoris_strategic_supply_management 10.1.0.7
ibm emptoris_strategic_supply_management 10.1.0.10
ibm emptoris_strategic_supply_management 10.0.2.17
ibm emptoris_strategic_supply_management 10.1.1.2
ibm emptoris_strategic_supply_management 10.0.2.10
ibm emptoris_strategic_supply_management 10.1.0.6
ibm emptoris_strategic_supply_management 10.0.1.1
ibm emptoris_strategic_supply_management 10.0.2.16
ibm emptoris_strategic_supply_management 10.1.1.10
ibm emptoris_strategic_supply_management 10.0.2.0
ibm emptoris_strategic_supply_management 10.0.2.2
ibm emptoris_strategic_supply_management 10.1.0.8
ibm emptoris_strategic_supply_management 10.1.1.5
ibm emptoris_strategic_supply_management 10.0.1.3
ibm emptoris_strategic_supply_management 10.1.0.2
ibm emptoris_strategic_supply_management 10.0.0.3
ibm emptoris_strategic_supply_management 10.0.0.1
ibm emptoris_strategic_supply_management 10.1.0.5
ibm emptoris_strategic_supply_management 10.1.0.11
ibm emptoris_strategic_supply_management 10.0.1.0
ibm emptoris_strategic_supply_management 10.1.1.8
ibm emptoris_strategic_supply_management 10.0.2.1
ibm emptoris_strategic_supply_management 10.0.2.7
ibm emptoris_strategic_supply_management 10.1.0.0
ibm emptoris_strategic_supply_management 10.0.2.12
ibm emptoris_strategic_supply_management 10.1.1.4
CVE-2016-8953 MEDIUM

IBM Emptoris Sourcing 9.5.x through 10.1.x could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 118840.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-601,

Products Affected

Vendor Product Version
ibm emptoris_sourcing 10.0.1
ibm emptoris_sourcing 9.5.1.1
ibm emptoris_sourcing 10.0.2
ibm emptoris_sourcing 9.5.1.2
ibm emptoris_sourcing 10.0.4
ibm emptoris_sourcing 10.1.0
ibm emptoris_sourcing 10.1.1
ibm emptoris_sourcing 9.5
ibm emptoris_sourcing 9.5.1.3
ibm emptoris_sourcing 10.0.0
ibm emptoris_sourcing 9.5.0.1
CVE-2016-8954 HIGH

IBM dashDB Local uses hard-coded credentials that could allow a remote attacker to gain access to the Docker container or database.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-798,

Products Affected

Vendor Product Version
ibm dashdb_local 1.1.0
ibm dashdb_local 1.2.1
ibm dashdb_local 1.3.0
ibm dashdb_local 1.0.0
ibm dashdb_local 1.3.1
ibm dashdb_local 1.1.1
ibm dashdb_local 1.2.0
CVE-2016-8960 MEDIUM

IBM Cognos Business Intelligence 10.2 could allow a user with lower privilege Capabilities to adopt the Capabilities of a higher-privilege user by intercepting the higher-privilege user's cookie value from its HTTP request and then reusing it in subsequent requests. IBM Reference #: 1993718.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm cognos_business_intelligence 10.2.1
ibm cognos_business_intelligence 10.2
ibm cognos_business_intelligence 10.2.1.1
ibm cognos_business_intelligence 10.2.2
CVE-2016-8961 MEDIUM

IBM BigFix Inventory v9 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-601,

Products Affected

Vendor Product Version
ibm license_metric_tool 9.2.0
ibm bigfix_inventory *
CVE-2016-8962 MEDIUM

IBM BigFix Inventory 9.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 118851.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm bigfix_inventory *
CVE-2016-8963 LOW

IBM BigFix Inventory v9 stores potentially sensitive information in log files that could be read by a local user.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm license_metric_tool 9.2.0
ibm bigfix_inventory *
CVE-2016-8964 MEDIUM

IBM BigFix Inventory v9 9.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 118853.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,CWE-254,

Products Affected

Vendor Product Version
ibm bigfix_inventory *
ibm license_metric_tool *
CVE-2016-8966 MEDIUM

IBM BigFix Inventory v9 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm license_metric_tool 9.2.0
ibm bigfix_inventory 9.2
CVE-2016-8967 LOW

IBM BigFix Inventory v9 9.2 stores user credentials in plain in clear text which can be read by a local user.

CVSS 2.0

Severity: LOW

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm license_metric_tool 9.2.0
ibm bigfix_inventory 9.2
CVE-2016-8968 LOW

IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1998515.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_collaborative_lifecycle_management 6.0.2
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_collaborative_lifecycle_management 6.0.0
CVE-2016-8971 MEDIUM

IBM WebSphere MQ 8.0 could allow an authenticated user with queue manager permissions to cause a segmentation fault which would result in the box having to be rebooted to resume normal operations. IBM Reference #: 1998663.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm websphere_mq 8.0.0.5
ibm websphere_mq 8.0.0.1
ibm websphere_mq 8.0.0.3
ibm websphere_mq 8.0.0.4
ibm websphere_mq 8.0
ibm websphere_mq 8.0.0.2
CVE-2016-8972 HIGH

IBM AIX 6.1, 7.1, and 7.2 could allow a local user to gain root privileges using a specially crafted command within the bellmail client. IBM APARs: IV91006, IV91007, IV91008, IV91010, IV91011.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm aix 7.2
ibm vios 2.2.5.0
ibm vios 2.2.2.6
ibm vios 2.2.3.70
ibm vios 2.2.2.2
ibm vios 2.2.3.1
ibm vios 2.2.3.0
ibm vios 2.2.4.30
ibm vios 2.2.4.0
ibm vios 2.2.3.80
ibm vios 2.2.2.0
ibm vios 2.2.2.4
ibm vios 2.2.0.0
ibm vios 2.2.3.4
ibm vios 2.2.1.0
ibm vios 2.2.1.5
ibm vios 2.2.1.6
ibm vios 2.2.1.8
ibm vios 2.2.2.1
ibm vios 2.2.2.70
ibm vios 2.2.4.22
ibm vios 2.2.3.52
ibm aix 6.1
ibm vios 2.2.0.10
ibm vios 2.2.1.1
ibm vios 2.2.1.4
ibm vios 2.2.5.10
ibm vios 2.2.3.3
ibm aix 7.1
ibm vios 2.2.3.2
ibm vios 2.2.3.50
ibm vios 2.2.0.12
ibm vios 2.2.0.13
ibm vios 2.2.1.3
ibm vios 2.2.3.51
ibm vios 2.2.3.60
ibm vios 2.2.4.10
ibm vios 2.2.1.7
ibm vios 2.2.4.21
ibm vios 2.2.0.11
ibm vios 2.2.2.3
ibm vios 2.2.4.23
CVE-2016-8973 MEDIUM

IBM Rhapsody DM 4.0, 5.0 and 6.0 contains an undisclosed vulnerability that may allow an authenticated user to upload infected malicious files to the server. IBM Reference #: 1999960.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-434,

Products Affected

Vendor Product Version
ibm rational_rhapsody_design_manager 4.0.4
ibm rational_rhapsody_design_manager 4.0.5
ibm rational_rhapsody_design_manager 5.0.1
ibm rational_rhapsody_design_manager 4.0.7
ibm rational_rhapsody_design_manager 5.0
ibm rational_rhapsody_design_manager 4.0.3
ibm rational_rhapsody_design_manager 4.0.1
ibm rational_rhapsody_design_manager 4.0.2
ibm rational_rhapsody_design_manager 4.0
ibm rational_rhapsody_design_manager 6.0
ibm rational_rhapsody_design_manager 4.0.6
ibm rational_rhapsody_design_manager 6.0.1
ibm rational_rhapsody_design_manager 6.0.2
ibm rational_rhapsody_design_manager 5.0.2
CVE-2016-8974 HIGH

IBM Rhapsody DM 4.0, 5.0 and 6.0 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM Reference #: 1997798.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm rational_rhapsody_design_manager 4.0.4
ibm rational_rhapsody_design_manager 4.0.5
ibm rational_rhapsody_design_manager 5.0.1
ibm rational_rhapsody_design_manager 4.0.7
ibm rational_rhapsody_design_manager 5.0
ibm rational_rhapsody_design_manager 4.0.3
ibm rational_rhapsody_design_manager 4.0.1
ibm rational_rhapsody_design_manager 4.0.2
ibm rational_rhapsody_design_manager 4.0
ibm rational_rhapsody_design_manager 6.0
ibm rational_rhapsody_design_manager 4.0.6
ibm rational_rhapsody_design_manager 6.0.1
ibm rational_rhapsody_design_manager 6.0.2
ibm rational_rhapsody_design_manager 5.0.2
CVE-2016-8975 LOW

IBM Rhapsody DM 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 118912.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rhapsody_design_manager 6.0.3
ibm rhapsody_design_manager 6.0.1
ibm rhapsody_design_manager 6.0.2
ibm rhapsody_design_manager 5.0.2
ibm rhapsody_design_manager 6.0
ibm rhapsody_design_manager 5.0
ibm rhapsody_design_manager 5.0.1
CVE-2016-8977 MEDIUM

IBM BigFix Inventory v9 could disclose sensitive information to an unauthorized user using HTTP GET requests. This information could be used to mount further attacks against the system.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm license_metric_tool 9.2.0
ibm bigfix_inventory 9.2
CVE-2016-8980 HIGH

IBM BigFix Inventory v9 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm license_metric_tool 9.2.0
ibm bigfix_inventory 9.2
CVE-2016-8981 LOW

IBM BigFix Inventory v9 allows web pages to be stored locally which can be read by another user on the system.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm license_metric_tool 9.2.0
ibm bigfix_inventory 9.2
CVE-2016-8982 MEDIUM

IBM InfoSphere Information Server stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm infosphere_datastage 11.3
ibm infosphere_datastage 9.1
ibm infosphere_datastage 8.7
CVE-2016-8986 MEDIUM

IBM WebSphere MQ 8.0 could allow an authenticated user with access to the queue manager to bring down MQ channels using specially crafted HTTP requests. IBM Reference #: 1998648.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm websphere_mq 8.0.0.0
ibm websphere_mq 8.0.0.5
ibm websphere_mq 8.0.0.1
ibm websphere_mq 8.0.0.3
ibm websphere_mq 8.0.0.4
ibm websphere_mq 8.0
ibm websphere_mq 8.0.0.2
CVE-2016-8987 MEDIUM

IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow an authenticated user to view incorrect item sets that they should not have access to view.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm maximo_asset_management 7.6
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.5
CVE-2016-8998 MEDIUM

IBM Tivoli Storage Manager Server 7.1 could allow an authenticated user with TSM administrator privileges to cause a buffer overflow using a specially crafted SQL query and execute arbitrary code on the server. IBM Reference #: 1998747.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager 7.1.1.1
ibm tivoli_storage_manager 7.1.3.1
ibm tivoli_storage_manager 7.1.1.100
ibm tivoli_storage_manager 7.1.1
ibm tivoli_storage_manager 7.1.1.200
ibm tivoli_storage_manager 7.1.1.2
ibm tivoli_storage_manager 7.1.4.1
ibm tivoli_storage_manager 7.1.5
ibm tivoli_storage_manager 7.1.3
ibm tivoli_storage_manager 7.1.7
ibm tivoli_storage_manager 7.1.3.2
ibm tivoli_storage_manager 7.1.4.2
ibm tivoli_storage_manager 7.1.1.300
ibm tivoli_storage_manager 7.1.3.100
ibm tivoli_storage_manager 7.1.4
ibm tivoli_storage_manager 7.1.5.200
ibm tivoli_storage_manager 7.1.3.000
CVE-2016-8999 LOW

IBM InfoSphere Information Server contains a Path-relative stylesheet import vulnerability that allows attackers to render a page in quirks mode thereby facilitating an attacker to inject malicious CSS.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm infosphere_information_server 11.3
ibm infosphere_datastage 11.3
ibm infosphere_information_server 11.5
ibm infosphere_datastage 9.1
ibm infosphere_datastage 11.5
ibm infosphere_information_server 9.1
ibm infosphere_datastage 8.7
ibm infosphere_information_server 8.7
ibm infosphere_information_server_on_cloud 11.5
CVE-2016-9000 MEDIUM

IBM InfoSphere DataStage is vulnerable to cross-frame scripting, caused by insufficient HTML iframe protection. A remote attacker could exploit this vulnerability using a specially-crafted URL to navigate to a web page the attacker controls. An attacker could use this vulnerability to conduct clickjacking or other client-side browser attacks.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm infosphere_datastage 11.3
ibm infosphere_datastage 9.1
ibm infosphere_datastage 11.5
ibm infosphere_datastage 8.7
ibm infosphere_information_server_on_cloud 11.5
CVE-2016-9005 HIGH

IBM System Storage TS3100-TS3200 Tape Library could allow an unauthenticated user with access to the company network, to change a user's password and gain remote access to the system.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm system_storage_ts3100-ts3200_tape_library *
CVE-2016-9006 LOW

IBM UrbanCode Deploy 6.1 and 6.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: C1000264.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm urbancode_deploy 6.1.0.3
ibm urbancode_deploy 6.2.2
ibm urbancode_deploy 6.2.3.1
ibm urbancode_deploy 6.1.1.8
ibm urbancode_deploy 6.1.1.1
ibm urbancode_deploy 6.1.1.2
ibm urbancode_deploy 6.1.3.3
ibm urbancode_deploy 6.1.1
ibm urbancode_deploy 6.1.1.5
ibm urbancode_deploy 6.2.1
ibm urbancode_deploy 6.1.0.1
ibm urbancode_deploy 6.2.0.0
ibm urbancode_deploy 6.1.1.6
ibm urbancode_deploy 6.1.0.4
ibm urbancode_deploy 6.1.3.1
ibm urbancode_deploy 6.2.0.1
ibm urbancode_deploy 6.1.3.2
ibm urbancode_deploy 6.2.1.1
ibm urbancode_deploy 6.1
ibm urbancode_deploy 6.1.2
ibm urbancode_deploy 6.2.0.2
ibm urbancode_deploy 6.1.0.2
ibm urbancode_deploy 6.2.1.2
ibm urbancode_deploy 6.1.3
ibm urbancode_deploy 6.1.1.3
ibm urbancode_deploy 6.1.1.7
ibm urbancode_deploy 6.1.1.4
ibm urbancode_deploy 6.2.2.1
ibm urbancode_deploy 6.2.3.0
CVE-2016-9008 MEDIUM

IBM UrbanCode Deploy could allow a malicious user to access the Agent Relay ActiveMQ Broker JMX interface and run plugins on the agent.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm urbancode_deploy 6.1.0.3
ibm urbancode_deploy 6.2.2
ibm urbancode_deploy 6.0.1.3
ibm urbancode_deploy 6.1.1.8
ibm urbancode_deploy 6.0.1.4
ibm urbancode_deploy 6.0.1.7
ibm urbancode_deploy 6.1.1.1
ibm urbancode_deploy 6.1.1.2
ibm urbancode_deploy 6.1.3.3
ibm urbancode_deploy 6.1.1
ibm urbancode_deploy 6.1.1.5
ibm urbancode_deploy 6.2.1
ibm urbancode_deploy 6.0.1.13
ibm urbancode_deploy 6.1.0.1
ibm urbancode_deploy 6.2.0.0
ibm urbancode_deploy 6.0.1.14
ibm urbancode_deploy 6.0.1.5
ibm urbancode_deploy 6.1.1.6
ibm urbancode_deploy 6.1.0.4
ibm urbancode_deploy 6.1.3.1
ibm urbancode_deploy 6.2.0.1
ibm urbancode_deploy 6.1.3.2
ibm urbancode_deploy 6.2.1.1
ibm urbancode_deploy 6.1
ibm urbancode_deploy 6.1.2
ibm urbancode_deploy 6.0.1.6
ibm urbancode_deploy 6.0.1.11
ibm urbancode_deploy 6.2.0.2
ibm urbancode_deploy 6.1.0.2
ibm urbancode_deploy 6.0.1.8
ibm urbancode_deploy 6.1.3
ibm urbancode_deploy 6.0.1.9
ibm urbancode_deploy 6.1.1.3
ibm urbancode_deploy 6.0.1.10
ibm urbancode_deploy 6.0.1
ibm urbancode_deploy 6.0.1.12
ibm urbancode_deploy 6.0.1.2
ibm urbancode_deploy 6.1.1.7
ibm urbancode_deploy 6.1.1.4
ibm urbancode_deploy 6.2.2.1
ibm urbancode_deploy 6.0.1.1
ibm urbancode_deploy 6.0
CVE-2016-9009 MEDIUM

IBM WebSphere MQ 8.0 could allow an authenticated user with authority to create a cluster object to cause a denial of service to MQ clustering. IBM Reference #: 1998647.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,CWE-264,

Products Affected

Vendor Product Version
ibm websphere_mq 8.0.0.0
ibm websphere_mq 8.0.0.5
ibm websphere_mq 8.0.0.1
ibm websphere_mq 8.0.0.3
ibm websphere_mq 8.0.0.4
ibm websphere_mq 8.0
ibm websphere_mq 8.0.0.2
CVE-2016-9010 MEDIUM

IBM WebSphere Message Broker 9.0 and 10.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM Reference #: 1997906.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-254,

Products Affected

Vendor Product Version
ibm websphere_message_broker 8.0
ibm integration_bus 9.0
ibm integration_bus 10.0
CVE-2016-9691 HIGH

IBM WebSphere Cast Iron Solution 7.0.0 and 7.5.0.0 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM X-Force ID: 119515.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm websphere_cast_iron_solution 7.5.0.0
ibm websphere_cast_iron_solution 7.5.0.1
ibm websphere_cast_iron_solution 7.5.1.0
ibm websphere_cast_iron_solution 7.0.0
ibm websphere_cast_iron_solution 7.0.0.2
ibm websphere_cast_iron_solution 7.0.0.1
CVE-2016-9692 HIGH

IBM WebSphere Cast Iron Solution 7.0.0 and 7.5.0.0 is vulnerable to External Service Interaction attack, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to induce the application to perform server-side DNS lookups or HTTP requests to arbitrary domain names. By submitting suitable payloads, an attacker can cause the application server to attack other systems that it can interact with. IBM X-Force ID: 119516.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm websphere_cast_iron_solution 7.5.0.0
ibm websphere_cast_iron_solution 7.5.0.1
ibm websphere_cast_iron_solution 7.5.1.0
ibm websphere_cast_iron_solution 7.0.0
ibm websphere_cast_iron_solution 7.0.0.2
ibm websphere_cast_iron_solution 7.0.0.1
CVE-2016-9693 MEDIUM

IBM Business Process Manager 7.5, 8.0, and 8.5 has a file download capability that is vulnerable to a set of attacks. Ultimately, an attacker can cause an unauthenticated victim to download a malicious payload. An existing file type restriction can be bypassed so that the payload might be considered executable and cause damage on the victim's machine. IBM Reference #: 1998655.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm business_process_manager 8.0.1.2
ibm websphere 7.2.0.2
ibm business_process_manager 8.5.6.0
ibm business_process_manager 8.0.1.1
ibm websphere 7.2.0.4
ibm business_process_manager 7.5.0.1
ibm business_process_manager 8.5.0.2
ibm business_process_manager 7.5.1.0
ibm business_process_manager 7.5.1.1
ibm websphere 7.2.0.1
ibm websphere 7.2.0.3
ibm business_process_manager 8.5.6.2
ibm business_process_manager 8.5.5.0
ibm business_process_manager 8.0.1.0
ibm business_process_manager 7.5.1.2
ibm websphere 7.2.0.5
ibm business_process_manager 8.0.0.0
ibm business_process_manager 8.5.7.0
ibm business_process_manager 8.5.0.1
ibm websphere 7.2
ibm business_process_manager 8.0.1.3
ibm business_process_manager 8.5.0.0
ibm business_process_manager 7.5.0.0
CVE-2016-9694 LOW

IBM Rhapsody DM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1999960.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_rhapsody_design_manager 4.0.4
ibm rational_rhapsody_design_manager 4.0.5
ibm rational_rhapsody_design_manager 5.0.1
ibm rational_rhapsody_design_manager 4.0.7
ibm rational_rhapsody_design_manager 5.0
ibm rational_rhapsody_design_manager 4.0.3
ibm rational_rhapsody_design_manager 4.0.1
ibm rational_rhapsody_design_manager 4.0.2
ibm rational_rhapsody_design_manager 4.0
ibm rational_rhapsody_design_manager 6.0
ibm rational_rhapsody_design_manager 4.0.6
ibm rational_rhapsody_design_manager 6.0.1
ibm rational_rhapsody_design_manager 6.0.2
ibm rational_rhapsody_design_manager 5.0.2
CVE-2016-9696 LOW

IBM Rhapsody DM 4.0, 5.0, and 6.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM Reference #: 1999960.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_rhapsody_design_manager 4.0.4
ibm rational_rhapsody_design_manager 4.0.5
ibm rational_rhapsody_design_manager 5.0.1
ibm rational_rhapsody_design_manager 4.0.7
ibm rational_rhapsody_design_manager 5.0
ibm rational_rhapsody_design_manager 4.0.3
ibm rational_rhapsody_design_manager 4.0.1
ibm rational_rhapsody_design_manager 4.0.2
ibm rational_rhapsody_design_manager 4.0
ibm rational_rhapsody_design_manager 6.0
ibm rational_rhapsody_design_manager 4.0.6
ibm rational_rhapsody_design_manager 6.0.1
ibm rational_rhapsody_design_manager 6.0.2
ibm rational_rhapsody_design_manager 5.0.2
CVE-2016-9697 LOW

An unspecified vulnerability in IBM Rhapsody DM 4.0, 5.0, and 6.0 could allow an attacker to perform a JSON Hijacking Attack. A JSON Hijacking Attack may expose to an attacker information passed between the server and the browser. IBM Reference #: 1999960.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_rhapsody_design_manager 4.0.4
ibm rational_rhapsody_design_manager 4.0.5
ibm rational_rhapsody_design_manager 5.0.1
ibm rational_rhapsody_design_manager 4.0.7
ibm rational_rhapsody_design_manager 5.0
ibm rational_rhapsody_design_manager 4.0.3
ibm rational_rhapsody_design_manager 4.0.1
ibm rational_rhapsody_design_manager 4.0.2
ibm rational_rhapsody_design_manager 4.0
ibm rational_rhapsody_design_manager 6.0
ibm rational_rhapsody_design_manager 4.0.6
ibm rational_rhapsody_design_manager 6.0.1
ibm rational_rhapsody_design_manager 6.0.2
ibm rational_rhapsody_design_manager 5.0.2
CVE-2016-9698 HIGH

IBM Rhapsody DM 4.0, 5.0, and 6.0 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM Reference #: 1999960.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm rational_rhapsody_design_manager 4.0.4
ibm rational_rhapsody_design_manager 4.0.5
ibm rational_rhapsody_design_manager 5.0.1
ibm rational_rhapsody_design_manager 4.0.7
ibm rational_rhapsody_design_manager 5.0
ibm rational_rhapsody_design_manager 4.0.3
ibm rational_rhapsody_design_manager 4.0.1
ibm rational_rhapsody_design_manager 4.0.2
ibm rational_rhapsody_design_manager 4.0
ibm rational_rhapsody_design_manager 6.0
ibm rational_rhapsody_design_manager 4.0.6
ibm rational_rhapsody_design_manager 6.0.1
ibm rational_rhapsody_design_manager 6.0.2
ibm rational_rhapsody_design_manager 5.0.2
CVE-2016-9700 MEDIUM

IBM Jazz Foundation could allow an authenticated attacker to obtain sensitive information from error message stack traces. IBM X-Force ID: 119528.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_rhapsody_design_manager 4.0.4
ibm rational_rhapsody_design_manager 4.0.5
ibm rational_doors_next_generation 4.0.0
ibm rational_collaborative_lifecycle_management 4.0.6
ibm rational_engineering_lifecycle_manager 4.0.7
ibm rational_quality_manager 4.0.6
ibm rational_software_architect_design_manager 6.0.1
ibm rational_team_concert 5.0
ibm rational_software_architect_design_manager 4.0.7
ibm rational_quality_manager 6.0.1
ibm rational_engineering_lifecycle_manager 5.0.2
ibm rational_rhapsody_design_manager 5.0.2
ibm rational_quality_manager 4.0.3
ibm rational_engineering_lifecycle_manager 6.0.2
ibm rational_collaborative_lifecycle_management 6.0.3
ibm rational_team_concert 4.0.1
ibm rational_team_concert 6.0.0
ibm rational_team_concert 4.0.5
ibm rational_doors_next_generation 5.0
ibm rational_team_concert 4.0.2
ibm rational_quality_manager 5.0
ibm rational_collaborative_lifecycle_management 4.0.5
ibm rational_collaborative_lifecycle_management 4.0.7
ibm rational_collaborative_lifecycle_management 5.0.0
ibm rational_collaborative_lifecycle_management 4.0.3
ibm rational_software_architect_design_manager 4.0.6
ibm rational_doors_next_generation 4.0.7
ibm rational_doors_next_generation 4.0.2
ibm rational_software_architect_design_manager 5.0.0
ibm rational_rhapsody_design_manager 4.0.7
ibm rational_engineering_lifecycle_manager 5.0
ibm rational_doors_next_generation 6.0.0
ibm rational_engineering_lifecycle_manager 6.0.0
ibm rational_team_concert 5.0.2
ibm rational_collaborative_lifecycle_management 4.0.1
ibm rational_rhapsody_design_manager 5.0
ibm rational_engineering_lifecycle_manager 6.0.3
ibm rational_team_concert 4.0.3
ibm rational_collaborative_lifecycle_management 4.0.2
ibm rational_team_concert 4.0.0
ibm rational_quality_manager 4.0.1
ibm rational_team_concert 4.0.6
ibm rational_quality_manager 4.0.0
ibm rational_quality_manager 5.0.0
ibm rational_engineering_lifecycle_manager 4.0.5
ibm rational_software_architect_design_manager 5.0.2
ibm rational_engineering_lifecycle_manager 6.0.1
ibm rational_software_architect_design_manager 6.0.0
ibm rational_doors_next_generation 4.0.4
ibm rational_rhapsody_design_manager 6.0.3
ibm rational_quality_manager 4.0.4
ibm rational_software_architect_design_manager 4.0.0
ibm rational_engineering_lifecycle_manager 4.0.6
ibm rational_rhapsody_design_manager 4.0.3
ibm rational_doors_next_generation 5.0.0
ibm rational_doors_next_generation 5.0.2
ibm rational_quality_manager 4.0.2
ibm rational_doors_next_generation 4.0
ibm rational_doors_next_generation 5.0.1
ibm rational_software_architect_design_manager 4.0.1
ibm rational_collaborative_lifecycle_management 4.0.4
ibm rational_team_concert 4.0.0.1
ibm rational_engineering_lifecycle_manager 4.0.3
ibm rational_engineering_lifecycle_manager 4.0.4
ibm rational_rhapsody_design_manager 5.0.0
ibm rational_software_architect_design_manager 4.0.2
ibm rational_collaborative_lifecycle_management 6.0
ibm rational_engineering_lifecycle_manager 5.0.0
ibm rational_quality_manager 4.0.0.1
ibm rational_quality_manager 4.0.0.2
ibm rational_team_concert 6.0.1
ibm rational_rhapsody_design_manager 6.0
ibm rational_quality_manager 4.0.7
ibm rational_rhapsody_design_manager 4.0.6
ibm rational_rhapsody_design_manager 6.0.1
ibm rational_rhapsody_design_manager 6.0.2
ibm rational_software_architect_design_manager 5.0
ibm rational_software_architect_design_manager 4.0.4
ibm rational_team_concert 6.0.2
ibm rational_doors_next_generation 4.0.1
ibm rational_engineering_lifecycle_manager 5.0.1
ibm rational_team_concert 4.0.7
ibm rational_team_concert 6.0
ibm rational_software_architect_design_manager 4.0.3
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_quality_manager 5.0.2
ibm rational_rhapsody_design_manager 4.0.1
ibm rational_rhapsody_design_manager 4.0.2
ibm rational_team_concert 4.0.0.2
ibm rational_rhapsody_design_manager 4.0
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_collaborative_lifecycle_management 4.0.0
ibm rational_quality_manager 6.0.3
ibm rational_doors_next_generation 6.0.1
ibm rational_rhapsody_design_manager 5.0.1
ibm rational_doors_next_generation 6.0.3
ibm rational_team_concert 4.0
ibm rational_doors_next_generation 4.0.5
ibm rational_collaborative_lifecycle_management 4.0
ibm rational_team_concert 6.0.3
ibm rational_doors_next_generation 4.0.6
ibm rational_doors_next_generation 4.0.3
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 4.0
ibm rational_collaborative_lifecycle_management 5.0
ibm rational_team_concert 5.0.0
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_software_architect_design_manager 4.0.5
ibm rational_team_concert 4.0.4
ibm rational_software_architect_design_manager 5.0.1
ibm rational_software_architect_design_manager 4.0
ibm rational_quality_manager 4.0.5
ibm rational_quality_manager 6.0.2
ibm rational_doors_next_generation 6.0.2
ibm rational_quality_manager 6.0.0
ibm rational_collaborative_lifecycle_management 6.0.0
ibm rational_team_concert 5.0.1
ibm rational_rhapsody_design_manager 6.0.0
CVE-2016-9701 LOW

IBM Team Concert 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 119529.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_team_concert 4.0.0.1
ibm rational_team_concert 4.0
ibm rational_collaborative_lifecycle_management 4.0.6
ibm rational_team_concert 5.0.2
ibm rational_collaborative_lifecycle_management 6.0
ibm rational_collaborative_lifecycle_management 4.0
ibm rational_collaborative_lifecycle_management 4.0.1
ibm rational_team_concert 6.0.3
ibm rational_team_concert 5.0
ibm rational_team_concert 4.0.3
ibm rational_team_concert 6.0.1
ibm rational_collaborative_lifecycle_management 4.0.2
ibm rational_collaborative_lifecycle_management 5.0
ibm rational_team_concert 4.0.0
ibm rational_team_concert 4.0.6
ibm rational_team_concert 6.0.2
ibm rational_team_concert 5.0.0
ibm rational_team_concert 4.0.7
ibm rational_collaborative_lifecycle_management 6.0.3
ibm rational_team_concert 4.0.1
ibm rational_team_concert 6.0.0
ibm rational_team_concert 6.0
ibm rational_team_concert 4.0.5
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_team_concert 4.0.2
ibm rational_team_concert 4.0.4
ibm rational_collaborative_lifecycle_management 4.0.5
ibm rational_collaborative_lifecycle_management 4.0.7
ibm rational_collaborative_lifecycle_management 5.0.0
ibm rational_collaborative_lifecycle_management 4.0.3
ibm rational_team_concert 4.0.0.2
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_collaborative_lifecycle_management 4.0.0
ibm rational_collaborative_lifecycle_management 6.0.0
ibm rational_collaborative_lifecycle_management 4.0.4
ibm rational_team_concert 5.0.1
CVE-2016-9703 LOW

IBM Security Identity Manager Virtual Appliance does not invalidate session tokens which could allow an unauthorized user with physical access to the work station to obtain sensitive information.

CVSS 2.0

Severity: LOW

Problem Type: CWE-384,

Products Affected

Vendor Product Version
ibm security_identity_manager_virtual_appliance 7.0.1.1
ibm security_identity_manager_virtual_appliance 7.0.0.2
ibm security_identity_manager_virtual_appliance 7.0.1.4
ibm security_identity_manager_virtual_appliance 7.0.0.3
ibm security_identity_manager_virtual_appliance 7.0.1.0
ibm security_identity_manager_virtual_appliance 7.0.1.2
ibm security_identity_manager_virtual_appliance 7.0.0.1
ibm security_identity_manager_virtual_appliance 7.0.1.3
ibm security_identity_manager_virtual_appliance 7.0.0.0
CVE-2016-9704 MEDIUM

IBM Security Identity Manager Virtual Appliance is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm security_identity_manager_virtual_appliance 7.0.1.1
ibm security_identity_manager_virtual_appliance 7.0.0.2
ibm security_identity_manager_virtual_appliance 7.0.1.4
ibm security_identity_manager_virtual_appliance 7.0.0.3
ibm security_identity_manager_virtual_appliance 7.0.1.0
ibm security_identity_manager_virtual_appliance 7.0.1.2
ibm security_identity_manager_virtual_appliance 7.0.0.1
ibm security_identity_manager_virtual_appliance 7.0.1.3
ibm security_identity_manager_virtual_appliance 7.0.0.0
CVE-2016-9706 HIGH

IBM Integration Bus 9.0 and 10.0 and WebSphere Message Broker SOAP FLOWS is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM Reference #: 1997918.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm websphere_message_broker 8.0
ibm integration_bus 9.0
ibm integration_bus 10.0
CVE-2016-9707 HIGH

IBM Jazz Foundation is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM Reference #: 2000784.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm rational_rhapsody_design_manager 4.0.4
ibm rational_rhapsody_design_manager 4.0.5
ibm rational_software_architect_design_manager 6.0
ibm rational_collaborative_lifecycle_management 4.0.6
ibm rational_engineering_lifecycle_manager 4.0.7
ibm rational_quality_manager 4.0.6
ibm rational_software_architect_design_manager 6.0.1
ibm rational_team_concert 5.0
ibm rational_software_architect_design_manager 4.0.7
ibm rational_quality_manager 6.0.1
ibm rational_engineering_lifecycle_manager 5.0.2
ibm rational_rhapsody_design_manager 5.0.2
ibm rational_quality_manager 4.0.3
ibm rational_engineering_lifecycle_manager 6.0.2
ibm rational_collaborative_lifecycle_management 6.0.3
ibm rational_team_concert 4.0.1
ibm rational_team_concert 4.0.5
ibm rational_doors_next_generation 5.0
ibm rational_team_concert 4.0.2
ibm rational_quality_manager 5.0
ibm rational_collaborative_lifecycle_management 4.0.5
ibm rational_collaborative_lifecycle_management 4.0.7
ibm rational_collaborative_lifecycle_management 4.0.3
ibm rational_software_architect_design_manager 4.0.6
ibm rational_doors_next_generation 4.0.7
ibm rational_doors_next_generation 4.0.2
ibm rational_doors_next_generation 6.0
ibm rational_rhapsody_design_manager 4.0.7
ibm rational_engineering_lifecycle_manager 5.0
ibm rational_team_concert 5.0.2
ibm rational_collaborative_lifecycle_management 4.0.1
ibm rational_rhapsody_design_manager 5.0
ibm rational_engineering_lifecycle_manager 6.0.3
ibm rational_team_concert 4.0.3
ibm rational_engineering_lifecycle_manager 4.0
ibm rational_collaborative_lifecycle_management 4.0.2
ibm rational_engineering_lifecycle_manager 4.0.2
ibm rational_quality_manager 4.0.1
ibm rational_team_concert 4.0.6
ibm rational_engineering_lifecycle_manager 4.0.5
ibm rational_software_architect_design_manager 5.0.2
ibm rational_engineering_lifecycle_manager 6.0.1
ibm rational_quality_manager 6.0
ibm rational_doors_next_generation 4.0.4
ibm rational_rhapsody_design_manager 6.0.3
ibm rational_quality_manager 4.0.4
ibm rational_engineering_lifecycle_manager 4.0.6
ibm rational_rhapsody_design_manager 4.0.3
ibm rational_doors_next_generation 5.0.2
ibm rational_quality_manager 4.0.2
ibm rational_software_architect_design_manager 6.0.3
ibm rational_doors_next_generation 4.0
ibm rational_doors_next_generation 5.0.1
ibm rational_software_architect_design_manager 4.0.1
ibm rational_collaborative_lifecycle_management 4.0.4
ibm rational_team_concert 4.0.0.1
ibm rational_engineering_lifecycle_manager 4.0.3
ibm rational_engineering_lifecycle_manager 4.0.4
ibm rational_software_architect_design_manager 4.0.2
ibm rational_collaborative_lifecycle_management 6.0
ibm rational_engineering_lifecycle_manager 4.0.1
ibm rational_quality_manager 4.0.0.1
ibm rational_quality_manager 4.0.0.2
ibm rational_team_concert 6.0.1
ibm rational_rhapsody_design_manager 6.0
ibm rational_quality_manager 4.0.7
ibm rational_rhapsody_design_manager 4.0.6
ibm rational_rhapsody_design_manager 6.0.1
ibm rational_rhapsody_design_manager 6.0.2
ibm rational_software_architect_design_manager 5.0
ibm rational_software_architect_design_manager 4.0.4
ibm rational_team_concert 6.0.2
ibm rational_doors_next_generation 4.0.1
ibm rational_engineering_lifecycle_manager 5.0.1
ibm rational_team_concert 4.0.7
ibm rational_team_concert 6.0
ibm rational_collaborative_lifecycle_management 6.0.2
ibm rational_software_architect_design_manager 4.0.3
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_quality_manager 5.0.2
ibm rational_rhapsody_design_manager 4.0.1
ibm rational_rhapsody_design_manager 4.0.2
ibm rational_team_concert 4.0.0.2
ibm rational_rhapsody_design_manager 4.0
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_quality_manager 6.0.3
ibm rational_doors_next_generation 6.0.1
ibm rational_rhapsody_design_manager 5.0.1
ibm rational_doors_next_generation 6.0.3
ibm rational_team_concert 4.0
ibm rational_doors_next_generation 4.0.5
ibm rational_collaborative_lifecycle_management 4.0
ibm rational_team_concert 6.0.3
ibm rational_doors_next_generation 4.0.6
ibm rational_doors_next_generation 4.0.3
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 4.0
ibm rational_collaborative_lifecycle_management 5.0
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_software_architect_design_manager 6.0.2
ibm rational_software_architect_design_manager 4.0.5
ibm rational_engineering_lifecycle_manager 6.0
ibm rational_team_concert 4.0.4
ibm rational_software_architect_design_manager 5.0.1
ibm rational_software_architect_design_manager 4.0
ibm rational_quality_manager 4.0.5
ibm rational_quality_manager 6.0.2
ibm rational_doors_next_generation 6.0.2
ibm rational_team_concert 5.0.1
CVE-2016-9710 MEDIUM

IBM Predictive Solutions Foundation (formerly PMQ) could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-crafted URL to specify a file from the local system, which could allow the attacker to obtain sensitive information. IBM X-Force ID: 119618.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm cognos_business_intelligence_server 10.2.1.1
ibm cognos_business_intelligence_server 10.2.0
ibm cognos_business_intelligence_server 10.2.1
ibm cognos_business_intelligence_server 10.2.2
ibm cognos_business_intelligence_server 10.1.1
CVE-2016-9711 MEDIUM

IBM Predictive Solutions Foundation (IBM Cognos Analytics 11.0) reveals sensitive information in detailed error messages that could aid an attacker in further attacks against the system. IBM X-Force ID: 119619.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm cognos_analytics 11.0.0
CVE-2016-9714 MEDIUM

IBM InfoSphere Master Data Management Server 10.1, 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 119727.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm infosphere_master_data_management_server 10.1
ibm infosphere_master_data_management_server 11.5
ibm infosphere_master_data_management_server 11.0
ibm infosphere_master_data_management_server 11.3
ibm infosphere_master_data_management_server 11.6
ibm infosphere_master_data_management_server 11.4
CVE-2016-9715 LOW

IBM InfoSphere Master Data Management Server 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 119728.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm infosphere_master_data_management_server 11.5
ibm infosphere_master_data_management_server 11.0
ibm infosphere_master_data_management_server 11.3
ibm infosphere_master_data_management_server 11.6
ibm infosphere_master_data_management_server 11.4
CVE-2016-9716 MEDIUM

IBM InfoSphere Master Data Management Server 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 119729.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm infosphere_master_data_management_server 11.5
ibm infosphere_master_data_management_server 11.0
ibm infosphere_master_data_management_server 11.3
ibm infosphere_master_data_management_server 11.6
ibm infosphere_master_data_management_server 11.4
CVE-2016-9717 MEDIUM

HTTP Parameter Override is identified in the IBM Infosphere Master Data Management (MDM) 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 product. It enables attackers by exposing the presence of duplicated parameters which may produce an anomalous behavior in the application that can be potentially exploited.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm infosphere_master_data_management_server 10.1
ibm infosphere_master_data_management_server 11.5
ibm infosphere_master_data_management_server 11.0
ibm infosphere_master_data_management_server 11.3
ibm infosphere_master_data_management_server 11.6
ibm infosphere_master_data_management_server 11.4
CVE-2016-9718 LOW

IBM InfoSphere Master Data Management Server 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 119732.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm infosphere_master_data_management_server 10.1
ibm infosphere_master_data_management_server 11.5
ibm infosphere_master_data_management_server 11.0
ibm infosphere_master_data_management_server 11.3
ibm infosphere_master_data_management_server 11.6
ibm infosphere_master_data_management_server 11.4
CVE-2016-9719 LOW

IBM InfoSphere Master Data Management Server 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 119733.

CVSS 2.0

Severity: LOW

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm infosphere_master_data_management_server 10.1
ibm infosphere_master_data_management_server 11.5
ibm infosphere_master_data_management_server 11.0
ibm infosphere_master_data_management_server 11.3
ibm infosphere_master_data_management_server 11.6
ibm infosphere_master_data_management_server 11.4
CVE-2016-9720 MEDIUM

IBM QRadar 7.2 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM Reference #: 1999533.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.2
ibm qradar_incident_forensics 7.2.3
ibm qradar_security_information_and_event_manager 7.2.8
ibm qradar_incident_forensics 7.2.6
ibm qradar_incident_forensics 7.2.8
ibm qradar_incident_forensics 7.2.2
ibm qradar_incident_forensics 7.2.5
ibm qradar_incident_forensics 7.2.1
ibm qradar_security_information_and_event_manager 7.2.5
ibm qradar_security_information_and_event_manager 7.2.0
ibm qradar_security_information_and_event_manager 7.2.7
ibm qradar_incident_forensics 7.2.4
ibm qradar_incident_forensics 7.2.0
ibm qradar_security_information_and_event_manager 7.2.3
ibm qradar_security_information_and_event_manager 7.2.6
ibm qradar_security_information_and_event_manager 7.2.4
ibm qradar_security_information_and_event_manager 7.2.1
ibm qradar_incident_forensics 7.2.7
CVE-2016-9722 MEDIUM

IBM QRadar 7.2 and 7.3 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. IBM X-Force ID: 119737.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.2
ibm qradar_security_information_and_event_manager 7.2.8
ibm qradar_security_information_and_event_manager 7.2.0
ibm qradar_security_information_and_event_manager 7.2.7
ibm qradar_security_information_and_event_manager 7.3.0
ibm qradar_security_information_and_event_manager 7.2.3
ibm qradar_security_information_and_event_manager 7.2.6
ibm qradar_security_information_and_event_manager 7.2.4
ibm qradar_security_information_and_event_manager 7.2.1
ibm qradar_security_information_and_event_manager 7.2.5
CVE-2016-9723 MEDIUM

IBM QRadar 7.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1999534.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.2
ibm qradar_incident_forensics 7.2.3
ibm qradar_security_information_and_event_manager 7.2.8
ibm qradar_incident_forensics 7.2.6
ibm qradar_incident_forensics 7.2.8
ibm qradar_incident_forensics 7.2.2
ibm qradar_incident_forensics 7.2.5
ibm qradar_incident_forensics 7.2.1
ibm qradar_security_information_and_event_manager 7.2.5
ibm qradar_security_information_and_event_manager 7.2.0
ibm qradar_security_information_and_event_manager 7.2.7
ibm qradar_incident_forensics 7.2.4
ibm qradar_incident_forensics 7.2.0
ibm qradar_security_information_and_event_manager 7.2.3
ibm qradar_security_information_and_event_manager 7.2.6
ibm qradar_security_information_and_event_manager 7.2.4
ibm qradar_security_information_and_event_manager 7.2.1
ibm qradar_incident_forensics 7.2.7
CVE-2016-9724 HIGH

IBM QRadar 7.2 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM Reference #: 1999537.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.2
ibm qradar_security_information_and_event_manager 7.2.8
ibm qradar_security_information_and_event_manager 7.2.0
ibm qradar_security_information_and_event_manager 7.2.7
ibm qradar_security_information_and_event_manager 7.2.3
ibm qradar_security_information_and_event_manager 7.2.6
ibm qradar_security_information_and_event_manager 7.2.4
ibm qradar_security_information_and_event_manager 7.2.1
ibm qradar_security_information_and_event_manager 7.2.5
CVE-2016-9725 MEDIUM

IBM QRadar Incident Forensics 7.2 allows for Cross-Origin Resource Sharing (CORS), which is a mechanism that allows web sites to request resources from external sites, avoiding the need to duplicate them. IBM Reference #: 1999539.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.2
ibm qradar_security_information_and_event_manager 7.2.8
ibm qradar_security_information_and_event_manager 7.2.0
ibm qradar_security_information_and_event_manager 7.2.7
ibm qradar_security_information_and_event_manager 7.2.3
ibm qradar_security_information_and_event_manager 7.2.6
ibm qradar_security_information_and_event_manager 7.2.4
ibm qradar_security_information_and_event_manager 7.2.1
ibm qradar_security_information_and_event_manager 7.2.5
CVE-2016-9726 HIGH

IBM QRadar Incident Forensics 7.2 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM Reference #: 1999542.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.2
ibm qradar_incident_forensics 7.2.3
ibm qradar_security_information_and_event_manager 7.2.8
ibm qradar_incident_forensics 7.2.6
ibm qradar_incident_forensics 7.2.8
ibm qradar_incident_forensics 7.2.2
ibm qradar_incident_forensics 7.2.5
ibm qradar_incident_forensics 7.2.1
ibm qradar_security_information_and_event_manager 7.2.5
ibm qradar_security_information_and_event_manager 7.2.0
ibm qradar_security_information_and_event_manager 7.2.7
ibm qradar_incident_forensics 7.2.4
ibm qradar_incident_forensics 7.2.0
ibm qradar_security_information_and_event_manager 7.2.3
ibm qradar_security_information_and_event_manager 7.2.6
ibm qradar_security_information_and_event_manager 7.2.4
ibm qradar_security_information_and_event_manager 7.2.1
ibm qradar_incident_forensics 7.2.7
CVE-2016-9727 HIGH

IBM QRadar 7.2 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM Reference #: 1999542.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.2
ibm qradar_incident_forensics 7.2.3
ibm qradar_security_information_and_event_manager 7.2.8
ibm qradar_incident_forensics 7.2.6
ibm qradar_incident_forensics 7.2.8
ibm qradar_incident_forensics 7.2.2
ibm qradar_incident_forensics 7.2.5
ibm qradar_incident_forensics 7.2.1
ibm qradar_security_information_and_event_manager 7.2.5
ibm qradar_security_information_and_event_manager 7.2.0
ibm qradar_security_information_and_event_manager 7.2.7
ibm qradar_incident_forensics 7.2.4
ibm qradar_incident_forensics 7.2.0
ibm qradar_security_information_and_event_manager 7.2.3
ibm qradar_security_information_and_event_manager 7.2.6
ibm qradar_security_information_and_event_manager 7.2.4
ibm qradar_security_information_and_event_manager 7.2.1
ibm qradar_incident_forensics 7.2.7
CVE-2016-9728 MEDIUM

IBM Qradar 7.2 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, information in the back-end database. IBM Reference #: 1999543.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.2
ibm qradar_security_information_and_event_manager 7.2.8
ibm qradar_security_information_and_event_manager 7.2.0
ibm qradar_security_information_and_event_manager 7.2.7
ibm qradar_security_information_and_event_manager 7.2.3
ibm qradar_security_information_and_event_manager 7.2.6
ibm qradar_security_information_and_event_manager 7.2.4
ibm qradar_security_information_and_event_manager 7.2.1
ibm qradar_security_information_and_event_manager 7.2.5
CVE-2016-9729 MEDIUM

IBM QRadar 7.2 does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. IBM Reference #: 1999545.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.2
ibm qradar_security_information_and_event_manager 7.2.8
ibm qradar_security_information_and_event_manager 7.2.0
ibm qradar_security_information_and_event_manager 7.2.7
ibm qradar_security_information_and_event_manager 7.2.3
ibm qradar_security_information_and_event_manager 7.2.6
ibm qradar_security_information_and_event_manager 7.2.4
ibm qradar_security_information_and_event_manager 7.2.1
ibm qradar_security_information_and_event_manager 7.2.5
CVE-2016-9730 MEDIUM

IBM QRadar Incident Forensics 7.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM Reference #: 1999549.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.2
ibm qradar_incident_forensics 7.2.3
ibm qradar_security_information_and_event_manager 7.2.8
ibm qradar_incident_forensics 7.2.6
ibm qradar_incident_forensics 7.2.8
ibm qradar_incident_forensics 7.2.2
ibm qradar_incident_forensics 7.2.5
ibm qradar_incident_forensics 7.2.1
ibm qradar_security_information_and_event_manager 7.2.5
ibm qradar_security_information_and_event_manager 7.2.0
ibm qradar_security_information_and_event_manager 7.2.7
ibm qradar_incident_forensics 7.2.4
ibm qradar_incident_forensics 7.2.0
ibm qradar_security_information_and_event_manager 7.2.3
ibm qradar_security_information_and_event_manager 7.2.6
ibm qradar_security_information_and_event_manager 7.2.4
ibm qradar_security_information_and_event_manager 7.2.1
ibm qradar_incident_forensics 7.2.7
CVE-2016-9731 LOW

IBM Business Process Manager is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm business_process_manager 8.5.7.0
CVE-2016-9732 LOW

IBM Curam Social Program Management 6.0, 6.1, 6.2 and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 119761.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm curam_social_program_management 6.1.0.2
ibm curam_social_program_management 6.1.0.4
ibm curam_social_program_management 6.0.4.8
ibm curam_social_program_management 6.0.5.9
ibm curam_social_program_management 6.1.0.1
ibm curam_social_program_management 6.0.4.9
ibm curam_social_program_management 6.2.0.3
ibm curam_social_program_management 6.0.5.10
ibm curam_social_program_management 6.0.4.0
ibm curam_social_program_management 6.0.5.5
ibm curam_social_program_management 6.2.0.0
ibm curam_social_program_management 6.0.5.2
ibm curam_social_program_management 6.0.5.1
ibm curam_social_program_management 6.2.0.2
ibm curam_social_program_management 6.1.1.2
ibm curam_social_program_management 6.0.5.3
ibm curam_social_program_management 6.2.0.1
ibm curam_social_program_management 6.0.4.5
ibm curam_social_program_management 7.0.0.1
ibm curam_social_program_management 6.0.4.7
ibm curam_social_program_management 6.0.4.3
ibm curam_social_program_management 6.0.5.4
ibm curam_social_program_management 6.0.4.4
ibm curam_social_program_management 6.1.0.3
ibm curam_social_program_management 6.0.5
ibm curam_social_program_management 6.0.4.1
ibm curam_social_program_management 6.0.5.0
ibm curam_social_program_management 6.1.1.0
ibm curam_social_program_management 6.1.1.3
ibm curam_social_program_management 6.2.0.4
ibm curam_social_program_management 6.0.5.8
ibm curam_social_program_management 6.0.5.7
ibm curam_social_program_management 6.0.5.6
ibm curam_social_program_management 6.1.0.0
ibm curam_social_program_management 6.0.4.2
ibm curam_social_program_management 6.1.1.4
ibm curam_social_program_management 6.0.4.6
ibm curam_social_program_management 6.1.1.1
ibm curam_social_program_management 7.0.0.0
CVE-2016-9733 LOW

IBM Team Concert (RTC) 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 119762.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_team_concert 4.0.0.1
ibm rational_team_concert 4.0
ibm rational_collaborative_lifecycle_management 4.0.6
ibm rational_team_concert 5.0.2
ibm rational_collaborative_lifecycle_management 6.0
ibm rational_collaborative_lifecycle_management 4.0
ibm rational_collaborative_lifecycle_management 4.0.1
ibm rational_team_concert 6.0.3
ibm rational_team_concert 5.0
ibm rational_team_concert 4.0.3
ibm rational_team_concert 6.0.1
ibm rational_collaborative_lifecycle_management 4.0.2
ibm rational_collaborative_lifecycle_management 5.0
ibm rational_team_concert 4.0.0
ibm rational_team_concert 4.0.6
ibm rational_team_concert 6.0.2
ibm rational_team_concert 5.0.0
ibm rational_team_concert 4.0.7
ibm rational_collaborative_lifecycle_management 6.0.3
ibm rational_team_concert 4.0.1
ibm rational_team_concert 6.0.0
ibm rational_team_concert 6.0
ibm rational_team_concert 4.0.5
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_team_concert 4.0.2
ibm rational_team_concert 4.0.4
ibm rational_collaborative_lifecycle_management 4.0.5
ibm rational_collaborative_lifecycle_management 4.0.7
ibm rational_collaborative_lifecycle_management 5.0.0
ibm rational_collaborative_lifecycle_management 4.0.3
ibm rational_team_concert 4.0.0.2
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_collaborative_lifecycle_management 4.0.0
ibm rational_collaborative_lifecycle_management 6.0.0
ibm rational_collaborative_lifecycle_management 4.0.4
ibm rational_team_concert 5.0.1
CVE-2016-9735 MEDIUM

IBM Jazz Foundation could allow an authenticated user to obtain sensitive information from stack traces. IBM X-Force ID: 119781,

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_rhapsody_design_manager 4.0.4
ibm rational_rhapsody_design_manager 4.0.5
ibm rational_software_architect_design_manager 6.0
ibm rational_collaborative_lifecycle_management 4.0.6
ibm rational_engineering_lifecycle_manager 4.0.7
ibm rational_quality_manager 4.0.6
ibm rational_software_architect_design_manager 6.0.1
ibm rational_team_concert 5.0
ibm rational_software_architect_design_manager 4.0.7
ibm rational_quality_manager 6.0.1
ibm rational_engineering_lifecycle_manager 5.0.2
ibm rational_rhapsody_design_manager 5.0.2
ibm rational_quality_manager 4.0.3
ibm rational_engineering_lifecycle_manager 6.0.2
ibm rational_collaborative_lifecycle_management 6.0.3
ibm rational_team_concert 4.0.1
ibm rational_team_concert 4.0.5
ibm rational_doors_next_generation 5.0
ibm rational_team_concert 4.0.2
ibm rational_quality_manager 5.0
ibm rational_collaborative_lifecycle_management 4.0.5
ibm rational_collaborative_lifecycle_management 4.0.7
ibm rational_collaborative_lifecycle_management 4.0.3
ibm rational_software_architect_design_manager 4.0.6
ibm rational_doors_next_generation 4.0.7
ibm rational_doors_next_generation 4.0.2
ibm rational_doors_next_generation 6.0
ibm rational_rhapsody_design_manager 4.0.7
ibm rational_engineering_lifecycle_manager 5.0
ibm rational_team_concert 5.0.2
ibm rational_rhapsody_design_manager 5.0
ibm rational_engineering_lifecycle_manager 6.0.3
ibm rational_team_concert 4.0.3
ibm rational_engineering_lifecycle_manager 4.0
ibm rational_collaborative_lifecycle_management 4.0.2
ibm rational_engineering_lifecycle_manager 4.0.2
ibm rational_quality_manager 4.0.1
ibm rational_team_concert 4.0.6
ibm rational_engineering_lifecycle_manager 4.0.5
ibm rational_software_architect_design_manager 5.0.2
ibm rational_engineering_lifecycle_manager 6.0.1
ibm rational_quality_manager 6.0
ibm rational_doors_next_generation 4.0.4
ibm rational_rhapsody_design_manager 6.0.3
ibm rational_quality_manager 4.0.4
ibm rational_engineering_lifecycle_manager 4.0.6
ibm rational_rhapsody_design_manager 4.0.3
ibm rational_doors_next_generation 5.0.2
ibm rational_quality_manager 4.0.2
ibm rational_software_architect_design_manager 6.0.3
ibm rational_doors_next_generation 4.0
ibm rational_doors_next_generation 5.0.1
ibm rational_software_architect_design_manager 4.0.1
ibm rational_collaborative_lifecycle_management 4.0.4
ibm rational_engineering_lifecycle_manager 4.0.3
ibm rational_engineering_lifecycle_manager 4.0.4
ibm rational_software_architect_design_manager 4.0.2
ibm rational_collaborative_lifecycle_management 6.0
ibm rational_engineering_lifecycle_manager 4.0.1
ibm rational_team_concert 6.0.1
ibm rational_rhapsody_design_manager 6.0
ibm rational_quality_manager 4.0.7
ibm rational_rhapsody_design_manager 4.0.6
ibm rational_rhapsody_design_manager 6.0.1
ibm rational_rhapsody_design_manager 6.0.2
ibm rational_software_architect_design_manager 5.0
ibm rational_software_architect_design_manager 4.0.4
ibm rational_team_concert 6.0.2
ibm rational_doors_next_generation 4.0.1
ibm rational_engineering_lifecycle_manager 5.0.1
ibm rational_team_concert 4.0.7
ibm rational_team_concert 6.0
ibm rational_collaborative_lifecycle_management 6.0.2
ibm rational_software_architect_design_manager 4.0.3
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_quality_manager 5.0.2
ibm rational_rhapsody_design_manager 4.0.1
ibm rational_rhapsody_design_manager 4.0.2
ibm rational_rhapsody_design_manager 4.0
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_quality_manager 6.0.3
ibm rational_doors_next_generation 6.0.1
ibm rational_rhapsody_design_manager 5.0.1
ibm rational_doors_next_generation 6.0.3
ibm rational_team_concert 4.0
ibm rational_doors_next_generation 4.0.5
ibm rational_collaborative_lifecycle_management 4.0
ibm rational_team_concert 6.0.3
ibm rational_doors_next_generation 4.0.6
ibm rational_doors_next_generation 4.0.3
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 4.0
ibm rational_collaborative_lifecycle_management 5.0
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_software_architect_design_manager 6.0.2
ibm rational_software_architect_design_manager 4.0.5
ibm rational_engineering_lifecycle_manager 6.0
ibm rational_team_concert 4.0.4
ibm rational_software_architect_design_manager 5.0.1
ibm rational_software_architect_design_manager 4.0
ibm rational_quality_manager 4.0.5
ibm rational_quality_manager 6.0.2
ibm rational_doors_next_generation 6.0.2
ibm rational_team_concert 5.0.1
CVE-2016-9736 MEDIUM

IBM WebSphere Application Server using malformed SOAP requests could allow a remote attacker to obtain sensitive information.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_application_server 9.0
ibm websphere_application_server 8.0
ibm websphere_application_server 8.5
CVE-2016-9737 LOW

IBM TRIRIGA 3.3, 3.4, and 3.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1996200.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tririga_application_platform 3.4.1.2
ibm tririga_application_platform 3.4.2.4
ibm tririga_application_platform 3.4.2.0
ibm tririga_application_platform 3.3.2.5
ibm tririga_application_platform 3.3.0.1
ibm tririga_application_platform 3.3.1.0
ibm tririga_application_platform 3.3.2.1
ibm tririga_application_platform 3.3.0.2
ibm tririga_application_platform 3.3.2.0
ibm tririga_application_platform 3.3.2.2
ibm tririga_application_platform 3.4.2.2
ibm tririga_application_platform 3.3.1.1
ibm tririga_application_platform 3.4.2.1
ibm tririga_application_platform 3.4.2.3
ibm tririga_application_platform 3.5.2
ibm tririga_application_platform 3.4.1.0
ibm tririga_application_platform 3.4.0.1
ibm tririga_application_platform 3.3.2.4
ibm tririga_application_platform 3.4.1.1
ibm tririga_application_platform 3.3.1.2
ibm tririga_application_platform 3.4.2.5
ibm tririga_application_platform 3.4.0.0
ibm tririga_application_platform 3.3.1.3
ibm tririga_application_platform 3.3.2.3
ibm tririga_application_platform 3.4.1.3
ibm tririga_application_platform 3.3.0.0
CVE-2016-9738 MEDIUM

IBM QRadar 7.2 and 7.3 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 119783.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-254,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.2
ibm qradar_security_information_and_event_manager 7.2.8
ibm qradar_security_information_and_event_manager 7.2.0
ibm qradar_security_information_and_event_manager 7.2.7
ibm qradar_security_information_and_event_manager 7.3.0
ibm qradar_security_information_and_event_manager 7.2.3
ibm qradar_security_information_and_event_manager 7.2.6
ibm qradar_security_information_and_event_manager 7.2.4
ibm qradar_security_information_and_event_manager 7.2.1
ibm qradar_security_information_and_event_manager 7.2.5
CVE-2016-9739 LOW

IBM Security Identity Manager Virtual Appliance stores user credentials in plain in clear text which can be read by a local user.

CVSS 2.0

Severity: LOW

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm security_identity_manager 7.0.1.0
ibm security_identity_manager 7.0.1.1
ibm security_identity_manager 7.0.1.4
ibm security_identity_manager 7.0.0.1
ibm security_identity_manager 7.0.0.0
ibm security_identity_manager 7.0.0.3
ibm security_identity_manager 7.0.1.2
ibm security_identity_manager 7.0.0.2
ibm security_identity_manager 7.0.1.3
CVE-2016-9740 HIGH

IBM QRadar 7.2 could allow a remote attacker to consume all resources on the server due to not properly restricting the size or amount of resources requested by an actor. IBM Reference #: 1999556.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-399,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.2
ibm qradar_security_information_and_event_manager 7.2.8
ibm qradar_security_information_and_event_manager 7.2.0
ibm qradar_security_information_and_event_manager 7.2.7
ibm qradar_security_information_and_event_manager 7.2.3
ibm qradar_security_information_and_event_manager 7.2.6
ibm qradar_security_information_and_event_manager 7.2.4
ibm qradar_security_information_and_event_manager 7.2.1
ibm qradar_security_information_and_event_manager 7.2.5
CVE-2016-9746 LOW

IBM Team Concert (RTC) 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 119821.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_team_concert 4.0.0.1
ibm rational_team_concert 4.0
ibm rational_collaborative_lifecycle_management 4.0.6
ibm rational_team_concert 5.0.2
ibm rational_collaborative_lifecycle_management 6.0
ibm rational_collaborative_lifecycle_management 4.0.1
ibm rational_team_concert 6.0.3
ibm rational_team_concert 5.0
ibm rational_team_concert 4.0.3
ibm rational_team_concert 6.0.1
ibm rational_collaborative_lifecycle_management 4.0.2
ibm rational_collaborative_lifecycle_management 5.0
ibm rational_team_concert 4.0.0
ibm rational_team_concert 4.0.6
ibm rational_team_concert 6.0.2
ibm rational_team_concert 5.0.0
ibm rational_team_concert 4.0.7
ibm rational_collaborative_lifecycle_management 6.0.3
ibm rational_team_concert 4.0.1
ibm rational_team_concert 6.0.0
ibm rational_team_concert 6.0
ibm rational_team_concert 4.0.5
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_team_concert 4.0.2
ibm rational_team_concert 4.0.4
ibm rational_collaborative_lifecycle_management 4.0.5
ibm rational_collaborative_lifecycle_management 4.0.7
ibm rational_collaborative_lifecycle_management 5.0.0
ibm rational_collaborative_lifecycle_management 4.0.3
ibm rational_team_concert 4.0.0.2
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_collaborative_lifecycle_management 4.0.0
ibm rational_collaborative_lifecycle_management 6.0.0
ibm rational_collaborative_lifecycle_management 4.0.4
ibm rational_team_concert 5.0.1
CVE-2016-9747 LOW

IBM RELM 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_engineering_lifecycle_manager 4.0.3
ibm rational_engineering_lifecycle_manager 4.0.4
ibm rational_collaborative_lifecycle_management 4.0.6
ibm rational_engineering_lifecycle_manager 4.0.7
ibm rational_engineering_lifecycle_manager 6.0.0
ibm rational_collaborative_lifecycle_management 4.0.1
ibm rational_engineering_lifecycle_manager 5.0.0
ibm rational_collaborative_lifecycle_management 4.0.2
ibm rational_engineering_lifecycle_manager 5.0.2
ibm rational_engineering_lifecycle_manager 5.0.1
ibm rational_engineering_lifecycle_manager 6.0.2
ibm rational_engineering_lifecycle_manager 4.0.5
ibm rational_collaborative_lifecycle_management 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_engineering_lifecycle_manager 6.0.1
ibm rational_collaborative_lifecycle_management 4.0.5
ibm rational_collaborative_lifecycle_management 4.0.7
ibm rational_collaborative_lifecycle_management 5.0.0
ibm rational_collaborative_lifecycle_management 4.0.3
ibm rational_engineering_lifecycle_manager 4.0.6
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_collaborative_lifecycle_management 4.0.0
ibm rational_collaborative_lifecycle_management 6.0.0
ibm rational_collaborative_lifecycle_management 4.0.4
CVE-2016-9748 MEDIUM

IBM Rational DOORS Next Generation 5.0 and 6.0 discloses sensitive information in error response messages that could be used for further attacks against the system.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_doors_next_generation 5.0.0
ibm rational_doors_next_generation 5.0.2
ibm rational_doors_next_generation 6.0.2
ibm rational_doors_next_generation 6.0.0
ibm rational_doors_next_generation 5.0
ibm rational_doors_next_generation 5.0.1
ibm rational_requirements_composer 4.0.7
ibm rational_doors_next_generation 6.0.1
CVE-2016-9749 LOW

IBM Campaign 9.1.0, 9.1.2, 10.0, and 10.1 could allow an authenticated user with access to the local network to bypass security due to lack of input validation. IBM X-Force ID: 120206.

CVSS 2.0

Severity: LOW

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm campaign 9.1.0.1
ibm campaign 9.1.0.5
ibm campaign 10.0.0.1
ibm campaign 10.0.0.2
ibm campaign 9.1.0.2
ibm campaign 9.1.2.2
ibm campaign 9.1.0.4
ibm campaign 9.1.0.11
ibm campaign 10.1
ibm campaign 9.1.0.6
ibm campaign 9.1.0.7
ibm campaign 9.1.0.9
ibm campaign 10.0.0.0
ibm campaign 9.1.0.10
ibm campaign 9.1.0.8
ibm campaign 9.1.0.3
ibm campaign 9.1.2.3
ibm campaign 9.1.0.12
ibm campaign 9.1.2.0
ibm campaign 9.1.2.1
ibm campaign 9.1.2.4
ibm campaign 9.1.0.0
CVE-2016-9750 MEDIUM

IBM QRadar 7.2 and 7.3 stores user credentials in plain in clear text which can be read by an authenticated user. IBM X-Force ID: 120207.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-255,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.0
ibm qradar_security_information_and_event_manager 7.3.0
CVE-2016-9879 MEDIUM

An issue was discovered in Pivotal Spring Security before 3.2.10, 4.1.x before 4.1.4, and 4.2.x before 4.2.1. Spring Security does not consider URL path parameters when processing security constraints. By adding a URL path parameter with an encoded "/" to a request, an attacker may be able to bypass a security constraint. The root cause of this issue is a lack of clarity regarding the handling of path parameters in the Servlet Specification. Some Servlet containers include path parameters in the value returned for getPathInfo() and some do not. Spring Security uses the value returned by getPathInfo() as part of the process of mapping requests to security constraints. The unexpected presence of path parameters can cause a constraint to be bypassed. Users of Apache Tomcat (all current versions) are not affected by this vulnerability since Tomcat follows the guidance previously provided by the Servlet Expert group and strips path parameters from the value returned by getContextPath(), getServletPath(), and getPathInfo(). Users of other Servlet containers based on Apache Tomcat may or may not be affected depending on whether or not the handling of path parameters has been modified. Users of IBM WebSphere Application Server 8.5.x are known to be affected. Users of other containers that implement the Servlet specification may be affected.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-417,

Products Affected

Vendor Product Version
ibm websphere_application_server 8.5.0.2
ibm websphere_application_server 8.5.5.2
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 8.5.5.7
vmware spring_security 3.2.8
vmware spring_security 3.2.0
vmware spring_security 4.1.2
vmware spring_security 4.2.0
ibm websphere_application_server 8.5.5.5
vmware spring_security 3.2.7
vmware spring_security 3.2.9
ibm websphere_application_server 8.5.5.8
vmware spring_security 4.1.3
ibm websphere_application_server 8.5.5.0
ibm websphere_application_server 8.5.5.9
vmware spring_security 3.2.4
vmware spring_security 3.2.5
ibm websphere_application_server 8.5.5.6
vmware spring_security 3.2.3
vmware spring_security 3.2.1
vmware spring_security 3.2.2
vmware spring_security 3.2.6
ibm websphere_application_server 8.5.5.3
ibm websphere_application_server 8.5.5.4
vmware spring_security 4.1.1
ibm websphere_application_server 8.5.0.1
ibm websphere_application_server 8.5.5.1
vmware spring_security 4.1.0
CVE-2016-9972 MEDIUM

IBM QRadar 7.2 and 7.3 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 120208.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.2
ibm qradar_security_information_and_event_manager 7.2.8
ibm qradar_security_information_and_event_manager 7.2.0
ibm qradar_security_information_and_event_manager 7.2.7
ibm qradar_security_information_and_event_manager 7.3.0
ibm qradar_security_information_and_event_manager 7.2.3
ibm qradar_security_information_and_event_manager 7.2.6
ibm qradar_security_information_and_event_manager 7.2.4
ibm qradar_security_information_and_event_manager 7.2.1
ibm qradar_security_information_and_event_manager 7.2.5
CVE-2016-9973 LOW

IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120209.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_rhapsody_design_manager 4.0.4
ibm rational_rhapsody_design_manager 4.0.5
ibm rational_software_architect_design_manager 6.0
ibm rational_collaborative_lifecycle_management 4.0.6
ibm rational_engineering_lifecycle_manager 4.0.7
ibm rational_quality_manager 4.0.6
ibm rational_software_architect_design_manager 6.0.1
ibm rational_team_concert 5.0
ibm rational_software_architect_design_manager 4.0.7
ibm rational_quality_manager 6.0.1
ibm rational_engineering_lifecycle_manager 5.0.2
ibm rational_rhapsody_design_manager 5.0.2
ibm rational_quality_manager 4.0.3
ibm rational_engineering_lifecycle_manager 6.0.2
ibm rational_collaborative_lifecycle_management 6.0.3
ibm rational_team_concert 4.0.1
ibm rational_team_concert 4.0.5
ibm rational_doors_next_generation 5.0
ibm rational_team_concert 4.0.2
ibm rational_quality_manager 5.0
ibm rational_collaborative_lifecycle_management 4.0.5
ibm rational_collaborative_lifecycle_management 4.0.7
ibm rational_collaborative_lifecycle_management 4.0.3
ibm rational_software_architect_design_manager 4.0.6
ibm rational_doors_next_generation 4.0.7
ibm rational_doors_next_generation 4.0.2
ibm rational_doors_next_generation 6.0
ibm rational_rhapsody_design_manager 4.0.7
ibm rational_engineering_lifecycle_manager 5.0
ibm rational_team_concert 5.0.2
ibm rational_collaborative_lifecycle_management 4.0.1
ibm rational_rhapsody_design_manager 5.0
ibm rational_engineering_lifecycle_manager 6.0.3
ibm rational_team_concert 4.0.3
ibm rational_collaborative_lifecycle_management 4.0.2
ibm rational_quality_manager 4.0.1
ibm rational_team_concert 4.0.6
ibm rational_engineering_lifecycle_manager 4.0.5
ibm rational_software_architect_design_manager 5.0.2
ibm rational_engineering_lifecycle_manager 6.0.1
ibm rational_quality_manager 6.0
ibm rational_doors_next_generation 4.0.4
ibm rational_rhapsody_design_manager 6.0.3
ibm rational_quality_manager 4.0.4
ibm rational_engineering_lifecycle_manager 4.0.6
ibm rational_rhapsody_design_manager 4.0.3
ibm rational_doors_next_generation 5.0.2
ibm rational_quality_manager 4.0.2
ibm rational_software_architect_design_manager 6.0.3
ibm rational_doors_next_generation 4.0
ibm rational_doors_next_generation 5.0.1
ibm rational_software_architect_design_manager 4.0.1
ibm rational_collaborative_lifecycle_management 4.0.4
ibm rational_engineering_lifecycle_manager 4.0.3
ibm rational_engineering_lifecycle_manager 4.0.4
ibm rational_software_architect_design_manager 4.0.2
ibm rational_collaborative_lifecycle_management 6.0
ibm rational_team_concert 6.0.1
ibm rational_rhapsody_design_manager 6.0
ibm rational_quality_manager 4.0.7
ibm rational_rhapsody_design_manager 4.0.6
ibm rational_rhapsody_design_manager 6.0.1
ibm rational_rhapsody_design_manager 6.0.2
ibm rational_software_architect_design_manager 5.0
ibm rational_software_architect_design_manager 4.0.4
ibm rational_team_concert 6.0.2
ibm rational_doors_next_generation 4.0.1
ibm rational_engineering_lifecycle_manager 5.0.1
ibm rational_team_concert 4.0.7
ibm rational_team_concert 6.0
ibm rational_collaborative_lifecycle_management 6.0.2
ibm rational_software_architect_design_manager 4.0.3
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_quality_manager 5.0.2
ibm rational_rhapsody_design_manager 4.0.1
ibm rational_rhapsody_design_manager 4.0.2
ibm rational_rhapsody_design_manager 4.0
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_quality_manager 6.0.3
ibm rational_doors_next_generation 6.0.1
ibm rational_rhapsody_design_manager 5.0.1
ibm rational_doors_next_generation 6.0.3
ibm rational_team_concert 4.0
ibm rational_doors_next_generation 4.0.5
ibm rational_collaborative_lifecycle_management 4.0
ibm rational_team_concert 6.0.3
ibm rational_doors_next_generation 4.0.6
ibm rational_doors_next_generation 4.0.3
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 4.0
ibm rational_collaborative_lifecycle_management 5.0
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_software_architect_design_manager 6.0.2
ibm rational_software_architect_design_manager 4.0.5
ibm rational_engineering_lifecycle_manager 6.0
ibm rational_team_concert 4.0.4
ibm rational_software_architect_design_manager 5.0.1
ibm rational_software_architect_design_manager 4.0
ibm rational_quality_manager 4.0.5
ibm rational_quality_manager 6.0.2
ibm rational_doors_next_generation 6.0.2
ibm rational_team_concert 5.0.1
CVE-2016-9975 MEDIUM

IBM Jazz for Service Management 1.1.2.1 and 1.1.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM Reference #: 1998714.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm dashboard_application_services_hub 3.1.3
ibm dashboard_application_services_hub 3.1.2.1
CVE-2016-9976 MEDIUM

IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-crafted URL request, which could allow the attacker to execute arbitrary code on the vulnerable server. IBM X-Force ID: 120252.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
ibm maximo_asset_management 7.6
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.5
ibm maximo_asset_management_essentials 7.5
ibm maximo_asset_management_essentials 7.1
CVE-2016-9977 MEDIUM

IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a remote attacker to hijack a user's session, caused by the failure to invalidate an existing session identifier. An attacker could exploit this vulnerability to gain access to another user's session. IBM X-Force ID: 120253.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm maximo_asset_management 7.6
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.5
ibm maximo_asset_management_essentials 7.5
ibm maximo_asset_management_essentials 7.1
CVE-2016-9978 MEDIUM

IBM Curam Social Program Management 5.2, 6.0, and 7.0 could allow an authenticated attacker to disclose sensitive information. IBM X-Force ID: 120254.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm curam_social_program_management 6.1.0.2
ibm curam_social_program_management 6.0.4.8
ibm curam_social_program_management 6.0.5.9
ibm curam_social_program_management 6.1.0.1
ibm curam_social_program_management 6.2.0.3
ibm curam_social_program_management 5.2
ibm curam_social_program_management 6.0.4.0
ibm curam_social_program_management 6.0.5.5
ibm curam_social_program_management 6.2.0.0
ibm curam_social_program_management 6.0.5.2
ibm curam_social_program_management 6.0.5.1
ibm curam_social_program_management 6.2.0.2
ibm curam_social_program_management 6.1.1.2
ibm curam_social_program_management 6.0.5.3
ibm curam_social_program_management 6.2.0.1
ibm curam_social_program_management 6.0.4.5
ibm curam_social_program_management 6.0.4.7
ibm curam_social_program_management 6.0
ibm curam_social_program_management 6.0.4.3
ibm curam_social_program_management 6.0.5.4
ibm curam_social_program_management 6.0.4.4
ibm curam_social_program_management 6.1.0.3
ibm curam_social_program_management 6.0.5
ibm curam_social_program_management 6.0.0
ibm curam_social_program_management 6.0.4.1
ibm curam_social_program_management 6.0.5.0
ibm curam_social_program_management 6.1.1.0
ibm curam_social_program_management 6.1.1.3
ibm curam_social_program_management 6.0.5.8
ibm curam_social_program_management 6.0.5.7
ibm curam_social_program_management 6.0.5.6
ibm curam_social_program_management 6.1.0.0
ibm curam_social_program_management 6.0.4.2
ibm curam_social_program_management 6.0.4.6
ibm curam_social_program_management 6.1.1.1
ibm curam_social_program_management 7.0.0.0
CVE-2016-9979 LOW

IBM Curam Social Program Management 5.2, 6.0, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120255.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm curam_social_program_management 6.1.0.2
ibm curam_social_program_management 6.0.4.8
ibm curam_social_program_management 6.0.5.9
ibm curam_social_program_management 6.1.0.1
ibm curam_social_program_management 6.2.0.3
ibm curam_social_program_management 6.0.4.0
ibm curam_social_program_management 6.0.5.5
ibm curam_social_program_management 6.2.0.0
ibm curam_social_program_management 6.0.5.2
ibm curam_social_program_management 6.0.5.1
ibm curam_social_program_management 6.2.0.2
ibm curam_social_program_management 6.1.1.2
ibm curam_social_program_management 6.0.5.3
ibm curam_social_program_management 6.2.0.1
ibm curam_social_program_management 6.0.4.5
ibm curam_social_program_management 6.0.4.7
ibm curam_social_program_management 6.0.4.3
ibm curam_social_program_management 6.0.5.4
ibm curam_social_program_management 6.0.4.4
ibm curam_social_program_management 6.1.0.3
ibm curam_social_program_management 6.0.5
ibm curam_social_program_management 6.0.4.1
ibm curam_social_program_management 6.0.5.0
ibm curam_social_program_management 6.1.1.0
ibm curam_social_program_management 6.1.1.3
ibm curam_social_program_management 6.0.5.8
ibm curam_social_program_management 6.0.5.7
ibm curam_social_program_management 6.0.5.6
ibm curam_social_program_management 6.1.0.0
ibm curam_social_program_management 6.0.4.2
ibm curam_social_program_management 6.0.4.6
ibm curam_social_program_management 6.1.1.1
ibm curam_social_program_management 7.0.0.0
CVE-2016-9980 LOW

IBM Curam Social Program Management 5.2, 6.0, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120256.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm curam_social_program_management 6.1.0.2
ibm curam_social_program_management 6.0.4.8
ibm curam_social_program_management 6.0.5.9
ibm curam_social_program_management 6.1.0.1
ibm curam_social_program_management 6.2.0.3
ibm curam_social_program_management 5.2
ibm curam_social_program_management 6.0.4.0
ibm curam_social_program_management 6.0.5.5
ibm curam_social_program_management 6.2.0.0
ibm curam_social_program_management 6.0.5.2
ibm curam_social_program_management 6.0.5.1
ibm curam_social_program_management 6.2.0.2
ibm curam_social_program_management 6.1.1.2
ibm curam_social_program_management 6.0.5.3
ibm curam_social_program_management 6.2.0.1
ibm curam_social_program_management 6.0.4.5
ibm curam_social_program_management 6.0.4.7
ibm curam_social_program_management 6.0
ibm curam_social_program_management 6.0.4.3
ibm curam_social_program_management 6.0.5.4
ibm curam_social_program_management 6.0.4.4
ibm curam_social_program_management 6.1.0.3
ibm curam_social_program_management 6.0.5
ibm curam_social_program_management 6.0.0
ibm curam_social_program_management 6.0.4.1
ibm curam_social_program_management 6.0.5.0
ibm curam_social_program_management 6.1.1.0
ibm curam_social_program_management 6.1.1.3
ibm curam_social_program_management 6.0.5.8
ibm curam_social_program_management 6.0.5.7
ibm curam_social_program_management 6.0.5.6
ibm curam_social_program_management 6.1.0.0
ibm curam_social_program_management 6.0.4.2
ibm curam_social_program_management 6.0.4.6
ibm curam_social_program_management 6.1.1.1
ibm curam_social_program_management 7.0.0.0
CVE-2016-9981 MEDIUM

IBM AppScan Enterprise Edition 9.0 contains an unspecified vulnerability that could allow an attacker to hijack a valid user's session. IBM X-Force ID: 120257

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-384,

Products Affected

Vendor Product Version
ibm security_appscan 9.0.1.0
ibm security_appscan 9.0.1.1
ibm security_appscan 9.0.0.0
ibm security_appscan 9.0.3.0
ibm security_appscan 9.0.3.5
ibm security_appscan 9.0.3.1
ibm security_appscan 9.0.2.0
ibm security_appscan 9.0.0.1
ibm security_appscan 9.0.3.4
ibm security_appscan 9.0.2.1
CVE-2016-9982 MEDIUM

IBM Sterling B2B Integrator Standard Edition 5.2 could allow an authenticated user to obtain sensitive information such as account lists due to improper access control. IBM X-Force ID: 120274.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2
CVE-2016-9983 LOW

IBM Sterling B2B Integrator Standard Edition 5.2 could allow an authenticated user with special privileges to view files that they should not have access to. IBM X-Force ID: 120275.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2
CVE-2016-9984 MEDIUM

IBM Maximo Asset Management 7.5 and 7.6 could allow a remote authenticated attacker to execute arbitrary commands on the system as administrator. IBM X-Force ID: 120276.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ibm maximo_asset_management 7.6
ibm maximo_asset_management 7.5
CVE-2016-9985 LOW

IBM Cognos Server 10.1.1 and 10.2 stores highly sensitive information in log files that could be read by a local user. IBM Reference #: 1999671.

CVSS 2.0

Severity: LOW

Problem Type: CWE-532,

Products Affected

Vendor Product Version
ibm cognos_business_intelligence 10.2
ibm cognos_business_intelligence 10.1.1
CVE-2016-9986 LOW

IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120552.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm jazz_reporting_service 6.0.3
ibm jazz_reporting_service 5.0.2
ibm jazz_reporting_service 6.0
ibm jazz_reporting_service 6.0.2
ibm jazz_reporting_service 6.0.1
ibm jazz_reporting_service 5.0
ibm jazz_reporting_service 5.0.1
CVE-2016-9987 LOW

IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120553.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm jazz_reporting_service 6.0.3
ibm jazz_reporting_service 5.0.2
ibm jazz_reporting_service 6.0
ibm jazz_reporting_service 6.0.2
ibm jazz_reporting_service 6.0.1
ibm jazz_reporting_service 5.0
ibm jazz_reporting_service 5.0.1
CVE-2016-9988 LOW

IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120554.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm jazz_reporting_service 6.0.3
ibm jazz_reporting_service 5.0.2
ibm jazz_reporting_service 6.0
ibm jazz_reporting_service 6.0.2
ibm jazz_reporting_service 6.0.1
ibm jazz_reporting_service 5.0
ibm jazz_reporting_service 5.0.1
CVE-2016-9989 LOW

IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120555.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm jazz_reporting_service 6.0.3
ibm jazz_reporting_service 5.0.2
ibm jazz_reporting_service 6.0
ibm jazz_reporting_service 6.0.2
ibm jazz_reporting_service 6.0.1
ibm jazz_reporting_service 5.0
ibm jazz_reporting_service 5.0.1
CVE-2016-9990 MEDIUM

IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1998824.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm inotes 8.5.2.1
ibm inotes 8.5.2.3
ibm inotes 9.0.1.0
ibm inotes 8.5.3.2
ibm inotes 9.0.1.3
ibm inotes 9.0.1.6
ibm inotes 8.5.3.4
ibm inotes 8.5.3.1
ibm inotes 8.5.3.0
ibm inotes 8.5.1.4
ibm inotes 9.0.1.1
ibm inotes 8.5.3.3
ibm inotes 8.5.3.5
ibm inotes 9.0.0.0
ibm inotes 9.0.1.2
ibm inotes 9.0.1.4
ibm inotes 8.5.2.0
ibm inotes 8.5.3.6
ibm inotes 8.5.0.0
ibm inotes 8.5.0.1
ibm inotes 8.5.1.1
ibm inotes 8.5.1.5
ibm inotes 8.5.2.2
ibm inotes 8.5.1.0
ibm inotes 9.0.1.5
ibm inotes 8.5.1.2
ibm inotes 8.5.1.3
CVE-2016-9991 MEDIUM

IBM Sterling Order Management 9.2 through 9.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 121314.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm sterling_selling_and_fulfillment_foundation 9.4.0
ibm sterling_selling_and_fulfillment_foundation 9.5.0
ibm sterling_selling_and_fulfillment_foundation 9.2.1
ibm sterling_selling_and_fulfillment_foundation 9.3.0
ibm sterling_selling_and_fulfillment_foundation 9.2.0
CVE-2016-9992 MEDIUM

IBM Kenexa LCMS Premier on Cloud 9.0, and 10.0.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM Reference #: 1992067.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm kenexa_lcms_premier 9.5
ibm kenexa_lcms_premier 10.2
ibm kenexa_lcms_premier 9.0
ibm kenexa_lcms_premier 10.0
ibm kenexa_lcms_premier 10.1
ibm kenexa_lcms_premier 9.2
ibm kenexa_lcms_premier 9.2.1
ibm kenexa_lcms_premier 9.3
ibm kenexa_lcms_premier 9.1
ibm kenexa_lcms_premier 9.4
CVE-2016-9993 MEDIUM

IBM Kenexa LCMS Premier on Cloud 9.0, and 10.0.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM Reference #: 1992067.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm kenexa_lcms_premier 9.5
ibm kenexa_lcms_premier 10.2
ibm kenexa_lcms_premier 9.0
ibm kenexa_lcms_premier 10.0
ibm kenexa_lcms_premier 10.1
ibm kenexa_lcms_premier 9.2
ibm kenexa_lcms_premier 9.2.1
ibm kenexa_lcms_premier 9.3
ibm kenexa_lcms_premier 9.1
ibm kenexa_lcms_premier 9.4
CVE-2016-9994 MEDIUM

IBM Kenexa LCMS Premier on Cloud 9.0, and 10.0.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM Reference #: 1976805.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm kenexa_lcms_premier 9.5
ibm kenexa_lcms_premier 9.0
ibm kenexa_lcms_premier 10.0
ibm kenexa_lcms_premier 9.2
ibm kenexa_lcms_premier 9.2.1
ibm kenexa_lcms_premier 9.3
ibm kenexa_lcms_premier 9.1
ibm kenexa_lcms_premier 9.4
CVE-2017-1092 HIGH

IBM Informix Open Admin Tool 11.5, 11.7, and 12.1 could allow an unauthorized user to execute arbitrary code as system admin on Windows servers. IBM X-Force ID: 120390.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm informix_open_admin_tool 11.5
ibm informix_open_admin_tool 12.1
ibm informix_open_admin_tool 11.7
CVE-2017-1093 HIGH

IBM AIX 6.1, 7.1, and 7.2 could allow a local user to exploit a vulnerability in the bellmail binary to gain root privileges.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm aix 7.2
ibm aix 6.1
ibm aix 7.1
CVE-2017-1096 LOW

IBM Jazz Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120656.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm jazz_reporting_service 6.0.3
ibm jazz_reporting_service 5.0.2
ibm jazz_reporting_service 6.0
ibm jazz_reporting_service 6.0.2
ibm jazz_reporting_service 6.0.1
ibm jazz_reporting_service 5.0
ibm jazz_reporting_service 5.0.1
CVE-2017-1097 MEDIUM

IBM Emptoris Strategic Supply Management Platform 10.0.0.x through 10.1.1.x is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 120657.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm emptoris_strategic_supply_management 10.0.2.5
ibm emptoris_strategic_supply_management 10.0.0.0
ibm emptoris_strategic_supply_management 10.1.0.1
ibm emptoris_strategic_supply_management 10.1.1.1
ibm emptoris_strategic_supply_management 10.0.2.9
ibm emptoris_strategic_supply_management 10.1.1.9
ibm emptoris_strategic_supply_management 10.0.2.4
ibm emptoris_strategic_supply_management 10.1.0.3
ibm emptoris_strategic_supply_management 10.1.1.3
ibm emptoris_strategic_supply_management 10.0.2.6
ibm emptoris_strategic_supply_management 10.1.1.0
ibm emptoris_strategic_supply_management 10.1.0.12
ibm emptoris_strategic_supply_management 10.1.1.12
ibm emptoris_strategic_supply_management 10.0.1.2
ibm emptoris_strategic_supply_management 10.0.1.4
ibm emptoris_strategic_supply_management 10.1.1.6
ibm emptoris_strategic_supply_management 10.1.1.7
ibm emptoris_strategic_supply_management 10.0.2.11
ibm emptoris_strategic_supply_management 10.0.2.3
ibm emptoris_strategic_supply_management 10.0.2.8
ibm emptoris_strategic_supply_management 10.0.2.13
ibm emptoris_strategic_supply_management 10.1.1.11
ibm emptoris_strategic_supply_management 10.0.2.14
ibm emptoris_strategic_supply_management 10.0.2.15
ibm emptoris_strategic_supply_management 10.1.0.9
ibm emptoris_strategic_supply_management 10.0.0.2
ibm emptoris_strategic_supply_management 10.0.4.0
ibm emptoris_strategic_supply_management 10.1.0.4
ibm emptoris_strategic_supply_management 10.1.0.7
ibm emptoris_strategic_supply_management 10.1.0.10
ibm emptoris_strategic_supply_management 10.0.2.17
ibm emptoris_strategic_supply_management 10.1.1.2
ibm emptoris_strategic_supply_management 10.0.2.10
ibm emptoris_strategic_supply_management 10.1.0.13
ibm emptoris_strategic_supply_management 10.1.0.6
ibm emptoris_strategic_supply_management 10.0.1.1
ibm emptoris_strategic_supply_management 10.0.2.16
ibm emptoris_strategic_supply_management 10.1.1.10
ibm emptoris_strategic_supply_management 10.1.0.14
ibm emptoris_strategic_supply_management 10.0.2.0
ibm emptoris_strategic_supply_management 10.0.2.2
ibm emptoris_strategic_supply_management 10.1.0.8
ibm emptoris_strategic_supply_management 10.1.1.5
ibm emptoris_strategic_supply_management 10.0.1.3
ibm emptoris_strategic_supply_management 10.1.0.2
ibm emptoris_strategic_supply_management 10.0.0.3
ibm emptoris_strategic_supply_management 10.0.0.1
ibm emptoris_strategic_supply_management 10.1.0.5
ibm emptoris_strategic_supply_management 10.1.0.11
ibm emptoris_strategic_supply_management 10.0.1.0
ibm emptoris_strategic_supply_management 10.1.1.8
ibm emptoris_strategic_supply_management 10.0.2.1
ibm emptoris_strategic_supply_management 10.0.2.7
ibm emptoris_strategic_supply_management 10.1.0.0
ibm emptoris_strategic_supply_management 10.0.2.12
ibm emptoris_strategic_supply_management 10.1.1.4
CVE-2017-1098 LOW

IBM Emptoris Supplier Lifecycle Management 10.1.0.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120658.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm emptoris_supplier_lifecycle_management 10.1.0.4
ibm emptoris_supplier_lifecycle_management 10.1.0.10
ibm emptoris_supplier_lifecycle_management 10.1.0.12
ibm emptoris_supplier_lifecycle_management 10.1.0.1
ibm emptoris_supplier_lifecycle_management 10.1.0.9
ibm emptoris_supplier_lifecycle_management 10.1.0.2
ibm emptoris_supplier_lifecycle_management 10.1.0.3
ibm emptoris_supplier_lifecycle_management 10.1.0.8
ibm emptoris_supplier_lifecycle_management 10.1.0.0
ibm emptoris_supplier_lifecycle_management 10.1.0.13
ibm emptoris_supplier_lifecycle_management 10.1.0.11
ibm emptoris_supplier_lifecycle_management 10.1.0.5
ibm emptoris_supplier_lifecycle_management 10.1.0.6
ibm emptoris_supplier_lifecycle_management 10.1.0.7
CVE-2017-1099 MEDIUM

IBM Jazz Foundation could expose potentially sensitive information to authenticated users through stack trace error conditions. IBM X-Force ID: 120659.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_rhapsody_design_manager 4.0.4
ibm rational_rhapsody_design_manager 4.0.5
ibm rational_software_architect_design_manager 6.0
ibm rational_collaborative_lifecycle_management 4.0.6
ibm rational_engineering_lifecycle_manager 4.0.7
ibm rational_quality_manager 4.0.6
ibm rational_software_architect_design_manager 6.0.1
ibm rational_team_concert 5.0
ibm rational_software_architect_design_manager 4.0.7
ibm rational_quality_manager 6.0.1
ibm rational_engineering_lifecycle_manager 5.0.2
ibm rational_rhapsody_design_manager 5.0.2
ibm rational_quality_manager 4.0.3
ibm rational_engineering_lifecycle_manager 6.0.2
ibm rational_collaborative_lifecycle_management 6.0.3
ibm rational_team_concert 4.0.1
ibm rational_team_concert 4.0.5
ibm rational_doors_next_generation 5.0
ibm rational_team_concert 4.0.2
ibm rational_quality_manager 5.0
ibm rational_collaborative_lifecycle_management 4.0.5
ibm rational_collaborative_lifecycle_management 4.0.7
ibm rational_collaborative_lifecycle_management 4.0.3
ibm rational_software_architect_design_manager 4.0.6
ibm rational_doors_next_generation 4.0.7
ibm rational_doors_next_generation 4.0.2
ibm rational_doors_next_generation 6.0
ibm rational_rhapsody_design_manager 4.0.7
ibm rational_engineering_lifecycle_manager 5.0
ibm rational_team_concert 5.0.2
ibm rational_rhapsody_design_manager 5.0
ibm rational_engineering_lifecycle_manager 6.0.3
ibm rational_team_concert 4.0.3
ibm rational_engineering_lifecycle_manager 4.0
ibm rational_collaborative_lifecycle_management 4.0.2
ibm rational_engineering_lifecycle_manager 4.0.2
ibm rational_quality_manager 4.0.1
ibm rational_team_concert 4.0.6
ibm rational_engineering_lifecycle_manager 4.0.5
ibm rational_software_architect_design_manager 5.0.2
ibm rational_engineering_lifecycle_manager 6.0.1
ibm rational_quality_manager 6.0
ibm rational_doors_next_generation 4.0.4
ibm rational_rhapsody_design_manager 6.0.3
ibm rational_quality_manager 4.0.4
ibm rational_engineering_lifecycle_manager 4.0.6
ibm rational_rhapsody_design_manager 4.0.3
ibm rational_doors_next_generation 5.0.2
ibm rational_quality_manager 4.0.2
ibm rational_software_architect_design_manager 6.0.3
ibm rational_doors_next_generation 4.0
ibm rational_doors_next_generation 5.0.1
ibm rational_software_architect_design_manager 4.0.1
ibm rational_collaborative_lifecycle_management 4.0.4
ibm rational_engineering_lifecycle_manager 4.0.3
ibm rational_engineering_lifecycle_manager 4.0.4
ibm rational_software_architect_design_manager 4.0.2
ibm rational_collaborative_lifecycle_management 6.0
ibm rational_engineering_lifecycle_manager 4.0.1
ibm rational_team_concert 6.0.1
ibm rational_rhapsody_design_manager 6.0
ibm rational_quality_manager 4.0.7
ibm rational_rhapsody_design_manager 4.0.6
ibm rational_rhapsody_design_manager 6.0.1
ibm rational_rhapsody_design_manager 6.0.2
ibm rational_software_architect_design_manager 5.0
ibm rational_software_architect_design_manager 4.0.4
ibm rational_team_concert 6.0.2
ibm rational_doors_next_generation 4.0.1
ibm rational_engineering_lifecycle_manager 5.0.1
ibm rational_team_concert 4.0.7
ibm rational_team_concert 6.0
ibm rational_collaborative_lifecycle_management 6.0.2
ibm rational_software_architect_design_manager 4.0.3
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_quality_manager 5.0.2
ibm rational_rhapsody_design_manager 4.0.1
ibm rational_rhapsody_design_manager 4.0.2
ibm rational_rhapsody_design_manager 4.0
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_quality_manager 6.0.3
ibm rational_doors_next_generation 6.0.1
ibm rational_rhapsody_design_manager 5.0.1
ibm rational_doors_next_generation 6.0.3
ibm rational_team_concert 4.0
ibm rational_doors_next_generation 4.0.5
ibm rational_collaborative_lifecycle_management 4.0
ibm rational_team_concert 6.0.3
ibm rational_doors_next_generation 4.0.6
ibm rational_doors_next_generation 4.0.3
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 4.0
ibm rational_collaborative_lifecycle_management 5.0
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_software_architect_design_manager 6.0.2
ibm rational_software_architect_design_manager 4.0.5
ibm rational_engineering_lifecycle_manager 6.0
ibm rational_team_concert 4.0.4
ibm rational_software_architect_design_manager 5.0.1
ibm rational_software_architect_design_manager 4.0
ibm rational_quality_manager 4.0.5
ibm rational_quality_manager 6.0.2
ibm rational_doors_next_generation 6.0.2
ibm rational_team_concert 5.0.1
CVE-2017-1100 LOW

IBM Quality Manager (RQM) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120661.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager 4.0.3
ibm rational_quality_manager 5.0.2
ibm rational_quality_manager 6.0
ibm rational_quality_manager 4.0.4
ibm rational_quality_manager 4.0.6
ibm rational_quality_manager 5.0
ibm rational_quality_manager 4.0.0.1
ibm rational_quality_manager 4.0.0.2
ibm rational_quality_manager 4.0.5
ibm rational_quality_manager 6.0.2
ibm rational_quality_manager 4.0.7
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 6.0.1
ibm rational_quality_manager 4.0.2
ibm rational_quality_manager 6.0.3
ibm rational_quality_manager 4.0
ibm rational_quality_manager 4.0.1
CVE-2017-1101 LOW

IBM Quality Manager (RQM) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120662.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager 4.0.3
ibm rational_quality_manager 5.0.2
ibm rational_quality_manager 6.0
ibm rational_quality_manager 4.0.4
ibm rational_quality_manager 4.0.6
ibm rational_quality_manager 5.0
ibm rational_quality_manager 4.0.0.1
ibm rational_quality_manager 4.0.0.2
ibm rational_quality_manager 4.0.5
ibm rational_quality_manager 6.0.2
ibm rational_quality_manager 4.0.7
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 6.0.1
ibm rational_quality_manager 4.0.2
ibm rational_quality_manager 6.0.3
ibm rational_quality_manager 4.0
ibm rational_quality_manager 4.0.1
CVE-2017-1102 LOW

IBM Quality Manager (RQM) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120663.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager 4.0.3
ibm rational_quality_manager 5.0.2
ibm rational_quality_manager 6.0
ibm rational_quality_manager 4.0.4
ibm rational_quality_manager 4.0.6
ibm rational_quality_manager 5.0
ibm rational_quality_manager 4.0.0.1
ibm rational_quality_manager 4.0.0.2
ibm rational_quality_manager 4.0.5
ibm rational_quality_manager 6.0.2
ibm rational_quality_manager 4.0.7
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 6.0.1
ibm rational_quality_manager 4.0.2
ibm rational_quality_manager 6.0.3
ibm rational_quality_manager 4.0
ibm rational_quality_manager 4.0.1
CVE-2017-1103 HIGH

IBM Team Concert (RTC) is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM X-Force ID: 120665.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm rational_team_concert 5.0.2
ibm rational_quality_manager 4.0.6
ibm rational_team_concert 6.0.3
ibm rational_team_concert 4.0.3
ibm rational_team_concert 6.0.1
ibm rational_quality_manager 4.0.7
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 6.0.1
ibm rational_team_concert 4.0.0
ibm rational_quality_manager 4.0.1
ibm rational_team_concert 4.0.6
ibm rational_team_concert 6.0.2
ibm rational_quality_manager 4.0.0
ibm rational_quality_manager 4.0.3
ibm rational_team_concert 5.0.0
ibm rational_team_concert 4.0.7
ibm rational_team_concert 4.0.1
ibm rational_team_concert 6.0.0
ibm rational_quality_manager 5.0.0
ibm rational_team_concert 4.0.5
ibm rational_team_concert 4.0.2
ibm rational_quality_manager 5.0.2
ibm rational_quality_manager 4.0.4
ibm rational_team_concert 4.0.4
ibm rational_quality_manager 4.0.5
ibm rational_quality_manager 6.0.2
ibm rational_quality_manager 6.0.0
ibm rational_quality_manager 4.0.2
ibm rational_team_concert 5.0.1
CVE-2017-1104 LOW

IBM Quality Manager (RQM) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120666.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager 4.0.3
ibm rational_quality_manager 5.0.2
ibm rational_quality_manager 6.0
ibm rational_quality_manager 4.0.4
ibm rational_quality_manager 4.0.6
ibm rational_quality_manager 5.0
ibm rational_quality_manager 4.0.0.1
ibm rational_quality_manager 4.0.0.2
ibm rational_quality_manager 4.0.5
ibm rational_quality_manager 6.0.2
ibm rational_quality_manager 4.0.7
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 6.0.1
ibm rational_quality_manager 4.0.2
ibm rational_quality_manager 6.0.3
ibm rational_quality_manager 4.0
ibm rational_quality_manager 4.0.1
CVE-2017-1105 LOW

IBM DB2 for Linux, UNIX and Windows 9.2, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) is vulnerable to a buffer overflow that could allow a local user to overwrite DB2 files or cause a denial of service. IBM X-Force ID: 120668.

CVSS 2.0

Severity: LOW

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2 11.1
ibm data_server_runtime_client -
ibm db2_connect 10.1
ibm data_server_client -
ibm db2 9.7
ibm data_server_driver_for_odbc_and_cli -
ibm data_server_driver_package -
ibm db2_connect 10.5
ibm db2 10.1
ibm db2_connect 9.7
ibm db2_connect 11.1.0.0
CVE-2017-1106 LOW

IBM Curam Social Program Management 5.2, 6.0, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120744.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm curam_social_program_management 6.1.0.2
ibm curam_social_program_management 6.1.0.4
ibm curam_social_program_management 6.0.4.8
ibm curam_social_program_management 6.0.5.9
ibm curam_social_program_management 6.1.0.1
ibm curam_social_program_management 6.0.4.9
ibm curam_social_program_management 6.2.0.3
ibm curam_social_program_management 6.0.5.10
ibm curam_social_program_management 5.2
ibm curam_social_program_management 6.0.4.0
ibm curam_social_program_management 6.0.5.5
ibm curam_social_program_management 6.2.0.0
ibm curam_social_program_management 6.0.5.2
ibm curam_social_program_management 6.0.5.1
ibm curam_social_program_management 6.2.0.2
ibm curam_social_program_management 6.1.1.2
ibm curam_social_program_management 6.0.5.3
ibm curam_social_program_management 6.2.0.1
ibm curam_social_program_management 6.0.4.5
ibm curam_social_program_management 7.0.0.1
ibm curam_social_program_management 6.0.4.7
ibm curam_social_program_management 6.0
ibm curam_social_program_management 6.0.4.3
ibm curam_social_program_management 6.0.5.4
ibm curam_social_program_management 6.0.4.4
ibm curam_social_program_management 6.1.0.3
ibm curam_social_program_management 6.0.5
ibm curam_social_program_management 6.0.0
ibm curam_social_program_management 6.0.4.1
ibm curam_social_program_management 6.0.5.0
ibm curam_social_program_management 6.1.1.0
ibm curam_social_program_management 6.1.1.3
ibm curam_social_program_management 6.2.0.4
ibm curam_social_program_management 6.0.5.8
ibm curam_social_program_management 6.0.5.7
ibm curam_social_program_management 6.0.5.6
ibm curam_social_program_management 6.1.0.0
ibm curam_social_program_management 6.0.4.2
ibm curam_social_program_management 6.1.1.4
ibm curam_social_program_management 6.0.4.6
ibm curam_social_program_management 6.1.1.1
ibm curam_social_program_management 7.0.0.0
CVE-2017-1110 MEDIUM

IBM Curam Social Program Management 6.0, 6.1, 6.2, and 7.0 contains an unspecified vulnerability that could allow an authenticated user to view the incidents of a higher privileged user. IBM X-Force ID: 120915.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm curam_social_program_management 6.1.0.2
ibm curam_social_program_management 6.1.0.4
ibm curam_social_program_management 6.0.4.8
ibm curam_social_program_management 6.0.5.9
ibm curam_social_program_management 6.1.0.1
ibm curam_social_program_management 6.0.4.9
ibm curam_social_program_management 6.2.0.3
ibm curam_social_program_management 6.0.5.10
ibm curam_social_program_management 6.0.4.0
ibm curam_social_program_management 6.0.5.5
ibm curam_social_program_management 6.2.0.0
ibm curam_social_program_management 6.0.5.2
ibm curam_social_program_management 6.0.5.1
ibm curam_social_program_management 6.2.0.2
ibm curam_social_program_management 6.1.1.2
ibm curam_social_program_management 6.0.5.3
ibm curam_social_program_management 6.2.0.1
ibm curam_social_program_management 6.0.4.5
ibm curam_social_program_management 7.0.0.1
ibm curam_social_program_management 6.0.4.7
ibm curam_social_program_management 6.0.4.3
ibm curam_social_program_management 6.0.5.4
ibm curam_social_program_management 6.0.4.4
ibm curam_social_program_management 6.1.0.3
ibm curam_social_program_management 6.0.5
ibm curam_social_program_management 6.0.4.1
ibm curam_social_program_management 6.0.5.0
ibm curam_social_program_management 6.1.1.0
ibm curam_social_program_management 6.1.1.3
ibm curam_social_program_management 6.2.0.4
ibm curam_social_program_management 6.0.5.8
ibm curam_social_program_management 6.0.5.7
ibm curam_social_program_management 6.0.5.6
ibm curam_social_program_management 6.1.0.0
ibm curam_social_program_management 6.0.4.2
ibm curam_social_program_management 6.1.1.4
ibm curam_social_program_management 6.0.4.6
ibm curam_social_program_management 6.1.1.1
ibm curam_social_program_management 7.0.0.0
CVE-2017-1113 LOW

IBM Rational Team Concert (RTC) 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 121151.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_team_concert 5.0.0
ibm rational_team_concert 4.0.0.1
ibm rational_team_concert 4.0.7
ibm rational_team_concert 4.0.1
ibm rational_team_concert 6.0.0
ibm rational_team_concert 6.0
ibm rational_team_concert 4.0
ibm rational_team_concert 4.0.5
ibm rational_team_concert 4.0.2
ibm rational_team_concert 5.0.2
ibm rational_team_concert 4.0.4
ibm rational_team_concert 6.0.3
ibm rational_team_concert 5.0
ibm rational_team_concert 4.0.3
ibm rational_team_concert 6.0.1
ibm rational_team_concert 4.0.0.2
ibm rational_team_concert 4.0.0
ibm rational_team_concert 4.0.6
ibm rational_team_concert 5.0.1
ibm rational_team_concert 6.0.2
CVE-2017-1114 LOW

IBM Campaign 9.1, 9.1.2, and 10 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 121152.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm campaign 10.0
ibm campaign 9.1
ibm campaign 9.1.2
CVE-2017-1115 LOW

IBM Campaign 9.1, 9.1.2, and 10 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 121153.

CVSS 2.0

Severity: LOW

Problem Type: CWE-74,

Products Affected

Vendor Product Version
ibm campaign 10.0
ibm campaign 9.1
ibm campaign 9.1.2
CVE-2017-1116 MEDIUM

IBM Campaign 8.6, 9.0, 9.1, 9.1.1, 9.1.2, and 10.0 contains excessive details on the client side which could provide information useful for an authenticated user to conduct other attacks. IBM X-Force ID: 121154.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm campaign 10.0
ibm campaign 8.6
ibm campaign 9.1
ibm campaign 9.1.1
ibm campaign 9.1.2
ibm campaign 9.0
CVE-2017-1117 LOW

IBM WebSphere MQ 8.0 and 9.0 could allow an authenticated user to cause a denial of service to the MQXR channel when trace is enabled. IBM X-Force ID: 121155.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_mq 8.0.0.0
ibm websphere_mq 8.0.0.5
ibm websphere_mq 8.0.0.1
ibm websphere_mq 8.0.0.3
ibm websphere_mq 8.0.0.4
ibm websphere_mq 9.0.1
ibm websphere_mq 9.0.0.0
ibm websphere_mq 8.0
ibm websphere_mq 8.0.0.2
CVE-2017-1118 MEDIUM

IBM WebSphere MQ Internet Pass-Thru 2.0 and 2.1 could allow n attacker to cause the MQIPT to stop responding due to an incorrectly configured security policy. IBM X-Force ID: 121156.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_mq_internet_pass-thru 2.1
ibm websphere_mq_internet_pass-thru 2.0
CVE-2017-1119 MEDIUM

IBM Marketing Operations 9.1.0, 9.1.2, and 10.1 could allow a remote attacker to obtain sensitive information. An attacker could send a specially-crafted request to cause an error message to be returned containing the full root path. An attacker could use this information to launch further attacks against the affected system. IBM X-Force ID: 121171.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm marketing_operations *
ibm marketing_operations 10.1
CVE-2017-1120 MEDIUM

IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 2000152.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 9.0
ibm websphere_portal 8.5
CVE-2017-1121 LOW

IBM WebSphere Application Server 7.0, 8.0, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1997743

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_application_server 9.0
ibm websphere_application_server 7.0
ibm websphere_application_server 8.0
ibm websphere_application_server 8.5
ibm websphere_application_server 8.5.5
CVE-2017-1122 MEDIUM

IBM Security Guardium 8.2, 9.0, and 10.0 contains a vulnerability that could allow a local attacker with CLI access to inject arbitrary commands which would be executed as root. IBM X-Force ID: 121174.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm security_guardium 9.0
ibm security_guardium 10.0.1
ibm security_guardium 10.0
ibm security_guardium 9.1
ibm security_guardium 8.2
ibm security_guardium 10.1
ibm security_guardium 10.1.2
ibm security_guardium 9.5
CVE-2017-1124 LOW

IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a local attacker to obtain sensitive information using HTTP Header Injection. IBM Reference #: 1998053.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm maximo_asset_management 7.1.1.9
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.6.0.3
ibm maximo_asset_management 7.5.0.1
ibm maximo_asset_management 7.5.0.10
ibm maximo_asset_management 7.1.1.10
ibm maximo_asset_management 7.6.0.4
ibm maximo_asset_management 7.1.1.1
ibm maximo_asset_management 7.6
ibm maximo_asset_management 7.6.0.0
ibm maximo_asset_management 7.1.1.12
ibm maximo_asset_management 7.1.1.3
ibm maximo_asset_management 7.6.0.5
ibm maximo_asset_management 7.5.0.3
ibm maximo_asset_management 7.6.0.2
ibm maximo_asset_management 7.5.0.9
ibm maximo_asset_management 7.5.0.6
ibm maximo_asset_management 7.5.0.0
ibm maximo_asset_management 7.1.1.7
ibm maximo_asset_management 7.5.0.7
ibm maximo_asset_management 7.5.0.4
ibm maximo_asset_management 7.5.0.5
ibm maximo_asset_management 7.1.1.2
ibm maximo_asset_management 7.1.1.6
ibm maximo_asset_management 7.1.1.5
ibm maximo_asset_management 7.1.1.11
ibm maximo_asset_management 7.1.2
ibm maximo_asset_management 7.6.0.1
ibm maximo_asset_management 7.1.1
ibm maximo_asset_management 7.1.1.8
ibm maximo_asset_management 7.5.0.8
CVE-2017-1125 LOW

IBM Cognos Analytics 10.1 and 10.2 could allow a local user to craft a URL which could confirm the existence of and expose postial contents of a file. IBM X-Force ID: 121340.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm cognos_business_intelligence_server 10.2.1.1
ibm cognos_business_intelligence_server 10.2.0
ibm cognos_business_intelligence_server 10.2.1
ibm cognos_business_intelligence_server 10.2.2
ibm cognos_business_intelligence_server 10.1.1
CVE-2017-1126 MEDIUM

IBM WebSphere Message Broker (IBM Integration Bus 9.0 and 10.0) could allow an unauthorized user to obtain sensitive information about software versions that could lead to further attacks. IBM X-Force ID: 121341.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm integration_bus 10.0.0.3
ibm websphere_message_broker 8.0.0.4
ibm integration_bus 10.0.0.0
ibm integration_bus 10.0.0.7
ibm integration_bus 9.0.0.0
ibm integration_bus 10.0.0.1
ibm websphere_message_broker 8.0.0.7
ibm integration_bus 9.0.0.8
ibm integration_bus 10.0.0.4
ibm integration_bus 9.0.0.2
ibm integration_bus 9.0.0.7
ibm integration_bus 10.0.0.6
ibm integration_bus 10.0.0.5
ibm integration_bus 10.0.0.2
ibm websphere_message_broker 8.0.0.6
ibm integration_bus 10.0.0.9
ibm integration_bus 9.0.0.5
ibm integration_bus 9.0.0.4
ibm websphere_message_broker 8.0.0.0
ibm integration_bus 10.0.0.8
ibm websphere_message_broker 8.0.0.3
ibm websphere_message_broker 8.0.0.2
ibm integration_bus 9.0.0.6
ibm websphere_message_broker 8.0.0.5
ibm integration_bus 9.0.0.1
ibm websphere_message_broker 8.0.0.1
ibm websphere_message_broker 8.0.0.8
CVE-2017-1127 LOW

IBM Rational DOORS Next Generation 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_doors_next_generation 6.0
ibm rational_requirements_composer 4.0.4
ibm rational_doors_next_generation 6.0.0
ibm rational_requirements_composer 4.0.2
ibm rational_doors_next_generation 5.0
ibm rational_requirements_composer 4.0.1
ibm rational_requirements_composer 4.0.3
ibm rational_requirements_composer 4.0.7
ibm rational_requirements_composer 4.0.0.1
ibm rational_doors_next_generation 5.0.0
ibm rational_doors_next_generation 5.0.2
ibm rational_doors_next_generation 6.0.2
ibm rational_requirements_composer 4.0.0
ibm rational_requirements_composer 4.0.0.2
ibm rational_requirements_composer 4.0.5
ibm rational_requirements_composer 4.0.6
ibm rational_doors_next_generation 5.0.1
ibm rational_requirements_composer 4.0
ibm rational_doors_next_generation 6.0.1
CVE-2017-1128 LOW

IBM Rational DOORS Next Generation 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_requirements_composer 4.0.4
ibm rational_doors_next_generation 6.0.0
ibm rational_requirements_composer 4.0.2
ibm rational_doors_next_generation 5.0
ibm rational_requirements_composer 4.0.1
ibm rational_requirements_composer 4.0.3
ibm rational_requirements_composer 4.0.7
ibm rational_requirements_composer 4.0.0.1
ibm rational_doors_next_generation 5.0.0
ibm rational_doors_next_generation 5.0.2
ibm rational_doors_next_generation 6.0.2
ibm rational_requirements_composer 4.0.0
ibm rational_requirements_composer 4.0.0.2
ibm rational_requirements_composer 4.0.5
ibm rational_requirements_composer 4.0.6
ibm rational_doors_next_generation 5.0.1
ibm rational_requirements_composer 4.0
ibm rational_doors_next_generation 6.0.1
CVE-2017-1129 MEDIUM

IBM Notes 8.5 and 9.0 is vulnerable to a denial of service. If a user is persuaded to click on a malicious link, it could cause the Notes client to hang and have to be restarted. IBM X-Force ID: 121370.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm inotes 8.5.2.1
ibm inotes 9.0.1.1
ibm expeditor 6.2.1
ibm inotes 9.0.1.8
ibm inotes 9.0.0.0
ibm expeditor 6.2.3
ibm inotes 9.0.1.0
ibm expeditor 6.2.2
ibm inotes 8.5.2.0
ibm inotes 8.5.3.6
ibm inotes 8.5.0.0
ibm inotes 8.5.1.1
ibm inotes 8.5.1.5
ibm inotes 8.5.1.0
ibm inotes 8.5.3.1
ibm inotes 8.5.3.0
ibm inotes 8.5.2.4
CVE-2017-1130 MEDIUM

IBM Notes 8.5 and 9.0 is vulnerable to a denial of service. If a user is persuaded to click on a malicious link, it would open up many file select dialog boxes which would cause the client hang and have to be restarted. IBM X-Force ID: 121371.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm inotes 8.5.2.1
ibm inotes 9.0.1.1
ibm inotes 9.0.1.8
ibm inotes 9.0.0.0
ibm inotes 9.0.1.0
ibm inotes 8.5.2.0
ibm inotes 8.5.3.6
ibm inotes 8.5.0.0
ibm inotes 8.5.1.1
ibm inotes 8.5.1.5
ibm inotes 8.5.1.0
ibm inotes 8.5.3.1
ibm inotes 8.5.3.0
ibm inotes 8.5.2.4
CVE-2017-1131 MEDIUM

IBM Sterling B2B Integrator Standard Edition 5.2 could allow an authenticated user to obtain sensitive information by using unsupported, specially crafted HTTP commands. IBM X-Force ID: 121375.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2
CVE-2017-1132 LOW

IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 121418.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2
CVE-2017-1133 LOW

IBM QRadar 7.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1999534.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.2
ibm qradar_incident_forensics 7.2.3
ibm qradar_security_information_and_event_manager 7.2.8
ibm qradar_incident_forensics 7.2.6
ibm qradar_incident_forensics 7.2.8
ibm qradar_incident_forensics 7.2.2
ibm qradar_incident_forensics 7.2.5
ibm qradar_incident_forensics 7.2.1
ibm qradar_security_information_and_event_manager 7.2.5
ibm qradar_security_information_and_event_manager 7.2.0
ibm qradar_security_information_and_event_manager 7.2.7
ibm qradar_incident_forensics 7.2.4
ibm qradar_incident_forensics 7.2.0
ibm qradar_security_information_and_event_manager 7.2.3
ibm qradar_security_information_and_event_manager 7.2.6
ibm qradar_security_information_and_event_manager 7.2.4
ibm qradar_security_information_and_event_manager 7.2.1
ibm qradar_incident_forensics 7.2.7
CVE-2017-1134 HIGH

IBM Reliable Scalable Cluster Technology could allow a local user to escalate their privileges to gain root access. IBM Reference #: 1998459.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm power_hardware_management_console 3.3.2
ibm power_hardware_management_console 4.1
CVE-2017-1137 MEDIUM

IBM WebSphere Application Server 8.0 and 8.5.5 could provide weaker than expected security. A remote attacker could exploit this weakness to obtain sensitive information and gain unauthorized access to the admin console. IBM X-Force ID: 121549.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_application_server 8.0
ibm websphere_application_server 8.5
ibm websphere_application_server 8.5.5
CVE-2017-1140 LOW

IBM Business Process Manager 8.0 and 8.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm business_process_manager 8.0.1.2
ibm business_process_manager 8.5.6.0
ibm business_process_manager 8.0.1.1
ibm business_process_manager 8.5.5.0
ibm business_process_manager 8.0.1.0
ibm business_process_manager 8.0.0.0
ibm business_process_manager 8.5.7.0
ibm business_process_manager 8.5.0.1
ibm business_process_manager 8.0.1.3
ibm business_process_manager 8.5.0.0
ibm business_process_manager 8.5.0.2
CVE-2017-1141 MEDIUM

IBM Insights Foundation for Energy 1.0, 1.5, and 1.6 could allow an authenticated user to obtain sensitive information from error messages. IBM X-Force ID: 121907.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm insights_foundation_for_energy 1.0
ibm insights_foundation_for_energy 1.6
ibm insights_foundation_for_energy 1.5
CVE-2017-1142 MEDIUM

IBM Kenexa LCMS Premier on Cloud 9.x and 10.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set the secure flag for the session cookie in SSL mode. By intercepting its transmission within an HTTP session, an attacker could exploit this vulnerability to capture the cookie and obtain sensitive information. IBM Reference #: 1998874.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm kenexa_lcms_premier 9.5
ibm kenexa_lcms_premier 10.2
ibm kenexa_lcms_premier 10.0
ibm kenexa_lcms_premier 10.3
ibm kenexa_lcms_premier 9.2
ibm kenexa_lcms_premier 9.2.1
ibm kenexa_lcms_premier 9.3
ibm kenexa_lcms_premier 9.1
ibm kenexa_lcms_premier 9.4
CVE-2017-1143 LOW

IBM Kenexa LCMS Premier on Cloud 9.x and 10.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM Reference #: 1998874.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm kenexa_lcms_premier 9.5
ibm kenexa_lcms_premier 10.2
ibm kenexa_lcms_premier 10.0
ibm kenexa_lcms_premier 10.3
ibm kenexa_lcms_premier 9.2
ibm kenexa_lcms_premier 9.2.1
ibm kenexa_lcms_premier 9.3
ibm kenexa_lcms_premier 9.1
ibm kenexa_lcms_premier 9.4
CVE-2017-1144 LOW

IBM WebSphere Message Broker could allow a local user with specialized access to prevent the message broker from starting. IBM X-Force ID: 122033.

CVSS 2.0

Severity: LOW

Problem Type: CWE-426,

Products Affected

Vendor Product Version
ibm integration_bus 10.0.0.3
ibm websphere_message_broker 8.0.0.4
ibm integration_bus 9.0
ibm integration_bus 10.0.0.7
ibm integration_bus 10.0.0.1
ibm websphere_message_broker 8.0.0.7
ibm websphere_message_broker 8.0
ibm integration_bus 10.0.0.4
ibm integration_bus 9.0.0.2
ibm integration_bus 9.0.0.7
ibm integration_bus 10.0.0.6
ibm integration_bus 10.0.0.5
ibm integration_bus 10.0.0.2
ibm websphere_message_broker 8.0.0.6
ibm integration_bus 9.0.0.5
ibm integration_bus 9.0.0.4
ibm websphere_message_broker 8.0.0.3
ibm websphere_message_broker 8.0.0.2
ibm integration_bus 10.0
ibm integration_bus 9.0.0.6
ibm websphere_message_broker 8.0.0.5
ibm integration_bus 9.0.0.1
ibm websphere_message_broker 8.0.0.1
ibm integration_bus 9.0.0.3
ibm websphere_message_broker 8.0.0.8
CVE-2017-1145 HIGH

IBM WebSphere MQ 8.0.0.6 does not properly terminate channel agents when they are no longer needed, which could allow a user to cause a denial of service through resource exhaustion. IBM Reference #: 1999672.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-404,

Products Affected

Vendor Product Version
ibm websphere_mq 8.0.0.6
CVE-2017-1146 LOW

IBM Content Navigator 2.0.3 and 3.0.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1999736.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm content_navigator 3.0.0
ibm content_navigator 2.0.3
CVE-2017-1147 LOW

IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 122200.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm openpages_grc_platform 7.1.0.0
ibm openpages_grc_platform 7.2.0.0
ibm openpages_grc_platform 7.2.0.1
ibm openpages_grc_platform 7.1.0.2
ibm openpages_grc_platform 7.2.0.2
ibm openpages_grc_platform 7.1.0.1
ibm openpages_grc_platform 7.2.0.3
ibm openpages_grc_platform 7.3.0.0
ibm openpages_grc_platform 7.2.0.4
ibm openpages_grc_platform 7.1.0.3
CVE-2017-1148 MEDIUM

IBM OpenPages GRC Platform 7.2 and 7.3 with OpenPages Loss Event Entry (LEE) application could allow a user to obtain sensitive information including private APIs that could be used in further attacks against the system. IBM X-Force ID: 122201.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm openpages_grc_platform 7.1.0.0
ibm openpages_grc_platform 7.2.0.0
ibm openpages_grc_platform 7.2.0.1
ibm openpages_grc_platform 7.1.0.2
ibm openpages_grc_platform 7.2.0.2
ibm openpages_grc_platform 7.1.0.1
ibm openpages_grc_platform 7.2.0.3
ibm openpages_grc_platform 7.3.0.0
ibm openpages_grc_platform 7.2.0.4
ibm openpages_grc_platform 7.1.0.3
CVE-2017-1149 HIGH

IBM UrbanCode Deploy (UCD) 6.0, 6.1, and 6.2 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM X-Force ID: 122202.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm urbancode_deploy 6.1.0.3
ibm urbancode_deploy 6.0.1.3
ibm urbancode_deploy 6.1.1.8
ibm urbancode_deploy 6.0.1.4
ibm urbancode_deploy 6.0.1.7
ibm urbancode_deploy 6.1.1.1
ibm urbancode_deploy 6.1.1.2
ibm urbancode_deploy 6.1.1.5
ibm urbancode_deploy 6.2.1
ibm urbancode_deploy 6.0.1.0
ibm urbancode_deploy 6.0.1.13
ibm urbancode_deploy 6.1.0.1
ibm urbancode_deploy 6.2.0.0
ibm urbancode_deploy 6.0.1.5
ibm urbancode_deploy 6.1.1.6
ibm urbancode_deploy 6.1.0.4
ibm urbancode_deploy 6.1.1.0
ibm urbancode_deploy 6.1.3.1
ibm urbancode_deploy 6.2.0.1
ibm urbancode_deploy 6.1.3.2
ibm urbancode_deploy 6.2.1.1
ibm urbancode_deploy 6.1
ibm urbancode_deploy 6.1.2
ibm urbancode_deploy 6.0.1.6
ibm urbancode_deploy 6.0.1.11
ibm urbancode_deploy 6.2.0.2
ibm urbancode_deploy 6.0.1.8
ibm urbancode_deploy 6.1.3
ibm urbancode_deploy 6.0.1.9
ibm urbancode_deploy 6.1.1.3
ibm urbancode_deploy 6.0.1.10
ibm urbancode_deploy 6.0.1.12
ibm urbancode_deploy 6.0.1.2
ibm urbancode_deploy 6.1.1.7
ibm urbancode_deploy 6.1.1.4
ibm urbancode_deploy 6.0.1.1
ibm urbancode_deploy 6.0
ibm urbancode_deploy 6.2.0.201
CVE-2017-1150 LOW

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.1, 10.5, and 11.1 could allow an authenticated attacker with specialized access to tables that they should not be permitted to view. IBM Reference #: 1999515.

CVSS 2.0

Severity: LOW

Problem Type: CWE-269,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2 11.1
ibm db2 10.1
CVE-2017-1151 MEDIUM

IBM WebSphere Application Server 8.0, 8.5, 8.5.5, and 9.0 using OpenID Connect (OIDC) configured with a Trust Association Interceptor (TAI) could allow a user to gain elevated privileges on the system. IBM Reference #: 1999293.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_application_server 9.0
ibm websphere_application_server 8.0
ibm websphere_application_server 8.5
ibm websphere_application_server 8.5.5
CVE-2017-1152 MEDIUM

IBM Financial Transaction Manager 3.0.1 and 3.0.2 does not properly update the SESSIONID with each request, which could allow a user to obtain the ID in further attacks against the system. IBM X-Force ID: 122293.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-384,

Products Affected

Vendor Product Version
ibm financial_transaction_manager 3.0.2.0
ibm financial_transaction_manager 3.0.1.0
CVE-2017-1153 MEDIUM

IBM TRIRIGA Report Manager 3.2 through 3.5 contains a vulnerability that could allow an authenticated user to execute actions that they do not have access to. IBM Reference #: 1999563.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm tririga_application_platform 3.5.1.3
ibm tririga_application_platform 3.4.1.2
ibm tririga_application_platform 3.4.2.4
ibm tririga_application_platform 3.4.2.0
ibm tririga_application_platform 3.3.2.5
ibm tririga_application_platform 3.5.1
ibm tririga_application_platform 3.3.0.1
ibm tririga_application_platform 3.5.0.2
ibm tririga_application_platform 3.3.1.0
ibm tririga_application_platform 3.3.2.1
ibm tririga_application_platform 3.3.0.2
ibm tririga_application_platform 3.3.2.0
ibm tririga_application_platform 3.3.2.2
ibm tririga_application_platform 3.4.2.2
ibm tririga_application_platform 3.3.1.1
ibm tririga_application_platform 3.5.0.0
ibm tririga_application_platform 3.4.2.1
ibm tririga_application_platform 3.4.2.3
ibm tririga_application_platform 3.5.2
ibm tririga_application_platform 3.5.0.1
ibm tririga_application_platform 3.4.1.0
ibm tririga_application_platform 3.4.0.1
ibm tririga_application_platform 3.3.2.4
ibm tririga_application_platform 3.4.1.1
ibm tririga_application_platform 3.3.1.2
ibm tririga_application_platform 3.5.1.1
ibm tririga_application_platform 3.4.2.5
ibm tririga_application_platform 3.4.0.0
ibm tririga_application_platform 3.3.1.3
ibm tririga_application_platform 3.5.1.2
ibm tririga_application_platform 3.3.2.3
ibm tririga_application_platform 3.4.1.3
ibm tririga_application_platform 3.3.0.0
CVE-2017-1154 MEDIUM

IBM Algorithmics One-Algo Risk Application 4.9.1, 5.0, and 5.1.0 could allow a user to gain access to files in the local environment which should not be viewed by application users. IBM Reference #: 1999892.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm algo_one 5.1.0
ibm algo_one 4.9.1
ibm algo_one 5.0.0
CVE-2017-1155 MEDIUM

IBM Algorithmics One-Algo Risk Application 4.9.1, 5.0, and 5.1.0 could allow a user to gain access to another user's reports using a specially crafted HTTP request. IBM Reference #: 1999754.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm algo_one 5.1.0
ibm algo_one 4.9.1
ibm algo_one 5.0.0
CVE-2017-1156 MEDIUM

IBM WebSphere Portal 8.5 and 9.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force. ID: 122592

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-601,

Products Affected

Vendor Product Version
ibm websphere_portal 9.0
ibm websphere_portal 8.5
CVE-2017-1157 MEDIUM

IBM Jazz Reporting Service (JRS) 5.0 and 6.0 could allow an authenticated attacker to access report data that should be restricted to authorized users. IBM X-Force ID: 122788.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm jazz_reporting_service 6.0
ibm jazz_reporting_service 5.0
CVE-2017-1159 MEDIUM

IBM Business Process Manager 8.0 and 8.5 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 122891.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-601,

Products Affected

Vendor Product Version
ibm business_process_manager 8.0.1.2
ibm business_process_manager 8.5.6.0
ibm business_process_manager 8.0.1.1
ibm business_process_manager 7.5.0.1
ibm business_process_manager 8.5.0.2
ibm business_process_manager 7.5.1.0
ibm business_process_manager 7.5.1.1
ibm business_process_manager 8.5.5.0
ibm business_process_manager 8.0.1.0
ibm business_process_manager 7.5.1.2
ibm business_process_manager 8.0.0.0
ibm business_process_manager 8.5.7.0
ibm business_process_manager 8.5.0.1
ibm business_process_manager 8.0.1.3
ibm business_process_manager 8.5.0.0
ibm business_process_manager 7.5.0.0
CVE-2017-1160 LOW

IBM Financial Transaction Manager for ACH Services for Multi-Platform 3.0.0.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 122892.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm financial_transaction_manager 3.0.0.12
ibm financial_transaction_manager 3.0.0.4
ibm financial_transaction_manager 3.0.0.9
ibm financial_transaction_manager 3.0.0.7
ibm financial_transaction_manager 3.0.0.0
ibm financial_transaction_manager 3.0.0.11
ibm financial_transaction_manager 3.0.0.3
ibm financial_transaction_manager 3.0.0.10
ibm financial_transaction_manager 3.0.0.2
ibm financial_transaction_manager 3.0.0.5
ibm financial_transaction_manager 3.0.0.8
ibm financial_transaction_manager 3.0.0.6
ibm financial_transaction_manager 3.0.0.1
ibm financial_transaction_manager 3.0.0.15
ibm financial_transaction_manager 3.0.0.14
ibm financial_transaction_manager 3.0.0.13
CVE-2017-1161 HIGH

IBM API Connect 5.0.6.0 could allow a remote attacker to execute arbitrary commands on the system, caused by improper validation of URLs for the Developer Portal. By crafting a malicious URL, an attacker could exploit this vulnerability to execute arbitrary commands on the system with the privileges of the www-data user. IBM X-Force ID: 122956.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm api_connect 5.0.6.0
CVE-2017-1162 MEDIUM

IBM QRadar 7.2 and 7.3 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 122957.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.2
ibm qradar_security_information_and_event_manager 7.2.8
ibm qradar_security_information_and_event_manager 7.2.0
ibm qradar_security_information_and_event_manager 7.2.7
ibm qradar_security_information_and_event_manager 7.3.0
ibm qradar_security_information_and_event_manager 7.2.3
ibm qradar_security_information_and_event_manager 7.2.6
ibm qradar_security_information_and_event_manager 7.2.4
ibm qradar_security_information_and_event_manager 7.2.1
ibm qradar_security_information_and_event_manager 7.2.5
CVE-2017-1164 LOW

IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123036.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_collaborative_lifecycle_management 6.0.3
ibm rational_collaborative_lifecycle_management 6.0.2
ibm rational_collaborative_lifecycle_management 4.0.6
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_collaborative_lifecycle_management 6.0
ibm rational_collaborative_lifecycle_management 4.0
ibm rational_collaborative_lifecycle_management 4.0.1
ibm rational_collaborative_lifecycle_management 4.0.5
ibm rational_collaborative_lifecycle_management 4.0.7
ibm rational_collaborative_lifecycle_management 4.0.3
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_collaborative_lifecycle_management 4.0.2
ibm rational_collaborative_lifecycle_management 5.0
ibm rational_collaborative_lifecycle_management 6.0.4
ibm rational_collaborative_lifecycle_management 4.0.4
CVE-2017-1168 LOW

IBM Rational Engineering Lifecycle Manager 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123187.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_engineering_lifecycle_manager 5.0.1
ibm rational_engineering_lifecycle_manager 6.0.2
ibm rational_engineering_lifecycle_manager 4.0.3
ibm rational_engineering_lifecycle_manager 4.0.4
ibm rational_engineering_lifecycle_manager 4.0.5
ibm rational_engineering_lifecycle_manager 4.0.7
ibm rational_engineering_lifecycle_manager 6.0.0
ibm rational_engineering_lifecycle_manager 6.0.1
ibm rational_engineering_lifecycle_manager 4.0.6
ibm rational_engineering_lifecycle_manager 5.0.0
ibm rational_engineering_lifecycle_manager 6.0.3
ibm rational_engineering_lifecycle_manager 5.0.2
CVE-2017-1169 LOW

IBM DOORS next Generation (DNG/RRC) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123188.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_collaborative_lifecycle_management 6.0.3
ibm rational_collaborative_lifecycle_management 6.0.2
ibm rational_collaborative_lifecycle_management 4.0.6
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_collaborative_lifecycle_management 6.0
ibm rational_collaborative_lifecycle_management 4.0
ibm rational_collaborative_lifecycle_management 4.0.1
ibm rational_collaborative_lifecycle_management 4.0.5
ibm rational_collaborative_lifecycle_management 4.0.7
ibm rational_collaborative_lifecycle_management 4.0.3
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_collaborative_lifecycle_management 4.0.2
ibm rational_collaborative_lifecycle_management 5.0
ibm rational_collaborative_lifecycle_management 6.0.4
ibm rational_collaborative_lifecycle_management 4.0.4
CVE-2017-1170 MEDIUM

IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 8.0 could allow a local user to hijack a user's session. IBM X-Force ID: 123230.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_commerce 8.0.0.9
ibm websphere_commerce 8.0.0.6
ibm websphere_commerce 8.0.0.4
ibm websphere_commerce 8.0.0.7
ibm websphere_commerce 8.0.1.1
ibm websphere_commerce 8.0.0.1
ibm websphere_commerce 8.0.0.3
ibm websphere_commerce 8.0.3.2
ibm websphere_commerce 8.0.1.2
ibm websphere_commerce 8.0.3.3
ibm websphere_commerce 8.0.0.15
ibm websphere_commerce 8.0.0.13
ibm websphere_commerce 8.0.0.10
ibm websphere_commerce 8.0.1.8
ibm websphere_commerce 8.0.1.0
ibm websphere_commerce 8.0.0.2
ibm websphere_commerce 8.0.0.8
ibm websphere_commerce 8.0.3.0
ibm websphere_commerce 8.0.0.16
ibm websphere_commerce 8.0.3.1
ibm websphere_commerce 8.0.1.4
ibm websphere_commerce 8.0.0.11
ibm websphere_commerce 8.0.0.0
ibm websphere_commerce 8.0.1.5
ibm websphere_commerce 8.0.1.6
ibm websphere_commerce 8.0.1.9
ibm websphere_commerce 8.0.0.14
ibm websphere_commerce 8.0.0.5
ibm websphere_commerce 8.0.1.3
ibm websphere_commerce 8.0.0.12
ibm websphere_commerce 8.0.1.7
ibm websphere_commerce 8.0.0.17
CVE-2017-1171 MEDIUM

The IBM TRIRIGA Application Platform 3.3, 3,4, and 3,5 contain a vulnerability that could allow an authenticated user to execute Application actions they do not have access to. IBM Reference #: 2001083.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm tririga_application_platform 3.5.1.3
ibm tririga_application_platform 3.4.1.2
ibm tririga_application_platform 3.4.2.4
ibm tririga_application_platform 3.4.2.0
ibm tririga_application_platform 3.3.2.5
ibm tririga_application_platform 3.5.1
ibm tririga_application_platform 3.3.0.1
ibm tririga_application_platform 3.5.0.2
ibm tririga_application_platform 3.3.1.0
ibm tririga_application_platform 3.3.2.1
ibm tririga_application_platform 3.3.0.2
ibm tririga_application_platform 3.3.2.0
ibm tririga_application_platform 3.3.2.2
ibm tririga_application_platform 3.4.2.2
ibm tririga_application_platform 3.3.1.1
ibm tririga_application_platform 3.5.0.0
ibm tririga_application_platform 3.4.2.1
ibm tririga_application_platform 3.4.2.3
ibm tririga_application_platform 3.5.2
ibm tririga_application_platform 3.5.0.1
ibm tririga_application_platform 3.4.1.0
ibm tririga_application_platform 3.4.0.1
ibm tririga_application_platform 3.3.2.4
ibm tririga_application_platform 3.4.1.1
ibm tririga_application_platform 3.3.1.2
ibm tririga_application_platform 3.5.1.1
ibm tririga_application_platform 3.4.2.5
ibm tririga_application_platform 3.4.0.0
ibm tririga_application_platform 3.3.1.3
ibm tririga_application_platform 3.5.1.2
ibm tririga_application_platform 3.3.2.3
ibm tririga_application_platform 3.4.1.3
ibm tririga_application_platform 3.3.0.0
CVE-2017-1174 MEDIUM

IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 123296.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2
CVE-2017-1175 HIGH

IBM Maximo Asset Management 7.1, 7.5, and 7.6 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 123297.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm maximo_asset_management 7.6
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.5
ibm maximo_asset_management 7.1.1
CVE-2017-1176 LOW

IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a local user to obtain sensitive information due to inappropriate data retention of attachments. IBM X-Force ID: 123299.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm maximo_asset_management 7.6
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.5
ibm maximo_asset_management 7.1.1
CVE-2017-1177 MEDIUM

IBM BigFix Compliance 1.7 through 1.9.91 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 123429.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm bigfix_compliance *
CVE-2017-1178 MEDIUM

IBM Endpoint Manager for Security and Compliance 1.9.70 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123430.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm bigfix_security_compliance_analytics 1.9.70
CVE-2017-1179 MEDIUM

IBM BigFix Compliance Analytics 1.9.79 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 123431.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-326,

Products Affected

Vendor Product Version
ibm bigfix_security_compliance_analytics 1.9.70
CVE-2017-1180 LOW

The IBM TRIRIGA Document Manager contains a vulnerability that could allow an authenticated user to execute actions they did not have access to. IBM Reference #: 2001084.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm tririga_application_platform 3.5.1.3
ibm tririga_application_platform 3.4.1.2
ibm tririga_application_platform 3.4.2.4
ibm tririga_application_platform 3.4.2.0
ibm tririga_application_platform 3.3.2.5
ibm tririga_application_platform 3.5.1
ibm tririga_application_platform 3.3.0.1
ibm tririga_application_platform 3.5.0.2
ibm tririga_application_platform 3.3.1.0
ibm tririga_application_platform 3.3.2.1
ibm tririga_application_platform 3.3.0.2
ibm tririga_application_platform 3.3.2.0
ibm tririga_application_platform 3.4.2.2
ibm tririga_application_platform 3.3.1.1
ibm tririga_application_platform 3.5.0.0
ibm tririga_application_platform 3.4.2.1
ibm tririga_application_platform 3.4.2.3
ibm tririga_application_platform 3.5.2
ibm tririga_application_platform 3.5.0.1
ibm tririga_application_platform 3.3.2.4
ibm tririga_application_platform 3.4.1.1
ibm tririga_application_platform 3.3.1.2
ibm tririga_application_platform 3.5.1.1
ibm tririga_application_platform 3.4.2.5
ibm tririga_application_platform 3.5.1.0
ibm tririga_application_platform 3.4.0.0
ibm tririga_application_platform 3.3.1.3
ibm tririga_application_platform 3.5.1.2
ibm tririga_application_platform 3.3.2.3
ibm tririga_application_platform 3.4.1.3
ibm tririga_application_platform 3.3.0.0
CVE-2017-1181 LOW

IBM Tivoli Monitoring Portal V6 client could allow a local attacker to gain elevated privileges for IBM Tivoli Monitoring, caused by the default console connection not being encrypted. IBM X-Force ID: 123487.

CVSS 2.0

Severity: LOW

Problem Type: CWE-319,

Products Affected

Vendor Product Version
ibm tivoli_monitoring 6.3.0.7
ibm tivoli_monitoring 6.2.2.9
ibm tivoli_monitoring 6.2.3.5
CVE-2017-1182 MEDIUM

IBM Tivoli Monitoring Portal v6 could allow a local (network adjacent) attacker to execute arbitrary commands on the system, when default client-server default communications, HTTP, are being used. IBM X-Force ID: 123493.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm tivoli_monitoring 6.3.0.7
ibm tivoli_monitoring 6.2.2.9
ibm tivoli_monitoring 6.2.3.5
CVE-2017-1183 MEDIUM

IBM Tivoli Monitoring Portal v6 could allow a local (network adjacent) attacker to modify SQL commands to the Portal Server, when default client-server communications, HTTP, are being used. IBM X-Force ID: 123494.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm tivoli_monitoring 6.3.0.7
ibm tivoli_monitoring 6.2.2.9
ibm tivoli_monitoring 6.2.3.5
CVE-2017-1189 MEDIUM

IBM WebSphere Portal and Web Content Manager 6.1, 7.0, and 8.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123558.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.0
ibm websphere_portal 6.1.0.3
ibm websphere_portal 8.0
ibm websphere_portal 7.0.0.1
ibm websphere_portal 6.1.5.2
ibm websphere_portal 6.1.0.2
ibm websphere_portal 6.1.0.4
ibm websphere_portal 8.0.0.1
ibm websphere_portal 7.0.0.2
ibm websphere_portal 6.1.5.0
ibm websphere_portal 6.1.0.6
ibm websphere_portal 6.1.5.3
ibm websphere_portal 7.0.0.0
ibm websphere_portal 6.1.0.1
ibm websphere_portal 6.1.5.1
ibm websphere_portal 6.1.0.5
ibm websphere_portal 6.1.0.0
CVE-2017-1190 MEDIUM

IBM Emptoris Strategic Supply Management Platform 10.x and 10.1 could allow a local user with special access roles to execute arbitrary code on the system. By manipulating a configurable property, an attacker could exploit this vulnerability to gain full control over the system. IBM X-Force ID: 123559.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm emptoris_strategic_supply_management 10.0.2.0
ibm emptoris_strategic_supply_management 10.0.2.5
ibm emptoris_strategic_supply_management 10.0.0.0
ibm emptoris_strategic_supply_management 10.0.2.2
ibm emptoris_strategic_supply_management 10.1.0.1
ibm emptoris_strategic_supply_management 10.1.1.1
ibm emptoris_strategic_supply_management 10.0.2.9
ibm emptoris_strategic_supply_management 10.0.2.4
ibm emptoris_strategic_supply_management 10.1.0.8
ibm emptoris_strategic_supply_management 10.1.0.3
ibm emptoris_strategic_supply_management 10.1.1.3
ibm emptoris_strategic_supply_management 10.0.2.6
ibm emptoris_strategic_supply_management 10.1.1.5
ibm emptoris_strategic_supply_management 10.1.1.0
ibm emptoris_strategic_supply_management 10.0.1.3
ibm emptoris_strategic_supply_management 10.0.1.2
ibm emptoris_strategic_supply_management 10.1.0.2
ibm emptoris_strategic_supply_management 10.0.1.4
ibm emptoris_strategic_supply_management 10.1.1.6
ibm emptoris_strategic_supply_management 10.1.1.7
ibm emptoris_strategic_supply_management 10.0.0.3
ibm emptoris_strategic_supply_management 10.0.0.1
ibm emptoris_strategic_supply_management 10.0.2.11
ibm emptoris_strategic_supply_management 10.0.2.3
ibm emptoris_strategic_supply_management 10.1.0.5
ibm emptoris_strategic_supply_management 10.0.2.8
ibm emptoris_strategic_supply_management 10.0.2.13
ibm emptoris_strategic_supply_management 10.0.1.0
ibm emptoris_strategic_supply_management 10.1.1.8
ibm emptoris_strategic_supply_management 10.0.2.1
ibm emptoris_strategic_supply_management 10.0.2.14
ibm emptoris_strategic_supply_management 10.0.2.15
ibm emptoris_strategic_supply_management 10.1.0.9
ibm emptoris_strategic_supply_management 10.0.0.2
ibm emptoris_strategic_supply_management 10.0.2.7
ibm emptoris_strategic_supply_management 10.0.4.0
ibm emptoris_strategic_supply_management 10.1.0.4
ibm emptoris_strategic_supply_management 10.1.0.7
ibm emptoris_strategic_supply_management 10.1.0.10
ibm emptoris_strategic_supply_management 10.1.0.0
ibm emptoris_strategic_supply_management 10.1.1.2
ibm emptoris_strategic_supply_management 10.0.2.10
ibm emptoris_strategic_supply_management 10.0.2.12
ibm emptoris_strategic_supply_management 10.1.0.6
ibm emptoris_strategic_supply_management 10.0.1.1
ibm emptoris_strategic_supply_management 10.1.1.4
CVE-2017-1191 MEDIUM

An undisclosed vulnerability in CLM applications (including IBM Rational Collaborative Lifecycle Management 4.0, 5.0, and 6.0) with potential for failure to restrict URL Access. IBM X-Force ID: 123661.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
ibm rational_engineering_lifecycle_manager *
ibm rational_software_architect_design_manager 5.0.0
ibm rational_software_architect_design_manager 5.0.2
ibm rational_software_architect_design_manager 6.0.0
ibm rational_software_architect_design_manager *
ibm rational_software_architect_design_manager 5.0.1
ibm rational_software_architect_design_manager 6.0.1
ibm rational_rhapsody_design_manager *
ibm rational_collaborative_lifecycle_management *
ibm rational_doors_next_generation *
ibm rational_team_concert *
CVE-2017-1192 MEDIUM

IBM Sterling B2B Integrator 5.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume memory resources. IBM X-Force ID: 123663.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2
CVE-2017-1193 MEDIUM

IBM Sterling B2B Integrator Standard Edition 5.2 could allow user to obtain sensitive information using an HTTP GET request. IBM X-Force ID: 123667.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2
CVE-2017-1194 MEDIUM

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 123669.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm websphere_application_server 9.0
ibm websphere_application_server 7.0
ibm websphere_application_server 8.0
ibm websphere_application_server 8.5
CVE-2017-1195 MEDIUM

IBM Curam Social Program Management 6.0, 6.1, 6.2, and 7.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 123670.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-601,

Products Affected

Vendor Product Version
ibm curam_social_program_management 6.1.0.2
ibm curam_social_program_management 6.1.0.4
ibm curam_social_program_management 6.0.4.8
ibm curam_social_program_management 6.0.5.9
ibm curam_social_program_management 6.1.0.1
ibm curam_social_program_management 6.0.4.9
ibm curam_social_program_management 6.2.0.3
ibm curam_social_program_management 6.0.5.10
ibm curam_social_program_management 6.0.4.0
ibm curam_social_program_management 6.0.5.5
ibm curam_social_program_management 6.2.0.0
ibm curam_social_program_management 6.0.5.2
ibm curam_social_program_management 6.0.5.1
ibm curam_social_program_management 6.2.0.2
ibm curam_social_program_management 6.1.1.2
ibm curam_social_program_management 6.0.5.3
ibm curam_social_program_management 6.2.0.1
ibm curam_social_program_management 6.0.4.5
ibm curam_social_program_management 7.0.0.1
ibm curam_social_program_management 6.0.4.7
ibm curam_social_program_management 6.0.4.3
ibm curam_social_program_management 6.0.5.4
ibm curam_social_program_management 6.0.4.4
ibm curam_social_program_management 6.1.0.3
ibm curam_social_program_management 6.0.5
ibm curam_social_program_management 6.0.4.1
ibm curam_social_program_management 6.0.5.0
ibm curam_social_program_management 6.1.1.0
ibm curam_social_program_management 6.1.1.3
ibm curam_social_program_management 6.2.0.4
ibm curam_social_program_management 6.0.5.8
ibm curam_social_program_management 6.0.5.7
ibm curam_social_program_management 6.0.5.6
ibm curam_social_program_management 6.1.0.0
ibm curam_social_program_management 6.0.4.2
ibm curam_social_program_management 6.1.1.4
ibm curam_social_program_management 6.0.4.6
ibm curam_social_program_management 6.1.1.1
ibm curam_social_program_management 7.0.0.0
CVE-2017-1196 MEDIUM

IBM BigFix Compliance (TEMA SUAv1 SCA SCM) 1.9.70 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 123671.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-521,

Products Affected

Vendor Product Version
ibm bigfix_security_compliance_analytics 1.9.70
CVE-2017-1197 MEDIUM

IBM BigFix Compliance (TEMA SUAv1 SCA SCM) uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 123672.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-307,

Products Affected

Vendor Product Version
ibm bigfix_security_compliance_analytics 1.9.70
CVE-2017-1198 MEDIUM

IBM BigFix Compliance 1.7 through 1.9.91 (TEMA SUAv1 SCA SCM) stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 123673.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-532,

Products Affected

Vendor Product Version
ibm bigfix_compliance *
CVE-2017-1199 LOW

IBM InfoSphere Master Data Management Server 10.0, 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123674.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm infosphere_master_data_management_server 10.1
ibm infosphere_master_data_management_server 11.5
ibm infosphere_master_data_management_server 11.0
ibm infosphere_master_data_management_server 11.3
ibm infosphere_master_data_management_server 11.6
ibm infosphere_master_data_management_server 11.4
CVE-2017-1200 MEDIUM

IBM BigFix Compliance 1.7 through 1.9.91 (TEMA SUAv1 SCA SCM) does not validate, or incorrectly validates, a certificate.This weakness might allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack. The software might connect to a malicious host while believing it is a trusted host, or the software might be deceived into accepting spoofed data that appears to originate from a trusted host. IBM X-Force ID: 123675.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-295,

Products Affected

Vendor Product Version
ibm bigfix_compliance *
CVE-2017-1201 LOW

IBM BigFix Compliance Analytics 1.9.79 (TEMA SUAv1 SCA SCM) stores user credentials in clear text which can be read by a local user. IBM X-Force ID: 123676.

CVSS 2.0

Severity: LOW

Problem Type: CWE-522,

Products Affected

Vendor Product Version
ibm bigfix_security_compliance_analytics 1.9.79
CVE-2017-1202 LOW

IBM BigFix Compliance 1.7 through 1.9.91 (TEMA SUAv1 SCA SCM) is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 123677.

CVSS 2.0

Severity: LOW

Problem Type: CWE-74,

Products Affected

Vendor Product Version
ibm bigfix_compliance *
CVE-2017-1203 MEDIUM

IBM Tivoli Endpoint Manager (for Lifecycle/Power/Patch) Platform and Applications is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123678.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm bigfix_platform 9.2.2
ibm bigfix_platform 9.2.0
ibm bigfix_platform 9.1
ibm bigfix_platform 9.5
ibm bigfix_platform 9.1.7
ibm bigfix_platform 9.2.6
ibm bigfix_platform 9.2.1
ibm bigfix_platform 9.1.3
ibm bigfix_platform 9.1.6
ibm bigfix_platform 9.2.4
ibm bigfix_platform 9.2
ibm bigfix_platform 9.5.6
ibm bigfix_platform 9.2.5
ibm bigfix_platform 9.1.4
ibm bigfix_platform 9.1.5
ibm bigfix_platform 9.2.7
ibm bigfix_platform 9.2.3
ibm bigfix_platform 9.5.5
CVE-2017-1204 HIGH

IBM Tealeaf Customer Experience 8.7, 8.8, and 9.0.2 contains hard-coded credentials. A remote attacker could exploit this vulnerability to gain access to the system. IBM X-Force ID: 123740.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-798,

Products Affected

Vendor Product Version
ibm tealeaf_customer_experience 8.8
ibm tealeaf_customer_experience 8.7
ibm tealeaf_customer_experience 9.0.2
CVE-2017-1205 HIGH

IBM Platform LSF 10.1 contains an unspecified vulnerability that could allow a local user to escalate their privileges and obtain root access. IBM X-Force ID: 123741.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm spectrum_lsf 9.1.1
ibm spectrum_lsf 9.1.2
ibm spectrum_lsf 8.3
ibm spectrum_lsf 9.1.3
ibm spectrum_lsf 10.1.0.1
CVE-2017-1207 LOW

IBM WebSphere Message Broker stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 123777.

CVSS 2.0

Severity: LOW

Problem Type: CWE-522,

Products Affected

Vendor Product Version
ibm integration_bus 10.0.0.3
ibm websphere_message_broker 8.0.0.4
ibm integration_bus 10.0.0.7
ibm integration_bus 10.0.0.1
ibm websphere_message_broker 8.0.0.7
ibm integration_bus 10.0.0.4
ibm integration_bus 9.0.0.2
ibm integration_bus 9.0.0.7
ibm integration_bus 10.0.0.6
ibm integration_bus 10.0.0.5
ibm integration_bus 10.0.0.2
ibm websphere_message_broker 8.0.0.6
ibm integration_bus 9.0.0
ibm integration_bus 9.0.0.5
ibm integration_bus 9.0.0.4
ibm websphere_message_broker 8.0.0.0
ibm integration_bus 10.0.0
ibm websphere_message_broker 8.0.0.3
ibm websphere_message_broker 8.0.0.2
ibm integration_bus 9.0.0.6
ibm websphere_message_broker 8.0.0.5
ibm integration_bus 9.0.0.1
ibm websphere_message_broker 8.0.0.1
ibm integration_bus 9.0.0.3
CVE-2017-1208 LOW

IBM Maximo Asset Management 7.1, 7.5, and 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123778.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm maximo_asset_management 7.6
ibm maximo_asset_management 7.1
ibm maximo_asset_management 7.5
ibm maximo_asset_management 7.1.1
CVE-2017-1209 LOW

IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123849.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm daeja_viewone 4.1.5
ibm daeja_viewone 5.0.0
ibm daeja_viewone 5.0.2
ibm daeja_viewone 4.1.5.1
CVE-2017-1210 MEDIUM

IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0.2 could allow an unauthenticated attacker to inject data into log files made to look legitimate. IBM X-Force ID: 123850.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm daeja_viewone 4.1.5
ibm daeja_viewone 5.0.0
ibm daeja_viewone 5.0.2
ibm daeja_viewone 4.1.5.1
CVE-2017-1211 LOW

IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0.2 could disclose sensitive information to a local user when logging is enabled. IBM X-Force ID: 123851.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm daeja_viewone 4.1.5
ibm daeja_viewone 5.0.0
ibm daeja_viewone 5.0.2
ibm daeja_viewone 4.1.5.1
CVE-2017-1212 MEDIUM

IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0.2 is vulnerable to a denial of service when viewing or opening a large file. IBM X-Force ID: 123852.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm daeja_viewone 4.1.5
ibm daeja_viewone 5.0.0
ibm daeja_viewone 4.1.5.1
ibm daeja_viewone 5.0.1
CVE-2017-1214 LOW

IBM iNotes 8.5 and 9.0 could allow a remote attacker to send a malformed email to a victim, that when opened could cause an information disclosure. IBM X-Force ID: 123854.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm inotes 8.5.2.1
ibm inotes 8.5.2.3
ibm inotes 9.0.1.0
ibm inotes 8.5.3.2
ibm inotes 9.0.1.3
ibm inotes 9.0.1.6
ibm inotes 8.5.3.4
ibm inotes 8.5.3.1
ibm inotes 8.5.3.0
ibm inotes 8.5.1.4
ibm inotes 9.0.1.7
ibm inotes 9.0.1.1
ibm inotes 8.5.3.3
ibm inotes 8.5.3.5
ibm inotes 9.0.0.0
ibm inotes 9.0.1.2
ibm inotes 9.0.1.4
ibm inotes 8.5.2.0
ibm inotes 8.5.0.0
ibm inotes 8.5.0.1
ibm inotes 8.5.1.1
ibm inotes 8.5.1.5
ibm inotes 8.5.2.2
ibm inotes 8.5.1.0
ibm inotes 9.0.1.5
ibm inotes 8.5.1.2
ibm inotes 8.5.1.3
CVE-2017-1217 MEDIUM

IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123857

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 9.0
ibm websphere_portal 8.5
CVE-2017-1218 MEDIUM

IBM Tivoli Endpoint Manager is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 123858.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm bigfix_platform 9.5.6
ibm bigfix_platform 9.5
ibm bigfix_platform 9.2.7
ibm bigfix_platform 9.2.6
ibm bigfix_platform 9.5.5
CVE-2017-1219 MEDIUM

IBM Tivoli Endpoint Manager is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 123859.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm bigfix_platform 9.2.2
ibm bigfix_platform 9.2.0
ibm bigfix_platform 9.1
ibm bigfix_platform 9.1.7
ibm bigfix_platform 9.2.6
ibm bigfix_platform 9.2.1
ibm bigfix_platform 9.1.3
ibm bigfix_platform 9.1.6
ibm bigfix_platform 9.2.4
ibm bigfix_platform 9.2
ibm bigfix_platform 9.2.5
ibm bigfix_platform 9.1.4
ibm bigfix_platform 9.1.5
ibm bigfix_platform 9.2.7
ibm bigfix_platform 9.2.3
CVE-2017-1220 MEDIUM

IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 123860.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm bigfix_platform 9.2
ibm bigfix_platform 9.5
CVE-2017-1221 MEDIUM

IBM Tivoli Endpoint Manager (IBM BigFix 9.2 and 9.5) does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 123861.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-521,

Products Affected

Vendor Product Version
ibm bigfix_platform 9.2
ibm bigfix_platform 9.5
CVE-2017-1222 MEDIUM

IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. IBM X-Force ID: 123862.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm bigfix_platform 9.2
ibm bigfix_platform 9.5
CVE-2017-1223 MEDIUM

IBM Tivoli Endpoint Manager could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 123902.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-601,

Products Affected

Vendor Product Version
ibm bigfix_platform 9.5.6
ibm bigfix_platform 9.5
ibm bigfix_platform 9.2.7
ibm bigfix_platform 9.2.6
ibm bigfix_platform 9.5.5
CVE-2017-1224 MEDIUM

IBM Tivoli Endpoint Manager uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 123903.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-326,

Products Affected

Vendor Product Version
ibm bigfix_platform 9.5.6
ibm bigfix_platform 9.5
ibm bigfix_platform 9.2.7
ibm bigfix_platform 9.2.6
ibm bigfix_platform 9.5.5
CVE-2017-1225 MEDIUM

IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 123904.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm bigfix_platform 9.2
ibm bigfix_platform 9.5
CVE-2017-1226 MEDIUM

IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) generates an error message in error logs that includes sensitive information about its environment which could be used in further attacks against the system. IBM X-Force ID: 123905.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm bigfix_platform 9.2
ibm bigfix_platform 9.5
CVE-2017-1227 HIGH

IBM Tivoli Endpoint Manager could allow a unauthorized user to consume all resources and crash the system. IBM X-Force ID: 123906.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-770,

Products Affected

Vendor Product Version
ibm bigfix_platform 9.2
ibm bigfix_platform 9.1
ibm bigfix_platform 9.5
CVE-2017-1228 MEDIUM

IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable the secure cookie attribute. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 123907.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm bigfix_platform 9.2
ibm bigfix_platform 9.5
CVE-2017-1229 MEDIUM

IBM Tivoli Endpoint Manager (IBM BigFix 9.2 and 9.5) could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 123908.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm bigfix_platform 9.2
ibm bigfix_platform 9.5
CVE-2017-1230 MEDIUM

IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) uses insufficiently random numbers or values in a security context that depends on unpredictable numbers. This weakness may allow attackers to expose sensitive information by guessing tokens or identifiers. IBM X-Force ID: 123909.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm bigfix_platform 9.2
ibm bigfix_platform 9.5
CVE-2017-1231 LOW

IBM BigFix Platform 9.5 - 9.5.9 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 123910.

CVSS 2.0

Severity: LOW

Problem Type: CWE-522,

Products Affected

Vendor Product Version
ibm bigfix_platform *
CVE-2017-1232 MEDIUM

IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors. IBM X-Force ID: 123911.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-319,

Products Affected

Vendor Product Version
ibm bigfix_platform 9.2
ibm bigfix_platform 9.5
CVE-2017-1233 HIGH

IBM Remote Control v9 could allow a local user to use the component to replace files to which he does not have write access and which he can cause to be executed with Local System or root privileges. IBM X-Force ID: 123912.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-863,

Products Affected

Vendor Product Version
ibm bigfix_remote_control 9.1.4
CVE-2017-1234 LOW

IBM QRadar 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123913.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.2
ibm qradar_security_information_and_event_manager 7.2.8
ibm qradar_security_information_and_event_manager 7.2.0
ibm qradar_security_information_and_event_manager 7.2.7
ibm qradar_security_information_and_event_manager 7.3.0
ibm qradar_security_information_and_event_manager 7.2.3
ibm qradar_security_information_and_event_manager 7.2.6
ibm qradar_security_information_and_event_manager 7.2.4
ibm qradar_security_information_and_event_manager 7.2.1
ibm qradar_security_information_and_event_manager 7.2.5
CVE-2017-1235 MEDIUM

IBM WebSphere MQ 8.0 could allow an authenticated user to cause a premature termination of a client application thread which could potentially cause denial of service. IBM X-Force ID: 123914.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_mq 8.0.0.0
ibm websphere_mq 8.0.0.6
ibm websphere_mq 8.0.0.5
ibm websphere_mq 8.0.0.1
ibm websphere_mq 8.0.0.3
ibm websphere_mq 8.0.0.4
ibm websphere_mq 8.0.0.2
CVE-2017-1236 MEDIUM

IBM WebSphere MQ 9.0.2 could allow an authenticated user to potentially cause a denial of service by saving an incorrect channel status inquiry. IBM X-Force ID: 124354

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm websphere_mq 9.0.2
CVE-2017-1237 LOW

IBM Jazz based applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 124355.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
ibm rational_engineering_lifecycle_manager *
ibm rational_engineering_lifecycle_manager 5.0.1
ibm rational_rhapsody_design_manager 5.0.1
ibm rational_software_architect_design_manager 6.0.0
ibm rational_software_architect_design_manager 5.0.1
ibm rational_software_architect_design_manager 6.0.1
ibm rational_rhapsody_design_manager *
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_collaborative_lifecycle_management *
ibm rational_quality_manager 5.0.1
ibm rational_doors_next_generation 5.0.1
ibm rational_team_concert 5.0.1
ibm rational_doors_next_generation *
ibm rational_team_concert *
CVE-2017-1238 LOW

IBM Quality Manager (RQM) 5.0.x and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 124356.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
ibm rational_collaborative_lifecycle_management *
CVE-2017-1239 MEDIUM

IBM Quality Manager (RQM) 5.0.x and 6.0 through 6.0.5 could reveal sensitive information in HTTP 500 Internal Server Error responses. IBM X-Force ID: 124357.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
ibm rational_collaborative_lifecycle_management *
CVE-2017-1240 MEDIUM

IBM Rhapsody DM products could reveal sensitive information in HTTP 500 Internal Server Error responses. IBM X-Force ID: 124359.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_rhapsody_design_manager 4.0.4
ibm rational_rhapsody_design_manager 4.0.5
ibm rational_software_architect_design_manager 6.0
ibm rational_collaborative_lifecycle_management 4.0.6
ibm rational_engineering_lifecycle_manager 4.0.7
ibm rational_quality_manager 4.0.6
ibm rational_software_architect_design_manager 6.0.1
ibm rational_team_concert 5.0
ibm rational_software_architect_design_manager 4.0.7
ibm rational_quality_manager 6.0.1
ibm rational_engineering_lifecycle_manager 5.0.2
ibm rational_rhapsody_design_manager 5.0.2
ibm rational_quality_manager 4.0.3
ibm rational_engineering_lifecycle_manager 6.0.2
ibm rational_collaborative_lifecycle_management 6.0.3
ibm rational_team_concert 4.0.1
ibm rational_team_concert 4.0.5
ibm rational_doors_next_generation 5.0
ibm rational_team_concert 4.0.2
ibm rational_quality_manager 5.0
ibm rational_collaborative_lifecycle_management 4.0.5
ibm rational_collaborative_lifecycle_management 4.0.7
ibm rational_collaborative_lifecycle_management 4.0.3
ibm rational_software_architect_design_manager 4.0.6
ibm rational_doors_next_generation 4.0.7
ibm rational_doors_next_generation 4.0.2
ibm rational_doors_next_generation 6.0
ibm rational_rhapsody_design_manager 4.0.7
ibm rational_engineering_lifecycle_manager 5.0
ibm rational_team_concert 5.0.2
ibm rational_collaborative_lifecycle_management 4.0.1
ibm rational_rhapsody_design_manager 5.0
ibm rational_engineering_lifecycle_manager 6.0.3
ibm rational_team_concert 6.0.4
ibm rational_team_concert 4.0.3
ibm rational_collaborative_lifecycle_management 4.0.2
ibm rational_quality_manager 4.0.1
ibm rational_team_concert 4.0.6
ibm rational_engineering_lifecycle_manager 4.0.5
ibm rational_software_architect_design_manager 5.0.2
ibm rational_engineering_lifecycle_manager 6.0.1
ibm rational_quality_manager 6.0
ibm rational_doors_next_generation 4.0.4
ibm rational_rhapsody_design_manager 6.0.3
ibm rational_quality_manager 4.0.4
ibm rational_rhapsody_design_manager 6.0.4
ibm rational_engineering_lifecycle_manager 4.0.6
ibm rational_rhapsody_design_manager 4.0.3
ibm rational_doors_next_generation 5.0.2
ibm rational_quality_manager 4.0.2
ibm rational_doors_next_generation 5.0.1
ibm rational_software_architect_design_manager 4.0.1
ibm rational_collaborative_lifecycle_management 4.0.4
ibm rational_team_concert 4.0.0.1
ibm rational_engineering_lifecycle_manager 4.0.3
ibm rational_engineering_lifecycle_manager 4.0.4
ibm rational_software_architect_design_manager 4.0.2
ibm rational_collaborative_lifecycle_management 6.0
ibm rational_quality_manager 4.0.0.1
ibm rational_quality_manager 4.0.0.2
ibm rational_team_concert 6.0.1
ibm rational_rhapsody_design_manager 6.0
ibm rational_quality_manager 4.0.7
ibm rational_rhapsody_design_manager 4.0.6
ibm rational_rhapsody_design_manager 6.0.1
ibm rational_rhapsody_design_manager 6.0.2
ibm rational_software_architect_design_manager 5.0
ibm rational_software_architect_design_manager 4.0.4
ibm rational_team_concert 6.0.2
ibm rational_doors_next_generation 4.0.1
ibm rational_engineering_lifecycle_manager 5.0.1
ibm rational_team_concert 4.0.7
ibm rational_team_concert 6.0
ibm rational_software_architect_design_manager 4.0.3
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_quality_manager 5.0.2
ibm rational_rhapsody_design_manager 4.0.1
ibm rational_rhapsody_design_manager 4.0.2
ibm rational_team_concert 4.0.0.2
ibm rational_rhapsody_design_manager 4.0
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_quality_manager 6.0.3
ibm rational_quality_manager 6.0.4
ibm rational_collaborative_lifecycle_management 6.0.4
ibm rational_doors_next_generation 6.0.1
ibm rational_rhapsody_design_manager 5.0.1
ibm rational_doors_next_generation 6.0.3
ibm rational_team_concert 4.0
ibm rational_doors_next_generation 4.0.5
ibm rational_collaborative_lifecycle_management 4.0
ibm rational_team_concert 6.0.3
ibm rational_engineering_lifecycle_manager 6.0.4
ibm rational_doors_next_generation 4.0.6
ibm rational_doors_next_generation 4.0.3
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 4.0
ibm rational_collaborative_lifecycle_management 5.0
ibm rational_doors_next_generation 6.0.4
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_software_architect_design_manager 4.0.5
ibm rational_engineering_lifecycle_manager 6.0
ibm rational_team_concert 4.0.4
ibm rational_software_architect_design_manager 5.0.1
ibm rational_software_architect_design_manager 4.0
ibm rational_quality_manager 4.0.5
ibm rational_quality_manager 6.0.2
ibm rational_doors_next_generation 6.0.2
ibm rational_team_concert 5.0.1
CVE-2017-1241 MEDIUM

An unspecified vulnerability in IBM Jazz Foundation based applications might allow the display of stack trace information to an attacker. IBM X-Force ID: 124523.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_collaborative_lifecycle_management 6.0.3
ibm rational_collaborative_lifecycle_management 6.0.2
ibm rational_collaborative_lifecycle_management 4.0.6
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_collaborative_lifecycle_management 6.0
ibm rational_collaborative_lifecycle_management 4.0
ibm rational_collaborative_lifecycle_management 4.0.1
ibm rational_collaborative_lifecycle_management 4.0.5
ibm rational_collaborative_lifecycle_management 4.0.7
ibm rational_collaborative_lifecycle_management 4.0.3
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_collaborative_lifecycle_management 4.0.2
ibm rational_collaborative_lifecycle_management 5.0
ibm rational_collaborative_lifecycle_management 6.0.4
ibm rational_collaborative_lifecycle_management 4.0.4
CVE-2017-1242 LOW

IBM Quality Manager (RQM) 5.0.x and 6.0 through 6.0.5 are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 124524.

CVSS 2.0

Severity: LOW

Problem Type: CWE-94,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
ibm rational_collaborative_lifecycle_management *
CVE-2017-1245 LOW

IBM Rational Software Architect Design Manager 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 124580.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_software_architect_design_manager 6.0.1
ibm rational_software_architect_design_manager 5.0.0
ibm rational_software_architect_design_manager 5.0.2
ibm rational_software_architect_design_manager 6.0.0
ibm rational_software_architect_design_manager 6.0.2
ibm rational_software_architect_design_manager 5.0.1
CVE-2017-1247 LOW

IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 124627.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_doors_next_generation 6.0.3
ibm rational_requirements_composer 4.0.4
ibm rational_doors_next_generation 6.0.0
ibm rational_requirements_composer 4.0.2
ibm rational_doors_next_generation 5.0
ibm rational_requirements_composer 4.0.1
ibm rational_requirements_composer 4.0.3
ibm rational_requirements_composer 4.0.7
ibm rational_doors_next_generation 5.0.0
ibm rational_doors_next_generation 5.0.2
ibm rational_doors_next_generation 6.0.2
ibm rational_requirements_composer 4.0.5
ibm rational_requirements_composer 4.0.6
ibm rational_doors_next_generation 5.0.1
ibm rational_doors_next_generation 6.0.1
CVE-2017-1248 MEDIUM

IBM Quality Manager (RQM) 5.0.x and 6.0 through 6.0.5 are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 124628.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-94,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
ibm rational_collaborative_lifecycle_management *
CVE-2017-1249 LOW

IBM Rhapsody DM 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rhapsody_design_manager 6.0.3
ibm rhapsody_design_manager 6.0.1
ibm rhapsody_design_manager 6.0.2
ibm rhapsody_design_manager 5.0.2
ibm rhapsody_design_manager 6.0
ibm rhapsody_design_manager 5.0
ibm rhapsody_design_manager 5.0.1
CVE-2017-1250 LOW

IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force 124630.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_collaborative_lifecycle_management 6.0.3
ibm rational_quality_manager 5.0.0
ibm rational_collaborative_lifecycle_management 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_quality_manager 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.5
ibm rational_collaborative_lifecycle_management 5.0.0
ibm rational_quality_manager 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_quality_manager 6.0.0
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 6.0.1
ibm rational_quality_manager 6.0.5
ibm rational_collaborative_lifecycle_management 6.0.0
ibm rational_quality_manager 6.0.3
ibm rational_quality_manager 6.0.4
ibm rational_collaborative_lifecycle_management 6.0.4
CVE-2017-1251 MEDIUM

An undisclosed vulnerability in CLM applications may result in some administrative deployment parameters being shown to an attacker. IBM X-Force ID: 124631.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_rhapsody_design_manager 4.0.4
ibm rational_rhapsody_design_manager 4.0.5
ibm rational_software_architect_design_manager 6.0
ibm rational_collaborative_lifecycle_management 4.0.6
ibm rational_engineering_lifecycle_manager 4.0.7
ibm rational_quality_manager 4.0.6
ibm rational_software_architect_design_manager 6.0.1
ibm rational_team_concert 5.0
ibm rational_software_architect_design_manager 4.0.7
ibm rational_quality_manager 6.0.1
ibm rational_engineering_lifecycle_manager 5.0.2
ibm rational_rhapsody_design_manager 5.0.2
ibm rational_quality_manager 4.0.3
ibm rational_engineering_lifecycle_manager 6.0.2
ibm rational_collaborative_lifecycle_management 6.0.3
ibm rational_team_concert 4.0.1
ibm rational_team_concert 4.0.5
ibm rational_doors_next_generation 5.0
ibm rational_team_concert 4.0.2
ibm rational_quality_manager 5.0
ibm rational_collaborative_lifecycle_management 4.0.5
ibm rational_collaborative_lifecycle_management 4.0.7
ibm rational_collaborative_lifecycle_management 4.0.3
ibm rational_software_architect_design_manager 4.0.6
ibm rational_doors_next_generation 4.0.7
ibm rational_doors_next_generation 4.0.2
ibm rational_doors_next_generation 6.0
ibm rational_rhapsody_design_manager 4.0.7
ibm rational_engineering_lifecycle_manager 5.0
ibm rational_team_concert 5.0.2
ibm rational_collaborative_lifecycle_management 4.0.1
ibm rational_rhapsody_design_manager 5.0
ibm rational_engineering_lifecycle_manager 6.0.3
ibm rational_team_concert 6.0.4
ibm rational_team_concert 4.0.3
ibm rational_collaborative_lifecycle_management 4.0.2
ibm rational_quality_manager 4.0.1
ibm rational_team_concert 4.0.6
ibm rational_engineering_lifecycle_manager 4.0.5
ibm rational_software_architect_design_manager 5.0.2
ibm rational_engineering_lifecycle_manager 6.0.1
ibm rational_quality_manager 6.0
ibm rational_doors_next_generation 4.0.4
ibm rational_rhapsody_design_manager 6.0.3
ibm rational_quality_manager 4.0.4
ibm rational_rhapsody_design_manager 6.0.4
ibm rational_engineering_lifecycle_manager 4.0.6
ibm rational_rhapsody_design_manager 4.0.3
ibm rational_doors_next_generation 5.0.2
ibm rational_quality_manager 4.0.2
ibm rational_doors_next_generation 5.0.1
ibm rational_software_architect_design_manager 4.0.1
ibm rational_collaborative_lifecycle_management 4.0.4
ibm rational_team_concert 4.0.0.1
ibm rational_engineering_lifecycle_manager 4.0.3
ibm rational_engineering_lifecycle_manager 4.0.4
ibm rational_software_architect_design_manager 4.0.2
ibm rational_collaborative_lifecycle_management 6.0
ibm rational_quality_manager 4.0.0.1
ibm rational_quality_manager 4.0.0.2
ibm rational_team_concert 6.0.1
ibm rational_rhapsody_design_manager 6.0
ibm rational_quality_manager 4.0.7
ibm rational_rhapsody_design_manager 4.0.6
ibm rational_rhapsody_design_manager 6.0.1
ibm rational_rhapsody_design_manager 6.0.2
ibm rational_software_architect_design_manager 5.0
ibm rational_software_architect_design_manager 4.0.4
ibm rational_team_concert 6.0.2
ibm rational_doors_next_generation 4.0.1
ibm rational_engineering_lifecycle_manager 5.0.1
ibm rational_team_concert 4.0.7
ibm rational_team_concert 6.0
ibm rational_software_architect_design_manager 4.0.3
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_quality_manager 5.0.2
ibm rational_rhapsody_design_manager 4.0.1
ibm rational_rhapsody_design_manager 4.0.2
ibm rational_team_concert 4.0.0.2
ibm rational_rhapsody_design_manager 4.0
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_quality_manager 6.0.3
ibm rational_quality_manager 6.0.4
ibm rational_collaborative_lifecycle_management 6.0.4
ibm rational_doors_next_generation 6.0.1
ibm rational_rhapsody_design_manager 5.0.1
ibm rational_doors_next_generation 6.0.3
ibm rational_team_concert 4.0
ibm rational_doors_next_generation 4.0.5
ibm rational_collaborative_lifecycle_management 4.0
ibm rational_team_concert 6.0.3
ibm rational_engineering_lifecycle_manager 6.0.4
ibm rational_doors_next_generation 4.0.6
ibm rational_doors_next_generation 4.0.3
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 4.0
ibm rational_collaborative_lifecycle_management 5.0
ibm rational_doors_next_generation 6.0.4
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_software_architect_design_manager 4.0.5
ibm rational_engineering_lifecycle_manager 6.0
ibm rational_team_concert 4.0.4
ibm rational_software_architect_design_manager 5.0.1
ibm rational_software_architect_design_manager 4.0
ibm rational_quality_manager 4.0.5
ibm rational_quality_manager 6.0.2
ibm rational_doors_next_generation 6.0.2
ibm rational_team_concert 5.0.1
CVE-2017-1253 MEDIUM

IBM Security Guardium 10.0 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 124633.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-78,

Products Affected

Vendor Product Version
ibm security_guardium 10.0.1
ibm security_guardium 10.0
ibm security_guardium 10.1
ibm security_guardium 10.1.2
CVE-2017-1254 MEDIUM

IBM Security Guardium 10.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume memory resources. IBM X-Force ID: 124634.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm security_guardium 10.0.1
ibm security_guardium 10.0
ibm security_guardium 10.1
ibm security_guardium 10.1.2
CVE-2017-1255 MEDIUM

IBM Security Guardium 10.0, 10.0.1, and 10.1 through 10.1.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 124675.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-326,

Products Affected

Vendor Product Version
ibm security_guardium 10.0.1
ibm security_guardium 10.1.4
ibm security_guardium 10.0
ibm security_guardium 10.1.3
ibm security_guardium 10.1
ibm security_guardium 10.1.2
CVE-2017-1256 MEDIUM

IBM Security Guardium 10.0, 10.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 124678

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm security_guardium 10.0
ibm security_guardium 10.1
CVE-2017-1257 MEDIUM

IBM Security Guardium 10.0 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 124684.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_guardium 10.0.1
ibm security_guardium 10.0
ibm security_guardium 10.1.3
ibm security_guardium 10.1.2
ibm security_guardium 10.1.0
CVE-2017-1258 MEDIUM

IBM Security Guardium 10.0 and 10.1 does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. IBM X-Force ID: 124685

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm security_guardium 10.0.1
ibm security_guardium 10.0
ibm security_guardium 10.1
ibm security_guardium 10.1.2
CVE-2017-1261 LOW

IBM Security Guardium 10.0 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 124736.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_guardium 10.0.1
ibm security_guardium 10.0
ibm security_guardium 10.1.3
ibm security_guardium 10.1.2
ibm security_guardium 10.1.0
CVE-2017-1262 MEDIUM

IBM Security Guardium 10.0 is vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache poisoning, cross-site scripting, and possibly obtain sensitive information. IBM X-Force ID: 124737.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-113,

Products Affected

Vendor Product Version
ibm security_guardium 10.0.1
ibm security_guardium 10.0
ibm security_guardium 10.1.3
ibm security_guardium 10.1.2
ibm security_guardium 10.1.0
CVE-2017-1264 MEDIUM

IBM Security Guardium 10.0 does not prove or insufficiently proves that the actors identity is correct which can lead to exposure of resources or functionality to unintended actors. IBM X-Force ID: 124739.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm security_guardium 10.0.1
ibm security_guardium 10.0
ibm security_guardium 10.1
ibm security_guardium 10.1.2
CVE-2017-1265 MEDIUM

IBM Security Guardium 10.0, 10.0.1, 10.1, 10.1.2, 10.1.3, 10.1.4, and 10.5 does not validate, or incorrectly validates, a certificate. This weakness might allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) techniques. IBM X-Force ID: 124740.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-295,

Products Affected

Vendor Product Version
ibm security_guardium *
CVE-2017-1266 MEDIUM

IBM Security Guardium 10.0 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. IBM X-Force ID: 124741.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-732,

Products Affected

Vendor Product Version
ibm security_guardium 10.0.1
ibm security_guardium 10.0
ibm security_guardium 10.1.3
ibm security_guardium 10.1.2
ibm security_guardium 10.1.0
CVE-2017-1267 MEDIUM

IBM Security Guardium 10.0 and 10.1 processes patches, image backups and other updates without sufficiently verifying the origin and integrity of the code. IBM X-Force ID: 124742.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm security_guardium 9.0
ibm security_guardium 10.0.1
ibm security_guardium 10.0
ibm security_guardium 9.1
ibm security_guardium 10.1
ibm security_guardium 10.1.2
ibm security_guardium 9.5
CVE-2017-1268 LOW

IBM Security Guardium 10 and 10.5 uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the software does not also use a salt as part of the input. IBM X-Force ID: 124743.

CVSS 2.0

Severity: LOW

Problem Type: CWE-310,

Products Affected

Vendor Product Version
ibm security_guardium *
CVE-2017-1269 HIGH

IBM Security Guardium 10.0 and 10.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-force ID: 124744

CVSS 2.0

Severity: HIGH

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm security_guardium 10.0.1
ibm security_guardium 10.0
ibm security_guardium 10.1
ibm security_guardium 10.1.2
CVE-2017-1270 LOW

IBM Security Guardium 10.0 does not renew a session variable after a successful authentication which could lead to session fixation/hijacking vulnerability. This could force a user to utilize a cookie that may be known to an attacker. IBM X-Force ID: 124745.

CVSS 2.0

Severity: LOW

Problem Type: CWE-384,

Products Affected

Vendor Product Version
ibm security_guardium 10.0.1
ibm security_guardium 10.0
ibm security_guardium 10.1.3
ibm security_guardium 10.1.2
ibm security_guardium 10.1.0
CVE-2017-1271 MEDIUM

IBM Security Guardium 9.0, 9.1, and 9.5 supports interaction between multiple actors and allows those actors to negotiate which algorithm should be used as a protection mechanism such as encryption or authentication, but it does not select the strongest algorithm that is available to both parties. IBM X-Force ID: 124746.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-326,

Products Affected

Vendor Product Version
ibm security_guardium 9.0
ibm security_guardium 9.1
ibm security_guardium 9.5
CVE-2017-1272 MEDIUM

IBM Security Guardium 10.0 and 10.5 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 124747. IBM X-Force ID: 124747.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_guardium *
CVE-2017-1274 MEDIUM

IBM Domino 8.5.3, and 9.0 is vulnerable to a stack based overflow in the IMAP service that could allow an authenticated attacker to execute arbitrary code by specifying a large mailbox name. IBM X-Force ID: 124749.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm domino 9.0.0.0
ibm domino 9.0.1.8
ibm domino 9.0.1
ibm domino 8.5.3.6
ibm domino 8.5.3
CVE-2017-1275 LOW

IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 124750.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_collaborative_lifecycle_management 6.0.3
ibm rational_quality_manager 5.0.0
ibm rational_collaborative_lifecycle_management 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_quality_manager 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.5
ibm rational_collaborative_lifecycle_management 5.0.0
ibm rational_quality_manager 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_quality_manager 6.0.0
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 6.0.1
ibm rational_quality_manager 6.0.5
ibm rational_collaborative_lifecycle_management 6.0.0
ibm rational_quality_manager 6.0.3
ibm rational_quality_manager 6.0.4
ibm rational_collaborative_lifecycle_management 6.0.4
CVE-2017-1276 LOW

IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 124751.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_doors_next_generation 6.0.3
ibm rational_requirements_composer 4.0.4
ibm rational_doors_next_generation 6.0.0
ibm rational_requirements_composer 4.0.2
ibm rational_doors_next_generation 5.0
ibm rational_requirements_composer 4.0.1
ibm rational_requirements_composer 4.0.3
ibm rational_requirements_composer 4.0.7
ibm rational_doors_next_generation 5.0.0
ibm rational_doors_next_generation 5.0.2
ibm rational_doors_next_generation 6.0.2
ibm rational_requirements_composer 4.0.5
ibm rational_requirements_composer 4.0.6
ibm rational_doors_next_generation 5.0.1
ibm rational_doors_next_generation 6.0.1
CVE-2017-1277 LOW

IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 124752.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_collaborative_lifecycle_management 6.0.3
ibm rational_quality_manager 5.0.0
ibm rational_collaborative_lifecycle_management 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_quality_manager 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.5
ibm rational_collaborative_lifecycle_management 5.0.0
ibm rational_quality_manager 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_quality_manager 6.0.0
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 6.0.1
ibm rational_quality_manager 6.0.5
ibm rational_collaborative_lifecycle_management 6.0.0
ibm rational_quality_manager 6.0.3
ibm rational_quality_manager 6.0.4
ibm rational_collaborative_lifecycle_management 6.0.4
CVE-2017-1278 LOW

IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0 and 6.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 124756.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_doors_next_generation 6.0.3
ibm rational_requirements_composer 4.0.4
ibm rational_doors_next_generation 6.0.0
ibm rational_requirements_composer 4.0.2
ibm rational_doors_next_generation 5.0
ibm rational_requirements_composer 4.0.1
ibm rational_requirements_composer 4.0.3
ibm rational_requirements_composer 4.0.7
ibm rational_doors_next_generation 5.0.0
ibm rational_doors_next_generation 5.0.2
ibm rational_doors_next_generation 6.0.2
ibm rational_requirements_composer 4.0.5
ibm rational_requirements_composer 4.0.6
ibm rational_doors_next_generation 5.0.1
ibm rational_doors_next_generation 6.0.1
CVE-2017-1279 MEDIUM

IBM Tealeaf Customer Experience 8.7, 8.8, and 9.0.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 124757.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm tealeaf_customer_experience 8.8
ibm tealeaf_customer_experience 8.7
ibm tealeaf_customer_experience 9.0.2
CVE-2017-1280 LOW

IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 124758.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_collaborative_lifecycle_management 6.0.3
ibm rational_quality_manager 5.0.0
ibm rational_collaborative_lifecycle_management 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_quality_manager 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.5
ibm rational_collaborative_lifecycle_management 5.0.0
ibm rational_quality_manager 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_quality_manager 6.0.0
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 6.0.1
ibm rational_quality_manager 6.0.5
ibm rational_collaborative_lifecycle_management 6.0.0
ibm rational_quality_manager 6.0.3
ibm rational_quality_manager 6.0.4
ibm rational_collaborative_lifecycle_management 6.0.4
CVE-2017-1281 LOW

IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 124759.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_collaborative_lifecycle_management 6.0.3
ibm rational_quality_manager 5.0.0
ibm rational_collaborative_lifecycle_management 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_quality_manager 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.5
ibm rational_collaborative_lifecycle_management 5.0.0
ibm rational_quality_manager 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_quality_manager 6.0.0
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 6.0.1
ibm rational_quality_manager 6.0.5
ibm rational_collaborative_lifecycle_management 6.0.0
ibm rational_quality_manager 6.0.3
ibm rational_quality_manager 6.0.4
ibm rational_collaborative_lifecycle_management 6.0.4
CVE-2017-1282 LOW

IBM Content Navigator & CMIS 2.0 and 3.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 124760.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm content_navigator 2.0.3.7
ibm content_navigator 2.0.3.5
ibm content_navigator 2.0.3.8
ibm content_navigator 3.0.0
ibm content_navigator 2.0.3.6
CVE-2017-1283 MEDIUM

IBM WebSphere MQ 8.0 and 9.0 could allow an authenticated user to cause a shared memory leak by MQ applications using dynamic queues, which can lead to lack of resources for other MQ applications. IBM X-Force ID: 125144.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-772,

Products Affected

Vendor Product Version
ibm websphere_mq 9.0
ibm websphere_mq 9.0.3
ibm websphere_mq 8.0.0.3
ibm websphere_mq 8.0.0.4
ibm websphere_mq 9.0.0.1
ibm websphere_mq 8.0.0.7
ibm websphere_mq 8.0.0.2
ibm websphere_mq 8.0.0.6
ibm websphere_mq 8.0.0.5
ibm websphere_mq 8.0.0.1
ibm websphere_mq 9.0.1
ibm websphere_mq 8.0
ibm websphere_mq 9.0.4
ibm websphere_mq 9.0.2
CVE-2017-1284 LOW

IBM WebSphere MQ 9.0.1 and 9.0.2 could allow a local user with ability to run or enable trace, to obtain sensitive information from WebSphere Application Server traces including user credentials. IBM X-Force ID: 125145.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_mq 9.0.1
ibm websphere_mq 9.0.2
CVE-2017-1285 MEDIUM

IBM WebSphere MQ 9.0.1 and 9.0.2 could allow an authenticated user with authority to send a specially crafted message that would cause a channel to remain in a running state but not process messages. IBM X-Force ID: 125146.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm websphere_mq 9.0.1
ibm websphere_mq 9.0.2
CVE-2017-1286 MEDIUM

Sensitive information about the configuration of the IBM UrbanCode Deploy 6.1 through 6.9.6.0 server and database can be obtained by a user who has been given elevated permissions in the UI, even after those elevated permissions have been revoked. IBM X-Force ID: 125147.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm urbancode_deploy *
CVE-2017-1287 MEDIUM

IBM Rhapsody DM 5.0 and 6.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-601,

Products Affected

Vendor Product Version
ibm rhapsody_design_manager 6.0.3
ibm rhapsody_design_manager 6.0.1
ibm rhapsody_design_manager 6.0.2
ibm rhapsody_design_manager 5.0.2
ibm rhapsody_design_manager 6.0
ibm rhapsody_design_manager 5.0
ibm rhapsody_design_manager 5.0.1
CVE-2017-1289 MEDIUM

IBM SDK, Java Technology Edition is vulnerable XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume memory resources. IBM X-Force ID: 125150.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm sdk *
CVE-2017-1290 LOW

IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125151.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm openpages_grc_platform 7.1.0.0
ibm openpages_grc_platform 7.2.0.0
ibm openpages_grc_platform 7.2.0.1
ibm openpages_grc_platform 7.1.0.2
ibm openpages_grc_platform 7.2.0.2
ibm openpages_grc_platform 7.1.0.1
ibm openpages_grc_platform 7.2.0.3
ibm openpages_grc_platform 7.3.0.0
ibm openpages_grc_platform 7.2.0.4
ibm openpages_grc_platform 7.1.0.3
CVE-2017-1291 LOW

IBM Maximo Asset Management 7.5 and 7.6 is vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache poisoning, cross-site scripting, and possibly obtain sensitive information. IBM X-Force ID: 125152.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm maximo_asset_management 7.6
ibm maximo_asset_management 7.5
ibm maximo_asset_management_essentials 7.5
CVE-2017-1292 MEDIUM

IBM Maximo Asset Management 7.5 and 7.6 generates error messages that could reveal sensitive information that could be used in further attacks against the system. IBM X-Force ID: 125153.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm maximo_asset_management 7.6
ibm maximo_asset_management 7.5
ibm maximo_asset_management_essentials 7.5
CVE-2017-1293 LOW

IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125154.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_collaborative_lifecycle_management 6.0.3
ibm rational_quality_manager 5.0.0
ibm rational_collaborative_lifecycle_management 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_quality_manager 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.5
ibm rational_collaborative_lifecycle_management 5.0.0
ibm rational_quality_manager 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_quality_manager 6.0.0
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 6.0.1
ibm rational_quality_manager 6.0.5
ibm rational_collaborative_lifecycle_management 6.0.0
ibm rational_quality_manager 6.0.3
ibm rational_quality_manager 6.0.4
ibm rational_collaborative_lifecycle_management 6.0.4
CVE-2017-1294 LOW

IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125155.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_collaborative_lifecycle_management 6.0.3
ibm rational_quality_manager 5.0.0
ibm rational_collaborative_lifecycle_management 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_quality_manager 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.5
ibm rational_collaborative_lifecycle_management 5.0.0
ibm rational_quality_manager 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_quality_manager 6.0.0
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 6.0.1
ibm rational_quality_manager 6.0.5
ibm rational_collaborative_lifecycle_management 6.0.0
ibm rational_quality_manager 6.0.3
ibm rational_quality_manager 6.0.4
ibm rational_collaborative_lifecycle_management 6.0.4
CVE-2017-1295 MEDIUM

IBM RSA DM contains unspecified vulnerability in CLM Applications with potential for information leakage. IBM X-Force ID: 125157.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_collaborative_lifecycle_management 6.0.3
ibm rational_collaborative_lifecycle_management 6.0.2
ibm rational_collaborative_lifecycle_management 4.0.6
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_collaborative_lifecycle_management 6.0
ibm rational_collaborative_lifecycle_management 4.0
ibm rational_collaborative_lifecycle_management 4.0.1
ibm rational_collaborative_lifecycle_management 4.0.5
ibm rational_collaborative_lifecycle_management 4.0.7
ibm rational_collaborative_lifecycle_management 4.0.3
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_collaborative_lifecycle_management 4.0.2
ibm rational_collaborative_lifecycle_management 5.0
ibm rational_collaborative_lifecycle_management 6.0.4
ibm rational_collaborative_lifecycle_management 4.0.4
CVE-2017-1297 MEDIUM

IBM DB2 for Linux, UNIX and Windows 9.2, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) is vulnerable to a stack-based buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code. IBM X-Force ID: 125159.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2 11.1
ibm data_server_runtime_client -
ibm db2_connect 10.1
ibm data_server_client -
ibm db2 9.7
ibm data_server_driver_for_odbc_and_cli -
ibm data_server_driver_package -
ibm db2_connect 10.5
ibm db2 10.1
ibm db2_connect 9.7
ibm db2_connect 11.1.0.0
CVE-2017-1299 LOW

IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125161.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_collaborative_lifecycle_management 6.0.3
ibm rational_quality_manager 5.0.0
ibm rational_collaborative_lifecycle_management 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_quality_manager 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.5
ibm rational_collaborative_lifecycle_management 5.0.0
ibm rational_quality_manager 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_quality_manager 6.0.0
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 6.0.1
ibm rational_quality_manager 6.0.5
ibm rational_collaborative_lifecycle_management 6.0.0
ibm rational_quality_manager 6.0.3
ibm rational_quality_manager 6.0.4
ibm rational_collaborative_lifecycle_management 6.0.4
CVE-2017-1300 MEDIUM

IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 125162.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm openpages_grc_platform 7.1.0.0
ibm openpages_grc_platform 7.2.0.0
ibm openpages_grc_platform 7.2.0.1
ibm openpages_grc_platform 7.1.0.2
ibm openpages_grc_platform 7.2.0.2
ibm openpages_grc_platform 7.1.0.1
ibm openpages_grc_platform 7.2.0.3
ibm openpages_grc_platform 7.3.0.0
ibm openpages_grc_platform 7.2.0.4
ibm openpages_grc_platform 7.1.0.3
CVE-2017-1301 LOW

IBM Spectrum Protect 7.1 and 8.1 could allow a local attacker to launch a symlink attack. IBM Spectrum Protect Backup-archive Client creates temporary files insecurely. A local attacker could exploit this vulnerability by creating a symbolic link from a temporary file to various files on the system, which could allow the attacker to overwrite arbitrary files on the system with elevated privileges. IBM X-Force ID: 125163.

CVSS 2.0

Severity: LOW

Problem Type: CWE-59,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager 7.1.3.1
ibm tivoli_storage_manager 6.3.2.2
ibm tivoli_storage_manager 6.3.6
ibm tivoli_storage_manager 6.3.3
ibm tivoli_storage_manager 6.1.1
ibm tivoli_storage_manager 7.1.3
ibm tivoli_storage_manager 6.1.5
ibm tivoli_storage_manager 6.2.4
ibm tivoli_storage_manager 7.1..5.100
ibm tivoli_storage_manager 7.1.3.2
ibm tivoli_storage_manager 6.2.3
ibm tivoli_storage_manager 7.1.0.3
ibm tivoli_storage_manager 7.1.4.2
ibm tivoli_storage_manager 7.1.4
ibm tivoli_storage_manager 7.1.6
ibm tivoli_storage_manager 7.1.1.1
ibm tivoli_storage_manager 6.4.3
ibm tivoli_storage_manager 7.1.1.100
ibm tivoli_storage_manager 7.1.1
ibm tivoli_storage_manager 6.4.2.600
ibm tivoli_storage_manager 6.3.1.2
ibm tivoli_storage_manager 6.3.0.15
ibm tivoli_storage_manager 6.4.1
ibm tivoli_storage_manager 7.1.6.6
ibm tivoli_storage_manager 6.4.2
ibm tivoli_storage_manager 6.1.3
ibm tivoli_storage_manager 7.1.1.300
ibm tivoli_storage_manager 7.1.5.200
ibm tivoli_storage_manager 7.1.3.000
ibm tivoli_storage_manager 6.1
ibm tivoli_storage_manager 6.2.1
ibm tivoli_storage_manager 6.1.0
ibm tivoli_storage_manager 6.3
ibm tivoli_storage_manager 6.4.2.200
ibm tivoli_storage_manager 6.4.2.500
ibm tivoli_storage_manager 7.1.1.2
ibm tivoli_storage_manager 6.3.1
ibm tivoli_storage_manager 6.1.5.5
ibm tivoli_storage_manager 6.1.2
ibm tivoli_storage_manager 7.1.4.1
ibm tivoli_storage_manager 7.1
ibm tivoli_storage_manager 7.1.5
ibm tivoli_storage_manager 6.3.4
ibm tivoli_storage_manager 7.1.0.1
ibm tivoli_storage_manager 7.1.3.100
ibm tivoli_storage_manager 6.4.3.1
ibm tivoli_storage_manager 6.3.5
ibm tivoli_storage_manager 6.3.0.17
ibm tivoli_storage_manager 6.1.5.6
ibm tivoli_storage_manager 8.1.0.2
ibm tivoli_storage_manager 6.4.1.0
ibm tivoli_storage_manager 7.1.1.200
ibm tivoli_storage_manager 8.1.0
ibm tivoli_storage_manager 6.2.0
ibm tivoli_storage_manager 6.3.0.5
ibm tivoli_storage_manager 6.3.6.100
ibm tivoli_storage_manager 7.1.0.2
ibm tivoli_storage_manager 6.4.2.100
ibm tivoli_storage_manager 6.3.5.1
ibm tivoli_storage_manager 6.1.4
ibm tivoli_storage_manager 6.2.2
ibm tivoli_storage_manager 6.1.5.4
CVE-2017-1302 LOW

IBM Sterling B2B Integrator Standard Edition 5.2 could allow a local user view sensitive information due to improper access controls. IBM X-Force ID: 125456.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2
CVE-2017-1303 MEDIUM

IBM WebSphere Portal and Web Content Manager 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125457.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
134c704f-9b21-4f2e-91b3-4a467353bcc0 6.1 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N 2.8 2.7

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 9.0
ibm websphere_portal 8.0
ibm websphere_portal 8.5
ibm websphere_portal 7.0
CVE-2017-1304 MEDIUM

IBM has identified a vulnerability with IBM Spectrum Scale/GPFS utilized on the Elastic Storage Server (ESS)/GPFS Storage Server (GSS) during testing of an unsupported configuration, where users applications are running on an active ESS I/O server node and utilize direct I/O to perform a read or a write to a Spectrum Scale file. This vulnerability may result in the use of an incorrect memory address, leading to a Spectrum Scale/GPFS daemon failure with a Signal 11, and possibly leading to denial of service or undetected data corruption. IBM X-Force ID: 125458.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 6.2 MEDIUM CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H 1.4 4.7

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm elastic_storage_server 3.0.5
ibm elastic_storage_server 2.5.5
ibm elastic_storage_server 4.5.0
ibm elastic_storage_server 4.6.0
ibm elastic_storage_server 4.0.6
ibm elastic_storage_server 2.5.0
ibm elastic_storage_server 3.5.0
ibm elastic_storage_server 5.0.1
ibm elastic_storage_server 3.5.6
ibm elastic_storage_server 2.0.0
ibm elastic_storage_server 5.0.0
ibm elastic_storage_server 3.0.0
ibm elastic_storage_server 4.0.0
CVE-2017-1305 LOW

IBM DOORS Next Generation (DNG/RRC) 6.0.2 and 6.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125459.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_doors_next_generation 6.0.3
ibm rational_doors_next_generation 6.0.2
CVE-2017-1306 LOW

IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125460.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_collaborative_lifecycle_management 6.0.3
ibm rational_quality_manager 5.0.0
ibm rational_collaborative_lifecycle_management 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_quality_manager 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.5
ibm rational_collaborative_lifecycle_management 5.0.0
ibm rational_quality_manager 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_quality_manager 6.0.0
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 6.0.1
ibm rational_quality_manager 6.0.5
ibm rational_collaborative_lifecycle_management 6.0.0
ibm rational_quality_manager 6.0.3
ibm rational_quality_manager 6.0.4
ibm rational_collaborative_lifecycle_management 6.0.4
CVE-2017-1308 MEDIUM

IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0 could allow an authenticated attacker to download files they should not have access to due to improper access controls. IBM X-Force ID: 125462.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-552,

Products Affected

Vendor Product Version
ibm daeja_viewone 4.1.5
ibm daeja_viewone 4.1.5.1
ibm daeja_viewone 5.0
CVE-2017-1309 LOW

IBM InfoSphere Master Data Management Server 11.0 - 11.6 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 125463.

CVSS 2.0

Severity: LOW

Problem Type: CWE-312,

Products Affected

Vendor Product Version
ibm infosphere_master_data_management_server 11.5
ibm infosphere_master_data_management_server 11.0
ibm infosphere_master_data_management_server 11.3
ibm infosphere_master_data_management_server 11.6
ibm infosphere_master_data_management_server 11.4
CVE-2017-1310 MEDIUM

IBM Informix Dynamic Server 12.1 could allow an authenticated user to cause a buffer overflow that would write large assertion fail files to the server. Done enough times, this could use large parts of the file system and cause the server to crash. IBM X-Force ID: 125569.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm informix_dynamic_server 12.10
CVE-2017-1311 MEDIUM

IBM Insights Foundation for Energy 2.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 125719.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm insights_foundation_for_energy 2.0
CVE-2017-1312 LOW

IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125723.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_collaborative_lifecycle_management 6.0.3
ibm rational_collaborative_lifecycle_management 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_collaborative_lifecycle_management 6.0
ibm rational_quality_manager 5.0.2
ibm rational_quality_manager 6.0
ibm rational_collaborative_lifecycle_management 6.0.5
ibm rational_quality_manager 5.0
ibm rational_quality_manager 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 6.0.1
ibm rational_quality_manager 6.0.5
ibm rational_quality_manager 6.0.3
ibm rational_collaborative_lifecycle_management 5.0
ibm rational_quality_manager 6.0.4
ibm rational_collaborative_lifecycle_management 6.0.4
CVE-2017-1313 LOW

IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125724.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_collaborative_lifecycle_management 6.0.3
ibm rational_collaborative_lifecycle_management 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_collaborative_lifecycle_management 6.0
ibm rational_quality_manager 5.0.2
ibm rational_quality_manager 6.0
ibm rational_collaborative_lifecycle_management 6.0.5
ibm rational_quality_manager 5.0
ibm rational_quality_manager 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 6.0.1
ibm rational_quality_manager 6.0.5
ibm rational_quality_manager 6.0.3
ibm rational_collaborative_lifecycle_management 5.0
ibm rational_quality_manager 6.0.4
ibm rational_collaborative_lifecycle_management 6.0.4
CVE-2017-1314 LOW

IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125725.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_collaborative_lifecycle_management 6.0.3
ibm rational_collaborative_lifecycle_management 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_collaborative_lifecycle_management 6.0
ibm rational_quality_manager 5.0.2
ibm rational_quality_manager 6.0
ibm rational_collaborative_lifecycle_management 6.0.5
ibm rational_quality_manager 5.0
ibm rational_quality_manager 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 6.0.1
ibm rational_quality_manager 6.0.5
ibm rational_quality_manager 6.0.3
ibm rational_collaborative_lifecycle_management 5.0
ibm rational_quality_manager 6.0.4
ibm rational_collaborative_lifecycle_management 6.0.4
CVE-2017-1315 LOW

IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125727.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_collaborative_lifecycle_management 6.0.3
ibm rational_collaborative_lifecycle_management 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_collaborative_lifecycle_management 6.0
ibm rational_quality_manager 5.0.2
ibm rational_quality_manager 6.0
ibm rational_collaborative_lifecycle_management 6.0.5
ibm rational_quality_manager 5.0
ibm rational_quality_manager 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 6.0.1
ibm rational_quality_manager 6.0.5
ibm rational_quality_manager 6.0.3
ibm rational_collaborative_lifecycle_management 5.0
ibm rational_quality_manager 6.0.4
ibm rational_collaborative_lifecycle_management 6.0.4
CVE-2017-1316 LOW

IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125728.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_collaborative_lifecycle_management 6.0.3
ibm rational_collaborative_lifecycle_management 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_collaborative_lifecycle_management 6.0
ibm rational_quality_manager 5.0.2
ibm rational_quality_manager 6.0
ibm rational_collaborative_lifecycle_management 6.0.5
ibm rational_quality_manager 5.0
ibm rational_quality_manager 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 6.0.1
ibm rational_quality_manager 6.0.5
ibm rational_quality_manager 6.0.3
ibm rational_collaborative_lifecycle_management 5.0
ibm rational_quality_manager 6.0.4
ibm rational_collaborative_lifecycle_management 6.0.4
CVE-2017-1317 LOW

IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125729.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_collaborative_lifecycle_management 6.0.3
ibm rational_collaborative_lifecycle_management 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_collaborative_lifecycle_management 6.0
ibm rational_quality_manager 5.0.2
ibm rational_quality_manager 6.0
ibm rational_collaborative_lifecycle_management 6.0.5
ibm rational_quality_manager 5.0
ibm rational_quality_manager 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 6.0.1
ibm rational_quality_manager 6.0.5
ibm rational_quality_manager 6.0.3
ibm rational_collaborative_lifecycle_management 5.0
ibm rational_quality_manager 6.0.4
ibm rational_collaborative_lifecycle_management 6.0.4
CVE-2017-1318 HIGH

IBM MQ Appliance 8.0 and 9.0 could allow an authenticated messaging administrator to execute arbitrary commands on the system, caused by command execution. IBM X-Force ID: 125730.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-78,

Products Affected

Vendor Product Version
ibm mq_appliance 8.0.0.1
ibm mq_appliance 8.0.0.3
ibm mq_appliance 9.0.2
ibm mq_appliance 8.0.0.4
ibm mq_appliance 8.0.0.2
ibm mq_appliance 8.0.0.5
ibm mq_appliance 8.0.0.0
ibm mq_appliance 9.0.1
ibm mq_appliance 8.0.0.6
CVE-2017-1319 MEDIUM

IBM Tivoli Federated Identity Manager 6.2 is affected by a vulnerability due to a missing secure attribute in encrypted session (SSL) cookie. IBM X-Force ID: 125731.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-326,

Products Affected

Vendor Product Version
ibm tivoli_federated_identity_manager 6.2.1
ibm tivoli_federated_identity_manager 6.2.2
ibm tivoli_federated_identity_manager 6.2.0
CVE-2017-1320 LOW

IBM Tivoli Federated Identity Manager 6.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125732.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tivoli_federated_identity_manager 6.2.0.3
ibm tivoli_federated_identity_manager 6.2.1.1
ibm tivoli_federated_identity_manager 6.2.1.7
ibm tivoli_federated_identity_manager 6.2.2.9
ibm tivoli_federated_identity_manager 6.2.0.12
ibm tivoli_federated_identity_manager 6.2.0.13
ibm tivoli_federated_identity_manager 6.2.0.1
ibm tivoli_federated_identity_manager 6.2.1.4
ibm tivoli_federated_identity_manager 6.2.0.9
ibm tivoli_federated_identity_manager 6.2.0.16
ibm tivoli_federated_identity_manager 6.2.0.8
ibm tivoli_federated_identity_manager 6.2.0.11
ibm tivoli_federated_identity_manager 6.2.2.10
ibm tivoli_federated_identity_manager 6.2.2.4
ibm tivoli_federated_identity_manager 6.2.1.6
ibm tivoli_federated_identity_manager 6.2.0.10
ibm tivoli_federated_identity_manager 6.2.2.13
ibm tivoli_federated_identity_manager 6.2.2.3
ibm tivoli_federated_identity_manager 6.2.2.7
ibm tivoli_federated_identity_manager 6.2.2.17
ibm tivoli_federated_identity_manager 6.2.1
ibm tivoli_federated_identity_manager 6.2.1.5
ibm tivoli_federated_identity_manager 6.2.2.8
ibm tivoli_federated_identity_manager 6.2.2.15
ibm tivoli_federated_identity_manager 6.2.0.15
ibm tivoli_federated_identity_manager 6.2.0.17
ibm tivoli_federated_identity_manager 6.2.2.11
ibm tivoli_federated_identity_manager 6.2.0
ibm tivoli_federated_identity_manager 6.2.2.2
ibm tivoli_federated_identity_manager 6.2.0.14
ibm tivoli_federated_identity_manager 6.2.1.3
ibm tivoli_federated_identity_manager 6.2.0.2
ibm tivoli_federated_identity_manager 6.2.2
ibm tivoli_federated_identity_manager 6.2.2.6
ibm tivoli_federated_identity_manager 6.2.2.16
ibm tivoli_federated_identity_manager 6.2.1.9
ibm tivoli_federated_identity_manager 6.2.1.8
ibm tivoli_federated_identity_manager 6.2.2.12
ibm tivoli_federated_identity_manager 6.2.2.14
ibm tivoli_federated_identity_manager 6.2.1.2
CVE-2017-1321 MEDIUM

IBM InfoSphere Information Server 9.1, 11.3, and 11.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125916.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 6.1 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N 2.8 2.7

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm infosphere_information_server 11.3
ibm infosphere_information_server 11.5
ibm infosphere_information_server 9.1
ibm infosphere_information_server_on_cloud 11.5
CVE-2017-1322 MEDIUM

IBM API Connect 5.0.6.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume memory resources. IBM X-Force ID: 125918.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm api_connect 5.0.2.0
ibm api_connect 5.0.0.0
ibm api_connect 5.0.1.0
ibm api_connect 5.0.4.0
ibm api_connect 5.0.0.1
ibm api_connect 5.0.5.0
ibm api_connect 5.0.6.0
ibm api_connect 5.0.6.2
ibm api_connect 5.0.7.0
ibm api_connect 5.0.3.0
ibm api_connect 5.0.6.1
CVE-2017-1324 LOW

IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125975.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_engineering_lifecycle_manager 5.0.1
ibm rational_engineering_lifecycle_manager 6.0.2
ibm rational_engineering_lifecycle_manager 4.0.3
ibm rational_engineering_lifecycle_manager 4.0.4
ibm rational_engineering_lifecycle_manager 4.0.5
ibm rational_engineering_lifecycle_manager 4.0.7
ibm rational_engineering_lifecycle_manager 6.0.0
ibm rational_engineering_lifecycle_manager 6.0.1
ibm rational_engineering_lifecycle_manager 4.0.6
ibm rational_engineering_lifecycle_manager 5.0.0
ibm rational_engineering_lifecycle_manager 6.0.4
ibm rational_engineering_lifecycle_manager 6.0.3
ibm rational_engineering_lifecycle_manager 5.0.2
CVE-2017-1325 MEDIUM

IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125976.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm inotes 8.5.2.1
ibm inotes 8.5.2.3
ibm inotes 9.0.1.0
ibm inotes 8.5.3.2
ibm inotes 9.0.1.3
ibm inotes 9.0.1.6
ibm inotes 8.5.3.4
ibm inotes 8.5.3.1
ibm inotes 8.5.3.0
ibm inotes 8.5.1.4
ibm inotes 9.0.1.7
ibm inotes 9.0.1.1
ibm inotes 8.5.3.3
ibm inotes 8.5.3.5
ibm inotes 9.0.0.0
ibm inotes 9.0.1.2
ibm inotes 9.0.1.4
ibm inotes 8.5.2.0
ibm inotes 8.5.0.0
ibm inotes 8.5.0.1
ibm inotes 8.5.1.1
ibm inotes 8.5.1.5
ibm inotes 8.5.2.2
ibm inotes 8.5.1.0
ibm inotes 9.0.1.5
ibm inotes 8.5.1.2
ibm inotes 8.5.1.3
CVE-2017-1326 MEDIUM

IBM Sterling File Gateway does not properly restrict user requests based on permission level. This allows for users to update data related to other users, by manipulating the parameters passed in the POST request. IBM X-Force ID: 126060.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-269,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2
CVE-2017-1327 MEDIUM

IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126062.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm inotes 8.5.2.1
ibm inotes 9.0.1.1
ibm inotes 9.0.1.8
ibm inotes 9.0.0.0
ibm inotes 9.0.1.0
ibm inotes 8.5.2.0
ibm inotes 8.5.3.6
ibm inotes 8.5.0.0
ibm inotes 8.5.1.1
ibm inotes 8.5.1.5
ibm inotes 8.5.1.0
ibm inotes 8.5.3.1
ibm inotes 8.5.3.0
ibm inotes 8.5.2.4
CVE-2017-1328 MEDIUM

IBM API Connect 5.0.0.0 - 5.0.6.0 could allow a remote attacker to bypass security restrictions of the api, caused by improper handling of security policy. By crafting a suitable request, an attacker could exploit this vulnerability to bypass security and use the vulnerable API. IBM X-Force ID: 126230.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm api_connect 5.0.2.0
ibm api_connect 5.0.0.0
ibm api_connect 5.0.1.0
ibm api_connect 5.0.4.0
ibm api_connect 5.0.0.1
ibm api_connect 5.0.5.0
ibm api_connect 5.0.6.0
ibm api_connect 5.0.6.2
ibm api_connect 5.0.3.0
ibm api_connect 5.0.6.1
CVE-2017-1329 LOW

IBM Quality Manager (RQM) 5.0.x and 6.0 through 6.0.5 are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 126231.

CVSS 2.0

Severity: LOW

Problem Type: CWE-94,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
ibm rational_collaborative_lifecycle_management *
CVE-2017-1331 LOW

IBM Content Navigator 2.0.3 and 3.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126233.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm content_navigator 2.0.3.7
ibm content_navigator 2.0.3.5
ibm content_navigator 2.0.3.8
ibm content_navigator 3.0.0
ibm content_navigator 2.0.3.6
CVE-2017-1332 MEDIUM

IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126234.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm inotes 8.5.2.1
ibm inotes 9.0.1.1
ibm inotes 9.0.1.8
ibm inotes 9.0.0.0
ibm inotes 9.0.1.0
ibm inotes 8.5.2.0
ibm inotes 8.5.3.6
ibm inotes 8.5.0.0
ibm inotes 8.5.1.1
ibm inotes 8.5.1.5
ibm inotes 8.5.1.0
ibm inotes 8.5.3.1
ibm inotes 8.5.3.0
ibm inotes 8.5.2.4
CVE-2017-1333 MEDIUM

IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 could allow an unauthenticated user to obtain sensitive information about the server that could be used in future attacks against the system. IBM X-Force ID: 126241.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm openpages_grc_platform 7.1.0.0
ibm openpages_grc_platform 7.2.0.0
ibm openpages_grc_platform 7.2.0.1
ibm openpages_grc_platform 7.1.0.2
ibm openpages_grc_platform 7.2.0.2
ibm openpages_grc_platform 7.1.0.1
ibm openpages_grc_platform 7.2.0.3
ibm openpages_grc_platform 7.3.0.0
ibm openpages_grc_platform 7.2.0.4
ibm openpages_grc_platform 7.1.0.3
CVE-2017-1334 LOW

IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126242.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_engineering_lifecycle_manager 5.0.1
ibm rational_engineering_lifecycle_manager 6.0.2
ibm rational_engineering_lifecycle_manager 4.0.3
ibm rational_engineering_lifecycle_manager 4.0.4
ibm rational_engineering_lifecycle_manager 4.0.5
ibm rational_engineering_lifecycle_manager 4.0.7
ibm rational_engineering_lifecycle_manager 6.0.0
ibm rational_engineering_lifecycle_manager 6.0.1
ibm rational_engineering_lifecycle_manager 4.0.6
ibm rational_engineering_lifecycle_manager 5.0.0
ibm rational_engineering_lifecycle_manager 6.0.4
ibm rational_engineering_lifecycle_manager 6.0.3
ibm rational_engineering_lifecycle_manager 5.0.2
CVE-2017-1335 LOW

IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126243.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_engineering_lifecycle_manager 5.0.1
ibm rational_engineering_lifecycle_manager 6.0.2
ibm rational_engineering_lifecycle_manager 4.0.3
ibm rational_engineering_lifecycle_manager 4.0.4
ibm rational_engineering_lifecycle_manager 4.0.5
ibm rational_engineering_lifecycle_manager 4.0.7
ibm rational_engineering_lifecycle_manager 6.0.0
ibm rational_engineering_lifecycle_manager 6.0.1
ibm rational_engineering_lifecycle_manager 4.0.6
ibm rational_engineering_lifecycle_manager 5.0.0
ibm rational_engineering_lifecycle_manager 6.0.4
ibm rational_engineering_lifecycle_manager 6.0.3
ibm rational_engineering_lifecycle_manager 5.0.2
CVE-2017-1336 LOW

IBM Infosphere BigInsights 4.2.0 could allow an attacker to inject code that could allow access to restricted data and files. IBM X-Force ID: 126244.

CVSS 2.0

Severity: LOW

Problem Type: CWE-94,

Products Affected

Vendor Product Version
ibm infosphere_biginsights 4.2.0
CVE-2017-1337 MEDIUM

IBM WebSphere MQ 9.0.1 and 9.0.2 Java/JMS application can incorrectly transmit user credentials in plain text. IBM X-Force ID: 126245.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-522,

Products Affected

Vendor Product Version
ibm websphere_mq 9.0.1
ibm websphere_mq 9.0.2
CVE-2017-1338 LOW

IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126246.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_requirements_composer 5.0.1
ibm rational_doors_next_generation 6.0.3
ibm rational_requirements_composer 4.0.4
ibm rational_doors_next_generation 6.0.0
ibm rational_requirements_composer 4.0.2
ibm rational_requirements_composer 4.0.1
ibm rational_requirements_composer 4.0.3
ibm rational_requirements_composer 4.0.7
ibm rational_doors_next_generation 6.0.2
ibm rational_requirements_composer 5.0.2
ibm rational_requirements_composer 4.0.5
ibm rational_requirements_composer 4.0.6
ibm rational_requirements_composer 5.0.0
ibm rational_doors_next_generation 6.0.1
CVE-2017-1339 LOW

IBM Spectrum Protect 7.1 and 8.1 (formerly Tivoli Storage Manager) Server uses weak encryption for the password. A database administrator may be able to decrypt the IBM Spectrum protect client or administrator password which can result in information disclosure or a denial of service. IBM X-Force ID: 126247.

CVSS 2.0

Severity: LOW

Problem Type: CWE-327,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager 7.1.3.1
ibm tivoli_storage_manager 6.3.2.2
ibm tivoli_storage_manager 6.3.6
ibm tivoli_storage_manager 6.3.3
ibm tivoli_storage_manager 6.1.1
ibm tivoli_storage_manager 7.1.3
ibm tivoli_storage_manager 6.1.5
ibm tivoli_storage_manager 6.2.4
ibm tivoli_storage_manager 7.1..5.100
ibm tivoli_storage_manager 7.1.3.2
ibm tivoli_storage_manager 6.2.3
ibm tivoli_storage_manager 7.1.0.3
ibm tivoli_storage_manager 7.1.4.2
ibm tivoli_storage_manager 7.1.4
ibm tivoli_storage_manager 7.1.6
ibm tivoli_storage_manager 7.1.7.100
ibm tivoli_storage_manager 7.1.1.1
ibm tivoli_storage_manager 6.4.3
ibm tivoli_storage_manager 7.1.1.100
ibm tivoli_storage_manager 7.1.1
ibm tivoli_storage_manager 6.4.2.600
ibm tivoli_storage_manager 6.3.1.2
ibm tivoli_storage_manager 6.3.0.15
ibm tivoli_storage_manager 6.4.1
ibm tivoli_storage_manager 6.4.2
ibm tivoli_storage_manager 6.1.3
ibm tivoli_storage_manager 7.1.1.300
ibm tivoli_storage_manager 7.1.5.200
ibm tivoli_storage_manager 7.1.3.000
ibm tivoli_storage_manager 7.1.7.200
ibm tivoli_storage_manager 6.1
ibm tivoli_storage_manager 6.2.1
ibm tivoli_storage_manager 6.1.0
ibm tivoli_storage_manager 6.3
ibm tivoli_storage_manager 6.4.2.200
ibm tivoli_storage_manager 6.4.2.500
ibm tivoli_storage_manager 7.1.1.2
ibm tivoli_storage_manager 6.3.1
ibm tivoli_storage_manager 6.1.5.5
ibm tivoli_storage_manager 6.1.2
ibm tivoli_storage_manager 7.1.4.1
ibm tivoli_storage_manager 7.1
ibm tivoli_storage_manager 7.1.5
ibm tivoli_storage_manager 8.1.1.100
ibm tivoli_storage_manager 7.1.7
ibm tivoli_storage_manager 6.3.4
ibm tivoli_storage_manager 7.1.0.1
ibm tivoli_storage_manager 7.1.3.100
ibm tivoli_storage_manager 6.4.3.1
ibm tivoli_storage_manager 6.3.5
ibm tivoli_storage_manager 6.3.0.17
ibm tivoli_storage_manager 6.1.5.6
ibm tivoli_storage_manager 6.4.1.0
ibm tivoli_storage_manager 7.1.1.200
ibm tivoli_storage_manager 8.1.0
ibm tivoli_storage_manager 6.2.0
ibm tivoli_storage_manager 6.3.0.5
ibm tivoli_storage_manager 6.3.6.100
ibm tivoli_storage_manager 7.1.0.2
ibm tivoli_storage_manager 6.4.2.100
ibm tivoli_storage_manager 6.3.5.1
ibm tivoli_storage_manager 6.1.4
ibm tivoli_storage_manager 8.1.1
ibm tivoli_storage_manager 6.2.2
ibm tivoli_storage_manager 6.1.5.4
CVE-2017-1340 MEDIUM

IBM Jazz Reporting Service (JRS) 6.0.4 could allow an authenticated user to obtain information on another server that the current report builder interacts with. IBM X-Force ID: 126455.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm jazz_reporting_service 6.0.4
CVE-2017-1341 MEDIUM

IBM WebSphere MQ 8.0 and 9.0 could allow, under special circumstances, an unauthorized user to access an object which they should have been denied access. IBM X-Force ID: 126456.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_mq 9.0
ibm websphere_mq 9.0.3
ibm websphere_mq 8.0.0.3
ibm websphere_mq 8.0.0.4
ibm websphere_mq 9.0.0.1
ibm websphere_mq 8.0.0.7
ibm websphere_mq 8.0.0.2
ibm websphere_mq 8.0.0.6
ibm websphere_mq 8.0.0.5
ibm websphere_mq 8.0.0.1
ibm websphere_mq 9.0.1
ibm websphere_mq 9.0.2
CVE-2017-1342 MEDIUM

IBM Insights Foundation for Energy 2.0 could reveal sensitive information in error messages to authenticated users that could e used to conduct further attacks. IBM X-Force ID: 126457.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm insights_foundation_for_energy 2.0
CVE-2017-1345 LOW

IBM Insights Foundation for Energy 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126460.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm insights_foundation_for_energy 2.0
CVE-2017-1346 LOW

IBM Business Process Manager 7.5, 8.0, and 8.5 temporarily stores files in a temporary folder during offline installs which could be read by a local user within a short timespan. IBM X-Force ID: 126461.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,CWE-362,

Products Affected

Vendor Product Version
ibm business_process_manager 8.0.1.2
ibm business_process_manager 8.5.6.0
ibm business_process_manager 8.0.1.1
ibm business_process_manager 7.5.0.1
ibm business_process_manager 8.5.6.1
ibm business_process_manager 8.5.0.2
ibm business_process_manager 7.5.1.0
ibm business_process_manager 7.5.1.1
ibm business_process_manager 8.5.6.2
ibm business_process_manager 8.5.5.0
ibm business_process_manager 8.0.1.0
ibm business_process_manager 7.5.1.2
ibm business_process_manager 8.0.0.0
ibm business_process_manager 8.5.7.0
ibm business_process_manager 8.5.0.1
ibm business_process_manager 8.0.1.3
ibm business_process_manager 8.5.0.0
ibm business_process_manager 7.5.0.0
CVE-2017-1347 MEDIUM

IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 126462.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2
CVE-2017-1348 LOW

IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126524.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2
CVE-2017-1349 LOW

IBM Sterling B2B Integrator Standard Edition 5.2 stores potentially sensitive information from HTTP sessions that could be read by a local user. IBM X-Force ID: 126525.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2
CVE-2017-1350 HIGH

IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 could allow a user to escalate their privileges to administrator due to improper access controls. IBM X-Force ID: 126526.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm infosphere_information_server 11.3
ibm infosphere_information_server 11.5
ibm infosphere_information_server 9.1
ibm infosphere_information_server 11.7
CVE-2017-1352 MEDIUM

IBM Maximo Asset Management 7.5 and 7.6 could allow an authenticated user to inject commands into work orders that could be executed by another user that downloads the affected file. IBM X-Force ID: 126538.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-77,

Products Affected

Vendor Product Version
ibm maximo_asset_management 7.6
ibm maximo_asset_management 7.5
CVE-2017-1353 LOW

IBM Atlas eDiscovery Process Management 6.0.3 could allow an authenticated attacker to obtain sensitive information when an unsuspecting user clicks on unsafe third-party links. IBM X-Force ID: 126680.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm atlas_ediscovery_process_management 6.0.3.4
ibm atlas_ediscovery_process_management 6.0.3.2
ibm atlas_ediscovery_process_management 6.0.3
ibm atlas_ediscovery_process_management 6.0.3.3
ibm atlas_ediscovery_process_management 6.0.3.5
CVE-2017-1354 LOW

IBM Atlas eDiscovery Process Management 6.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126681.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm atlas_ediscovery_process_management 6.0.3.4
ibm atlas_ediscovery_process_management 6.0.3.2
ibm atlas_ediscovery_process_management 6.0.3
ibm atlas_ediscovery_process_management 6.0.3.3
ibm atlas_ediscovery_process_management 6.0.3.5
CVE-2017-1355 MEDIUM

IBM Atlas eDiscovery Process Management 6.0.3 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 126682.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm atlas_ediscovery_process_management 6.0.3.4
ibm atlas_ediscovery_process_management 6.0.3.2
ibm atlas_ediscovery_process_management 6.0.3
ibm atlas_ediscovery_process_management 6.0.3.3
ibm atlas_ediscovery_process_management 6.0.3.5
CVE-2017-1356 MEDIUM

IBM Atlas eDiscovery Process Management 6.0.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 126683.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm atlas_ediscovery_process_management 6.0.3.4
ibm atlas_ediscovery_process_management 6.0.3.2
ibm atlas_ediscovery_process_management 6.0.3
ibm atlas_ediscovery_process_management 6.0.3.3
ibm atlas_ediscovery_process_management 6.0.3.5
CVE-2017-1357 MEDIUM

IBM Maximo Asset Management 7.5 and 7.6 could allow an authenticated user to manipulate work orders to forge emails which could be used to conduct further advanced attacks. IBM X-Force ID: 126684.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm maximo_asset_management_essentials 7.5.0.7
ibm maximo_asset_management 7.5.0.2
ibm maximo_asset_management_essentials 7.6.0.6
ibm maximo_asset_management 7.6.0.3
ibm maximo_asset_management_essentials 7.6.0.7
ibm maximo_asset_management 7.5.0.1
ibm maximo_asset_management 7.5.0.10
ibm maximo_asset_management_essentials 7.6.0.3
ibm maximo_asset_management_essentials 7.5.0.5
ibm maximo_asset_management 7.6.0.4
ibm maximo_asset_management_essentials 7.6.0.0
ibm maximo_asset_management_essentials 7.6.0.4
ibm maximo_asset_management_essentials 7.5.0.0
ibm maximo_asset_management_essentials 7.5.0.6
ibm maximo_asset_management 7.6.0.0
ibm maximo_asset_management_essentials 7.5.0.8
ibm maximo_asset_management_essentials 7.6.0.2
ibm maximo_asset_management 7.6.0.5
ibm maximo_asset_management 7.5.0.3
ibm maximo_asset_management 7.6.0.2
ibm maximo_asset_management_essentials 7.5.0.2
ibm maximo_asset_management_essentials 7.5.0.1
ibm maximo_asset_management_essentials 7.5.0.4
ibm maximo_asset_management 7.5.0.9
ibm maximo_asset_management_essentials 7.5.0.10
ibm maximo_asset_management 7.5.0.6
ibm maximo_asset_management 7.5.0.0
ibm maximo_asset_management 7.6.0.7
ibm maximo_asset_management 7.5.0.7
ibm maximo_asset_management_essentials 7.5.0.9
ibm maximo_asset_management 7.5.0.4
ibm maximo_asset_management 7.5.0.5
ibm maximo_asset_management_essentials 7.6.0.1
ibm maximo_asset_management_essentials 7.5.0.3
ibm maximo_asset_management 7.6.0.1
ibm maximo_asset_management_essentials 7.6.0.5
ibm maximo_asset_management 7.5.0.8
ibm maximo_asset_management 7.6.0.6
CVE-2017-1359 LOW

IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126686.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_engineering_lifecycle_manager 5.0.1
ibm rational_engineering_lifecycle_manager 6.0.2
ibm rational_engineering_lifecycle_manager 4.0.3
ibm rational_engineering_lifecycle_manager 4.0.4
ibm rational_engineering_lifecycle_manager 4.0.5
ibm rational_engineering_lifecycle_manager 4.0.7
ibm rational_engineering_lifecycle_manager 6.0.0
ibm rational_engineering_lifecycle_manager 6.0.1
ibm rational_engineering_lifecycle_manager 4.0.6
ibm rational_engineering_lifecycle_manager 5.0.0
ibm rational_engineering_lifecycle_manager 6.0.4
ibm rational_engineering_lifecycle_manager 6.0.3
ibm rational_engineering_lifecycle_manager 5.0.2
CVE-2017-1362 LOW

IBM Security Identity Manager Adapters 6.0 and 7.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 126801.

CVSS 2.0

Severity: LOW

Problem Type: CWE-522,

Products Affected

Vendor Product Version
ibm security_identity_manager 6.0
ibm security_identity_manager 7.0
CVE-2017-1363 LOW

IBM Team Concert (RTC) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126856.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_collaborative_lifecycle_management 6.0.3
ibm rational_collaborative_lifecycle_management 6.0.2
ibm rational_collaborative_lifecycle_management 4.0.6
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_collaborative_lifecycle_management 6.0
ibm rational_collaborative_lifecycle_management 4.0
ibm rational_collaborative_lifecycle_management 4.0.1
ibm rational_collaborative_lifecycle_management 4.0.5
ibm rational_collaborative_lifecycle_management 4.0.7
ibm rational_collaborative_lifecycle_management 4.0.3
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_collaborative_lifecycle_management 4.0.2
ibm rational_collaborative_lifecycle_management 5.0
ibm rational_collaborative_lifecycle_management 6.0.4
ibm rational_collaborative_lifecycle_management 4.0.4
CVE-2017-1364 LOW

IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126857.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_engineering_lifecycle_manager 5.0.1
ibm rational_engineering_lifecycle_manager 6.0.2
ibm rational_engineering_lifecycle_manager 4.0.3
ibm rational_engineering_lifecycle_manager 4.0.4
ibm rational_engineering_lifecycle_manager 4.0.5
ibm rational_engineering_lifecycle_manager 4.0.7
ibm rational_engineering_lifecycle_manager 6.0.0
ibm rational_engineering_lifecycle_manager 6.0.1
ibm rational_engineering_lifecycle_manager 4.0.6
ibm rational_engineering_lifecycle_manager 5.0.0
ibm rational_engineering_lifecycle_manager 6.0.4
ibm rational_engineering_lifecycle_manager 6.0.3
ibm rational_engineering_lifecycle_manager 5.0.2
CVE-2017-1365 LOW

IBM Team Concert (RTC including IBM Rational Collaborative Lifecycle Management 4.0, 5.0., and 6.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-force ID: 126858.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
ibm rational_engineering_lifecycle_manager *
ibm rational_software_architect_design_manager 5.0.0
ibm rational_software_architect_design_manager 5.0.2
ibm rational_software_architect_design_manager 6.0.0
ibm rational_software_architect_design_manager *
ibm rational_software_architect_design_manager 5.0.1
ibm rational_software_architect_design_manager 6.0.1
ibm rational_rhapsody_design_manager *
ibm rational_collaborative_lifecycle_management *
ibm rational_doors_next_generation *
ibm rational_team_concert *
CVE-2017-1366 MEDIUM

IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 126859.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-326,

Products Affected

Vendor Product Version
ibm security_identity_governance_and_intelligence 5.2
ibm security_identity_governance_and_intelligence 5.2.2
ibm security_identity_governance_and_intelligence 5.2.2.1
ibm security_identity_governance_and_intelligence 5.2.1
ibm security_identity_governance_and_intelligence 5.2.3.1
ibm security_identity_governance_and_intelligence 5.2.3.2
ibm security_identity_governance_and_intelligence 5.2.3
CVE-2017-1367 MEDIUM

IBM Security Identity Governance and Intelligence Virtual Appliance 5.2 through 5.2.3.2 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 126860.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_identity_governance_and_intelligence *
CVE-2017-1368 MEDIUM

IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 126861.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-384,

Products Affected

Vendor Product Version
ibm security_identity_governance_and_intelligence 5.2
ibm security_identity_governance_and_intelligence 5.2.2
ibm security_identity_governance_and_intelligence 5.2.2.1
ibm security_identity_governance_and_intelligence 5.2.1
ibm security_identity_governance_and_intelligence 5.2.3.1
ibm security_identity_governance_and_intelligence 5.2.3.2
ibm security_identity_governance_and_intelligence 5.2.3
CVE-2017-1369 LOW

IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126862.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_engineering_lifecycle_manager 5.0.1
ibm rational_engineering_lifecycle_manager 6.0.2
ibm rational_engineering_lifecycle_manager 4.0.3
ibm rational_engineering_lifecycle_manager 4.0.4
ibm rational_engineering_lifecycle_manager 4.0.5
ibm rational_engineering_lifecycle_manager 4.0.7
ibm rational_engineering_lifecycle_manager 6.0.0
ibm rational_engineering_lifecycle_manager 6.0.1
ibm rational_engineering_lifecycle_manager 4.0.6
ibm rational_engineering_lifecycle_manager 5.0.0
ibm rational_engineering_lifecycle_manager 6.0.4
ibm rational_engineering_lifecycle_manager 6.0.3
ibm rational_engineering_lifecycle_manager 5.0.2
CVE-2017-1370 MEDIUM

IBM Jazz Reporting Service (JRS) 5.0 and 6.0 could disclose sensitive information, including user credentials, through an error message from the Report Builder administrator configuration page. IBM X-Force ID: 126863.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-209,

Products Affected

Vendor Product Version
ibm jazz_reporting_service 6.0.3
ibm jazz_reporting_service 5.0.2
ibm jazz_reporting_service 6.0
ibm jazz_reporting_service 6.0.2
ibm jazz_reporting_service 6.0.1
ibm jazz_reporting_service 5.0
ibm jazz_reporting_service 5.0.1
ibm jazz_reporting_service 6.0.4
CVE-2017-1371 MEDIUM

Builder tools running in the IBM TRIRIGA Application Platform 3.3, 3.4, and 3.5 contains a vulnerability that could allow an authenticated user to execute Builder tool actions they do not have access to. IBM X-Force ID: 126864.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm tririga_application_platform 3.5.1.3
ibm tririga_application_platform 3.4.1.2
ibm tririga_application_platform 3.4.2.4
ibm tririga_application_platform 3.4.2.0
ibm tririga_application_platform 3.3.2.5
ibm tririga_application_platform 3.5.2.1
ibm tririga_application_platform 3.5.1
ibm tririga_application_platform 3.3.0.1
ibm tririga_application_platform 3.5.0.2
ibm tririga_application_platform 3.3.1.0
ibm tririga_application_platform 3.3.2.1
ibm tririga_application_platform 3.3.0.2
ibm tririga_application_platform 3.3.2.0
ibm tririga_application_platform 3.3.2.2
ibm tririga_application_platform 3.4.2.2
ibm tririga_application_platform 3.3.1.1
ibm tririga_application_platform 3.5.0.0
ibm tririga_application_platform 3.4.2.1
ibm tririga_application_platform 3.4.2.3
ibm tririga_application_platform 3.5.2
ibm tririga_application_platform 3.5.0.1
ibm tririga_application_platform 3.4.1.0
ibm tririga_application_platform 3.4.0.1
ibm tririga_application_platform 3.3.2.4
ibm tririga_application_platform 3.4.1.1
ibm tririga_application_platform 3.3.1.2
ibm tririga_application_platform 3.5.1.1
ibm tririga_application_platform 3.4.2.5
ibm tririga_application_platform 3.4.0.0
ibm tririga_application_platform 3.3.1.3
ibm tririga_application_platform 3.5.1.2
ibm tririga_application_platform 3.5.2.2
ibm tririga_application_platform 3.3.2.3
ibm tririga_application_platform 3.4.1.3
ibm tririga_application_platform 3.3.0.0
CVE-2017-1372 LOW

IBM TRIRIGA Application Platform 3.3, 3.4, and 3.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126865.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tririga_application_platform 3.5.1.3
ibm tririga_application_platform 3.4.1.2
ibm tririga_application_platform 3.4.2.4
ibm tririga_application_platform 3.4.2.0
ibm tririga_application_platform 3.3.2.5
ibm tririga_application_platform 3.5.2.1
ibm tririga_application_platform 3.5.1
ibm tririga_application_platform 3.3.0.1
ibm tririga_application_platform 3.5.0.2
ibm tririga_application_platform 3.3.1.0
ibm tririga_application_platform 3.3.2.1
ibm tririga_application_platform 3.3.0.2
ibm tririga_application_platform 3.3.2.0
ibm tririga_application_platform 3.3.2.2
ibm tririga_application_platform 3.4.2.2
ibm tririga_application_platform 3.3.1.1
ibm tririga_application_platform 3.5.0.0
ibm tririga_application_platform 3.4.2.1
ibm tririga_application_platform 3.4.2.3
ibm tririga_application_platform 3.5.2
ibm tririga_application_platform 3.5.0.1
ibm tririga_application_platform 3.4.1.0
ibm tririga_application_platform 3.4.0.1
ibm tririga_application_platform 3.3.2.4
ibm tririga_application_platform 3.4.1.1
ibm tririga_application_platform 3.3.1.2
ibm tririga_application_platform 3.5.1.1
ibm tririga_application_platform 3.4.2.5
ibm tririga_application_platform 3.4.0.0
ibm tririga_application_platform 3.3.1.3
ibm tririga_application_platform 3.5.1.2
ibm tririga_application_platform 3.5.2.2
ibm tririga_application_platform 3.3.2.3
ibm tririga_application_platform 3.4.1.3
ibm tririga_application_platform 3.3.0.0
CVE-2017-1373 MEDIUM

Reports executed in the IBM TRIRIGA Application Platform 3.3, 3.4, and 3.5 contains a vulnerability that could allow an authenticated user to execute a report they do not have access to. IBM X-Force ID: 126866.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm tririga_application_platform 3.5.1.3
ibm tririga_application_platform 3.4.1.2
ibm tririga_application_platform 3.4.2.4
ibm tririga_application_platform 3.4.2.0
ibm tririga_application_platform 3.3.2.5
ibm tririga_application_platform 3.5.2.1
ibm tririga_application_platform 3.5.1
ibm tririga_application_platform 3.3.0.1
ibm tririga_application_platform 3.5.0.2
ibm tririga_application_platform 3.3.1.0
ibm tririga_application_platform 3.3.2.1
ibm tririga_application_platform 3.3.0.2
ibm tririga_application_platform 3.3.2.0
ibm tririga_application_platform 3.3.2.2
ibm tririga_application_platform 3.4.2.2
ibm tririga_application_platform 3.3.1.1
ibm tririga_application_platform 3.5.0.0
ibm tririga_application_platform 3.4.2.1
ibm tririga_application_platform 3.4.2.3
ibm tririga_application_platform 3.5.2
ibm tririga_application_platform 3.5.0.1
ibm tririga_application_platform 3.4.1.0
ibm tririga_application_platform 3.4.0.1
ibm tririga_application_platform 3.3.2.4
ibm tririga_application_platform 3.4.1.1
ibm tririga_application_platform 3.3.1.2
ibm tririga_application_platform 3.5.1.1
ibm tririga_application_platform 3.4.2.5
ibm tririga_application_platform 3.4.0.0
ibm tririga_application_platform 3.3.1.3
ibm tririga_application_platform 3.5.1.2
ibm tririga_application_platform 3.5.2.2
ibm tririga_application_platform 3.3.2.3
ibm tririga_application_platform 3.4.1.3
ibm tririga_application_platform 3.3.0.0
CVE-2017-1374 MEDIUM

Sensitive data can be exposed in the IBM TRIRIGA Application Platform 3.3, 3.4, and 3.5 that can lead to an attacker gaining unauthorized access to the system. IBM X-Force ID: 126867.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm tririga_application_platform 3.5.1.3
ibm tririga_application_platform 3.4.1.2
ibm tririga_application_platform 3.4.2.4
ibm tririga_application_platform 3.4.2.0
ibm tririga_application_platform 3.3.2.5
ibm tririga_application_platform 3.5.2.1
ibm tririga_application_platform 3.5.1
ibm tririga_application_platform 3.3.0.1
ibm tririga_application_platform 3.5.0.2
ibm tririga_application_platform 3.3.1.0
ibm tririga_application_platform 3.3.2.1
ibm tririga_application_platform 3.3.0.2
ibm tririga_application_platform 3.3.2.0
ibm tririga_application_platform 3.3.2.2
ibm tririga_application_platform 3.4.2.2
ibm tririga_application_platform 3.3.1.1
ibm tririga_application_platform 3.5.0.0
ibm tririga_application_platform 3.4.2.1
ibm tririga_application_platform 3.4.2.3
ibm tririga_application_platform 3.5.2
ibm tririga_application_platform 3.5.0.1
ibm tririga_application_platform 3.4.1.0
ibm tririga_application_platform 3.4.0.1
ibm tririga_application_platform 3.3.2.4
ibm tririga_application_platform 3.4.1.1
ibm tririga_application_platform 3.3.1.2
ibm tririga_application_platform 3.5.1.1
ibm tririga_application_platform 3.4.2.5
ibm tririga_application_platform 3.4.0.0
ibm tririga_application_platform 3.3.1.3
ibm tririga_application_platform 3.5.1.2
ibm tririga_application_platform 3.5.2.2
ibm tririga_application_platform 3.3.2.3
ibm tririga_application_platform 3.4.1.3
ibm tririga_application_platform 3.3.0.0
CVE-2017-1375 MEDIUM

IBM System Storage Storwize V7000 Unified (V7000U) 1.5 and 1.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 126868.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-326,

Products Affected

Vendor Product Version
ibm storwize_unified_v7000_software 1.5
ibm storwize_unified_v7000_software 1.6
CVE-2017-1376 HIGH

A flaw in the IBM J9 VM class verifier allows untrusted code to disable the security manager and elevate its privileges. IBM X-Force ID: 126873.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-829,

Products Affected

Vendor Product Version
ibm operations_analytics_predictive_insights 1.3.3
ibm operations_analytics_predictive_insights 1.3.0
ibm operations_analytics_predictive_insights 1.3.6
ibm operations_analytics_predictive_insights 1.3.2
ibm operations_analytics_predictive_insights 1.3.5
ibm operations_analytics_predictive_insights 1.3.1
CVE-2017-1377 MEDIUM

IBM Runbook Automation reveals sensitive information in error messages that could be used in further attacks against the system. IBM X-Force ID: 126874.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm runbook_automation -
CVE-2017-1378 LOW

IBM Spectrum Protect 7.1 and 8.1 (formerly Tivoli Storage Manager) disclosed unencrypted login credentials to Vmware vCenter in the application trace output which could be obtained by a local user. IBM X-Force ID: 126875.

CVSS 2.0

Severity: LOW

Problem Type: CWE-522,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager 7.1.3.1
ibm tivoli_storage_manager 6.3.2.2
ibm tivoli_storage_manager 6.3.6
ibm tivoli_storage_manager 6.3.3
ibm tivoli_storage_manager 6.1.1
ibm tivoli_storage_manager 7.1.3
ibm tivoli_storage_manager 7.1.6.5
ibm tivoli_storage_manager 6.1.5
ibm tivoli_storage_manager 6.2.4
ibm tivoli_storage_manager 7.1..5.100
ibm tivoli_storage_manager 7.1.3.2
ibm tivoli_storage_manager 6.2.3
ibm tivoli_storage_manager 7.1.0.3
ibm tivoli_storage_manager 7.1.4.2
ibm tivoli_storage_manager 7.1.4
ibm tivoli_storage_manager 7.1.6
ibm tivoli_storage_manager 7.1.1.1
ibm tivoli_storage_manager 6.4.3
ibm tivoli_storage_manager 7.1.1.100
ibm tivoli_storage_manager 7.1.1
ibm tivoli_storage_manager 6.4.2.600
ibm tivoli_storage_manager 6.3.1.2
ibm tivoli_storage_manager 6.3.0.15
ibm tivoli_storage_manager 6.4.1
ibm tivoli_storage_manager 6.4.2
ibm tivoli_storage_manager 6.1.3
ibm tivoli_storage_manager 7.1.1.300
ibm tivoli_storage_manager 7.1.5.200
ibm tivoli_storage_manager 7.1.3.000
ibm tivoli_storage_manager 6.1
ibm tivoli_storage_manager 6.2.1
ibm tivoli_storage_manager 6.1.0
ibm tivoli_storage_manager 6.3
ibm tivoli_storage_manager 6.4.2.200
ibm tivoli_storage_manager 6.4.2.500
ibm tivoli_storage_manager 7.1.1.2
ibm tivoli_storage_manager 6.3.1
ibm tivoli_storage_manager 6.1.5.5
ibm tivoli_storage_manager 6.1.2
ibm tivoli_storage_manager 7.1.4.1
ibm tivoli_storage_manager 7.1
ibm tivoli_storage_manager 7.1.5
ibm tivoli_storage_manager 6.3.4
ibm tivoli_storage_manager 7.1.0.1
ibm tivoli_storage_manager 7.1.3.100
ibm tivoli_storage_manager 6.4.3.1
ibm tivoli_storage_manager 6.3.5
ibm tivoli_storage_manager 6.3.0.17
ibm tivoli_storage_manager 6.1.5.6
ibm tivoli_storage_manager 8.1.0.2
ibm tivoli_storage_manager 6.4.1.0
ibm tivoli_storage_manager 7.1.1.200
ibm tivoli_storage_manager 8.1.0
ibm tivoli_storage_manager 6.2.0
ibm tivoli_storage_manager 6.3.0.5
ibm tivoli_storage_manager 6.3.6.100
ibm tivoli_storage_manager 7.1.0.2
ibm tivoli_storage_manager 6.4.2.100
ibm tivoli_storage_manager 6.3.5.1
ibm tivoli_storage_manager 6.1.4
ibm tivoli_storage_manager 6.2.2
ibm tivoli_storage_manager 6.1.5.4
CVE-2017-1379 MEDIUM

IBM API Connect 5.0.0.0 could allow a remote attacker to obtain sensitive information, caused by improper handling of requests to the Developer Portal. IBM X-Force ID: 127002.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm api_connect 5.0.2.0
ibm api_connect 5.0.1.0
ibm api_connect 5.0.4.0
ibm api_connect 5.0.6.0
ibm api_connect 5.0.7.0
ibm api_connect 5.0.0.0
ibm api_connect 5.0.0.1
ibm api_connect 5.0.5.0
ibm api_connect 5.0.6.2
ibm api_connect 5.0.7.1
ibm api_connect 5.0.3.0
ibm api_connect 5.0.6.1
CVE-2017-1380 LOW

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 127151.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_application_server *
CVE-2017-1381 LOW

IBM WebSphere Application Server Proxy Server or On-demand-router (ODR) 7.0, 8.0, 8.5, 9.0 and could allow a local attacker to obtain sensitive information, caused by stale data being cached and then served. IBM X-Force ID: 127152.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_application_server *
CVE-2017-1382 LOW

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 might create files using the default permissions instead of the customized permissions when custom startup scripts are used. A local attacker could exploit this to gain access to files with an unknown impact. IBM X-Force ID: 127153.

CVSS 2.0

Severity: LOW

Problem Type: CWE-276,

Products Affected

Vendor Product Version
ibm websphere_application_server *
CVE-2017-1383 MEDIUM

IBM InfoSphere Information Server 9.1, 11.3, and 11.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 127155.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm infosphere_information_server 11.3
ibm infosphere_information_server 11.5
ibm infosphere_information_server 9.1
CVE-2017-1386 MEDIUM

IBM API Connect 5.0.0.0 could allow a user to bypass policy restrictions and create non-compliant passwords which could be intercepted and decrypted using man in the middle techniques. IBM X-Force ID: 127160.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-521,

Products Affected

Vendor Product Version
ibm api_management 4.0.0.1
ibm api_management 4.0.1.0
ibm api_connect 5.0.2.0
ibm api_connect 5.0.1.0
ibm api_connect 5.0.4.0
ibm api_connect 5.0.6.0
ibm api_connect 5.0.7.0
ibm api_management 4.0.2.0
ibm api_management 4.0.4.0
ibm api_management 4.0.4.4
ibm api_management 4.0.3.0
ibm api_management 4.0.4.2
ibm api_management 4.0.4.1
ibm api_connect 5.0.0.0
ibm api_connect 5.0.0.1
ibm api_connect 5.0.5.0
ibm api_connect 5.0.6.2
ibm api_management 4.0.4.3
ibm api_management 4.0.2.1
ibm api_connect 5.0.3.0
ibm api_connect 5.0.6.1
ibm api_management 4.0.4.5
ibm api_management 4.0.0.0
CVE-2017-1395 MEDIUM

IBM Security Identity Governance and Intelligence Virtual Appliance 5.2 through 5.2.3.2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 127341.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_identity_governance_and_intelligence *
CVE-2017-1396 MEDIUM

IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. IBM X-Force ID: 127342.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-275,

Products Affected

Vendor Product Version
ibm security_identity_governance_and_intelligence 5.2
ibm security_identity_governance_and_intelligence 5.2.2
ibm security_identity_governance_and_intelligence 5.2.2.1
ibm security_identity_governance_and_intelligence 5.2.1
ibm security_identity_governance_and_intelligence 5.2.3.1
ibm security_identity_governance_and_intelligence 5.2.3.2
ibm security_identity_governance_and_intelligence 5.2.3
CVE-2017-1398 MEDIUM

IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 6.0, 7.0, and 8.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 127385.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-601,

Products Affected

Vendor Product Version
ibm websphere_commerce 8.0.0.9
ibm websphere_commerce 6.0.0.6
ibm websphere_commerce 8.0.0.6
ibm websphere_commerce 7.0.0.2
ibm websphere_commerce 7.0
ibm websphere_commerce 8.0.0.3
ibm websphere_commerce 8.0.1.12
ibm websphere_commerce 8.0.1.2
ibm websphere_commerce 8.0.0.15
ibm websphere_commerce 8.0.0.13
ibm websphere_commerce 8.0.0.10
ibm websphere_commerce 7.0.0.1
ibm websphere_commerce 6.0.0.5
ibm websphere_commerce 8.0.1.8
ibm websphere_commerce 7.0.0.4
ibm websphere_commerce 6.0.0.1
ibm websphere_commerce 6.0.0.2
ibm websphere_commerce 8.0.1.4
ibm websphere_commerce 8.0.0.0
ibm websphere_commerce 8.0.0.19
ibm websphere_commerce 8.0.1.5
ibm websphere_commerce 8.0.1.9
ibm websphere_commerce 6.0.0.3
ibm websphere_commerce 8.0.0.14
ibm websphere_commerce 8.0.1.7
ibm websphere_commerce 7.0.0.6
ibm websphere_commerce 7.0.0.7
ibm websphere_commerce 6.0.0.11
ibm websphere_commerce 6.0.0.10
ibm websphere_commerce 7.0.0.3
ibm websphere_commerce 8.0.0.4
ibm websphere_commerce 8.0.0.7
ibm websphere_commerce 8.0.1.1
ibm websphere_commerce 6.0.0.7
ibm websphere_commerce 6.0.0.8
ibm websphere_commerce 8.0.0.1
ibm websphere_commerce 7.0.0.5
ibm websphere_commerce 6.0.0.0
ibm websphere_commerce 8.0.1.0
ibm websphere_commerce 7.0.0.8
ibm websphere_commerce 8.0.0.2
ibm websphere_commerce 8.0.0.8
ibm websphere_commerce 7.0.0.9
ibm websphere_commerce 8.0.1.11
ibm websphere_commerce 8.0.0.16
ibm websphere_commerce 8.0.0.11
ibm websphere_commerce 8.0.1.6
ibm websphere_commerce 8.0.0.5
ibm websphere_commerce 6.0.0.4
ibm websphere_commerce 6.0.0.9
ibm websphere_commerce 8.0.1.3
ibm websphere_commerce 8.0.0.12
ibm websphere_commerce 8.0.0.18
ibm websphere_commerce 8.0.0.17
CVE-2017-1405 MEDIUM

IBM Security Identity Manager Virtual Appliance 7.0 processes patches, image backups and other updates without sufficiently verifying the origin and integrity of the code. IBM X-Force ID: 127392.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-345,

Products Affected

Vendor Product Version
ibm security_identity_manager 7.0
ibm security_identity_manager 7.0.1
CVE-2017-1407 HIGH

IBM Security Identity Manager Virtual Appliance 6.0 and 7.0 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 127394.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 2.8 5.9

CVSS 2.0

Severity: HIGH

Problem Type: CWE-77,

Products Affected

Vendor Product Version
ibm security_identity_manager 7.0.0.0
ibm security_privileged_identity_manager 2.0.2
ibm security_privileged_identity_manager 2.0.1
ibm security_identity_governance_and_intelligence 5.2.1
ibm security_identity_manager 6.0.0.0
ibm security_identity_governance_and_intelligence 5.2.0
ibm security_privileged_identity_manager 2.0.0
CVE-2017-1409 MEDIUM

IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 127396.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_identity_governance_and_intelligence 5.2
ibm security_identity_governance_and_intelligence 5.2.2
ibm security_identity_governance_and_intelligence 5.2.2.1
ibm security_identity_governance_and_intelligence 5.2.1
ibm security_identity_governance_and_intelligence 5.2.3.1
ibm security_identity_governance_and_intelligence 5.2.3.2
ibm security_identity_governance_and_intelligence 5.2.3
CVE-2017-1411 MEDIUM

IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 127399.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-522,

Products Affected

Vendor Product Version
ibm security_identity_governance_and_intelligence 5.2
ibm security_identity_governance_and_intelligence 5.2.2
ibm security_identity_governance_and_intelligence 5.2.2.1
ibm security_identity_governance_and_intelligence 5.2.1
ibm security_identity_governance_and_intelligence 5.2.3.1
ibm security_identity_governance_and_intelligence 5.2.3.2
ibm security_identity_governance_and_intelligence 5.2.3
CVE-2017-1412 MEDIUM

IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 127400.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_identity_governance_and_intelligence 5.2
ibm security_identity_governance_and_intelligence 5.2.2
ibm security_identity_governance_and_intelligence 5.2.2.1
ibm security_identity_governance_and_intelligence 5.2.1
ibm security_identity_governance_and_intelligence 5.2.3.1
ibm security_identity_governance_and_intelligence 5.2.3.2
ibm security_identity_governance_and_intelligence 5.2.3
CVE-2017-1418 LOW

IBM Integration Bus 9.0.0.0, 9.0.0.11, 10.0.0.0, and 10.0.0.14 (including IBM WebSphere Message Broker 8.0.0.0 and 8.0.0.9) has insecure permissions on certain files. A local attacker could exploit this vulnerability to modify or delete these files with an unknown impact. IBM X-Force ID: 127406.

CVSS 2.0

Severity: LOW

Problem Type: CWE-275,

Products Affected

Vendor Product Version
ibm websphere_message_broker *
ibm integration_bus *
CVE-2017-1421 MEDIUM

IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm inotes 8.5.2.1
ibm inotes 9.0.1.1
ibm inotes 9.0.1.8
ibm inotes 9.0
ibm inotes 8.5.3.6
ibm inotes 8.5.1.1
ibm inotes 8.5.1.5
ibm inotes 8.5.3
ibm inotes 9.0.1
ibm inotes 8.5.3.1
ibm inotes 8.5.1
ibm inotes 8.5.2.4
ibm inotes 8.5
ibm inotes 8.5.2
CVE-2017-1422 LOW

IBM MaaS360 DTM all versions up to 3.81 does not perform proper verification for user rights of certain applications which could disclose sensitive information. IBM X-Force ID: 127412.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm maas360_dtm *
CVE-2017-1423 MEDIUM

IBM WebSphere Portal 8.5 and 9.0 exposes backend server URLs that are configured for usage by the Web Application Bridge component. IBM X-Force ID: 127476.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_portal 8.5.0.0
ibm websphere_portal 9.0.0.0
CVE-2017-1424 LOW

IBM Business Process Manager 8.5.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 127477.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm business_process_manager 8.5.7.0
CVE-2017-1425 LOW

IBM Business Process Manager 8.0.1.1 and 8.5.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 127478.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm business_process_manager 8.0.1.1
ibm business_process_manager 8.5.7.0
CVE-2017-1427 MEDIUM

IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 127579.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm cognos_analytics 11.0.5
ibm cognos_analytics 11.0.6
ibm cognos_analytics 11.0.1
ibm cognos_analytics 11.0.3
ibm cognos_analytics 11.0.2
ibm cognos_analytics 11.0.0
ibm cognos_analytics 11.0.4
CVE-2017-1428 MEDIUM

IBM Cognos Analytics 11.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 127583.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm cognos_analytics 11.0.5
ibm cognos_analytics 11.0.6
ibm cognos_analytics 11.0.1
ibm cognos_analytics 11.0.3
ibm cognos_analytics 11.0.2
ibm cognos_analytics 11.0.0
ibm cognos_analytics 11.0.4
CVE-2017-1429 LOW

IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 127587.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_engineering_lifecycle_manager 5.0.1
ibm rational_engineering_lifecycle_manager 6.0.2
ibm rational_engineering_lifecycle_manager 4.0.3
ibm rational_engineering_lifecycle_manager 4.0.4
ibm rational_engineering_lifecycle_manager 4.0.5
ibm rational_engineering_lifecycle_manager 4.0.7
ibm rational_engineering_lifecycle_manager 6.0.0
ibm rational_engineering_lifecycle_manager 6.0.1
ibm rational_engineering_lifecycle_manager 4.0.6
ibm rational_engineering_lifecycle_manager 5.0.0
ibm rational_engineering_lifecycle_manager 6.0.4
ibm rational_engineering_lifecycle_manager 6.0.3
ibm rational_engineering_lifecycle_manager 5.0.2
CVE-2017-1431 LOW

IBM InfoSphere Streams 4.0, 4.1, and 4.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 127632.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm infosphere_streams 4.1
ibm infosphere_streams 4.0
ibm infosphere_streams 4.0.1
ibm infosphere_streams 4.2.1
ibm infosphere_streams 4.1.1
ibm infosphere_streams 4.2
CVE-2017-1433 MEDIUM

IBM WebSphere MQ 7.5, 8.0, and 9.0 could allow an authenticated user to insert messages with a corrupt RFH header into the channel which would cause it to restart. IBM X-Force ID: 127803.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_mq 9.0
ibm websphere_mq 7.5.0.4
ibm websphere_mq 7.5.0.1
ibm websphere_mq 8.0.0.3
ibm websphere_mq 8.0.0.4
ibm websphere_mq 7.5.0.7
ibm websphere_mq 9.0.0.1
ibm websphere_mq 7.5
ibm websphere_mq 8.0.0.7
ibm websphere_mq 8.0.0.2
ibm websphere_mq 7.5.0.2
ibm websphere_mq 8.0.0.6
ibm websphere_mq 8.0.0.5
ibm websphere_mq 8.0.0.1
ibm websphere_mq 7.5.0.3
ibm websphere_mq 7.5.0.5
ibm websphere_mq 7.5.0.8
ibm websphere_mq 8.0
ibm websphere_mq 7.5.0.6
CVE-2017-1434 LOW

IBM DB2 for Linux, UNIX and Windows 11.1 (includes DB2 Connect Server) under unusual circumstances, could expose highly sensitive information in the error log to a local user.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm db2_connect 11.1.0.0
ibm db2 11.1.0.0
CVE-2017-1438 HIGH

IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user with DB2 instance owner privileges to obtain root access. IBM X-Force ID: 128057.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm db2_connect 10.1
ibm db2_connect 9.7.0.11
ibm db2 10.1.0.1
ibm db2_connect 10.1.0.3
ibm db2_connect 9.7.0.8
ibm db2 11.1.0.0
ibm db2_connect 9.7.0.6
ibm db2 10.5.0.1
ibm db2 10.5.0.2
ibm db2 9.7.0.2
ibm db2 9.7.0.1
ibm db2_connect 10.5.0.5
ibm db2 10.1.0.5
ibm db2_connect 9.7
ibm db2_connect 11.1.0.0
ibm db2 10.5.0.4
ibm db2 10.1.0.3
ibm db2_connect 10.1.0.5
ibm db2 10.5.0.7
ibm db2 9.7.0.7
ibm db2_connect 10.1.0.4
ibm db2 9.7
ibm db2 9.7.0.3
ibm db2 10.5.0.3
ibm db2 9.7.0.11
ibm db2_connect 9.7.0.4
ibm db2_connect 10.1.0.2
ibm db2_connect 10.5.0.3
ibm db2_connect 9.7.0.9
ibm db2 10.5
ibm db2 9.7.0.9
ibm db2_connect 9.7.0.5
ibm db2_connect 10.5.0.2
ibm db2 9.7.0.5
ibm db2_connect 10.5.0.4
ibm db2 9.7.0.6
ibm db2 9.7.0.10
ibm db2 9.7.0.8
ibm db2 10.1.0.4
ibm db2 10.1
ibm db2_connect 9.7.0.10
ibm db2_connect 10.1.0.1
ibm db2_connect 10.5.0.6
ibm db2_connect 9.7.0.7
ibm db2 10.1.0.2
ibm db2_connect 9.7.0.3
ibm db2 9.7.0.4
ibm db2 10.5.0.5
ibm db2_connect 10.5.0.7
ibm db2_connect 10.5.0.1
ibm db2 10.5.0.6
ibm db2_connect 10.5
ibm db2_connect 9.7.0.1
ibm db2_connect 9.7.0.2
CVE-2017-1439 HIGH

IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user with DB2 instance owner privileges to obtain root access. IBM X-Force ID: 128058.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm db2_connect 10.1
ibm db2_connect 9.7.0.11
ibm db2 10.1.0.1
ibm db2_connect 10.1.0.3
ibm db2_connect 9.7.0.8
ibm db2 11.1.0.0
ibm db2_connect 9.7.0.6
ibm db2 10.5.0.1
ibm db2 10.5.0.2
ibm db2 9.7.0.2
ibm db2 9.7.0.1
ibm db2_connect 10.5.0.5
ibm db2 10.1.0.5
ibm db2_connect 9.7
ibm db2_connect 11.1.0.0
ibm db2 10.5.0.4
ibm db2 10.1.0.3
ibm db2_connect 10.1.0.5
ibm db2 10.5.0.7
ibm db2 9.7.0.7
ibm db2_connect 10.1.0.4
ibm db2 9.7
ibm db2 9.7.0.3
ibm db2 10.5.0.3
ibm db2 9.7.0.11
ibm db2_connect 9.7.0.4
ibm db2_connect 10.1.0.2
ibm db2_connect 10.5.0.3
ibm db2_connect 9.7.0.9
ibm db2 10.5
ibm db2 9.7.0.9
ibm db2_connect 9.7.0.5
ibm db2_connect 10.5.0.2
ibm db2 9.7.0.5
ibm db2_connect 10.5.0.4
ibm db2 9.7.0.6
ibm db2 9.7.0.10
ibm db2 9.7.0.8
ibm db2 10.1.0.4
ibm db2 10.1
ibm db2_connect 9.7.0.10
ibm db2_connect 10.1.0.1
ibm db2_connect 10.5.0.6
ibm db2_connect 9.7.0.7
ibm db2 10.1.0.2
ibm db2_connect 9.7.0.3
ibm db2 9.7.0.4
ibm db2 10.5.0.5
ibm db2_connect 10.5.0.7
ibm db2_connect 10.5.0.1
ibm db2 10.5.0.6
ibm db2_connect 10.5
ibm db2_connect 9.7.0.1
ibm db2_connect 9.7.0.2
CVE-2017-1440 MEDIUM

IBM Emptoris Services Procurement 10.0.0.5 could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-crafted URL to specify a malicious file from a remote system, which could allow the attacker to execute arbitrary code on the vulnerable Web server. IBM X-Force ID: 128105.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-94,

Products Affected

Vendor Product Version
ibm emptoris_services_procurement 10.0.0.4
ibm emptoris_services_procurement 10.0.0.3
ibm emptoris_services_procurement 10.0.0.1
ibm emptoris_services_procurement 10.0.0.2
ibm emptoris_services_procurement 10.0.0.5
ibm emptoris_services_procurement 10.1.1.0
ibm emptoris_services_procurement 10.0.0.0
CVE-2017-1441 LOW

IBM Emptoris Services Procurement 10.0.0.5 could allow a local user to view sensitive information stored locally due to improper access control. IBM X-Force ID: 128106.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm emptoris_services_procurement 10.0.0.4
ibm emptoris_services_procurement 10.0.0.3
ibm emptoris_services_procurement 10.0.0.1
ibm emptoris_services_procurement 10.0.0.2
ibm emptoris_services_procurement 10.0.0.5
ibm emptoris_services_procurement 10.1.1.0
ibm emptoris_services_procurement 10.0.0.0
CVE-2017-1442 MEDIUM

IBM Emptoris Services Procurement 10.0.0.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 128107.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm emptoris_services_procurement 10.0.0.4
ibm emptoris_services_procurement 10.0.0.3
ibm emptoris_services_procurement 10.0.0.1
ibm emptoris_services_procurement 10.0.0.2
ibm emptoris_services_procurement 10.0.0.5
ibm emptoris_services_procurement 10.1.1.0
ibm emptoris_services_procurement 10.0.0.0
CVE-2017-1443 MEDIUM

IBM Emptoris Services Procurement 10.0.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128109.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm emptoris_services_procurement 10.0.0.4
ibm emptoris_services_procurement 10.0.0.3
ibm emptoris_services_procurement 10.0.0.1
ibm emptoris_services_procurement 10.0.0.2
ibm emptoris_services_procurement 10.0.0.5
ibm emptoris_services_procurement 10.1.1.0
ibm emptoris_services_procurement 10.0.0.0
CVE-2017-1444 LOW

IBM Emptoris Sourcing 9.5 - 10.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128110.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm emptoris_sourcing 10.0.1
ibm emptoris_sourcing 9.5.1.1
ibm emptoris_sourcing 10.0.2
ibm emptoris_sourcing 9.5
ibm emptoris_sourcing 10.0.0
ibm emptoris_sourcing 9.5.1.0
ibm emptoris_sourcing 9.5.0.2
ibm emptoris_sourcing 9.5.1.2
ibm emptoris_sourcing 10.0.4
ibm emptoris_sourcing 10.1.0
ibm emptoris_sourcing 10.1.1
ibm emptoris_sourcing 9.5.1.3
ibm emptoris_sourcing 10.1.3
ibm emptoris_sourcing 9.5.0.1
CVE-2017-1445 LOW

IBM Emptoris Spend Analysis 9.5.0.0 through 10.1.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128170.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm emptoris_spend_analysis 9.5.0.3
ibm emptoris_spend_analysis 10.0.2
ibm emptoris_spend_analysis 10.0.0.0
ibm emptoris_spend_analysis 10.1.1
ibm emptoris_spend_analysis 9.5.0.4
ibm emptoris_spend_analysis 10.0.4
ibm emptoris_spend_analysis 9.5.0.0
ibm emptoris_spend_analysis 10.0.1.0
ibm emptoris_spend_analysis 10.0.1
ibm emptoris_spend_analysis 9.5.0.2
ibm emptoris_spend_analysis 10.0.0.1
ibm emptoris_spend_analysis 9.5.0.1
CVE-2017-1446 LOW

IBM Emptoris Spend Analysis 9.5.0.0 through 10.1.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128171.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 5.4 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N 2.3 2.7

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm emptoris_spend_analysis 9.5.0.4
ibm emptoris_spend_analysis 9.5.0.0
ibm emptoris_spend_analysis 10.0.2.0
ibm emptoris_spend_analysis 10.0.1.0
ibm emptoris_spend_analysis 10.1.1.0
ibm emptoris_spend_analysis 9.5.0.3
ibm emptoris_spend_analysis 9.5.0.2
ibm emptoris_spend_analysis 10.0.0.0
ibm emptoris_spend_analysis 10.0.0.1
ibm emptoris_spend_analysis 10.0.4.0
ibm emptoris_spend_analysis 9.5.0.1
CVE-2017-1447 LOW

IBM Emptoris Sourcing 9.5 - 10.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128172.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm emptoris_sourcing 10.0.1
ibm emptoris_sourcing 9.5.1.1
ibm emptoris_sourcing 10.0.2
ibm emptoris_sourcing 9.5
ibm emptoris_sourcing 10.0.0
ibm emptoris_sourcing 9.5.1.0
ibm emptoris_sourcing 9.5.0.2
ibm emptoris_sourcing 9.5.1.2
ibm emptoris_sourcing 10.0.4
ibm emptoris_sourcing 10.1.0
ibm emptoris_sourcing 10.1.1
ibm emptoris_sourcing 9.5.1.3
ibm emptoris_sourcing 10.1.3
ibm emptoris_sourcing 9.5.0.1
CVE-2017-1448 MEDIUM

IBM Emptoris Supplier Lifecycle Management 10.0.x and 10.1.x could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 128173.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-601,

Products Affected

Vendor Product Version
ibm emptoris_strategic_supply_management 10.0.2.5
ibm emptoris_strategic_supply_management 10.0.0.0
ibm emptoris_strategic_supply_management 10.1.0.1
ibm emptoris_strategic_supply_management 10.1.1.1
ibm emptoris_strategic_supply_management 10.0.2.9
ibm emptoris_strategic_supply_management 10.1.1.9
ibm emptoris_strategic_supply_management 10.0.2.4
ibm emptoris_strategic_supply_management 10.1.0.3
ibm emptoris_strategic_supply_management 10.1.1.3
ibm emptoris_strategic_supply_management 10.0.2.6
ibm emptoris_strategic_supply_management 10.1.1.0
ibm emptoris_supplier_lifecycle_management 10.0.0.2
ibm emptoris_strategic_supply_management 10.0.1.2
ibm emptoris_supplier_lifecycle_management 10.0.1.0
ibm emptoris_strategic_supply_management 10.0.1.4
ibm emptoris_strategic_supply_management 10.1.1.6
ibm emptoris_strategic_supply_management 10.1.1.7
ibm emptoris_strategic_supply_management 10.0.2.11
ibm emptoris_strategic_supply_management 10.0.2.3
ibm emptoris_supplier_lifecycle_management 10.0.2.0
ibm emptoris_strategic_supply_management 10.0.2.8
ibm emptoris_strategic_supply_management 10.0.2.13
ibm emptoris_supplier_lifecycle_management 10.0.0.3
ibm emptoris_strategic_supply_management 10.0.2.14
ibm emptoris_strategic_supply_management 10.0.2.15
ibm emptoris_supplier_lifecycle_management 10.0.1.2
ibm emptoris_strategic_supply_management 10.1.0.9
ibm emptoris_strategic_supply_management 10.0.0.2
ibm emptoris_strategic_supply_management 10.0.4.0
ibm emptoris_strategic_supply_management 10.1.0.4
ibm emptoris_supplier_lifecycle_management 10.0.2.2
ibm emptoris_strategic_supply_management 10.1.0.7
ibm emptoris_strategic_supply_management 10.1.0.10
ibm emptoris_strategic_supply_management 10.0.2.17
ibm emptoris_strategic_supply_management 10.1.1.2
ibm emptoris_strategic_supply_management 10.0.2.10
ibm emptoris_strategic_supply_management 10.1.0.6
ibm emptoris_strategic_supply_management 10.0.1.1
ibm emptoris_strategic_supply_management 10.0.2.16
ibm emptoris_strategic_supply_management 10.1.1.10
ibm emptoris_supplier_lifecycle_management 10.0.0.1
ibm emptoris_strategic_supply_management 10.0.2.0
ibm emptoris_strategic_supply_management 10.0.2.2
ibm emptoris_strategic_supply_management 10.1.0.8
ibm emptoris_strategic_supply_management 10.1.1.5
ibm emptoris_strategic_supply_management 10.0.1.3
ibm emptoris_strategic_supply_management 10.1.0.2
ibm emptoris_supplier_lifecycle_management 10.0.2.3
ibm emptoris_strategic_supply_management 10.0.0.3
ibm emptoris_supplier_lifecycle_management 10.0.2.7
ibm emptoris_strategic_supply_management 10.0.0.1
ibm emptoris_supplier_lifecycle_management 10.0.1.1
ibm emptoris_strategic_supply_management 10.1.0.5
ibm emptoris_strategic_supply_management 10.1.0.11
ibm emptoris_strategic_supply_management 10.0.1.0
ibm emptoris_strategic_supply_management 10.1.1.8
ibm emptoris_strategic_supply_management 10.0.2.1
ibm emptoris_supplier_lifecycle_management 10.0.0.0
ibm emptoris_strategic_supply_management 10.0.2.7
ibm emptoris_strategic_supply_management 10.1.0.0
ibm emptoris_strategic_supply_management 10.0.2.12
ibm emptoris_supplier_lifecycle_management 10.0.2.6
ibm emptoris_supplier_lifecycle_management 10.0.2.5
ibm emptoris_strategic_supply_management 10.1.1.4
CVE-2017-1449 MEDIUM

IBM Emptoris Sourcing 9.5 - 10.1.3 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 128174.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-601,

Products Affected

Vendor Product Version
ibm emptoris_sourcing 10.0.1
ibm emptoris_sourcing 9.5.1.1
ibm emptoris_sourcing 10.0.2
ibm emptoris_sourcing 9.5
ibm emptoris_sourcing 10.0.0
ibm emptoris_sourcing 9.5.1.0
ibm emptoris_sourcing 9.5.0.2
ibm emptoris_sourcing 9.5.1.2
ibm emptoris_sourcing 10.0.4
ibm emptoris_sourcing 10.1.0
ibm emptoris_sourcing 10.1.1
ibm emptoris_sourcing 9.5.1.3
ibm emptoris_sourcing 10.1.3
ibm emptoris_sourcing 9.5.0.1
CVE-2017-1450 MEDIUM

IBM Emptoris Sourcing 9.5 - 10.1.3 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 128177.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-601,

Products Affected

Vendor Product Version
ibm emptoris_sourcing 10.0.1
ibm emptoris_sourcing 9.5.1.1
ibm emptoris_sourcing 10.0.2
ibm emptoris_sourcing 9.5
ibm emptoris_sourcing 10.0.0
ibm emptoris_sourcing 9.5.1.0
ibm emptoris_sourcing 9.5.0.2
ibm emptoris_sourcing 9.5.1.2
ibm emptoris_sourcing 10.0.4
ibm emptoris_sourcing 10.1.0
ibm emptoris_sourcing 10.1.1
ibm emptoris_sourcing 9.5.1.3
ibm emptoris_sourcing 10.1.3
ibm emptoris_sourcing 9.5.0.1
CVE-2017-1451 HIGH

IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user with DB2 instance owner privileges to obtain root access. IBM X-Force ID: 128178.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm db2_connect 10.1
ibm db2_connect 9.7.0.11
ibm db2 10.1.0.1
ibm db2_connect 10.1.0.3
ibm db2_connect 9.7.0.8
ibm db2 11.1.0.0
ibm db2_connect 9.7.0.6
ibm db2 10.5.0.1
ibm db2 10.5.0.2
ibm db2 9.7.0.2
ibm db2 9.7.0.1
ibm db2_connect 10.5.0.5
ibm db2 10.1.0.5
ibm db2_connect 9.7
ibm db2_connect 11.1.0.0
ibm db2 10.5.0.4
ibm db2 10.1.0.3
ibm db2_connect 10.1.0.5
ibm db2 10.5.0.7
ibm db2 9.7.0.7
ibm db2_connect 10.1.0.4
ibm db2 9.7
ibm db2 9.7.0.3
ibm db2 10.5.0.3
ibm db2 9.7.0.11
ibm db2_connect 9.7.0.4
ibm db2_connect 10.1.0.2
ibm db2_connect 10.5.0.3
ibm db2_connect 9.7.0.9
ibm db2 10.5
ibm db2 9.7.0.9
ibm db2_connect 9.7.0.5
ibm db2_connect 10.5.0.2
ibm db2 9.7.0.5
ibm db2_connect 10.5.0.4
ibm db2 9.7.0.6
ibm db2 9.7.0.10
ibm db2 9.7.0.8
ibm db2 10.1.0.4
ibm db2 10.1
ibm db2_connect 9.7.0.10
ibm db2_connect 10.1.0.1
ibm db2_connect 10.5.0.6
ibm db2_connect 9.7.0.7
ibm db2 10.1.0.2
ibm db2_connect 9.7.0.3
ibm db2 9.7.0.4
ibm db2 10.5.0.5
ibm db2_connect 10.5.0.7
ibm db2_connect 10.5.0.1
ibm db2 10.5.0.6
ibm db2_connect 10.5
ibm db2_connect 9.7.0.1
ibm db2_connect 9.7.0.2
CVE-2017-1452 HIGH

IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user to obtain elevated privilege and overwrite DB2 files. IBM X-Force ID: 128180.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm db2_connect 10.1
ibm db2_connect 9.7.0.11
ibm db2 10.1.0.1
ibm db2_connect 10.1.0.3
ibm db2_connect 9.7.0.8
ibm db2 11.1.0.0
ibm db2_connect 9.7.0.6
ibm db2 10.5.0.1
ibm db2 10.5.0.2
ibm db2 9.7.0.2
ibm db2 9.7.0.1
ibm db2_connect 10.5.0.5
ibm db2 10.1.0.5
ibm db2_connect 9.7
ibm db2_connect 11.1.0.0
ibm db2 10.5.0.4
ibm db2 10.1.0.3
ibm db2_connect 10.1.0.5
ibm db2 10.5.0.7
ibm db2 9.7.0.7
ibm db2_connect 10.1.0.4
ibm db2 9.7
ibm db2 9.7.0.3
ibm db2 10.5.0.3
ibm db2 9.7.0.11
ibm db2_connect 9.7.0.4
ibm db2_connect 10.1.0.2
ibm db2_connect 10.5.0.3
ibm db2_connect 9.7.0.9
ibm db2 10.5
ibm db2 9.7.0.9
ibm db2_connect 9.7.0.5
ibm db2_connect 10.5.0.2
ibm db2 9.7.0.5
ibm db2_connect 10.5.0.4
ibm db2 9.7.0.6
ibm db2 9.7.0.10
ibm db2 9.7.0.8
ibm db2 10.1.0.4
ibm db2 10.1
ibm db2_connect 9.7.0.10
ibm db2_connect 10.1.0.1
ibm db2_connect 10.5.0.6
ibm db2_connect 9.7.0.7
ibm db2 10.1.0.2
ibm db2_connect 9.7.0.3
ibm db2 9.7.0.4
ibm db2 10.5.0.5
ibm db2_connect 10.5.0.7
ibm db2_connect 10.5.0.1
ibm db2 10.5.0.6
ibm db2_connect 10.5
ibm db2_connect 9.7.0.1
ibm db2_connect 9.7.0.2
CVE-2017-1453 HIGH

IBM Security Access Manager Appliance 9.0.3 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 128372.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-78,

Products Affected

Vendor Product Version
ibm security_access_manager_9.0_firmware 9.0.3.0
CVE-2017-1457 MEDIUM

IBM QRadar Network Security 5.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128376.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm qradar_network_security 5.4
CVE-2017-1458 MEDIUM

IBM QRadar Network Security 5.4 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 128377.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm qradar_network_security 5.4
CVE-2017-1459 MEDIUM

IBM Security Access Manager Appliance 8.0.0 and 9.0.0 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. IBM X-Force ID: 128378.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-732,

Products Affected

Vendor Product Version
ibm security_access_manager_for_mobile *
ibm security_access_manager_for_web_8.0_firmware *
ibm security_access_manager_9.0_firmware *
CVE-2017-1460 MEDIUM

IBM i OSPF 6.1, 7.1, 7.2, and 7.3 is vulnerable when a rogue router spoofs its origin. Routing tables are affected by a missing LSA, which may lead to loss of connectivity. IBM X-Force ID: 128379.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm i 7.1
ibm i 7.2
ibm i 6.1
ibm i 7.3
CVE-2017-1461 LOW

IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128460.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_doors_next_generation *
CVE-2017-1462 LOW

IBM Rhapsody DM 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128461.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_rhapsody_design_manager 5.0.1
ibm rational_rhapsody_design_manager 5.0.0
ibm rational_rhapsody_design_manager 6.0.1
ibm rational_rhapsody_design_manager 6.0.2
ibm rational_rhapsody_design_manager 6.0.3
ibm rational_rhapsody_design_manager 6.0.4
ibm rational_rhapsody_design_manager 5.0.2
ibm rational_rhapsody_design_manager 6.0.0
CVE-2017-1465 LOW

IBM TRIRIGA 3.2, 3.3, 3.4, and 3.5 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 128464.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm tririga_application_platform 3.5.2.3
ibm tririga_application_platform 3.5.1.3
ibm tririga_application_platform 3.4.1.2
ibm tririga_application_platform 3.4.2.4
ibm tririga_application_platform 3.4.2.0
ibm tririga_application_platform 3.3.2.5
ibm tririga_application_platform 3.5.2.1
ibm tririga_application_platform 3.5.1
ibm tririga_application_platform 3.3.0.1
ibm tririga_application_platform 3.5.3
ibm tririga_application_platform 3.5.0.2
ibm tririga_application_platform 3.3.1.0
ibm tririga_application_platform 3.3.2.1
ibm tririga_application_platform 3.3.0.2
ibm tririga_application_platform 3.3.2.0
ibm tririga_application_platform 3.3.2.2
ibm tririga_application_platform 3.4.2.2
ibm tririga_application_platform 3.3.1.1
ibm tririga_application_platform 3.5.0.0
ibm tririga_application_platform 3.4.2.1
ibm tririga_application_platform 3.4.2.3
ibm tririga_application_platform 3.5.2
ibm tririga_application_platform 3.5.0.1
ibm tririga_application_platform 3.4.1.0
ibm tririga_application_platform 3.4.0.1
ibm tririga_application_platform 3.3.2.4
ibm tririga_application_platform 3.4.1.1
ibm tririga_application_platform 3.3.1.2
ibm tririga_application_platform 3.5.1.1
ibm tririga_application_platform 3.4.2.5
ibm tririga_application_platform 3.4.0.0
ibm tririga_application_platform 3.3.1.3
ibm tririga_application_platform 3.5.1.2
ibm tririga_application_platform 3.5.2.2
ibm tririga_application_platform 3.3.2.3
ibm tririga_application_platform 3.4.1.3
ibm tririga_application_platform 3.3.0.0
CVE-2017-1467 MEDIUM

A network layer security vulnerability in InfoSphere Information Server 9.1, 11.3, and 11.5 can lead to privilege escalation or unauthorized access. IBM X-Force ID: 128466.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm infosphere_information_server 11.3
ibm infosphere_information_server 11.5
ibm infosphere_information_server 9.1
CVE-2017-1468 MEDIUM

IBM InfoSphere Information Server 9.1, 11.3, and 11.5 could allow a local user to gain elevated privileges by placing arbitrary files in installation directories. IBM X-force ID: 128467.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm infosphere_information_server 11.3
ibm infosphere_information_server 11.5
ibm infosphere_information_server 9.1
CVE-2017-1469 MEDIUM

IBM InfoSphere Information Server 9.1, 11.3, and 11.5 could allow a local user to gain elevated privileges by placing arbitrary files in installation directories. IBM X-Force ID: 128468.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-94,

Products Affected

Vendor Product Version
ibm infosphere_information_server 11.3
ibm infosphere_information_server 11.5
ibm infosphere_information_server 9.1
CVE-2017-1473 MEDIUM

IBM Security Access Manager Appliance 8.0.0 through 8.0.1.6 and 9.0.0 through 9.0.3.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 128605.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-326,

Products Affected

Vendor Product Version
ibm security_access_manager_for_mobile 8.0.1
ibm security_access_manager_for_mobile 8.0.0.2
ibm security_access_manager_for_web_firmware 8.0.1.3
ibm security_access_manager_for_web_firmware 8.0.1.6
ibm security_access_manager_for_mobile 8.0.1.4
ibm security_access_manager_firmware 9.0.2.0
ibm security_access_manager_for_web_firmware 8.0.0.3
ibm security_access_manager_for_web_firmware 8.0.1.2
ibm security_access_manager_for_web_firmware 8.0.1.4
ibm security_access_manager_firmware 9.0.0
ibm security_access_manager_for_mobile 8.0.0.3
ibm security_access_manager_for_web_firmware 8.0.0.2
ibm security_access_manager_firmware 9.0.2.1
ibm security_access_manager_firmware 9.0.3.1
ibm security_access_manager_for_mobile 8.0.1.2
ibm security_access_manager_for_web_firmware 8.0.0
ibm security_access_manager_for_web_firmware 8.0.0.5
ibm security_access_manager_for_mobile 8.0.0.5
ibm security_access_manager_firmware 9.0.3
ibm security_access_manager_for_web_firmware 8.0.0.4
ibm security_access_manager_for_mobile 8.0.0
ibm security_access_manager_for_web_firmware 8.0.1.5
ibm security_access_manager_firmware 9.0.0.1
ibm security_access_manager_for_mobile 8.0.0.4
ibm security_access_manager_for_web_firmware 8.0.1
ibm security_access_manager_for_mobile 8.0.0.1
ibm security_access_manager_for_mobile 8.0.1.3
ibm security_access_manager_for_web_firmware 8.0.0.1
ibm security_access_manager_for_mobile 8.0.1.6
ibm security_access_manager_for_mobile 8.0.1.5
ibm security_access_manager_firmware 9.0.1.0
CVE-2017-1474 MEDIUM

IBM Security Access Manager Appliance 7.0.0, 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 128606.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_access_manager_for_mobile *
ibm security_access_manager *
ibm security_access_manager_for_web *
CVE-2017-1476 MEDIUM

IBM Security Access Manager Appliance 7.0.0, 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 128610.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_access_manager_for_mobile *
ibm security_access_manager *
ibm security_access_manager_for_web *
CVE-2017-1477 MEDIUM

IBM Security Access Manager Appliance 9.0.3 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 128612.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm security_access_manager_9.0_firmware 9.0.3.0
CVE-2017-1478 LOW

IBM Security Access Manager Appliance 9.0.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 128613.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_access_manager_9.0_firmware 9.0.0
ibm security_access_manager_9.0_firmware 9.0.0.1
ibm security_access_manager_9.0_firmware 9.0.3
ibm security_access_manager_9.0_firmware 9.0.2.0
ibm security_access_manager_9.0_firmware 9.0.1.0
ibm security_access_manager_9.0_firmware 9.0.3.1
ibm security_access_manager_9.0_firmware 9.0.2.1
CVE-2017-1480 MEDIUM

IBM Security Access Manager Appliance 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 stores potentially sensitive information in log files that could be read by a remote user. IBM X-Force ID: 128617.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-532,

Products Affected

Vendor Product Version
ibm security_access_manager_for_mobile *
ibm security_access_manager *
ibm security_access_manager_for_web *
CVE-2017-1481 MEDIUM

IBM Sterling B2B Integrator Standard Edition 5.2 allows a user to view sensitive information that belongs to another user. IBM X-Force ID: 128619.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2
CVE-2017-1482 LOW

IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128620.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2
CVE-2017-1483 HIGH

IBM Security Identity Manager Adapters 6.0 and 7.0 does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. IBM X-Force ID: 128621.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-306,

Products Affected

Vendor Product Version
ibm security_identity_governance_and_intelligence 5.2
ibm security_identity_manager 7.0.0.0
ibm security_privileged_identity_manager 2.0.2
ibm security_privileged_identity_manager 2.0.1
ibm security_identity_governance_and_intelligence 5.2.1
ibm security_identity_manager 6.0.0.0
ibm security_privileged_identity_manager 2.0
CVE-2017-1484 MEDIUM

IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 7.0 and 8.0 could allow an authenticated attacker to obtain information such as user personal data. IBM X-Force ID: 128622.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_commerce 8.0.0.9
ibm websphere_commerce 8.0.4.6
ibm websphere_commerce 8.0.4.0
ibm websphere_commerce 8.0.0.6
ibm websphere_commerce 7.0
ibm websphere_commerce 8.0.0.3
ibm websphere_commerce 8.0.1.12
ibm websphere_commerce 8.0.4.7
ibm websphere_commerce 8.0.1.2
ibm websphere_commerce 8.0.3.3
ibm websphere_commerce 8.0.0.15
ibm websphere_commerce 8.0.0.13
ibm websphere_commerce 8.0.0.10
ibm websphere_commerce 8.0.1.8
ibm websphere_commerce 8.0.4.3
ibm websphere_commerce 8.0.3.1
ibm websphere_commerce 8.0.1.4
ibm websphere_commerce 8.0.0.0
ibm websphere_commerce 8.0.0.19
ibm websphere_commerce 8.0.3.4
ibm websphere_commerce 8.0.1.5
ibm websphere_commerce 8.0.1.9
ibm websphere_commerce 8.0.4.2
ibm websphere_commerce 8.0.0.14
ibm websphere_commerce 8.0.4.1
ibm websphere_commerce 8.0.4.8
ibm websphere_commerce 8.0.1.7
ibm websphere_commerce 8.0.4.4
ibm websphere_commerce 8.0.0.4
ibm websphere_commerce 8.0.0.7
ibm websphere_commerce 8.0.1.1
ibm websphere_commerce 8.0.0.1
ibm websphere_commerce 8.0.1.10
ibm websphere_commerce 8.0.3.2
ibm websphere_commerce 8.0.1.0
ibm websphere_commerce 8.0.0.2
ibm websphere_commerce 8.0.0.8
ibm websphere_commerce 8.0.4.5
ibm websphere_commerce 8.0.1.11
ibm websphere_commerce 8.0.3.0
ibm websphere_commerce 8.0.0.16
ibm websphere_commerce 8.0.0.11
ibm websphere_commerce 8.0.1.13
ibm websphere_commerce 8.0.1.6
ibm websphere_commerce 8.0.0.5
ibm websphere_commerce 8.0.1.3
ibm websphere_commerce 8.0.0.12
ibm websphere_commerce 8.0.0.18
ibm websphere_commerce 8.0.0.17
CVE-2017-1485 LOW

IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128623.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm cognos_analytics 11.0.5
ibm cognos_analytics 11.0.6
ibm cognos_analytics 11.0.1
ibm cognos_analytics 11.0.3
ibm cognos_analytics 11.0.2
ibm cognos_analytics 11.0.0
ibm cognos_analytics 11.0.4
CVE-2017-1486 MEDIUM

IBM Cognos Business Intelligence 10.2, 10.2.1, 10.2.1.1, and 10.2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128624.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm cognos_business_intelligence 10.2.1
ibm cognos_business_intelligence 10.2
ibm cognos_business_intelligence 10.2.1.1
ibm cognos_business_intelligence 10.2.2
CVE-2017-1487 MEDIUM

IBM Sterling File Gateway 2.2 could allow an authenticated attacker to obtain sensitive information such as login ids on the system. IBM X-Force ID: 128626.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm sterling_file_gateway 2.2
CVE-2017-1488 MEDIUM

An undisclosed vulnerability in Jazz common products exists with potential for information disclosure. IBM X-Force ID: 128627.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
ibm rational_engineering_lifecycle_manager *
ibm rational_engineering_lifecycle_manager 5.0.1
ibm rational_rhapsody_design_manager 5.0.1
ibm rational_software_architect_design_manager 6.0.0
ibm rational_software_architect_design_manager 5.0.1
ibm rational_software_architect_design_manager 6.0.1
ibm rational_rhapsody_design_manager *
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_collaborative_lifecycle_management *
ibm rational_quality_manager 5.0.1
ibm rational_doors_next_generation 5.0.1
ibm rational_team_concert 5.0.1
ibm rational_doors_next_generation *
ibm rational_team_concert *
CVE-2017-1489 MEDIUM

IBM Security Access Manager 6.1, 7.0, 8.0, and 9.0 e-community configurations may be affected by a redirect vulnerability. ECSSO Master Authentication can redirect to a server not participating in an e-community domain. IBM X-Force ID: 128687.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-601,

Products Affected

Vendor Product Version
ibm tivoli_access_manager_for_e-business 6.1.1.23
ibm tivoli_access_manager_for_e-business 6.1.1.1
ibm tivoli_access_manager_for_e-business 6.1.0.9
ibm tivoli_access_manager_for_e-business 6.1.0.2
ibm security_access_manager_for_web_software 7.0.0.6
ibm security_access_manager_for_web 8.0.0.2
ibm security_access_manager_for_web 8.0.1.0
ibm tivoli_access_manager_for_e-business 6.1.0.16
ibm tivoli_access_manager_for_e-business 6.1.1.12
ibm security_access_manager_for_web_software 7.0.0.13
ibm security_access_manager_for_web 8.0.0.0
ibm tivoli_access_manager_for_e-business 6.1.1.4
ibm tivoli_access_manager_for_e-business 6.1.1.30
ibm security_access_manager_for_web 8.0.0.5
ibm security_access_manager_for_web_appliance 7.0.0.20
ibm tivoli_access_manager_for_e-business 6.1.1.18
ibm security_access_manager_for_web_appliance 7.0.0.6
ibm tivoli_access_manager_for_e-business 6.1.1.6
ibm security_access_manager_for_web_software 7.0.0.3
ibm security_access_manager_for_mobile 8.0.0.31
ibm tivoli_access_manager_for_e-business 6.1.0.4
ibm security_access_manager_for_mobile 8.0
ibm security_access_manager 9.0.0.1
ibm tivoli_access_manager_for_e-business 6.1.0.21
ibm security_access_manager_for_web_appliance 7.0.0.23
ibm security_access_manager_for_mobile 8.0.0.0
ibm security_access_manager_for_web_appliance 7.0.0.29
ibm security_access_manager_for_web_software 7.0.0.11
ibm tivoli_access_manager_for_e-business 6.1.0.5
ibm security_access_manager_for_web_software 7.0.0.7
ibm tivoli_access_manager_for_e-business 6.1.0.14
ibm tivoli_access_manager_for_e-business 6.1.0.28
ibm security_access_manager_for_web_software 7.0.0.18
ibm security_access_manager_for_web_software 7.0
ibm tivoli_access_manager_for_e-business 6.1.1.29
ibm tivoli_access_manager_for_e-business 6.1.1.28
ibm security_access_manager_for_web_appliance 7.0.0.25
ibm tivoli_access_manager_for_e-business 6.1.0.31
ibm security_access_manager_for_mobile 8.0.1.3
ibm tivoli_access_manager_for_e-business 6.1.0.29
ibm security_access_manager_for_web_appliance 7.0.0.16
ibm security_access_manager_for_mobile 8.0.1.6
ibm security_access_manager_for_mobile 8.0.1.5
ibm tivoli_access_manager_for_e-business 6.1.0.6
ibm security_access_manager_for_web_software 7.0.0.14
ibm security_access_manager_for_web_appliance 7.0.0.30
ibm security_access_manager_for_web_appliance 7.0.0.7
ibm tivoli_access_manager_for_e-business 6.1.0.20
ibm security_access_manager_for_web_software 7.0.0.15
ibm tivoli_access_manager_for_e-business 6.1.1.17
ibm security_access_manager_for_web 8.0.0.31
ibm tivoli_access_manager_for_e-business 6.1.1.14
ibm tivoli_access_manager_for_e-business 6.1.0.18
ibm security_access_manager_for_mobile 8.0.0.3
ibm tivoli_access_manager_for_e-business 6.1.0.25
ibm security_access_manager_for_web_software 7.0.0.25
ibm security_access_manager_for_mobile 8.0.1.2
ibm tivoli_access_manager_for_e-business 6.1.1.16
ibm tivoli_access_manager_for_e-business 6.1.0.19
ibm security_access_manager_for_web_appliance 7.0.0.3
ibm tivoli_access_manager_for_e-business 6.1.0.30
ibm security_access_manager_for_web_software 7.0.0.20
ibm tivoli_access_manager_for_e-business 6.1.1.27
ibm tivoli_access_manager_for_e-business 6.1.1.7
ibm tivoli_access_manager_for_e-business 6.1.0
ibm security_access_manager_for_web 8.0.1.1
ibm tivoli_access_manager_for_e-business 6.1.1.8
ibm security_access_manager_for_web 8.0.1.6
ibm security_access_manager 9.0.1.0
ibm tivoli_access_manager_for_e-business 6.1.0.13
ibm tivoli_access_manager_for_e-business 6.1.1.22
ibm security_access_manager_for_web_appliance 7.0
ibm security_access_manager 9.0.2.1
ibm tivoli_access_manager_for_e-business 6.1.1.21
ibm security_access_manager_for_mobile 8.0.0.22
ibm security_access_manager_for_mobile 8.0.0.1
ibm tivoli_access_manager_for_e-business 6.1.1.13
ibm security_access_manager_for_web_software 7.0.0.28
ibm security_access_manager_for_mobile 8.0.1.0
ibm tivoli_access_manager_for_e-business 6.1.1
ibm security_access_manager_for_mobile 8.0.0.2
ibm security_access_manager_for_web_software 7.0.0.1
ibm security_access_manager_for_web_appliance 7.0.0.8
ibm security_access_manager_for_mobile 8.0.1.4
ibm tivoli_access_manager_for_e-business 6.1.1.20
ibm security_access_manager_for_web_software 7.0.0.2
ibm security_access_manager_for_web 8.0.0.1
ibm tivoli_access_manager_for_e-business 6.1.0.7
ibm security_access_manager_for_web 8.0.1.4
ibm security_access_manager_for_web 8.0.0.4
ibm tivoli_access_manager_for_e-business 6.1.1.25
ibm security_access_manager_for_web_software 7.0.0.21
ibm security_access_manager_for_web_appliance 7.0.0.22
ibm tivoli_access_manager_for_e-business 6.1.0.11
ibm tivoli_access_manager_for_e-business 6.1.1.10
ibm security_access_manager_for_web_software 7.0.0.23
ibm security_access_manager_for_web_software 7.0.0.26
ibm tivoli_access_manager_for_e-business 6.1.1.19
ibm security_access_manager_for_web_software 7.0.0.24
ibm tivoli_access_manager_for_e-business 6.1.1.5
ibm tivoli_access_manager_for_e-business 6.1.0.23
ibm tivoli_access_manager_for_e-business 6.1.1.2
ibm security_access_manager_for_web_software 7.0.0.12
ibm security_access_manager_for_web_appliance 7.0.0.11
ibm security_access_manager_for_web_appliance 7.0.0.10
ibm tivoli_access_manager_for_e-business 6.1.1.9
ibm security_access_manager_for_web_software 7.0.0.10
ibm security_access_manager_for_web_appliance 7.0.0.9
ibm security_access_manager_for_web_appliance 7.0.0.13
ibm security_access_manager_for_web_software 7.0.0.22
ibm security_access_manager_for_web_appliance 7.0.0.21
ibm tivoli_access_manager_for_e-business 6.1.0.24
ibm tivoli_access_manager_for_e-business 6.1.1.15
ibm security_access_manager_for_web_software 7.0.0.27
ibm security_access_manager_for_web_software 7.0.0.17
ibm security_access_manager_for_web_software 7.0.0.9
ibm tivoli_access_manager_for_e-business 6.1.0.27
ibm tivoli_access_manager_for_e-business 6.1.0.12
ibm security_access_manager_for_web_software 7.0.0.16
ibm security_access_manager_for_web_appliance 7.0.0.24
ibm security_access_manager_for_web 8.0.1.3
ibm security_access_manager_for_web_appliance 7.0.0.15
ibm tivoli_access_manager_for_e-business 6.1.1.11
ibm security_access_manager_for_web_appliance 7.0.0.18
ibm security_access_manager 9.0.0.0
ibm security_access_manager_for_web_appliance 7.0.0.28
ibm security_access_manager_for_web 8.0.1.5
ibm tivoli_access_manager_for_e-business 6.1.0.8
ibm security_access_manager_for_web_appliance 7.0.0.17
ibm security_access_manager_for_web_appliance 7.0.0.26
ibm tivoli_access_manager_for_e-business 6.1.0.17
ibm security_access_manager_for_web 8.0.0.22
ibm security_access_manager_for_web_appliance 7.0.0.5
ibm security_access_manager_for_mobile 8.0.0.5
ibm security_access_manager_for_web 8.0.1.2
ibm security_access_manager_for_mobile 8.0.1.1
ibm security_access_manager_for_web_software 7.0.0.8
ibm security_access_manager_for_web_software 7.0.0.29
ibm security_access_manager_for_web_appliance 7.0.0.19
ibm security_access_manager_for_mobile 8.0.0.4
ibm security_access_manager_for_web_appliance 7.0.0.4
ibm tivoli_access_manager_for_e-business 6.1.1.26
ibm security_access_manager 9.0.2.0
ibm tivoli_access_manager_for_e-business 6.1.0.15
ibm tivoli_access_manager_for_e-business 6.1.1.3
ibm tivoli_access_manager_for_e-business 6.1.1.24
ibm tivoli_access_manager_for_e-business 6.1.0.22
ibm security_access_manager_for_web_software 7.0.0.19
ibm tivoli_access_manager_for_e-business 6.1.0.26
ibm tivoli_access_manager_for_e-business 6.1.0.3
ibm security_access_manager_for_web_software 7.0.0.4
ibm security_access_manager_for_web 8.0.0.3
ibm security_access_manager_for_web_appliance 7.0.0.14
ibm tivoli_access_manager_for_e-business 6.1.0.1
ibm security_access_manager_for_web_appliance 7.0.0.1
ibm security_access_manager_for_web_software 7.0.0.5
ibm security_access_manager_for_web_appliance 7.0.0.2
ibm security_access_manager_for_web 8.0
ibm security_access_manager 9.0.3.0
ibm security_access_manager_for_web_appliance 7.0.0.12
ibm tivoli_access_manager_for_e-business 6.1.0.10
ibm security_access_manager_for_web_software 7.0.0.30
ibm security_access_manager_for_web_appliance 7.0.0.27
CVE-2017-1490 LOW

An unspecified vulnerability in the Lifecycle Query Engine of Jazz Reporting Service 6.0 through 6.0.4 could disclose highly sensitive information.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm jazz_reporting_service 6.0.3
ibm jazz_reporting_service 6.0
ibm jazz_reporting_service 6.0.2
ibm jazz_reporting_service 6.0.1
ibm jazz_reporting_service 6.0.4
CVE-2017-1491 MEDIUM

IBM QRadar Network Security 5.4 supports interaction between multiple actors and allows those actors to negotiate which algorithm should be used as a protection mechanism such as encryption or authentication, but it does not select the strongest algorithm that is available to both parties. IBM X-Force ID: 128689.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm qradar_network_security 5.4
CVE-2017-1493 MEDIUM

IBM UrbanCode Deploy (UCD) 6.1 and 6.2 could allow an authenticated user to edit objects that they should not have access to due to improper access controls. IBM X-Force ID: 128691.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-269,

Products Affected

Vendor Product Version
ibm urbancode_deploy 6.1.0.3
ibm urbancode_deploy 6.2.6.1
ibm urbancode_deploy 6.2.3.1
ibm urbancode_deploy 6.1.1.8
ibm urbancode_deploy 6.2.5.0
ibm urbancode_deploy 6.1.1.1
ibm urbancode_deploy 6.1.1.2
ibm urbancode_deploy 6.1.3.3
ibm urbancode_deploy 6.2.4.1
ibm urbancode_deploy 6.2.5.1
ibm urbancode_deploy 6.1.1.5
ibm urbancode_deploy 6.2.1.0
ibm urbancode_deploy 6.2.4.2
ibm urbancode_deploy 6.1.3.4
ibm urbancode_deploy 6.1.0.1
ibm urbancode_deploy 6.2.0.0
ibm urbancode_deploy 6.1.1.6
ibm urbancode_deploy 6.1.0.4
ibm urbancode_deploy 6.1.1.0
ibm urbancode_deploy 6.1.3.1
ibm urbancode_deploy 6.2.0.1
ibm urbancode_deploy 6.1.3.2
ibm urbancode_deploy 6.1.3.6
ibm urbancode_deploy 6.2.1.1
ibm urbancode_deploy 6.1
ibm urbancode_deploy 6.1.3.5
ibm urbancode_deploy 6.1.2
ibm urbancode_deploy 6.2.0.2
ibm urbancode_deploy 6.2.1.2
ibm urbancode_deploy 6.1.3
ibm urbancode_deploy 6.1.1.3
ibm urbancode_deploy 6.2.4.0
ibm urbancode_deploy 6.2.2.0
ibm urbancode_deploy 6.1.1.7
ibm urbancode_deploy 6.2.5.2
ibm urbancode_deploy 6.1.1.4
ibm urbancode_deploy 6.2.2.1
ibm urbancode_deploy 6.2.3.0
ibm urbancode_deploy 6.2.6.0
ibm urbancode_deploy 6.2.0.201
CVE-2017-1494 LOW

IBM Business Process Manager 8.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128692.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm business_process_manager 8.5.6.0
ibm business_process_manager 8.5.5.0
ibm business_process_manager 8.5.7.0
CVE-2017-1495 MEDIUM

IBM InfoSphere Information Server 9.1, 11.3, and 11.5 could allow a privileged user to cause a memory dump that could contain highly sensitive information including access credentials. IBM X-Force ID: 128693.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm infosphere_information_server 11.3
ibm infosphere_information_server 11.5
ibm infosphere_information_server 9.1
CVE-2017-1496 LOW

IBM Sterling B2B Integrator Standard Edition 5.2.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128694.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator 5.2.6
ibm sterling_b2b_integrator 5.2
ibm sterling_b2b_integrator 5.2.1
ibm sterling_b2b_integrator 5.2.5
ibm sterling_b2b_integrator 5.2.3
ibm sterling_b2b_integrator 5.2.4
ibm sterling_b2b_integrator 5.2.2
CVE-2017-1497 MEDIUM

IBM Sterling File Gateway 2.2 could allow an unauthorized user to view files they should not have access to providing they know the directory location of the file. IBM X-Force ID: 128695.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm sterling_file_gateway 2.2
CVE-2017-1498 LOW

IBM Connections 5.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 129020.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm connections 5.5.0.0
CVE-2017-1499 MEDIUM

IBM Maximo Asset Management 7.5 and 7.6 could allow a remote attacker to include arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable Web server. IBM X-Force ID: 129106.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-434,

Products Affected

Vendor Product Version
ibm maximo_asset_management_essentials 7.5.0.0
ibm maximo_asset_management 7.6.0.0
ibm maximo_asset_management 7.5.0.0
CVE-2017-1500 MEDIUM

A Reflected Cross Site Scripting (XSS) vulnerability exists in the authorization function exposed by RESTful Web Api of IBM Worklight Framework 6.1, 6.2, 6.3, 7.0, 7.1, and 8.0. The vulnerable parameter is "scope"; if you set as its value a "realm" not defined in authenticationConfig.xml, you get an HTTP 403 Forbidden response and the value will be reflected in the body of the HTTP response. By setting it to arbitrary JavaScript code it is possible to modify the flow of the authorization function, potentially leading to credential disclosure within a trusted session.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm mobilefirst_platform_foundation 8.0.0.0
ibm worklight 6.1.0.2
ibm worklight 6.2.0.1
ibm mobilefirst_platform_foundation 6.3.0.0
ibm mobilefirst_platform_foundation 7.0.0.0
ibm mobilefirst_platform_foundation 7.1.0.0
CVE-2017-1501 MEDIUM

IBM WebSphere Application Server 8.0, 8.5, and 9.0 could provide weaker than expected security after using the Admin Console to update the web services security bindings settings. IBM X-Force ID: 129576.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_application_server 9.0.0.2
ibm websphere_application_server 8.0.0.8
ibm websphere_application_server 9.0.0.0
ibm websphere_application_server 8.0.0.5
ibm websphere_application_server 9.0.0.4
ibm websphere_application_server 8.0.0.3
ibm websphere_application_server 8.0.0.6
ibm websphere_application_server 8.0.0.1
ibm websphere_application_server 8.0.0.4
ibm websphere_application_server 8.0.0.7
ibm websphere_application_server 8.0.0.0
ibm websphere_application_server 8.0.0.12
ibm websphere_application_server 9.0.0.3
ibm websphere_application_server 8.0.0.9
ibm websphere_application_server 8.0.0.11
ibm websphere_application_server 8.5.5.11
ibm websphere_application_server 8.0.0.10
ibm websphere_application_server 8.5.5.10
ibm websphere_application_server 8.0.0.13
ibm websphere_application_server 9.0.0.1
ibm websphere_application_server 8.0.0.2
CVE-2017-1502 LOW

IBM Content Navigator & CMIS 2.0.3, 3.0.0, and 3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 129577.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm content_navigator 3.0.1
ibm content_navigator 3.0.0
ibm content_navigator 2.0.3
CVE-2017-1503 MEDIUM

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache poisoning, cross-site scripting, and possibly obtain sensitive information. IBM X-Force ID: 129578.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_application_server 9.0
ibm websphere_application_server 7.0
ibm websphere_application_server 8.0
ibm websphere_application_server 8.5
CVE-2017-1504 MEDIUM

IBM WebSphere Application Server version 9.0.0.4 could provide weaker than expected security after using the PasswordUtil command to enable AES password encryption. IBM X-Force ID: 129579.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_application_server 9.0.0.4
CVE-2017-1506 MEDIUM

IBM Cognos TM1 10.2 and 10.2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 129617.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm cognos_tm1 10.2.2
ibm cognos_tm1 10.2
CVE-2017-1507 MEDIUM

IBM Jazz Foundation Products could disclose sensitive information during a scan that could lead to further attacks against the system. IBM X-Force ID: 129619.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_rhapsody_design_manager 4.0.4
ibm rational_rhapsody_design_manager 4.0.5
ibm rational_software_architect_design_manager 6.0
ibm rational_collaborative_lifecycle_management 4.0.6
ibm rational_engineering_lifecycle_manager 4.0.7
ibm rational_quality_manager 4.0.6
ibm rational_software_architect_design_manager 6.0.1
ibm rational_team_concert 5.0
ibm rational_software_architect_design_manager 4.0.7
ibm rational_quality_manager 6.0.1
ibm rational_engineering_lifecycle_manager 5.0.2
ibm rational_rhapsody_design_manager 5.0.2
ibm rational_quality_manager 4.0.3
ibm rational_engineering_lifecycle_manager 6.0.2
ibm rational_collaborative_lifecycle_management 6.0.3
ibm rational_team_concert 4.0.1
ibm rational_team_concert 4.0.5
ibm rational_doors_next_generation 5.0
ibm rational_team_concert 4.0.2
ibm rational_quality_manager 5.0
ibm rational_collaborative_lifecycle_management 4.0.5
ibm rational_collaborative_lifecycle_management 4.0.7
ibm rational_collaborative_lifecycle_management 4.0.3
ibm rational_software_architect_design_manager 4.0.6
ibm rational_doors_next_generation 4.0.7
ibm rational_doors_next_generation 4.0.2
ibm rational_doors_next_generation 6.0
ibm rational_rhapsody_design_manager 4.0.7
ibm rational_engineering_lifecycle_manager 5.0
ibm rational_team_concert 5.0.2
ibm rational_collaborative_lifecycle_management 4.0.1
ibm rational_rhapsody_design_manager 5.0
ibm rational_engineering_lifecycle_manager 6.0.3
ibm rational_team_concert 6.0.4
ibm rational_team_concert 4.0.3
ibm rational_collaborative_lifecycle_management 4.0.2
ibm rational_quality_manager 4.0.1
ibm rational_team_concert 4.0.6
ibm rational_engineering_lifecycle_manager 4.0.5
ibm rational_software_architect_design_manager 5.0.2
ibm rational_engineering_lifecycle_manager 6.0.1
ibm rational_quality_manager 6.0
ibm rational_doors_next_generation 4.0.4
ibm rational_rhapsody_design_manager 6.0.3
ibm rational_quality_manager 4.0.4
ibm rational_rhapsody_design_manager 6.0.4
ibm rational_engineering_lifecycle_manager 4.0.6
ibm rational_rhapsody_design_manager 4.0.3
ibm rational_doors_next_generation 5.0.2
ibm rational_quality_manager 4.0.2
ibm rational_doors_next_generation 5.0.1
ibm rational_software_architect_design_manager 4.0.1
ibm rational_collaborative_lifecycle_management 4.0.4
ibm rational_team_concert 4.0.0.1
ibm rational_engineering_lifecycle_manager 4.0.3
ibm rational_engineering_lifecycle_manager 4.0.4
ibm rational_software_architect_design_manager 4.0.2
ibm rational_collaborative_lifecycle_management 6.0
ibm rational_quality_manager 4.0.0.1
ibm rational_quality_manager 4.0.0.2
ibm rational_team_concert 6.0.1
ibm rational_rhapsody_design_manager 6.0
ibm rational_quality_manager 4.0.7
ibm rational_rhapsody_design_manager 4.0.6
ibm rational_rhapsody_design_manager 6.0.1
ibm rational_rhapsody_design_manager 6.0.2
ibm rational_software_architect_design_manager 5.0
ibm rational_software_architect_design_manager 4.0.4
ibm rational_team_concert 6.0.2
ibm rational_doors_next_generation 4.0.1
ibm rational_engineering_lifecycle_manager 5.0.1
ibm rational_team_concert 4.0.7
ibm rational_team_concert 6.0
ibm rational_software_architect_design_manager 4.0.3
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_quality_manager 5.0.2
ibm rational_rhapsody_design_manager 4.0.1
ibm rational_rhapsody_design_manager 4.0.2
ibm rational_team_concert 4.0.0.2
ibm rational_rhapsody_design_manager 4.0
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_quality_manager 6.0.3
ibm rational_quality_manager 6.0.4
ibm rational_collaborative_lifecycle_management 6.0.4
ibm rational_doors_next_generation 6.0.1
ibm rational_rhapsody_design_manager 5.0.1
ibm rational_doors_next_generation 6.0.3
ibm rational_team_concert 4.0
ibm rational_doors_next_generation 4.0.5
ibm rational_collaborative_lifecycle_management 4.0
ibm rational_team_concert 6.0.3
ibm rational_engineering_lifecycle_manager 6.0.4
ibm rational_doors_next_generation 4.0.6
ibm rational_doors_next_generation 4.0.3
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 4.0
ibm rational_collaborative_lifecycle_management 5.0
ibm rational_doors_next_generation 6.0.4
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_software_architect_design_manager 4.0.5
ibm rational_engineering_lifecycle_manager 6.0
ibm rational_team_concert 4.0.4
ibm rational_software_architect_design_manager 5.0.1
ibm rational_software_architect_design_manager 4.0
ibm rational_quality_manager 4.0.5
ibm rational_quality_manager 6.0.2
ibm rational_doors_next_generation 6.0.2
ibm rational_team_concert 5.0.1
CVE-2017-1508 MEDIUM

IBM Informix Dynamic Server 12.1 could allow a local user logged in with database administrator user to gain root privileges. IBM X-Force ID: 129620.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm informix_dynamic_server 12.10
CVE-2017-1509 MEDIUM

IBM Jazz Foundation products could allow an authenticated user to obtain sensitive information from a stack trace that could be used to aid future attacks. IBM X-Force ID: 129719.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
ibm rational_engineering_lifecycle_manager *
ibm rational_engineering_lifecycle_manager 5.0.1
ibm rational_rhapsody_design_manager 5.0.1
ibm rational_software_architect_design_manager 6.0.0
ibm rational_software_architect_design_manager 5.0.1
ibm rational_software_architect_design_manager 6.0.1
ibm rational_rhapsody_design_manager *
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_collaborative_lifecycle_management *
ibm rational_quality_manager 5.0.1
ibm rational_doors_next_generation 5.0.1
ibm rational_team_concert 5.0.1
ibm rational_doors_next_generation *
ibm rational_team_concert *
CVE-2017-1515 MEDIUM

IBM Doors Web Access 9.5 and 9.6 could allow an authenticated user to obtain sensitive information from HTTP internal server error responses. IBM X-Force ID: 129825.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm engineering_requirements_management_doors *
CVE-2017-1516 LOW

IBM Doors Web Access 9.5 and 9.6 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 129826.

CVSS 2.0

Severity: LOW

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm engineering_requirements_management_doors *
CVE-2017-1519 MEDIUM

IBM DB2 10.5 and 11.1 contains a denial of service vulnerability. A remote user can cause disruption of service for DB2 Connect Server setup with a particular configuration. IBM X-Force ID: 129829.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2_connect 10.5.0.2
ibm db2 10.5.0.7
ibm db2_connect 10.5.0.4
ibm db2 11.1.0.0
ibm db2 10.5.0.5
ibm db2 10.5.0.1
ibm db2 10.5.0.3
ibm db2_connect 10.5.0.7
ibm db2_connect 10.5.0.1
ibm db2 10.5.0.6
ibm db2_connect 10.5
ibm db2 10.5.0.2
ibm db2_connect 10.5.0.5
ibm db2_connect 10.5.0.6
ibm db2_connect 11.1.0.0
ibm db2_connect 10.5.0.3
ibm db2 10.5.0.4
CVE-2017-1520 MEDIUM

IBM DB2 9.7, 10,1, 10.5, and 11.1 is vulnerable to an unauthorized command that allows the database to be activated when authentication type is CLIENT. IBM X-Force ID: 129830.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm db2_connect 10.1
ibm db2_connect 9.7.0.11
ibm db2 10.1.0.1
ibm db2_connect 10.1.0.3
ibm db2_connect 9.7.0.8
ibm db2 11.1.0.0
ibm db2_connect 9.7.0.6
ibm db2 10.5.0.1
ibm db2 10.5.0.2
ibm db2 9.7.0.2
ibm db2 9.7.0.1
ibm db2_connect 10.5.0.5
ibm db2 10.1.0.5
ibm db2_connect 9.7
ibm db2_connect 11.1.0.0
ibm db2 10.5.0.4
ibm db2 10.1.0.3
ibm db2_connect 10.1.0.5
ibm db2 10.5.0.7
ibm db2 9.7.0.7
ibm db2_connect 10.1.0.4
ibm db2 9.7
ibm db2 9.7.0.3
ibm db2 10.5.0.3
ibm db2 9.7.0.11
ibm db2_connect 9.7.0.4
ibm db2_connect 10.1.0.2
ibm db2_connect 10.5.0.3
ibm db2_connect 9.7.0.9
ibm db2 10.5
ibm db2 9.7.0.9
ibm db2_connect 9.7.0.5
ibm db2_connect 10.5.0.2
ibm db2 9.7.0.5
ibm db2_connect 10.5.0.4
ibm db2 9.7.0.6
ibm db2 9.7.0.10
ibm db2 9.7.0.8
ibm db2 10.1.0.4
ibm db2 10.1
ibm db2_connect 9.7.0.10
ibm db2_connect 10.1.0.1
ibm db2_connect 10.5.0.6
ibm db2_connect 9.7.0.7
ibm db2 10.1.0.2
ibm db2_connect 9.7.0.3
ibm db2 9.7.0.4
ibm db2 10.5.0.5
ibm db2_connect 10.5.0.7
ibm db2_connect 10.5.0.1
ibm db2 10.5.0.6
ibm db2_connect 10.5
ibm db2_connect 9.7.0.1
ibm db2_connect 9.7.0.2
CVE-2017-1521 MEDIUM

IBM Tivoli Endpoint Manager (for Lifecycle/Power/Patch) Platform and Applications (IBM BigFix Platform 9.2 and 9.5) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 129831.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm bigfix_platform 9.2
ibm bigfix_platform 9.5
CVE-2017-1522 LOW

IBM Content Navigator & CMIS 2.0.3, 3.0.0, and 3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 129832.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm content_navigator 3.0.1
ibm content_navigator 2.0.3.8
ibm content_navigator 3.0.0
CVE-2017-1523 MEDIUM

IBM InfoSphere Master Data Management - Collaborative Edition 11.5 could allow an unauthorized user to download reports without authentication. IBM X-Force ID: 129892.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-306,

Products Affected

Vendor Product Version
ibm infosphere_master_data_management 11.5
CVE-2017-1524 MEDIUM

IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) could allow an authenticated user to obtain sensitive information from a specially crafted HTTP request that could be used to aid future attacks. IBM X-Force ID: 129970.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_rhapsody_design_manager 5.0.1
ibm rational_software_architect_design_manager 5.0.0
ibm rational_rhapsody_design_manager 5.0.0
ibm rational_team_concert 5.0.2
ibm rational_software_architect_design_manager *
ibm rational_engineering_lifecycle_manager 5.0.0
ibm rational_software_architect_design_manager 6.0.1
ibm rational_rhapsody_design_manager *
ibm rational_collaborative_lifecycle_management *
ibm rational_quality_manager 5.0.1
ibm rational_engineering_lifecycle_manager 5.0.2
ibm rational_rhapsody_design_manager 5.0.2
ibm rational_doors_next_generation *
ibm rational_team_concert *
ibm rational_quality_manager *
ibm rational_team_concert 5.0.0
ibm rational_engineering_lifecycle_manager *
ibm rational_engineering_lifecycle_manager 5.0.1
ibm rational_quality_manager 5.0.0
ibm rational_software_architect_design_manager 5.0.2
ibm rational_software_architect_design_manager 6.0.0
ibm rational_quality_manager 5.0.2
ibm rational_software_architect_design_manager 5.0.1
ibm rational_doors_next_generation 5.0.0
ibm rational_doors_next_generation 5.0.2
ibm rational_doors_next_generation 5.0.1
ibm rational_team_concert 5.0.1
CVE-2017-1527 HIGH

IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 130156.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm business_process_manager 8.0.1.2
ibm business_process_manager 8.5.6.0
ibm business_process_manager 8.0.1.1
ibm business_process_manager 7.5.0.1
ibm business_process_manager 8.5.6.1
ibm business_process_manager 8.5.0.2
ibm business_process_manager 7.5.1.0
ibm business_process_manager 7.5.1.1
ibm business_process_manager 8.5.6.2
ibm business_process_manager 8.5.5.0
ibm business_process_manager 8.0.1.0
ibm business_process_manager 7.5.1.2
ibm business_process_manager 8.0.0.0
ibm business_process_manager 8.5.7.0
ibm business_process_manager 8.5.0.1
ibm business_process_manager 8.0.1.3
ibm business_process_manager 8.5.0.0
ibm business_process_manager 7.5.0.0
CVE-2017-1530 LOW

IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 130409.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm business_process_manager 8.0.1.2
ibm business_process_manager 8.5.6.0
ibm business_process_manager 8.0.1.1
ibm business_process_manager 7.5.0.1
ibm business_process_manager 8.5.6.1
ibm business_process_manager 8.5.0.2
ibm business_process_manager 7.5.1.0
ibm business_process_manager 7.5.1.1
ibm business_process_manager 8.5.6.2
ibm business_process_manager 8.5.5.0
ibm business_process_manager 8.0.1.0
ibm business_process_manager 7.5.1.2
ibm business_process_manager 8.0.0.0
ibm business_process_manager 8.5.7.0
ibm business_process_manager 8.5.0.1
ibm business_process_manager 8.0.1.3
ibm business_process_manager 8.5.0.0
ibm business_process_manager 7.5.0.0
CVE-2017-1531 LOW

IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 130410.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm business_process_manager 8.0.1.2
ibm business_process_manager 8.5.6.0
ibm business_process_manager 8.0.1.1
ibm business_process_manager 7.5.0.1
ibm business_process_manager 8.5.6.1
ibm business_process_manager 8.5.0.2
ibm business_process_manager 7.5.1.0
ibm business_process_manager 7.5.1.1
ibm business_process_manager 8.5.6.2
ibm business_process_manager 8.5.5.0
ibm business_process_manager 8.0.1.0
ibm business_process_manager 7.5.1.2
ibm business_process_manager 8.0.0.0
ibm business_process_manager 8.5.7.0
ibm business_process_manager 8.5.0.1
ibm business_process_manager 8.0.1.3
ibm business_process_manager 8.5.0.0
ibm business_process_manager 7.5.0.0
CVE-2017-1532 LOW

IBM DOORS 9.5 and 9.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 130411.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm engineering_requirements_management_doors *
CVE-2017-1533 MEDIUM

IBM Security Access Manager Appliance 9.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 130675.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm security_access_manager_9.0_firmware *
CVE-2017-1534 MEDIUM

IBM Security Access Manager Appliance 8.0.0 and 9.0.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 130676.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-601,

Products Affected

Vendor Product Version
ibm security_access_manager_for_mobile 8.0.1
ibm security_access_manager_for_mobile 8.0.0.2
ibm security_access_manager_for_web_firmware 8.0.1.3
ibm security_access_manager_for_web_firmware 8.0.1.6
ibm security_access_manager_for_mobile 8.0.1.4
ibm security_access_manager_firmware 9.0.2.0
ibm security_access_manager_for_web_firmware 8.0.0.3
ibm security_access_manager_for_web_firmware 8.0.1.2
ibm security_access_manager_for_web_firmware 8.0.1.4
ibm security_access_manager_firmware 9.0.0
ibm security_access_manager_for_mobile 8.0.0.3
ibm security_access_manager_for_web_firmware 8.0.0.2
ibm security_access_manager_firmware 9.0.2.1
ibm security_access_manager_for_mobile 8.0.1.2
ibm security_access_manager_for_web_firmware 8.0.0
ibm security_access_manager_for_web_firmware 8.0.0.5
ibm security_access_manager_for_mobile 8.0.0.5
ibm security_access_manager_firmware 9.0.3
ibm security_access_manager_for_web_firmware 8.0.0.4
ibm security_access_manager_for_mobile 8.0.0
ibm security_access_manager_for_web_firmware 8.0.1.5
ibm security_access_manager_firmware 9.0.0.1
ibm security_access_manager_for_mobile 8.0.0.4
ibm security_access_manager_for_web_firmware 8.0.1
ibm security_access_manager_for_mobile 8.0.0.1
ibm security_access_manager_for_mobile 8.0.1.3
ibm security_access_manager_for_web_firmware 8.0.0.1
ibm security_access_manager_for_mobile 8.0.1.6
ibm security_access_manager_for_mobile 8.0.1.5
ibm security_access_manager_firmware 9.0.1.0
CVE-2017-1535 LOW

IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 130677.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm cognos_analytics 11.0.5
ibm cognos_analytics 11.0.6
ibm cognos_analytics 11.0.1
ibm cognos_analytics 11.0.3
ibm cognos_analytics 11.0.2
ibm cognos_analytics 11.0.0
ibm cognos_analytics 11.0.4
CVE-2017-1536 LOW

IBM Support Tools for Lotus WCM (IBM WebSphere Portal 7.0, 8.0, 8.5 and 9.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 130733.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 9.0
ibm websphere_portal 8.0
ibm websphere_portal 8.5
ibm websphere_portal 7.0
CVE-2017-1538 MEDIUM

IBM Financial Transaction Manager for ACH Services for Multi-Platform 3.0.2 could allow an authenticated user to obtain sensitive information from an undocumented URL. IBM X-Force ID: 130735.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm financial_transaction_manager 3.0.2.0
ibm financial_transaction_manager 3.0.2.1
CVE-2017-1539 MEDIUM

IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to privilege escalation by not properly distinguishing internal group memberships from user registry group memberships. By manipulating LDAP group membership an attack might gain privileged access. IBM X-Force ID: 130807.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm business_process_manager 8.0.1.2
ibm business_process_manager 8.5.6.0
ibm business_process_manager 8.0.1.1
ibm business_process_manager 7.5.0.1
ibm business_process_manager 8.5.6.1
ibm business_process_manager 8.5.0.2
ibm business_process_manager 7.5.1.0
ibm business_process_manager 7.5.1.1
ibm business_process_manager 8.5.6.2
ibm business_process_manager 8.5.5.0
ibm business_process_manager 8.0.1.0
ibm business_process_manager 7.5.1.2
ibm business_process_manager 8.0.0.0
ibm business_process_manager 8.5.7.0
ibm business_process_manager 8.5.0.1
ibm business_process_manager 8.0.1.3
ibm business_process_manager 8.5.0.0
ibm business_process_manager 7.5.0.0
CVE-2017-1540 LOW

IBM Doors Web Access 9.5 and 9.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 130808.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm engineering_requirements_management_doors *
CVE-2017-1541 HIGH

A flaw in the AIX 5.3, 6.1, 7.1, and 7.2 JRE/SDK installp and updatep packages prevented the java.security, java.policy and javaws.policy files from being updated correctly. IBM X-Force ID: 130809.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm aix 7.2
ibm aix 5.3
ibm aix 6.1
ibm aix 7.1
CVE-2017-1544 LOW

IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway 2.2.0 through 2.2.6) caches usernames and passwords in browsers that could be used by a local attacker to obtain sensitive information. IBM X-Force ID: 130812.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm sterling_file_gateway *
CVE-2017-1545 LOW

IBM Doors Web Access 9.5 and 9.6 could allow an attacker with physical access to the system to log into the application using previously stored credentials. IBM X-Force ID: 130914.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm engineering_requirements_management_doors *
CVE-2017-1546 LOW

IBM DOORS Next Generation (DNG/RRC) 4.07, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 130915.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_doors_next_generation 6.0
ibm rational_requirements_composer 5.0
ibm rational_requirements_composer 5.0.1
ibm rational_doors_next_generation 6.0.3
ibm rational_doors_next_generation 6.0.2
ibm rational_requirements_composer 5.0.2
ibm rational_requirements_composer 4.0.7
ibm rational_doors_next_generation 6.0.4
ibm rational_requirements_composer 4.0
ibm rational_doors_next_generation 6.0.1
CVE-2017-1548 MEDIUM

IBM Sterling File Gateway 2.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 131288.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm sterling_file_gateway 2.2
CVE-2017-1549 LOW

IBM Sterling File Gateway 2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 131289.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm sterling_file_gateway 2.2
CVE-2017-1550 MEDIUM

IBM Sterling File Gateway 2.2 could allow an authenticated user to change other user's passwords. IBM X-Force ID: 131290.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm sterling_file_gateway 2.2
CVE-2017-1551 MEDIUM

IBM API Connect 5.0.0.0 through 5.0.7.2 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 131291.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm api_connect 5.0.2.0
ibm api_connect 5.0.1.0
ibm api_connect 5.0.4.0
ibm api_connect 5.0.7.2
ibm api_connect 5.0.6.0
ibm api_connect 5.0.7.0
ibm api_connect 5.0.6.3
ibm api_connect 5.0.6.4
ibm api_connect 5.0.0.0
ibm api_connect 5.0.0.1
ibm api_connect 5.0.5.0
ibm api_connect 5.0.6.2
ibm api_connect 5.0.7.1
ibm api_connect 5.0.3.0
ibm api_connect 5.0.6.1
CVE-2017-1552 MEDIUM

IBM Infosphere BigInsights 4.2.0 and 4.2.5 is vulnerable to link injection. By persuading a victim to click on a specially-crafted URL link, a remote attacker could exploit this vulnerability to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 131396.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm infosphere_biginsights 4.2.5
ibm infosphere_biginsights 4.2.0
CVE-2017-1553 LOW

IBM Infosphere BigInsights 4.2.0 and 4.2.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 131397.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm infosphere_biginsights 4.2.5
ibm infosphere_biginsights 4.2.0
CVE-2017-1554 LOW

IBM Infosphere BigInsights 4.2.0 and 4.2.5 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 131398.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm infosphere_biginsights 4.2.5
ibm infosphere_biginsights 4.2.0
CVE-2017-1555 MEDIUM

IBM API Connect 5.0.0.0 through 5.0.7.2 could allow an authenticated user to generate an API token when not subscribed to the application plan. IBM X-Force ID: 131545.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm api_connect 5.0.2.0
ibm api_connect 5.0.1.0
ibm api_connect 5.0.4.0
ibm api_connect 5.0.7.2
ibm api_connect 5.0.6.0
ibm api_connect 5.0.7.0
ibm api_connect 5.0.6.3
ibm api_connect 5.0.6.4
ibm api_connect 5.0.0.0
ibm api_connect 5.0.0.1
ibm api_connect 5.0.5.0
ibm api_connect 5.0.6.2
ibm api_connect 5.0.7.1
ibm api_connect 5.0.3.0
ibm api_connect 5.0.6.1
CVE-2017-1556 MEDIUM

IBM API Connect 5.0.7.0 through 5.0.7.2 is vulnerable to a regular expression attack that could allow an authenticated attacker to use a regex and cause the system to slow or hang. IBM X-Force ID: 131546.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm api_connect 5.0.7.2
ibm api_connect 5.0.7.0
ibm api_connect 5.0.7.1
CVE-2017-1557 MEDIUM

IBM WebSphere MQ 8.0 and 9.0 could allow an authenticated user with authority to send a specially crafted request that could cause a channel process to cease processing further requests. IBM X-Force ID: 131547.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_mq 9.0
ibm websphere_mq 9.0.3
ibm websphere_mq 8.0.0.3
ibm websphere_mq 8.0.0.4
ibm websphere_mq 9.0.0.1
ibm websphere_mq 8.0.0.7
ibm websphere_mq 8.0.0.2
ibm websphere_mq 8.0.0.6
ibm websphere_mq 8.0.0.5
ibm websphere_mq 8.0.0.1
ibm websphere_mq 9.0.1
ibm websphere_mq 8.0
ibm websphere_mq 9.0.2
CVE-2017-1558 MEDIUM

IBM Maximo Asset Management 7.5 and 7.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 131548.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-601,

Products Affected

Vendor Product Version
ibm maximo_asset_management 7.6
ibm maximo_asset_management 7.5
ibm maximo_asset_management_essentials 7.5
CVE-2017-1559 MEDIUM

Multiple IBM Rational products could disclose sensitive information by an attacker that intercepts vulnerable requests. IBM X-Force ID: 131758.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
ibm rational_engineering_lifecycle_manager *
ibm rational_engineering_lifecycle_manager 5.0.1
ibm rational_rhapsody_design_manager 5.0.1
ibm rational_software_architect_design_manager 6.0.0
ibm rational_software_architect_design_manager 5.0.1
ibm rational_software_architect_design_manager 6.0.1
ibm rational_rhapsody_design_manager *
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_collaborative_lifecycle_management *
ibm rational_quality_manager 5.0.1
ibm rational_doors_next_generation 5.0.1
ibm rational_team_concert 5.0.1
ibm rational_doors_next_generation *
ibm rational_team_concert *
CVE-2017-1560 LOW

IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 131759.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_doors_next_generation *
CVE-2017-1561 LOW

IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 131760.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_collaborative_lifecycle_management 6.0.3
ibm rational_collaborative_lifecycle_management 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_collaborative_lifecycle_management 6.0
ibm rational_quality_manager 5.0.2
ibm rational_quality_manager 6.0
ibm rational_collaborative_lifecycle_management 6.0.5
ibm rational_quality_manager 5.0
ibm rational_quality_manager 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 6.0.1
ibm rational_quality_manager 6.0.5
ibm rational_quality_manager 6.0.3
ibm rational_collaborative_lifecycle_management 5.0
ibm rational_quality_manager 6.0.4
ibm rational_collaborative_lifecycle_management 6.0.4
CVE-2017-1562 LOW

IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 131761.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_collaborative_lifecycle_management 6.0.3
ibm rational_collaborative_lifecycle_management 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_collaborative_lifecycle_management 6.0
ibm rational_quality_manager 5.0.2
ibm rational_quality_manager 6.0
ibm rational_collaborative_lifecycle_management 6.0.5
ibm rational_quality_manager 5.0
ibm rational_quality_manager 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 6.0.1
ibm rational_quality_manager 6.0.5
ibm rational_quality_manager 6.0.3
ibm rational_collaborative_lifecycle_management 5.0
ibm rational_quality_manager 6.0.4
ibm rational_collaborative_lifecycle_management 6.0.4
CVE-2017-1563 LOW

IBM Doors Web Access 9.5 and 9.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 131763.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm engineering_requirements_management_doors *
CVE-2017-1564 LOW

IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 131764.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_collaborative_lifecycle_management 6.0.3
ibm rational_collaborative_lifecycle_management 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_collaborative_lifecycle_management 6.0
ibm rational_quality_manager 5.0.2
ibm rational_quality_manager 6.0
ibm rational_collaborative_lifecycle_management 6.0.5
ibm rational_quality_manager 5.0
ibm rational_quality_manager 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 6.0.1
ibm rational_quality_manager 6.0.5
ibm rational_quality_manager 6.0.3
ibm rational_collaborative_lifecycle_management 5.0
ibm rational_quality_manager 6.0.4
ibm rational_collaborative_lifecycle_management 6.0.4
CVE-2017-1565 LOW

IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 131765.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_collaborative_lifecycle_management 6.0.3
ibm rational_collaborative_lifecycle_management 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_collaborative_lifecycle_management 6.0
ibm rational_quality_manager 5.0.2
ibm rational_quality_manager 6.0
ibm rational_collaborative_lifecycle_management 6.0.5
ibm rational_quality_manager 5.0
ibm rational_quality_manager 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 6.0.1
ibm rational_quality_manager 6.0.5
ibm rational_quality_manager 6.0.3
ibm rational_collaborative_lifecycle_management 5.0
ibm rational_quality_manager 6.0.4
ibm rational_collaborative_lifecycle_management 6.0.4
CVE-2017-1567 LOW

IBM Doors Web Access 9.5 and 9.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 131769.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm engineering_requirements_management_doors *
CVE-2017-1568 LOW

IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 131778.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_collaborative_lifecycle_management 6.0.3
ibm rational_collaborative_lifecycle_management 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_collaborative_lifecycle_management 6.0
ibm rational_quality_manager 5.0.2
ibm rational_quality_manager 6.0
ibm rational_collaborative_lifecycle_management 6.0.5
ibm rational_quality_manager 5.0
ibm rational_quality_manager 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 6.0.1
ibm rational_quality_manager 6.0.5
ibm rational_quality_manager 6.0.3
ibm rational_collaborative_lifecycle_management 5.0
ibm rational_quality_manager 6.0.4
ibm rational_collaborative_lifecycle_management 6.0.4
CVE-2017-1569 MEDIUM

IBM WebSphere Commerce 7.0 and 8.0 contains an unspecified vulnerability in Marketing ESpot's that could cause a denial of service. IBM X-Force ID: 131779.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_commerce 8.0.0.9
ibm websphere_commerce 8.0.4.0
ibm websphere_commerce 8.0.0.6
ibm websphere_commerce 7.0.0.2
ibm websphere_commerce 8.0.0.3
ibm websphere_commerce 8.0.1.12
ibm websphere_commerce 8.0.1.2
ibm websphere_commerce 8.0.3.3
ibm websphere_commerce 8.0.0.15
ibm websphere_commerce 8.0.0.13
ibm websphere_commerce 8.0.0.10
ibm websphere_commerce 7.0.0.1
ibm websphere_commerce 8.0.1.8
ibm websphere_commerce 8.0.4.3
ibm websphere_commerce 7.0.0.4
ibm websphere_commerce 8.0.3.1
ibm websphere_commerce 8.0.1.4
ibm websphere_commerce 8.0.0.0
ibm websphere_commerce 8.0.0.19
ibm websphere_commerce 8.0.3.4
ibm websphere_commerce 8.0.1.5
ibm websphere_commerce 8.0.1.9
ibm websphere_commerce 8.0.4.2
ibm websphere_commerce 8.0.0.14
ibm websphere_commerce 8.0.4.1
ibm websphere_commerce 8.0.1.7
ibm websphere_commerce 8.0.4.4
ibm websphere_commerce 7.0.0.6
ibm websphere_commerce 7.0.0.7
ibm websphere_commerce 7.0.0.3
ibm websphere_commerce 8.0.0.4
ibm websphere_commerce 8.0.0.7
ibm websphere_commerce 8.0.1.1
ibm websphere_commerce 8.0.0.1
ibm websphere_commerce 7.0.0.5
ibm websphere_commerce 8.0.1.10
ibm websphere_commerce 8.0.3.2
ibm websphere_commerce 8.0.1.0
ibm websphere_commerce 7.0.0.8
ibm websphere_commerce 8.0.0.2
ibm websphere_commerce 8.0.0.8
ibm websphere_commerce 8.0.4.5
ibm websphere_commerce 8.0.1.11
ibm websphere_commerce 8.0.3.0
ibm websphere_commerce 8.0.0.16
ibm websphere_commerce 8.0.0.11
ibm websphere_commerce 8.0.1.13
ibm websphere_commerce 8.0.1.6
ibm websphere_commerce 8.0.0.5
ibm websphere_commerce 7.0.0.0
ibm websphere_commerce 8.0.1.3
ibm websphere_commerce 8.0.0.12
ibm websphere_commerce 8.0.0.18
ibm websphere_commerce 8.0.0.17
CVE-2017-1570 MEDIUM

IBM Jazz Foundation products could allow an authenticated user to obtain sensitive information from stack traces. IBM X-Force ID: 131852.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_rhapsody_design_manager 4.0.4
ibm rational_rhapsody_design_manager 4.0.5
ibm rational_software_architect_design_manager 6.0
ibm rational_collaborative_lifecycle_management 4.0.6
ibm rational_engineering_lifecycle_manager 4.0.7
ibm rational_quality_manager 4.0.6
ibm rational_software_architect_design_manager 6.0.1
ibm rational_team_concert 5.0
ibm rational_software_architect_design_manager 4.0.7
ibm rational_quality_manager 6.0.1
ibm rational_engineering_lifecycle_manager 5.0.2
ibm rational_rhapsody_design_manager 5.0.2
ibm rational_quality_manager 4.0.3
ibm rational_engineering_lifecycle_manager 6.0.2
ibm rational_collaborative_lifecycle_management 6.0.3
ibm rational_team_concert 4.0.1
ibm rational_team_concert 4.0.5
ibm rational_doors_next_generation 5.0
ibm rational_team_concert 4.0.2
ibm rational_quality_manager 5.0
ibm rational_collaborative_lifecycle_management 4.0.5
ibm rational_collaborative_lifecycle_management 4.0.7
ibm rational_collaborative_lifecycle_management 4.0.3
ibm rational_software_architect_design_manager 4.0.6
ibm rational_doors_next_generation 4.0.7
ibm rational_doors_next_generation 4.0.2
ibm rational_doors_next_generation 6.0
ibm rational_rhapsody_design_manager 4.0.7
ibm rational_engineering_lifecycle_manager 5.0
ibm rational_team_concert 5.0.2
ibm rational_collaborative_lifecycle_management 4.0.1
ibm rational_rhapsody_design_manager 5.0
ibm rational_engineering_lifecycle_manager 6.0.3
ibm rational_team_concert 6.0.4
ibm rational_team_concert 4.0.3
ibm rational_collaborative_lifecycle_management 4.0.2
ibm rational_quality_manager 4.0.1
ibm rational_team_concert 4.0.6
ibm rational_engineering_lifecycle_manager 4.0.5
ibm rational_software_architect_design_manager 5.0.2
ibm rational_engineering_lifecycle_manager 6.0.1
ibm rational_quality_manager 6.0
ibm rational_doors_next_generation 4.0.4
ibm rational_rhapsody_design_manager 6.0.3
ibm rational_quality_manager 4.0.4
ibm rational_rhapsody_design_manager 6.0.4
ibm rational_engineering_lifecycle_manager 4.0.6
ibm rational_rhapsody_design_manager 4.0.3
ibm rational_doors_next_generation 5.0.2
ibm rational_quality_manager 4.0.2
ibm rational_doors_next_generation 5.0.1
ibm rational_software_architect_design_manager 4.0.1
ibm rational_collaborative_lifecycle_management 4.0.4
ibm rational_team_concert 4.0.0.1
ibm rational_engineering_lifecycle_manager 4.0.3
ibm rational_engineering_lifecycle_manager 4.0.4
ibm rational_software_architect_design_manager 4.0.2
ibm rational_collaborative_lifecycle_management 6.0
ibm rational_quality_manager 4.0.0.1
ibm rational_quality_manager 4.0.0.2
ibm rational_team_concert 6.0.1
ibm rational_rhapsody_design_manager 6.0
ibm rational_quality_manager 4.0.7
ibm rational_rhapsody_design_manager 4.0.6
ibm rational_rhapsody_design_manager 6.0.1
ibm rational_rhapsody_design_manager 6.0.2
ibm rational_software_architect_design_manager 5.0
ibm rational_software_architect_design_manager 4.0.4
ibm rational_team_concert 6.0.2
ibm rational_doors_next_generation 4.0.1
ibm rational_engineering_lifecycle_manager 5.0.1
ibm rational_team_concert 4.0.7
ibm rational_team_concert 6.0
ibm rational_software_architect_design_manager 4.0.3
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_quality_manager 5.0.2
ibm rational_rhapsody_design_manager 4.0.1
ibm rational_rhapsody_design_manager 4.0.2
ibm rational_team_concert 4.0.0.2
ibm rational_rhapsody_design_manager 4.0
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_quality_manager 6.0.3
ibm rational_quality_manager 6.0.4
ibm rational_collaborative_lifecycle_management 6.0.4
ibm rational_doors_next_generation 6.0.1
ibm rational_rhapsody_design_manager 5.0.1
ibm rational_doors_next_generation 6.0.3
ibm rational_team_concert 4.0
ibm rational_doors_next_generation 4.0.5
ibm rational_collaborative_lifecycle_management 4.0
ibm rational_team_concert 6.0.3
ibm rational_engineering_lifecycle_manager 6.0.4
ibm rational_doors_next_generation 4.0.6
ibm rational_doors_next_generation 4.0.3
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 4.0
ibm rational_collaborative_lifecycle_management 5.0
ibm rational_doors_next_generation 6.0.4
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_software_architect_design_manager 4.0.5
ibm rational_engineering_lifecycle_manager 6.0
ibm rational_team_concert 4.0.4
ibm rational_software_architect_design_manager 5.0.1
ibm rational_software_architect_design_manager 4.0
ibm rational_quality_manager 4.0.5
ibm rational_quality_manager 6.0.2
ibm rational_doors_next_generation 6.0.2
ibm rational_team_concert 5.0.1
CVE-2017-1571 LOW

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 131853.

CVSS 2.0

Severity: LOW

Problem Type: CWE-327,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2 11.1
ibm db2 10.1
ibm db2 9.7
CVE-2017-1575 LOW

IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway 2.2.0 through 2.2.6) uses weaker than expected cryptographic algorithms that could allow a local attacker to decrypt highly sensitive information. IBM X-Force ID: 132032.

CVSS 2.0

Severity: LOW

Problem Type: CWE-327,

Products Affected

Vendor Product Version
ibm sterling_file_gateway *
CVE-2017-1577 MEDIUM

IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 132117.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.1
ibm websphere_portal 8.0.0.0
ibm websphere_portal 7.0.0.2
ibm websphere_portal 8.5.0.0
ibm websphere_portal 7.0.0.1
ibm websphere_portal 7.0.0.0
ibm websphere_portal 9.0.0.0
CVE-2017-1583 MEDIUM

IBM WebSphere Application Server (IBM Liberty for Java for Bluemix 3.13)could allow a remote attacker to obtain sensitive information caused by improper error handling by MyFaces in JSF.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm liberty 3.13
CVE-2017-1591 MEDIUM

IBM WebSphere DataPower Appliances 7.0.0 through 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 132368.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm datapower_gateway 7.5.0.0
ibm datapower_gateway 7.5.2.1
ibm datapower_gateway 7.0.0.15
ibm datapower_gateway 7.2.0.8
ibm datapower_gateway 7.1.0.7
ibm datapower_gateway 7.1.0.15
ibm datapower_gateway 7.2.0.10
ibm datapower_gateway 7.5.0.9
ibm datapower_gateway 7.2.0.2
ibm datapower_gateway 7.1.0.6
ibm datapower_gateway 7.5.2.3
ibm datapower_gateway 7.0.0.4
ibm datapower_gateway 7.5.2.7
ibm datapower_gateway 7.0.0.8
ibm datapower_gateway 7.0.0.17
ibm datapower_gateway 7.2.0.5
ibm datapower_gateway 7.0.0.9
ibm datapower_gateway 7.0.0.10
ibm datapower_gateway 7.0.0.2
ibm datapower_gateway 7.0.0.14
ibm datapower_gateway 7.1.0.12
ibm datapower_gateway 7.2.0.7
ibm datapower_gateway 7.1.0.4
ibm datapower_gateway 7.1.0.17
ibm datapower_gateway 7.5.0.2
ibm datapower_gateway 7.2.0.13
ibm datapower_gateway 7.5.0.4
ibm datapower_gateway 7.5.1.5
ibm datapower_gateway 7.0.0.5
ibm datapower_gateway 7.5.2.5
ibm datapower_gateway 7.0.0.6
ibm datapower_gateway 7.2.0.9
ibm datapower_gateway 7.5.0.7
ibm datapower_gateway 7.5.1.2
ibm datapower_gateway 7.5.2.0
ibm datapower_gateway 7.5.1.6
ibm datapower_gateway 7.5.1.1
ibm datapower_gateway 7.5.1.3
ibm datapower_gateway 7.5.2.6
ibm datapower_gateway 7.0.0.3
ibm datapower_gateway 7.1.0.3
ibm datapower_gateway 7.5.0.5
ibm datapower_gateway 7.0.0.7
ibm datapower_gateway 7.2.0.3
ibm datapower_gateway 7.2.0.15
ibm datapower_gateway 7.2.0.0
ibm datapower_gateway 7.0.0.13
ibm datapower_gateway 7.6.0.0
ibm datapower_gateway 7.1.0.13
ibm datapower_gateway 7.5.1.4
ibm datapower_gateway 7.1.0.18
ibm datapower_gateway 7.1.0.8
ibm datapower_gateway 7.5.0.6
ibm datapower_gateway 7.0.0.0
ibm datapower_gateway 7.1.0.10
ibm datapower_gateway 7.2.0.4
ibm datapower_gateway 7.5.0.1
ibm datapower_gateway 7.2.0.1
ibm datapower_gateway 7.2.0.6
ibm datapower_gateway 7.5.0.3
ibm datapower_gateway 7.2.0.12
ibm datapower_gateway 7.0.0.11
ibm datapower_gateway 7.1.0.11
ibm datapower_gateway 7.0.0.18
ibm datapower_gateway 7.1.0.14
ibm datapower_gateway 7.5.2.2
ibm datapower_gateway 7.1.0.1
ibm datapower_gateway 7.5.2.4
ibm datapower_gateway 7.1.0.9
ibm datapower_gateway 7.5.1.0
ibm datapower_gateway 7.0.0.19
ibm datapower_gateway 7.5.1.8
ibm datapower_gateway 7.1.0.2
ibm datapower_gateway 7.1.0.16
ibm datapower_gateway 7.5.1.7
ibm datapower_gateway 7.0.0.12
ibm datapower_gateway 7.2.0.14
ibm datapower_gateway 7.1.0.0
ibm datapower_gateway 7.0.0.16
ibm datapower_gateway 7.2.0.11
ibm datapower_gateway 7.1.0.5
ibm datapower_gateway 7.5.0.8
ibm datapower_gateway 7.0.0.1
ibm datapower_gateway 7.5.2.8
CVE-2017-1592 LOW

IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 132493.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_collaborative_lifecycle_management 6.0.3
ibm rational_collaborative_lifecycle_management 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_collaborative_lifecycle_management 6.0
ibm rational_quality_manager 5.0.2
ibm rational_quality_manager 6.0
ibm rational_collaborative_lifecycle_management 6.0.5
ibm rational_quality_manager 5.0
ibm rational_quality_manager 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 6.0.1
ibm rational_quality_manager 6.0.5
ibm rational_quality_manager 6.0.3
ibm rational_collaborative_lifecycle_management 5.0
ibm rational_quality_manager 6.0.4
ibm rational_collaborative_lifecycle_management 6.0.4
CVE-2017-1593 LOW

IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 132494.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_doors_next_generation *
CVE-2017-1595 LOW

IBM Security Guardium 10.0 Database Activity Monitor could allow a local attacker to obtain highly sensitive information via unspecified vectors. IBM X-Force ID: 132549.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_guardium 10.0.1
ibm security_guardium 10.0
ibm security_guardium 10.1.3
ibm security_guardium 10.1.2
ibm security_guardium 10.1.0
CVE-2017-1596 LOW

IBM Security Guardium 10.0 Database Activity Monitor could allow a local attacker to obtain highly sensitive information via unspecified vectors. IBM X-Force ID: 132550.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_guardium 10.0.1
ibm security_guardium 10.0
ibm security_guardium 10.1.3
ibm security_guardium 10.1.2
ibm security_guardium 10.1.0
CVE-2017-1597 MEDIUM

IBM Security Guardium 10.0, 10.0.1, 10.1, 10.1.2, 10.1.3, 10.1.4, and 10.5 Database Activity Monitor does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 132610.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-521,

Products Affected

Vendor Product Version
ibm security_guardium *
CVE-2017-1598 MEDIUM

IBM Security Guardium 10.0 Database Activity Monitor uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 132611.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-327,

Products Affected

Vendor Product Version
ibm security_guardium 10.0.1
ibm security_guardium 10.0
ibm security_guardium 10.1.3
ibm security_guardium 10.1.2
ibm security_guardium 10.1.0
CVE-2017-1600 LOW

IBM Security Guardium 10.0 Database Activity Monitor is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 132613.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm security_guardium 10.0.1
ibm security_guardium 10.0
ibm security_guardium 10.1.3
ibm security_guardium 10.1.2
ibm security_guardium 10.1.0
CVE-2017-1601 HIGH

IBM Security Guardium 10.0, 10.0.1, and 10.1 through 10.1.4 Database Activity Monitor does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 132624.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-521,

Products Affected

Vendor Product Version
ibm security_guardium_database_activity_monitor 10.0
ibm security_guardium_database_activity_monitor 10.1.2
ibm security_guardium_database_activity_monitor 10.1.4
ibm security_guardium_database_activity_monitor 10.0.1
ibm security_guardium_database_activity_monitor 10.1
ibm security_guardium_database_activity_monitor 10.1.3
CVE-2017-1602 MEDIUM

IBM RSA DM (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) could allow an authenticated user to access settings that they should not be able to using a specially crafted URL. IBM X-Force ID: 132625.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-552,

Products Affected

Vendor Product Version
ibm rational_rhapsody_design_manager 5.0.1
ibm rational_software_architect_design_manager 5.0.0
ibm rational_rhapsody_design_manager 5.0.0
ibm rational_team_concert 5.0.2
ibm rational_software_architect_design_manager *
ibm rational_engineering_lifecycle_manager 5.0.0
ibm rational_software_architect_design_manager 6.0.1
ibm rational_rhapsody_design_manager *
ibm rational_collaborative_lifecycle_management *
ibm rational_quality_manager 5.0.1
ibm rational_engineering_lifecycle_manager 5.0.2
ibm rational_rhapsody_design_manager 5.0.2
ibm rational_doors_next_generation *
ibm rational_team_concert *
ibm rational_quality_manager *
ibm rational_team_concert 5.0.0
ibm rational_engineering_lifecycle_manager *
ibm rational_engineering_lifecycle_manager 5.0.1
ibm rational_quality_manager 5.0.0
ibm rational_software_architect_design_manager 5.0.2
ibm rational_software_architect_design_manager 6.0.0
ibm rational_quality_manager 5.0.2
ibm rational_software_architect_design_manager 5.0.1
ibm rational_doors_next_generation 5.0.0
ibm rational_doors_next_generation 5.0.2
ibm rational_doors_next_generation 5.0.1
ibm rational_team_concert 5.0.1
CVE-2017-1604 LOW

IBM Maximo Anywhere 7.5 and 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 132851.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm maximo_anywhere 7.6.1.0
ibm maximo_anywhere 7.5.2.1
ibm maximo_anywhere 7.6.2.0
ibm maximo_anywhere 7.5.1.2
ibm maximo_anywhere 7.5.2.2
ibm maximo_anywhere 7.6.0.0
ibm maximo_anywhere 7.5.2.0
CVE-2017-1606 MEDIUM

IBM Financial Transaction Manager (FTM) for Multi-Platform (MP) 3.0.0.0 through 3.0.0.7 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 132926.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm financial_transaction_manager 3.0.0.4
ibm financial_transaction_manager 3.0.0.2
ibm financial_transaction_manager 3.0.0.5
ibm financial_transaction_manager 3.0.0.6
ibm financial_transaction_manager 3.0.0.1
ibm financial_transaction_manager 3.0.0.7
ibm financial_transaction_manager 3.0.0.0
ibm financial_transaction_manager 3.0.0.3
CVE-2017-1607 LOW

IBM DOORS Next Generation (DNG/RRC) 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 132927.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_doors_next_generation 6.0
ibm rational_doors_next_generation 6.0.3
ibm rational_doors_next_generation 6.0.2
ibm rational_doors_next_generation 6.0.4
ibm rational_doors_next_generation 6.0.1
CVE-2017-1608 LOW

IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 132928.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_collaborative_lifecycle_management 6.0.3
ibm rational_collaborative_lifecycle_management 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_collaborative_lifecycle_management 6.0
ibm rational_quality_manager 5.0.2
ibm rational_quality_manager 6.0
ibm rational_collaborative_lifecycle_management 6.0.5
ibm rational_quality_manager 5.0
ibm rational_quality_manager 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 6.0.1
ibm rational_quality_manager 6.0.5
ibm rational_quality_manager 6.0.3
ibm rational_collaborative_lifecycle_management 5.0
ibm rational_quality_manager 6.0.4
ibm rational_collaborative_lifecycle_management 6.0.4
CVE-2017-1609 LOW

IBM Quality Manager (RQM) 5.0 through 5.0.2 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 132929.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
CVE-2017-1612 MEDIUM

IBM WebSphere MQ 7.0, 7.1, 7.5, 8.0, and 9.0 service trace module could be used to execute untrusted code under 'mqm' user. IBM X-Force ID: 132953.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_mq 7.5.0.1
ibm websphere_mq 8.0.0.3
ibm websphere_mq 8.0.0.4
ibm websphere_mq 7.0.1.7
ibm websphere_mq 7.0.1.12
ibm websphere_mq 7.0.1.1
ibm websphere_mq 7.5.0.7
ibm websphere_mq 7.0.1.3
ibm websphere_mq 7.5
ibm websphere_mq 7.1.0.0
ibm websphere_mq 7.1.0.7
ibm websphere_mq 7.1.0.8
ibm websphere_mq 9.0.3.0
ibm websphere_mq 8.0.0.2
ibm websphere_mq 9.0.1.0
ibm websphere_mq 7.5.0.2
ibm websphere_mq 8.0.0.5
ibm websphere_mq 9.0.2.0
ibm websphere_mq 8.0.0.1
ibm websphere_mq 7.1.0.5
ibm websphere_mq 7.5.0.3
ibm websphere_mq 7.1.0.4
ibm websphere_mq 7.1.0.6
ibm websphere_mq 7.0.1.9
ibm websphere_mq 7.1.0.2
ibm websphere_mq 8.0
ibm websphere_mq 7.0.1.6
ibm websphere_mq 7.5.0.6
ibm websphere_mq 9.0
ibm websphere_mq 7.1.0.3
ibm websphere_mq 7.5.0.4
ibm websphere_mq 7.0.1.0
ibm websphere_mq 7.0.1.5
ibm websphere_mq 9.0.0.1
ibm websphere_mq 8.0.0.7
ibm websphere_mq 7.0.1.8
ibm websphere_mq 7.0.1.10
ibm websphere_mq 7.0.1.11
ibm websphere_mq 7.0.1.4
ibm websphere_mq 7.0.1.2
ibm websphere_mq 8.0.0.6
ibm websphere_mq 7.1.0.1
ibm websphere_mq 7.0.1.13
ibm websphere_mq 7.0.1.14
ibm websphere_mq 7.5.0.5
ibm websphere_mq 7.5.0.8
CVE-2017-1613 MEDIUM

IBM Connections 6.0 could allow an unauthenticated remote attacker to gain unauthenticated or unauthorized access to non-sensitive Engagement Center template data. IBM X-Force ID: 132954.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm connections 6.0
CVE-2017-1621 LOW

IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 133088.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_collaborative_lifecycle_management 6.0.3
ibm rational_collaborative_lifecycle_management 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_collaborative_lifecycle_management 6.0
ibm rational_quality_manager 5.0.2
ibm rational_quality_manager 6.0
ibm rational_collaborative_lifecycle_management 6.0.5
ibm rational_quality_manager 5.0
ibm rational_quality_manager 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 6.0.1
ibm rational_quality_manager 6.0.5
ibm rational_quality_manager 6.0.3
ibm rational_collaborative_lifecycle_management 5.0
ibm rational_quality_manager 6.0.4
ibm rational_collaborative_lifecycle_management 6.0.4
CVE-2017-1622 MEDIUM

IBM QRadar SIEM 7.2.8 and 7.3 does not validate, or incorrectly validates, a certificate. This weakness might allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack. IBM X-force ID: 133120.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-295,

Products Affected

Vendor Product Version
ibm qradar_incident_forensics *
ibm qradar_incident_forensics 7.2.8
ibm qradar_incident_forensics 7.3.1
CVE-2017-1623 MEDIUM

IBM QRadar 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 133121.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.2
ibm qradar_security_information_and_event_manager 7.2.8
ibm qradar_security_information_and_event_manager 7.2.0
ibm qradar_security_information_and_event_manager 7.2.7
ibm qradar_security_information_and_event_manager 7.3.0
ibm qradar_security_information_and_event_manager 7.2.3
ibm qradar_security_information_and_event_manager 7.2.6
ibm qradar_security_information_and_event_manager 7.2.4
ibm qradar_security_information_and_event_manager 7.2.1
ibm qradar_security_information_and_event_manager 7.2.5
CVE-2017-1624 MEDIUM

IBM QRadar 7.3 and 7.3.1 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. IBM X-Force ID: 133122.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-732,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.3.1
ibm qradar_security_information_and_event_manager 7.3.0
CVE-2017-1625 MEDIUM

IBM Pulse for QRadar 1.0.0 - 1.0.3 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 133123.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm qradar_pulse 1.0.3
ibm qradar_pulse 1.0.1
ibm qradar_pulse 1.0.0
ibm qradar_pulse 1.0.2
CVE-2017-1628 MEDIUM

IBM Business Process Manager 8.6.0.0 allows authenticated users to stop and resume the Event Manager by calling a REST API with incorrect authorization checks.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-863,

Products Affected

Vendor Product Version
ibm business_process_manager 8.6.0.0
CVE-2017-1629 LOW

IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 133127.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
ibm rational_engineering_lifecycle_manager *
ibm rational_rhapsody_design_manager *
ibm rational_collaborative_lifecycle_management *
ibm rational_software_architect_design_manager *
ibm rational_doors_next_generation *
ibm rational_team_concert *
CVE-2017-1631 MEDIUM

IBM Jazz for Service Management (IBM Tivoli Components 1.1.3) is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 133140.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm jazz_for_service_management 1.1.3
CVE-2017-1632 LOW

IBM Sterling File Gateway 2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 133178.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm sterling_file_gateway 2.2
CVE-2017-1633 MEDIUM

IBM Sterling B2B Integrator 5.2 through 5.2.6 could allow an authenticated attacker to obtain sensitive variable name information using specially crafted HTTP requests. IBM X-Force ID: 133180.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator *
CVE-2017-1635 MEDIUM

IBM Tivoli Monitoring V6 6.2.2.x could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free error. A remote attacker could exploit this vulnerability to execute arbitrary code on the system or cause the application to crash. IBM X-Force ID: 133243.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-416,

Products Affected

Vendor Product Version
ibm tivoli_monitoring 6.2.2.9
ibm tivoli_monitoring 6.2.2.3
ibm tivoli_monitoring 6.2.2.4
ibm tivoli_monitoring 6.2.2.5
ibm tivoli_monitoring 6.2.2.8
ibm tivoli_monitoring 6.2.2
ibm tivoli_monitoring 6.2.2.7
ibm tivoli_monitoring 6.2.2.2
ibm tivoli_monitoring 6.2.2.6
CVE-2017-1649 LOW

IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 133259.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
CVE-2017-1650 LOW

IBM DOORS Next Generation (DNG/RRC) 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 133260.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_doors_next_generation 6.0
ibm rational_doors_next_generation 6.0.3
ibm rational_doors_next_generation 6.0.2
ibm rational_doors_next_generation 6.0.4
ibm rational_doors_next_generation 6.0.1
CVE-2017-1651 LOW

IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 133261.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_collaborative_lifecycle_management 6.0.3
ibm rational_collaborative_lifecycle_management 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_collaborative_lifecycle_management 6.0
ibm rational_quality_manager 5.0.2
ibm rational_quality_manager 6.0
ibm rational_collaborative_lifecycle_management 6.0.5
ibm rational_quality_manager 5.0
ibm rational_quality_manager 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 6.0.1
ibm rational_quality_manager 6.0.5
ibm rational_quality_manager 6.0.3
ibm rational_collaborative_lifecycle_management 5.0
ibm rational_quality_manager 6.0.4
ibm rational_collaborative_lifecycle_management 6.0.4
CVE-2017-1652 LOW

IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 133263.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_collaborative_lifecycle_management 6.0.3
ibm rational_collaborative_lifecycle_management 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_collaborative_lifecycle_management 6.0
ibm rational_quality_manager 5.0.2
ibm rational_quality_manager 6.0
ibm rational_collaborative_lifecycle_management 6.0.5
ibm rational_quality_manager 5.0
ibm rational_quality_manager 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 6.0.1
ibm rational_quality_manager 6.0.5
ibm rational_quality_manager 6.0.3
ibm rational_collaborative_lifecycle_management 5.0
ibm rational_quality_manager 6.0.4
ibm rational_collaborative_lifecycle_management 6.0.4
CVE-2017-1653 LOW

IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 6.0.x) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 133268.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
ibm rational_software_architect_design_manager 6.0.1
ibm rational_engineering_lifecycle_manager *
ibm rational_rhapsody_design_manager *
ibm rational_software_architect_design_manager 6.0
ibm rational_collaborative_lifecycle_management *
ibm rational_doors_next_generation *
ibm rational_team_concert *
CVE-2017-1654 LOW

IBM Spectrum Scale 4.1.1 and 4.2.0 - 4.2.3 could allow a local unprivileged user access to information located in dump files. User data could be sent to IBM during service engagements. IBM X-Force ID: 133378.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm general_parallel_file_system 4.1.0.4
ibm spectrum_scale *
ibm general_parallel_file_system 4.1.0.7
ibm spectrum_scale 5.0.0.0
ibm general_parallel_file_system 4.1.0.2
ibm general_parallel_file_system 4.1.0.3
ibm general_parallel_file_system 4.1.0.0
ibm general_parallel_file_system 4.1.0.8
ibm general_parallel_file_system 4.1.0.1
ibm general_parallel_file_system 4.1.0.6
ibm general_parallel_file_system 4.1.0.5
CVE-2017-1655 LOW

IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 133379.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
ibm rational_engineering_lifecycle_manager *
ibm rational_rhapsody_design_manager *
ibm rational_collaborative_lifecycle_management *
ibm rational_software_architect_design_manager *
ibm rational_doors_next_generation *
ibm rational_team_concert *
CVE-2017-1664 MEDIUM

IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 133557.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-326,

Products Affected

Vendor Product Version
ibm security_key_lifecycle_manager 2.5.0.5
ibm security_key_lifecycle_manager 2.5.0.8
ibm security_key_lifecycle_manager 2.7.0
ibm security_key_lifecycle_manager 2.7.0.2
ibm security_key_lifecycle_manager 2.5.0.0
ibm security_key_lifecycle_manager 2.5.0.1
ibm security_key_lifecycle_manager 2.5.0
ibm security_key_lifecycle_manager 2.5.0.3
ibm security_key_lifecycle_manager 2.6.0
ibm security_key_lifecycle_manager 2.5.0.7
ibm security_key_lifecycle_manager 2.7.0.1
ibm security_key_lifecycle_manager 2.6.0.3
ibm security_key_lifecycle_manager 2.5.0.6
ibm security_key_lifecycle_manager 2.5.0.2
ibm security_key_lifecycle_manager 2.5.0.4
ibm security_key_lifecycle_manager 2.6.0.1
ibm security_key_lifecycle_manager 2.6.0.2
CVE-2017-1665 MEDIUM

IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 133559.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-326,

Products Affected

Vendor Product Version
ibm security_key_lifecycle_manager 2.5.0.5
ibm security_key_lifecycle_manager 2.5.0.8
ibm security_key_lifecycle_manager 2.7.0
ibm security_key_lifecycle_manager 2.7.0.2
ibm security_key_lifecycle_manager 2.5.0.0
ibm security_key_lifecycle_manager 2.5.0.1
ibm security_key_lifecycle_manager 2.5.0
ibm security_key_lifecycle_manager 2.5.0.3
ibm security_key_lifecycle_manager 2.6.0
ibm security_key_lifecycle_manager 2.5.0.7
ibm security_key_lifecycle_manager 2.7.0.1
ibm security_key_lifecycle_manager 2.6.0.3
ibm security_key_lifecycle_manager 2.5.0.6
ibm security_key_lifecycle_manager 2.5.0.2
ibm security_key_lifecycle_manager 2.5.0.4
ibm security_key_lifecycle_manager 2.6.0.1
debian debian_linux 9.0
ibm security_key_lifecycle_manager 2.6.0.2
CVE-2017-1666 MEDIUM

IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 133540.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm security_key_lifecycle_manager 2.5.0.5
ibm security_key_lifecycle_manager 2.5.0.8
ibm security_key_lifecycle_manager 2.7.0
ibm security_key_lifecycle_manager 2.7.0.2
ibm security_key_lifecycle_manager 2.5.0.1
ibm security_key_lifecycle_manager 2.5.0
ibm security_key_lifecycle_manager 2.5.0.3
ibm security_key_lifecycle_manager 2.6.0
ibm security_key_lifecycle_manager 2.5.0.7
ibm security_key_lifecycle_manager 2.7.0.1
ibm security_key_lifecycle_manager 2.6.0.3
ibm security_key_lifecycle_manager 2.5.0.6
ibm security_key_lifecycle_manager 2.5.0.2
ibm security_key_lifecycle_manager 2.5.0.4
ibm security_key_lifecycle_manager 2.6.0.1
ibm security_key_lifecycle_manager 2.6.0.2
CVE-2017-1668 MEDIUM

IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 133562.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-601,

Products Affected

Vendor Product Version
ibm security_key_lifecycle_manager 2.5.0.5
ibm security_key_lifecycle_manager 2.5.0.8
ibm security_key_lifecycle_manager 2.7.0
ibm security_key_lifecycle_manager 2.7.0.2
ibm security_key_lifecycle_manager 2.5.0.1
ibm security_key_lifecycle_manager 2.5.0
ibm security_key_lifecycle_manager 2.5.0.3
ibm security_key_lifecycle_manager 2.6.0
ibm security_key_lifecycle_manager 2.5.0.7
ibm security_key_lifecycle_manager 2.7.0.1
ibm security_key_lifecycle_manager 2.6.0.3
ibm security_key_lifecycle_manager 2.5.0.6
ibm security_key_lifecycle_manager 2.5.0.2
ibm security_key_lifecycle_manager 2.5.0.4
ibm security_key_lifecycle_manager 2.6.0.1
ibm security_key_lifecycle_manager 2.6.0.2
CVE-2017-1669 MEDIUM

IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 133636.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_key_lifecycle_manager 2.5.0.5
ibm security_key_lifecycle_manager 2.5.0.8
ibm security_key_lifecycle_manager 2.7.0
ibm security_key_lifecycle_manager 2.7.0.2
ibm security_key_lifecycle_manager 2.5.0.0
ibm security_key_lifecycle_manager 2.5.0.1
ibm security_key_lifecycle_manager 2.5.0.3
ibm security_key_lifecycle_manager 2.6.0
ibm security_key_lifecycle_manager 2.5.0.7
ibm security_key_lifecycle_manager 2.7.0.1
ibm security_key_lifecycle_manager 2.6.0.3
ibm security_key_lifecycle_manager 2.5.0.6
ibm security_key_lifecycle_manager 2.5.0.2
ibm security_key_lifecycle_manager 2.5.0.4
ibm security_key_lifecycle_manager 2.6.0.1
ibm security_key_lifecycle_manager 2.6.0.2
CVE-2017-1670 HIGH

IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 133637.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm security_key_lifecycle_manager 2.5.0.5
ibm security_key_lifecycle_manager 2.5.0.8
ibm security_key_lifecycle_manager 2.7.0
ibm security_key_lifecycle_manager 2.7.0.2
ibm security_key_lifecycle_manager 2.5.0.1
ibm security_key_lifecycle_manager 2.5.0
ibm security_key_lifecycle_manager 2.5.0.3
ibm security_key_lifecycle_manager 2.6.0
ibm security_key_lifecycle_manager 2.5.0.7
ibm security_key_lifecycle_manager 2.7.0.1
ibm security_key_lifecycle_manager 2.6.0.3
ibm security_key_lifecycle_manager 2.5.0.6
ibm security_key_lifecycle_manager 2.5.0.2
ibm security_key_lifecycle_manager 2.5.0.4
ibm security_key_lifecycle_manager 2.6.0.1
ibm security_key_lifecycle_manager 2.6.0.2
CVE-2017-1671 MEDIUM

IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 133638.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm security_key_lifecycle_manager 2.5.0.5
ibm security_key_lifecycle_manager 2.5.0.8
ibm security_key_lifecycle_manager 2.7.0
ibm security_key_lifecycle_manager 2.7.0.2
ibm security_key_lifecycle_manager 2.5.0.1
ibm security_key_lifecycle_manager 2.5.0
ibm security_key_lifecycle_manager 2.5.0.3
ibm security_key_lifecycle_manager 2.6.0
ibm security_key_lifecycle_manager 2.5.0.7
ibm security_key_lifecycle_manager 2.7.0.1
ibm security_key_lifecycle_manager 2.6.0.3
ibm security_key_lifecycle_manager 2.5.0.6
ibm security_key_lifecycle_manager 2.5.0.2
ibm security_key_lifecycle_manager 2.5.0.4
ibm security_key_lifecycle_manager 2.6.0.1
ibm security_key_lifecycle_manager 2.6.0.2
CVE-2017-1672 MEDIUM

IBM Tivoli Key Lifecycle Manager 2.6 and 2.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 133639.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm security_key_lifecycle_manager 2.6.0.1
ibm security_key_lifecycle_manager 2.7.0
ibm security_key_lifecycle_manager 2.7.0.2
ibm security_key_lifecycle_manager 2.6.0
ibm security_key_lifecycle_manager 2.7.0.1
ibm security_key_lifecycle_manager 2.6.0.2
ibm security_key_lifecycle_manager 2.6.0.3
CVE-2017-1673 MEDIUM

IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 133640.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm security_key_lifecycle_manager 2.5.0.5
ibm security_key_lifecycle_manager 2.5.0.8
ibm security_key_lifecycle_manager 2.7.0
ibm security_key_lifecycle_manager 2.7.0.2
ibm security_key_lifecycle_manager 2.5.0.0
ibm security_key_lifecycle_manager 2.5.0.1
ibm security_key_lifecycle_manager 2.5.0
ibm security_key_lifecycle_manager 2.5.0.3
ibm security_key_lifecycle_manager 2.6.0
ibm security_key_lifecycle_manager 2.5.0.7
ibm security_key_lifecycle_manager 2.7.0.1
ibm security_key_lifecycle_manager 2.6.0.3
ibm security_key_lifecycle_manager 2.5.0.6
ibm security_key_lifecycle_manager 2.5.0.2
ibm security_key_lifecycle_manager 2.5.0.4
ibm security_key_lifecycle_manager 2.6.0.1
ibm security_key_lifecycle_manager 2.6.0.2
CVE-2017-1677 MEDIUM

IBM Data Server Driver for JDBC and SQLJ (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) deserializes the contents of /tmp/connlicj.bin which leads to object injection and potentially arbitrary code execution depending on the classpath. IBM X-Force ID: 133999.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-502,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2 11.1
ibm db2 10.1
ibm db2 9.7
CVE-2017-1678 LOW

IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 134000.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_doors_next_generation *
CVE-2017-1679 LOW

IBM OpenPages GRC Platform 7.2, 7.3, 7.4, and 8.0 could allow an attacker to obtain sensitive information from error log files. IBM X-Force ID: 134001.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 5.5 MEDIUM CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N 1.8 3.6

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm openpages_grc_platform 7.2.0.0
ibm openpages_grc_platform 8.0.0.0
ibm openpages_grc_platform 7.4.0.0
ibm openpages_grc_platform 7.3.0.0
CVE-2017-1681 LOW

IBM WebSphere Application Server (IBM Liberty for Java for Bluemix 3.15) could allow a local attacker to obtain sensitive information, caused by improper handling of application requests, which could allow unauthorized access to read a file. IBM X-Force ID: 134003.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm liberty *
CVE-2017-1682 LOW

IBM Connections 4.0, 4.5, 5.0, 5.5, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 134004.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm connections 5.0
ibm connections 4.5
ibm connections 5.5
ibm connections 6.0
ibm connections 4.0
CVE-2017-1683 LOW

IBM Connections Engagement Center 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 134005.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm connections_engagement_center 6.0
CVE-2017-1688 LOW

IBM DOORS Next Generation (DNG/RRC) 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 134063.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_doors_next_generation 6.0
ibm rational_doors_next_generation 6.0.3
ibm rational_doors_next_generation 6.0.2
ibm rational_doors_next_generation 6.0.4
ibm rational_doors_next_generation 6.0.1
CVE-2017-1689 LOW

IBM DOORS Next Generation (DNG/RRC) 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 134064.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_doors_next_generation 6.0
ibm rational_doors_next_generation 6.0.3
ibm rational_doors_next_generation 6.0.2
ibm rational_doors_next_generation 6.0.4
ibm rational_doors_next_generation 6.0.1
CVE-2017-1690 LOW

IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 134065.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_collaborative_lifecycle_management 6.0.3
ibm rational_collaborative_lifecycle_management 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_collaborative_lifecycle_management 6.0
ibm rational_quality_manager 5.0.2
ibm rational_quality_manager 6.0
ibm rational_collaborative_lifecycle_management 6.0.5
ibm rational_quality_manager 5.0
ibm rational_quality_manager 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 6.0.1
ibm rational_quality_manager 6.0.5
ibm rational_quality_manager 6.0.3
ibm rational_collaborative_lifecycle_management 5.0
ibm rational_quality_manager 6.0.4
ibm rational_collaborative_lifecycle_management 6.0.4
CVE-2017-1691 LOW

IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 134066.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_collaborative_lifecycle_management 6.0.3
ibm rational_quality_manager 5.0.0
ibm rational_collaborative_lifecycle_management 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_quality_manager 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.5
ibm rational_collaborative_lifecycle_management 5.0.0
ibm rational_quality_manager 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_quality_manager 6.0.0
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 6.0.1
ibm rational_quality_manager 6.0.5
ibm rational_collaborative_lifecycle_management 6.0.0
ibm rational_quality_manager 6.0.3
ibm rational_quality_manager 6.0.4
ibm rational_collaborative_lifecycle_management 6.0.4
CVE-2017-1692 HIGH

IBM AIX 5.3, 6.1, 7.1, and 7.2 contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges. IBM X-Force ID: 134067.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm aix 7.2
ibm aix 5.3
ibm aix 6.1
ibm aix 7.1
CVE-2017-1693 MEDIUM

IBM Integration Bus 9.0 and 10.0 could allow an attacker that has captured a valid session id to hijack another users session during a small timeframe before the session times out. IBM X-Force ID: 134164.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-613,

Products Affected

Vendor Product Version
ibm integration_bus 9.0.0.8
ibm integration_bus 10.0.0.4
ibm integration_bus 9.0.0.2
ibm integration_bus 10.0.0.3
ibm integration_bus 9.0.0.7
ibm integration_bus 10.0.0.6
ibm integration_bus 10.0.0.5
ibm integration_bus 10.0.0.2
ibm integration_bus 10.0.0.9
ibm integration_bus 9.0.0.5
ibm integration_bus 9.0.0.4
ibm integration_bus 10.0.0.8
ibm integration_bus 10.0.0.0
ibm integration_bus 10.0.0.7
ibm integration_bus 10.0
ibm integration_bus 9.0.0.6
ibm integration_bus 9.0.0.1
ibm integration_bus 9.0.0.3
ibm integration_bus 9.0.0.0
ibm integration_bus 10.0.0.1
CVE-2017-1694 MEDIUM

IBM Integration Bus 9.0 and 10.0 transmits user credentials in plain in clear text which can be read by an attacker using man in the middle techniques. IBM X-Force ID: 134165.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-319,

Products Affected

Vendor Product Version
ibm integration_bus 9.0.0.8
ibm integration_bus 10.0.0.4
ibm integration_bus 9.0.0.2
ibm integration_bus 9.0.0.9
ibm integration_bus 10.0.0.3
ibm integration_bus 9.0.0.7
ibm integration_bus 10.0.0.6
ibm integration_bus 10.0.0.5
ibm integration_bus 10.0.0.2
ibm integration_bus 10.0.0.9
ibm integration_bus 9.0.0.5
ibm integration_bus 9.0.0.4
ibm integration_bus 10.0.0.8
ibm integration_bus 10.0.0.0
ibm integration_bus 10.0.0.7
ibm integration_bus 9.0.0.6
ibm integration_bus 9.0.0.1
ibm integration_bus 9.0.0.3
ibm integration_bus 9.0.0.0
ibm integration_bus 10.0.0.1
CVE-2017-1695 MEDIUM

IBM QRadar SIEM 7.2 and 7.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 134177.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-326,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.8
ibm qradar_security_information_and_event_manager 7.3.1
ibm qradar_security_information_and_event_manager *
CVE-2017-1696 HIGH

IBM QRadar 7.2 and 7.3 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 134178.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.3.0
CVE-2017-1698 MEDIUM

IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 could reveal sensitive information from an error message that could lead to further attacks against the system. IBM X-Force ID: 124390.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.0
ibm websphere_portal 8.5.0.0
ibm websphere_portal 7.0.0.0
ibm websphere_portal 9.0.0.0
CVE-2017-1699 LOW

IBM MQ Managed File Transfer Agent 8.0 and 9.0 sets insecure permissions on certain files it creates. A local attacker could exploit this vulnerability to modify or delete data contained in the files with an unknown impact. IBM X-Force ID: 134391.

CVSS 2.0

Severity: LOW

Problem Type: CWE-732,

Products Affected

Vendor Product Version
ibm websphere_mq 9.0
ibm websphere_mq 9.0.3
ibm websphere_mq 8.0.0.3
ibm websphere_mq 8.0.0.4
ibm websphere_mq 9.0.0.1
ibm websphere_mq 8.0.0.2
ibm websphere_mq 8.0.0.6
ibm websphere_mq 8.0.0.5
ibm websphere_mq 8.0.0.1
ibm websphere_mq 9.0.1
ibm websphere_mq 8.0
ibm websphere_mq 9.0.2
CVE-2017-1700 MEDIUM

IBM Jazz Team Server affecting the following IBM Rational Products: Collaborative Lifecycle Management (CLM), Rational DOORS Next Generation (RDNG), Rational Engineering Lifecycle Manager (RELM), Rational Team Concert (RTC), Rational Quality Manager (RQM), Rational Rhapsody Design Manager (Rhapsody DM), and Rational Software Architect (RSA DM) could allow an authenticated user to cause a denial of service due to incorrect authorization for resource intensive scenarios. IBM X-Force ID: 134392.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-863,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
ibm rational_engineering_lifecycle_manager *
ibm rational_rhapsody_design_manager *
ibm rational_collaborative_lifecycle_management *
ibm rational_software_architect_design_manager *
ibm rational_doors_next_generation *
ibm rational_team_concert *
CVE-2017-1701 MEDIUM

IBM Team Concert (RTC) 5.0, 5.0.1, 5.0.2, 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, and 6.0.5 stores credentials for users using a weak encryption algorithm, which could allow an authenticated user to obtain highly sensitive information. IBM X-Force ID: 134393.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-326,

Products Affected

Vendor Product Version
ibm rational_collaborative_lifecycle_management *
ibm rational_team_concert *
CVE-2017-1705 MEDIUM

IBM Security Privileged Identity Manager 2.1.0 contains left-over, sensitive information in page comments. While this information is not visible at first it can be obtained by viewing the page source. IBM X-Force ID: 134427.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_privileged_identity_manager 2.1.0
CVE-2017-1710 HIGH

A vulnerability in the Service Assistant GUI in IBM Storwize V7000 (2076) 8.1 could allow a remote attacker to perform a privilege escalation. IBM X-Force ID: 134531.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm storwize_v5000_firmware 8.1
ibm san_volume_controller_firmware 8.1
ibm storwize_v7000_firmware 8.1
ibm flashsystem_v9000_firmware 8.1
CVE-2017-1711 MEDIUM

IBM iNotes 8.5 and 9.0 SUService can be misguided into running malicious code from a DLL masquerading as a windows DLL in the temp directory. IBM X-Force ID: 134532.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-426,

Products Affected

Vendor Product Version
ibm client_application_access 1.0.1.0
ibm notes 8.5.0.0
ibm notes 8.5.3.0
ibm notes 8.5.2.0
ibm notes 9.0.0.0
ibm client_application_access 1.0.1.1
ibm notes 8.5.1.0
ibm notes 9.0.1.0
ibm client_application_access 1.0.1.2
CVE-2017-1713 MEDIUM

IBM InfoSphere Streams 4.2.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 134632.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-326,

Products Affected

Vendor Product Version
ibm infosphere_streams 4.2.1
CVE-2017-1714 HIGH

IBM Notes and Domino NSD 8.5 and 9.0 could allow an authenticated local user without administrative privileges to gain System privilege. IBM X-Force ID: 134633.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm client_application_access 1.0.1.0
ibm notes 8.5.0.0
ibm notes 8.5.3.0
ibm notes 8.5.2.0
ibm notes 9.0.0.0
ibm client_application_access 1.0.1.1
ibm notes 8.5.1.0
ibm notes 9.0.1.0
ibm client_application_access 1.0.1.2
CVE-2017-1715 LOW

IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 134637.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_collaborative_lifecycle_management 6.0.3
ibm rational_quality_manager 5.0.0
ibm rational_collaborative_lifecycle_management 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_quality_manager 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.5
ibm rational_collaborative_lifecycle_management 5.0.0
ibm rational_quality_manager 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_quality_manager 6.0.0
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 6.0.1
ibm rational_quality_manager 6.0.5
ibm rational_collaborative_lifecycle_management 6.0.0
ibm rational_quality_manager 6.0.3
ibm rational_quality_manager 6.0.4
ibm rational_collaborative_lifecycle_management 6.0.4
CVE-2017-1716 LOW

IBM Tivoli Workload Scheduler 8.6.0, 9.1.0, and 9.2.0 could disclose sensitive information to a local attacker due to improper permission settings. IBM X-Force ID: 134638.

CVSS 2.0

Severity: LOW

Problem Type: CWE-732,

Products Affected

Vendor Product Version
ibm tivoli_workload_scheduler 9.2
ibm tivoli_workload_scheduler 8.6
ibm tivoli_workload_scheduler 9.1
CVE-2017-1717 LOW

IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 134796.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_collaborative_lifecycle_management 6.0.3
ibm rational_quality_manager 5.0.0
ibm rational_collaborative_lifecycle_management 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.1
ibm rational_quality_manager 5.0.2
ibm rational_collaborative_lifecycle_management 6.0.5
ibm rational_collaborative_lifecycle_management 5.0.0
ibm rational_quality_manager 6.0.2
ibm rational_collaborative_lifecycle_management 5.0.1
ibm rational_quality_manager 6.0.0
ibm rational_quality_manager 5.0.1
ibm rational_quality_manager 6.0.1
ibm rational_quality_manager 6.0.5
ibm rational_collaborative_lifecycle_management 6.0.0
ibm rational_quality_manager 6.0.3
ibm rational_quality_manager 6.0.4
ibm rational_collaborative_lifecycle_management 6.0.4
CVE-2017-1720 MEDIUM

IBM Notes 8.5 and 9.0 could allow a local attacker to execute arbitrary commands by carefully crafting a command line sent via the shared memory IPC. IBM X-Force ID: 134807.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-77,

Products Affected

Vendor Product Version
ibm client_application_access 1.0.1.0
ibm notes 8.5.0.0
ibm notes 8.5.3.0
ibm notes 8.5.2.0
ibm notes 9.0.0.0
ibm client_application_access 1.0.1.1
ibm notes 8.5.1.0
ibm notes 9.0.1.0
ibm client_application_access 1.0.1.2
CVE-2017-1721 MEDIUM

IBM Security QRadar SIEM 7.2 and 7.3 could allow an unauthenticated user to execute code remotely with lower level privileges under unusual circumstances. IBM X-Force ID: 134810.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-94,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.8
ibm qradar_security_information_and_event_manager 7.3.0
ibm qradar_security_information_and_event_manager *
CVE-2017-1722 MEDIUM

IBM Security QRadar SIEM 7.2 and 7.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 134811.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.8
ibm qradar_security_information_and_event_manager 7.3.0
ibm qradar_security_information_and_event_manager *
CVE-2017-1723 MEDIUM

IBM Security QRadar SIEM 7.2 and 7.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 134812.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm qradar_network_insights *
ibm qradar_incident_forensics *
ibm qradar_incident_forensics 7.3.0
ibm qradar_security_information_and_event_manager 7.2.8
ibm qradar_incident_forensics 7.2.8
ibm qradar_incident_forensics 7.3.1
ibm qradar_network_insights 7.2.8
ibm qradar_security_information_and_event_manager *
ibm qradar_security_information_and_event_manager 7.3.1
ibm qradar_security_information_and_event_manager 7.3.0
ibm qradar_network_insights 7.3.0
ibm qradar_network_insights 7.3.1
CVE-2017-1724 LOW

IBM Security QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 134814.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm qradar_risk_manager 7.3.0
ibm qradar_network_insights *
ibm qradar_risk_manager *
ibm qradar_incident_forensics *
ibm qradar_incident_forensics 7.3.0
ibm qradar_security_information_and_event_manager 7.2.8
ibm qradar_incident_forensics 7.2.8
ibm qradar_incident_forensics 7.3.1
ibm qradar_network_insights 7.2.8
ibm qradar_risk_manager 7.3.1
ibm qradar_security_information_and_event_manager *
ibm qradar_risk_manager 7.2.8
ibm qradar_vulnerability_manager *
ibm qradar_vulnerability_manager 7.3.1
ibm qradar_security_information_and_event_manager 7.3.1
ibm qradar_security_information_and_event_manager 7.3.0
ibm qradar_vulnerability_manager 7.2.8
ibm qradar_network_insights 7.3.0
ibm qradar_vulnerability_manager 7.3.0
ibm qradar_network_insights 7.3.1
CVE-2017-1725 MEDIUM

IBM Jazz Team Server affecting the following IBM Rational Products: Collaborative Lifecycle Management (CLM), Rational DOORS Next Generation (RDNG), Rational Engineering Lifecycle Manager (RELM), Rational Team Concert (RTC), Rational Quality Manager (RQM), Rational Rhapsody Design Manager (Rhapsody DM), and Rational Software Architect (RSA DM) contain an undisclosed vulnerability with the potential for information disclosure. IBM X-Force ID: 134820.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
ibm rational_engineering_lifecycle_manager *
ibm rational_rhapsody_design_manager *
ibm rational_collaborative_lifecycle_management *
ibm rational_software_architect_design_manager *
ibm rational_doors_next_generation *
ibm rational_team_concert *
CVE-2017-1727 MEDIUM

IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 discloses sensitive information in error messages that could aid an attacker in further attacks against the system. IBM X-Force ID: 134869.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-532,

Products Affected

Vendor Product Version
ibm security_key_lifecycle_manager 2.5.0.5
ibm security_key_lifecycle_manager 2.5.0.8
ibm security_key_lifecycle_manager 2.7.0
ibm security_key_lifecycle_manager 2.7.0.2
ibm security_key_lifecycle_manager 2.5.0.0
ibm security_key_lifecycle_manager 2.5.0.1
ibm security_key_lifecycle_manager 2.5.0.3
ibm security_key_lifecycle_manager 2.6.0
ibm security_key_lifecycle_manager 2.5.0.7
ibm security_key_lifecycle_manager 2.7.0.1
ibm security_key_lifecycle_manager 2.6.0.3
ibm security_key_lifecycle_manager 2.5.0.6
ibm security_key_lifecycle_manager 2.5.0.2
ibm security_key_lifecycle_manager 2.5.0.4
ibm security_key_lifecycle_manager 2.6.0.1
ibm security_key_lifecycle_manager 2.6.0.2
CVE-2017-1729 LOW

IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 134909.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
CVE-2017-1731 MEDIUM

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could provide weaker than expected security when using the Administrative Console. An authenticated remote attacker could exploit this vulnerability to possibly gain elevated privileges.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_application_server *
CVE-2017-1732 MEDIUM

IBM Security Access Manager for Enterprise Single Sign-On 8.2.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 134913.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_access_manager_for_enterprise_single_sign-on 8.2.2
CVE-2017-1733 LOW

IBM QRadar 7.3 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 134914.

CVSS 2.0

Severity: LOW

Problem Type: CWE-532,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.3.1
ibm qradar_security_information_and_event_manager 7.3.0
CVE-2017-1734 MEDIUM

IBM Jazz Team Server affecting the following IBM Rational Products: Collaborative Lifecycle Management (CLM), Rational DOORS Next Generation (RDNG), Rational Engineering Lifecycle Manager (RELM), Rational Team Concert (RTC), Rational Quality Manager (RQM), Rational Rhapsody Design Manager (Rhapsody DM), and Rational Software Architect (RSA DM) stores potentially sensitive information in a cache that could be read by authenticated users. IBM X-Force ID: 134915.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
ibm rational_engineering_lifecycle_manager *
ibm rational_rhapsody_design_manager *
ibm rational_collaborative_lifecycle_management *
ibm rational_software_architect_design_manager *
ibm rational_doors_next_generation *
ibm rational_team_concert *
CVE-2017-1738 LOW

IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 contains an undisclosed vulnerability that would allow an authenticated user to obtain elevated privileges. IBM X-Force ID: 134919.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
CVE-2017-1739 LOW

IBM Curam Social Program Management 6.0.5, 6.1.1, 6.2.0, and 7.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 134921.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm curam_social_program_management 6.1.0.2
ibm curam_social_program_management 6.1.0.4
ibm curam_social_program_management 6.0.5.9
ibm curam_social_program_management 6.1.0.1
ibm curam_social_program_management 6.1.1.5
ibm curam_social_program_management 6.2.0.3
ibm curam_social_program_management 6.0.5.10
ibm curam_social_program_management 6.2.0.5
ibm curam_social_program_management 6.0.5.5
ibm curam_social_program_management 6.2.0.0
ibm curam_social_program_management 6.0.5.2
ibm curam_social_program_management 6.0.5.1
ibm curam_social_program_management 6.2.0.6
ibm curam_social_program_management 6.2.0.2
ibm curam_social_program_management 6.1.1.2
ibm curam_social_program_management 7.0.1.1
ibm curam_social_program_management 6.0.5.3
ibm curam_social_program_management 6.2.0.1
ibm curam_social_program_management 7.0.0.1
ibm curam_social_program_management 6.1.0.5
ibm curam_social_program_management 6.0.5.4
ibm curam_social_program_management 7.0.0.2
ibm curam_social_program_management 6.1.0.3
ibm curam_social_program_management 6.1.1.6
ibm curam_social_program_management 6.0.5.0
ibm curam_social_program_management 6.1.1.0
ibm curam_social_program_management 6.1.1.3
ibm curam_social_program_management 6.2.0.4
ibm curam_social_program_management 6.0.5.8
ibm curam_social_program_management 6.0.5.7
ibm curam_social_program_management 7.0.1.0
ibm curam_social_program_management 6.0.5.6
ibm curam_social_program_management 6.1.0.0
ibm curam_social_program_management 6.1.1.4
ibm curam_social_program_management 6.1.1.1
ibm curam_social_program_management 7.0.0.0
CVE-2017-1740 LOW

IBM Curam Social Program Management 6.0.5, 6.1.1, 6.2.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 134922.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm curam_social_program_management 6.1.0.2
ibm curam_social_program_management 6.1.0.4
ibm curam_social_program_management 6.0.5.9
ibm curam_social_program_management 6.1.0.1
ibm curam_social_program_management 6.1.1.5
ibm curam_social_program_management 6.2.0.3
ibm curam_social_program_management 6.0.5.10
ibm curam_social_program_management 6.2.0.5
ibm curam_social_program_management 6.0.5.5
ibm curam_social_program_management 6.2.0.0
ibm curam_social_program_management 6.0.5.2
ibm curam_social_program_management 6.0.5.1
ibm curam_social_program_management 6.2.0.6
ibm curam_social_program_management 6.2.0.2
ibm curam_social_program_management 6.1.1.2
ibm curam_social_program_management 7.0.1.1
ibm curam_social_program_management 6.0.5.3
ibm curam_social_program_management 6.2.0.1
ibm curam_social_program_management 7.0.0.1
ibm curam_social_program_management 6.1.0.5
ibm curam_social_program_management 6.0.5.4
ibm curam_social_program_management 7.0.0.2
ibm curam_social_program_management 6.1.0.3
ibm curam_social_program_management 6.0.5
ibm curam_social_program_management 6.1.1.6
ibm curam_social_program_management 6.0.5.0
ibm curam_social_program_management 6.1.1.0
ibm curam_social_program_management 6.1.1.3
ibm curam_social_program_management 6.2.0.4
ibm curam_social_program_management 6.0.5.8
ibm curam_social_program_management 7.0.2.0
ibm curam_social_program_management 6.0.5.7
ibm curam_social_program_management 7.0.1.0
ibm curam_social_program_management 6.0.5.6
ibm curam_social_program_management 6.1.0.0
ibm curam_social_program_management 6.1.1.4
ibm curam_social_program_management 6.1.1.1
ibm curam_social_program_management 7.0.0.0
CVE-2017-1741 MEDIUM

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sensitive information caused by improper handling of Administrative Console panel fields. When exploited an attacker could read files on the file system. IBM X-Force ID: 134931.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_application_server 9.0
ibm websphere_application_server 7.0
ibm websphere_application_server 8.0
ibm websphere_application_server 8.5
CVE-2017-1743 MEDIUM

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sensitive information caused by improper handling of Administrative Console panel fields. When exploited an attacker could browse the file system. IBM X-Force ID: 134933.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_application_server 9.0
ibm websphere_application_server 7.0
ibm websphere_application_server 8.0
ibm websphere_application_server 8.5
CVE-2017-1746 MEDIUM

IBM Jazz for Service Management (IBM Tivoli Components 1.1.3) is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 135519.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm jazz_for_service_management 1.1.3
CVE-2017-1747 MEDIUM

A specially crafted message could cause a denial of service in IBM WebSphere MQ 9.0, 9.0.0.1, 9.0.0.2, 9.0.1, 9.0.2, 9.0.3, and 9.0.4 applications consuming messages that it needs to perform data conversion on. IBM X-Force ID: 135520.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm websphere_mq 9.0
ibm websphere_mq 9.0.3
ibm websphere_mq 9.0.1
ibm websphere_mq 9.0.0.1
ibm websphere_mq 9.0.4
ibm websphere_mq 9.0.2
ibm websphere_mq 9.0.0.2
CVE-2017-1748 MEDIUM

IBM Connections 5.0, 5.5, and 6.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 135521.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-601,

Products Affected

Vendor Product Version
ibm connections 5.0.0.0
ibm connections 5.5.0.0
ibm connections 6.0
CVE-2017-1749 MEDIUM

IBM UrbanCode Deploy 6.1 through 6.9.6.0 could allow a remote attacker to traverse directories on the system. An unauthenticated attacker could alter UCD deployments. IBM X-Force ID: 135522.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm urbancode_deploy *
CVE-2017-1750 LOW

IBM Jazz Reporting Service (JRS) 5.0 through 5.0.2 and 6.0 through 6.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 135523.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm jazz_reporting_service 6.0.3
ibm jazz_reporting_service 6.0.5
ibm jazz_reporting_service 5.0.2
ibm jazz_reporting_service 6.0
ibm jazz_reporting_service 6.0.2
ibm jazz_reporting_service 6.0.1
ibm jazz_reporting_service 5.0
ibm jazz_reporting_service 5.0.1
ibm jazz_reporting_service 6.0.4
CVE-2017-1751 LOW

IBM Robotic Process Automation with Automation Anywhere 10.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 135546.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm robotic_process_automation_with_automation_anywhere 10.0.0
CVE-2017-1752 MEDIUM

IBM UrbanCode Deploy 6.1 and 6.2 could allow an authenticated privileged user to obtain highly sensitive information. IBM X-Force ID: 135547.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm urbancode_deploy *
CVE-2017-1753 LOW

Multiple IBM Rational products are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 135655.

CVSS 2.0

Severity: LOW

Problem Type: CWE-94,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
ibm rational_engineering_lifecycle_manager *
ibm rational_rhapsody_design_manager *
ibm rational_software_architect_design_manager *
ibm rational_doors_next_generation *
ibm rational_team_concert *
CVE-2017-1755 MEDIUM

IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 could allow a local attacker to inject commands into malicious files that could be executed by the administrator. IBM X-Force ID: 135855.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm security_identity_governance_and_intelligence 5.2
ibm security_identity_governance_and_intelligence 5.2.2
ibm security_identity_governance_and_intelligence 5.2.2.1
ibm security_identity_governance_and_intelligence 5.2.1
ibm security_identity_governance_and_intelligence 5.2.3.1
ibm security_identity_governance_and_intelligence 5.2.3.2
ibm security_identity_governance_and_intelligence 5.2.3
CVE-2017-1756 LOW

IBM Business Process Manager 8.6 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 135856.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm business_process_manager 8.0.1.2
ibm business_process_manager 8.5.6.0
ibm business_process_manager 8.0.1.1
ibm websphere 7.2.0.4
ibm business_process_manager 7.5.1.0
ibm websphere 7.2.0.0
ibm business_process_manager 8.0.1.0
ibm business_process_manager 7.5.1.2
ibm business_process_manager_enterprise_service_bus 8.6.0.0
ibm business_process_manager 8.0.0.0
ibm business_process_manager 8.5.7.0
ibm business_process_manager 8.0.1.3
ibm websphere 7.2.0.2
ibm business_process_manager 7.5.0.1
ibm business_process_manager 8.5.6.1
ibm business_process_manager 8.5.0.2
ibm business_process_manager 7.5.1.1
ibm websphere 7.2.0.1
ibm websphere 7.2.0.3
ibm business_process_manager 8.5.6.2
ibm business_process_manager 8.5.5.0
ibm websphere 7.2.0.5
ibm business_process_manager 8.5.0.1
ibm business_process_manager 8.6.0.0
ibm business_process_manager 8.5.0.0
ibm business_process_manager 7.5.0.0
CVE-2017-1757 MEDIUM

IBM Security Guardium 10.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 135858.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm security_guardium 10.0.1
ibm security_guardium 10.0
ibm security_guardium 10.1.3
ibm security_guardium 10.1.2
ibm security_guardium 10.1.0
CVE-2017-1758 MEDIUM

IBM Financial Transaction Manager for ACH Services for Multi-Platform (IBM Control Center 6.0 and 6.1, IBM Financial Transaction Manager 3.0.2, 3.0.3, 3.0.4, and 3.1.0, IBM Transformation Extender Advanced 9.0) is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 135859.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm transformation_extender_advanced 9.0
ibm financial_transaction_manager 3.0.2.0
ibm control_center 6.1.1.0
ibm financial_transaction_manager 3.0.4.0
ibm control_center 6.0.0.1
ibm control_center 6.0.0.0
ibm financial_transaction_manager 3.0.2.1
ibm control_center 6.1.0.0
ibm financial_transaction_manager 3.0.3.0
ibm control_center 6.1.0.1
ibm financial_transaction_manager 3.1.0.0
CVE-2017-1760 LOW

IBM WebSphere MQ 7.5, 8.0, and 9.0 could allow a local user to crash the queue manager agent thread and expose some sensitive information. IBM X-Force ID: 126454.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_mq 9.0
ibm websphere_mq 9.0.3
ibm websphere_mq 7.5.0.4
ibm websphere_mq 7.5.0.1
ibm websphere_mq 8.0.0.3
ibm websphere_mq 8.0.0.4
ibm websphere_mq 7.5.0.7
ibm websphere_mq 9.0.0.1
ibm websphere_mq 7.5
ibm websphere_mq 8.0.0.2
ibm websphere_mq 7.5.0.2
ibm websphere_mq 8.0.0.6
ibm websphere_mq 8.0.0.5
ibm websphere_mq 8.0.0.1
ibm websphere_mq 7.5.0.3
ibm websphere_mq 9.0.1
ibm websphere_mq 7.5.0.5
ibm websphere_mq 7.5.0.8
ibm websphere_mq 8.0
ibm websphere_mq 9.0.2
ibm websphere_mq 7.5.0.6
CVE-2017-1761 MEDIUM

IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 136005.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.1
ibm websphere_portal 8.0.0.0
ibm websphere_portal 7.0.0.2
ibm websphere_portal 8.5.0.0
ibm websphere_portal 7.0.0.0
ibm websphere_portal 9.0.0.0
CVE-2017-1762 LOW

IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 136006.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
ibm rational_engineering_lifecycle_manager *
ibm rational_rhapsody_design_manager *
ibm rational_collaborative_lifecycle_management *
ibm rational_software_architect_design_manager *
ibm rational_doors_next_generation *
ibm rational_team_concert *
CVE-2017-1764 LOW

IBM Cognos Business Intelligence 10.2, 10.2.1, 10.2.1.1, and 10.2.2, under specialized circumstances, could expose plain text credentials to a local user. IBM X-Force ID: 136149.

CVSS 2.0

Severity: LOW

Problem Type: CWE-522,

Products Affected

Vendor Product Version
ibm cognos_business_intelligence 10.2.1
ibm cognos_business_intelligence 10.2
ibm cognos_business_intelligence 10.2.1.1
ibm cognos_business_intelligence 10.2.2
CVE-2017-1765 MEDIUM

IBM Business Process Manager 8.6 could allow an authenticated user with special privileges to reveal sensitive information about the application server. IBM X-Force ID: 136150.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm business_process_manager 8.0.1.2
ibm business_process_manager 8.5.6.0
ibm business_process_manager 8.0.1.1
ibm business_process_manager 8.5.6.1
ibm business_process_manager 8.5.0.2
ibm business_process_manager 8.5.6.2
ibm business_process_manager 8.5.5.0
ibm business_process_manager 8.0.1.0
ibm business_process_manager_enterprise_service_bus 8.6.0.0
ibm business_process_manager 8.0.0.0
ibm business_process_manager 8.5.7.0
ibm business_process_manager 8.5.0.1
ibm business_process_manager 8.6.0.0
ibm business_process_manager 8.0.1.3
ibm business_process_manager 8.5.0.0
CVE-2017-1766 MEDIUM

Due to incorrect authorization in IBM Business Process Manager 8.6 an attacker can claim and work on ad hoc tasks he is not assigned to. IBM X-Force ID: 136151.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-863,

Products Affected

Vendor Product Version
ibm business_process_manager 8.5.6.0
ibm business_process_manager 8.5.6.2
ibm business_process_manager 8.5.5.0
ibm business_process_manager 8.5.7.0
ibm business_process_manager 8.5.6.1
ibm business_process_manager 8.6.0.0
CVE-2017-1767 LOW

IBM Business Process Manager 8.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 136152.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm business_process_manager 8.5.6.0
ibm business_process_manager 8.5.6.2
ibm business_process_manager 8.5.5.0
ibm business_process_manager 8.5.7.0
ibm business_process_manager 8.5.6.1
ibm business_process_manager 8.6.0.0
CVE-2017-1768 MEDIUM

IBM Security Guardium Big Data Intelligence (SonarG) 3.1 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 136471.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_guardium_big_data_intelligence 3.1
CVE-2017-17689 MEDIUM

The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
kde trojita -
microsoft outlook 2010
google gmail -
kde kmail -
ibm notes -
emclient emclient -
flipdogsolutions maildroid -
horde horde_imp -
gnome evolution -
microsoft outlook 2007
microsoft outlook 2013
freron mailmate -
r2mail2 r2mail2 -
apple mail -
ritlabs the_bat -
microsoft outlook 2016
bloop airmail -
9folders nine -
postbox-inc postbox -
mozilla thunderbird -
CVE-2017-1769 MEDIUM

IBM Business Process Manager 8.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 136783.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm business_process_manager 8.6.0.0
CVE-2017-1772 MEDIUM

IBM Worklight (IBM MobileFirst Platform Foundation 6.3, 7.0, 7.1, and 8.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 136786.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm mobilefirst_platform_foundation 8.0.0.0
ibm mobilefirst_platform_foundation 6.3.0.0
ibm mobilefirst_platform_foundation 7.0.0.0
ibm mobilefirst_platform_foundation 7.1.0.0
CVE-2017-1773 MEDIUM

IBM DataPower Gateways 7.1, 7,2, 7.5, and 7.6 could allow an attacker using man-in-the-middle techniques to spoof DNS responses to perform DNS cache poisoning and redirect Internet traffic. IBM X-Force ID: 136817.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-345,

Products Affected

Vendor Product Version
ibm datapower_gateway *
CVE-2017-1774 MEDIUM

IBM Security Guardium Big Data Intelligence (SonarG) 3.1 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 136818.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_guardium_big_data_intelligence 3.1
CVE-2017-1779 LOW

IBM Cognos Analytics 11.0 could store cached credentials locally that could be obtained by a local user. IBM X-Force ID: 136824.

CVSS 2.0

Severity: LOW

Problem Type: CWE-522,

Products Affected

Vendor Product Version
ibm cognos_analytics 11.0.5.0
ibm cognos_analytics 11.0.6.0
netapp oncommand_insight -
ibm cognos_analytics 11.0.1
ibm cognos_analytics 11.0.3
ibm cognos_analytics 11.0.7.0
ibm cognos_analytics 11.0.2
ibm cognos_analytics 11.0.0
ibm cognos_analytics 11.0.4
CVE-2017-1783 LOW

IBM Cognos Analytics 11.0 could allow a local user to change parameters set from the Cognos Analytics menus without proper authentication. IBM X-Force ID: 136857.

CVSS 2.0

Severity: LOW

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm cognos_analytics 11.0.5.0
ibm cognos_analytics 11.0.6.0
netapp oncommand_insight -
ibm cognos_analytics 11.0.1
ibm cognos_analytics 11.0.3
ibm cognos_analytics 11.0.7.0
ibm cognos_analytics 11.0.2
ibm cognos_analytics 11.0.0
ibm cognos_analytics 11.0.4
CVE-2017-1784 LOW

IBM Cognos Analytics 11.0 could produce results in temporary files that contain highly sensitive information that can be read by a local user. IBM X-Force ID: 136858.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm cognos_analytics 11.0.5.0
ibm cognos_analytics 11.0.6.0
netapp oncommand_insight -
ibm cognos_analytics 11.0.1
ibm cognos_analytics 11.0.3
ibm cognos_analytics 11.0.7.0
ibm cognos_analytics 11.0.2
ibm cognos_analytics 11.0.0
ibm cognos_analytics 11.0.4
CVE-2017-1785 MEDIUM

IBM API Connect 5.0.7 and 5.0.8 could allow an authenticated remote user to modify query parameters to obtain sensitive information. IBM X-Force ID: 136859.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm api_connect 5.0.7.2
ibm api_connect 5.0.8.1
ibm api_connect 5.0.7.0
ibm api_connect 5.0.7.1
ibm api_connect 5.0.8.0
CVE-2017-1786 LOW

IBM WebSphere MQ 8.0 through 8.0.0.8 and 9.0 through 9.0.4 under special circumstances could allow an authenticated user to consume all resources due to a memory leak resulting in service loss. IBM X-Force ID: 136975.

CVSS 2.0

Severity: LOW

Problem Type: CWE-772,

Products Affected

Vendor Product Version
ibm websphere_mq *
CVE-2017-1787 LOW

IBM Publishing Engine 2.1.2 and 6.0.5 contains an undisclosed vulnerability that could allow a local user with administrative privileges to obtain hard coded user credentials. IBM X-Force ID: 137022.

CVSS 2.0

Severity: LOW

Problem Type: CWE-798,

Products Affected

Vendor Product Version
ibm engineering_lifecycle_optimization_-_publishing 2.1.2
ibm engineering_lifecycle_optimization_-_publishing 6.0.5
CVE-2017-1788 MEDIUM

IBM WebSphere Application Server 9 installations using Form Login could allow a remote attacker to conduct spoofing attacks. IBM X-Force ID: 137031.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_application_server *
CVE-2017-1789 HIGH

IBM Tivoli Monitoring V6 6.2.3 and 6.3.0 could allow an unauthenticated user to remotely execute code through unspecified methods. IBM X-Force ID: 137034.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-94,

Products Affected

Vendor Product Version
ibm tivoli_monitoring 6.3.0.6
ibm tivoli_monitoring 6.2.3
ibm tivoli_monitoring 6.3.0.1
ibm tivoli_monitoring 6.2.3.1
ibm tivoli_monitoring 6.2.3.5
ibm tivoli_monitoring 6.3.0.5
ibm tivoli_monitoring 6.2.3.3
ibm tivoli_monitoring 6.3.0
ibm tivoli_monitoring 6.3.0.3
ibm tivoli_monitoring 6.3.0.7
ibm tivoli_monitoring 6.2.3.2
ibm tivoli_monitoring 6.2.3.4
ibm tivoli_monitoring 6.3.0.2
ibm tivoli_monitoring 6.3.0.4
CVE-2017-1790 LOW

IBM DOORS Next Generation (DNG/RRC) 5.0, 5.0.1, 5.0.2, and 6.0 through 6.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 137035.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_requirements_composer 5.0
ibm rational_requirements_composer 5.0.1
ibm rational_doors_next_generation 6.0.5
ibm rational_doors_next_generation 6.0.3
ibm rational_doors_next_generation 6.0.2
ibm rational_doors_next_generation 6.0.0
ibm rational_requirements_composer 5.0.2
ibm rational_doors_next_generation 6.0.4
ibm rational_doors_next_generation 6.0.1
CVE-2017-1791 LOW

IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 137036.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
CVE-2017-1792 LOW

IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 137037.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
CVE-2017-1793 LOW

IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 137038.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
CVE-2017-1794 MEDIUM

IBM Tivoli Monitoring 6.2.3 through 6.2.3.5 and 6.3.0 through 6.3.0.7 are vulnerable to both TEPS user privilege escalation and possible denial of service due to unconstrained memory growth. IBM X-Force ID: 137039.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-400,

Products Affected

Vendor Product Version
ibm tivoli_monitoring *
CVE-2017-1795 LOW

IBM WebSphere MQ 7.5, 8.0, and 9.0 through 9.0.4 could allow a local user to obtain highly sensitive information via trace logs in IBM WebSphere MQ Managed File Transfer. IBM X-Force ID: 137042.

CVSS 2.0

Severity: LOW

Problem Type: CWE-532,

Products Affected

Vendor Product Version
ibm websphere_mq_managed_file_transfer 9.0.3
ibm websphere_mq_managed_file_transfer 7.5.0.0
ibm websphere_mq_managed_file_transfer *
ibm websphere_mq_managed_file_transfer 9.0.1
ibm websphere_mq_managed_file_transfer 9.0.4
ibm websphere_mq_managed_file_transfer 9.0.2
CVE-2017-3744 MEDIUM

In the IMM2 firmware of Lenovo System x servers, remote commands issued by LXCA or other utilities may be captured in the First Failure Data Capture (FFDC) service log if the service log is generated when that remote command is running. Captured command data may contain clear text login information. Authorized users that can capture and export FFDC service log data may have access to these remote commands.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-532,

Products Affected

Vendor Product Version
ibm integrated_management_module_firmware *
lenovo integrated_management_module_firmware *
CVE-2017-3752 MEDIUM

An industry-wide vulnerability has been identified in the implementation of the Open Shortest Path First (OSPF) routing protocol used on some Lenovo switches. Exploitation of these implementation flaws may result in attackers being able to erase or alter the routing tables of one or many routers, switches, or other devices that support OSPF within a routing domain.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
lenovo g8272_firmware *
ibm g8332_firmware *
ibm layer_2/3_copper_firmware *
lenovo g8264_firmware *
ibm virtual_fabric_10gb *
lenovo g8332_firmware *
lenovo g8052_firmware *
ibm fabric_cn4093_10gb_firmware *
ibm g8264cs_firmware *
lenovo g8124e_firmware *
ibm 1:10g_firmware *
lenovo si4091_firmware *
ibm g8124e_firmware *
ibm g8316_firmware *
ibm 1g_l2-7_slb *
lenovo fabric_cn4093_10gb_firmware *
ibm g8264t_firmware *
ibm en2092_1gb_firmware *
ibm g8124_firmware *
ibm g8264_firmware *
lenovo g8296_firmware *
lenovo fabric_en4093r_10gb_firmware *
ibm g8052_firmware *
lenovo g8264cs_firmware *
ibm fabric_en4093/en4093r_10gb_firmware *
CVE-2017-3768 HIGH

An unprivileged attacker with connectivity to the IMM2 could cause a denial of service attack on the IMM2 (Versions earlier than 4.4 for Lenovo System x and earlier than 6.4 for IBM System x). Flooding the IMM2 with a high volume of authentication failures via the Common Information Model (CIM) used by LXCA and OneCLI and other tools can exhaust available system memory which can cause the IMM2 to reboot itself until the requests cease.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-400,

Products Affected

Vendor Product Version
lenova flex_system_x240_m5_firmware *
lenova flex_system_x480_x6_firmware *
ibm system_x3250_m4_firmware *
lenova flex_system_x880_firmware *
ibm system_x3500_m4_firmware *
ibm system_x3550_m4_firmware *
lenova system_x3750_m4_firmware *
ibm bladecenter_hs22_firmware *
lenova flex_system_x240_m4_firmware *
ibm nextscale_nx360_m4_firmware *
ibm system_x3950_x6_firmware *
ibm system_x3650_m4_bd_firmware *
ibm system_x3650_m4_firmware *
ibm flex_system_x280_m4_firmware *
lenova system_x3850_x6_firmware *
ibm flex_system_x880_m4_firmware *
ibm system_x3650_m4_hd_firmware *
lenova flex_system_x280_x6_firmware *
ibm system_x3750_m4_firmware *
ibm system_x3530_m4_firmware *
lenova system_x3250_m6_firmware *
ibm flex_system_x480_m4_firmware *
ibm system_x3100_m4_firmware *
ibm system_x3630_m4_firmware *
ibm idataplex_dx360_m4_firmware *
ibm system_x3250_m5_firmware *
ibm flex_system_x220_m4_firmware *
lenova flex_system_x440_m4_firmware *
lenova system_x3500_m5_firmware *
lenova system_x3950_x6_firmware *
lenova nextscale_nx360_m5_firmware *
ibm flex_system_x440_m4_firmware *
ibm flex_system_x222_m4_firmware *
ibm flex_system_x240_m4_firmware *
ibm bladecenter_hs23e_firmware *
ibm system_x3100_m5_firmware *
lenova system_x3550_m5_firmware *
ibm idataplex_dx360_m4_water_cooled_firmware *
lenova system_x3650_m5_firmware *
ibm system_x3850_x6_firmware *
ibm system_x3300_m4_firmware *
ibm bladecenter_hs23_firmware *
CVE-2017-5638 HIGH

The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header, as exploited in the wild in March 2017 with a Content-Type header containing a #cmd= string.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 3.9 5.9
134c704f-9b21-4f2e-91b3-4a467353bcc0 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 3.9 5.9

CVSS 2.0

Severity: HIGH

Problem Type: CWE-755,CWE-755,

Products Affected

Vendor Product Version
ibm storwize_v5000_firmware 7.8.1.0
oracle weblogic_server 10.3.6.0.0
oracle weblogic_server 12.2.1.2.0
lenovo storage_v5030_firmware 7.7.1.6
arubanetworks clearpass_policy_manager *
ibm storwize_v5000_firmware 7.7.1.6
ibm storwize_v7000_firmware 7.8.1.0
ibm storwize_v7000_firmware 7.7.1.6
netapp oncommand_balance -
oracle weblogic_server 12.1.3.0.0
hp server_automation 10.1.0
hp server_automation 10.0.0
hp server_automation 10.2.0
oracle weblogic_server 12.2.1.1.0
hp server_automation 10.5.0
apache struts *
ibm storwize_v3500_firmware 7.7.1.6
ibm storwize_v3500_firmware 7.8.1.0
lenovo storage_v5030_firmware 7.8.1.0
hp server_automation 9.1.0
CVE-2018-1000181 MEDIUM

Kitura 2.3.0 and earlier have an unintended read access to unauthorised files and folders that can be exploited by a crafted URL resulting in information disclosure.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm kitura *
CVE-2018-1361 MEDIUM

IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 137158.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 8.5.0.0
ibm websphere_portal 9.0.0.0
CVE-2018-1362 MEDIUM

IBM Curam Social Program Management 6.0.5, 6.1.1, 6.2.0, and 7.0.1 within Citizen Portal could allow an authenticated user to withdraw other user's submitted applications from the system and possibly obtain privileges. IBM X-Force ID: 137380.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm curam_social_program_management 6.0.5
ibm curam_social_program_management 7.0.1
ibm curam_social_program_management 6.1.1.0
ibm curam_social_program_management 6.2.0.0
CVE-2018-1363 LOW

IBM Jazz Reporting Service (JRS) 5.0 through 5.0.2 and 6.0 through 6.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 137448.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm jazz_reporting_service 6.0.3
ibm jazz_reporting_service 6.0.5
ibm jazz_reporting_service 5.0.2
ibm jazz_reporting_service 6.0
ibm jazz_reporting_service 6.0.2
ibm jazz_reporting_service 6.0.1
ibm jazz_reporting_service 5.0
ibm jazz_reporting_service 5.0.1
ibm jazz_reporting_service 6.0.4
CVE-2018-1364 MEDIUM

IBM Content Navigator 2.0 and 3.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 137449.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm content_navigator 3.0.2
ibm content_navigator 3.0.3
ibm content_navigator 2.0.3
CVE-2018-1366 MEDIUM

IBM Content Navigator 2.0 and 3.0 is vulnerable to Comma Separated Value (CSV) Injection. An attacker could exploit this vulnerability to exploit other vulnerabilities in spreadsheet software. IBM X-Force ID: 137452.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm content_navigator 3.0.1
ibm content_navigator 3.0.0
ibm content_navigator 3.0.2
ibm content_navigator 2.0.2.7
ibm content_navigator 3.0.3
ibm content_navigator 2.0.2.8
CVE-2018-1368 LOW

IBM Security Guardium Database Activity Monitor 9.0, 9.1, and 9.5 could allow a local user with low privileges to view report pages and perform some actions that only an admin should be performing, so there is risk that someone not authorized can change things that they are not suppose to. IBM X-Force ID: 137765.

CVSS 2.0

Severity: LOW

Problem Type: CWE-269,

Products Affected

Vendor Product Version
ibm security_guardium_database_activity_monitor 9.1
ibm security_guardium_database_activity_monitor 9.0
ibm security_guardium_database_activity_monitor 9.5
CVE-2018-1369 MEDIUM

IBM Security Guardium Big Data Intelligence (SonarG) 3.1 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 137767.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_guardium_big_data_intelligence 3.1
CVE-2018-1370 MEDIUM

IBM Security Guardium Big Data Intelligence (SonarG) 3.1 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. IBM X-Force ID: 137769.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-732,

Products Affected

Vendor Product Version
ibm security_guardium_big_data_intelligence 3.1
CVE-2018-1371 MEDIUM

An IBM WebSphere MQ 8.0.0.8, 9.0.0.2, and 9.0.4 Client connecting to a MQ Queue Manager can cause a SIGSEGV in the AMQRMPPA channel process terminating it. IBM X-Force ID: 137771.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_mq 8.0.0.8
ibm websphere_mq 9.0.4
ibm websphere_mq 9.0.0.2
CVE-2018-1372 MEDIUM

IBM Security Guardium Big Data Intelligence (SonarG) 3.1 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 137772.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-521,

Products Affected

Vendor Product Version
ibm security_guardium_big_data_intelligence 3.1
CVE-2018-1373 MEDIUM

IBM Security Guardium Big Data Intelligence (SonarG) 3.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 137773.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-307,

Products Affected

Vendor Product Version
ibm security_guardium_big_data_intelligence 3.1
CVE-2018-1374 MEDIUM

An IBM WebSphere MQ (Maintenance levels 7.1.0.0 - 7.1.0.9, 7.5.0.0 - 7.5.0.8, 8.0.0.0 - 8.0.0.8, 9.0.0.0 - 9.0.0.2, and 9.0.0 - 9.0.4) client connecting to a Queue Manager could cause a SIGSEGV in the Channel process amqrmppa. IBM X-Force ID: 137775.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm websphere_mq 8.0.0.0
ibm websphere_mq 7.5.0.1
ibm websphere_mq 8.0.0.3
ibm websphere_mq 8.0.0.4
ibm websphere_mq 7.5
ibm websphere_mq 7.1.0.7
ibm websphere_mq 7.1.0.8
ibm websphere_mq 8.0.0.2
ibm websphere_mq 7.5.0.2
ibm websphere_mq 8.0.0.5
ibm websphere_mq 8.0.0.1
ibm websphere_mq 7.1.0.5
ibm websphere_mq 7.5.0.3
ibm websphere_mq 7.1.0.4
ibm websphere_mq 7.1.0.6
ibm websphere_mq 9.0.0.0
ibm websphere_mq 7.1.0.2
ibm websphere_mq 9.0.4
ibm websphere_mq 7.1.0.9
ibm websphere_mq 9.0.3
ibm websphere_mq 7.1.0.3
ibm websphere_mq 7.5.0.4
ibm websphere_mq 9.0.0.1
ibm websphere_mq 8.0.0.7
ibm websphere_mq 7.1
ibm websphere_mq 8.0.0.8
ibm websphere_mq 9.0.0.2
ibm websphere_mq 8.0.0.6
ibm websphere_mq 9.0.0
ibm websphere_mq 7.1.0.1
ibm websphere_mq 9.0.1
ibm websphere_mq 9.0.2
CVE-2018-1375 MEDIUM

IBM Security Guardium Big Data Intelligence (SonarG) 3.1 does not renew a session variable after a successful authentication which could lead to session fixation/hijacking vulnerability. This could force a user to utilize a cookie that may be known to an attacker. IBM X-Force ID: 137776.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-384,

Products Affected

Vendor Product Version
ibm security_guardium_big_data_intelligence 3.1
CVE-2018-1376 MEDIUM

IBM Security Guardium Big Data Intelligence (SonarG) 3.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 137777.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm security_guardium_big_data_intelligence 3.1
CVE-2018-1377 LOW

IBM Security Guardium Big Data Intelligence (SonarG) 3.1 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 137778.

CVSS 2.0

Severity: LOW

Problem Type: CWE-522,

Products Affected

Vendor Product Version
ibm security_guardium_big_data_intelligence 3.1
CVE-2018-1380 MEDIUM

IBM InfoSphere Master Data Management Collaboration Server 11.4, 11.5, and 11.6 could allow an authenticated user with CA level access to change change their ca-id to another users and read sensitive information. IBM X-Force ID: 138077.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm infosphere_master_data_management 11.4
ibm infosphere_master_data_management 11.5
ibm infosphere_master_data_management 11.6
CVE-2018-1382 LOW

IBM API Connect 5.0.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138079.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm api_connect 5.0.7.2
ibm api_connect 5.0.8.1
ibm api_connect *
ibm api_connect 5.0.7.0
ibm api_connect 5.0.7.1
ibm api_connect 5.0.8.0
CVE-2018-1383 HIGH

A software logic bug creates a vulnerability in an AIX 6.1, 7.1, and 7.2 daemon which could allow a user with root privileges on one system, to obtain root access on another machine. IBM X-force ID: 138117.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm aix 7.2
ibm aix 6.1.8
ibm aix 6.1.3
ibm aix 7.1.2
ibm aix 7.1.4
ibm aix 6.1
ibm aix 7.2.1
ibm aix 7.1
ibm aix 7.1.5
ibm aix 7.2.2
ibm aix 7.1.1
ibm aix 6.1.9
ibm aix 6.1.1
ibm aix 6.1.7
ibm aix 6.1.2
ibm aix 6.1.5
ibm aix 6.1.4
ibm aix 6.1.6
ibm aix 7.1.3
CVE-2018-1384 LOW

IBM Business Process Manager 8.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138135.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm business_process_manager 8.0.1.2
ibm business_process_manager 8.5.6.0
ibm business_process_manager 8.0.1.1
ibm websphere_process_server 7.0.0.4
ibm websphere_enterprise_service_bus 7.0.0.4
ibm business_process_manager 7.5.1.0
ibm websphere_enterprise_service_bus 7.0.0.5
ibm websphere_process_server 7.0.0.2
ibm websphere_process_server 7.0.0.3
ibm business_process_manager 8.0.1.0
ibm business_process_manager 7.5.1.2
ibm business_process_manager_enterprise_service_bus 8.6.0.0
ibm websphere_enterprise_service_bus 7.0.0.2
ibm business_process_manager 8.0.0.0
ibm business_process_manager 8.5.7.0
ibm business_process_manager 8.0.1.3
ibm websphere_enterprise_service_bus 7.0.0.1
ibm websphere_enterprise_service_bus 7.5.1.2
ibm websphere_enterprise_service_bus 7.5.0.0
ibm business_process_manager 7.5.0.1
ibm websphere_enterprise_service_bus 7.0.0.0
ibm websphere_process_server 7.0.0.1
ibm business_process_manager 8.5.6.1
ibm websphere_enterprise_service_bus 7.5.1.0
ibm business_process_manager 8.5.0.2
ibm business_process_manager 7.5.1.1
ibm websphere_enterprise_service_bus 7.5.1.1
ibm business_process_manager 8.5.6.2
ibm business_process_manager 8.5.5.0
ibm websphere_process_server 7.0.0.5
ibm business_process_manager 8.5.0.1
ibm business_process_manager 8.6.0.0
ibm business_process_manager 8.5.0.0
ibm websphere_enterprise_service_bus 7.5.0.1
ibm websphere_process_server 7.0
ibm websphere_enterprise_service_bus 7.0.0.3
ibm business_process_manager 7.5.0.0
CVE-2018-1386 MEDIUM

IBM Tivoli Workload Automation for AIX (IBM Workload Scheduler 8.6, 9.1, 9.2, 9.3, and 9.4) contains directories with improper permissions that could allow a local user to with special access to gain root privileges. IBM X-Force ID: 138208.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 1.8 5.9

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-732,

Products Affected

Vendor Product Version
ibm tivoli_workload_scheduler 9.3
ibm tivoli_workload_scheduler 9.4
ibm tivoli_workload_scheduler 9.2
ibm tivoli_workload_scheduler 8.6
ibm tivoli_workload_scheduler 9.1
CVE-2018-1387 MEDIUM

IBM Application Performance Management for Monitoring & Diagnostics (IBM Monitoring 8.1.3 and 8.1.4) may release sensitive personal data to the staff who can access to the database of this product. IBM X-Force ID: 138210.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm application_performance_management 8.1.4.0
ibm monitoring 8.1.3.0
ibm monitoring 8.1.4.0
ibm cloud_apm_data_collector 7.4
ibm cloud_apm_data_collector 7.3
CVE-2018-1388 MEDIUM

GSKit V7 may disclose side channel information via discrepancies between valid and invalid PKCS#1 padding. IBM X-Force ID: 138212.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_mq 7.0.1.0
ibm websphere_mq 7.0.1.7
ibm websphere_mq 7.0.1.5
ibm websphere_mq 7.0.1.12
ibm websphere_mq 7.0.1.1
ibm websphere_mq 7.0.1.3
ibm websphere_mq 7.0.1.8
ibm websphere_mq 7.0.1.10
ibm websphere_mq 7.0.1.11
ibm websphere_mq 7.0.1.4
ibm websphere_mq 7.0.1.2
ibm websphere_mq 7.0.1.13
ibm websphere_mq 7.0.1.14
ibm websphere_mq 7.0.1.9
ibm websphere_mq 7.0.1.6
CVE-2018-1389 MEDIUM

IBM API Connect 5.0.0.0 through 5.0.8.2 is impacted by generated LoopBack APIs for a Model using the BelongsTo/HasMany relationship allowing unauthorized modification of information. IBM X-Force ID: 138213.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm api_connect *
CVE-2018-1390 LOW

IBM Financial Transaction Manager for Check Services for Multi-Platform 3.0, 3.0.2, and 3.0.2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138221.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm financial_transaction_manager 3.0.5.0
ibm financial_transaction_manager 3.0.2.0
ibm financial_transaction_manager 3.0.2.1
ibm financial_transaction_manager 3.0.0.0
CVE-2018-1391 MEDIUM

IBM Financial Transaction Manager 3.0.4 and 3.1.0 for ACH Services for Multi-Platform could allow an authenticated user to execute a specially crafted command that could cause a denial of service. IBM X-Force ID: 138376.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm financial_transaction_manager 3.0.4.0
ibm financial_transaction_manager 3.1.0.0
CVE-2018-1392 LOW

IBM Financial Transaction Manager 3.0.4 and 3.1.0 for ACH Services for Multi-Platform could allow an authenticated user to execute a specially crafted command that could obtain sensitive information. IBM X-Force ID: 138377.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm financial_transaction_manager 3.0.4.0
ibm financial_transaction_manager 3.1.0.0
CVE-2018-1393 MEDIUM

IBM Financial Transaction Manager for ACH Services for Multi-Platform 3.0.6 could allow an authenticated user to execute a specially crafted command that could obtain sensitive information. IBM X-Force ID: 138378.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm financial_transaction_manager 3.0.6.0
CVE-2018-1394 LOW

Multiple IBM Rational products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138425.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
ibm rational_engineering_lifecycle_manager *
ibm rational_rhapsody_design_manager *
ibm rational_software_architect_design_manager *
ibm rational_doors_next_generation *
ibm rational_team_concert *
CVE-2018-1395 LOW

IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138427.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
CVE-2018-1396 LOW

IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138429.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
CVE-2018-1398 MEDIUM

IBM Sterling File Gateway 2.2.0 through 2.2.6 could allow a remote attacker to download certain files that could contain sensitive information. IBM X-Force ID: 138434.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm sterling_file_gateway *
CVE-2018-1399 LOW

IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5 and 5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138435.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm daeja_viewone 4.1.5
ibm daeja_viewone 5.0.2
ibm daeja_viewone 5.0.1
ibm daeja_viewone 5.0.3
CVE-2018-1401 MEDIUM

IBM WebSphere Portal 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138437.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.0
ibm websphere_portal 8.5.0.0
ibm websphere_portal 9.0.0.0
CVE-2018-1403 LOW

IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138439.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
CVE-2018-1404 LOW

IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138440.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
CVE-2018-1405 LOW

IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138441.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
CVE-2018-1407 LOW

IBM Rational Team Concert 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138445.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_team_concert *
CVE-2018-1408 LOW

IBM Rational Team Concert 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138446.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_team_concert *
CVE-2018-1409 HIGH

IBM Notes Diagnostics (IBM Client Application Access and IBM Notes) could allow a local user to execute commands on the system. By crafting a command line sent via the shared memory IPC, which could be tricked into executing an executable chosen by the attacker. IBM X-Force ID: 138708.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm client_application_access 1.0.0.1
ibm notes 9.0.1.9
ibm notes 8.5.1.5
ibm notes 8.5.3.6
ibm notes 8.5.2.4
ibm notes 9.0
ibm client_application_access 1.0.1.2
ibm client_application_access 1.0.1
CVE-2018-1410 MEDIUM

IBM Notes Diagnostics (IBM Client Application Access and IBM Notes) could allow a local user to execute commands on the system. By crafting a command line sent via the shared memory IPC, which could be tricked into executing an executable chosen by the attacker. IBM X-Force ID: 138709.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm client_application_access 1.0.0.1
ibm notes 9.0.1.9
ibm notes 8.5.1.5
ibm notes 8.5.3.6
ibm notes 8.5.2.4
ibm notes 9.0
ibm client_application_access 1.0.1.2
ibm client_application_access 1.0.1
CVE-2018-1411 HIGH

IBM Notes Diagnostics (IBM Client Application Access and IBM Notes) could allow a local user to execute commands on the system. By crafting a command line sent via the shared memory IPC, which could be tricked into executing an executable chosen by the attacker. IBM X-Force ID: 138710.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm client_application_access 1.0.0.1
ibm notes 9.0.1.9
ibm notes 8.5.1.5
ibm notes 8.5.3.6
ibm notes 8.5.2.4
ibm notes 9.0
ibm client_application_access 1.0.1.2
ibm client_application_access 1.0.1
CVE-2018-1413 LOW

IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138819.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
netapp oncommand_insight -
ibm cognos_analytics *
CVE-2018-1414 MEDIUM

IBM Maximo Asset Management 7.5 and 7.6 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 138820.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm maximo_asset_management_essentials 7.5.0.0
ibm maximo_asset_management 7.6.0.0
ibm maximo_asset_management 7.5.0.0
CVE-2018-1415 LOW

IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138821.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm maximo_asset_management 7.6.0.8
ibm maximo_asset_management 7.6.0.5
ibm maximo_asset_management 7.6.0.6
ibm maximo_asset_management 7.6.0.7
CVE-2018-1416 MEDIUM

IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138822.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.1
ibm websphere_portal 8.0.0.0
ibm websphere_portal 7.0.0.2
ibm websphere_portal 8.5.0.0
ibm websphere_portal 7.0.0.1
ibm websphere_portal 7.0.0.0
ibm websphere_portal 9.0.0.0
CVE-2018-1417 MEDIUM

Under certain circumstances, a flaw in the J9 JVM (IBM SDK, Java Technology Edition 7.1 and 8.0) allows untrusted code running under a security manager to elevate its privileges. IBM X-Force ID: 138823.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-732,

Products Affected

Vendor Product Version
ibm java_sdk 6.1.0.0
ibm java_sdk 7.1.0.0
ibm java_sdk 8.0.0.0
ibm java_sdk 6.0.0.0
ibm java_sdk 7.0.0.0
CVE-2018-1418 MEDIUM

IBM Security QRadar SIEM 7.2 and 7.3 could allow a user to bypass authentication which could lead to code execution. IBM X-Force ID: 138824.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.8
ibm qradar_security_information_and_event_manager 7.3.1
ibm qradar_security_information_and_event_manager 7.3.0
ibm qradar_security_information_and_event_manager *
CVE-2018-1419 LOW

IBM WebSphere MQ 8.0 and 9.0, when configured to use a PAM module for authentication, could allow a user to cause a deadlock in the IBM MQ PAM code which could result in a denial of service. IBM X-Force ID: 138949.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_mq 9.0
ibm websphere_mq 9.0.3
ibm websphere_mq 8.0.0.3
ibm websphere_mq 8.0.0.4
ibm websphere_mq 9.0.0.1
ibm websphere_mq 8.0.0.7
ibm websphere_mq 8.0.0.8
ibm websphere_mq 8.0.0.2
ibm websphere_mq 9.0.0.2
ibm websphere_mq 8.0.0.6
ibm websphere_mq 8.0.0.5
ibm websphere_mq 8.0.0.1
ibm websphere_mq 9.0.1
ibm websphere_mq 8.0
ibm websphere_mq 9.0.4
ibm websphere_mq 9.0.2
CVE-2018-1420 MEDIUM

IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 resets access control settings to the out of the box configuration during Combined Cumulative Fix (CF) installation. This can lead to security miss-configuration of the installation. IBM X-Force ID: 138950.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-732,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.1
ibm websphere_portal 8.0.0.0
ibm websphere_portal 7.0.0.2
ibm websphere_portal 8.5.0.0
ibm websphere_portal 7.0.0.1
ibm websphere_portal 7.0.0.0
ibm websphere_portal 9.0.0.0
CVE-2018-1421 MEDIUM

IBM WebSphere DataPower Appliances 7.1, 7.2, 7.5, 7.5.1, 7.5.2, and 7.6 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 139023.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm datapower_gateway *
CVE-2018-1422 LOW

IBM Jazz Foundation products (IBM Rational DOORS Next Generation 5.0 through 5.0.2 and 6.0 through 6.0.5) are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 139025.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_doors_next_generation *
CVE-2018-1423 MEDIUM

IBM Jazz Foundation products could disclose sensitive information to an authenticated attacker that could be used in further attacks against the system. IBM X-Force ID: 139026.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
ibm rational_engineering_lifecycle_manager *
ibm rational_rhapsody_design_manager *
ibm rational_collaborative_lifecycle_management *
ibm rational_software_architect_design_manager *
ibm rational_doors_next_generation *
ibm rational_team_concert *
CVE-2018-1424 MEDIUM

IBM Marketing Platform 9.1.0, 9.1.2, and 10.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 139029.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm marketing_platform 10.1
ibm marketing_platform 9.1.2
ibm marketing_platform 9.1.0
CVE-2018-1425 MEDIUM

IBM Security Guardium Big Data Intelligence (SonarG) 3.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 139003.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-326,

Products Affected

Vendor Product Version
ibm security_guardium_big_data_intelligence 3.1
CVE-2018-1426 MEDIUM

IBM GSKit (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) duplicates the PRNG state across fork() system calls when multiple ICC instances are loaded which could result in duplicate Session IDs and a risk of duplicate key material. IBM X-Force ID: 139071.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-335,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2 11.1
ibm db2 10.1
ibm db2 9.7
CVE-2018-1427 LOW

IBM GSKit (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) contains several environment variables that a local attacker could overflow and cause a denial of service. IBM X-Force ID: 139072.

CVSS 2.0

Severity: LOW

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2 11.1
ibm db2 10.1
ibm db2 9.7
CVE-2018-1428 LOW

IBM GSKit (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 139073.

CVSS 2.0

Severity: LOW

Problem Type: CWE-327,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2 11.1
ibm db2 10.1
ibm db2 9.7
CVE-2018-1429 LOW

IBM MQ Appliance 9.0.1, 9.0.2, 9.0.3, amd 9.0.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 139077.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm mq_appliance 9.0.2
ibm mq_appliance 9.0.4
ibm mq_appliance 9.0.3
ibm mq_appliance 9.0.1
CVE-2018-1430 LOW

IBM API Connect 5.0.0.0 through 5.0.8.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 139226.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm api_connect *
CVE-2018-1431 MEDIUM

A vulnerability in GSKit affects IBM Spectrum Scale 4.1.1, 4.2.0, 4.2.1, 4.2.3, and 5.0.0 that could allow a local attacker to obtain control of the Spectrum Scale daemon and to access and modify files in the Spectrum Scale file system, and possibly to obtain administrator privileges on the node. IBM X-Force ID: 139240.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm spectrum_scale *
ibm general_parallel_file_system *
CVE-2018-1432 MEDIUM

IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 is vulnerable to cross-frame scripting which is a vulnerability that allows an attacker to load Information Server components inside an HTML iframe tag on a malicious page. The attacker could use this weakness to devise a Clickjacking attack to conduct phishing, frame sniffing, social engineering or Cross-Site Request Forgery attacks. IBM X-Force ID: 139360.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,CWE-1021,

Products Affected

Vendor Product Version
ibm infosphere_information_server 11.3
ibm infosphere_information_server 11.5
ibm infosphere_information_server 9.1
ibm infosphere_information_server 11.7
CVE-2018-1433 MEDIUM

IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) web handler /DownloadFile does not require authentication to read arbitrary files from the system. IBM X-Force ID: 139473.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 3.9 3.6

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm storwize_v5000_firmware *
ibm storwize_v7000_firmware *
ibm san_volume_controller_firmware *
ibm storwize_v3700_firmware *
ibm storwize_v3500_firmware *
ibm spectrum_virtualize *
ibm spectrum_virtualize_for_public_cloud *
ibm storwize_v9000_firmware *
CVE-2018-1434 MEDIUM

IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) are vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 139474.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 2.8 5.9

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm storwize_v5000_firmware *
ibm storwize_v7000_firmware *
ibm san_volume_controller_firmware *
ibm storwize_v3700_firmware *
ibm storwize_v3500_firmware *
ibm spectrum_virtualize *
ibm spectrum_virtualize_for_public_cloud *
ibm storwize_v9000_firmware *
CVE-2018-1435 MEDIUM

IBM Notes 8.5 and 9.0 is vulnerable to a DLL hijacking attack. A remote attacker could trick a user to double click a malicious executable in an attacker-controlled directory, which could result in code execution. IBM X-Force ID: 139563.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-426,

Products Affected

Vendor Product Version
ibm notes 9.0.1.9
ibm notes 8.5.2
ibm notes 8.5.3
ibm notes 8.5.1.5
ibm notes 8.5.3.6
ibm notes 8.5.0.2
ibm notes 9.0.1
ibm notes 8.5.2.4
ibm notes 8.5.1
ibm notes 9.0
ibm notes 8.5
CVE-2018-1437 HIGH

IBM Notes 8.5 and 9.0 could allow an attacker to execute arbitrary code on the system, caused by an error related to multiple untrusted search path. A local attacker could exploit this vulnerability to DLL hijacking to execute arbitrary code on the system or cause the application to crash. IBM X-Force ID: 139565.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-426,

Products Affected

Vendor Product Version
ibm notes 9.0.1.9
ibm notes 8.5.2
ibm notes 8.5.3
ibm notes 8.5.1.5
ibm notes 8.5.3.6
ibm notes 8.5.0.2
ibm notes 9.0.1
ibm notes 8.5.2.4
ibm notes 8.5.1
ibm notes 9.0
ibm notes 8.5
CVE-2018-1438 MEDIUM

IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) web handler /DLSnap could allow an unauthenticated attacker to read arbitrary files on the system. IBM X-Force ID: 139566.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 3.9 3.6

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm storwize_v5000_firmware *
ibm storwize_v7000_firmware *
ibm san_volume_controller_firmware *
ibm storwize_v3700_firmware *
ibm storwize_v3500_firmware *
ibm spectrum_virtualize *
ibm spectrum_virtualize_for_public_cloud *
ibm storwize_v9000_firmware *
CVE-2018-1439 LOW

IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 139589.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
CVE-2018-1440 LOW

IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 139595.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
CVE-2018-1441 MEDIUM

IBM Application Performance Management - Response Time Monitoring Agent (IBM Monitoring 8.1.3 and 8.1.4) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 139597.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm monitoring 8.1.3
ibm monitoring 8.1.4
CVE-2018-1442 MEDIUM

IBM Application Performance Management - Response Time Monitoring Agent (IBM Monitoring 8.1.4) is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 139598.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm monitoring 8.1.4
CVE-2018-1443 MEDIUM

An XML parsing vulnerability affects IBM SAML-based single sign-on (SSO) systems (IBM Security Access Manager 9.0.0 - 9.0.4 and IBM Tivoli Federated Identity Manager 6.2 - 6.0.2.) This vulnerability can allow an attacker with authenticated access to trick SAML systems into authenticating as a different user without knowledge of the victim users password. IBM X-Force ID: 139754.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm tivoli_federated_identity_manager 6.2.1
ibm security_access_manager *
ibm tivoli_federated_identity_manager 6.2.2
ibm tivoli_federated_identity_manager 6.2.0
CVE-2018-1444 LOW

IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 139906.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 8.5.0.0
ibm websphere_portal 9.0.0.0
CVE-2018-1445 LOW

IBM WebSphere Portal 8.0.0 through 8.0.0.1, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 139907.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 9.0
ibm websphere_portal *
ibm websphere_portal 8.5
CVE-2018-1447 MEDIUM

The GSKit (IBM Spectrum Protect 7.1 and 7.2) and (IBM Spectrum Protect Snapshot 4.1.3, 4.1.4, and 4.1.6) CMS KDB logic fails to salt the hash function resulting in weaker than expected protection of passwords. A weak password may be recovered. Note: After update the customer should change password to ensure the new password is stored more securely. Products should encourage customers to take this step as a high priority action. IBM X-Force ID: 139972.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-916,

Products Affected

Vendor Product Version
ibm spectrum_protect_for_virtual_environments *
ibm spectrum_protect_for_space_management *
ibm spectrum_protect_snapshot *
CVE-2018-1448 LOW

IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) contains a vulnerability that could allow a local user to overwrite arbitrary files owned by the DB2 instance owner. IBM X-Force ID: 140043.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2 11.1
ibm db2 10.1
ibm db2 9.7
CVE-2018-1449 LOW

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability that could allow a local user to overwrite arbitrary files owned by the DB2 instance owner. IBM X-Force ID: 140044.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2 11.1
ibm db2 10.1
ibm db2 9.7
CVE-2018-1450 LOW

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability that could allow a local user to overwrite arbitrary files owned by the DB2 instance owner. IBM X-Force ID: 140045.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2 11.1
ibm db2 10.1
ibm db2 9.7
CVE-2018-1451 LOW

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability that could allow a local user to overwrite arbitrary files owned by the DB2 instance owner. IBM X-Force ID: 140046.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2 11.1
ibm db2 10.1
ibm db2 9.7
CVE-2018-1452 LOW

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability that could allow a local user to overwrite arbitrary files owned by the DB2 instance owner. IBM X-Force ID: 140047.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2 11.1
ibm db2 10.1
ibm db2 9.7
CVE-2018-1453 MEDIUM

IBM Security Identity Manager Virtual Appliance 7.0 allows an authenticated attacker to upload or transfer files of dangerous types that can be automatically processed within the environment. IBM X-Force ID: 140055.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-434,

Products Affected

Vendor Product Version
ibm security_identity_manager 7.0
ibm security_identity_manager 7.0.1
CVE-2018-1454 MEDIUM

IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 140089.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-319,

Products Affected

Vendor Product Version
ibm infosphere_information_server 11.3
ibm infosphere_information_server 11.5
ibm infosphere_information_server 11.7
CVE-2018-1455 MEDIUM

IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 11029.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm tivoli_application_dependency_discovery_manager 7.2.2
ibm tivoli_application_dependency_discovery_manager 7.3.0
CVE-2018-1456 MEDIUM

IBM Rhapsody DM 5.0 through 5.0.2 and 6.0 through 6.0.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 140091.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm rational_rhapsody_design_manager 5.0.1
ibm rational_software_architect_design_manager 5.0.0
ibm rational_rhapsody_design_manager 5.0.0
ibm rational_software_architect_design_manager 5.0.2
ibm rational_software_architect_design_manager 6.0.0
ibm rational_rhapsody_design_manager 6.0.3
ibm rational_software_architect_design_manager 5.0.1
ibm rational_rhapsody_design_manager 6.0.4
ibm rational_software_architect_design_manager 6.0.1
ibm rational_rhapsody_design_manager 6.0.5
ibm rational_rhapsody_design_manager 6.0.1
ibm rational_rhapsody_design_manager 6.0.2
ibm rational_rhapsody_design_manager 5.0.2
ibm rational_rhapsody_design_manager 6.0.0
CVE-2018-1457 HIGH

An undisclosed vulnerability in IBM Rational DOORS 9.5.1 through 9.6.1.10 application allows an attacker to gain DOORS administrator privileges. IBM X-Force ID: 140208.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 3.9 5.9

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm engineering_requirements_management_doors *
CVE-2018-1458 MEDIUM

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10,1, 10.5 and 11.1 could allow a local user to execute arbitrary code and conduct DLL hijacking attacks. IBM X-Force ID: 140209.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-426,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2 11.1
ibm db2 10.1
ibm db2 9.7
CVE-2018-1459 MEDIUM

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to stack based buffer overflow, caused by improper bounds checking which could lead an attacker to execute arbitrary code. IBM X-Force ID: 140210.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-787,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2 11.1
ibm db2 10.1
ibm db2 9.7
CVE-2018-1460 HIGH

IBM Netezza Platform Software (IBM PureData System for Analytics 1.0.0) could allow a local user to modify a world writable file, which could be used to execute commands as root. IBM X-Force ID: 140211.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-269,

Products Affected

Vendor Product Version
ibm puredata_system_for_analytics 1.0.0
CVE-2018-1461 LOW

IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 140362.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 5.4 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N 2.3 2.7

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm storwize_v5000_firmware *
ibm storwize_v7000_firmware *
ibm san_volume_controller_firmware *
ibm storwize_v3700_firmware *
ibm storwize_v3500_firmware *
ibm spectrum_virtualize *
ibm spectrum_virtualize_for_public_cloud *
ibm storwize_v9000_firmware *
CVE-2018-1462 MEDIUM

IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) could allow an authenticated user to access system files they should not have access to including deleting files or causing a denial of service. IBM X-Force ID: 140363.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.6 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H 2.8 4.7

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-863,

Products Affected

Vendor Product Version
ibm storwize_v5000_firmware *
ibm storwize_v7000_firmware *
ibm san_volume_controller_firmware *
ibm storwize_v3700_firmware *
ibm storwize_v3500_firmware *
ibm spectrum_virtualize *
ibm spectrum_virtualize_for_public_cloud *
ibm storwize_v9000_firmware *
CVE-2018-1463 MEDIUM

IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) could allow an authenticated user to access system files they should not have access to some of which could contain account credentials. IBM X-Force ID: 140368.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 6.5 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N 2.8 3.6

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-863,

Products Affected

Vendor Product Version
ibm storwize_v5000_firmware *
ibm storwize_v7000_firmware *
ibm san_volume_controller_firmware *
ibm storwize_v3700_firmware *
ibm storwize_v3500_firmware *
ibm spectrum_virtualize *
ibm spectrum_virtualize_for_public_cloud *
ibm storwize_v9000_firmware *
CVE-2018-1464 MEDIUM

IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) could allow an authenticated user to obtain sensitive information that they should not have authorization to read. IBM X-Force ID: 140395.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 6.5 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N 2.8 3.6

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm storwize_v5000_firmware *
ibm storwize_v7000_firmware *
ibm san_volume_controller_firmware *
ibm storwize_v3700_firmware *
ibm storwize_v3500_firmware *
ibm spectrum_virtualize *
ibm spectrum_virtualize_for_public_cloud *
ibm storwize_v9000_firmware *
CVE-2018-1465 LOW

IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) could allow an authenticated user to obtain the private key which could make intercepting GUI communications possible. IBM X-Force ID: 140396.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 5.3 MEDIUM CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N 1.6 3.6

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm storwize_v5000_firmware *
ibm storwize_v7000_firmware *
ibm san_volume_controller_firmware *
ibm storwize_v3700_firmware *
ibm storwize_v3500_firmware *
ibm spectrum_virtualize *
ibm spectrum_virtualize_for_public_cloud *
ibm storwize_v9000_firmware *
CVE-2018-1466 LOW

IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products (6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) use weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 140397.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 5.3 MEDIUM CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N 1.6 3.6

CVSS 2.0

Severity: LOW

Problem Type: CWE-326,

Products Affected

Vendor Product Version
ibm storwize_v5000_firmware *
ibm storwize_v7000_firmware *
ibm san_volume_controller_firmware *
ibm storwize_v3700_firmware *
ibm storwize_v3500_firmware *
ibm spectrum_virtualize *
ibm spectrum_virtualize_for_public_cloud *
ibm storwize_v9000_firmware *
CVE-2018-1467 MEDIUM

The IBM Storwize V7000 Unified management Web interface 1.6 exposes internal cluster details to unauthenticated users. IBM X-Force ID: 140398.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm storwize_unified_v7000_software 1.6
CVE-2018-1468 MEDIUM

IBM API Connect 5.0.8.1 and 5.0.8.2 could allow a user to get access to internal environment and sensitive API details to which they are not authorized. IBM X-Force ID: 140399.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm api_connect 5.0.8.1
ibm api_connect 5.0.8.2
CVE-2018-1469 HIGH

IBM API Connect Developer Portal 5.0.0.0 through 5.0.8.2 could allow an unauthenticated attacker to execute system commands using specially crafted HTTP requests. IBM X-Force ID: 140605.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm api_connect *
CVE-2018-1470 MEDIUM

IBM Sterling File Gateway 2.2.0 through 2.2.6 could allow a remote authenticated attacker to obtain sensitive information displayed in the URL that could lead to further attacks against the system. IBM X-Force ID: 140688.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm sterling_file_gateway *
CVE-2018-1473 MEDIUM

IBM BigFix Platform 9.2 and 9.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 140691.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm bigfix_platform *
CVE-2018-1474 MEDIUM

IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 is vulnerable to HTTP response splitting attacks, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject arbitrary HTTP headers and cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache poisoning or cross-site scripting, and possibly obtain sensitive information. IBM X-force ID: 140692.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-74,

Products Affected

Vendor Product Version
ibm bigfix_platform *
CVE-2018-1475 MEDIUM

IBM BigFix Platform 9.2 and 9.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 140756.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-307,

Products Affected

Vendor Product Version
ibm bigfix_platform *
CVE-2018-1476 MEDIUM

IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 140757.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm bigfix_platform *
CVE-2018-1478 MEDIUM

IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 140760.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm bigfix_platform *
CVE-2018-1479 MEDIUM

IBM BigFix Platform 9.2 and 9.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 140761.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm bigfix_platform *
CVE-2018-1480 MEDIUM

IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 does not set the 'HttpOnly' attribute on authorization tokens or session cookies. If a Cross-Site Scripting vulnerability also existed attackers may be able to get the cookie values via malicious JavaScript and then hijack the user session. IBM X-Force ID: 140762.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-384,

Products Affected

Vendor Product Version
ibm bigfix_platform *
CVE-2018-1481 MEDIUM

IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 140763.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm bigfix_platform *
CVE-2018-1483 MEDIUM

IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 140918.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 9.0
ibm websphere_portal 8.5.0.0
CVE-2018-1484 MEDIUM

IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 140969.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-384,

Products Affected

Vendor Product Version
ibm bigfix_platform *
CVE-2018-1485 MEDIUM

IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 does not renew a session variable after a successful authentication which could lead to session fixation/hijacking vulnerability. This could force a user to utilize a cookie that may be known to an attacker. IBM X-Force ID: 140970.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-384,

Products Affected

Vendor Product Version
ibm bigfix_platform *
CVE-2018-1487 MEDIUM

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5 and 11.1 binaries load shared libraries from an untrusted path potentially giving low privilege users full access to the DB2 instance account by loading a malicious shared library. IBM X-Force ID: 140972.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-426,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2 11.1
ibm db2 10.1
ibm db2 9.7
CVE-2018-1488 HIGH

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5 and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-Force ID: 140973.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2 11.1
CVE-2018-1492 MEDIUM

IBM Jazz Foundation products could allow a user with physical access to the system to log in as another user due to the server's failure to properly log out from the previous session. IBM X-Force ID: 140977.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-384,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
ibm rational_engineering_lifecycle_manager *
ibm rational_rhapsody_design_manager *
ibm rational_collaborative_lifecycle_management *
ibm rational_software_architect_design_manager *
ibm rational_doors_next_generation *
ibm rational_team_concert *
CVE-2018-1494 LOW

IBM DOORS Next Generation (DNG/RRC) 5.0 through 5.0.2 and 6.0 through 6.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 141097.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_doors_next_generation 5.0.2
ibm rational_doors_next_generation 6.0.5
ibm rational_doors_next_generation 6.0.3
ibm rational_doors_next_generation 6.0.2
ibm rational_doors_next_generation 6.0.0
ibm rational_doors_next_generation 5.0
ibm rational_doors_next_generation 5.0.1
ibm rational_doors_next_generation 6.0.4
ibm rational_doors_next_generation 6.0.1
CVE-2018-1495 MEDIUM

IBM FlashSystem V840 and V900 products could allow an authenticated attacker with specialized access to overwrite arbitrary files which could cause a denial of service. IBM X-Force ID: 141148.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-269,

Products Affected

Vendor Product Version
ibm flashsystem_840_firmware -
ibm flashsystem_900_firmware -
CVE-2018-1496 LOW

IBM Content Navigator 2.0.3, 3.0.0, 3.0.1, 3.0.2, and 3.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 141219.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm content_navigator 3.0.1
ibm content_navigator 3.0.0
ibm content_navigator 3.0.2
ibm content_navigator 3.0.3
ibm content_navigator 2.0.3
CVE-2018-1498 LOW

IBM Security Guardium EcoSystem 10.5 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 141223.

CVSS 2.0

Severity: LOW

Problem Type: CWE-522,

Products Affected

Vendor Product Version
ibm security_guardium 10.5
CVE-2018-1502 LOW

IBM Content Manager Enterprise Edition Resource Manager 8.4.3 and 9.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 141338.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm content_manager 8.5
ibm content_manager 8.4.3
CVE-2018-1503 MEDIUM

IBM WebSphere MQ 7.5, 8.0, and 9.0 could allow a remotely authenticated attacker to to send invalid or malformed headers that could cause messages to no longer be transmitted via the affected channel. IBM X-Force ID: 141339.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm websphere_mq *
CVE-2018-1504 MEDIUM

IBM i2 Enterprise Insight Analysis 2.1.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 141340.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm i2_enterprise_insight_analysis 2.1.7
ibm i2_enterprise_insight_analysis 2.1.8
CVE-2018-1505 LOW

IBM i2 Enterprise Insight Analysis 2.1.7 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 141413.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm i2_enterprise_insight_analysis 2.1.7
ibm i2_enterprise_insight_analysis 2.1.8
CVE-2018-1507 LOW

IBM DOORS Next Generation (DNG/RRC) 6.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 141415.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_doors_next_generation 6.0.5
CVE-2018-1509 MEDIUM

IBM Security Guardium EcoSystem 10.5 does not validate, or incorrectly validates, a certificate.This weakness might allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack. The software might connect to a malicious host while believing it is a trusted host, or the software might be deceived into accepting spoofed data that appears to originate from a trusted host. IBM X-Force ID: 141417.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-295,

Products Affected

Vendor Product Version
ibm security_guardium 10.5
CVE-2018-1513 LOW

IBM Sterling B2B Integrator Standard Edition 5.2.0 through 5.2.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 141551.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator *
CVE-2018-1514 MEDIUM

IBM Robotic Process Automation with Automation Anywhere 10.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 141622.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm robotic_process_automation_with_automation_anywhere 10.0
CVE-2018-1515 MEDIUM

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5 and 11.1, under specific or unusual conditions, could allow a local user to overflow a buffer which may result in a privilege escalation to the DB2 instance owner. IBM X-Force ID: 141624.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2 11.1
CVE-2018-1517 MEDIUM

A flaw in the java.math component in IBM SDK, Java Technology Edition 6.0, 7.0, and 8.0 may allow an attacker to inflict a denial-of-service attack with specially crafted String data. IBM X-Force ID: 141681.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
redhat enterprise_linux_desktop 7.0
redhat satellite 5.6
ibm software_development_kit 8.0
redhat enterprise_linux_server 7.0
redhat enterprise_linux_desktop 6.0
redhat enterprise_linux_workstation 7.0
ibm software_development_kit 6
ibm software_development_kit 6.0
redhat satellite 5.7
ibm software_development_kit 6r1
redhat enterprise_linux_workstation 6.0
redhat enterprise_linux_server 6.0
ibm software_development_kit 7
redhat satellite 5.8
ibm software_development_kit 8
ibm software_development_kit 7r1
ibm software_development_kit 7.0
CVE-2018-1518 LOW

IBM InfoSphere Information Server 11.7 is affected by a weak password encryption vulnerability that could allow a local user to obtain highly sensitive information. IBM X-Force ID: 141682.

CVSS 2.0

Severity: LOW

Problem Type: CWE-326,

Products Affected

Vendor Product Version
ibm infosphere_information_server_on_cloud 11.7
ibm infosphere_information_server 11.7
CVE-2018-1521 LOW

IBM Rational Team Concert 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 141802.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_team_concert *
CVE-2018-1522 LOW

IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 141803.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
CVE-2018-1523 LOW

IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 141804.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
CVE-2018-1524 HIGH

IBM Maximo Asset Management 7.6 through 7.6.3 installs with a default administrator account that a remote intruder could use to gain administrator access to the system. This vulnerability is due to an incomplete fix for CVE-2015-4966. IBM X-Force ID: 142116.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-1188,

Products Affected

Vendor Product Version
ibm maximo_for_transportation 7.6.1.0
ibm maximo_for_transportation 7.6.2.1
ibm maximo_for_utilities 7.6.0.0
ibm maximo_for_nuclear_power 7.6.0.0
ibm smartcloud_control_desk 7.6.0.0
ibm maximo_for_aviation 7.6.3.0
ibm maximo_asset_management *
ibm maximo_for_aviation 7.6.1.0
ibm maximo_for_oil_and_gas 7.6.0.0
ibm maximo_for_aviation 7.6.2.0
ibm maximo_for_transportation 7.6.2.3
ibm maximo_for_transportation 7.6.2.0
ibm maximo_for_transportation 7.6.2.4
ibm maximo_for_life_sciences 7.6.0.0
ibm maximo_for_aviation 7.6.0.0
ibm smartcloud_control_desk 7.6.0.1
ibm maximo_for_oil_and_gas 7.5.0.0
ibm maximo_for_aviation 7.6.2.1
ibm maximo_for_transportation 7.6.2.2
CVE-2018-1525 MEDIUM

IBM i2 Enterprise Insight Analysis 2.1.7 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 142117.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-319,

Products Affected

Vendor Product Version
ibm i2_enterprise_insight_analysis 2.1.7
ibm i2_enterprise_insight_analysis 2.1.8
CVE-2018-1528 MEDIUM

IBM Maximo Asset Management 7.6 through 7.6.3 could allow an authenticated user to obtain sensitive information from the WhoAmI API. IBM X-Force ID: 142290.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm maximo_for_transportation 7.6.1.0
ibm maximo_for_transportation 7.6.2.1
ibm maximo_for_utilities 7.6.0.0
ibm maximo_for_nuclear_power 7.6.0.0
ibm smartcloud_control_desk 7.6.0.0
ibm maximo_for_aviation 7.6.3.0
ibm maximo_asset_management *
ibm maximo_for_aviation 7.6.1.0
ibm maximo_for_oil_and_gas 7.6.0.0
ibm maximo_for_aviation 7.6.2.0
ibm maximo_for_transportation 7.6.2.3
ibm maximo_for_transportation 7.6.2.0
ibm maximo_for_transportation 7.6.2.4
ibm maximo_for_life_sciences 7.6.0.0
ibm maximo_for_aviation 7.6.0.0
ibm smartcloud_control_desk 7.6.0.1
ibm maximo_for_aviation 7.6.2.1
ibm maximo_for_transportation 7.6.2.2
CVE-2018-1529 LOW

IBM Rational DOORS Next Generation 5.0 through 5.0.2, 6.0 through 6.0.5 and IBM Rational Requirements Composer 5.0 through 5.0.2 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142291.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_requirements_composer *
ibm rational_doors_next_generation *
CVE-2018-1532 MEDIUM

IBM API Connect 5.0.0.0 through 5.0.8.2 does not properly update the SESSIONID with each request, which could allow a user to obtain the ID in further attacks against the system. IBM X-Force ID: 142430.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm api_connect *
CVE-2018-1533 LOW

IBM Rational Publishing Engine 6.0.5 and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142431.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm engineering_lifecycle_optimization_-_publishing 6.0.6
ibm engineering_lifecycle_optimization_-_publishing 6.0.5
CVE-2018-1534 LOW

IBM Rational Publishing Engine 6.0.5 and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142432.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm engineering_lifecycle_optimization_-_publishing 6.0.6
ibm engineering_lifecycle_optimization_-_publishing 6.0.5
CVE-2018-1535 LOW

IBM Rational Rhapsody Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 and IBM Rational Software Architect Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 124557.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_rhapsody_design_manager *
ibm rational_software_architect_design_manager *
CVE-2018-1536 LOW

IBM Rational Rhapsody Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 and IBM Rational Software Architect Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142558.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_rhapsody_design_manager *
ibm rational_software_architect_design_manager *
CVE-2018-1539 MEDIUM

IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 could allow remote attackers to bypass authentication via a direct request or forced browsing to a page other than URL intended. IBM X-Force ID: 142561.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm rational_engineering_lifecycle_manager *
CVE-2018-1541 LOW

IBM WebSphere Commerce Enterprise V7, V8, and V9 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142596.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_commerce 7.0.0.9
ibm websphere_commerce *
CVE-2018-1542 MEDIUM

IBM FileNet Content Manager, IBM Content Foundation, and IBM Case Foundation Administration Console for Content Platform Engine (ACCE) 5.2.1 and 5.5.0 are vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 142597.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm filenet_content_manager 5.2.1
ibm content_foundation 5.2.1
ibm content_foundation 5.5.0
ibm filenet_content_manager 5.5.0
CVE-2018-1543 MEDIUM

IBM WebSphere MQ 8.0 and 9.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly validate the SSL certificate. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 142598.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-295,

Products Affected

Vendor Product Version
ibm websphere_mq 9.0
ibm websphere_mq 8.0
CVE-2018-1544 MEDIUM

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to overflow a buffer which may result in a privilege escalation to the DB2 instance owner. IBM X-Force ID: 142648.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2 11.1
ibm db2 10.1
ibm db2 9.7
CVE-2018-1545 MEDIUM

IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 142649.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 3.9 3.6

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-326,

Products Affected

Vendor Product Version
ibm spectrum_protect_client *
ibm spectrum_protect_for_virtual_environments *
CVE-2018-1546 MEDIUM

IBM API Connect 5.0.0.0 through 5.0.8.3 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 142650.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
psirt@us.ibm.com 5.9 MEDIUM CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N 2.2 3.6

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm api_connect *
CVE-2018-1547 MEDIUM

IBM Robotic Process Automation with Automation Anywhere 10.0 could allow a remote attacker to execute arbitrary code on the system, caused by improper output encoding in an CSV export. By persuading a victim to download the CSV export, to open it in Microsoft Excel and to confirm the two security questions, an attacker could exploit this vulnerability to run any command or program on the victim's machine. IBM X-Force ID: 142651.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm robotic_process_automation_with_automation_anywhere 10.0
CVE-2018-1548 MEDIUM

IBM API Connect 2018.1.0.0, 2018.2.1, 2018.2.2, 2018.2.3, and 2018.2.4 contains a vulnerability that could allow an authenticated user to obtain sensitive information. IBM X-Force ID: 142657.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm api_connect *
CVE-2018-1549 MEDIUM

IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache poisoning, cross-site scripting, and possibly obtain sensitive information. IBM X-Force ID: 142658.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-74,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
CVE-2018-1550 LOW

IBM Spectrum Protect 7.1 and 8.1 could allow a local user to corrupt or delete highly sensitive information that would cause a denial of service to other users. IBM X-Force ID: 142696.

CVSS 2.0

Severity: LOW

Problem Type: CWE-269,

Products Affected

Vendor Product Version
ibm tivoli_storage_manager *
ibm tivoli_storage_manager_for_virtual_environments *
ibm tivoli_storage_manager_for_space_management *
CVE-2018-1551 MEDIUM

IBM WebSphere MQ 8.0.0.2 through 8.0.0.8 and 9.0.0.0 through 9.0.0.3 could allow users to have more authority than they should have if an MQ administrator creates an invalid user group name. IBM X-Force ID: 142888.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-732,

Products Affected

Vendor Product Version
ibm websphere_mq *
CVE-2018-1552 HIGH

IBM Robotic Process Automation with Automation Anywhere 10.0 and 11.0 allows a remote attacker to execute arbitrary code on the system, caused by a missing restriction in which file types can be uploaded to the control room. By uploading a malicious file and tricking a victim to run it, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 142889.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-434,

Products Affected

Vendor Product Version
ibm robotic_process_automation_with_automation_anywhere 10
ibm robotic_process_automation_with_automation_anywhere 11
CVE-2018-1553 MEDIUM

IBM WebSphere Application Server Liberty prior to 18.0.0.2 could allow a remote attacker to obtain sensitive information, caused by mishandling of exceptions by the SAML Web SSO feature. IBM X-Force ID: 142890.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_application_server *
CVE-2018-1554 LOW

IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142891.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm maximo_asset_management *
CVE-2018-1555 LOW

IBM FileNet Content Manager 5.2.1 and 5.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142892.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm filenet_content_manager 5.2.1
ibm content_foundation 5.2.1
ibm content_foundation 5.5.0
ibm filenet_content_manager 5.5.0
CVE-2018-1556 LOW

IBM FileNet Content Manager 5.2.1 and 5.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142893.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm filenet_content_manager 5.2.1
ibm content_foundation 5.2.1
ibm content_foundation 5.5.0
ibm filenet_content_manager 5.5.0
CVE-2018-1557 LOW

IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142955.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
CVE-2018-1558 LOW

IBM Rational Collaborative Lifecycle Management 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142956.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
ibm rational_engineering_lifecycle_manager *
ibm rational_rhapsody_design_manager *
ibm rational_collaborative_lifecycle_management *
ibm rational_software_architect_design_manager *
ibm rational_doors_next_generation *
ibm rational_team_concert *
CVE-2018-1560 LOW

IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142958.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_engineering_lifecycle_manager *
CVE-2018-1563 LOW

IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway 2.2.0 through 2.2.6) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142967.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator *
ibm sterling_file_gateway *
CVE-2018-1564 LOW

IBM Sterling B2B Integrator Standard Edition 5.2 through 5.2.6 could allow a local user with administrator privileges to obtain user passwords found in debugging messages. IBM X-Force ID: 142968.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator *
CVE-2018-1565 MEDIUM

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to overflow a buffer which may result in a privilege escalation to the DB2 instance owner. IBM X-Force ID: 143022.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2 11.1
ibm db2 10.1
ibm db2 9.7
CVE-2018-1566 MEDIUM

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to execute arbitrary code due to a format string error. IBM X-Force ID: 143023.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-134,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2 11.1
ibm db2 10.1
ibm db2 9.7
CVE-2018-1567 HIGH

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbitrary Java code through the SOAP connector with a serialized object from untrusted sources. IBM X-Force ID: 143024.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-502,

Products Affected

Vendor Product Version
ibm websphere_application_server *
CVE-2018-1568 LOW

IBM QRadar SIEM 7.2 and 7.3 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 143118.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm qradar_incident_forensics *
ibm qradar_incident_forensics 7.2.8
ibm qradar_incident_forensics 7.3.1
CVE-2018-1571 HIGH

IBM QRadar 7.2 and 7.3 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 143121.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.8
ibm qradar_security_information_and_event_manager 7.3.1
ibm qradar_security_information_and_event_manager 7.3.0
ibm qradar_security_information_and_event_manager *
CVE-2018-1583 MEDIUM

IBM StoredIQ 7.6 could allow an authenticated attacker to bypass certain security restrictions. By sending a specially-crafted request, an authenticated attacker could exploit this vulnerability to access and manipulate documents on StoredIQ managed data sources. IBM X-Force ID: 143331.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm storediq 7.6.0
CVE-2018-1584 LOW

IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 143497.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm maximo_asset_management 7.6
CVE-2018-1585 LOW

IBM Rational Rhapsody Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 and IBM Rational Software Architect Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 143498.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_rhapsody_design_manager *
ibm rational_software_architect_design_manager *
CVE-2018-1587 MEDIUM

IBM Rational Rhapsody Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 and IBM Rational Software Architect Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.1 could reveal technical error messages to allow an adversary to gain information about the application and database that could be used to conduct further attacks. IBM X-Force ID: 143500.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_rhapsody_design_manager *
ibm rational_software_architect_design_manager *
CVE-2018-1588 MEDIUM

IBM Jazz Foundation (IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6) is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 143501.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm rational_engineering_lifecycle_manager *
CVE-2018-1593 MEDIUM

IBM Multi-Cloud Data Encryption (MDE) 2.1 could allow an unauthorized user to manipulate data due to missing file checksums. IBM X-Force ID: 143568.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-326,

Products Affected

Vendor Product Version
ibm multi-cloud_data_encryption *
CVE-2018-1595 MEDIUM

IBM Spectrum Symphony and Platform Symphony 7.1.2 and 7.2.0.2 could allow an authenticated user to execute arbitrary commands due to improper handling of user supplied input. IBM X-Force ID: 143622.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm platform_symphony 7.1.1
ibm spectrum_symphony 7.1.2
ibm spectrum_symphony 7.2.0.2
ibm platform_symphony 6.1.1
ibm platform_symphony 7.1.0
CVE-2018-1599 LOW

IBM API Connect 5.0.0.0 through 5.0.8.3 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 143744.

CVSS 2.0

Severity: LOW

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm api_connect *
CVE-2018-1600 MEDIUM

IBM BigFix Platform 9.2 and 9.5 transmits sensitive or security-critical data in clear text in a communication channel that can be sniffed by unauthorized actors. IBM X-Force ID: 143745.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-319,

Products Affected

Vendor Product Version
ibm bigfix_platform *
CVE-2018-1601 LOW

IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 143791.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
CVE-2018-1602 LOW

IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 143792.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
CVE-2018-1603 LOW

IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 143793.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
CVE-2018-1604 LOW

IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 143794.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
CVE-2018-1605 LOW

IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 143795.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
CVE-2018-1606 MEDIUM

IBM Jazz based applications (IBM Rational Collaborative Lifecycle Management 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational DOORS Next Generation 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational Quality Manager 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational Rhapsody Design Manager 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational Software Architect Design Manager 5.0 through 5.02 and 6.0 through 6.0.1, IBM Rational Team Concert 5.0 through 5.02 and 6.0 through 6.0.6) could allow an authenticated user to obtain sensitive information from an error message that could be used in further attacks against the system. IBM X-Force ID: 143796.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
ibm rational_engineering_lifecycle_manager *
ibm rational_rhapsody_design_manager *
ibm rational_collaborative_lifecycle_management *
ibm rational_software_architect_design_manager *
ibm rational_doors_next_generation *
ibm rational_team_concert *
CVE-2018-1607 MEDIUM

IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 143797.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm rational_engineering_lifecycle_manager *
CVE-2018-1610 LOW

IBM Rational DOORS Next Generation 5.0 through 5.0.2 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 143931.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_doors_next_generation *
CVE-2018-1612 MEDIUM

IBM QRadar Incident Forensics (IBM QRadar SIEM 7.2, and 7.3) could allow a remote attacker to bypass authentication and obtain sensitive information. IBM X-Force ID: 144164.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.8
ibm qradar_security_information_and_event_manager 7.3.1
ibm qradar_security_information_and_event_manager 7.3.0
ibm qradar_security_information_and_event_manager *
CVE-2018-1614 MEDIUM

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using malformed SAML responses from the SAML identity provider could allow a remote attacker to obtain sensitive information. IBM X-Force ID: 144270.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_application_server 9.0
ibm websphere_application_server 7.0
ibm websphere_application_server 8.0
ibm websphere_application_server 8.5
CVE-2018-1618 MEDIUM

IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 144343.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm security_privileged_identity_manager 2.1.1
CVE-2018-1621 LOW

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local attacker to obtain clear text password in a trace file caused by improper handling of some datasource custom properties. IBM X-Force ID: 144346.

CVSS 2.0

Severity: LOW

Problem Type: CWE-312,

Products Affected

Vendor Product Version
ibm websphere_application_server 9.0.0.0
ibm websphere_application_server 7.0.0.0
ibm websphere_application_server 8.5.0.0
ibm websphere_application_server 8.0.0.0
CVE-2018-1622 MEDIUM

IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 144348.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm security_privileged_identity_manager 2.1.1
CVE-2018-1623 LOW

IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 144408.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_privileged_identity_manager 2.1.1
CVE-2018-1625 MEDIUM

IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 144410.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_privileged_identity_manager 2.1.1
CVE-2018-1626 MEDIUM

IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 does not renew a session variable after a successful authentication which could lead to session fixation/hijacking vulnerability. This could force a user to utilize a cookie that may be known to an attacker. IBM X-Force ID: 144411.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-384,

Products Affected

Vendor Product Version
ibm security_privileged_identity_manager 2.1.1
CVE-2018-1638 MEDIUM

IBM API Connect 5.0.0.0-5.0.8.3 Developer Portal does not enforce Two Factor Authentication (TFA) while resetting a user password but enforces it for all other login scenarios. IBM X-Force ID: 144483.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm api_connect *
CVE-2018-1639 MEDIUM

The Report Builder of Jazz Reporting Service 5.0 through 5.0.2 and 6.0 through 6.0.6 could allow an authenticated user to obtain sensitive information beyond its assigned privileges. IBM X-Force ID: 144579.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm jazz_reporting_service *
CVE-2018-1640 HIGH

IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 144580.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm security_privileged_identity_manager 2.1.1
CVE-2018-1643 MEDIUM

The Installation Verification Tool of IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 144588

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_application_server *
CVE-2018-1644 MEDIUM

IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 9.0.0.0 - 9.0.0.4, 8.0.0.0 - 8.0.0.19, 8.0.1.0 - 8.0.1.13, 8.0.3.0 - 8.0.3.6, 8.0.4.0 - 8.0.4.14, and 7.0.0.0 Feature Pack 8 could allow an authenticated user to obtain sensitive information about another user.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_commerce 7.0
ibm websphere_commerce *
CVE-2018-1647 MEDIUM

IBM QRadar Incident Forensics 7.2 and 7.3 does not properly restrict the size or amount of resources requested which could allow an unauthenticated user to cause a denial of service. IBM X-Force ID: 144650.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-770,

Products Affected

Vendor Product Version
ibm qradar_incident_forensics *
ibm qradar_incident_forensics 7.2.8
ibm qradar_incident_forensics 7.3.1
CVE-2018-1648 MEDIUM

IBM QRadar SIEM 7.2 and 7.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 144653.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-326,

Products Affected

Vendor Product Version
ibm qradar_incident_forensics *
ibm qradar_incident_forensics 7.2.8
ibm qradar_incident_forensics 7.3.1
CVE-2018-1649 MEDIUM

IBM QRadar Incident Forensics 7.2 and 7.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 144655.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm qradar_incident_forensics *
ibm qradar_incident_forensics 7.2.8
ibm qradar_incident_forensics 7.3.1
CVE-2018-1650 LOW

IBM QRadar SIEM 7.2 and 7.3 uses hard-coded credentials which could allow an attacker to bypass the authentication configured by the administrator. IBM X-Force ID: 144656.

CVSS 2.0

Severity: LOW

Problem Type: CWE-798,

Products Affected

Vendor Product Version
ibm qradar_incident_forensics *
ibm qradar_incident_forensics 7.2.8
ibm qradar_incident_forensics 7.3.1
CVE-2018-1652 LOW

IBM DataPower Gateway 7.1.0.0 through 7.1.0.19, 7.2.0.0 through 7.2.0.16, 7.5.0.0 through 7.5.0.10, 7.5.1.0 through 7.5.1.9, 7.5.2.0 through 7.5.2.9, and 7.6.0.0 through 7.6.0.2 and IBM MQ Appliance 8.0.0.0 through 8.0.0.8 and 9.0.1 through 9.0.5 could allow a local user to cause a denial of service through unknown vectors. IBM X-Force ID: 144724.

CVSS 2.0

Severity: LOW

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm mq_appliance *
ibm datapower_gateway *
CVE-2018-1653 LOW

IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 144726.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm security_access_manager *
CVE-2018-1654 MEDIUM

IBM Curam Social Program Management 6.0.5, 6.1.1, 6.2.0, 7.0.1, and 7.0.3 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 144747.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-601,

Products Affected

Vendor Product Version
ibm curam_social_program_management *
CVE-2018-1655 LOW

IBM AIX 5.3, 6.1, 7.1, and 7.2 contains a vulnerability in the rmsock command that may be used to expose kernel memory. IBM X-Force ID: 144748.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm aix 7.2
ibm aix 5.3
ibm aix 6.1
ibm aix 7.1
CVE-2018-1656 MEDIUM

The IBM Java Runtime Environment's Diagnostic Tooling Framework for Java (DTFJ) (IBM SDK, Java Technology Edition 6.0 , 7.0, and 8.0) does not protect against path traversal attacks when extracting compressed dump files. IBM X-Force ID: 144882.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
redhat enterprise_linux_desktop 7.0
redhat satellite 5.6
redhat enterprise_linux_server 7.0
oracle enterprise_manager_base_platform 13.2.0.0.0
ibm sdk 7.0
redhat enterprise_linux_desktop 6.0
redhat enterprise_linux_workstation 7.0
ibm sdk 6.0
ibm sdk 8.0
redhat satellite 5.7
redhat enterprise_linux_workstation 6.0
redhat enterprise_linux_server 6.0
oracle enterprise_manager_base_platform 13.3.0.0.0
redhat satellite 5.8
CVE-2018-1657 LOW

IBM Publishing Engine 2.1.2, 6.0.5, and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-force ID: 144883.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm engineering_lifecycle_optimization_-_publishing 2.1.2
ibm engineering_lifecycle_optimization_-_publishing 6.0.6
ibm engineering_lifecycle_optimization_-_publishing 6.0.5
CVE-2018-1658 LOW

IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 through 6.0.6) is vulnerable to HTTP header injection, caused by improper validation of input. By persuading a victim to visit a specially-crafted Web page, a remote attacker could exploit this vulnerability to inject arbitrary HTTP headers, which will allow the attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 144884.

CVSS 2.0

Severity: LOW

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm rational_collaborative_lifecycle_management *
CVE-2018-1659 LOW

IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 144885.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_engineering_lifecycle_manager *
CVE-2018-1660 LOW

IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-force ID: 144886.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.1
ibm websphere_portal 8.0.0.0
ibm websphere_portal 7.0.0.2
ibm websphere_portal 8.5.0.0
ibm websphere_portal 7.0.0.1
ibm websphere_portal 7.0.0.0
ibm websphere_portal 9.0.0.0
CVE-2018-1661 MEDIUM

IBM DataPower Gateways 7.5, 7.5.1, 7.5.2, and 7.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 144887.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm datapower_gateway *
CVE-2018-1663 MEDIUM

IBM DataPower Gateways 7.5, 7.5.1, 7.5.2, 7.6, and 2018.4 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 144889.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm datapower_gateway 2018.4
ibm datapower_gateway *
CVE-2018-1664 LOW

IBM DataPower Gateway 7.1.0.0 - 7.1.0.23, 7.2.0.0 - 7.2.0.21, 7.5.0.0 - 7.5.0.16, 7.5.1.0 - 7.5.1.15, 7.5.2.0 - 7.5.2.15, and 7.6.0.0 - 7.6.0.8 as well as IBM DataPower Gateway CD 7.7.0.0 - 7.7.1.2 echoing of AMP management interface authorization headers exposes login credentials in browser cache. IBM X-Force ID: 144890.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm datapower_gateway *
CVE-2018-1665 MEDIUM

IBM DataPower Gateway 7.6.0.0 through 7.6.0.10, 7.5.2.0 through 7.5.2.17, 7.5.1.0 through 7.5.1.17, 7.5.0.0 through 7.5.0.18, and 7.7.0.0 through 7.7.1.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 144891.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-326,

Products Affected

Vendor Product Version
ibm datapower_gateway *
CVE-2018-1666 MEDIUM

IBM DataPower Gateway 2018.4.1.0, 7.6.0.0 through 7.6.0.11, 7.5.2.0 through 7.5.2.18, 7.5.1.0 through 7.5.1.18, 7.5.0.0 through 7.5.0.19, and 7.7.0.0 through 7.7.1.3 could allow an authenticated user to inject arbitrary messages that would be displayed on the UI. IBM X-Force ID: 144892.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm datapower_gateway *
ibm datapower_gateway 2018.4.1.0
CVE-2018-1667 LOW

IBM DataPower Gateway 7.6.0.0 through 7.6.0.10, 7.5.2.0 through 7.5.2.17, 7.5.1.0 through 7.5.1.17, 7.5.0.0 through 7.5.0.18, and 7.7.0.0 through 7.7.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 144893.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm datapower_gateway *
CVE-2018-1668 MEDIUM

IBM DataPower Gateway 7.5.0.0 through 7.5.0.19, 7.5.1.0 through 7.5.1.18, 7.5.2.0 through 7.5.2.18, and 7.6.0.0 through 7.6.0.11 appliances allows "null" logins which could give read access to IPMI data to obtain sensitive information. IBM X-Force ID: 144894.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm datapower_gateway *
CVE-2018-1669 MEDIUM

IBM DataPower Gateway 7.1.0.0 - 7.1.0.23, 7.2.0.0 - 7.2.0.21, 7.5.0.0 - 7.5.0.16, 7.5.1.0 - 7.5.1.15, 7.5.2.0 - 7.5.2.15, and 7.6.0.0 - 7.6.0.8 as well as IBM DataPower Gateway CD 7.7.0.0 - 7.7.1.2 are vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 144950.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm datapower_gateway *
CVE-2018-1670 MEDIUM

IBM Financial Transaction Manager for ACH Services for Multi-Platform 3.0.2 could allow an authenticated user to obtain sensitive product configuration information from log files. IBM X-Force ID: 144946.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm financial_transaction_manager 3.0.2.0
ibm financial_transaction_manager 3.0.2.1
CVE-2018-1671 MEDIUM

IBM Curam Social Program Management 7.0.3 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-force ID: 144951.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm curam_social_program_management 7.0.3.0
CVE-2018-1672 MEDIUM

IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 may fail to set the correct user context in certain impersonation scenarios, which can allow a user to act with the identity of a different user. IBM X-Force ID: 144958.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.1
ibm websphere_portal 8.0.0.0
ibm websphere_portal 7.0.0.2
ibm websphere_portal 8.5.0.0
ibm websphere_portal 7.0.0.1
ibm websphere_portal 7.0.0.0
ibm websphere_portal 9.0.0.0
CVE-2018-1673 MEDIUM

IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 145108.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.1
ibm websphere_portal 8.0.0.0
ibm websphere_portal 7.0.0.2
ibm websphere_portal 8.5.0.0
ibm websphere_portal 7.0.0.1
ibm websphere_portal 7.0.0.0
ibm websphere_portal 9.0.0.0
CVE-2018-1674 MEDIUM

IBM Business Process Manager 8.5 through 8.6 and 18.0.0.0 through 18.0.0.1 are vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 145109.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm business_process_manager 8.5.6.0
ibm business_process_manager 8.5.5.0
ibm business_automation_workflow 18.0.0.0
ibm business_automation_workflow 18.0.0.1
ibm business_process_manager 8.5.7.0
ibm business_process_manager 8.6.0.0
ibm business_process_manager *
CVE-2018-1675 MEDIUM

IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 could expose password hashes in stored in system memory on target systems that are configured to use TADDM. IBM X-Force ID: 145110.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm tivoli_application_dependency_discovery_manager *
CVE-2018-1676 MEDIUM

IBM Planning Analytics 2.0.0 through 2.0.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 145118.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm planning_analytics_local *
CVE-2018-1677 LOW

IBM DataPower Gateways 7.1, 7.2, 7.5, 7.5.1, 7.5.2, 7.6, and 7.7 and IBM MQ Appliance are vulnerable to a denial of service, caused by the improper handling of full file system. A local attacker could exploit this vulnerability to cause a denial of service. IBM X-Force ID: 145171.

CVSS 2.0

Severity: LOW

Problem Type: CWE-755,

Products Affected

Vendor Product Version
ibm datapower_gateway *
CVE-2018-1679 MEDIUM

IBM Sterling B2B Integrator Standard Edition 5.2 through 5.2.6 could allow an unauthenticated user to obtain sensitive information that could be used in further attacks against the system. IBM X-Force ID: 145180.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator *
CVE-2018-1680 MEDIUM

IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 145236.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-521,

Products Affected

Vendor Product Version
ibm security_privileged_identity_manager 2.1.1
CVE-2018-1683 MEDIUM

IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive information, caused by the failure to encrypt ORB communication. IBM X-Force ID: 145455.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-311,

Products Affected

Vendor Product Version
ibm websphere_application_server *
CVE-2018-1684 MEDIUM

IBM WebSphere MQ 8.0 through 9.1 is vulnerable to a error with MQTT topic string publishing that can cause a denial of service attack. IBM X-Force ID: 145456.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_mq *
ibm websphere_mq 9.1.0.0
CVE-2018-1685 MEDIUM

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability in db2cacpy that could allow a local user to read any file on the system. IBM X-Force ID: 145502.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2 11.1
ibm db2 10.1
ibm db2 9.7
CVE-2018-1686 LOW

IBM Maximo Asset Management 7.6 through 7.6.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 145505.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm maximo_asset_management *
CVE-2018-1688 LOW

IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 through 6.0.6) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 145509.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
ibm rational_engineering_lifecycle_manager *
ibm rational_rhapsody_design_manager *
ibm rational_collaborative_lifecycle_management *
ibm rational_software_architect_design_manager *
ibm rational_doors_next_generation *
ibm rational_team_concert *
CVE-2018-1690 LOW

IBM Rhapsody Model Manager 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 145510.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rhapsody_model_manager 6.0.6
CVE-2018-1691 LOW

IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 145582.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
CVE-2018-1692 LOW

IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 145583.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
CVE-2018-1694 MEDIUM

IBM Jazz applications (IBM Rational Collaborative Lifecycle Management 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational DOORS Next Generation 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational Quality Manager 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational Rhapsody Design Manager 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational Software Architect Design Manager 5.0 through 5.02 and 6.0 through 6.0.1, IBM Rational Team Concert 5.0 through 5.02 and 6.0 through 6.0.6) could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 145609.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
ibm rational_engineering_lifecycle_manager *
ibm rational_rhapsody_design_manager *
ibm rational_collaborative_lifecycle_management *
ibm rational_software_architect_design_manager *
ibm rational_doors_next_generation *
ibm rational_team_concert *
CVE-2018-1695 MEDIUM

IBM WebSphere Application Server 7.0, 8.0, and 8.5.5 installations using Form Login could allow a remote attacker to conduct spoofing attacks. IBM X-Force ID: 145769.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-290,

Products Affected

Vendor Product Version
ibm websphere_application_server 8.5.5.0
ibm websphere_application_server 7.0.0.0
ibm websphere_application_server 8.0.0.0
CVE-2018-1697 MEDIUM

IBM Maximo Asset Management 7.6 could allow an authenticated user to enumerate usernames using a specially crafted HTTP request. IBM X-Force ID: 145966.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm maximo_asset_management 7.6
CVE-2018-1698 MEDIUM

IBM Maximo Asset Management 7.6 through 7.6.3 could allow an unauthenticated attacker to obtain sensitive information from error messages. IBM X-Force ID: 145967.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm maximo_asset_management *
CVE-2018-1699 MEDIUM

IBM Maximo Asset Management 7.6 through 7.6.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 145968.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm maximo_asset_management *
CVE-2018-1701 MEDIUM

IBM InfoSphere Information Server 11.7 could allow an authenciated user under specialized conditions to inject commands into the installation process that would execute on the WebSphere Application Server. IBM X-Force ID: 145970.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm infosphere_information_server_on_cloud 11.7
ibm infosphere_information_server 11.7
CVE-2018-1702 MEDIUM

IBM Platform Symphony 7.1 Fix Pack 1 and 7.1.1 and IBM Spectrum Symphony 7.1.2 and 7.2.0.2 are vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 146189.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm platform_symphony 7.1.1
ibm platform_symphony 7.1
ibm spectrum_symphony 7.1.2
ibm spectrum_symphony 7.2.0.2
CVE-2018-1704 MEDIUM

IBM Platform Symphony 7.1 Fix Pack 1 and 7.1.1 and IBM Spectrum Symphony 7.1.2 and 7.2.0.2 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 146339.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-601,

Products Affected

Vendor Product Version
ibm platform_symphony 7.1.1
ibm platform_symphony 7.1
ibm spectrum_symphony 7.1.2
ibm spectrum_symphony 7.2.0.2
CVE-2018-1705 MEDIUM

IBM Platform Symphony 7.1 Fix Pack 1 and 7.1.1 and IBM Spectrum Symphony 7.1.2 and 7.2.0.2 contain an information disclosure vulnerability that could allow an authenticated attacker to obtain highly sensitive information. IBM X-Force ID: 146340.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm platform_symphony 7.1.1
ibm platform_symphony 7.1
ibm spectrum_symphony 7.1.2
ibm spectrum_symphony 7.2.0.2
CVE-2018-1706 LOW

IBM Spectrum Symphony 7.2.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 146341.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm spectrum_symphony 7.2.0.2
CVE-2018-1708 MEDIUM

IBM Spectrum Symphony 7.1.2 and 7.2.0.2 could allow an authenticated user to obtain sensitive user information such as passwords through the WebUI. IBM X-Force ID: 146343.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm platform_symphony 7.1.1
ibm platform_symphony 7.1
ibm specturm_symphony 7.2.0.2
ibm specturm_symphony 7.1.2
CVE-2018-1710 MEDIUM

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.1, 10.5, and 11.1 tool db2licm is affected by buffer overflow vulnerability that can potentially result in arbitrary code execution. IBM X-Force ID: 146364.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2 11.1
ibm db2 10.1
CVE-2018-1711 MEDIUM

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to to gain privileges due to allowing modification of columns of existing tasks. IBM X-Force ID: 146369.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-732,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2 11.1
ibm db2 10.1
ibm db2 9.7
CVE-2018-1712 HIGH

IBM API Connect's Developer Portal 5.0.0.0 through 5.0.8.3 is vulnerable to Server Side Request Forgery. An attacker, using specially crafted input parameters can trick the server into making potentially malicious calls within the trusted network. IBM X-Force ID: 146370.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm api_connect *
CVE-2018-1715 LOW

IBM Maximo Asset Management 7.6 through 7.6.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 147003.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm maximo_asset_management *
CVE-2018-1716 MEDIUM

IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 147164.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.1
ibm websphere_portal 8.0.0.0
ibm websphere_portal 7.0.0.2
ibm websphere_portal 8.5.0.0
ibm websphere_portal 7.0.0.1
ibm websphere_portal 7.0.0.0
ibm websphere_portal 9.0.0.0
CVE-2018-1718 MEDIUM

IBM Sterling B2B Integrator Standard Edition 5.2.0.1 - 5.2.6.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 147166.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator *
CVE-2018-1719 MEDIUM

IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security under certain conditions. This could result in a downgrade of TLS protocol. A remote attacker could exploit this vulnerability to perform man-in-the-middle attacks. IBM X-Force ID: 147292.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_application_server *
CVE-2018-1722 HIGH

IBM Security Access Manager Appliance 9.0.4.0 and 9.0.5.0 could allow remote code execution when Advanced Access Control or Federation services are running. IBM X-Force ID: 147370.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm security_access_manager 9.0.4.0
ibm security_access_manager 9.0.5.0
CVE-2018-1723 LOW

IBM Spectrum Scale 4.1.1.0, 4.1.1.20, 4.2.0.0, 4.2.3.10, 5.0.0 and 5.0.1.2 could allow an unprivileged, authenticated user with access to a GPFS node to read arbitrary files available on this node. IBM X-Force ID: 147373.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm spectrum_scale *
CVE-2018-1724 MEDIUM

IBM Spectrum LSF 9.1.1 9.1.2, 9.1.3, and 10.1 could allow a local user to change their job user at job submission time due to improper file permission settings. IBM X-Force ID: 147439.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-732,

Products Affected

Vendor Product Version
ibm spectrum_lsf 9.1.1
ibm spectrum_lsf 9.1.2
ibm spectrum_lsf 10.1
ibm spectrum_lsf 9.1.3
CVE-2018-1727 MEDIUM

IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 147630.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm infosphere_information_server 11.3
ibm infosphere_information_server 11.5
ibm infosphere_information_server 9.1
ibm infosphere_information_server 11.7
CVE-2018-1728 LOW

IBM QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 147707.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm qradar_incident_forensics *
ibm qradar_incident_forensics 7.2.8
ibm qradar_incident_forensics 7.3.1
CVE-2018-1730 MEDIUM

IBM QRadar SIEM 7.2 and 7.3 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 147709.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.8
ibm qradar_security_information_and_event_manager 7.3.1
ibm qradar_security_information_and_event_manager *
CVE-2018-1731 LOW

IBM DOORS Next Generation (DNG/RRC) 5.0 through 5.0.3 and 6.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 147710.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm doors_next_generation *
CVE-2018-1732 MEDIUM

IBM QRadar Advisor with Watson 1.14.0 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 147810.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm qradar_advisor_with_watson *
CVE-2018-1733 MEDIUM

IBM QRadar SIEM 7.2 and 7.3 fails to adequately filter user-controlled input data for syntax that has control-plane implications which could allow an attacker to modify displayed content. IBM X-Force ID: 147811.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm qradar_security_information_and_event_manager 7.2.8
ibm qradar_security_information_and_event_manager 7.3.1
ibm qradar_security_information_and_event_manager *
CVE-2018-1736 MEDIUM

IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 147906.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-601,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.1
ibm websphere_portal 8.0.0.0
ibm websphere_portal 7.0.0.2
ibm websphere_portal 8.5.0.0
ibm websphere_portal 7.0.0.1
ibm websphere_portal 7.0.0.0
ibm websphere_portal 9.0.0.0
CVE-2018-1738 MEDIUM

IBM Security Key Lifecycle Manager 2.6, 2.7, 3.0 could allow an authenticated user to obtain highly sensitive information or jeopardize system integrity due to improper authentication mechanisms. IBM X-Force ID: 147907.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm security_key_lifecycle_manager *
CVE-2018-1740 LOW

IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148419.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm security_access_manager *
CVE-2018-1741 MEDIUM

IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 does not properly limit the number or frequency of interaction which could be used to cause a denial of service, compromise program logic or other consequences. IBM X-Force ID: 148420.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm security_key_lifecycle_manager *
CVE-2018-1742 HIGH

IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 148421.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-798,

Products Affected

Vendor Product Version
ibm security_key_lifecycle_manager *
CVE-2018-1743 MEDIUM

IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 148422.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_key_lifecycle_manager *
CVE-2018-1744 MEDIUM

IBM Security Key Lifecycle Manager 2.5, 2.6, 2.7, and 3.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 148423.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm security_key_lifecycle_manager *
CVE-2018-1745 HIGH

IBM Security Key Lifecycle Manager 2.7 and 3.0 could allow an unauthenticated user to restart the SKLM server due to missing authentication. IBM X-Force ID: 148424.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-306,

Products Affected

Vendor Product Version
ibm security_key_lifecycle_manager *
CVE-2018-1747 MEDIUM

IBM Security Key Lifecycle Manager 2.5, 2.6, 2.7, and 3.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 148428.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm security_key_lifecycle_manager *
CVE-2018-1749 MEDIUM

IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 uses incomplete blacklisting for input validation which allows attackers to bypass application controls resulting in direct impact to the system and data integrity. IBM X-Force ID: 148484.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm security_key_lifecycle_manager *
CVE-2018-1750 MEDIUM

IBM Security Key Lifecycle Manager 3.0 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. IBM X-Force ID: 148511.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-732,

Products Affected

Vendor Product Version
ibm security_key_lifecycle_manager 3.0.0.1
ibm security_key_lifecycle_manager 3.0
ibm security_key_lifecycle_manager *
CVE-2018-1751 MEDIUM

IBM Security Key Lifecycle Manager 3.0 through 3.0.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 148512.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-326,

Products Affected

Vendor Product Version
ibm security_key_lifecycle_manager *
CVE-2018-1753 MEDIUM

IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 148514.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_key_lifecycle_manager *
CVE-2018-1755 MEDIUM

IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive information, caused by incorrect transport being used when Liberty is configured to use Java Authentication SPI for Containers (JASPIC). This can happen when the Application Server is configured to permit access on non-secure (http) port and using JASPIC or JSR375 authentication.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_application_server *
CVE-2018-1756 MEDIUM

IBM Security Identity Governance and Intelligence 5.2.3.2 and 5.2.4 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, information in the back-end database. IBM X-Force ID: 148599.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm security_identity_governance_and_intelligence 5.2.3.2
ibm security_identity_governance_and_intelligence 5.2.4
CVE-2018-1757 MEDIUM

IBM Security Identity Governance and Intelligence 5.2.3.2 and 5.2.4 could allow an attacker to obtain sensitive information due to missing authentication in IGI for the survey application. IBM X-Force ID: 148601.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-306,

Products Affected

Vendor Product Version
ibm security_identity_governance_and_intelligence 5.2.3.2
ibm security_identity_governance_and_intelligence 5.2.4
CVE-2018-1759 LOW

IBM Rational Quality Manager 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148613.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
CVE-2018-1761 LOW

IBM Rational Team Concert 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148615.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_team_concert *
CVE-2018-1762 LOW

IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148616.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
ibm rational_engineering_lifecycle_manager *
ibm rational_rhapsody_design_manager *
ibm rational_collaborative_lifecycle_management *
ibm rational_software_architect_design_manager *
ibm rational_doors_next_generation *
ibm rational_team_concert *
CVE-2018-1763 LOW

IBM Rational Quality Manager 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148617.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
CVE-2018-1764 LOW

IBM Rational Quality Manager 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148618.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
CVE-2018-1766 LOW

IBM Team Concert (RTC) 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148620.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_team_concert *
CVE-2018-1767 MEDIUM

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Cachemonitor is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148621.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_application_server *
CVE-2018-1768 LOW

IBM Spectrum Protect Plus 10.1.0 and 10.1.1 could disclose sensitive information when an authorized user executes a test operation, the user id an password may be displayed in plain text within an instrumentation log file. IBM X-Force ID: 148622.

CVSS 2.0

Severity: LOW

Problem Type: CWE-532,

Products Affected

Vendor Product Version
ibm spectrum_protect_plus 10.1.1
ibm spectrum_protect_plus 10.1.0
CVE-2018-1770 MEDIUM

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 148686.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm websphere_application_server *
CVE-2018-1771 HIGH

IBM Domino 9.0 and 9.0.1 could allow an attacker to execute commands on the system by triggering a buffer overflow in the parsing of command line arguments passed to nsd.exe. IBM X-force ID: 148687.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm domino 9.0.0.0
ibm domino 9.0.1.10
ibm domino *
ibm notes 9.0.1.10
ibm notes 9.0.0.0
ibm notes *
CVE-2018-1772 LOW

IBM SPSS Analytic Server 3.1.1.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148689.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm spss_analytic_server 3.1.1.1
CVE-2018-1773 MEDIUM

IBM Datacap Fastdoc Capture 9.1.1, 9.1.3, and 9.1.4 could allow an authenticated user to bypass future authentication mechanisms once the initial login is completed. IBM X-Force ID: 148691.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm datacap 9.1.1
ibm datacap 9.1.4
ibm datacap 9.1.3
CVE-2018-1774 MEDIUM

IBM API Connect 5.0.0.0, 5.0.8.4, 2018.1 and 2018.3.6 is vulnerable to CSV injection via the developer portal and analytics that could contain malicious commands that would be executed once opened by an administrator. IBM X-Force ID: 148692.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-1236,

Products Affected

Vendor Product Version
ibm api_connect *
CVE-2018-1775 MEDIUM

IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products versions 7.5 through 8.2 could allow an authenticated user to download arbitrary files from the operating system. IBM X-Force ID: 148757.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm spectrum_virtualize_software_for_public_cloud *
ibm spectrum_virtualize_software *
CVE-2018-1777 LOW

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148800.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_application_server *
CVE-2018-1778 HIGH

IBM LoopBack (IBM API Connect 2018.1, 2018.4.1, 5.0.8.0, and 5.0.8.4) could allow an attacker to bypass authentication if the AccessToken Model is exposed over a REST API, it is then possible for anyone to create an AccessToken for any User provided they know the userId and can hence get access to the other user’s data / access to their privileges (if the user happens to be an Admin for example). IBM X-Force ID: 148801.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm api_connect *
CVE-2018-1779 MEDIUM

IBM API Connect 2018.1 through 2018.3.7 could allow an unauthenticated attacker to cause a denial of service due to not setting limits on JSON payload size. IBM X-Force ID: 148802.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-770,

Products Affected

Vendor Product Version
ibm api_connect *
CVE-2018-1780 HIGH

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local db2 instance owner to obtain root access by exploiting a symbolic link attack to read/write/corrupt a file that they originally did not have permission to access. IBM X-Force ID: 148803.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-59,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2 11.1
ibm db2 10.1
ibm db2 9.7
CVE-2018-1781 HIGH

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to obtain root access by exploiting a symbolic link attack to read/write/corrupt a file that they originally did not have permission to access. IBM X-Force ID: 148804.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-59,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2 11.1
ibm db2 10.1
ibm db2 9.7
CVE-2018-1782 MEDIUM

IBM GPFS (IBM Spectrum Scale 5.0.1.0 and 5.0.1.1) allows a local, unprivileged user to cause a kernel panic on a node running GPFS by accessing a file that is stored on a GPFS file system with mmap, or by executing a crafted file stored on a GPFS file system. IBM X-Force ID: 148805.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm spectrum_scale 5.0.1.0
ibm spectrum_scale 5.0.1.1
CVE-2018-1783 LOW

IBM GPFS (IBM Spectrum Scale 4.1.1.0, 4.1.1.20, 4.2.0.0, 4.2.3.10, 5.0.0 and 5.0.1.2) command line utility allows an unprivileged, authenticated user with access to a GPFS node to forcefully terminate GPFS and deny access to data available through GPFS. IBM X-Force ID: 148806.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm spectrum_scale *
CVE-2018-1784 HIGH

IBM API Connect 5.0.0.0 and 5.0.8.4 is affected by a NoSQL Injection in MongoDB connector for the LoopBack framework. IBM X-Force ID: 148807.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm api_connect *
CVE-2018-1785 MEDIUM

IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive information. IBM X-Force ID: 148870.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 3.9 3.6

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-326,

Products Affected

Vendor Product Version
ibm spectrum_protect_client *
ibm spectrum_protect_for_virtual_environments *
CVE-2018-1786 MEDIUM

IBM Spectrum Protect 7.1 and 8.1 dsmc and dsmcad processes incorrectly accumulate TCP/IP sockets in a CLOSE_WAIT state. This can cause TCP/IP resource leakage and may result in a denial of service. IBM X-Force ID: 148871.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-400,

Products Affected

Vendor Product Version
ibm spectrum_protect *
ibm tivoli_storage_manager_for_virtual_environments_data_protection_for_hyper-v *
ibm tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware *
ibm tivoli_storage_manager *
ibm spectrum_protect_manager_for_virtual_environments_data_protection_for_vmware *
ibm spectrum_protect_for_virtual_environments_data_protection_for_hyper-v *
CVE-2018-1788 LOW

IBM Spectrum Protect Server 7.1 and 8.1 could disclose highly sensitive information via trace logs to a local privileged user. IBM X-Force ID: 148873.

CVSS 2.0

Severity: LOW

Problem Type: CWE-532,

Products Affected

Vendor Product Version
ibm spectrum_protect_server *
CVE-2018-1789 MEDIUM

IBM API Connect v2018.1.0 through v2018.3.4 could allow an attacker to send a specially crafted request to conduct a server side request forgery attack. IBM X-Force ID: 148939.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-918,

Products Affected

Vendor Product Version
ibm api_connect *
CVE-2018-1791 MEDIUM

IBM Connections 5.0, 5.5, and 6.0 is vulnerable to an External Service Interaction attack, caused by improper validation of a request property. By submitting suitable payloads, an attacker could exploit this vulnerability to induce the Connections server to attack other systems. IBM X-Force ID: 148946.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm connections 5.0
ibm connections 5.5
ibm connections 6.0
CVE-2018-1792 HIGH

IBM WebSphere MQ 8.0.0.0 through 8.0.0.10, 9.0.0.0 through 9.0.0.5, 9.0.1 through 9.0.5, and 9.1.0.0 could allow a local user to inject code that could be executed with root privileges. IBM X-Force ID: 148947.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-94,

Products Affected

Vendor Product Version
ibm websphere_mq *
ibm websphere_mq 9.1.0.0
CVE-2018-1793 MEDIUM

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using SAML ear is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148948.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_application_server 9.0
ibm websphere_application_server 7.0
ibm websphere_application_server 8.0
ibm websphere_application_server 8.5
CVE-2018-1794 MEDIUM

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using OAuth ear is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148949.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_application_server *
CVE-2018-1795 MEDIUM

IBM Robotic Process Automation with Automation Anywhere Enterprise 10 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 149073.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm robotic_process_automation_with_automation_anywhere 10.0
CVE-2018-1797 MEDIUM

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using Enterprise bundle Archives (EBA) could allow a local attacker to traverse directories on the system. By persuading a victim to extract a specially-crafted ZIP archive containing "dot dot slash" sequences (../), an attacker could exploit this vulnerability to write to arbitrary files on the system. Note: This vulnerability is known as "Zip-Slip". IBM X-Force ID: 149427.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm websphere_application_server *
CVE-2018-1798 MEDIUM

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 149428.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_application_server *
CVE-2018-1799 LOW

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local unprivileged user to overwrite files on the system which could cause damage to the database. IBM X-Force ID: 149429.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2 11.1
ibm db2 10.1
ibm db2 9.7
CVE-2018-1800 LOW

IBM Sterling B2B Integrator Standard Edition 5.2.6.0 and 6.2.6.1 could allow a local user to obtain highly sensitive information during a short time period when installation is occurring. IBM X-Force ID: 149607.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator *
ibm sterling_b2b_integrator 6.2.6.1
CVE-2018-1801 MEDIUM

IBM App Connect V11.0.0.0 through V11.0.0.1, IBM Integration Bus V10.0.0.0 through V10.0.0.13, IBM Integration Bus V9.0.0.0 through V9.0.0.10, and WebSphere Message Broker V8.0.0.0 through V8.0.0.9 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to consume memory resources. IBM X-Force ID: 149639.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm websphere_message_broker *
ibm app_connect *
ibm integration_bus *
CVE-2018-1802 MEDIUM

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 binaries load shared libraries from an untrusted path potentially giving low privilege user full access to the DB2 instance account by loading a malicious shared library. IBM X-Force ID: 149640.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-426,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2 11.1
ibm db2 10.1
ibm db2 9.7
CVE-2018-1803 MEDIUM

IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 149702.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-1021,

Products Affected

Vendor Product Version
ibm security_access_manager *
CVE-2018-1804 MEDIUM

IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 does not set the secure attribute on authorization tokens or session cookies. This could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 149703.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-384,

Products Affected

Vendor Product Version
ibm security_access_manager *
CVE-2018-1805 MEDIUM

IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 149704.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_access_manager *
CVE-2018-1808 MEDIUM

IBM WebSphere Commerce 9.0.0.0 through 9.0.0.6 could allow some server-side code injection due to inadequate input control. IBM X-Force ID: 149828.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-94,

Products Affected

Vendor Product Version
ibm websphere_commerce *
CVE-2018-1812 LOW

IBM Robotic Process Automation with Automation Anywhere Enterprise 10 is vulnerable to persistent cross-site scripting, caused by missing escaping of a database field. An attacker that has access to the Control Room database could exploit this vulnerability to execute script in a victim's web browser within the security context of the hosting Web site, once victim opens a certain page in Control Room. IBM X-Force ID: 149883.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm robotic_process_automation_with_automation_anywhere 10.0
CVE-2018-1813 MEDIUM

IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 uses incomplete blacklisting for input validation which allows attackers to bypass application controls resulting in direct impact to the system and data integrity. IBM X-Force ID: 150017.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm security_access_manager *
CVE-2018-1814 MEDIUM

IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 150018.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-326,

Products Affected

Vendor Product Version
ibm security_access_manager *
CVE-2018-1815 MEDIUM

IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 for Enterprise Single-Sign On is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 150019.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm security_access_manager *
CVE-2018-1817 MEDIUM

IBM Security Guardium 10 and 10.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 150021.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm security_guardium *
CVE-2018-1818 HIGH

IBM Security Guardium 10 and 10.5 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 150022.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-798,

Products Affected

Vendor Product Version
ibm security_guardium *
CVE-2018-1819 MEDIUM

IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.0.2, 3.0.4, 3.0.6, and 3.2.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-force ID: 150023.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm financial_transaction_manager 3.0.2.0
ibm financial_transaction_manager 3.0.6.0
ibm financial_transaction_manager 3.1.0.2
ibm financial_transaction_manager 3.0.6.1
ibm financial_transaction_manager 3.0.4.0
ibm financial_transaction_manager 3.0.2.1
ibm financial_transaction_manager 3.1.0.1
ibm financial_transaction_manager 3.2.0.0
ibm financial_transaction_manager 3.1.0.0
CVE-2018-1820 LOW

IBM WebSphere Portal 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 150096.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_portal 8.0.0.1
ibm websphere_portal 8.0.0.0
ibm websphere_portal 8.5.0.0
ibm websphere_portal 9.0.0.0
CVE-2018-18202 MEDIUM

The QLogic 4Gb Fibre Channel 5.5.2.6.0 and 4/8Gb SAN 7.10.1.20.0 modules for IBM BladeCenter have an undocumented support account with a support password, an undocumented diags account with a diags password, and an undocumented prom account with a prom password.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm qlogic_4_gb_fibre_channel_expansion_card_firmware 5.5.2.6.0
ibm qlogic_20-port_4/8_gb_san_switch_module_firmware 7.10.1.20.0
CVE-2018-1821 MEDIUM

IBM Operational Decision Management 8.5, 8.6, 8.7, 8.8, and 8.9 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 150170.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm operational_decision_manager *
CVE-2018-1822 HIGH

IBM FlashSystem 900 product GUI allows a specially crafted attack to bypass the authentication requirements of the system, resulting in the ability to remotely change the superuser password. This can be used by an attacker to gain administrative control or to deny service. IBM X-Force ID: 150296.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-287,

Products Affected

Vendor Product Version
ibm flashsystem_900_firmware 1.4
ibm flashsystem_840_firmware 1.4
CVE-2018-1823 LOW

IBM Rational Quality Manager 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 150426.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
ibm rational_collaborative_lifecycle_management *
CVE-2018-1824 LOW

IBM Rational Quality Manager 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 150427.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
ibm rational_collaborative_lifecycle_management *
CVE-2018-1825 LOW

IBM Rational Quality Manager 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 150428.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
ibm rational_collaborative_lifecycle_management *
CVE-2018-1829 LOW

IBM Rational Quality Manager 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 150432.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
ibm rational_collaborative_lifecycle_management *
CVE-2018-1833 LOW

IBM Event Streams 2018.3.0 could allow a remote attacker to submit an API request with a fake Host request header. An attacker, who has already gained authorised access via the CLI, could exploit this vulnerability to spoof the request header. IBM X-Force ID: 150507.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm event_streams 2018.3.0
CVE-2018-1834 HIGH

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability that could allow a local user to escalate their privileges to root through a symbolic link attack. IBM X-Force ID: 150511.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-59,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2 11.1
ibm db2 10.1
ibm db2 9.7
CVE-2018-1835 MEDIUM

IBM Daeja ViewONE Professional, Standard & Virtual 5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 150514.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm daeja_viewone 5.0
CVE-2018-1836 LOW

IBM WebSphere MQ 9.0.2, 9.0.3, 9.0.4, 9.0.5, 9.1.0.0, and 9.1.0.1 console is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 150661.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm mq *
CVE-2018-1838 MEDIUM

IBM WebSphere Application Server 8.5 and 9.0 in IBM Cloud could allow a remote attacker to obtain sensitive information caused by improper handling of passwords. IBM X-Force ID: 150811.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_application_server 9.0.0.0
ibm websphere_application_server *
ibm websphere_application_server 8.5.0.0
CVE-2018-1840 MEDIUM

IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to gain elevated privileges on the system, caused when a security domain is configured to use a federated repository other than global federated repository and then migrated to a newer release of WebSphere Application Server. IBM X-Force ID: 150813.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-668,

Products Affected

Vendor Product Version
ibm websphere_application_server *
CVE-2018-1841 LOW

IBM Cloud Private 2.1.0 could allow a local user to obtain the CA Private Key due to it being world readable in boot/master node. IBM X-Force ID: 150901.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm cloud_private 2.1.0
CVE-2018-1842 LOW

IBM Cognos Analytics 11 Configuration tool, under certain circumstances, will bypass OIDC namespace signature verification on its id_token. IBM X-Force ID: 150902.

CVSS 2.0

Severity: LOW

Problem Type: CWE-347,

Products Affected

Vendor Product Version
netapp oncommand_insight -
ibm cognos_analytics *
CVE-2018-1843 LOW

The Identity and Access Management (IAM) services (IBM Cloud Private 3.1.0) do not use a secure channel, such as SSL, to exchange information only when accessed internally from within the cluster. It could be possible for an attacker with access to network traffic to sniff packets from the connection and uncover data. IBM X-Force ID: 150903

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm cloud_private 3.1.0
CVE-2018-1844 MEDIUM

IBM FileNet Content Manager 5.2.1 and 5.5.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 150904.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm filenet_content_manager 5.2.1
ibm filenet_content_manager 5.5.0
CVE-2018-1846 MEDIUM

IBM Rational Engineering Lifecycle Manager 5.0 through 5.0.2 and 6.0 through 6.0.6 are vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 150945.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm rational_engineering_lifecycle_manager *
CVE-2018-1848 MEDIUM

IBM Business Automation Workflow 18.0.0.0 and 18.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 150947.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm business_process_manager 8.5.6.0
ibm business_process_manager 8.5.5.0
ibm business_automation_workflow 18.0.0.0
ibm business_automation_workflow 18.0.0.1
ibm business_process_manager 8.5.7.0
ibm business_process_manager 8.6.0.0
ibm business_process_manager *
ibm websphere *
CVE-2018-1850 HIGH

IBM Security Access Manager Appliance 9.0.3.1, 9.0.4.0 and 9.0.5.0 could allow unauthorized administration operations when Advanced Access Control services are running. IBM X-Force ID: 150998.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm security_access_manager 9.0.3.1
ibm security_access_manager 9.0.4.0
ibm security_access_manager 9.0.5.0
CVE-2018-1851 HIGH

IBM WebSphere Application Server Liberty OpenID Connect could allow a remote attacker to execute arbitrary code on the system, caused by improper deserialization. By sending a specially-crafted request to the RP service, an attacker could exploit this vulnerability to execute arbitrary code. IBM X-Force ID: 150999.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-502,

Products Affected

Vendor Product Version
ibm websphere_application_server *
CVE-2018-1857 MEDIUM

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1 could allow a user to bypass FGAC control and gain access to data they shouldn't be able to see. IBM X-Force ID: 151155.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm db2 11.1
CVE-2018-1859 MEDIUM

IBM API Connect 5.0.0.0 through 5.0.8.4 could allow a user authenticated as an administrator with limited rights to escalate their privileges. IBM X-Force ID: 151258.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm api_connect *
CVE-2018-1871 LOW

IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.0.0, 3.0.2, and 3.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 151329.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm financial_transaction_manager 3.0.5.0
ibm financial_transaction_manager 3.0.2.0
ibm financial_transaction_manager 3.0.5.1
ibm financial_transaction_manager 3.0.0.0
CVE-2018-1872 LOW

IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 151330.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm maximo_asset_management 7.6
CVE-2018-1874 LOW

IBM API Connect 5.0.0.0 through 5.0.8.5 could display highly sensitive information to an attacker with physical access to the system. IBM X-Force ID: 151636.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm api_connect *
CVE-2018-1875 MEDIUM

IBM InfoSphere Information Governance Catalog 11.3, 11.5, and 11.7 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 151639.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-601,

Products Affected

Vendor Product Version
ibm infosphere_information_governance_catalog 11.7
ibm infosphere_information_governance_catalog 11.3
ibm infosphere_information_server_on_cloud 11.7
ibm infosphere_information_governance_catalog 11.5
ibm infosphere_information_server_on_cloud 11.5
CVE-2018-1876 LOW

IBM Robotic Process Automation with Automation Anywhere 11 could under certain cases, display the password in a Control Room log file after installation. IBM X-Force ID: 151707.

CVSS 2.0

Severity: LOW

Problem Type: CWE-532,

Products Affected

Vendor Product Version
ibm robotic_process_automation_with_automation_anywhere 11.0
CVE-2018-1877 LOW

IBM Robotic Process Automation with Automation Anywhere 11 could store highly sensitive information in the form of unencrypted passwords that would be available to a local user. IBM X-Force ID: 151713.

CVSS 2.0

Severity: LOW

Problem Type: CWE-312,

Products Affected

Vendor Product Version
ibm robotic_process_automation_with_automation_anywhere 11.0
CVE-2018-1878 MEDIUM

IBM Robotic Process Automation with Automation Anywhere 11 could disclose sensitive information in a web request that could aid in future attacks against the system. IBM X-Force ID: 151714.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm robotic_process_automation_with_automation_anywhere 11
CVE-2018-1883 MEDIUM

A problem within the IBM MQ 9.0.2, 9.0.3, 9.0.4, 9.0.5, and 9.1.0.0 Console REST API Could allow attackers to execute a denial of service attack preventing users from logging into the MQ Console REST API. IBM X-Force ID: 151969.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm mq 9.1.0.0
ibm mq *
CVE-2018-1884 MEDIUM

IBM Case Manager 5.2.0.0, 5.2.0.4, 5.2.1.0, 5.2.1.7, 5.3.0.0, and 5.3.3.0 is vulnerable to a "zip slip" vulnerability which could allow a remote attacker to execute code using directory traversal techniques. IBM X-Force ID: 151970.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm case_manager 5.3.3.0
ibm case_manager 5.2.1.0
ibm case_manager 5.2.1.7
ibm case_manager 5.2.0.4
ibm case_manager 5.2.0.0
ibm case_manager 5.3.0.0
CVE-2018-1886 MEDIUM

IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 152021.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_access_manager *
CVE-2018-1887 MEDIUM

IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 152078.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-798,

Products Affected

Vendor Product Version
ibm security_access_manager *
CVE-2018-1888 MEDIUM

An untrusted search path vulnerability in IBM i Access for Windows versions 7.1 and earlier on Windows can allow arbitrary code execution via a Trojan horse DLL in the current working directory, related to use of the LoadLibrary function. IBM X-Force ID: 152079.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-426,

Products Affected

Vendor Product Version
ibm i_access *
CVE-2018-1889 LOW

IBM Security Guardium 10.0 and 10.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152080.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm security_guardium *
CVE-2018-1890 MEDIUM

IBM SDK, Java Technology Edition Version 8 on the AIX platform uses absolute RPATHs which may facilitate code injection and privilege elevation by local users. IBM X-Force ID: 152081.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-427,

Products Affected

Vendor Product Version
ibm sdk 8.0
CVE-2018-1891 LOW

IBM Security Guardium 10 and 10.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152082.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm security_guardium *
CVE-2018-1895 LOW

IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152159.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm infosphere_information_governance_catalog 11.7
ibm infosphere_information_governance_catalog 11.3
ibm infosphere_information_server_on_cloud 11.7
ibm infosphere_information_governance_catalog 11.5
ibm infosphere_information_server_on_cloud 11.5
CVE-2018-1896 LOW

IBM Connections 5.0, 5.5, and 6.0 is vulnerable to possible host header injection attack that could cause navigation to the attacker's domain. IBM X-Force ID: 152456.

CVSS 2.0

Severity: LOW

Problem Type: CWE-74,

Products Affected

Vendor Product Version
ibm connections 5.0
ibm connections 5.5
ibm connections 6.0
CVE-2018-1897 MEDIUM

IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5., and 11.1 db2pdcfg is vulnerable to a stack based buffer overflow, caused by improper bounds checking which could allow an attacker to execute arbitrary code. IBM X-Force ID: 152462.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-787,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2 11.1
ibm db2 10.1
ibm db2 9.7
CVE-2018-1899 LOW

IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow an attacker to change one of the settings related to InfoSphere Business Glossary Anywhere due to improper access control. IBM X-Force ID: 152528.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm infosphere_information_governance_catalog 11.7
ibm infosphere_information_governance_catalog 11.3
ibm infosphere_information_server_on_cloud 11.7
ibm infosphere_information_governance_catalog 11.5
ibm infosphere_information_server_on_cloud 11.5
CVE-2018-1900 LOW

IBM Curam Social Program Management 6.0.5, 6.1.1, 6.2.0, 7.0.1, and 7.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152529.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm curam_social_program_management *
CVE-2018-1901 MEDIUM

IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to temporarily gain elevated privileges on the system, caused by incorrect cached value being used. IBM X-Force ID: 152530.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_application_server *
CVE-2018-1902 MEDIUM

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to spoof connection information which could be used to launch further attacks against the system. IBM X-Force ID: 152531.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_application_server *
CVE-2018-1904 HIGH

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbitrary Java code through an administrative client class with a serialized object from untrusted sources. IBM X-Force ID: 152533.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-502,

Products Affected

Vendor Product Version
ibm websphere_application_server *
CVE-2018-1905 MEDIUM

IBM WebSphere Application Server 9.0.0.0 through 9.0.0.9 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 152534.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm websphere_application_server *
CVE-2018-1906 MEDIUM

IBM InfoSphere Information Server 11.3, 11.5, and 11.7could allow an authenticated user to download code using a specially crafted HTTP request. IBM X-Force ID: 152663.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm infosphere_information_server 11.3
ibm infosphere_information_server 11.5
ibm infosphere_information_server_on_cloud 11.7
ibm infosphere_information_server_on_cloud 11.5
ibm infosphere_information_server 11.7
CVE-2018-1908 LOW

IBM Robotic Process Automation with Automation Anywhere 11 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152671.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm robotic_process_automation_with_automation_anywhere *
CVE-2018-1910 LOW

IBM Rational Engineering Lifecycle Manager 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152734.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_engineering_lifecycle_manager *
CVE-2018-1911 LOW

IBM DOORS Next Generation (DNG/RRC) 5.0 through 5.0.2 and 6.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152735.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_doors_next_generation *
CVE-2018-1912 LOW

IBM DOORS Next Generation (DNG/RRC) 6.0.2 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152736.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_doors_next_generation *
CVE-2018-1913 LOW

IBM DOORS Next Generation (DNG/RRC) 5.0 through 5.0.3 and 6.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152737.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm doors_next_generation *
CVE-2018-1914 LOW

IBM Rational Engineering Lifecycle Manager 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152738.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_engineering_lifecycle_manager *
CVE-2018-1916 LOW

IBM Jazz Foundation (IBM Rational Engineering Lifecycle Manager 5.0 through 6.0.6) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152740.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
ibm rational_engineering_lifecycle_manager *
ibm rational_rhapsody_design_manager *
ibm rational_collaborative_lifecycle_management *
ibm rational_software_architect_design_manager *
ibm rational_doors_next_generation *
ibm rational_team_concert *
CVE-2018-1917 MEDIUM

IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow an authenticated user to access JSP files and disclose sensitive information. IBM X-Force ID: 152784.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm infosphere_information_server 11.3
ibm infosphere_information_server 11.5
ibm infosphere_information_server_on_cloud 11.7
ibm infosphere_information_server_on_cloud 11.5
ibm infosphere_information_server 11.7
CVE-2018-1918 LOW

IBM Jazz Reporting Service (JRS) 6.0.3, 6.0.4, 6.0.5, and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152785.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm jazz_reporting_service *
CVE-2018-1920 MEDIUM

IBM Marketing Platform 9.1.0, 9.1.2 and 10.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 152855.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm marketing_platform 10.1
ibm marketing_platform 9.1.2
ibm marketing_platform 9.1.0
CVE-2018-1922 MEDIUM

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is affected by buffer overflow vulnerability that can potentially result in arbitrary code execution. IBM X-Force ID: 152858.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2 11.1
ibm db2 10.1
ibm db2 9.7
CVE-2018-1923 MEDIUM

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is affected by buffer overflow vulnerability that can potentially result in arbitrary code execution. IBM X-Force ID: 152859.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2 11.1
ibm db2 10.1
ibm db2 9.7
CVE-2018-1926 MEDIUM

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Admin Console is vulnerable to cross-site request forgery, caused by improper validation of user-supplied input. By persuading a user to visit a malicious URL, a remote attacker could send a specially-crafted request. An attacker could exploit this vulnerability to perform CSRF attack and update available applications. IBM X-Force ID: 152992.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm websphere_application_server *
CVE-2018-1927 MEDIUM

IBM StoredIQ 7.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 153118.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
ibm storediq *
CVE-2018-1928 LOW

IBM StoredIQ 7.6.0 does not implement proper authorization of user roles due to which it was possible for a low privileged user to access the application endpoints of high privileged users and also perform some state changing actions restricted to a high privileged user. IBM X-Force ID: 153119.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm storediq *
CVE-2018-1929 MEDIUM

IBM Rational Engineering Lifecycle Manager 5.0 through 6.0.6 could allow a malicious user to be allowed to view any view if he knows the URL link of a the view, and access information that should not be able to see. IBM X-Force ID: 153120.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm rational_engineering_lifecycle_manager *
CVE-2018-1932 MEDIUM

IBM API Connect 5.0.0.0 through 5.0.8.4 is affected by a vulnerability in the role-based access control in the management server that could allow an authenticated user to obtain highly sensitive information. IBM X-Force ID: 153175.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm api_connect *
CVE-2018-1935 MEDIUM

IBM Connections 5.0, 5.5, and 6.0 could allow an authenticated user to obtain sensitive information from invalid request error messages. IBM X-Force ID: 153315.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm connections 5.0
ibm connections 5.5
ibm connections 6.0
CVE-2018-1936 HIGH

IBM DB2 9.7, 10.1, 10.5, and 11.1 libdb2e.so.1 is vulnerable to a stack based buffer overflow, caused by improper bounds checking which could allow an attacker to execute arbitrary code. IBM X-Force ID: 153316.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-787,

Products Affected

Vendor Product Version
ibm db2 11.1.2.2
ibm db2 11.1.3.3
ibm db2 11.1.4.4
ibm db2 9.7.0.9
ibm db2 10.1.0.1
ibm db2 10.1.0.6
ibm db2 9.7.0.5
ibm db2 9.7.0.0
ibm db2 9.7.0.6
ibm db2 9.7.0.10
ibm db2 11.1.0.0
ibm db2 9.7.0.8
ibm db2 10.5.0.1
ibm db2 10.1.0.4
ibm db2 10.5.0.9
ibm db2 10.5.0.8
ibm db2 10.5.0.2
ibm db2 9.7.0.2
ibm db2 9.7.0.1
ibm db2 10.1.0.5
ibm db2 10.5.0.10
ibm db2 10.1.0.2
ibm db2 10.5.0.4
ibm db2 11.1.1.1
ibm db2 10.1.0.0
ibm db2 10.1.0.3
ibm db2 10.5.0.7
ibm db2 9.7.0.4
ibm db2 9.7.0.7
ibm db2 10.5.0.0
ibm db2 9.7.0.3
ibm db2 10.5.0.5
ibm db2 10.5.0.3
ibm db2 9.7.0.11
ibm db2 10.5.0.6
CVE-2018-1937 LOW

IBM Cloud Private 3.1.1 could alllow a local user with administrator privileges to intercept highly sensitive unencrypted data. IBM X-Force ID: 153317.

CVSS 2.0

Severity: LOW

Problem Type: CWE-311,

Products Affected

Vendor Product Version
ibm cloud_private 3.1.1
CVE-2018-1938 LOW

IBM Cloud Private 3.1.1 could alllow a local user with administrator privileges to intercept highly sensitive unencrypted data. IBM X-Force ID: 153318.

CVSS 2.0

Severity: LOW

Problem Type: CWE-311,

Products Affected

Vendor Product Version
ibm cloud_private 3.1.1
CVE-2018-1939 MEDIUM

IBM Cloud Private 3.1.1 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 153319.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-601,

Products Affected

Vendor Product Version
ibm cloud_private 3.1.1
CVE-2018-1941 MEDIUM

IBM Campaign 9.1.0 and 9.1.2 could allow a local user to obtain admini privileges due to the application not validating access permissions. IBM X-Force ID: 153382.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-269,

Products Affected

Vendor Product Version
ibm campaign *
CVE-2018-1944 HIGH

IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 153386.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-798,

Products Affected

Vendor Product Version
ibm security_identity_governance_and_intelligence *
CVE-2018-1945 MEDIUM

IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 153387.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm security_identity_governance_and_intelligence *
CVE-2018-1946 MEDIUM

IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance supports interaction between multiple actors and allows those actors to negotiate which algorithm should be used as a protection mechanism such as encryption or authentication, but it does not select the strongest algorithm that is available to both parties. IBM X-Force ID: 153388.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-326,

Products Affected

Vendor Product Version
ibm security_identity_governance_and_intelligence *
CVE-2018-1947 MEDIUM

IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 153427.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm security_identity_governance_and_intelligence *
CVE-2018-1948 MEDIUM

IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 153428.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-384,

Products Affected

Vendor Product Version
ibm security_identity_governance_and_intelligence *
CVE-2018-1949 MEDIUM

IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 153429.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_identity_governance_and_intelligence *
CVE-2018-1950 MEDIUM

IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance generates an error message that includes sensitive information about its environment, users, or associated data which could be used in further attacks against the system. IBM X-Force ID: 153430.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm security_identity_governance_and_intelligence *
CVE-2018-1951 LOW

IBM Publishing Engine 2.1.2, 6.0.5, and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 153494.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm engineering_lifecycle_optimization_-_publishing 2.1.2
ibm engineering_lifecycle_optimization_-_publishing 6.0.6
ibm engineering_lifecycle_optimization_-_publishing 6.0.5
CVE-2018-1952 LOW

IBM Jazz Foundation (IBM Rational Engineering Lifecycle Manager 5.0 through 6.0.6) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 153495.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_quality_manager *
ibm rational_engineering_lifecycle_manager *
ibm rational_rhapsody_design_manager *
ibm rational_collaborative_lifecycle_management *
ibm rational_software_architect_design_manager *
ibm rational_doors_next_generation *
ibm rational_team_concert *
CVE-2018-1956 MEDIUM

IBM Security Identity Manager 6.0.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 153628.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-521,

Products Affected

Vendor Product Version
ibm security_identity_manager *
CVE-2018-1957 LOW

IBM WebSphere Application Server 9 could allow sensitive information to be available caused by mishandling of data by the application based on an incorrect return by the httpServletRequest#authenticate() API when an unprotected URI is accessed. IBM X-Force ID: 153629.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm websphere_application_server *
CVE-2018-1959 MEDIUM

IBM Security Identity Manager 7.0.1 Virtual Appliance contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 153633.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-798,

Products Affected

Vendor Product Version
ibm security_identity_manager *
CVE-2018-1962 LOW

IBM Security Identity Manager 7.0.1 Virtual Appliance does not invalidate session tokens when the logout button is pressed. The lack of proper session termination may allow attackers with local access to login into a closed browser session. IBM X-Force ID: 153658.

CVSS 2.0

Severity: LOW

Problem Type: CWE-384,

Products Affected

Vendor Product Version
ibm security_identity_manager *
CVE-2018-1967 MEDIUM

IBM Security Identity Manager 6.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 153748.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm security_identity_manager *
CVE-2018-1969 MEDIUM

IBM Security Identity Manager 6.0.0 allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment. IBM X-Force ID: 153750.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-434,

Products Affected

Vendor Product Version
ibm security_identity_manager *
CVE-2018-1970 MEDIUM

IBM Security Identity Manager 7.0.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 153751.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm security_access_manager *
CVE-2018-1973 HIGH

IBM API Connect 5.0.0.0 through 5.0.8.4 allows a user with limited 'API Administrator level access to give themselves full 'Administrator' level access through the members functionality. IBM X-Force ID: 153914.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-269,

Products Affected

Vendor Product Version
ibm api_connect *
CVE-2018-1974 MEDIUM

IBM WebSphere 8.0.0.0 through 9.1.1 could allow an authenticated attacker to escalate their privileges when using multiplexed channels. IBM X-Force ID: 153915.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm websphere_mq *
CVE-2018-1976 MEDIUM

IBM API Connect 5.0.0.0 through 5.0.8.4 is impacted by sensitive information disclosure via a REST API that could allow a user with administrative privileges to obtain highly sensitive information. IBM X-Force ID: 154031.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm api_connect *
CVE-2018-1977 MEDIUM

IBM DB2 for Linux, UNIX and Windows 11.1 (includes DB2 Connect Server) contains a denial of service vulnerability. A remote, authenticated DB2 user could exploit this vulnerability by issuing a specially-crafted SELECT statement with TRUNCATE function. IBM X-Force ID: 154032.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ibm db2 11.1
CVE-2018-1978 HIGH

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-ForceID: 154069.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2 11.1
ibm db2 10.1
ibm db2 9.7
CVE-2018-1980 HIGH

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-ForceID: 154078.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2 11.1
ibm db2 10.1
ibm db2 9.7
CVE-2018-1982 LOW

IBM Rational Team Concert 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 154135.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_team_concert *
CVE-2018-1983 LOW

IBM Rational Team Concert 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 154136.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_collaborative_lifecycle_management *
ibm rational_team_concert *
CVE-2018-1984 LOW

IBM Rational Team Concert 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 154137.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm rational_team_concert *
CVE-2018-1992 MEDIUM

The IBM Power 9 OP910, OP920, and FW910 boot firmware's bootloader is responsible for loading and validating the initial boot firmware image that drives the rest of the system's hardware initialization. The bootloader firmware contains a buffer overflow vulnerability such that, if an attacker were able to replace the initial boot firmware image with a very carefully crafted and sufficiently large, malicious replacement, it could cause the bootloader, during the load of that image, to overwrite its own instruction memory and circumvent secure boot protections, install trojans, etc. IBM X-Force ID: 154345.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
ibm power_system_s914_(9009-41a)_firmware *
ibm power_system_s924_(9009-42a)_firmware *
ibm power_system_lc921_(9006-12p)_firmware *
ibm power_system_h922_(9223-22h)_firmware *
ibm power_system_h924_(9223-42h)_firmware *
ibm power_system_l922_(9008-22l)_firmware *
ibm power_system_ac922_(8335-gth)_firmware *
ibm power_system_lc922_(9006-22p)_firmware *
ibm power_system_s922_(9009-22a)_firmware *
ibm power_system_ac922_(8335-gtg)_firmware *
ibm power_system_ac922_(8335-gtx)_firmware *
CVE-2018-1993 LOW

IBM Spectrum Scale (GPFS) 4.1.1, 4.2.0, 4.2.1, 4.2.2, 4.2.3, and 5.0.0 where the use of Local Read Only Cache (LROC) is enabled may caused read operation on a file to return data from a different file. IBM X-Force ID: 154440.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm spectrum_scale *
CVE-2018-1996 LOW

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could provide weaker than expected security, caused by the improper TLS configuration. A remote attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 154650.

CVSS 2.0

Severity: LOW

Problem Type: CWE-327,

Products Affected

Vendor Product Version
ibm websphere_application_server *
CVE-2018-1998 HIGH

IBM WebSphere MQ 8.0.0.0 through 9.1.1 could allow a local user to inject code that could be executed with root privileges. This is due to an incomplete fix for CVE-2018-1792. IBM X-ForceID: 154887.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-78,

Products Affected

Vendor Product Version
ibm websphere_mq *
CVE-2018-2006 MEDIUM

IBM Robotic Process Automation with Automation Anywhere 11 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to upload arbitrary files to the system. IBM X-Force ID: 155008.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
ibm robotic_process_automation_with_automation_anywhere *
CVE-2018-2009 MEDIUM

IBM API Connect v2018.1 and 2018.4.1 is affected by an information disclosure vulnerability in the consumer API. Any registered user can obtain a list of all other users in all other orgs, including email id/names, etc. IBM X-Force ID: 155148.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm api_connect *
CVE-2018-2019 MEDIUM

IBM Security Identity Manager 6.0.0 Virtual Appliance is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 155265.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm security_identity_manager 6.0.0.2
ibm security_identity_manager 6.0.0
ibm security_identity_manager 6.0.0.20
ibm security_identity_manager 6.0.0.5
ibm security_identity_manager 6.0.0.6
ibm security_identity_manager 6.0.0.18
ibm security_identity_manager 6.0.0.1
ibm security_identity_manager 6.0.0.4
ibm security_identity_manager 6.0.0.10
ibm security_identity_manager 6.0.0.0
ibm security_identity_manager 6.0.0.3
ibm security_identity_manager 6.0.0.19
ibm security_identity_manager 6.0.0.14
CVE-2018-2026 MEDIUM

IBM Financial Transaction Manager 3.2.1 for Digital Payments could allow an authenticated user to obtain a directory listing of internal product files. IBM X-Force ID: 155552.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm financial_transaction_manager 3.2.1.0
CVE-2018-9068 MEDIUM

The IMM2 First Failure Data Capture function collects management module logs and diagnostic information when a hardware error is detected. This information is made available for download through an SFTP server hosted on the IMM2 management network interface. In versions earlier than 4.90 for Lenovo System x and earlier than 6.80 for IBM System x, the credentials to access the SFTP server are hard-coded and described in the IMM2 documentation, allowing an attacker with management network access to obtain the collected FFDC data. After applying the update, the IMM2 will create random SFTP credentials for use with OneCLI.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-798,

Products Affected

Vendor Product Version
lenovo flex_system_x480_x6_firmware *
lenovo flex_system_x880_firmware *
lenovo system_x3950_x6_firmware *
ibm system_x3250_m4_firmware *
lenovo system_x3750_m4_firmware *
ibm system_x3500_m4_firmware *
ibm system_x3550_m4_firmware *
ibm bladecenter_hs22_firmware *
lenovo flex_system_x240_m5_firmware *
lenovo system_x3500_m5_firmware *
ibm nextscale_nx360_m4_firmware *
ibm system_x3950_x6_firmware *
lenovo system_x3250_m6_firmware *
ibm system_x3650_m4_bd_firmware *
lenovo system_x3550_m5_firmware *
ibm system_x3650_m4_firmware *
lenovo nextscale_nx360_m5_firmware *
ibm flex_system_x280_m4_firmware *
ibm flex_system_x880_m4_firmware *
ibm system_x3650_m4_hd_firmware *
ibm system_x3750_m4_firmware *
ibm system_x3530_m4_firmware *
lenovo flex_system_x440_m4_firmware *
ibm flex_system_x480_m4_firmware *
ibm system_x3100_m4_firmware *
ibm system_x3630_m4_firmware *
lenovo system_x3650_m5_firmware *
ibm idataplex_dx360_m4_firmware *
ibm system_x3250_m5_firmware *
ibm flex_system_x220_m4_firmware *
lenovo system_x3850_x6_firmware *
lenovo flex_system_x280_x6_firmware *
ibm flex_system_x440_m4_firmware *
ibm flex_system_x222_m4_firmware *
lenovo flex_system_x240_m4_firmware *
ibm flex_system_x240_m4_firmware *
ibm bladecenter_hs23e_firmware *
ibm system_x3100_m5_firmware *
ibm idataplex_dx360_m4_water_cooled_firmware *
ibm system_x3850_x6_firmware *
ibm system_x3300_m4_firmware *
ibm bladecenter_hs23_firmware *
CVE-2018-9085 MEDIUM

A write protection lock bit was left unset after boot on an older generation of Lenovo and IBM System x servers, potentially allowing an attacker with administrator access to modify the subset of flash memory containing Intel Server Platform Services (SPS) and the system Flash Descriptors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-276,

Products Affected

Vendor Product Version
ibm system_x3250_m4_firmware *
lenovo system_x3750_m4_firmware *
ibm system_x3500_m4_firmware *
ibm system_x3550_m4_firmware *
ibm system_x3950_x6_firmware *
ibm flex_system_x480_x6_firmware *
ibm system_x3650_m4_bd_firmware *
ibm system_x3650_m4_firmware *
ibm system_x3650_m4_hd_firmware *
ibm system_x3750_m4_firmware *
ibm system_x3530_m4_firmware *
lenovo flex_system_x440_m4_firmware *
ibm system_x3100_m4_firmware *
ibm system_x3630_m4_firmware *
ibm flex_system_x880_x6_firmware *
ibm idataplex_dx360_m4_firmware *
ibm system_x3250_m5_firmware *
ibm flex_system_x220_m4_firmware *
ibm flex_system_x280_x6_firmware *
ibm flex_system_x440_m4_firmware *
ibm flex_system_x222_m4_firmware *
lenovo flex_system_x240_m4_firmware *
ibm flex_system_x240_m4_firmware *
ibm bladecenter_hs23e_firmware *
ibm system_x3100_m5_firmware *
ibm idataplex_dx360_m4_water_cooled_firmware *
ibm system_x3850_x6_firmware *
ibm system_x3300_m4_firmware *
ibm bladecenter_hs23_firmware *
CVE-2019-4008 MEDIUM

API Connect V2018.1 through 2018.4.1.1 is impacted by access token leak. Authorization tokens in some URLs can result in the tokens being written to log files. IBM X-Force ID: 155626.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 3.9 5.9

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-532,

Products Affected

Vendor Product Version
ibm api_connect *
CVE-2019-4014 HIGH

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-Force ID: 155892.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 1.8 5.9

CVSS 2.0

Severity: HIGH

Problem Type: CWE-120,

Products Affected

Vendor Product Version
ibm db2 11.1.2.2
ibm db2 11.1.3.3
ibm db2 11.1.4.4
ibm db2 9.7.0.9
ibm db2 10.1.0.1
ibm db2 10.1.0.6
ibm db2 9.7.0.5
ibm db2 9.7.0.0
ibm db2 9.7.0.6
ibm db2 9.7.0.10
ibm db2 11.1.0.0
ibm db2 9.7.0.8
ibm db2 10.5.0.1
ibm db2 10.1.0.4
ibm db2 10.5.0.9
ibm db2 10.5.0.8
ibm db2 10.5.0.2
ibm db2 9.7.0.2
ibm db2 9.7.0.1
ibm db2 10.1.0.5
ibm db2 10.5.0.10
ibm db2 10.1.0.2
ibm db2 10.5.0.4
ibm db2 11.1.1.1
ibm db2 10.1.0.0
ibm db2 10.1.0.3
ibm db2 10.5.0.7
ibm db2 9.7.0.4
ibm db2 9.7.0.7
ibm db2 10.5.0.0
ibm db2 9.7.0.3
ibm db2 10.5.0.5
ibm db2 10.5.0.3
ibm db2 9.7.0.11
ibm db2 10.5.0.6
CVE-2019-4015 HIGH

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-ForceID: 155893.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 1.8 5.9

CVSS 2.0

Severity: HIGH

Problem Type: CWE-120,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2 11.1
ibm db2 10.1
ibm db2 9.7
CVE-2019-4016 HIGH

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-ForceID: 155894.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 1.8 5.9

CVSS 2.0

Severity: HIGH

Problem Type: CWE-120,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2 11.1
ibm db2 10.1
ibm db2 9.7
CVE-2019-4027 LOW

IBM Sterling B2B Integrator 5.2.0.1 through 6.0.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-ForceID: 155905.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 5.4 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N 2.3 2.7

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator *
CVE-2019-4028 LOW

IBM Sterling B2B Integrator 5.2.0.1 through 6.0.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 155906.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 5.4 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N 2.3 2.7

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator *
CVE-2019-4029 LOW

IBM Sterling B2B Integrator 5.2.0.1 through 6.0.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-force ID: 155907.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 5.4 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N 2.3 2.7

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator *
CVE-2019-4030 LOW

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 155946.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 5.4 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N 2.3 2.7

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm websphere_application_server *
ibm websphere_virtual_enterprise 7.0
ibm websphere_virtual_enterprise 8.0
CVE-2019-4032 HIGH

IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.1.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-ForceID: 155998.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 3.9 5.9

CVSS 2.0

Severity: HIGH

Problem Type: CWE-89,

Products Affected

Vendor Product Version
ibm financial_transaction_manager *
CVE-2019-4034 MEDIUM

IBM Content Navigator 3.0CD is could allow an attacker to execute arbitrary code on a user's workstation. When editing an executable file in ICN with Edit service, it will be executed on the user's workstation. IBM X-Force ID: 156000.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 2.8 5.9

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm content_navigator 3.0.0
CVE-2019-4035 MEDIUM

IBM Content Navigator 3.0CD could allow attackers to direct web traffic to a malicious site. If attackers make a fake IBM Content Navigator site, they can send a link to ICN users to send request to their Edit client directly. Then Edit client will download documents from the fake ICN website. IBM X-Force ID: 156001.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 5.4 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N 2.3 2.7

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-601,

Products Affected

Vendor Product Version
ibm content_navigator 3.0.0
CVE-2019-4038 MEDIUM

IBM Security Identity Manager 6.0 and 7.0 could allow an attacker to create unexpected control flow paths through the application, potentially bypassing security checks. Exploitation of this weakness can result in a limited form of code injection. IBM X-Force ID: 156162.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 6.2 MEDIUM CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H 0.3 5.9

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-94,

Products Affected

Vendor Product Version
ibm security_identity_manager *
CVE-2019-4040 MEDIUM

IBM I 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 156164.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 6.1 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N 2.8 2.7

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ibm i 7.2
ibm i 7.3
CVE-2019-4043 MEDIUM

IBM Sterling B2B Integrator Standard Edition 5.2.0 snf 6.0.0.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 156239.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.1 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L 2.8 4.2

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-611,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator *
ibm sterling_b2b_integrator 6.0.0.0
CVE-2019-4046 MEDIUM

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by improper handling of request headers. A remote attacker could exploit this vulnerability to cause the consumption of Memory. IBM X-Force ID: 156242.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 3.9 3.6

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-400,

Products Affected

Vendor Product Version
ibm websphere_application_server *
CVE-2019-4052 MEDIUM

IBM API Connect 2018.1 and 2018.4.1.2 apis can be leveraged by unauthenticated users to discover login ids of registered users. IBM X-Force ID: 156544.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 3.9 3.6

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ibm api_connect *
CVE-2019-4059 MEDIUM

IBM Rational ClearCase 1.0.0.0 GIT connector does not sufficiently protect the document database password. An attacker could obtain the password and gain unauthorized access to the document database. IBM X-Force ID: 156583.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 3.9 5.9

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-522,

Products Affected

Vendor Product Version
ibm rational_clearcase *
CVE-2019-4061 MEDIUM

IBM BigFix Platform 9.2 and 9.5 could allow an attacker to query the relay remotely and gather information about the updates and fixlets deployed to the associated sites due to not enabling authenticated access. IBM X-Force ID: 156869.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 5.3 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N 3.9 1.4

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
ibm bigfix_platform *
CVE-2019-4063 MEDIUM

IBM Sterling B2B Integrator 5.2.0.1 through 6.0.0.0 Standard Edition could allow highly sensitive information to be transmitted in plain text. An attacker could obtain this information using man in the middle techniques. IBM X-ForceID: 157008.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 5.9 MEDIUM CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N 2.2 3.6

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-319,

Products Affected

Vendor Product Version
ibm sterling_b2b_integrator *
CVE-2019-4080 MEDIUM

IBM WebSphere Application Server Admin Console 7.5, 8.0, 8.5, and 9.0 is vulnerable to a potential denial of service, caused by improper parameter parsing. A remote attacker could exploit this to consume all available CPU resources. IBM X-Force ID: 157380.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 6.5 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H 2.8 3.6

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-400,

Products Affected

Vendor Product Version
ibm websphere_application_server *
CVE-2019-4093 LOW

IBM Tivoli Storage Manager (IBM Spectrum Protect 8.1.7) could allow a user to restore files and directories using IBM Spectrum Prootect Client Web User Interface on Windows that they should not have access to due to incorrect file permissions. IBM X-Force ID: 157981.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 4.4 MEDIUM CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N 1.8 2.5

CVSS 2.0

Severity: LOW

Problem Type: CWE-732,

Products Affected

Vendor Product Version
ibm spectrum_protect 8.1.7
CVE-2019-4094 HIGH

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 binaries load shared libraries from an untrusted path potentially giving low privilege user full access to root by loading a malicious shared library. IBM X-Force ID: 158014.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 1.8 5.9

CVSS 2.0

Severity: HIGH

Problem Type: CWE-427,

Products Affected

Vendor Product Version
ibm db2 10.5
ibm db2 11.1
ibm db2 10.1
ibm db2 9.7